Menu

Monthly Archives: June 2016

Red Hat: 2016:1271-01: python-django-horizon: Important Advisory Posted by Anthony Pell    An update for python-django-horizon is now available for Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: python-django-horizon security and bug […]

Red Hat: 2016:1269-01: python-django-horizon: Important Advisory Posted by Anthony Pell    An update for python-django-horizon is now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: python-django-horizon security update Advisory […]

Red Hat: 2016:1268-01: python-django-horizon: Important Advisory Posted by Anthony Pell    An update for python-django-horizon is now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: python-django-horizon security update Advisory […]

Red Hat: 2016:1270-01: python-django-horizon: Important Advisory Posted by Anthony Pell    An update for python-django-horizon is now available for Red Hat OpenStack Platform 8.0 (Liberty). Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: python-django-horizon security update Advisory ID: RHSA-2016:1270-01 Product: Red Hat […]

Ransomware A Two-Year Nightmare in the Making
Advantech Patches WebAccess Remote Code Execution Flaws
CEO salaries should be linked to their firm’s cyber security, says UK parliament
Severe flaws in widely used open source library put many projects at risk
⊛ Facebook CEO tapes over his webcam. Maybe you should do the same?
Senate rejects FBI bid for warrantless access to internet browsing histories
Top website domains are vulnerable to email spoofing
Israeli cybersecurity boom ‘sustainable’, argues industry’s father
Tech jobs report: Security, devops, and big data stay hot
Stuxnet was the opening shot of decades of non-stop cyber warfare
Hacker, Bromium donate $30,000 in bug bounty cash to charity
Google turns to codeless tap factor authenticaton
Carbonite online backup accounts under password reuse attack
IDG Contributor Network: 3 ways an appsec program saves time for developers
‘Plane Hacker’ Roberts hacks cows
Google Simplifies Two-Step Verification
How Red Hat uses CVSS v3 to Assist in Rating Flaws
Tor Teams Up With Experts to Protect Users from FBI Hacking
Bitcoin Phishing Campaign Uncovered
⊛ Online backup firm Carbonite tells users to change their passwords now
Meet the 18-Year-Old Who Hacked the Pentagon

Slackware: 2016-172-01: libarchive: Security Update Posted by Anthony Pell    New libarchive packages are available for Slackware 14.1 and -current to fix security issues. [More Info…] [slackware-security] libarchive (SSA:2016-172-01) New libarchive packages are available for Slackware 14.1 and -current to fix security issues. Here are the details from the Slackware 14.1 ChangeLog: +————————–+ patches/packages/libarchive-3.2.1-i486-1_slack14.1.txz: Upgraded. […]

Slackware: 2016-172-02: pcre: Security Update Posted by Anthony Pell    New pcre packages are available for Slackware 14.1 and -current to fix security issues. [More Info…] [slackware-security] pcre (SSA:2016-172-02) New pcre packages are available for Slackware 14.1 and -current to fix security issues. Here are the details from the Slackware 14.1 ChangeLog: +————————–+ patches/packages/pcre-8.39-i486-1_slack14.1.txz: Upgraded. […]

Red Hat: 2016:1262-01: chromium-browser: Important Advisory Posted by Anthony Pell    An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: chromium-browser security update Advisory ID: RHSA-2016:1262-01 Product: Red Hat […]

Discovered: June 20, 2016 Updated: June 20, 2016 6:57:37 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Backdoor.Dexbia is a Trojan horse that opens a back door on the compromised computer. […]

Hackers sold access to 170,000 compromised servers, many in the US

APPLE-SA-2016-06-20-2 OS X: Flash Player plug-in blocked Subject: APPLE-SA-2016-06-20-2 OS X: Flash Player plug-in blocked From: Apple Product Security Date: Mon, 20 Jun 2016 17:03:34 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-06-20-2 OS X: Flash Player plug-in blocked Due to security issues in older versions, Apple has updated the web plug-in blocking mechanism to […]

APPLE-SA-2016-06-20-1 AirPort Base Station Firmware Update 7.6.7 and 7.7.7 Subject: APPLE-SA-2016-06-20-1 AirPort Base Station Firmware Update 7.6.7 and 7.7.7 From: Apple Product Security Date: Mon, 20 Jun 2016 12:57:18 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-06-20-1 AirPort Base Station Firmware Update 7.6.7 and 7.7.7 AirPort Base Station Firmware Update 7.6.7 and 7.7.7 is now […]

Dept. of Justice Makes Plea for Mass Surveillance, Hacking
⊛ Android malware uses Google Talk to call Chinese numbers
Tech groups say FBI shouldn’t be allowed to do mass hacking
Meet the hacker taking over ISIS twitter accounts
Apple Patches AirPort Remote Code Execution Flaw
Apple fixes serious flaw in AirPort wireless routers
Acer experiences major data breach

Acer has experienced a major data breach, with up to 34,500 of its customers thought to be affected. It has already submitted a “breach notification sample” to the Office of the Attorney General in California, which states that one of its ecommerce sites was compromised. Worryingly, the electronics corporation has admitted that the data breach […]

Interview with a Craigslist scammer

One of my most popular posts of all time is about sticking it to Craigslist scammers. And no wonder: I get one or two emails a week from people who have been scammed or almost scammed on Craiglist. The victims are always upset and want my help getting the scammer arrested, which is nearly impossible. My […]

Monsanto sues ex-employee accused of stealing data
No watershed: China hacker groups in decline before Xi-Obama deal
Drubbed StubHub carder grub guilty, faces 12 years in cooler club
‘Nobody cares about your heart-rate’
Good hacker uses vid vulns to spy on Quebec Liberal Party meetings
AirPort owners: Apple’s patched a mystery vuln
GoToMyPC Suffers Major Password Reuse Attack
Student creates glove that reduces Parkinson’s tremors by 80%

Debian: 3605-1: libxslt: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3605-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso June 19, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libxslt CVE ID : CVE-2015-7995 CVE-2016-1683 CVE-2016-1684 Debian Bug : 802971 Several vulnerabilities were discovered in libxslt, an XSLT processing runtime library, which could lead […]

Multiple vulnerabilities have been found in PHP, the worst of which could lead to arbitrary code execution, or cause a Denial of Service condition. – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201606-09 FFmpeg: Multiple vulnerabilities Posted by Anthony Pell    Multiple vulnerabilities have been found in FFmpeg, the worst of which could lead to arbitrary code execution or Denial of Service condition. – – – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201606-08 Adobe Flash Player: Multiple vulnerabilities Posted by Anthony Pell    Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which allows remote attackers to execute arbitrary code. – – – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201606-07 dhcpcd: Multiple vulnerabilities Posted by Anthony Pell    Multiple vulnerabilities have been found in dhcpcd allowing remote attackers to possibly execute arbitrary code or cause a Denial of Service. – – – – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201606-06 nginx: Multiple vulnerabilities Posted by Anthony Pell    Multiple vulnerabilities have been found in nginx, the worst of which may allow a remote attacker to cause a Denial of Service. – – – – – – – – – – – – – – – – – – – – – – – […]

An update for flash-plugin is now available for Red Hat Enterprise Linux 5 Supplementary and Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: flash-plugin security update Advisory ID: RHSA-2016:1238-01 Product: Red Hat Enterprise Linux Supplementary Advisory […]

An update for ImageMagick is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: ImageMagick security update Advisory ID: RHSA-2016:1237-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2016:1237 Issue […]

Debian: 3604-1: drupal7: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3604-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff June 16, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : drupal7 CVE ID : not yet available A privilege escalation vulnerability has been found in the User module of the Drupal content management framework. For […]

Gentoo: 201606-05 spice: Multiple vulnerabilities Posted by Anthony Pell    Multiple vulnerabilities have been found in spice, the worst of which may result in the remote execution of arbitrary code. – – – – – – – – – – – – – – – – – – – – – – – – – […]

xDedic Scope May Be Larger Than Originally Thought
Aggressive Triada, Horde Variants Up Mobile Malware Threat
⊛ Evil Santa Ded Cryptor ransomware places victims on the ‘naughty’ list
Acer Ecommerce Site Spills Credit Card Information of Thousands
GoToMyPC Suffers Security Breach; Resets Passwords
Israel and US forge human-free cyber info-sharing pact
⊛ Scammers claim there is a virus in Apple’s iTunes database
Patrick Wardle on macOS Gatekeeper, Crypto Enhancements
Sirin Labs’ Solarin isn’t for pro-privacy bankers. It’s for rich execs who want bling
⊛ Acer to notify customers of online store data breach
T-Mobile Czech ad man steals, sells, 1.5 million customer records
Ransomware scum build weapon from JavaScript
Beware; Latest PayPal Phishing Scam Comes From Irish Government Email
VerticalScope Breach; 45 Million Users Affected
⊛ GoToMyPC accounts hacked, all customer passwords reset

Several vulnerabilities were discovered in libxslt, an XSLT processing runtime library, which could lead to information disclosure or denial-of-service (application crash) against an application using the libxslt library. For the stable distribution (jessie), these problems have been fixed in version 1.1.28-2+deb8u1. We recommend that you upgrade your libxslt packages.

FBI builds mammoth facial recognition database raising huge privacy concerns

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Tor torpedoed! Tesco Bank app won’t run with privacy tool installed

Discovered: June 17, 2016 Updated: June 17, 2016 10:54:40 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows NT, Windows Vista, Windows XP Trojan.Ransomcrypt.AZ is a Trojan horse that encrypts files on the compromised computer and asks the user to pay in order to decrypt […]

There’s a lot that happens in the security world, with many stories getting lost in the mix. In an effort to keep our readers informed and updated, we present the Webroot Threat Recap, highlighting 5 major security news stories of the week. Compromised RDP Servers Offer Cheap Attack Platform Recently, researchers discovered an online marketplace that allowed […]

A month to save digital currency Ethereum?

A privilege escalation vulnerability has been found in the User module of the Drupal content management framework. For additional information, please refer to the upstream advisory at https://www.drupal.org/SA-CORE-2016-002. For the stable distribution (jessie), this problem has been fixed in version 7.32-1+deb8u7. For the unstable distribution (sid), this problem has been fixed in version 7.44-1. We […]

Risk High Date Discovered June 14, 2016 Description Microsoft Edge is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can take advantage of this vulnerability to execute arbitrary code in the context of the currently logged-in user. Failed attacks […]

Thinking outside the security space
FBI’s iPhone paid-for hack should be barred, say ex-govt officials
Google’s Android Rewards Program Pays Out Half Million in First Year
You Acer holes! PC maker leaks payment cards in e-store hack
Yes, even coders make the mistake of reusing passwords
Threatpost News Wrap, June 17, 2016
Breached Credentials Used to Access Github Repositories
With 36 security fixes, you should either update Adobe Flash now… or kill it
Apple will require HTTPS connections for iOS apps by the end of 2016
Donald Trump claims the Democratic National Convention hacked itself
Surveillance reform measure blocked in the wake of Orlando killings
Flaws expose Cisco RV series routers, firewalls to hacking
ScarCruft APT Group Used Latest Flash Zero Day in Two Dozen Attacks
GitHub resets passwords for lazy, reckless users
Fear your on-premises security, not the cloud
London Mayor election day bug forced staff to query vote DB by hand
Edgier Edge pledge: TLS fledge no speed wedge, Redmond man said