Monday, March 3, 2014

The Reg Security: Update your Mac NOW: Apple fixes OS X 'goto fail' SSL spying vuln [Mon Mar 3 2014]

Dear etechnews today,

Your weekly security newsletter from theregister.co.uk
for the week ending 3rd March 2014


*** Security News ***

MtGox to customers: Your call is important to us … NOT!
Call centre hell awaits Bitcoin's bereft brigades
http://www.theregister.co.uk/2014/03/03/mtgox_to_customers_your_call_is_important_to_us_not/

IM demo for TOR coming soon
Instantbird to land on an onion by end of March
http://www.theregister.co.uk/2014/03/03/im_demo_for_tor_coming_soon/

Cisco kicks off $300k Internet of Things security competition
Borg wants an Internet of secure things and wants you to do the heavy
thinking
http://www.theregister.co.uk/2014/03/03/cisco_kicks_off_iot_security_comp/

RSA booked TV's Stephen Colbert to give the final speech. This is what
happened next
Comic gives security bods a healthy dose of truthiness
http://www.theregister.co.uk/2014/03/01/stephen_colbert_roasts_rsa_nsa_and_edward_snowden/

Secret Service probes possible data-leak hack attack at Sears – report
So far, so good – no sign of any database breach, says US goliath
http://www.theregister.co.uk/2014/03/01/sears_tied_to_secret_service_attack_investigation/

Crap hospital databases next goldmine for cyber-crooks, say Microsoft's
botnet slayers
Your medical files are worth big bucks to fraudsters
http://www.theregister.co.uk/2014/02/28/microsoft_botnet_takedown_team_say_healthcare_is_herders_next_target/

Two in five Brits cough up for CryptoLocker ransomware's demands
Cowed victims hand over thousands rather than install basic security
measures
http://www.theregister.co.uk/2014/02/28/cryptolocker_victims_pay_up_survey/

Microsoft Research co-develops cloud data scrambler
'Melbourne Shuffle' will make it harder for cloud operators to mine or
sniff your data
http://www.theregister.co.uk/2014/02/28/microsoft_research_chap_codevelops_cloud_data_scrambler/

Government-built malware running out of control, F-Secure claims
What if antivirus companies are whitelisting state malware...
http://www.theregister.co.uk/2014/02/28/governmentbuilt_malware_running_out_of_control_fsecure_tells_trustycon/

RSA rebel conference TrustyCon sells out despite 'dirty tricks'
Raises $20,000 for EFF, and support for some in security industry
http://www.theregister.co.uk/2014/02/28/rsa_rebel_conference_trustycon_sells_out_despite_claimed_dirty_tricks/

Apple slams shut TEN code execution holes in QuickTime on Windows
Plus stability fix for iTunes on Redmond-powered PCs
http://www.theregister.co.uk/2014/02/28/apple_drops_patches_for_windows_quicktime_and_itunes/

UK spies on MILLIONS of Yahoo! webcams, ogles sex vids - report
Perfectly legal for us to watch your unencrypted steamy cam sessions,
sniffs GCHQ
http://www.theregister.co.uk/2014/02/27/gchq_optic_nerve/

Well done on the privacy lawsuit. Now NSA will keep your phone records
INDEFINITELY
Unintended consequences
http://www.theregister.co.uk/2014/02/27/nsa_phone_dragnet_lawsuit_backfires/

Energy firms' security so POOR, insurers REFUSE to take their cash
They're turning down MULTI-MILLION pound contracts...
http://www.theregister.co.uk/2014/02/27/energy_sector_refused_cyber_insurance/

YouTube to take down THAT anti-Muslim vid ... over COPYRIGHT issues
Actor manages to do what angry hacktivists could not
http://www.theregister.co.uk/2014/02/27/youtube_pulls_inflammatory_anti_muslim_vid/

Q&A: Schneier on trust, NSA spying and the end of US internet hegemony
Basically, we're screwed for the next decade or so
http://www.theregister.co.uk/2014/02/27/qa_schneier_on_trust_nsa_spying_and_the_end_of_us_internet_hegemony/

Oz feds kick the metadata retention can, again
Please sir, may I have some more?
http://www.theregister.co.uk/2014/02/27/oz_feds_kick_the_metadata_retention_can_again/

UK unis, McAfee collude to beat collusion attacks
EPSRC splashes cash at security
http://www.theregister.co.uk/2014/02/27/uk_unis_mcafee_collude_to_beat_collusion_attacks/

OpenID Foundation launches XML-free ID handler
OpenID Connect spec touts simpler messaging
http://www.theregister.co.uk/2014/02/27/openid_foundation_launches_xmlfree_id_handler/

New FBI boss says cyber crime, not terrorism, is top of Feds' todo list
Malware cousin of fingerprint and DNA database to be shared with
infosec world
http://www.theregister.co.uk/2014/02/27/new_fbi_boss_pledges_cyber_crime_not_terrorism_will_dominate_agency_in_the_next_decade/

Boeing going ... GONE: Black phone will SELF-DESTRUCT in 30 secs
FCC filings reveal hush-hush device which destroys itself when tampered
with
http://www.theregister.co.uk/2014/02/26/boeing_black/

Microsoft hardens EMET security tool: OK, it's not invulnerable, but
it's free
Hopes to slap down more zero-day attacks...
http://www.theregister.co.uk/2014/02/26/ms_emet_revamp/

Like WhatsApp? Meet 'desktop' version... and his BANK ACCOUNT RAIDING
Trojan pal
Spam scam blam, moolah scram
http://www.theregister.co.uk/2014/02/26/whatsapp_scams/

Wot a COCKUP: Poorly NHS websites spawn SPAMMY VIAGRA ads
Up to individual orgs to deal with security, sniffs HSCIC
http://www.theregister.co.uk/2014/02/26/poorly_nhs_website_is_handing_out_cocksure_doses_of_spammy_viagra/

ZeuS KICKS that SaaS: Trojan raids Salesforce.com accounts
CRM giant's customers take an arrow to the knee... – reports
http://www.theregister.co.uk/2014/02/26/zeus_salesforce_malware/

CipherCloud launches 'watch your cloud app' protection
Compatibility matters
http://www.theregister.co.uk/2014/02/26/ciphercloud_launches/

Dating app spent months as STALKING app
Tinder plugs leak that let you track your intended for months at a
time, to within 30m
http://www.theregister.co.uk/2014/02/26/dating_app_spent_months_as_stalking_app/

Aaah-CHOOO! Brit boffins say WiFi can 'sneeze' malware
Vulnerable access points could spread viruses like that snuffly chapy
next to you on the train
http://www.theregister.co.uk/2014/02/26/wifi_access_points_great_infection_vectors_say_uk_boffins/

Schneier: NSA snooping tactics will be copied by criminals in 3 to 5
years
The good news? Strong crypto still works
http://www.theregister.co.uk/2014/02/26/nsa_snooping_tactics_will_be_copied_by_criminals_in_35_years/

Update your Mac NOW: Apple fixes OS X 'goto fail' SSL spying vuln
Guys, Patch Tuesday is for Microsoft and Adobe, this should have been
Patch Friday
http://www.theregister.co.uk/2014/02/25/apple_mac_os_x_10_9_2_ssl/

Microsoft: NSA snooping? Code backdoors? Our hands are clean!
Mass spying would be 'nuts', 'economic suicide'
http://www.theregister.co.uk/2014/02/25/our_hands_are_clean_on_nsa_surveillance_and_code_backdoors_says_microsoft/

Make cyberwar a no-no equal to nukes, bio, and chemical attacks, says
RSA headman
And while you're at it, Art Coviello suggests, break up the NSA
http://www.theregister.co.uk/2014/02/25/make_cyberwar_as_much_of_a_nono_as_nuclear_chemical_exchanges_says_rsa/

iOS 7: Even if you don't jailbreak your iPhone, bugs STILL CREEP IN
Oh, and that SSL bugfix last week? Old news, my boy
http://www.theregister.co.uk/2014/02/25/ithings_snoopware_risk/

China's web giants unite to defuse Windows XP bombshell
Tencent, Sogou, Kingsoft and others will provide support for local
users
http://www.theregister.co.uk/2014/02/25/windows_xp_hedge_web_tencent_china/

Evil or benign? 'Trusted proxy' draft debate rages on
Crypto is a minefield, but we always knew that
http://www.theregister.co.uk/2014/02/25/evil_or_benign_trusted_proxy_draft_debate_rages_on/

Pony up: Botnet succesfully targets Bitcoin
Password-lifting network converted to cryptocoin-thievery
http://www.theregister.co.uk/2014/02/25/pony_up_more_bitcoins_go_missing_to_theives/

Prez Obama cyber-guru: Think your data is safe in an EU cloud? The NSA
will raid your servers
But US govt shouldn't be 'f**king' with crypto algorithms
http://www.theregister.co.uk/2014/02/24/richard_clarke_csa_comments/


*** Whitepaper ***

5 DNS security risks that keep you up at night
Find out all of the scary details about potential DNS attacks and what you can do to prevent them.
http://whitepapers.theregister.co.uk/d/c38/9e7f3/6e7/f46eecc4?td=week_sec_e



------------------------------------------------------------------------

This email was sent to garn14.tech@blogger.com

To change your email or your email subscriptions

http://account.theregister.co.uk/login/

To unsubscribe from all The Register newsletters

http://account.theregister.co.uk/unsubscribe/649203/acc978a1

The Register and its contents are Copyright © 2014 Situation Publishing.
All rights reserved.

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.