Menu

Category Archives: Security

Articles about security

Surveillance Middlemen Make it Harder to Track Who’s Responsible For Hacks
Long-Secret Stingray Manuals Detail How Police Can Spy on Phones
Microsoft Intune to support Android for Work
Google offers $200K for top prize in new Android hack challenge
Hackers smear Olympic athletes with data dump of medical files
US National Security Agency gets CREST smile
So, Gov.UK infosec in 2015. ‘Chaotic’. Cost £300m. NINE THOUSAND data breaches…
Logins for US Navy, NASA’s JPL among US gov logins sold on deepweb
Great British Block-Off: GCHQ floats plan to share its DNS filters
Top infosec vendors, cops, liberate thousands from ransomware
Researcher reports XSS hole in Google France
Sports doping agency WADA says hackers lifted Olympic athletes’ medical records

Dawid Golunski discovered that the mysqld_safe wrapper provided by the MySQL database server insufficiently restricted the load path for custom malloc implementations, which could result in privilege escalation. The vulnerability was addressed by upgrading MySQL to the new upstream version 5.5.52, which includes additional changes, such as performance improvements, bug fixes, new features, and possibly […]

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

A patchtastic day for Flash and Windows users – don’t delay!
Using a thing made by Microsoft, Apple or Adobe? It probably needs a patch today
This man is creating a chatbot for his mom so they can talk after she dies
Hacker jailed after stealing thousands of pounds worth of gold bullion
Microsoft Patches 47 Vulnerabilities with September Patch Tuesday
‘Now the cyber is so big’ says Donald Trump
Backdoor targeting corporate data through… Microsoft Publisher files?
iOS 10 Security Updates Move to HTTPS

Red Hat: 2016:1858-01: ruby193-rubygem-actionpack: Moderate Advisory Posted by Anthony Pell    An update for ruby193-rubygem-actionpack is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: ruby193-rubygem-actionpack security update Advisory ID: RHSA-2016:1858-01 Product: Red Hat Software Collections […]

Red Hat: 2016:1857-01: ror40-rubygem-actionpack: Moderate Advisory Posted by Anthony Pell    An update for ror40-rubygem-actionpack is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: ror40-rubygem-actionpack security update Advisory ID: RHSA-2016:1857-01 Product: Red Hat Software Collections […]

Red Hat: 2016:1855-01: rh-ror42: Moderate Advisory Posted by Anthony Pell    An update for rh-ror42-rubygem-actionview, rh-ror42-rubygem-activerecord, and rh-ror42-rubygem-actionpack is now available for Red Hat Software Collections. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: rh-ror42 security update Advisory ID: RHSA-2016:1855-01 Product: Red Hat Software Collections Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-1855.html Issue date: 2016-09-13 CVE Names: CVE-2016-6316 CVE-2016-6317 […]

Red Hat: 2016:1856-01: rh-ror41-rubygem-actionview: Moderate Advisory Posted by Anthony Pell    An update for rh-ror41-rubygem-actionview is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: rh-ror41-rubygem-actionview security update Advisory ID: RHSA-2016:1856-01 Product: Red Hat Software Collections […]

An update for libarchive is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: libarchive security update Advisory ID: RHSA-2016:1844-01 Product: Red Hat Enterprise Linux […]

An update for libarchive is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: libarchive security update Advisory ID: RHSA-2016:1850-01 Product: Red Hat Enterprise Linux […]

An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: chromium-browser security update Advisory ID: RHSA-2016:1854-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-1854.html Issue date: 2016-09-12 CVE Names: […]

Adobe Back With New Flash Player Security Update

Risk Level: Very Low. Type: Trojan.

Discovered: September 12, 2016 Updated: September 13, 2016 3:19:08 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Trojan.Riccietex is a Trojan horse that installs potentially malicious software and modifies browser settings […]

Tor Joins Movement Against Expanding Hacking Powers
Anonymous ‘Fancy Bears’ Hack World Anti-Doping Agency (WADA) Again
Judge Rules Use of FBI Malware Is A ‘Search’
No over-the-air update means GM has to recall four million cars to fix fatal software defect
UK oversight body tipped to examine phone snooping tech in prisons
Facebook Post Tagging Scam Steals Your Login Credentials
Generic OS X Malware Detection Method Explained
How encryption molded crypto-ransomware

Ransomware is a major threat that keeps growing over time. According to Cisco’s recent midyear report, it dominates the malware market and is the most profitable malware type in history. By now, it seems unlikely any regular reader of our blog does not already know something about ransomware. If you do not—or would like a […]

Security Solved: Company says their tech renders servers hack proof
DDoS Attacks Up by 75 Percent in Q2 2016
Bad news: MySQL can dish out root access to cunning miscreants
Afraid of online hacks? Worry more about your phone

I talk a lot about the security problems and weaknesses of the internet, as well as the devices connected to it. It’s all true, and we badly need improvements. Yet the irony is that security in our online world is actually better than in our physical world. Think of how many people are scammed by […]

Action Fraud warns of fraudulent anti-fraud warnings posing as Action Fraud
IP telephony biz VoIPtalk quietly admits to possible data breach
Security takes a backseat for uninterrupted, video game marathons

��}ے�ƒ��(A�”i/}o��%�:#YZ�|�gdmG(���f��8��O�1���32_��YA6�M��t�%�ʪ�����ʪ|t��룷�}�����Ww����z���5�b��4t��q��? ��0��u�

Infected Android phones could flood America’s 911 with DDoS attacks
Dropbox apologies for clunky administrator account access on Macs

Risk High Date Discovered September 13, 2016 Description Microsoft Office is prone to a remote memory-corruption vulnerability because it fails to properly handle objects in memory. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions. […]

Risk High Date Discovered September 13, 2016 Description Microsoft Office is prone to a remote memory-corruption vulnerability because it fails to properly handle objects in memory. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions. […]

Risk High Date Discovered September 13, 2016 Description Microsoft Office is prone to a remote memory-corruption vulnerability because it fails to properly handle objects in memory. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions. […]

Risk High Date Discovered September 13, 2016 Description Microsoft Office is prone to a remote memory-corruption vulnerability because it fails to properly handle objects in memory. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions. […]

Risk High Date Discovered September 13, 2016 Description Microsoft Office is prone to a remote memory-corruption vulnerability because it fails to properly handle objects in memory. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions. […]

Risk High Date Discovered September 13, 2016 Description Microsoft Office is prone to a remote memory-corruption vulnerability because it fails to properly handle objects in memory. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions. […]

Risk High Date Discovered September 13, 2016 Description Microsoft Office is prone to a remote memory-corruption vulnerability because it fails to properly handle objects in memory. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions. […]

Risk High Date Discovered September 13, 2016 Description Microsoft Office is prone to a remote memory-corruption vulnerability because it fails to properly handle objects in memory. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions. […]

Risk High Date Discovered September 13, 2016 Description Microsoft Windows is prone to a remote code-execution vulnerability. Successful exploits will allow an attacker to execute arbitrary code on the target system. Failed attacks will cause denial of service conditions. Technologies Affected Microsoft Windows 10 Version 1607 for 32-bit Systems Microsoft Windows 10 Version 1607 for […]

Risk Medium Date Discovered September 13, 2016 Description Microsoft Office is prone to a security vulnerability that may allow attackers to conduct spoofing attacks. An attacker can exploit this issue to perform unauthorized actions; other attacks are also possible. Technologies Affected Microsoft Outlook 2007 Microsoft Outlook 2010 (32-bit editions) Service Pack 2 Microsoft Outlook 2010 […]

Multiple vulnerabilities in OpenJPEG, a JPEG 2000 image compression / decompression library, may result in denial of service or the execution of arbitrary code if a malformed JPEG 2000 file is processed. For the stable distribution (jessie), these problems have been fixed in version 2.1.0-2+deb8u1. We recommend that you upgrade your openjpeg2 packages.

New Windows Patch Policy At Odds With Acceptable Risk
FDA, DHS Investigating St. Jude Device Vulnerabilities
Bitcoin Mining malware infects Seagate Central NAS devices

Debian: 3665-1: openjpeg2: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3665-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff September 11, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : openjpeg2 CVE ID : CVE-2015-6581 CVE-2015-8871 CVE-2016-1924 CVE-2016-7163 Multiple vulnerabilities in OpenJPEG, a JPEG 2000 image compression / decompression library, may result in denial of […]

Slackware: 2016-254-01: gnutls: Security Update Posted by Anthony Pell    New gnutls packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue. [More Info…] [slackware-security] gnutls (SSA:2016-254-01) New gnutls packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue. Here are the details from the […]

Debian: 3664-1: pdns: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3664-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso September 10, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : pdns CVE ID : CVE-2016-5426 CVE-2016-5427 CVE-2016-6172 Debian Bug : 830808 Multiple vulnerabilities have been discovered in pdns, an authoritative DNS server. The Common Vulnerabilities […]

Debian: 3663-1: xen: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3663-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso September 09, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : xen CVE ID : CVE-2016-7092 CVE-2016-7094 CVE-2016-7154 Multiple vulnerabilities have been discovered in the Xen hypervisor. The Common Vulnerabilities and Exposures project identifies the following […]

Ubuntu: 3075-1: Imlib2 vulnerabilities Posted by Anthony Pell    Several security issues were fixed in Imlib2. ========================================================================== Ubuntu Security Notice USN-3075-1 September 09, 2016 imlib2 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: Several security issues were […]

Slackware: 2016-252-01: php: Security Update Posted by Anthony Pell    New php packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…] [slackware-security] php (SSA:2016-252-01) New php packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues. Here are the details from the Slackware 14.2 […]

After sitting down with Hal Lonas to get a deeper look at the inner workings of Webroot, there was no questioning why he’s uniquely qualified to serve as the company’s CTO. And with machine learning getting thrown around as the hot new buzzword, it was refreshing to hear Hal’s down-to-earth perspective on motivations, ideas, solutions […]

Malware Authors Rename Ransomware After Emsisoft’ Security Researcher
Critical MySQL Vulnerability Disclosed
Meet DDoSaaS: Distributed Denial of Service-as-a-Service
How 911 emergency services across the United States could be knocked offline by a mobile botnet
Sniffing your storage could lead to sensitive leaks, warn infosec bods
Crafty GovRAT malware is growing, targeting U.S. government employees
Keep the faith: A vote for voting systems
Bank’s data center knocked offline by really loud noise
FBI arrests Crackas With Attitude who allegedly hacked CIA boss’s AOL account
Discover VASCO’s top 10 tips for a successful and secure Mobile First Strategy! Register now for this webinar
Israeli Pentagon DDoSers explain their work, get busted by FBI
Peccant pwners post 670,000 Pokémon punter MD5 passwords
SOHOpeless Seagate NAS boxen become malware distributors
33 million CLEARTEXT creds for Russian IM site dumped by chap behind Last.FM mess
PCI Council wants upgradeable credit card readers … next year
Linode fends off multiple DDOS attacks
BDSwiss Trading Hacked; Sensitive Data, Passports, Credit Cards Leaked
FBI Arrests Two Alleged Hackers of Crackas With Attitude Group
US Emergency Phone System ‘911’ Can Be Hacked Through TDoS Attack
Exile Mod Gaming Forum Hacked; 12,000 Accounts Leaked
White House appoints first Federal Chief Information Security Officer
WordPress urges users to update now to fix critical security holes
This USB stick will fry your unsecured computer
CallJam malware infects Androids and keeps ringing premium rate numbers

Multiple vulnerabilities have been discovered in pdns, an authoritative DNS server. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2016-5426 / CVE-2016-5427 Florian Heinz and Martin Kluge reported that the PowerDNS Authoritative Server accepts queries with a qname’s length larger than 255 bytes and does not properly handle dot inside labels. A remote, […]

Seagate sued by its own staff for leaking personal info to identity thieves
Samsung Galaxy Note 7 on Burning Spree; Burns House and Jeep

It was discovered that incorrect SASL authentication in the Inspircd IRC server may lead to users impersonating other users. For the stable distribution (jessie), this problem has been fixed in version 2.0.17-1+deb8u2. For the unstable distribution (sid), this problem has been fixed in version 2.0.23-1. We recommend that you upgrade your inspircd packages.