Menu

Category Archives: Security

Articles about security

Pompeo sworn in as CIA chief amid opposition from surveillance critics
Apps Carrying HummingBad Variant Booted From Google Play
I don’t care what your eyeballs tell you. Alternative fact is, we’ve locked up your files
Why Linux Installers Need to Add Security Features
Keeping Linux devices secure with rigorous long-term maintenance
Linux Is Part of the IoT Security Problem, Dev Tells Linux Conference
The evolution of (and solution to) ransomware

Contrary to popular belief, ransomware has been around for decades. The first malware program to lock up people’s files and ask for a ransom was the PC Cyborg Trojan in 1989. It was created by Harvard-trained evolutionary biologist Dr. Joseph Popp, who was working on several AIDS-related projects at the time. Dr. Popp sent a […]

LinuxSecurity.com: An update for mysql is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Firejail, the worst of which may allow privilege escalation.

HummingBad malware returns in new, more annoying variant

LinuxSecurity.com: Multiple vulnerabilities have been discovered in WebP, the worst of which could allow a remote attacker to cause a Denial of Service condition.

LinuxSecurity.com: An update for squid is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: An update for squid34 is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: Multiple vulnerabilities have been found in LibRaw, the worst of which may allow attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in ADOdb, all of which could allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in ICU, the worst of which could cause a Denial of Service condition.

Furby Rickroll demo: What fresh hell is this?
Kid hackers break XSS defences, find hack hole in 2 million websites
Microsoft fixes remote desktop app Mac hole
VXers gift their mates an Android bank-raiding app’s source code

LinuxSecurity.com: New mozilla-firefox packages are available for Slackware 14.1, 14.2, and -current to fix security issues. [More Info…]

Apple issues security patches for… just about everything

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Western Union coughs up $586m for turning a blind eye to fraudsters
Cisco’s WebEx Chrome plugin will execute evil code, install malware via secret ‘magic URL’
What links macOS, iOS, Safari, tvOS, watchOS? They all need patching

LinuxSecurity.com: ## Version 2.2.4 – 2017-01-18 ### Security – gdImageCreate() doesn’t check foroversized images and as such is prone to DoS vulnerabilities. (CVE-2016-9317)- double-free in gdImageWebPtr() (CVE-2016-6912) – potential unsigned underflowin gd_interpolation.c – DOS vulnerability in gdImageCreateFromGd2Ctx() ###Fixed – Fix #354: Signed Integer Overflow gd_io.c – Fix #340: System frozen -Fix OOB reads of the […]

LinuxSecurity.com: The 4.9.5 stable kernel update contains a number of important fixes across thetree.

LinuxSecurity.com: The 4.9.5 stable kernel update contains a number of important fixes across thetree.

ThePirateBay.org goes down; dark web domain is up and running
Apple Patches Critical Kernel Vulnerabilities
China’s Great Firewall to crack down on unofficial VPNs – state-approved net connections only
Secure Email Service Lavabit Relaunches
WatchMojo’s official YouTube Channel Terminated Due to a Glitch (Updated)
IBM stuffs visualization tech into its bulging, uh, security portfolio
Heartbleed Persists on 200,000 Servers, Devices

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: This update addresses the following vulnerabilities: *[CVE-2016-7656](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7656),[CVE-2016-7635](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7635),[CVE-2016-7654](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7654),[CVE-2016-7639](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7639),[CVE-2016-7645](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7645),[CVE-2016-7652](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7652),[CVE-2016-7641](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7641),[CVE-2016-7632](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7632),[CVE-2016-7599](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7599),[CVE-2016-7592](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7592),[CVE-2016-7589](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7589),[CVE-2016-7623](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7623),[CVE-2016-7586](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7586)Additional fixes: * Create GLX OpenGL contexts using version 3.2 (core profile)when available to reduce the memory consumption on Mesa based drivers. * Improvememory pressure handler to reduce the CPU usage on memory pressure situations. *Fix a regression in WebKitWebView title notify signal emission that caused thesignal to […]

Heartbleed is not dead. And isn’t likely to be any time soon
Sage and Satan Ransomware, Double Trouble
Bug allowed attackers to delete ANY Facebook video they chose
Head of GCHQ Robert Hannigan steps down for ‘personal reasons’
DuckDuckGo Search Engine Hits a Milestone with 14 Million Searches a Day
Lloyds Bank outage: DDoS is prime suspect
Massive Twitter Botnet Dormant Since 2013
BBC, NYT Twitter accounts hacked; posts fake news about Trump and Putin
Twitter hack sees New York Times warn of Russian missile strike against USA
Protected US military server poked via army recruitment website
It’s 2017 and 200,000 services still have unpatched Heartbleeds
Go dark with the flow: Lavabit lives again
Satan enters roll-your-own ransomware game
Symantec carpeted over dodgy certificates, again
Mozilla wants infosec activism to be the next green movement

LinuxSecurity.com: Multiple vulnerabilities have been found in zlib, the worst of which could allow attackers to cause a Denial of Service condition.

LinuxSecurity.com: Multiple vulnerabilities have been found in DirectFB, all of which could allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A buffer overflow in DCRaw might allow remote attackers to cause a Denial of Service condition.

LinuxSecurity.com: A buffer overflow in Lua might allow context-dependent attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in libupnp, the worst of which could lead to the execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in DBD::mysql, the worst of which might allow an attacker to execute arbitrary code.

LinuxSecurity.com: A buffer overflow in PPP might allow remote attackers to cause a Denial of Service condition.

LinuxSecurity.com: Multiple vulnerabilities have been found in QEMU, the worst of which could cause a Denial of Service condition.

Employment scam targets college students and their bank accounts

LinuxSecurity.com: check valid input arguments for nla_reserve() (rh #1414305, CVE-2017-0386)

security update

security update

security update

Radio Station Transmission Hacked with F*** Donald Trump Song
Researchers condemn unsubstantiated WhatsApp “Backdoor” story by Guardian
Mozilla’s First Internet Health Report Tackles Security, Privacy
India’s Famous Horse Racing Site Hacked with Dharma Ransomware
Protesters Called To Join Inauguration Day DDoS Attack
Rsync errors lead to data breach at Canadian ISP, KWIC Internet
Encrypted email service ProtonMail opens door for Tor users
7 (more) security TED Talks you can’t miss
350,000 Twitter bot sleeper cell betrayed by love of Star Wars and Windows Phone
Researcher claims to expose identity of Mirai Botnet Author
Coalition of Cryptographers, Researchers Urge Guardian to Retract WhatsApp Story

security update

Rap for crap WhatsApp trap flap: Yack yack app claptrap slapped
Hadoop, CouchDB Next Targets in Wave of Database Attacks

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Multiple vulnerabilities have been found in cURL, the worst of which could allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in NSS, the worst of which could allow remote attackers to obtain access to private key information.

LinuxSecurity.com: Multiple vulnerabilities have been found in irssi, the worst of which could allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A heap-based buffer overflow in CVS might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in IcedTea allowing remote attackers to affect confidentiality, integrity, and availability through various vectors.

LinuxSecurity.com: An update for java-1.8.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 6 and Oracle Java for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

Hack the Army Bounty Pays Out $100,000; 118 Flaws Fixed
General Electrics plays down industrial control plant vulnerabilities