US-CERT Warns HTTPS Inspection May Degrade TLS Security

Security tools that proxy and inspect HTTPS traffic create a blindspot for network administrators trying to determine whether communication between clients and servers is secure. Continue reading US-CERT Warns HTTPS Inspection May Degrade TLS Security

Fileless Malware Campaigns Tied to Same Attacker

Two recent fileless malware campaigns targeting financial institutions, government agencies and other enterprises have been linked to the same attack group. Continue reading Fileless Malware Campaigns Tied to Same Attacker

FSB Officers, Criminal Hackers Indicted in Yahoo Breach

The Department of Justice indicted four individuals, including two Russian FSB officers, for their roles in the Yahoo breach. Continue reading FSB Officers, Criminal Hackers Indicted in Yahoo Breach

FSB Officers, Criminal Hackers Indicted in Yahoo Breach

The Department of Justice indicted four individuals, including two Russian FSB officers, for their roles in the Yahoo breach. Continue reading FSB Officers, Criminal Hackers Indicted in Yahoo Breach

JSON Libraries Patched Against Invalid Curve Crypto Attack

JSON libraries using the JWE specification to create, sign and encrypt access tokens have been patched against an attack that allows for the recovery of a private key. Continue reading JSON Libraries Patched Against Invalid Curve Crypto Attack

Patch Tuesday Returns; Microsoft Quiet on Postponement

Microsoft released 18 security bulletins, eight rated critical. The company also patched publicly disclosed vulnerabilities that surfaced since last month’s postponement of Patch Tuesday. Continue reading Patch Tuesday Returns; Microsoft Quiet on Postponement

WordPress REST API Bug Could Be Used in Stored XSS Attacks

The recently patched REST API Endpoint vulnerability in WordPress could be leveraged to pull off stored cross-site scripting attacks. Continue reading WordPress REST API Bug Could Be Used in Stored XSS Attacks

38 Android Devices Infected with Malware Preinstalled in Supply Chain

Researchers at Check Point found and remediated malware on 38 Android devices that were infected somewhere along the supply chain. Continue reading 38 Android Devices Infected with Malware Preinstalled in Supply Chain