Friday, 10 February 2017

Wordpress blogs defaced in hack attacks

A security flaw in the WordPress blogging software has let hackers attack and deface tens of thousands of sites.
One estimate suggests more than 1.5 million pages on blogs have been defaced.
The security firm that found the vulnerability said some hackers were now trying to use it to take over sites rather than just spoil pages.
WordPress urged site owners to update software to avoid falling victim.
Feeding frenzy
The vulnerability is found in an add-on for the WordPress blogging software that was introduced in versions released at the end of 2016.
Security firm Sucuri found the "severe" bug and informed WordPress about it on 20 January.
In a blogpost, WordPress said it delayed going public about the flaw so it could prompt hosting firms to update their software to a fixed version.
The patched version of WordPress was formally released on 26 January and led to many sites and blogs automatically applying the update.
However, many blogs have not followed suit leaving them open to defacement attacks.
Security firm WordFence said it had seen evidence that 20 hacker groups were trying to meddle with vulnerable sites. About 40,000 blogs are believed to have been hit.
The vulnerability had set off a "feeding frenzy" among hacker groups, WordFence founder Mark Maunder told the Bleeping Computer tech news site.
"During the past 48 hours we have seen over 800,000 attacks exploiting this specific vulnerability across the WordPress sites we monitor," he added.
Sucuri said some hacker groups had moved on from defacement to attempts to use the bug to hijack sites for their own ends.
"Attackers are starting to think of ways to monetise this vulnerability," wrote Sucuri founder Daniel Cid. "Defacements don't offer economic returns, so that will likely die soon."
Hackers were keen to use the vulnerable sites as proxies for spam or malware campaigns, he said.

Tuesday, 7 February 2017

TV maker unlawfully tracked viewing habits

TV maker Vizio has agreed to pay out $2.2m in order to settle allegations it unlawfully collected viewing data on its customers.
The US Federal Trade Commission said the company’s smart TV technology had captured data on what was being viewed on screen and transmitted it to the firm’s servers.
The data was sold to third parties, the FTC said.
Vizio has said the data sent could not be matched up to individuals.
It wrote: " [The firm] never paired viewing data with personally identifiable information such as name or contact information, and the Commission did not allege or contend otherwise.
"Instead, as the complaint notes, the practices challenged by the government related only to the use of viewing data in the ‘aggregate’ to create summary reports measuring viewing audiences or behaviours.”
'Second-by-second'
The FTC said the data collection began in February 2014 and affected around 11 million televisions.
"Vizio collected unique data from each household with a Vizio smart TV that included not only second-by-second viewing information, but also the household’s IP address, nearby access points, zip code, and other information,” the FTC said in a blog post explaining the settlement.
"They also shared that information with other companies."
It added: "This settlement stops Vizio’s unauthorised tracking, and makes clear that smart TV makers should get people’s consent before collecting and sharing television viewing information.”
As part of the settlement Vizio agreed to more prominently tell its customers how data is stored and collected, and to seek firmer, clearer consent beforehand. The company has been ordered to delete the data it collected.
Smart TVs - sets that have additional features such as on-demand viewing or video calling - have raised privacy concerns before. In 2015 it emerged Samsung’s models were transmitting potentially sensitive voice data without users’ knowledge.

Uber hires 'flying car engineer' from Nasa

A former Nasa engineer has been hired by taxi-hailing firm Uber to help its research into flying cars.

Mark Moore is joining Uber's Elevate division as its director of engineering for aviation.
Uber's interest in flying cars was outlined in a White Paper in October, which discussed vertical take-off and landing on-demand (VTOL) aviation.
It welcomed Mr Moore's appointment, adding its wider role was as a catalyst to the "growing VTOL ecosystem".
Uber is already investing in self-driving cars, with partnerships with Volvo and Daimler.
In its White Paper, Uber said that on-demand aviation "has the potential to radically improve urban mobility, giving people back time lost in their daily commutes".
"Just as skyscrapers allowed cities to use limited land more efficiently, urban air transportation will use three-dimensional airspace to alleviate transportation congestion on the ground."
It envisaged a network of small, electric aircraft that would take off and land vertically.
Mr Moore explored a similar concept in a paper published while he was at Nasa.
He said that electric propulsion was a "potential game changing technology" for aircraft, adding that the only thing holding it back was current battery storage.
Slovakian company Aeromobil is one of several working on a prototype flying car, which it is aiming to commercialise this year.

Monday, 6 February 2017

Google Surpasses Apple to Become the Most Valuable Brand in the World: Report

Breaking Apple's five-year record, Google has taken the top spot as the most valuable brand in the world. In the latest Brand Finance Global 500 report, Apple comes in second, followed by Amazon, AT&T, Microsoft, Samsung, Verizon, Walmart, Facebook, and ICBC.
Brand Finance's analysts feel that Apple has "over-exploited the goodwill of its customers" and has "repeatedly disillusioned its advocates with tweaks when material changes were expected." Here the report is talking about the minimal changes introduced on iPhone devices year after year. Furthermore, the report says that "the snaking queues of early adopters have shrunk almost to the point of invisibility," and that "Apple's loss has been Google's gain." Google has been given a brand value of $109.47 billion (roughly Rs. Rs. 7,36,016 crores), compared to Apple's $107.141 billion (roughly Rs. 7,20,294 crores)
"Put simply, Apple has over-exploited the goodwill of its customers, it has failed to generate significant revenues from newer products such as the Apple Watch and cannot demonstrate that genuinely innovative technologies desired by consumers are in the pipeline. Its brand has lost its lustre and must now compete on an increasingly level playing field not just with traditional rival Samsung, but a slew of Chinese brands such as Huawei and OnePlus in the smartphone market, Apple's key source of
profitability," the report reads.

Sunday, 5 February 2017

Microsoft Hardens Latest Windows Version Against Hackers

Microsoft has fortified the latest version of Windows to make it more secure than previous editions, but the strongest protections will be available only to those willing to pay a steep price for them.

Windows 10 Anniversary Update has introduced many mitigation techniques in core Windows components and the Microsoft Edge browser, helping protect customers from entire classes of exploits for very recent and even undisclosed vulnerabilities, Matt Oh and Elia Florio of Microsoft's Windows Defender ATP Research Team wrote in an online post last week.

Countering unidentified vulnerabilities -- also known as "zero day" vulnerabilities -- is particularly important because they are a powerful tool used to penetrate systems and steal data by attackers, especially those working for nation-states.

Rather than focus on a single vulnerability, Microsoft is focusing on mitigation techniques that counter classes of exploits, Oh and Florio explained.

"As a result, these mitigation techniques are significantly reducing attack surfaces that would have been available to future Zero-Day exploits," they wrote.

Paying for Protection

For the most effective post-breach protection, customers should sign up for Windows Defender ATP, Oh and Florio suggested, a service that is available only to users of Windows Enterprise E5.

That appears to be a departure from how Windows security was treated in the past, observed Michael Cherry, an analyst with Directions on Microsoft.

When Microsoft launched its Trustworthy Computing initiative in 2002, there was a commitment to making all versions of Windows equally secure, he recalled.

"Now, what Microsoft is saying in a subtle way," Cherry told TechNewsWorld, is that "to be the most secure on Windows, you should be using Windows Defender Advanced Threat Protection -- but we're saving that for our best customers, our customers willing to pay for the enterprise edition. That's a big change that's happening in Windows security."
What Users Get

Nevertheless, the security improvements in the new Windows 10 Anniversary Update are worthwhile for consumers.

"This is great news for users," said Jerome Segura, a senior security researcher for Malwarebytes.

"Microsoft is addressing zero days and exploits in general by sandboxing a lot of the components in the operating system," he told TechNewsWorld.

Sandboxing is a technique used to isolate activity in a space where it can be observed without affecting its surroundings. If it behaves badly in the sandbox, then it won't be allowed to play with the other parts of a system.

Sandbox techniques were used in Windows 10 to neutralize an exploit that used corrupt fonts to gain escalated privileges on a system, Microsoft's Oh and Florio explained. Escalated privileges allow an intruder greater freedom to roam and access data on a network.

Room for Improvement

While Microsoft is making good progress in hardening the Windows kernel, it could improve the operating system's security in other areas, too. One of those areas is third-party applications and components.

"While it's trying to ensure that its operating system is secure, it still depends on Flash, Java and other pieces of software. At the end of the day, the security of the system is going to depend on all the pieces, not just what Microsoft ships," Malwarebytes' Segura observed.

"You can have an OS that's safe, but if you have an outdated Flash plug-in, you can still get infected," he pointed out.

Hackers also are exploiting Microsoft Office documents.

"Microsoft needs to tighten up legacy code like macros -- either disable it or sandbox it," Segura said.

Threat to Security Vendors?

As Windows security improves, will it threaten the security ecosystem that has grown up around the OS?

"Ultimately, Microsoft's new anti-exploit features in Windows calls into question the value of legacy antivirus protections," said Simon Crosby, CTO of Bromium.

"However, it is important to note that relatively few enterprises use Windows 10 yet, so any Microsoft mitigation in Windows 10 that fails to address the legacy Windows installed base cannot address threats targeting [the security ecosystem]," he told TechNewsWorld.

Windows users still need to use antivirus programs, added Jack E. Gold, founder and principal analyst with J.Gold Associates. "Microsoft is pushing its antivirus program," he told TechNewsWorld, "so it's not saying you don't need antivirus anymore."

Tuesday, 31 January 2017

Samsung galaxy S8 coming soon

Samsung could ditch the home button on its upcoming Galaxy S8 phone, making way for a larger screen that fills the front of the device.

Leaked images of the next generation of the Korean electronics giant's flagship handset show it could have a large display with curved edges and a selfie camera right at the top.

The pictures also dispel any suggestions that Samsung is planning to ditch the 3.5mm headphone jack.
The Galaxy S8 will come in two sizes with 5.8-inch and 6.2-inch versions, according to prominent leaker Evan Blass, who posted the alleged pictures of the phone. The screen will take up 83pc of the front of the phones when switched on and will use AMOLED technology. It could also be pressure sensitive, following Apple's lead with 3D Touch.

Samsung has taken the popular curved design from the Edge versions of earlier models for all of the handsets.

The front-facing camera on the phone will be 8MP, with the one on the rear next to the fingerprint sensor 12MP. The main camera could have a new augmented image search that lets users search the web for items they point it at. For example, it could take them to a shopping website for a product in the frame. 

Next to the selfie camera is a second iris scanning sensor, first found on the recalled Note 7, which will let users unlock their phone by looking at it.

The phones are expected to run Android Nougat, the latest version of the Google-made software. They could feature the first application for Samsung's yet-to-be-unveiled virtual intelligent assistant, which rumours say will be called Bixby.

They will be 11pc faster and 20pc more energy efficient than the Galaxy S7, Venture Beat reports, thanks to improved microchip and graphics technology. It comes with the ability to connect to a monitor so to control the phone with a keyboard and mouse, the Guardian reports.

WhatsApp to let users edit and recall sent messages

WhatsApp could soon introduce the ability to recall sent messages, easing the minds of people that regularly panic after sending texts by mistake.

The long-awaited feature will mean that users can delete a message from the receivers phone if it is yet to be read. The delete function is currently being tested on the beta version of WhatsApp's next update, along with the ability to edit send messages that haven't been read.

Features are generally included in beta versions before making them into a full consumer release, although it is unclear when this might be.

As well as these edit tools, WhatsApp is also testing a new feature that could make it a lot easier to coordinate meeting a group of friends.

A new feature unique to WhatsApp is being tested that lets users send friends their moving location so that they can find one another more easily.

Called Live Location Tracking, it lets users show their movements to friends within a group chat. They can opt to share their moving position for a limited time of one, two or five minutes.

It builds on WhatsApp's popular send your location feature that allows users to share their exact position at a given time.
WhatsApp users will probably have to manually turn it on in Settings, allaying privacy fears. It is currently being tested in the beta version of the messaging app's next update, meaning that it could soon be released to all users, although no time frame has been announced.

Other features being tested in the beta include the ability to reply to status messages, as well as shaking you phone within a conversation to contact WhatsApp and report spam.

One of its biggest focuses recently has been to add live features that take it beyond text messaging, such as video calling. It also recently added the ability to edit pictures and draw on them, in a similar way to Snapchat.