Menu

Monthly Archives: February 2016

Source: TheIntercept – Posted by Anthony Pell    If the U.S. government tries to strong-arm American companies into ending the sale of products or applications with unbreakable encryption, the technology won�t disappear, a group of researchers conclude in a new report. It would still be widely available elsewhere. Some U.S. law enforcement officials argue that […]

Source: arsTechnica – Posted by Anthony Pell    An estimated 63 percent of the encryption products available today are developed outside US borders, according to a new report that takes a firm stance against the kinds of mandated backdoors some federal officials have contended are crucial to ensuring national security. The report, prepared by security […]

Posted by Anthony Pell    New upstream release: fixes CVE-2015-8476. ——————————————————————————– Fedora Update Notification FEDORA-2015-39522bb8c9 2016-02-11 09:49:16.132384 ——————————————————————————– Name : php-PHPMailer Product : Fedora 22 Version : 5.2.14 Release : 1.fc22 URL : http://phpmailer.worxware.com/ Summary : PHP email transport class with a lot of features Description : Full Featured Email Transfer Class for PHP. PHPMailer […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 22 php-PHPMailer-5.2.14-1.fc22 Fedora 23 firefox-44.0.1-2.fc23 Fedora 23 php-PHPMailer-5.2.14-1.fc23 Fedora 23 firebird-2.5.5.26952.0-1.fc23 Red Hat: 2016:0166-01: flash-plugin: Critical Advisory Fedora 23 gsi-openssh-7.1p2-3.fc23 Fedora 22 claws-mail-3.13.2-1.fc22 Red Hat: 2016:0157-01: python-django: Moderate Advisory […]

Posted by Anthony Pell    New upstream release: fixes CVE-2015-8476. ——————————————————————————– Fedora Update Notification FEDORA-2015-abf9659276 2016-02-11 09:49:39.042856 ——————————————————————————– Name : php-PHPMailer Product : Fedora 23 Version : 5.2.14 Release : 1.fc23 URL : http://phpmailer.worxware.com/ Summary : PHP email transport class with a lot of features Description : Full Featured Email Transfer Class for PHP. PHPMailer […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 22 php-PHPMailer-5.2.14-1.fc22 Fedora 23 firefox-44.0.1-2.fc23 Fedora 23 php-PHPMailer-5.2.14-1.fc23 Fedora 23 firebird-2.5.5.26952.0-1.fc23 Red Hat: 2016:0166-01: flash-plugin: Critical Advisory Fedora 23 gsi-openssh-7.1p2-3.fc23 Fedora 22 claws-mail-3.13.2-1.fc22 Red Hat: 2016:0157-01: python-django: Moderate Advisory […]

Update from 3.13.1 to 3.13.2 for bug-fixes. Includes security fix forCVE-2015-8708. ——————————————————————————– Fedora Update Notification FEDORA-2016-b211281b8e 2016-02-10 10:19:50.055896 ——————————————————————————– Name : claws-mail Product : Fedora 22 Version : 3.13.2 Release : 1.fc22 URL : http://claws-mail.org Summary : Email client and news reader based on GTK+ Description : Claws Mail is an email client (and news […]

Updated python-django packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 5.0 for Red Hat Enterprise Linux 7. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: python-django security update Advisory ID: RHSA-2016:0157-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0157.html Issue date: 2016-02-10 CVE Names: CVE-2015-8213 […]

Updated python-django packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 7.0. Red Hat Product Security has rated this update as having Moderate security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: python-django security update Advisory ID: RHSA-2016:0156-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0156.html […]

Updated python-django packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 5.0 for Red Hat Enterprise Linux 6. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: python-django security update Advisory ID: RHSA-2016:0158-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0158.html Issue date: 2016-02-10 CVE Names: CVE-2015-8213 […]

Posted by Anthony Pell    This update fixes for security vulnerabilities, including CVE-2016-0775,CVE-2016-0740. ——————————————————————————– Fedora Update Notification FEDORA-2016-4b06195979 2016-02-09 16:33:27.876837 ——————————————————————————– Name : python-pillow Product : Fedora 23 Version : 3.0.0 Release : 2.fc23 URL : http://python-pillow.github.io/ Summary : Python image processing library Description : Python image processing library, fork of the Python Imaging Library […]

Posted by Anthony Pell    Several security issues were fixed in nginx. ========================================================================== Ubuntu Security Notice USN-2892-1 February 09, 2016 nginx vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS Summary: Several security issues were fixed in nginx. Software Description: – nginx: small, powerful, […]

Risk Medium Date Discovered February 9, 2016 Description Microsoft ASP.NET is prone to a cross-site request-forgery vulnerability. An attacker can exploit this issue to perform unauthorized actions in the context of a logged-in user of the affected application. This may aid in other attacks. Technologies Affected Microsoft ASP.NET MVC 5.0 Microsoft ASP.NET MVC 6.0 Microsoft […]

Risk High Date Discovered February 9, 2016 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will […]

Risk Medium Date Discovered February 9, 2016 Description Microsoft Internet Explorer is prone to an information-disclosure vulnerability. Successful exploits will allow attackers to obtain sensitive information that may aid in further attacks. Internet Explorer 9, 10, 11 are vulnerable. Technologies Affected Microsoft Internet Explorer 10 Microsoft Internet Explorer 11 Microsoft Internet Explorer 9 Recommendations Run […]

Risk Medium Date Discovered February 9, 2016 Description Microsoft Windows is prone to a local security-bypass vulnerability. A local attacker can leverage this issue to bypass certain security restrictions and perform unauthorized actions. Recommendations Permit local access for trusted individuals only. Where possible, use restricted environments and restricted shells. Allow only trusted individuals to have […]

Risk Medium Date Discovered February 9, 2016 Description Microsoft Windows is prone to a local privilege-escalation vulnerability. A local attacker can exploit this issue to execute arbitrary code in kernel mode with elevated privileges. Recommendations Permit local access for trusted individuals only. Where possible, use restricted environments and restricted shells. To exploit this vulnerability, an […]

Risk Medium Date Discovered February 9, 2016 Description Microsoft Windows is prone to a denial of service vulnerability. An attacker can exploit this issue to cause the system to stop responding, denying service to legitimate users. Recommendations Block external access at the network boundary, unless external parties require service. If global access isn’t needed, filter […]

Risk Medium Date Discovered February 9, 2016 Description Microsoft Windows is prone to a local privilege-escalation vulnerability. A local attacker can leverage this issue to execute arbitrary code with elevated privileges. Recommendations Permit local access for trusted individuals only. Where possible, use restricted environments and restricted shells. Ensure that only trusted users have local, interactive […]

Risk Medium Date Discovered February 9, 2016 Description Microsoft Windows is prone to a local privilege-escalation vulnerability. A local attacker can leverage this issue to execute arbitrary code with elevated privileges. Recommendations Permit local access for trusted individuals only. Where possible, use restricted environments and restricted shells. Ensure that only trusted users have local, interactive […]

Risk High Date Discovered February 9, 2016 Description Microsoft Office is prone to a remote memory-corruption vulnerability because it fails to properly handle objects in memory. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions. […]

Risk High Date Discovered February 9, 2016 Description Microsoft Office is prone to a remote memory-corruption vulnerability because it fails to properly handle objects in memory. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions. […]

Microsoft fixes 36 flaws in IE, Edge, Office, Windows, .Net Framework
Setting up a Windows 10 picture PIN
Identity thieves obtain 100,000 electronic filing PINs from IRS system
Let’s bring back the balance between IT and business
Police surround anti-swatting Congresswoman’s home in swatting attack
Facebook given 3 months to stop tracking non-users in France
Wired to ad blocker users: pay up for ad-free site or you get nothing

Source: ZDNet Security – Posted by Dave Wreski    A new bill introduced by two congressmen aims to prevent local legislatures from enacting laws weakening security or banning sales of encrypted smartphones in their states. On Wednesday, Rep. Ted Lieu (D-CA, 33rd) introduced the bipartisan draft bill — dubbed the Ensuring National Constitutional Rights of […]

Gmail to warn you if your friends aren’t using secure e-mail
Google has confirmed a number of changes to Gmail with the arrival of two new features that will let you know if the people you�re corresponding with [...]

Source: arsTechnica – Posted by Anthony Pell    Google has confirmed a number of changes to Gmail with the arrival of two new features that will let you know if the people you�re corresponding with aren�t hip with TLS encryption. The alterations are fairly subtle: when you receive a message from, or are on the […]

Source: tomsHardware – Posted by Dave Wreski    After New York and California tried to pass bills that ban phones from using disk encryption that only the device owners can decrypt, senator John McCain wants to ban all encryption that can�t be decrypted by companies and the government at the federal level. McCain called for […]

Source: Motherboard – Posted by Anthony Pell    A hacker, who wishes to remain anonymous, plans to dump the apparent names, job titles, email addresses and phone numbers of over 20,000 supposed Federal Bureau of Investigation (FBI) employees, as well as over 9,000 alleged Department of Homeland Security (DHS) employees, Motherboard has learned. The hacker […]

Type: Vulnerability. Microsoft Active Directory Federation Services is prone to a denial of service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: New libsndfile packages are available for Slackware 13.37, 14.0, 14.1, and -current to fix security issues. [More Info…]

LinuxSecurity.com: New curl packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix a security issue. [More Info…]

LinuxSecurity.com: USN-2880-1 introduced a regression in Firefox.

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

Many of you are probably familiar with VirusTotal, a service that allows you to scan a file or URL using multiple antivirus and URL scanners. VirusTotal results are often used in write-ups about new malware to show how widely a sample is detected by the AV community. We receive links to VirusTotal results via our […]

Google adds warning to unencrypted emails

In a 2016 survey of 500 PC gamers, Webroot discovered statistically significant differences in the ways that male and female gamers approach internet security, 3rd party modifications, and the way they choose to portray their gender online. In fact, we found surprisingly large discrepancies between those who identified as male and those who identified as […]

Southwest Airlines flight giveaway scams spread on Facebook

There is no such thing as a free lunch, and even if there was… who likes airline food that much anyway? The post Southwest Airlines flight giveaway scams spread on Facebook appeared first on We Live Security.

US government wants to sharply increase spending on cyber security
Cybersecurity e-learning course launches in the UK for HR staff

A new e-learning tool has been launched in the UK to help HR professionals effectively deal with cybersecurity issues in the British workplace. The post Cybersecurity e-learning course launches in the UK for HR staff appeared first on We Live Security.

Safer Internet Day: 6 tips for your kids (and for you, too!)
Adwind evolves to offer cyber criminals one-stop shop for malware
Stay safe with our Facebook cheat sheet

Learn how to boost your Facebook privacy on Safer Internet Day with our excellent cheat sheet. It’ll work to your advantage now and in the future. The post Stay safe with our Facebook cheat sheet appeared first on We Live Security.

How “gag clauses” are used to squash negative reviews and punish reviewers
Innocent Chrome game used as cover for many tentacled Android invader
5 tips to protect your admin credentials
Teen sues TV station for broadcasting sexting video along with his name

LinuxSecurity.com: Nearly three years after former NSA contractor Edward Snowden first leaked details about massive domestic spying, his revelations have prompted a broader discourse, especially among legal scholars, over the potentially invasive nature of big data cybersurveillance tools.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Outlook for Mac is prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.

LinuxSecurity.com: An updated sos package that fixes one security issue and one bug is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having Moderate security [More…]

LinuxSecurity.com: Updated python-django packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 6.0 for RHEL 7. Red Hat Product Security has rated this update as having Moderate security [More…]

LinuxSecurity.com: Update from 3.13.1 to 3.13.2 for bug-fixes. Includes security fix forCVE-2015-8708.

LinuxSecurity.com: – update to upstream release 1.8.1 – CVE-2016-0747: Insufficient limits ofCNAME resolution in resolver – CVE-2016-0746: Use-after-free during CNAMEresponse processing in resolver – CVE-2016-0742: Invalid pointer dereference inresolver

LinuxSecurity.com: Prosody 0.9.10 ============== A summary of changes in this release: Security——– * mod_dialback: Adopt key generation algorithm from XEP-0185, toprevent impersonation attacks (CVE-2016-0756) Fixes and improvements———————- * Startup: Open /dev/urandom read-only, to fix afailure to start on some systems (fixes #585) * Networking: Improve handling ofthe ‘select’ network backend running out of file descriptors […]

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

security update

security update

security update

security update

Hacker says he’s breached DHS and FBI, leaks claimed staff data
Student arrested for grade changing school data breach

A 17-year-old student in American has been arrested and charged with illegally accessing government computers, months after the data breach took place. The post Student arrested for grade changing school data breach appeared first on We Live Security.

Java installer flaw shows why you should clear your Downloads folder
Report: Hacker steals, posts personal details on 9,000 DHS employees
Cyber criminals cash out using PowerShell, other legitimate tools
Remtasu is disguising itself as a tool to appropriate Facebook accounts

Almost a year ago we warned about the spreading of Remtasu, and far from lessening, we have been able to identify numerous instances of this threat being propagated further. The post Remtasu is disguising itself as a tool to appropriate Facebook accounts appeared first on We Live Security.

Malware Museum shows how it was “before it was all about money”
Burglars allegedly spoof caller ID to scare couple out of their home
What happens when you fly your drone into the Empire State Building
Facebook taunts send another “catch me if you can” crook to jail
Google says “No more” to deceptive download and play buttons in ads
The security review: Encryption 101 and Android security updates

Highlights from the past seven days in information security include encryption insights, Android updates, Facebook at 12 and a data breach at UCF in the US. The post The security review: Encryption 101 and Android security updates appeared first on We Live Security.