Menu

Link

Come see me speaking at The Shard in London about security
CloudPets Notifies California AG of Data Breach
Slack Fixes Cross-Origin Token Theft Bug
Robots Rife With Cybersecurity Holes
Software engineer detained at JFK airport; forced to prove he is really an engineer
Coachella festival website hacked; user data at risk
Million-Plus WordPress Sites Exposed by Vulnerable Plugin
How to recover from the OSX/Filecoder.E ransomware on your Mac
Gatekeeper-like feature for Windows 10 only allows apps to be installed from the Microsoft Store
Amazon Web Services suffer massive outage taking popular sites down
Google Discloses Critical Existing Bug in Internet Explorer and Edge
Siemens RUGGEDCOM NMS Equipment Vulnerable to CSRF, XSS
Dridex Trojan Gets A Major ‘AtomBombing’ Update
Unpatched SMB Zero Day Easily Exploitable
Stuffed Toys manufacturer hacked; millions of accounts and voice messages stolen
Children’s Voice Messages Leaked in CloudPets Database Breach
Torvalds Downplays SHA-1 Threat to Git
Our TV Viewing Habits Can Be Monitored for the Benefit of Marketers
Over 800,000 user account details stolen from vulnerable forums running vBulletin
Boeing Notifies 36,000 Employees Following Breach
126 vBulletin forums hacked; 819,977 accounts leaked on hacking forums
Google Discloses Another ‘High Severity’ Microsoft Bug
New Phishing Scam Targets Digital Payment and Online Banking Users
Evolved Version of MongoDB Ransomware Caught Targeting MySQL Databases
Katie Moussouris on Bug Bounty Programs, Hack the Army, and Wassenaar
Google Releases E2EMail to Open Source
Necurs Botnet Learns New DDoS Trick
Movie night? Nope. It’s a fake iTunes receipt from phishers targeting Apple users
Saudi-Iran: Proxy Wars Escalate To Direct Cyber Attacks
Change.org sends password reset email after CloudBleed bug
Cellebrite Can Now Unlock, Extract Data From iPhone 6 and 6 Plus
Was Your Google Account Unexpectedly Signed Out Today? Company Explains Why
Researchers Uncover New Leads Behind Shamoon2
Facebook goes down; comes back with suspicious account activity alert
Google Researchers Successfully Broke SHA-1 Web Security Tool
Threatpost News Wrap, February 24, 2017
Uber Sued by Google’s Waymo for Stealing its Self-Driving Car Technology
Cloudflare Bug Leaks Sensitive Data
It’s raining. It’s pouring. This fake weather app is stealing your credentials
British man arrested after 900,000 broadband routers knocked offline in Germany
CloudFlare Blames Internal Faults for Memory and Client Data Leakage
Someone from China is Distributing Mirai Malware Through Windows Botnet
Policy Experts Push To Make Vulnerability Equities Process Law
BitTorrent distribution sites dropping crypto-ransomware on macOS
First Practical SHA-1 Collision Attack Arrives
10 Powerful But Not Yet Promoted Antivirus for PC, Mac, Android, iPhone
Barely 1% of Android users are running Nougat, as Apple shows how to update devices properly
Impact of New Linux Kernel DCCP Vulnerability Limited
Smashing Security #009: False flags and hacker clues
Java, Python FTP Injection Attacks Bypass Firewalls
Destructive Mac ransomware spread as cracks to pirate commercial software
Publicly Disclosed Windows Vulnerabilities Await Patches
‘Zombie script’ deluges Internet Explorer 11 with pop-up alerts until user closes tab
How to Install TOR on Android and iOS Devices
Criminals Monetizing Attacks Against Unpatched WordPress Sites
Chrome Users Beware- Do Not Fall Prey to Missing Font Malware Campaign
BugDrop Malware Campaign Obtains Data by Compromising PC Microphones
Google Upspin Secure File-Sharing Released to Open Source
Intermediate CA Caching Could Be Used to Fingerprint Firefox Users
Gordon Ramsay’s father-in-law charged with hacking celebrity chef’s email
Good news and bad news on the Microsoft patch front
South Korea’s Asiana Airlines Website Hacked with Pro-Serbian Messages
Operation BugDrop – hackers steal gigabytes of data from organisations, record conversations
Smashing Security podcast: Macs and malware
Tiny “Spyslide Webcam Cover” Protects Your Privacy From Hackers, Spies
Check How Facebook AI Monitors Your Activities with this Crazy Chrome Extension
Data Stealing Malware TeamSpy Resurfaces in Spam Campaign
OpenSSL Update Fixes High-Severity DoS Vulnerability
You are not alone; YouTube is down for everyone (Updated)
TeamSpy malware targeting users through malicious TeamViewer app
Google Discloses Unpatched Microsoft Vulnerability
Rook Security on Online Extortion
Windows Botnet Spreading Mirai Variant
Prison for former sysadmin who hacked industrial facility and caused a million dollars worth of damage
How to protect your Microsoft account with two-step verification (2SV)
EA Servers Go Down; Battlefield 1 Servers Facing Outage
Gun Retailer Airsoft GI’s Forum Hacked; 65,000 User Accounts Leaked
Hacker defaces Donald Trump fundraising site via subdomain takeover attack
It’s too easy to steal a second-hand connected car
Donald Trump Website Hacked by Iraqi Hacker
Google goes public about unpatched Windows vulnerability
German parents urged to destroy data-collecting toy doll
Goodbye Spy Toy: Germany Bans My Friend Cayla Doll
Charging Smartphone in Public Ports Leads to Data Hack — So Let’s Stop
Apple May Introduce Facial Recognition Instead of Touch ID in iPhone 8
Hackers Selling Undetectable Proton Malware for macOS in 40 BTC
IDF targeted by sophisticated cyber espionage through Android devices
Squirrels, Not Hackers, Pose Biggest Threat to Electric Grid
SMTP Strict Transport Security Coming Soon to Gmail, Other Webmail Providers
Cris Thomas on Cyberwar Rhetoric
To Spy or Not to Spy; Congress to Decide
Graham Cluley named most entertaining security blog
Bangkok Police Arrests Ukrainian Hacker Planning ATM Malware Attack
Divide Between Work, Personal Data on Android Breached
Smashing Security podcast #008: ‘I’ll give you my Android when you pry it from my cold, dead paws’
Magento stores targeted by self-healing malware that steals credit card details
Another Yahoo Hack: Company Issues Security Notice to Users
Researchers develop battery that could run for more than a decade
Researchers Discover Yet Another Malware Designed to Compromise Mac Devices
More Yahoo users warned of malicious account access via forged cookies