Skip to main content

Security

Hacker-Turned-FBI Informant Sabu Has Sentencing Postponed for Seventh Time

posted onMay 8, 2014
by l33tdawg

It seems like the FBI is not quite finished with one of its most valuable assets, Hector Monsegur (aka Sabu) the former Anonymous and LulzSec member who had his sentencing postponed for a seventh time on Wednesday.

Monsegur was due before Judge Loretta Preska in New York on Thursday but he has once again had his sentencing postponed according to sources speaking to the Daily Beast website.

Instagram 'image viewer' apps pose a greater risk than phishing websites

posted onMay 8, 2014
by l33tdawg

Malwarebytes has warned Instagram users that downloading third-party applications that enable them to download their Instagram photos and videos to desktop machines could expose them to a number of security vulnerabilities.

Malwarebytes said that the possible threats - files and websites alike - that take advantage of a software's popularity could spell bad news for users in terms of internet congestion, unwanted redirection to websites and possible installation of other programs without the user's consent.

iOS 7 flaw bypasses lock screen, lets anyone access your contact list

posted onMay 8, 2014
by l33tdawg

Security issues with iOS 7 seem to be popping up everywhere. Last week, we reported that iOS 7 suffered from a bug which left email attachments unencrypted -- and while Apple has prepared a fix for the issue, a new one has appeared in its place.

According to Egyptian neurosurgeon and part-time security researcher Sherif Hashim, a flaw in iOS 7's Siri voice assistant allows anyone to bypass the iPhone lock screen and access the contact list. In a video posted on his YouTube channel, Hashim detailed the method of attack.

Serious security flaw in OAuth, OpenID discovered

posted onMay 8, 2014
by l33tdawg

Following in the steps of the OpenSSL vulnerability Heartbleed, another major flaw has been found in popular open-source security software. This time, the holes have been found in the log-in tools OAuth and OpenID, used by many websites and tech titans including Google, Facebook, Microsoft, and LinkedIn, among others.

Syrian Electronic Army Hijacks WSJ Twitter Accounts

posted onMay 7, 2014
by l33tdawg

The Syrian Electronic Army has hijacked a total of four Twitter accounts of the Wall Street Journal (WSJ) and has posted a message claiming that Ira Winker is a cockroach.

The Syrian hacktivists hijacked the WSJ Africa (@wsjafrica), the WSJ Europe (@wsjeurope), the WSJ Vintage (@vsjvintage), and the WSJ.D (@wsjd) Twitter accounts, Poynter reported. They posted the message “@Irawinkler is a cockroach,” along with a picture of Ira Winkler’s head on the body of a cockroach.

DrawQuest closes down after suffering a security breach

posted onMay 6, 2014
by l33tdawg

DrawQuest, the iPad that lets users channel their creativity through drawing, has been living on its last legs since early this year and now it has closed down with immediate effect after suffering a security breach.

Founder Chris Poole, who also started 4Chan, first announced the closure of DrawQuest in January but there was later optimism that it would be able to continue running for users for “as long as possible,” despite its team all moving to new work. A hack on its Amazon-hosted servers has proved to be the final nail in its coffin, however.

High school senior charged with hacking report-card system

posted onMay 5, 2014
by l33tdawg

An 18-year old student appeared before a judge Friday after he was arrested for allegedly changing grades for students in a Northwest Miami-Dade school.

Miami School Board Police arrested Jose Bautista on Thursday after the principal turned him in. He faces charges of intellectual property offense, modifying programs and an offense against computer users.

Details of IE zero-day exploit published

posted onMay 2, 2014
by l33tdawg
Credit: en.wikipedia.org/wiki/Internet_Explorer

Now that the IE zero day which caused so much panic over the last several days has been patched, researchers are much more free to discuss details of the attack.

Cisco's Snort IPS network shows that their customers began on April 24 with several phishing attacks.

The attack relies on getting a user to visit a web site with the malicious code and this was the purpose of the phishing emails. Cisco found these subject lines used in the attacks:

John McAfee Releases 'Chadder' Secure Messaging App

posted onMay 2, 2014
by l33tdawg

If anyone knows a thing or two about avoiding prying eyes, it's John McAfee.

After managing to elude Belizean authorities in an epic real-life murder drama last year, the antivirus pioneer is now looking to help you keep your own communications under wraps. In partnership with Rochester, N.Y.-based startup Etransfr, McAfee's software development company Future Tense Systems on Friday unveiled a new secure messaging app, dubbed Chadder.