The White House today announced that Brigadier General (retired) Gregory J. Touhill has been named the first Federal Chief Information Security Officer (CISO).
read more
WordPress Flaw Allows XSS Attack via Image Filenames
WordPress users have been advised to update their installations to version 4.6.1, which fixes a couple of security flaws and over a dozen functionality bugs affecting previous versions.
read more
“Armada Collective” DDoS Threats Strike Again
There is a current extortion campaign that seems particularly focused in the UK. The threat is to deliver a DDoS attack together with ransomware infections if the victim does not pay a ransom in bitcoins. The ransom starts relatively low at just 1 bitcoin, but increases to 20 bitcoins if not paid within a certain time. The attackers claim to be the Armada Collective.
read more
The Malware Battle Is Mostly Silent
Malware’s success relies on the ability to remain stealthy, and the authors of malicious programs go to great lengths to make that happen, while also ensuring that their identity remains hidden. As a general rule, malware developers tend to avoid contact with security researchers, to avoid stepping into the spotlight, but this rule can be broken occasionally.
read more
DropboxCache Cross-Platform Backdoor Targets OS X
DropboxCache, a Linux backdoor that was found earlier this year to have migrated to Windows, is targeting Mac OS X devices as well, Kaspersky Lab security researchers warn.
read more
Leadership, Not Technology, Blamed for Huge OPM Breach
A report published this week by the U.S. House of Representatives Committee on Oversight and Government Reform said the data breaches disclosed by the Office of Personnel Management (OPM) last year were a result of culture and leadership failures, and should not be blamed on technology.
read more
USB Hacking Devices Can Steal Credentials From Locked Computers
A researcher has shown how easy it is for hackers to steal credentials from locked Windows and Mac OS X computers using a small USB device.
read more
St. Jude Sues MedSec Over Device Security Allegations
St. Jude Medical has filed a lawsuit against MedSec and Muddy Waters, claiming that the companies made financially motivated false statements regarding the security of its medical devices.
read more
Managed Security Services, a Mission and Service Evolution
Faced with a proliferation of security products and point solutions to combat increasingly sophisticated threats, it didn’t take long for companies to recognize that a certain amount of bench strength – knowledge and personnel – was required to manage unprecedented complexity and get the full value from these investments. Organizations turned to managed security service providers (MSSPs) to alleviate the burden of maintaining the health of these systems and responding to tickets.
read more
Intel to Spin Off McAfee as Independent Security Firm
Roughly six years after announcing that it would acquire security firm McAfee, Intel Corporation said it would spin off its security division as an independent company under the name McAfee.
read more

