Grindr’s Bug Bounty Pledge Doesn’t Translate to Security

At SAS@Home, Luta Security CEO Katie Moussouris stressed that bug bounty programs aren’t a ‘silver bullet’ for security teams. Continue reading Grindr’s Bug Bounty Pledge Doesn’t Translate to Security

Microsoft Zerologon Flaw Under Attack By Iranian Nation-State Actors

Microsoft warns that the MERCURY APT has been actively exploiting CVE-2020-1472 in campaigns for the past two weeks. Continue reading Microsoft Zerologon Flaw Under Attack By Iranian Nation-State Actors

Video-Game Piracy Group ‘Team Xecuter’ Leaders in Custody

The two alleged leaders of Team Xecuter targeted popular consoles like the Nintendo Switch, the Sony PlayStation Classic and Microsoft Xbox. Continue reading Video-Game Piracy Group ‘Team Xecuter’ Leaders in Custody

Voter Registration ‘Error’ Phish Hits During U.S. Election Frenzy

Phishing emails tell recipients that their voter’s registration applications are incomplete – but instead steal their social security numbers, license data and more. Continue reading Voter Registration ‘Error’ Phish Hits During U.S. Election Frenzy

Years-Long ‘SilentFade’ Attack Drained Facebook Victims of $4M

Facebook detailed an ad-fraud cyberattack that’s been ongoing since 2016, stealing Facebook credentials and browser cookies. Continue reading Years-Long ‘SilentFade’ Attack Drained Facebook Victims of $4M

305 CVEs and Counting: Bug-Hunting Stories From a Security Engineer

Larry Cashdollar, senior security response engineer at Akamai, talks about the craziest stories he’s faced, reporting CVEs since 1994. Continue reading 305 CVEs and Counting: Bug-Hunting Stories From a Security Engineer

Emotet Emails Strike Thousands of DNC Volunteers

Hundreds of U.S. organizations on Thursday received emails purporting to come from the Democratic National Committee, in a new politically charged Emotet spear-phishing attack. Continue reading Emotet Emails Strike Thousands of DNC Volunteers