Menu

Category Archives: Security

Articles about security

LinuxSecurity.com: This updates includes a rebase from tomcat 8.0.36 up to 8.0.38 which resolvesmultiple CVEs and a problem that 8.0.37 introduces to freeipa: * rhbz#1375581 -CVE-2016-5388 Tomcat: CGI sets environmental variable based on user suppliedProxy request header * rhbz#1390532 – CVE-2016-0762 CVE-2016-5018 CVE-2016-6794CVE-2016-6796 CVE-2016-6797 tomcat: various flaws and includes two additionalCVE fixes along with one […]

LinuxSecurity.com: Security fix for CVE-2016-8864

LinuxSecurity.com: This update backports an upstream patch to fix multiple integer overflows(CVE-2016-9085).

LinuxSecurity.com: This updates includes a rebase from tomcat 8.0.36 up to 8.0.38 which resolvesmultiple CVEs and a problem that 8.0.37 introduces to freeipa: * rhbz#1375581 -CVE-2016-5388 Tomcat: CGI sets environmental variable based on user suppliedProxy request header * rhbz#1390532 – CVE-2016-0762 CVE-2016-5018 CVE-2016-6794CVE-2016-6796 CVE-2016-6797 tomcat: various flaws and includes two additionalCVE fixes along with one […]

LinuxSecurity.com: – update to 1.8.18p1 – fixes CVE-2016-7076

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: The system could be made to crash under certain conditions.

LinuxSecurity.com: The system could be made to crash under certain conditions.

LinuxSecurity.com: The system could be made to crash under certain conditions.

LinuxSecurity.com: The system could be made to crash under certain conditions.

Origin of the beasties: Mirai botnet missing link revealed as DVR player
Army Bug Bounty Building New Relationships with Hackers
DoS technique lets a single laptop take down an enterprise firewall
Adult FriendFinder users get their privates exposed… again – reports
AdultFriendFinder Network Hacked; 412 Million User Accounts Exposed
Pay up or your data gets it. Ransomware highwaymen’s attacks on small biz octuple
Security Sessions: How to prepare for a data breach
Encrypted email sign-ups instantly double in wake of Trump victory
412 million FriendFinder Network accounts said to be exposed in hack
Developers, don’t DDoS your own apps
Google Pixel, Safari, and Microsoft Edge all pwned at PwnFest 2016

LinuxSecurity.com: An update for policycoreutils is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

Risk Level: Very Low. Type: Trojan.

Your body reveals your password by interfering with Wi-Fi

security update

Wireless Brain Interface Can Make the Paralyzed Walk Again

Risk Level: Very Low. Type: Virus, Worm.

Did Facebook tell your friends that you had died?
Hackers Pwned Apple Safari in 20 seconds; Google Pixel in 60 seconds
The worst people you meet doing IT security

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Russia shoves antitrust probe into Microsoft after Kaspersky gripes about Windows 10
Encrypted email service ProtonMail says new users up 100% since Trump victory
Facebook buys stolen passwords on the black market to protect your account

security update

Your online identity is at risk now more than ever. This week’s cyber news update covers the growing threat of online banking attacks and phishing scams across the globe. Tesco Bank Hacked For Millions Tesco’s banking services released a statement earlier this week announcing that several thousand bank accounts had been hacked, resulting in the theft […]

Type: Vulnerability. Microsoft SQL Server is prone to a privilege-escalation vulnerability; fixes are available.

Computer System of Canadian Casino Hacked; Financial Data Stolen
Hackers Disclose Easily Exploitable Flaws in Microsoft Edge and VMware
Graham Cluley on Jenny Radcliffe’s new podcast, ‘The Human Factor’
BlackNurse Low-Volume DoS Attack Targets Firewalls
Pawn Storm used Microsoft zero-day in spear-phishing attacks before patch
Join the Q: British intel agencies seek tech-savvy apprentices
Capgemini sloppily leaks data of 780,000 Michael Page job seekers to anyone on the internet
Sednit: A very digested read

This feature offers a very digested read of ESET’s trilogy of research papers on Sednit, one of the most notorious groups of cyberattackers in the world. The post Sednit: A very digested read appeared first on WeLiveSecurity.

Russian banks floored by withering DDoS attacks
OpenSSL Patches High-Severity Denial-of-Service Bug
Google Pixel pwned in 60 seconds
ICO concerned about privacy protection on WhatsApp/Facebook

Concerns over unprotected customer data sharing on WhatsApp and Facebook results in UK Information Commissioner threatening to enforce action. The post ICO concerned about privacy protection on WhatsApp/Facebook appeared first on WeLiveSecurity.

Reg meets ‘Lokihardt’, quite possibly the world’s best hacker
What strange madness is this? Microsoft makes patch data RESTful
Make phishing great again: Hackers prod US think tanks, NGOs amid Trump win shockwaves
Recruitment giant PageGroup hacked, Capgemini dev server blamed for info leak
Adobe Developing Photoshop for Audio Files with Project VoCo
Microsoft to revamp its documentation for security patches
Over 300k Android Devices Infected with Banking Trojan
Signal Audit Reveals Protocol Cryptographically Sound
Top Russian Banks Suffer Powerful DDoS Attacks

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for systemd is now available for Red Hat Enterprise Linux 7.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

Siemens Discloses Local Privilege Escalation Bug in SCADA Gear
Yahoo Tells SEC It Knew About Data Breach in 2014
Left-wing website blames breach on pro-Trump trolls
Apple ID smishing evolves to lure more victims

Smishing is nothing new. But that doesn’t mean that the criminals hell bent on stealing Apple ID password are resting on their laurels. The post Apple ID smishing evolves to lure more victims appeared first on WeLiveSecurity.

Some! at! Yahoo! knew! about! mega-breach! as! early! as! 2014!
OAuth 2.0 Hack Exposes 1 Billion Mobile Apps to Account Hijacking
Tesco Bank Suffered Data Breach; Thousands of Accounts Compromised
9% off Nest Cam Indoor Security Camera – Deal Alert
Brand new TalkTalk customer is targeted by phone scammer
Google punishes web backsliders in Chrome
Worries and uncertainty cloud outlook for digital privacy under President Trump
Yahoo investigating if insiders knew of hack
What went wrong at Tesco Bank?
Some Yahoo staff knew in 2014 that it had been hacked
Google fixes Safe Browsing security loophole

Google has announced new measures that resolve a security loophole that allows certain websites to circumnavigate its Safe Browsing service. The post Google fixes Safe Browsing security loophole appeared first on WeLiveSecurity.

Hackers cook god-mode remote exploits against Edge, VMware in world-first
Tesco Bank not alone in being targeted by Retefe malware

Tesco Bank, which recently saw thousands of its customers lose funds to cybercriminals, has been found on the target list of the so-called Retefe malware. The post Tesco Bank not alone in being targeted by Retefe malware appeared first on WeLiveSecurity.

How to avoid DDoSing yourself
IoT worm can hack Philips Hue lightbulbs, spread across cities
$10m of Bangladeshi SWIFT heist ended up in Filipino Casino

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

LinuxSecurity.com: This update contains security fix for CVE-2016-8883, CVE-2016-8882,CVE-2016-8881, CVE-2016-8880, CVE-2016-8884, CVE-2016-8885, CVE-2016-8887,CVE-2016-8886. —- New version of jasper is available (jasper-1.900.13).Security fix for CVE-2016-8690, CVE-2016-8691, CVE-2016-8692, CVE-2016-8693.—- New version of jasper is available (1.900.3) —- Security fix forCVE-2016-2089 —- New version of jasper is available.

LinuxSecurity.com: – fixed permissions of initramfs file, if microcode is prepended(CVE-2016-8637)

LinuxSecurity.com: Security fix for CVE-2016-5181, CVE-2016-5182, CVE-2016-5183, CVE-2016-5184,CVE-2016-5185, CVE-2016-5187, CVE-2016-5188, CVE-2016-5192, CVE-2016-5189,CVE-2016-5186, CVE-2016-5191, CVE-2016-5190, CVE-2016-5193, CVE-2016-5194Security fix for CVE-2016-5198 Update to new stable, 54.0.2840.90.

LinuxSecurity.com: several qemu security fixes

LinuxSecurity.com: Security fix for CVE-2016-5181, CVE-2016-5182, CVE-2016-5183, CVE-2016-5184,CVE-2016-5185, CVE-2016-5187, CVE-2016-5188, CVE-2016-5192, CVE-2016-5189,CVE-2016-5186, CVE-2016-5191, CVE-2016-5190, CVE-2016-5193, CVE-2016-5194Security fix for CVE-2016-5198 Update to new stable, 54.0.2840.90.

Fatigue fears over bug bounty programs
Locky Targets OPM Breach Victims

security update

Fake pharmacy sites gets crafty with modified goodbye messages

Type: Vulnerability. Microsoft Office is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Office is prone to a remote memory-corruption vulnerability; fixes are available.