by Peter Bright from Ars Technica - All content on (#JF58)
Starting with the 1988 Morris Worm, this flaw has bitten everyone from Linux to Windows.
|
Story
Some PDFs from Blackhat 2015Similar News
by LXer from LinuxQuestions.org on (#JF4S)
Published at LXer: Oracle's chief security officer, Mary Ann Davidson, recently ticked off almost everyone in the security business. She proclaimed that you had to do security "expertise in-house...
|
by Jessica Elgot from World news | The Guardian on (#JE5S)
Woman drank contents of bottle after being told she could not carry it in her hand luggage, only to be prevented from flying because she was too drunkA Chinese woman reportedly downed a full bottle of £120 cognac at security control after she was told she was not allowed to take liquids on board her flight – which she was then prevented from boarding.The woman, who has been named only as Zhao, was deemed too drunk to fly by staff at Beijing Capital international airport when she collapsed shortly after drinking the bottle of Rémy Martin XO Excellence. Continue reading...
CentOS has updated httpd (C6:denial of service) and nss (C5: two vulnerabilities).Oracle has updated httpd (OL7; OL6:denial of service), mariadb (OL7: multipleunspecified vulnerabilities), and nss (OL5:two vulnerabilities).Red Hat has updated httpd (RHEL7; RHEL6:HTTP request smuggling), httpd24-httpd(RHSCL2: multiple vulnerabilities), libunwind (RHELOSP6: buffer overflow), mariadb (RHEL7: multiple vulnerabilities), nss (RHEL5: two vulnerabilities), openstack-neutron (RHELOSP6: denial ofservice), openstack-swift (RHELOSP6;RHELOSP5: arbitrary object deletion),python-django (RHELOSP6; RHELOSP5: denial of service), python-django-horizon (RHELOSP6: cross-sitescripting), python-keystoneclient (RHELOSP6; RHELOSP5:two vulnerabilities), qemu-kvm-rhev (RHELOSP6; RHELOSP5:information leak), redis (RHELOSP6: codeexecution), and thunderbird (RHEL5,6,7: multiple vulnerabilities).Scientific Linux has updated httpd (SL7; SL6:denial of service), mariadb (SL7: multiplevulnerabilities), nss (SL5: twovulnerabilities), and thunderbird (SL5,6,7:multiple vulnerabilities).Ubuntu has updated thunderbird(15.04, 14.04, 12.04: multiple vulnerabilities).
by Natasha Lomas from Crunch Hype on (#JDV3)
Butterfleye is a hardware startup aiming to build a connected home security camera that avoids coming across as creepily prying. Read More
|
by Oliver Holmes in Bangkok from World news | The Guardian on (#JCKW)
Thailand police use ‘imagination’ to ‘connect the dots’ in search for prime suspect who set off a bomb which killed 20 and injured 120Police in Thailand say they have used their “imagination†to piece together the movements of the prime suspect in a bomb attack at a shrine last week that killed 20 people because most of the security cameras on the getaway route were broken.Related: Bangkok explosion: fatal blast at Erawan shrine Continue reading...
from heise online News on (#JD6G)
Hacker-Attacken auf Industrie-IT, das Design und die Bewertung sicherer Software-Architekturen sowie das Spannungsfeld zwischen funktionaler Sicherheit und IT-Sicherheit sind drei der zentralen Themen auf dem diesjährigen Bremer IT-Sicherheitstag.
|
by Megan Geuss from Ars Technica - All content on (#JBCT)
Court says Wyndham hotels practices could be considered “unfair†and “deceptive.â€
|
Debian-LTS has updated extplorer (cross-site scripting), roundup (multiple vulnerabilities), and wesnoth-1.8 (information leak).Mageia has updated libcryptopp(MG4,5: information disclosure), mediawiki(MG4,5: multiple vulnerabilities), openssh(MG4,5: multiple vulnerabilities), php (MG5; MG4:multiple vulnerabilities), and x11-server(MG5: permission bypass).openSUSE has updated wireshark(13.2: multiple vulnerabilities) and xfsprogs (13.2, 13.1: information disclosure).Red Hat has updated rh-ruby22-ruby (RHSCL2: DNS hijacking).Slackware has updated gnutls (denial of service).SUSE has updated glibc(SLE11SP3,4: multiple vulnerabilities) and kvm (SLE11SP2: two vulnerabilities).
by Ian Traynor in Brussels from World news | The Guardian on (#JA1V)
Berlin in particular is determined to draw up mandatory quotas for refugees and is warning of reintroducing national border controlsGermany and France are to launch a drive for more concerted European immigration and security policies following the foiled attack on an Amsterdam-Paris high-speed train and with Europe reeling under the strain of the biggest migration emergency since the end of the second world war.
from on (#J9WD)
Thailand's police chief says blast probe hindered by broken security cameras in Bangkok
|
by Cory Doctorow from on (#J866)
|
by LXer from LinuxQuestions.org on (#J995)
Published at LXer: During the LinuxCon and CloudOpen events that took place last week in Seattle, North America, Linux Foundation's Core Infrastructure Initiative announced that they are developing...
|
by Reuters in Gevgelija from World news | The Guardian on (#J6YA)
Riot police remain but fail to slow passage of migrants crossing from Greece on way through Balkans to western EuropeHundreds of migrants have crossed unhindered from Greece into Macedonia after overwhelmed security forces appeared to abandon a bid to stem their flow through the Balkans to western Europe following days of chaos and confrontation.
by Jared Malsin in Cairo from World news | The Guardian on (#J61T)
With journalists and activists jailed and a new terrorism law in effect, a culture of fear is growing in EgyptThe blast shook buildings for miles around. Sleeping residents awoke, called each other, then stared at glowing screens, seeking an explanation for the explosion and the sirens wailing in the distance.Last Thursday a massive car bomb had detonated outside a security building in Shubra Al-Khaima, a working-class district on Cairo’s northern edge. Chunks of concrete had been blasted off the building, shards of glass were sprinkled across the pavement. The windows of the neighbouring apartment building had been blown out, the private spaces of the families within flung open to the street. Continue reading...
by Yael Grauer from Feed: All Latest on (#J4TD)
Shockingly, none of this news is about cheating spouses! The post Security News This Week: Police Use Mobile Cell Phone Trackers to Avoid Court Orders appeared first on WIRED.
|
by Sam Thielman from Technology | The Guardian on (#J4RG)
A Microsoft product called Yammer was open to anyone who’d ever been a contractor or an employee at the Department of Veterans AffairsA chat network used by staff at the Department of Veterans Affairs (VA) was a major security risk and open to anyone who had ever been a contractor or an employee at the VA, an internal investigation found.According to the VA’s Office of the Inspector General the chat software, a Microsoft product called Yammer, “did not have an administrator or system set in place to ensure removal of former VA or contractor employeesâ€. Only an administrator could remove an employee from the system, so everyone who had ever logged maintained access to the service.
by Cory Doctorow from on (#J2QT)
|
Fedora has updated pure-ftpd(F21: denial of service).Red Hat has updated openshift(RHOSE3: privilege escalation).SUSE has updated xen (SLE11SP1: two vulnerabilities).Ubuntu has updated subversion(15.04, 14.04, 12.04: multiple vulnerabilities) and firefox (15.04, 14.04, 12.04: regression inprevious update).
Thanks to a string of theater-related tragedies, going to the theater is about to become as enjoyable as going to the airport.
|
by Ben Jacobs in Washington from World news | The Guardian on (#J0VB)
Democratic hopeful will lay out goal of ensuring within two terms of office that 50% of Americans have enough retirement savingsRelated: O'Malley accuses Democratic party of 'stacking the deck' in Clinton's favorThe Democratic presidential hopeful Martin O’Malley is to unveil a detailed plan to expand social security on Friday.
by LXer from LinuxQuestions.org on (#J05V)
Published at LXer: VIDEO: The head of the Linux Foundation's security program details a new initiative to help projects develop and to identify secure best practices. Read More......
|
You had one job, US Investigations Services… The US Department of Justice (DoJ) will pocket $30m (£19.14m) from the company tasked with screening, among others, whistleblower Edward Snowden.…
|
by Angelique Chrisafis in Calais from World news | The Guardian on (#HZKV)
People in New Jungle camp say Theresa May’s attempts to tackle crisis at French port will not deter those fleeing war from trying to reach UKAs rain lashed the flimsy, makeshift tents in the Calais migrant camp known as the New Jungle, the word had gone round that a British minister was in town.Among the people waiting to attempt to stow away on lorries to England after dark, some had hoped that the home secretary, Theresa May, would announce a radical change of heart. Continue reading...
by Cory Doctorow from on (#HZKB)
-Bruce Sterling
|
from Techreport on (#HZC7)
Silent Circle is releasing a new version of its Blackphone, creatively named Blackphone 2. The device runs a security-oriented version of Android called Silent OS, which packed with features intended to make businesses' data more secure. ...Read more...
Debian has updated conntrack (denial of service), openjdk-6 (multiple vulnerabilities), vlc (code execution), and zendframework (XML External Entity attack).Debian-LTS has updated conntrack (denial of service).Fedora has updated mariadb (F22:multiple vulnerabilities).Red Hat has updated mariadb55-mariadb (RHSCL2: multiplevulnerabilities) and rh-mariadb100-mariadb(RHSCL2: multiple vulnerabilities).SUSE has updated kvm (SLE11SP1: code execution).
Google says multitasking app flap is overstated Yet another potentially serious security flaw has been revealed in Android.…
|
by Ron Miller from Crunch Hype on (#HYTE)
AppInside, a tool designed to help app developers check for security vulnerabilities, announced a $2.3 million seed round from Boston’s Accomplice today.When a company commissions an app, they are putting their brand’s reputation on the line when people download it to their tablet or smartphone, Elon Ohevya, co-founder and CEO of AppInside told TechCrunch.Mobile devices… Read More
|
from on (#HYR8)
A B.C. man with a titanium hip wasn’t allowed to board his plane when an all-female security team refused to frisk him.
|
from on (#HYN5)
Massive car bomb claimed by IS strikes Cairo security building at night, wounds 29
|
by Guardian Staff from World news | The Guardian on (#HXWC)
Egyptian civilians and security forces gather at the site of the car bomb that exploded near a security building in Cairo on Thursday morning, injuring at least six people. The bomb was detonated near a security services building in the Shubra Al-Khaima area and is the latest in a series of violent attacks in Egypt Continue reading...
by Reuters from World news | The Guardian on (#HX8R)
United States Investigations Services strikes deal with justice department after claims it took shortcuts when vetting federal employeesUnited States Investigations Services Inc, the private firm that vetted former National Security Agency contractor Edward Snowden, has agreed to a settlement worth at least $30m, resolving US claims connected to its background investigations.
by LXer from LinuxQuestions.org on (#HX79)
Published at LXer: The founder of Linux explains why he's not thinking about the next 10 years of Linux and why security is all about finding bugs. Read More......
|
by Jared Malsin in Cairo from World news | The Guardian on (#HX4F)
Blast happened close to state security building in Egyptian capital in the early hours of Thursday morning, wounding six police officersA car bomb exploded near a security building in Cairo early on Thursday morning Egypt’s interior ministry has said, in the latest of a series of violent attacks that have shaken the capital in recent months.The blast happened close to the national security agency building in Shubra Al-Khaima, a neighbourhood on the northern edge of the Egyptian capital. Continue reading...
by LXer from LinuxQuestions.org on (#HWVD)
Published at LXer: The Linux Foundation's Core Infrastructure Initiative is reaching out to the community to help determine which open-source projects practice good security methods. Read...
|
by LXer from LinuxQuestions.org on (#HWNH)
Published at LXer: The second day of LinuxCon in Seattle started with an announcement by Linux Foundation Executive Director Jim Zemlin about the Core Infrastructure Initiative. The CII will have a...
|
by Sam Thielman from Technology | The Guardian on (#HWF2)
Brian Krebs says public shaming culture could put lives at risk after the release of personal information from the infidelity websiteTop data security analyst Brian Krebs has warned that people could take their lives after their personal details were exposed in a hack of infidelity website Ashley Madison.“We have to be very cautious and I think sensitive to this,†Krebs, who broke the initial story, said. “There’s a very real chance that people are going to overreact. I wouldn’t be surprised if we saw people taking their lives because of this, and obviously piling on with ridicule and trying to out people is not gonna help the situation.†Continue reading...