WordPress tightens security with two-factor authentication

The new feature is immediately available for users and "secret" codes can be accessed via SMS or through the Google Authenticator app.

Spear phishing campaign targeted energy sector

The unsuccessful attacks were the result of email addresses being publicly posted on an electric company's website.

Android trojan spreads through Cutwail spam botnet

Attackers use phishing emails, which include links to a fake Adobe Flash update, to lure victims into installing the Stels trojan.

Firefox 20 released, makes "private browsing" easier

The release patches 13 vulnerabilities, five of which are deemed "critical."

Electronic road signs hacked in Illinois

Electronic road signs in St. Charles, Ill. were hacked on Thursday, displaying messages that had nothing to do with a pipeline project taking place nearby.

Buggy DIY botnet tool leaks in black market

A new do-it-yourself botnet generating tool has leaked in the wild, but miscreants believe it's not worth its $10,000 price tag.

IRS warns phishing attacks are among "dirty dozen" tax scams

IRS warns phishing attacks are among "dirty dozen" tax scams

Phishing attacks were among the top 12 schemes hatched by tax season scammers.

Wells Fargo bank website hit by DDoS attack

Wells Fargo's online banking website was allegedly struck by a cyber attack on Tuesday, temporarily limiting service for its customers.

Phishing scammer gets five year sentence

A Romanian citizen was sentenced in a New Haven, Conn. U.S. District Court.

Targeted Android attacks discovered by researchers

Targeted Android attacks discovered by researchers

Attached as a malicious APK file in a spear phishing email, once installed, the program siphons data that includes contacts, call logs, SMS messages, and more.

Former student accused of stealing identities pleads guilty

Matthew Weaver used a keylogger to steal student passwords and cast 480 votes for himself as student council president.

Report: 78% of IT security pros admit plugging in "found" USB drives

Even IT security professionals are clearly ignoring basic security rules, a new survey found.

Reuters social media editor disputes Anonymous conspiracy accusations

Matthew Keys denies he gave "anyone" login information that could enable them to make changes to a Los Angeles Times article.

Thirty-five percent of companies opt not to use encryption

A survey of 5,000 senior IT managers conducted by market research firm B2B International has found that 35 percent of organizations worldwide don't use encryption to protect data.

Head of cyber security at DHS resigns

The deputy undersecretary for cyber security at DHS, Michael Weatherford, has resigned to take a position as principal at global security advisory firm, The Chertoff Group.

Reuters social media editor indicted for conspiring with Anonymous

Matthew Keys, 26, was indicted in California on charges that he helped Anonymous members deface the website of the Los Angeles Times.

Card-skimming ring leader to serve up to 13.5 years in prison

A Manhattan man will serve anywhere from four-and-a-half to 13-and-a-half years in prison for organizing a card-skimming ring that led to the fraudulent purchase of luxury goods.

Faux pope dupes thousands of followers on Twitter

A fake Twitter account posing as newly elected Pope Jorge Bergoglio deceived more than 100,000 followers, posting strange messages.

DDoS attack strikes JPMorgan Chase website

A representative of JPMorgan Chase has confirmed the website of the banking giant suffered a distributed denial-of-service attack Tuesday.

Celebrity data stolen from online credit report service

As the FBI continues to investigate the dumped data of high-ranking government officials and celebrities, Equifax confirms that some of the information published was accessed from AnnualCreditReport.com.

Tripwire acquires nCircle to scale its risk management offerings

Expected to close in April, the deal will make Tripwire one of the largest security and vulnerability management vendors in the industry.

Nearly all apps vulnerable to exploit

Researchers also found that the median number of vulnerabilities per application was 13 flaws.

Small businesses in crosshairs of new malware-laden email ruse

The Federal Trade Commission and the Better Business Bureau are alerting businesses about the new threat.

Using new tactics, Asprox botnet goes unnoticed

Known for distributing postal-themed spam, the Asprox botnet has remained effective, though less noticeable due to evasion techniques.

Adobe hurries update to fix Flash zero-day vulnerabilities

Adobe this week released an update to its Flash Player to close three vulnerabilities, two of which are under active attack.

NBC.com serves Citadel trojan

The site was hacked Thursday afternoon and contained links to the RedKit exploit kit

How to avoid being hacked like Burger King? Twitter says follow this advice

Twitter's director of information security is helping other users not suffer the same fate as Burger King and Jeep.

Adobe patches against PDF exploits that overran sandbox

Adobe on Wednesday made available a security update to its Reader and Acrobat software to close two vulnerabilities that are under active attack.

Sony pushes for class action suit dismissal

The electronics giant is scheduled go before a California judge in September to request the suit dismissal.

Lawyer representing Hammond asks judge to step back

Attorneys representing accused Anonymous member and political activist Jeremy Hammond has requested that the judge presiding over his case recuse herself due to a conflict of interest, according to reports.

Spam floods Twitter after pope resigns

After news broke that Pope Benedict XVI would step down as head of the Catholic Church, fraudsters took to Twitter to take advantage of the developing story.

Department of Energy to spend $20M on cyber security

The U.S. Department of Energy (DOE) looks to step up its security efforts by spending $20 million on more advanced cyber security tools.

Former President George H.W. Bush's family, friends emails hacked

The FBI is looking into hacks involving email accounts with which President George H. W. Bush corresponded.

Following breaches, Utah Senate passes data protection law

Sen. Stuart Reid (R-Utah) began drafting the bill last year, following a massive breach in the state of nearly 800,000 Medicaid records.

Wall Street Journal also a victim of espionage

Less than a day after The New York Times revealed that its reporters were targeted by Chinese hackers, The Wall Street Journal disclosed on Thursday that its systems were also breached by attackers from China wanting to observe the newspaper's coverage of the country.

U.S. hosts most botnet command servers worldwide

The U.S. hosts 631 active command-and-control hubs for botnets, according to McAfee.

Barrett Brown pleads innocent following third indictment

Barrett Brown, who sometimes publicly spoke for the Anonymous collective, pleaded innocent on Wednesday in Dallas federal court to new charges that he concealed evidence, apparently related to a raid on his apartment earlier this year, according to a report.

XSS attacks see big rise last quarter

Cloud hosting provider FireHost noted a 160 percent spike in XSS attacks from Q3 to Q4 2012.

Sony fined in U.K. for PlayStation breach

After exposing the personal data of millions of customers, Sony Computer Entertainment Europe has earned a £250,000 penalty.

Shylock variant targets Skype users

The updated trojan contains a new plug-in that can carry out a slew of malicious functions in the VoIP service.

Oracle quarterly update offers 86 security fixes

Oracle on Tuesday shipped its quarterly security update to close 86 vulnerabilities across its product line.

Global Payments now expects to pay $94M for breach costs

The payment processor suffered a breach in 2011, where 1.5 million credit and debit card numbers were compromised.

Firefox 18 includes security fixes, app features Safe Browsing

Firefox 18 includes security fixes, app features Safe Browsing

A majority of the bugs patched in the latest version of Mozilla's web browser were deemed "critical."

Update fixes hole in Facebook Camera app

A bug report leads to an update in a Facebook app.

FCC releases Smartphone Security Checker

The tool can be customized for each of the four major mobile operating systems

Blue Coat to buy Crossbeam Systems

The acquisition is expected to close Dec. 31 for an undisclosed amount.

John McAfee back in U.S.

The anti-virus pioneer returned to the U.S. on Wednesday following deportation from Guatemala.

Romanian phisher faces 35 years after conviction

A federal investigation launched seven years ago into a phishing campaign targeting customers of the People's United Bank in Connecticut has netted a 10th conviction, prosecutors said Tuesday.

Report: John McAfee suffers heart attack after arrest

Anti-virus company founder John McAfee reportedly suffered two mild heart attacks Thursday, while being detained in Guatemala.

Yahoo email hijack possible with $700 XSS exploit

A hacker, selling an exploit on a cyber crime forum for $700 a pop, found a vulnerability in Yahoo.com that could allow attackers to intercept or send emails from victims' email accounts.

Firefox 17 includes security fixes, Social API debut

Mozilla has packaged fixes for nearly 30 security vulnerabilities into the latest version of its web browser, Firefox 17.

PCI council issues guidance to help meet risk assessment piece

The PCI Security Standards Council, the body that manages payment security industries guidelines, on Friday released a methodology for meeting a risk management requirement included in the standard.

Adobe Connect forum pulled offline after database breach

Connectusers.com, an Adobe customer forum for its Connect online-conferencing service, was pulled offline by Adobe after the forum's database was breached.

Chrome adds a Flash sandbox for all operating systems

Google announced Tuesday that the Adobe Flash Player, which comes built in to its Chrome browser, is also now "sandboxed" for all major platforms, including Windows, Mac, Linux and Chrome OS.

Man arrested for encouraging DDoS on UK gov sites

An unnamed man from Staffordshire, England, was arrested and questioned about his involvement in plans to DDoS websites for the Home Office and Home Secretary Theresa May.

Adobe releases updates for Flash Player, AIR

The scheduled patch addresses seven "critical" flaws that could allow attackers to take over affected systems.

Vupen discovers Windows 8 zero-day exploit for sale

Controversial bug-seller Vupen has discovered a zero-day that bypasses multiple exploit safeguards in Windows 8.

Scammers pounce on Hurricane Sandy to spread spam

Phishing emails targeting victims of Sandy begin to make the rounds online.

Ransomware perps claim to be Anonymous

Even though the ransomware perpetrators claim to be hacktivist group Anonymous, researchers believe scammers are likely copycats.

EMC, RSA buy online fraud technology maker

EMC has acquired Menlo Park, Calif.-based online fraud detection provider Silver Tail Systems. Silver Tail, which offers "real-time web session and behavioral analysis" for banking, e-commerce and government customers, will operate as part of RSA, EMC's security division.

LinkedIn users being targeted by fake photo email

Scammers use a click-the-pic ruse to redirect users to the Blackhole exploit kit

DHS awards contracts for cyber security innovation

The U.S. Department of Homeland Security awarded 34 contracts to secure domestic critical infrastructure.

Facebook pledges $250K to UAB research team

Facebook announced this week that it is donating $250,000 to the Center for Information Assurance and Joint Forensics Research at the University of Alabama at Birmingham (UAB).

FCC OKs encrypted TV signals to prevent cable theft

The FCC lifted a ban on basic cable signal encryption in a move to prevent illegal access to cable.

Oracle to push 109 patches on Tuesday

Flaws in several Oracle products will be addressed by the quarterly update.

Rapid7, Veracode complete mobile security purchases

Rapid7, a Boston-based vulnerability management and penetration testing company, has acquired Seattle start-up Mobilisafe, which makes cloud-based mobile risk management technology.

Microsoft asks: Are you cloud ready?

Microsoft on Tuesday announced the release of a survey that organizations can use to gauge their capability to migrate to the cloud.

Microsoft buys authentication maker PhoneFactor

Microsoft on Thursday announced that it has acquired PhoneFactor, provider of multifactor authentication technology delivered via a mobile device.

ATM and car hacker exits McAfee for IOActive return

Barnaby Jack, well known for showcasing ATM vulnerabilities, is on his way back to IOActive after a year-long stint with McAfee.

App released for Android USSD exploit

The vulnerability, notably demonstrated at the Ekoparty security conference in Buenos Aires last month, could allow an attacker to remotely reset phones running Android operating systems.

Qualys opens higher in first day of trading

Qualys, a cloud security provider headquartered in Redwood City, Calif., began trading Friday on the NASDAQ, debuting at $12 a share.

FERC establishes cyber security office

The agency that regulates the transmission of electricity, oil and natural gas in the United States has created a new office to concentrate on cyber security.

Microsoft releases urgent browser patch to curb online attacks

The most critical flaw could lead to the installation of the backdoor trojan Poison Ivy on victims' machines.

Password cracking vulnerability in Oracle database

Attackers could link password hash with specific session key to crack users' passwords.

Massachusetts hospital to pay HIPAA fine

Massachusetts Eye and Ear Infirmary and Massachusetts Eye and Ear Associates have agreed to pay $1.5 million to settle potential HIPAA violations.

14 charged in stolen ID tax fraud

A 14-member gang alleged to have used stolen identities in a tax refund scheme have been charged in five criminal complaints with conspiracy to defraud the United States and other counts of theft of government property.

Air Force Association receives $1 million grant for CyberPatriot contest

The Northrup Grumman Foundation has contributed $1 million to the Air Force Association toward the growing CyberPatriot competition.

Subway restaurant hackers admit to crime spree

Charged in 2011 with conspiracy to commit computer fraud, wire fraud and access device fraud, two hackers have pleaded guilty to hijacking the processing systems of more than 150 Subway restaurants.

Banking malware Tinba infects 60,000 users in Turkey

Targets of the malware include government portals and Turkish financial institutions.

Twitter adds famed security expert to team

Charlie Miller, well-known for his work in penetration testing, will be joining Twitter's security team.

Apple issues Java updates after Oracle emergency patch

Apple has released Java updates to patch vulnerabilities in Mac OS X Lion, Mountain Lion and Snow Leopard.

McAfee: Malware breaking records, again

Security firm McAfee said it's amassed 1.5 million more malware samples in the second quarter of this year compared to the first quarter.

Mozilla releases patches for more than 30 Firefox bugs

The latest version of Mozilla's Firefox browser features security fixes for more than 30 vulnerabilities.

Researchers spot new keylogger that hides in Windows help file

A new data-stealing trojan has turned up on the systems of one of Radware's customers, according to researchers at the network security firm.

Adobe releases another round of updates for Flash Player

In a week, Adobe pushed two security updates for vulnerabilities in its Flash Player, affecting Windows, Macintosh, Linux and Android operating systems.

Despite patch, exploits against new Java bug picking up

Detection rates for exploits against the vulnerability (CVE-2012-1723) are now overtaking attacks abusing a previous widely attacked Java bug (CVE-2012-0507), which was used to spread the widespread Flashback trojan that targeted Mac users.

Twenty-six bugs patched in Google Chrome 21 release

The release of Google Chrome 21 features 26 patched vulnerabilities, six which are classified by the company as "high-priority."

Apple buys AuthenTec to beef up iPhone security

In a rare acquisition, Apple has acquired Melbourne, Fla.-based mobile and network security firm AuthenTec for $356 million.

Global Payments says breach will cost $85 million

Breached payment processor Global Payments announced Thursday that it has completed its investigation into the incident, and determined the clean-up and response will cost $84.4 million.

Anonymous targets Anaheim after residents protest police

Hacktivist collective Anonymous, in a video posted Wednesday on YouTube, called on its supporters to deface Anaheim, Calif. city websites, steal data, dox police officers and bombard officials with emails in response to two fatal shootings by police and their resulting response to protests in the city over the last several days.

Mozilla releases Firefox 14 to close several major holes

Mozilla has issued patches for 14 vulnerabilities, four which are deemed "critical," in the latest edition of its Firefox browser.

Mozilla's Firefox browser now encrypts Google searches

Mozilla's Firefox browser now encrypts Google searches

The latest version of Mozilla's popular Firefox browser has expanded its security features.

Cisco buys Virtuata for virtual security

Cisco has acquired Milpitas, Calif.-based Virtuata, a security software start-up that safeguards virtual machine data, for an undisclosed sum.

Final sentence in multi-million dollar hacking ring

Joshuah Witt, 35, the final member of a Seattle crime ring that combined hacking with old-fashioned breaking-and-entering, has been sentenced to just under eight years in federal prison, federal prosecutors announced Friday.

Oracle plans 88 security fixes on Tuesday

Oracle on Tuesday is planning to release 88 patches to address vulnerabilities across a wide range of the company's products, according to an announcement.

Rap artist busted on credit card fraud charges

Authorities charged California rapper Guerilla Black with purchasing some 30,000 credit card numbers and using them to buy merchandise.

Facebook opens "checkpoint" for virus infections

Facebook this week announced a new "malware checkpoint" capability through which users who believe their accounts have been infected can test them against one of two anti-virus products.

Anonymous hijacked the Syria emails released by WikiLeaks

Anonymous has taken credit for hacking computer systems to yield 2.4 million emails on Syrian politicians, ministries, and government-connected companies.

New Zeus variant comes with encryption upgrade

Researchers at ThreatMetrix Labs have come across a new variant of the peer-to-peer (P2P) version of the notorious Zeus trojan.

SpyEye purveyors get prison time in the U.K.

Three men who used the SpyEye trojan to break into online bank accounts have been sentenced to prison in the U.K.

Sign up for our newsletters

POLL