LinuxSecurity.com: An update that fixes 21 vulnerabilities is now available. An update that fixes 21 vulnerabilities is now available. An update that fixes 21 vulnerabilities is now available.
LinuxSecurity.com: An update that fixes 21 vulnerabilities is now available. An update that fixes 21 vulnerabilities is now available. An update that fixes 21 vulnerabilities is now available.
The number of IoT devices is set to surpass 20 billion by 2020. We take a look at how connected things threaten our security as cybercriminals exploit weaknesses in the smartphones that control them. The post Are smartphones threatening the security of our IoT devices? appeared first on WeLiveSecurity
Trick the firmware and you have access to the whole system. Here at Black Hat, there are a lot of people doing just that. The post Black Hat: Hacking the firmware, the next frontier appeared first on WeLiveSecurity
Anton Cherepanov, a malware researcher at ESET, has picked up a Pwnie Award for Best Backdoor at this year’s ceremony at Black Hat USA 2017 in Las Vegas. The post ESET’s Anton Cherepanov picks up Pwnie for Best Backdoor appeared first on WeLiveSecurity
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low.
Risk Level: Very Low. Type: Trojan.
LinuxSecurity.com: This update addresses the following vulnerabilities: * [CVE-2017-7018](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7018), [CVE-2017-7030](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7030), [CVE-2017-7034](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7034), [CVE-2017-7037](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7037),
LinuxSecurity.com: ## 2.8.25 (2017-07-17) * security #23507 [Security] validate empty passwords again (xabbuh) * bug #23526 [HttpFoundation] Set meta refresh time to 0 in RedirectResponse content (jnvsor) * bug #23540 Disable inlining deprecated services (alekitto) * bug #23468 [DI] Handle root namespace in service definitions (ro0NL) * bug #23256 [Security] Fix authentication.failure event
LinuxSecurity.com: – Upgrade to upstream v3.0.15 release. See upstream ChangeLog for details (in freeradius-doc subpackage). – Resolves: Bug#1471848 CVE-2017-10978 freeradius: Out-of-bounds read/write due to improper output buffer size check in make_secret() – Resolves: Bug#1471860 CVE-2017-10983 freeradius: Out-of-bounds read in
LinuxSecurity.com: Rebuilt to new upstream version 2.7.1 fixes rhbz#1443071 and rhbz#1443129
LinuxSecurity.com: This update fixes multiple security vulnerabilities (CVE-2017-7515, CVE-2017-9775, CVE-2017-9776, CVE-2017-9865).
LinuxSecurity.com: * Bump to 1.8.3 * Security fix for CVE-2017-8932 * add support for 28+bit OIDs in asn1
A homograph attack is what happens when attackers register domains that are similar to the originals, with valid certificates. The post Homograph attacks: Don’t believe everything you see appeared first on WeLiveSecurity
If industry frameworks are to inform and secure the critical infrastructure writ large, here at Black Hat there a lot of people punching holes in them, and in simple ways. The post Black Hat 2017 industrial hacking: The song remains the same appeared first on WeLiveSecurity
This year at Black Hat, tiny automated hacking platforms are everywhere, loaded with tasty purpose-built tools that can be used to break into your systems. The post Black Hat 2017: Non-standard hacking platforms reign supreme appeared first on WeLiveSecurity
Risk Level: Very Low. Type: Trojan.
security update
security update
security update
LinuxSecurity.com: This release fixes a use-after-free in replaceChild() call.
LinuxSecurity.com: * CVE-2017-7718: cirrus: OOB read access issue (bz #1443443) * CVE-2016-9603: cirrus: heap buffer overflow via vnc connection (bz #1432040) * CVE-2017-7377: 9pfs: fix file descriptor leak (bz #1437872) * CVE-2017-7980: cirrus: OOB r/w access issues in bitblt (bz #1444372) * CVE-2017-8112: vmw_pvscsi: infinite loop in pvscsi_log2 (bz #1445622) * CVE-2017-8309: audio: host memory […]
LinuxSecurity.com: Multiple vulnerabilities were found in in qemu, a fast processor emulator: CVE-2017-9310
LinuxSecurity.com: Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in sandbox bypass, use of insecure cryptography, side channel attacks, information disclosure, the execution of arbitrary code, denial of service or
LinuxSecurity.com: Multiple security issues have been found in Thunderbird, which may lead to the execution of arbitrary code or denial of service. Debian follows the extended support releases (ESR) of Thunderbird.
LinuxSecurity.com: Fix CVE-2017-11368 (remote triggerable assertion failure in krb5kdc)
LinuxSecurity.com: This release fixes a use-after-free in replaceChild() call.
A jump box is a secure computer that all admins first connect to before launching any administrative task or use as an origination point to connect to other servers or untrusted environments. Over the last few years, with malicious hackers and malware infesting nearly every enterprise network at will, security admins have been looking for […]
When it comes to protecting corporate information, some doubt whether or not the cloud is the best option. We look at all the security services available. The post Is it safe to store corporate information on Google Drive (or similar services)? appeared first on WeLiveSecurity
Cameron Camp, in attendance at this year’s Black Hat in Las Vegas, takes a closer look at attacks against physical infrastructure. The post Black Hat 2017: Hacking the physical world appeared first on WeLiveSecurity
LinuxSecurity.com: Several security issues were fixed in the Linux kernel.
LinuxSecurity.com: This update includes the latest stable release of _Apache Subversion_, version **1.9.6**. ### User-visible changes: #### Client-side bugfixes: * cp/mv: improve error message when target is an unversioned dir * merge: reduce memory usage with large amounts of mergeinfo ([issue 4667](https://issues.apache.org/jira/browse/SVN-4667)) #### Server-side
Social engineering may play a vital part in persuading a victim to open a malicious executable or website, says ESET’s David Harley on social engineering and ransomware. The post Social engineering and ransomware appeared first on WeLiveSecurity
ESET researchers have discovered an Android app store distributing malware on a mass scale. The post Malware found lurking behind every app at alternative Android store appeared first on WeLiveSecurity
A new £20 million cybersecurity programme to train teenagers will be launched in the UK this autumn, as part of the government’s plans to address the skills gap. The post £20 million cybersecurity programme to train teenagers set to launch in UK appeared first on WeLiveSecurity
LinuxSecurity.com: Fix CVE-2017-11368 (remote triggerable assertion failure in krb5kdc)
LinuxSecurity.com: librsvg 2.40.18 release, fixing CVE-2017-11464 (division-by-zero in the Gaussian blur code). For details, see https://mail.gnome.org/archives/ftp-release- list/2017-July/msg00078.html
security update
Type: Vulnerability. Adobe Flash Player is prone to multiple remote code-execution vulnerabilities; fixes are available.
