Menu

Category Archives: Security

Articles about security

LinuxSecurity.com: Rebase to upstream 4.4.3: http://www.freeipa.org/page/Releases/4.4.3 —- -Fixes 1395311 – CVE-2016-9575 ipa: Insufficient permission check in certprofile-mod – Fixes 1370493 – CVE-2016-7030 ipa: DoS attack against kerberized servicesby abusing password policy

LinuxSecurity.com: Security fix for CVE-2016-9957, CVE-2016-9958, CVE-2016-9959, CVE-2016-9960,CVE-2016-9961

LinuxSecurity.com: x86 CMPXCHG8B emulation fails to ignore operand size override [XSA-200,CVE-2016-9932] (#1404262) —- ARM guests may induce host asynchronous abort[XSA-201, CVE-2016-9815,

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security fix for BZ#1401985

LinuxSecurity.com: This release fixes CVE-2016-1249 (out-of-bound read when using server-sideprepared statements) and CVE-2016-1251 vulnerability (a use after free whenusing prepared statements).

LinuxSecurity.com: Security fix for CVE-2016-9844

LinuxSecurity.com: The 4.8.14 stable kernel update contains a number of important fixes across thetree.

LinuxSecurity.com: – Security fix for CVE-2016-8670 – Security fix for CVE-2016-6911 – Security fixfor CVE-2016-7568 – For Fedora 26 disabled two tests – they are failing becauseof freetype 2.7 (https://github.com/libgd/libgd/issues/302,https://github.com/libgd/libgd/issues/217)

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security fix for CVE-2016-9844

Risk Level: Very Low. Type: Trojan.

Insecure NAS Device Exposes 350 Ameriprise Investment Accounts
Cyber insurance brokers: If it makes you feel any better, 2016 was not our year either
Akamai buys bot-sniffing startup Cyberfend
Yahoo’s billion account database for sale on the black market
IoT attacks: 10 things you need to know

IoT attacks are on the rise. As the technology becomes more relevant to our lives, we take a look at what the state of play is. The post IoT attacks: 10 things you need to know appeared first on WeLiveSecurity

PayAsUGym breach exposes passwords
Review: Threat hunting turns the tables on attackers
10 biggest hacks of user data in 2016
Bayrob: Romanian auction fraud suspects extradited to the US
Vera for Microsoft protects Office 365 files everywhere
Netgear releases firmware updates for vulnerable routers
Tordow 2.0 Android banking trojan gains root access, mimics ransomware
LinkedIn training arm Lynda.com suffers data breach
FYI! – Your! hacked! Yahoo! account! is! worth! $0.0003!

LinuxSecurity.com: Security Report Summary

security update

LinuxSecurity.com: ARM guests may induce host asynchronous abort [XSA-201, CVE-2016-9815,CVE-2016-9816, CVE-2016-9817, CVE-2016-9818] (#1399747) qemu: Divide by zerovulnerability in cirrus_do_copy (#1399055) [CVE-2016-9921, CVE-2016-9922] Qemu:9pfs: memory leakage via proxy/handle callbacks (#1402278) qemu ioport arrayoverflow [XSA-199, CVE-2016-9637]

LinuxSecurity.com: – update to the new upstream version (50.1.0) – fixed X Window crashes(mozbz#1271100)

New Tech Lets You Use Smartphone, Tablet without Draining their Battery
SQL Injection Attack is Tied to Election Commission Breach
LinkedIn’s training arm resets 55,000 members’ passwords

security update

security update

security update

PCILeech Allows Hacking of Apple Mac Encryption Passcode in Seconds
IoT Nightmare: Wearable Health Gadgets Pose New Kind of Privacy Risks for Users
Hack attack fear scares Canadian exam board away from online tests
KickassTorrents is back as katcr.co domain under its original team
0-days hitting Fedora and Ubuntu open desktops to a world of hurt
The Coolest Hacks Of 2016
‘I told him to cut it out’ – Obama is convinced Putin’s hackers swung the election for Trump

  Who remembers the Atari 2600? Yeah, I don’t either. Just kidding. Maybe. It’s hard to think about the words tech and toys together before the 1990s. However, they were a thing. Kids of the late 70s reveled in the Atari 2600. It became a staple of pop culture—defining a generation of gaming young enthusiasts. […]

Cybersecurity skills gap: it’s big and it’s bad for security

The cybersecurity skills gap is a big problem for organizations struggling to protect rapidly expanding systems from a growing range of threats. We look at how big and what to do about it. The post Cybersecurity skills gap: it’s big and it’s bad for security appeared first on WeLiveSecurity

Houston, we have a problem: ‘App dev stole our radio station’
DDoS Attack by Phantom Squad: EA, Battlefield 1 servers go down
Don’t panic, friends, but the Chinese navy just nicked one of America’s underwater drones
Tordow Banking Trojan – A Grave Threat for Android Users

  Credit card fraud and email scams aren’t the only thing you have to worry about this holiday season. Criminals in the UK are stepping up their game by using radio frequencies to steal cars. Ransomware Uses Credit Card Emails with Infected Attachments A new ransomware variant of Cerber is using fake credit card reports […]

Man accused of taking pics under skirt told by court to share his iPhone Passcode
Banks ‘not doing enough’ to protect against bank-transfer scams
Remote Code Execution Bug Found in Ubuntu Quantal
Nagios Core Patches Root, RCE Vulnerabilities
Apple’s macOS file encryption easily bypassed without the latest fixes
Tales of WordPress Plugin Insecurity Overblown, Researchers Say
DDoS in 2017: Strap yourself in for a bumpy ride
Threatpost News Wrap, December 16, 2016
National Lottery whacked with £3m fine for suspect ticket win
Don’t let cybercriminals ruin Christmas: Beware these 12 threats

With spirits and internet usage at an all time high, there’s no better time for cybercriminals to lure a victim online. Here are 12 threats to be aware of. The post Don’t let cybercriminals ruin Christmas: Beware these 12 threats appeared first on WeLiveSecurity

49% off CyberPower Surge Protector 3-AC Outlet with 2 USB (2.1A) Charging Ports – Deal Alert
US voting machine certification agency probes potential hack
5 things you should do following the Yahoo breach
9 lessons from 25 years of Linux kernel development
Trump, tech leaders avoided encryption and surveillance talk at summit
Band of Big Brothers: Meet Trump’s spy team
Shadow Brokers re-emerge, with NSA’s secret exploits for sale

LinuxSecurity.com: Security Report Summary

German infosec agency urges security review after Yahoo! flensing
Ransomware scum face unified white hat army
Macbook seized or stolen? But you’ve set a FileVault password, right? Ha, it’s useless

security update

The Mirai botnet: what it is, what it has done, and how to find out if you’re part of it

LinuxSecurity.com: Update to Chromium 55. Security fix for CVE-2016-5199, CVE-2016-5200,CVE-2016-5201, CVE-2016-5202, CVE-2016-9651, CVE-2016-5208, CVE-2016-5207,CVE-2016-5206, CVE-2016-5205, CVE-2016-5204, CVE-2016-5209, CVE-2016-5203,CVE-2016-5210, CVE-2016-5212, CVE-2016-5211, CVE-2016-5213, CVE-2016-5214,CVE-2016-5216, CVE-2016-5215, CVE-2016-5217, CVE-2016-5218, CVE-2016-5219,CVE-2016-5221, CVE-2016-5220, CVE-2016-5222, CVE-2016-9650, CVE-2016-5223,CVE-2016-5226, CVE-2016-5225, CVE-2016-5224, CVE-2016-9652

LinuxSecurity.com: – update to the new upstream version (50.1.0) – fixed X Window crashes(mozbz#1271100)

LinuxSecurity.com: * Security fix for CVE-2016-9888

LinuxSecurity.com: Disable insecure FLX plugin (rhbz#1397441)

LinuxSecurity.com: vmncdec: Sanity-check width/height before using it —- Remove insecure nsfplugin (#1395126)

Dear hackers, Ubuntu’s app crash reporter will happily execute your evil code on a victim’s box
ThePirateBay and Four Other Websites to be Blocked in Australia

security update

10 Ways to Protect Your WordPress Site You Didn’t Know About

LinuxSecurity.com: Update to Chromium 55. Security fix for CVE-2016-5199, CVE-2016-5200,CVE-2016-5201, CVE-2016-5202, CVE-2016-9651, CVE-2016-5208, CVE-2016-5207,CVE-2016-5206, CVE-2016-5205, CVE-2016-5204, CVE-2016-5209, CVE-2016-5203,CVE-2016-5210, CVE-2016-5212, CVE-2016-5211, CVE-2016-5213, CVE-2016-5214,CVE-2016-5216, CVE-2016-5215, CVE-2016-5217, CVE-2016-5218, CVE-2016-5219,CVE-2016-5221, CVE-2016-5220, CVE-2016-5222, CVE-2016-9650, CVE-2016-5223,CVE-2016-5226, CVE-2016-5225, CVE-2016-5224, CVE-2016-9652

LinuxSecurity.com: – update to the new upstream version (50.1.0) – fixed X Window crashes(mozbz#1271100)

DNSChanger Exploit Kit Hijacks Routers, Not Browsers
Microsoft, Google to Block Flash by Default in Edge, Chrome

LinuxSecurity.com: This updates includes a rebase from tomcat 8.0.38 up to 8.0.39 which resolvesmultiple CVEs: * #1397493 – CVE-2016-6816 CVE-2016-6817 CVE-2016-8735 tomcat:various flaws

LinuxSecurity.com: Apport could be made to run programs as your login if it opened aspecially crafted file.

LinuxSecurity.com: This updates includes a rebase from tomcat 8.0.38 up to 8.0.39 which resolvesmultiple CVEs: * #1397493 – CVE-2016-6816 CVE-2016-6817 CVE-2016-8735 tomcat:various flaws

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: New mozilla-firefox packages are available for Slackware 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: Update LXC to the latest stable version. See[here](https://linuxcontainers.org/lxc/news/) for the list of changes.

LinuxSecurity.com: **Version 1.2.3** – Searching in both contacts and groups when LDAP addressbookwith group_filters option is used – Fix vulnerability in handling of mail()’s5th argument – Fix To: header encoding in mail sent with mail() method (#5475) -Fix flickering of header topline in min-mode (#5426) – Fix bug where folderslist would scroll to top when […]

LinuxSecurity.com: Update LXC to the latest stable version. See[here](https://linuxcontainers.org/lxc/news/) for the list of changes.

This Malware converts your Computer into a Cryptocurrency Miner

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.