Sunday, July 6, 2014

The Reg Security: Oh SNAP! Old-school '80s Unix hack to smack OSX, iOS, Red Hat? [Mon Jul 7 2014]

Dear etechnews today,

Your weekly security newsletter from theregister.co.uk
for the week ending 7th July 2014





*** Security News ***

USA to insist on pre-flight mobe power probe
Prove it works or it can't come aboard flights to USA
http://www.theregister.co.uk/2014/07/07/usa_to_insist_on_preflight_mobe_power_probe/

'Spy-proof' IM launched: Aims to offer anonymity to whistleblowers
*reaction gif* I'm just getting all the secret files. BRB...
http://www.theregister.co.uk/2014/07/04/anonymous_im_for_whistleblowers/

Crypto thwarts TINY MINORITY of Feds' snooping efforts
Dire warnings from cops fall flat thanks to official US.gov figures
http://www.theregister.co.uk/2014/07/04/us_wiretap_stats_show_crypto_doesnt_stop_law_enforcement/

Journal that published Facebook emoto-furtle study: Proper boffins get
CONSENT
There's a thing called 'Common Rule'. Heard of it, Mr Z?
http://www.theregister.co.uk/2014/07/04/pnas_concerned_over_facebook_emotion_contagion_study/

So which miscreants wrote the CosmicDuke info-slurping nasty?
Finnish researchers spot link to long-ago anti-NATO attacks
http://www.theregister.co.uk/2014/07/04/cosmicduke_linked_to_anti_nato_gov_attacks_fsecure/

Austrian Tor exit relay operator guilty of ferrying child porn
All care but no responsibility defence didn't fly
http://www.theregister.co.uk/2014/07/04/austrian_tor_exit_relay_op_found_guitly_for_ferrying_child_p0rn/

PANDA chomps through Spotify's DRM
Tough slog to free ogg
http://www.theregister.co.uk/2014/07/04/spotify_drm_broken/

What do we want? CAT VIDEOS! How do we get them? TOR!
Anonymity outfit responds to NSA targeting allegations
http://www.theregister.co.uk/2014/07/04/what_do_we_want_cat_videos_how_do_we_get_them_tor/

Big Java security fixes on the way – but not so fast, Windows XP users
Didn't you hear? Oracle quit testing Java on XP months ago
http://www.theregister.co.uk/2014/07/04/oracle_winxp_end_of_support/

Hacked Israel Defence Force Twitter account spruiks nuke leak fears
Syrian hackers pop Twitter Hootsuite dashboard
http://www.theregister.co.uk/2014/07/04/hacked_israel_defence_force_spruiks_nuke_leak_fears/

Your Android phone is a SNITCH: Wi-Fi bug makes you easy to track
Even asleep, your mobe could be blabbing your every move
http://www.theregister.co.uk/2014/07/03/eff_android_wifi_tracking_bug/

Windows users: You get a patch! And you get a patch! And you get a
patch! Everybody gets...
But not you, Windows XP. No Patch Tuesday for you
http://www.theregister.co.uk/2014/07/03/patch_tuesday_coming_up_and_servers_are_getting_a_bumper_dose/

Use Tor or 'EXTREMIST' Tails Linux? Congrats, you're on an NSA list
Penguinista mag readers, privacy-conscious netizens and more targeted,
claims report
http://www.theregister.co.uk/2014/07/03/nsa_xkeyscore_stasi_scandal/

Future Apple gumble could lock fanbois out of their own devices
Travelling outside your own hood? Just in case ... *clang*
http://www.theregister.co.uk/2014/07/03/apple_location_security_tech_could_auto_lock_your_istuff/

You CAN'T bust into our login app's password vault, insists Roboform
Um, I've made a vid of me doing exactly that, claims bloke
http://www.theregister.co.uk/2014/07/03/roboform_security_worries/

Oh SNAP! Old-school '80s Unix hack to smack OSX, iOS, Red Hat?
REAL damage to *nix systems, tools ... via SIMPLE wildcard poison
tricks, claims researcher
http://www.theregister.co.uk/2014/07/03/unix_wildcard_vuln_lets_hackers_modify_shell_scripts/

AVG: We need laws to stop biz from tracking our kids
CTO of antivirus firm calls for new laws on children's privacy
http://www.theregister.co.uk/2014/07/03/avg_data_about_children/

NSA man says agency can track you through POWER LINES
Boffins throw cold water on electric eavesdropping claims raised in
German media
http://www.theregister.co.uk/2014/07/03/tinfoil_hatters_spook_says_nsa_can_track_whistleblowers_through_power_lines/

BAE retracts hedge fund hack allegation
Well, this IS awkward, seeing as Wall Street formed a group to stop it
happening again
http://www.theregister.co.uk/2014/07/03/bae_retracts_hedge_fund_hack_allegation/

Secluded HijackRAT: Monster mobile malware multitool from HELL
Probably has feature for getting banking details out of horses' hooves
http://www.theregister.co.uk/2014/07/03/android_nasty_packs_multiple_tricks/

Brazilian baddies bank Boleto billions
Tremendous takings through a trillion tiny transactions
http://www.theregister.co.uk/2014/07/03/brazilian_baddies_bank_boleto_billions/

Google BLOCKS access to Goldman client-leak email
Choc Factory to bank: 'Don't panic. No one read the message'
http://www.theregister.co.uk/2014/07/03/goldman_wants_google_to_delete_clientleak_email/

HOLD THE FRONT PAGE: US govt backs mass spying by US govt
Sucks to be you, Johnny Foreigner. But think of all the terrorism Uncle
Sam's tackling
http://www.theregister.co.uk/2014/07/03/us_government_says_spying_by_us_government_is_ok/

Running Cisco's VoIP manager? Four words you don't want to hear:
'Backdoor SSH root key'
Hardwired login in Unified Comms Domain Manager
http://www.theregister.co.uk/2014/07/02/cisco_you_cant_just_leave_your_ssh_keys_lying_around/

Travel website Hotel Hippo yanked offline after data leaks spotted
Whose credit card details and address d'ya fancy reading?
http://www.theregister.co.uk/2014/07/02/hotel_hippo_goes_offline_gaping_security_holes_scott_helme/

Cybercrooks breed SELF-CLONING MUTANT that STEALS your BANK DETAILS
Fresh Cridex variant plays merry hell via email
http://www.theregister.co.uk/2014/07/02/cridex_trojan_email_worm_hybrid/

MONSTER COOKIES can nom nom nom ALL THE BLOGS
Blog networks can be force-fed more than they can chew
http://www.theregister.co.uk/2014/07/02/monster_cookies_can_nom_nom_nom_all_the_blogs/

Redmond's EMET defense tool disabled by exploit torpedo
With latest version shot to pieces, work begins on beta bomb
http://www.theregister.co.uk/2014/07/02/redmonds_emet_defense_tool_disabled_by_exploit_torpedo/

Sydney wallows in cesspit of WiFi obsolescence and ignorance
World of Warbiking WiFi sniffing peloton finds lots of unsecured
connections
http://www.theregister.co.uk/2014/07/02/sydney_wallowing_in_cesspit_of_wifi_obsolescence/

EFF sues NSA over snoops 'hoarding' zero-day security bugs
Wants docs showing who chooses to keep us unsafe online
http://www.theregister.co.uk/2014/07/02/eff_sues_nsa_over_agencys_policy_of_hoarding_zeroday_flaws/

Sorry, chaps! We didn't mean to steamroller legit No-IP users –
Microsoft
Meanwhile, miscreants are DDoSing the hapless DNS provider
http://www.theregister.co.uk/2014/07/01/sorry_chaps_microsoft_unborks_legitimate_noip_users_domains/

'I don't want to go on the cart' ... OpenSSL revived with survival
roadmap
Heartbleed-battered crypto library reveals long path back to health
http://www.theregister.co.uk/2014/07/01/openssl_roadmap/

Microsoft thumbs nose at NSA, hardens crypto for Outlook, OneDrive
New server-side feature makes it harder for spies to snoop
http://www.theregister.co.uk/2014/07/01/outlook_onedrive_improved_crypto/

PayPal says sorry: Fat fingers froze fundraiser for anti-spy ProtonMail
Payment goliath blames 'technical problem' for account block
http://www.theregister.co.uk/2014/07/01/paypal_unfreezes_funds_for_protonmail_encrypted_email_startup/

New NSA boss plays down impact of Snowden leaks
You have not heard me say 'OMG, the sky is falling'
http://www.theregister.co.uk/2014/07/01/nsa_rogers_interview/

Deja-vu alert: Russian hackers target US, Euro energy giants
It's here - just click through to last week
http://www.theregister.co.uk/2014/07/01/wondering_where_our_story_on_russians_hacking_energy_companies_is/

GCSE Computing teachers cry victory as board decides NOT to bin tech
teens' work
'No suggestion of widespread malpractice', Cambridge Assessment now
says
http://www.theregister.co.uk/2014/07/01/gcse_computing_teachers_tweet_cambridge_assessment_into_submission_over_cheating_claims/

Iraq civil war: You can fight with an AK-47 ... or a HOME-COOKED Trojan
Researcher spots spike in cyber-espionage tools
http://www.theregister.co.uk/2014/07/01/iraq_civil_war_malware/

MIT and CERN's secure webmail plan stumped by PayPal freeze
Money-shuffler shutters cash flow after asking if crypto is legal
http://www.theregister.co.uk/2014/07/01/proton_mail_caught_by_paypal_processing_freeze/

Redmond reinstates infosec mailing list after Canadian law panic
Canada Day legalese proves no match for Microsoft
http://www.theregister.co.uk/2014/07/01/casl_confusion_as_redmond_reinstates_infosec_mailing_list/

Anti-snoop Android 'Blackphone' sees the light of day
Silent Circle's phone for the security conscious reaches first buyers
http://www.theregister.co.uk/2014/07/01/antisnoop_android_blackphone_sees_the_light_of_day/

Microsoft's anti-malware crusade knackers '4 MILLION' No-IP users
Dynamic DNS biz cries foul as Redmond seeks to smash software nasties
http://www.theregister.co.uk/2014/07/01/microsoft_takes_over_noip_domains_to_block_malware_marketing/

Apple ships security fixes for iOS, OS X, Safari ... basically
EVERYTHING
Here comes the next big slew of WebKit bug fixes
http://www.theregister.co.uk/2014/06/30/apple_june_30_patches/

Using Android 4.3? Don't let malware snatch your private login keys
Bad news: One in ten devices suffer KeyStore flaw. Good news: It's hard
to exploit
http://www.theregister.co.uk/2014/06/30/android_jelly_bean_users_open_to_passwordstealing_flaw/

Remaining Snowden docs will be released to avert 'unspecified US war' –
‪Cryptome‬
Not by us, though, says coy leaker tweet
http://www.theregister.co.uk/2014/06/30/remaining_snowden_documents_will_be_release_to_avert_war_cryptome/

Application delivery controllers tighten the security perimeter
Protect your assets
http://www.theregister.co.uk/2014/06/30/data_security/

London teen charged over Spamhaus mega-DDoS attacks
Accused will tap the boards before the beak today
http://www.theregister.co.uk/2014/06/30/ddos_charges/

Dropbox used as command and control for Taiwan time bomb
PlugX trojan gets an upgrade for new attacks
http://www.theregister.co.uk/2014/06/30/dropbox_used_as_command_and_control_in_taiwanese_govt_attack/


*** Whitepaper ***

Maximizing your infrastructure through virtualization
Virtualization continues to be one of the most effective ways to consolidate, reduce cost, and make data centers more efficient.
http://whitepapers.theregister.co.uk/d/ccd/9e7f3/765/d568bf19?td=week_sec_e



------------------------------------------------------------------------

This email was sent to garn14.tech@blogger.com

To change your email or your email subscriptions

http://account.theregister.co.uk/login/

To unsubscribe from all The Register newsletters

http://account.theregister.co.uk/unsubscribe/649203/acc978a1

The Register and its contents are Copyright © 2014 Situation Publishing.
All rights reserved.

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.