Menu

Category Archives: Security

Articles about security

Retailers! Avoid getting hacked during the holiday season (or any other time of the year)

Tips for cash-strapped retailers looking to avoid getting hacked, during the holiday shopping season, or any other season. The post Retailers! Avoid getting hacked during the holiday season (or any other time of the year) appeared first on WeLiveSecurity

PHPMailer, SwiftMailer Updates Resolve Critical Remote Code Execution Vulnerabilities
Microsoft May Stop Forcing You to Upgrade to Windows 10
Threatpost 2016 Year in Review
Meet the Leet DDoS Botnet, Just as Powerful as Mirai
Sultry Sextortion Sisters Meet Their Match In Nigerian Oil Billionaire
5 key technologies to double down on now
5 signs we’re finally getting our act together on security

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: New samba packages are available for Slackware 14.2 and -current to fix security issues. [More Info…]

LinuxSecurity.com: New python packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: Update to 2.2.4 with backport for XSS vulnerability.

LinuxSecurity.com: Update to latest jquery1 stable, with backport fix for XSS vulnerability.)

LinuxSecurity.com: This update adds security sandboxing to tracker-extract.

LinuxSecurity.com: Update to latest jquery1 stable, with backport fix for XSS vulnerability.)

LinuxSecurity.com: fix for “TLS SecurityMode.required bypass via StripTLS attack”(rhbz#1406703,1406704)

security update

LG Smart TV Screen Bricked After Android Ransomware Infection
How to Choose the Perfect Laptop for Online Study
Someone DDoSed ExtraTorrent Domain while ThePirateBay suffered downtime

LinuxSecurity.com: * Mon Dec 12 2016 Norvald H. Ryeng – 5.7.17-1 -Update to MySQL 5.7.17, for various fixes described athttps://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-17.html – Add newplugin: connnection_control.so – Add MySQL Group Replication:group_replication.so – Add numactl-devel to buildreq and enable NUMA support (ifavailable) – Simplify boost path – Build compat-openssl10 in rawhide for now -Reqs. in -devel packages was […]

LinuxSecurity.com: Updated to 2.1.4

LinuxSecurity.com: This update contains a **SECURITY** fix for an issue with potentially seriousconsequences but very limited scope. If an administrator of a wiki you talked tousing python-wikitcms were malicious, they could cause arbitrary code executionas the user running wikitcms. No-one besides a wiki administrator could do this,as it requires crafting the wiki’s response to an […]

LinuxSecurity.com: Updated to 2.1.4

LinuxSecurity.com: This update contains a **SECURITY** fix for an issue with potentially seriousconsequences but very limited scope. If an administrator of a wiki you talked tousing python-wikitcms were malicious, they could cause arbitrary code executionas the user running wikitcms. No-one besides a wiki administrator could do this,as it requires crafting the wiki’s response to an […]

LinuxSecurity.com: Update to 2.2.4 with backport for XSS vulnerability.

LinuxSecurity.com: Security fix for CVE-2016-4330, CVE-2016-4331, CVE-2016-4332, CVE-2016-4333

LinuxSecurity.com: two security flaws (#1406840) x86 PV guests may be able to mask interrupts[XSA-202, CVE-2016-10024] x86: missing NULL pointer check in VMFUNC emulation[XSA-203, CVE-2016-10025] x86: Mishandling of SYSCALL singlestep duringemulation [XSA-204, CVE-2016-10013] (#1406260)

LinuxSecurity.com: * Mon Dec 12 2016 Norvald H. Ryeng – 5.7.17-1 -Update to MySQL 5.7.17, for various fixes described athttps://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-17.html – Add newplugin: connnection_control.so – Add MySQL Group Replication:group_replication.so – Add numactl-devel to buildreq and enable NUMA support (ifavailable) – Simplify boost path – Build compat-openssl10 in rawhide for now -Reqs. in -devel packages was […]

LinuxSecurity.com: – fix floating point buffer overflow issues (CVE-2016-9586)

Three Chinese Hackers Made Millions by Hacking American Law Firms
Thai Police Arrest 9 Suspects Behind Cyber Attacks on Gov’t Sites
Leaked info confirms in-house hacking capabilities of Israeli firm Cellebrite
US Immigration asking foreign travelers for their social media account details
Four New Normals for 2017
Trio charged with $4m insider trading by hacking merger lawyers
Encryption in 2016: Small victories add up
How Microsoft will drive enterprise IT in 2017
Android Trojan Switcher Infects Routers via DNS Hijacking
What is encryption and how does it work?

It has become one of the most topical and discussed topics in information security in recent times. In this video we outline some of the key aspects of encryption. The post What is encryption and how does it work? appeared first on WeLiveSecurity

security update

PHPMailer Bug Leaves Millions of Websites Open to Attack

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security fix for CVE-2016-8743, CVE-2016-2161, CVE-2016-0736

LinuxSecurity.com: Security fix for CVE-2016-8743, CVE-2016-2161, CVE-2016-0736

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: New expat packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: New openssh packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: New httpd packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: Multiple vulnerabilities have been found in Samba, the worst of which may allow execution of arbitrary code with root privileges.

LinuxSecurity.com: Multiple vulnerabilities have been found in Xerces-C++, the worst of which may allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities were found in Tor, the worst of which could allow remote attackers to cause a Denial of Service condition.

The real reason we can't secure the internet

Last week I speculated that the current horrible state of internet security may well be as good as we’re ever going to get. I focused on the technical and historical reasons why I believe that to be true. Today, I’ll tell you why I’m convinced that, even if we were able to solve the technical […]

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Firejail, the worst of which may allow bypassing of sandbox protection.

15% off Nest Cam Indoor Security Camera – Deal Alert
A year in infosec: Bears, botnets, breaches … and elections

security update

Man Jailed for uploading UK’s Top 40 singles on The Pirate Bay and KickAssTorrents

security update

security update

Tumblr Attackers Now threatening to Ruin Christmas for Xbox Users with DDoS Attacks
Cerber Ransomware Infecting Devices by Exploiting Flaws in Web Browsers

security update

Android-compatible Google Daydream VR Controller Hacked to Run on iOS
Clever Facebook Hack Reveals Private Email Address of Any User
Exim gives Linux admins a security fix for Christmas
Steam and Origin Servers Down? Phantom Squad and PoodleCorp Claim Responsibility

LinuxSecurity.com: ### Botan 1.10.14 ### * NOTE WELL: Botan 1.10.x is supported for securitypatches only until 2017-12-31 * Fix integer overflow during BER decoding, foundby Falko Strenzke. This bug is not thought to be directly exploitable butupgrading ASAP is advised. (CVE-2016-9132) * Fix two cases where (in errorsituations) an exception would be thrown from a […]

LinuxSecurity.com: gdk-pixbuf 2.36.2 release. * Remove the pixdata loader (#776004) * Fixinteger overflows in the jpeg loader (#775218) * Add an external thumbnailerfor images * Fix a NULL pointer dereference (#776026) * Fix a memory leak(#776020) * Support bmp headers with bitmask (#766890) * Add tests for scaling(#80925) * Handle compressed pixdata in resources (#776105) […]

LinuxSecurity.com: Security fix for CVE-2016-2125, CVE-2016-2126

LinuxSecurity.com: ### Botan 1.10.14 ### * NOTE WELL: Botan 1.10.x is supported for securitypatches only until 2017-12-31 * Fix integer overflow during BER decoding, foundby Falko Strenzke. This bug is not thought to be directly exploitable butupgrading ASAP is advised. (CVE-2016-9132) * Fix two cases where (in errorsituations) an exception would be thrown from a […]

  As 2016 comes to a close, it’s time to reflect back on the largest/most significant security news stories that left an impact on the world. Mirai Botnet Being hailed as the largest attack of its kind in history, the DDoS attack launched by the Mirai botnet encompassed over 100,000 unique endpoints and hit a […]

Cisco Warns of Critical Flaw in CloudCenter Orchestrator Systems
Netgear plays down router security flaw
Apple gives iOS app developers more time to encrypt communications
Apple Delays App Transport Security Deadline
Customers reporting their Groupon accounts are being hacked
US healthcare under siege: Got good insurance?
Free cybersecurity tools for all your needs

LinuxSecurity.com: The 4.8.15 stable kernel update contains a number of important fixes across thetree.

LinuxSecurity.com: x86 CMPXCHG8B emulation fails to ignore operand size override [XSA-200,CVE-2016-9932] (#1404262) —- ARM guests may induce host asynchronous abort[XSA-201, CVE-2016-9815, CVE-2016-9816, CVE-2016-9817, CVE-2016-9818] (#1399747)qemu: Divide by zero vulnerability in cirrus_do_copy (#1399055) [CVE-2016-9921,CVE-2016-9922] Qemu: 9pfs: memory leakage via proxy/handle callbacks (#1402278)qemu ioport array overflow [XSA-199, CVE-2016-9637]

LinuxSecurity.com: The 4.8.15 stable kernel update contains a number of important fixes across thetree.

Apple drops requirement for apps to use HTTPS by 2017
Sneaky chat app Signal deploys decoy domains to deny despots
Inflight Entertainment Service Provider Gogo Launches Bug Bounty Program
Bad news: Exim hole was going to be patched on Xmas Day. Good news: Keyword ‘was’
Smashing Security #001: ‘One cup, two hotel guests’
Fancy Bear used Android malware to track Ukrainian artillery
Data Breach: Anonymous hacks Thai Navy, Ministry of Foreign Affairs
NIST Calls for Submissions to Secure Data Against Quantum Computing
Siemens Patches Insufficient Entropy Vulnerability in ICS Systems

Risk Level: Very Low. Type: Trojan.

‘DNC hackers’ used mobile malware to track Ukrainian artillery – researchers
Once again, you can decrypt your CryptXXX ransomware files for free
Groupon frauds blamed on third-party password breaches
Hackers Suspected of Causing Second Power Outage in Ukraine
Congressional Group Says Encryption Backdoors Are a Bad Idea
OurMine hijacks Netflix’s US Twitter account

Netflix has become the latest big name brand to have one of its social media accounts hijacked by OurMine. The post OurMine hijacks Netflix’s US Twitter account appeared first on WeLiveSecurity

Instant Verification lets mobile users authenticate themselves without an SMS