Microsoft warns this year’s crop of tax scams use social engineering attacks based on fear to spread banking Trojans and collect personal info.

Locky, Cerber Ransomware Skilled at Hiding
Since January, a number of ransomware families are sharing a common infrastructure with different techniques allowing the malware to hide from detection systems.

Code Execution Vulnerability Found in Libpurple IM Library
A severe vulnerability has been disclosed in libpurple, the library used in the development of a number of popular instant messaging clients, including Adium for the macOS platform.

Critical Moodle Vulnerability Could Lead to Server Compromise
A critical vulnerability in Moodle, an open source system deployed across hundreds of thousands of universities, could expose the server to compromise.

LastPass Fixes Three Password Theft Vulnerabilities
LastPass has fixed three bugs in the password manager discovered by Google research Tavis Ormandy in the last 24 hours.

SAP Vulnerability Puts Business Data at Risk for Thousands of Companies
Researchers at ERPScan today disclosed details and a proof-of-concept exploit for a SAP GUI remote code execution vulnerability patched last week.

Blank Slate Spam Campaign Spreads Cerber Ransomware
A spam campaign called Blank Slate is spreading Cerber ransomware and abusing hosting providers to register new domains as soon as they’re taken down.

Google, Jigsaw Partner on Free Tools to Secure Elections
Jigsaw and Google said they would offer a free suite of security tools aimed at securing political elections.

Park uses facial recognition to wipe out toilet paper thieves
‘I am a bit uncomfortable about being watched in such places’, as one user of the public facilities in Beijing’s Tiantin Park noted, is probably the understatement of the week

Russian bank claims hackers are trying to connect it to Trump
Claims of DNS spoofing between a Russian bank and a Trump server add ‘fake traffic’ to the lexicon of obfuscation