Menu

Latest articles

New Windows Patch Policy At Odds With Acceptable Risk
FDA, DHS Investigating St. Jude Device Vulnerabilities
Bitcoin Mining malware infects Seagate Central NAS devices

Debian: 3665-1: openjpeg2: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3665-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff September 11, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : openjpeg2 CVE ID : CVE-2015-6581 CVE-2015-8871 CVE-2016-1924 CVE-2016-7163 Multiple vulnerabilities in OpenJPEG, a JPEG 2000 image compression / decompression library, may result in denial of […]

Slackware: 2016-254-01: gnutls: Security Update Posted by Anthony Pell    New gnutls packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue. [More Info…] [slackware-security] gnutls (SSA:2016-254-01) New gnutls packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue. Here are the details from the […]

Debian: 3664-1: pdns: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3664-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso September 10, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : pdns CVE ID : CVE-2016-5426 CVE-2016-5427 CVE-2016-6172 Debian Bug : 830808 Multiple vulnerabilities have been discovered in pdns, an authoritative DNS server. The Common Vulnerabilities […]

Debian: 3663-1: xen: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3663-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso September 09, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : xen CVE ID : CVE-2016-7092 CVE-2016-7094 CVE-2016-7154 Multiple vulnerabilities have been discovered in the Xen hypervisor. The Common Vulnerabilities and Exposures project identifies the following […]

Ubuntu: 3075-1: Imlib2 vulnerabilities Posted by Anthony Pell    Several security issues were fixed in Imlib2. ========================================================================== Ubuntu Security Notice USN-3075-1 September 09, 2016 imlib2 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: Several security issues were […]

Slackware: 2016-252-01: php: Security Update Posted by Anthony Pell    New php packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…] [slackware-security] php (SSA:2016-252-01) New php packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues. Here are the details from the Slackware 14.2 […]

After sitting down with Hal Lonas to get a deeper look at the inner workings of Webroot, there was no questioning why he’s uniquely qualified to serve as the company’s CTO. And with machine learning getting thrown around as the hot new buzzword, it was refreshing to hear Hal’s down-to-earth perspective on motivations, ideas, solutions […]

Malware Authors Rename Ransomware After Emsisoft’ Security Researcher
Critical MySQL Vulnerability Disclosed
Meet DDoSaaS: Distributed Denial of Service-as-a-Service
4.5 million web servers have private keys that are publicly known!
14-year-old sues Facebook over nude photo posted to “shame” site
The US gets its first Chief Information Security Officer
How 911 emergency services across the United States could be knocked offline by a mobile botnet
Scammer unmasked by friend’s poor Facebook privacy
Sniffing your storage could lead to sensitive leaks, warn infosec bods
Crafty GovRAT malware is growing, targeting U.S. government employees
Keep the faith: A vote for voting systems
Bank’s data center knocked offline by really loud noise
FBI arrests Crackas With Attitude who allegedly hacked CIA boss’s AOL account
Discover VASCO’s top 10 tips for a successful and secure Mobile First Strategy! Register now for this webinar
Israeli Pentagon DDoSers explain their work, get busted by FBI
Peccant pwners post 670,000 Pokémon punter MD5 passwords
SOHOpeless Seagate NAS boxen become malware distributors
33 million CLEARTEXT creds for Russian IM site dumped by chap behind Last.FM mess
PCI Council wants upgradeable credit card readers … next year
Linode fends off multiple DDOS attacks
BDSwiss Trading Hacked; Sensitive Data, Passports, Credit Cards Leaked
FBI Arrests Two Alleged Hackers of Crackas With Attitude Group
US Emergency Phone System ‘911’ Can Be Hacked Through TDoS Attack
Exile Mod Gaming Forum Hacked; 12,000 Accounts Leaked
White House appoints first Federal Chief Information Security Officer
WordPress urges users to update now to fix critical security holes
This USB stick will fry your unsecured computer
CallJam malware infects Androids and keeps ringing premium rate numbers

Multiple vulnerabilities have been discovered in pdns, an authoritative DNS server. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2016-5426 / CVE-2016-5427 Florian Heinz and Martin Kluge reported that the PowerDNS Authoritative Server accepts queries with a qname’s length larger than 255 bytes and does not properly handle dot inside labels. A remote, […]

Seagate sued by its own staff for leaking personal info to identity thieves
Samsung Galaxy Note 7 on Burning Spree; Burns House and Jeep

It was discovered that incorrect SASL authentication in the Inspircd IRC server may lead to users impersonating other users. For the stable distribution (jessie), this problem has been fixed in version 2.0.17-1+deb8u2. For the unstable distribution (sid), this problem has been fixed in version 2.0.23-1. We recommend that you upgrade your inspircd packages.

Patched Android Libutils Vulnerability Harkens Back to Stagefright

Debian: 3662-1: inspircd: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3662-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff September 08, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : inspircd CVE ID : CVE-2016-7142 It was discovered that incorrect SASL authentication in the Inspircd IRC server may lead to users impersonating other users. For […]

White House Hires First Federal CISO

There’s a lot that happens in the cybersecurity world, with many stories getting lost in the mix. In an effort to keep our readers informed and updated, we present the Webroot Threat Recap, highlighting 5 major security news stories of the week. No Site is Immune to  User Information Exposure In yet another example of poor cybersecurity, Brazzers […]

Google to slap warnings on non-HTTPS sites
A USB device can steal login credentials even if the PC is locked
Facebook censors iconic image of Vietnamese girl fleeing napalm attack
Online DDoS service vDOS hacked, spills details of its customers and targets
Xen Project patches serious virtual machine escape flaws
Scammers sent to the slammer for romance and secret shopping fraud
Unencrypted website? Expect to start being shamed by Google Chrome from January
Fallout Over OPM Breach Report Begins
Luabot Malware Turning Linux Based IoT Devices into DDoS Botnet
Sidestepping your lockscreen with an innocent-looking USB stick
Google to draw attention to insecure HTTP websites

Google is looking to deliver even greater transparency when it comes to online security by identifying publicly – or “marking”, as it puts it – websites that are not as secure as they should be. In a blog, Emily Schechter, a product manager within the tech giant’s Chrome security team, revealed that as of 2017, its browser […]

<div>Grace Hopper: Computer bugs & the language of programming</div>

So, the story goes something like this. In 1947, in Virginia, US, an error was spotted on the Harvard Mark II, one of the first programmable computers in the world. A team went to investigate, discovering that a moth had been caught between a relay in a machine. It was subsequently removed and taped to […]

NHS health apps project plan: Powered by your medical records
NHS hospitals told to swallow stronger anti-ransomware medication
Top smut site stops Flashing, adopts HTML5

Multiple vulnerabilities have been discovered in the Xen hypervisor. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2016-7092 (XSA-185) Jeremie Boutoille of Quarkslab and Shangcong Luan of Alibaba discovered a flaw in the handling of L3 pagetable entries, allowing a malicious 32-bit PV guest administrator can escalate their privilege to that of the […]

Discovered: September 9, 2016 Updated: September 9, 2016 3:40:08 PM Type: Trojan Systems Affected: Linux Linux.Luabot is a Trojan horse for Linux computers that may perform malicious activities. Symantec Security Response is currently investigating this threat and will post more information as it becomes available. Antivirus Protection Dates Initial Rapid Release version September 9, 2016 […]

A USB device is all it takes to steal credentials from locked PCs
Come in HTTP, your time is up: Google Chrome to shame leaky non-HTTPS sites from January
Hypervisor security ero-Xen: How guest VMs can hijack host servers
Chrome to Label Some HTTP Sites ‘Not Secure’ in 2017
20% off Kuna Smart Home Security Outdoor Light & Camera – Deal Alert

Red Hat: 2016:1820-01: postgresql92-postgresql: Moderate Advisory Posted by Anthony Pell    An update for postgresql92-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: postgresql92-postgresql security update Advisory ID: RHSA-2016:1820-01 Product: Red Hat Software Collections […]

Red Hat: 2016:1821-01: rh-postgresql95-postgresql: Moderate Advisory Posted by Anthony Pell    An update for rh-postgresql95-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: rh-postgresql95-postgresql security update Advisory ID: RHSA-2016:1821-01 Product: Red Hat Software Collections […]

Debian: 3661-1: charybdis: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3661-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff September 06, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : charybdis CVE ID : CVE-2016-7143 It was discovered that incorrect SASL authentication in the Charybdis IRC server may lead to users impersonating other users. For […]

Anonymous Hacker Might Get 16 Years For Exposing Steubenville Rape Scandal
Holy Mokes! OS X users warned of sophisticated backdoor malware
WordPress Update Resolves XSS, Path Traversal Vulnerabilities
Google Chrome to start marking HTTP connections as insecure
Hacked uTorrent Forum, Mail.ru, Yandex.ru Data Goes on Darknet for Sale
DHS Urges Vigilance in Protecting Networking Gear
FTC Panel Encourages Basic Security Hygiene to Counter Ransomware
Security Sessions: Why security training matters for all IT staff
Report claims national security was put at risk by the OPM data breach
WordPress bloggers ‘strongly encouraged’ to immediately apply security update
Cryptomining malware on NAS servers – is one of them yours?
Would you hand over your social media account details for a new job?
Intel sells off majority stake in McAfee unit
How to avoid certificate pinning in the latest versions of Android

We previously explained how to construct an analysis environment enabling the certificate pinning process to be bypassed in Android applications, in order to be able to examine network traffic and to easily determine what data is being transmitted over secure communications protocols. In particular, we looked at the steps to take to install Cydia Substrate and Android SSL […]

Why quantum computing has the cybersecurity world white-knuckled
Politician’s password accidentally tweeted to thousands
Google Shares Android Nougat, Safe Browsing Security Enhancements
Google squashes another Mediaserver bug in Android
Rugged devops: Build security into software development
Kaspersky to 1337 haxors: take down our power grid. We dare you
Business security: Securing your data weak points

��}�r�F���vU�a�g�1�~ˤW��Ļv쳔��},��@@Q���}��������7�’���_�(�v�;{76����t����L?y�����?ޞ���^��~s��(;�1�aG�����쫎� �(��]�6�>T�ν’#nX�{�D�=�Ƞ�*�eb_v�cύ��g3�+��:Jį”F8X�Y��0X�����c3V�[�c�L,�]F��-���T�� �[��b �w�(�0e}9�֍�t����iXcZv��UK�}&j��DkQ/@D^�x�z5����Ϟ=��� CIŖ�6�,0�?l�H%,:�O+������ذ�� �a�f��FV2��qd>U�Q��?��UZ_���h5�{B�^�7D�l�Xx�i}�Ӈ�K��d’*�x��V�Q;L������R���u��� M��x�O�-����#�nc�g�?�l���Y���翋�^Q[���(�/�}o7v�U뽻�ћ��4W���n�/s� :`[9�½/�6�y5ߪ�e��z)�g��/] /����l���+^�HW[�:*� (�ت��N��&������G�� �r�ccÝ~�u!ҏAC�����]��k�Y�a��D�������r��3�}�;3�k��7�ȡ$ E�}���G�9�/�ƩH�m�]r3��1vol�� ��8�Qb�A�)ǚ� q#B#�k���#4��H�1#��Qx bh�n��0N�@_��屗�|�O���^0�x�A�l��ڎ�PQN|h[ ��’�,�V�DM6�St���&r����$��v��zSs �}o�” ����(18���!3�q8͑��I��@!h�;��(�Xq����#e�IPϗ@͹�q�҆�xC�#���y{���.�A]����� �nG���Ca=!��5*�G�1���D������9c��P�n�M,�[�R� e0i`�1�qx��!�I���”n��t�pb ���AS��)~�Z4��CT’N�zs�!�!�L��4A�t+�(4�ۡ�N۱���#;D*�70.ɩ�+��-

Printers now the least-secure things on the internet
Ten-year-old Windows Media Player hack is the new black, again
Read the damning dossier on the security stupidity that let China ransack OPM’s systems

Risk Level: Very Low. Type: Trojan.

McAfee’s back! Intel flogs security software biz, pockets $3.1bn
St Jude sues short-selling MedSec over pacemaker ‘hack’ report
Want the iPhone 7? Make sure you sell your old phone safely!
Dell has acquired RSA – download a PDF to read all about it