Menu

Category Archives: Security

Articles about security

LinuxSecurity.com: * [7.56](https://www.drupal.org/project/drupal/releases/7.56) * [SA- CORE-2017-003](https://www.drupal.org/SA-CORE-2017-003)

LinuxSecurity.com: New upstream release fixing moderate security issue CVE-2017-7526.

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

security update

Google Employees Data Stolen After Data Breach
Researchers Find BlackEnergy APT Links in ExPetr Code
Classic Ether Wallet Compromised via Social Engineering

LinuxSecurity.com: Daniel J. Bernstein, Joachim Breitner, Daniel Genkin, Leon Groot Bruinderink, Nadia Heninger, Tanja Lange, Christine van Vredendaal and Yuval Yarom discovered that Libgcrypt is prone to a local side-channel attack allowing full key recovery for RSA-1024.

Eugene Kaspersky says U.S. government can examine his company’s source code
Pakistani man jailed for 4 years over $19.6M hacking scheme
Two-factor authentication: An underutilized security measure in businesses

ESET’s Josep Albors discusses two-factor authentication, which is an underutilized security measure in businesses all over the world. The post Two-factor authentication: An underutilized security measure in businesses appeared first on WeLiveSecurity

Now criminals are ringing up British MPs to ask them their passwords

Risk Level: Low. Type: Trojan, Worm.

LinuxSecurity.com: – http://www.zabbix.com/rn3.0.8 – http://www.zabbix.com/rn3.0.9 – https://www.zabbix.com/documentation/3.0/manual/introduction/whatsnew308 – https://www.zabbix.com/documentation/3.0/manual/introduction/whatsnew309

LinuxSecurity.com: – http://www.zabbix.com/rn3.0.8 – http://www.zabbix.com/rn3.0.9 – https://www.zabbix.com/documentation/3.0/manual/introduction/whatsnew308 – https://www.zabbix.com/documentation/3.0/manual/introduction/whatsnew309

LinuxSecurity.com: A fix for an out-of-bounds write in systemd-resolved after a crafted DNS packet (CVE-2017-9445). No need to reboot or log out.

LinuxSecurity.com: xen: various flaws (#1463247) blkif responses leak backend stack data [XSA-216] page transfer may allow PV guest to elevate privilege [XSA-217] Races in the grant table unmap code [XSA-218] x86: insufficient reference counts during shadow emulation [XSA-219] x86: PKRU and BND* leakage between vCPU-s [XSA-220] stale P2M mappings due to insufficient error checking [XSA-222] […]

Savvy MSPs know that automation improves efficiency and strengthens their bottom line. In a nutshell, automation enables an MSP to reduce the amount of time its technicians spend handling routine or repetitive tasks, thus cutting costs for service delivery and freeing those techs to devote more attention to activities that generate more revenue. Enabling Creativity […]

Afghan robotic team of girls denied US visa

LinuxSecurity.com: Updates to the latest upstream OpenVPN 2.3.17, containing security updates for CVE-2017-7508, CVE-2017-7520 and CVE-2017-7521.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has 9 fixes An update that solves two vulnerabilities and has 9 fixes An update that solves two vulnerabilities and has 9 fixes is now available. is now available.

Wikileaks Exposes CIA’ Linux Hacking, Geolocation Tracker Malware

LinuxSecurity.com: New glibc packages are available for Slackware 14.2 and -current to fix security issues.

LinuxSecurity.com: New kernel packages are available for Slackware 14.2 and -current to fix security issues.

Siemens Patches Critical Intel AMT Flaw in Industrial Products
Majority of Sites Fail Mozilla’s Comprehensive Security Review
Feedback scammers attempting to extort millions from 5,000 major companies
UN: Terrorists can access WMDs via Dark Web
UK government threatens to launch drone strikes against hackers

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any more questions? Just ask. Ukraine Hit With Nationwide Cyberattack In the past week, Ukrainian officials have been making announcements regarding […]

This company deliberately deleted its customer email mailing list. Maybe you should too
U.S Senate wants to ban Kaspersky’ Software for Links to Russia
TeleBots are back: Supply-chain attacks against Ukraine

This blogpost reveals many details about the Diskcoder.C (aka ExPetr or NotPetya) outbreak and related information about previously unpublished attacks. The post TeleBots are back: Supply-chain attacks against Ukraine appeared first on WeLiveSecurity

Threatpost News Wrap, June 30, 2017
Workplace social media security: 5 questions answered

Workplace social media security is undoubtedly important for many businesses. In this feature, we answer five key questions relating to it. The post Workplace social media security: 5 questions answered appeared first on WeLiveSecurity

This Retail Website Considers Password Security Optional

LinuxSecurity.com: New httpd packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: New bind packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: New kernel packages are available for Slackware 14.1 to fix security issues.

LinuxSecurity.com: New libgcrypt packages are available for Slackware 14.2 and -current to fix a security issue.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

Bluetooth-enabled Fidget Spinners are Blowing Up
ExPetr Called a Wiper Attack, Not Ransomware

LinuxSecurity.com: CVE-2017-1000381: c-ares NAPTR parser out of bounds access

LinuxSecurity.com: An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata is now available. is now available.

Linux Systemd Bug Could Have Led to Crash, Code Execution
U.S. Senate committee wants to ban Kaspersky products from the Department of Defense
Microsoft to use AI in Windows 10 to counter malware attacks
How to keep Debian Linux patched with latest security updates automatically
Linux: A Hacker’s Preference
A critical flaw allows hacking Linux machines with just a malicious DNS Response
Petya not a ransomware but much worse
8tracks hacked: 18 million user account details stolen

LinuxSecurity.com: An update that solves 5 vulnerabilities and has one errata An update that solves 5 vulnerabilities and has one errata An update that solves 5 vulnerabilities and has one errata is now available. is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata is now available. is now available.

How to make a strong password

Passwords are often the first line of defense in protecting our personal and financial information, so it pays to have a strong, long and complex password (and easy to remember). Our one minute guide shows you how. The post How to make a strong password appeared first on WeLiveSecurity

What Are Linux Logs? How to View Them, Most Important Directories, and More
New Research Shows Cybersecurity Battleground Shifting to Linux and Web Servers

LinuxSecurity.com: An update that solves three vulnerabilities and has 6 fixes An update that solves three vulnerabilities and has 6 fixes An update that solves three vulnerabilities and has 6 fixes is now available. is now available.

Smashing Security #031: Petya (don’t know the name of this ransomware)

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Risk Level: Very Low. Type: Virus, Worm.

security update

‘Little Hope’ to Recover Data Lost to Petya Ransomware
Microsoft Issues ‘Important’ Security Fix for Azure AD Connect

LinuxSecurity.com: Several issues were discovered in openvpn, a virtual private network application. CVE-2017-7479

LinuxSecurity.com: The security update announced as DSA-3886-1 caused regressions for some applications using Java – including jsvc, LibreOffice and Scilab – due to the fix for CVE-2017-1000364. Updated packages are now available to correct this issue. For reference, the relevant part of the original

LinuxSecurity.com: An update that contains security fixes can now be installed. An update that contains security fixes can now be installed. An update that contains security fixes can now be installed.

LinuxSecurity.com: systemd-resolved could be made to crash or run programs if it received a specially crafted DNS response.

LinuxSecurity.com: An update that contains security fixes can now be installed. An update that contains security fixes can now be installed. An update that contains security fixes can now be installed.

Risk Level: Low. Type: Trojan.

New Petya Distribution Vectors Bubbling to Surface
Average Bug Bounty Payments Growing
Four arrested as Microsoft and UK police team up to crack down on technical support scammers
Idea to encrypt Web traffic at rest hits the IETF’s Standard Track
How to secure your CMS with out patching
Even weak hackers can pull off a password reset MitM attack via account registration
Year-old vulnerability allowed pro-ISIS hackers to hack US government websites

LinuxSecurity.com: An update that contains security fixes can now be installed. An update that contains security fixes can now be installed. An update that contains security fixes can now be installed.

Hackers Demand Banks $315k Ransom or Face DDoS Attacks

A host of companies across industries have confirmed attacks today by a brutal wave of ransomware, including global law firm DLA Piper, U.S. pharmaceutical giant Merck, and the Danish shipping company Maersk. Although targets originally appeared in Ukraine—shutting down power plants, banking services and supermarkets—this latest cyberattack has quickly spanned critical economic sectors around the […]

The Amazon Echo (Horror) Show
Complex Petya-Like Ransomware Outbreak Worse than WannaCry