Threatpost for B2B

Syndicate content
The First Stop For Security News
Updated: 11 hours 10 min ago

FTC Hires Privacy Researcher Ashkan Soltani as Chief Technologist

Tue, 10/21/2014 - 12:44
The FTC has hired Ashkan Soltani, a highly regarded and respected technologist and privacy researcher, as its chief technologist. The move is the latest in a string of interesting hires by the Federal Trade Commission. In 2009 the agency hired Chris Soghoian, a privacy and security researcher, as its first in-house principal technologist. Soghoian had […]

Staples Looking into Potential Payment Card Breach

Tue, 10/21/2014 - 12:08
The office supply chain Staples is reportedly looking into a payment data card breach, potentially making it the latest in a long line of retail establishments to suffer a compromise over the last year.

Google Adds Hardware Security Key For Account Protection

Tue, 10/21/2014 - 09:18
Google is introducing an improved two-factor authentication system for Gmail and its other services that uses a tiny hardware token that will only work on legitimate Google sites. The new Security Key system is meant to help defeat attacks that rely on highly plausible fake sites that are designed to capture users’ credentials. Attackers often go […]

Obama Executive Order Forces Chip & Pin Payment on Government

Mon, 10/20/2014 - 14:59
The Obama administration has issued an executive order aimed at speeding up the adoption of chip and PIN or EMV payment systems here in the United States.

EFF, Snowden Dispute FBI Claims on Device Encryption

Mon, 10/20/2014 - 12:42
The FBI has long said that the use of strong encryption software hampers the bureau’s investigations and makes life easier for criminals. Current FBI Director James Comey continued this line of reasoning in a speech on Oct. 17, saying that the use of crypto could lead the country to a dark place, and the EFF […]

Privacy Criticism Hits OSX Yosemite over Location Data

Mon, 10/20/2014 - 09:24
Apple has fixed a huge number of security vulnerabilities in OS X and iTunes and, at the same time, is being hit with criticisms about privacy issues in the new version of OS X. The latest version of the operating system, known as Yosemite, sends location information to Apple by default via the Spotlight search […]

Microsoft Selective with FASTFAT Driver Patch Deployments

Fri, 10/17/2014 - 13:20
Microsoft, in 2009, silently fixed a FASTFAT driver flaw in Windows 7, leaving the same vulnerability in older Windows versions until it was patched this week.

Microsoft Changing Detection of Adware and Browser Modifiers

Fri, 10/17/2014 - 13:06
One of the not-so-great side effects of the transition to virtually everything being done in the Web browser now is that advertisers, attackers and scammers constantly are trying to get their code to run in users’ browsers, any way they can. A lot of this is done through extensions and browser objects, some of which […]

APTs Target Victims with Precision, Ephemeral Malvertising

Fri, 10/17/2014 - 12:33
A new precisely targeted and fleeting form of malvertising is being deployed by APT groups to target organizations in the U.S. defense industrial base.

Facebook Tool Mines Stolen Passwords, Notifies Affected Users

Fri, 10/17/2014 - 11:00
Facebook announced that it has developed a tool that combs through paste sites where stolen credentials are posted looking for Facebook passwords. Users are then notified and must do a password reset.

SAP Patches DoS Flaw in Netweaver

Fri, 10/17/2014 - 09:32
SAP has released a fix for a remotely exploitable denial-of-service in its Netweaver platform. The bug is confirmed to affect several versions of the platform and may be present in others, as well. Researchers at Core Security discovered the vulnerability and reported it to SAP in June. Netweaver is a platform that allows users to build and […]

Recognizing Evasive Behaviors Seen as Key to Detecting Advanced Malware

Thu, 10/16/2014 - 13:55
Academic Giovanni Vigna of UCSB has been studying techniques used by malware writers to evade analysis, and urges detection tools to develop an understanding of evasive behavior.

Mobile Device Encryption Could Lead to a ‘Very, Very Dark Place’, FBI Director Says

Thu, 10/16/2014 - 12:48
FBI Director James Comey said Thursday that the recent movement toward default encryption of smartphones and other devices could “lead us to a very, very dark place.” Echoing comments made by law enforcement officials for the last several decades, Comey said that the advanced cryptosystems available today threaten to cripple the ability of intelligence and law […]

OpenSSL Releases Patch for POODLE Attack

Thu, 10/16/2014 - 09:29
The OpenSSL Project has released a new version of the encryption software, which patches several security flaws, including the bug that is exploited by the POODLE attack on SSLv3. The updated versions of OpenSSL come just a couple of days after a trio of researchers at Google revealed the POODLE attack, which allows an attacker to […]

Facebook to Double Bounty Payouts For Ad Code Bugs

Wed, 10/15/2014 - 14:00
Facebook said it will double bug bounty payouts for the remainder of the year for serious vulnerabilities in its ad code.

Two Patched Zero Days Targeting Windows Kernel

Wed, 10/15/2014 - 13:58
Security firms have peeled back the layers on two zero day vulnerabilities that are currently being used in limited, targeted attacks against the Windows Kernel.

Drupal Fixes Highly Critical SQL Injection Flaw

Wed, 10/15/2014 - 12:34
Drupal has patched a critical SQL injection vulnerability in version 7.x of the content management system that can allow arbitrary code execution.

Microsoft Extends SHA-2, TLS Support for Windows

Wed, 10/15/2014 - 10:40
Microsoft announced that it has extended support for SHA-2 and TLS in supported versions of Windows.

Browser Vendors Move to Disable SSLv3 in Wake of POODLE Attack

Wed, 10/15/2014 - 09:35
With details of the new POODLE attack on SSLv3 now public, browser vendors are in the process of planning how they're going to address the issue in their products in a way that doesn't break the Internet for millions of users but still provides protection.

Java Reflection API Woes Resurface in Latest Oracle Patches

Wed, 10/15/2014 - 08:55
Oracle's Critical Patch update addresses 154 vulnerabilities, many of which are remotely exploitable. Security Explorations of Poland, meanwhile, published details on a number of Java flaws in the Java Reflection API.