In an attempt to provide increased security and privacy for its users, WordPress has announced that upcoming features will require hosts to support HTTPS.
read more
10 Days of DDoS: an Actor’s “Working” Hours
Threat actors working on a schedule similar to that of legitimate businesses recently launched large distributed denial of service (DDoS) attacks for ten days in a row, CloudFlare researchers warn.
read more
Intelligence or Not Intelligence? That is the Question.
Contextual Intelligence Derived from Deep & Dark Web Data Can Deliver Truly Invaluable Insights
read more
China-Linked Spies Target Taiwan With IE Exploit
A cyberespionage group linked to China has been spotted targeting government organizations in Taiwan using an Internet Explorer vulnerability patched by Microsoft earlier this year.
read more
White House Should Lead Broad Cybersecurity Effort: Panel
The White House should lead a broad cybersecurity effort with the private sector to guard against potentially crippling attacks and boost confidence in the digital economy, a presidential commission said Friday.
read more
Implantable Cardiac Defibrillators Easily Hacked: Researchers
The communication protocol used by some of the latest generation of Implantable Cardioverter Defibrillators (ICDs) is weak enough to allow even attackers without advanced knowledge to reverse-engineer it and exploit vulnerabilities such as denial of service (DoS), security researchers have discovered.
read more
50 Million Potentially Impacted by AirDroid Vulnerabilities
Vulnerabilities in the Android remote management tool AirDroid potentially impact over 50 million devices, security researchers at Zimperium zLabs warn.
read more
Eight Vulnerabilities Found in Moxa NPort Devices
Security researchers have discovered a total of eight vulnerabilities in NPort serial device servers produced by Taiwan-based industrial automation solutions provider Moxa, ICS-CERT reported on Thursday.
read more
Google Launches OSS-Fuzz Open Source Fuzzing Service
Just two months after Microsoft announced its Project Springfield code fuzzing service, Google has launched the beta of its own OSS-Fuzz. The purpose in both cases is to help developers locate the bugs that eventually lead to breaches. But the services, like the two organizations, are very different: one is paid for while the other is free; one is proprietary while the other is open source.
read more
Researchers Propose Software Mitigations for Rowhammer Attacks
A team of researchers has proposed two software-based methods that could be used to mitigate Rowhammer, a type of attack that exploits weaknesses in the design of dynamic random-access memory (DRAM).
read more


