Hackers Are Using Reddit to Connect 17,000 Macs to a Botnet

Saturday, October 4th, 2014

Bad news for Mac users: You're at risk for an insidious malware that will connect your computer to a botnet. Hackers have developed a backdoor entry called "Mac.BackDoor.iWorm" that gains access to Macs and uses Reddit to connect the hacked computer with a command server. Once the computer is infected, the ...

Cleaning up after password dumps

Wednesday, September 10th, 2014

One of the unfortunate realities of the Internet today is a phenomenon known in security circles as “credential dumps”—the posting of lists of usernames and passwords on the web. We’re always monitoring for these dumps so we can respond quickly to protect our users. This week, we identified several lists ...

Massive, undetectable security flaw found in USB: It’s time to get your PS/2 keyboard out of the cupboard

Thursday, July 31st, 2014

Security researchers have found a fundamental flaw that could affect billions of USB devices. This flaw is so serious that, now that it has been revealed, you probably shouldn’t plug a USB device into your computer ever again. There are no known effective defenses against this variety of USB attack, though ...

“Weaponized” exploit can steal sensitive user data on eBay, Tumblr, et al.

Tuesday, July 8th, 2014

A serious attack involving a widely used Web communication format is exposing millions of end users' authentication credentials on sites including eBay, Tumblr, and Instagram, a well-respected security researcher said Tuesday. The exploit—which stems from the ease of embedding malicious commands into Adobe Flash files before they're executed—has been largely mitigated ...

Microsoft will patch IE zero day but doesn’t give timeline

Friday, May 23rd, 2014

Microsoft said Thursday it plans eventually to patch a vulnerability in Internet Explorer 8 that it's known about for seven months, but it didn't say when. A security research group within Hewlett-Packard called the Zero Day Initiative (ZDI) released details of the flaw on Wednesday after giving Microsoft months to address ...