Sunday, August 3, 2014

14 antivirus apps found to have security problems [Mon Aug 4 2014]

Dear etechnews today,

Your weekly security newsletter from theregister.co.uk
for the week ending 4th August 2014





*** Security News ***

Cisco patches OSPF bug that sends traffic into black holes
If the NSA had known about this flaw it would never have needed
backdoors
http://www.theregister.co.uk/2014/08/04/cisco_patches_ospf_bug/

Your fitness tracker is a SNITCH says Symantec
Broadcast your bonks to the WHOLE WIDE WORLD
http://www.theregister.co.uk/2014/08/04/your_fitness_tracker_is_a_snitch_says_symantec/

Mozilla gaffe exposed 76,000 email addresses, 4000 passwords
You know the drill: Utter expletive, grind teeth, change passwords, get
on with life
http://www.theregister.co.uk/2014/08/03/mozilla_gaffe_exposed_76000_email_addresses_4000_passwords/

Hey, big spender. Are you as secure as a whitebox vendor?
The Internet of Stuff is a HUGE LIABILITY
http://www.theregister.co.uk/2014/08/01/hey_big_spender_are_you_as_secure_as_a_whitebox_vendor/

Pentagon hacker McKinnon can't visit sick dad for fear of extradition
Leaving England for Scotland a danger, advise lawyers
http://www.theregister.co.uk/2014/08/01/pentagon_hacker_mckinnon_wary_of_visiting_sick_father_in_scotland_over_extradition_fears/

IBM snaps up identity access gatekeeper tech
Beefs up security portfolio with CrossIdeas
http://www.theregister.co.uk/2014/08/01/ibm_crossideas_acquisition/

Security chap writes recipe for Raspberry Pi honeypot network
Cunning security plan: dangle £28 ARM boxes and watch crooks take the
bait
http://www.theregister.co.uk/2014/08/01/bust_comment_crew_with_this_armada_of_raspberry_pi_honeypots/

Retailers shot up by PoS scraping brute force cannon
Run end-to-end crypto or die trying, hacker warns
http://www.theregister.co.uk/2014/08/01/retailers_shot_up_by_pos_scraping_brute_force_cannon/

Plug and PREY: Hackers reprogram USB drives to silently infect PCs
BadUSB instructs gadget chips to inject key-presses, redirect net
traffic and more
http://www.theregister.co.uk/2014/07/31/black_hat_hackers_drive_truck_through_hole_in_usb_security/

Microsoft's Euro cloud darkens: US FEDS can dig into foreign servers
They're not emails, they're business records, says court
http://www.theregister.co.uk/2014/07/31/microsoft_overseas_data_ruling/

Grabby baddie scours Paddy Power's towers: 650k punters leaked and it
took 4 years to admit it
We're still a safe bet, say bookies
http://www.theregister.co.uk/2014/07/31/paddy_power_data_breach/

Pentagon hacker McKinnon reinvents himself as SEO guru
From UFO coverup to SEO bigging-up
http://www.theregister.co.uk/2014/07/31/ex_hacker_mckinnon_seo_guru/

Securobods claim Middle East govts' fingerprints all over malware flung
at journos
Shoots down aptitude of badness-slingers
http://www.theregister.co.uk/2014/07/31/citizen_lab_alleges_middle_east_regimes_fling_malware_at_dissidents/

AVG stung as search revenue from freebie scanners dries up
Come back, freetards
http://www.theregister.co.uk/2014/07/31/avg_results/

Fiendishly complex password app extension ships for iOS 8
Just slip it in, won't hurt a bit, 1Password makers urge devs
http://www.theregister.co.uk/2014/07/31/1password_app_extension_ships_for_ios_8/

Russia to SAP, Apple: Hand over source code to prove you're not spies
And they'd get away with it too, if weren't for that meddling Snowden
http://www.theregister.co.uk/2014/07/31/russia_to_sap_apple_hand_over_source_code_to_prove_youre_not_spies/

BitTorrent launches decentralised crypto-fied chat app
Voice and text snuck onto freedom-loving nodes
http://www.theregister.co.uk/2014/07/31/bittorrent_launches_decentralised_cryptofied_chat_app/

Multipath TCP speeds up the internet so much that security breaks
Black Hat research says proposed protocol will bork network probes,
flummox firewalls
http://www.theregister.co.uk/2014/07/31/multipath_tcp_will_bork_your_network_probes_flummox_your_firewalls/

Tor attack nodes RIPPED MASKS off users for 6 MONTHS
Traffic confirmation attack bared users' privates - but to whom?
http://www.theregister.co.uk/2014/07/30/tor_decloaking_attack/

iWallet: No BONKING PLEASE, we're Apple
BLE-ding iPhones, not NFC bonkers, will drive trend - marketeers
http://www.theregister.co.uk/2014/07/30/apple_iwallet/

Firm issues soft denial against Iron Dome hack
Confirmed 'Chinese hack' downgraded to 'alleged' intrusion
http://www.theregister.co.uk/2014/07/30/firm_issues_soft_denial_against_iron_dome_hack/

DDOS takes down Cirrus Communications
Australian fixed wireless provider loses half its network for a day or
so
http://www.theregister.co.uk/2014/07/30/ddos_takes_down_cirrus_communications/

'Things' on the Internet-of-things have 25 vulnerabilities apiece
Leaking sprinklers, overheated thermostats and picked locks all online
http://www.theregister.co.uk/2014/07/30/each_internetofthings_thing_contains_25_vulnerabilities/

Keep your iPhone calls private, whispers Signal
Marlinspike's voice crypto comes to iOS
http://www.theregister.co.uk/2014/07/30/keep_your_iphone_calls_private_whispers_signal/

Thwarted dev sets Instasheep to graze on Facebook accounts
Zuck-land tried to fix crumbling cookie with HTTPS but developer won't
bite
http://www.theregister.co.uk/2014/07/30/instagrampopping_tool_born_after_facebook_denies_bug_bounty/

Canada's boffins need A WHOLE YEAR to recover from China hack attack
'State-sponsored actor' breached National Research Council network
http://www.theregister.co.uk/2014/07/30/canadas_nrc_will_need_a_year_to_recover_from_china_hack_attack/

Senate introduces USA FREEDOM Act to curb NSA spying excesses
Good news if you're an American, less so for everyone else
http://www.theregister.co.uk/2014/07/29/senate_introduces_usa_freedom_act_to_curb_nsa_spying_excesses/

Android busted for carrying Fake ID: OS doesn't check who really made
that 'Adobe' plugin
Versions 2.1 to 4.4 vulnerable to masquerading malware
http://www.theregister.co.uk/2014/07/29/android_fake_id_certificate_chain_bug/

BlackBerry: We'll buy Angela Merkel's phone security company. HA!
Secusmart apparently to BOOST rep for snoop-proofness
http://www.theregister.co.uk/2014/07/29/blackberry_secusmart_slurp/

Only '3% of web servers in top corps' fully fixed after Heartbleed
snafu
Just slapping a patched OpenSSL on a machine ain't going to cut it,
we're told
http://www.theregister.co.uk/2014/07/29/only_3_of_top_firms_fully_patched_against_heartbleed_flaw/

14 antivirus apps found to have security problems
Vendors just don't care, says researcher, after finding basic boo-boos
in security software
http://www.theregister.co.uk/2014/07/29/antivirus_blood_splattered_as_biz_warned_audit_or_die/

Malware gets your Android blabbering to HACKERS
Boffins get your mobe to spill the beans using Google text-to-speech
kit
http://www.theregister.co.uk/2014/07/29/bump_in_the_night_nope_its_your_android_blabbering_to_hackers/

Google Maps community competition falls foul of Indian regulations
Oh look! Such a lovely SECRET MILITARY BASE!
http://www.theregister.co.uk/2014/07/29/google_maps_community_competition_falls_foul_of_indian_regulations/

Israel's Iron Dome missile tech stolen by Chinese hackers
Corporate raiders Comment Crew fingered for attacks
http://www.theregister.co.uk/2014/07/29/iron_dome_missile_shield_hacked_by_china/

Secure microkernel that uses maths to be 'bug free' goes open source
Hacker-repelling, drone-protecting code will soon be yours to tweak as
you see fit
http://www.theregister.co.uk/2014/07/28/aussie_droneprotecting_hackerdetecting_kernel_goes_open_source/


*** Whitepaper ***

Achieving security with cloud data protection
More and more companies recognize the value and convenience of using cloud backup to protect their server data. But what are the security concerns?
http://whitepapers.theregister.co.uk/d/d3b/9e7f3/781/fe3e9600?td=week_sec_e



------------------------------------------------------------------------

This email was sent to garn14.tech@blogger.com

To change your email or your email subscriptions

http://account.theregister.co.uk/login/

To unsubscribe from all The Register newsletters

http://account.theregister.co.uk/unsubscribe/649203/acc978a1

The Register and its contents are Copyright © 2014 Situation Publishing.
All rights reserved.

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.