Google is looking to deliver even greater transparency when it comes to online security by identifying publicly – or “marking”, as it puts it – websites that are not as secure as they should be. In a blog, Emily Schechter, a product manager within the tech giant’s Chrome security team, revealed that as of 2017, its browser […]
So, the story goes something like this. In 1947, in Virginia, US, an error was spotted on the Harvard Mark II, one of the first programmable computers in the world. A team went to investigate, discovering that a moth had been caught between a relay in a machine. It was subsequently removed and taped to […]
Multiple vulnerabilities have been discovered in the Xen hypervisor. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2016-7092 (XSA-185) Jeremie Boutoille of Quarkslab and Shangcong Luan of Alibaba discovered a flaw in the handling of L3 pagetable entries, allowing a malicious 32-bit PV guest administrator can escalate their privilege to that of the […]
Discovered: September 9, 2016 Updated: September 9, 2016 3:40:08 PM Type: Trojan Systems Affected: Linux Linux.Luabot is a Trojan horse for Linux computers that may perform malicious activities. Symantec Security Response is currently investigating this threat and will post more information as it becomes available. Antivirus Protection Dates Initial Rapid Release version September 9, 2016 […]
Red Hat: 2016:1820-01: postgresql92-postgresql: Moderate Advisory Posted by Anthony Pell An update for postgresql92-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: postgresql92-postgresql security update Advisory ID: RHSA-2016:1820-01 Product: Red Hat Software Collections […]
Red Hat: 2016:1821-01: rh-postgresql95-postgresql: Moderate Advisory Posted by Anthony Pell An update for rh-postgresql95-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: rh-postgresql95-postgresql security update Advisory ID: RHSA-2016:1821-01 Product: Red Hat Software Collections […]
Debian: 3661-1: charybdis: Summary Posted by Anthony Pell Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3661-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff September 06, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : charybdis CVE ID : CVE-2016-7143 It was discovered that incorrect SASL authentication in the Charybdis IRC server may lead to users impersonating other users. For […]
We previously explained how to construct an analysis environment enabling the certificate pinning process to be bypassed in Android applications, in order to be able to examine network traffic and to easily determine what data is being transmitted over secure communications protocols. In particular, we looked at the steps to take to install Cydia Substrate and Android SSL […]
��}�r�F���vU�a�g�1�~ˤW��Ļv쳔��},��@@Q���}��������7�’���_�(�v�;{76����t����L?y�����?ޞ���^��~s��(;�1�aG�����쫎� �(��]�6�>T�ν’#nX�{�D�=�Ƞ�*�eb_v�cύ��g3�+��:Jį”F8X�Y��0X�����c3V�[�c�L,�]F��-���T�� �[��b �w�(�0e}9�֍�t����iXcZv��UK�}&j��DkQ/@D^�x�z5����Ϟ=��� CIŖ�6�,0�?l�H%,:�O+������ذ�� �a�f��FV2��qd>U�Q��?��UZ_���h5�{B�^�7D�l�Xx�i}�Ӈ�K��d’*�x��V�Q;L������R���u��� M��x�O�-����#�nc�g�?�l���Y���翋�^Q[���(�/�}o7v�U뽻�ћ��4W���n�/s� :`[9�½/�6�y5ߪ�e��z)�g��/] /����l���+^�HW[�:*� (�ت��N��&������G�� �r�ccÝ~�u!ҏAC�����]��k�Y�a��D�������r��3�}�;3�k��7�ȡ$ E�}���G�9�/�ƩH�m�]r3��1vol�� ��8�Qb�A�)ǚ� q#B#�k���#4��H�1#��Qx bh�n��0N�@_��屗�|�O���^0�x�A�l��ڎ�PQN|h[ ��’�,�V�DM6�St���&r����$��v��zSs �}o�” ����(18���!3�q8͑��I��@!h�;��(�Xq����#e�IPϗ@�q�҆�xC�#���y{���.�A]����� �nG���Ca=!��5*�G�1���D������9c��P�n�M,�[�R� e0i`�1�qx��!�I���”n��t�pb ���AS��)~�Z4��CT’N�zs�!�!�L��4A�t+�(4�ۡ�N۱���#;D*�70.ɩ�+��-
Risk Level: Very Low. Type: Trojan.
It was discovered that incorrect SASL authentication in the Charybdis IRC server may lead to users impersonating other users. For the stable distribution (jessie), this problem has been fixed in version 3.4.2-5+deb8u2. For the unstable distribution (sid), this problem has been fixed in version 3.5.3-1. We recommend that you upgrade your charybdis packages.
Sometimes, the easy way out is the road to ruin. After WeLiveSecurity published the article Ransomware: To pay or not to pay?, SC Computing’s Bradley Barth picked up on a point I made there, where I said that we hear of instances where organizations pay ransomware even though they have backups because it’s cheaper. No […]
The Office of Personnel Management (OPM) has been heavily criticized by the Republican members of the House Oversight and Government Reform Committee for not having in place appropriate cybersecurity measures, which contributed to last year’s major data breach. According to a report from the committee, OPM’s senior leadership were also held culpable for the security incident, […]
Discovered: September 7, 2016 Updated: September 7, 2016 2:03:19 PM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Ransom.Cry is a Trojan horse that may perform malicious activities on the compromised computer. Symantec Security Response […]
Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-5147 A cross-site scripting issue was discovered. CVE-2016-5148 Another cross-site scripting issue was discovered. CVE-2016-5149 Max Justicz discovered a script injection issue in extension handling. CVE-2016-5150 A use-after-free issue was discovered in Blink/Webkit. CVE-2016-5151 A use-after-free issue was discovered in the pdfium library. CVE-2016-5152 GiWan […]
Red Hat: 2016:1815-01: kernel: Important Advisory Posted by Anthony Pell An update for kernel is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel security and bug fix update Advisory […]
Red Hat: 2016:1814-01: kernel: Important Advisory Posted by Anthony Pell An update for kernel is now available for Red Hat Enterprise Linux 6.5 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel security and bug fix update Advisory […]
Debian: 3660-1: chromium-browser: Summary Posted by Anthony Pell Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3660-1 security@debian.org https://www.debian.org/security/ Michael Gilbert September 05, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : chromium-browser CVE ID : CVE-2016-5147 CVE-2016-5148 CVE-2016-5149 CVE-2016-5150 CVE-2016-5151 CVE-2016-5152 CVE-2016-5153 CVE-2016-5154 CVE-2016-5155 CVE-2016-5156 CVE-2016-5157 CVE-2016-5158 CVE-2016-5159 CVE-2016-5160 CVE-2016-5161 CVE-2016-5162 CVE-2016-5163 CVE-2016-5164 CVE-2016-5165 CVE-2016-5166 CVE-2016-5167 […]
People have trouble prioritizing risk. For example, you often hear about the threat of voter fraud, when all evidence suggests that the risks of such fraud are inconsequential. In truth, hacked voting machines are much more likely to affect an election’s outcome. Why would an election fraudster try to herd a flock of criminal participants to […]
