Menu

Monthly Archives: February 2017

Amazon Web Services suffer massive outage taking popular sites down
Google Discloses Critical Existing Bug in Internet Explorer and Edge
Siemens RUGGEDCOM NMS Equipment Vulnerable to CSRF, XSS

LinuxSecurity.com: cirrus_bitblt_cputovideo does not check if memory region is safe [XSA-209,CVE-2017-2620] (#1425420)

LinuxSecurity.com: This update rebases RPM to the official 4.13.0.1 release(http://rpm.org/wiki/Releases/4.13.0.1) which includes several importantsecurity and regression fixes.

Data and kids’ voice messages exposed in CloudPets breach

LinuxSecurity.com: New release (1.10a). Security fix for CVE-2016-6265

LinuxSecurity.com: Security fix for CVE-2017-2616

LinuxSecurity.com: Security fix for CVE-2016-6265

LinuxSecurity.com: Security fix for CVE-2016-8745

Dridex Trojan Gets A Major ‘AtomBombing’ Update
Security slip-ups in 1Password and other password managers ‘extremely worrying’
‘Filecode’ ransomware attacks your Mac – how to recover for free
IDG Contributor Network: The dangers of the public internet
News in brief: moon tourists to launch ‘next year’; health provider fined after breach; drone pilot jailed
Unpatched SMB Zero Day Easily Exploitable
Stuffed Toys manufacturer hacked; millions of accounts and voice messages stolen
Children’s Voice Messages Leaked in CloudPets Database Breach
MWC: Completely superfluous ‘AI’ added to consumer items
Judge denies blanket right to compel fingerprint iPhone unlocking
Torvalds Downplays SHA-1 Threat to Git
Our TV Viewing Habits Can Be Monitored for the Benefit of Marketers
Fears over net neutrality as FCC rules on disclosure eased
10 reasons why cybercriminals target smartphones

There is a real feeling that smartphones are becoming a bigger target for cybercriminals. So why are they so eager to get into our devices? The post 10 reasons why cybercriminals target smartphones appeared first on WeLiveSecurity

Over 800,000 user account details stolen from vulnerable forums running vBulletin
Health firm gets £200k slap after IVF patients’ data leaks online
Will a cyber crisis add to chaos of Trump’s first 100 days?
This tiny chip could revolutionize smartphone and IoT security
Carders capitalize on Cloudflare problems, claim 150 million logins for sale
Google End-to-End encrypted email code goes open-source
Red alert! Beware of insiders bearing APTs

We live in a global society. While your country’s economy may be stagnating or barely growing, someone else’s economy is probably booming. It’s no wonder your company is reaching across international borders to establish new business ties and revenue sources. That’s all well and good. But you should also know that I’ve consulted for a […]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5.9 Long Life. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5.6 Long Life. Red Hat Product Security has rated this update as having a security impact [More…]

MWC: BlackBerry misses a chance to tell a compelling security story
Germany, France lobby hard for terror-busting encryption backdoors – Europe seems to agree

LinuxSecurity.com: An update for java-1.7.0-ibm is now available for Red Hat Enterprise Linux 5 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 6 Supplementary and Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for java-1.6.0-ibm is now available for Red Hat Enterprise Linux 5 Supplementary and Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

Two million recordings of families imperiled by cloud-connected toys’ crappy MongoDB
ESET antivirus cracks opens Apple Macs to remote root execution via man-in-middle diddle
Microsoft slaps Apple Gatekeeper-like controls on Windows 10: Install only apps from store
Apple’s macOS is the safer choice – but not for the reason you think
Google Chrome 56’s crypto tweak ‘borked thousands of computers’ using Blue Coat security
Personalized spam campaign targets Germany with password-stealing malware
The highly-specific spammers using breached personal information are at it againRead More
Boeing Notifies 36,000 Employees Following Breach

security update

126 vBulletin forums hacked; 819,977 accounts leaked on hacking forums

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 9.0 (Mitaka). Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 8.0 (Liberty). Red Hat Product Security has rated this update as having a security impact [More…]

News in brief: D-Link vulnerabilities; SHA-1 woe; MySQL hacks
Google Discloses Another ‘High Severity’ Microsoft Bug
New Phishing Scam Targets Digital Payment and Online Banking Users

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: This update prevents `python-cjson` from crashing when attempting to parseheavily nested JSON structures (which could be exploited for denial of servicepurposes, against any application that uses `python-cjson` to parse arbitraryinput).

LinuxSecurity.com: memory leak when destroying guest without PT devices [XSA-207] (#1422492) updatepatches for XSA-208 after upstream revision (no functional change) —- Qemu:net: mcf_fec: infinite loop while receiving data in mcf_fec_receive[CVE-2016-9776] Qemu: audio: memory leakage in ac97 [CVE-2017-5525] (#1414111)Qemu: audio: memory leakage in es1370 device [CVE-2017-5526] (#1414211) oobaccess in cirrus bitblt copy [XSA-208, CVE-2017-2615] (#1418243)

LinuxSecurity.com: This update prevents `python-cjson` from crashing when attempting to parseheavily nested JSON structures (which could be exploited for denial of servicepurposes, against any application that uses `python-cjson` to parse arbitraryinput).

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Fix for CVE-2017-5495

LinuxSecurity.com: Security fix for CVE-2017-2616

LinuxSecurity.com: Update to 0.7.10

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.6 Advanced Update Support and Red Hat Enterprise Linux 6.6 Telco Extended Update Support. [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

Cloudbleed’s silver lining: the response system worked
Evolved Version of MongoDB Ransomware Caught Targeting MySQL Databases
Katie Moussouris on Bug Bounty Programs, Hack the Army, and Wassenaar
Attackers using cracked builder to duplicate and spread Betabot
NHS patient letters meant for GPs went undelivered for years
Wikipedia’s bot-on-bot battles that can last for years
Google Releases E2EMail to Open Source
IT admin was authorized to trash employer’s network he says
DNS attacks: How they try to direct you to fake pages

ESET’s Josep Albors looks at how DNS attacks will try and direct you to fake pages. The post DNS attacks: How they try to direct you to fake pages appeared first on WeLiveSecurity

New prison law will let mobile networks deploy IMSI catchers
Necurs Botnet Learns New DDoS Trick
Monday review – the hot 30 stories of the week
What IT must do now that Cloudflare leaked user data
Don’t panic about SHA-1—fix it
D-Link resolves enterprise switch hacker risk
Google’s Project Zero reveals another Microsoft flaw
Git fscked by SHA-1 collision? Not so fast, says Linus Torvalds

security update

Movie night? Nope. It’s a fake iTunes receipt from phishers targeting Apple users
Saudi-Iran: Proxy Wars Escalate To Direct Cyber Attacks

security update

Change.org sends password reset email after CloudBleed bug

security update

Cellebrite Can Now Unlock, Extract Data From iPhone 6 and 6 Plus
Was Your Google Account Unexpectedly Signed Out Today? Company Explains Why
Netflix Debuts ‘Stethoscope’ Open-Source Security Tool
Malware Lets a Drone Steal Data by Watching a Computer’s Blinking LED
UK cops can keep millions of mugshots of innocent folks on file
NSA snoops told: Get your checkbooks and pens ready for a cyber-weapon shopping spree
Don’t worry about Privacy Shield, it’s fine. Really. I promise, says US trade watchdog head
Researchers Uncover New Leads Behind Shamoon2