Menu

Latest articles

Millions of Android devices vulnerable to Stagefright bug again
Hackers can hack Internet Connected Sex Toys and Record Videos

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Ubuntu: 2935-2: PAM regression Red Hat: 2016:0458-01: bind97: Important Advisory Red Hat: 2016:0459-01: bind: Important Advisory Ubuntu: 2935-1: PAM vulnerabilities Ubuntu: 2930-3: Linux kernel (Raspberry Pi 2) vulnerabilities Debian: 3518-1: […]

Posted by Anthony Pell    Updated bind97 packages that fix two security issues are now available for Red Hat Enterprise Linux 5. Red Hat Product Security has rated this update as having Important security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: bind97 security update Advisory ID: RHSA-2016:0458-01 Product: Red Hat Enterprise Linux Advisory URL: […]

Updated bind packages that fix two security issues are now available for Red Hat Enterprise Linux 5, 6, and 7. Red Hat Product Security has rated this update as having Important security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: bind security update Advisory ID: RHSA-2016:0459-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0459.html Issue […]

ProtonMail: Encrypted key to a more secure future

Encryption is “key” to a more secure future, ProtonMail’s co-founder and CEO Dr. Andy Yen has told We Live Security. In an email, he said that with the “growth of ecommerce and all our data and business moving online”, the “only viable” way of maintaining information security is through end-to-encryption. His comments come at a […]

Locky Ransomware Spreading in Massive Spam Attack
DIRB – Domain Brute-forcing Tool
VMware fixes XSS flaws in vRealize for Linux
Cyber Criminals Hijack BBC, MSN and NYT Website To Serve Malicious Ads
FBI identifies WhatsApp as next target while court case with Apple goes on
Attackers exploit Apple DRM weakness to infect non-jailbroken iOS devices
This is how criminals install credit card skimmer within seconds

Several security issues were fixed in PAM. ========================================================================== Ubuntu Security Notice USN-2935-1 March 16, 2016 pam vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: Several security issues were fixed in PAM. Software Description: – pam: Pluggable Authentication Modules […]

Posted by Anthony Pell    Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2930-3 March 16, 2016 linux-raspi2 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 Summary: Several security issues were fixed in the kernel. Software Description: – linux-raspi2: Linux kernel for Raspberry […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3518-1 security@debian.org https://www.debian.org/security/ Sebastien Delafond March 16, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : spip CVE ID : CVE-2016-3153 CVE-2016-3154 Several vulnerabilities were found in SPIP, a website engine for publishing, resulting in code injection. CVE-2016-3153 g0uZ et sambecks, from team root-me, discovered that arbitrary PHP code could […]

Posted by Anthony Pell    New git packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix security issues. [More Info…] [slackware-security] git (SSA:2016-075-01) New git packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix security issues. Here are the details from the Slackware 14.1 ChangeLog: […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Ubuntu: 2935-1: PAM vulnerabilities Ubuntu: 2930-3: Linux kernel (Raspberry Pi 2) vulnerabilities Debian: 3518-1: spip: Summary Slackware: 2016-075-01: git: Security Update Slackware: 2016-075-02: seamonkey: Security Update Fedora 22 pcre-8.38-3.fc22 Fedora […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Ubuntu: 2935-1: PAM vulnerabilities Ubuntu: 2930-3: Linux kernel (Raspberry Pi 2) vulnerabilities Debian: 3518-1: spip: Summary Slackware: 2016-075-01: git: Security Update Slackware: 2016-075-02: seamonkey: Security Update Fedora 22 pcre-8.38-3.fc22 Fedora […]

– Update to the latest upstream – 45.0 ——————————————————————————– Fedora Update Notification FEDORA-2016-5b2c402bb1 2016-03-15 19:46:12.477825 ——————————————————————————– Name : firefox Product : Fedora 22 Version : 45.0 Release : 4.fc22 URL : https://www.mozilla.org/projects/firefox/ Summary : Mozilla Firefox Web browser Description : Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability. ——————————————————————————– […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Ubuntu: 2935-1: PAM vulnerabilities Ubuntu: 2930-3: Linux kernel (Raspberry Pi 2) vulnerabilities Debian: 3518-1: spip: Summary Slackware: 2016-075-01: git: Security Update Slackware: 2016-075-02: seamonkey: Security Update Fedora 22 pcre-8.38-3.fc22 Fedora […]

Posted by Anthony Pell    Updated rh-php56-php packages that fix multiple security issues are now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having Moderate security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: rh-php56-php security update Advisory ID: RHSA-2016:0457-01 Product: Red Hat Software Collections Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0457.html […]

Posted by Anthony Pell    Updated rh-ror41-rubygem-actionview packages that fix two security issues are now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having Important security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: rh-ror41 security update Advisory ID: RHSA-2016:0456-01 Product: Red Hat Software Collections Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0456.html […]

Updated ruby193-rubygem-actionpack and ruby193-rubygem-activerecord packages that fix multiple security issues are now available for Red Hat Software Collections. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: ruby193 security update Advisory ID: RHSA-2016:0455-01 Product: Red Hat Software Collections Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0455.html Issue date: 2016-03-15 CVE Names: CVE-2015-7576 CVE-2015-7577 CVE-2016-0751 CVE-2016-0752 CVE-2016-2097 CVE-2016-2098 ===================================================================== 1. Summary: Updated […]

Updated ror40-rubygem-actionpack and ror40-rubygem-activerecord packages that fix multiple security issues are now available for Red Hat Software Collections. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: ror40 security update Advisory ID: RHSA-2016:0454-01 Product: Red Hat Software Collections Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0454.html Issue date: 2016-03-15 CVE Names: CVE-2015-7576 CVE-2015-7577 CVE-2015-7581 CVE-2016-0751 CVE-2016-0752 CVE-2016-2097 CVE-2016-2098 ===================================================================== 1. Summary: […]

Google adds transparency to online encryption

��}�۸��oOվLoLi-����3���c�Y�-;����v� �8C�4/���N�y���W�<�c�!:�]��q��s�,/��A�;�ƌڽ;���{4a1�E �1q.�ڑ��̋��Y�42��Z�.c<�i����Cc_#V��6~yb��N�UA�x�e��ztºڅæ��J�c���.�3�qh_vΫZ�D�ul3��R�=���o�?���=j�:?��6�������>}��XD���㝓��]-�g.�ƌb��$� �42a�C�Z:|�@w59���Ԝ2׹`$��́?���!���1��Ȃ���28,�C�����5r2v”��#�����;��ԉ���Fo�Q��.��ӚPێHR/ hȼ��>�=�#�3�8�,QiK��͢A���p�4B����l���V��2��Y0R0�, �x0���`%� gڂ�_��,��v�bP���k!�� u�eⳠ��&��$d4��k��E~�i���oH�

Hackers can change election result using flaws in Electronic Voting Machines
How the Candidates View Cybersecurity, From Total Indifference to Mild Indifference
Why Apple went to war with the FBI
Former cyber czar says NSA could crack the San Bernadino shooter’s phone
Large advertising-based cyber attack hit BBC, New York Times, MSN
NSFW: John Oliver wants Apple to come clean

Several vulnerabilities were found in SPIP, a website engine for publishing, resulting in code injection. CVE-2016-3153 g0uZ et sambecks, from team root-me, discovered that arbitrary PHP code could be injected when adding content. CVE-2016-3154 Gilles Vincent discovered that deserializing untrusted content could result in arbitrary objects injection. For the oldstable distribution (wheezy), these problems have […]

Pedophiles May Be Using Anonymous’ Symbolic Mask To Trap Children
Google increases bug bounty reward for Chromebook to $100,000

Risk High Date Discovered March 8, 2016 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted webpage. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause […]

Risk High Date Discovered March 8, 2016 Description Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed […]

Anonymous Urge Hackers To Join Them in Cyber Attacks Against Donald Trump

Several security issues were fixed in Exim. ========================================================================== Ubuntu Security Notice USN-2933-1 March 15, 2016 exim4 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: Several security issues were fixed in Exim. Software Description: – exim4: Exim is a […]

Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2932-1 March 14, 2016 linux-lts-vivid vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: – linux-lts-vivid: Linux hardware enablement kernel from Vivid for Trusty […]

Posted by Anthony Pell    Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2931-1 March 14, 2016 linux-lts-utopic vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: – linux-lts-utopic: Linux hardware enablement […]

Posted by Anthony Pell    Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2930-2 March 14, 2016 linux-lts-wily vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: – linux-lts-wily: Linux hardware enablement […]

Posted by Anthony Pell    Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2930-1 March 14, 2016 linux vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 Summary: Several security issues were fixed in the kernel. Software Description: – linux: Linux kernel Details: Ben […]

Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2929-1 March 14, 2016 linux vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: – linux: Linux kernel Details: Ben Hawkes discovered that the […]

Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2929-2 March 14, 2016 linux-lts-trusty vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 12.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: – linux-lts-trusty: Linux hardware enablement kernel from Trusty for Precise […]

The system could be made to crash or run programs as an administrator bysomeone with physical access. ========================================================================== Ubuntu Security Notice USN-2928-1 March 14, 2016 linux vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 12.04 LTS Summary: The system could be made to crash or run programs as […]

The system could be made to crash or run programs as an administratorby someone with physical access. ========================================================================== Ubuntu Security Notice USN-2928-2 March 14, 2016 linux-ti-omap4 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 12.04 LTS Summary: The system could be made to crash or run programs as […]

Posted by Anthony Pell    graphite2 could be made to crash or run programs as your login if it openeda specially crafted font. ========================================================================== Ubuntu Security Notice USN-2927-1 March 14, 2016 graphite2 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS Summary: graphite2 could […]

Bangladesh central bank boss quits over $100m cyberheist

��}�۶��o�*��)S�E�67�X�g�����z&��s�S I��H���(�T}�v���j� �&ߓl7R�E�Fv�]�� 4��F��@?�������o���_��s��8��ĥި�1���H#AȆ�EO�G�d��~��sš^tW�:�������p�bʋ�c��Cߋ�dz�i��zZ�.�&6x`�i����CcO#�~5��j���8�’�����z����W���s�M?���Sǎ�=��;3�q?|���q�+`�`��wFB��(��,3�����Vid�l�� t<�:���ir��ө9e�s�"f%��L˟4��!�j�c6aQ�shMސ�a����w��� �c'"H<��A�L�_�M�N<&��0��N��`A�ڀ9�����d@�O?�pC `ȷ�VkB�ـ�c�D�æ�[%+��B'(���&�N�wt�:q���c2�C̅�� @�g�Ԛ��|-������uZ�f��lo7Y �C{h` ND;a�;��a��B?`a<���( �w�ڡ�t�tƎ岅�q�V�%c���m�t# ]�?� PxOP���i0R��0��o��V���Ʉ�3mA鿛-��ƴ��($ �ˏ�B���x��jA�/�?��’d4��+:�S����(&G�ސ�MF�g����T�mrJϩx��ĭ�����<�l�:G,�a�#�#������E�i�Ҍ̩釣_��4�/M��/M^��n�b��KSkh�T3o?"? -��Ҡ3`���*�j���Nu[:��^ـɛv�z{=�m�sW��<�n�&W�5�4���7�k��霆�� LNe��kˋkh

Tech giants ‘to boost encryption services’

��}�۸��o�j���Li-����3���c���[<���؎ "!�3I�2�w��;�O���!R�'H��}�����h���������ڗ]��q��|}�7��@�[njZ�[���>������]��s#�F���g 1ů�������1 Bu�h�(��U����/��co���8YP/�u�5b�.���ra���Q��Զ�q�b��4��Al׎l�h�I�mUAy��aZhGL�`�=�M@�s3��6��/�?��^�9��O-�Z���ɋ�[��s���f�s^��$���mш��V������㝽���n��|o��l�??~���q�#`�`:�{N�t�0�9,3�����f*d�,�v?�]�:���*r��ө>e�}�BfƁ�tӛS_�HјMXh�w�� i�Ρ������h9�!A����#{b��,2��1`D#�ֻ�0�#��N�9

This is Why People Fear the ‘Internet of Things’
After Apple, is WhatsApp US government’s next crypto target?
How to get started in IT security consulting
Symantec partners with hosting providers to offer free TLS certificates to website owners
Mouse movements are enough to track down Tor users
The best new security features of Windows 10

Almost every day I hear from customers or friends who are worried about security threats reported in the media. Increasingly, I find myself saying: “That’s handled by default in Windows 10.” Windows 10 contains many new security features. Last year, InfoWorld’s Fahmida Rashid provided a great overview in her article, “Why Windows 10 is the […]

Multiple vulnerabilities were discovered in the dissectors/parsers for DNP, RSL, LLRP, GSM A-bis OML, ASN 1 BER which could result in denial of service. For the oldstable distribution (wheezy), these problems have been fixed in version 1.8.2-5wheezy18. For the stable distribution (jessie), these problems have been fixed in version 1.12.1+g01b65bf-4+deb8u5. For the testing distribution (stretch), […]

Multiple vulnerabilities have been found in the Graphite font rendering engine which might result in denial of service or the execution of arbitrary code if a malformed font file is processed. For the oldstable distribution (wheezy), these problems have been fixed in version 1.3.6-1~deb7u1. For the stable distribution (jessie), these problems have been fixed in […]

Advertisements on the internet are no longer just a nuisance. They are now also potentially dangerous. Even sticking to widely used and trusted websites can be risky, as the banner ads they contain may be carrying malicious code. “Malvertising”, a combination of “malware” and “advertising”, is the technique of using trusted ad networks to deliver […]

Posted by Anthony Pell    Updated OpenStack Orchestration packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: openstack-heat security advisory Advisory ID: RHSA-2016:0442-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0442.html Issue date: […]

Posted by Anthony Pell    Updated OpenStack Orchestration packages that fix one security issue and two bugs are now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: openstack-heat bug fix and security advisory Advisory ID: RHSA-2016:0440-01 Product: Red Hat Enterprise Linux OpenStack […]

Posted by Anthony Pell    Updated OpenStack Orchestration packages that fix one security issue and two bugs are now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: openstack-heat bug fix and security advisory Advisory ID: RHSA-2016:0441-01 Product: Red Hat Enterprise Linux OpenStack […]

Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3517-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso March 14, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : exim4 CVE ID : CVE-2016-1531 A local root privilege escalation vulnerability was found in Exim, Debian’s default mail transfer agent, in configurations using the ‘perl_startup’ option (Only Exim via […]

phpMyAdmin 4.5.5.1 (2016-02-29) =============================== This releasefixes multiple XSS vulnerabilities, please see PMASA-2016-10, PMASA-2016-11, andPMASA-2016-12 for details; additionally it fixes a vulnerability allowing man-in-the-middle attack on an API call to GitHub, see PMASA-2016-13 for details.It also inclues fixes for the following bugs: – issue #11971 CREATE UNIQUEINDEX index type is not recognized by parser. – issue […]

Posted by Anthony Pell    phpMyAdmin 4.5.5.1 (2016-02-29) =============================== This releasefixes multiple XSS vulnerabilities, please see PMASA-2016-10, PMASA-2016-11, andPMASA-2016-12 for details; additionally it fixes a vulnerability allowing man-in-the-middle attack on an API call to GitHub, see PMASA-2016-13 for details.It also inclues fixes for the following bugs: – issue #11971 CREATE UNIQUEINDEX index type is not […]

This update provides recent upstream (security) release, sanitizing X11authentication credentials. ——————————————————————————– Fedora Update Notification FEDORA-2016-bb59db3c86 2016-03-13 19:43:42.937000 ——————————————————————————– Name : openssh Product : Fedora 23 Version : 7.2p2 Release : 1.fc23 URL : http://www.openssh.com/portable.html Summary : An open source implementation of SSH protocol versions 1 and 2 Description : SSH (Secure SHell) is a program […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Red Hat: 2016:0442-01: openstack-heat: Moderate Advisory Red Hat: 2016:0440-01: openstack-heat bug fix and: Moderate Advisory Red Hat: 2016:0441-01: openstack-heat bug fix and: Moderate Advisory Debian: 3517-1: exim4: Summary Fedora 22 […]

Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3516-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff March 13, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : wireshark CVE ID : CVE-2015-8731 CVE-2016-2523 CVE-2016-2530 CVE-2016-2531 CVE-2016-2532 Multiple vulnerabilities were discovered in the dissectors/parsers for DNP, RSL, LLRP, GSM A-bis OML, ASN 1 BER which could result […]

Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3515-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff March 13, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : graphite2 CVE ID : CVE-2016-1977 CVE-2016-2790 CVE-2016-2791 CVE-2016-2792 CVE-2016-2793 CVE-2016-2794 CVE-2016-2795 CVE-2016-2796 CVE-2016-2797 CVE-2016-2798 CVE-2016-2799 CVE-2016-2800 CVE-2016-2801 CVE-2016-2802 Multiple vulnerabilities have been found in the Graphite font rendering engine which might result in denial […]

Fix CVE-2016-0739 ——————————————————————————– Fedora Update Notification FEDORA-2016-dc9e8da03c 2016-03-13 09:04:20.341288 ——————————————————————————– Name : libssh Product : Fedora 22 Version : 0.7.3 Release : 1.fc22 URL : http://www.libssh.org Summary : A library implementing the SSH protocol Description : The ssh library was designed to be used by programmers needing a working SSH implementation by the mean of […]

Fix manipulating environment variables to align with how glibc handlesduplicated environment variables. Perl now uses the first variable listed in theenvironment array and it removes any subsequent entries of the same-namedvariable from the array, so that child processes have only one variable instancein its environment. ——————————————————————————– Fedora Update Notification FEDORA-2016-1fb63e3bf3 2016-03-13 09:04:20.340939 ——————————————————————————– Name : […]

Security vs convenience: The story of ransomware spread by spam email
Sun of a gun: a solar energy “Do Not Call” violator is brought to justice
Cybercrooks bilk men for 3 times as much money as women
Hacker’s typo trips the alarm on billion-dollar cyber bank heist
The security review: Android banking trojan poses as Flash Player

Welcome to this week’s security review, which includes insight into a new Android banking trojan, details on a new Mac-based ransomware, the legacy of the women of ENIAC and a profile piece on Parisa Tabriz. Android banking trojan poses as Flash Player and bypasses 2FA ESET’s Lukas Stefanko revealed that a new Android trojan, detected […]

Review: Consider VPN services for hotspot protection
Social Engineering – when charming crooks talk to helpful users [Security SOS Week]
4 reasons not to pay up in a ransomware attack
Fight, Apple, fight: Don’t let the feds kill our security

A local root privilege escalation vulnerability was found in Exim, Debian’s default mail transfer agent, in configurations using the perl_startup option (Only Exim via exim4-daemon-heavy enables Perl support). To address the vulnerability, updated Exim versions clean the complete execution environment by default, affecting Exim and subprocesses such as transports calling other programs, and thus may […]

Salt Lake City Police, Airport Websites DDoSed Against Teenager Shooting
Anti-DDoS firm Staminus hacked, private data posted online
DDoS attacks: Getting bigger and more dangerous all the time

Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix. The Common Vulnerabilities and Exposures project identifies the following issues: CVE-2015-7560 Jeremy Allison of Google, Inc. and the Samba Team discovered that Samba incorrectly handles getting and setting ACLs on a symlink path. An authenticated malicious client can use […]

A lot happens in the security world, and many stories get lost in the mix. In an effort to keep our readers informed and updated, we present the Webroot Threat Recap, highlighting 5 major security news stories of the week. Tax Season Leads to Rise in Phishing Attacks As we’ve seen in the past, corporations […]

Posted by Anthony Pell    **Version 1.1.21** – 27 February 2016. * Improvement and security fix intransforming ‘font’ element. ——————————————————————————– Fedora Update Notification FEDORA-2016-6b977c4737 2016-03-11 09:31:28.305942 ——————————————————————————– Name : php-htmLawed Product : Fedora 23 Version : 1.1.21 Release : 1.fc23 URL : http://www.bioinformatics.org/phplabware/internal_utilities/htmLawed/ Summary : PHP code to purify and filter HTML Description : PHP […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 23 php-htmLawed-1.1.21-1.fc23 Fedora 23 kernel-4.4.4-301.fc23 Fedora 23 firefox-45.0-4.fc23 Slackware: 2016-070-01: openssh: Security Update Ubuntu: 2920-1: Oxide vulnerabilities Red Hat: 2016:0430-01: xerces-c: Important Advisory Ubuntu: 2926-1: OTR vulnerability Debian: 3513-1: […]

– Update to the latest upstream – 45.0 ——————————————————————————– Fedora Update Notification FEDORA-2016-be6d3fff4a 2016-03-11 09:31:28.303965 ——————————————————————————– Name : firefox Product : Fedora 23 Version : 45.0 Release : 4.fc23 URL : https://www.mozilla.org/projects/firefox/ Summary : Mozilla Firefox Web browser Description : Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability. ——————————————————————————– […]

Posted by Anthony Pell    New openssh packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix security issues. [More Info…] [slackware-security] openssh (SSA:2016-070-01) New openssh packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix security issues. Here are the details from the Slackware 14.1 ChangeLog: […]

Several security issues were fixed in Oxide. ========================================================================== Ubuntu Security Notice USN-2920-1 March 10, 2016 oxide-qt vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS Summary: Several security issues were fixed in Oxide. Software Description: – oxide-qt: Web browser engine for Qt (QML plugin) […]

Posted by Anthony Pell    Updated xerces-c packages that fix one security issue are now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having Important security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: xerces-c security update Advisory ID: RHSA-2016:0430-01 Product: Red Hat Enterprise Linux Advisory URL: […]