Earlier this month, Tumblr revealed that it had recently become aware that user addresses and salted and hashed passwords dating back to 2013 had fallen into the hands of hackers. We recently learned that a third party had obtained access to a set of Tumblr user email addresses with salted and hashed passwords from early […]
Risk Level: Very Low. Type: Trojan.
CISSP stands for Certified Information Systems Security Professional, a qualification that I obtained on this day in 1996. Back then, very few people had heard of CISSP or the organization that created it, the International Information Systems Security Certification Consortium. This non-profit professional body is known as (ISC)2 which is pronounced “I-S-C-squared” (because the name […]
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan, Worm.
Ubuntu: 2985-2: GNU C Library regression Posted by Anthony Pell USN-2985-1 introduced a regression in the GNU C Library. ========================================================================== Ubuntu Security Notice USN-2985-2 May 26, 2016 eglibc, glibc regression ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: […]
Discovered: May 26, 2016 Updated: May 26, 2016 5:44:20 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Trojan.Zekapab is a Trojan horse that downloads potentially malicious files and steals information from […]
Discovered: May 26, 2016 Updated: May 26, 2016 8:16:42 PM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Backdoor.Zekapab is a Trojan horse that opens a back door on the compromised computer and may perform […]
Government IT Systems Long Outdated In a recent study done by the Government Accountability Office, a large portion of the US government’s critical business systems have been found to be requiring an increasing amount for maintaining their basic operation, but also they are a major security risk. From defense systems to scientific research systems, these […]
Decision makers at banks are in the dark when it comes to data breaches at their organization, according to KPMG’s 2016 Banking Outlook Survey. It revealed that this is especially the case when it comes to the second tier of senior management. For example, while 12% of CEOs were unaware as to whether their networks […]
Several vulnerabilities were discovered in libgd2, a library for programmatic graphics creation and manipulation. A remote attacker can take advantage of these flaws to cause a denial-of-service against an application using the libgd2 library. For the stable distribution (jessie), these problems have been fixed in version 2.1.0-5+deb8u3. For the unstable distribution (sid), these problems have […]
An update for rh-mariadb100-mariadb is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: rh-mariadb100-mariadb security update Advisory ID: RHSA-2016:1132-01 Product: Red Hat Software Collections Advisory URL: https://access.redhat.com/errata/RHSA-2016:1132 Issue date: 2016-05-26 CVE Names: CVE-2015-3210 CVE-2015-3217 CVE-2015-4792 […]
Ubuntu: 2985-1: GNU C Library vulnerabilities Posted by Anthony Pell Several security issues were fixed in the GNU C Library. ========================================================================== Ubuntu Security Notice USN-2985-1 May 25, 2016 eglibc, glibc vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS […]
Ubuntu: 2950-5: Samba regression Posted by Anthony Pell USN-2950-1 introduced a regression in Samba. ========================================================================== Ubuntu Security Notice USN-2950-5 May 25, 2016 samba regression ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 – Ubuntu 14.04 LTS Summary: USN-2950-1 introduced a regression in Samba. […]
Slackware: 2016-145-01: libarchive: Security Update Posted by Anthony Pell New libarchive packages are available for Slackware 14.1 and -current to fix a security issue. [More Info…] [slackware-security] libarchive (SSA:2016-145-01) New libarchive packages are available for Slackware 14.1 and -current to fix a security issue. Here are the details from the Slackware 14.1 ChangeLog: +————————–+ […]
Red Hat: 2016:1106-01: jq: Moderate Advisory Posted by Anthony Pell An update for jq is now available for Red Hat OpenStack Platform 8.0 (Liberty). Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: jq security update Advisory ID: RHSA-2016:1106-01 Product: Red Hat […]
Several security issues were fixed in PHP. ========================================================================== Ubuntu Security Notice USN-2984-1 May 24, 2016 php5, php7.0 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: Several security issues were fixed in PHP. Software Description: […]
An update for kernel is now available for Red Hat Enterprise Linux 6.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel security, bug fix, and enhancement update Advisory ID: RHSA-2016:1100-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-1100.html […]
On this day, May 25, in the year 2018, the General Data Protection Regulation will go into effect. Commonly referred to as GDPR or the Regulation, this set of rules governing the privacy and security of personal data is being laid down by the European Commission, but it has serious implications for companies in countries […]
ESET LiveGrid® telemetry shows a spike in detections of the JS/Danger.ScriptAttachment malware in several European countries. The most notable detection ratios are seen in Luxembourg (67%), Czech Republic (60%), Austria (57%), Netherlands (54%) and the UK (51%), but also in other European states. After arriving as an email attachment, the threat behind these detections is designed […]
Risk Level: Very Low. Type: Trojan.
Our news about ransomware TeslaCrypt operators shutting up shop attracted a lot of attention and prompted several additional questions. So we’ve approached the best-placed person to address them – Igor Kabina, the ESET malware researcher who first noticed that things had started to change around TeslaCrypt ransomware and ultimately created the universal ESET TeslaCrypt decryption […]
What is the most important thing you should take with you on a cosmic trip? As highlighted by an annual celebration on May 25th, dubbed Towel Day, it is the humble towel. As the late author Douglas Adams put it in his famous Hitchhiker’s Guide to the Galaxy: “A towel, it says, is about the […]
Discovered: May 25, 2016 Updated: May 25, 2016 11:17:28 AM Type: Trojan Infection Length: 126,976 bytes Systems Affected: Windows 2000, Windows 7, Windows 8, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Backdoor.Psiload is a Trojan horse that opens a back door on the compromised […]
Discovered: May 25, 2016 Updated: May 25, 2016 1:22:17 PM Also Known As: Bloccato [Trend] Type: Trojan Infection Length: Varies Systems Affected: Windows 7, Windows 8, Windows Vista Trojan.Ransomcrypt.AV is a Trojan horse that encrypts files on the compromised computer and asks the user to pay in order to decrypt them. Antivirus Protection Dates Initial […]
Risk Level: Very Low. Type: Trojan.
It was discovered that a buffer overflow in the XMLRPC response encoding code of the Atheme IRC services may result in denial of service. For the stable distribution (jessie), this problem has been fixed in version 6.0.11-2+deb8u1. For the testing distribution (stretch), this problem has been fixed in version 7.0.7-2. For the unstable distribution (sid), […]
Red Hat: 2016:1098-01: jq: Moderate Advisory Posted by Anthony Pell An update for jq is now available for Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: jq security update Advisory […]
Red Hat: 2016:1099-01: jq: Moderate Advisory Posted by Anthony Pell An update for jq is now available for Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: jq security update Advisory […]
Debian: 3586-1: atheme-services: Summary Posted by Anthony Pell Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3586-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff May 23, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : atheme-services CVE ID : CVE-2016-4478 It was discovered that a buffer overflow in the XMLRPC response encoding code of the Atheme IRC services may result […]
An update for kernel is now available for Red Hat Enterprise Linux 6.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel security and bug fix update Advisory ID: RHSA-2016:1096-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-1096.html Issue […]
��ݒ�F�0x-E�J���O�b�Z�Xg%[������Ej���lZVļ��칛۽܈}���d�d3�����lJ�7�K P�U������������N����3���W/����h�L=����_�����ܫ~-�I�����Cs�-?�_�:wM��߁’��є’65�/�{ٯ�~���x;y� ů~-�W�� ‘v�
Nearly everything we do in computer security is meant to protect data. After all, we don’t deploy antimalware software, tighten security configurations, or implement firewalls to protect users, per se. Job No. 1 is to protect the organization’s data — including employee and (especially) customer data. But guess what? People need to work with that […]
Risk Level: Very Low. Type: Trojan.
Multiple vulnerabilities were discovered in the dissectors/parsers for PKTC, IAX2, GSM CBCH and NCP which could result in denial of service. For the stable distribution (jessie), these problems have been fixed in version 1.12.1+g01b65bf-4+deb8u6. For the testing distribution (stretch), these problems have been fixed in version 2.0.3+geed34f0-1. For the unstable distribution (sid), these problems have […]
Debian: 3585-1: wireshark: Summary Posted by Anthony Pell Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3585-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff May 22, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : wireshark CVE ID : CVE-2016-4006 CVE-2016-4079 CVE-2016-4080 CVE-2016-4081 CVE-2016-4082 CVE-2016-4085 Multiple vulnerabilities were discovered in the dissectors/parsers for PKTC, IAX2, GSM CBCH and NCP which […]
Slackware: 2016-141-01: curl: Security Update Posted by Anthony Pell New curl packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix a security issue. [More Info…] [slackware-security] curl (SSA:2016-141-01) New curl packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix a security issue. Here are […]
Risk Level: Very Low. Type: Trojan.
