New research into VPNFilter finds more devices hit by malware that’s nastier than first thought, making rebooting and remediating of routers more urgent. The post VPNFilter update: More bad news for routers appeared first on WeLiveSecurity
LinuxSecurity.com: Several security issues were fixed in procps-ng.
Reading Time: ~3 min.GDPR represents a massive paradigm shift for global businesses. Every organization that handles data belonging to European residents must now follow strict security guidelines and businesses are now subject to hefty fines if data breaches are not disclosed. Organizations around the world have been busy preparing to comply with these new regulations, […]
LinuxSecurity.com: Some more efail fixes, https://enigmail.net/index.php/en/download/changelog
LinuxSecurity.com: **Version 4.0.11** (2018-05-25) * bug #27364 [DI] Fix bad exception on uninitialized references to non-shared services (nicolas-grekas) * bug #27359 [HttpFoundation] Fix perf issue during MimeTypeGuesser intialization (nicolas- grekas) * security #cve-2018-11408 [SecurityBundle] Fail if security.http_utils cannot be configured * security #cve-2018-11406 clear CSRF tokens when the user
LinuxSecurity.com: **Version 2.8.41** (2018-05-25) * bug #27359 [HttpFoundation] Fix perf issue during MimeTypeGuesser intialization (nicolas-grekas) * security #cve-2018-11408 [SecurityBundle] Fail if security.http_utils cannot be configured * security #cve-2018-11406 clear CSRF tokens when the user is logged out * security #cve-2018-11385 Adding session authentication strategy to Guard
With the 2018 FIFA World Cup in Russia just days away, fraudsters are increasingly using all things soccer as bait to reel in unsuspecting fans so that they get more than they bargained for The post You have NOT won! A look at fake FIFA World Cup-themed lotteries and giveaways appeared first on WeLiveSecurity
Thanks to everyone who reads us and voted for us! The post WeLiveSecurity named Best Corporate Security Blog! appeared first on WeLiveSecurity
security update
LinuxSecurity.com: Several security issues were fixed in Git.
Following the massive cyberattack on banks in Mexico, we consider what can cybersecurity can do to help the industry The post The cyberattack on banks in Mexico: The challenges posed to cybersecurity appeared first on WeLiveSecurity
LinuxSecurity.com: **Version 3.4.11** (2018-05-25) * bug #27364 [DI] Fix bad exception on uninitialized references to non-shared services (nicolas-grekas) * bug #27359 [HttpFoundation] Fix perf issue during MimeTypeGuesser intialization (nicolas- grekas) * security #cve-2018-11408 [SecurityBundle] Fail if security.http_utils cannot be configured * security #cve-2018-11406 clear CSRF tokens when the user
security update
security update
LinuxSecurity.com: Several security issues were fixed in Liblouis.
Reading Time: ~4 min.Nearly 50% of Americans don’t use antivirus software That’s right; something as basic as installing internet security software (which we all know we’re supposed to use) is completely ignored by about half the US. You’d be amazed how common this and other risky online behaviors are. We did a survey of people’s […]
The FBI say yes but should you follow this advice? And if you do follow it, do you know how to do so safely? The post Router reboot: How to, why to, and what not to do appeared first on WeLiveSecurity
LinuxSecurity.com: CVE-2016-9396
LinuxSecurity.com: An update is now available for Red Hat OpenShift Application Runtimes. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
LinuxSecurity.com: An update for rh-java-common-xmlrpc is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
The scam circulated through WhatsApp aimed at users in Brazil claiming that Nike will give away the jersey that the team will wear at Russia 2018. The post False contest to win jersey of the Brazilian team found on WhatsApp appeared first on WeLiveSecurity
security update
security update
LinuxSecurity.com: It was discovered that Wireshark, a network protocol analyzer, contained several vulnerabilities in the dissectors for PCP, ADB, NBAP, UMTS MAC, IEEE 802.11, SIGCOMP, LDSS, GSM A DTAP and Q.931, which result in denial of service or the execution of arbitrary code.
LinuxSecurity.com: The redmine security update announced as DSA-4191-1 caused regressions with multi-value fields while doing queries on project issues due to an bug in the patch to address CVE-2017-15569. Updated packages are now available to correct this issue.
LinuxSecurity.com: CVE-2016-9396
LinuxSecurity.com: Security fix for CVE-2016-5003, CVE-2016-5002
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1780
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1779
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1777
LinuxSecurity.com: Man Yue Mo, Lars Krapf and Pierre Ernst discovered that Batik, a toolkit for processing SVG images, did not properly validate its input. This would allow an attacker to cause a denial-of-service, mount cross-site scripting attacks, or access restricted files on the
LinuxSecurity.com: It was discovered that Zookeeper, a service for maintaining configuration information, enforced no authentication/authorisation when a server attempts to join a Zookeeper quorum.
LinuxSecurity.com: New git packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues.
