Add new comment

Community news and analysis: April 2014

Posted on April 24, 2014 - 15:09 by ccondon

April news from around our partner community includes updates to several major malware variants, two new vulnerability disclosure programs, and a critical security update for the popular Jetpack WordPress plugin. 

Malware analysis

Facebook webinject leads to iBanking mobile bot (ESET)

Update to Linux/Ebury, updated indicators of compromise (ESET)

Significant update to P2P Zeus botnet malware (Fortinet)

Other security news

New Security Measures Will Affect Older (non-OAuth 2.0) Applications (Google Online Security Blog)

$10,000 Security Bug Bounty for Certification Verification (Mozilla)

Testing for Heartbleed vulnerability without exploiting the server (Mozilla)

Why data is the new hacker currency (SiteLock)

New CloudFlare vulnerability disclosure program (CloudFlare)

Critical update for Jetpack WordPress plugin (Sucuri)

Filtered HTML

  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <blockquote> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

Plain text

  • No HTML tags allowed.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Lines and paragraphs break automatically.