Menu

Category Archives: Security

Articles about security

Apple, Facebook and Coinbase coughed data to finger alleged pirate king
How Apple and Facebook Helped US to Arrest Kickass Torrents’ Owner

Several security issues have been discovered in the Squid caching proxy. CVE-2016-4051: CESG and Yuriy M. Kaminskiy discovered that Squid cachemgr.cgi was vulnerable to a buffer overflow when processing remotely supplied inputs relayed through Squid. CVE-2016-4052: CESG discovered that a buffer overflow made Squid vulnerable to a Denial of Service (DoS) attack when processing ESI […]

Google Fixes 48 Bugs, Sandbox Escape, in Chrome
Firefox to Block Flash in August, Disable in 2017

An update for java-1.6.0-sun is now available for Oracle Java for Red Hat Enterprise Linux 5, Oracle Java for Red Hat Enterprise Linux 6, and Oracle Java for Red Hat Enterprise Linux 7. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: java-1.6.0-sun security update Advisory ID: RHSA-2016:1477-01 Product: Oracle Java for Red Hat Enterprise Linux […]

An update for java-1.7.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 5, Oracle Java for Red Hat Enterprise Linux 6, and Oracle Java for Red Hat Enterprise Linux 7. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: java-1.7.0-oracle security update Advisory ID: RHSA-2016:1476-01 Product: Oracle Java for Red Hat Enterprise Linux […]

An update for java-1.8.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 6 and Oracle Java for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: java-1.8.0-oracle security update Advisory ID: RHSA-2016:1475-01 Product: Oracle Java […]

Red Hat: 2016:1474-01: openstack-neutron: Low Advisory Posted by Anthony Pell    An update for openstack-neutron is now available for Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Low: openstack-neutron security, bug fix, […]

Red Hat: 2016:1473-01: openstack-neutron: Low Advisory Posted by Anthony Pell    An update for openstack-neutron is now available for Red Hat OpenStack Platform 8.0 (Liberty). Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Low: openstack-neutron security and bug fix update Advisory ID: RHSA-2016:1473-01 […]

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: java-1.8.0-openjdk security update Advisory ID: RHSA-2016:1458-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2016:1458 Issue […]

Gentoo: 201607-16 arpwatch: Privilege escalation Posted by Anthony Pell    arpwatch is vulnerable to the escalation of privileges. – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – Gentoo […]

Gentoo: 201607-15 NTP: Multiple vulnerabilities Posted by Anthony Pell    Multiple vulnerabilities have been found in NTP, the worst of which could lead to Denial of Service. – – – – – – – – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201607-14 Ansible: Privilege escalation Posted by Anthony Pell    A vulnerability in Ansible may allow local attackers to gain escalated privileges or write arbitrary files. – – – – – – – – – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201607-13 libbsd: Arbitrary code execution Posted by Anthony Pell    A buffer overflow in libbsd might allow remote attackers to execute arbitrary code. – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201607-12 Exim: Arbitrary code execution Posted by Anthony Pell    A local attacker could execute arbitrary code by providing unsanitized data to a data source or escalate privileges. – – – – – – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201607-11 Bugzilla: Multiple vulnerabilities Posted by Anthony Pell    Multiple vulnerabilities have been found in Bugzilla, the worst of which could lead to the escalation of privileges. – – – – – – – – – – – – – – – – – – – – – – – – – – – […]

Bosses at UK infosec biz Quadsys confess to hacking rival reseller

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

EFF Files Lawsuit Challenging DMCA’s Restrictions on Security Researchers
15 Vulnerabilities in SAP HANA Outlined
Playstation chief Shuhei Yoshida has his Twitter hacked by OurMine
GOP delegates suckered into connecting to insecure Wi-Fi hotspots
How to secure your cyber infrastructure from threats like ransomware?
Ransomware gang: How can I extort you today?
Turns out that you can’t trust ‘Trump free Wifi’ at the Republican National Congress
Cisco patches critical exposure in management software
Petition urges Apple not to release technology for jamming phone cameras
IoT Insecurity: Pinpointing the Problems
Hackers are targeting the Rio Olympics, so watch out for these cyberthreats
Drupalgeddon hits Warframe – nearly 800,000 gamers’ account details being sold on the net
Analyzing Mr. Robot: S02E01

��}ے�F���(QsD�”�[߻�:RKkF����h����$� ƥٴ���p�m^�e#6b����OΗlfV���l�c�J3�@�*+++3+3+�����oO�~x�}}�����&��a��5�jߟ֘��}5������w�n���Oy� ֠ν� 7��{�D�MyhPQ��ٗ�ډpC�����5f�_�Zȯ�66xhN?�� G�^������g��ډ�zFh�,��/��|Uט�A���3O�a��̶���◶�5��b�k���h�i8|Э�4b�p-�C�]r��& “���aϸ�/����}�G;���s����7�����M����o.��U����ipi8�e��t3`O^�����n����vv:����W’�v�=��%,��L�v/�ϝA-�&�B��”�56�mj�o��u=��!��f�;�%��v8�M1m�����$�”봻z�MOO”�`��?��W��j�#��Og�������V��74dWS�w���GŸ��-�*�~|��آ2�K�8���� �ӹLJ7>0]jPa!oO��܈B;�r%y�5p(�n��&*”ܸ,��?��5b߻)#�$^�&x���*{Ԛz�����T�%̼J����ta��E��?�%�6L�n��Z��1�)-�Wm�w����w�W�$r#x���0�]�0uR�CGкu���Z0wC�jN9J����v�DT������c;= b~��/��F��{�в���Kh+1B��ۏ-�p��)Z#b�f)���E�V=�z�;^��bQfNN�����t����������v:{�>�v��C(ߦc�6s�Ks��/����wJ>0�{�k�4��O��/f5�-�)�S��”�hSKۧ�` �������,�J%���`+0�PD��İx�o��C�t�6�����tf�|G���”x��)[��C˅�H�Y�PP�~����q��M ���`��� plm�3iiZw���j|d8?�B��䌘��}Z���Fԁ�d�M�/�+{E=‰OQ`�,a��B��’�e�s�€�p�l�|c���!��ۓ�h��R)1�@����a2ԡ����R�@�1� �hyAhK%5�� ����u�J�>5C�Y��}uʸ�^����K8�㥟�#V���Q�����M ��]�`3nN���J`�)���n�m�����M �0�n�V���l����A��1� y����@�WF5U=.�uo��a�t%�k�u@�I������ ��.��^��%����&>/�roE5*K�,Pd�3�2��@�%o?�*]v�a�A��R�X;���E�A?Wi��yN���O �������OJ’oY�)��Q��[1����,�G��~��O��Y�-� ��8��`�e�� ��u�ܡ���nw#]�}���Fk���l)ӡWFȃ�}�cy[�[��JykO��5L8�-{mt�r@o���fF���f�B�wrc�5L�gU}U�Be?�%蛬��K������$j�TPMq� �la�=`�s|*w���l2��?.mn ӿM+��+`�,_x���Y��N*ĴyX�V�Zq���,l�� � /�@U�H} 8?����d�A��G!-�8i’����)�}g���w3’�B�� +6�!��`$Ŋ���߾��E�j�E����b����i���d�X�7�*��b� f�gp�gh���F>���0/�ͮ��P�f{_-s�Q��bVWղ�U s/]�J˜�V�Ug��f��d{m�7�G����彁R�z5����YW_��)1�9m7: ��>��8�E��`�����=���8�D�F�D�9�^�lu��b~K�z�ա��i��9Pd�1�z�@oR�d�pl�=4���L~�|ò���i�ţm(ߣգfY�i�e �֓�;��2�`�N~ti!IWg0.VX�?~�ﰼLӸBF3��`�}M�V⽘6����@.yB=��šIB�7&��] [ph�v��Mj�`_̡����Eǒ�.�~�ygt� ���A1��2x/���;�铱�9Q@)�R�a 6g�*,Iõ��4�W�Gn�f[��t�%M���gՑz)1�V�R��29�>�`�,�cp/V@��=�])}lQX9;n9�’ ��r�sv^��-���c�%uOlTB� 7��v��&o���}*E�Ȁ���k��qՅ��2�oGߺ�On2͖7 ��e���$�Fhw�b��1xt��f���ի��T}���MUW8*���ٌ`� �}a�Di=�zŴ��x��-��§�휏|&YF?nd#YcFVӔF�.Q�#�4:��”�5LF+� ���+��M���tL�?M0i /��*�e#_fb oQuzr�)Ώ�~C��3��e`Tb����~�}##]��7�����ӥ���㧴��w�ɽ��xL�+}Q�����նU/��L�x�T��:s|���;?�����[�?o���5����U������[���5{ �|ޚ�yk�j��fޚ}b}ޚ�yk��ٹ&>o���5������P��7����?�� “6�t(1p�et�rw��Q -�!�ۉ�-�5�D�g�F�ϻID��I=�DӡKr�⁘��_�6f-�J��~F4O�p����B��9�F�H�J�kof�{�!������o��o����U

Microsoft and pals re-write arms control pact to save infosec industry
Asian nations mull regional ‘Europol’ in fight against cybercrime
Kickass Torrents Goes Down; Owner Arrested
Massive DDoS Attack Shut Down Several Pro-ISIS Websites

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Users of iPhones and Macs must update to avoid Stagefright-like bug
Everyone’s favorite infosec biz – Blue Coat – must cough up $40m to rival in patent rip-off row
Salesforce will only support Nexus and Samsung Galaxy phones to avoid Android fragmentation
Firefox to banish hidden Flash files – and kill off sneaky ad snoopers
Oracle’s monster security update fixes Java, database bugs
SoakSoak Botnet Pushing Neutrino Exploit Kit and CryptXXX Ransomware

Anti-virus software is a program or set of programs that are designed to prevent, search for, detect, and remove viruses, and other forms of malware such as worms, trojans, adware, and more. As our world continues to become ever more connected, anti-virus remains critical for users seeking to keep their devices protected. However, it’s vital that the […]

US Congress websites recovering after three-day DDoS attack
Oracle issues largest patch bundle ever, fixing 276 security flaws
Oracle Patches Record 276 Vulnerabilities with July Critical Patch Update
How Bad is the North Korean Cyber Threat?
Feds shut down tech support scammers, freeze assets
Jackware: When connected cars meet ransomware

2016 is already being dubbed “The Year of Ransomware” and ransomware features prominently in my upcoming “Mid-Year Threat Review” webinar. In that webinar I will also be talking about the IoT (Internet of Things) and more specifically the IoIT (the Internet of Insecure Things); mainly because risks arising from the latter are on the rise. […]

New HIPAA guidance addresses ransomware
Google says government requests for user data at all-time high
Russian security firm linked to cybercrime gang
Hacker shows Reg how one leaked home address can lead to ruin
What’s big and red and squashes 276 bugs, 19 of them critical?
Flaws found in security products from AVG, Symantec and McAfee
WordPress admin? Thinking of spending time with the family? Think again
WhatsApp gets another Brazilian whack as magistrate blocks it again

Scott Geary of VendHQ discovered that the Apache HTTPD server used the value of the Proxy header from HTTP requests to initialize the HTTP_PROXY environment variable for CGI scripts, which in turn was incorrectly used by certain HTTP client implementations to configure the proxy for outgoing HTTP requests. A remote attacker could possibly use this […]

Anonymous DDoS Rio Court Website for Blocking WhatsApp in Brazil
Apple kills eavesdrop bug in FaceTime
What keeps former New York Mayor Rudy Giuliani awake at night?

It was discovered that Django, a high-level Python web development framework, is prone to a cross-site scripting vulnerability in the admin’s add/change related popup. For the stable distribution (jessie), this problem has been fixed in version 1.7.7-1+deb8u5. We recommend that you upgrade your python-django packages.

A vulnerability was discovered in mysql-connector-java, a Java database (JDBC) driver for MySQL, which may result in unauthorized update, insert or delete access to some MySQL Connectors accessible data as well as read access to a subset of MySQL Connectors accessible data. The vulnerability was addressed by upgrading mysql-connector-java to the new upstream version 5.1.39, […]

The Troubling State of Security Cameras; Thousands of Devices Vulnerable
BlackBerry chief: We don’t have to make phones to make phones

Debian: 3622-1: python-django: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3622-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso July 18, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : python-django CVE ID : CVE-2016-6186 It was discovered that Django, a high-level Python web development framework, is prone to a cross-site scripting vulnerability in the […]

An update for httpd is now available for Red Hat Enterprise Linux 5 and Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: httpd security update Advisory ID: RHSA-2016:1421-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2016:1421 Issue […]

An update for httpd is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: httpd security and bug fix update Advisory ID: RHSA-2016:1422-01 Product: Red […]

Debian: 3621-1: mysql-connector-java: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3621-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso July 18, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : mysql-connector-java CVE ID : CVE-2015-2575 A vulnerability was discovered in mysql-connector-java, a Java database (JDBC) driver for MySQL, which may result in unauthorized update, insert […]

Red Hat: 2016:1420-01: httpd24-httpd: Important Advisory Posted by Anthony Pell    An update for httpd24-httpd is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: httpd24-httpd security update Advisory ID: RHSA-2016:1420-01 Product: Red Hat Software Collections […]

DDoS trends: Bigger, badder but not longer

How are they a security threat? People, not computers, create computer threats. Computer predators victimize others for their own gain. Give them access to the internet — and to your PC — and the threat they pose to your security increases exponentially. Computer hackers are unauthorized users who break into computer systems in order to steal, […]

Google Chrome Malware Leads to Sketchy Facebook Likes
Carbon Black snaps up cloud-dwelling threat-sniffing ‘next-gen AV’
Ex-Cardinals Exec Sentenced Four Years for Astros Hack
Steemit experienced hack, theft of user funds, and DDoS attack
Baton Rouge City Website Hacked Against Alton Sterling’s Death
IoT baby monitor style hacks still a threat

APPLE-SA-2016-07-18-6 iTunes 12.4.2 Subject: APPLE-SA-2016-07-18-6 iTunes 12.4.2 From: Apple Product Security Date: Mon, 18 Jul 2016 17:26:55 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-07-18-6 iTunes 12.4.2 iTunes 12.4.2 for Windows is now available and addresses the following: libxml2 Impact: Multiple vulnerabilities in libxml2 Description: Multiple memory corruption issues were addressed through improved memory handling. […]

APPLE-SA-2016-07-18-5 Safari 9.1.2 Subject: APPLE-SA-2016-07-18-5 Safari 9.1.2 From: Apple Product Security Date: Mon, 18 Jul 2016 17:22:29 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-07-18-5 Safari 9.1.2 Safari 9.1.2 is now available and addresses the following: WebKit Available for: OS X El Capitan v10.11.6 Impact: Visiting a malicious website may disclose image data from another […]

APPLE-SA-2016-07-18-4 tvOS 9.2.2 Subject: APPLE-SA-2016-07-18-4 tvOS 9.2.2 From: Apple Product Security Date: Mon, 18 Jul 2016 17:21:14 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-07-18-4 tvOS 9.2.2 tvOS 9.2.2 is now available and addresses the following: CoreGraphics Available for: Apple TV (4th generation) Impact: A remote attacker may be able to execute arbitrary code Description: […]

APPLE-SA-2016-07-18-3 watchOS 2.2.2 Subject: APPLE-SA-2016-07-18-3 watchOS 2.2.2 From: Apple Product Security Date: Mon, 18 Jul 2016 17:20:02 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-07-18-3 watchOS 2.2.2 watchOS 2.2.2 is now available and addresses the following: CoreGraphics Available for: Apple Watch Sport, Apple Watch, Apple Watch Edition, and Apple Watch Hermes Impact: A remote attacker […]

APPLE-SA-2016-07-18-2 iOS 9.3.3 Subject: APPLE-SA-2016-07-18-2 iOS 9.3.3 From: Apple Product Security Date: Mon, 18 Jul 2016 17:17:26 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-07-18-2 iOS 9.3.3 iOS 9.3.3 is now available and addresses the following: Calendar Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later Impact: A […]

APPLE-SA-2016-07-18-1 OS X El Capitan v10.11.6 and Security Update 2016-004 Subject: APPLE-SA-2016-07-18-1 OS X El Capitan v10.11.6 and Security Update 2016-004 From: Apple Product Security Date: Mon, 18 Jul 2016 17:14:08 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-07-18-1 OS X El Capitan v10.11.6 and Security Update 2016-004 OS X El Capitan v10.11.6 and Security […]

If you find the FBI’s cybercrime webpage can you let them know?
Security software that uses ‘code hooking’ opens the door to hackers
Hacker Steals Amazon Marketplace Credentials from 3rd Party Server
Apple fixes FaceTime eavesdropping bug, other other flaws may remain
Your antivirus doesn’t like Ammyy. And fraudsters will use that to RAT you out (again)
Malicious scripts gaining prevalence in Brazil

Had we looked at a map of malware detections in Brazil a year ago, we would have seen that the two main computer threats were the downloaders that installed banking trojans, and the banking trojans themselves. Today the situation remains the same, but with an extra special ingredient – while threats used to be Windows .exe […]

Apple Fixes Vulnerabilities Across OS X, iOS, Safari