Sunday, February 3, 2013

The Reg Security: Hackers squeeze through DVR hole, break into CCTV cameras [Mon Feb 4 2013]

Dear etechnews today,

Your weekly security newsletter from theregister.co.uk
for the week ending 4th February 2013

RSA Conference 2013
Feb 25 - Mar 1
San Francisco, US

RSA Conference 2013: Mastering data to secure the world. Attend Feb 25 - Mar 1 & access 275+ sessions.
http://reg.cx/1Yqb



*** Security News ***

Twitter clients stay signed in with pre-breach passwords
OAuth means apps can connect despite reset of passwords made unsafe by
breach
http://www.theregister.co.uk/2013/02/04/twitter_oauth_apps_logged_in_with_old_passwords/

Schmidt slams China as world's most prolific hacker
Google exec chairman has nothing to lose in book-based rant
http://www.theregister.co.uk/2013/02/04/google_schmidt_slams_china/

Twitter breach leaks emails, passwords of 250,000 users
Links to media site attacks suspected
http://www.theregister.co.uk/2013/02/02/twitter_breach_leaks_user_data/

Rotund Mega baron Dotcom offers bounty for breaking his crypto
Can you burst the bulging cloud locker for €10,000?
http://www.theregister.co.uk/2013/02/01/mega_crypto_break_bounty/

First the NYT, now the Wall Street Journal: But are hacking attacks
from China new?
If this is a surprise, where have you been for a decade? Mars?
http://www.theregister.co.uk/2013/02/01/wsj_blames_china_for_hack_attacks/

Filthy! old! blog! bug! blamed! for! Yahoo! webmail! hijacks!
Unpatched WordPress flaw clears way for inbox takeovers
http://www.theregister.co.uk/2013/02/01/yahoo_webmail_hijacks/

Sick software nasty uses child abuse pics to extort infected victims
Pay €100 'fine' to rid PCs of horror images
http://www.theregister.co.uk/2013/02/01/ransomware_trojan/

Symantec: Don't blame us for New York Times hack
AV giant says AV isn't enough these days...
http://www.theregister.co.uk/2013/02/01/symantec_responds_nyt_apt/

Apple blocks Java on the Mac over security concerns
Will no one rid us of this turbulent software?
http://www.theregister.co.uk/2013/02/01/apple_blocks_java_mac/

UK cookies cop changes own policy to 'implied consent'
Information Commissioner's Office says deadly threat to privacy now
well understood
http://www.theregister.co.uk/2013/02/01/ico_cookie_policy_change/

Quantum crypto still not proven, claim Cambridge experts
Thirty years of experiments still haven't proven quantum entanglement
http://www.theregister.co.uk/2013/02/01/cambridge_boffins_doubt_quantum_experiments/

'Silent but deadly' Java security update breaks legacy apps - dev
Oh man, that's foul ...
http://www.theregister.co.uk/2013/01/31/java_security_update/

'Gaia' Lovelock: Wind turbines 'may become like Easter Island statues'
Blasts Green 'fundamentalists' destroying civilisation
http://www.theregister.co.uk/2013/01/31/lovelock_wind_fu/

Report: DDoS attacks now MORE ANGRY, complex and targeted
Less like the Hulk, more like Iron Man
http://www.theregister.co.uk/2013/01/31/ddos_survey_arbor/

Great Firewall architects fingered for GitHub attack
Crude man-in-the-middle attack followed White House petition
http://www.theregister.co.uk/2013/01/31/github_ssl_man_in_the_middle_attack/

Snooping on movement can reveal smartphone PINs
Accelerometer as attack vector
http://www.theregister.co.uk/2013/01/31/smartphone_accelerometer_data_leak/

RSA adds Big Data analytics to security service suite
Finding needles in the haystack
http://www.theregister.co.uk/2013/01/31/rsa_security_analytics/

Hacker faces 105 years inside after FBI 'sexploitation' arrest
Over 350 women blackmailed into baring all
http://www.theregister.co.uk/2013/01/30/fbi_arrest_sexploitation_hacker/

Web smut sites are SAFER than search engines, declares Cisco
Network giant: Perimeters are porous, get used to it
http://www.theregister.co.uk/2013/01/30/cisco_security_report/

Muslim vid protest hackers turn web-flood hosepipe away from US banks
But Iran not behind DDoS attacks, say security bods
http://www.theregister.co.uk/2013/01/30/hackers_suspend_us_bank_attacks/

PayPal plugs SQL injection hole, tosses $3k to bug-hunter
Flaw threatened exposure of financial privates
http://www.theregister.co.uk/2013/01/30/paypal_sql_infection_flaw/

Oracle 'fesses up: Java security flaws more than storm in teacup
Remains silent on shifting crapware with its patches
http://www.theregister.co.uk/2013/01/30/oracle_java_security_analysis/

Startup decloaks, rolls out cloudy security 'conductor'
Let all make sure we're on the same hymn sheet here
http://www.theregister.co.uk/2013/01/30/netcitadel_security_policy_orcestration/

Indonesian hackers protest hacker's arrest ... by hacking
Hacker accused of defacing President's website faces 12 years inside
http://www.theregister.co.uk/2013/01/30/hacker_indonesia_sby_arrest/

Apple, Google tumble off top 20 trusted companies list
Facebook, Yahoo! also not well-trusted to protect personal information
http://www.theregister.co.uk/2013/01/30/top_20_companies_trusted_to_protect_personal_information/

UPnP scan shows 50 million network devices open to packet attack
Lock down now to avoid getting Plug and Pwned
http://www.theregister.co.uk/2013/01/29/hdmoore_upnp_flaw_rapid7/

They didn't predict that: Astrologers! blamed! after! Yahoo! hack!
When Jupiter aligns, your web app will meet a mysterious SQL stranger
http://www.theregister.co.uk/2013/01/29/yahoo_hack_analysis/

Hackers squeeze through DVR hole, break into CCTV cameras
Miscreants can copy, delete streams and even control the device
http://www.theregister.co.uk/2013/01/29/cctv_vuln/

Berners-Lee says snoop law could see spies blackmail soldiers
We know what you browsed, now hand over state secrets or we tell
http://www.theregister.co.uk/2013/01/29/tim_berners_lee_web_snoop_law_dangerous/

Google offers $3.14159 MILLION in prizes for hacking Chrome OS
Third Pwnium contest offers hackers a piece of the pie
http://www.theregister.co.uk/2013/01/29/google_third_pwnium_prizes/

Pentagon plans massive surge in Cyber Command staff
Boosting online warrior numbers from 900 to 4,900
http://www.theregister.co.uk/2013/01/29/pentagon_expands_online_war/

HP launches security service for after the horse has bolted
Security is dead, get over it
http://www.theregister.co.uk/2013/01/28/hp_security_service/

Anons hack Asteroids into US DoJ website in Swartz death protest
And more than a gigabyte of 'state secrets' in leak threat
http://www.theregister.co.uk/2013/01/28/anon_doj_hack_swartz_protest/

Spammers joyride Doctor Who's Twitter TARDIS, turn man into Shirley
Temple
Won't someone please think of the children poor celebs?
http://www.theregister.co.uk/2013/01/28/doctor_who_twit_jacked/

Pop tix touts slung in the cooler for 4 years after £3m web scam
Fans tricked into buying tickets that never existed
http://www.theregister.co.uk/2013/01/28/ticket_touts_jailed/

Patch often: Cyber-crim toolkits love stinky old gaping holes
Updating software is better than relying on AV - shock finding
http://www.theregister.co.uk/2013/01/28/exploit_kits_mine_old_vulns/



------------------------------------------------------------------------

This email was sent to garn14.tech@blogger.com

To change your email or your email subscriptions

http://account.theregister.co.uk/login/

To unsubscribe from all The Register newsletters

http://account.theregister.co.uk/unsubscribe/649203/acc978a1

The Register and its contents are Copyright © 2013 Situation Publishing.
All rights reserved.

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.