Lucian ConstantinReporter, IDG News Service, IDG News Service

Lucian Constantin writes about information security, privacy and data protection.

PCWorld News

Microsoft revokes trust in certificate authority operated by the Indian government

A security breach at India's National Informatics Centre resulted in at least 45 rogue digital certificates for Google and Yahoo domains

PCWorld News

Malware hidden in Chinese inventory scanners targeted logistics, shipping firms

Researchers from TrapX discovered a sophisticated multistage cyberespionage attack that started in the supply chain

ssl lock internet

Beyond Google, rogue digital certificates also targeted Yahoo domains, possibly others

The full scope of the security breach is currently unknown, a Google security engineer said

PCWorld News

International law enforcement operation disrupts Shylock banking malware

Police in eight countries worked with security vendors to seize domain names and servers used by the Trojan program

PCWorld News

Botnet brute-forces remote access to point-of-sale systems

A new malware threat scans the Internet for POS systems and tries to access them using common usernames and passwords

avg secure search blowup

Vulnerability in AVG security toolbar puts IE users at risk

Bad design decisions could have enabled malware infections, researchers from CERT/CC said.

android malware

Android bug lets apps make rogue phone calls

The flaw affects the majority of Android devices in use and could easily be exploited by malware to make premium-rate calls.

malware 0 100257425 orig

Attack on Dailymotion redirected visitors to exploits

A rogue iframe injected into the site led visitors to exploits that installed a click-fraud Trojan program, researchers from Symantec said

PCWorld News

Ruby on Rails gets patches for SQL injection vulnerabilities

The two vulnerabilities affect Rails applications that use PostgreSQL as a database system

PCWorld News

Hardcoded SSH key gives backdoor access to Cisco communications manager

Cisco released new software versions to fix the issue and patch another serious vulnerability

PCWorld News

Critical vulnerability in popular WordPress newsletter plug-in endangers many blogs

Attackers could exploit a flaw in the MailPoet Newsletters plug-in to take full control of vulnerable blogs, researchers from Sucuri said

PCWorld News

Israeli security startup firm Hexadite automates cyber incident response

The company claims its product reduces cyber incident response times by up to 95 percent

Microsoft resumes emailed security notifications days after announcing its demise

The next security notifications will go out Thursday ahead of monthly security patches

malware 0 100257425 orig 100309194 large

New malware program hooks into networking APIs to steal banking data

The Emotet malware can sniff information even from HTTPS connections, researchers from Trend Micro said.

android devil malware

Rare text message worm targets Android devices

The new Selfmite Android malware spreads by sending text messages with a malicious link to the device owner's contacts