Monday, September 15, 2014

Leak of '5 MEELLLION Gmail passwords' creates security flap [ Mon Sep 15 2014]

Dear etechnews today,



Your weekly security newsletter from theregister.co.uk

for the week ending 15th September 2014



Advertisement



Nordic IT Security

November 5 2014, Stockholm , Sweden .- http://reg.cx/2c1Z

Claim your Reg reader 30% discount - using code THEREG30 in the booking form: http://reg.cx/2c22







*** Security News ***



Hackers pop Brazil newspaper to root home routers

Step One: try default passwords. Step Two: Repeat Step One until

success

http://www.theregister.co.uk/2014/09/15/hackers_pop_brazil_paper_to_root_home_routers/



New Snowden leak: US and Brit spooks 'tap into German telco networks to

map end devices'

Deutsche Telekom: 'completely unacceptable, if true'

http://www.theregister.co.uk/2014/09/14/snowden_leaks_alleged_treasure_map_programme_for_nsa_and_gchq_to_spy_on_german_telecoms/



Apple Pay is a tidy payday for Apple with 0.15% cut, sources say

Cupertino slurps 15 cents from every $100 purchase

http://www.theregister.co.uk/2014/09/13/apple_to_get_15_cents_for_every_100_dollar_payment_on_its_pay_service_says_ft/



Not pro Bono: Apple's audio junk mail made spammers' lives easier

The U in U2 stands for Unwanted

http://www.theregister.co.uk/2014/09/13/apple_u2_push_security_risk/



Beware geeks bearing gifts: Steam-draining nasty spreads via Twitch

Eskimo infection will drop you right Inuit

http://www.theregister.co.uk/2014/09/12/twitch_spam_spreading_malware_that_drains_steam_accounts/



iPhone NFC: 'Apple, photos and security ... WHAT could go WRONG?'

Plus: 'Naturism ... you don't need to be totally naked'

http://www.theregister.co.uk/2014/09/12/quotw_ending_september_13/



CryptoLocker-style ransomware booms 700 PER CENT this year

Even as cops crow over decapitated hydra, new versions spring up

unchecked

http://www.theregister.co.uk/2014/09/12/file_scrambling_ransomware_plague/



UK.gov's flagship infosec program ISN'T DELIVERING - but all's still

well, say auditors

'Varied' understanding is no barrier to £860m cash pile

http://www.theregister.co.uk/2014/09/12/uk_cyber_security_strategy/



What kind of mugs do you take us for? Malicious sites in spam scams

target UK

Blighty tops phishermen's friend index

http://www.theregister.co.uk/2014/09/12/phishing_threat_index/



spɹɐʍʞɔɐB writing is spammers' new mail filter avoidance trick

Sexe.doc? More like Scod.exe

http://www.theregister.co.uk/2014/09/12/backwards_writing_new_bulk_email_trick/



Hacker publishes tech support phone scammer slammer

Now who's got a 'security problem on your computer'?

http://www.theregister.co.uk/2014/09/12/phone_scammer_slammer/



NORKS ban Wi-Fi and satellite internet at embassies

Crackdown on tardy diplomatic sysadmins providing accidental unfiltered

internet access

http://www.theregister.co.uk/2014/09/12/norks_bans_wifi_and_satellite_internet_at_embassies/



US! govt! ordered! Yahoo! to! hand! over! user! data! or! pay! $250k!

fine! PER! DAY!

That's gotta be worth a few exclamation marks

http://www.theregister.co.uk/2014/09/12/us_government_threatened_yahoo_with_250000_per_day_fine/



5 Nigerian gangs dominate Craigslist buyer scams

Likely Lads from Lagos still skilled at parting fools from money

http://www.theregister.co.uk/2014/09/11/nigerian_gangs_dominate_craiglist_scams/



Intellifridge terror: Internet of Stuff kit must fend off hackers of

the FU-TURE-TURE-TURE

Security with 10-year lifespan needed

http://www.theregister.co.uk/2014/09/11/iot_security_study_beecham/



This flashlight app requires: Your contacts list, identity, access to

your camera...

Who us, dodgy? Vast majority of mobile apps fail privacy test

http://www.theregister.co.uk/2014/09/11/mobile_app_privacy_survey/



Leak of '5 MEELLLION Gmail passwords' creates security flap

You should be OK if you're not using ANCIENT password

http://www.theregister.co.uk/2014/09/11/gmail_password_leak_flap/



Satellite weather forecast: Cloudy with a chance of p0wnage

Flaws found in ground control for Polar Satellite won't be fixed for

TWO YEARS

http://www.theregister.co.uk/2014/09/11/tomorrows_weather_cloudy_with_a_chance_of_p0wnage/



Microsoft to patch ASP.NET mess even if you don't

We know what's good for you, because we made the mess says Redmond

http://www.theregister.co.uk/2014/09/11/microsoft_kills_dangerous_aspnet_setting_for_good/



PayPal goes crypto-currency with Bitcoin

eBay no Silk Road

http://www.theregister.co.uk/2014/09/11/paypal_goes_cryptocurrency_with_bitcoin/



TorrentLocker unpicked: Crypto coding shocker defeats extortionists

Lousy XOR opens door into which victims can shove a foot

http://www.theregister.co.uk/2014/09/11/torrentlocker_contains_freeunlock_crypto_shocker/



Webmin hole allows attackers to wipe servers clean

No RCE, but lots of Unix DDoS fun

http://www.theregister.co.uk/2014/09/11/webmin/



2016: Robo-butlers, flying cars, and Google's internet Terminators

hunting SHA-1 SSL certs

More likely: World War III and discount smartwatches

http://www.theregister.co.uk/2014/09/10/google_sha_1_2016/



Payment security bods: Nice pay-by-bonk (hint: NO ONE uses it) on

iPhone 6, Apple

Retailers won't lose sales 'cos they can't take mobe payments

http://www.theregister.co.uk/2014/09/10/apple_pay_reaction/



Troll or thief? User claims Bitcoin founder Satoshi Nakamoto dox

sabotage

Ransoming Nakamoto's dox over Pastebin? Really?

http://www.theregister.co.uk/2014/09/10/troll_or_thief_user_claims_satoshi_dox_sabotage/



YouTube, Amazon and Yahoo! caught in malvertising mess

Cisco says 'Kyle and Stan' attack is spreading through compromised ad

networks

http://www.theregister.co.uk/2014/09/10/big_names_caught_in_kyle_and_stan_malicious_ad_attack/



OpenSSL promises devs advance notice of future bugs, slaps if they blab

Future Heartbleeds without the heartache

http://www.theregister.co.uk/2014/09/10/openssl_to_open_up_about_bugs/



Comcast using JavaScript to inject advertising from Wi-Fi hotspots

They're not ads but watermarks, telco insists

http://www.theregister.co.uk/2014/09/10/comcast_using_javascript_to_inject_advertising_from_wifi_hotspots/



Microsoft tells judge: Hold us in contempt of court, we're NOT giving

user emails to US govt

Says it still won't give feds access to Ireland data center

http://www.theregister.co.uk/2014/09/10/microsoft_contempt_of_court/



Microsoft unloads monster-sized can of bug spray on Internet Explorer,

again

Another month, another 37 vulnerabilities to fix

http://www.theregister.co.uk/2014/09/09/september_patch_tuesday/



Phishing miscreants THWART securo-sleuths with AES-256 crypto

Well, at least someone listened to Snowden about privacy...

http://www.theregister.co.uk/2014/09/09/phishing_scam_uses_aes_crypto_to_hide/



Use home networking kit? DDoS bot is BACK... and it has EVOLVED

OMG, it reconfigures your firewall... SAVE yourselves, Linux lords

http://www.theregister.co.uk/2014/09/09/linux_modem_bot/



Greater dev access to iOS 8 will put us AT RISK from HACKERS

Knocking holes in Apple's walled garden could backfire, says

securo-chap

http://www.theregister.co.uk/2014/09/09/ios_8_more_dev_access_increases_risks/



Ultimate hardware hack: Home Depot nailed by vice merchants

BlackPOS 'Target' malware implicated

http://www.theregister.co.uk/2014/09/09/home_depot_fesses_up_indicates_april_hack/



Enigmail PGP plugin forgets to encrypt mail sent as blind copies

User now 'waiting for the bad guys come and get me with their

water-boards'

http://www.theregister.co.uk/2014/09/09/enigmail_encryption_error_prompts_plaintext_panic/



Everyone taking part in Patch Tuesday step forward. NOT SO FAST, Adobe!

Critical fix will have to wait a few days

http://www.theregister.co.uk/2014/09/09/everyone_taking_part_in_patch_tuesday_step_forward_not_so_fast_adobe/



China is now 99.8% sure you're you, thanks to world's-best facial

recognition wares

Travelling to Beijing? Better grow a mo, horns, pack on some pounds and

pray

http://www.theregister.co.uk/2014/09/09/china_builds_998_accurate_facial_recog_system/



Salesforce: Oh no! Dyre RATs are thirsty for our customers' logins

But attacks weren't the cause of server outage, we're told

http://www.theregister.co.uk/2014/09/08/salesforcecom_warns_users_they_are_the_target_for_new_rat_dyre/



Snowden shouldn't be extradited to US if he testifies about NSA spying,

says Swiss gov

Extradition could be off the cards, says attorney general

http://www.theregister.co.uk/2014/09/08/edward_snowden_should_not_be_extradited_to_us_he_testfies_about_surveillance_in_switzerland_says_attorney_general/



Celeb nudie iCloud pervs hatched photo-slurping Flappy Bird plot

July plan would have seen Flappy fappening

http://www.theregister.co.uk/2014/09/08/icloud_hackers_mull_malware_follow_up/



Dodgy Norton update borks UNDEAD XP systems

Securo-bods: 'Turn off browser protection... that might help'

http://www.theregister.co.uk/2014/09/08/dodgy_norton_update_hits_win_xp/



Mozilla certification revocation: 107,000 websites sunk by untrusted

torpedo

Abandon hope all ye who click here

http://www.theregister.co.uk/2014/09/08/107000_dodgy_sites_struck_by_mozilla_untrusted_torpedo/



Nude celeb pics wrongly blamed for DDOS at New Zealand's largest ISP

Actual culprit appears to be silly router configurations and

Euro-nasties

http://www.theregister.co.uk/2014/09/08/nude_celeb_pics_wrongly_blamed_for_ddos_at_new_zealands_largest_isp/





*** Whitepaper ***



Achieving security with cloud data protection

More and more companies recognize the value and convenience of using cloud backup to protect their server data. But what are the security concerns?

http://whitepapers.theregister.co.uk/d/d3b/9e7f3/7ab/41cea695?td=week_sec_e







------------------------------------------------------------------------



This email was sent to garn14.tech@blogger.com



To change your email or your email subscriptions



http://account.theregister.co.uk/login/



To unsubscribe from all The Register newsletters



http://account.theregister.co.uk/unsubscribe/649203/acc978a1



The Register and its contents are Copyright © 2014 Situation Publishing.

All rights reserved.

No comments:

Post a Comment