Software

Certificate Interruptus: Survey Finds Heartbleed Fixes Incomplete At Most Firms

In-brief: Three quarters of Global 2000 organizations have yet to fully remediate the Heartbleed vulnerability one year after it was discovered, according to a study by the firm Venafi.

Research: IoT Hubs Expose Connected Homes to Hackers

In-brief: A study of common connected home gateways finds lax security that could expose consumers to snooping or even malicious attacks, according to the application security firm Veracode. 

Drug Pumps Vulnerable to trivial Hacks, DHS warns

In-brief: The Department of Homeland Security warned that drug infusion pump management software sold by Hospira contains serious and exploitable vulnerabilities that could be used to remotely take control of the devices. 

Supply Chain Hackers Use Short List of Techniques | Trend Micro

In-brief: Trend Micro notes that supply chain attacks are on the rise, with attackers relying on a short list of techniques including compromises of source code, firmware and so-called “watering hole” attacks.

IoT Hackers: The FTC Wants You!

In-brief: The Federal Trade Commission announced this week that it is creating a new Office of Technology Research and Investigation to expand the FTC’s research into areas such as privacy, data security, connected cars, smart homes, algorithmic transparency, emerging payment methods, big data, and the Internet of Things.