Wednesday, April 30, 2014

Google Debuts Dedicated Productivity Apps For iOS

Google has released standalone apps for Google Docs and Google Sheets, breaking out these two productivity applications from within Google Drive, which is where users could go to access them on iPhone and iPad in the past

4chan admits it suffered hack attack

has admitted that it suffered a security breach last week that saw a hacker gain unauthorized access to user information.

Google Stops Mining Education Gmail And Google Apps Accounts For Ad Targeting

The move comes after Google’s use of data from its education products came under fire by students and others during a court case last year that claimed the scanning violated user privacy rights.

Tuesday, April 29, 2014

Firefox 29 and Thunderbird 24.5

Mozilla has released critical updates for Firefox and Thunderbird.

AOL asks users to change passwords

"At AOL, we care deeply about the safety and security of your online experience. We are writing to notify you that AOL is investigating a security incident that involved unauthorized access to AOL's network and systems"

Microsoft releases critical patch for Adobe Flash

Microsoft has released an emergency patch for Flash.  Update your Windows using Check for Updates.

Captain Kirk get NASA's highest honor

This weekend, the acclaimed actor and director was honored with NASA’s Distinguished Public Service medal, the highest award bestowed by the agency to non-government personnel.

Critical Patch for Adobe Flash

Adobe has released security updates for Adobe Flash Player 13.0.0.182 and earlier versions for Windows, Adobe Flash Player 13.0.0.201 and earlier versions for Macintosh and Adobe Flash Player 11.2.202.350 and earlier versions for Linux. These updates address vulnerabilities that could potentially allow an attacker to take control of the affected system.

Sunday, April 27, 2014

Heartbleed Health Report

The number of devices still at risk is harrowing: HP printers, Polycom video conferencing systems, WatchGuard firewalls, VMWare systems, and Synology storage servers. Weaver counts tens of thousands of users of the Parallels Plesk Panel web hosting control panel that are vulnerable too — those could become a prime target of hackers looking to take control of websites.

Hacker claim of bug in fixed OpenSSL likely a scam

Hackers claim to have found a new vulnerability and are selling it for 2.5 bitcoins, or $870

Hackers targeting newly discovered flaw in Microsoft Internet Explorer

Hackers are already at work exploiting a newly discovered flaw in Microsoft’s Internet Explorer that has left more than half of the world’s Web browsers vulnerable to attack, including those on many federal government computers.

New Internet Explorer 0-Day in the Wild

The bad guys are using a new vulnerability to exploit Windows.  Use Firefox or Chrome until it is patched.

Thursday, April 24, 2014

Report: Google to end forced G+ integration, drastically cut division resources

The report states that Google+ will no longer be considered a product that competes with Facebook and Twitter, and that Google's mission to force Google+ into every product will end.

OpenSSL and others funded through Core Infrastructure Initiative

Cisco, Dell, Facebook, Fujitsu, Google, IBM, Intel, Microsoft, NetApp, Rackspace, and VMware have all pledged to commit at least $100,000 a year for at least three years

Wednesday, April 23, 2014

Inside the ‘DarkMarket’ Prototype, a Silk Road the FBI Can Never Seize

If DarkMarket’s distributed architecture works, law enforcement would be forced to go after every contraband buyer and seller one by one, a notion that could signal a new round in the cat-and-mouse game of illicit online sales.

FCC may endorse pay-for-play deals

ISPs could charge for improved access as long as they don't block Web services.

 

 

Heartbleed Puts 150 Million Android App Downloads at Risk

According to FireEye, Android apps can often bypass the operating system's libraries for cryptography and use their own native OpenSSL libraries, which may not have been patched

ARIN Is Down To the Last /8 of IPv4 Addresses

and as such ARIN is no longer able to receive additional IPv4 resources from the IANA

You Can Now Run Beta Versions of OS X—For Free

Until Tuesday, Apple charged users $99 a year to test out new OS X software—doing so required a paid-up developer account.

Apple releases patches for OS X and Safari

All OS X users should check for updates using Software update to patch the operating system and Safari.

Tuesday, April 22, 2014

DSL router patch merely hides backdoor instead of closing it

Researcher finds secret “knock” opens admin for some Linksys, Netgear routers.

AOL email hacked: Several users complain about compromised accounts

If you get an email from an "@aol.com" account that looks suspicious and contains a link, do not click on it.

iOS 7.1.1 released

iOS 7.1.1, labeled as build 11D201, offers additional improvements to Apple's Touch ID, fixes a bug that impacts keyboard responsiveness, and fixes a bug involving Bluetooth keyboards with VoiceOver enabled.

Apple Security Update 2014-002

"Apple today released Security Update 2014–002 for Mavericks, Mountain Lion, and Lion users."  All OS X users should use Software Update to check for patches.

LibreSSL Project Announced

In the wake of Heartbleed, OpenBSD group is creating a simpler, cleaner version of the dominant OpenSSL.

Microsoft OneDrive for Business modifies files as it syncs

However, unlike the consumer version of OneDrive, we found out by accident that what gets synced to the cloud is generally not the same as what gets synced back from the cloud, even when no one has touched the files online or elsewhere.

Monday, April 21, 2014

Netflix is about to get more expensive

The price hike coincides with a controversial “interconnection” deal in which Netflix agreed to pay Comcast for better Internet service delivery.

Netflix officially comes out against the Comcast-TWC merger

Netflix on Monday also officially took a stance against the proposed $45 billion merger of Comcast and Time Warner Cable.

Oracle Gives Heartbleed Update, Patches 14 Products

The purpose of this document is to list Oracle products that depend on OpenSSL and to document their current status with respect to the OpenSSL versions that were reported as vulnerable to the publicly disclosed ‘heartbleed’ vulnerability CVE-2014-0160.

Active malware campaign steals Apple passwords from jailbroken iPhones

Security researchers have uncovered an active malware campaign in the wild that steals the Apple ID credentials from jailbroken iPhones and iPads.

Sunday, April 20, 2014

'Heartbleed' Exploit Forces Healthcare.gov to Reset User Passwords

However, we're resetting current passwords out of an abundance of caution, to ensure the protection of your information

3 Million Cards Impacted in Michaels Breach

Michaels confirmed yesterday that most of its U.S. stores were compromised on and off for eight months and that payment card information of nearly three million of its customers may have been impacted

Thursday, April 17, 2014

Nasty Heartbleed bug exposes OpenVPN private keys

Wednesday's confirmation means any OpenVPN server—and likely servers using any other VPN application that may rely on OpenSSL—should follow the multistep path for recovering from Heartbleed

Google App Lets You Control Your Computer From Your Phone

The new software will let you control your Mac or PC from any Android device.

Google develops computer vision accurate enough to solve its own CAPTCHAs

The new system was developed to help Google automatically analyze hard-to-read signs and house numbers photographed by its Street View cameras, allowing it to accurately match images with locations on a map.

Wednesday, April 16, 2014

Heartbleed hacker arrested

A 19-year-old student has been arrested for allegedly exploiting the Heartbleed vulnerability to steal taxpayer data from as many as 900 Canadians, authorities said Wednesday.

Microsoft Security Essentials Update Makes Windows XP Unusable

There are plenty of users out there who are still running Windows XP, even though Microsoft no longer provides updates and security patches for this particular OS version, but many are running the freeware Security Essentials in an attempt to protect their data.

Critical Oracle Patches released

Oracle has released a swathe of security updates culminating in a massive 104 new security fixes for products including Java, Fusion Middleware, and MySQL.

HD Manufacturer LaCie Admits Yearlong Data Breach

The announcement warns that anyone who purchased an external hard drive or any form of LaCie hardware off of the company’s website during that time period may have had their data stolen.

Tuesday, April 15, 2014

Microsoft confirms it's dropping Windows 8.1 support

Microsoft TechNet blog makes clear that Windows 8.1 will not be patched; users must get Windows 8.1 Update if they want security patches

Monday, April 14, 2014

First sites admit data loss through Heartbleed attacks

Canada’s tax authority and a popular British parenting website both lost user data after attackers exploited the Heartbleed SSL vulnerability, they said Monday.

Sunday, April 13, 2014

Reverse Heartbleed Testing

Client using the vulnerable version of OpenSSL are subject to information leakage.  Most browsers are unaffected.

Wednesday, April 9, 2014

Adobe Patches Flash Player

All users should upgrade, details at Adobe.

Tuesday, April 8, 2014

April 2014 Patch Tuesday

Microsoft has released a smaller amount of patches this month, two of them critical (office/IE).

Windows XP support has ended

Any flaws discovered from now on—and it's inevitable that some will be discovered—will never be publicly patched.

OpenSSL Vulnerability "HeartBleed"

The Heartbleed bug allows anyone on the Internet to read the memory of the systems protected by the vulnerable versions of the OpenSSL software. This compromises the secret keys used to identify the service providers and to encrypt the traffic, the names and passwords of the users and the actual content.  You can check your own sites.   UTC does not appear to be vulnerable.

Sunday, April 6, 2014

Graphene battery research by Samsung experiences breakthrough in manufacturing process

However, the reason we haven’t seen devices using graphene yet is due to difficulties in the implementation of the delicate processes involved in building graphene layers on a large manufacturing scale.

6TB HDD

Seagate sub LaCie has pre-announced a 6TB near line disk drive from its parent and it doesn't appear to use the slow write shingled magnetic recording technology.

The #1 paid app in the Google Playstore "Virus Shield" is a complete scam

Android Police has discovered that all the app does is change a red "X" graphic to a red "check" graphic.

HTTPS Strict Transport Protocol (HSTS) in Internet Explorer 12

Browsers supporting HSTS force any sessions sent over HTTP to be sent instead over HTTPS, encrypting communication to and from a website.

Microsoft products to block "adware"

New objective criteria drafted up by the company stipulates that by July 1 internet ads must have a visible close button and must clearly state who’s behind them, or they’ll be branded as adware.

Powershell Malware

Most significantly, instead of creating or including executable code, CRIGENT uses the Windows PowerShell to carry out its routines. PowerShell is a powerful interactive shell/scripting tool that is available for all current versions of Windows

Saturday, April 5, 2014

Microsoft's Security Products Will Block Adware By Default Starting On July 1

As of July 1, the company's security products will immediately stop any adware they detect and notify the user, who can then restore the program if they wish. Currently, when any of Microsoft's security products (including Microsoft Security Essentials and Microsoft Forefront) detects a program as adware, it will alert the user and offer them a recommended action

Wednesday, April 2, 2014

Threshold Revealed: Microsoft Talks the Future of Windows

Microsoft on Wednesday confirmed my previous reports that it would ship a Windows update that brings back the Start menu as an option and lets users run Modern apps on the Windows desktop in floating windows.

NASA must immediately cease contact with Russia

that this move comes less than a month after NASA administrator Charles Bolden assured the public that the situation in Ukraine's Crimean peninsula wouldn't disrupt space cooperation between the United States and Russia

Hackers Turn Security Camera DVRs Into Worst Bitcoin Miners Ever

But it also tries to earn a little scratch for its creators by mining bitcoins, a processor-intensive activity that would probably slow down any infected DVR.

Windows 8.1 Update 1 Review

Update 1 matters, and is the clearest indication yet that Microsoft remains committed to listening to feedback and writing the wrongs of the original release of Windows 8.

Tuesday, April 1, 2014

Boxee.tv hacked.

Hackers posted names, e-mail addresses, message histories, and partially protected login credentials for more than 158,000 forum users of Boxee.tv, the Web-based television service that was acquired by Samsung last year, researchers said.