Jakub Palaczynski discovered that websvn, a web viewer for Subversion repositories, does not correctly sanitize user-supplied input, which allows a remote user to run reflected cross-site scripting attacks. For the oldstable distribution (wheezy), this problem has been fixed in version 2.3.3-1.1+deb7u2. For the stable distribution (jessie), this problem has been fixed in version 2.3.3-1.2+deb8u1. We […]
lighttpd, a small webserver, is vulnerable to the POODLE attack via the use of SSLv3. This protocol is now disabled by default. For the oldstable distribution (wheezy), this problem has been fixed in version 1.4.31-4+deb7u4. We recommend that you upgrade your lighttpd packages.
ESET researchers have found 343 malicious porn clicker trojans, which ESET detects as Android/Clicker, on Google Play over the last seven months – and their numbers keep rising. In one of the largest malware campaigns on the Google Play Store yet, criminals continue to upload further variants of these malicious apps to the official app store […]
Malicious porn clickers are mostly fake versions of popular games with very similar names and icons to legitimate applications. For instance, there were more than 30 bogus Subway Surfers and more than 60 fake GTA applications. These apps have nothing in common with the official Subway Surfers or GTA games. The trojans were mostly devoid […]
Discovered: February 23, 2016 Updated: February 24, 2016 12:22:47 PM Type: Trojan Infection Length: 82,444 bytes Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Backdoor.Rifelku is a Trojan horse that opens a back door on the compromised computer. Antivirus […]
Aris Adamantiadis discovered that libssh, a tiny C SSH library, incorrectly generated a short ephemeral secret for the diffie-hellman-group1 and diffie-hellman-group14 key exchange methods. The resulting secret is 128 bits long, instead of the recommended sizes of 1024 and 2048 bits respectively. This flaw could allow an eavesdropper with enough resources to decrypt or intercept […]
Andreas Schneider reported that libssh2, a SSH2 client-side library, passes the number of bytes to a function that expects number of bits during the SSHv2 handshake when libssh2 is to get a suitable value for group order in the Diffie-Hellman negotiation. This weakens significantly the handshake security, potentially allowing an eavesdropper with enough resources to […]
Cyber threats come from a wide array of sources, but can be grouped into three categories: HacktivistsThese are tech-savvy individuals who are normally motivated by morality. These individuals are also classed by many (including the FBI) as terrorists. One of the main hactivist groups out there is anonymous. This group rose from one of the […]
��}��8��o;����,�-R��R}Y��ew�wl����{gݾ H�$VQ$͏R�ݎ�w�?�w�qO��&�$� �$HQ*I%{���Ǔ���yN~8{����G�h�������S����=��I�G��7�)k��} ��y4a��߁’��єE����ؾ�i’�17���>��P��i�����pB��E�8�i�������ě�4�� �����,_եS�Ӯl6� RJ�l+��,ve��ԉ�ڑM=R���2Hc�;L��W,�G����E��m�{��q�y�zfQf�^�/o���___[��˲��ul�F�h� ؓ�����’�n�g���v�Ms�仓�ݧO̶�E�����% ����h�p� �K��P#Sfٴ����� tO�Cj��wU�Z,��~a�~e����7s�$d�v��Z�d��K�P� ��@�����ވ�!TG8���_�g�P��k��P �-Ck��H ���R�zC�j��F��h�h��:PIG�q��A��$�9l�C�W(��s����Q^�i�C�–����|d�A��w �q�(�~�!F�;G�ȓ�%�INe��u��Et�T͓A����_�qz�f�#�T��c���AU�h#Y�fKo����Q�y����fr�qᏕք����” i`)���tJ�������K�ށP/��|����-%�7������T�D���3F#/��8Y6�_$��U��W4 ����Tf��Oܨ��*PG�խ����[��уꯪֲ��q�8pX��v�3��jX�)��5���:�p�#�M� �aFh�^�G�b�z �ᎍQ�MO��=�,V��k�u�{��UO���z�ެՇF�=���՚�0wM�m֮�wa��$��^����F�U�[���͚’}�|W��3?�4e+h*��v����k���k����k�LlǪk��Q}��c ��!��>�4̟`0���S��x�㫟�wτ_>�P���e/e���`�%�6�E� ���Gu���]�����W�ŗv�͂���wU Z�k���2a̪�ߵ��!5##���*���ju�!K�j��U���7��G�KtW 5��`�>W���(�i�w������vؼ�r@���;������L���8S7�/�@G�����Ze_’�O�#b�i�_Y��k��i��_�J/�E��� �Mc�8�b�*��^�!|��ǻ��M]tT��a��V����`�1�t��Z!bIRY{zs� �!��}�qB}0�U�c`깸t�Eo%ފ�V�G+��~OPU��`�������G�ȋnדDX^E�����K��[��j�ST��m0��n’��7����h��7]X����Y��*}qdx^�C��;t9� �ag����V�zw�^��Y07�U���{p��>8� ��6����L/���h��`wx�`�^�n�,���8�� u��o�S3x���W�4��y3��^��0t�@�FV}KԂ��s/G a/�5’Q@”냴�Cϱ����7�]�������:/*��b��b�fZ&��E”Z��]$�3M�U�g�Oۮ>����(�@Fo�(�I�7.N<��f���9�;Prh�� m��1��@�1� ����s�!�7 Ѐ�!�b��0<�q�%+P�K�dO �eL��o�w��ſ�0T�EdM,e����O5X�%�c��v?�j���Y��SM�d�N������ ]B�(�Y�H��4��.��0?���D�[` ^�”��x�(uo���m�K����s_{3@x`������U��: 3��Q�(����8�T�V`��ƾf��R’s���T6A�#���_o�d�إ_UI�+z���zM���U�%��@�y�GRU���H=��zT�I�(t�+�[���&g��s*�&0ݟ�^H=��ۮc��E’J�rn���’�+q����q(���S’�) ƶ�G�_�������V/�������D�cC���,��E�L�C��Rk�&�`�A�x0’t�c~�.0*�3�?i��3Hܩ3�Z�0�La&b��Bq�M�M�aM^d��?����٣��g�¡�bY�(^��p7}�X�ؙf�X�L�)�?�Wk�ܝy�[�ʙ�:���F�79�����ȁ�@o�vz’F8a,��`��a�e!���?à�ɠ��i��G{��-‘�~�d8�z�m�������o�o�9a:�SL</頾�A�h�B�ϧ��e�̈��`0J�#�k����~�}p��XX`�&w[L����f!�L]2
Most parents think carefully about when to give their children their first set of house keys, or let them go out to play with no adult supervision. Yet in our digitalized world, the same caution should be exercised in the virtual world, such as on social networks or when giving children their first smart gadgets. […]
Nowadays, the internet and technology have become so important for business, travel and many other everyday tasks that they practically surround us all the time. This is true for the younger generation as well, including even the smallest children, but online surveys by ESET show that a majority of parents in Russia, the United Kingdom, […]
Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-1622 It was discovered that a maliciously crafted extension could bypass the Same Origin Policy. CVE-2016-1623 Mariusz Mlynski discovered a way to bypass the Same Origin Policy. CVE-2016-1624 lukezli discovered a buffer overflow issue in the Brotli library. CVE-2016-1625 Jann Horn discovered a way to […]
A new form of ransomware has hit the scene, and although this one has a playful nickname it is no fun at all. The bad news is that “Locky” ransomware will encrypt virtually every commonly used file-type and targets not only local drives, but any networked drives it can find, even if they are unmapped. […]
I hope you weren’t one of the hundreds of people who downloaded a compromised version of the Linux Mint operating system on Saturday. Because if you were, it’s possible that you’re not just running one of the more user-friendly flavours of Linux on your computer but also playing host to a Linux ELF trojan called […]
Welcome to this week’s security review, which includes a detailed report from ESET on the state of information security in companies in the EMEA region, helpful advice on support scams and the rise of Android ransomware. The state of information security in companies in the EMEA region For this extensive report, ESET spoke to 1,700 […]
Alexander Izmailov discovered that didiwiki, a wiki implementation, failed to correctly validate user-supplied input, thus allowing a malicious user to access any part of the filesystem. For the oldstable distribution (wheezy), this problem has been fixed in version 0.5-11+deb7u1. For the stable distribution (jessie), this problem has been fixed in version 0.5-11+deb8u1. For the testing […]
Stepan Golosunov discovered that xdelta3, a diff utility which works with binary files, is affected by a buffer overflow vulnerability within the main_get_appheader function, which may lead to the execution of arbitrary code. For the oldstable distribution (wheezy), this problem has been fixed in version 3.0.0.dfsg-1+deb7u1. For the stable distribution (jessie), this problem has been […]
Gustavo Grieco discovered an out-of-bounds write vulnerability in cpio, a tool for creating and extracting cpio archive files, leading to a denial of service (application crash). For the oldstable distribution (wheezy), this problem has been fixed in version 2.11+dfsg-0.1+deb7u2. For the stable distribution (jessie), this problem has been fixed in version 2.11+dfsg-4.1+deb8u1. For the unstable […]
A lot happens in the security world, some big and some small, and many stories get lost in the mix. In an effort to keep our readers informed and updated, we present the Webroot Threat Recap, highlighting 5 major security news stories of the week. Samsung Smart TV’s, Too Smart? Recently, it has come to […]
��}ے�8�������)QR�n�|�ryڳvۧ��{��T@”$��”i^J�v;b�a�6��}߈��?�/�L$A�RI*�/��� $yC”������:���=��s#�F���g�_=-b7Q�쁣�zu�c֘嫺t�zڵ�f�DJ�mE��Ů�!��:�];����C갞Yi�yc��1���”��@�����~ �� �:oZ/,��ѷ�٫�;��M��o�����UY��:�E#f4M�����A��Y��=i���n�iy!#��P�W�n�7��nG��>�Б�uC�z.Ș�oZM��h��ac�ө��>M��@�HR�� �s�v<�z�X̽@�//��=t���� ��]����%�G��gc1*���؏���&șl���d�QD�J�g1t̍R�v�'Vք����;}K{~<��`�-)����%�֖-�:�@�<�R՛R�]��K*���LnF#/����%4��= Rpv��NcQd����Gm@C�=�#��?5Bcfx��’M�Sc����Sc�u����5h ��;�!0|ȴ��t�/�B-‘�OHQ�:��-]�����p�;c ����s��-c_�����`��Vi}P�>&��U����4 ����Tf�gI���V�[��1fw�o�G��_U�ei��Eq�=����8���i�2��s@ ����ku(�!�%�C��8aFX�^�G�b�z�K86F�7=7�ijXuo���u�V=}n����z�V��F���^Wk���q4�Y�v��}��ޓ��z=�� 9�P�f�����52}��V;z`~Ji�V�T [�xh��G�Rq��UY/|>?��oA%�N���jP�g�u2��:�}�G�1B�}������=�a��a��D*�N��’@���7��y� �|<��3�ë^*8��j�&�K�1l���B����8 � �jY�����v�͂���wU Z����`I�����f�NKʢ��߁�P"��p�U5���s �����.����V���U��Y�V�}� [U��a�2R_b�jh�4�X�ęVq2oO�_����u��”�߳��w��S�d�8|�n�^`��&0�X�r�� h�}�0{��*�F�10��3g��”�[I�[�s� �h�4�� ��߶;���:3��`��ŀw�Ib�F��w�kOwPKP�v�v��Gyv��YlDc’J�ݡ�����k�g�*�U@�yL}���)���`vG�!z&�M��`(�ή��/����ϋ�(��n��Xk ��v�鈺�9h�����`n$���5���A����*�ac/��o)���(�Nv���� ���&Ϣ�ݡс�|P�P���n65��{�U�M�k���,��%8 GW�ZԿod0�C1 UϽ��-�x֜D����g=���l�X���:^p�p���S]O5xQ)�+’���2 4.�J4�2��i�J?�/|�v�=p�J��]�P��ܹ8�+�a8�g,@ɡQ�(��W”�Ժ��`|d4N�’��u����@憠�kL��Ƒ��@��ؒ�8�1�%ޅk}���l�&�Ț��VӉ�_j0�Kea�a��`��íU��E��(j�`�P�C�f|���oƂ�*���=�����F��o�|�b��|wvFZF��d�*0q�B�;�m!�����xl�| ��D�nDo&��r���h�T��*��SFj�4~ 9���#ɜ��+���{��ϵcQ���|k8���Fc� �A��Ԥ�� ]B�(�Y�h��4 �.��0>�W�D�k ^�2��x�( o���o��V ��~�Y�偙�s6�V�V�$�0Wh�G����pR}_���;�9��J�T�=�yx�nt�hV$q?ժ�!O�g��,��n�� m�4��w?�FR�?O�zbO�D�Iz���x�O �=M#�zZ���� “��PZ��=(�Q����Gt���ޙ0(���h�4 |�q�=,���h�0ޡ��+� �p���` a���K.�J!�z>eUX���3/$A�eD>6J�m�rR���ZW �oF���3�E�#����8�}�ʾ!s?��d@J7
An anonymous contributor working with VeriSign iDefense Labs discovered that libreoffice, a full-featured office productivity suite, did not correctly handle Lotus WordPro files. This would enable an attacker to crash the program, or execute arbitrary code, by supplying a specially crafted LWP file. For the oldstable distribution (wheezy), these problems have been fixed in version […]
Parts 1 and 2 of this series provided an overview of Threat Intelligence and hopefully offered some understanding as to what role it can play in helping secure an IoT infrastructure. For those familiar with cyber security and how to implement Threat Intelligence in traditional network appliances the jump to securing an IoT Gateway is […]
A new ransomware has been discovered and what sets apart this variant from the rest is its implementation of a chat interface embedded into the product. That link for “Live Chat” will prompt the window for live support. The window should look like this and will allow you to talk directly with the cyber criminal. […]
As 2015 slides into the cybersecurity history books as “the year of the healthcare breach” I decided to examine one aspect of medical data privacy that is sometimes overlooked: the impact of breaches on patient-doctor information exchange. Specifically, I’m concerned that high profile healthcare-related IT security breaches may lead more people to withhold sensitive information […]
