Sunday, November 16, 2014

Annus HORRIBILIS for TLS! ALL the bigguns now officially pwned in 2014 [ Mon Nov 17 2014]

Dear etechnews today,

Your weekly security newsletter from theregister.co.uk
for the week ending 17th November 2014

Advertisement

Nullcon International Security Conference,Goa ,4-7 Feb 2015

Our motto - 'The neXt security thing' drives the objective of the conference i.e. to discuss and showcase the future of information security, offensive and defensive security technology.
More info:- http://reg.cx/2d3h
20% Discount Code:- THEREG2015




*** Security News ***

Meet OneRNG: a fully-open entropy generator for a paranoid age
Kiwis to seek random investors for crowd-funded randomiser
http://go.reg.cx/ml/9e7f3/549218ff/1384f1bb/2d9q

VXers Shellshocking embedded BusyBox boxen
It's 2014 and some people are still using default user names and
passwords
http://go.reg.cx/ml/9e7f3/549218ff/1384f1bb/2d9p

You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
http://go.reg.cx/ml/9e7f3/549218ff/1384f1bb/2d9j

EVERYTHING needs crypto says Internet Architecture Board
Calls for all new protocols to protect privacy, all the time,
everywhere
http://go.reg.cx/ml/9e7f3/549218ff/1384f1bb/2d9f

Oi, Europe! Tell US feds to GTFO of our servers, say Microsoft and pals
By writing a really angry letter about how it's harming our cloud
business, ta
http://go.reg.cx/ml/9e7f3/549218ff/1384f1bb/2d8K

Apple: Want a PATCH for iOS Masque attack? TOUGH LUCK, FANBOI
Nobody has been affected, says firm
http://go.reg.cx/ml/9e7f3/549218ff/1384f1bb/2d8G

HSBC Turkey WON'T reissue cards despite 2.7 MILLION account details
going AWOL
Not enough info stolen to make fraud possible, says bank
http://go.reg.cx/ml/9e7f3/549218ff/1384f1bb/2d8g

Poll trolls' GCHQ script sock puppets manipulate muppets
Stop and Thinkst: Is that really the Most Popular story or did haxxors
Bash it out?
http://go.reg.cx/ml/9e7f3/549218ff/1384f1bb/2d88

Dormant IP addresses RIPE for hijacking
'That's not us spamming, honest' cries hosting firm
http://go.reg.cx/ml/9e7f3/549218ff/1384f1bb/2d83

US Marshals commit DIRTBOX INTRUSION on Americans, says report
Mobe-tracking planes deployed across country
http://go.reg.cx/ml/9e7f3/549218ff/1384f1bb/2d80

US carder gets nine years in cooler, must pay back $50 MEELLION
Department of Justice goes gangbusters in pursuit of carder.su crims
http://go.reg.cx/ml/9e7f3/549218ff/1384f1bb/2d7Y

Lads from Lagos using 'Predator Pain' on hapless 419 victims
Emails from thieving RATs contain keyloggers
http://go.reg.cx/ml/9e7f3/549218ff/1384f1bb/2d7G

UK.gov teams up with moneymen on HACK ATTACK INSURANCE
Cover for biz ... but you'll have to jump through hoops
http://go.reg.cx/ml/9e7f3/549218ff/1384f1bb/2d7x

Pay-by-bonk chip lets hackers pop all your favourite phones
Think your phone is safe? You've got NFC
http://go.reg.cx/ml/9e7f3/549218ff/1384f1bb/2d7e

'Chinese hackers' pop US weather bureau, flatten forecast feeds
NOAA hack was COVERED UP yells congressman
http://go.reg.cx/ml/9e7f3/549218ff/1384f1bb/2d76

ISPs are stripping encryption from netizens' email – EFF
Civil liberties body in shock blog
http://go.reg.cx/ml/9e7f3/549218ff/1384f1bb/2d6R

Yorkshire man NICKS 1,000 Orange customer records. Court issues TINY
FINE
Change the law – chuck baddies in jail, says watchdog
http://go.reg.cx/ml/9e7f3/549218ff/1384f1bb/2d6A

Annus HORRIBILIS for TLS! ALL the bigguns now officially pwned in 2014
Critical crypto nought-day not the worst of mega Nov patch batch
http://go.reg.cx/ml/9e7f3/549218ff/1384f1bb/2d6x

Target, Home Depot and UPS attacks: Dude, you need to rethink
point-of-sale security
BlackPOS, FrameworkPOS, Backoff probed
http://go.reg.cx/ml/9e7f3/549218ff/1384f1bb/2d6v

Cybersecurity? Nothing to do with us, mate – Google and Facebook
Industry lobby group begs EU to ditch new cyber law
http://go.reg.cx/ml/9e7f3/549218ff/1384f1bb/2d6d

DAY ZERO, and COUNTING: EVIL 'UNICORN' all-Windows vuln - are YOU
patched?
We will all remember the 11th of November
http://go.reg.cx/ml/9e7f3/549218ff/1384f1bb/2d6a

Iranian contractor named as Stuxnet 'patient zero'
Hell-worm targeted five companies before plundering Natanz
http://go.reg.cx/ml/9e7f3/549218ff/1384f1bb/2d5X

Patch Windows boxes NOW – unless you want to be owned by a web page or
network packet
Someone, come up with a catchy logo for this SSL hole
http://go.reg.cx/ml/9e7f3/549218ff/1384f1bb/2d5P

Most convincing PHISHING pages hoodwink nearly half of you – Google
Please update your details...
http://go.reg.cx/ml/9e7f3/549218ff/1384f1bb/2d5z

German spies want millions of Euros to buy zero-day code holes
Because once we own them, nobody else can ... oh, wait
http://go.reg.cx/ml/9e7f3/549218ff/1384f1bb/2d5c

British drones target ISIS for the first time
Reasons to fear the Reaper
http://go.reg.cx/ml/9e7f3/549218ff/1384f1bb/2d5a

EMET 5.0 crashes Patch Tuesday party
Patch this and this and this and this
http://go.reg.cx/ml/9e7f3/549218ff/1384f1bb/2d57

Hacker Hammond's laptop protected by pet password
'Chewy123' easy as ABC
http://go.reg.cx/ml/9e7f3/549218ff/1384f1bb/2d55

Mozilla makeover to boost Tor torque, capacity
Privacy pundits launch Polaris project
http://go.reg.cx/ml/9e7f3/549218ff/1384f1bb/2d54

Names, ages, addresses, SSNs of US postal staff slurped in 'mega-hack'
Beware of the dog ... or the dragon?
http://go.reg.cx/ml/9e7f3/549218ff/1384f1bb/2d4U

Got an iPhone or iPad? LOOK OUT for MASQUE-D INTRUDERS
UNjailbroken iOS 7, 8 open to evil, says secbiz FireEye
http://go.reg.cx/ml/9e7f3/549218ff/1384f1bb/2d4R

Feeling safe in your executive hotel suite, Mr CEO? Well, DON'T
Corporate bosses clobbered on luxury venue networks by 'Darkhotel'
http://go.reg.cx/ml/9e7f3/549218ff/1384f1bb/2d4P

BrowserStack HACK ATTACK: Service still suspended after rogue email
Admits breach, but only within email address list
http://go.reg.cx/ml/9e7f3/549218ff/1384f1bb/2d4K

Someone has broken into your systems. Now what?
Never let a good crisis go to waste
http://go.reg.cx/ml/9e7f3/549218ff/1384f1bb/2d4B

Aussie feds consider job offer to 'LulzSec leader' who wasn't
Man jailed for simple website defacement protests his technical
impotence
http://go.reg.cx/ml/9e7f3/549218ff/1384f1bb/2d4n

Emoticons blast three security holes in Pidgin :-(
Dump docs on users' disks using only ASCII art (°O°)
http://go.reg.cx/ml/9e7f3/549218ff/1384f1bb/2d4j


*** Whitepaper ***

The Heartbleed Bug: how to protect your business with Symantec
What happens when the next Heartbleed (or worse) comes along, and what can you do to weather another chapter in an all-too-familiar string of debilitating attacks?
http://whitepapers.theregister.co.uk/d/dd7/9e7f3/7ea/0ba033fa?td=week_sec_e



------------------------------------------------------------------------

This email was sent to garn14.tech@blogger.com

To change your email or your email subscriptions

http://account.theregister.co.uk/login/

To unsubscribe from all The Register newsletters

http://account.theregister.co.uk/unsubscribe/649203/acc978a1

The Register and its contents are Copyright © 2014 Situation Publishing.
All rights reserved.

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.