Inside the Latest Apple iMessage Bug
Researchers from Bishop Fox and Uber found a frighteningly simple way to spread trouble through Apple iMessage. Continue reading Inside the Latest Apple iMessage Bug
Collaborate Disseminate
A number of publicly disclosed vulnerabilities in Moxa networking gear won’t be patched until August, if at all, according to ICS-CERT. Continue reading Moxa Won’t Patch Publicly Disclosed Flaws Until August
Adobe will release an emergency Flash Player update as soon as Thursday, patching a critical vulnerability that is being publicly attacked. Continue reading Emergency Update Coming for Flash Vulnerability Under Attack
New life has been injected into the BREACH crypto attacks by researchers who have discovered how to bypass existing mitigations. Continue reading BREACH Attacks Revived to Steal Private Messages from Gmail, Facebook
Today’s monthly Android Nexus Security Bulletin from Google includes a patch for a vulnerability being exploited in the wild to root Nexus 5 Android devices. Continue reading Google Patches Old Flaw Exploited by Rooting Application
The United States and Canada issued a joint advisory on the threat posed by crypto-ransomware. Continue reading US, Canada Issue Ransomware Advisory
Reddit has removed a warrant canary from its latest transparency report, indicating it has received its first National Security Letter. Continue reading Reddit Removes NSL Warrant Canary from Transparency Report
The Department of Defense announced that registration for its Hack the Pentagon bug bounty trial program is open, and that the program will be run on the HackerOne platform. Continue reading Hack the Pentagon Trial Program Registration Open
Check Point has discovered a weakness that allows hackers to use phishing to carry out man-in-the-middle attacks between iOS devices and mobile device management tools and allow an attacker to push malicious apps to devices. Continue reading SideStepper Allows for MiTM Between iOS Devices, MDM Tools
Two VeriSign researchers are expected to deliver a talk this week that explains how two Chinese domains were the targets of 2015 DDoS attacks that impacted the Internet’s root name servers. Continue reading Root Servers Were Not Targets of 2015 DDoS Attack