Menu

Monthly Archives: November 2016

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Trump’s torture support could mean the end of GCHQ-NSA relationship

LinuxSecurity.com: – new upstream version (49.0.2)

LinuxSecurity.com: Security fix for CVE-2016-7035 (improper IPC guarding)

LinuxSecurity.com: Update to 1.10.12

LinuxSecurity.com: Security Report Summary

Google to Red Flag ‘Repeat Offender’ Websites
November Patch Tuesday fixes controversial Windows 0-day hole
UK’s ‘FBI’ hit by DDoS barrage
Los Angeles: Warm weather, movie stars — and 100 million monthly cyber attacks
Tech support scammers bite Chrome users with forgotten 2014 bug
WoT pulls browser extension after privacy failure
Understanding and mitigating the Dirty Cow Vulnerability
Losses and sales up, shares down at Sophos
Locky ransomware disguises itself as account suspensions and suspicious movements
Facebook suspends plans to collect WhatsApp user data in the UK
Careers in fighting cybercrime

Interested in a career where you get to fight cybercrime on a daily basis? ESET’s senior research fellow David Harley takes a look at some key things. The post Careers in fighting cybercrime appeared first on WeLiveSecurity.

Top 5 Online Dangers For Kids
iOS WebView Problem Allows Attackers to Initiate Phone Calls
iOS 10.2 will make your local iPhone backup much much harder to crack
Would your password withstand 100 guesses from a hacker?
What do you give a bear that wants to fork SSL? Whatever it wants!
Canada immigration website goes down as Donald Trump gains lead

LinuxSecurity.com: An update for flash-plugin is now available for Red Hat Enterprise Linux 5 Supplementary and Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

Finns chilling as DDoS knocks out building control system
Microsoft has patched the zero-day security hole disclosed by Google
Update now! Bug means large PAC files can crash Android phones
Computer glitches force US election poll stations to stay open for longer
Judge throws out Trump lawyer’s demand for poll worker info – because it’ll feed Twitter trolls
TrickBot Banking Trojan Adds New Browser Manipulation Tools
The big day is here and it’s time to decide: Patch Flash, Windows, Office or Android first?

security update

security update

Microsoft Patches Zero Day Disclosed by Google
Google Releases Supplemental Patch for Dirty Cow Vulnerability

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 8.0 (Liberty). Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 9.0 (Mitaka). Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Security Report Summary

Adobe fixes flaws in Flash Player and Adobe Connect
Hacker used password resets to break into 1,050 university email accounts
Adobe Patches Nine Code Execution Flaws in Flash Player
Android’s security update for November 2016 – good news and bad moos
SpamTorte botnet gets turbo-charged
Android patches fix Drammer RAM attack, but not Dirty Cow exploit
DDoS Attacks on Apartments’ Heating System Left Residents Cold and Angry
Hackers Leak Crucial Data From 7 Indian Missions
Definitely not another Stuxnet, researchers claim as they demo industrial control rootkit
Secure your router: How to help prevent the next internet takedown

Secure your router, says ESET’s Lysa Myers. It can help protect all of your connected devices while they are in your home. The post Secure your router: How to help prevent the next internet takedown appeared first on WeLiveSecurity.

Insecure IoT gear can help hackers turn your phone into a GPS tracker
Microsoft to shield world chess champion from Russian hackers
VASCO white paper: Why RASP technology is critical for modern app security
Who needs a Stingray when Wi-Fi can do the job?
No, you still don’t need an RFID-blocking wallet
<div>No, you still don't need an RFID-blocking wallet</div>

Back in January, I wrote one of my most popular posts ever: “Why you don’t need an RFID-blocking wallet.” As the title suggests, I argued that it’s a waste of money to buy a wallet with special shielding to protect your chipped credit card from RFID scanners wielded by street criminals seeking to snatch your […]

Targeted online guessing ‘a major threat to online security’

Targeted online guessing represents a major threat to online security, according to new research. The post Targeted online guessing ‘a major threat to online security’ appeared first on WeLiveSecurity.

LinuxSecurity.com: An update for pacemaker is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

‘Trust it’: Results of Signal’s first formal crypto analysis are in
Google to patch Chrome mobile hole after bank trojan hits 318k users
Netflix flattens bug that allowed account p0wnage via voicemail
Turn off remote admin, SOHOpeless D-Link owners
Ransomware repulsion regimes revealed!
Android’s Hover feature is a data HOOVER

Risk Level: Very Low. Type: Trojan.

China passes new Cybersecurity Law – you have seven months to comply if you wanna do biz in Middle Kingdom
Carriers are going virtual to give enterprises more freedom
Chinese chap in the clink for trying to swap US Navy FPGAs with fakes to beat export ban
Risk of Election Day Cyberattacks Low According To Experts
Tesco Bank Stops Online Transactions After Money Missing from 20K Accounts
Beware; LinkedIn Users Hit with Sophisticated Phishing Campaign
Microsoft Tears off the Band-Aid with EMET

LinuxSecurity.com: Add patch to fix dnf module groupinstall handling —- Update to new ansible2.2 version. For full changes see:https://github.com/ansible/ansible/blob/stable-2.2/CHANGELOG.md

LinuxSecurity.com: This update fixes a rare ocasion where ghostscript would fail when displaying*.ps files. More info can be found[here](http://bugs.ghostscript.com/show_bug.cgi?id=697286). —- This is asecurity update for these CVEs: *[CVE-2016-8602](https://bugzilla.redhat.com/show_bug.cgi?id=1383940) – *checkfor sufficient params in .sethalftone5* *[CVE-2016-7977](https://bugzilla.redhat.com/show_bug.cgi?id=1380415) – *.libfiledoes not honor -dSAFER* [This CVE is now correctly fixed, previous release wasaccidentally missing the fix.]

LinuxSecurity.com: The 4.8.6 stable update contains a number of important fixes across the tree.

LinuxSecurity.com: Security fix for CVE-2016-6293

LinuxSecurity.com: October 2016 CPU fixes: http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html#AppendixJAVA

LinuxSecurity.com: – new upstream version (49.0.2)

LinuxSecurity.com: Bump version to 1.3.5.15-1

LinuxSecurity.com: Security fix for CVE-2016-7035 (improper IPC guarding)

LinuxSecurity.com: – fix cookie injection for other servers (CVE-2016-8615) – compare user/passwdcase-sensitively while reusing connections (CVE-2016-8616) – base64: check forinteger overflow on large input (CVE-2016-8617) – fix double-free in krb5 code(CVE-2016-8619) – fix double-free in curl_maprintf() (CVE-2016-8618) – fix globparser write/read out of bounds (CVE-2016-8620) – fix out-of-bounds read incurl_getdate() (CVE-2016-8621) – fix URL unescape […]

Clever Gmail Hack Let Attackers Take Over Accounts
Worried about the Tesco Bank attack? Here’s our advice
Tor marketplaces shut down by Operation Hyperion
U.K. bank suspends online payments after fraud hits 20,000 accounts
Cisco’s Mobile Careers Site Exposed Job Seekers Data
Web security still outstandingly mediocre, experts report
Applied for a job at Cisco? Your personal data and passwords could have been stolen
Need to review 650,000 emails in eight days? Easy with a computer
WikiLeaks Releases DNCLeak2; Suffers Massive DDoS Attack
Oil exec accused of impersonating Elon Musk in an email sues Tesla over Twitter hack
How to do an APK Analysis Using AppMon

There are a great many tools available to help quickly analyze the behavior of mobile malware samples. In the case of Android, one such app is AppMon. The post How to do an APK Analysis Using AppMon appeared first on WeLiveSecurity.

Ukrainian hackers ‘snatch huge email cache from Kremlin’
Boffins turn phone into tracker by abusing pairing with – that’s right – IoT kit
Monday review – the hot 17 stories of the week
Tesco Bank limits online transactions after fraud hits thousands
Microsoft EMET gets end-of-life reprieve
20,000 Tesco Bank accounts raided by hackers, money stolen

LinuxSecurity.com: An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for java-1.6.0-ibm is now available for Red Hat Enterprise Linux 5 Supplementary and Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]