Vulnerability Lab security researchers claim that Wickr Inc., the company behind encrypted messaging service Wickr, hasn’t paid promised bounties for multiple vulnerabilities disclosed years ago, although the company did patch all of them.
read more
Managing Risks of “Potentially Unwanted” Programs in the Enterprise
Potentially Unwanted Programs Put Enterprise Data at Risk. How do You Tell Good Apps from Bad Apps?
read more
The Battle With “Potentially Unwanted” Programs in the Enterprise
Potentially Unwanted Programs Put Enterprise Data at Risk. How do You Tell Good Apps from Bad Apps?
read more
China-Linked Cyberspies Lure Victims With Security Conference Invites
A China-linked cyber espionage group known as Lotus Blossom, Elise and Esile has used fake invitations to Palo Alto Networks’ upcoming Cybersecurity Summit to trick users into installing a piece of malware on their systems.
read more
Many Joomla Sites Hacked via Recently Patched Flaws
Less than 24 hours after Joomla released patches for a couple of critical account creation vulnerabilities, researchers noticed that malicious actors had already started exploiting the flaws in the wild.
read more
Network Visibility: See Mo’ Evil
Acrid gasoline fumes filled the rundown barn as a chainsaw revved too close for comfort. Hot breath brushed my ear with a taunting echo, “I want your pretty hair. I want your pretty hair.” I couldn’t see a thing, but perhaps that’s because my face was burrowed too far into the back of my husband’s neck as I clung to him like a crazed spider monkey. “R-u-n!!!”
read more
AtomBombing: The Windows Vulnerability that Cannot be Patched
Researchers have discovered a code-injection vulnerability in the Windows operating system that cannot, because of the nature of the operating system, be patched. It could be used to bypass current malware protection solutions in place.
read more
Mirai Botnet Infects Devices in 164 Countries
Mirai, the infamous botnet used in the recent massive distributed denial of service (DDoS) attacks against Brian Krebs’ blog and Dyn’s DNS infrastructure, has ensnared Internet of Things (IoT) devices in 164 countries, researchers say.
read more
Australian Red Cross Leaks Blood Donor Data
The Australian Red Cross Blood Service apologised on Friday to donors after one of its third-party service providers inadvertently made accessible a backup database containing the personal details of 550,000 individuals.
read more
How to Intelligently Share Cyber Threat Intelligence
A lot has been written on the importance of information sharing in the cybersecurity community. There is seemingly an ISAC for every industry these days. We’re talking the talk, and on the surface it looks like some organizations are starting to walk the walk. But in reality, we’re still just scratching the surface when it comes to sharing cyber threat information, let alone sharing intelligence that is useful and practical.
read more

