Menu

Latest articles

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security fix for CVE-2016-8743, CVE-2016-2161, CVE-2016-0736

LinuxSecurity.com: Security fix for CVE-2016-8743, CVE-2016-2161, CVE-2016-0736

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: New expat packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: New openssh packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: New httpd packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: Multiple vulnerabilities have been found in Samba, the worst of which may allow execution of arbitrary code with root privileges.

LinuxSecurity.com: Multiple vulnerabilities have been found in Xerces-C++, the worst of which may allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities were found in Tor, the worst of which could allow remote attackers to cause a Denial of Service condition.

The real reason we can't secure the internet

Last week I speculated that the current horrible state of internet security may well be as good as we’re ever going to get. I focused on the technical and historical reasons why I believe that to be true. Today, I’ll tell you why I’m convinced that, even if we were able to solve the technical […]

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Firejail, the worst of which may allow bypassing of sandbox protection.

15% off Nest Cam Indoor Security Camera – Deal Alert
A year in infosec: Bears, botnets, breaches … and elections

security update

Man Jailed for uploading UK’s Top 40 singles on The Pirate Bay and KickAssTorrents

security update

security update

Tumblr Attackers Now threatening to Ruin Christmas for Xbox Users with DDoS Attacks
Cerber Ransomware Infecting Devices by Exploiting Flaws in Web Browsers

security update

Android-compatible Google Daydream VR Controller Hacked to Run on iOS
Clever Facebook Hack Reveals Private Email Address of Any User
Exim gives Linux admins a security fix for Christmas
Steam and Origin Servers Down? Phantom Squad and PoodleCorp Claim Responsibility

LinuxSecurity.com: ### Botan 1.10.14 ### * NOTE WELL: Botan 1.10.x is supported for securitypatches only until 2017-12-31 * Fix integer overflow during BER decoding, foundby Falko Strenzke. This bug is not thought to be directly exploitable butupgrading ASAP is advised. (CVE-2016-9132) * Fix two cases where (in errorsituations) an exception would be thrown from a […]

LinuxSecurity.com: gdk-pixbuf 2.36.2 release. * Remove the pixdata loader (#776004) * Fixinteger overflows in the jpeg loader (#775218) * Add an external thumbnailerfor images * Fix a NULL pointer dereference (#776026) * Fix a memory leak(#776020) * Support bmp headers with bitmask (#766890) * Add tests for scaling(#80925) * Handle compressed pixdata in resources (#776105) […]

LinuxSecurity.com: Security fix for CVE-2016-2125, CVE-2016-2126

LinuxSecurity.com: ### Botan 1.10.14 ### * NOTE WELL: Botan 1.10.x is supported for securitypatches only until 2017-12-31 * Fix integer overflow during BER decoding, foundby Falko Strenzke. This bug is not thought to be directly exploitable butupgrading ASAP is advised. (CVE-2016-9132) * Fix two cases where (in errorsituations) an exception would be thrown from a […]

  As 2016 comes to a close, it’s time to reflect back on the largest/most significant security news stories that left an impact on the world. Mirai Botnet Being hailed as the largest attack of its kind in history, the DDoS attack launched by the Mirai botnet encompassed over 100,000 unique endpoints and hit a […]

Nook 7 tablet updated to neutralise ADUPS fear, says Barnes & Noble
News in brief: Snowden denies allegations; Uber moves to Arizona; Wikipedia reveals most edited page
Cisco Warns of Critical Flaw in CloudCenter Orchestrator Systems
Netgear plays down router security flaw
Group that attacked Tumblr threatens to DDoS Xbox for Christmas
Encryption backdoors are ‘against the national interest’
Apple gives iOS app developers more time to encrypt communications
Apple Delays App Transport Security Deadline
Customers reporting their Groupon accounts are being hacked
Vice is the latest site to call it a day on comments
US healthcare under siege: Got good insurance?
Free cybersecurity tools for all your needs

LinuxSecurity.com: The 4.8.15 stable kernel update contains a number of important fixes across thetree.

LinuxSecurity.com: x86 CMPXCHG8B emulation fails to ignore operand size override [XSA-200,CVE-2016-9932] (#1404262) —- ARM guests may induce host asynchronous abort[XSA-201, CVE-2016-9815, CVE-2016-9816, CVE-2016-9817, CVE-2016-9818] (#1399747)qemu: Divide by zero vulnerability in cirrus_do_copy (#1399055) [CVE-2016-9921,CVE-2016-9922] Qemu: 9pfs: memory leakage via proxy/handle callbacks (#1402278)qemu ioport array overflow [XSA-199, CVE-2016-9637]

LinuxSecurity.com: The 4.8.15 stable kernel update contains a number of important fixes across thetree.

Apple drops requirement for apps to use HTTPS by 2017
Sneaky chat app Signal deploys decoy domains to deny despots
Passwords, patches and backup – three easy tips in our Facebook Live video
Inflight Entertainment Service Provider Gogo Launches Bug Bounty Program
Bad news: Exim hole was going to be patched on Xmas Day. Good news: Keyword ‘was’
Sing a song of ransomware…
News in brief: Groupon grief; Apple encryption delay; post-quantum crypto
Smashing Security #001: ‘One cup, two hotel guests’
Fancy Bear used Android malware to track Ukrainian artillery
Data Breach: Anonymous hacks Thai Navy, Ministry of Foreign Affairs
NIST Calls for Submissions to Secure Data Against Quantum Computing
Siemens Patches Insufficient Entropy Vulnerability in ICS Systems

Risk Level: Very Low. Type: Trojan.

‘DNC hackers’ used mobile malware to track Ukrainian artillery – researchers
Pow! Captain America and other Marvel heroes defeated by bad passwords
Once again, you can decrypt your CryptXXX ransomware files for free
Groupon frauds blamed on third-party password breaches
Government’s “general and indiscriminate” data collection ruled unlawful
AT&T takes aim at scam callers
Hackers Suspected of Causing Second Power Outage in Ukraine
Congressional Group Says Encryption Backdoors Are a Bad Idea
OurMine hijacks Netflix’s US Twitter account

Netflix has become the latest big name brand to have one of its social media accounts hijacked by OurMine. The post OurMine hijacks Netflix’s US Twitter account appeared first on WeLiveSecurity

Instant Verification lets mobile users authenticate themselves without an SMS
NIST requests ideas for crypto that can survive quantum computers

LinuxSecurity.com: Security fix for CVE-2016-9036, CVE-2016-9037

LinuxSecurity.com: Security fix for CVE-2016-9036, CVE-2016-9037

LinuxSecurity.com: – Fixed crash in auth process when auth-policy was configured and authenticationwas aborted/failed without a username set. – director: If two users haddifferent tags but the same hash, the users may have been redirected to thewrong tag’s hosts. – Index files may have been thought incorrectly lost, causing”Missing middle file seq=..” to be logged […]

LinuxSecurity.com: Security fix for CVE-2016-9036, CVE-2016-9037

LinuxSecurity.com: Security fix for CVE-2016-9036, CVE-2016-9037

Risk Level: Very Low. Type: Trojan, Worm.

OurMine hackers hack Marvel and Netflix Twitter accounts
Don’t pay up to decrypt – cure found for CryptXXX ransomware, again

security update

security update

security update

Our 12 tips for staying safe online this Christmas
News in brief: crackdown on drones; Egypt blocks Signal; Nook 7 warning
New Wave of Hailstorm Spam Pelts Inboxes

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: The system could be made to expose sensitive information.

LinuxSecurity.com: The system could be made to expose sensitive information.

Student makes documentary after spying on thief who stole his smartphone

Risk Level: Very Low. Type: Trojan.

VMware removes hard-coded root access key from vSphere Data Protection
Nmap security scanner gets new scripts, performance boosts
Netflix US Twitter account hacked
Meet Jarvis – Zuck’s new AI assistant
Beware: Android Super Mario Run is Actually Malware; Don’t Download It
Smile! You’re on a stolen iPhone’s candid camera!

  Did we get you to click? That’s how the bad guys get you, too. One little click on the wrong link and your clients’ businesses could be up the proverbial creek. Theft only comprises one aspect of the activities cybercriminals undertake, but it’s a sizeable chunk of their enterprise. What’s worth noting is what […]