Google pays $75000 in bounty, patches 159 security holes in new Chrome 38

Table Of Contents Chrome 38 Googletoday released the latest version of its popular web client Chrome. Google has paid $75000.00 / 59,250.00 in bounty money to these testers. Whats fixed The largest slice of the bounty cake went to security researcher, Juri Aedla. Other fixes Google stated that 113, out of the total 159 security holes. One of the major modifications in Chrome 38 is a new built-in automatic update mechanism....

October 8, 2014 · 1 min · 88 words · Bruce Benitez

Jennifer Lawrence’s Wikipedia Page Defaced to Show ‘au naturel’ Pic

The page was returned to its normal state after no less than 20 minutes. His/her first attempt was more successful and lasted for 14 minutes before the image was deleted. The second attempt only lasted for about 4 minutes. source: www.techworm.net

October 8, 2014 · 1 min · 41 words · Stacy Johnson

Pakistan Peoples Party Website hacked amid Bilawal Bhutto’s controversial Statement

To Citizens of Pakistan, Pakistans Army, Pakistan Peoples Party and Specially Mr. Bilawal Bhutto . Without any Violence Let Me tell you that Pakistan will never Get Kashmir. This is the Truth. The LOC is the de-facto border between India and Pakistan. The resultant cyberware between the hacking communities of respective countries take down and deface the website of each other. A mirror( web cached version) of the deface page can be seen here...

October 8, 2014 · 1 min · 78 words · Dr. Alexis Thompson

USA’s largest bond insurer MBIA Inc suffers a huge data breach due to server misconfiguration

MBIA, Inc. is a financial services company and USAs largest bond insurer. It was founded in 1973 as the Municipal Bond Insurance Association. It is headquartered in Armonk, New York, and has approximately 400 employees. They are also not sure as to how long the server breach existed. The company stated that it had learned of the problem from an outside computer expert Monday. So far, the spokesman said, there was no evidence of suspicious or improper transactions in customer accounts....

October 8, 2014 · 1 min · 148 words · Carol Rogers

#OpHK aka Operation Hong Kong: Anonymous hacks Chinese Government website

Anonymous earlier today hacked and defaced many Hong Kong based websites including few of the Chinese Government websites. Once again the Chinese government strikes hard at its own people. At this very moment Chinese police forces are hurting innocent citizens who cry for liberty. We are only targeting .gov.cn and .gov.hk .mil.cn in opposition to their oppressive ways. We emphatically condemn those attacks against non governmental or non military targets....

October 7, 2014 · 1 min · 135 words · Cynthia Bowman

ABC’s broadcasting systems Taken Off AIR by Ransomware Attack

The email containing the CryptoLocker key in ransomware is spreading far and wide in Australia. What is Crypto-ransomware? Cryptomalware affecting Australian users is from Cryptolocker family. Once the attachment to the email is opened, the payload in the attachment gets executed. How the Crypto-ransomware spread in Australia? Once on the cloned website, the victim is asked to follow procedures to download a zip file. It thenlocks down the computer and asks for a ransom....

October 7, 2014 · 1 min · 76 words · Crystal Perez

Massive Russian QBot banking Trojan botnet claims 500,000 victims

Russian involvement Proofpoint has traced the infrastructure of QBot all the way to Russia. The report says that the cybercriminals obtained the authorised WordPress administrator logins through online legit purchases. Windows XP clients comprised 52 per cent of the infected systems in the cybercrime groups botnet. The cybercrime group also made money by selling access to compromised systems on underground forums. The effects of the QBot banking trojan are not known as of now....

October 7, 2014 · 1 min · 76 words · Barbara Alvarez

Saks Fifth Avenue Department Store insider job, Identity theft causes $400,000 loss

Saks has not named any of the 50 clients whose identity was stolen during this escapade. source: www.techworm.net

October 7, 2014 · 1 min · 18 words · Anthony Humphrey

AT&T Suffers Another Massive Data Breach due to a Inside Job

Inside job again! CPNI is information related to the telecommunications services you purchase from us. How many AT&T customers are affected? However AT&T is not sure what information or how the information was misused. If you havent set up a passcode you are required to set it up ASAP. However only redemption was the fact that the customers data was not financially misused in that breach. source: www.techworm.net

October 6, 2014 · 1 min · 68 words · Mark Gray

BashBug casualty, Hackers exploit Shellshock to breach Yahoo, Lycos & Winzip servers

These unknown hackers then used those hacked servers to probe for other potential victims. Now he has turned into a full time dedicated white hat researcher cum, engineer cum consultant. The box that was probing me was actually a server on the winzip.com domain. A crafted web request targeting a vulnerable CGI app could launch code/command on the server. DHCP clients invoke shell scripts to configure the system, with values taken from a potentially malicious server....

October 6, 2014 · 2 min · 324 words · Tyler Duncan

FBI: $5,000 Reward for one of San Diego FBI’s Most Wanted Cyber Fugitive

That is called digital identity theft and the police come after you. And what if the number of people affected are 40,000 and the police is the FBI? You get a bounty on your head. This is the story of John Gordon Baden. John appears to have carried out these digital theft operations with 2 accomplices Jason Bailey and Victor Fernandez. The trio operated from a city in Mexico. The charges filed FBI ranges from computer hacking and goes all the way to identity theft....

October 6, 2014 · 1 min · 108 words · Katie Johnson

Default Android Browser SOP bypass flaw allows hackers to steal data from open tabs

The vulnerability is in how Javascript is handled by the Android function responsible for loading frame URLs. The PoC is given below courtesy Rafay Baloch. Older Android >4.4 users still vulnerable? As said above, older Android users are still vulnerable to this major security threat. Google doles out latest Android versions on its stock edition handsets and tablets like Google Nexus etc. This flaw hits most of the users who are in lower middle and middle segment smartphone buyers....

October 5, 2014 · 1 min · 110 words · Maria Romero

Google Indonesia Hacked and defaced by Team MaDLeeTs

Table Of Contents Google Indonesia was Hacked earlier today and left defaced for hours. Google.co.id was apparently hijacked using a hacking method known as DNS Poisoning. What is DNS Poisoning? Normally, a networked computer uses a DNS server provided by an Internet service provider (ISP). How long the Website was left defaced? ]Struck by 1337, Security is just an Illusion message on the deface page read. Using the Domain Registrar hack, they updated domain name servers....

October 5, 2014 · 1 min · 91 words · Brittany Douglas