Menu

Monthly Archives: March 2017

LinuxSecurity.com: The 4.9.13 update contains a number of important fixes across the tree.

LinuxSecurity.com: WARNING: Please note that this update comes with a slightly different syntax ofsesman.ini file, so if you edited this file by hand, you may need to look at the.rpmnew file and merge any required changes by hand. This release also createsthree files in /etc/xrdp directory if they don’t already exist or are empty: -rsakeys.ini […]

Hundreds of Android Apps on Google Play Store Infected with Windows Malware
DDoS attack pummels Luxembourg state servers
How Threat Modeling Helps Discover Security Vulnerabilities

security update

Cisco Warns of High Severity Bug in NetFlow Appliance
WordPress Plugin NextGEN Gallery Vulnerable to SQL Injection Attack

Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability.

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.5 Advanced Update Support and Red Hat Enterprise Linux 6.5 Telco Extended Update Support. [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.2 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

132 Google Play Apps Booted For Malicious IFrames
News in brief: AI boost to video streaming; Mayer loses bonus; move to tackle comment trolls
Ransomware roundtable: Is this the new spam?
Cloudflare chief pledges third-party review of code
Keys for Dharma Ransomware Released
Cloudbleed Triggered 1.2M Times, Damage Kept to Minimum
Poor robot security could lead to ‘Skynet’ nightmare, warn researchers
Chrome for MacOS to block rogue ad injections and settings changes
Yahoo Tells SEC Executives Failed to Act on Breach
Android Password Manager You Trust Could be Exposing Login Data
We found a hidden backdoor in Chinese Internet of Things devices – researchers
FCC halts data security regulations for broadband providers
Why Internet of Things is the world’s greatest cyber security threat
Yahoo execs botched its response to 2014 breach, investigation finds
Google reCaptcha Bypass Technique Uses Google’s Own Tools
Twitter scrambles those anonymous account eggs
Smashing Security #010: The dolls must be destroyed
Famed Hacker Kevin Mitnick Shows You How to Go Invisible Online
Researchers find “severe” flaw in WordPress plugin with 1 million installs
Over a million websites could be at risk from critical WordPress gallery plugin flaw
Dark net webmail provider Sigaint still in the, er, dark
Major internet safety strategy to ‘bolster online safety’ for children in the UK

The UK is developing an internet safety strategy in an attempt to secure a position as “the safest place in the world for young people to go online”. The post Major internet safety strategy to ‘bolster online safety’ for children in the UK appeared first on WeLiveSecurity

Chatting with David Dufour, senior director of engineering, Webroot, is always interesting. Quite frankly, so is pinning him down for a short Q+A  about his experience at RSA 2017. One thing I could be sure of, though, was David having an opinion and being a straight shooter. As a first time attendee, I was curious […]

LinuxSecurity.com: Security Report Summary

Yahoo! dysfunction! meant! security! warnings! were! ignored!
Slack only took five hours to fix bug that could have allowed hackers to hijack your account

LinuxSecurity.com: Security Report Summary

Yahoo CEO Marissa Mayer will miss out on cash bonus after security breaches

security update

Come see me speaking at The Shard in London about security
Online shops plundered by bank card-stealing malware after bungling backend Aptos hacked
US-Europe Privacy Shield not worth the paper it’s printed on – civil liberties groups
Old Windows malware may have tampered with 132 Android apps
WordPress photo plugin opens ‘a million sites’ to SQLi database feasting
CloudPets Notifies California AG of Data Breach

security update

LinuxSecurity.com: The newest upstream commit, CVE-2017-6350 vim: Integer overflow at anunserialize_uep memory allocation site, CVE-2017-6349 vim: Integer overflow at au_read_undo memory allocation site

LinuxSecurity.com: fix CVE-2017-3156 (rhbz#1425455,1425458)

Slack Fixes Cross-Origin Token Theft Bug

LinuxSecurity.com: Security fix for CVE-2017-2586, CVE-2017-2587 and CVE-2017-5849, —- Addlicense information file copyright_summary —- New version of netpbm isavailable (10.77.00) —- add missing directives about bundled librariesjasper and jbigkit —- New version of netpbm is available (10.76.00)

LinuxSecurity.com: An update for openstack-puppet-modules is now available for Red Hat OpenStack Platform 8.0 (Liberty). Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for openstack-puppet-modules is now available for Red Hat OpenStack Platform 9.0 (Mitaka). Red Hat Product Security has rated this update as having a security impact [More…]

News in brief: AWS fail hits services; YouTube launches streaming service; Windows gets ‘walled garden’ option

LinuxSecurity.com: Security Report Summary

Unholy trinity of AKBuilder, Dyzap and Betabot used in new malware campaigns
Robots Rife With Cybersecurity Holes
Software engineer detained at JFK airport; forced to prove he is really an engineer
Is E2EMail a new beginning or the end for Google’s End-to-End?
Smart teddy bear maker faces scrutiny over data breach response
Infosec white-coats: Robots are riddled with software security bugs
Coachella festival website hacked; user data at risk
Vice News YouTube commenter set for retrial over ‘menacing’ posts
Speaking in Tech: A chat with Web 2.0 MySpace worm dude Samy Kamkar
Million-Plus WordPress Sites Exposed by Vulnerable Plugin
MWC: IoT security message drowned out by noise of nostalgia
Massive Bug May Have Leaked User Data From Millions of Sites. So … Change Your Passwords
Here’s Why Net Neutrality is Essential in Trump’s America
Google shifts on email encryption tool, leaving its fate unclear
Palo Alto Networks buys LightCyber for $105m
Talking Android ransomware extorts victims

Talking Android ransomware sounds like something out of a science fiction movie. It’s not – it’s very real, explains ESET’s Lukas Stefanko. The post Talking Android ransomware extorts victims appeared first on WeLiveSecurity

How to recover from the OSX/Filecoder.E ransomware on your Mac
Prisoners’ ‘innovative’ anti-IMSI catcher defence was… er, tinfoil
Gatekeeper-like feature for Windows 10 only allows apps to be installed from the Microsoft Store

LinuxSecurity.com: An update for qemu-kvm is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

Tricksy bugs in Zscaler admin portal let you ruin a coworker’s day
CloudPets’ woes worsen: Webpages can turn kids’ stuffed toys into creepy audio bugs

LinuxSecurity.com: Security Report Summary

security update