Monday, February 24, 2014

The Reg Security: Apple promises SSL snooping fix for Mac OS X 10.9 users ' very soon' [Mon Feb 24 2014]

Dear etechnews today,

Your weekly security newsletter from theregister.co.uk
for the week ending 24th February 2014


*** Security News ***

Saving private spying: IETF reveals crypto-busting proxy proposal
'Explicit Trusted Proxy' would allow carriers to decrypt data to speed
transmission
http://www.theregister.co.uk/2014/02/24/saving_private_spying_cryptobusting_proxy_proposal_surfaces_at_ietf/

Apple promises SSL snooping fix for Mac OS X 10.9 users 'very soon'
Safari, Mail, iMessage, Facetime, Twitter and more blown apart by cert
bug
http://www.theregister.co.uk/2014/02/23/apple_mac_os_x_10_9_ssl_fix/

Harvard student thrown off 14,000-core super ... for mining Dogecoin
Wow. Very misuse. Much banned. 'For fairly obvious reasons'
http://www.theregister.co.uk/2014/02/22/harvard_student_abuses_supercomputer_to_mine_dogecoin/

Google nets Spider.io to thwart fraudsters
Click-fraud specialist heads to Mountain View
http://www.theregister.co.uk/2014/02/22/google_gets_spiderio_to_thwart_fraudsters/

Uni of Maryland hacked: 300,000 SSNs of staff, students, alumni swiped
Secret Service called in after NSA's favorite campus ravaged
http://www.theregister.co.uk/2014/02/21/alumi_alert_as_university_of_maryland_loses_over_300000_records_in_online_attack/

Update your iThings NOW: Apple splats scary SSL snooping bug in iOS
OS X Mavericks still VULNERABLE, millions at risk of web hijacking
http://www.theregister.co.uk/2014/02/21/apple_patches_ios_ssl_vulnerability/

Reg HPC man relives 0-day rootkit GROUNDHOG DAY
Okay, campers, rise and shine, and don't forget your booties...
http://www.theregister.co.uk/2014/02/21/merry_fing_christmas/

Robot army to police football World Cup
They inspected Fukushima, now it's Brazil's turn ...
http://www.theregister.co.uk/2014/02/21/robot_world_cup_fifa_packbot/

How many mobile apps collect data on users? Oh ... nearly all of them
Free or paid, Android or iOS, your apps are spying on YOU – report
http://www.theregister.co.uk/2014/02/21/appthority_app_privacy_study/

New Flash vuln exploited (again). Adobe posts emergency fix (again)
Miscreants attack fresh hole ... Windows, Mac, Linux peeps at risk
http://www.theregister.co.uk/2014/02/20/flash_adobe_posts_emergency_fix/

Beware Greeks bearing lists: Bank-raiding nasty Zeus smuggles attack
orders in JPEGs
Trojan stashes config files in photos in mythology mash-up
http://www.theregister.co.uk/2014/02/20/zeus_bank_hackers_hiding_malware_controls_in_jpg_in_a_nod_to_the_ancients/

Korean credit card companies hit with 90-day, $100m sales ban
Punishment for losing 20m customer records makes other data breach laws
look wimpy
http://www.theregister.co.uk/2014/02/20/korean_banks_hit_with_three_month_ban/

Conspiracy theories rage as 100 website defacements hit Singapore
Government sites left alone, opposition hit by 'Indonesian' attacker
http://www.theregister.co.uk/2014/02/20/singapore_web_site_defacement_100/

Belkin patches WeMo bug
Fixes available on AppStore, Google Play
http://www.theregister.co.uk/2014/02/20/belkin_on_wemo_bug_get_the_patch/

Aargh! Bamboozled by security licensing - what works for my family?
Guide this reader through the vendor maze
http://www.theregister.co.uk/2014/02/19/readers_corner_it_security_software/

Snowden journo boyf grill under anti-terror law was legal, says UK
court
Media couple: 'Days of the British Empire are over', 'Britain is as bad
as EGYPT'
http://www.theregister.co.uk/2014/02/19/snowden_journo_boyf_grill_under_antiterror_law_was_legal_says_uk_court/

Silk Road admins: Sorry for the hack, we're sorting out refunds
Head of drugs market vows to make good on lost cryptogeld
http://www.theregister.co.uk/2014/02/19/silk_road_admins_promise_to_pay_back_hacked_funds/

Nasty holes found in Belkin's home automation kit
WeMo leaves key under mat for crooks, invites them in to rummage about
http://www.theregister.co.uk/2014/02/19/wemo_home_automation_is_insecure_ioactive/

Zoom out for a view of malware, say boffins
Forest, trees – you know the drill
http://www.theregister.co.uk/2014/02/18/zoom_out_for_a_view_of_malware_say_boffins/

Quantum comms can be made even more secure
Digital signatures using quantum states
http://www.theregister.co.uk/2014/02/18/quantum_comms_can_be_made_even_more_secure/

WordPress two-factor login plugin bug, er, bypasses 2-factor login
Cross-site vulnerability exposes bloggers
http://www.theregister.co.uk/2014/02/18/wordpress_2fa_bug_can_bypass_authentication/

FireEye enters crowded IPS market
More signal, less noise
http://www.theregister.co.uk/2014/02/18/fireeye_enters_crowded_ips_market/

Syrian Electronic Army slurps a MILLION reader passwords from Forbes
And slaps the MD5-hashed secrets all over the web
http://www.theregister.co.uk/2014/02/17/sea_slurps_a_million_ids_from_forbes/

MtGox claims to have a fix ready for Bitcoin withdrawal woes
Customers to get access to their funds real soon now, like
http://www.theregister.co.uk/2014/02/17/mtgox_bitcoin_withdrawal_fix/

Russian cybercrooks shun real currencies, develop private altcoins
Only n00bs need real-world cash in the cryptocurrency era
http://www.theregister.co.uk/2014/02/17/russian_underground_alt_digicoins_flourish/

Devs angrily dismiss Absolute Computrace rootkit accusation
This was sorted five years ago, rages anti-theft software haus
http://www.theregister.co.uk/2014/02/17/kaspersky_computrace/


*** Whitepaper ***

An On-Premise Private PaaS
Learn how OpenShift Enterprise can help architects standardize development processes, while letting developers focus on their code.
http://whitepapers.theregister.co.uk/d/c3e/9e7f3/6e0/557b0014?td=week_sec_e



------------------------------------------------------------------------

This email was sent to garn14.tech@blogger.com

To change your email or your email subscriptions

http://account.theregister.co.uk/login/

To unsubscribe from all The Register newsletters

http://account.theregister.co.uk/unsubscribe/649203/acc978a1

The Register and its contents are Copyright © 2014 Situation Publishing.
All rights reserved.

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.