Menu

Category Archives: Security

Articles about security

Linux Foundation tackles open source security with new badge program
Enterprise Node.js upgrade focuses on security
Hacker selling over 272 million webmail passwords for $1? Don’t panic
10-year-old Finnish boy uncovers Instagram comments vulnerability

��}��6��oOU��S���mn���c��/���x=�/�c{� �8C�/���LU�a��ڭ�_��� ξI�d��/�h4��lٹ�”�F���h4�Gw��xt�˛�䇓W/��l=�����4�?k$�й�i�而�88h6�Q`NXӋ�iP�Σ1�v�<��MXLyQ��8=���b����,`�į��˸� ZcF,�%����H�_ �??=1��I@cgઠ^<�1{��U=:a=��a��c��Ա�q�f����Aω��E]�kWA���eF��̸`�3t,@��ȧ����?ý�~�캯:�l���������C����V�{^��$���cӘ��������~g�����Qg���~w��j�}�t��vW�"��t��iQ<�A�L�2�L�xL1�a��N�~�e� ߵ���9ј�I��6�=6Z;��I�u�zx��~Ђ��Rp��|���A��N�j��p� ���YѯI��Ԏ����$�mV�����6vv�۝F��ګ7@2� ˌ�g4�?�}Y��.�F��e���*p�VwG�j���l��a�Zk�6��F�n����Z���l M%��-3 �Ed+ٱ1�Ve���섎^�H�4�huhդA�<�h�vͪ_a���!'����ș0���0��D*�N�� ���Wo�w� �B|�J_a�GqH��`���$_1l�!�H��=�5a��LTAj����{����f찑�6��dz wsF#�����rBx5:w��Y4�9�c:pY�RQ�N������_e䶹k���Y��p��@���e�+�����F��$��r��3�$�?J�9�]+;ޡx�u�����������E��b�zZ���Y*Z�����k�͎ޟ�>m�����]�x.�M�P%gܸ8��s��; `�,�@ɡQ�)u�m����}J����hh��&���ބ�@ֆ �1kN��&���@��Ԃ�0�1OxW��w�^���a���ȺX�ֲ��uX��s��v/����X���}����5>^�³T���� j���!�R��1=�~�?a� �L� �)f.5X��8h���� t|cj�ys�rHpK��뗼=>&�E�g�.td�”�?HBg����s�~����ͼ�^�a��W @T����t�܇��>gF�E�@��N��_I��^���o����wꇢ�3$����t�)�%� 6zyS9(��t�kR`��7)tłZq����I�^o6A�=X��#w ˤ��!j�c�-Ȁ{����l$S���_��ɈGROkkD�F�0O�g���:����)��r$�2d�8||Z��}: �E�,(ry3C�H� X��]?<����b�h9C�K��/��|��2w=jR�#�`N:+�H�����E� 6 ���y�M��o#�7��>y~���,��C���̫�Ue�l�,�V� �41#f|}�5���n”��C”R�O���+y�{����2�Y�rͅ<�N���ʫ€�p��|S��!.#���h��R)�r �K���l�czF뿔�@�0. ����σX�J���5+�u��d+�E�NМ'6#?�Q,B�y{���9K�;��H*�H�؄���77����;��6)`G��l�ty�UHis�0�f��Υ/�Y��� �A����9��dѐ���$�B!,�8k’×k��/�}w���=’�B��9@Rl@!�?`$�5�~��.U���?{���)6���o[te�&z�:Ч��”�+�Z(���f:�T����7���_���l�Q�WHt�{C�y����0b�,ȑirp �R���v7��.�Wz���Yc��N�⼓*����no�{ )6��~:��D��M�7���ki�UE����s��k� E�t�h�����uΗ�U~�k�o��-o1*z�OuYM}-���}�̍�W��V��N�O���b�� ��%��`��E����Ce���&N�� ةP�����V�w�$�!0F�x�� �p@�^P�F�s��e�dR��.��#��8,��/˝�(4����EP�D0�T�Uߤǝ5rA݄�’���h��7� ���W��_鰼nl��Q��d4Lmk�����K_u�!3ͱVS��qo!��ҭ�|��]��x0���86�����Cy� �&����*_�J�Vesq�F���ߖyi��ˡ-�fKF��e��M߫鱟Xc�p/57^�>�`,�)Ϸ?��]v����� 3a)��RTx�j�C��l)��uD4�|��K���y����y��0F�u����$�i�p�GF��Z�߿ph7k�E�+ ��{�(8,��#V!���|J �_q�.q|J��� ���s�y??���T�z3EJ���y��������T.Z՛p)d�j|�$N�`��O����o1�,f�Q�L+���M”))�Ld�_���y��i��’~晠�OJ�Uy�M/��uT�����KI�������&Y�7S5��Bue;�R��”Ϻ:��>)N��.0��~V�� ��c�%u���V�� cG�’��-#a�>{�y,T’Κ������Q���������u���a9l;�).�z���pE�#~������W�ƭ���ӧO�����bK �fL�� �����S��]��zU�VlB�t:`,��Z���>��!5�q�3�;�Z�7�I�&p�9�=��M�Mo���S~� ����[:��%g�uL��p#��i�5�ʚ|���f#� ߹�ν�� v�~�5f���A� ��]���sas�VK��]Fܼ�4-ts���*D}�} ��)��RC��$�;�����(��FH���/��%�q��T޽��j�p|��2�=렿�~�����?0�}?�’������$��8kH���A���Q$��`�wF�Nac�O�y� ԛ�l��ck�,y��~r�x@�HRpE�s�0�y����ע�����{D� ��}��6��oOU��S���mn���c��/���x=�/�c{� �8C�/���LU�a��ڭ�_��� ξI�d��/�h4��lٹ�”�F���h4�Gw��xt�˛�䇓W/��l=�����4�?k$�й�i�而�88h6�Q`NXӋ�iP�Σ1�v�<��MXLyQ��8=���b����,`�į��˸� […]

Data Security in the Cloud 2016 – hear me speak in London

Pascal Cuoq and Miod Vallat discovered that Libtasn1, a library to manage ASN.1 structures, does not correctly handle certain malformed DER certificates. A remote attacker can take advantage of this flaw to cause an application using the Libtasn1 library to hang, resulting in a denial of service. For the stable distribution (jessie), this problem has […]

Two vulnerabilities were discovered in openafs, an implementation of the distributed filesystem AFS. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2015-8312 Potential denial of service caused by a bug in the pioctl logic allowing a local user to overrun a kernel buffer with a single NUL byte. CVE-2016-2860 Peter Iannucci discovered that […]

Blake Burkhart discovered an arbitrary code execution flaw in Mercurial, a distributed version control system, when using the convert extension on Git repositories with specially crafted names. This flaw in particular affects automated code conversion services that allow arbitrary repository names. For the stable distribution (jessie), this problem has been fixed in version 3.1.2-2+deb8u3. For […]

Attackers can exploit Samsung SmartThings design flaws to break into your home
Here’s Your Chance to Use IBM’s Remotely Accessible Quantum Computer
OpIcarus: Hacktivists Shut Down Central Bank of Cyprus with DDoS Attack
Windows ‘God Mode’ Feature Exploited by New Malware to Avoid Identification
OpenSSL patches two high-severity flaws
Quantum computers pose a huge threat to security, and the NIST wants your help
Trend Micro: 6 most popular homebrewed terrorist tools
4 projects ripe for a Rust rewrite

An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: kernel security, bug fix, and enhancement update Advisory ID: RHSA-2016:0715-01 […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Red Hat: 2016:0715-01: kernel: Moderate Advisory Fedora 22 cacti-0.8.8g-1.fc22 Fedora 23 cacti-0.8.8g-1.fc23 Slackware: 2016-124-01: openssl: Security Update Red Hat: 2016:0716-01: java-1.8.0-ibm: Critical Advisory Debian: 3566-1: openssl: Summary Red Hat: 2016:0711-01: […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Red Hat: 2016:0715-01: kernel: Moderate Advisory Fedora 22 cacti-0.8.8g-1.fc22 Fedora 23 cacti-0.8.8g-1.fc23 Slackware: 2016-124-01: openssl: Security Update Red Hat: 2016:0716-01: java-1.8.0-ibm: Critical Advisory Debian: 3566-1: openssl: Summary Red Hat: 2016:0711-01: […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Red Hat: 2016:0715-01: kernel: Moderate Advisory Fedora 22 cacti-0.8.8g-1.fc22 Fedora 23 cacti-0.8.8g-1.fc23 Slackware: 2016-124-01: openssl: Security Update Red Hat: 2016:0716-01: java-1.8.0-ibm: Critical Advisory Debian: 3566-1: openssl: Summary Red Hat: 2016:0711-01: […]

An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: java-1.8.0-ibm security update Advisory ID: RHSA-2016:0716-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0716.html Issue date: 2016-05-03 CVE Names: […]

Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3566-1 security@debian.org https://www.debian.org/security/ Alessandro Ghedini May 03, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : openssl CVE ID : CVE-2016-2105 CVE-2016-2106 CVE-2016-2107 CVE-2016-2108 CVE-2016-2109 CVE-2016-2176 Several vulnerabilities were discovered in OpenSSL, a Secure Socket Layer toolkit. CVE-2016-2105 Guido Vranken discovered that an overflow can […]

Posted by Anthony Pell    An updated Jenkins package and image that include a security fix are now available for Red Hat OpenShift Enterprise 3.1. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: jenkins security update Advisory ID: RHSA-2016:0711-01 Product: Red Hat […]

Posted by Anthony Pell    Several security issues were fixed in OpenSSL. ========================================================================== Ubuntu Security Notice USN-2959-1 May 03, 2016 openssl vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: Several security issues were fixed […]

Microsoft’s Word Flaw Keyboard for iPhone Makes Texting Easy
Jigsaw and how ransomware is becoming more aggressive with new capabilities

��}��6��o�*��_YR,����3�||���ر73�r�Iv�”!��dxYqu�a�G؟[�Op�MΓlw$�4��$[�dgߜ�~5����Y}����ǽ�����t�6�x��h�9 �K�[Q�`sn;���og0�Æ��b�/���[I��K����”�$RF<�s�ԐF�t�.������4v6s"��c��bg���m�p�`Lc�6��0vb����L#s�L�f3�BӋ�����.�7es��iȣP�<�`��cDž!��CC���R��:Ai��f�����q��1��М�FlfB+?�L ��Ds`C׹�Lv�ꛮ�/"�ljB�șz�<^]�@��H�#u��%�i�'�]�a��BU��f��������3�ZZ���S�� 5�����_��%i�GqQ(ȽsT���a�X._YGM)�C�X��_�+Vt# ]�?�7P��Q�~���ʩD����c�4�e���$c��g���Q���j�}��w��;t�{�w����Zps߆�Ymp�p������j�9gnN��#���$p}ӎ�׍8��t�z��î�.�*H�S�<��!��KX�;á��}�#�P[�����uP��O�_���;��M��Jfk�XzZC��e��[��’�3s�-�D����FZ�� ��t�v�j�’�)BN�D��3`Ʋ�a���T�D��G@�ٛ�����N����)ẖi]3�iPv�^ڌ.`#_d��￷�E�-h|�������ʉ@�y�U}�j@�r�� t ��i�N��1kʢ֑�aġD�֌ ��’_�����.�a�pZ��Q�a�N�����bY�v�_m 3Ȍ�����3�a�[����.5ν{=^ȏ-,’��;�E�j��[BWul�J�G:+tW5�CC�Ո� ��ʋ��mg>�Z4w���W�>ܾe;Q��c�hQ��qg�@��m��0gW߼ע� hս�qg:��Y�ϋ/h ^�� ��Ǭ���a�%(��@���PH��8S���/���Ă���)�,X>���u#m��T�F�10�=c犿)���oS���Mfl�T՟�;���:���`�+�Ő�7�I��Q��;�=�������]��p&�Ю1��&�O�čӿ;d�@�=�ҹ!�9 C��� �vo�i�v3U�vfwd��2�n����5���*���8��8�C3� v��@Ҋag�NL�Z����w�&<�)`�*HMO߿w�;8:� ��6�����L/���h��pwxZNh�F��~M����<@O�&��tj�z�*��{�޻ga��Q����m=��[� �v ' a��c�^�8d��A�̑�:X��N����w�}�O5=U�E��Zl2L^M��}`�KE+��w)�z=����Oۮ6w�!no)�@Fo�(�I�;2.�������s^t�Ш�D��6Y�Ʀ} J�����К�M<_j�!< ֆ �17�Qtn&���@�vڊ�;�sO8i��w�������J�m��me߿�a�n$��Q� K��G�p~4��̷�*��·���T�5D5~���7��� �n�C�Dg�����v���FQ�]��x���� 57#��A��K8!d9�i��!pkP�F2%@_>-��9N���[�T(P�r#C�^ |�O8�c���O�Z�8<�7�a�:P�S0�;x0yG,Q��d��j�'˗v�����S! �����Bw�[���X��}�{��d

The CloudFlare and Tor Stalemate Is Harming Users
How Craig Wright Privately ‘Proved’ He Created Bitcoin
New BlackArch Linux version released, now provides 1400 pentesting tools
Google introduces HTTPS for blogspot domain names

Google is adding further security to the world wide web by introducing HTTPS for every blogspot domain name. In an official company blog, Milinda Perera, software engineer based in the tech giant’s security team, said every page will now be encrypted. Where previously this was an opt-in setting, Google has decided that this type of […]

Panama Papers leak explained: What you need to know about the Mossack Fonseca hack
5 secure habits of the paranoid PC user
Admins: Don’t wait for ImageMagick patch
Advertising company given access to 1.6 million NHS patient records
10-year-old Kid Hacks Instagram, Gets $10,000 Reward from Facebook
Targeted malware attack spends decade sliding under the radar
Fake Google Chrome Update Leads to Android Malware Stealing Personal Data
How to perform a risk assessment

Several security vulnerabilities were found in botan1.10, a C++ library which provides support for many common cryptographic operations, including encryption, authentication, X.509v3 certificates and CRLs. CVE-2015-5726 The BER decoder would crash due to reading from offset 0 of an empty vector if it encountered a BIT STRING which did not contain any data at all. […]

Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-1660 Atte Kettunen discovered an out-of-bounds write issue. CVE-2016-1661 Wadih Matar discovered a memory corruption issue. CVE-2016-1662 Rob Wu discovered a use-after-free issue related to extensions. CVE-2016-1663 A use-after-free issue was discovered in Blink’s bindings to V8. CVE-2016-1664 Wadih Matar discovered a way to spoof […]

Two highly dangerous OpenSSL security bugs have been patched

Posted by Anthony Pell    New mercurial packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix a security issue. [More Info…] [slackware-security] mercurial (SSA:2016-123-01) New mercurial packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix a security issue. Here are the details from the Slackware […]

Git contains multiple vulnerabilities that allow for the remote execution of arbitrary code. – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – Gentoo Linux Security Advisory GLSA 201605-01 […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Slackware: 2016-123-01: mercurial: Security Update Gentoo: 201605-01 Git: Multiple vulnerabilities Ubuntu: 2957-2: Libtasn1 vulnerability Fedora 23 php-5.6.21-1.fc23 Ubuntu: 2958-1: poppler vulnerabilities Ubuntu: 2957-1: Libtasn1 vulnerability Red Hat: 2016:0708-01: java-1.6.0-ibm: Critical […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Slackware: 2016-123-01: mercurial: Security Update Gentoo: 201605-01 Git: Multiple vulnerabilities Ubuntu: 2957-2: Libtasn1 vulnerability Fedora 23 php-5.6.21-1.fc23 Ubuntu: 2958-1: poppler vulnerabilities Ubuntu: 2957-1: Libtasn1 vulnerability Red Hat: 2016:0708-01: java-1.6.0-ibm: Critical […]

poppler could be made to crash or run programs if it opened a speciallycrafted file. ========================================================================== Ubuntu Security Notice USN-2958-1 May 02, 2016 poppler vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: poppler could be made to crash […]

Libtasn1 could be made to hang if it processed specially crafted data. ========================================================================== Ubuntu Security Notice USN-2957-1 May 02, 2016 libtasn1-3, libtasn1-6 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: Libtasn1 could be made to hang if it […]

New anti-hacking law promises life imprisonment to vehicle hackers
PwnedList Gets Pwned, shutting down service in few days
Third party risks ‘ a serious risk’

��}��8��oWD�LaJm��Q��,y��k���.���c{ I��H�G���؍�}���’�}�y��@��T*��0E�D”3�H$���>{s��׷�ɏ�^�|��h��Pw�W���|�?`c�x�#2�”��0���Ϙ���s�єQkp���f,����>��E_9�܈���n�3���W_��ed`���!��q4�b���W��’ډ7�id��,���̚�|U��X_�����(Szn[Ѵo��d��”�kG6u�Ф�w� Mg�}�BfƁ-tӛs_�Hє�Xh�w�� i�Ρ���;��jy7�C��#��G����YdnGS�F4m��(�#� �p`�тvx�����F( ��^�w�����!��d�h��l�04e��G�`B]�7>�!�Ґ�s��0�� ���G�nT�����l�{��I�ւ��o=����f�pm?96hkb�m����v�]g��=��>h�����f��vh{{k�!�}T���c��m�OY��$$}�Yѐ���Ht������� ?�����8�^t?JK������zq`2���;���B�&����NlaKg!�+k0�2�N�Ao���`��w�~�]c��c�k�m�Zf�s�X ��|Ab�G:�2{�0����@�ٲ�>a7v/���J�R�����ݿo�c�q��� K�”O5��枯����#��u�K�$�3v�D���+&@�^}x����b�����~ko���m���f��j7[�y�hD��e��;̝D�A��G��=@X�= �}�߷��/p�j����[��*��ol6��v�R��54���<6�00���d��[��§�wt�D���DiB�:�}�Z'S۱f� [�&9�q]�?��̇YƂ��&R_pj7��go^�@���� u�5��)�4?g��^Ҍ.`#_����7&y9� h|�S�z~]|i� �,x�(�k(вj���,�5i��4[��,j�FJD5��PC��m�p���Vm.(�VyV�$�Y�Б��)��n��2��I����W����Ǭ���<�R�ܿ?֣�|l`9����T�ټj]ղ���Έ@Mhb�dU�X�ϐb΂E�g���’�F-��5�,��R�bx�dxU�”V�GUbl�T�_�;�b}��;��p������v=�A4`B6����޵/<�A)AI���/�3�ԍ�t�XlLc'J���i|X�N�K/�[��dd!�����` v;�:�8���h�eRn���Eu�F��B�?G��Q@�z�C�f ��j�tL]sR_�g�b,��@����ݿ���è`�M�`Qޒ�%��(�F��Ӵx5K�9�+��x�u��螹��dMϬ�B-�U����i����D� ;K(���]u�/|�v��= pS(�`��F�Jθqq�y�6Cw�φ,�@ɡQ��t�ͥ���uJ����h`N�&�-4�}߀�kC�ň�0�8��؄Z���2� g�5�.�Q;�/8�d�K�F���[���,���&,�’����ES��gQTZ��`�Y��)@5~����rv��@��.Eǧ�!�}GnA>��9� �e�&���t�6�1�0�cx���Q��a9Ì��ШJ�p�F�r �/��Y�<�e�J��K�}Z�(�AG�py��y,��cҸ�ou��GRX�xd�3�SJ���#��N�+&Ԋ��忀��{�0��]��a~6��D�l/x��Y�uw��=T%q�� �}ad�,�IZ3��,Q��d���BO/�k�w�$�V����9R��3���s�q�w;�� �������W3Ek��Yrݦ|���.�J-s�s�Z�!r��)�r�$6�f �?{���~�Ӄ^(��B�6�}e��ܽ�r_P+�� ����9P21;ɟl��+VU,S,'[���f��?�3x��]�Uͥ�bg�W^±�(�Ȑ�#/��84R�� �!?��#�� ��}��8��oWD�LaJm��Q��,y��k���.���c{ I��H�G���؍�}���’�}�y��@��T*��0E�D”3�H$���>{s��׷�ɏ�^�|��h��Pw�W���|�?`c�x�#2�”��0���Ϙ���s�єQkp���f,����>��E_9�܈���n�3���W_��ed`���!��q4�b���W��’ډ7�id��,���̚�|U��X_�����(Szn[Ѵo��d��”�kG6u�Ф�w� Mg�}�BfƁ-tӛs_�Hє�Xh�w�� i�Ρ���;��jy7�C��#��G����YdnGS�F4m��(�#� �p`�тvx�����F( ��^�w�����!��d�h��l�04e��G�`B]�7>�!�Ґ�s��0�� ���G�nT�����l�{��I�ւ��o=����f�pm?96hkb�m����v�]g��=��>h�����f��vh{{k�!�}T���c��m�OY��$$}�Yѐ���Ht������� ?�����8�^t?JK������zq`2���;���B�&����NlaKg!�+k0�2�N�Ao���`��w�~�]c��c�k�m�Zf�s�X ��|Ab�G:�2{�0����@�ٲ�>a7v/���J�R�����ݿo�c�q��� K�”O5��枯����#��u�K�$�3v�D���+&@�^}x����b�����~ko���m���f��j7[�y�hD��e��;̝D�A��G��=@X�= �}�߷��/p�j����[��*��ol6��v�R��54���<6�00���d��[��§�wt�D���DiB�:�}�Z'S۱f� [�&9�q]�?��̇YƂ��&R_pj7��go^�@���� u�5��)�4?g��^Ҍ.`#_����7&y9� h|�S�z~]|i� �,x�(�k(вj���,�5i��4[��,j�FJD5��PC��m�p���Vm.(�VyV�$�Y�Б��)��n��2��I����W����Ǭ���<�R�ܿ?֣�|l`9����T�ټj]ղ���Έ@Mhb�dU�X�ϐb΂E�g���’�F-��5�,��R�bx�dxU�”V�GUbl�T�_�;�b}��;��p������v=�A4`B6����޵/<�A)AI���/�3�ԍ�t�XlLc'J���i|X�N�K/�[��dd!�����` v;�:�8���h�eRn���Eu�F��B�?G��Q@�z�C�f ��j�tL]sR_�g�b,��@����ݿ���è`�M�`Qޒ�%��(�F��Ӵx5K�9�+��x�u��螹��dMϬ�B-�U����i����D� ;K(���]u�/|�v��= pS(�`��F�Jθqq�y�6Cw�φ,�@ɡQ��t�ͥ���uJ����h`N�&�-4�}߀�kC�ň�0�8��؄Z���2� g�5�.�Q;�/8�d�K�F���[���,���&,�’����ES��gQTZ��`�Y��)@5~����rv��@��.Eǧ�!�}GnA>��9� �e�&���t�6�1�0�cx���Q��a9Ì��ШJ�p�F�r �/��Y�<�e�J��K�}Z�(�AG�py��y,��cҸ�ou��GRX�xd�3�SJ���#��N�+&Ԋ��忀��{�0��]��a~6��D�l/x��Y�uw��=T%q�� �}ad�,�IZ3��,Q��d���BO/�k�w�$�V����9R��3���s�q�w;�� �������W3Ek��Yrݦ|���.�J-s�s�Z�!r��)�r�$6�f �?{���~�Ӄ^(��B�6�}e��ܽ�r_P+�� ����9P21;ɟl��+VU,S,'[���f��?�3x��]�Uͥ�bg�W^±�(�Ȑ�#/��84R�� �!?��#��

How to recover from an Alpha ransomware attack
The IoT company behind the curtain
Think that printer in the corner isn’t a threat? Think again
Thousands of taxpayers affected by W-2 Phishing attacks this year
Privacy Activists Cheer Passage of Email Privacy Act, Brace for Senate Battle
Two Tips to Keep Your Phone’s Encrypted Messages Encrypted
Microsoft’s CEO explains why his company sued the U.S. government
Google renews focus on Mediaserver flaws in latest Android Security Bulletin
Tick-tock: Time is running out to move from SHA-1 to SHA-2

Are you ready for the coming SHA-1 deprecation deadline? I suspect most companies aren’t. They don’t know about the issue — and the pending January 1, 2017 deadline. Others are probably aware that there is something called “SHA-1 deprecation” and have gotten some browser certificate errors, but don’t fully appreciate the need to be substantially […]

Edward Snowden – the movie

Several vulnerabilities were discovered in OpenSSL, a Secure Socket Layer toolkit. CVE-2016-2105 Guido Vranken discovered that an overflow can occur in the function EVP_EncodeUpdate(), used for Base64 encoding, if an attacker can supply a large amount of data. This could lead to a heap corruption. CVE-2016-2106 Guido Vranken discovered that an overflow can occur in […]

Anonymous Target Bank of Greece Website with Massive DDoS Attack

It was discovered that a heap overflow in the Poppler PDF library may result in denial of service and potentially the execution of arbitrary code if a malformed PDF file is opened. For the stable distribution (jessie), this problem has been fixed in version 0.26.5-2+deb8u1. For the testing distribution (stretch), this problem has been fixed […]

Microsoft Planning to Use DNA for Data Storage

An update for java-1.6.0-ibm is now available for Red Hat Enterprise Linux 5 Supplementary and Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: java-1.6.0-ibm security update Advisory ID: RHSA-2016:0708-01 Product: Red Hat Enterprise Linux Supplementary Advisory […]

Posted by Anthony Pell    An update for mercurial is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: mercurial security update Advisory ID: RHSA-2016:0706-01 […]

Posted by Anthony Pell    An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: chromium-browser security update Advisory ID: RHSA-2016:0707-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0707.html […]

An update for rh-mysql56-mysql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: rh-mysql56-mysql security update Advisory ID: RHSA-2016:0705-01 Product: Red Hat Software Collections Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0705.html Issue date: 2016-05-02 CVE Names: CVE-2015-4792 CVE-2015-4800 CVE-2015-4802 […]

Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3565-1 security@debian.org https://www.debian.org/security/ Sebastien Delafond May 02, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : botan1.10 CVE ID : CVE-2015-5726 CVE-2015-5727 CVE-2015-7827 CVE-2016-2194 CVE-2016-2195 CVE-2016-2849 Debian Bug : 817932 822698 Several security vulnerabilities were found in botan1.10, a C++ library which provides support for […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3564-1 security@debian.org https://www.debian.org/security/ Michael Gilbert May 02, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : chromium-browser CVE ID : CVE-2016-1660 CVE-2016-1661 CVE-2016-1662 CVE-2016-1663 CVE-2016-1664 CVE-2016-1665 CVE-2016-1666 Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-1660 Atte Kettunen discovered an out-of-bounds write issue. CVE-2016-1661 Wadih Matar discovered a […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Red Hat: 2016:0708-01: java-1.6.0-ibm: Critical Advisory Red Hat: 2016:0706-01: mercurial: Important Advisory Red Hat: 2016:0707-01: chromium-browser: Important Advisory Red Hat: 2016:0705-01: rh-mysql56-mysql: Critical Advisory Debian: 3565-1: botan1.10: Summary Debian: 3564-1: […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Red Hat: 2016:0708-01: java-1.6.0-ibm: Critical Advisory Red Hat: 2016:0706-01: mercurial: Important Advisory Red Hat: 2016:0707-01: chromium-browser: Important Advisory Red Hat: 2016:0705-01: rh-mysql56-mysql: Critical Advisory Debian: 3565-1: botan1.10: Summary Debian: 3564-1: […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Red Hat: 2016:0708-01: java-1.6.0-ibm: Critical Advisory Red Hat: 2016:0706-01: mercurial: Important Advisory Red Hat: 2016:0707-01: chromium-browser: Important Advisory Red Hat: 2016:0705-01: rh-mysql56-mysql: Critical Advisory Debian: 3565-1: botan1.10: Summary Debian: 3564-1: […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Red Hat: 2016:0708-01: java-1.6.0-ibm: Critical Advisory Red Hat: 2016:0706-01: mercurial: Important Advisory Red Hat: 2016:0707-01: chromium-browser: Important Advisory Red Hat: 2016:0705-01: rh-mysql56-mysql: Critical Advisory Debian: 3565-1: botan1.10: Summary Debian: 3564-1: […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Red Hat: 2016:0708-01: java-1.6.0-ibm: Critical Advisory Red Hat: 2016:0706-01: mercurial: Important Advisory Red Hat: 2016:0707-01: chromium-browser: Important Advisory Red Hat: 2016:0705-01: rh-mysql56-mysql: Critical Advisory Debian: 3565-1: botan1.10: Summary Debian: 3564-1: […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3563-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff May 01, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : poppler CVE ID : CVE-2015-8868 It was discovered that a heap overflow in the Poppler PDF library may result in denial of service and potentially the execution of arbitrary code if a malformed PDF […]

Consider Selfie Sticks Old-School — Time to use Hover Drones for Selfies
IT leaders pick productivity over security
Microsoft to begin SHA-1 crypto shutoff with Windows 10’s summer upgrade
TrueCrypter ransomware lets you pay with Amazon gift cards
Qatar National Bank Accepts Data Breach while Hackers Release Inside Video

Several vulnerabilities were discovered in tardiff, a tarball comparison tool. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2015-0857 Rainer Mueller and Florian Weimer discovered that tardiff is prone to shell command injections via shell meta-characters in filenames in tar files or via shell meta-characters in the tar filename itself. CVE-2015-0858 Florian Weimer […]

Lifeboat Hacked, Millions of Minecraft Passwords Stolen
New Android Malware RuMMS Targeting Users through Smishing

APPLE-SA-2016-04-28-1 OS X: Flash Player plug-in blocked Subject: APPLE-SA-2016-04-28-1 OS X: Flash Player plug-in blocked From: Apple Product Security <email@hidden> Date: Thu, 28 Apr 2016 15:05:32 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-04-28-1 OS X: Flash Player plug-in blocked Due to security and stability issues in older versions, Apple has updated the web plug-in […]

Security Bulletin: Steps you should take to fix a Java SE security risk on your computer

Welcome to a very unusual cybersecurity article! Why is it unusual? The title of this Security Bulletin and most of its content was provided by Oracle, the maker of the Java computer programming language. In fact, ESET is publishing this information on We Live Security at the request of Oracle. And Oracle made the request […]

We’re Going HTTPS: Here’s How WIRED Is Tackling a Huge Security Upgrade
Suspect jailed indefinitely for refusing to decrypt hard drives