2018年12月7日 星期五

Trello: How To Be Your Most Productive Self: Let Go Of Being Perfect

Perfectionism-final-2.0
We live in an era of overachievement, and in this era flaunting those achievements (we’re looking at you, social media) is totally the norm.
REF: https://blog.trello.com/productive-not-perfectionism

2018年12月6日 星期四

TrendLabs: A Look into the Connection Between XLoader and FakeSpy, and Their Possible Ties With the Yanbian Gang

Figure 1. Monthly infection count for XLoader and FakeSpy attacks this year
Figure 1. Monthly infection count for XLoader and FakeSpy attacks this year
REF: https://blog.trendmicro.com/trendlabs-security-intelligence/a-look-into-the-connection-between-xloader-and-fakespy-and-their-possible-ties-with-the-yanbian-gang/

2018年12月5日 星期三

Announcing CrossOver 18.1.0

CrossOver 18.1 supports Visio 2016 on Linux.

For macOS users, CrossOver 18.1 contains a number of important bug fixes. We have resolved a bug which prevented game downloads and the Steam Store page from working on the latest Steam release. CrossOver 18.1 also addresses an issue some macOS users experienced running recent versions of Quicken on CrossOver 18. Those who experienced crashes or launch failures when using Quicken 2016-2018 should see full functionality on CrossOver 18.1.

Finally, CrossOver 18.1 restores controller support for Steam on both macOS and Linux.

REF: https://www.codeweavers.com/support/forums/announce/?t=24;mhl=212141;msg=212141#msg212141

2018年12月4日 星期二

Trello: That Stress You Feel? It’s A ‘Mental Load’ Of Invisible Work That Needs Talking About

feminists call out the mental load as an expectation placed on women in gender-conforming households
Source: The gender wars of household chores: a feminist comic
REF: https://blog.trello.com/mental-load-invisible-work-stress

2018年12月3日 星期一

[USN-3830-1] OpenJDK regression

---------- Forwarded message ---------
From: Steve Beattie
Date: 2018年11月28日 週三 下午5:16

USN-3804-1 fixed vulnerabilities in OpenJDK. Unfortunately, that update
introduced a regression when validating JAR files that prevented Java
applications from finding classes in some situations. This update
fixes the problem.

We apologize for the inconvenience.

References:
  https://usn.ubuntu.com/usn/usn-3830-1
  https://usn.ubuntu.com/usn/usn-3804-1
  https://launchpad.net/bugs/1800792

2018年12月2日 星期日

TrendLabs: Trickbot Shows Off New Trick: Password Grabber Module

Figure 6. Trickbot’s shareDll32 module allows it to connect to a C&C server to download a copy of itself
REF: https://blog.trendmicro.com/trendlabs-security-intelligence/trickbot-shows-off-new-trick-password-grabber-module/

2018年12月1日 星期六

[USN-3817-1] Python vulnerabilities

---------- Forwarded message ---------
From: Marc Deslauriers
Date: 2018年11月14日 週三 上午1:03

Summary:

Several security issues were fixed in Python.

Software Description:
- python2.7: An interactive high-level object-oriented language
- python3.5: An interactive high-level object-oriented language
- python3.4: An interactive high-level object-oriented language

Details:

It was discovered that Python incorrectly handled large amounts of data. A
remote attacker could use this issue to cause Python to crash, resulting in
a denial of service, or possibly execute arbitrary code. This issue only
affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2018-1000030)

It was discovered that Python incorrectly handled running external commands
in the shutil module. A remote attacker could use this issue to cause
Python to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2018-1000802)

It was discovered that Python incorrectly used regular expressions
vulnerable to catastrophic backtracking. A remote attacker could possibly
use this issue to cause a denial of service. This issue only affected
Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2018-1060, CVE-2018-1061)

It was discovered that Python failed to initialize Expat's hash salt. A
remote attacker could possibly use this issue to cause hash collisions,
leading to a denial of service. (CVE-2018-14647)

References:
  https://usn.ubuntu.com/usn/usn-3817-1
  CVE-2018-1000030, CVE-2018-1000802, CVE-2018-1060, CVE-2018-1061,
  CVE-2018-14647