CDSA News Headlines

 

What’s Next For Network Security (Dark Reading)

Network security as we know it ultimately will operate hand in hand with software-defined networking (SDN) and virtualization, security experts here said. SDN could be a game-ch... More

Microsoft to Retire Support for SHA1 Certificates in the Next 4 Months (ARS Technica)

Microsoft plans to retire support for TLS certificates signed by the SHA1 hashing algorithm in the next four months, an acceleration brought on by new research showing it was even ... More

Aging and Bloated OpenSSL is Purged of Two High-Severity Bugs (ARS Technica)

Maintainers of the OpenSSL cryptographic library have patched high-severity holes that could make it possible for attackers to decrypt login credentials or execute malicious code o... More

Criminals Peddling Affordable AlphaLocker Ransomware (Threat Post)

It’s rare a week goes by now without a new strain of ransomware making headlines. Researchers described one of the latest earlier this week, a relatively affordable ransomware-as... More

Top U.S. Computer Science Undergrad Programs Flunk Cybersecurity (Forbes)

A new study out from CloudPassage — a cloud security firm based in San Francisco — concludes that the American higher-education system is failing at preparing students for care... More

10-Year-Old Gets $10,000 Bounty for Finding Instagram Vulnerability (ARS Technica)

A 10-year-old schoolboy from Finland has become the youngest recipient of a £7,000 ($10,000) award under Facebook's bug bounty program, after he found a vulnerability that allowed... More

Weekend Vulnerability and Patch Report, May 8, 2016 (Citadel Information Group)

Important Security Updates Apple OS X: Apple has released an update for OS X El Capitan v10.11 and later for XCode 7.3.1 to fix a heap-based buffer overflow issue that existed i... More

Report: Google Play Infested with Cash-Stealing Web Apps (The Register)

Security researcher Joshua Shilko says phishing apps targeting some of the world's biggest payment services have slipped past screening and landed on Google Play. Shilko says he... More

Irremovable Data-Stealing Android Malware Poses as Google Chrome Update (ZD Net)

A banking and personal information stealing mobile malware posing as a Google Chrome update for Android, and which can't be removed from the infected device, has been spotted in th... More

Check Your Spotify Account: Users Report Unusual Activity After Credentials Posted Online (Financial Post)

If you use the popular music streaming service Spotify, there is a chance you may be vulnerable after a report has surfaced that the emails, usernames, passwords and other details ... More

Firefox: Mozilla Patches Critical Flaws that let Attackers Execute Malicious Code (ZD Net)

Mozilla has released Firefox 46 and patched several memory bugs that could let an attacker take control of a system. The new version of Firefox includes fixes for 10 security is... More

Hackers Steal Millions of Minecraft Passwords (BBC)

Hackers have stolen login data for more than seven million members of the Minecraft site Lifeboat. Lifeboat lets members run servers for customised, multiplayer maps for the smart... More

How to Stay Secure at the Hotel on a Business Trip (Dark Reading)

In 2014, cybercriminals in the DarkHotel campaign targeted business executives staying at hotels in Asia. The attackers used spearphishing as well as kernel-mode keystroke logger a... More

Office 365 Vulnerability Exposed any Federated Account (ThreatPost)

A severe vulnerability in the way Microsoft Office 365 handles federated identities via SAML put an attacker in position to have access to any account and data, including email mes... More

Privacy Activists Cheer Passage of Email Privacy Act, Brace for Senate Battle (ThreatPost)

In a vote of 419-0 on Wednesday, the U.S. House of Representatives passed the Email Privacy Act that would require the government to obtain a warrant in order to access digital com... More

Weekend Vulnerability and Patch Report, May 1, 2016 (Citadel Information Group)

Important Security Updates Apple QuickTime for Window: On April 14, US-CERT advised Microsoft Windows users to remove QuickTime. This followed a report in ars technica that Appl... More

Cloud Keynote: Sony Exec Recommends Learning from Piracy (ETC Centric)

Sony DADC NMS (New Media Services) CTO and head of strategy Andy Shenkler keynoted ETC’s Cloud Innovation Conference at NAB 2016 in Las Vegas. Rather than talk pure technology ab... More

PlayStation Network to Get Two-Factor Authentication (PC Mag)

Sony plans to add two-factor authentication to its PlayStation Network. Following Tuesday's PlayStation 3 firmware update (version 4.80), some eagle-eyed users spotted a mention... More

Information Security Culture: It’s Time to Upgrade to 2.0 (Info Security)

Information security requires an approach that involves people, process and technology. But, while we have made great strides in technological advancements in information security,... More

Law Enforcement, Government Agencies See Phishing as Main Cyber Risk (Softpedia)

The Global Cyber Alliance (GCA) was founded at the start of January this year, and on March 19 held its first Strategic Advisory Committee (SAC) meeting. Here, founding members ... More

Sign up for our newsletters
* indicates required
MESA Newsletters