Chris Baker's Blog

  • Increase font size
  • Default font size
  • Decrease font size
Home News
News

Researchers find critical vulnerability in Java 7 patch hours after release

E-mail Print PDF

Java vuln found in java updateAccording to Mac World, security researchers from Poland-based security firm Security Explorations claim to have discovered a vulnerability in the Java 7 security update released Thursday that can be exploited to escape the Java sandbox and execute arbitrary code on the underlying system.

Oracle broke out of its regular four-month patching cycle on Thursday to release Java 7 Update 7, an emergency security update that addressed three vulnerabilities, including two that were being exploited by attackers to infect computers with malware since last week.

 

Cold War Gives Way To Code War

E-mail Print PDF

Cofer Black speaks about coming "Code War"US counterterrorism expert Cofer Black warned Wednesday that the Cold War has given way to a "Code War" in which cyber weapons can be unleashed with devastating consequences.

A sophisticated hacking campaign exposed earlier by computer security firm McAfee was no surprise to Cofer, who saw it as a sign of more to come. The United States, United Nations, defense contractors and the International Olympic Committee were targets of a massive global cyber spying campaign, McAfee said, with China seen as the likely culprit.

California-based McAfee said in a report that it had identified 72 victims in 14 countries of a hacking effort dubbed "Operation Shady RAT," which it traced back to at least 2006.

Read the full article by Glenn Chapman (AFP)

 

Stuxnet: Deciphered

E-mail Print PDF

Stuxnet: DecipheredWired's Kim Zetter has written a fascinating article detailing the unravelling of the Stuxnet malware, the world’s first publicized cyberweapon. Research from experts around the globe have revealed that Stuxnet's intent was industrial sabotage of centrifuges in Iran's developing Nuclear facilities. While most of the over-arching details concerning Stuxnet have been discovered, many of its details still remain a mystery.

Read the full article on Wired's Threat Level
 

American Internet ID System

E-mail Print PDF

American Internet ID SystemPresident Obama will give the United States Commerce Department the authority over a proposed national cybersecurity measure that would involve giving each American a unique online identity.

It's "the absolute perfect spot in the U.S. government" to centralize efforts toward creating an "identity ecosystem" for the Internet, White House Cybersecurity Coordinator Howard Schmidt said.1

 

Cyberattacks Have Hit Most Large Canadian Firms

E-mail Print PDF
Cyberattacks Hit Major Canadian FirmsA secret government report on cyberattacks says that 86 per cent of large Canadian corporations have been "hit" and that espionage hacking on the private sector has doubled in two years.

"Cyberespionage attacks are causing considerable economic damage," says the 2010 "threat paper," released to Postmedia News through access-to-information laws.

The heavily redacted report was prepared by the Public Safety Department with input from the Canadian Security Intelligence Service, the Defence Department, the RCMP and the Privy Council Office.

Read the full article on the Vancouver Sun

 

PS3 Offically Hacked & Jailbroken

E-mail Print PDF

The PS3 has been officially hacked allowing for backed up games to be played off internal or external hard drive. The original hack was released a few weeks ago as a USB dongle that mod chip suppliers were selling for $170 US. Hackers have now found a way to program their own USB dongle with the Blackcat programmable USB kit. This sells for $30-$40 depending on where you buy it.

Sony has been very proactive in patching security holes in the PS3 firmware; even going so far as to remove the install other OS feature which allowed users to install linux.[1]

 



Twitter

Polls

What's your favorite browser?