A newly discovered variant of the HummingBad Android malware has been downloaded millions of times after infecting 20 applications in Google Play, Check Point security researchers warn.
read more
China Cracks Down on Bids to Bypass Online Censorship
Beijing – China has announced a 14-month campaign to "clean up" internet service providers and crack down on devices such as virtual private networks (VPNs) used to evade strict censorship.
read more
Researchers Link “de-identified” Browsing History to Social Media Accounts
Researchers Demonstrate How "de-identified" Web Browsing Histories Can be Linked to Social Media Accounts
read more
Overhyped Media Reports Bad For ICS Security: Experts
Overblown media reports describing critical infrastructure incidents can have a negative impact on cybersecurity in the industrial control systems (ICS) sector, experts have warned.
read more
Heartbleed Still Affects 200,000 Devices: Shodan
While the number of services affected by the OpenSSL flaw known as Heartbleed has decreased, the Shodan search engine has still found nearly 200,000 vulnerable devices.
read more
Finding the ROI in Threat Intelligence
Threat intelligence can play an important role in improving an organization’s overall cybersecurity posture, provided the right case is made and the right processes are put in place. In the past, I’ve addressed the topic of whether an organization should invest in a dedicated threat intelligence team or subscribe to a threat intelligence service.
read more
Yahoo Faces SEC Probe into Breach Disclosures
In November 2016 Yahoo announced that it was cooperating with federal, state and foreign agencies, including the US Securities and Exchange Commission (SEC), who were seeking information on the data breaches also announced during 2016. In December, the SEC issued requests for relevant documents from Yahoo, and Yahoo is now reported to be under investigation.
read more
Expert Hacks Internal DoD Network via Army Website
A security researcher who took part in the Hack the Army bug bounty program managed to gain access to an internal Department of Defense (DoD) network from a public-facing Army recruitment website.
read more
Symantec Revokes Wrongly Issued Certificates
Symantec has revoked numerous wrongly issued certificates, including for domains such as example.com and test.com. This is not the first time the security firm’s certificate issuance practices have come under scrutiny.
read more
Satan RaaS Promises Large Gains With Zero Coding Needed
A newly discovered family of ransomware is being offered via the Ransomware-as-a-Service (RaaS) business model, allowing cybercriminals to easily customize their own versions of the malware, researchers explain.
read more


