Sunday, August 11, 2013

The Reg Security: NSA gets burned by a sysadmin, decides to burn 90% of its sysadmins [Mon Aug 12 2013]

Dear etechnews today,

Your weekly security newsletter from theregister.co.uk
for the week ending 12th August 2013


*** Security News ***

Android bug batters Bitcoin wallets
Old flaw, new problem
http://www.theregister.co.uk/2013/08/12/android_bug_batters_bitcoin_wallets/

NSA to world: we're only watching 1.6% of internet
Trust us: we're hardly paying attention to the stuff we do collect
http://www.theregister.co.uk/2013/08/12/nsa_says_it_only_watches_one_point_six_per_cent_of_the_internet/

Admins warned: Drill SSL knowledge into your Chrome users
Google research finds whopping SSL click-through rates
http://www.theregister.co.uk/2013/08/10/chrome_ssl_clickthrough_report/

Second LulzSec Sony website hacker starts a year in the cooler
And 21-year-old must do 1,000 hours unpaid work, cough up $600k to
media goliath... lulz?
http://www.theregister.co.uk/2013/08/09/lulzsec_hacker_jailed/

NSA gets burned by a sysadmin, decides to burn 90% of its sysadmins
Need to end planet-wide-snooping leaks? That'll do the trick, thinks US
spymaster
http://www.theregister.co.uk/2013/08/09/snowden_nsa_to_sack_90_per_cent_sysadmins_keith_alexander/

Serious Farce Office: 32K secret BAE probe files spaffed to WRONG bod
Anti-fraud squad coughs to stunning evidence leak blunder
http://www.theregister.co.uk/2013/08/09/serious_fraud_office_makes_seriously_stupid_mistake/

Silent Circle shutters email service
Follows Lavabit in closing down service it can't guarantee to be secure
http://www.theregister.co.uk/2013/08/09/silent_circle_shutters_email_service/

Mozilla links Gmail with Persona for email-based single sign-on
Usernames and passwords not needed
http://www.theregister.co.uk/2013/08/09/persona_identity_bridge_for_gmail/

Snowden's secure email provider Lavabit shuts down under gag order
Won't be 'complicit in crimes against the American people'
http://www.theregister.co.uk/2013/08/08/lavabit_shuts_down/

Child abuse ransomware tweaked to tout bogus antivirus saviours
Crass, fiendish and no doubt a good money-spinner
http://www.theregister.co.uk/2013/08/08/ransomware_scareware_hybrid_scam/

HP plugs password-leaking printer flaw
Bad news: Most office bods won't patch it. Good news: Most office bods
won't find password
http://www.theregister.co.uk/2013/08/08/hp_plug_password_leaking_printer_vuln/

Blogs with 'weakest of the weak' passwords hijacked for bot army
Wordpress, Joomla, Datalife Engine - they're all under cyber-crims'
control
http://www.theregister.co.uk/2013/08/08/fort_disco_bruteforce_blog_attack/

So, you gonna foot this '$200bn' hacking bill, insurance giants asked
Cyber-cleanups of cyber-raids on Uncle Sam's cyber-assets cost
cyber-amounts of cash
http://www.theregister.co.uk/2013/08/08/obama_sets_out_plans_to_insure_firms_against_hack_attacks/

Chrome, Firefox blab your passwords in a just few clicks: Shrug, wary
or kill?
Vote now: Browsers reveal logins on idle PCs, but is it a code flaw or
a brain bug?
http://www.theregister.co.uk/2013/08/08/browser_password_poll/

Infosec analysts back away from 'Feds attacked Tor' theory
Those IP addresses we said belong to the NSA? We were probably wrong
http://www.theregister.co.uk/2013/08/08/infosec_analysts_back_away_feds_attacked_tor_theory/

Malicious snoopware targeting India found at tiny Midwest ISP
'Official' decoys hide potential espionage campaign
http://www.theregister.co.uk/2013/08/07/india_cyberespionage/

Suspected brains behind bank-account-draining Gozi extradited to US
Latvian gov votes to ship alleged Trojan co-conspirator to New York
http://www.theregister.co.uk/2013/08/07/gozi_trojan_suspect_extradition/

Hacktivists torch C4's Jon Snow's web diary, reveal 'nuke strike' on
Syria
Breaking news, literally
http://www.theregister.co.uk/2013/08/07/c4_hacktivist_defacement/

Twitter hardens two-factor authentication with app-based secure logins
SMS, phone number no longer needed
http://www.theregister.co.uk/2013/08/07/twitter_hardens_two_factor_authentication/

Stop! Yammer time: Microsoft blats biz babble account hijacking bug
You can't touch this other users' logins, Miss Hacker
http://www.theregister.co.uk/2013/08/06/yammer_authentication_flaw/

Horrific moment curvy mum-of-none Mail Online spills everyone's data
'Once you go cyber, they got you by the short n curlies' - DM
commentard
http://www.theregister.co.uk/2013/08/06/daily_mail_data_breach/

Hey, you know Android apps can 'access ALL' of your Google account?
One-click login hands over keys to Gmail, Google Drive et al, says
researcher
http://www.theregister.co.uk/2013/08/06/android_oneclick_authentication_open_to_hacking/

Windows Phones BLAB passwords to hackers, thanks to weak crypto
Rogue Wi-Fi hotspots can hoover up and CRACK encrypted login info
http://www.theregister.co.uk/2013/08/06/microsoft_win_phone_wifi_vuln/

Did a bunch of bankers fax a stranger's sensitive privates to YOU?
Bank fined £75K for 3-year fail.. and, er, you've got a FAX MACHINE?
http://www.theregister.co.uk/2013/08/06/bank_of_scotland_fax_blunder_fine/

REVEALED: Cyberthug tool that BREAKS HSBC's anti-Trojan tech
Browser lockdown method also used by PayPal
http://www.theregister.co.uk/2013/08/06/trusteer_pushes_updates_after_cybercrook_brew_up_browser_lockdown_exploit/

Tor fingers Firefox flaw for FAIL but FBI's also in the frame
Malware means 'attacker now has a list of vulnerable Tor users'
http://www.theregister.co.uk/2013/08/06/tor_fingers_firefox_for_fail/

They don't recognise us as HUMAN: Disability groups want CAPTCHAs
killed
Oz advocay group floats non-W3C-approved alternative
http://www.theregister.co.uk/2013/08/05/disability_groups_want_captchas_rendered_extinct/

Posh potty owners flushed by dodgy Bluetooth password
Power behind the throne
http://www.theregister.co.uk/2013/08/05/posh_potty_owners_left_flushed_by_poor_bluetooth_password/

Child porn hidden in legit hacked websites: 100s redirected to sick
images
So warns the Internet Watch Foundation
http://www.theregister.co.uk/2013/08/05/iwf_business_sites_hacked_to_host_images/

Bad timing: New HTML5 trickery lets hackers silently spy on browsers
Sub-millisecond precision in your rendering engine. What could possibly
go wrong?
http://www.theregister.co.uk/2013/08/05/html5_timing_attacks/

Earn £8,000 a MONTH with bogus apps from Russian malware factories
DIY SMS-scam kits anyone can use - even your grandparents!
http://www.theregister.co.uk/2013/08/05/mobile_malware_lookout/

Lumpy milk and exploding yoghurt? Your fridge could be riddled with
MALWARE
Security bod predicts future where virus writers steal your lunch
http://www.theregister.co.uk/2013/08/05/food_gone_rotten_perhaps_your_fridge_has_got_a_virus/



RSA Conference Europe

Over 70 information security track sessions plus debates and keynotes.
Build your knowledge and further your career.

http://reg.cx/26Xk




------------------------------------------------------------------------

This email was sent to garn14.tech@blogger.com

To change your email or your email subscriptions

http://account.theregister.co.uk/login/

To unsubscribe from all The Register newsletters

http://account.theregister.co.uk/unsubscribe/649203/acc978a1

The Register and its contents are Copyright © 2013 Situation Publishing.
All rights reserved.

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.