Menu

Monthly Archives: January 2017

LinuxSecurity.com: Update to the latest stable version. See https://ikiwiki.info/news/ for the listof changes. Security fix for CVE-2016-10026, CVE-2016-9646, CVE-2017-0356.

LinuxSecurity.com: Fix validation logic in the base consumer The base consumer is intended to onlyderive its validation switch from the on-disk configuration if the child classdoesn’t override the validate_signatures switch. There was a bug here where thedefault value provided in the base class made it appear as if *all* childconsumers had turned *off* validation, which […]

LinuxSecurity.com: Update to the latest stable version. See https://ikiwiki.info/news/ for the listof changes. Security fix for CVE-2016-10026, CVE-2016-9646, CVE-2017-0356.

LinuxSecurity.com: New mozilla-thunderbird packages are available for Slackware 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for puppet-swift is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Security Report Summary

Facebook Launches “Security Key” Feature to Protect User Accounts
Cisco Warns of Critical Flaw in Teleconferencing Gear
VPN on Android means ‘Voyeuristic Peeper Network’ in many cases

security update

Wow, look out, hackers: Trump to order 60-day cybersecurity probe
WordPress 4.7.2 Update Fixes XSS, SQL Injection Bugs
OpenSSL issues new patches as Heartbleed still lurks
LeakedSource data breach website goes offline following alleged police raid
Dridex Returns With Windows UAC Bypass Method

Major Dark Web Marketplace Hacked Recently, a hacker using the alias cypher0007 reached out to AtlasBay, a large dark web market, with information on two significant vulnerabilities that allowed him to access over 200,000 private messages, names, and addresses. Along with retrieving a good amount of buyer and seller information, the hacker also revealed that […]

News in brief: Fancy Bear ‘attacked TV network’; Lavabit comes back to life; museum does geek history
Raise your glasses! Wine is 2.0!
Threatpost News Wrap, January 27, 2017
Google to Operate its Own Root CA
Texas cops lose evidence going back eight years in ransomware attack
National Audit Office: UK’s military is buying more than it can afford
Trump’s attorney-general choice wants to ‘overcome encryption’
Google launches root certificate authority
US and Russia engaged in legal tug of war over LinkedIn hack suspect
Pay for experts to rise as cybercrime ‘to cost $6tn a year by 2021’
That Hearbleed problem may be more pervasive than you think
Securing MySQL DBMS
Breach Notification Website LeakedSource Allegedly Raided, Shut Down
Smashing Security podcast #005: ‘Upskirt insecurity’
218,000 private unencrypted AlphaBay dark web messages exposed
Celebgate hacker who stole nude photos gets nine months in jail
An introduction to private browsing

Privacy and security fears are driving many people to look into the possibilities of private browsing. We investigate what it is and how you stay anonymous online The post An introduction to private browsing appeared first on WeLiveSecurity

Sednit: How this notorious cyberespionage group operates

Take a closer look at the cyberespionage group Sednit, which has targeted over 1000 high-profile individuals and organizations with phishing attacks and zero-day exploits. The post Sednit: How this notorious cyberespionage group operates appeared first on WeLiveSecurity

No, disabling your anti-virus software does not make security sense
Trump administration is giving us a good lesson on Twitter security
Data Privacy Day: know the risks of Amazon Alexa and Google Home
Facebook taps FIDO U2F for stronger login security
Worrying about data privacy isn’t enough: Here’s how to own your online presence

ESET’s Ondrej Kubovič: “Worrying about privacy isn’t enough” – here’s how to control your data privacy and online presence. The post Worrying about data privacy isn’t enough: Here’s how to own your online presence appeared first on WeLiveSecurity

PayPal users targeted in sophisticated new phishing campaign

Recent phishing scams targeted both Gmail and Yahoo, and now attackers have their sights set on PayPal with some very convincing bait. The post PayPal users targeted in sophisticated new phishing campaign appeared first on WeLiveSecurity

LeakedSource website goes dark amid claims of police raid
Bookish hacker finds holes in Amazon, Apple, Google epub services
Uber pays hacker US$9,000 for partner firm’s bug
Former Mozilla dev joins chorus roasting antivirus, says ‘It’s poison!’
Americans fear their data isn’t safe, yet do little to defend it
The security of President Trump’s Android smartphone
Malicious “Charger Ransomware” App Discovered on Google Play Store
Trump signs ‘no privacy for non-Americans’ order – what does that mean for rest of us?

security update

More mobe malware creeps into Google Play – this time, ransomware
Your Facebook account is now more secure than your bank’s (probably)
Facebook Touts ‘Safer’ Security Key Login
Machine behaviors that threaten enterprise security
Bill Calls for Study of Cybersecurity Standards for Cars

LinuxSecurity.com: An update for ansible is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: – new upstream (51.0)

LinuxSecurity.com: * CVE-2016-6836: vmxnet: Information leakage in vmxnet3_complete_packet (bz#1366370) * CVE-2016-7909: pcnet: Infinite loop in pcnet_rdra_addr (bz #1381196)* CVE-2016-7994: virtio-gpu: memory leak in resource_create_2d (bz #1382667) *CVE-2016-8577: 9pfs: host memory leakage in v9fs_read (bz #1383286) *CVE-2016-8578: 9pfs: potential NULL dereferencein 9pfs routines (bz #1383292) *CVE-2016-8668: OOB buffer access in rocker switch emulation (bz #1384898) *CVE-2016-8669: […]

LinuxSecurity.com: Update to ansible 2.2.1. Fixes several CVEs as well as a number of otherbugfixes. See: https://github.com/ansible/ansible/blob/stable-2.2/CHANGELOG.mdfor full changes.

LinuxSecurity.com: Update to ansible 2.2.1. Fixes several CVEs as well as a number of otherbugfixes. See: https://github.com/ansible/ansible/blob/stable-2.2/CHANGELOG.mdfor full changes.

Clock’s ticking for MD5-signed JAR files, says Oracle
Firefox flags Web of Trust add-on as suspicious, blocks by default
News in brief: real Q is a woman; Trump ‘still using Android phone’; Apple to join AI group
Voyeur adult website hacked; 180k members data leaked
Uber.com Backup Bug Nets Researcher $9K
How one man could have deleted any public Facebook video
Raspberry Pi to get a boost in brain power thanks to Google’s AI tools
Google to Block .js Attachments in Gmail
President Trump tweets from insecure Android, security boffins roll eyes
High-Severity Chrome Vulnerabilities Earn Researcher $32K in Rewards
Dark Web’ Largest Trading Platform AlphaBay Hacked; 200k Messages Leaked
Desperately seeking cybersecurity skills

Cybercrime is victimizing US companies and consumers, but a gap in cybersecurity skills presents a problem for the federal government. ESET’s Stephen Cobb investigates. The post Desperately seeking cybersecurity skills appeared first on WeLiveSecurity

In a bad mood? You might not be allowed to log on
10 questions to ask IDaaS vendors before you buy
In real life, Q is a woman! Head of MI6 calls for more female techies at SIS
Half of Ransomware Victims Pay Criminals’ Demands to Recover Data
Google pressure on devs to fix security issues bears fruit
Firefox 51 delivers a mix of security, performance and reliability tweaks, implements FLAC audio sup
Self-protection is key to Linux kernel security

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

Disk-nuking malware takes out Saudi Arabian gear. Yeah, wipe that smirk off your face, Iran
‘Celebgate’ nudes thief gets just nine months of porridge
Get 72% off NordVPN Virtual Private Network Service For a Limited Time – Deal Alert
Cisco WebEx code execution hole – what you need to know
HummingWhale Malware infected Android Apps Downloaded Millions of Times
Trump lieutenants ‘use private email’ for govt work… but who’d make a big deal out of that?
Hacker Selling 126 Million Cell Phone Details of “U.S. Cellular” Customers
Shamoon malware revisiting Saudi Arabia; cyberinfrastructure on high alert
Default Credentials Found in Schneider Electric Wonderware Historian
Firefox 51 Begins Warning Users of Insecure HTTP Connections
Linux nasty kicks weak, hacked gadgets when they’re already down
News in brief: 1984 tops bestseller charts; Alexa pleases Trekkies; HP extends battery recall
Penguins force-fed root: Cruel security flaw found in systemd v228
Kaspersky cybercrime investigator cuffed in Russian treason probe

To address the need for application security in the digital transformation era, F5 is releasing a new host of products and services. “The digital transformation has really changed security as a whole,” says Preston Hogue, Director of Security Marketing and Competitive Intelligence. What he means is that everything—EVERYTHING—is moving to the cloud. Think about the […]

Court rejects US government appeal in case of Microsoft overseas email
Lloyds Banking Group hit with distributed denial of service attack

Lloyds Banking Group fell victim to an attempted cyberattack earlier this month, which saw cybercriminals attempt to crash the online banking service over a two day period. The post Lloyds Banking Group hit with distributed denial of service attack appeared first on WeLiveSecurity

Verizon’s $4.8bn acquisition of Yahoo put on hold after breach revelations
China clamps down tighter on web use with new VPN ban