Menu

Category Archives: Security

Articles about security

Discovered: March 8, 2016 Updated: March 8, 2016 11:30:37 AM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Downloader.Poshedo is a Trojan horse that downloads malicious files to the compromised computer. Antivirus Protection Dates Initial Rapid Release […]

Seemingly every day, we’re reminded that companies need to work harder to stay secure during a time where cybercrime is rampant and many organizations remain vulnerable to attack.  I’ve recently been speaking to the press about what can and should be done to mitigate these risks. I hope the following questions and answers will help shed some […]

Posted by Anthony Pell    Several security issues were fixed in Thunderbird. ========================================================================== Ubuntu Security Notice USN-2904-1 March 08, 2016 thunderbird vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: Several security issues were fixed in Thunderbird. Software Description: […]

Updated python-django packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 7.0 Operational Tools. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: python-django security update Advisory ID: RHSA-2016:0360-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0360.html Issue date: 2016-03-08 CVE Names: CVE-2015-8213 ===================================================================== 1. Summary: Updated […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Ubuntu: 2904-1: Thunderbird vulnerabilities Red Hat: 2016:0360-01: python-django: Moderate Advisory Slackware: 2016-067-01: php: Security Update Ubuntu: 2915-3: Django regression Ubuntu: 2921-1: Squid vulnerabilities Ubuntu: 2915-2: Django regression Red Hat: 2016:0359-01: […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Ubuntu: 2904-1: Thunderbird vulnerabilities Red Hat: 2016:0360-01: python-django: Moderate Advisory Slackware: 2016-067-01: php: Security Update Ubuntu: 2915-3: Django regression Ubuntu: 2921-1: Squid vulnerabilities Ubuntu: 2915-2: Django regression Red Hat: 2016:0359-01: […]

Several security issues were fixed in Squid. ========================================================================== Ubuntu Security Notice USN-2921-1 March 07, 2016 squid3 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: Several security issues were fixed in Squid. Software Description: – squid3: Web proxy cache […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Ubuntu: 2904-1: Thunderbird vulnerabilities Red Hat: 2016:0360-01: python-django: Moderate Advisory Slackware: 2016-067-01: php: Security Update Ubuntu: 2915-3: Django regression Ubuntu: 2921-1: Squid vulnerabilities Ubuntu: 2915-2: Django regression Red Hat: 2016:0359-01: […]

Updated chromium-browser packages that fix multiple security issues are now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having Important security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: chromium-browser security update Advisory ID: RHSA-2016:0359-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0359.html Issue date: […]

Posted by Anthony Pell    Updated openstack-glance packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Low: openstack-glance security update Advisory ID: RHSA-2016:0358-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0358.html Issue date: 2016-03-07 […]

x86: inconsistent cachability flags on guest mappings [XSA-154, CVE-2016-2270](#1309324) VMX: guest user mode may crash guest with non-canonical RIP [XSA-170,CVE-2016-2271] (#1309323) ——————————————————————————– Fedora Update Notification FEDORA-2016-f8121efdac 2016-03-06 19:17:26.629611 ——————————————————————————– Name : xen Product : Fedora 22 Version : 4.5.2 Release : 8.fc22 URL : http://xen.org/ Summary : Xen is a virtual machine monitor Description : […]

Avoid possible XML entity expansion security issue. ——————————————————————————– Fedora Update Notification FEDORA-2016-ff39572e31 2016-03-06 19:17:26.629243 ——————————————————————————– Name : exiv2 Product : Fedora 22 Version : 0.24 Release : 5.fc22 URL : http://www.exiv2.org/ Summary : Exif and Iptc metadata manipulation library Description : A command line utility to access image metadata, allowing one to: * print the […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Ubuntu: 2904-1: Thunderbird vulnerabilities Red Hat: 2016:0360-01: python-django: Moderate Advisory Slackware: 2016-067-01: php: Security Update Ubuntu: 2915-3: Django regression Ubuntu: 2921-1: Squid vulnerabilities Ubuntu: 2915-2: Django regression Red Hat: 2016:0359-01: […]

GIMP is vulnerable to multiple buffer overflows which could result in the execution of arbitrary code or Denial of Service. – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – […]

Collaborating on incident response: Rook Security
Privacy groups want rules for how ISPs can track their customers
It’s 2016: Do you know where your data is?
Multi-factor authentication goes mainstream
Verizon Wireless fined $1.35m in ‘supercookie’ privacy settlement

Verizon Wireless will pay a $1.35 million fine after the company inserted undeletable ‘supercookies’ into its users’ browsing sessions without consent, reports Reuters. Unlike regular tracking cookies, the so-called supercookies are much harder to delete and can’t be bypassed within private browsing sessions. These cookies can anonymously collect information about users’ web activity, either to be […]

Introducing Google’s ‘Security Princess’: Parisa Tabriz

��}��Ʋ�o���0�ND�”��ҮH]i%ۺ�,Ż�ﹶ�5�$vA��riYU��’�J��+�S�’p���DS�9��5��ߞh��Ⱦ�k��M��?l���oLE� �kP�������`�g߿��X�Y�����k̶�5�k�s�|�`Γ� h�1iO��^���g����’ԇs=��kL=�����%�[Svy h��Z�E�������4“��Hr��1[E���k_z������n��>�Gg�=Wn”K�x�Dɿ[$Lӱp�}ˮ/��ӮBG۷�)X��v�u����D�dK}�%�@�> ������3��C���0 ���ޡ_5I��z:�9��^G��E07���5c���*�ac/�o�ߊ���a�0l����@���&ϲ��u9�CG���L]�$�?K�c���g�/�TteW�w�E�q�n�^���J/��5gQ�”�ҙCϱ����70���u^� �b��1y=.�A�����eߜ����f_a�=�W������:M,3t�m��2���fuAl@k�1te���?�>K����_Y=��~�q$��#V��o �

Why security is really all about trust

Security isn’t black and white. It isn’t a choice between full security and no security — it’s a continuum with a lot of gray in between. Full security, even if achievable, would “secure” things beyond the realm of reasonable usability. But even then hackers would find a way in. Usable security comes down to a single […]

Demand for security skills is ballooning: So can former hacker hotbed Romania help?
Let’s Encrypt reaches one million certificate encryption milestone
DOJ appeals New York court order in favor of Apple

Discovered: March 6, 2016 Updated: March 8, 2016 2:01:58 AM Type: Trojan Infection Length: Varies Systems Affected: Mac OS X OSX.Keranger is a Trojan horse for Mac OS X computers that encrypts files on the compromised computer and asks the user to pay in order to decrypt them. For more information, please see the following […]

Google patches remote-execution flaws in Android

Palo Alto Networks recently discovered ransomware hidden inside of the torrenting app ‘Transmission’. While this may come as a shock to those that still believe the Mac is a fortress that can’t be broken, the rest of us are not shocked at all. In fact, a few months back I wrote a blog warning Mac users not […]

First Mac ransomware had sights on encrypting backups, too
Is a cyber-liability insurance policy in your company’s future?
You can now Trump Donald Trump on this website
Consumer and enterprise social engineering tricks: What’s working
Webroot on the rise of polymorphic malware threats
“Accessibility Malware” puts 65% percent of old version Android devices at risk
PhishLabs on the growing sophistication of business email scams
Behavioral biometrics and the future of the password
BioCatch on the rise of behavioral biometrics
Ransom Malware Targets Apple Users for First Time
Beware spear phishers trying to hijack your website

A simple trick of social engineering could result in you handing over control of your website to a malicious attacker. To show just how easy it is to fall for a spear phishing attack that could hijack your website’s DNS entries and even give hackers the ability to edit your webpages, read on… Here is […]

The ultimate hackathon survival guide
MIT’s new 5-atom quantum computer could make today’s encryption obsolete
The security review: Security is ‘easy’ – just ask someone at RSA

��}�۶��o�*��gM)I}̗g,��c���ڱ��9ٳNv “!�3��hg������ [�O��’�’�n��%�F#;ɖ}Nl��Fw��h��{����?߾ ߾�j���Ǔx�����|������}-�I����Cs�,��נΝ�F��x�=������9q/��q��̏���iĖ��Z�.ca��m�52e�K�Z�>|��@�55ij�̜1Ͻ`��I��s���,4RV���c���”m:��xHN����v���|.�Z��9yw��Fq�ǖu7Oa�q;r�Ұ��<�#q��c���?�/��lBfמ@ٮ�!#�sƹ�EO��/�̂�1<�0$Ō#ĴE��(H|k&���mKМ���*�˸�YЛ����|`Bo���;{V�g���!�ed����Y�c��s�Q���"e!��P ^��#&�OQoԗ��*���[Z0W|����8c,�Uy������W�*y�g#W[W��!�]��ج~�*a2��y�)(�|��E��3���;�Ý�ao�a�}�n/�ޝ�1[��9현^@�8�H�k��T���.wz]�,�ڗz*���Ц��k�'�)��ڒ�q&^ҫO��4�ܚk�_��������*_R��2��_�c��-�π�X��xCB/��)�k4`$�孋3zA�[m%��� f��,d���=aq<�I�|Ԇ���AM���h�hqsf��GKЇ�h�A�~�D�����~�GKki�T3C?x�D6�?j�0�D�<�z���du}�Kl錋�2h?���S��6_������v��(�rj�ְe7?���Ӡ͏4"vh *��K~��Y��5[N�6�,��e��A�WC�:Z�(bq�s�z�{���X����<�p�2$�nxI�F`�aFk�~�b�H�$Kml��`z��q���now���w�鶲��~��n��-ی��4�߿{�h����d�c���:p�VoW�j�����Ka�������N��~h��l��e4e+h���yd�<����e��[U���{:�D���FkB�& C�;��sv� [��9 q!���; a�q�a���T����+@�������"|޽�8���6����VL��n��h��h{x�nd��s�O�e�C9�C�� ��P��v:uO� U�yF�{f�z���Gi�JTK�w�EtQ�n^�@�*/��3’qDb磲�y�X����D���]�_���;/��jQ’��������:KE+����r������§mט��w�r�@Fo�(�I�0.����e��)+:P h��U�p7*ec��Rc0?2����s�!�7 `��d1f֔�S��A���VK��[�|馽�߅[pg����H�M��md߿5a��ש��}�5a�/�� �ɔœ���Q�Z�`�Y��s�j��������b��4=��iE�?��z� }�UG’ywrB�f�|ØS���&�=L”u!�`��x�U���~L/’`� �E0ʓ ��$��gէ����t䜎�?�>I�����_I#��O>����0?�l�s�”�m5K<��Q����ퟲ�ܔv�w��LX�?c� b l�E�� ��_���0����o�K�t��;����G����G�"�U�!��/�̇��e�V�̲ϱٖܽ� ex��J5�������cw:&�M��:������4"X�����ihB! ^�J#eÃ�GO�O˽}@�����H�ne�`�%�'� �1��p����|�x?��_q�)#�q<5Ŏ�~��]���s�FG���l1t����T`Vj���sZ_�=�W��x}�^_G��+4u�'��[z��~t&�^_h�3��ꮾ��#$���}�xG��L� �hV�_�j鋱ҫ���w�r�Mۣ��O/p�E|(|A����}5 o���s�?�:Q0�0���N� �K�gL�x�Sx�d��2p���(ṃǔ�e��a��F­�&x�o��C��آ������"�c�N_<����b0�G��S��F��8y���41�!�z]Y=��Q���:T��&’�ln���.�X-DxH�”�Y�|%�D�p�RX�6+X�Z�s�ܶ p�|^0P1�G.��@�R�����t�Y��RJ�ȅmx� u�AEh�W �!(�1Ɯ �V�!�0�����㚥�G E]1��2�A$hW��^��X�Y��z�:,��=Y��_��’@�>y.��’�y�>�����+x�|�^�*j���Tf��K��^&�1�A�(��tS�TO�;�y����fCm����N;�F��^Qki$/���BP�ɫ’���$�_ ���ɘ���~}�ѐg���v� vI�!f��iI�s�3��)��|4�{I�}aM�n��4����}lI��y���z*^��ΚjT��Y�ȲgPeJ�&��~�eu��f�”5UH+(g�W�T-��* `�gV��”��kQǍ����>�Jgo��;R԰���������T�ĩ���>���U;�Q/y�FrD��[47���X�)aG�(�`����:����~iZ�j��K_d�0��9@(�$U% ��� Ȧ���Iz��X㬝_�-0��J�����]OI����#�� D�Q�HV]pђ��o�?��@�?oǦk�6٣PՁ>��s�����KE����NW ���Rõ”�V�2�K����wz�m2 �#E�9���mF^�r�ck2�t�*jd,�έ]);��v{�#E��0�c�E�X��3���d�j���v��=��ȫ~:���K�&ݛ�Jе������[�ܹ��uHx�oo�*!=/�u�xeA�媗z��5�k ��sU�I��k����a1>C�t�h�D�z�}��~�k�o﫽g9*z�tU-�Z92�N�S�i%_u����`�l{`��K2��/� �W�k��&’�uΏt;{� ��0�`�[(E���F��v�z��y��}Mg n��*�c���ĵ#����”��!�~_K,u�W�Kz��t)=:�Jd,��|=”*6����C�n^l1�B��c�a�Wg�Z�>3l� h�����d���U���qSf�!�������?��Qug(�I��3J�g�Z�s��SB�&4�4Dr”�=���I�V����ܒ��V��Ւ��T��k�g~g|�4ߋk�����I7ס���!��*=76B/�”�P���@�P���`�;�>Lau⻦��U�W ��^Z8�&�K�sҗ����7�3�� b]§YH�&SŨ����Nz� �eN�����!l�e�9���Q)r�����M�Z�2����OKԣ5q�ű!��o�Y��0���Ϟ=���#*���p>^Yb��.����4�?]�R6��#6��w:����q-G�l�y�P�ո�I,ܴK��$bK6��B��F`}M|ж��W蝢Kd}�:�’f�v���]���n�BPs_U4��k�M�Y� O�ͱx�O�-�ܜ�+�t��2k��� ���E��!Z�^�W���S��T�w���uPߩu���F��6″�փu�O4��|*��`��� ��<���@WϹ�VQ8�.2|�J�Gt}���ok_�hO�}�^Ɉ�%�y��E�]�X��;IB@�}�8� oe���%� � iL�hNFt�z��$H<��������a��6pK�cI�ٞc0���NYt�8 […]

DoD Invites Hackers to Hack the Pentagon
Whole lotta onions: Number of Tor hidden sites spikes-along with paranoia

Several vulnerabilities were discovered in JasPer, a library for manipulating JPEG-2000 files. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2016-1577 Jacob Baines discovered a double-free flaw in the jas_iccattrval_destroy function. A remote attacker could exploit this flaw to cause an application using the JasPer library to crash, or potentially, to execute arbitrary […]

Several vulnerabilities have been discovered in the chromium web browser. CVE-2015-8126 Joerg Bornemann discovered multiple buffer overflow issues in the libpng library. CVE-2016-1630 Mariusz Mlynski discovered a way to bypass the Same Origin Policy in Blink/Webkit. CVE-2016-1631 Mariusz Mlynski discovered a way to bypass the Same Origin Policy in the Pepper Plugin API. CVE-2016-1632 A […]

Go home SSLv2, you’re DROWNing
Primes, parameters and moduli
The SLOTH attack and IKE/IPsec
DevOps On The Desktop: Containers Are Software As A Service
Risk report update: April to October 2015
Red Hat CVE Database Revamp
Important security notice regarding signing key and distribution of Red Hat Ceph Storage on Ubuntu and CentOS
Factoring RSA Keys With TLS Perfect Forward Secrecy
Secure distribution of RPM packages
Remote code execution via serialized data
Time Warner Cable’ Business Class Customer Support portal Hacked

Several security issues have been corrected in multiple demuxers and decoders of the libav multimedia library. For the oldstable distribution (wheezy), these problems have been fixed in version 6:0.8.17-2. For the stable distribution (jessie), libav has been updated to 11.6-1~deb8u1 which brings several further bugfixes as detailed in the upstream changelog: https://git.libav.org/?p=libav.git;a=blob;f=Changelog;hb=refs/tags/v11.6 We recommend that […]

Multiple vulnerabilities were discovered in the dissectors/parsers for Pcapng, NBAP, UMTS FP, DCOM, AllJoyn, T.38, SDP, NLM, DNS, BED, SCTP, 802.11, DIAMETER, VeriWave, RVSP, ANSi A, GSM A, Ascend, NBAP, ZigBee ZCL and Sniffer which could result in denial of service. For the oldstable distribution (wheezy), these problems have been fixed in version 1.8.2-5wheezy17. For […]

Hackers Target Oil and Gas Companies Through Internet-Linked Systems
Are ‘Artificially Intelligent’ Hackers The New Thing?

Alvaro Muñoz and Christian Schneider discovered that BeanShell, an embeddable Java source interpreter, could be leveraged to execute arbitrary commands: applications including BeanShell in their classpath are vulnerable to this flaw if they deserialize data from an untrusted source. For the oldstable distribution (wheezy), this problem has been fixed in version 2.0b4-12+deb7u1. For the stable […]

On Monday of this week, Webroot joined Cloudera, the leading provider of modern data management and analytics systems built on Apache Hadoop, in announcing Open Network Insight (ONI) Project, a database and tools designed specifically for cyber security incident response. ONI will enable security analysts and responders to manipulate the massive amounts of data generated within […]

Raising awareness of business email threats: AppRiver
Why data security is getting more complex: Vormetric
Network hacking methods and prevention tips
Behind the scenes of Vidder’s $10K hacking contest
The tricky balance between back doors and encryption: Zscaler’s Jay Chaudhry
How Verizon’s new Data Breach Digest provides insights into security attacks

German Hospitals Latest Ransomware Target In the past week, several German hospitals have reported ransomware attacks on their internal systems. While one of the hospitals was able to minimize the damage by isolating the infected server, Lukas Hospital wasn’t as fortunate, as their system had been encrypted before they could react properly. Fortunately, the hospitals […]

Security spotlight: Kevin Walker, Juniper’s Security CTO
The family security checklist

��}ے�F���(A”io}Q�H�%�5G��ny�>�OG(���fsdE�?��n�n���F����|�ff@�l6%�Ҍ%�ʪ�[efeU=���ۓ�?�y�~�����’��e.��}Mx��B1r��?>b�8�L��T�^t_�:wO�w��{}������cǓ�-.K���ω���]�oWA���z��B��3r,��� � ;��?f�a������t��ݯ��[����W’��=mw%,��L��.X(ܾ�sWD!1�_�݊”�M�����_’@辦H<�͌�p�K + �xnX�Ԝ��O�TD&|'h&5�,�����w��u�v�D���_?����7a��Oc:����DZ�b�^���q�,��&ºp�(~l�Bw�Ed�NP"ȿ8ޘ��$��`�8��x~���Ob6�X��G��0�?�$x��YW"�M�%��������P`� �掠�:2����0��,��p��%:���ꚭ�)����� ���� D�I�]�a�I� B�&�>�������z���=�=:j�?l��Z��া �u-�N�h��Q��b?@]z{8Δ���t�)�$p}nGi�gES�”4΃q�=��bІ���⡝k/J�Sε��xҲb 7�+��$�`�[�B+q�O���?o�b�P���!N�&��p��ŷ,p��4�)��0y��_r�V@�;3dz�q6��?wNE�#�g�!���َ�h66#cf���g���lZ~(~6����A���55h ��7���%����)*��Z�ş��g���-�G�*�0� �1�ўGO�N��q�}�p�ú7J�hM(�#�c�NpŞ�`�bF.k�~�c�H�4�jl�Bz�o���^wo�����4���A��j�Mˈ���8�]���Qs�������>r��-64LO@L�2� l7>@���;:��kïO���u����>_����f �”{���>.(�C�C���K�+Pn����-+��ak�q�^���eQ��@q(�ܚP��Ӏ����_�wQ������u� Z8t(Gr�eq��q5� 3R������� �Q/�n��q<�L=ֱ���h�U��h|�K]մ}+Ai��] ��M�VR�贔��]g:�z3��7�'b��ޱ�(p���E�F�Ł�܋��m��0�.�ң �nU}�g<��X[L��;�x���#�bF���^����� �-c �g�gW�'^�!���wK?/��.f�9v�����3o��B@k�I����)�,�,}=��w�H���E`v�F-��M���[@Q@�]w�~�A����Gqȃ��ÖH�v���9H��:z�.��Hˮ�Դ���[����0*�ac?��ߊ���a�0�Z�х�ϲ��u9�CW���JQ�N�.��R�g䶱o��ﳴ�W�Q���%@��ƢF� 7/G aK/��=gq�b�#�u����70���[{��^�J�b��3y=.��y��V*a�)��m�S,�ۮ>u�!���”��ޮ�P%�d����#0�3Q��Q��t�����} JM��(xhM�&��u�ބ�|C��X��(:�I��iZ���“1�k�]�lv�_��ԉlHW��9�j�����Hk��?��’SO|����|�ϥ��BT�7���.Hp7O��”�8�=�y�ju�����ԅO]]l��NOY�h����KD����I�.�]����.4�-�{1����K6���?��$�c5����1䜍��X��>=���WV��~i�*Έ���[å�HKB m�a�T.�jJ�R`���bA�8LD�H���&0�v9�ϖ����I��fR��v��G��᭬/?�~ɪF��s��ma���L��PԱ�&�=������$Ѥ�S ��7Εp_ڵ&���ڇ�G�����G5����|(�D��~)�I[3˺�d[r�����������_����0I_kkL���0_��T_K�3��H!/GJ#e�AF��’���>���X��O�z@.7��`ƒI���M��%��h��0�!��+���6P� ��1%3�Ë�9�D5/D� ${�=������dܙ )PE�ր����ت�b`m-G�����p���@#G0��e��j�/�ؐ�2� Hy_�S#�y׎���{$�7��o�FS`�� �R�Y��Z�4��{�_懦���{���_��[{R{v�C�V;>�j�O��b�_ܭ�������yh�ǣ�L�C4�B�_�zլ-hU[����C@��hZ.���6��%.�Ї�h09�;��q0xC-�S���� �iO�2�r�U^�]}j��!�ƒ�”�*�j.��k�R �����8���]T��htP�?�,�ً�o��o_k����P�`�����bw�L���W�U��e�#�F⸪�PN��Y67��X�K�&vxH&�,���W4″��ֱ��3W�:��(�L.L��#��T ��@ȇ�How�Y��VJ�”�¶?:�H�cP��w�c�i+��5@s��)�b����q�+�r�XSLR{����W�Lx�E���}�6X�h�Y��H�Ț,��dJ����� k ׫ �+�����^�)mV2��>{,7�lR����a��q���v’eN�S���6j����z���xa��#4+f��t�����ב�x��i8Gz�X�i�J�%D6���.5Z�:S��Vr��T˭� �I1^�ci���� �SL�#L�&BPJ*jl&�0f�`UC��+�s���` M� �@��-o3�W��0��’w�� ��i�~`����H ��x�x�����?�10~-1�]0���p˔�1��m��R����e���K����[3�̐�&ө����Tv*�L5Q6���b��)��K��R{he���y��’ �j�$ .��e��:&G#�Y����y����p�?��������E0��H#y%�T���~|<ʥ�hw��3�S9+�E^�ro]���8�l���B�D�]P{o����!�1HCC�w瑓�l)7�W��m2, �L��S?:&�Ѯ��k���j�)j�`( y�@ïa”~[�W�!�j�)���d�uC�>z��0$ٵ��”TSB>��1[9������Y/y����[47��ߡ,��J�cv��?��xy�UHqs�4�f���/�Y���t(�$U& ��� �⡈��Qz��X��Y;YI[`Z�2��[���s�&x=[d�r�+P��P���K�$�.�h�xv=�Vn 7�7�m�u�Q�����9����ݕ���i��f�kA�]��JxCEw����d�^��KFp��Ð�M�7U�`hi�ME����ܹ �ڬ<7�o�*!#/� �xeA!�r�K�S�J,��B�w�?�oP3�38�34NG��I(��[j-j9npM���}��,�R�YMU˿V���ŪSƬU���:ív�y���r�69Wl�Ĕ/� VW��Ce���u{��DE�4�W�1�W<�o��Ie<��.�ʭ00�G:�� ���۔��i��Z���;A[����]�V�5�Z��z-�kB��S{�5(�fMj��s��e����ޫ�|�� […]

Just 1 in 7 security chiefs report to the CEO, despite boardroom concern

Most businesses now recognize internet security as a real concern, yet new research has found that just 1 in 7 security chiefs report directly to their CEO. An ISACA and RSA conference report titled State of Cybersecurity: Implications for 2016, found that 82% of information security professionals feel that their board of directors is either concerned or very […]

RSA: Will your next phone have quantum cryptographic 2FA?

��}��F��o)��P�&�”��R�H�Ԓǚ�,�[�W�v�”�n���l����k#�”�.�`�M�I.3� �f�)پ�f,�@UVVVfVVVV��{��������ׯ���}&�EO;�Xx��n�Y�WO��e����1#�xhh�ٯ��_�����$�3p�^�� {$�U=>=������c��-.K��ω���]�kWA���F��¸�3t,@��r�O~�/����0�s_w����?’/o����8�:���&�w���l�s`�_��t����wv�����Z����w���=mw%,��L���Y(ܞ�3WDc!�1�_�݊”�M�����_�0�=M �t:5��u.D$�$t�i��40R�x,&”j�w�֤��et�=����{��ލ��!����3q�!l6u�1`�`�ѿ�8vbW���l�_[/Źy�r-Iu�”<�xh�Z��Ʉ�3mI�?�-���4ΒPJr���8zK��O���%?�,c�P����N�M�ϣ���x�79�I�<�=���6����ևw�0��=��&y��I�4��|A�’Y���!X�@���GZ���X1R;����П��~�ۢ�����k���;�칵_o��z�2c�9��O?���MWx�x��n�p�����`���z6v�%�0B�����F�n����[���{�bM�Տ,3 �Gd+ٱ1�VU�����”Q�p�աU�����5�~�-#����z�”g�cC����T�D�� �����w� �B|ױ���.�a�`q�fk�a�N�~Ȟ�`Y�v�_u 3Ȍ���~�t��9a”j���á�4΃C3����S�� �J����U ۷���UG �)٪Oj�M�Y��3|#�8��5�’b��ޱ�(p��֬(���8�3�O}�6�h���јZU_����C���ZW�S��!k1��_�J/ƕ���2Z��Q�’�]�O�C���Ww˕f~e���:s�����=`���ia dՙ7�kO�r΂��o�o �]723#�YhL|�sů��������[�Ys������י)4��4��Cޮ’�M���e����s.|�E)AI�2��gr�ls��Ő’n���E� �X���-Q�j�!f����`��N@�>5�=2Zh�l 7CE���:�F�~�B�?�G1����:N3��b��C�Y3���!z�1��LKTAj��.����è`���p�=��+�ۣ0a”���Z�ѹ�ϲ���+��P��v:u�z�*�

8 fears keeping security professionals up at night
DROWN Flaw Illustrates Dangers of Intentionally Weak Crypto
Hacker Says He Can Hijack a $35K Police Drone a Mile Away
US to renegotiate rules on exporting “intrusion software”
New attack steals secret crypto keys from Android and iOS phones

Discovered: March 4, 2016 Updated: March 4, 2016 2:54:01 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows Me, Windows NT, Windows Vista, Windows XP Trojan.Snifula.F!gm is a heuristic detection used to detect threats associated with the Trojan.Snifula.F family. Antivirus Protection Dates Initial Rapid Release version March 4, 2016 revision 019 […]

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service, information leak or data loss. CVE-2013-4312 Tetsuo Handa discovered that users can use pipes queued on local (Unix) sockets to allocate an unfair share of kernel memory, leading to denial-of-service (resource exhaustion). This issue was previously […]

Ralf Schlatterbeck discovered an information leak in roundup, a web-based issue tracking system. An authenticated attacker could use it to see sensitive details about other users, including their hashed password. After applying the update, which will fix the shipped templates, the site administrator should ensure the instanced versions (in /var/lib/roundup usually) are also updated, either […]

The update for linux issued as DSA-3426-1 and DSA-3434-1 to address CVE-2015-8543 uncovered a bug in ctdb, a clustered database to store temporary data, leading to broken clusters. Updated packages are now available to address this problem. For the oldstable distribution (wheezy), this problem has been fixed in version 1.12+git20120201-5. For the stable distribution (jessie), […]

PHP.Cryptolocker.G is a Trojan horse that encrypts files on the compromised computer and then prompts the user to purchase a password in order to decrypt them. For more information on ransomware, see our blog: The dawn of ransomwear: How ransomware could move to wearable devices

Risk High Date Discovered February 12, 2008 Description Microsoft Publisher is prone to a remote code-execution vulnerability. An attacker could exploit this issue by enticing a victim to open a malicious Publisher file. Successfully exploiting this issue would allow the attacker to execute arbitrary code in the context of the currently logged-in user. Technologies Affected […]

Risk High Date Discovered February 12, 2008 Description Microsoft Publisher is prone to a remote code-execution vulnerability. An attacker could exploit this issue by enticing a victim to open a malicious Publisher file. Successfully exploiting this issue would allow the attacker to execute arbitrary code in the context of the currently logged-in user. Technologies Affected […]

Risk High Date Discovered February 23, 2007 Description Microsoft Office Publisher is prone to a remote code-execution vulnerability. An attacker can exploit this issue by enticing an unsuspecting victim to open a maliciously crafted Publisher file. Successful exploits may allow attackers to execute arbitrary code with privileges of the user running the application. This may […]

On encryption, AT&T backs Apple versus the feds
US says cyberbattle against ISIS will black them out
One-third of HTTPS websites left vulnerable to DROWN attack

A new vulnerability could leave as many as one-third of HTTPS websites open to decryption, meaning that sensitive data including usernames, passwords and credit card numbers could be at risk. The vulnerability has been dubbed DROWN (Decrypting RSA with Obsolete and Weakened eNcryption) and affects servers using an SSLv2 certificate. The website for DROWN states that as many as 33% of sites […]

Cisco issues critical patch for Nexus switches to remove hardcoded credentials
<div>Security is ‘easy': Just ask someone at RSA</div>

��}�۶��o�*��gM)����%{��{3�ɞk{�(�8C?F�8Su�am�n�}���’��&�I��R$Ei4�I��|�”�F���h4���9~�Ϸ/���^��s��8�x̳�QO��ӉƂ��˞&F�l��a�)F�9�M?��A�;���r�w��{<�EE �K�^�c��܏�w��k̖�zZ�/�&6xd��0�q/��Ɓƚ�j8����q,&��/��wF�Xշ&��]�|�0Ε��N<�9�µ�A?���ص

Make threat intelligence meaningful: A 4-point plan
FBI vs. Apple Establishes a New Phase of the Crypto Wars
Apple vs. FBI: Even Cryptographers Cannot Agree
Latest attack against TLS shows the pitfalls of intentionally weakening encryption
The US Department of Defense searches for hackers to penetrate the Pentagon