Menu

Monthly Archives: September 2017

LinuxSecurity.com: A vulnerability in MCollective might allow remote attackers to execute arbitrary code.

News in brief: Pratchett’s data steamrollered; WikiLeaks hit by hackers; Instagram details for sale
Lawyer suggests tying access to encryption to verified ID
Leaky S3 bucket sloshes deets of thousands with US security clearance
Trove of Private Military Contractor Job Applicants Exposed Online
Security-focused phone launches crowdfunding drive
Tempted to join the games in the crytpcurrency playground?

LinuxSecurity.com: Several security issues were fixed in FontForge.

LinuxSecurity.com: Libidn2 2.0.4 (released 2017-08-30) integer overflow in bidi.c/_isBidi() * Fix integer overflow in puny_decode.c/decode_digit() * Improve docs * Fix idna_free() to idn_free() * Update fuzzer corpora

LinuxSecurity.com: Qemu: usb: ohci: infinite loop due to incorrect return value [CVE-2017-9330] (#1457698) Qemu: nbd: segmentation fault due to client non-negotiation [CVE-2017-9524] (#1460173) Qemu: qemu-nbd: server breaks with SIGPIPE upon client abort [CVE-2017-10664] (#1466466) Qemu: exec: oob access during dma operation [CVE-2017-11334] (#1471640) revised full fix for XSA-226 (regressed

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available. An update that fixes 6 vulnerabilities is now available. An update that fixes 6 vulnerabilities is now available.

Six million Instagram accounts hacked

A hack believed to target only celebrity accounts on Instagram has also accessed millions of users’ private data. The post Six million Instagram accounts hacked appeared first on WeLiveSecurity

LinuxSecurity.com: Several security issues were fixed in Liblouis.

Crypto-busters reverse nearly 320 MEELLION hashed passwords

LinuxSecurity.com: An update that solves 9 vulnerabilities and has two fixes An update that solves 9 vulnerabilities and has two fixes An update that solves 9 vulnerabilities and has two fixes is now available. is now available.

security update

Asterisk RTP bug worse than first thought: think intercepted streams

LinuxSecurity.com: This update fixes CVE-2017-12982.

LinuxSecurity.com: This update fixes CVE-2017-12982.

LinuxSecurity.com: Qemu: usb: ohci: infinite loop due to incorrect return value [CVE-2017-9330] (#1457698) Qemu: nbd: segmentation fault due to client non-negotiation [CVE-2017-9524] (#1460173) Qemu: qemu-nbd: server breaks with SIGPIPE upon client abort [CVE-2017-10664] (#1466466) Qemu: exec: oob access during dma operation [CVE-2017-11334] (#1471640) revised full fix for XSA-226 (regressed

Stolen 6M Celebrities data from Instagram sold on Dark Web

LinuxSecurity.com: Libidn2 2.0.4 (released 2017-08-30) integer overflow in bidi.c/_isBidi() * Fix integer overflow in puny_decode.c/decode_digit() * Improve docs * Fix idna_free() to idn_free() * Update fuzzer corpora

security update

security update

security update

LinuxSecurity.com: Libidn2 2.0.4 (released 2017-08-30) integer overflow in bidi.c/_isBidi() * Fix integer overflow in puny_decode.c/decode_digit() * Improve docs * Fix idna_free() to idn_free() * Update fuzzer corpora

LinuxSecurity.com: **Version 2.2.5** – 2017-08-30 * **Security** – Double-free in gdImagePngPtr(). **CVE-2017-6362** – Buffer over-read into uninitialized memory. **CVE-2017-7890** * **Fixed** – Fix #109: XBM reading fails with printed error – Fix #338: Fatal and normal libjpeg/ibpng errors not distinguishable – Fix #357: 2.2.4: Segfault in test suite – Fix #386:

LinuxSecurity.com: – Update to 2.6.0 Release notes: https://tls.mbed.org/tech- updates/releases/mbedtls-2.6.0-2.1.9-and-1.3.21-released Security Advisory: https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security- advisory-2017-02

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available. An update that fixes 6 vulnerabilities is now available. An update that fixes 6 vulnerabilities is now available.

LinuxSecurity.com: An update that solves three vulnerabilities and has 5 fixes An update that solves three vulnerabilities and has 5 fixes An update that solves three vulnerabilities and has 5 fixes is now available. is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

DailyStormer comes back with Albanian domain; gets booted off

From streaming entertainment to social media to our online bank accounts and software, we are inundated every day with the need to create and remember new passwords. In fact, one study revealed that Americans have an average of 130 online accounts registered to a single email address. And what are the chances that those 130 […]

‘HoeflerText’ Popups Target Browsers With RAT and Locky Ransomware
US cops can’t keep license plate data scans secret without reason
Massive Locky Ransomware Strain Hits US with Over 23 Million Emails
News in brief: Call to link encryption to ID; Facebook maps everyone; Mirai ‘blackmailer’ extradited
Massive Locky ransomware campaign sends out 23 million emails in 24 hours
Online file conversion services – why trust them?
Hacker Charged for Crashing Businesses Using Millions of Mirai botnet
Open source or proprietary: how should we secure voting systems?
‘Independent’ gov law reviewer wants users preemptively identified before they’re ‘allowed’ to use encryption
Threatpost News Wrap, September 1, 2017
Ex-cop who won’t decrypt hard drives still in jail indefinitely
No Fix Planned For LabVIEW Bug, Says National Instruments
US Government Site Was Hosting Ransomware
Insecure Office 365 setups could be a ticking time bomb for your business
Blonde girlfriend’s passport let dark-haired man fly from London to Germany
Twitter struggles to deal with the sock-puppet and bot armies
Snoops ‘n’ snitches auditor IPCO gets up and running
Instagram warns users of API bug on heels of nude Bieber photos leak
China’s cybersecurity law grants government ‘unprecedented’ control over foreign tech
Connect at mine free Wi-Fi! I would knew what I is do! I is cafe boss!
WikiLeaks suffer defacement at the hands of OurMine group

WikiLeaks’ whistleblowing website suffered an attack from the group known as OurMine on Thursday The post WikiLeaks suffer defacement at the hands of OurMine group appeared first on WeLiveSecurity

IRS-Themed Ransomware Using Old-School Tactics Over the past week, researchers have discovered a new ransomware variant that attempts to impersonate both the IRS and the FBI, similar to the FBI lockscreen malware that was popular several years ago. By tricking the victim into opening a link to a fake FBI questionnaire, the ransomware is downloaded […]

Asterisk bugs make a right mess of RTP
AT&T customers with Arris modems at risk, claim infosec bods