LinuxSecurity.com: USN 3366-1 introduced a regression in OpenJDK 8.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
LinuxSecurity.com: Several security issues were fixed in Apache HTTP Server.
LinuxSecurity.com: Update to latest snapshot that contains fixes for the latest Talos discovered CVEs.
LinuxSecurity.com: Update to latest snapshot that contains fixes for the latest Talos discovered CVEs.
LinuxSecurity.com: Fix for multiple CVEs
This past May, Webroot surveyed more than 600 IT decision-makers at medium-sized companies (with between 100 and 499 employees) in the U.S., U.K., and Australia. The survey focused on how these small businesses perceived new threats facing their organizations. Were they prepared to manage fallout and recovery process after a cyberattack? Did they understand the […]
LinuxSecurity.com: Several security issues were fixed in NSS.
Risk Level: Very Low. Type: Trojan.
security update
security update
LinuxSecurity.com: Update to 5.2.24: fixes XSS vulnerability CVE-2017-11503.
LinuxSecurity.com: MinGW cross compiled librsvg 2.40.18 release, fixing CVE-2017-11464 (division- by-zero in the Gaussian blur code).
LinuxSecurity.com: Several issues have been discovered in the MySQL database server. The vulnerabilities are addressed by upgrading MySQL to the new upstream version 5.5.57, which includes additional changes, such as performance improvements, bug fixes, new features, and possibly incompatible
LinuxSecurity.com: MinGW cross compiled librsvg 2.40.18 release, fixing CVE-2017-11464 (division- by-zero in the Gaussian blur code).
LinuxSecurity.com: In DSA 3918 Thunderbird was upgraded to the latest ESR series. This update upgrades Enigmail, the OpenPGP extention for Thunderbird, to version 1.9.8.1 to restore full compatibility.
LinuxSecurity.com: Several security issues were fixed in the Linux kernel.
The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any more questions? Just ask. Mac Backdoor Just Discovered, Active For Years Researchers have only recently discovered a previously undetectable backdoor […]
LinuxSecurity.com: New squashfs-tools packages are available for Slackware 14.2 and -current to fix security issues.
LinuxSecurity.com: MinGW cross compiled librsvg 2.40.18 release, fixing CVE-2017-11464 (division- by-zero in the Gaussian blur code).
LinuxSecurity.com: An update that fixes 21 vulnerabilities is now available. An update that fixes 21 vulnerabilities is now available. An update that fixes 21 vulnerabilities is now available.
LinuxSecurity.com: An update that fixes 21 vulnerabilities is now available. An update that fixes 21 vulnerabilities is now available. An update that fixes 21 vulnerabilities is now available.
The number of IoT devices is set to surpass 20 billion by 2020. We take a look at how connected things threaten our security as cybercriminals exploit weaknesses in the smartphones that control them. The post Are smartphones threatening the security of our IoT devices? appeared first on WeLiveSecurity
Trick the firmware and you have access to the whole system. Here at Black Hat, there are a lot of people doing just that. The post Black Hat: Hacking the firmware, the next frontier appeared first on WeLiveSecurity
Anton Cherepanov, a malware researcher at ESET, has picked up a Pwnie Award for Best Backdoor at this year’s ceremony at Black Hat USA 2017 in Las Vegas. The post ESET’s Anton Cherepanov picks up Pwnie for Best Backdoor appeared first on WeLiveSecurity
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low.
Risk Level: Very Low. Type: Trojan.
LinuxSecurity.com: This update addresses the following vulnerabilities: * [CVE-2017-7018](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7018), [CVE-2017-7030](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7030), [CVE-2017-7034](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7034), [CVE-2017-7037](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7037),
LinuxSecurity.com: ## 2.8.25 (2017-07-17) * security #23507 [Security] validate empty passwords again (xabbuh) * bug #23526 [HttpFoundation] Set meta refresh time to 0 in RedirectResponse content (jnvsor) * bug #23540 Disable inlining deprecated services (alekitto) * bug #23468 [DI] Handle root namespace in service definitions (ro0NL) * bug #23256 [Security] Fix authentication.failure event
LinuxSecurity.com: – Upgrade to upstream v3.0.15 release. See upstream ChangeLog for details (in freeradius-doc subpackage). – Resolves: Bug#1471848 CVE-2017-10978 freeradius: Out-of-bounds read/write due to improper output buffer size check in make_secret() – Resolves: Bug#1471860 CVE-2017-10983 freeradius: Out-of-bounds read in
LinuxSecurity.com: Rebuilt to new upstream version 2.7.1 fixes rhbz#1443071 and rhbz#1443129
LinuxSecurity.com: This update fixes multiple security vulnerabilities (CVE-2017-7515, CVE-2017-9775, CVE-2017-9776, CVE-2017-9865).
LinuxSecurity.com: * Bump to 1.8.3 * Security fix for CVE-2017-8932 * add support for 28+bit OIDs in asn1
A homograph attack is what happens when attackers register domains that are similar to the originals, with valid certificates. The post Homograph attacks: Don’t believe everything you see appeared first on WeLiveSecurity
If industry frameworks are to inform and secure the critical infrastructure writ large, here at Black Hat there a lot of people punching holes in them, and in simple ways. The post Black Hat 2017 industrial hacking: The song remains the same appeared first on WeLiveSecurity
This year at Black Hat, tiny automated hacking platforms are everywhere, loaded with tasty purpose-built tools that can be used to break into your systems. The post Black Hat 2017: Non-standard hacking platforms reign supreme appeared first on WeLiveSecurity
Risk Level: Very Low. Type: Trojan.
