Menu

Monthly Archives: May 2016

By the numbers: Cyber attack costs compared
Microsoft has a dirty little Windows 10 upgrade trick up its sleeve
How to protect your LinkedIn account from hackers with two-step verification (2SV)
New DMA Locker ransomware is ramping up for widespread attacks
Critical infrastructure: It’s time to make security a priority

��ݒ�F�0x-E�J���O�b�Z�Xg%[������Ej���lZVļ��칛۽܈}���d�d3�����lJ�7�K P�U������������N����3���W/����h�L=����_����ˆ�ܫ~-�I�����Cs�-?�_�:wM��߁’��є’65�/�{ٯ�~���x;y� ů~-�W�� ‘v�

Poisoned Word document attack refuses to work if it believes it is being watched
New Surveillance System May Let Cops Use All of the Cameras
Boston BSides needs more space to grow
Where Should Security Keys be Kept in the Cloud?
5 steps to stronger data security

Nearly everything we do in computer security is meant to protect data. After all, we don’t deploy antimalware software, tighten security configurations, or implement firewalls to protect users, per se. Job No. 1 is to protect the organization’s data — including employee and (especially) customer data. But guess what? People need to work with that […]

20 million Instagram accounts were put at risk through sloppy security hole

Risk Level: Very Low. Type: Trojan.

Hacker Sentenced for Reporting Flaws in Police Communications System
Teenager charged over Mumsnet hack and DDoS attack

Multiple vulnerabilities were discovered in the dissectors/parsers for PKTC, IAX2, GSM CBCH and NCP which could result in denial of service. For the stable distribution (jessie), these problems have been fixed in version 1.12.1+g01b65bf-4+deb8u6. For the testing distribution (stretch), these problems have been fixed in version 2.0.3+geed34f0-1. For the unstable distribution (sid), these problems have […]

Hackers Destroy Fur Affinity Art Gallery Website

Debian: 3585-1: wireshark: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3585-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff May 22, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : wireshark CVE ID : CVE-2016-4006 CVE-2016-4079 CVE-2016-4080 CVE-2016-4081 CVE-2016-4082 CVE-2016-4085 Multiple vulnerabilities were discovered in the dissectors/parsers for PKTC, IAX2, GSM CBCH and NCP which […]

Slackware: 2016-141-01: curl: Security Update Posted by Anthony Pell    New curl packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix a security issue. [More Info…] [slackware-security] curl (SSA:2016-141-01) New curl packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix a security issue. Here are […]

LinkedIn’s poor handling of 2012 data breach comes back to haunt it
Recently patched Flash Player exploit is being used in widespread attacks
How data virtualization delivers on the devops promise
VIDEO: How one ISP discouraged users from enabling two-step verification
Criminals Steal 1.44 billion Yen ($13 million) from 1,400 ATMs in 2½ hours

Risk Level: Very Low. Type: Trojan.

Attackers can pwn 60% of Android phones using critical flaw
How to review your privacy on Windows 10
Stay Away from Google’s New Messaging App Allo—Alerts Edward Snowden
Teacher’s Email Hacked, Distributes Porn to Staff, Students and Parents

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Discovered: May 19, 2016 Updated: May 19, 2016 9:01:34 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows NT, Windows Vista, Windows XP Trojan.Ransomcrypt.AT is a Trojan horse that encrypts files on the compromised computer. Antivirus Protection Dates Initial Rapid Release version May 20, 2016 revision 034 […]

Risk Level: Very Low. Type: Trojan.

Everything We Know About How the FBI Hacks People
Hacker fans give Mr. Robot website free security checkup
Hidden Microphones Exposed As Part of Government Surveillance Program In The Bay Area
Now Translate Languages Effortlessly with This Tiny Earpiece
Hacktivists Shut Down Donald Trump Hotel Collections Website

Gustavo Grieco discovered several flaws in the way librsvg, a SAX-based renderer library for SVG files, parses SVG files with circular definitions. A remote attacker can take advantage of these flaws to cause an application using the librsvg library to crash. For the stable distribution (jessie), these problems have been fixed in version 2.40.5-1+deb8u2. For […]

A lot happens in the security world and many stories get lost in the mix. In an effort to keep our readers informed and updated, we present the Webroot Threat Recap, highlighting 5 major security news stories of the week. TeslaCrypt Closing It’s Doors Here’s a bit of good ransomware news, for once. This week, […]

Another nail in Flash’s coffin. Google Chrome to block Flash by default on most websites

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3584-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso May 19, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : librsvg CVE ID : CVE-2015-7558 CVE-2016-4347 CVE-2016-4348 Gustavo Grieco discovered several flaws in the way librsvg, a SAX-based renderer library for SVG files, parses SVG files with circular definitions. A remote attacker can take […]

LinkedIn Hack Saga Continues – These Passwords were Mostly Present in the Data
Criminal defendants demand to see FBI’s secret hacking tool
What’s your favourite computer security blog? Vote now!
Google’s Android N strengthens security core
Hit by TeslaCrypt ransomware? Here’s the solution
117 million LinkedIn members compromised by 2012 data breach

Over 117 million emails and passwords belonging to LinkedIn members have been put online for sale, it has been revealed. Worryingly, this trove of information is not thought to have been obtained from a recent data breach. In fact, it is believed that the data was accessed in 2012, when the professional social network was […]

New tech support scams mimic ransomware, lock users’ computers
Catalan Police Union Server Destroyed, Data Leaked Against Police Brutality

It was discovered that the swift3 (S3 compatibility) middleware plugin for Swift performed insufficient validation of date headers which might result in replay attacks. For the stable distribution (jessie), this problem has been fixed in version 1.7-5+deb8u1. For the testing distribution (stretch), this problem has been fixed in version 1.9-1. For the unstable distribution (sid), […]

Hacker Steals and Donates €10K in Bitcoin to Kurdish Group

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3583-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff May 18, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : swift-plugin-s3 CVE ID : CVE-2015-8466 Debian Bug : 822688 It was discovered that the swift3 (S3 compatibility) middleware plugin for Swift performed insufficient validation of date headers which might result in replay attacks. For […]

How to stop Windows 10 from Automatically Updating Your Computer
Open source tool watches Linux systems, containers for suspicious activity

Discovered: May 18, 2016 Updated: May 19, 2016 2:15:03 PM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Trojan.Ransomlock.AS is a Trojan horse that locks the desktop, making the computer unusable. Antivirus Protection Dates Initial Rapid Release […]

APPLE-SA-2016-05-18-1 OS X: Flash Player plug-in blocked Subject: APPLE-SA-2016-05-18-1 OS X: Flash Player plug-in blocked From: Apple Product Security <email@hidden> Date: Wed, 18 May 2016 15:34:13 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-05-18-1 OS X: Flash Player plug-in blocked Due to security issues in older versions, Apple has updated the web plug-in blocking mechanism […]

Developer of anonymous Tor software dodges FBI, leaves US
It’s trivially easy to identify you based on records of your calls and texts
How to empty your bank’s vault with a few clicks and lines of code
Ransomware for sale on nonsensical dark web malware site
Linux containers vs. VMs: A security comparison
Did Anonymous Hack Turkish Hospitals Resulting in Massive Data Breach?
Google’s Allo fails to use end-to-end encryption by default
Cyber Criminals Using Rio Olympics as Bait to Target Users with Phishing Scams
ESET releases new decryptor for TeslaCrypt ransomware

��}�r�Ʋ�o�*�0�OdL�(Y2�k���co���N�C�A�!�qT�����+l�>��7�’���/R;�-�� 0��������������’g���|w�����Og��%��M �O�t� 6=”�(��M}}N /|�@�{OgԴ����}:��ɋj��ع(‘̋�igK�*��JD�”�4r6sB��#�/�#g��Fm�p�`D#�6��4r”�_��:�P3�!���� �~�2��g4t�|A��|a�!*���Ԧ�8~a��LȒ��� xL���6GhD��D���j=�”��ܱ���=h�t�����naU�p�gfH�al�=�(C{G�,�#�~��b⫁�L�y�a�v#�mw�F{���!��ii{��B)�4��P[���hh��I��i-��%#CB�P?l*}d� ��s�F��MC2 ��1؏��D�6~6B}��`�� �lX,�?����A���h ��7�!0�E��O tlA^:���?#=�rc[:�^9ѻ�ޞ~>3s��w������`L�”�0[����&v�l~�L��X�T��Ѽ���PGi�쁥Oi� ��ѣ쯆ҵ��q@�8p��:��{��5l����BA�3_iA�#�(�u�+��3qͩ2L��i�F`N�I��’`�0�6��{���~���m���f��j7[���fd����FSw�7�f��5���{��z�V��“cw��#�F�����:MT���K�y�s�Ҕn��d�汥��50�Jvl��UY/|�<3�߃H46)MhU7}�z���q�ռ�'�)B�}���O�3�a�a���T����k@���w?���A~�xb��ش.)�4?e��^Ҍ.`#_����7�y9� h|�������� A�i�Q~�P�e�|z��Jk�z�i�̊��i�wq(E�5� ���&���±#.1!(�� ��IP��cѓS,��.� d����[=#��h#�y4ѥ�y�h�G���r�W��?d�f�y���e3+Fi��]M�O �VC�q�U� �;�)���9̤����O���N����(���8�3Xt}�t4��G�˕œ�U_gԙ΢#ҡ�����xv��#�&z���^� ��S(����i�bϮ��^�!�����O�25��RW+d�8�@e�㡽���ĪȪ�S��)Ŝcf�c�g�j㥖�o�s���y��U1�j2�����*1�� ��/�l���,�9�}�*y1���z��h�l�ׇ��2�E)AI���υ3��ԍ�t"�tb�n��[#���虗�Q_2�ST��]0���&�Y�S-�Lj�M��(�N����#��#㘱(�ӯ;� �6L'�g-A��C��טK=,P�����{���0*�aS,��[2��[���A}xZN`����<�&�C92�.�Ap�+���t� �A�����z�f���Ga� T����U�q�S+�rVz9f�D��O�f��`e�;o��.�Z���u^��բJp1y3-�q��V"a� �:��W��ۮ6w�ne���&?�����&�)����P������9 ���2�?Q� �)A �@��c�Z�B���a��e܂�͕Ȁ��B�!7��%��f��ᅮF��|�y,�8�x�ou��RX�dl�/:�ւsQ�1Fxy݄�XP+ b���ޫ��Ƀ��Y��B�H|����C�8�G�J7e����/i�P��MuP�4�^� h[i�p�y�yԯ�?����Gմ��u��j�����a�ɓ^�p��U��y�F��/�2I+`.[؀hK~`,��t-IU��1��3���(��P|�( �,”�l�R���y9�”�2r-��9����{v*�(�C�v�{0oqɢ>S���{����B� ��8�{-��W7�V`��U;�m�x��)Z�͒>�V-u5Vj�;^y�z�NX��’qP���������~�Ӄ^(üB�3��3/q��}A��8|盬&�~%���� �B��b�b9�*�(�6��’�!�Ã`E�*�j.����3|j��,s��H�C#5,���#�<=5L�#�`N:+�D���W�E� 6 ��E���o#�wF"�����a��M ȱ�`���1X�9��@�i���k�Ue�t'xb�!=�B�)bFL���+7��n ��C"܄O���+y�{����&���r�Z�K&�M�s�€�p�O�|��%!�B���h��F)1�@�zG��PGl zF���@�L1� �hy�#q6Jj���wZ��7�=A��ؔ���`O���3Wn��Yd;d?��(�¿�s�����K�YPkR�S�7���� �z[Nޮd���Tjw��Ž0��Ҕg�tt��x�')�������%��G��Oq[�J�mp+�N%�̭昬R�m2cs�N�Z�Peg���>L�g7�?�ɷЭ���;�׵�ۇ�[,-4f ���P>/G�0r�L]Cbpײ��O��s&E�┬�”^%&��N��)��4F��31��|��Ɗ%�:�VG��1`,�P���1L���’”D��].X`뺮Ȉ�4��uy P�wgf�)���O��SI��N����m�m�eu���B֩=�s���n8�J�M���iXI����LV���uu����^�5����I��X�O�׮r�;�hv,N9�ѣ�u,�s�8�����ouX����ݶ|-N [Y:�R�l�9����ܗ��*��M�y 5b�5�A��(�.����K�ޥ�B�I>��P�^�(e �W�yL0�����J!�s��3G��x���׹H|z_8Z��R�pSX�q�%�������|�{��Ij���l��*,�#~�H7y��Nx��d+)9�lKDx��>&2D;0m’�H{�ʹ�|�)�YV�a�lY�Ͱ�g��_h(!�v��.������Q0|�C�����P��g�I�Q��r���.ff�>�y������M��6���fw��$DD:i-�xLd�]����|����}����s~(�g�L����z6��4�T��8��B��dz�t�?F�ulz��<�g���i�I'��N���崊�S�P;y)�ZX�1��c�p�*��2Q�j.�P��WJ:Y�*ώmn�N�ө�k��낉�,R�q��ֆ�5V+u喁 7���6�/o{���8*�� g�/l�pw�xxd��r���&�usӰ����J���{�%Z�)?�~�z�j�*K��x�⦪[./����hm� �q,N<���f��0ZV~�P3�A���c�����;�7X�d������/7c�bΖ�[��?���R�o���(�/��o7���サ�ڛl�X���JS&�����v�ֱ���yO&�GZ��V�4����@�?�MBF������’�rGDu������%7�֨��3/y�S�ǛP��%�D^lƒ�ѝ�(+Ҹ�I>/��g=tXf[��3RS^���N.���:YL2�BPG��} �O�(���0��7��t’z���,/�ȡ�Q2�[`�D�z;�R���B�I~`���C_��”��@�6″�ԁ<�G�$�l��җsP8�q(��Ot�ϒ�{�� ����e�ȥ�8�;��e��xxx@�i��{�J���f���R�q��.S�?������k�A����JK���4�U ,ЂN(�V"Ыc|���7��'/���+Z�I@i�:���U�wz�s�Y�kF��?��� R��JCjYs�R��J�s��d��N^��p�0 bB��RN�T����M[~f�K��G� r�WD���� […]

Cybercriminals are increasingly embracing a sophisticated business-model approach

Posted by Anthony Pell    USN-2950-1 introduced regressions in Samba. ========================================================================== Ubuntu Security Notice USN-2950-4 May 18, 2016 samba regressions ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 12.04 LTS Summary: USN-2950-1 introduced regressions in Samba. Software Description: – samba: SMB/CIFS file, print, and login server for Unix Details: […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Ubuntu: 2950-4: Samba regressions Ubuntu: 2983-1: Expat vulnerability Debian: 3582-1: expat: Summary Ubuntu: 2982-1: Libksba vulnerabilities Ubuntu: 2981-1: libarchive vulnerabilities Ubuntu: 2980-1: libndp vulnerability Debian: 3581-1: libndp: Summary Gentoo: 201605-02 […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3582-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso May 18, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : expat CVE ID : CVE-2016-0718 Gustavo Grieco discovered that Expat, an XML parsing C library, does not properly handle certain kinds of malformed input documents, resulting in buffer overflows during processing and error reporting. […]

Posted by Anthony Pell    Libksba could be made to crash or run programs if it decoded speciallycrafted data. ========================================================================== Ubuntu Security Notice USN-2982-1 May 17, 2016 libksba vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 […]

libarchive could be made to crash or run programs if it opened a speciallycrafted file. ========================================================================== Ubuntu Security Notice USN-2981-1 May 17, 2016 libarchive vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: libarchive could […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Ubuntu: 2950-4: Samba regressions Ubuntu: 2983-1: Expat vulnerability Debian: 3582-1: expat: Summary Ubuntu: 2982-1: Libksba vulnerabilities Ubuntu: 2981-1: libarchive vulnerabilities Ubuntu: 2980-1: libndp vulnerability Debian: 3581-1: libndp: Summary Gentoo: 201605-02 […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3581-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso May 17, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libndp CVE ID : CVE-2016-3698 Debian Bug : 824545 Julien Bernard discovered that libndp, a library for the IPv6 Neighbor Discovery Protocol, does not properly perform input and origin checks during the reception of […]

Posted by Anthony Pell    Multiple vulnerabilities have been found in the Chromium web browser, the worst of which allows remote attackers to execute arbitrary code. – – – – – – – – – – – – – – – – – – – – – – – – – – – – – […]

Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2978-2 May 16, 2016 linux-lts-wily vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: – linux-lts-wily: Linux hardware enablement kernel from Wily for Trusty […]

Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2978-1 May 16, 2016 linux vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 Summary: Several security issues were fixed in the kernel. Software Description: – linux: Linux kernel Details: David Matlack discovered that the Kernel-based […]

The system could be made to crash or run programs as an administrator. ========================================================================== Ubuntu Security Notice USN-2979-4 May 16, 2016 linux-snapdragon vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS Summary: The system could be made to crash or run programs as an administrator. Software Description: […]

Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2979-2 May 16, 2016 linux-lts-xenial vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: – linux-lts-xenial: Linux hardware enablement kernel from Xenial for Trusty […]

Hacker Selling 117 million LinkedIn Login Credentials
Modified version of Skimer malware makes stealing cash from ATMs easy
A hacker is selling 167 million LinkedIn user records
Operation Groundbait: Espionage in Ukrainian war zones

��}�۸��o�j��OY�Z$�1��X���9��׎g�lNv7*J�$z(�ˏ��ީ��_�WH��#�J�G�’�p�$�H��h4�w�ƾ��P$�h4��F�����’g�������7wϢ�K˛�5��ߟj��Ĺ�klzDfQ��&��Ɯ�^x_�:wϨe�����9�,^T����E_;a^D�H?[�T#c�E�22����� B��h�j�T��w��O�6���*�W/�Ԟ�|UϚӾv�ЅςH)�p�hַ�3�:��$��D�����ri�]i��ԥz�DT���3qƀ���QǺ����#�=�M�m���;��������ߝ�;������:�Q��V��888�>���N:����^��j��i���xij5 B:�؍ml�C�_��:̼�3���������1���c�ֽ �72Z�j���Ƨ�7��V���ָ?28��$/��T��M�?6�4���e���ul�q�(܃�1q�>=��y����4g�ք�LA����i,f�ZS���[X1R?��4����O��>a6���w�{���a��L�[�f��j4�FĞ[�������Ro�]�mm�au�%�ֽ~����F��v����l7P�֏����{�t M%�5��F��”[Ɏ��*�ϖg��;���������S�>�9�]7���Is��cWa�S��}�clh�?�`”���v� x���{���kïO,��>��la��C�F�H_!�_�O�r����Ȱl��t��d��I��A�r1�t���y��hZeQ���0�P”����k̓��v��.�`�`]�rk*ȃ�b’A���DON�,v�د�dFH�~�jNE؟�z�w�hbH����Ĉ���F�R�F�.tU�f�y��Bw5P���Tu�q0�#�-��`�Euv�,�=�J�;2���(���`�>�$_1�Ӊ���]����4X `�*HM��p��=<� ��6e�rwxK��pwGa4�h�;<�N0^ �/yM������^t��o�S3x���W�m���8;x���� �Y��l�o3�rVz9b�D��O�f��`e�;o��.�����T�Su^� ������L��D� �P��6:�A�^���sgඑ�`�v�B�|��� c�Ew�O�4�@ɡQ�9u��-�����!�&�/u���� kC�ň��0ZqĒ�ئZ�)�R� �5�.�s��oq��"�!���t��,�� :YX�j X�O�4���9�f��(j�OW��,U�%@5~���7��� (�:��iº�Ʊ��e7m¦q�gjS��X�չg9������;Y?:��$A�AL������5�0|x9w���]���t�yI�]��^��w��/.,#�q7~��ը.�Ⱥ������7��@�ZL������?�N��d��ğ��~����}��ύcQř��=|k��7���

Jigsaw ransomware 2.0: A fake or work in progress?

Just recently we reported on various ransomware types that failed in their malicious intentions. Some were cracked by security experts due to poor implementation, while others flopped because the decryption key had been ‘left’ on the victims’ machine, allowing decryption of files without paying the ransom. But the threat seen by ESET researchers over the […]

Google to shutter SSLv3, RC4 from SMTP servers, Gmail
Android apps ‘need to follow better security practice’

Many Android apps in Google Play are still not following best practice when it comes to authentication and authorization. Writing on its Android Developers Blog, Isabella Chen, a software engineer at Google, said that this can leave apps “vulnerable to attack”. It is important that developers make their applications as secure as possible, so that […]

117 million hacked LinkedIn email addresses and passwords put up for sale
If this malware finds any of over 400 security products installed, it won’t bother infecting…

Gustavo Grieco discovered that Expat, an XML parsing C library, does not properly handle certain kinds of malformed input documents, resulting in buffer overflows during processing and error reporting. A remote attacker can take advantage of this flaw to cause an application using the Expat library to crash, or potentially, to execute arbitrary code with […]

Anonymous Target North Carolina Government Sites Against anti-LGBT Law

Nikolay Ermishkin from the Mail.Ru Security Team and Stewie discovered several vulnerabilities in ImageMagick, a program suite for image manipulation. These vulnerabilities, collectively known as ImageTragick, are the consequence of lack of sanitization of untrusted input. An attacker with control on the image input could, with the privileges of the user running the application, execute […]

Let’s Welcome Ross – World’s First AI Lawyer
Error 56. Has the iOS 9.3.2 update turned your iPad Pro into a brick?
Take care when taking screenshots… or blame it on a virus

APPLE-SA-2016-05-16-6 iTunes 12.4 Subject: APPLE-SA-2016-05-16-6 iTunes 12.4 From: Apple Product Security <email@hidden> Date: Mon, 16 May 2016 15:47:53 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-05-16-6 iTunes 12.4 iTunes 12.4 is now available and addresses the following: iTunes Available for: Windows 7 and later Impact: Running the iTunes installer in an untrusted directory may have […]