Posted by John Barrett on January 28, 2012 ·
Recently Microsoft released several security patches for a vulnerability discovered in Windows Media components in their Microsoft Security Bulletin MS12-004 – Critical. The vulnerability affects more or less all Windows operating systems 32 and 64 bits starting with Windows XP SP3, ending with Windows 7 and Windows Server 2008 R2 and consists in allowing of remote code execution when a specially crafted MIDI file is handled by Windows Media Player or DirectShow.
Affected Windows operating [...]
Posted by Slippery Slim on January 28, 2012 ·
Symantec has identified multiple publisher IDs on the Android Market that are being used to push out Android.Counterclank. This is a minor modification of Android.Tonclank, a bot-like threat that can receive commands to carry out certain actions, as well as steal information from the device.
Source
What started out as a way to provide a cheaper phone is now becoming a headache. Licensing is a heavy hitter in the cost of a phone. Manufactures pay serious money to use propitiatory software by Apple [...]
Posted by Slippery Slim on January 23, 2012 ·
The talk presented the findings of “Project Basecamp,” a volunteer-led security audit of leading programmable logic controllers (PLCs). The audit found that decrepit hardware, buggy software and pitiful or nonexistent security features make thousands of PLCs vulnerable to trivial attacks by external hackers that could cause PLC devices to crash or run malicious code.
Source
This opens a whole new field of malware attack area of opportunity. It’s been coming for a long time with [...]
Posted by John Barrett on January 20, 2012 ·
Megaupload.com , the well known file-sharing website was taken down by authorities(read FBI) and its co-founder Kim Dotcom and several other members from the staff were charged for: Conspiracy to Commit Racketeering, Conspiracy to Commit Copyright Infringement, Conspiracy to Commit Money Laundering, Criminal Copyright Infringement by distributing a Copyrighted Work Being Prepared for Commercial Distribution on a Computer Network & Aiding and Abetting of Criminal Copyright Infringement and Criminal [...]
Posted by Slippery Slim on January 18, 2012 ·
Tokyo, we have a problem
Japanese space engineers have admitted one of their computers has been infected by a Trojan that may have leaked sensitive data, including system login information, to hackers.
Data exposed by the breach may have included emails, technical specifications and operational information as well as login credentials. The space agency has reset potentially exposed passwords while it continues to investigate the scope of the breach.
Source
It’s often in today’s connected [...]
Posted by John Barrett on January 17, 2012 ·
In December 2011 Stefan Viebhock published a report about a vulnerability discovered and analyzed by him in Wi-Fi Protected Setup(WPS) previously known as Wi-Fi Simple Config. Introduced by Wi-Fi Alliance in 2007 year, WPS allows users without an advanced knowledge about Wi-Fi router’s configurations to easily setup their home Wi-Fi networks, adding new devices or enabling the security. The user can add a new device in the wireless network either by pushing a button on both wireless router [...]
Posted by Slippery Slim on January 14, 2012 ·
Viruses stole City College of S.F. data for years
Personal banking information and other data from perhaps tens of thousands of students, faculty and administrators at City College of San Francisco have been stolen in what is being called “an infestation” of computer viruses with origins in criminal networks in Russia, China and other countries, The Chronicle has learned.
“Given the outright mismanagement of our networks, if someone’s information is stolen, are we liable for [...]