New Bug Found in iPhone Which Stores User Input Data And Transfer To Remote Server

FireEye is the same Security research firm which had previously discovered a major flaw/zero day vulnerability in Internet Explorer. Potential attackers can use such information to reconstruct every character the victim inputs. FireEye gave the example of the Music player App on a iPhone. The Music Player App keeps on continuously refreshing itself even if background refresh has been disabled by the user. source: www.techworm.net

February 27, 2014 · 1 min · 65 words · Evelyn Stewart

Royal Mail the latest weapon of Ransomware makers, CryptoLocker to lure victims

Read More source: www.techworm.net

February 27, 2014 · 1 min · 4 words · Annette Savage

Youtube ads Spreading Malware to viewers

To sort this out Bromium worked with Google security team to sort this out on YourTube. source: www.techworm.net

February 26, 2014 · 1 min · 18 words · Elizabeth Willis

Mt.Gox goes offline, no explanation given but reports say it lost $350 million to a hacking over the year

All seemed well last Tuesday when Mt.Gox issued a presser claiming that the Exchange will be online by Thursday. It seems that the Mt.Gox management was giving false hopes to its customers and Bitcoin aficionados in general. Today it has shut down for business with the web URL returning a empty website. source: www.techworm.net

February 25, 2014 · 1 min · 54 words · James Williams

Anonymous targets ‘Facebook Pedophiles’ POSTs forces Facebook to take them down

just do not post them at all, even to friends only. They can be stolen; just dont put them on Facebook. source: www.techworm.net

February 24, 2014 · 1 min · 23 words · Justin Zuniga

Major encryption flaw in Apple’s iOS 7; Apple releases fix to patch it up

This also means that the flaw would have allowed the potential hacker to take full control of your system. But no sooner it put this comment, its engineers worked overtime to patch this exploit. The patch for iOS 7 users is availablehere. source: www.techworm.net

February 24, 2014 · 1 min · 44 words · Mary Rivera

The International Council of E-Commerce Consultants hacked and defaced

The International Council of E-Commerce Consultants (https://www.eccouncil.org/) was hacked and defaced today by an Anonymous hacker, who said himself a certified unethical software security professional, and signed as Eugene Belford The reason behind hacking is still not clear.A deface page can be still seen on the website, which shows a email request from Edward Snowden requesting to appear in the Certification exam of EC-Council, with his passport, Examination program form, and a experience certificate from Department of Defense special representative japan....

February 23, 2014 · 1 min · 85 words · Ronald Mcclure

War Against Mobile Adware Still Exists, More Than 1000 Of Mobile Apps Contains Adware

Read More source: www.techworm.net

February 23, 2014 · 1 min · 4 words · Nathan Brady

Internet Bug Bounty Program Pays First Reward For Adobe Vulnerability

Chris Evans, a Google security engineer and a member of the IBB said that IBB culture is to look mainly at whether a given discovery or piece of research helped make us all safer. Our aim is to motivate and incentives any high-impact work that leads to a safer internet for all.Evan said IBB does not want or need details of unfixed vulnerabilities that would violate strict need-to-know handlingOnce a public advisory and fix is issued, researchers or their friends may file IBB bugs to nominate their bugs for reward....

February 22, 2014 · 1 min · 126 words · Chelsea Smith

WhatsApp had 4 gaping SSL security holes which would have compromised its 430 million user ids and phone numbers

Without SSL pinning enforced, an attacker could man-in-the-middle the connection between the mobile applications and back-end web services. SSL Null Ciphers Support EnabledIt gets worse. Null Ciphers do not perform any encryption. That is, it simply copies the input stream to the output stream without any changes. SSLv2 is vulnerable to several specific attacks which require sniffing and man-in-the-middling. In addition, SSLv2 utilizes MAC post-encryption and 40-bit MACs, which are both considered design flaw weaknesses....

February 22, 2014 · 1 min · 77 words · Carol Cook

Anonymous angered by Documentary maker.

(Admin Notes: This Article is a guest post from an Unknown Source) Read More source: www.techworm.net

February 21, 2014 · 1 min · 16 words · Reginald Pearson

Namecheap targeted with 100GBPs, massive DDoS attack

Today is one of the days that, as a service provider who strives to deliver excellence day in and day out, you wish you never had The sheer size of the attack overwhelmed many of our DNS servers, resulting in inaccessibility and sluggish performance, Our initial estimates show the attack size to be over 100Gbps, making this one of the largest attacks anyone has seen or dealt with. And this is a new punch in of attack, one that we and our hardware and online grid partners had not encountered before....

February 21, 2014 · 1 min · 95 words · Victoria Stafford

Zero Day Vulnerability Found In Internet Explorer, Microsoft Released a Security Patch

On a Microsoft support page, the company recommended that users restart IE after installing the Fix it to avoid experiencing increased memory usage while browsing the web. Read More source: www.techworm.net

February 21, 2014 · 1 min · 31 words · Amber Goodman