Menu

Latest articles

Risk Medium Date Discovered August 12, 2008 Description Microsoft Windows Messenger is prone to an information-disclosure vulnerability. An attacker can exploit this issue by enticing an unsuspecting victim to visit a malicious HTML page. Successfully exploiting this issue allows remote attackers to obtain sensitive information that may aid in further attacks. Technologies Affected Microsoft Windows […]

Risk High Date Discovered June 17, 2008 Description Microsoft Word is prone to a remote memory-corruption vulnerability. An attacker could exploit this issue by enticing a victim to open and interact with malicious Word files. Successfully exploiting this issue will corrupt memory and crash the application. Given the nature of this issue, attackers may also […]

APPLE-SA-2016-03-28-1 OS X: Flash Player plug-in blocked Subject: APPLE-SA-2016-03-28-1 OS X: Flash Player plug-in blocked From: Apple Product Security <email@hidden> Date: Mon, 28 Mar 2016 13:20:04 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-03-28-1 OS X: Flash Player plug-in blocked Due to security issues in older versions, Apple has updated the web plug-in blocking mechanism […]

Free Bitdefender tool prevents Locky, other ransomware infections — for now
FBI Finally Hacks San Bernardino Gunman’s iPhone Proving Snowden Was Right
How one developer just broke Node, Babel and thousands of projects in 11 lines of JavaScript
Snowden ‘more helpful than dangerous’ says ex-Colin Powell aide
Way to Go, FCC. Now Manufacturers Are Locking Down Routers
Google Fixes Four Critical Vulnerabilities in Latest Chrome Build
FBI hack may raise questions about iPhone security
Spread honeypots over your defense plan

I love honeypots. I’ve even written a book about them. Any time you set up a fake system that nothing and no one should try to connect to, you cull invaluable information that any security defender will find useful. I’m still surprised that honeypots aren’t part of every organization’s security strategy. My guess is that’s […]

Guido Vranken discovered several vulnerabilities in dhcpcd, a DHCP client, which may result in denial of service. For the oldstable distribution (wheezy), these problems have been fixed in version 1:3.2.3-11+deb7u1. We recommend that you upgrade your dhcpcd packages.

Kashyap Thimmaraju and Bhargava Shastry discovered a remotely triggerable buffer overflow vulnerability in openvswitch, a production quality, multilayer virtual switch implementation. Specially crafted MPLS packets could overflow the buffer reserved for MPLS labels in an OVS internal data structure. A remote attacker can take advantage of this flaw to cause a denial of service, or […]

Discovered: March 29, 2016 Updated: March 29, 2016 1:49:56 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Trojan.Cryptolocker.AJ is a Trojan horse that encrypts files on the compromised computer. Symantec Security Response is […]

Risk High Date Discovered February 5, 2015 Description Adobe Flash Player is prone to multiple unspecified security vulnerabilities. Attackers can exploit these issues to execute arbitrary code in the context of the user running the affected application. Failed attacks may cause denial-of-service conditions. Recommendations Run all software as a nonprivileged user with minimal access rights. […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 22 webkitgtk4-2.10.9-1.fc22 Debian: 3532-1: quagga: Summary Fedora 24 php-pecl-http-2.5.6-1.fc24 Fedora 24 samba-4.4.0-0.7.rc4.fc24 Fedora 24 libotr-4.1.1-1.fc24 Fedora 24 drupal6-emfield-2.7-1.fc24 Fedora 24 criu-2.0-1.fc24 Fedora 24 openssh-7.2p2-1.fc24 Community Linux Events Linux User […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3532-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso March 27, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : quagga CVE ID : CVE-2016-2342 Debian Bug : 819179 Kostya Kortchinsky discovered a stack-based buffer overflow vulnerability in the VPNv4 NLRI parser in bgpd in quagga, a BGP/OSPF/RIP routing daemon. A remote attacker can […]

Posted by Anthony Pell    **Version 2.5.6** * Fix php-bug php#71719: Buffer overflow in HTTP url parsingfunctions (Mike, rc0r) * Fix gh-issue #28: Possible null pointer dereference inphp_http_url_mod() (rc0r) * Fix gh-issue #22: Fix PHP5 config.w32 (Jan Ehrhardt)* Fix gh-issue #20: setSslOptions notice with curl 7.43 (Mike, Vitaliy Demidov) ——————————————————————————– Fedora Update Notification FEDORA-2016-9d6b6d0689 2016-03-27 […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 22 webkitgtk4-2.10.9-1.fc22 Debian: 3532-1: quagga: Summary Fedora 24 php-pecl-http-2.5.6-1.fc24 Fedora 24 samba-4.4.0-0.7.rc4.fc24 Fedora 24 libotr-4.1.1-1.fc24 Fedora 24 drupal6-emfield-2.7-1.fc24 Fedora 24 criu-2.0-1.fc24 Fedora 24 openssh-7.2p2-1.fc24 Community Linux Events Linux User […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 22 webkitgtk4-2.10.9-1.fc22 Debian: 3532-1: quagga: Summary Fedora 24 php-pecl-http-2.5.6-1.fc24 Fedora 24 samba-4.4.0-0.7.rc4.fc24 Fedora 24 libotr-4.1.1-1.fc24 Fedora 24 drupal6-emfield-2.7-1.fc24 Fedora 24 criu-2.0-1.fc24 Fedora 24 openssh-7.2p2-1.fc24 Community Linux Events Linux User […]

Posted by Anthony Pell    ### 6.x-2.7 Fixes [Embedded Media Field – Moderately Critical – Access Bypass -DRUPAL-SA-CONTRIB-2016-004](https://www.drupal.org/node/2666446) #### Changessince 6.x-2.6: * by dalin: Ensure that width and height are always numbers. *#1868588 by tangent: URL detection regex does not match hyphens / breaks HTMLmarkup ——————————————————————————– Fedora Update Notification FEDORA-2016-f0bb0dad51 2016-03-27 00:00:51.401145 ——————————————————————————– Name : […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 22 webkitgtk4-2.10.9-1.fc22 Debian: 3532-1: quagga: Summary Fedora 24 php-pecl-http-2.5.6-1.fc24 Fedora 24 samba-4.4.0-0.7.rc4.fc24 Fedora 24 libotr-4.1.1-1.fc24 Fedora 24 drupal6-emfield-2.7-1.fc24 Fedora 24 criu-2.0-1.fc24 Fedora 24 openssh-7.2p2-1.fc24 Community Linux Events Linux User […]

This update provides recent upstrem fix published with openssh-7.2p2 (#1316529). ——————————————————————————– Fedora Update Notification FEDORA-2016-0bcab055a7 2016-03-27 00:00:51.399587 ——————————————————————————– Name : openssh Product : Fedora 24 Version : 7.2p2 Release : 1.fc24 URL : http://www.openssh.com/portable.html Summary : An open source implementation of SSH protocol versions 1 and 2 Description : SSH (Secure SHell) is a program […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 22 webkitgtk4-2.10.9-1.fc22 Debian: 3532-1: quagga: Summary Fedora 24 php-pecl-http-2.5.6-1.fc24 Fedora 24 samba-4.4.0-0.7.rc4.fc24 Fedora 24 libotr-4.1.1-1.fc24 Fedora 24 drupal6-emfield-2.7-1.fc24 Fedora 24 criu-2.0-1.fc24 Fedora 24 openssh-7.2p2-1.fc24 Community Linux Events Linux User […]

Posted by Anthony Pell    Cumulative maintenance release from upstream. Highlights are: * SSH RSAhostkeys smaller than 2048 bits now work properly. * MLSD response lines are nowproperly CRLF terminated. * Fixed selection of DH groups from TLSDHParamFile(CVE-2016-3125) Various other bug fixes are also included. ——————————————————————————– Fedora Update Notification FEDORA-2016-ac3587be9a 2016-03-27 00:00:51.398858 ——————————————————————————– Name : […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 22 webkitgtk4-2.10.9-1.fc22 Debian: 3532-1: quagga: Summary Fedora 24 php-pecl-http-2.5.6-1.fc24 Fedora 24 samba-4.4.0-0.7.rc4.fc24 Fedora 24 libotr-4.1.1-1.fc24 Fedora 24 drupal6-emfield-2.7-1.fc24 Fedora 24 criu-2.0-1.fc24 Fedora 24 openssh-7.2p2-1.fc24 Community Linux Events Linux User […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 22 webkitgtk4-2.10.9-1.fc22 Debian: 3532-1: quagga: Summary Fedora 24 php-pecl-http-2.5.6-1.fc24 Fedora 24 samba-4.4.0-0.7.rc4.fc24 Fedora 24 libotr-4.1.1-1.fc24 Fedora 24 drupal6-emfield-2.7-1.fc24 Fedora 24 criu-2.0-1.fc24 Fedora 24 openssh-7.2p2-1.fc24 Community Linux Events Linux User […]

Anonymous Relaunches #OpCanary, Targets Canadian Mining Firm

Discovered: March 26, 2016 Updated: March 28, 2016 2:05:38 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows NT, Windows Vista, Windows XP Trojan.Ransomcrypt.AF is a Trojan horse that encrypts files on the compromised computer and asks the user to pay in order to decrypt them. For […]

Apple demands delay in NY iPhone case
Petya ransomware overwrites MBRs, locking users out of their computers
Google Submariner surfaces untrusted certificate authorities
Apple Watch saves life of 62-year-old man suffering heart attack
Impressed with Wikileaks, Brazilian Activists Launch BrasiLeaks

Kostya Kortchinsky discovered a stack-based buffer overflow vulnerability in the VPNv4 NLRI parser in bgpd in quagga, a BGP/OSPF/RIP routing daemon. A remote attacker can exploit this flaw to cause a denial of service (daemon crash), or potentially, execution of arbitrary code, if bgpd is configured with BGP peers enabled for VPNv4. For the oldstable […]

What happens when Google Maps go wrong? Wrong House Gets Demolished

Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-1646 Wen Xu discovered an out-of-bounds read issue in the v8 library. CVE-2016-1647 A use-after-free issue was discovered. CVE-2016-1648 A use-after-free issue was discovered in the handling of extensions. CVE-2016-1649 lokihardt discovered a buffer overflow issue in the Almost Native Graphics Layer Engine (ANGLE) library. […]

Multiple security vulnerabilities have been fixed in the Tomcat servlet and JSP engine, which may result on bypass of security manager restrictions, information disclosure, denial of service or session fixation. For the oldstable distribution (wheezy), these problems have been fixed in version 6.0.45+dfsg-1~deb7u1. We recommend that you upgrade your tomcat6 packages.

Verizon Hacked Again, 1.5M Customers Data Available for Sale
Facebook to be the biggest virtual graveyard by 2098
Iranians charged with cyberattacks on US banks, New York dam
It’s time for security spring cleaning
Smartphone Lookalike Gun Coming This Year

Posted by Anthony Pell    **Version 2.5.6** * Fix php-bug php#71719: Buffer overflow in HTTP url parsingfunctions (Mike, rc0r) * Fix gh-issue #28: Possible null pointer dereference inphp_http_url_mod() (rc0r) * Fix gh-issue #22: Fix PHP5 config.w32 (Jan Ehrhardt)* Fix gh-issue #20: setSslOptions notice with curl 7.43 (Mike, Vitaliy Demidov) ——————————————————————————– Fedora Update Notification FEDORA-2016-474c1d8264 2016-03-25 […]

Fix signature verification bypass attack, reported by Jann Horn ——————————————————————————– Fedora Update Notification FEDORA-2016-b98995ae24 2016-03-25 01:07:07.545267 ——————————————————————————– Name : torbrowser-launcher Product : Fedora 23 Version : 0.2.4 Release : 1.fc23 URL : https://github.com/micahflee/torbrowser-launcher Summary : Tor Browser Bundle managing tool Description : Tor Browser Launcher is intended to make Tor Browser easier to install and […]

OpenJDK could be made to crash or run programs as your login if it receivedspecially crafted input. ========================================================================== Ubuntu Security Notice USN-2942-1 March 24, 2016 openjdk-7 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS Summary: OpenJDK could be made to crash or run […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 php-pecl-http-2.5.6-1.fc23 Fedora 23 torbrowser-launcher-0.2.4-1.fc23 Ubuntu: 2942-1: OpenJDK 7 vulnerability Red Hat: 2016:0516-01: java-1.8.0-oracle: Critical Advisory Red Hat: 2016:0513-01: java-1.8.0-openjdk: Critical Advisory Red Hat: 2016:0515-01: java-1.7.0-oracle: Critical Advisory Red […]

Posted by Anthony Pell    An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: java-1.8.0-openjdk security update Advisory ID: RHSA-2016:0513-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0513.html Issue date: […]

Posted by Anthony Pell    An update for java-1.7.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 5, Oracle Java for Red Hat Enterprise Linux 6, and Oracle Java for Red Hat Enterprise Linux 7. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: java-1.7.0-oracle security update Advisory ID: RHSA-2016:0515-01 Product: Oracle Java […]

Posted by Anthony Pell    An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 5 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: java-1.7.0-openjdk security update Advisory ID: RHSA-2016:0512-01 Product: Red Hat Enterprise […]

Posted by Anthony Pell    An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: java-1.8.0-openjdk security update Advisory ID: RHSA-2016:0514-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0514.html Issue date: […]

Posted by Anthony Pell    An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: java-1.7.0-openjdk security update Advisory ID: RHSA-2016:0511-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0511.html Issue date: […]

Quagga could be made to crash or run programs if it received speciallycrafted network traffic. ========================================================================== Ubuntu Security Notice USN-2941-1 March 24, 2016 quagga vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: Quagga could be made to crash […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3527-1 security@debian.org https://www.debian.org/security/ Sebastien Delafond March 24, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : inspircd CVE ID : CVE-2015-8702 It was discovered that inspircd, an IRC daemon, incorrectly handled PTR lookups of connecting users. This flaw allowed a remote attacker to crash the application by setting up malformed […]

An update for python-django is now available for Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: python-django security update Advisory ID: RHSA-2016:0505-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: […]

New ransomware abuses Windows PowerShell, Word document macros
The Badlock bug: Start your patch prep today

A lot happens in the security world and many stories get lost in the mix. In an effort to keep our readers informed and updated, we present the Webroot Threat Recap, highlighting 5 major security news stories of the week. Microsoft Addresses Macro Malware Issue With macros being a major vulnerability point in Microsoft Office […]

10 big announcements from Google’s Cloud Conference
Why IT can’t handle data breaches alone
Bruce Schneier on the Integration of Privacy and Security
Only 0.1% of you are doing web server security right
Verizon’s breach experts missed one right under their noses
Apple vs. FBI is over, but the encryption battle rages on
Microsoft’s ‘Tay and You’ AI bot went completely Nazi

Multiple vulnerabilities have been found in Redmine, a project management web application, which may result in information disclosure. For the stable distribution (jessie), these problems have been fixed in version 3.0~20140825-8~deb8u2. For the testing distribution (stretch), these problems have been fixed in version 3.2.0-1. For the unstable distribution (sid), these problems have been fixed in […]

Stefan Sperling discovered that pidgin-otr, a Pidgin plugin implementing Off-The-Record messaging, contained a use-after-free bug. This could be used by a malicious remote user to intentionally crash the application, thus causing a denial-of-service. For the stable distribution (jessie), this problem has been fixed in version 4.0.1-1+deb8u1. For the testing (stretch) and unstable (sid) distributions, this […]

It was discovered that libmatroska, an extensible open standard audio/video container format, incorrectly processed EBML lacing. By providing maliciously crafted input, an attacker could use this flaw to force some leakage of information located in the process heap memory. For the oldstable distribution (wheezy), this problem has been fixed in version 1.3.0-2+deb7u1. For the stable […]

Expert Palestinian Hacker Indicted for Hacking Israeli Drones
U.S. government accuses 7 Iranians of hacking banks, New York dam
Emergency Java update fixes two-year-old flaw after researchers bypass old patch
USB Trojan hides in portable applications, targets air-gapped systems
Rise in malicious domains portends rise in attacks

Discovered: March 23, 2016 Updated: March 24, 2016 3:19:59 PM Also Known As: RANSOM_MAKTUB.A [Trend] Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Trojan.Cryptolocker.AI is a Trojan horse that encrypts files on the compromised […]

Pakistan-Linked Hackers Conduct Third Cyber-Espionage Campaign Against India
FBI Adds Syrian Electronic Army Hackers in Cyber’s Most Wanted List
To stop the hackers, security teams need to share more data on attacks
Paris terrorists used burner phones, not encryption, to evade detection
How to make Android a real part of your business

It was discovered that inspircd, an IRC daemon, incorrectly handled PTR lookups of connecting users. This flaw allowed a remote attacker to crash the application by setting up malformed DNS records, thus causing a denial-of-service, For the oldstable distribution (wheezy), this problem has been fixed in version 2.0.5-1+deb7u2. For the stable distribution (jessie), this problem […]

DOJ knew of possible iPhone-cracking method before Apple case
Artificial Intelligence Robot claims it will destroy human race

Vincent LE GARREC discovered an integer overflow in pixman, a pixel-manipulation library for X and cairo. A remote attacker can exploit this flaw to cause an application using the pixman library to crash, or potentially, to execute arbitrary code with the privileges of the user running the application. For the oldstable distribution (wheezy), this problem […]

ISPs have built huge data systems to track us with, report says

Updated nss-util packages that fix one security issue are now available for Red Hat Enterprise Linux 6.2, 6.4, and 6.5 Advanced Update Support, and Red Hat Enterprise Linux 6.6 and 7.1 Extended Update Support. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: nss-util security update Advisory ID: RHSA-2016:0495-01 Product: Red Hat Enterprise Linux Advisory URL: […]

Posted by Anthony Pell    Updated krb5 packages that fix two security issues are now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having Moderate security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: krb5 security update Advisory ID: RHSA-2016:0493-01 Product: Red Hat Enterprise Linux Advisory URL: […]

Posted by Anthony Pell    Updated tomcat6 packages that fix one security issue and one bug are now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having Moderate security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: tomcat6 security and bug fix update Advisory ID: RHSA-2016:0492-01 Product: […]

Posted by Anthony Pell    An updated foomatic package that fixes three security issues is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having Moderate security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: foomatic security update Advisory ID: RHSA-2016:0491-01 Product: Red Hat Enterprise Linux Advisory […]

Updated kernel packages that fix one security issue, several bugs, and add one enhancement are now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having Moderate security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: kernel security, bug fix, and enhancement update Advisory ID: RHSA-2016:0494-01 Product: Red […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Red Hat: 2016:0495-01: nss-util: Critical Advisory Red Hat: 2016:0493-01: krb5: Moderate Advisory Red Hat: 2016:0492-01: tomcat6: Moderate Advisory Red Hat: 2016:0491-01: foomatic: Moderate Advisory Red Hat: 2016:0494-01: kernel: Moderate Advisory […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Red Hat: 2016:0495-01: nss-util: Critical Advisory Red Hat: 2016:0493-01: krb5: Moderate Advisory Red Hat: 2016:0492-01: tomcat6: Moderate Advisory Red Hat: 2016:0491-01: foomatic: Moderate Advisory Red Hat: 2016:0494-01: kernel: Moderate Advisory […]

CVE-2016-3119, NULL dereference in LDAP module. —- Fix an issue with returncodes on `gss_inquire_attrs_for_mech`. This resolves an issue with gss-ntlmssp,and anything else that is interposing but not implementing the correspondingmechglue function. ——————————————————————————– Fedora Update Notification FEDORA-2016-56840babc3 2016-03-22 15:54:44.506003 ——————————————————————————– Name : krb5 Product : Fedora 23 Version : 1.14.1 Release : 3.fc23 URL : http://web.mit.edu/kerberos/www/ […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3525-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso March 22, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : pixman CVE ID : CVE-2014-9766 Vincent LE GARREC discovered an integer overflow in pixman, a pixel-manipulation library for X and cairo. A remote attacker can exploit this flaw to cause an application using the […]

FBI could ‘bypass’ Apple to unlock San Bernardino iPhone

The FBI has said it may no longer need Apple’s assistance in opening the locked iPhone belonging to an attacker in December’s San Bernardino, California shooting. As reported by the BBC, a court hearing with Apple scheduled for today (March 22nd) has been postponed at the request of the US Department of Justice, after federal […]

Microsoft adds macros lockdown feature in Office 2016 in response to increasing attacks