Menu

Monthly Archives: April 2016

Shock Clock, a wearable that will shock you to get out of the bed
5 tips for defending against advanced persistent threats
Insider threats: A persistent and widespread problem

When it comes to cybercrime, a lot of the focus is centered on external threats and on the individuals who actively attempt to cause harm and damage, whether by infecting a computer system with malware or through the encryption of files for reasons of extortion. This attention understandable. Threats posed by cybercriminals to organizations is great, so […]

Creators of SpyEye Virus Sentenced to 24 Years in Prison
Misunderstanding Indicators of Compromise
How I Hacked Facebook, and Found Someone’s Backdoor Script
The dark side of biometric identification

As I read about the Kuwaiti government’s plan to test and log the DNA of everyone in that country, I was reminded of what a bad idea such schemes are. It’s great for law enforcement, I guess, but it’s terrible for personal privacy and overall security. What do I mean that it’s bad for security? […]

Using the Java Security Manager in Enterprise Application Platform 7

Several issues have been discovered in the MySQL database server. The vulnerabilities are addressed by upgrading MySQL to the new upstream version 5.5.49. Please see the MySQL 5.5 Release Notes and Oracle’s Critical Patch Update advisory for further details: For the stable distribution (jessie), these problems have been fixed in version 5.5.49-0+deb8u1. We recommend that […]

Pentagon Wants One-of-A-Kind Encryption Enabled Messaging App

Risk High Date Discovered November 11, 2014 Description Microsoft Windows is prone to a remote privilege-escalation vulnerability. An attacker can exploit this vulnerability to execute arbitrary code with elevated privileges. Technologies Affected Microsoft Windows 7 for 32-bit Systems SP1 Microsoft Windows 7 for x64-based Systems SP1 Microsoft Windows 8 for 32-bit Systems Microsoft Windows 8 […]

Risk High Date Discovered September 30, 2003 Description Multiple vulnerabilities were reported in the ASN.1 parsing code in OpenSSL. Attackers could exploit these issues to cause a denial of service or to execute arbitrary code. Recommendations Block external access at the network boundary, unless external parties require service. If global access isn’t needed, filter access […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 python-tgcaptcha2-0.3.1-1.fc23 Fedora 23 parallel-20160222-1.fc23 Fedora 23 thunderbird-45.0-2.fc23 Fedora 23 openssh-7.2p2-3.fc23 Fedora 22 python-tgcaptcha2-0.3.1-1.fc22 Fedora 22 parallel-20160222-1.fc22 Debian: 3556-1: libgd2: Summary Fedora 23 w3m-0.5.3-24.fc23 Community Linux Events Linux User […]

Posted by Anthony Pell    Update to version 20160222-1 to fix bugs(#1285888,1307846,1320511,1320956,1320958) ——————————————————————————– Fedora Update Notification FEDORA-2016-73eb29f890 2016-04-24 17:22:11.575647 ——————————————————————————– Name : parallel Product : Fedora 23 Version : 20160222 Release : 1.fc23 URL : http://www.gnu.org/software/parallel/ Summary : Shell tool for executing jobs in parallel Description : GNU Parallel is a shell tool for executing […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 python-tgcaptcha2-0.3.1-1.fc23 Fedora 23 parallel-20160222-1.fc23 Fedora 23 thunderbird-45.0-2.fc23 Fedora 23 openssh-7.2p2-3.fc23 Fedora 22 python-tgcaptcha2-0.3.1-1.fc22 Fedora 22 parallel-20160222-1.fc22 Debian: 3556-1: libgd2: Summary Fedora 23 w3m-0.5.3-24.fc23 Community Linux Events Linux User […]

Security fix for CVE-2015-8325: ignore PAM environment vars when UseLogin=yes. ——————————————————————————– Fedora Update Notification FEDORA-2016-7f5004093e 2016-04-24 17:22:11.574810 ——————————————————————————– Name : openssh Product : Fedora 23 Version : 7.2p2 Release : 3.fc23 URL : http://www.openssh.com/portable.html Summary : An open source implementation of SSH protocol versions 1 and 2 Description : SSH (Secure SHell) is a program […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 python-tgcaptcha2-0.3.1-1.fc23 Fedora 23 parallel-20160222-1.fc23 Fedora 23 thunderbird-45.0-2.fc23 Fedora 23 openssh-7.2p2-3.fc23 Fedora 22 python-tgcaptcha2-0.3.1-1.fc22 Fedora 22 parallel-20160222-1.fc22 Debian: 3556-1: libgd2: Summary Fedora 23 w3m-0.5.3-24.fc23 Community Linux Events Linux User […]

Posted by Anthony Pell    Update to version 20160222-1 to fix bugs(#1285888,1307846,1320511,1320956,1320958) ——————————————————————————– Fedora Update Notification FEDORA-2016-7eb5caa94d 2016-04-24 17:21:43.073116 ——————————————————————————– Name : parallel Product : Fedora 22 Version : 20160222 Release : 1.fc22 URL : http://www.gnu.org/software/parallel/ Summary : Shell tool for executing jobs in parallel Description : GNU Parallel is a shell tool for executing […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3556-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso April 24, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libgd2 CVE ID : CVE-2016-3074 Debian Bug : 822242 Hans Jerry Illikainen discovered that libgd2, a library for programmatic graphics creation and manipulation, suffers of a signedness vulnerability which may result in a heap […]

Resolves:rh#1324349 – denial of service with crafted html files ——————————————————————————– Fedora Update Notification FEDORA-2016-80c07fbb6c 2016-04-24 01:34:43.161129 ——————————————————————————– Name : w3m Product : Fedora 23 Version : 0.5.3 Release : 24.fc23 URL : http://w3m.sourceforge.net/ Summary : A pager with Web browsing abilities Description : The w3m program is a pager (or text file viewer) that can […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 python-tgcaptcha2-0.3.1-1.fc23 Fedora 23 parallel-20160222-1.fc23 Fedora 23 thunderbird-45.0-2.fc23 Fedora 23 openssh-7.2p2-3.fc23 Fedora 22 python-tgcaptcha2-0.3.1-1.fc22 Fedora 22 parallel-20160222-1.fc22 Debian: 3556-1: libgd2: Summary Fedora 23 w3m-0.5.3-24.fc23 Community Linux Events Linux User […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 python-tgcaptcha2-0.3.1-1.fc23 Fedora 23 parallel-20160222-1.fc23 Fedora 23 thunderbird-45.0-2.fc23 Fedora 23 openssh-7.2p2-3.fc23 Fedora 22 python-tgcaptcha2-0.3.1-1.fc22 Fedora 22 parallel-20160222-1.fc22 Debian: 3556-1: libgd2: Summary Fedora 23 w3m-0.5.3-24.fc23 Community Linux Events Linux User […]

Posted by Anthony Pell    The 4.5.2 stable update contains a number of important fixes across the tree.This build should also boot on some of the i686 systems that would not bootbefore. ——————————————————————————– Fedora Update Notification FEDORA-2016-7f37d42add 2016-04-23 23:42:43.599148 ——————————————————————————– Name : binutils Product : Fedora 24 Version : 2.26 Release : 18.fc24 URL : […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 python-tgcaptcha2-0.3.1-1.fc23 Fedora 23 parallel-20160222-1.fc23 Fedora 23 thunderbird-45.0-2.fc23 Fedora 23 openssh-7.2p2-3.fc23 Fedora 22 python-tgcaptcha2-0.3.1-1.fc22 Fedora 22 parallel-20160222-1.fc22 Debian: 3556-1: libgd2: Summary Fedora 23 w3m-0.5.3-24.fc23 Community Linux Events Linux User […]

Facebook has more than 1million users on Tor
Malvertising attack silently infects old Android devices with ransomware
Stolen usernames and passwords still cause almost a quarter of all data breaches
Hell froze over. Hacked firm cares more about its users’ security than its corporate image
4 tech nightmares keeping IT leaders up at night
Phantom riders abusing stolen Uber users’ accounts for strange journeys
US no longer requires Apple’s help to crack iPhone in New York case
Why email hasn’t killed the fax
Get FREE threat intelligence on hackers and exploits with the Recorded Future Cyber Daily [Sponsor]

Several vulnerabilities were discovered in imlib2, an image manipulation library. CVE-2011-5326 Kevin Ryde discovered that attempting to draw a 2×1 radi ellipse results in a floating point exception. CVE-2014-9771 It was discovered that an integer overflow could lead to invalid memory reads and unreasonably large memory allocations. CVE-2016-3993 Yuriy M. Kaminskiy discovered that drawing using […]

Anonymous Ghost Squad’s DDoS Attack Shuts Down KKK Website

Hans Jerry Illikainen discovered that libgd2, a library for programmatic graphics creation and manipulation, suffers of a signedness vulnerability which may result in a heap overflow when processing specially crafted compressed gd2 data. A remote attacker can take advantage of this flaw to cause an application using the libgd2 library to crash, or potentially, to […]

Xbox Live’ Social and Gaming Service Goes Down
Bank implements poor security measures, loses $81 million
Security Experts Discover Malware in Facebook’s Staff Server
SMS phishing attackers continue to pursue Apple users

��}�۶��o�*�ӧ,)����%{�$�kǾ’�s�EBg(���ht������1�j�`�M�lw��i4�I���ĦH��ht7����o������ûׯ��}<��.sMo�׸��|�� �#粯��C6�����ǁ1�-/��A�;�'ܴw��{��<_�3���]8|�a���9v<���±�N?����1]=�L��;U�ƾ?v�91�/x��=��k^�����#?L������;����÷����_<������х�:�s��Q����?�8y}��0q�13�ش�yE/�,�Y��<= ��$�Ϗ[��]��6��� �?a3?qm6�l�� ��'H�xb��!�gI3�C�4��pN�ȩ�n�բ��.��I(�y�f��Іn M�����i�����ޣ��Mk@��G ��X�ez���7N�vg���iu{�h�)%�zJI]�Q7q���±�4B?�al���ƙ�c���( 5 ߴ�l�`����]�tw������j�Aw�<<���VZ�����ڒ�UaXҝ�(�%���Ϗ�R �S��V�ƒ���w��N��8'�Y�8o��?|�����������v��g�)�j(qg�x�?3Ng��g� �a��O�Ќ�Ϡ�EGk�֊�����ZD�跖����߽����Қ4Ռ�Ï����' z6�V�V�7���Awml�,�TY�I�v�q=s��ct�}����uo�x�j�fsش���̮��OfȬ�� ��.�J^�Y��5�v�2�=��y��m�4�� |:0 Y���!��@��k��~�ob�H�$#ml�Bz��o���now���w��6���~��n�Mˈ��fl��ӫz�p�7�’��5ׁ���z�V�^�ocw_�#�zg���ovؾ���F��^�*�)_AS�l�#ˈB�o”����b��^�l����P�p�5�U�Ƴ�’�k׭��8j�r�”���)h�C�’L�2� j7���o^�@��{����C�E�q�Ԃm��6c���+�����q@v�m���.�r@ {<|R/��kв����m�9n��4�fEY�-�;�8�@�:�Bu�������B�E1��ֱ���h�Y��hՅ�jھ� �4��j��-�VR���).�w������}ڤ��}�{�v��5燰�DIf�`�a�M/�C�’A93��K_.�hbZU_’�O�C����Z�V�;��!k3��_�J/�%�k�1��F �8�Ϯ�’^�!|�����b��.qj��j�9v���&�=`�1,�iu d�1���=7�9�����w�H�u~+����b��&���oM��k�5�Z�’���lw���uf���#m�Ő���Ib&�V���_wQJP���v��™�.��:sl>27N��”�z���-Q_j�3T��m0 ��n’��c��l��Z&[�M�B�(�ζ��ߧP�OGơ��Q��v�C�g�V[�tdz��~{��}Lx87R�U�������0*�ac?�oo����(�F�����jt�x�hb{(����n�KE};���G=H����c��������(]�j�ற���$ӆ����#���ˡo�Y���$m��w��VG� t������.�O5=U�E��Z�1L^O��}�:KE+����r��ѭ ��ۮ>u�!n )�@Fo�(TI�Ǿ�pt��(94���n����i_�R�0?r3�&hO�:�CoB@��KhӚFѩ��~�VK��[�=�|��߅�og���PO� ���g߿5`�n�����Hk�R<�,��Ly�ШJ�h�����_��y��{�L�徳�ӂ�@i��:rNGÏ���5=���wVW����#Q���=|k���` h���>�t�N������ ]��V&<�$��Z-`j����D�m�<�jG*9$*�[.�����!��}� r�c�r��������/Gé��<�AG�]���})_ʾ��^e�x@r7<�-�g�Tk4�����)��5�kӃ�c��Qa�Q�.�ZD}��x*�А{���+8�߿{��}�����7wS�jg�ծd��'r��z�p��6�/0Ԣ����� .� d�SmO�(6øv��]���s�zG���hrt�RAP*0+�Z���7w��e~h�n߽ׯ������’�`�>tk��3���9��G���� � ������C�=-g���Qr�f|�`լ-ƪV����C�ğS��i�+��v�z{ݽ�A���y=��m�f�g^�� }�}A�v+|�]9��PS�{�?j�Пi�U,S,'[%�է����)<�؀`0�kz��(Z.��E����q_��ɋw���� ����p������`�;�9��Ѵ�ܫת�ֲđ�F� U(��1��[�b����g�XN�/�+{E=‰OR`۬`��R�K'�U�s�Ua�@��9h��KBEp��T�k�s���(�$��^�0��sfs���=�” ���|�6X��z�Vm�đ5Y��oɔ�h�c�E6��$�WW[_J��rS>Z�d 5|�Xl*���/o��YK`�Y�1�7;ݔ9��Nic��In�YP��GLك�i�G��0� Z1妠;��0�0��$�Uŋ�6H�I8byQI5s- ��4܇d��mS�U�3�hE�Zn��iMr�3Ld�g�����`则`�����$�h �B���%��,kH�R���1�SSbB0�ESm�*5�v����=U�f��z���K<�E��'��j�$ E��*&GK�Y����y����0J �6j�!��36�a ę K{)`�Aa'���8�=9��V�#'c�+��kQ�Z�l��/M��zZR�;��eJ �}���N�hA_X2@���r�5u��ֺ�[��rz^e������%t(��T��_�ɲ�_uY�.�ٰР� i�)��b�"�h�K`p+5�N�<'�iE�G�eע���}���޲�w��n%Q�o���e�=���~�T��mѪO.o]���8Zo�V�i�lu�ܡ���~g+]}��nz�;��;�%�C�̘G1��N��S�Ԛ�!�1J�θ�pa�zM��3��r4g0����`"~W�T��C�-떀}�Wu���ѣ��j�`,;�).���-�qLs�O�Nc���f$�ABX�-������.��� �1;�۟y*]^gR��/L�Y��s�l6Ch � @U� H�p~�̐���$�� BX,�q�N�/i�M/�}�}pp='�C��@Vl@!�/0������ߺ��E�ꂋ��g���g�����m�[����)���z~�.�n{o;)R� W��[*�e�@?'����d����ވ�-�^�rij k2�t�JrdZ��-]);��v{�cy�J����

SpyEye Makers Get 24 Years in Prison
FBI Hints It Paid Hackers $1 Million to Get Into San Bernardino iPhone
700 Million People Just Got Encryption That Congress Can’t Touch
Anonymous Shutdown Denver Police Website Against Fatal Shooting
Crooks Target Apple Users with ‘Apple ID Expiration’ Phishing Scam

CVE-2016-3960 (XSA-173) Ling Liu and Yihan Lian of the Cloud Security Team, Qihoo 360 discovered an integer overflow in the x86 shadow pagetable code. A HVM guest using shadow pagetables can cause the host to crash. A PV guest using shadow pagetables (i.e. being migrated) with PV superpages enabled (which is not the default) can […]

Anonymous Hacker Arrested for Hacking, Leaking Filipinos’ Voters Data
Ubuntu Snap doesn’t have the security issue — X11 does

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3553-1 security@debian.org https://www.debian.org/security/ Sebastien Delafond April 22, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : varnish CVE ID : CVE-2015-8852 Debian Bug : 783510 Régis Leroy from Makina Corpus discovered that varnish, a caching HTTP reverse proxy, is vulnerable to HTTP smuggling issues, potentially resulting in cache poisoning or […]

**Version 0.90.3** * security update to prevent a minor vulnerability *fix issues with post-only ticket form See [changelog](https://github.com/glpi-project/glpi/issues?q=milestone:0.90.3) for more details. —- **Version0.90.2** Include bugfixes and some minor features : * An alert in centralpage when some of your mysql tables are marked as crashed * A betterflexibility in splitted layout for small screens * […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Debian: 3553-1: varnish: Summary Fedora 22 glpi-0.90.3-1.fc22 Fedora 22 springframework-amqp-1.3.9-4.fc22 Fedora 22 drupal7-block_class-2.3-1.fc22 Fedora 23 libtasn1-4.8-1.fc23 Fedora 23 glpi-0.90.3-1.fc23 Fedora 23 drupal7-block_class-2.3-1.fc23 Debian: 3554-1: xen: Summary Community Linux Events Linux […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Debian: 3553-1: varnish: Summary Fedora 22 glpi-0.90.3-1.fc22 Fedora 22 springframework-amqp-1.3.9-4.fc22 Fedora 22 drupal7-block_class-2.3-1.fc22 Fedora 23 libtasn1-4.8-1.fc23 Fedora 23 glpi-0.90.3-1.fc23 Fedora 23 drupal7-block_class-2.3-1.fc23 Debian: 3554-1: xen: Summary Community Linux Events Linux […]

Update to 4.8 ——————————————————————————– Fedora Update Notification FEDORA-2016-383b8250e6 2016-04-21 21:27:32.207875 ——————————————————————————– Name : libtasn1 Product : Fedora 23 Version : 4.8 Release : 1.fc23 URL : http://www.gnu.org/software/libtasn1/ Summary : The ASN.1 library used in GNUTLS Description : A library that provides Abstract Syntax Notation One (ASN.1, as specified by the X.680 ITU-T recommendation) parsing and […]

**Version 0.90.3** * security update to prevent a minor vulnerability *fix issues with post-only ticket form See [changelog](https://github.com/glpi-project/glpi/issues?q=milestone:0.90.3) for more details. —- **Version0.90.2** Include bugfixes and some minor features : * An alert in centralpage when some of your mysql tables are marked as crashed * A betterflexibility in splitted layout for small screens * […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Debian: 3553-1: varnish: Summary Fedora 22 glpi-0.90.3-1.fc22 Fedora 22 springframework-amqp-1.3.9-4.fc22 Fedora 22 drupal7-block_class-2.3-1.fc22 Fedora 23 libtasn1-4.8-1.fc23 Fedora 23 glpi-0.90.3-1.fc23 Fedora 23 drupal7-block_class-2.3-1.fc23 Debian: 3554-1: xen: Summary Community Linux Events Linux […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3554-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso April 21, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : xen CVE ID : CVE-2016-3158 CVE-2016-3159 CVE-2016-3960 Multiple vulnerabilities have been discovered in the Xen hypervisor. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2016-3158, CVE-2016-3159 (XSA-172) Jan Beulich from SUSE discovered […]

An update for java-1.7.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 5, Oracle Java for Red Hat Enterprise Linux 6, and Oracle Java for Red Hat Enterprise Linux 7. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: java-1.7.0-oracle security update Advisory ID: RHSA-2016:0678-01 Product: Oracle Java for Red Hat Enterprise Linux […]

An update for java-1.6.0-sun is now available for Oracle Java for Red Hat Enterprise Linux 5, Oracle Java for Red Hat Enterprise Linux 6, and Oracle Java for Red Hat Enterprise Linux 7. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: java-1.6.0-sun security update Advisory ID: RHSA-2016:0679-01 Product: Oracle Java for Red Hat Enterprise Linux […]

An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: java-1.7.0-openjdk security update Advisory ID: RHSA-2016:0675-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0675.html Issue date: 2016-04-21 CVE Names: CVE-2016-0686 CVE-2016-0687 […]

An update for java-1.8.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 6 and Oracle Java for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: java-1.8.0-oracle security update Advisory ID: RHSA-2016:0677-01 Product: Oracle Java […]

Facebook bug hunter stumbles on backdoor left by hackers
FBI paid over $1.3 million to hack into San Bernardino iPhone that contained ‘nothing of real significance’
DRAM bitflipping exploits that hijack computers just got easier
Female Hackers Still Face Harassment at Conferences
Hacking Team postmortem is something all security leaders should read
Denial-of-service attacks now a cover for something more sinister
The FBI paid more than $1 million to hack the San Bernardino iPhone
Opera Puts Free VPN to its Browser for Anonymous Web Surfing
Two-factor authentication coming to PlayStation Network

��}�r�8���j�a�Li”����R��dfrN.>c�7;’ɪ �hS$Ëe}W}���j�!�j�`�M�’�n�x�,�J2���% 4��F��@=|���������ׯ��m�ÉMl�: s�_���lh]wwt@�a��;�� 3��u�5���w4a!�E5�1��:ʉ�� ���2�:JȮCp’���$RF8f�C3xC��s�{����CM#�c+ He�Gڿ�!0�~�R ��v�”ꛩ�h2��LYP�O#�۔ZXY>�_�c��h�Z�2)YP��q�”f@:��-]�)� ��4�ً�ij����|�E�C�H�&��WT�U�P���rLw�����C��t�’�O�+������{#Ч���� �{c�����7��{��RS�)��{�~n��r�I�����i��d|�t������E�_��L��Ӂs��)Xj�����C���a�p�V��~mP��&f�V?]Q�:}�S�����q� ��@�Z3;}�Bn�^����_�i*�C���භM}h��9|zZ1u,�Pi�zJ �8�`ϑVӻ&�>X�@��MGJ�ӡX1R9Q���NN�f>qMV��i���vv��Z�߫��z�6�C�9 鯿��Tu�9�p�m�V�`�{��#a�v:&v�%�0B�4vk�o�Q�A��w������MBS����٪�=��Ȗ�c����z��9���(��P�ЪN=�9��ز�ʠz�-k#�yh��O�5�`:1�a���T����@���׿�Y�a~��xBm�O���q����X/nF��/�W�?*�,�� 4��A�M��l�?��UhY��^��`�R�6�5ZR5��#%ƼPEq�mg�p���`�8s@��Rȃ�b’A���EOP9�n��U2��I��O7�����]=�R�lo�p*+XN����,U�Vo*BW�Lw!���*j�#C�U��A��WF�-k2�Z0�l6�������`͈�Lˆ�8S’�}�7AG��_��`L���cf���i�I�_����������J�P[��� iu��g仑c���/�~���֑X饗2�|���쨮�i���z�/��*u�R�Y��t�6����LK�72�����t��U1�j<����*1V� ��/�lqs��Bs0��y�{�^=�@4`B6��7��c]���R���a�3�?��e�i̥�dC�a�����<`E�^Y�D}�HCLPD����~����}Z���8@�dC�i����4��w*����w�0}�m;t& �ac��3���oы��gzX� R��w��[�aT��F�?�ޒ�%��Q�0�oρ��W�Kˉ�E�C9�}�y ��&��t��A��ӌ��w���8;x�����u��y�Q�_˼��^�]sFB���'i3�mae�9o��������$�����^’?2f�q��ߏ|u!!g���r�u�U�̜�^����60�a�Ǯ�tI�[ƲOsR��!��� �I��kz�������!�>TEkH*�ns�HK@�M�aƣ�sJ�R�b`���)te�B?b�/ q�^5`j�r��l�K�”��4����4$J�[ .�����.��7��tX�?cC�gl�F�9�)dQ���^�+�TX�Z��~i�5�6v��’OZ��6�’�$�M�”��ύ̻�2q+`f .�і�s�m`x��F6��8���ב5�&�( ��]||��( �,�Qb��4�9/R#%Ã��O�O�ݦ�]u޸gB= � “�`�|�y#’L����0�!��+�R`nF��9c f�����H&�.�l�Ҭ�*~g^H���6�|�-�˔�$+K80/�]�����@G:WM��p8��B��}��I�+��nx�[�.hI�VSnd��{} �p1�”`#����‡� t�9�q���v���Og���bΪ’�U/e��++�� z�`l�&�/0Ԣ�,�~Z3kAͮY�O�w���?@�A��’uN� �~�|��)yCX�∟[� �� (��Z�,��w[�”?�L�c?������T���}���B�u���>���%�!i���c�>.f�ڐ3D��M�”�UM���Z����C�ğQ���[�%`���v����Fz�t�z�{`� �(S�^�� ���Z�V��7�(X;� ͉�����T��|�|9�*�(�61�’�!��`E�:(k.�K����=�d%C���(Ԣ�H�c|C~�#��s� ��O�;|��b2�qX6u.K�Q�x ��^~q��?y�Z�f�ր����9�~kp��g|Zt=�TԲ�j��8�v��P�r������/�i DxH���|%�x�p�X�6KX�X�s��p�|Z0F1�Z��@�b�ׁ�h S4Wa��P9����a2ԡ;=�t_Ix�}FZ4���C3�Jj�[�s6�`U�$�K��qNLF~{uF�C^�?�ӵ����|�Wk�dQ��v�#�pp������8`��vo+��/��^�+�V2��>y�7�X}����’��c$o6�1s�’ɝ����ܮ@m�����]�m��|�6h�l����>´C�3��fT/f��N�ˋR�ѕ4|Z��>$��p�����@+)�y�����bt�)�d�6X�g ��9hJ���1T�� ��2���E ��]Ȟ���=5�L�p�(i�A�� ��?�#�MYi���B��z��Ɯ%�,ǃ9?V��r (,��6HC��̍|r�fS�7u]Wd�S;������7�ȄHq�l��@�ƲS�e�ei[(Fi��^)d��C+3��}X��b��M���N�H��/cr��������X;�/��`E5*K�,Pd�3�2��@�%o��2]v�a�+����v�+�+���`���3��u�Rp�5�c�l���O���[2���Q��n����������TN�m�U���69u�0Xm�V�q�d�U�Pcgw���.�>CC��g���h)աW4dAH~a����-�’㔌��3 ��YF��t}w3�ٓ�9�Y ������y�R��!�� �&j/�R�ɓ'{�. �<�a�����M`��.��&9�點�N�4]^’b�4y�y�*��~8; ���d�A�n��b����˵Ʀɾ�_�߿��V�ko��H�o0��w߸�5��D�9-��ަ�G� ��s���n=�d�S=%���Z(����f:�T���.�S^t��/�~N�o���dG��S$:q�!y�g}`-�”Èq@׮ G����Х��n�6���O��1�XͲ�J=�b�y’�p�K~���h�8@�o ����]w��DV����W�vks�.�� Y੾�����=0�������t֔���r��U� […]

How to protect your Apple ID account against hackers
Key battle looms in the war to protect privacy
Fake social button code on websites attacks visitors via the Angler exploit kit

Régis Leroy from Makina Corpus discovered that varnish, a caching HTTP reverse proxy, is vulnerable to HTTP smuggling issues, potentially resulting in cache poisoning or bypassing of access control policies. For the oldstable distribution (wheezy), this problem has been fixed in version 3.0.2-2+deb7u2. We recommend that you upgrade your varnish packages.

Creators of SpyEye Trojan Aleksandr Panin, Hamza Bendelladj Sentenced
Kickass Torrents Community Targeted with Phishing Scam

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: java-1.8.0-openjdk security update Advisory ID: RHSA-2016:0650-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0650.html Issue date: 2016-04-20 CVE Names: CVE-2016-0686 CVE-2016-0687 […]

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: java-1.8.0-openjdk security update Advisory ID: RHSA-2016:0651-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0651.html Issue date: 2016-04-20 CVE Names: CVE-2016-0686 CVE-2016-0687 […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Red Hat: 2016:0650-01: java-1.8.0-openjdk: Critical Advisory Red Hat: 2016:0651-01: java-1.8.0-openjdk: Critical Advisory Fedora 23 springframework-amqp-1.3.9-4.fc23 Fedora 24 mercurial-3.7.3-1.fc24 Fedora 24 webkitgtk4-2.12.1-1.fc24 Fedora 23 kernel-4.4.7-300.fc23 Fedora 22 libreswan-3.17-1.fc22 Fedora 24 w3m-0.5.3-24.fc24 […]

Cisco fixes serious denial-of-service flaws in wireless LAN controllers, other products
How Easy is it to Tamper with Traffic Sensors in Russia? VERY!
CryptXXX ransomware steals bitcoins and data from infected PCs
Opera browser gets a free VPN – but you’ll need more than this to stay safe online
Security risks with higher level languages in middleware products

Discovered: April 21, 2016 Updated: April 21, 2016 2:34:07 PM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Trojan.Exedapan is a Trojan horse that downloads additional files and steals information from the compromised computer. Antivirus Protection Dates […]

Newly discovered PWOBot malware is a total keylogger
Viber to Put Full End-to-End Encryption on Their Messaging App
Coinbitclip Trojan: A Grave Threat to BitCoin Wallets
Oracle security update includes Java, MySQL, Oracle Database fixes

CVE-2016-3630, CVE-2016-3068, CVE-2016-3069 ——————————————————————————– Fedora Update Notification FEDORA-2016-74f9a65b3a 2016-04-20 15:24:02.554822 ——————————————————————————– Name : mercurial Product : Fedora 24 Version : 3.7.3 Release : 1.fc24 URL : http://www.selenic.com/mercurial/ Summary : Mercurial — a distributed SCM Description : Mercurial is a fast, lightweight source control management system designed for efficient handling of very large distributed projects. Quick […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 mercurial-3.7.3-1.fc24 Fedora 24 webkitgtk4-2.12.1-1.fc24 Fedora 23 kernel-4.4.7-300.fc23 Fedora 22 libreswan-3.17-1.fc22 Fedora 24 w3m-0.5.3-24.fc24 Fedora 24 keepassx-0.4.4-1.fc24 Ubuntu: 2951-1: OptiPNG vulnerabilities Ubuntu: 2950-1: Samba vulnerabilities Community Linux Events Linux […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 mercurial-3.7.3-1.fc24 Fedora 24 webkitgtk4-2.12.1-1.fc24 Fedora 23 kernel-4.4.7-300.fc23 Fedora 22 libreswan-3.17-1.fc22 Fedora 24 w3m-0.5.3-24.fc24 Fedora 24 keepassx-0.4.4-1.fc24 Ubuntu: 2951-1: OptiPNG vulnerabilities Ubuntu: 2950-1: Samba vulnerabilities Community Linux Events Linux […]

Cybercriminals could access calls and texts using just your phone number

Your phone number holds the key that could give cybercriminals access to your location, phone calls and texts, according to a new report by CBS 60 Minutes. The security flaw was demonstrated on – and with the permission of – US congressman Ted Lieu, who was given a new phone in California and was able […]

Hackers turn their back on exploiting Java, to focus on Flash flaws