Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Discovered: May 19, 2016 Updated: May 19, 2016 9:01:34 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows NT, Windows Vista, Windows XP Trojan.Ransomcrypt.AT is a Trojan horse that encrypts files on the compromised computer. Antivirus Protection Dates Initial Rapid Release version May 20, 2016 revision 034 […]
Risk Level: Very Low. Type: Trojan.
Gustavo Grieco discovered several flaws in the way librsvg, a SAX-based renderer library for SVG files, parses SVG files with circular definitions. A remote attacker can take advantage of these flaws to cause an application using the librsvg library to crash. For the stable distribution (jessie), these problems have been fixed in version 2.40.5-1+deb8u2. For […]
A lot happens in the security world and many stories get lost in the mix. In an effort to keep our readers informed and updated, we present the Webroot Threat Recap, highlighting 5 major security news stories of the week. TeslaCrypt Closing It’s Doors Here’s a bit of good ransomware news, for once. This week, […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3584-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso May 19, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : librsvg CVE ID : CVE-2015-7558 CVE-2016-4347 CVE-2016-4348 Gustavo Grieco discovered several flaws in the way librsvg, a SAX-based renderer library for SVG files, parses SVG files with circular definitions. A remote attacker can take […]
Over 117 million emails and passwords belonging to LinkedIn members have been put online for sale, it has been revealed. Worryingly, this trove of information is not thought to have been obtained from a recent data breach. In fact, it is believed that the data was accessed in 2012, when the professional social network was […]
It was discovered that the swift3 (S3 compatibility) middleware plugin for Swift performed insufficient validation of date headers which might result in replay attacks. For the stable distribution (jessie), this problem has been fixed in version 1.7-5+deb8u1. For the testing distribution (stretch), this problem has been fixed in version 1.9-1. For the unstable distribution (sid), […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3583-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff May 18, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : swift-plugin-s3 CVE ID : CVE-2015-8466 Debian Bug : 822688 It was discovered that the swift3 (S3 compatibility) middleware plugin for Swift performed insufficient validation of date headers which might result in replay attacks. For […]
Discovered: May 18, 2016 Updated: May 19, 2016 2:15:03 PM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Trojan.Ransomlock.AS is a Trojan horse that locks the desktop, making the computer unusable. Antivirus Protection Dates Initial Rapid Release […]
APPLE-SA-2016-05-18-1 OS X: Flash Player plug-in blocked Subject: APPLE-SA-2016-05-18-1 OS X: Flash Player plug-in blocked From: Apple Product Security <email@hidden> Date: Wed, 18 May 2016 15:34:13 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-05-18-1 OS X: Flash Player plug-in blocked Due to security issues in older versions, Apple has updated the web plug-in blocking mechanism […]
��}�r�Ʋ�o�*�0�OdL�(Y2�k���co���N�C�A�!�qT�����+l�>��7�’���/R;�-�� 0��������������’g���|w�����Og��%��M �O�t� 6=”�(��M}}N /|�@�{OgԴ����}:��ɋj��ع(‘̋�igK�*��JD�”�4r6sB��#�/�#g��Fm�p�`D#�6��4r”�_��:�P3�!���� �~�2��g4t�|A��|a�!*���Ԧ�8~a��LȒ��� xL���6GhD��D���j=�”��ܱ���=h�t�����naU�p�gfH�al�=�(C{G�,�#�~��b⫁�L�y�a�v#�mw�F{���!��ii{��B)�4��P[���hh��I��i-��%#CB�P?l*}d� ��s�F��MC2 ��1؏��D�6~6B}��`�� �lX,�?����A���h ��7�!0�E��O tlA^:���?#=�rc[:�^9ѻ�ޞ~>3s��w������`L�”�0[����&v�l~�L��X�T��Ѽ���PGi�쁥Oi� ��ѣ쯆ҵ��q@�8p��:��{��5l����BA�3_iA�#�(�u�+��3qͩ2L��i�F`N�I��’`�0�6��{���~���m���f��j7[���fd����FSw�7�f��5���{��z�V��“cw��#�F�����:MT���K�y�s�Ҕn��d�汥��50�Jvl��UY/|�<3�߃H46)MhU7}�z���q�ռ�'�)B�}���O�3�a�a���T����k@���w?���A~�xb��ش.)�4?e��^Ҍ.`#_����7�y9� h|�������� A�i�Q~�P�e�|z��Jk�z�i�̊��i�wq(E�5� ���&���±#.1!(�� ��IP��cѓS,��.� d����[=#��h#�y4ѥ�y�h�G���r�W��?d�f�y���e3+Fi��]M�O �VC�q�U� �;�)���9̤����O���N����(���8�3Xt}�t4��G�˕�U_gԙ#ҡ�����xv��#�&z���^� ��S(����i�bϮ��^�!�����O�25��RW+d�8�@e�㡽���ĪȪ�S��)Ŝcf�c�g�j㥖�o�s���y��U1�j2�����*1�� ��/�l���,�9�}�*y1���z��h�l�ׇ��2�E)AI���υ3��ԍ�t"�tb�n��[#���虗�Q_2�ST��]0���&�Y�S-�Lj�M��(�N����#��#㘱(�ӯ;� �6L'�g-A��C��טK=,P�����{���0*�aS,��[2��[���A}xZN`����<�&�C92�.�Ap�+���t� �A�����z�f���Ga� T����U�q�S+�rVz9f�D��O�f��`e�;o��.�Z���u^��բJp1y3-�q��V"a� �:��W��ۮ6w�ne���&?�����&�)����P������9 ���2�?Q� �)A �@��c�Z�B���a��e܂�͕Ȁ��B�!7��%��f��ᅮF��|�y,�8�x�ou��RX�dl�/:�ւsQ�1Fxy݄�XP+ b���ޫ��Ƀ��Y��B�H|����C�8�G�J7e����/i�P��MuP�4�^� h[i�p�y�yԯ�?����Gմ��u��j�����a�ɓ^�p��U��y�F��/�2I+`.[hK~`,��t-IU��1��3���(��P|�( �,”�l�R���y9�”�2r-��9����{v*�(�C�v�{0oqɢ>S���{����B� ��8�{-��W7�V`��U;�m�x��)Z�͒>�V-u5Vj�;^y�z�NX��’qP���������~�Ӄ^(üB�3��3/q��}A��8|盬&�~%���� �B��b�b9�*�(�6��’�!�Ã`E�*�j.����3|j��,s��H�C#5,���#�<=5L�#�`N:+�D���W�E� 6 ��E���o#�wF"�����a��M ȱ�`���1X�9��@�i���k�Ue�t'xb�!=�B�)bFL���+7��n ��C"܄O���+y�{����&���r�Z�K&�M�s��p�O�|��%!�B���h��F)1�@�zG��PGl zF���@�L1� �hy�#q6Jj���wZ��7�=A��ؔ���`O���3Wn��Yd;d?��(�¿�s�����K�YPkR�S�7���� �z[Nޮd���Tjw��Ž0��Ҕg�tt��x�')�������%��G��Oq[�J�mp+�N%�̭昬R�m2cs�N�Z�Peg���>L�g7�?�ɷЭ���;��ۇ�[,-4f ���P>/G�0r�L]Cbpײ��O��s&E�┬�”^%&��N��)��4F��31��|��Ɗ%�:�VG��1`,�P���1L���’”D��].X`뺮Ȉ�4��uy P�wgf�)���O��SI��N����m�m�eu���B֩=�s���n8�J�M���iXI����LV���uu����^�5����I��X�O�r�;�hv,N9�ѣ�u,�s�8�����ouX����ݶ|-N [Y:�R�l�9����ܗ��*��M�y 5b�5�A��(�.����K�ޥ�B�I>��P�^�(e �W�yL0�����J!�s��3G��x���H|z_8Z��R�pSX�q�%�������|�{��Ij���l��*,�#~�H7y��Nx��d+)9�lKDx��>&2D;0m’�H{�ʹ�|�)�YV�a�lY�Ͱ�g��_h(!�v��.������Q0|�C�����P��g�I�Q��r���.ff�>�y������M��6���fw��$DD:i-�xLd�]����|����}����s~(�g�L����z6��4�T��8��B��dz�t�?F�ulz��<�g���i�I'��N���崊�S�P;y)�ZX�1��c�p�*��2Q�j.�P��WJ:Y�*ώmn�N�ө�k��낉�,R�q��ֆ�5V+u喁 7���6�/o{���8*�� g�/l�pw�xxd��r���&�usӰ����J���{�%Z�)?�~�z�j�*K��x�⦪[./����hm� �q,N<���f��0ZV~�P3�A���c�����;�7X�d������/7c�bΖ�[��?���R�o���(�/��o7���サ�ڛl�X���JS&�����v�ֱ���yO&�GZ��V�4����@�?�MBF������’�rGDu������%7�֨��3/y�S�ǛP��%�D^l�ѝ�(+Ҹ�I>/��g=tXf[��3RS^���N.���:YL2�BPG��} �O�(���0��7��t’z���,/�ȡ�Q2�[`�D�z;�R���B�I~`���C_��”��@�6″�ԁ<�G�$�l��җsP8�q(��Ot�ϒ�{�� ����e�ȥ�8�;��e��xxx@�i��{�J���f���R�q��.S�?������k�A����JK���4�U ,ЂN(�V"Ыc|���7��'/���+Z�I@i�:���U�wz�s�Y�kF��?��� R��JCjYs�R��J�s��d��N^��p�0 bB��RN�T����M[~f�K��G� r�WD���� […]
Posted by Anthony Pell USN-2950-1 introduced regressions in Samba. ========================================================================== Ubuntu Security Notice USN-2950-4 May 18, 2016 samba regressions ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 12.04 LTS Summary: USN-2950-1 introduced regressions in Samba. Software Description: – samba: SMB/CIFS file, print, and login server for Unix Details: […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Ubuntu: 2950-4: Samba regressions Ubuntu: 2983-1: Expat vulnerability Debian: 3582-1: expat: Summary Ubuntu: 2982-1: Libksba vulnerabilities Ubuntu: 2981-1: libarchive vulnerabilities Ubuntu: 2980-1: libndp vulnerability Debian: 3581-1: libndp: Summary Gentoo: 201605-02 […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3582-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso May 18, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : expat CVE ID : CVE-2016-0718 Gustavo Grieco discovered that Expat, an XML parsing C library, does not properly handle certain kinds of malformed input documents, resulting in buffer overflows during processing and error reporting. […]
Posted by Anthony Pell Libksba could be made to crash or run programs if it decoded speciallycrafted data. ========================================================================== Ubuntu Security Notice USN-2982-1 May 17, 2016 libksba vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 […]
libarchive could be made to crash or run programs if it opened a speciallycrafted file. ========================================================================== Ubuntu Security Notice USN-2981-1 May 17, 2016 libarchive vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: libarchive could […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Ubuntu: 2950-4: Samba regressions Ubuntu: 2983-1: Expat vulnerability Debian: 3582-1: expat: Summary Ubuntu: 2982-1: Libksba vulnerabilities Ubuntu: 2981-1: libarchive vulnerabilities Ubuntu: 2980-1: libndp vulnerability Debian: 3581-1: libndp: Summary Gentoo: 201605-02 […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3581-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso May 17, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libndp CVE ID : CVE-2016-3698 Debian Bug : 824545 Julien Bernard discovered that libndp, a library for the IPv6 Neighbor Discovery Protocol, does not properly perform input and origin checks during the reception of […]
Posted by Anthony Pell Multiple vulnerabilities have been found in the Chromium web browser, the worst of which allows remote attackers to execute arbitrary code. – – – – – – – – – – – – – – – – – – – – – – – – – – – – – […]
Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2978-2 May 16, 2016 linux-lts-wily vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: – linux-lts-wily: Linux hardware enablement kernel from Wily for Trusty […]
Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2978-1 May 16, 2016 linux vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 Summary: Several security issues were fixed in the kernel. Software Description: – linux: Linux kernel Details: David Matlack discovered that the Kernel-based […]
The system could be made to crash or run programs as an administrator. ========================================================================== Ubuntu Security Notice USN-2979-4 May 16, 2016 linux-snapdragon vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS Summary: The system could be made to crash or run programs as an administrator. Software Description: […]
Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2979-2 May 16, 2016 linux-lts-xenial vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: – linux-lts-xenial: Linux hardware enablement kernel from Xenial for Trusty […]
��}�۸��o�j��OY�Z$�1��X���9��g�lNv7*J�$z(�ˏ��ީ��_�WH��#�J�G�’�p�$�H��h4�w�ƾ��P$�h4��F�����’g�������7wϢ�K˛�5��ߟj��Ĺ�klzDfQ��&��Ɯ�^x_�:wϨe�����9�,^T����E_;a^D�H?[�T#c�E�22����� B��h�j�T��w��O�6���*�W/�Ԟ�|UϚӾv�ЅςH)�p�hַ�3�:��$��D�����ri�]i��ԥz�DT���3qƀ���QǺ����#�=�M�m���;��������ߝ�;������:�Q��V��888�>���N:����^��j��i���xij5 B:�؍ml�C�_��:̼�3���������1���c�ֽ �72Z�j���Ƨ�7��V���ָ?28��$/��T��M�?6�4���e���ul�q�(܃�1q�>=��y����4g�ք�LA����i,f�ZS���[X1R?��4����O��>a6���w�{���a��L�[�f��j4�FĞ[�������Ro�]�mm�au�%�ֽ~����F��v����l7P�֏����{�t M%�5��F��”[Ɏ��*�ϖg��;���������S�>�9�]7���Is��cWa�S��}�clh�?�`”���v� x���{���kïO,��>��la��C�F�H_!�_�O�r����Ȱl��t��d��I��A�r1�t���y��hZeQ���0�P”����k̓��v��.�`�`]�rk*ȃ�b’A���DON�,v�د�dFH�~�jNE؟�z�w�hbH����Ĉ���F�R�F�.tU�f�y��Bw5P���Tu�q0�#�-��`�Euv�,�=�J�;2���(���`�>�$_1�Ӊ���]����4X `�*HM��p��=<� ��6e�rwxK��pwGa4�h�;<�N0^ �/yM������^t��o�S3x���W�m���8;x���� �Y��l�o3�rVz9b�D��O�f��`e�;o��.�����T�Su^� ������L��D� �P��6:�A�^���sgඑ�`�v�B�|��� c�Ew�O�4�@ɡQ�9u��-�����!�&�/u���� kC�ň��0ZqĒ�ئZ�)�R� �5�.�s��oq��"�!���t��,�� :YX�j X�O�4���9�f��(j�OW��,U�%@5~���7��� (�:��iº�Ʊ��e7m¦q�gjS��X�չg9������;Y?:��$A�AL������5�0|x9w���]���t�yI�]��^��w��/.,#�q7~��ը.�Ⱥ������7��@�ZL������?�N��d��ğ��~����}��ύcQř��=|k��7���
Just recently we reported on various ransomware types that failed in their malicious intentions. Some were cracked by security experts due to poor implementation, while others flopped because the decryption key had been ‘left’ on the victims’ machine, allowing decryption of files without paying the ransom. But the threat seen by ESET researchers over the […]
Many Android apps in Google Play are still not following best practice when it comes to authentication and authorization. Writing on its Android Developers Blog, Isabella Chen, a software engineer at Google, said that this can leave apps “vulnerable to attack”. It is important that developers make their applications as secure as possible, so that […]
Gustavo Grieco discovered that Expat, an XML parsing C library, does not properly handle certain kinds of malformed input documents, resulting in buffer overflows during processing and error reporting. A remote attacker can take advantage of this flaw to cause an application using the Expat library to crash, or potentially, to execute arbitrary code with […]
Nikolay Ermishkin from the Mail.Ru Security Team and Stewie discovered several vulnerabilities in ImageMagick, a program suite for image manipulation. These vulnerabilities, collectively known as ImageTragick, are the consequence of lack of sanitization of untrusted input. An attacker with control on the image input could, with the privileges of the user running the application, execute […]
APPLE-SA-2016-05-16-6 iTunes 12.4 Subject: APPLE-SA-2016-05-16-6 iTunes 12.4 From: Apple Product Security <email@hidden> Date: Mon, 16 May 2016 15:47:53 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-05-16-6 iTunes 12.4 iTunes 12.4 is now available and addresses the following: iTunes Available for: Windows 7 and later Impact: Running the iTunes installer in an untrusted directory may have […]
APPLE-SA-2016-05-16-5 Safari 9.1.1 Subject: APPLE-SA-2016-05-16-5 Safari 9.1.1 From: Apple Product Security <email@hidden> Date: Mon, 16 May 2016 15:47:18 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-05-16-5 Safari 9.1.1 Safari 9.1.1 is now available and addresses the following: Safari Available for: OS X Mavericks v10.9.5, OS X Yosemite v10.10.5, and OS X El Capitan v10.11.5 Impact: […]
APPLE-SA-2016-05-16-4 OS X El Capitan 10.11.5 and Security Update 2016-003 Subject: APPLE-SA-2016-05-16-4 OS X El Capitan 10.11.5 and Security Update 2016-003 From: Apple Product Security <email@hidden> Date: Mon, 16 May 2016 15:47:01 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-05-16-4 OS X El Capitan 10.11.5 and Security Update 2016-003 OS X El Capitan 10.11.5 and […]
APPLE-SA-2016-05-16-3 watchOS 2.2.1 Subject: APPLE-SA-2016-05-16-3 watchOS 2.2.1 From: Apple Product Security <email@hidden> Date: Mon, 16 May 2016 15:45:42 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-05-16-3 watchOS 2.2.1 watchOS 2.2.1 is now available and addresses the following: CommonCrypto Available for: Apple Watch Sport, Apple Watch, Apple Watch Edition, and Apple Watch Hermes Impact: A malicious […]
APPLE-SA-2016-05-16-2 iOS 9.3.2 Subject: APPLE-SA-2016-05-16-2 iOS 9.3.2 From: Apple Product Security <email@hidden> Date: Mon, 16 May 2016 15:45:17 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-05-16-2 iOS 9.3.2 iOS 9.3.2 is now available and addresses the following: Accessibility Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later Impact: […]
APPLE-SA-2016-05-16-1 tvOS 9.2.1 Subject: APPLE-SA-2016-05-16-1 tvOS 9.2.1 From: Apple Product Security <email@hidden> Date: Mon, 16 May 2016 15:43:43 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-05-16-1 tvOS 9.2.1 tvOS 9.2.1 is now available and addresses the following: CFNetwork Proxies Available for: Apple TV (4th generation) Impact: An attacker in a privileged network position may be […]
Data is king — for attackers as well as defenders. Malicious hackers have long collected and used data in a systematic manner. For example, they investigate all the public-facing servers of a particular target company, as well as document their IP addresses, services, software versions, and back-end relationships. They collect as much publicly accessible information […]
Julien Bernard discovered that libndp, a library for the IPv6 Neighbor Discovery Protocol, does not properly perform input and origin checks during the reception of a NDP message. An attacker in a non-local network could use this flaw to advertise a node as a router, and cause a denial of service attack, or act as […]
Security professionals gave a large collective sigh of sadness this past weekend when BoingBoing published this headline by Cory Doctorow: “Half of Americans reluctant to shop online due to privacy & security fears.” Sarcastic remarks like “No kidding” and “You don’t say” floated through the infosec ether. Why? Because anyone who has studied information security […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3579-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso May 16, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : xerces-c CVE ID : CVE-2016-2099 Debian Bug : 823863 Gustavo Grieco discovered an use-after-free vulnerability in xerces-c, a validating XML parser library for C++, due to not properly handling invalid characters in XML input […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3578-1 security@debian.org https://www.debian.org/security/ Alessandro Ghedini May 14, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libidn CVE ID : CVE-2015-2059 It was discovered that libidn, the GNU library for Internationalized Domain Names (IDNs), did not correctly handle invalid UTF-8 input, causing an out-of-bounds read. This could allow attackers to […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3577-1 security@debian.org https://www.debian.org/security/ Alessandro Ghedini May 14, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : jansson CVE ID : CVE-2016-4425 Debian Bug : 823238 Gustavo Grieco discovered that jansson, a C library for encoding, decoding and manipulating JSON data, did not limit the recursion depth when parsing JSON arrays […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3576-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff May 13, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : icedove CVE ID : CVE-2016-1979 CVE-2016-2805 CVE-2016-2807 Multiple security issues have been found in Icedove, Debian’s version of the Mozilla Thunderbird mail client: Multiple memory safety errors may lead to the execution of arbitrary […]
Planning and policies are essential to good security, but it’s also important to expect the unexpected whenever humans and computers mix. Having a log of user activities can help you deal with those unforeseen circumstances. In our previous posts in this series, we talked about verifying people’s identities with authentication, and then using authorization and […]
Welcome to this week’s security review, which includes an online safety guide for families over the years, the repercussions of last year’s data breach at TalkTalk, and a warning from Adobe of a Flash zero-day vulnerability. Online safety for families across the years Looking for a handy guide to cyber-parenting in the 21st century, one […]
Gustavo Grieco discovered an use-after-free vulnerability in xerces-c, a validating XML parser library for C++, due to not properly handling invalid characters in XML input documents in the DTDScanner. For the stable distribution (jessie), this problem has been fixed in version 3.1.1-5.1+deb8u2. For the testing distribution (stretch), this problem has been fixed in version 3.1.3+debian-2. […]
