Mike Mimoso and Chris Brook recap the news of the week, including the EternalRocks worm, the latest on WannaCry, a subtitle hack, and a Twitter flaw.
Pacemaker Ecosystem Fails its Cybersecurity Checkup
Pacemakers and pacemaker programmers lack authentication and are plagued with thousands of software vulnerabilities across leading manufacturers.
Mark Dowd on Exploit Mitigation Development
Mark Dowd discusses why certain exploit mitigations have been so successful in driving up the cost of exploit development for attackers.
Samba Patches Wormable Bug Exploitable With One Line Of Code
The Samba Team has patched a severe bug that leaves computers vulnerable to wormable exploit.
Twitter Flaw Could Have Allowed Attacker to Tweet From Any Account
Twitter fixed a flaw in its Twitter Ads service could have allowed an attacker to tweet as any user.
Android Overlay and Accessibility Features Leave Millions at Risk
Researchers warn two features, not flaws, in Android can be used together to open devices up to attack.
Password Breaches Fueling Booming Credential Stuffing Business
The market for automated credential stuffing tools is growing fast, because of a record number of breaches.
Yahoo Retires ImageMagick After Bugs Leak Server Memory
Researcher Chris Evans reported a new bug and showed how also used a previously known flaw in ImageMagick to leak Yahoo server data and steal images and authentication secrets.
Google Elevates Security in Android O
Android O, due in the third quarter, figures to elevate the security of the mobile OS with new features focused on improved third-party patching, a new permission model and hardening of existing features.
Subtitle Hack Leaves 200 Million Vulnerable to Remote Code Execution
Attackers can remotely execute code on targeted systems via specially crafted subtitle files for videos.