Menu

Monthly Archives: June 2016

Google to shower 50%+ more gold on code-bearing bug hunters
Feds warn of skyrocketing business compromise scams
Non-US encryption is ‘theoretical,’ claims CIA chief in backdoor debate
Robot Runs Away from Lab; Blocks Traffic in Russia
Lone hacker claims to have broken into US Democrat servers
How to survive multiple-hat security syndrome
How to catch pentest teams and other actors on a network
Anti-Surveillance Measure Quashed: Orlando Massacre Cited as Reason
Kill Flash now. Or patch these 36 vulnerabilities. Your choice
Muslim Brotherhood’s Website Suffers DDoS Attacks and Data Leak

Debian: 3603-1: libav: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3603-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff June 14, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libav CVE ID : CVE-2016-3062 Several security issues have been corrected in multiple demuxers and decoders of the libav multimedia library. A full list of […]

Debian: 3602-1: php5: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3602-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso June 14, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : php5 CVE ID : CVE-2013-7456 CVE-2016-3074 CVE-2016-4537 CVE-2016-4538 CVE-2016-4539 CVE-2016-4540 CVE-2016-4541 CVE-2016-4542 CVE-2016-4543 CVE-2016-4544 CVE-2016-5093 CVE-2016-5094 CVE-2016-5095 CVE-2016-5096 Several vulnerabilities were found in PHP, a […]

Report: FBI Doing Poor Job Securing 411 Million Facial Recognition Photos

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Security Sessions: How CSOs can reduce alert fatigue
Hacking Facebook Account by Simply Knowing Account Phone Number
Inside the xDedic Hacked Server Marketplace
GitHub presses big red password reset button after third-party breach
Ad hoc operations in the SOC can lead to pain
So, just why is 18atcskd2w such a popular password?
Telegram calls claims of bug in messaging service bogus »
Where’s the macro? Malware authors are now using OLE embedding to deliver malicious files »
Cisco Won’t Patch Critical RV Wireless Router Vulnerability Until Q3
Why your password policy still sucks
Smut shaming: Anonymous fights Islamic State… with porn
Like Macros Before It, Attackers Shifting to OLE to Spread Malware
5 Ways to Defuse Data Threat from Departing Employees
Companies pay out billions to fake-CEO email scams
Hack the hackers: Eavesdrop for intel on emerging threats
Dodgy creds found in Siemens ICS gear
Microsoft planning blockchain-as-a-service for Azure apps
Password reset: 45 million creds leak from popular .com forums
SOHOpeless Cisco wireless kit needs critical patch
Microsoft releases open source bug-bomb in the rambling house of C

Risk Level: Very Low. Type: Trojan.

Several security issues have been corrected in multiple demuxers and decoders of the libav multimedia library. A full list of the changes is available at https://git.libav.org/?p=libav.git;a=blob;f=Changelog;hb=refs/tags/v11.7 For the stable distribution (jessie), this problem has been fixed in version 6:11.7-1~deb8u1. We recommend that you upgrade your libav packages.

Several vulnerabilities were found in PHP, a general-purpose scripting language commonly used for web application development. The vulnerabilities are addressed by upgrading PHP to the new upstream version 5.6.22, which includes additional bug fixes. Please refer to the upstream changelog for more information: For the stable distribution (jessie), these problems have been fixed in version […]

Spam King sent down for 30 months

Risk High Date Discovered June 14, 2016 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will […]

Risk Medium Date Discovered June 14, 2016 Description Microsoft Windows is prone to an information disclosure vulnerability. Successful exploits will allow attackers to obtain sensitive information that may aid in further attacks. Technologies Affected Microsoft Edge Microsoft Windows 10 version 1511 for 32-bit Systems Microsoft Windows 10 version 1511 for x64-based Systems Microsoft Windows 8.1 […]

Risk High Date Discovered June 14, 2016 Description Microsoft Internet Explorer is prone to a remote privilege-escalation vulnerability. An attacker can exploit this issue to gain elevated privileges. Successful exploits may aid in further attacks. Internet Explorer 9, 10, and 11 are vulnerable. Technologies Affected Microsoft Internet Explorer 10 Microsoft Internet Explorer 11 Microsoft Internet […]

Risk High Date Discovered June 14, 2016 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will […]

Risk High Date Discovered June 14, 2016 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will […]

Risk High Date Discovered June 14, 2016 Description Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed […]

Risk High Date Discovered June 14, 2016 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will […]

Risk Medium Date Discovered June 14, 2016 Description Microsoft Internet Explorer is prone to a security-bypass vulnerability that affects the XSS Filter. An attacker can exploit this issue by tricking an unsuspecting victim into viewing a page containing malicious content. They can then execute arbitrary script code in the context of the user running the […]

Patched BadTunnel Windows Bug Has ‘Extensive’ Impact
FBI: Email Scams Take $3.1 Billion Toll on Businesses
Admins in outcry as Microsoft fix borks Group Policy
Underground Market Selling Cheap Access to Hacked Servers
Think hovering your mouse over the URL will save you? Think again!
Computer crash wipes out years of Air Force investigation records »
Critical Adobe Flash bug under active attack currently has no patch »
Say Hello to Ransomware Targeting Smart TV
Sofacy NotSoGood: Time to switch up our Trojan-slinging tactics
Cybercrooks are pimping out pwned RDP servers
Adobe warns: Cyberespionage group targeting critical Flash bug
Patch Tuesday: IE/Edge share an exploit and Windows 10 advances to build 10586.420
Cost of a data breach: $4 million. Benefits of responding quickly: Priceless
Safari 10 to turn off Flash by default
A popular cloud privacy bill stalls in the Senate
Here Is How Hackers Bypass Google’s Two-Factor Authentication
Let’s Encrypt accidentally leaks user email data
Russian hackers breach DNC computers, steal data on Trump
SAP patch batch includes fix for 3-year-old info disclosure vuln
VerticalScope experiences major data breach: 45 million records stolen

VerticalScope has experienced a major data breach, with cybercriminals making off with over 45 million records belonging to over 1,100 websites, it has been reported. LeakedSource, which provides detailed information on data breaches, said that some of the websites impacted by this include Techsupportforum.com, MobileCampsites.com, Pbnation.com and Motorcycle.com. It is believed that the security incident […]

Block malware, ransomware, and phishing with 5 layers
Home invasion? 3 fears about Google Home
Biz security deadline knocked back 3 months ‘cos Brits ignored it
East Euro crims pwning ‘high profile’ victims with Flash zero day

There’s a lot that happens in the security world, with many stories getting lost in the mix. In an effort to keep our readers informed and updated, we present the Webroot Threat Recap, highlighting 5 major security news stories of the week. Human Error Remains Top Security Threat In a study conducted over the course of 3 […]

Chinese loan sharks seek salacious selfies as collateral

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Russian government hackers spent a year in our servers, admits DNC
North Korea stole F-15 blueprints and 42,000 defense-related documents from South Korea
Hackers Found Their Way Inside Telegram App

Multiple security issues have been found in Icedove, Debian’s version of the Mozilla Thunderbird mail client: Multiple memory safety errors may lead to the execution of arbitrary code or denial of service. Debian follows the extended support releases (ESR) of Thunderbird. Support for the 38.x series has ended, so starting with this update we’re now […]

Microsoft June Patch Tuesday Fixes 44 Vulnerabilities
Verizon Patches Serious Email Flaw That Left Millions Exposed
It’s [insert month] of 2016, and your Windows PC can still be owned by [insert document type]
Telegram bug allows attackers to crash devices, jack up phone bills
Apple quietly launches next-gen encrypted file system
DNC Hacked, Research on Trump Stolen

Red Hat: 2016:1225-01: kernel: Important Advisory Posted by Anthony Pell    An update for kernel is now available for Red Hat Enterprise Linux 6.5 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel security and bug fix update Advisory […]

Debian: 3601-1: icedove: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3601-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff June 13, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : icedove CVE ID : CVE-2016-2806 Multiple security issues have been found in Icedove, Debian’s version of the Mozilla Thunderbird mail client: Multiple memory safety errors […]

Security products may seem like ‘snake oil’, but that’s OK

Risk Level: Very Low. Type: Trojan.

Buggy vote-counting software borks Australian govenment election
Someone is hacking traffic signs in US and replacing them with their own messages
Fix Coming for Flash Vulnerability Under Attack
RAA Ransomware Composed Entirely of JavaScript
Don’t run JS email attachments: ​they​ can carry potent ransomware
Clueless s’kiddies using exploit kits are behind ransomware surge
Meaningful Surveillance Reform Risks Defeat
D-Link Patches Weak Crypto in mydlink Devices
Half of Brit small biz hit by cyber crime. 10% spend zilch on infosec
Greenwich University target of revenge hack; results in huge data breach