Menu

Latest articles

What IP/URL Based Threat Intelligence Can and Can’t do for the IoT
Some notes on VirusTotal
Female PC gamers and Online Security
Threat Recap: Week of January 31st
Threat Intelligence: An Overview
Top Browser Plugins to Increase Browsing Security and Privacy
Threat Recap: Week of January 24th
Worst Passwords of 2015, Best Passwords of 2016
Are adblocker blockers really THAT bad? [Chet Chat Podcast 231]
Selfie + money + Snapchat = robbed! Don’t flash your cash…
Follower: the “creepiest social network” that follows you in real life
Stung by stingrays: NYPD reveals over 1000 cellphone interceptions
Android inventor wants to give out free dashcams… in exchange for your data
Secret Facebook groups being used by pedophiles to swap obscene images
Monday review – the hot 26 stories of the week
Are adblocker blockers really THAT bad? [Chet Chat Podcast 231]
Selfie + money + Snapchat = robbed! Don’t flash your cash…
Follower: the “creepiest social network” that follows you in real life
Stung by stingrays: NYPD reveals over 1000 cellphone interceptions
Android inventor wants to give out free dashcams… in exchange for your data
Please vote for Naked Security in the 2016 Security Blogger Awards!
Secret Facebook groups being used by pedophiles to swap obscene images
Monday review – the hot 26 stories of the week

APPLE-SA-2016-01-25-1 tvOS 9.1.1 Subject: APPLE-SA-2016-01-25-1 tvOS 9.1.1 From: Apple Product Security Date: Mon, 25 Jan 2016 11:36:06 -0800 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-01-25-1 tvOS 9.1.1 tvOS 9.1.1 is now available and addresses the following: Disk Images Available for: Apple TV (4th generation) Impact: A local user may be able to execute arbitrary code […]

APPLE-SA-2016-01-19-3 Safari 9.0.3 Subject: APPLE-SA-2016-01-19-3 Safari 9.0.3 From: Apple Product Security Date: Tue, 19 Jan 2016 15:48:17 -0800 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-01-19-3 Safari 9.0.3 Safari 9.0.3 is now available and addresses the following: WebKit Available for: OS X Mavericks v10.9.5, OS X Yosemite v10.10.5, OS X El Capitan v10.11 to v10.11.2 Impact: […]

APPLE-SA-2016-01-19-2 OS X El Capitan 10.11.3 and Security Update 2016-001 Subject: APPLE-SA-2016-01-19-2 OS X El Capitan 10.11.3 and Security Update 2016-001 From: Apple Product Security Date: Tue, 19 Jan 2016 15:46:58 -0800 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-01-19-2 OS X El Capitan 10.11.3 and Security Update 2016-001 OS X El Capitan 10.11.3 and Security […]

APPLE-SA-2016-01-19-1 iOS 9.2.1 Subject: APPLE-SA-2016-01-19-1 iOS 9.2.1 From: Apple Product Security Date: Tue, 19 Jan 2016 15:43:37 -0800 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-01-19-1 iOS 9.2.1 iOS 9.2.1 is now available and addresses the following: Disk Images Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later Impact: […]

APPLE-SA-2016-01-07-1 QuickTime 7.7.9 Subject: APPLE-SA-2016-01-07-1 QuickTime 7.7.9 From: Apple Product Security Date: Thu, 07 Jan 2016 17:40:44 -0800 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-01-07-1 QuickTime 7.7.9 [Re-sending with a valid signature] QuickTime 7.7.9 is now available and addresses the following: QuickTime Available for: Windows 7 and Windows Vista Impact: Viewing a maliciously crafted movie […]

APPLE-SA-2016-01-07-1 QuickTime 7.7.9 Subject: APPLE-SA-2016-01-07-1 QuickTime 7.7.9 From: Apple Product Security Date: Thu, 07 Jan 2016 16:07:02 -0800 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-01-07-1 QuickTime 7.7.9 QuickTime 7.7.9 is now available and addresses the following: QuickTime Available for: Windows 7 and Windows Vista Impact: Viewing a maliciously crafted movie file may lead to an […]

Holger Fuhrmannek discovered that missing input sanitising in the Graphite font rendering engine could result in the execution of arbitrary code. For the oldstable distribution (wheezy), this problem has been fixed in version 38.6.1esr-1~deb7u1. For the stable distribution (jessie), this problem has been fixed in version 38.6.1esr-1~deb8u1. For the unstable distribution (sid), this problem has […]

Several vulnerabilities have been found in PostgreSQL-9.4, a SQL database system. CVE-2016-0766 A privilege escalation vulnerability for users of PL/Java was discovered. Certain custom configuration settings (GUCs) for PL/Java will now be modifiable only by the database superuser to mitigate this issue. CVE-2016-0773 Tom Lane and Greg Stark discovered a flaw in the way PostgreSQL […]

Several vulnerabilities have been found in PostgreSQL-9.1, a SQL database system. CVE-2015-5288 Josh Kupershmidt discovered a vulnerability in the crypt() function in the pgCrypto extension. Certain invalid salt arguments can cause the server to crash or to disclose a few bytes of server memory. CVE-2016-0766 A privilege escalation vulnerability for users of PL/Java was discovered. […]

Daniel Genkin, Lev Pachmanov, Itamar Pipman and Eran Tromer discovered that the ECDH secret decryption keys in applications using the libgcrypt20 library could be leaked via a side-channel attack. See https://www.cs.tau.ac.IL/~tromer/ecdh/ for details. For the stable distribution (jessie), this problem has been fixed in version 1.6.3-2+deb8u1. For the unstable distribution (sid), this problem has been […]

Several vulnerabilities were discovered in the resolver in nginx, a small, powerful, scalable web/proxy server, leading to denial of service or, potentially, to arbitrary code execution. These only affect nginx if the resolver directive is used in a configuration file. For the oldstable distribution (wheezy), these problems have been fixed in version 1.2.1-2.2+wheezy4. For the […]

Two vulnerabilities were discovered in wordpress, a web blogging tool. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2016-2221 Shailesh Suthar discovered an open redirection vulnerability. CVE-2016-2222 Ronni Skansing discovered a server-side request forgery (SSRF) vulnerability. For the oldstable distribution (wheezy), these problems have been fixed in version 3.6.1+dfsg-1~deb7u10. For the stable distribution […]

Several vulnerabilities were discovered in qemu, a full virtualization solution on x86 hardware. CVE-2015-7295 Jason Wang of Red Hat Inc. discovered that the Virtual Network Device support is vulnerable to denial-of-service, that could occur when receiving large packets. CVE-2015-7504 Qinghao Tang of Qihoo 360 Inc. and Ling Liu of Qihoo 360 Inc. discovered that the […]

Several vulnerabilities were discovered in qemu-kvm, a full virtualization solution on x86 hardware. CVE-2015-7295 Jason Wang of Red Hat Inc. discovered that the Virtual Network Device support is vulnerable to denial-of-service (via resource exhaustion), that could occur when receiving large packets. CVE-2015-7504 Qinghao Tang of Qihoo 360 Inc. and Ling Liu of Qihoo 360 Inc. […]

Several vulnerabilities were discovered in qemu, a full virtualization solution on x86 hardware. CVE-2015-7295 Jason Wang of Red Hat Inc. discovered that the Virtual Network Device support is vulnerable to denial-of-service (via resource exhaustion), that could occur when receiving large packets. CVE-2015-7504 Qinghao Tang of Qihoo 360 Inc. and Ling Liu of Qihoo 360 Inc. […]

It was discovered that polarssl, a library providing SSL and TLS support, contained two heap-based buffer overflows that could allow a remote attacker to trigger denial of service (via application crash) or arbitrary code execution. For the oldstable distribution (wheezy), these problems have been fixed in version 1.2.9-1~deb7u6. For the stable distribution (jessie), these problems […]

U.S. Encryption Ban Would Force Companies To Migrate, Say Researchers
Source: tomsHardware – Posted by Anthony Pell    Harvard researchers Bruce Schneier and Saranya Vijayakumar teamed up with independent researcher [...]
Teenage alleged hacker ‘Cracka’ arrested by UK police for CIA, FBI data breaches
Source: ZDNet Security – Posted by Anthony Pell    A 16-year-old has been arrested on suspicion of being “Cracka,” the hacker believed to [...]
Monitor Server Logs in Real-Time with “Log.io” Tool
Posted by Alex    Log.io is a small simple but effective application build on top of Node.js and Socket.io, which allows to monitor Linux servers log files [...]
Gmail to warn you if your friends aren’t using secure e-mail
Source: arsTechnica – Posted by Anthony Pell    Google has confirmed a number of changes to Gmail with the arrival of two new features that will let [...]
Are adblocker blockers really THAT bad? [Chet Chat Podcast 231]
Latest Intelligence for January 2016
Support scams: What do I do now?

Note: This blog article expands on some of the content that originally appeared in a lengthy article on support scams for ITSecurity UK, and subsequently in an article for the ESET Threat Report for December 2015. I’m returning to the theme of what to do if a scammer actually gets a foothold on your system, […]

Selfie + money + Snapchat = robbed! Don’t flash your cash…
Follower: the “creepiest social network” that follows you in real life
Stung by stingrays: NYPD reveals over 1000 cellphone interceptions
US hospital hit with ’random’ ransomware attack

��}��8��o;���’,�-R��R}Y��e�w���u�* ��H��R�1�qq���”� ��d��2�)J%�d��Ξi�”�D”��H$�w��:9����dz����~0��q�;�i��:Ո��}�Ӽ��D��hxcߘ���ՠέF��-x��=����:�ۗ=��s#�F���g�_=-bWQ�쁣�z�Ǭ1�Wu��K��|/���3ۊ&=�]�C��ub�vdSG��a=������C;b�%�=Dh�����zA�u^��X�������k��c���U�ixIۢ3�������A��Q��=i����f��?���q��#�-`�`:�{A��0�;,�0������0�ȔY6�i~`��u����f3c��lv47�޴1�u�T#��)�Ck�t���E�����:9��!A����#{j��,2�� `D’�޿� �#��:%/��:dbG��?��u-o �Bo:�#4����ACT��R�b�0���0=ʀ�.o�C�”�qH�R�.yd;Μ�ᐅ!,�~����0b�:�%3�.��|�hrj�� A�bw8�n�E� ��fC5���O9�E�iv�V��kġ�tHj�Jz֢.Zl�H��� �s�v���� h8p>j�ñ�t��fE�ƾ�Q+L�����7:�^l���J�B�E ]�GCXJ�a��5���3�|泩��>eQd����Gm@C�(�#��_�6Bcfx���’I�kc�����kc�u����5h ��;��C�}Ԡ3`���*�rB����ݡ[����u��`g�Ç����2�O���[wF�(.UZԇ���obUi��%� Ne���ɍ�8�u�Z�� �1���|ݻ���j-K�,�w�e�@����êe`�ǀ�Hs���P����[�y�e�9��{�Ŋ ��i6�������bս��^���=0[��_�7��Z}hD�џ��14̟`0���S�� x���:��1�W��’�q�qz)��>��X/i���/�W��߫�0�e=��.>�A�,xX]|Wՠe�J{�YZ}�c�괤,��FJ���BU�s�����±#.X��� �NE:=9Ų��b�j@f�!����S}d(���Us�kG#Cj�{�FF4��U,’���C���j��BW�-o#�ԗ�j� �V}�q)Tm�o��1��é�y�����۷,;�:?��%�܁�q�n�^`��&�>�P��?�~ V��j��-+Ķzχ%���a ��@� k���s���`�� q��{�ꃹ��o�S��Em��+bx+��V�b���G^Xp��� 6`Bn��{׾�t�%i�h�.��fטKߎ�F4v���2����.��o�z��BLQD�7��~����~2fwd�e�#�t,`����Y��*}udx^F�w�:CS�|Ű3LGԅ��w�;D��Y07�U��ػw��>8� ��6����L/���h��`wx�`�^�n�,����]|�P���f:5��{�(��M�k���,��%8 CW�ZԿmd��D-�{9 [x9�9�Y��z���m�X���:^ptw���SMO�yQ)�+���2q4�’��H��r�i�*�l��y�է�8��$�s����2 xύ�ϻ��|v����V�K%lL�KPj�GF��m��~�M4`m���4�iy� T�_-�-ls���nƽ�7�j�����l5]���˿d�N��Z ���1a��pʢ�g�T���O����!@5�Am�7��� P’b�K�����r�߬�5ݦ8Tg��F��ȡ�6�si�T�’���1���������ԁO�^t�7���e4��Y�Ό�Uh�߃8pqb��p�8w��P�j�܍��|A�GÉh�T��=y9����BЫu>| =�88��ᅮ��G޾��*�T��[��΢��6X��MX�࡫H��#��A�+C�1���+�H��0V���”��/�>��x�(��m�K���0�_z3@�� z�F^��J��� ����~N�o+Բ^�W�yfU�b����v�VV�”��Vy�F��b���9�؀hK5�>;���I6��;��z��{:&�g��L��0 |��i�,��_:x4>;p^�d�Ã��O���G��1���N��D.o��`LI���N��bٗ��G=��y^��`��P�3�`���b�D9/�� {��ϟYUV#� �IPy�ր���`[��d`m%����ݫ�`���{0=�Б�e�hkྔ/e�pp?�3 ��nxJZ�߇�R�V;Vx�o����yA]XJ���@(1�b�EDLD�SQ��ԃ��׳��O�z�B��v�Y͔���,u|i���v@oMl˂y�Z4��Ł�խzXw�v������;�>�XGS&� �}w�e3���Z�?��ju��#^� L���VqN���{��P���s�W���h�WV��9�T������=߰��vemFH��}����3E}�����N�B�^�ƪ��O]k)�� A�:4{�̥���?侠@�� �� ��}��8��o;���’,�-R��R}Y��e�w���u�* ��H��R�1�qq���”� ��d��2�)J%�d��Ξi�”�D”��H$�w��:9����dz����~0��q�;�i��:Ո��}�Ӽ��D��hxcߘ���ՠέF��-x��=����:�ۗ=��s#�F���g�_=-bWQ�쁣�z�Ǭ1�Wu��K��|/���3ۊ&=�]�C��ub�vdSG��a=������C;b�%�=Dh�����zA�u^��X�������k��c���U�ixIۢ3�������A��Q��=i����f��?���q��#�-`�`:�{A��0�;,�0������0�ȔY6�i~`��u����f3c��lv47�޴1�u�T#��)�Ck�t���E�����:9��!A����#{j��,2�� `D’�޿� �#��:%/��:dbG��?��u-o �Bo:�#4����ACT��R�b�0���0=ʀ�.o�C�”�qH�R�.yd;Μ�ᐅ!,�~����0b�:�%3�.��|�hrj�� A�bw8�n�E� ��fC5���O9�E�iv�V��kġ�tHj�Jz֢.Zl�H��� �s�v���� h8p>j�ñ�t��fE�ƾ�Q+L�����7:�^l���J�B�E ]�GCXJ�a��5���3�|泩��>eQd����Gm@C�(�#��_�6Bcfx���’I�kc�����kc�u����5h ��;��C�}Ԡ3`���*�rB����ݡ[����u��`g�Ç����2�O���[wF�(.UZԇ���obUi��%� Ne���ɍ�8�u�Z�� �1���|ݻ���j-K�,�w�e�@����êe`�ǀ�Hs���P����[�y�e�9��{�Ŋ […]

Android inventor wants to give out free dashcams… in exchange for your data
Please vote for Naked Security in the 2016 Security Blogger Awards!
Secret Facebook groups being used by pedophiles to swap obscene images
The security review: Remtasu and Facebook cheat sheet

From an outbreak of malicious spyware to the UK’s bill on investigatory powers, here’s our comprehensive breakdown of cybersecurity news from the past week. Remtasu is disguised in Facebook hacking tool ESET’s Camilo Gutierrez Amaya reported how Remtasu, a well-known piece of spyware, which first surfaced almost four years ago, is now appearing in disguise […]

Monday review – the hot 26 stories of the week

Discovered: February 16, 2016 Updated: February 16, 2016 1:29:48 AM Type: Trojan Systems Affected: Windows 7, Windows Vista, Windows XP Infostealer.Banprox.B is a Trojan horse that may steal information from the compromised computer. Antivirus Protection Dates Initial Rapid Release version February 15, 2016 revision 034 Latest Rapid Release version February 15, 2016 revision 034 Initial […]

Discovered: February 15, 2016 Updated: February 15, 2016 5:40:48 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Backdoor.Contopee is a Trojan horse that opens a back door on the compromised computer. It may […]

Holger Fuhrmannek discovered that missing input sanitising in the Graphite font rendering engine could result in the execution of arbitrary code. For the oldstable distribution (wheezy), this problem has been fixed in version 38.6.1esr-1~deb7u1. For the stable distribution (jessie), this problem has been fixed in version 38.6.1esr-1~deb8u1. For the unstable distribution (sid), this problem has […]

Risk High Date Discovered November 10, 2015 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted webpage. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause […]

Risk High Date Discovered November 10, 2015 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted webpage. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause […]

Risk Medium Date Discovered November 10, 2015 Description Microsoft Windows is prone to a remote denial-of-service vulnerability. An attacker can exploit this issue to cause the system to become non-responsive, resulting in a denial-of-service condition. Recommendations Block external access at the network boundary, unless external parties require service. If global access isn’t needed, filter access […]

Risk Medium Date Discovered November 10, 2015 Description Microsoft Windows is prone to a security-bypass vulnerability. Successfully exploiting this issue may allow attackers to perform unauthorized actions by conducting a man-in-the-middle attack. This may lead to other attacks. Recommendations Block external access at the network boundary, unless external parties require service. If global access isn’t […]

Risk High Date Discovered November 10, 2015 Description Microsoft Windows is prone to a remote code-execution vulnerability. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial-of-service conditions. Technologies Affected Microsoft Windows 7 for 32-bit Systems SP1 Microsoft Windows […]

Risk High Date Discovered November 10, 2015 Description Microsoft .NET Framework is prone to a security-bypass vulnerability. An attacker can leverage this issue to bypass certain security restrictions and execute arbitrary code by exploiting another vulnerability in the application. Technologies Affected Microsoft .NET Framework 2.0 SP2 Microsoft .NET Framework 3.5 Microsoft .NET Framework 3.5.1 Microsoft […]

Risk Medium Date Discovered November 10, 2015 Description Microsoft .NET Framework is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the […]

Risk Medium Date Discovered November 10, 2015 Description The Microsoft .NET Framework is prone to a remote information-disclosure vulnerability. Attackers can exploit this issue to gain access to sensitive information that may aid in further attacks. Technologies Affected Microsoft .NET Framework 2.0 SP2 Microsoft .NET Framework 3.5 Microsoft .NET Framework 3.5.1 Microsoft .NET Framework 4.0 […]

Risk Medium Date Discovered November 10, 2015 Description Microsoft Windows is prone to a local privilege-escalation vulnerability. A local attacker can exploit this issue to gain elevated privileges on a targeted system. Technologies Affected Microsoft Windows 10 for 32-bit Systems Microsoft Windows 10 for x64-based Systems Microsoft Windows 10 version 1511 for 32-bit Systems Microsoft […]

Risk High Date Discovered November 10, 2015 Description Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted webpage. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks […]

Several vulnerabilities have been found in PostgreSQL-9.4, a SQL database system. CVE-2016-0766 A privilege escalation vulnerability for users of PL/Java was discovered. Certain custom configuration settings (GUCs) for PL/Java will now be modifiable only by the database superuser to mitigate this issue. CVE-2016-0773 Tom Lane and Greg Stark discovered a flaw in the way PostgreSQL […]

Several vulnerabilities have been found in PostgreSQL-9.1, a SQL database system. CVE-2015-5288 Josh Kupershmidt discovered a vulnerability in the crypt() function in the pgCrypto extension. Certain invalid salt arguments can cause the server to crash or to disclose a few bytes of server memory. CVE-2016-0766 A privilege escalation vulnerability for users of PL/Java was discovered. […]

Calls from the UK to make ‘malicious data breaches’ a criminal offence

��}��Ȳ�o��w(� d�l�n�6��å��=�a;d�l��%��v{“�;�{#vb#� v�����I��sI#j%��u˟6g�&�j�:�Q�3hM֐�`�:��������$�� v��o�&3’�F4�i��b’v���t݈�Bʾ���}25/(��?�c D�?���$Ð�քF����X!�L���,��!ޖ m����;�-�}]o �H4��ޮ�1-�m�#��4�� /�;�,KL�&gԚx����|��1������L�����ƫ�2z�V�i��RTK.4쌖�DÞhiO����D�Q�.����GA��G�sTե��a�X.]ZLf��1ò�D�I�J��Q��}�”&��%�r*P��+8�(6�R�UWփ���%���$C��h��*�F�h��f�ό�Q�u�׽�m�V���6������ h8�N7��L�1]�’$͞�o�Q�&���R���x��`,���i��p�k�Q$� LEm���6��W��_�JC����xc��ICy�Q�΀��J�P���+��,7����{�*k`P�N�”�� #����O���[wF��4a�lV�c��5���������KQ�jhUu�z��[���`���ݓՔ��ԏC’!��w��G����5[�”�5a��( (����J:���F�5����7���”��^?�c|�hJW�T0[��ң�ꛈl%;6�ت�=���� 5�UJZ�� ��}2q�f�?a���!’����1r��B64̞`0���Q�� x�Ӌ�t޿c�Qe M뢟1N�����ft�”{����6.(�A�Cݴ���N�MÇ��w5Z���@��4ƍ;F�aV�E#�ÈC�8�� �����v��.�a�`�遆kHȃ�b’A��yON�,v�ܯ:�d�K����钰?������H�޽���c ˉ_�������U ۷���UG ���j�� ���˾�mg:�Z4u:o���x��D�kΏ`A��L���8�^Ї0���&�Y�r�EЪ�:��x�N����=� �ϏH����GPz1.�4�M�PHk�pxơ�xv>�P���?�~���K�W�*q��0���Ϙj|�dU _��kO�|΂��o��!���5~������sů��U��UŪ^UIs�����wי4�_ /�4�YO �0!7��w����R���c��?���k̅�ɦ#3q���2M���y���PS��� ��n�i�v3�v���h�e�#�4,�Q���Y��*}ud�~š�;��f يag��LϚ�������0G������mu�wè`���p�;�����0a4���Z�х�ϼ�ݡ�C� ��&��tj�� U�2#zO7�Ǚ��Kp�.G�hp[�+�KǴ῍��H��ˡo�I���(l��w��x�� t��ã���O6=e�ZZ-����2u4ߧ��J��r����A�^��jSg�Ɩ�`�v�B��g�ʼn�_8�=�EJ��� 7�R66�KPj�Gj��m��~�M4am���4���$��(�H[�m�R�q_�5�.�|�o8�tY�K�Z���K���(�܍�:,��c��������(*���`�P�C�j|���o>��A0ݘ����O�C3�������ԅO�]tm�ק������ڥA�H����C]C�f����]��FU�Ds/6�&`�2��0�?T�$��pѧ��@i�@:r�G��O�5=���wR����w�c^���|���?����FC}��(��R���a�u�bA�8Lh�H�W�M`j�r��- 6Ņ��ؖ_�|��2$*�[.o[ﲪ���ܗ�MuX�?�#?�5l�A�s�E�?��� �&��*,�_9W�}f� �{�A���>�a�9Tq?�k�H��ȼ}W.��f�u� �x@�qû��D#���/~=p�c��$}�PQ�’`����R}%uϠOCa ��r$4R6���z�X����WXB�����1č�(��(B��CͣQbs<�Uؐ{��58�={��z�䯧/��n����8�U�RǗN����ım�_`�y�E.Y�Y�nD ���?�޺����q�.#�q<գ�c��۸���V�?s�� �N�#V� � L��WqN�����аݾ{�����9���C�ح��#U=~��^�i���G��mum9FHZ�s�v�G˙�1bQ_p�f|!a�P�R��g/�P!(��kFQ_�y�%n���/(�`r�w��f��*R�P�G��3���e��D�н������C4��E�UT�.qW|e%g��$k�`��Ob-���M�ߐ7�C��i?#�

Risk High Date Discovered November 10, 2015 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted webpage. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause […]

Risk High Date Discovered November 10, 2015 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted webpage. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause […]

Risk High Date Discovered November 10, 2015 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted webpage. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause […]

Risk High Date Discovered November 10, 2015 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted webpage. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause […]

Risk High Date Discovered November 10, 2015 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted webpage. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause […]

Risk High Date Discovered November 10, 2015 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted webpage. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause […]

Risk High Date Discovered November 10, 2015 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted webpage. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause […]

Risk High Date Discovered November 10, 2015 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted webpage. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause […]

Risk High Date Discovered November 10, 2015 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted webpage. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause […]

Risk High Date Discovered November 10, 2015 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted webpage. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause […]

Discovered: February 12, 2016 Updated: February 12, 2016 7:53:04 PM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Backdoor.Fimlis is a Trojan horse that opens a back door on the compromised computer and downloads potentially malicious files. […]

UK business decision makers see cyberattacks as their great nemesis

More and more business decision makers in the UK consider cyberattacks to be the greatest threat to their enterprise, according to a new study. The Risk:Value report by NTT Com Security reveals that approximately one fifth of respondents see cybercrime as the number one threat to their organization. Business decision makers also now anticipate the […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 22 nodejs-is-my-json-valid-2.12.4-1.fc22 Fedora 22 python-pymongo-2.5.2-8.fc22 Fedora 23 python-pymongo-2.5.2-8.fc23 Slackware: 2016-042-01: mozilla-firefox: Security Update Ubuntu: 2893-1: Firefox vulnerability Debian: 3473-1: nginx: Summary Ubuntu: 2894-1: PostgreSQL vulnerabilities Fedora 22 php-PHPMailer-5.2.14-1.fc22 Community […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 22 nodejs-is-my-json-valid-2.12.4-1.fc22 Fedora 22 python-pymongo-2.5.2-8.fc22 Fedora 23 python-pymongo-2.5.2-8.fc23 Slackware: 2016-042-01: mozilla-firefox: Security Update Ubuntu: 2893-1: Firefox vulnerability Debian: 3473-1: nginx: Summary Ubuntu: 2894-1: PostgreSQL vulnerabilities Fedora 22 php-PHPMailer-5.2.14-1.fc22 Community […]

Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS   Advisories Fedora 22 nodejs-is-my-json-valid-2.12.4-1.fc22 Fedora 22 python-pymongo-2.5.2-8.fc22 Fedora 23 python-pymongo-2.5.2-8.fc23 Slackware: 2016-042-01: mozilla-firefox: Security Update Ubuntu: 2893-1: Firefox vulnerability Debian: 3473-1: nginx: Summary Ubuntu: 2894-1: PostgreSQL vulnerabilities Fedora 22 php-PHPMailer-5.2.14-1.fc22 Community […]

Posted by Anthony Pell    Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3473-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso February 11, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : nginx CVE ID : CVE-2016-0742 CVE-2016-0746 CVE-2016-0747 Debian Bug : 812806 Several vulnerabilities were discovered in the resolver in nginx, a small, powerful, scalable web/proxy server, leading to denial […]

Daniel Genkin, Lev Pachmanov, Itamar Pipman and Eran Tromer discovered that the ECDH secret decryption keys in applications using the libgcrypt20 library could be leaked via a side-channel attack. See https://www.cs.tau.ac.IL/~tromer/ecdh/ for details. For the stable distribution (jessie), this problem has been fixed in version 1.6.3-2+deb8u1. For the unstable distribution (sid), this problem has been […]

Several vulnerabilities were discovered in the resolver in nginx, a small, powerful, scalable web/proxy server, leading to denial of service or, potentially, to arbitrary code execution. These only affect nginx if the resolver directive is used in a configuration file. For the oldstable distribution (wheezy), these problems have been fixed in version 1.2.1-2.2+wheezy4. For the […]

Risk Medium Date Discovered February 9, 2016 Description Microsoft Windows is prone to a multiple local privilege-escalation vulnerabilities. A local attacker can leverage these issues to execute arbitrary code with elevated privileges. Recommendations Permit local access for trusted individuals only. Where possible, use restricted environments and restricted shells. Ensure that only trusted users have local, […]

Risk High Date Discovered February 9, 2016 Description Microsoft Edge is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause […]

Risk High Date Discovered February 9, 2016 Description Microsoft Edge is prone to a security-bypass vulnerability. An attacker can leverage this issue to bypass certain security restrictions and execute arbitrary code by exploiting another vulnerability in the application. Technologies Affected Microsoft Edge Microsoft Windows 10 for 32-bit Systems Microsoft Windows 10 for x64-based Systems Microsoft […]

Risk Medium Date Discovered February 9, 2016 Description Microsoft .NET Framework is prone to a remote denial-of-service vulnerability. An attacker can exploit this issue to degrade the server performance, causing a denial-of-service condition. Given the nature of this issue, attackers may also be able to execute arbitrary code, but this has not been confirmed. Technologies […]

Risk Medium Date Discovered February 9, 2016 Description The Microsoft .NET Framework is prone to an information-disclosure vulnerability. Attackers can exploit this issue to gain access to sensitive information that may aid in further attacks. Recommendations Block external access at the network boundary, unless external parties require service. If global access isn’t needed, filter access […]

Risk Medium Date Discovered February 9, 2016 Description Microsoft Windows is prone to a local privilege-escalation vulnerability. A local attacker can exploit this issue to execute arbitrary code in kernel mode with elevated privileges. Recommendations Permit local access for trusted individuals only. Where possible, use restricted environments and restricted shells. To exploit this vulnerability, an […]

Risk Medium Date Discovered February 9, 2016 Description Microsoft Windows is prone to a local privilege-escalation vulnerability. A local attacker can exploit this issue to execute arbitrary code with elevated privileges. Failed exploit attempts will result in a denial of service condition. Recommendations Permit local access for trusted individuals only. Where possible, use restricted environments […]