After Mozilla announced that it might ban new certificates issued by Chinese certificate authority (CA) WoSign and its subsidiary StartCom for at least one year, Apple has decided to take measures.
read more
EMC Patches Critical Flaws in VMAX Storage Products
Researchers at vulnerability management services provider Digital Defense have identified a total of six flaws in the administration interface of EMC VMAX enterprise storage products.
read more
OpenJPEG Flaw Allows Code Execution via Malicious Image Files
An update released last week for the OpenJPEG library addresses several bugs and important security issues, including a flaw that can be exploited to execute arbitrary code using specially crafted image files.
read more
DressCode Malware Infects 400 Apps in Google Play
A recently discovered mobile malware family called DressCode has infected over 400 applications that are being distributed via Google Play, Trend Micro security researchers warn.
read more
Over 400 Vulnerabilities Reported to ICS-CERT in 2015
The Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) last week published its annual vulnerability coordination report for the fiscal year 2015. The report provides details on the number and types of security holes disclosed to the agency last year.
read more
Exploit Kits Take Cyberattacks to the Masses. But They’re Preventable.
Exploit Kits Can be Stopped When the Proper Steps are Taken
read more
DNS Data Can Help Attackers Deanonymize Tor Users
Researchers have disclosed a theoretical attack scenario that could allow global or semi-global adversaries to leverage Domain Name System (DNS) traffic to deanonymize Tor users.
read more
Hacker Releases Source Code of IoT Malware Mirai
A hacker has released the source code of Mirai, the Internet of Things (IoT) malware used to launch massive distributed denial-of-service (DDoS) attacks against the websites of journalist Brian Krebs and hosting provider OVH.
read more
Brazilian Hackers Using RDP to Spread Xpan Ransomware
Brazilian cybercriminals are expanding their tactics and have recently adopted ransomware as a new means of attack, Kaspersky Lab reveals.
read more
Encryptor RaaS Shuts Down Without Releasing Master Key
Security researchers earlier this year managed to zero-in on the Encryptor Ransomware-as-a-Service (Raas), which forced the developer to shut down the operation, but without releasing the master key to help victims.
read more

