Monday, October 28, 2013

The Reg Security: Apple accused over 'secure' iMessage encryption [ Mon Oct 28 2013]

Dear etechnews today,

Your weekly security newsletter from theregister.co.uk
for the week ending 28th October 2013


RSA Conference 2014
Feb. 24-28
San Francisco

Attend RSA Conference 2014 Feb 24-28 in San Francisco and access over 280+ sessions.
Register by Nov.15 and save $700.

http://reg.cx/28bW





*** Security News ***

IBM warns Storwize arrays can DELETE ALL DATA
Web interface authentication hole allows anyone to log in and drive the
array
http://www.theregister.co.uk/2013/10/28/ibm_storwize_arrays_at_risk_of_complete_deletion/

NSA.gov goes down after 'error during scheduled update'
Spook agency denies DDOS, blames sysadmins
http://www.theregister.co.uk/2013/10/28/nsagov_goes_down_after_error_during_scheduled_update/

PHP.net resets passwords after malware-flinging HACK FLAP
Revokes SSL cert as Java vuln find prompts slash-and-burn recovery
http://www.theregister.co.uk/2013/10/25/phpnet_compromise_analysis/

Irish privacy boss hauled to court for NOT probing Facebook for spook
links
'Do something' about PRISM data-slurping, says privacy crusader
http://www.theregister.co.uk/2013/10/25/irish_data_protection_commissioner_faces_possible_court_action_over_alleged_facebook_prism_data_harvesting/

Why Bletchley Park could never happen today
Can you keep a secret? No, course you can't
http://www.theregister.co.uk/2013/10/25/feature_bletchley_could_not_happen_today/

Biz bods, politicos, beware: 'BOTS are on the loose, and they're coming
for YOU
UK, US, Canada and India all report Mevade infections
http://www.theregister.co.uk/2013/10/25/mevade_apt_spreading_like_weeds_across_3_continents/

Norks seed online games with malware in fiendish DDoS plot
Seoul police believe country's love of gaming will be turned upon
itself
http://www.theregister.co.uk/2013/10/25/norks_malware_ddos_south_korea/

Naughty Flash Player BURIED ALIVE in OS X Mavericks Safari sandbox
Cupertino following the lead of Google, Microsoft, and Mozilla
http://www.theregister.co.uk/2013/10/24/safari_flash_player_sandbox/

Euro Parliament axes data sharing with US – the NSA swiped the bytes
anyway
Hacking claims now probed by Continent's cops
http://www.theregister.co.uk/2013/10/24/european_parliament_votes_to_suspend_datasharing_with_us/

Scared yet, web devs? Google smears malware warnings over PHP.net
Four infected pages out of 1,500? That's 4 TOO MANY
http://www.theregister.co.uk/2013/10/24/php_site_malware_warning_flap/

India tops APAC ransomware table with £2.5 BEELLION losses
Norton stats show rich pickings for criminals in the sub-continent
http://www.theregister.co.uk/2013/10/24/india_ransomware_security_apac/

Call yourself a 'hacker', watch your ex-boss seize your PC without
warning
Court rules coder's computer can be suddenly snatched in 'software
knockoff' spat
http://www.theregister.co.uk/2013/10/23/hacker_seizure_rights_case/

You. Netgear ReadyNAS owners. Have you closed your gaping holes today?
Firmware update slipped out to kill code-injection vuln
http://www.theregister.co.uk/2013/10/23/netgear_users_missing_old_patch_tripwire/

Chrome for the slurp-weary: Cookie-binning Aviator browser arrives
Chromium-based software promises ad- and track-blocking
http://www.theregister.co.uk/2013/10/23/privacyconscious_aviator_browser/

UK.gov open to hiring EX-CON hackers for cyber reserves
Justice League or Rogues Gallery?
http://www.theregister.co.uk/2013/10/23/hacker_wanted_uk_cyber_reserve_squad/

DARPA slaps $2m on the bar for the ULTIMATE security bug SLAYER
Brown trousers time for some in antivirus industry
http://www.theregister.co.uk/2013/10/22/darpa_sets_2_million_cash_prize_for_the_ultimate_vulnerability_scanner/

NSA-friendly cyber-slurp law CISPA back on the table with new Senate
bill
Unsurprisingly with spooks' full support
http://www.theregister.co.uk/2013/10/22/cispa_back_on_the_agenda/

Google pulls all Android apps linked to adware badness THAT MUST NOT BE
NAMED
'Vulna' library slurps text messages, phone call history, contact
lists, warns researcher
http://www.theregister.co.uk/2013/10/22/vulna_mobile_ad_threat_followup/

MoJ fined £140K for EMAILING privates of 1,000 inmates
Bewildered families of 3 lags mailed data by SAME clerk in 3 SEPARATE
mistakes
http://www.theregister.co.uk/2013/10/22/inmate_detail_mailout_data_breach/

D-Link hole-prober finds 'backdoor' in Chinese wireless routers
Tenda networking kit contains easily-cracked vuln, claims researcher
http://www.theregister.co.uk/2013/10/22/tenda_router_backdoor/

Unsupervised Brit kids are meeting STRANGERS from the INTERNET
Primary school children are taking risks online
http://www.theregister.co.uk/2013/10/22/brit_kid_internet_safety_survey/

Feds charge Vietnamese suspect with slurp'n'flog of half-a-million
Americans' ID data
'Fullz' sold included social security, bank account and bank routing
numbers
http://www.theregister.co.uk/2013/10/22/id_fraud_data_brokering_charges/

Web-email king Mail.ru gulps $15k fine, fights govt demand to slurp
data
Putin's bods wants users' records, internet site grows some balls
http://www.theregister.co.uk/2013/10/22/mailru_fights_rus_gov_data_requests/

Chinese hotel guests find data spaffed all over the internet
Probably better not register for Wi-Fi next time you're in the PRC
http://www.theregister.co.uk/2013/10/22/china_hotel_data_breach_victims/

Fraudster bought names and address from Experian, says Krebs
Data broker duped
http://www.theregister.co.uk/2013/10/22/fraudster_bought_names_and_address_from_experian_says_krebs/

New leak claim: NSA saw hole in Mexican prez's email box - and hacked
it
Operation Flatliquid sparks further fury down south
http://www.theregister.co.uk/2013/10/22/nsa_tailored_ops_squad_hacked_mexican_presidents_inbox_report/

First Lavabit, now CryptoSeal pulls the plug: VPN service axed
More NSA fallout
http://www.theregister.co.uk/2013/10/22/cryptoseal_shutters_consumer_vpn_service/

If there's somethin' strange in your network 'hood. Who y'gonna call?
Google's DDoS-busters
Project Shield guards activists, charities from web storms
http://www.theregister.co.uk/2013/10/21/google_project_shield_ddos/

Furious French choke on chardonnay over NSA's phone spying in France
Zut alors! Monsieur l'ambassadeur américain convoqué réunion sans café
http://www.theregister.co.uk/2013/10/21/france_snowden_nsa_call_eavesdropping/

Win a free pass to RSA Conference Europe
Amsterdam is lovely at this time of year ...
http://www.theregister.co.uk/2013/10/21/rsa_conference_europe_prize_draw/

Apple accused over 'secure' iMessage encryption
Infosec wallah questions security of fruity chat service
http://www.theregister.co.uk/2013/10/21/apple_accused_of_lying_about_spookproof_imessage/

Adobe hackers strike again: PR Newswire grovels to clients after latest
hack'n'grab
Sticky fingerprints left on server used for Adobe code slurp
http://www.theregister.co.uk/2013/10/21/pr_newswire_hackers_adobe_link/

Keeping your endpoint data safe: some simple precautions
Stay one step ahead
http://www.theregister.co.uk/2013/10/21/data_security/

Android's defences against malicious apps dissed by security bods
Your hacker barriers are mostly dialogue boxes, Mr Wonka
http://www.theregister.co.uk/2013/10/21/android_ios_security_comparison/


*** Whitepaper ***

The business case for a multi-tenant, cloud-based Recovery-as-a-Service solution
The cost of downtime to your business is higher than it ever has been. RaaS is designed for the recovery of full applications so you're up and running faster after a declaration.
http://whitepapers.theregister.co.uk/d/bfc/9e7f3/669/b85b5640?td=week_sec_e



RSA Conference Europe

Over 70 information security track sessions plus debates and keynotes.
Build your knowledge and further your career.

http://reg.cx/26Xk




------------------------------------------------------------------------

This email was sent to garn14.tech@blogger.com

To change your email or your email subscriptions

http://account.theregister.co.uk/login/

To unsubscribe from all The Register newsletters

http://account.theregister.co.uk/unsubscribe/649203/acc978a1

The Register and its contents are Copyright © 2013 Situation Publishing.
All rights reserved.

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.