Menu

Monthly Archives: July 2017

Google Patches Critical ‘Broadpwn’ Bug in July Security Update
Thousands of NZ Airport Passengers forced to surrender device password
Facebook fights gag prohibiting it from alerting users to search warrants
Two hackers arrested after a decade of selling malware
All you need to know about the move from SHA-1 to SHA-2

For the past two years, I’ve been busy helping Public Key Infrastructure (PKI) customers prepare for and move to SHA-2, the set of cryptographic hash functions that have succeeded SHA-1. Last year, moving to SHA-2 ahead of the global deadline was a nice-to-do preparatory step. This year, now that the migration deadline has passed, it’s required.Many digital-certificate-consuming […]

Everything you need to know about the latest variant of Petya

The latest global cyberattack, detected by ESET as Win32 / Diskcoder.C, considered a variant of Petya, once again highlights the reality outdated systems and insufficient security solutions are still widespread. The post Everything you need to know about the latest variant of Petya appeared first on WeLiveSecurity

Last month’s malware outbreak cost this household company £100 million

LinuxSecurity.com: An update that solves 16 vulnerabilities and has two fixes An update that solves 16 vulnerabilities and has two fixes An update that solves 16 vulnerabilities and has two fixes is now available. is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

Smashing Security #032: The iPhone 8, a data breach at the AA, and a mystery no show
Dark Web Marketplace AlphaBay Down; Users Fear Scam

LinuxSecurity.com: Update back to ISC supported version. Security fix for CVE-2017-3143, CVE-2017-3142, CVE-2017-3140 —- Update to 10.1.

LinuxSecurity.com: Update back to ISC supported version. Security fix for CVE-2017-3143, CVE-2017-3142, CVE-2017-3140 —- Update to 10.1.

LinuxSecurity.com: Update back to ISC supported version. Security fix for CVE-2017-3143, CVE-2017-3142, CVE-2017-3140 —- Update to 10.1.

LinuxSecurity.com: **Horde_Image 2.5.1** * [mjr] SECURITY: Fix more potential places for command injections. —- **Horde_Image 2.5.0** * [mjr] **SECURITY**: Prevent DOS attack by preventing an infinite loop in certain conditions (CVE-2017-9773, reported by Fariskhi Vidyan). * [mjr] **SECURITY**: Prevent RCE attacks by properly sanitizing shell arguments (CVE-2017-9774, reported by Fariskhi

LinuxSecurity.com: Security fix for CVE-2016-7968

LinuxSecurity.com: Security fix for CVE-2017-9604

LinuxSecurity.com: CVE-2017-9604 kmail: Send Later with Delay bypasses OpenPGP

Threat Actors Target Chinese Language News Sites
Critical Vulnerabilities Found in Pre-Installed Dell Software

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves 23 vulnerabilities and has four fixes An update that solves 23 vulnerabilities and has four fixes An update that solves 23 vulnerabilities and has four fixes is now available. is now available.

LinuxSecurity.com: An update that solves 6 vulnerabilities and has 12 fixes is An update that solves 6 vulnerabilities and has 12 fixes is An update that solves 6 vulnerabilities and has 12 fixes is now available. now available.

News in brief: cryptocurrency exchange hacked; laptop ban further eased; AA under fire over data breach
Libgcrypt ‘Sliding Right’ Attack Allows Recovery of RSA-1024 Keys
Illinois poised to ban geolocation tracking without consent
Judge: Facebook can Track Browsing Activity Even When You Log Out
Servers associated with NotPetya attack seized by Ukrainian Police
Bad things happen to good people – but you can help stop that
Google and Apple should do more to fight phone scammers, says researcher
Major cryptocurrency exchange hacked – customers’ Bitcoin and Ethereum accounts plundered
How did some Ethereum users find themselves with empty wallets?
GnuPG crypto library cracked, look for patches
Tor Browser 7.0.2 is released

LinuxSecurity.com: Multiple vulnerabilities have been found in IcedTea, the worst of which may allow execution of arbitrary code.

Risk Level: Very Low. Type: Trojan.

Teen Charged for Selling Malware Used in DDoS Attacks
News in brief: China tightens Great Firewall; student charged over DDoS attacks; health data posted online
Hackers Steal Billions in S.Korean Won by Hacking 4th Largest Bitcoin Exchange
GDPR: who needs to hire a data protection officer?
Kaspersky Willing to Share Its Source Code with US Govt
13GB Data of Automobile Insurance Giant AA Exposed Online
A Man-in-the-Middle Attack against a Password Reset System
HTTPS Certificate Revocation is broken, and it’s time for some new tools
With a single wiretap order, US authorities listened in on 3.3 million phone calls
Health trust rapped on illegal use of patient data in Google AI deal
Yes – despite what it says – AA customer credit card data was exposed
Analysis of TeleBots’ cunning backdoor

This article reveals details about the initial infection vector that was used during the DiskCoder.C outbreak. The post Analysis of TeleBots’ cunning backdoor appeared first on WeLiveSecurity

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: New upstream release fixing moderate security issue CVE-2017-7526.

LinuxSecurity.com: * [7.56](https://www.drupal.org/project/drupal/releases/7.56) * [SA- CORE-2017-003](https://www.drupal.org/SA-CORE-2017-003)

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

security update

Google Employees Data Stolen After Data Breach
Researchers Find BlackEnergy APT Links in ExPetr Code
Classic Ether Wallet Compromised via Social Engineering

LinuxSecurity.com: Daniel J. Bernstein, Joachim Breitner, Daniel Genkin, Leon Groot Bruinderink, Nadia Heninger, Tanja Lange, Christine van Vredendaal and Yuval Yarom discovered that Libgcrypt is prone to a local side-channel attack allowing full key recovery for RSA-1024.

News in brief: drone scare halts flights; laptop ban eased; Samsung to sell Galaxy Note 7
When is public information not public? When LinkedIn says so
Eugene Kaspersky says U.S. government can examine his company’s source code
Pakistani man jailed for 4 years over $19.6M hacking scheme
Two-factor authentication: An underutilized security measure in businesses

ESET’s Josep Albors discusses two-factor authentication, which is an underutilized security measure in businesses all over the world. The post Two-factor authentication: An underutilized security measure in businesses appeared first on WeLiveSecurity

Now criminals are ringing up British MPs to ask them their passwords

Risk Level: Low. Type: Trojan, Worm.

LinuxSecurity.com: – http://www.zabbix.com/rn3.0.8 – http://www.zabbix.com/rn3.0.9 – https://www.zabbix.com/documentation/3.0/manual/introduction/whatsnew308 – https://www.zabbix.com/documentation/3.0/manual/introduction/whatsnew309

LinuxSecurity.com: A fix for an out-of-bounds write in systemd-resolved after a crafted DNS packet (CVE-2017-9445). No need to reboot or log out.

LinuxSecurity.com: – http://www.zabbix.com/rn3.0.8 – http://www.zabbix.com/rn3.0.9 – https://www.zabbix.com/documentation/3.0/manual/introduction/whatsnew308 – https://www.zabbix.com/documentation/3.0/manual/introduction/whatsnew309

LinuxSecurity.com: xen: various flaws (#1463247) blkif responses leak backend stack data [XSA-216] page transfer may allow PV guest to elevate privilege [XSA-217] Races in the grant table unmap code [XSA-218] x86: insufficient reference counts during shadow emulation [XSA-219] x86: PKRU and BND* leakage between vCPU-s [XSA-220] stale P2M mappings due to insufficient error checking [XSA-222] […]

Savvy MSPs know that automation improves efficiency and strengthens their bottom line. In a nutshell, automation enables an MSP to reduce the amount of time its technicians spend handling routine or repetitive tasks, thus cutting costs for service delivery and freeing those techs to devote more attention to activities that generate more revenue. Enabling Creativity […]

Afghan robotic team of girls denied US visa

LinuxSecurity.com: Updates to the latest upstream OpenVPN 2.3.17, containing security updates for CVE-2017-7508, CVE-2017-7520 and CVE-2017-7521.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has 9 fixes An update that solves two vulnerabilities and has 9 fixes An update that solves two vulnerabilities and has 9 fixes is now available. is now available.

Wikileaks Exposes CIA’ Linux Hacking, Geolocation Tracker Malware