Menu

Latest articles

Update Node.js to the 5.x stable branch This update also includes a fix for aman-in-the-middle vulnerability in npm. ——————————————————————————– Fedora Update Notification FEDORA-2016-6ab2d29fba 2016-04-06 14:05:38.729188 ——————————————————————————– Name : nodejs-sqlite3 Product : Fedora 24 Version : 3.1.2 Release : 3.fc24 URL : https://github.com/mapbox/node-sqlite3 Summary : Asynchronous, non-blocking SQLite3 bindings for Node.js Description : Asynchronous, non-blocking SQLite3 […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 libmaxminddb-1.2.0-1.fc24 Fedora 23 python-rsa-3.4.1-1.fc23 Fedora 24 nodejs-5.10.0-1.fc24 Fedora 24 nodejs-sqlite3-3.1.2-3.fc24 Fedora 24 nodejs-iconv-2.1.11-8.fc24 Fedora 24 nodejs-zipfile-0.5.9-7.fc24 Fedora 24 nodejs-request-2.67.0-6.fc24 Fedora 24 nodejs-mapnik-3.5.6-2.fc24 Community Linux Events Linux User Groups […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 libmaxminddb-1.2.0-1.fc24 Fedora 23 python-rsa-3.4.1-1.fc23 Fedora 24 nodejs-5.10.0-1.fc24 Fedora 24 nodejs-sqlite3-3.1.2-3.fc24 Fedora 24 nodejs-iconv-2.1.11-8.fc24 Fedora 24 nodejs-zipfile-0.5.9-7.fc24 Fedora 24 nodejs-request-2.67.0-6.fc24 Fedora 24 nodejs-mapnik-3.5.6-2.fc24 Community Linux Events Linux User Groups […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 libmaxminddb-1.2.0-1.fc24 Fedora 23 python-rsa-3.4.1-1.fc23 Fedora 24 nodejs-5.10.0-1.fc24 Fedora 24 nodejs-sqlite3-3.1.2-3.fc24 Fedora 24 nodejs-iconv-2.1.11-8.fc24 Fedora 24 nodejs-zipfile-0.5.9-7.fc24 Fedora 24 nodejs-request-2.67.0-6.fc24 Fedora 24 nodejs-mapnik-3.5.6-2.fc24 Community Linux Events Linux User Groups […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 libmaxminddb-1.2.0-1.fc24 Fedora 23 python-rsa-3.4.1-1.fc23 Fedora 24 nodejs-5.10.0-1.fc24 Fedora 24 nodejs-sqlite3-3.1.2-3.fc24 Fedora 24 nodejs-iconv-2.1.11-8.fc24 Fedora 24 nodejs-zipfile-0.5.9-7.fc24 Fedora 24 nodejs-request-2.67.0-6.fc24 Fedora 24 nodejs-mapnik-3.5.6-2.fc24 Community Linux Events Linux User Groups […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 libmaxminddb-1.2.0-1.fc24 Fedora 23 python-rsa-3.4.1-1.fc23 Fedora 24 nodejs-5.10.0-1.fc24 Fedora 24 nodejs-sqlite3-3.1.2-3.fc24 Fedora 24 nodejs-iconv-2.1.11-8.fc24 Fedora 24 nodejs-zipfile-0.5.9-7.fc24 Fedora 24 nodejs-request-2.67.0-6.fc24 Fedora 24 nodejs-mapnik-3.5.6-2.fc24 Community Linux Events Linux User Groups […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 libmaxminddb-1.2.0-1.fc24 Fedora 23 python-rsa-3.4.1-1.fc23 Fedora 24 nodejs-5.10.0-1.fc24 Fedora 24 nodejs-sqlite3-3.1.2-3.fc24 Fedora 24 nodejs-iconv-2.1.11-8.fc24 Fedora 24 nodejs-zipfile-0.5.9-7.fc24 Fedora 24 nodejs-request-2.67.0-6.fc24 Fedora 24 nodejs-mapnik-3.5.6-2.fc24 Community Linux Events Linux User Groups […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 libmaxminddb-1.2.0-1.fc24 Fedora 23 python-rsa-3.4.1-1.fc23 Fedora 24 nodejs-5.10.0-1.fc24 Fedora 24 nodejs-sqlite3-3.1.2-3.fc24 Fedora 24 nodejs-iconv-2.1.11-8.fc24 Fedora 24 nodejs-zipfile-0.5.9-7.fc24 Fedora 24 nodejs-request-2.67.0-6.fc24 Fedora 24 nodejs-mapnik-3.5.6-2.fc24 Community Linux Events Linux User Groups […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 libmaxminddb-1.2.0-1.fc24 Fedora 23 python-rsa-3.4.1-1.fc23 Fedora 24 nodejs-5.10.0-1.fc24 Fedora 24 nodejs-sqlite3-3.1.2-3.fc24 Fedora 24 nodejs-iconv-2.1.11-8.fc24 Fedora 24 nodejs-zipfile-0.5.9-7.fc24 Fedora 24 nodejs-request-2.67.0-6.fc24 Fedora 24 nodejs-mapnik-3.5.6-2.fc24 Community Linux Events Linux User Groups […]

WhatsApp Encryption Explained — “Everything is not what it seems”
How Reporters Pulled Off the Panama Papers, the Biggest Leak in Whistleblower History
NoScript and other popular Firefox add-ons open millions to new attack
FBI says hack tool only works on iPhone 5c
Apple fixes iPhone passcode bypass flaw server-side, without having to push out an update
Emergency Adobe Flash update prepped as hackers actively exploit flaw
Hacked spyware firm Hacking Team dealt a further blow

Several vulnerabilities were discovered in cgit, a fast web frontend for git repositories written in C. A remote attacker can take advantage of these flaws to perform cross-site scripting, header injection or denial of service attacks. For the stable distribution (jessie), these problems have been fixed in version 0.10.2.git2.0.1-3+deb8u1. For the testing distribution (stretch), these […]

Several vulnerabilities were discovered in Django, a high-level Python web development framework. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2016-2512 Mark Striemer discovered that some user-supplied redirect URLs containing basic authentication credentials are incorrectly handled, potentially allowing a remote attacker to perform a malicious redirect or a cross-site scripting attack. CVE-2016-2513 Sjoerd […]

Domino’s fixes ‘free pizza’ bug in its Android app
Facebook to Help Users Detect if Someone is Impersonating their Profiles
Azerbaijani Hackers Hack Twitter Account of Russian Embassy in Armenia
Massive application-layer attacks could defeat hybrid DDoS protection
New Azure tool helps IT tame SaaS apps
IDG Contributor Network: You shall not PaaS!

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Red Hat: 2016:0601-01: bind: Important Advisory Ubuntu: 2947-3: Linux kernel (Raspberry Pi 2) vulnerabilities Ubuntu: 2949-1: Linux kernel (Vivid HWE) vulnerabilities Ubuntu: 2948-1: Linux kernel (Utopic HWE) vulnerabilities Ubuntu: 2947-2: […]

Posted by Anthony Pell    Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2947-3 April 06, 2016 linux-raspi2 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 Summary: Several security issues were fixed in the kernel. Software Description: – linux-raspi2: Linux kernel for Raspberry […]

Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2949-1 April 06, 2016 linux-lts-vivid vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: – linux-lts-vivid: Linux hardware enablement kernel from Vivid for Trusty […]

Posted by Anthony Pell    Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2948-1 April 06, 2016 linux-lts-utopic vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: – linux-lts-utopic: Linux hardware enablement […]

Posted by Anthony Pell    Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2947-2 April 06, 2016 linux-lts-wily vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: – linux-lts-wily: Linux hardware enablement […]

Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2946-1 April 06, 2016 linux vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: – linux: Linux kernel Details: Venkatesh Pottem discovered a use-after-free […]

Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2946-2 April 06, 2016 linux-lts-trusty vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 12.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: – linux-lts-trusty: Linux hardware enablement kernel from Trusty for Precise […]

Posted by Anthony Pell    Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2947-1 April 06, 2016 linux vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 Summary: Several security issues were fixed in the kernel. Software Description: – linux: Linux kernel Details: Ralf […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Red Hat: 2016:0601-01: bind: Important Advisory Ubuntu: 2947-3: Linux kernel (Raspberry Pi 2) vulnerabilities Ubuntu: 2949-1: Linux kernel (Vivid HWE) vulnerabilities Ubuntu: 2948-1: Linux kernel (Utopic HWE) vulnerabilities Ubuntu: 2947-2: […]

Posted by Anthony Pell    An update for graphite2 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: graphite2 security, bug fix, and enhancement […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3543-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff April 05, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : oar CVE ID : CVE-2016-1235 Emmanuel Thome discovered that missing sanitising in the oarsh command of OAR, a software used to manage jobs and resources of HPC clusters, could result in privilege escalation. For […]

Posted by Anthony Pell    patch to fix #1319858,#1319859,#1319861 ——————————————————————————– Fedora Update Notification FEDORA-2016-0fb6577f07 2016-04-05 13:05:11.637168 ——————————————————————————– Name : vtun Product : Fedora 23 Version : 3.0.3 Release : 15.fc23 URL : http://vtun.sourceforge.net Summary : Virtual tunnel over TCP/IP networks Description : VTun provides a method for creating Virtual Tunnels over TCP/IP networks and allows […]

When A Dark Web Volunteer Gets Raided By The Police
Apple fixes iOS lock screen bypass that gives attacker access to photos, contacts
WhatsApp adds end-to-end encryption for its one billion users

��}�۶��o�*�ӧL)I}̗g,��c���ڎ�39�s��DBg(���ht�����U��U��or�d���4��${�sS$�ݍF�������O��������7�N�G>$�8-��s�,?z�A�{O’�:�{�$�>������5q/��1�c���� h��<�ׯ���bU�NY_�t�,�a�+=s�x�wإk3C�h�wc�zFdS��;u�Ɯ�=fDňK�#׆�p?�lإ��6�g����ɞ��ҡ�3z������߷zwaw�zu-L�K����������?�<���;��vz���۝���_�x��IXD����_��y}-���&�b�B�E�2ǥ}-]�N`����lfΘ�^���I��s��Sk�SV=k8&y]}q��8� 腤� ����Y@�ȣc���S��i�Ġ��Md�cн������ݽ���A��ʞ���V��n�l3�/iL���4=��ɠ�z��u��#�ޮ��~��;8��8����k��[�� �~l��l>�g8e+p���yd�Qh�)v��[ClUՋ^�O���DC��քVM����sv�[��9 p�?E�4�%Ɓ��L&b_l7��/x����:�+��c�yCj_�3�i~�lc��S�F��^!��~k�� ���� ����ƍ��Y�Q}�Рe�3{��9Zk�z�i�hMY�.�;�8��cjOD���}�m���E1Ll�|n��5�J849��8��vz����1l��#��s���u��ׄ�s3,� �1w=l���C����y8�^��+���0*a,�^?m7��V��O�e��rL��q#C ������FCm��,��R���M C��V&��8��D�^��@��0}@�8z�D��H?��ЉZ�V֗��_���)��w�a&0��_�Y[i�h���]�����AMu��w�����[D��v�O��;�X�� ��͆|(�43)�I[5˾�d[�����ݧk�HF���կ��tL����u4″�� ���iD�T_K�3h�Є@�)��Mr>:-���G����H�TneA� K�N��c�ḗ��GC#��i^� q;0K-(,S�9������H�$�|���N�5��;�B T���4��”5��*�X[I�s���j4�z��#<.���/�fOp��K�R� '�:�@���)m�8��%����c��˩��1Oe1�~d�� ���N��߾���[��)e�3�jג�ѥ�C��y8q��j�x�J�?k9������G�>��߀]�A��’}O�(�a�~s�g3�����?u��-�F�CQ� � B��WQN����*=���=��h�����Lz�c�P׏Υ���q.l����W�V�Q�?v;��h9Q�F� ��mF�^����U�x�;K)D����(�k3�^���P� *’|�j�P�y��uB>�Ё��N� �K�gL�x��� �ȸ����%ފ�����R��F�y���/�郕���תÒ8�’�v�-� p�듗��1{1��7��֗�b�ܖ��+�BE �=���64��b�k�”>�5(�E��nJ��IQ�RpӣN�l���#�;>�iWGu����X���{�����{0e�)��ř��3|�Rn�iMa�E;�6�6��^�r�����D���Z��B(�؄]�?�X����.%�e*4D ��}hy�A�J���>yc”�P�j���B��y�H�ւ$��~k~*&�C’���(�6�p�����dΓ���i��rQ�܇�P���U�Rw&�!)u�S�?��)��J��IY�ۖ�Q^����Y&�P�L����w�OjrՠId28������� )7�C��a&�@ߺ5��d�-���dzO� ���;6][����)��� ���_��{���v��ߕ�e����_���n�P)ϡ��#�y���I0rд�����9�t%s��z�q���F��/�Ic��ΰ�b�y8�9������@Rn /���M��TU�����e����m��C��sc���W����@�W�Z�zit�XS���&S��O�7(��6�3TNG��IȜ���uU��P�f}_�=�Y�C>�U��ke���Œ;���T�H��.(�p��ɑ�����v��#u��- �������αֻuI��j���e�:� h��Ӿ����t�=�F���c�xt�<��y��Q،�V��S�W�����g�� gE ��;�D �澄�!4 �� OƓ�d�1��8=��v�!]��`�z-�G<�sD 6alK4��!�� �ê����t��Q@7�$�d�x!���~��&n�q�"xMӐa'I�G��`$x�D�k�^$'��DJB��x�u�H�sX]�u��k /D�@��S�SyT'�s�=��1�B����7�+PT**�y2���M�ZbV�HQ���r&��*��� G�g���C�>R� �g���2�AF���Q�d�?ȸ ��>^�?�b_���vo�-Y9h�.�s&E���EH9�t�Zf���]�)h�<�K��P�6��yq߳p�c�WǢ��E_��:}u,��X�ձh�� ����c�WǢ��E_��:}u,Z�_��:}u,��X�ձ�vf��m2dx�W���� !lo�"�S(o�u� ��,�p����~� =�� 3��=�l[Pd��’����x:aY�|P[�T�d��&/Dm���h���E)�gu�XC�_D��c�00?����k�4ˆ��k�����A.�o�E�g��F�,K�h��I�^�щ��^ ���h�� V.Z<��|�� X�X�ľ�zf�g�Hm�t�I�����g��ݝ�����������@�"�y�j�x̹�$_��者���J,�ȡ�2f�)OB.?��F�&�Y<��j�}a��̄�ni^Zw��ȼ�)�r-�5���E���~{��n�Y��J����g"�^�J�,Ⱦ0Ƙ�X��D��`4c��1B�tu��T��,�W�k] (�p R������b|]&*���Fѡ,�����xH�3����E��VZ��K ,T��Imb-p+��Z�j�D���]��2G��֒���=��4Q […]

Steam hacker says more vulnerabilities will be found, but not by him
Adobe to issue emergency patch for Flash vulnerability
Server software poses soft target for ransomware
How to protect your Facebook account with Two-Step Verification (2SV)
WhatsApp turns on end-to-end encryption for all
Inside job: What CIOs miss in preventing data leaks

Discovered: April 6, 2016 Updated: April 6, 2016 1:21:55 PM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Trojan.Cryptolocker.AL is a Trojan horse that encrypts files on the compromised computer. It then asks the user to pay […]

Discovered: April 6, 2016 Updated: April 6, 2016 3:00:24 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows NT, Windows Vista, Windows XP Trojan.Ransomcrypt.AE is a Trojan horse that encrypts files on the compromised computer and asks the user to pay in order to decrypt them. Antivirus […]

Mobile Spying – what’s possible, what’s ethical, what’s useful?
Three-year-old IBM patch for critical Java flaw is broken
Donald Trump Hotels Breached Again, Credit Card Data Compromised

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 fuse-encfs-1.8.1-1.fc24 Fedora 24 latex2rtf-2.3.10-1.fc24 Fedora 24 php-5.6.20-1.fc24 Debian: 3541-1: roundcube: Summary Gentoo: 201604-03 Xen: Multiple vulnerabilities Slackware: 2016-095-01: mozilla-thunderbird: Security Update Ubuntu: 2944-1: Libav vulnerabilities Ubuntu: 2945-1: XChat-GNOME […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 fuse-encfs-1.8.1-1.fc24 Fedora 24 latex2rtf-2.3.10-1.fc24 Fedora 24 php-5.6.20-1.fc24 Debian: 3541-1: roundcube: Summary Gentoo: 201604-03 Xen: Multiple vulnerabilities Slackware: 2016-095-01: mozilla-thunderbird: Security Update Ubuntu: 2944-1: Libav vulnerabilities Ubuntu: 2945-1: XChat-GNOME […]

Posted by Anthony Pell    31 Mar 2016, **PHP 5.6.20** **CLI Server:** * Fixed bug php#69953 (SupportMKCALENDAR request method). (Christoph) **Core:** * Fixed bug php#71596(Segmentation fault on ZTS with date function (setlocale)). (Anatol) **Curl:*** Fixed bug php#71694 (Support constant CURLM_ADDED_ALREADY). (mpyw) **Date:*** Fixed bug php#71635 (DatePeriod::getEndDate segfault). (Thomas Punt)**Fileinfo:** * Fixed bug php#71527 (Buffer over-write […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3541-1 security@debian.org https://www.debian.org/security/ Sebastien Delafond April 05, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : roundcube CVE ID : CVE-2015-8770 High-Tech Bridge Security Research Lab discovered that Roundcube, a webmail client, contained a path traversal vulnerability. This flaw could be exploited by an attacker to access sensitive files on […]

Multiple vulnerabilities have been found in Xen, the worst of which cause a Denial of Service. – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – Gentoo Linux Security […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 fuse-encfs-1.8.1-1.fc24 Fedora 24 latex2rtf-2.3.10-1.fc24 Fedora 24 php-5.6.20-1.fc24 Debian: 3541-1: roundcube: Summary Gentoo: 201604-03 Xen: Multiple vulnerabilities Slackware: 2016-095-01: mozilla-thunderbird: Security Update Ubuntu: 2944-1: Libav vulnerabilities Ubuntu: 2945-1: XChat-GNOME […]

Posted by Anthony Pell    Libav could be made to crash or run programs as your login if it opened aspecially crafted file. ========================================================================== Ubuntu Security Notice USN-2944-1 April 04, 2016 libav vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 12.04 LTS Summary: Libav could be made to […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 fuse-encfs-1.8.1-1.fc24 Fedora 24 latex2rtf-2.3.10-1.fc24 Fedora 24 php-5.6.20-1.fc24 Debian: 3541-1: roundcube: Summary Gentoo: 201604-03 Xen: Multiple vulnerabilities Slackware: 2016-095-01: mozilla-thunderbird: Security Update Ubuntu: 2944-1: Libav vulnerabilities Ubuntu: 2945-1: XChat-GNOME […]

Posted by Anthony Pell    patch to fix #1319858,#1319859,#1319861 ——————————————————————————– Fedora Update Notification FEDORA-2016-256f700c92 2016-04-04 17:23:29.743823 ——————————————————————————– Name : vtun Product : Fedora 24 Version : 3.0.3 Release : 15.fc24 URL : http://vtun.sourceforge.net Summary : Virtual tunnel over TCP/IP networks Description : VTun provides a method for creating Virtual Tunnels over TCP/IP networks and allows […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 24 fuse-encfs-1.8.1-1.fc24 Fedora 24 latex2rtf-2.3.10-1.fc24 Fedora 24 php-5.6.20-1.fc24 Debian: 3541-1: roundcube: Summary Gentoo: 201604-03 Xen: Multiple vulnerabilities Slackware: 2016-095-01: mozilla-thunderbird: Security Update Ubuntu: 2944-1: Libav vulnerabilities Ubuntu: 2945-1: XChat-GNOME […]

UL takes on cybersecurity testing and certification

Discovered: April 4, 2016 Updated: April 5, 2016 8:48:04 AM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Infostealer.Fakepude is a Trojan horse that steals information from the compromised computer. Antivirus Protection Dates Initial Rapid Release version […]

Discovered: April 1, 2016 Updated: April 4, 2016 9:50:42 AM Type: Trojan Infection Length: Varies Systems Affected: Linux, Solaris, Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP PHP.Ransomcrypt.B is a Trojan horse that encrypts files on the compromised server. Antivirus Protection […]

WhatsApp is now encrypting all your messages, by default, all the time, end-to-end
Trump Hotel Collection suffers data breach

The Trump Hotel Collection has once again suffered a data breach, according to a security expert. Brian Krebs reported that banking industry sources have informed him that the chain, which belongs to the Republican presidential candidate Donald Trump, has been the victim of another attack. Mr. Krebs said that he was alerted to this story […]

Trojan found in more than 100 Android apps on Google Play Store
Four tax scams to watch out for this tax season
Better History Chrome extension goes rogue, hijacks browsers and displays ads
Denial Syndrome: Users don’t think they’ll get hacked
This startup uses math to show whether your network is safe
Digital certificates are helping deliver malware

Digital certificates and malware go together like peanut butter and petroleum jelly — they can be sandwiched together easily, but the result is not exactly tasty or good for you. As you may know, digital certificates are used to cryptographically sign executable code and documents. If the digital certificate used for signing the content was […]

Prevent Neighbors from Stealing Your Bandwidth with This New Wi-Fi

Emmanuel Thome discovered that missing sanitising in the oarsh command of OAR, a software used to manage jobs and resources of HPC clusters, could result in privilege escalation. For the oldstable distribution (wheezy), this problem has been fixed in version 2.5.2-3+deb7u1. For the stable distribution (jessie), this problem has been fixed in version 2.5.4-2+deb8u1. For […]

Several vulnerabilities have been discovered in Mercurial, a distributed version control system. The Common Vulnerabilities and Exposures project identifies the following issues: CVE-2016-3068 Blake Burkhart discovered that Mercurial allows URLs for Git subrepositories that could result in arbitrary code execution on clone. CVE-2016-3069 Blake Burkhart discovered that Mercurial allows arbitrary code execution when converting Git […]

High-Tech Bridge Security Research Lab discovered that Roundcube, a webmail client, contained a path traversal vulnerability. This flaw could be exploited by an attacker to access sensitive files on the server, or even execute arbitrary code. For the oldstable distribution (wheezy), this problem has been fixed in version 0.7.2-9+deb7u2. For the testing (stretch) and unstable […]

Discovered: April 4, 2016 Updated: April 4, 2016 11:38:57 PM Type: Worm Infection Length: 262,144 bytes Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP W32.Ransomlock.AP is a is a worm that locks the desktop, making the compromised computer unusable. […]

Someone Hacked and Leaked Entire Turkish Citizenship Database Online

Risk High Date Discovered March 8, 2016 Description Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed […]

Alert Gamers: RAT Activity Identified in Steam Stealer Malware Scam

Posted by Anthony Pell    A NetworkManager 1.0.x branch stable update: * Release notes:https://cgit.freedesktop.org/NetworkManager/NetworkManager/tree/NEWS?h=1.0.12 *Release announcement: https://mail.gnome.org/archives/networkmanager-list/2016-April/msg00000.html ——————————————————————————– Fedora Update Notification FEDORA-2016-8201e3fefa 2016-04-03 14:04:39.114316 ——————————————————————————– Name : NetworkManager Product : Fedora 23 Version : 1.0.12 Release : 1.fc23 URL : http://www.gnome.org/projects/NetworkManager/ Summary : Network connection manager and user applications Description : NetworkManager is a system […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3540-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff April 03, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : lhasa CVE ID : CVE-2016-2347 Marcin Noga discovered an integer underflow in Lhasa, a lzh archive decompressor, which might result in the execution of arbitrary code if a malformed archive is processed. For the […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 NetworkManager-1.0.12-1.fc23 Debian: 3540-1: lhasa: Summary Gentoo: 201604-02 Xalan-Java: Arbitrary code execution Gentoo: 201604-01 QEMU: Multiple vulnerabilities Fedora 24 NetworkManager-pptp-1.2.0-0.3.beta3.fc24 Fedora 24 Update: NetworkManager-libreswan-1.2.0-0.4.beta3.fc24 Fedora 24 NetworkManager-vpnc-1.2.0-0.4.beta3.fc24 Fedora 24 […]

Posted by Anthony Pell    Multiple vulnerabilities have been found in QEMU, the worst of which could lead to arbitrary code execution, or cause a Denial of Service condition. – – – – – – – – – – – – – – – – – – – – – – – – – – […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 NetworkManager-1.0.12-1.fc23 Debian: 3540-1: lhasa: Summary Gentoo: 201604-02 Xalan-Java: Arbitrary code execution Gentoo: 201604-01 QEMU: Multiple vulnerabilities Fedora 24 NetworkManager-pptp-1.2.0-0.3.beta3.fc24 Fedora 24 Update: NetworkManager-libreswan-1.2.0-0.4.beta3.fc24 Fedora 24 NetworkManager-vpnc-1.2.0-0.4.beta3.fc24 Fedora 24 […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 NetworkManager-1.0.12-1.fc23 Debian: 3540-1: lhasa: Summary Gentoo: 201604-02 Xalan-Java: Arbitrary code execution Gentoo: 201604-01 QEMU: Multiple vulnerabilities Fedora 24 NetworkManager-pptp-1.2.0-0.3.beta3.fc24 Fedora 24 Update: NetworkManager-libreswan-1.2.0-0.4.beta3.fc24 Fedora 24 NetworkManager-vpnc-1.2.0-0.4.beta3.fc24 Fedora 24 […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 NetworkManager-1.0.12-1.fc23 Debian: 3540-1: lhasa: Summary Gentoo: 201604-02 Xalan-Java: Arbitrary code execution Gentoo: 201604-01 QEMU: Multiple vulnerabilities Fedora 24 NetworkManager-pptp-1.2.0-0.3.beta3.fc24 Fedora 24 Update: NetworkManager-libreswan-1.2.0-0.4.beta3.fc24 Fedora 24 NetworkManager-vpnc-1.2.0-0.4.beta3.fc24 Fedora 24 […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 NetworkManager-1.0.12-1.fc23 Debian: 3540-1: lhasa: Summary Gentoo: 201604-02 Xalan-Java: Arbitrary code execution Gentoo: 201604-01 QEMU: Multiple vulnerabilities Fedora 24 NetworkManager-pptp-1.2.0-0.3.beta3.fc24 Fedora 24 Update: NetworkManager-libreswan-1.2.0-0.4.beta3.fc24 Fedora 24 NetworkManager-vpnc-1.2.0-0.4.beta3.fc24 Fedora 24 […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 NetworkManager-1.0.12-1.fc23 Debian: 3540-1: lhasa: Summary Gentoo: 201604-02 Xalan-Java: Arbitrary code execution Gentoo: 201604-01 QEMU: Multiple vulnerabilities Fedora 24 NetworkManager-pptp-1.2.0-0.3.beta3.fc24 Fedora 24 Update: NetworkManager-libreswan-1.2.0-0.4.beta3.fc24 Fedora 24 NetworkManager-vpnc-1.2.0-0.4.beta3.fc24 Fedora 24 […]

Posted by Anthony Pell    Update to NetworkManager 1.2-beta3. Upstream release announcement:https://mail.gnome.org/archives/networkmanager-list/2016-March/msg00164.html ——————————————————————————– Fedora Update Notification FEDORA-2016-cd218eef79 2016-04-02 15:48:47.755168 ——————————————————————————– Name : NetworkManager Product : Fedora 24 Version : 1.2.0 Release : 0.8.beta3.fc24 URL : http://www.gnome.org/projects/NetworkManager/ Summary : Network connection manager and user applications Description : NetworkManager is a system service that manages network interfaces […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 NetworkManager-1.0.12-1.fc23 Debian: 3540-1: lhasa: Summary Gentoo: 201604-02 Xalan-Java: Arbitrary code execution Gentoo: 201604-01 QEMU: Multiple vulnerabilities Fedora 24 NetworkManager-pptp-1.2.0-0.3.beta3.fc24 Fedora 24 Update: NetworkManager-libreswan-1.2.0-0.4.beta3.fc24 Fedora 24 NetworkManager-vpnc-1.2.0-0.4.beta3.fc24 Fedora 24 […]