Menu

Latest articles

A Government Error Just Revealed Snowden Was the Target in the Lavabit Case
Pwn2Own Day Two: Safari, Edge Go Down And Winner Crowned
Google’s reverse engineering software BinDiff now free for researchers
Ransomware targets Flash and Silverlight vulnerabilities
Hackers Target NASA with DDoS Attack, Claim to Shutdown Email Servers

It was discovered that the ActiveMQ Java message broker performs unsafe deserialisation. For additional information, please refer to the upstream advisory at http://activemq.apache.org/security-advisories.data/CVE-2015-5254-announcement.txt. For the oldstable distribution (wheezy), this problem has been fixed in version 5.6.0+dfsg-1+deb7u2. For the stable distribution (jessie), this problem has been fixed in version 5.6.0+dfsg1-4+deb8u2. For the testing distribution (stretch), this […]

This update disables the Graphite font shaping library in Iceweasel, Debian’s version of the Mozilla Firefox web browser. For the oldstable distribution (wheezy), this problem has been fixed in version 38.7.1esr-1~deb7u1. For the stable distribution (jessie), this problem has been fixed in version 38.7.1esr-1~deb8u1. For the unstable distribution (sid), this problem has been fixed in […]

Apple to release iOS 9.3 after fixing iMessages encryption vulnerability

Posted by Anthony Pell    Update to 2.40 Fixes various security issues, seehttp://www.mozilla.org/security/known-vulnerabilities/seamonkey.html for moreinfo. ——————————————————————————– Fedora Update Notification FEDORA-2016-eacfc58fb9 2016-03-21 19:49:51.272763 ——————————————————————————– Name : seamonkey Product : Fedora 23 Version : 2.40 Release : 1.fc23 URL : http://www.seamonkey-project.org Summary : Web browser, e-mail, news, IRC client, HTML editor Description : SeaMonkey is an all-in-one […]

# Bugs fixed: * 762027 print-preview: Fix possible integer overflow flaw(CVE-2013-7447) # Updated translations: * Gaelic (Scottish) * Portuguese ——————————————————————————– Fedora Update Notification FEDORA-2016-330bfc0338 2016-03-21 19:49:51.272885 ——————————————————————————– Name : gnome-photos Product : Fedora 23 Version : 3.18.3 Release : 1.fc23 URL : https://live.gnome.org/GnomePhotos Summary : Access, organize and share your photos on GNOME Description : […]

Posted by Anthony Pell    Updated openssh packages that fix two security issues are now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having Moderate security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: openssh security update Advisory ID: RHSA-2016:0465-01 Product: Red Hat Enterprise Linux Advisory URL: […]

Posted by Anthony Pell    Updated openssh packages that fix two security issues are now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having Moderate security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: openssh security update Advisory ID: RHSA-2016:0466-01 Product: Red Hat Enterprise Linux Advisory URL: […]

Git could be made to crash or run programs as your login if it receivedchanges from a specially crafted remote repository. ========================================================================== Ubuntu Security Notice USN-2938-1 March 21, 2016 git vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: […]

Several security issues were fixed in WebKitGTK+. ========================================================================== Ubuntu Security Notice USN-2937-1 March 21, 2016 webkitgtk vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS Summary: Several security issues were fixed in WebKitGTK+. Software Description: – webkitgtk: Web content engine library for GTK+ Details: […]

Twitter security noticeboard

Ten years ago, Jack Dorsey, Noah Glass, Biz Stone and Evan Williams founded Twitter. Little would they know of its impact, its popularity and its usefulness to people the world over. As its celebrates its 10th birthday, we take a look at things from a security point of view with our ‘noticeboard’ feature. Here’s to […]

To pay or not to pay? What you should know about ransomware

��}�v۸��o���5��H��_�-�&�s;����ݽ=I�”!�6E2$e����+�9�w_l��S�$;r�{�uwl �B�P( �_�?:���1����ޣ�Q4v�C�aWa��ӉB� 쫮� ��(��=��>f�>Q����Q��O���E�g��׉}�U�<7bn��^�L!�x�*���p�� dQw �]��r8�W��v�}�}'��q�YC�/��1�*�6��^erOm+u-vi�L�/ b�vdSGM�n�����B;b�%�m"���|�o�����<�ɶ��Ң�5x矼���?6ywa��:e5��K�����le����w�ono��Z�W���fk���ы��[������ ��U���a�1 @�d7�P!cfٴ�����ttW�]<�N�)s�K2s�ѵnzcc�k)#�1 �Ρ�"���9t�<�~�X���� ��_Ϗ����ԎF��hZo� �#��N=��k���"�C�ˈF�ڛ�p�M��ޔо7�H@��Oi�b=KY��f`���B�(�^�&��Opjo@��%��MB(g1«t-2�i �cC�gg *�95/B�6 �!� �Y��=��u]1��L�z.p�����Bc ��PKɡA��țjP�������6��30��$���]��x82�b�J���Q~`� �M�U����d���������O'��w�t�g8^2�������zK����*I^U�=�C�t�3h�;�B��lm͎�l���0S����{& �L5�d6��`���_��~ì���Ī���%���������j8�u�z���EW��66�o5�m)��E��mlX:�>�,���`�D�{�Ҁ� �I������; ��C���R,��D���A�@=��[���lm7��w[�F��ܩ7��f�a��F�oju�a�0�:�S�[���lIX��ݮ��}�=�Pk����h�uP��z}�q�6�)�CS�l�}S�K�Rvl�VY.|q}J��`H���:ԪS�g�u4��f�o��Ac��’>��a�&��>*�OЙHeL�Ԯ�/߿�@���[���u�>�n�8�l�&����l�$ ���{m���]���:���Kh�;��͂��lZM���J� H f)�a�q�ޠ%yQ�����#��9�j����u�;��cF�]��qA�52��`�F�p틖�`^lv�]u 3�1����1�3���r��.%���@�����[��/2W�^�� Yհ>�P�g�o�� *�P�śJl��z>,S=�g�P����D�ԥ�E1g��3q��{�j�k-��U@��]*�Uѽjܽ�P��*1�o �����qu��Bu0��y1`��$р �(�_�}�i�I+F;�p榈Uc.�Љ�W�4��+����F�S@Fb�* ��L}�o�Y[�:2����7MX胠�2�F���A�?��Q@��`��$_1��u�k�C���V�zX� ���om<ނX�g��o��8=�G�� T�z�zZ��Ԃߍ��C�N!��Y�$ Hd�H�9���H��:^��������g�x�V�*���bZ������}m�q/�R�I10����bB�(���q��0�z9��&��Bw�H|;���Cu?�G�R�V�˧旤h�=�g1��_����� a�y�y�o��ݟ���’���+漶�Q[[���g���&(�g�$�m�&�/�̧/�-�v���}v�}��n$��+��} � �1�H��K���|��uumFHZ���r��L�p��Ϙn��`�PӾRg��ص*9DMӡa�U�.�č�!�4����QPx%��d��TA��b�b>Y+4o�mli��C8��E�UXV]n����s8v�t0���MB#� ��-՟��������9��´C�߉�p���up ‘ሕA)��R>+�p���1{�J�V.�dc����;�rs���6^�c)�d��(��z+ܘ@EA-��#w�D�M�����WU$:��=��@s&A�>��� �bal�Oΐp-�|��P�g.��HY��v}��c1�:��B@�5��s@A�*�-ܿ.���,]�颔���B�GnT�I}3�ȄH�O����@��c�Tʔw�2��ree�;z��*��Zf��?��U�*q��&�Pxo�crT�_���y���Cp�߇�?��������F�F(ɕ�3t� =y�xПD����/J��� *���[��a�,U�’�PcW b�,��Z�b�!�D��: qO�R�š��� ��.ܜ�g-{`���y��7*������%d��D��_ ɒ�ɲ2Yv�n���(���$R��6q8�J ��g��qA��+-cGl�m��%��T�~G�j�$��l��?G��t�;��ũ����>��u���p�= X��E��l�Z[�;��4I�A(u�s��戚2 zC#F�#���2��Ϥ��1����?�a��(tAӷWӛg�7�0�����a”>-[���!�n�!�B�D�yM��3�F��,�Pxr��K���o� ,m��#V��7u�ty��i�0�&���� �,L��C>��`�>���L�(�}���( �Ƃ’�$�ri�n�d��m��.�e�z�$� 2�GY��x��,JOM���=;�n�)V�i��2�ҲM�ȗe�Mq���@��z���n7�W��A��BťC�Ϻb�@��7;�U2 �#y�y��MFނp�cK2��4�J�gnΝ:wplv:�mq��gZ��q�Yc��N�`��,��#���i�8@R� +����&��4o,A���������]��E��3m{Z�,� […]

US will still push for encryption workarounds, even though iPhone hearing was postponed

APPLE-SA-2016-03-21-7 OS X Server 5.1 Subject: APPLE-SA-2016-03-21-7 OS X Server 5.1 From: Apple Product Security <email@hidden> Date: Mon, 21 Mar 2016 17:54:38 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-03-21-7 OS X Server 5.1 OS X Server 5.1 is now available and addresses the following: Server App Available for: OS X Yosemite v10.10.5 and later […]

APPLE-SA-2016-03-21-6 Safari 9.1 Subject: APPLE-SA-2016-03-21-6 Safari 9.1 From: Apple Product Security <email@hidden> Date: Mon, 21 Mar 2016 17:54:10 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-03-21-6 Safari 9.1 Safari 9.1 is now available and addresses the following: libxml2 Available for: OS X Mavericks v10.9.5, OS X Yosemite v10.10.5, OS X El Capitan v10.11 to v10.11.3 […]

APPLE-SA-2016-03-21-5 OS X El Capitan 10.11.4 and Security Update 2016-002 Subject: APPLE-SA-2016-03-21-5 OS X El Capitan 10.11.4 and Security Update 2016-002 From: Apple Product Security <email@hidden> Date: Mon, 21 Mar 2016 17:53:54 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-03-21-5 OS X El Capitan 10.11.4 and Security Update 2016-002 OS X El Capitan 10.11.4 and […]

APPLE-SA-2016-03-21-4 Xcode 7.3 Subject: APPLE-SA-2016-03-21-4 Xcode 7.3 From: Apple Product Security <email@hidden> Date: Mon, 21 Mar 2016 17:53:29 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-03-21-4 Xcode 7.3 Xcode 7.3 is now available and addresses the following: otool Available for: OS X El Capitan v10.11 and later Impact: A local attacker may be able to […]

APPLE-SA-2016-03-21-3 tvOS 9.2 Subject: APPLE-SA-2016-03-21-3 tvOS 9.2 From: Apple Product Security <email@hidden> Date: Mon, 21 Mar 2016 17:53:12 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-03-21-3 tvOS 9.2 tvOS 9.2 is now available and addresses the following: FontParser Available for: Apple TV (4th generation) Impact: Opening a maliciously crafted PDF file may lead to an […]

APPLE-SA-2016-03-21-2 watchOS 2.2 Subject: APPLE-SA-2016-03-21-2 watchOS 2.2 From: Apple Product Security <email@hidden> Date: Mon, 21 Mar 2016 17:51:14 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-03-21-2 watchOS 2.2 watchOS 2.2 is now available and addresses the following: Disk Images Available for: Apple Watch Sport, Apple Watch, Apple Watch Edition, and Apple Watch Hermes Impact: An […]

APPLE-SA-2016-03-21-1 iOS 9.3 Subject: APPLE-SA-2016-03-21-1 iOS 9.3 From: Apple Product Security <email@hidden> Date: Mon, 21 Mar 2016 17:49:31 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-03-21-1 iOS 9.3 iOS 9.3 is now available and addresses the following: AppleUSBNetworking Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later Impact: […]

Apple patches 56 vulnerabilities in OS X El Capitan, improves Live Photo sharing
Financial threats 2015: 73 percent drop in financial Trojan infections but threat is far from neutralized
Google warns of Android flaw used to gain root access to devices
Clarke: Precedent-Seeking FBI Won’t Ask NSA to Unlock Phone
Hackers Steal $81 Million from Federal Reserve
Tor Project says it can quickly catch spying code
Google, Microsoft, Yahoo, and others publish new email security standard
Get hired as a security pro: Insider tips

Over the years I’ve hired or helped hire hundreds of computer security folks. Although job interviews tend to last an hour, I can usually tell in a few minutes if I’m talking to the right person for the job. If I think I have the right person, I will lead them into saying the right […]

Discovered: March 21, 2016 Updated: March 22, 2016 10:29:37 AM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Infostealer.Olymvis is a Trojan horse that steals information from the compromised computer. Antivirus Protection Dates Initial Rapid Release version […]

Hacking Brain Possible with DARPA’ New Targeted Neuroplasticity Training Program
Facebook Develops Artificial Intelligence to Map World Populace Accurately

Alex Rousskov from The Measurement Factory discovered that Squid3, a fully featured web proxy cache, does not properly handle errors for certain malformed HTTP responses. A remote HTTP server can exploit this flaw to cause a denial of service (assertion failure and daemon exit). For the oldstable distribution (wheezy), this problem has been fixed in […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 webkitgtk3-2.4.10-1.fc23 Fedora 23 websvn-2.3.3-12.fc23 Fedora 23 proftpd-1.3.5b-1.fc23 Fedora 23 libvpx-1.4.0-6.fc23 Fedora 23 git-2.5.5-1.fc23 Debian: 3524-1: activemq: Summary Debian: 3523-1: iceweasel: Summary Fedora 22 websvn-2.3.3-12.fc22 Community Linux Events Linux […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 webkitgtk3-2.4.10-1.fc23 Fedora 23 websvn-2.3.3-12.fc23 Fedora 23 proftpd-1.3.5b-1.fc23 Fedora 23 libvpx-1.4.0-6.fc23 Fedora 23 git-2.5.5-1.fc23 Debian: 3524-1: activemq: Summary Debian: 3523-1: iceweasel: Summary Fedora 22 websvn-2.3.3-12.fc22 Community Linux Events Linux […]

Posted by Anthony Pell    Cumulative maintenance release from upstream. Highlights are: * SSH RSAhostkeys smaller than 2048 bits now work properly. * MLSD response lines are nowproperly CRLF terminated. * Fixed selection of DH groups from TLSDHParamFile(CVE-2016-3125). Various other bug fixes are also included. ——————————————————————————– Fedora Update Notification FEDORA-2016-977d57cf2d 2016-03-20 22:04:03.376869 ——————————————————————————– Name : […]

Fix CVE-2016-1621 in bundled libwebm code. ——————————————————————————– Fedora Update Notification FEDORA-2016-fae59061fe 2016-03-20 22:04:03.376115 ——————————————————————————– Name : libvpx Product : Fedora 23 Version : 1.4.0 Release : 6.fc23 URL : http://www.webmproject.org/code/ Summary : VP8 Video Codec SDK Description : libvpx provides the VP8 SDK, which allows you to integrate your applications with the VP8 video codec, […]

Security fix for CVE-2016-2315, CVE-2016-2324 (by updating to 2.5.5). ——————————————————————————– Fedora Update Notification FEDORA-2016-6554eff611 2016-03-20 22:04:03.375556 ——————————————————————————– Name : git Product : Fedora 23 Version : 2.5.5 Release : 1.fc23 URL : http://git-scm.com/ Summary : Fast Version Control System Description : Git is a fast, scalable, distributed revision control system with an unusually rich command […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3524-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff March 20, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : activemq CVE ID : CVE-2015-5254 It was discovered that the ActiveMQ Java message broker performs unsafe deserialisation. For additional information, please refer to the upstream advisory at http://activemq.apache.org/security-advisories.data/CVE-2015-5254-announcement.txt For the oldstable distribution (wheezy), this […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3523-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff March 20, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : iceweasel CVE ID : not available This update disables the Graphite font shaping library in Iceweasel, Debian’s version of the Mozilla Firefox web browser. For the oldstable distribution (wheezy), this problem has been fixed […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 webkitgtk3-2.4.10-1.fc23 Fedora 23 websvn-2.3.3-12.fc23 Fedora 23 proftpd-1.3.5b-1.fc23 Fedora 23 libvpx-1.4.0-6.fc23 Fedora 23 git-2.5.5-1.fc23 Debian: 3524-1: activemq: Summary Debian: 3523-1: iceweasel: Summary Fedora 22 websvn-2.3.3-12.fc22 Community Linux Events Linux […]

Posted by Anthony Pell    Cumulative maintenance release from upstream. Highlights are: * SSH RSAhostkeys smaller than 2048 bits now work properly. * MLSD response lines are nowproperly CRLF terminated. * Fixed selection of DH groups from TLSDHParamFile(CVE-2016-3125). Various other bug fixes are also included. ——————————————————————————– Fedora Update Notification FEDORA-2016-f95d8ea3ad 2016-03-20 16:01:37.694775 ——————————————————————————– Name : […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3522-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso March 20, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : squid3 CVE ID : CVE-2016-2571 Alex Rousskov from The Measurement Factory discovered that Squid3, a fully featured web proxy cache, does not properly handle errors for certain malformed HTTP responses. A remote HTTP server […]

Posted by Anthony Pell    Multiple vulnerabilities have been found in OpenSSL, the worst allowing remote attackers to decrypt TLS sessions. – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 webkitgtk3-2.4.10-1.fc23 Fedora 23 websvn-2.3.3-12.fc23 Fedora 23 proftpd-1.3.5b-1.fc23 Fedora 23 libvpx-1.4.0-6.fc23 Fedora 23 git-2.5.5-1.fc23 Debian: 3524-1: activemq: Summary Debian: 3523-1: iceweasel: Summary Fedora 22 websvn-2.3.3-12.fc22 Community Linux Events Linux […]

Symantec fixes high-risk flaws in Symantec Endpoint Protection
Tim Cook comments on iPhone data privacy and security
Google makes BinDiff code analysis plug-in available for free
27% of US office workers would sell their passwords
How FBI vs. Apple could cripple corporate and government security
The security review: What you need to know about Locky

Welcome to this week’s security review, which includes the Locky threat, the nuisance of Robocalls, another celeb-related iCloud breach and a warning from the FBI that cars are vulnerable to cyberattacks. Trojan Downloaders on the rise: Don’t let Locky or TeslaCrypt ruin your day ESET’s Josep Albors and Raphael Labaca Castro revealed that weeks after […]

Edward Snowden: Privacy can’t depend on corporations standing up to the government
How to fight off a zombie app-ocalypse
Researchers find flaw in Apple’s iMessage, decrypt iCloud photo
Google Removes SmeshApp Allegedly Used by Pakistan’ ISI to Spy on Indian military

Multiple security issues have been found in Icedove, Debian’s version of the Mozilla Thunderbird mail client: Multiple memory safety errors, integer overflows, buffer overflows and other implementation errors may lead to the execution of arbitrary code or denial of service. For the oldstable distribution (wheezy), these problems have been fixed in version 38.7.0-1~deb7u1. For the […]

ProtonMail Goes Public – Enjoy Encrypted Emails and Pay in Bitcoin
Secure Messaging Scorecard
US government pushed tech firms to hand over source code
How to respond to ransomware threats

Lael Cellier discovered two buffer overflow vulnerabilities in git, a fast, scalable, distributed revision control system, which could be exploited for remote execution of arbitrary code. For the oldstable distribution (wheezy), these problems have been fixed in version 1:1.7.10.4-1+wheezy3. For the stable distribution (jessie), these problems have been fixed in version 1:2.1.4-2.1+deb8u2. For the unstable […]

Anonymous Leak Data from Japan’ Safari Land-Natural Zoo For Animal Rights

Multiple security issues have been found in the Xen virtualisation solution, which may result in denial of service or information disclosure. The oldstable distribution (wheezy) will be updated in a separate DSA. For the stable distribution (jessie), these problems have been fixed in version 4.4.1-9+deb8u4. For the unstable distribution (sid), these problems will be fixed […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Slackware: 2016-077-01: mozilla-firefox: Security Update Debian: 3519-1: xen: Summary Fedora 22 jenkins-1.609.3-6.fc22 Fedora 22 jenkins-remoting-2.53.3-1.fc22 Fedora 22 python-django-1.8.11-1.fc22 Fedora 22 rubygem-actionpack-4.2.0-4.fc22 Fedora 22 rubygem-actionview-4.2.0-5.fc22 Fedora 23 jenkins-remoting-2.53.3-1.fc23 Community Linux Events […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3519-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff March 17, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : xen CVE ID : CVE-2015-8339 CVE-2015-8340 CVE-2015-8341 CVE-2015-8550 CVE-2015-8555 CVE-2016-1570 CVE-2016-1571 CVE-2016-2270 CVE-2016-2271 Multiple security issues have been found in the Xen virtualisation solution, which may result in denial of service or information disclosure. […]

Posted by Anthony Pell    Fixes CVE-2016-0788, CVE-2016-0789, CVE-2016-0790, CVE-2016-0791, CVE-2016-0792 ——————————————————————————– Fedora Update Notification FEDORA-2016-0f490eea10 2016-03-17 16:03:22.862356 ——————————————————————————– Name : jenkins Product : Fedora 22 Version : 1.609.3 Release : 6.fc22 URL : http://jenkins-ci.org Summary : An extendable open source continuous integration server Description : Jenkins is an award-winning application that monitors executions of […]

Posted by Anthony Pell    Fixes CVE-2016-0788, CVE-2016-0789, CVE-2016-0790, CVE-2016-0791, CVE-2016-0792 ——————————————————————————– Fedora Update Notification FEDORA-2016-0f490eea10 2016-03-17 16:03:22.862356 ——————————————————————————– Name : jenkins-remoting Product : Fedora 22 Version : 2.53.3 Release : 1.fc22 URL : https://github.com/jenkinsci/remoting Summary : Jenkins remoting module Description : This package is primarily used by Jenkins for slave node management, but it […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Slackware: 2016-077-01: mozilla-firefox: Security Update Debian: 3519-1: xen: Summary Fedora 22 jenkins-1.609.3-6.fc22 Fedora 22 jenkins-remoting-2.53.3-1.fc22 Fedora 22 python-django-1.8.11-1.fc22 Fedora 22 rubygem-actionpack-4.2.0-4.fc22 Fedora 22 rubygem-actionview-4.2.0-5.fc22 Fedora 23 jenkins-remoting-2.53.3-1.fc23 Community Linux Events […]

* Fix rails-html-sanitizer v1.0.3 compatibility. * Fix code injectionvulnerability (CVE-2016-2098). ——————————————————————————– Fedora Update Notification FEDORA-2016-3954061e32 2016-03-17 16:03:22.861593 ——————————————————————————– Name : rubygem-actionpack Product : Fedora 22 Version : 4.2.0 Release : 4.fc22 URL : http://www.rubyonrails.org Summary : Web-flow and rendering framework putting the VC in MVC Description : Eases web-request routing, handling, and response as a […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Slackware: 2016-077-01: mozilla-firefox: Security Update Debian: 3519-1: xen: Summary Fedora 22 jenkins-1.609.3-6.fc22 Fedora 22 jenkins-remoting-2.53.3-1.fc22 Fedora 22 python-django-1.8.11-1.fc22 Fedora 22 rubygem-actionpack-4.2.0-4.fc22 Fedora 22 rubygem-actionview-4.2.0-5.fc22 Fedora 23 jenkins-remoting-2.53.3-1.fc23 Community Linux Events […]

Posted by Anthony Pell    Fixes CVE-2016-0788, CVE-2016-0789, CVE-2016-0790, CVE-2016-0791, CVE-2016-0792,and possible NoClassDefFoundError: org/codehaus/stax2/XMLInputFactory2 exceptionbug. ——————————————————————————– Fedora Update Notification FEDORA-2016-641c8b4eb2 2016-03-17 16:03:46.458729 ——————————————————————————– Name : jenkins-remoting Product : Fedora 23 Version : 2.53.3 Release : 1.fc23 URL : https://github.com/jenkinsci/remoting Summary : Jenkins remoting module Description : This package is primarily used by Jenkins for slave […]

Posted by Anthony Pell    Fixes CVE-2016-0788, CVE-2016-0789, CVE-2016-0790, CVE-2016-0791, CVE-2016-0792,and possible NoClassDefFoundError: org/codehaus/stax2/XMLInputFactory2 exceptionbug. ——————————————————————————– Fedora Update Notification FEDORA-2016-641c8b4eb2 2016-03-17 16:03:46.458729 ——————————————————————————– Name : jenkins Product : Fedora 23 Version : 1.625.3 Release : 3.fc23 URL : http://jenkins-ci.org Summary : An extendable open source continuous integration server Description : Jenkins is an award-winning, cross-platform, […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Slackware: 2016-077-01: mozilla-firefox: Security Update Debian: 3519-1: xen: Summary Fedora 22 jenkins-1.609.3-6.fc22 Fedora 22 jenkins-remoting-2.53.3-1.fc22 Fedora 22 python-django-1.8.11-1.fc22 Fedora 22 rubygem-actionpack-4.2.0-4.fc22 Fedora 22 rubygem-actionview-4.2.0-5.fc22 Fedora 23 jenkins-remoting-2.53.3-1.fc23 Community Linux Events […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Slackware: 2016-077-01: mozilla-firefox: Security Update Debian: 3519-1: xen: Summary Fedora 22 jenkins-1.609.3-6.fc22 Fedora 22 jenkins-remoting-2.53.3-1.fc22 Fedora 22 python-django-1.8.11-1.fc22 Fedora 22 rubygem-actionpack-4.2.0-4.fc22 Fedora 22 rubygem-actionview-4.2.0-5.fc22 Fedora 23 jenkins-remoting-2.53.3-1.fc23 Community Linux Events […]

* Fix rails-html-sanitizer v1.0.3 compatiblity. * Fix code injectionvulnerability (CVE-2016-2098). ——————————————————————————– Fedora Update Notification FEDORA-2016-f6af14570f 2016-03-17 16:03:46.457347 ——————————————————————————– Name : rubygem-actionpack Product : Fedora 23 Version : 4.2.3 Release : 5.fc23 URL : http://www.rubyonrails.org Summary : Web-flow and rendering framework putting the VC in MVC Description : Eases web-request routing, handling, and response as a […]

A lot happens in the security world and many stories get lost in the mix. In an effort to keep our readers informed and updated, we present the Webroot Threat Recap, highlighting 5 major security news stories of the week. Credit Card Fraud Now Quicker Than Ever There are thousands of cases of credit card […]

5 things you need to know about SSL
Cyber warfare shows scary signs of where malware is headed
FBI warn that automobiles are vulnerable to cyberattacks

��}�r۸���j�aN��D$u�-v�|�����r۱���&Y$Bm�dx���q�y�ݪݪ}���’��MΓl7R�E�,+��Vr�$ 4��F��@?������o�N^����hO�Ro�՘g�r�� dC粫�2�����Q`N��E�4�s�јQ�w���&,����>%�EW;�y�q2�F�WW��ela���1 #w�xh�k��U����/O�#���*��ϻ��|U�NXW�p�4��X)=u�xܵم3`�� ���u�h@]�mUA���eF��̸`�3t���)�O�mz�_����a��n?�)k ��/����O�_ߜڗ��&�u���l��G������O�ww��;�΋��f��w������’���E���:�9 ��բx�h� �K��H#f;������1tW�C<�N�)s��A:���k)+� �,�ΡY�!��29t�=�o��]� 'c'"H��l�����ͳ`�4%4`Z6f�����T�L&4�iJ�I�fAo6�e�G�P��[~��؟P�[&N*~ �Y�5@�������ͧQL���%�����:�9��T#�^P�V�A�;Sdz�y: ��?s�YÀG�K>k}�_@���~�>X�95�p��⤈>X?d,^�׾�k���MA53�F�#�p���t�7^Z�ZM�HA`B7������� ���5�9�ޞE�����f��Ӯ��[w���(5��7���ob�h�� ɠ�79��s�F �{��Vo�݁9b17�/����_5�mk�Ð� 0�}��m�=�O�k��E�j`E ��@k@GH�i��If/f�ґ��v)VL�Ԏc0�F�0�’G`��6���tvv;��v#{n���F��������_��˼Q �:(}�4�1�����3���&�|A�,���I��^�#(�’�_GP�h�%8<��~� �x (����W[���R]��U�N�����}�gt���D,���F1g�b��3 �]72�3C�o������bx�txu��ցGub��T�_�;���:3��`�6?�b����$т �*���s�.J J҆���R8sͦ1��� i���d���=z���9 K��� �6o�i�v;U�h���8@�dC�XȢ��4���)T������8�Cl;�f �ac���T�rs��}JX83S�U����s�^���F;l䇳��-�^����c���8�x5:w��Y4�9�c�` ��!��t��A��UFn��f�z���Ga� T�z[�nP�n�^A�J/�=#qHb�#�u����7�]�� v���:/��jQ'��������:KE+����r����{��—mט8�7�� ��i�$�G��0t��(94���n�i��1�/@�1� c��'3�!4�M�Bֆ �1�&Qt���t*6�l���y��z��w���C-]D��R��-|�R��_��'k�"�K�шE�p~�t�N)]JR ���&���V&,�$��L�]��Mqnz@$�-g�g�~��C�ҽ����1����}���ၕ�S6�CV�V$�c�� ����h{��r��s�ܗ�� zk���|����â�P�Ľ���C��y��X&m̬�96 �����>_�F2�? �+D�ˑ�H�� #��c��bo��Ip�.�o�c��˭���x�>��^db���_O^�^?���k퇭���g5+Y��‰����<;� ��h���4���<6%�`ku�8��`�=�A����Zw�4~�:��a�]�nWG��+4u���}�[��~x&�^�k�3��aK_B[��V�<����b�h9C�K�ی/��|��2w<��*Es��(�jS�^����� &'|��j�PS�x�?j�ПjiU,S,'[��%�5&��?DxdFU�e�w�W^�uz�(Y��}?��#�M�ߐ_���E���

Security Sessions: Tips for building a security team
Watch Out Gamers: Steam Stealer malware is up and running
To bypass code-signing checks, malware gang steals lots of certificates
Encrypted email service ProtonMail comes out of beta, unveils iOS and Android apps
Vehicles ‘increasingly vulnerable’ to hacking, FBI warns
New exploit spotlights Android’s Stagefright vulnerability
The 10 Windows group policy settings you need to get right
Trojan Downloaders on the rise: Don’t let Locky or TeslaCrypt ruin your day

Weeks after it started attacking and encrypting victims’ files, Locky is still targeting many users. In order to provide more information about this threat, we have put together some information to help protect you in a better way. Short summary Win32/Filecoder.Locky.A is a ransomware variant that encrypts files with over 100 file types such as images, videos, databases, […]

iOS Malware AceDeceiver: Hide and Seek between Apple’s DRM Versus MITM

If you’re one of the people who is still stubbornly holding onto Windows XP (which stopped receiving support and security updates as of April 8, 2014), it’s time to let go. Likewise, if you’re using an outdated version of your preferred internet browser, it’s time to update. Right now. Why? In both scenarios, you’re putting your personal online […]