Sunday, June 29, 2014

The Reg Security: 'Heartbleed-based BYOD hack' pwns insurance giant Aviva' s iPhones [Mon Jun 30 2014]

Dear etechnews today,

Your weekly security newsletter from theregister.co.uk
for the week ending 30th June 2014





*** Security News ***

Zero-proof crypto scheme can divine truths from nothing
Boffins scheme to help blow up nukes could also be handy for electronic
voting
http://www.theregister.co.uk/2014/06/30/zeroproof_crypto_scheme_nukes_liars_helps_verify_secret_data/

Microsoft to shutter security email feed on July 1
Gov 'automated electronic messaging' bans force RSS feeds down infosec
pros' maws
http://www.theregister.co.uk/2014/06/29/microsoft_shutters_dustclad_security_mailing_list/

Surprise! NSA's first ever 'transparency' 'report' is anything but
Spies do spying ... and dictionary rewriting, too
http://www.theregister.co.uk/2014/06/27/nsa_issues_own_somewhat_murky_transparency_report/

Yet another WordPress vuln: Image furtler plugin lets BADNESS in
By the pricking of my thumbs, something wicked this way comes
http://www.theregister.co.uk/2014/06/27/wordpress_0day/

Android SMS worm punts dodgy downloads... from your MATES
If a friend texts you a URL, for pity's sake don't open it
http://www.theregister.co.uk/2014/06/27/selfmite_android_self_replicating_sms_worm/

NASA's Curiosity rover brought Earth BUG to Mars
A software bug, that is, as flaw turns up in popular compression
imaging algorithm
http://www.theregister.co.uk/2014/06/27/curosity_rover_brings_human_bugs_to_mars/

Send Bitcoin or we'll hate-spam you on Yelp, say crims
Extortion letters demand cryptocurrency from pizza parlours
http://www.theregister.co.uk/2014/06/27/bitcoin_brutes_post_notice_of_extortion_letters/

Germany dumps Verizon for Deutsche Telekom over NSA spying
Nein, danke, we need 'a very high level of security'
http://www.theregister.co.uk/2014/06/26/germany_boots_verizon/

What is ex-NSA spyboss selling for $1m a month, asks US congressman
Former snoop Gen Alexander's security consultancy under the microscope
http://www.theregister.co.uk/2014/06/26/congressman_calls_for_investigation_into_exnsa_chiefs_security_consultancy/

Average chump in 'bank' phone scam is STUNG for £10,000 - study
Get Safe Online launches campaign against 'social engineering'
http://www.theregister.co.uk/2014/06/26/get_safe_online_social_eng_awareness_campaign/

Attackers fling Stuxnet-style RATs at critical control software in
EUROPE
SCADA/ICS systems under attack, warns F-Secure
http://www.theregister.co.uk/2014/06/26/industrial_control_trojan/

Patch looks like Microsoft FAIL, quacks like FAIL, is actually quite
good
NOTHING to worry about, sysadmins, this unexpected dowload's a good 'un
http://www.theregister.co.uk/2014/06/26/patch_looks_like_microsoft_fail_quacks_like_a_microsoft_fail/

Half a meellion euros stolen in week-long bank smash 'n' grab
No need for subtlety as attackers hack and empty 190 accounts
http://www.theregister.co.uk/2014/06/26/half_a_imeellioni_euros_stolen_in_weeklong_bank_smash_n_grab/

PayPal 2FA mobe flaw chills 'warm and fuzzy' security feeling
Take another look at those pastebin dumps, bods say
http://www.theregister.co.uk/2014/06/26/paypal_2fa_mobe_flaw_chills_warm_and_fuzzy_security_feeling/

Google pries open YOUR mailbox, invites developer partners
What can possibly go wrong?
http://www.theregister.co.uk/2014/06/26/google_new_gmail_api/

Cryptome pulled OFFLINE due to malware infection: Founder cries foul
'Craven and shallow technical justification' for censorship, fumes
whistleblower
http://www.theregister.co.uk/2014/06/25/row_after_cryptome_pulled_offline/

27 Data-Slurping Facts BuzzFeed Doesn't Want You To Know!
'Fun' quizzes drill down into your MENTAL HEALTH PROBLEMS
http://www.theregister.co.uk/2014/06/25/buzzfeed_aggregated_data_slurp/

Own goal as World Cup Wi-Fi passwords spilled in newspaper snap
Not-so-L33t login now sprayed across Twitter
http://www.theregister.co.uk/2014/06/25/brace_yourselves_brazil_dill_in_world_cup_wifi_spill/

Sysadmins rejoice! Patch rampage killing off nasty DDoS attack vector
Server fleet open to NTP attack drops from 400k to just 17,000
http://www.theregister.co.uk/2014/06/25/sysadmins_rejoice_patch_rampage_killing_off_nasty_ddos_attack_vector/

SHOCKER: CIA CIO CAN confirm that AWS cloud safe for big government
CIA CIO: AWS RFP NOFORN SIGINT ICT A-OK
http://www.theregister.co.uk/2014/06/25/cia_cio_aws/

Passwords in plaintext? NOT OK, Cupid
Australian dating security service not a good match, says privacy
commissioner
http://www.theregister.co.uk/2014/06/25/passwords_in_plaintext_not_ok_cupid/

SHOCK HORROR: Oz's biggest govt agencies to miss infosec deadline
They patch when they feel like it and ignore spooks' advice
http://www.theregister.co.uk/2014/06/25/shock_horror_ozs_biggest_govt_agencies_to_miss_infosec_deadline/

Montana loses data on MORE PEOPLE THAN LIVE IN MONTANA
Health department hack leaves 1.3 million vulnerable
http://www.theregister.co.uk/2014/06/25/montana_loses_data_on_more_people_than_live_in_montana/

Got a botnet? Thinking of using it to mine Bitcoin? Don't bother
McAfee says crooks will be better off sticking to spam and DDoS
http://www.theregister.co.uk/2014/06/24/bad_news_malware_infections_are_mining_bitcoin_good_news_theyre_not_making_any_money/

EXPOSED: Massive mobile malware network used by cops globally
Police can deploy surveillance software that'll make hackers green with
envy
http://www.theregister.co.uk/2014/06/24/researchers_uncover_massive_mobile_malware_network_and_its_totally_legal/

Brit bank Barclays rolls out voice recog for telephone banking
I hab a cold. What do goo mean you can't berify?
http://www.theregister.co.uk/2014/06/24/barclays_voice_recognition/

Snowden defends mega spy blab: 'Public affairs have to be known by the
public'
Calls on Council of Europe to protect whistleblowers
http://www.theregister.co.uk/2014/06/24/edward_snowden_talks_to_council_of_europe_about_protecting_whisteblowers/

Daddy, what will you do in the new security wars?
Depends which enemy are we talking about, son
http://www.theregister.co.uk/2014/06/24/security_wars_you_aint_seen_nothing_yet/

F1 racing ace Michael Schumacher's medical records were pinched
We'll go after whoever's offering to sell them – Schumi's team
http://www.theregister.co.uk/2014/06/24/criminal_sanctions_threatened_over_michael_schumacher_f1_racer_medical_records_sale/

SEA hacks Reuters website widget DESPITE 2FA security
Ad agency Taboola unwittingly provides backdoor for attackers
http://www.theregister.co.uk/2014/06/24/reuters_hacked_by_sea/

Microsoft brings own security info exchange to the world
'Interflow' will allow pros to network and share machine-readable bug
data
http://www.theregister.co.uk/2014/06/24/microsoft_brings_own_security_info_exchange_to_the_world/

Cisco okayed for UK government comms
IPSec cleared for most gummint sites
http://www.theregister.co.uk/2014/06/24/cisco_okayed_for_uk_government_comms/

Comcast Xfinity evil twin steals subscriptions
That's not the login page you're looking for
http://www.theregister.co.uk/2014/06/24/comcast_xfinity_evil_twin_steals_subcriptions/

British Gas Twitter account hijacked by mystery phishermen
Login cred-stealing scammers get in, mayhem ensues
http://www.theregister.co.uk/2014/06/23/british_gas_twitter_account_hijacked_by_phishing_fraudsters/

'Heartbleed-based BYOD hack' pwns insurance giant Aviva's iPhones
Slabs and mobes moved to BB10... yes, you read that right
http://www.theregister.co.uk/2014/06/23/aviva_heartbleed_hack/

Traffic lights, fridges and how they've all got it in for us
Interthreat of things
http://www.theregister.co.uk/2014/06/23/hold_interthreat/

WiFi WarKitteh and DDoS Dog to stalk DEF CON 22
Pets make purrrfect pawns for surreptitious signal slurping
http://www.theregister.co.uk/2014/06/23/wifi_war_cat_ddos_dog_the_latest_in_animal_biotech_warfare/



------------------------------------------------------------------------

This email was sent to garn14.tech@blogger.com

To change your email or your email subscriptions

http://account.theregister.co.uk/login/

To unsubscribe from all The Register newsletters

http://account.theregister.co.uk/unsubscribe/649203/acc978a1

The Register and its contents are Copyright © 2014 Situation Publishing.
All rights reserved.

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.