Menu

Latest articles

Red Hat: 2016:1201-01: chromium-browser: Important Advisory Posted by Anthony Pell    An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: chromium-browser security update Advisory ID: RHSA-2016:1201-01 Product: Red Hat […]

Ubuntu: 2991-1: nginx vulnerability Posted by Anthony Pell    nginx could be made to crash if it received specially crafted networktraffic. ========================================================================== Ubuntu Security Notice USN-2991-1 June 02, 2016 nginx vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 – Ubuntu 14.04 LTS Summary: […]

Ubuntu: 2990-1: ImageMagick vulnerabilities Posted by Anthony Pell    Several security issues were fixed in ImageMagick. ========================================================================== Ubuntu Security Notice USN-2990-1 June 02, 2016 imagemagick vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: Several […]

Android gets patches for serious flaws in hardware drivers and mediaserver
Hackers Can Steal Mitsubishi Outlander Hybrid Car By Exploiting WiFi Access Point
Hackers Use Leaked LinkedIn Database to Hack Mark Zuckerberg’ Twitter, Pinterest
Lenovo users must uninstall Accelerator app due to dangerous security hole
Widespread exploits evade protections enforced by Microsoft EMET
VIDEO: Mark Zuckerberg, Kylie Jenner, Jack Black – hacked!
Hackers breach social media accounts of Mark Zuckerberg and other celebrities
The security review: Crouching Tiger, Hidden DNS

Welcome to this week’s security review, including the story of a DNS hijack that sets the victim’s computer to use specific DNS servers. The post The security review: Crouching Tiger, Hidden DNS appeared first on We Live Security.

5 trends shaking up multi-factor authentication

Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-1696 A cross-origin bypass was found in the bindings to extensions. CVE-2016-1697 Mariusz Mlynski discovered a cross-origin bypass in Blink/Webkit. CVE-2016-1698 Rob Wu discovered an information leak. CVE-2016-1699 Gregory Panakkal discovered an issue in the Developer Tools feature. CVE-2016-1700 Rob Wu discovered a use-after-free issue […]

Automated Web Application Scanner Acunetix Website Hacked
Sh0ping.su Hacked, Thousands of Credit Cards and Accounts Leaked
This System can Trace Calls, Texts, Location of Every Single Mobile Phone
Hackers Leak 36 million+ MongoDB Accounts
WordPress users warned of plugin flaw being exploited in porn spam attack
Privacy concern over EU’s plan to introduce ID cards for social media

Several vulnerabilities were discovered in libxml2, a library providing support to read, modify and write XML and HTML files. A remote attacker could provide a specially crafted XML or HTML file that, when processed by an application using libxml2, would cause a denial-of-service against the application, or potentially the execution of arbitrary code with the […]

There’s a lot that happens in the security world, with many stories getting lost in the mix. In an effort to keep our readers informed and updated, we present the Webroot Threat Recap, highlighting 5 major security news stories of the week. MySpace Hack Could Be Largest in Recent History Recently, LeakedSource announced that they had obtained […]

50 hackers Who Stole $25million Arrested by Russian Authorities

Discovered: June 2, 2016 Updated: June 3, 2016 3:43:31 PM Also Known As: IronGate [FireEye] Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Trojan.Gatenori is a Trojan horse that may attempt to gain access to […]

Beware online fraudsters jumping on the back of recent data breaches

The Internet Crime Complaint Center (IC3) has issued a public service announcement warning people about online fraudsters, who are attempting to exploit a recent spate of data breaches that have only just come to light. This includes historic security incidents at Myspace, Tumblr and LinkedIn, for example, which have collectively compromised hundreds of millions of […]

The huge Dropbox password leak that wasn’t
EU and US officials sign ‘umbrella’ data protection agreement, but it’s no Privacy Shield
Irongate malware targets industrial control systems – but is it in the wild or not?
How to delete your smartphone data securely before selling your device

Some people change their smartphone or tablet almost as casually as they change their clothes. They buy and later sell mobile devices without the slightest concern about the information that, one device after another, they keep putting in the hands of total strangers. This article is aimed at all those people, and in it you will be […]

Nearly all phishing emails now contain ransomware

��}ks۸���j���5��H��W�H����ɹy�=g��$��HH�M��u2�:?co��ت������@ |H�e%����# 4��F��@?�������’/��g�_��zl6��E�;sDW&��e���M;��9�T���Ǧu���H‚��LL�C�m �(�L�p�,(��j� ��.j#sIp�5?&��C[�2~P�s�”f��� �ƙ� ��f��oI�

8 reasons why your security awareness program sucks
How the Top 5 PC Makers Open Your Laptop to Hackers
Hackers Find Bugs, Extort Ransom and Call it a Public Service
Exposed! The tricks that ransomware plays
Woman spends 2.5 years in Argentinian prison after falling victim to romance scam

Risk Level: Very Low. Type: Trojan.

Dridex Malware is Back and Targeting Banking Sector in US
Anonymous Hacks Spanish Police Server, Leaks Data Against Gag Law

Debian: 3592-1: nginx: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3592-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff June 01, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : nginx CVE ID : CVE-2016-4450 It was discovered that a NULL pointer dereference in the Nginx code responsible for saving client request bodies to a […]

Extortion schemes expand, threatening consumers and businesses with data leaks
Spam is still a problem – for Outlook webmail users at least
50 detained as Russia swoops on $45 million banking malware gang
TeamViewer denies hack, as users claim computers remotely hijacked
Crouching Tiger, Hidden DNS

Working in customer care you get to see every kind of issue computer users can have. This can lead to extremely interesting situations. One particularly noteworthy issue we are seeing is an interesting DNS hijack that sets the victim’s computer to use specific DNS servers. While this attack might not sound that interesting and may […]

Judge Tosses Evidence Gathered by FBI’s Tor Exploit
The Romanian Teen Hacker Who Hunts Bugs to Resist the Dark Side
Network ELOFANTS and other insider threat insights from the DBIR and beyond

If you’re concerned about the security of your organization’s data you should be looking out for elofants on your network. I’ve seen them myself and, if your organization’s network is statistically average, then it is statistically likely to be harboring at least one ELOFANT, otherwise known as: Employee Left Or Fired, Access Not Terminated. While […]

New peripherals are bringing Windows Hello to any Windows 10 PC
Code red: Health IT must fix its security crisis
Add-ons bring Windows Hello to all Windows 10 PCs

Discovered: June 2, 2016 Updated: June 2, 2016 11:39:43 AM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Trojan.Uverat.B is a Trojan horse that opens a back door on the compromised computer. It may also […]

University of Calgary Network Suffers Malware Attack
Facebook’s Like button is tracking all of us, to target us with ads
Stealth Falcon spyware targeting critics of the UAE, say researchers
Facebook is Listening to Users’ Conversations, Here’s How to Stop it

An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: chromium-browser security update Advisory ID: RHSA-2016:1190-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://access.redhat.com/errata/RHSA-2016:1190 Issue date: 2016-06-01 CVE Names: […]

Debian: 3591-1: imagemagick: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3591-1 security@debian.org https://www.debian.org/security/ Luciano Bello June 01, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : imagemagick CVE ID : CVE-2016-5118 Debian Bug : 825799 Bob Friesenhahn from the GraphicsMagick project discovered a command injection vulnerability in ImageMagick, a program suite […]

Ubuntu: 2989-1: Linux kernel vulnerabilities Posted by Anthony Pell    Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2989-1 June 01, 2016 linux vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: […]

Debian: 3590-1: chromium-browser: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3590-1 security@debian.org https://www.debian.org/security/ Michael Gilbert June 01, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : chromium-browser CVE ID : CVE-2016-1667 CVE-2016-1668 CVE-2016-1669 CVE-2016-1670 CVE-2016-1672 CVE-2016-1673 CVE-2016-1674 CVE-2016-1675 CVE-2016-1676 CVE-2016-1677 CVE-2016-1678 CVE-2016-1679 CVE-2016-1680 CVE-2016-1681 CVE-2016-1682 CVE-2016-1683 CVE-2016-1684 CVE-2016-1685 CVE-2016-1686 CVE-2016-1687 CVE-2016-1688 […]

Ubuntu: 2988-1: LXD vulnerabilities Posted by Anthony Pell    Several security issues were fixed in LXD. ========================================================================== Ubuntu Security Notice USN-2988-1 May 31, 2016 lxd vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 Summary: Several security issues were fixed in LXD. Software Description: […]

Ubuntu: 2987-1: GD library vulnerabilities Posted by Anthony Pell    The GD library could be made to crash or run programs if it processed aspecially crafted image file. ========================================================================== Ubuntu Security Notice USN-2987-1 May 31, 2016 libgd2 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – […]

Ubuntu: 2986-1: dosfstools vulnerabilities Posted by Anthony Pell    dosfstools could be made to crash or run programs if it processed aspecially crafted filesystem. ========================================================================== Ubuntu Security Notice USN-2986-1 May 31, 2016 dosfstools vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 – Ubuntu […]

Anonymous Linked Team Hacks Kenyan Oil Firm Against Police Brutality
Ransomware demands are working, fueling an increase in attacks
Myspace data breach: 360 million accounts affected

��}�r۸���j�aN��D$u�-v���ɜ��r۱��Ηd] I�)�CR�u2�:��_�n�� [�Op�MΓl7R�E�,+���d.�H��ht7�����o�O~�|��Uǣd���]�Ə’ #:��Q����ņ�9�V?Рν�#j��{���{5b/��%����”,P �����O��?b�d��~�ڴ5x��쿳�5�o����i_u.�ZǗ��vB�fK{�b��}�tgo︽��|���l��;~���i�#`�`�^pA”�w�8��4Q H����NkdL]��ja��u���O�SsJ}��ԙD^236���!����؂���28,�C�����7r:�b��#�7o��d�%#�A���8���^���v(ZؤQ���^��=���q�$Hbb�I���5�T��4v”/,�R ^�h/!S;�XOf� ��6n�x�x.� c$��MtJf8��CF�����$ٗ4C�8>�)��ꍩYЁ��9v�`3��i7[{V�mYc�G�`�>Т![4��1GL/�XH�dƥ�g( �hp����t��q;Jְ��Uo�Y�^�_ׄ�j�̙ �4�:j�ǖ`�W���(�pz[�x�&:k��u��b�$g�0q�$��0�0�v��>�����җ+#ـV���`b=$-:���̊�` �>?$Mb6�A�%h��,B!�i���#�N�*|B�%��W�_o=+6u����:�ܮ�BX��g�^����D,F�gG1g��9�����Ff��c`�H��.�WO�W�XxT’��=AU�e��-n�3ShfaV#/F4�[Or-���”��ax���QJP�6�v��™�>6���t`O�$�{�L!�b`_zwD}�R!f��ͻ`��M@U��92:h�l7C�h���:�F��>�J�;2�K�$���`��$_1lӁ83���!z�˄F33,P�i��������0*�aC�6��dz wsF#�F����”x5���Y4�9����76����N���=H����-s�l݌����(]�jPo˜W@_����������>sg$�H�~�6s�|+{�x��Yt����T�Su^�բNp1y3-S�u��V*a�)�Z-������ۮ1���(�@Fo�(TI�97.���(�BzF���;E��J��v/A�Q��9#���3�!�7 `��d1��8���I����3Z�C�R�� �.�;�/8�tYK�Z���S��n�,�=��:,�C���ɘ

Printer security: Is your company’s data really safe?
IPv6 support finally coming to Fail2Ban with next major release
A Car’s Computer Can ‘Fingerprint’ You in Minutes Based on How You Drive
65 million Tumblr account records are up for sale on the underground market
Zero-days aren’t the problem — patches are

There’s a widely held view that our world is full of uber hackers who are too brilliant to stop. Thus, we should fear zero-day attacks because they’re our biggest problem. Nothing could be further from the truth. Most hackers follow the path created by a very few smart ones — and zero days make up […]

It was discovered that a NULL pointer dereference in the Nginx code responsible for saving client request bodies to a temporary file might result in denial of service: Malformed requests could crash worker processes. For the stable distribution (jessie), this problem has been fixed in version 1.6.2-5+deb8u2. For the unstable distribution (sid), this problem has […]

Bob Friesenhahn from the GraphicsMagick project discovered a command injection vulnerability in ImageMagick, a program suite for image manipulation. An attacker with control on input image or the input filename can execute arbitrary commands with the privileges of the user running the application. This update removes the possibility of using pipe (|) in filenames to […]

Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-1667 Mariusz Mylinski discovered a cross-origin bypass. CVE-2016-1668 Mariusz Mylinski discovered a cross-origin bypass in bindings to v8. CVE-2016-1669 Choongwoo Han discovered a buffer overflow in the v8 javascript library. CVE-2016-1670 A race condition was found that could cause the renderer process to reuse ids […]

Stealth Falcon Spyware Used by UAE to Intimidate Dissidents, Journalists

Several vulnerabilities have been discovered in gdk-pixbuf, a toolkit for image loading and pixel buffer manipulation. A remote attacker can take advantage of these flaws to cause a denial-of-service against an application using gdk-pixbuf (application crash), or potentially, to execute arbitrary code with the privileges of the user running the application, if a malformed image […]

An update for ntp is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: ntp security update Advisory ID: RHSA-2016:1141-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2016:1141 Issue […]

Slackware: 2016-152-01: imagemagick: Security Update Posted by Anthony Pell    New imagemagick packages are available for Slackware 14.0, 14.1, and -current to fix a security issue. [More Info…] [slackware-security] imagemagick (SSA:2016-152-01) New imagemagick packages are available for Slackware 14.0, 14.1, and -current to fix a security issue. Here are the details from the Slackware 14.1 […]

Slackware: 2016-152-02: mozilla-thunderbird: Security Update Posted by Anthony Pell    New mozilla-thunderbird packages are available for Slackware 14.1 and -current to fix security issues. [More Info…] [slackware-security] mozilla-thunderbird (SSA:2016-152-02) New mozilla-thunderbird packages are available for Slackware 14.1 and -current to fix security issues. Here are the details from the Slackware 14.1 ChangeLog: +————————–+ patches/packages/mozilla-thunderbird-45.1.1-i486-1_slack14.1.txz: Upgraded. […]

An update for squid is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: squid security update Advisory ID: RHSA-2016:1139-01 Product: Red Hat Enterprise […]

An update for squid is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: squid security update Advisory ID: RHSA-2016:1138-01 Product: Red Hat Enterprise […]

An update for squid34 is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: squid34 security update Advisory ID: RHSA-2016:1140-01 Product: Red Hat Enterprise […]

Multiple vulnerabilities have been found in Firefox, Thunderbird, Network Security Services (NSS), and NetScape Portable Runtime (NSPR) with the worst of which may allow remote execution of arbitrary code. – – – – – – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201605-05 Linux-PAM: Multiple vulnerabilities Posted by Anthony Pell    Multiple vulnerabilities have been found in Linux-PAM, allowing remote attackers to bypass the auth process and cause Denial of Service. – – – – – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201605-04 rsync: Multiple vulnerabilities Posted by Anthony Pell    Multiple vulnerabilities have been found in rsync, the worst of which could allow remote attackers to write arbitrary files. – – – – – – – – – – – – – – – – – – – – – – – – – – […]

Gentoo: 201605-03 libfpx: Denial of Service Posted by Anthony Pell    A double free vulnerability has been discovered in libfpx that allows remote attackers to cause a Denial of Service. – – – – – – – – – – – – – – – – – – – – – – – – – […]

Debian: 3589-1: gdk-pixbuf: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3589-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso May 30, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : gdk-pixbuf CVE ID : CVE-2015-7552 CVE-2015-8875 Several vulnerabilities have been discovered in gdk-pixbuf, a toolkit for image loading and pixel buffer manipulation. A remote attacker […]

Debian: 3588-1: symfony: Summary Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3588-1 security@debian.org https://www.debian.org/security/ Luciano Bello May 29, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : symfony CVE ID : CVE-2016-1902 CVE-2016-4423 Two vulnerabilities were discovered in Symfony, a PHP framework. CVE-2016-1902 Lander Brandt discovered that the class SecureRandom might generate […]

Risk Level: Very Low. Type: Trojan.

VIDEO: What the Katy Perry hack teaches us about computer security
Anonymous leads the way again as world’s most prolific hacktivist group
Laptop updaters riddled with security holes
Ransomware or ransomworm? Beware of ZCryptor!
You may take password security seriously now, but your past can haunt you
Review: Hot new tools to fight insider threats
Flaw in popular WordPress plug-in Jetpack puts over a million websites at risk
Sorry, dad, security isn’t what it used to be
Effective IT security habits of highly secure companies

Discovered: May 31, 2016 Updated: May 31, 2016 11:35:23 AM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP WSH.Downloader is a Trojan horse that downloads a malicious file to the compromised computer. Antivirus Protection Dates […]

Risk Level: Very Low. Type: Trojan.

France Weather Forecast Website Hacked By Anti-War Hacker

Two vulnerabilities were discovered in Symfony, a PHP framework. CVE-2016-1902 Lander Brandt discovered that the class SecureRandom might generate weak random numbers for cryptographic use under certain settings. If the functions random_bytes() or openssl_random_pseudo_bytes() are not available, the output of SecureRandom should not be consider secure. CVE-2016-4423 Marek Alaksa from Citadelo discovered that it is […]