Threatpost for B2B

Syndicate content
The First Stop For Security News
Updated: 17 hours 59 min ago

Backoff Sinkhole Reveals Sorry Point-of-Sale Security

Fri, 08/29/2014 - 14:25
A new analysis of sinkholes Backoff point-of-sale malware paints a bleak picture of the state of point-of-sale security.

CryptoWall’s Haul: $1M in Six Months

Fri, 08/29/2014 - 12:41
The CryptoWall ransomware has proven to be a profitable criminal enterprise, netting more than $1.1 million in six months. More than 1,600 victims have surfaced and more than 5 billion files have been encrypted.

Mozilla to Support Key Pinning in Firefox 32

Fri, 08/29/2014 - 11:12
Mozilla is planning to add support for public-key pinning in its Firefox browser in an upcoming version. In version 32, which would be the next stable version of the browser, Firefox will have key pins for a long list of sites, including many of Mozilla’s own sites, all of the sites pinned in Google Chrome […]

Nearly 100k Bugzilla Users Affected by Data Disclosure

Fri, 08/29/2014 - 09:31
The email addresses and encrypted passwords of nearly 100,000 users of Mozilla’s Bugzilla system were left on a publicly accessible server for several months earlier this year, the company said. The disclosure comes just a few weeks after Mozilla advised members of its Mozilla Developer Network to change their passwords because of a similar incident. On […]

IEEE Guides Software Architects Toward Secure Software Design

Thu, 08/28/2014 - 14:18
The IEEE's Center for Secure Design's new guidance for software architects called "Avoiding the Top 10 Software Security Design Flaws" debuted this week.

Windows XP-Heavy Turkey Overrun with GameOver Zeus Infections

Thu, 08/28/2014 - 08:50
GameOver Zeus and Sality banking malware infections are rampant in emerging countries such as Turkey where older, unpatched computers are prevalent, and security awareness is low.

Microsoft Fixes Broken Security Patch MS14-045

Wed, 08/27/2014 - 14:08
Microsoft re-released MS14-045 today two weeks after pulling it from Windows Update because the patch was causing system crashes and blue screens of death.

Verizon Bolsters User Authentication With QR Codes

Wed, 08/27/2014 - 14:04
Verizon announced Tuesday it will soon begin using QR codes to allow users to log in to sites and programs in its Universal Identity Services portfolio., TMZ Serving Malvertising Redirects to Angler Exploit Kit

Wed, 08/27/2014 - 11:48
Popular websites TMZ and are among a handful serving malicious ads redirecting visitors to the Angler Exploit Kit.

IBM: Heartbleed Attacks Thousands of Servers Daily

Wed, 08/27/2014 - 10:23
The 2014 IBM X-Force Threat Intelligence Quarterly takes a look back at Heartbleed and how organizations were affected by it.

Netflix Open Source Security Tools Solve Range of Challenges

Tue, 08/26/2014 - 15:10
Netflix engineers released two new application security tools to open source this week, a continuing effort from the streaming services company.

South Korean Data Breach Compromises 27 Million

Tue, 08/26/2014 - 12:55
A data breach in South Korea appears to have impacted as many 27 million citizens, up to 70 percent of the nation’s population.

50 Security Flaws Fixed in Google Chrome

Tue, 08/26/2014 - 10:40
Google has fixed 50 security vulnerabilities in its Chrome browser, including a critical string of bugs that can allow an attacker to execute arbitrary code outside of the browser’s sandbox. This is one of the larger batches of fixes that Google has produced for Chrome recently. The company releases frequent updates for the browser and often […]

Secret Service Warns 1,000 Businesses Hit by Backoff PoS Malware

Mon, 08/25/2014 - 14:30
DHS and the Secret Service warned businesses to be proactive about scanning for point-of-sale malware, especially Backoff, which has hit more than 1,000 businesses already.

AdThief iOS Malware Affecting 75K Jailbroken Devices

Mon, 08/25/2014 - 13:21
A relatively new form of malware on iOS is estimated to have stolen revenue from 22 million ads and infected upwards to 75,000 devices so far.

Side-Channel Android Weakness Likely on Other Platforms

Mon, 08/25/2014 - 12:32
Researchers have discovered a weakness in Android that is likely present in other leading operating systems that can be abused and lead to information leakage.

Mozilla Adding Granular App Permissions to Firefox OS

Mon, 08/25/2014 - 11:06
Mozilla is set to add a feature to its mobile Firefox OS that will give users the ability to revoke any application’s permissions on a granular basis. Firefox OS is the open source operating system that Mozilla built for smartphones. The software runs on a variety of devices from manufacturers such as Alcatel, ZTE and […]

PlayStation Network Back Online Following DDoS

Mon, 08/25/2014 - 10:25
Sony's PlayStation Network is back online following a bizarre series of events over the weekend involving a large-scale DDoS attack and a bomb threat against a commercial airline.

NIST Releases Secure Shell Guidance Document

Fri, 08/22/2014 - 14:08
NIST released Interagency Report 7966 this week, a guidance document for organizations using the Secure Shell network protocol for automated access.

Akeeba Patches Bypass Vulnerability in Joomla

Fri, 08/22/2014 - 13:10
The developers behind Akeeba fixed an outstanding issue this week that could have let anyone download users' site backups, passwords and user lists.