Month: March 2017

ComputerWorldIndependent

Password-stealing flaws in LastPass Chrome and Firefox extensions

Credit to Author: Darlene Storm| Date: Wed, 22 Mar 2017 06:25:00 -0700

Tavis Ormandy, a security researcher on Google’s Project Zero team, warned of flaws in LastPass browser extensions, vulnerabilities which – if a person surfed to a malicious site – would allow the malicious site to steal passwords from the password manager.

LastPass said it patched the vulnerability in its Chrome extension and said it is working on a fix for the flaw in its Firefox add-on.

Ormandy originally said the LastPass bug affected 4.1.42 Chrome and Firefox browser extensions. He developed a working exploit for a Windows box running the LastPass Chrome extension, but said it “could be made to work on other platforms.” He sent the details to LastPass before adding:

To read this article in full or to leave a comment, please click here

Read More
SecurityTrendMicro

Hackers Attempt To Extort Apple

Credit to Author: Mark Nunnikhoven (Vice President, Cloud Research)| Date: Wed, 22 Mar 2017 13:42:55 +0000

Briefcase full of moneyCybercrime is a business. Professional criminals refine their processes, measure performance, and regularly evaluate the return on their investments. Every move is strategic. We see this time and time again with ransomware campaigns and throughout the underground. Which is why the latest report from Joseph Cox at Motherboard is mind boggling. Joseph brings us the…

Read More