The HeartBleed Vulnerability: The Next Step for Users
On Monday, April 7, 2014, the information security community received news about a vulnerability in the OpenSSL (Open Secure Socket Layers) cryptographic library called the “Heartbleed” bug that can allow hackers the ability to collect passwords, credit cards numbers, private keys and other data on servers that operated the software.
Shylock Malware Resurges, Targets Top U.S. Banks
A posting in Information Week in there security /attacks sections : Beware the latest version of the banking malware known as Shylock -- also called Caphaw -- which has been retooled to target customers of 24 different banks. Security firm Zscaler reported Wednesday that over the last month it's seen the number of Shylock infections […]
Microsoft Issues Emergency 'Fix It' For IE Amid Attacks
A posting from Dark Reading in there Attacks and Breaches section: Security experts are urging users to apply newly released mitigations as a stop-gap while waiting for Microsoft to patch a newly discovered critical vulnerability in Internet Explorer. Microsoft rushed out a Fix It tool yesterday in lieu of a patch after reports surfaced that attackers […]
Facebook vulnerability that allowed any photo to be deleted earns $12,500 bounty
Facebook vulnerability that allowed any photo to be deleted earns $12,500 bounty
Putty Security Update (SSH Tool)
Several vulnerabilities where discovered in PuTTY, a Telnet/SSH client
for X. The Common Vulnerabilities and Exposures project identifies the
following problems:
Microsoft's Big Bucks For Bugs Ups The Ante
A Posting from Dark Reading in there Application Security section: When Microsoft senior security strategist Katie Moussouris was asked two years ago whether Microsoft would ever consider a bug bounty program of its own, she left the door open ever so slightly on whether the software giant would abandon its longtime philosophy of not paying […]
'BinaryPig' Uses Hadoop To Sniff Out Patterns In Malware
A Posting from Dark Reading in there Threat Intelligence section: As the menagerie of malware collected by security firms continues to multiply, researchers are looking for new ways to analyze the massive data sets to find interesting information in their malware zoos. At the Black Hat Security Briefings in late July, one trio of researchers […]
Medical Devices Subject To Cyberattack, FDA Warns
A posting from Dark Reading in there Vulnerability and Threat Section: The Food and Drug Administration last week warned that patient health could be threatened by the introduction of malware into medical equipment or unauthorized access to configuration settings in medical devices and hospital networks. In an alert posted last week, the FDA noted that many medical […]