Attackers are attempting to exploit the recent Apache Struts vulnerability on Windows servers and the payload is a variant of the Cerber ransomware.

Creating a More Altruistic Bug Bounty Program
David Jacoby and Frans Rosén said at this year’s Security Analyst Summit they offered companies free pen-testing and raised $15,000 for charity in the process.

Baseband Zero Day Exposes Millions of Mobile Phones to Attack
A previously undisclosed baseband vulnerability impacting Huawei smartphones, laptop WWAN modules and IoT components was revealed Thursday at the Infiltrate Conference

Researcher Warns SIEMs Are Weak Link In Network Security Chain
Security information and event management solutions are supposed to boost security, but researchers say the network analysis tools are ripe attack targets.

Bill would block warrantless searches of Americans’ phones at borders
Lawmakers from both sides of both houses propose bill to require warrants before Americans’ devices are searched at border crossings – although foreigners’ phones would remain liable to search

News in brief: NASA to crash probe into Saturn; laptop ban might widen; Facebook tool to spot fake news
Your daily round-up of some of the other stories in the news

WiFi-enabled adult toy comes up short on security
You’d hope that the makers of connected adult devices might have learned something from the WeVibe debacle. Apparently not, if this latest example is anything to go by

Uber Said To Use 'Sophisticated' Software To Defraud Drivers, Passengers
A class-action lawsuit against Uber alleges that Uber has “devised a ‘clever and sophisticated’ scheme in which it manipulates navigation data used to determine ‘upfront’ rider fare prices while secretly short-changing the driver,” reports Ars Technica. “When a rider uses…

Twitter Co-Founder Ev Williams Is Selling 30 Percent of His Stock For 'Personal' Reasons
The co-founder and current board member of Twitter, Ev Williams, said today that he plans to sell a “minority of [his] TWTR” stock over the next year, and doesn’t plan to sell “more than 30 percent” of his holdings. Williams…

New Destructive Malware Intentionally Bricks IoT Devices
An anonymous reader writes: “A new malware strain called BrickerBot is intentionally bricking Internet of Things (IoT) devices around the world by corrupting their flash storage capability and reconfiguring kernel parameters. The malware spreads by launching brute-force attacks on IoT…