Menu

Monthly Archives: February 2017

RSA Conference preview: The agenda can’t keep up
Despite the spiel, we’re still some decades from true anti-malware AI

LinuxSecurity.com: An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

That guy using a Surface you keep seeing around town could be a spook

Risk Level: Very Low. Type: Trojan.

Ex-FBI man spills on why hackers are winning the security game

LinuxSecurity.com: New openssl packages are available for Slackware 14.2 and -current to fix security issues. [More Info…]

LinuxSecurity.com: New bind packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue. [More Info…]

LinuxSecurity.com: New tcpdump packages are available for Slackware 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. NOTE: These updates also require the updated libpcap package. [More Info…]

LinuxSecurity.com: New php packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: Multiple vulnerabilities have been found in Graphviz and the extent of these vulnerabilities are unspecified.

LinuxSecurity.com: A vulnerability in Lsyncd allows execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in GnuTLS, the worst of which may allow execution of arbitrary code.

New Ticketbleed Vulnerability Bleeds Like Old Heartbleed.. Literally
Gmail’s Spam Filter Not Impenetrable For Hackers
Bugat-wielding hacker: Yes, I tried to nick $3.2m from US schools, oil biz
Lovely. Now someone’s ported IoT-menacing Mirai to Windows boxes
25% off Kuna Smart Home Security Outdoor Light & Camera – Deal Alert

security update

Run this in April: UPDATE Azure SET SQLthreat_detection = ‘generally available’
Tor and Its 10 Best Alternatives
IDG Contributor Network: Why executive orders aren’t enough to fix cybersecurity
News in brief: Big Brother in India; hacking warning to journalists; WordPress sites hit
Microsoft unveils a bonanza of security capabilities
Deleted browsing history on safari may not actually be deleted

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Minor upstream release fixing CVE-2016-8610, CVE-2017-3731, CVE-2017-3732.

LinuxSecurity.com: Important change: * most of the utilities were move to the new sub-package”server-utils” Other enhancements: (see changelog) * CVE fixes, SPECfilefixes, patches revision, tests blacklist revisions * Preparation and testing ofthe Cracklib plugin to be added

LinuxSecurity.com: Add upstream patches fixing CVE-2016-9577 and CVE-2016-9578

LinuxSecurity.com: gnome-boxes 3.20.4 release, fixing a possible security issue with storing theexpress installation password in clear text. – Store the user password in thekeyring during an express installation. – Fix typo in debug string. – Fix printfformat strings.

LinuxSecurity.com: Version 1.1.26 (released 24-Jan-2017) * security fix: escape nav_data name toavoid XSS attack Version 1.1.25 (released 15-Sep-2016) * fix _rev2optrevassertion on long input

Recent WordPress vulnerability used to deface 1.5 million pages
How would you feel about your kids’ teachers wearing a body camera?
No replacement yet named for White House chief infosec officer
Protecting Small Business from Increasing Cyber Attacks
1.5M Unpatched WordPress Sites Hacked Following Vulnerability Disclosure
How to better protect your WhatsApp account with two-step verification (2SV)
NSA contractor charged with stealing thousands of top-secret documents
Apple iCloud didn’t wipe ‘deleted’ browser histories for over a year
Scammers slip fake Amazon ad under Google’s nose

Macros Turn Focus Towards MacOS Researchers have discovered a trend of malicious Microsoft Word documents for MacOS that behave similar to Windows macro infections. The culprits download and execute a malicious payload to a user’s computer. While not particularly sophisticated, the macro-based infections focus on exploiting the users of the computer, rather than a software […]

Crossing border security? Here’s how you protect your data
Apple’s iCloud saved deleted browser records, security company finds
Microsoft lawsuit against indefinite gag orders can proceed
RSA Conference 2017: your chance to get to grips with ransomware
Arby’s Gets Roasted in Breach of 300K Payment Cards
Google set to purge Play store of apps lacking a privacy policy
Caution! The cloud’s backdoor is your datacenter

LinuxSecurity.com: Update to 2.1

LinuxSecurity.com: January 2017 security fixes – http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html#AppendixJAVA

LinuxSecurity.com: Security fix for CVE-2017-5884, CVE-2017-5885

LinuxSecurity.com: * various security relevant flaws

After Linux; Mirai Botnet is Available for Windows

LinuxSecurity.com: January 2017 security fixes – http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html#AppendixJAVA

Scottish court issues damages to couple over distress caused by neighbour’s use of CCTV
Explained: Apple iCloud kept ‘deleted’ browser histories for over a year
Russian Authorities Arrest Nine for Stealing $17 Million from Banks
Trump cybersecurity order morphs into 2,200-plus-word extravaganza

security update

security update

Clusters f**ked: Insecure Hadoop file systems wiped by miscreants

LinuxSecurity.com: Several security issues were fixed in the kernel.

Macs don’t get viruses? Hahaha, ha… seriously though, that Word doc could be malware
High Severity BIND Vulnerability Can Lead to A Crash

LinuxSecurity.com: Security Report Summary

InterContinental Hotels Group confirms suspected data breach

The InterContinental Hotels Group has revealed that 12 of its hotels suffered a data breach between August and December last year. The post InterContinental Hotels Group confirms suspected data breach appeared first on WeLiveSecurity

News in brief: Yahoo faced with suit; dev hits back at support scammers; Note 7 batteries flare up
Smashing Security podcast #007: ‘ASCII art attack’
Tried-and-true Triada supplants Hummingbad as top mobile malware
CryptoShield Infections from RIG EK Picking Up
If you’re attending BSidesSF, expect to see a lot of Mr Robot
Life after antivirus: Reinventing endpoint security
Google’s neural networks turn pixelated faces back into real ones
Dino Dai Zovi on Securing Linux in Modern Workloads
Consortium Publishes Manifesto on Autonomous Vehicle Security
How to create a robust data backup plan (and make sure it works)
Twitter says it’s taking steps to make its users safer
French man sues Uber after privacy bug led wife to suspect adultery
Sean Spicer’s WHOIS data is revealing his personal details
Cardiff researchers get £250k to monitor Brexit hate crime on Twitter
US could demand social media passwords of visa applicants
Anti-piracy software developer leaves website open to snoops
How to Manage the Security Vulnerabilities of Your Open Source Product
The Android Wear 2.0 terror and other fake news
USMC: We want more F-35s per year than you Limeys will get in half a decade

LinuxSecurity.com: Security Report Summary

Is GDPR good or bad news for business?

The General Data Protection Regulation (GDPR), the biggest reform of privacy legislation for 20 years, will come into effect on May 25, 2018, bringing with it major changes to Europe’s privacy laws. The post Is GDPR good or bad news for business? appeared first on WeLiveSecurity

LinuxSecurity.com: An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 6 Supplementary and Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

Mag publisher Future stored your FileSilo passwords in plaintext. Then hackers hit
F5’s Big-IP leaks little chunks of memory, even SSL session IDs

LinuxSecurity.com: Several security issues were fixed in OpenJDK 7.

security update

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: Upstream 3.2.7 (important security fix)

LinuxSecurity.com: Version 1.1.26 (released 24-Jan-2017) * security fix: escape nav_data name toavoid XSS attack Version 1.1.25 (released 15-Sep-2016) * fix _rev2optrevassertion on long input