The European Union has published its proposal (PDF) for a revised Regulation on the export of dual use goods.
read more
Sensitive FDA Systems at Risk of Cyberattacks: Audit
A report made available this week by the U.S. Government Accountability Office (GAO) shows that the Food and Drug Administration (FDA) needs to address some serious cybersecurity weaknesses that expose industry and public health data.
read more
Yahoo! Doesn’t Revoke iOS Mail Access After Password Change
Users resetting their Yahoo! passwords might also want to check the list of authorized apps and devices, because iOS Mail will continue to have access to the account even after a password reset, researchers discovered.
read more
Cisco Forgets to Remove Testing Interface From Security Appliance
Cisco inadvertently introduced a critical vulnerability in its email security appliances by forgetting to remove an internal testing interface from software releases made available to customers.
read more
Building Automation Products Vulnerable to Remote Attacks
Building automation products from American Auto-Matrix are affected by a couple of high-severity vulnerabilities that allow remote hackers to compromise the affected system, ICS-CERT warned on Thursday.
read more
Tofsee Malware Distribution Switched From Exploit Kit to Spam
The RIG exploit kit recently stopped distributing Tofsee and cybercriminals have decided to use the botnet’s own spamming capabilities to deliver the malware, Cisco’s Talos team reported on Thursday.
read more
Zerodium Boosts Bounty for iOS Exploit to $1.5 Million
ZERODIUM, a leading zero-day exploit broker, has published its revised bounty figures for the amount it will pay for new zero-days. The highest figure is reserved for iOS – now up to $1.5 million for "fully functional/reliable exploits meeting ZERODIUM's requirements". It was 'only' $500,000 in September 2015.
read more
Dridex Banking Trojan Adopts Improved Encryption
The infamous Dridex banking Trojan has adopted new tactics and more advanced encryption and obfuscation to better avoid detection and to hinder security analysis, researchers warn.
read more
“Vendetta Brothers” Are After Your Payment Card Data
If you live in the United States or one of several Nordic countries, your payment card data might be of interest to a duo of cybercriminals that FireEye refers to as the “Vendetta Brothers.”
read more
Firms Spend Big Money on Flaws They Could Fix in Development
Companies are spending millions on bug bounty programs whose goal is to identify vulnerabilities, but it might be more efficient to take a proactive approach and focus on identifying flaws in the development phase.
read more

