The Pentagon plans to spend an additional $900 million in the coming year to boost cyber defense measures, Defense Secretary Ashton Carter said Thursday.
US officials are still reeling from last year's revelation that personal data from some 20 million federal employees, contractors and others had been hacked in a massive breach at the Office of Personnel Management.
read more
Mozilla Allows Symantec to Issue SHA-1 Certificates to Payment Processor
Mozilla has decided to allow Symantec to issue nine new SSL certificates signed using the SHA-1 cryptographic hash function to payment processor Worldpay after the company failed to upgrade devices in time.
read more
Over 60 Vulnerabilities Patched in Apple TV
Apple has patched more than 60 vulnerabilities with the release of Apple TV 7.2.1, including flaws that can lead to arbitrary code execution, application crashes, and information disclosure.
read more
Apple Asks to Block Court Order to Help Decrypt iPhone
Apple on Thursday urged a federal court to toss out an order that the company help the FBI hack into an iPhone used by a shooter in the San Bernardino attack, arguing that it was a "dangerous power."
The legal response was fired in what promised to be a landmark case pitting national security against personal privacy.
read more
Palo Alto Networks Fixes PAN-OS Vulnerabilities
Palo Alto Networks has released updates for PAN-OS, the operating system of its enterprise security platform, to address several vulnerabilities, including ones rated “critical” and “high” severity.
read more
Breach Detection Time Improves, Destructive Attacks Rise: FireEye
In its seventh annual Mandiant M-Trends report, FireEye-owned Mandiant said that organizations are improving on the time it takes to detect a security breach.
While the positive news on improved breach detection is exciting in the current days of cyber doom and gloom, Mandiant also found an increase in the number of destructive attacks hitting organizations.
read more
Apple Case Not About Setting Precedent: FBI Chief
FBI Director James Comey on Thursday defended his agency's efforts to force Apple to help unlock an iPhone used by one of the San Bernardino attackers, as he warned of risks of unbreakable encryption.
"The San Bernardino litigation is not about us trying to send a message or establish some kind of precedent," Comey told lawmakers at the House Intelligence Committee.
read more
Cisco Patches Command Injection Flaw in ACE Appliance
Cisco has released software updates for its ACE 4710 appliance to address a high severity command injection vulnerability.
read more
Over 700 Million Data Records Compromised in 2015: Report
Last year, 1,673 data breaches resulted in roughly 707 million data records being compromised worldwide, according to statistics from Gemalto’s Breach Level Index report.
read more
Securely Surfing the IoT Tsunami
The IoT wave is building like a thunderous tsunami, growing larger on the horizon by the day. What is missing from the conversation, however, is how large a role software plays in the IoT equation. Plugging something into the Internet does not make it work — it just makes it vulnerable. Value is created through the associated software. In fact, we have almost reached the point where the actual product or device and the associated software become a single logical unit to the consumer.
read more

