Take a closer look at the cyberespionage group Sednit, which has targeted over 1000 high-profile individuals and organizations with phishing attacks and zero-day exploits. The post Sednit: How this notorious cyberespionage group operates appeared first on WeLiveSecurity
ESET’s Ondrej Kubovič: “Worrying about privacy isn’t enough” – here’s how to control your data privacy and online presence. The post Worrying about data privacy isn’t enough: Here’s how to own your online presence appeared first on WeLiveSecurity
Recent phishing scams targeted both Gmail and Yahoo, and now attackers have their sights set on PayPal with some very convincing bait. The post PayPal users targeted in sophisticated new phishing campaign appeared first on WeLiveSecurity
security update
LinuxSecurity.com: An update for ansible is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact [More…]
LinuxSecurity.com: Security Report Summary
LinuxSecurity.com: – new upstream (51.0)
LinuxSecurity.com: * CVE-2016-6836: vmxnet: Information leakage in vmxnet3_complete_packet (bz#1366370) * CVE-2016-7909: pcnet: Infinite loop in pcnet_rdra_addr (bz #1381196)* CVE-2016-7994: virtio-gpu: memory leak in resource_create_2d (bz #1382667) *CVE-2016-8577: 9pfs: host memory leakage in v9fs_read (bz #1383286) *CVE-2016-8578: 9pfs: potential NULL dereferencein 9pfs routines (bz #1383292) *CVE-2016-8668: OOB buffer access in rocker switch emulation (bz #1384898) *CVE-2016-8669: […]
LinuxSecurity.com: Update to ansible 2.2.1. Fixes several CVEs as well as a number of otherbugfixes. See: https://github.com/ansible/ansible/blob/stable-2.2/CHANGELOG.mdfor full changes.
LinuxSecurity.com: Update to ansible 2.2.1. Fixes several CVEs as well as a number of otherbugfixes. See: https://github.com/ansible/ansible/blob/stable-2.2/CHANGELOG.mdfor full changes.
Cybercrime is victimizing US companies and consumers, but a gap in cybersecurity skills presents a problem for the federal government. ESET’s Stephen Cobb investigates. The post Desperately seeking cybersecurity skills appeared first on WeLiveSecurity
LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact [More…]
To address the need for application security in the digital transformation era, F5 is releasing a new host of products and services. “The digital transformation has really changed security as a whole,” says Preston Hogue, Director of Security Marketing and Competitive Intelligence. What he means is that everything—EVERYTHING—is moving to the cloud. Think about the […]
Lloyds Banking Group fell victim to an attempted cyberattack earlier this month, which saw cybercriminals attempt to crash the online banking service over a two day period. The post Lloyds Banking Group hit with distributed denial of service attack appeared first on WeLiveSecurity
Could the Internet of Things spark the Ransomware of Things? ESET’s Stephen Cobb examines how ransomware and jackware are evolving. The post RoT: Ransomware of Things appeared first on WeLiveSecurity
The US Securities and Exchange Commission is looking into whether Yahoo could have been quicker to tell investors about two record-breaking data breaches. The post Yahoo faces SEC probe into its two record-breaking data breaches appeared first on WeLiveSecurity
LinuxSecurity.com: Multiple vulnerabilities have been found in Oracle’s JRE and JDK software suites, the worst of which may allow execution of arbitrary code
LinuxSecurity.com: Multiple vulnerabilities have been found in X.Org X Server, the worst of which may allow authenticated attackers to read from or send information to arbitrary X11 clients.
LinuxSecurity.com: Security fix for CVE-2016-2120, CVE-2016-7068, CVE-2016-7072, CVE-2016-7073,CVE-2016-7074
LinuxSecurity.com: Security fix for console video game music emu vulnerability in the fullyoptional audacious-plugins-exotic subpackage: CVE-2016-9957, CVE-2016-9958,CVE-2016-9959, CVE-2016-9960, CVE-2016-9961
LinuxSecurity.com: Security fix for CVE-2016-6814
LinuxSecurity.com: Update to 0.8.0-6.git97f52c1
LinuxSecurity.com: Rebase to latest upstream gitrev 20161120
LinuxSecurity.com: Update from 3.8.1 to 3.8.2. Also fixes console video game music emuvulnerability in the fully optional audacious-plugins-exotic subpackage:CVE-2016-9957, CVE-2016-9958, CVE-2016-9959, CVE-2016-9960, CVE-2016-9961
LinuxSecurity.com: Update from 3.8.1 to 3.8.2. Also fixes console video game music emuvulnerability in the fully optional audacious-plugins-exotic subpackage:CVE-2016-9957, CVE-2016-9958, CVE-2016-9959, CVE-2016-9960, CVE-2016-9961
LinuxSecurity.com: Security fix for CVE-2016-2120, CVE-2016-7068, CVE-2016-7072, CVE-2016-7073,CVE-2016-7074
LinuxSecurity.com: Fix validation logic in the base consumer The base consumer is intended to onlyderive its validation switch from the on-disk configuration if the child classdoesn’t override the validate_signatures switch. There was a bug here where thedefault value provided in the base class made it appear as if *all* childconsumers had turned *off* validation, which […]
LinuxSecurity.com: This update fixes a security problem with the EDE package.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
