Menu

Category Archives: Security

Articles about security

Facebook is Listening to Users’ Conversations, Here’s How to Stop it

An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: chromium-browser security update Advisory ID: RHSA-2016:1190-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://access.redhat.com/errata/RHSA-2016:1190 Issue date: 2016-06-01 CVE Names: […]

Debian: 3591-1: imagemagick: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3591-1 security@debian.org https://www.debian.org/security/ Luciano Bello June 01, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : imagemagick CVE ID : CVE-2016-5118 Debian Bug : 825799 Bob Friesenhahn from the GraphicsMagick project discovered a command injection vulnerability in ImageMagick, a program suite […]

Ubuntu: 2989-1: Linux kernel vulnerabilities Posted by Anthony Pell    Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2989-1 June 01, 2016 linux vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: […]

Debian: 3590-1: chromium-browser: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3590-1 security@debian.org https://www.debian.org/security/ Michael Gilbert June 01, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : chromium-browser CVE ID : CVE-2016-1667 CVE-2016-1668 CVE-2016-1669 CVE-2016-1670 CVE-2016-1672 CVE-2016-1673 CVE-2016-1674 CVE-2016-1675 CVE-2016-1676 CVE-2016-1677 CVE-2016-1678 CVE-2016-1679 CVE-2016-1680 CVE-2016-1681 CVE-2016-1682 CVE-2016-1683 CVE-2016-1684 CVE-2016-1685 CVE-2016-1686 CVE-2016-1687 CVE-2016-1688 […]

Ubuntu: 2988-1: LXD vulnerabilities Posted by Anthony Pell    Several security issues were fixed in LXD. ========================================================================== Ubuntu Security Notice USN-2988-1 May 31, 2016 lxd vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 Summary: Several security issues were fixed in LXD. Software Description: […]

Ubuntu: 2987-1: GD library vulnerabilities Posted by Anthony Pell    The GD library could be made to crash or run programs if it processed aspecially crafted image file. ========================================================================== Ubuntu Security Notice USN-2987-1 May 31, 2016 libgd2 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – […]

Ubuntu: 2986-1: dosfstools vulnerabilities Posted by Anthony Pell    dosfstools could be made to crash or run programs if it processed aspecially crafted filesystem. ========================================================================== Ubuntu Security Notice USN-2986-1 May 31, 2016 dosfstools vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 – Ubuntu […]

Anonymous Linked Team Hacks Kenyan Oil Firm Against Police Brutality
Ransomware demands are working, fueling an increase in attacks
Myspace data breach: 360 million accounts affected

��}�r۸���j�aN��D$u�-v���ɜ��r۱��Ηd] I�)�CR�u2�:��_�n�� [�Op�MΓl7R�E�,+���d.�H��ht7�����o�O~�|��Uǣd���]�Ə’ #:��Q����ņ�9�V?Рν�#j��{���{5b/��%����”,P �����O��?b�d��~�ڴ5x��쿳�5�o����i_u.�ZǗ��vB�fK{�b��}�tgo︽��|���l��;~���i�#`�`�^pA”�w�8��4Q H����NkdL]��ja��u���O�SsJ}��ԙD^236���!����؂���28,�C�����7r:�b��#�7o��d�%#�A���8���^���v(ZؤQ���^��=���q�$Hbb�I���5�T��4v”/,�R ^�h/!S;�XOf� ��6n�x�x.� c$��MtJf8��CF�����$ٗ4C�8>�)��ꍩYЁ��9v�`3��i7[{V�mYc�G�`�>Т![4��1GL/�XH�dƥ�g( �hp����t��q;Jְ��Uo�Y�^�_ׄ�j�̙ �4�:j�ǖ`�W���(�pz[�x�&:k��u��b�$g�0q�$��0�0�v��>�����җ+#ـV���`b=$-:���̊�` �>?$Mb6�A�%h��,B!�i���#�N�*|B�%��W�_o=+6u����:�ܮ�BX��g�^����D,F�gG1g��9�����Ff��c`�H��.�WO�W�XxT’��=AU�e��-n�3ShfaV#/F4�[Or-���”��ax���QJP�6�v��™�>6���t`O�$�{�L!�b`_zwD}�R!f��ͻ`��M@U��92:h�l7C�h���:�F��>�J�;2�K�$���`��$_1lӁ83���!z�˄F33,P�i��������0*�aC�6��dz wsF#�F����”x5���Y4�9����76����N���=H����-s�l݌����(]�jPo˜W@_����������>sg$�H�~�6s�|+{�x��Yt����T�Su^�բNp1y3-S�u��V*a�)�Z-������ۮ1���(�@Fo�(TI�97.���(�BzF���;E��J��v/A�Q��9#���3�!�7 `��d1��8���I����3Z�C�R�� �.�;�/8�tYK�Z���S��n�,�=��:,�C���ɘ

Printer security: Is your company’s data really safe?
IPv6 support finally coming to Fail2Ban with next major release
A Car’s Computer Can ‘Fingerprint’ You in Minutes Based on How You Drive
65 million Tumblr account records are up for sale on the underground market
Zero-days aren’t the problem — patches are

There’s a widely held view that our world is full of uber hackers who are too brilliant to stop. Thus, we should fear zero-day attacks because they’re our biggest problem. Nothing could be further from the truth. Most hackers follow the path created by a very few smart ones — and zero days make up […]

Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-1667 Mariusz Mylinski discovered a cross-origin bypass. CVE-2016-1668 Mariusz Mylinski discovered a cross-origin bypass in bindings to v8. CVE-2016-1669 Choongwoo Han discovered a buffer overflow in the v8 javascript library. CVE-2016-1670 A race condition was found that could cause the renderer process to reuse ids […]

Bob Friesenhahn from the GraphicsMagick project discovered a command injection vulnerability in ImageMagick, a program suite for image manipulation. An attacker with control on input image or the input filename can execute arbitrary commands with the privileges of the user running the application. This update removes the possibility of using pipe (|) in filenames to […]

It was discovered that a NULL pointer dereference in the Nginx code responsible for saving client request bodies to a temporary file might result in denial of service: Malformed requests could crash worker processes. For the stable distribution (jessie), this problem has been fixed in version 1.6.2-5+deb8u2. For the unstable distribution (sid), this problem has […]

Stealth Falcon Spyware Used by UAE to Intimidate Dissidents, Journalists

Several vulnerabilities have been discovered in gdk-pixbuf, a toolkit for image loading and pixel buffer manipulation. A remote attacker can take advantage of these flaws to cause a denial-of-service against an application using gdk-pixbuf (application crash), or potentially, to execute arbitrary code with the privileges of the user running the application, if a malformed image […]

An update for ntp is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: ntp security update Advisory ID: RHSA-2016:1141-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2016:1141 Issue […]

Slackware: 2016-152-01: imagemagick: Security Update Posted by Anthony Pell    New imagemagick packages are available for Slackware 14.0, 14.1, and -current to fix a security issue. [More Info…] [slackware-security] imagemagick (SSA:2016-152-01) New imagemagick packages are available for Slackware 14.0, 14.1, and -current to fix a security issue. Here are the details from the Slackware 14.1 […]

Slackware: 2016-152-02: mozilla-thunderbird: Security Update Posted by Anthony Pell    New mozilla-thunderbird packages are available for Slackware 14.1 and -current to fix security issues. [More Info…] [slackware-security] mozilla-thunderbird (SSA:2016-152-02) New mozilla-thunderbird packages are available for Slackware 14.1 and -current to fix security issues. Here are the details from the Slackware 14.1 ChangeLog: +————————–+ patches/packages/mozilla-thunderbird-45.1.1-i486-1_slack14.1.txz: Upgraded. […]

An update for squid is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: squid security update Advisory ID: RHSA-2016:1139-01 Product: Red Hat Enterprise […]

An update for squid is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: squid security update Advisory ID: RHSA-2016:1138-01 Product: Red Hat Enterprise […]

An update for squid34 is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: squid34 security update Advisory ID: RHSA-2016:1140-01 Product: Red Hat Enterprise […]

Multiple vulnerabilities have been found in Firefox, Thunderbird, Network Security Services (NSS), and NetScape Portable Runtime (NSPR) with the worst of which may allow remote execution of arbitrary code. – – – – – – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201605-05 Linux-PAM: Multiple vulnerabilities Posted by Anthony Pell    Multiple vulnerabilities have been found in Linux-PAM, allowing remote attackers to bypass the auth process and cause Denial of Service. – – – – – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201605-04 rsync: Multiple vulnerabilities Posted by Anthony Pell    Multiple vulnerabilities have been found in rsync, the worst of which could allow remote attackers to write arbitrary files. – – – – – – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201605-03 libfpx: Denial of Service Posted by Anthony Pell    A double free vulnerability has been discovered in libfpx that allows remote attackers to cause a Denial of Service. – – – – – – – – – – – – – – – – – – – – – – – – – […]

Debian: 3589-1: gdk-pixbuf: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3589-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso May 30, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : gdk-pixbuf CVE ID : CVE-2015-7552 CVE-2015-8875 Several vulnerabilities have been discovered in gdk-pixbuf, a toolkit for image loading and pixel buffer manipulation. A remote attacker […]

Debian: 3588-1: symfony: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3588-1 security@debian.org https://www.debian.org/security/ Luciano Bello May 29, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : symfony CVE ID : CVE-2016-1902 CVE-2016-4423 Two vulnerabilities were discovered in Symfony, a PHP framework. CVE-2016-1902 Lander Brandt discovered that the class SecureRandom might generate […]

Risk Level: Very Low. Type: Trojan.

VIDEO: What the Katy Perry hack teaches us about computer security
Anonymous leads the way again as world’s most prolific hacktivist group
Laptop updaters riddled with security holes
Ransomware or ransomworm? Beware of ZCryptor!
You may take password security seriously now, but your past can haunt you
Review: Hot new tools to fight insider threats
Flaw in popular WordPress plug-in Jetpack puts over a million websites at risk
Effective IT security habits of highly secure companies
Sorry, dad, security isn’t what it used to be

Risk Level: Very Low. Type: Trojan.

Discovered: May 31, 2016 Updated: May 31, 2016 11:35:23 AM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP WSH.Downloader is a Trojan horse that downloads a malicious file to the compromised computer. Antivirus Protection Dates […]

France Weather Forecast Website Hacked By Anti-War Hacker

Two vulnerabilities were discovered in Symfony, a PHP framework. CVE-2016-1902 Lander Brandt discovered that the class SecureRandom might generate weak random numbers for cryptographic use under certain settings. If the functions random_bytes() or openssl_random_pseudo_bytes() are not available, the output of SecureRandom should not be consider secure. CVE-2016-4423 Marek Alaksa from Citadelo discovered that it is […]

Facebook’s Twin in North Korea Identified and Hacked within a Single day
Revealed: 65 million Pre-Yahoo Acquisition Tumblr Accounts Were Hacked
Anonymous Did Not Release Donald Trump’s Tax Returns
65 million Tumblr users should probably be careful…

Earlier this month, Tumblr revealed that it had recently become aware that user addresses and salted and hashed passwords dating back to 2013 had fallen into the hands of hackers. We recently learned that a third party had obtained access to a set of Tumblr user email addresses with salted and hashed passwords from early […]

How to protect your Hootsuite account from hackers

Risk Level: Very Low. Type: Trojan.

What the CISSP? 20 years as a Certified Information Systems Security Professional

CISSP stands for Certified Information Systems Security Professional, a qualification that I obtained on this day in 1996. Back then, very few people had heard of CISSP or the organization that created it, the International Information Systems Security Certification Consortium. This non-profit professional body is known as (ISC)2 which is pronounced “I-S-C-squared” (because the name […]

Researchers Validate Link Between Cancer and Cellphone Radiations
MySpace Hacked, 427 Million Users’ Emails Passwords Dumped Online
Pakistan’ Real Estate Giant Zameen.com Hacked, Entire Database Leaked
Researcher Pockets $30,000 in Chrome Bounties
Reddit forces password reset of 100,000 users

Risk Level: Very Low. Type: Trojan, Worm.

Risk Level: Very Low. Type: Trojan.

Fiverr Removes Attacker’s Adverts, Gets Non-stop DDoS Attacks
Reddit Hacking Saga Continues As Company Resets 100k Passwords

Ubuntu: 2985-2: GNU C Library regression Posted by Anthony Pell    USN-2985-1 introduced a regression in the GNU C Library. ========================================================================== Ubuntu Security Notice USN-2985-2 May 26, 2016 eglibc, glibc regression ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: […]

Discovered: May 26, 2016 Updated: May 26, 2016 5:44:20 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Trojan.Zekapab is a Trojan horse that downloads potentially malicious files and steals information from […]

Discovered: May 26, 2016 Updated: May 26, 2016 8:16:42 PM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Backdoor.Zekapab is a Trojan horse that opens a back door on the compromised computer and may perform […]

Government IT Systems Long Outdated In a recent study done by the Government Accountability Office, a large portion of the US government’s critical business systems have been found to be requiring an increasing amount for maintaining their basic operation, but also they are a major security risk. From defense systems to scientific research systems, these […]

What Controls the US Nuclear Operation? Floppy Disks and Outdated Computers
New JavaScript spam wave distributes Locky ransomware
Aerospace firm loses $47 million in cyber fraud, fires CEO
How to better protect your Tumblr account from hackers with two-step verification (2SV)
Beware the Android Adult Player app – ransomware lies within!
Decision makers at banks ‘in the dark’ about data breaches

Decision makers at banks are in the dark when it comes to data breaches at their organization, according to KPMG’s 2016 Banking Outlook Survey. It revealed that this is especially the case when it comes to the second tier of senior management. For example, while 12% of CEOs were unaware as to whether their networks […]

Major DNS provider hit by mysterious, focused DDoS attack
Hacker faces 10 years in prison for hacking highway sign with “Drive Crazy Yall”
FBI refuses to release Tor exploit details, evidence thrown out of court
5 active mobile threats spoofing enterprise apps

Several vulnerabilities were discovered in libgd2, a library for programmatic graphics creation and manipulation. A remote attacker can take advantage of these flaws to cause a denial-of-service against an application using the libgd2 library. For the stable distribution (jessie), these problems have been fixed in version 2.1.0-5+deb8u3. For the unstable distribution (sid), these problems have […]

South Korean Air Force Website Faces Cyber Attack
Google’s Abacus API adds security by subtracting passwords
PayPal Users Hit with ”Account Limitation” Phishing Scam

An update for rh-mariadb100-mariadb is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: rh-mariadb100-mariadb security update Advisory ID: RHSA-2016:1132-01 Product: Red Hat Software Collections Advisory URL: https://access.redhat.com/errata/RHSA-2016:1132 Issue date: 2016-05-26 CVE Names: CVE-2015-3210 CVE-2015-3217 CVE-2015-4792 […]

Ubuntu: 2985-1: GNU C Library vulnerabilities Posted by Anthony Pell    Several security issues were fixed in the GNU C Library. ========================================================================== Ubuntu Security Notice USN-2985-1 May 25, 2016 eglibc, glibc vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS […]

Ubuntu: 2950-5: Samba regression Posted by Anthony Pell    USN-2950-1 introduced a regression in Samba. ========================================================================== Ubuntu Security Notice USN-2950-5 May 25, 2016 samba regression ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 – Ubuntu 14.04 LTS Summary: USN-2950-1 introduced a regression in Samba. […]

Slackware: 2016-145-01: libarchive: Security Update Posted by Anthony Pell    New libarchive packages are available for Slackware 14.1 and -current to fix a security issue. [More Info…] [slackware-security] libarchive (SSA:2016-145-01) New libarchive packages are available for Slackware 14.1 and -current to fix a security issue. Here are the details from the Slackware 14.1 ChangeLog: +————————–+ […]

Red Hat: 2016:1106-01: jq: Moderate Advisory Posted by Anthony Pell    An update for jq is now available for Red Hat OpenStack Platform 8.0 (Liberty). Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: jq security update Advisory ID: RHSA-2016:1106-01 Product: Red Hat […]

Several security issues were fixed in PHP. ========================================================================== Ubuntu Security Notice USN-2984-1 May 24, 2016 php5, php7.0 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: Several security issues were fixed in PHP. Software Description: […]

An update for kernel is now available for Red Hat Enterprise Linux 6.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel security, bug fix, and enhancement update Advisory ID: RHSA-2016:1100-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-1100.html […]

GDPR Day: countdown to a global privacy and security regimen?

On this day, May 25, in the year 2018, the General Data Protection Regulation will go into effect. Commonly referred to as GDPR or the Regulation, this set of rules governing the privacy and security of personal data is being laid down by the European Commission, but it has serious implications for companies in countries […]

Another malware wave hits Europe, mainly downloading ransomware Locky

ESET LiveGrid® telemetry shows a spike in detections of the JS/Danger.ScriptAttachment malware in several European countries. The most notable detection ratios are seen in Luxembourg (67%), Czech Republic (60%), Austria (57%), Netherlands (54%) and the UK (51%), but also in other European states. After arriving as an email attachment, the threat behind these detections is designed […]

Leading DNS Provider NS1 Targeted with DDoS Attacks
Hire a DDoS attack for as little as five dollars
What’s old is new again with MIT’s latest bug finder
VIDEO: Should you really change your passwords frequently?
Researcher warns of ‘pastejacking’ hack attacks targeting users’ clipboards
Twitter accounts are getting hacked and spreading adult content
Tor Developers collaborate to accelerate development of Next Gen Onion Service
Good Bye Passwords as Google Plans a Different Verification Option
Paul Vixie on IPv6 NAT, IPv6 security and Internet of Things

Risk Level: Very Low. Type: Trojan.