The actor behind the Ursnif banking Trojan has been using new evasive macros in their latest infection campaign, demonstrating continuous evolution of tools and techniques, Proofpoint researchers reveal.
read more
U.S. Lawmakers: Russian Hackers Aim to Disrupt Election
Two US lawmakers who are members of their respective intelligence committees said Thursday that a spate of recent cyber attacks suggests Russia is trying to disrupt the November election.
read more
Yahoo Confirms Massive Data Breach of 500 Million Accounts
Following rumors that an announcement was soon to come, Yahoo! said Thursday that hackers managed to access data from at least 500 million user accounts in a cyberattack dating back to 2014.
read more
Organizations Exposed to Attacks by Flaws in Kerio Firewalls
Several important vulnerabilities affecting a firewall product from Kerio Technologies can be exploited by remote attackers to completely compromise an organization’s internal network, SEC Consult warned on Thursday.
read more
Privileged Credentials Remain Security Weak Point
read more
Continue readingGoogle to Revoke OAuth 2.0 Tokens Upon Password Reset
A new OAuth 2.0 token revocation rule will soon cause third-party mail apps to stop syncing data upon user password change, Google revealed on Wednesday.
read more
Is it Finally Time for Open Security?
One of the distinct advantages of working in the IT industry for over 35 years is all of the direct and indirect experience that brings, as well as the hindsight that comes with that.
read more
Over a Dozen Vulnerabilities Patched in OpenSSL
The OpenSSL Project announced on Thursday that more than a dozen vulnerabilities have been patched in OpenSSL with the release of versions 1.1.0a, 1.0.2i and 1.0.1u.
read more
The Latest Must-Have Car Accessory: Security
Fall is a great time of year. The kids go back to school. The weather begins to cool and the leaves change. Lord Football returns to his autumnal throne. Television shows return for a new season.
read more
Flaws in Cisco Cloud Services Platform Allow Command Execution
Cisco’s Cloud Services Platform (CSP), a product that is part of the company’s virtual networking offering, is plagued by two serious vulnerabilities that can be exploited by remote attackers to execute arbitrary code and commands.
read more

