Menu

Monthly Archives: April 2016

U.S government requested information on 5,200 accounts from Apple
Red Hat Product Security Risk Report: 2015
Oracle releases 136 security patches for wide range of products
DEF CON’s “Spot the Fed” contest a sore spot for Feds
Opinion: Burr-Feinstein antiencryption bill a firing offense
19 open source GitHub projects for security pros
CEO targeted by fraud twice a month
EFF sues to uncover government demands to decrypt communications
How to avoid sharing your location on Facebook and Twitter
Creepy adware takes screenshot of victim’s desktop without their permission
Buildings at risk of cyberattacks

In an increasingly connected world, the threat posed by cybercriminals will extend further than ever before – the Internet of Things (IoT) is shaking things up. It’s no longer about computers or smartphones being at risk – any object, any ‘thing’ that is powered by a computer and/or connected to the internet, is a target. This can […]

Discovered: April 20, 2016 Updated: April 20, 2016 2:37:09 PM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Infostealer.Multigpos is a Trojan horse that steals information from the compromised computer. Antivirus Protection Dates Initial Rapid Release version […]

Anonabox’ Devices Keep Identity Anonymous Using Tor and VPN

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 22 libreswan-3.17-1.fc22 Fedora 24 w3m-0.5.3-24.fc24 Fedora 24 keepassx-0.4.4-1.fc24 Ubuntu: 2951-1: OptiPNG vulnerabilities Ubuntu: 2950-1: Samba vulnerabilities Red Hat: 2016:0638-01: chromium-browser: Important Advisory Fedora 22 xerces-c-3.1.3-1.fc22 Fedora 23 firefox-45.0.2-1.fc23 Community […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 22 libreswan-3.17-1.fc22 Fedora 24 w3m-0.5.3-24.fc24 Fedora 24 keepassx-0.4.4-1.fc24 Ubuntu: 2951-1: OptiPNG vulnerabilities Ubuntu: 2950-1: Samba vulnerabilities Red Hat: 2016:0638-01: chromium-browser: Important Advisory Fedora 22 xerces-c-3.1.3-1.fc22 Fedora 23 firefox-45.0.2-1.fc23 Community […]

Revert to 0.4.4 for f24+, update to 0.4.4. ——————————————————————————– Fedora Update Notification FEDORA-2016-139a37787e 2016-04-18 17:24:04.550946 ——————————————————————————– Name : keepassx Product : Fedora 24 Version : 0.4.4 Release : 1.fc24 URL : http://keepassx.sourceforge.net Summary : Cross-platform password manager Description : KeePassX is an application for people with extremly high demands on secure personal data management. KeePassX […]

Outdated Git version in OS X puts developers at risk
Has your website been deleted? It may not be hackers at work… but a blundering web host
Viber follows WhatsApp in adding end-to-end encryption to its messaging service
Hackers can track your iPhone whatever security measures you take
Hack the Pentagon, and you could win $150,000
House Passes Bill to Sabotage Net Neutrality
Patch JBoss now to prevent SamSam ransomware attacks
Don’t be too quick to uninstall QuickTime for Windows, warns Adobe
Hands-on: Go (almost) anonymous on the Internet with Anonabox

Nothing on the Internet is perfectly anonymous. Despite what many people may tell you, the complexities of hardware and software systems make true anonymity almost impossible, particularly when the right people decide to expend the effort to find you. That said, there are reasonable (and even unreasonable) steps you can take to remain anonymous to […]

Discovered: April 19, 2016 Updated: April 19, 2016 2:54:24 PM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Trojan.Cryptolocker.AN is a Trojan horse that encrypts files on the compromised computer and asks the user to pay for […]

News about Company Deletion through One Corrupt Line of Code is Just a Hoax

Multiple security vulnerabilities have been discovered in the Tomcat servlet and JSP engine, which may result in information disclosure, the bypass of CSRF protections and bypass of the SecurityManager. For the oldstable distribution (wheezy), these problems have been fixed in version 7.0.28-4+deb7u4. This update also fixes CVE-2014-0119 and CVE-2014-0096. For the stable distribution (jessie), these […]

Anonymous Launches Dark Web Chat Service

Posted by Anthony Pell    OptiPNG could be made to crash or run programs as your login if it opened aspecially crafted file. ========================================================================== Ubuntu Security Notice USN-2951-1 April 18, 2016 optipng vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 […]

Posted by Anthony Pell    Several security issues were fixed in Samba. ========================================================================== Ubuntu Security Notice USN-2950-1 April 18, 2016 samba vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: Several security issues were fixed in Samba. Software Description: […]

Posted by Anthony Pell    An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: chromium-browser security update Advisory ID: RHSA-2016:0638-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0638.html […]

Posted by Anthony Pell    Update to xerces-c 3.1.3, fixing CVE-2016-0729 ——————————————————————————– Fedora Update Notification FEDORA-2016-880b91c090 2016-04-17 23:38:27.306984 ——————————————————————————– Name : xerces-c Product : Fedora 22 Version : 3.1.3 Release : 1.fc22 URL : http://xml.apache.org/xerces-c/ Summary : Validating XML Parser Description : Xerces-C is a validating XML parser written in a portable subset of C++. […]

– New upstream version (45.0.2) ——————————————————————————– Fedora Update Notification FEDORA-2016-0b80c47a4b 2016-04-17 23:39:23.511547 ——————————————————————————– Name : firefox Product : Fedora 23 Version : 45.0.2 Release : 1.fc23 URL : https://www.mozilla.org/projects/firefox/ Summary : Mozilla Firefox Web browser Description : Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability. ——————————————————————————– Update Information: – […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Ubuntu: 2951-1: OptiPNG vulnerabilities Ubuntu: 2950-1: Samba vulnerabilities Red Hat: 2016:0638-01: chromium-browser: Important Advisory Fedora 22 xerces-c-3.1.3-1.fc22 Fedora 23 firefox-45.0.2-1.fc23 Fedora 24 springframework-amqp-1.3.9-4.fc24 Fedora 24 glpi-0.90.3-1.fc24 Fedora 24 drupal7-block_class-2.3-1.fc24 Community […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Ubuntu: 2951-1: OptiPNG vulnerabilities Ubuntu: 2950-1: Samba vulnerabilities Red Hat: 2016:0638-01: chromium-browser: Important Advisory Fedora 22 xerces-c-3.1.3-1.fc22 Fedora 23 firefox-45.0.2-1.fc23 Fedora 24 springframework-amqp-1.3.9-4.fc24 Fedora 24 glpi-0.90.3-1.fc24 Fedora 24 drupal7-block_class-2.3-1.fc24 Community […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Ubuntu: 2951-1: OptiPNG vulnerabilities Ubuntu: 2950-1: Samba vulnerabilities Red Hat: 2016:0638-01: chromium-browser: Important Advisory Fedora 22 xerces-c-3.1.3-1.fc22 Fedora 23 firefox-45.0.2-1.fc23 Fedora 24 springframework-amqp-1.3.9-4.fc24 Fedora 24 glpi-0.90.3-1.fc24 Fedora 24 drupal7-block_class-2.3-1.fc24 Community […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Ubuntu: 2951-1: OptiPNG vulnerabilities Ubuntu: 2950-1: Samba vulnerabilities Red Hat: 2016:0638-01: chromium-browser: Important Advisory Fedora 22 xerces-c-3.1.3-1.fc22 Fedora 23 firefox-45.0.2-1.fc23 Fedora 24 springframework-amqp-1.3.9-4.fc24 Fedora 24 glpi-0.90.3-1.fc24 Fedora 24 drupal7-block_class-2.3-1.fc24 Community […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Ubuntu: 2951-1: OptiPNG vulnerabilities Ubuntu: 2950-1: Samba vulnerabilities Red Hat: 2016:0638-01: chromium-browser: Important Advisory Fedora 22 xerces-c-3.1.3-1.fc22 Fedora 23 firefox-45.0.2-1.fc23 Fedora 24 springframework-amqp-1.3.9-4.fc24 Fedora 24 glpi-0.90.3-1.fc24 Fedora 24 drupal7-block_class-2.3-1.fc24 Community […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3552-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff April 17, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : tomcat7 CVE ID : CVE-2015-5174 CVE-2015-5345 CVE-2015-5346 CVE-2015-5351 CVE-2016-0706 CVE-2016-0714 CVE-2016-0763 Multiple security vulnerabilities have been discovered in the Tomcat servlet and JSP engine, which may result in information disclosure, the bypass of CSRF […]

Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3551-1 security@debian.org https://www.debian.org/security/ Florian Weimer April 16, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : fuseiso CVE ID : CVE-2015-8836 CVE-2015-8837 Debian Bug : 779047 It was discovered that fuseiso, a user-space implementation of the ISO 9660 file system based on FUSE, contains several […]

How to make your WhatsApp even more private and secure
AI and humans successfully ‘predict most cyberattacks’

Researchers from MIT’s Computer Science and Artificial Intelligence Laboratory (CSAIL) have developed an artificial intelligence (AI) platform that can ‘predict 85% of cyberattacks’ so long as it benefits from human input. Its latest paper, AI2: Training a big data machine to defend, revealed that this unique approach is capable of delivering better results than machines […]

Decryption tool released for Locky ransomware impersonator
We all have a natural human tendency to trust… Be prepared! – Download VASCO’s Social Engineering eBook [Sponsor]
GozNym Malware Hits Banking Systems in Canada and The US

Previous posts in this series provided an overview of threat intelligence, its role within the IoT space, and how it can be used to prevent threats at the network perimeter in IoT Gateways. With the evolution of internet-connected devices and their growing resource capabilities, these “things” will increasingly become connected directly to the internet, forgoing connectivity […]

Hacker: This is how I broke into Hacking Team
Apple rebuts DOJ’s appeal in N.Y. meth dealer’s iPhone case
Latest Chrome Update Addresses Two High-Severity Vulnerabilities
Changing your password regularly is a terrible idea, and here’s why
Chrome extensions will soon have to tell you what data they collect
Encryption laws should think global, not local

Discovered: April 18, 2016 Updated: April 18, 2016 2:51:04 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Trojan.Ransomcrypt.AK is a Trojan horse that encrypts files on the compromised computer and asks the user […]

The Pirate Bay Goes Offline Worldwide Due To Technical Issues
Could Facebook Change Election Results?
Running QuickTime for Windows on your PC? You should uninstall it. NOW.

It was discovered that fuseiso, a user-space implementation of the ISO 9660 file system based on FUSE, contains several vulnerabilities. CVE-2015-8836 A stack-based buffer overflow may allow attackers who can trick a user into mounting a crafted ISO 9660 file system to cause a denial of service (crash), or, potentially, execute arbitrary code. CVE-2015-8837 An […]

Richland County Websites including Sheriffs Department Hacked
Latest Facebook Video Malware Scam Targets Chrome Users

Shayan Sadigh discovered a vulnerability in OpenSSH: If PAM support is enabled and the sshd PAM configuration is configured to read userspecified environment variables and the UseLogin option is enabled, a local user may escalate her privileges to root. In Debian UseLogin is not enabled by default. For the oldstable distribution (wheezy), this problem has […]

Stressful Friday for Gamers as Warcraft Servers DDoSed by Lizard Squad
Burr-Feinstein encryption bill is officially here in all its scary glory
Man Faces 10 Years in Prison for DDoS Attack against Security Researcher
Justin Trudeau owns reporter on sarcastic question about quantum computing
Location Data on Social Media Apps can Disclose Identity of Anonymous Users
DARPA Squad X program to help troops pinpoint enemy in warfare

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3549-1 security@debian.org https://www.debian.org/security/ Michael Gilbert April 15, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : chromium-browser CVE ID : CVE-2016-1651 CVE-2016-1652 CVE-2016-1653 CVE-2016-1654 CVE-2016-1655 CVE-2016-1657 CVE-2016-1658 CVE-2016-1659 Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-1651 An out-of-bounds read issue was discovered in the pdfium library. CVE-2016-1652 […]

A heap buffer overflow vulnerability was removed from the poppler library. ——————————————————————————– Fedora Update Notification FEDORA-2016-a97dfe609c 2016-04-15 03:13:35.677680 ——————————————————————————– Name : poppler Product : Fedora 23 Version : 0.34.0 Release : 2.fc23 URL : http://poppler.freedesktop.org/ Summary : PDF rendering library Description : Poppler, a PDF rendering library, is a fork of the xpdf PDF viewer […]

Posted by Anthony Pell    Rebased to 0.12.1. ——————————————————————————– Fedora Update Notification FEDORA-2016-e6e8436b98 2016-04-15 03:13:35.679696 ——————————————————————————– Name : qpid-proton Product : Fedora 23 Version : 0.12.1 Release : 1.fc23 URL : http://qpid.apache.org/proton/ Summary : A high performance, lightweight messaging library Description : Proton is a high performance, lightweight messaging library. It can be used in […]

Update to 4.8 ——————————————————————————– Fedora Update Notification FEDORA-2016-048ffb6235 2016-04-15 03:16:06.565301 ——————————————————————————– Name : libtasn1 Product : Fedora 24 Version : 4.8 Release : 1.fc24 URL : http://www.gnu.org/software/libtasn1/ Summary : The ASN.1 library used in GNUTLS Description : A library that provides Abstract Syntax Notation One (ASN.1, as specified by the X.680 ITU-T recommendation) parsing and […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Debian: 3549-1: chromium-browser: Summary Fedora 23 poppler-0.34.0-2.fc23 Fedora 23 qpid-proton-0.12.1-1.fc23 Fedora 24 libtasn1-4.8-1.fc24 Fedora 24 cryptopp-5.6.3-3.fc24 Fedora 24 samba-4.4.2-1.fc24 Debian: 3548-2: samba: Summary Fedora 22 samba-4.2.11-0.fc22 Community Linux Events Linux […]

Posted by Anthony Pell    Security fix for CVE-2015-5370, CVE-2016-2110, CVE-2016-2111, CVE-2016-2112,CVE-2016-2113, CVE-2016-2114, CVE-2016-2115, CVE-2016-2118 ——————————————————————————– Fedora Update Notification FEDORA-2016-383fce04e2 2016-04-15 03:16:06.564657 ——————————————————————————– Name : samba Product : Fedora 24 Version : 4.4.2 Release : 1.fc24 URL : http://www.samba.org/ Summary : Server and Client software to interoperate with Windows machines Description : Samba is the […]

Uninstall QuickTime for Windows now!
More than 45,000 sign petition against U.S. encryption-breaking bill
Badlock: Patch your Samba and Windows server now
The DNSSEC Root Signing Ceremony
Really? One key to bind them all – DNS.
Juniper Networks code review reveals no new backdoors
True confessions: Why I stick with my BlackBerry
Jigsaw decryption tool released for sadistic ransomware that deletes your files

Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-1651 An out-of-bounds read issue was discovered in the pdfium library. CVE-2016-1652 A cross-site scripting issue was discovered in extension bindings. CVE-2016-1653 Choongwoo Han discovered an out-of-bounds write issue in the v8 javascript library. CVE-2016-1654 Atte Kettunen discovered an uninitialized memory read condition. CVE-2016-1655 Rob […]

Sorry Folks Range Rover Sport 2016 Give Away is a Facebook Scam
Samsung Galaxy Phones Prone to Hacking via USB Cable even if Locked

Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix. The Common Vulnerabilities and Exposures project identifies the following issues: CVE-2015-5370 Jouni Knuutinen from Synopsys discovered flaws in the Samba DCE-RPC code which can lead to denial of service (crashes and high cpu consumption) and man-in-the-middle attacks. CVE-2016-2110 Stefan […]

Sweden Says its critical infrastructure was under Attack by Russian Hackers

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3548-2 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso April 14, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : samba Debian Bug : 820947 The upgrade to Samba 4.2 issued as DSA-3548-1 introduced a packaging regression causing an additional dependency on the samba binary package for the samba-libs, samba-common-bin, python-samba and samba-vfs-modules binary […]

Posted by Anthony Pell    Security fix for CVE-2015-5370, CVE-2016-2110, CVE-2016-2111, CVE-2016-2112,CVE-2016-2113, CVE-2016-2114, CVE-2016-2115, CVE-2016-2118 ——————————————————————————– Fedora Update Notification FEDORA-2016-48b3761baa 2016-04-14 00:52:48.149054 ——————————————————————————– Name : samba Product : Fedora 22 Version : 4.2.11 Release : 0.fc22 URL : http://www.samba.org/ Summary : Server and Client software to interoperate with Windows machines Description : Samba is the […]

Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3548-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso April 13, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : samba CVE ID : CVE-2015-5370 CVE-2016-2110 CVE-2016-2111 CVE-2016-2112 CVE-2016-2113 CVE-2016-2114 CVE-2016-2115 CVE-2016-2118 Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix. The […]

Posted by Anthony Pell    Security fix for CVE-2015-5370, CVE-2016-2110, CVE-2016-2111, CVE-2016-2112,CVE-2016-2113, CVE-2016-2114, CVE-2016-2115, CVE-2016-2118 ——————————————————————————– Fedora Update Notification FEDORA-2016-be53260726 2016-04-13 16:54:31.873262 ——————————————————————————– Name : samba Product : Fedora 23 Version : 4.3.8 Release : 0.fc23 URL : http://www.samba.org/ Summary : Server and Client software to interoperate with Windows machines Description : Samba is the […]