Menu

Category Archives: Security

Articles about security

IBM’s Watson is going to cybersecurity school
You too? Who’s on the hacker hit list
<div>You too? Who's on the hacker hit list</div>

Some users’ accounts are more attractive to malicious hackers than others. Computer security experts have long focused on local administrators/root — and recently even more on all-powerful network administrators such as members of the domain admin and enterprise admin groups. Those same experts warn about protecting even slightly elevated accounts, like those of network configuration […]

Risk High Date Discovered May 10, 2016 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will […]

Risk High Date Discovered May 10, 2016 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will […]

Rock Stevens, Andrew Ruef and Marcin Icewall Noga discovered a heap-based buffer overflow vulnerability in the zip_read_mac_metadata function in libarchive, a multi-format archive and compression library, which may lead to the execution of arbitrary code if a user or automated system is tricked into processing a specially crafted ZIP file. For the stable distribution (jessie), […]

Risk High Date Discovered May 10, 2016 Description Microsoft Office is prone to a remote memory-corruption vulnerability because it fails to properly handle objects in memory. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions. […]

Risk High Date Discovered May 10, 2016 Description Microsoft Edge is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can take advantage of this vulnerability to execute arbitrary code in the context of the currently logged-in user. Failed attacks […]

Risk High Date Discovered May 10, 2016 Description Microsoft Edge is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can take advantage of this vulnerability to execute arbitrary code in the context of the currently logged-in user. Failed attacks […]

Risk High Date Discovered May 10, 2016 Description Microsoft Edge is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can take advantage of this vulnerability to execute arbitrary code in the context of the currently logged-in user. Failed attacks […]

Risk Medium Date Discovered May 10, 2016 Description The Microsoft .NET Framework is prone to an information-disclosure vulnerability. An attacker can exploit this issue to perform man-in-the-middle attacks and obtain sensitive information. Successful exploits will lead to other attacks. Recommendations Block external access at the network boundary, unless external parties require service. If global access […]

Risk Medium Date Discovered May 10, 2016 Description Microsoft Internet Explorer is prone to a security-bypass vulnerability. An attacker can exploit this issue by tricking an unsuspecting victim into viewing a page containing malicious content. An attacker can exploit this issue to execute arbitrary script code in the context of the user running the application. […]

Risk Medium Date Discovered May 10, 2016 Description Microsoft Internet Explorer is prone to an information-disclosure vulnerability. Successful exploits will allow attackers to obtain sensitive information that may aid in further attacks. Internet Explorer 10, and 11 are vulnerable. Technologies Affected Microsoft Internet Explorer 10 Microsoft Internet Explorer 11 Recommendations Run all software as a […]

Risk High Date Discovered May 10, 2016 Description Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed […]

Sony To Produce Contact Lenses That Can Take Photos and Record Videos
How to work with rogue users

Simon McVittie discovered a cross-site scripting vulnerability in the error reporting of Ikiwiki, a wiki compiler. This update also hardens ikiwiki’s use of imagemagick in the img plugin. For the stable distribution (jessie), this problem has been fixed in version 3.20141016.3. For the unstable distribution (sid), this problem has been fixed in version 3.20160506. We […]

This Hacker was Arrested for Exposing Flaws in Lee County elections website
Aruba fixes networking device flaws that could open doors for hackers

Posted by Anthony Pell    Security fix for CVE-2015-8869 ——————————————————————————– Fedora Update Notification FEDORA-2016-1c4e616564 2016-05-09 00:02:50.053328 ——————————————————————————– Name : ocaml Product : Fedora 24 Version : 4.02.3 Release : 3.fc24 URL : http://www.ocaml.org Summary : OCaml compiler and programming environment Description : OCaml is a high-level, strongly-typed, functional and object-oriented programming language from the ML […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 ocaml-4.02.3-3.fc24 Fedora 22 openvas-gsa-6.0.10-3.fc22 Fedora 22 openvas-cli-1.4.4-1.fc22 Fedora 22 openvas-scanner-5.0.5-3.fc22 Fedora 22 openvas-manager-6.0.8-2.fc22 Fedora 22 openvas-libraries-8.0.7-2.fc22 Debian: 3571-1: ikiwiki: Summary Fedora 24 kernel-4.5.3-300.fc24 Community Linux Events Linux User […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 ocaml-4.02.3-3.fc24 Fedora 22 openvas-gsa-6.0.10-3.fc22 Fedora 22 openvas-cli-1.4.4-1.fc22 Fedora 22 openvas-scanner-5.0.5-3.fc22 Fedora 22 openvas-manager-6.0.8-2.fc22 Fedora 22 openvas-libraries-8.0.7-2.fc22 Debian: 3571-1: ikiwiki: Summary Fedora 24 kernel-4.5.3-300.fc24 Community Linux Events Linux User […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 ocaml-4.02.3-3.fc24 Fedora 22 openvas-gsa-6.0.10-3.fc22 Fedora 22 openvas-cli-1.4.4-1.fc22 Fedora 22 openvas-scanner-5.0.5-3.fc22 Fedora 22 openvas-manager-6.0.8-2.fc22 Fedora 22 openvas-libraries-8.0.7-2.fc22 Debian: 3571-1: ikiwiki: Summary Fedora 24 kernel-4.5.3-300.fc24 Community Linux Events Linux User […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 ocaml-4.02.3-3.fc24 Fedora 22 openvas-gsa-6.0.10-3.fc22 Fedora 22 openvas-cli-1.4.4-1.fc22 Fedora 22 openvas-scanner-5.0.5-3.fc22 Fedora 22 openvas-manager-6.0.8-2.fc22 Fedora 22 openvas-libraries-8.0.7-2.fc22 Debian: 3571-1: ikiwiki: Summary Fedora 24 kernel-4.5.3-300.fc24 Community Linux Events Linux User […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 ocaml-4.02.3-3.fc24 Fedora 22 openvas-gsa-6.0.10-3.fc22 Fedora 22 openvas-cli-1.4.4-1.fc22 Fedora 22 openvas-scanner-5.0.5-3.fc22 Fedora 22 openvas-manager-6.0.8-2.fc22 Fedora 22 openvas-libraries-8.0.7-2.fc22 Debian: 3571-1: ikiwiki: Summary Fedora 24 kernel-4.5.3-300.fc24 Community Linux Events Linux User […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3571-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff May 08, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : ikiwiki CVE ID : CVE-2016-4561 Simon McVittie discovered a cross-site scripting vulnerability in the error reporting of Ikiwiki, a wiki compiler. This update also hardens ikiwiki’s use of imagemagick in the img plugin. For […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 ocaml-4.02.3-3.fc24 Fedora 22 openvas-gsa-6.0.10-3.fc22 Fedora 22 openvas-cli-1.4.4-1.fc22 Fedora 22 openvas-scanner-5.0.5-3.fc22 Fedora 22 openvas-manager-6.0.8-2.fc22 Fedora 22 openvas-libraries-8.0.7-2.fc22 Debian: 3571-1: ikiwiki: Summary Fedora 24 kernel-4.5.3-300.fc24 Community Linux Events Linux User […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 ocaml-4.02.3-3.fc24 Fedora 22 openvas-gsa-6.0.10-3.fc22 Fedora 22 openvas-cli-1.4.4-1.fc22 Fedora 22 openvas-scanner-5.0.5-3.fc22 Fedora 22 openvas-manager-6.0.8-2.fc22 Fedora 22 openvas-libraries-8.0.7-2.fc22 Debian: 3571-1: ikiwiki: Summary Fedora 24 kernel-4.5.3-300.fc24 Community Linux Events Linux User […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 ocaml-4.02.3-3.fc24 Fedora 22 openvas-gsa-6.0.10-3.fc22 Fedora 22 openvas-cli-1.4.4-1.fc22 Fedora 22 openvas-scanner-5.0.5-3.fc22 Fedora 22 openvas-manager-6.0.8-2.fc22 Fedora 22 openvas-libraries-8.0.7-2.fc22 Debian: 3571-1: ikiwiki: Summary Fedora 24 kernel-4.5.3-300.fc24 Community Linux Events Linux User […]

Posted by Anthony Pell    Update to version 20160222-1 to fix bugs(#1285888,1307846,1320511,1320956,1320958) ——————————————————————————– Fedora Update Notification FEDORA-2016-6c03d31846 2016-05-07 11:36:53.859231 ——————————————————————————– Name : parallel Product : Fedora 24 Version : 20160222 Release : 1.fc24 URL : http://www.gnu.org/software/parallel/ Summary : Shell tool for executing jobs in parallel Description : GNU Parallel is a shell tool for executing […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 ocaml-4.02.3-3.fc24 Fedora 22 openvas-gsa-6.0.10-3.fc22 Fedora 22 openvas-cli-1.4.4-1.fc22 Fedora 22 openvas-scanner-5.0.5-3.fc22 Fedora 22 openvas-manager-6.0.8-2.fc22 Fedora 22 openvas-libraries-8.0.7-2.fc22 Debian: 3571-1: ikiwiki: Summary Fedora 24 kernel-4.5.3-300.fc24 Community Linux Events Linux User […]

Century’s Biggest Leak Panama Papers now Available Online
Big businesses in the UK ‘experience regular data breaches’

��}�۶��o�*���R,���ݒ�=vN|>��f&���(�8C�4/�Q��:��_��Cl�>�’�n��4 �8�v.�H��ht7��ѽg?����9������7wM��Cӝ��j?�(��ؾ�)��L��?4o��3j��}��y4��տO�G3���F?��EO9�܈��v��BF�WO��ed`�G���4���X�W��/��_���h���7#{�Ƞ^<�QkB�U]sF{ʅM�DR�mEӞE/��؏�];�MGG�C{�2Hϛ8T�j4���� �`�6/�}�[�w�����2ik��?y1|c�i~�����}�9/ka^��m�՛- ����������q{���nw��l�w�t��V��"��tl���)a�ph8���Ga���l������)tOC��ȡ����vi�F����ȃ������a�;���I���dPs4�!/������4�h8 l?7p����(�%��M��3ϝ�TZ�T����X6����� �����%4���C@-G��t����C��c @�冱gZsGk������n�a�y�l�7�,е�B�9�Y �G�z{8�̜Ѝ�Sҙ��x��#N�(�Ay��A{g�yp����i��”ГP�pd��t�ff�PV��2dbr�F;�h�@j�oفZI?of��:�YQ�s��*zD^pMgqF6ȯ�F����w���lF���l2��&��ĝ��Z��}:���E�!鑏���O��y���P��^0yg0҄�`”��`u�{�˽�;Ci(�T�}w?B/FT9�@g��b�e��}��ݑ[��Y�^��L���g�۳�1r�����#�ֽq�2�W3�ƨ�1�M��Y�xl7� uFe��#ȍj8�u�z��� ���{=x ��)mK�4����m�9�O�k��E�j` �=_i@G�=�i��IF*f����X1R;�������I}�Y������m���ڍ�Wo4�zc�G���~|Y��u’Ѵߡ���&p�VgG�j���,��a�Zk�6��F�����m���ﵮR��54�V?�a0Ꙉl);6�ت�>]���� 5&JZ�Mߧ�u����О�0�X�0{��D*�F�� ��W?�E�^~����34G罔q��M��4�s���+����I@v �e=��.��Cl<���hY,�^�&��Ҙ4�� ��,��FJD�RV��x��Ƕ�_va�k7T]CB�; 8t�{r�e���~Ձ� 3����Uc�K����2��c]h��z4�5,'~��C����W5���7��G+tW5�#��U��A��N��l�pf;t�`? ����}����L���8�nЇ0s��&`��j���ʾN�=�F��Eg�l�Z���燤I��^�#(���6'PHk�8�4X� `�*HMK����Q5� v����-�^���h�Ѡ:�9�+���u����h��MO�y��V�*����L��Y”Z���%�k���_�>m��̞�5$y.��Q(��3f{޹M����:P2h�o@�p�)acӺ0��;�f0��M^�³P�C�j�����ܕ�t”�&�@yM�w�����˙��![�q�ONH[o��(�r�8�W���Ɓ����1����| ��D nd^N��e60 `��^��SI;ʢOKR��!����H�$kz����&���G��=&�{�Vw�$�š���0�Q�9�T!I 0���&te�� ��/ q�^5`j�r��Gl�s�”��6��<���}�x~<�����~)0��ԀŒ193���c�r^p�=]��j�N�ߙ��� �t��D9���Z�s��������F�#����Q�}%_����^��x@p7

UAE InvestBank Hack: Leaked Data showing passport and Credit Card Details
Kiddicare customers at risk after data spills from test server
Twitter blocks access to analytics around its data by US intelligence agencies
The security review: Jigsaw and passphrases

��}�۶��o�*��)S�E�k�ǒ�=vN|�{3N���w “!�3��c4�3U���n�n�}���’��&�I�)�CI#;ɮ}>�”�F����n4�G�>y�˛�价�^��hO�Ro�Әg�x�� dC窧�#2�����G�9aM/��A�;�ƌ��;����h�bʋ��Ĺ�i’�3/6���K��i1�����5�a��^��4��p�����ğ4v� ����G,_գ��.6 �0VJO;�lv�X��?��ء�Y�e�v���fDŇK:C�D|O�|6�������a���iw,”�L��.H�ܞ�3�Ecƀ1�_�݊”�L��О��_�0�=M�t:5��u.YĬ$t�i��40$R�x�&,j�w��28,�C����}t�0�۱$��~;�7f��� #1���G����^�-CGp��ߝQD��z6 h�F,z�U�Yd�NP����`$�E�b���?��ߣbS 2;���r���N�c�,| �oD�h�(Ry��CR/�’S2�+/?A��Ű����5��xY��=`,w���{��n�u�L���9��P�j�H2��0�q�v}�z�P�;Cٯ.�Ř��c�lai��#��_hp� ]��1�(xg(9����9�`+���=����M��(�$��c���� c��֮�:|�nu[G�;[��Vk)��o��]m���9�= ����=gBGl�qTtg�>�#9�;M� #�1�{���N�c�#�}��bP�1�,�J�Q2��p�-(��=��.Y�B��/�[HJBo�(-���Xf���~xC�q�n�_|����k����L>A��”�H�’��%o�>��3u=��&y ����4��|A�I��’!X�@��KGZ�ףX1R;��6��П���}�۬�����k���;�칵_o��z�2c���?���M�y�x��n�h����+a���z6v��0B�����F�n�>��Z��{�댦l M%�Տ-3 �Ed+ٱ1�Ve����-}”Q��k��ЪI��y���q�U����BNTQQ�c� � �O0�He|�]���~�����W��’�uԺ�e�S��la��S�F��^!�����r�k������m�҉@�Y�V~WӠe鍽u�l�1j�k���,*�FJ�1�ƼPM�=�m�p��;�]CA�; Z8t zr�e���~Ձ� 3B����uch*����r��GCSj��f<��5,'��C�����5���o%�#�����QS�U��Aty�^U��3|#�8.�5�O�|�{�v���#�,Q�ɽt���m��?”-b��A�������2KpxF��xv>�P���>^����sU’����q����͝J �N�;���]723C���5&������bx�txu�4��:i��T՟�;���:3��`�N�b����$� r�{�{Υo�(%(I[F;�S���-���pl6�����4�#��K疨�5U���h�6��o�P5��l��Z&[����;@Q@�m#��A�?�GqH��`�A�$������H��=�5a��LTAj�������v찑ζ��dz w{F#�����rBx5�p��Y4�=�c:pY�aC*����9<ރT��6����8;x������� �j�^A�J/�=#qHb�#�u����7�]���[����T�z�[� :�7�2 4�S�J%�<��mv���_��g⺑�`�B��s����/�က��|%�F��Ԛ�O)S�C�0?2Zc��'3�!�7! ��d1f�I��$�ST�S-Xl�D��x.���'�Z�Dօ+[�߯����+t��v?����F,����c��(j����x�*��_�6���]u��У=�A�ʵ�fE�&.|��k9�I~8=%�E�e�.�^E&�� =ԅ0��a�ϣ��.4�-�y1����m`�(��P�g�,��e��J�B0�s6�Jz$����ᅮ��G�}��*ΐ���[�����6��LG��ҥ$��/oR���0a�/ q�^o6��=��a~���D�pM^�<ҏUdU#Sع��63Ax��ʆ~�j�J�Ds��Q��� �Ƶw:��o�+澰��ۻ���a�s��E�P�Ľ���C��y�X&m�,�m��zB�w�e#���/=r

FBI: No, you shouldn’t pay ransomware extortionists
How to protect your Dropbox account with two-step verification (2SV)
OpIcarus Finds More Targets as Banks in Panama, Bosnia and Kenya Go Offline
According to Chrome, Safari and FireFox ThePirateBay is a Phishing Site
40 million User Data from Adult Social Network Emerges on Dark Net
10-year-old gets $10,000 bounty for finding Instagram vulnerability
Another breach, another dollar: Is it time to kill the password?
Millions of stolen email credentials shared online by Russian hacker

Discovered: May 6, 2016 Updated: May 6, 2016 7:08:19 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 7, Windows Vista, Windows XP Backdoor.Duuzer.B is a Trojan horse that opens a back door on the compromised computer. Symantec Security Response is currently investigating this threat and will post more information as it becomes available. Antivirus […]

OpIcarus continues as hacktivists shut down 3 more banking websites
Visitors to TV station websites targeted in malvertising attack
If You Don’t Upgrade to Windows 10 Now – You Will Have to Pay $119 Later
GitLab repairs critical flaw that lets users log in as admins

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3570-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso May 05, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : mercurial CVE ID : CVE-2016-3105 Blake Burkhart discovered an arbitrary code execution flaw in Mercurial, a distributed version control system, when using the convert extension on Git repositories with specially crafted names. This flaw […]

Posted by Anthony Pell    Don’t export background images from deleted slides. ——————————————————————————– Fedora Update Notification FEDORA-2016-34f9ed9753 2016-05-05 10:04:33.646885 ——————————————————————————– Name : libreoffice Product : Fedora 23 Version : 5.0.6.2 Release : 3.fc23 URL : http://www.libreoffice.org/ Summary : Free Software Productivity Suite Description : LibreOffice is an Open Source, community-developed, office productivity suite. It includes […]

– new upstream version (46.0.1) – fixed focus on TWM (rhbz#1322626) ——————————————————————————– Fedora Update Notification FEDORA-2016-25843fda6b 2016-05-05 10:04:33.645657 ——————————————————————————– Name : firefox Product : Fedora 23 Version : 46.0.1 Release : 1.fc23 URL : https://www.mozilla.org/firefox/ Summary : Mozilla Firefox Web browser Description : Mozilla Firefox is an open-source web browser, designed for standards compliance, performance […]

Discovered: May 5, 2016 Updated: May 5, 2016 5:59:51 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Backdoor.Tronariv is a Trojan horse that opens a back door, steals information, and may download mailicious […]

Lenovo patches serious flaw in pre-installed support tool
India Blames ISI for Spying on Military Through Gaming and Music Apps
Data loss scenarios: Which are the most probable?

Research by a security company shows that running regular backups for data, as well as encrypting them, is necessary in order for organizations to ensure that their information neither gets lost, nor falls into the wrong hands. Drives that go undetected by the device – which can be caused by failing hardware or voltage fluctuations […]

Why ransomware works so well
Qualcomm flaw puts millions of Android devices at risk
Early warning signs of a DDoS attack
Hitler’s “unbreakable” encryption machine – and the Bletchley Park devices which cracked the code
Big data breaches found at major email services – expert
Tech groups call on presidential candidates to support encryption, embrace other IT issues
5 simple steps to controlling cloud access
Warrantless searches surge as online privacy dwindles
Interop: Getting a few more years out of your tech

Remember when a 100 Gigabyte hard drive was huge? I try not to think about it, but I also remember when no one could figure out what to do with a hard drive “that large”. Except we did. Now if you only have a 1 Terabyte hard drive we feel slightly sorry for you. Same […]

How to protect your PayPal account with two-step verification (2SV)
The Art of Hiding Cellphone, Laptop Cameras From Hackers and Government

It was discovered that libpam-sshauth, a PAM module to authenticate using an SSH server, does not correctly handle system users. In certain configurations an attacker can take advantage of this flaw to gain root privileges. For the stable distribution (jessie), this problem has been fixed in version 0.3.1-1+deb8u1. For the testing distribution (stretch), this problem […]

After Hacking Bush, Guccifer admits Hacking Hillary Clinton’s Private Email Server
Why most Android devices won’t patch the Qualcomm bug
Apple patches vulnerable OS X Git version that put developers at risk

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3569-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso May 05, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : openafs CVE ID : CVE-2015-8312 CVE-2016-2860 Two vulnerabilities were discovered in openafs, an implementation of the distributed filesystem AFS. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2015-8312 Potential denial of service […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3568-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso May 05, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libtasn1-6 CVE ID : CVE-2016-4008 Pascal Cuoq and Miod Vallat discovered that Libtasn1, a library to manage ASN.1 structures, does not correctly handle certain malformed DER certificates. A remote attacker can take advantage of […]

Posted by Anthony Pell    Several security issues were fixed in OpenJDK 7. ========================================================================== Ubuntu Security Notice USN-2964-1 May 05, 2016 openjdk-7 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS Summary: Several security issues were fixed in OpenJDK 7. Software Description: – openjdk-7: […]

Posted by Anthony Pell    Several security issues were fixed in OpenJDK 8. ========================================================================== Ubuntu Security Notice USN-2963-1 May 05, 2016 openjdk-8 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS Summary: Several security issues were fixed in OpenJDK 8. Software Description: – openjdk-8: Open Source Java […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Debian: 3569-1: openafs: Summary Debian: 3568-1: libtasn1-6: Summary Ubuntu: 2964-1: OpenJDK 7 vulnerabilities Ubuntu: 2963-1: OpenJDK 8 vulnerabilities Ubuntu: 2961-1: Little CMS vulnerability Debian: 3567-1: libpam-sshauth: Summary Fedora 23 obs-signd-2.2.1-8.fc23 […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3567-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso May 04, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libpam-sshauth CVE ID : CVE-2016-4422 It was discovered that libpam-sshauth, a PAM module to authenticate using an SSH server, does not correctly handle system users. In certain configurations an attacker can take advantage of […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Debian: 3569-1: openafs: Summary Debian: 3568-1: libtasn1-6: Summary Ubuntu: 2964-1: OpenJDK 7 vulnerabilities Ubuntu: 2963-1: OpenJDK 8 vulnerabilities Ubuntu: 2961-1: Little CMS vulnerability Debian: 3567-1: libpam-sshauth: Summary Fedora 23 obs-signd-2.2.1-8.fc23 […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Debian: 3569-1: openafs: Summary Debian: 3568-1: libtasn1-6: Summary Ubuntu: 2964-1: OpenJDK 7 vulnerabilities Ubuntu: 2963-1: OpenJDK 8 vulnerabilities Ubuntu: 2961-1: Little CMS vulnerability Debian: 3567-1: libpam-sshauth: Summary Fedora 23 obs-signd-2.2.1-8.fc23 […]

Security fix for CVE-2016-2108, CVE-2016-2107, CVE-2016-2105, CVE-2016-2106 ——————————————————————————– Fedora Update Notification FEDORA-2016-05c567df1a 2016-05-04 15:02:38.890153 ——————————————————————————– Name : openssl Product : Fedora 23 Version : 1.0.2h Release : 1.fc23 URL : http://www.openssl.org/ Summary : Utilities from the general purpose cryptography library with TLS implementation Description : The OpenSSL toolkit provides support for secure communications between machines. […]

Posted by Anthony Pell    USN-2950-1 introduced regressions in Samba. ========================================================================== Ubuntu Security Notice USN-2950-3 May 04, 2016 samba regressions ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: USN-2950-1 introduced regressions in Samba. Software Description: […]

Posted by Anthony Pell    USN-2950-1 introduced regressions in Samba. ========================================================================== Ubuntu Security Notice USN-2950-2 May 04, 2016 samba regressions ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: USN-2950-1 introduced regressions in Samba. Software Description: […]

Massive Data Breach Hits Russian Users of Gmail, Yahoo and Hotmail
Ransomware promises to donate ransom fees to a children’s charity
Why passwords fail end users
Methods hackers use to attack DNS
Open Source ImageMagick Security Bug Puts Sites at Risk

APPLE-SA-2016-05-03-1 Xcode 7.3.1 Subject: APPLE-SA-2016-05-03-1 Xcode 7.3.1 From: Apple Product Security <email@hidden> Date: Wed, 04 May 2016 10:36:15 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-05-03-1 Xcode 7.3.1 Xcode 7.3.1 is now available and addresses the following: Git Available for: OS X El Capitan v10.11 and later Impact: A remote attacker may be able to […]

272 million email accounts compromised in major data breach

��}�۶��o�*�ӧL)����%{����z&�͵�*��$�P$Ï��8Suco�އت}��79O��H��h4��l��0E�F���h4Џ�=����/��_��xO]�Ro�Әg�x�� d#粧��C2�����ǁ9eM/��A�;�’���;���{�br������L>���#�H�?��o�>��3s4y�����~�CSkh�T3o?”? -�~Ҡ3`���*�jB~@J:��&6�t���5�L�Y�,zVao������v��(�ګ�ưa�?���]��O4$Vohr*�.XT^Ù���v�2�,���e���ul�~�8 ܃�9�>�OOj��E�j`O ��@k@GlG����i/f�ұ���(VL��Nb�������c�f�����^cw��idϭ�z��h����Aj~|�V7]��I�˺��u��#�պ����ݗ8����k࿍v�D�|��X��k_e4e+h*��~d�Qh�(“[Ɏ�!�*�E��t�D���*G�C�& ���ǵkV� [5�9 p��>�x0���0��D*�N�� �����w� �B|6�čӿ��4�+z�¹%�@Mb�* ں ����T�q0�#���ɖp3��E( ��md��T�Ñq��q�4�v�$�@���0QϚ��oѳ_���@��m�>���m�Q���|{xK��p�Ga4�X�=<-'��W�s�K�E�C9�C� ��!��t��A��UFn�{f�z���Ga� T��w�E�3�6�{9 +����!��O�f�|��ʎw$�@w]?����$�NNH�l����8�W���&�����3���K�z ��D��^L/’`�r��0�?��$��i٧����t�F�_I��kz���o������G��3″�{��t�$�%���6�0�Q.8�t)I)0�˛�bA�8LX�H�כM`j�r��-6Ź������9N�^�h�:һ�]��ܗ���U��$w�SڢqAKz�~������� @ �z�zq#>*�1 �Pb��P����� r/21���o�����������ݔ�Zg�*Y��‰����<�8� ��h<�%偟5�F�pN�������7|2�I�S3�i����،<�!��q�O�z������Wk�U�����Y�� ���z:��_���?�����=��3��zs�q�7w��!i��C�=-g�ƈ3D����B��/�J/s��^�!r��)���4��f �?�{ݽ�^�݅^h�B�E=m��ܽ�r_P+�� ����9Ԕ0��Z'�gFj���V�F w��m<��+�QUs��]�p��cJ�2���Ob#���a�ߐ���q��

iPhone Users Hit with iCloud Account Deactivation Phishing Scam
Ka-ching! The data breach threat that targets retailers
NIST readies ‘post-quantum’ crypto competition
How to Conduct Internal Penetration Testing