Feed aggregator

The U.S., China and Internet Glass Houses

Threatpost for B2B - Tue, 05/20/2014 - 11:50
That was quite a show the government put on Monday. The dramatic press conference featuring Attorney General Eric Holder, the coordinated press leaks ahead of the announcement, the strong statements about the sanctity of American commerce and how the United States will prosecute those who conduct cyberespionage against American targets. There were even cyber-wanted posters. […]

More than 90 Arrested in Blackshades RAT Takedown

Threatpost for B2B - Tue, 05/20/2014 - 09:44
The FBI, Justice Department and law enforcement in 19 countries announced the takedown of the Blackshades operation, responsible for dissemination of the Blackshades RAT.

Analysis: Spam and online gambling - a surefire loser

Secure List feed for B2B - Tue, 05/20/2014 - 06:00
Who hasn’t dreamt of Lady Luck smiling on them and bestowing untold wealth without having to make the slightest effort?

XMPP Mandating Encryption on Messaging Service Operators

Threatpost for B2B - Mon, 05/19/2014 - 16:07
Beginning today, operators of instant massaging services that rely on the extensible messaging and presence protocol (XMPP) are expected to deploy encryption into the messaging platforms they maintain.

Malvertising Redirecting to Microsoft Silverlight Exploits

Threatpost for B2B - Mon, 05/19/2014 - 15:04
Researchers at Cisco spotted a recent malvertising campaign where victims were redirected by ads on the AppNexus network to sites hosting the Angler Exploit Kit and exploits against Silverlight vulnerabilities.

Facebook Takes Tougher Stand Against BREACH Attack

Threatpost for B2B - Mon, 05/19/2014 - 13:30
Facebook disclosed today how it has beefed up cross-site request forgery (CSRF) tokens in order to ward off the BREACH attack.

U.S. Indicts Five Chinese Army Officers for Alleged Cyberespionage Operations

Threatpost for B2B - Mon, 05/19/2014 - 11:30
The United States government on Monday made an unprecedented move in its efforts to combat cyberespionage operations against American companies, efforts that until now had mainly consisted of strongly worded statements and diplomacy. The Department of Justice indicted five officers of the Chinese People’s Liberation Army for allegedly hacking into networks run by companies such […]

Retailers Form ISAC to Share Threat Data

Threatpost for B2B - Mon, 05/19/2014 - 10:33
From the beginning of the cybercrime epidemic, retailers have been among the most frequent targets, and the last year has seen some of the larger compromises in history. The Target data breach is at the top of that list, involving more than 100 million customers, and after years of increasingly serious compromises the retail industry […]

Blog: The Bitcoin 2014 Conference - Are Crypto-Currencies Reaching Maturity?

Secure List feed for B2B - Sat, 05/17/2014 - 10:12
As the Bitcoin 2014 conference is unwinding here in Amsterdam today, I have to admit that I am impressed by how the crypto-currency community is making rapid steps towards reaching maturity.

Embedded Devices Leak Authentication Data Via SNMP Community String

Threatpost for B2B - Fri, 05/16/2014 - 13:55
Rapid7 today disclosed zero-day vulnerabilities in an enterprise-grade load balancer from Brocade and home DSL routers and cable modems that allow a hacker to steal authentication data from the SNMP community string.

PayPal Fixes Serious Account Hijacking Bug in Manager

Threatpost for B2B - Fri, 05/16/2014 - 11:30
PayPal patched a hole in its Manager functionality this week that could have made it easy for an attacker to hijack an admin’s account, change their password and steal their personal information -- not to mention their savings.

Snowden, Surveillance Prompt Tech Companies to Re-evaluate Privacy Attitudes

Threatpost for B2B - Fri, 05/16/2014 - 11:25
The EFF's annual Who Has Your Back? report praises Apple and Yahoo for its gains in transparency and fighting for users' privacy and civil liberties, while it singles out Snapchat for its shortcomings.

Critical Infrastructure Companies Continue to Patch Heartbleed

Threatpost for B2B - Fri, 05/16/2014 - 11:22
Industrial control systems manufacturers are continuing to discover and provide fixes for the OpenSSL Heartbleed vulnerability.

Apple Releases OS X 10.9.3, Fixes Serious Flaw in iTunes

Threatpost for B2B - Fri, 05/16/2014 - 02:39
Apple has released a new version of OS X Mavericks, which includes all of the security fixes it pushed out last month. OS X 10.9.3 includes the patches for the so-called triple handshake SSL vulnerability, as well as fixes for several remote code-execution vulnerabilities. The company also released a patch for iTunes that fixes a […]
Syndicate content