Menu

Monthly Archives: January 2017

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: This update addresses the following vulnerabilities: *[CVE-2016-7656](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7656),[CVE-2016-7635](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7635),[CVE-2016-7654](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7654),[CVE-2016-7639](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7639),[CVE-2016-7645](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7645),[CVE-2016-7652](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7652),[CVE-2016-7641](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7641),[CVE-2016-7632](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7632),[CVE-2016-7599](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7599),[CVE-2016-7592](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7592),[CVE-2016-7589](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7589),[CVE-2016-7623](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7623),[CVE-2016-7586](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7586)Additional fixes: * Create GLX OpenGL contexts using version 3.2 (core profile)when available to reduce the memory consumption on Mesa based drivers. * Improvememory pressure handler to reduce the CPU usage on memory pressure situations. *Fix a regression in WebKitWebView title notify signal emission that caused thesignal to […]

Heartbleed is not dead. And isn’t likely to be any time soon
Sage and Satan Ransomware, Double Trouble
Bug allowed attackers to delete ANY Facebook video they chose
Head of GCHQ Robert Hannigan steps down for ‘personal reasons’
DuckDuckGo Search Engine Hits a Milestone with 14 Million Searches a Day
Lloyds Bank outage: DDoS is prime suspect
Massive Twitter Botnet Dormant Since 2013
St Jude case highlights ongoing divide over ‘responsible bugs disclosure’
Israeli soldiers duped into installing malware via fake Facebook profiles
BBC, NYT Twitter accounts hacked; posts fake news about Trump and Putin
Twitter hack sees New York Times warn of Russian missile strike against USA
Monday review – the hot 31 stories of the week
Protected US military server poked via army recruitment website
It’s 2017 and 200,000 services still have unpatched Heartbleeds
Go dark with the flow: Lavabit lives again
Satan enters roll-your-own ransomware game
Symantec carpeted over dodgy certificates, again
Mozilla wants infosec activism to be the next green movement

LinuxSecurity.com: Multiple vulnerabilities have been found in zlib, the worst of which could allow attackers to cause a Denial of Service condition.

LinuxSecurity.com: Multiple vulnerabilities have been found in DirectFB, all of which could allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A buffer overflow in DCRaw might allow remote attackers to cause a Denial of Service condition.

LinuxSecurity.com: A buffer overflow in Lua might allow context-dependent attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in libupnp, the worst of which could lead to the execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in DBD::mysql, the worst of which might allow an attacker to execute arbitrary code.

LinuxSecurity.com: A buffer overflow in PPP might allow remote attackers to cause a Denial of Service condition.

LinuxSecurity.com: Multiple vulnerabilities have been found in QEMU, the worst of which could cause a Denial of Service condition.

Employment scam targets college students and their bank accounts

LinuxSecurity.com: check valid input arguments for nla_reserve() (rh #1414305, CVE-2017-0386)

security update

security update

security update

Radio Station Transmission Hacked with F*** Donald Trump Song
Researchers condemn unsubstantiated WhatsApp “Backdoor” story by Guardian
Mozilla’s First Internet Health Report Tackles Security, Privacy
India’s Famous Horse Racing Site Hacked with Dharma Ransomware
Protesters Called To Join Inauguration Day DDoS Attack
Rsync errors lead to data breach at Canadian ISP, KWIC Internet
Encrypted email service ProtonMail opens door for Tor users
7 (more) security TED Talks you can’t miss
350,000 Twitter bot sleeper cell betrayed by love of Star Wars and Windows Phone
Researcher claims to expose identity of Mirai Botnet Author
Coalition of Cryptographers, Researchers Urge Guardian to Retract WhatsApp Story

security update

Rap for crap WhatsApp trap flap: Yack yack app claptrap slapped
Hadoop, CouchDB Next Targets in Wave of Database Attacks
News in brief: Note 7 fire cause to be revealed; Trump gives up cellphone; Cortana moves on to Android lockscreen

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Multiple vulnerabilities have been found in cURL, the worst of which could allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in NSS, the worst of which could allow remote attackers to obtain access to private key information.

LinuxSecurity.com: Multiple vulnerabilities have been found in irssi, the worst of which could allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A heap-based buffer overflow in CVS might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in IcedTea allowing remote attackers to affect confidentiality, integrity, and availability through various vectors.

LinuxSecurity.com: An update for java-1.8.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 6 and Oracle Java for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

Hack the Army Bounty Pays Out $100,000; 118 Flaws Fixed
General Electrics plays down industrial control plant vulnerabilities
Ransomware attack hits St Louis Public library
Threatpost News Wrap, January 20, 2017
Trump’s ‘cyber tsar’ Giuliani among creds leaked in mass hacks
Protestors urged to try and swamp White House website
Google pushed developers to fix security flaws in 275,000 Android apps
Meitu app is all the rage, but privacy concerns abound
Email Encryption Service Provider ‘ProtonMail’ Now on Tor

MongoDB Hacks Spreading Fast In the past few weeks, researchers have been monitoring the steady rise of hacked MongoDB installations, now surpassing over 28,000 individual systems. While the attacks started with ransoming back the stolen data, the attackers have now begun simply deleting the information from the database and leaving the ransom note for payment […]

Alleged child molester caught after 18 years thanks to facial recognition
Attackers start wiping data from CouchDB and Hadoop databases
How to wake the enterprise from IoT security nightmares
Microsoft’s standing to sue over secret US data requests in question
School sues sysadmin for wiping its only login to Gmail
Fake news alert! Internet breaches are not cloud breaches
Unbreakable Locky ransomware is on the march again
Shocking crime surge – THE TRUTH: England, Wales stats now include hacking and fraud

LinuxSecurity.com: An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

Viral Chinese selfie app Meitu phones home with personal data
Operator of DDoS protection service named as Mirai author
Smashing Security #004: ‘You don’t mess with Brian Krebs’
Bring down the White House’s website for Trump’s inauguration, urges software engineer
What the end of Patch Tuesday means for businesses
The Changing Face of Carbanak
Google Maps Will Soon Find Parking Spot for You

LinuxSecurity.com: An update for openstack-cinder is now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for python-XStatic-jquery-ui is now available for Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Updated openstack-cinder packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7. [More…]

LinuxSecurity.com: An update for openstack-cinder is now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…]

ProtonMail Gets Own Tor-Accessible .Onion Hidden Service
Locky Limps Back into Action After Lull
The Mirai DDoS botnet: Brian Krebs claims to know who wrote it
The trouble with online porn: it’s impossible to block

Ransomware as a Service (RaaS) has been growing steadily since it made its debut in 2015 with Tox. With the new Satan service, it’s easier than ever. The idea is to use this web portal to contract threat actors to create new ransomware samples for distribution via the desired attack vector. This allows any potential […]

Cybersecurity skills shortage ‘still a global problem’

There are signs of improvement in the global cybersecurity skills gap, but serious problems still remain, a new report finds. The post Cybersecurity skills shortage ‘still a global problem’ appeared first on WeLiveSecurity

IS turns hobby drones into remote-control bombs
News in brief: Davos drones jammed; Nato warns of rising cyberattacks; computer fraud statistics revealed

Risk Level: Very Low. Type: Trojan.

Samsung SmartCam owners warned of hacker hijack vulnerability
Quimitchin Malware Targeting Mac Users also Compatible with Linux
‘Beeeellion-dollar’ mastercrooks in hotel, restaurant blitzkrieg
Facebook, Researcher at Odds Over Messenger Issue
Android Scoring System Roots Out Malicious, Harmful Apps