Software

Update: Hello Barbie Fails Another Security Test

In-brief: The security firm Bluebox says the mobile applications used with Hello Barbie contain security flaws that could lead to the theft of passwords and other information. Update: this story was updated to include comment from Bluebox and ToyTalk. PFR 12/4/2015

Firm Finds Crypto Keys Recycled on Thousands of Devices

In-brief: Encryption keys used to secure data on- and communications between embedded devices are being recycled, creating a huge vulnerability that malicious hackers could exploit to snoop on sensitive communications or impersonate devices.

ERP Opens Doors To Oil Industry Hacks | Motherboard

In-brief: the energy sector is particularly vulnerable to attack via ERP and other mission critical systems, according to a report.

Super Cookies, Web Analytics Behind Malicious Profiling

In-brief: FireEye is warning about a sophisticated campaign of online surveillance that combines web “super cookies” and common analytics software to target individuals with links to international diplomacy, the Russian government and the energy sector.

Firm Puzzled by Body Cams Infected with Malware

In-brief: a California company that makes wearable cameras that are used by law enforcement and the military said a report that it shipped cameras infected with the Conficker virus were “distressing,” but that it was unable to locate the malware on its devices or within its environment.