Menu

Monthly Archives: December 2016

LinuxSecurity.com: Security fix for CVE-2016-2125, CVE-2016-2126

LinuxSecurity.com: ### Botan 1.10.14 ### * NOTE WELL: Botan 1.10.x is supported for securitypatches only until 2017-12-31 * Fix integer overflow during BER decoding, foundby Falko Strenzke. This bug is not thought to be directly exploitable butupgrading ASAP is advised. (CVE-2016-9132) * Fix two cases where (in errorsituations) an exception would be thrown from a […]

  As 2016 comes to a close, it’s time to reflect back on the largest/most significant security news stories that left an impact on the world. Mirai Botnet Being hailed as the largest attack of its kind in history, the DDoS attack launched by the Mirai botnet encompassed over 100,000 unique endpoints and hit a […]

Nook 7 tablet updated to neutralise ADUPS fear, says Barnes & Noble
News in brief: Snowden denies allegations; Uber moves to Arizona; Wikipedia reveals most edited page
Cisco Warns of Critical Flaw in CloudCenter Orchestrator Systems
Netgear plays down router security flaw
Group that attacked Tumblr threatens to DDoS Xbox for Christmas
Encryption backdoors are ‘against the national interest’
Apple gives iOS app developers more time to encrypt communications
Apple Delays App Transport Security Deadline
Customers reporting their Groupon accounts are being hacked
Vice is the latest site to call it a day on comments
US healthcare under siege: Got good insurance?
Free cybersecurity tools for all your needs

LinuxSecurity.com: The 4.8.15 stable kernel update contains a number of important fixes across thetree.

LinuxSecurity.com: x86 CMPXCHG8B emulation fails to ignore operand size override [XSA-200,CVE-2016-9932] (#1404262) —- ARM guests may induce host asynchronous abort[XSA-201, CVE-2016-9815, CVE-2016-9816, CVE-2016-9817, CVE-2016-9818] (#1399747)qemu: Divide by zero vulnerability in cirrus_do_copy (#1399055) [CVE-2016-9921,CVE-2016-9922] Qemu: 9pfs: memory leakage via proxy/handle callbacks (#1402278)qemu ioport array overflow [XSA-199, CVE-2016-9637]

LinuxSecurity.com: The 4.8.15 stable kernel update contains a number of important fixes across thetree.

Apple drops requirement for apps to use HTTPS by 2017
Sneaky chat app Signal deploys decoy domains to deny despots
Passwords, patches and backup – three easy tips in our Facebook Live video
Inflight Entertainment Service Provider Gogo Launches Bug Bounty Program
Bad news: Exim hole was going to be patched on Xmas Day. Good news: Keyword ‘was’
Sing a song of ransomware…
News in brief: Groupon grief; Apple encryption delay; post-quantum crypto
Smashing Security #001: ‘One cup, two hotel guests’
Fancy Bear used Android malware to track Ukrainian artillery
Data Breach: Anonymous hacks Thai Navy, Ministry of Foreign Affairs
NIST Calls for Submissions to Secure Data Against Quantum Computing
Siemens Patches Insufficient Entropy Vulnerability in ICS Systems

Risk Level: Very Low. Type: Trojan.

‘DNC hackers’ used mobile malware to track Ukrainian artillery – researchers
Pow! Captain America and other Marvel heroes defeated by bad passwords
Once again, you can decrypt your CryptXXX ransomware files for free
Groupon frauds blamed on third-party password breaches
Government’s “general and indiscriminate” data collection ruled unlawful
AT&T takes aim at scam callers
Hackers Suspected of Causing Second Power Outage in Ukraine
Congressional Group Says Encryption Backdoors Are a Bad Idea
OurMine hijacks Netflix’s US Twitter account

Netflix has become the latest big name brand to have one of its social media accounts hijacked by OurMine. The post OurMine hijacks Netflix’s US Twitter account appeared first on WeLiveSecurity

Instant Verification lets mobile users authenticate themselves without an SMS
NIST requests ideas for crypto that can survive quantum computers

LinuxSecurity.com: Security fix for CVE-2016-9036, CVE-2016-9037

LinuxSecurity.com: Security fix for CVE-2016-9036, CVE-2016-9037

LinuxSecurity.com: – Fixed crash in auth process when auth-policy was configured and authenticationwas aborted/failed without a username set. – director: If two users haddifferent tags but the same hash, the users may have been redirected to thewrong tag’s hosts. – Index files may have been thought incorrectly lost, causing”Missing middle file seq=..” to be logged […]

LinuxSecurity.com: Security fix for CVE-2016-9036, CVE-2016-9037

LinuxSecurity.com: Security fix for CVE-2016-9036, CVE-2016-9037

Risk Level: Very Low. Type: Trojan, Worm.

OurMine hackers hack Marvel and Netflix Twitter accounts
Don’t pay up to decrypt – cure found for CryptXXX ransomware, again

security update

security update

security update

Our 12 tips for staying safe online this Christmas
News in brief: crackdown on drones; Egypt blocks Signal; Nook 7 warning
New Wave of Hailstorm Spam Pelts Inboxes

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: The system could be made to expose sensitive information.

LinuxSecurity.com: The system could be made to expose sensitive information.

Student makes documentary after spying on thief who stole his smartphone

Risk Level: Very Low. Type: Trojan.

VMware removes hard-coded root access key from vSphere Data Protection
Nmap security scanner gets new scripts, performance boosts
Netflix US Twitter account hacked
Meet Jarvis – Zuck’s new AI assistant
Beware: Android Super Mario Run is Actually Malware; Don’t Download It
Smile! You’re on a stolen iPhone’s candid camera!

  Did we get you to click? That’s how the bad guys get you, too. One little click on the wrong link and your clients’ businesses could be up the proverbial creek. Theft only comprises one aspect of the activities cybercriminals undertake, but it’s a sizeable chunk of their enterprise. What’s worth noting is what […]

How a hacked phone number cost Jered Kenna millions in bitcoins
Panasonic, IOActive Clash on Vulnerability Report
Tech companies like Privacy Shield but worry about legal challenges
Congressional report sides with Apple on encryption debate
Porn block on new PCs to ‘fight trafficking’ – unless you pay $20
Home routers under attack in ongoing malvertisement blitz
Op-ed: Why I’m not giving up on PGP
IDG Editors predict tech trends for 2017
Energy firm points to hackers after Kiev power outage
What is cyberbullying and how to defend against it?

Cyberbullying has come to be a huge problem on the internet. Here are some important things to be aware of. The post What is cyberbullying and how to defend against it? appeared first on WeLiveSecurity

LinuxSecurity.com: An update for gstreamer-plugins-good is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for gstreamer-plugins-bad-free is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

Facebook has stopped SHA-ring, a year later than it promised
Strong non-backdoored encryption is vital – but the Feds should totally be able to crack it, say House committees

LinuxSecurity.com: An update for vim is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

Wassenaar weapons pact talks collapse leaving software exploit exports in limbo

Risk Level: Very Low. Type: Trojan.

Pakistani hackers deface Google Bangladesh domain
China gives America its underwater drone back – with a warning
Year-end cybercrime update 2016: an avalanche of good news?

Highlighting 20 success stories in the struggle against cybercrime, from indictments to arrests, extraditions to sentencing. Law enforcement efforts in cyberspace may have borne more fruit in 2016 than in any other year. The post Year-end cybercrime update 2016: an avalanche of good news? appeared first on WeLiveSecurity

Wassenaar Renegotiation Will Be in Trump Administration’s Hands
Testing times: Can your crypto-code survive the Google gauntlet?
Anonymous Shut Down Thai Sites Against Internet Censorship, Surveillance Law

Type: Vulnerability. The Microsoft .NET Framework is prone to an information-disclosure vulnerability; fixes are available.

ShadowBrokers got NSA spy tools from rogue insider
Kingpin in $1m global bank malware ring gets five years in chokey