security

Samsung lock screen flaw found; company working on fix

A security researcher has revealed a method for accessing applications running on a locked Samsung handset.

The flaw is somewhat similar to one that was revealed by another researcher earlier this year on iPhones. On a Samsung handset, users can, from the lock screen, pretend to dial an emergency services number, quickly dismiss it, and with some sleight of hand, quickly gain access to any app or widget, or the settings menu in the device. The dialer can also be launched, allowing the "hacker" to place a call.

According to Terence Eden, who discovered the flaw and posted … Read more

South Korea probes 'massive' cyberattack

South Korea's police are currently investigating a "massive" hack attack on Internet service provider LG Uplus, which led to server outages at three domestic broadcasters and two major banks.

As a result, the army raised its alert status amid concerns the attacks were initiated by its neighbors in North Korea.

Reuters reported Wednesday that authorities were looking into the attack on LG Uplus, which was suspected to be conducted by a group calling itself the "Whois Team".

The investigations were triggered by disrupted servers at television networks YTN, MBC and KBS. Customers at Shinhan Bank … Read more

BlackBerry 10 erroneously reported as not secure enough by U.K.

Updated at 3:30 p.m. PT This article, originally headlined "BlackBerry 10 deemed not secure enough by U.K.," previously reported the U.K.'s Computer Experts Security Group had determined that the new operating system did not meet its standards. At the time of its publication, the CESG was unavailable for comment, so the article relied on the reporting of The Guardian. We have since learned that report was inaccurate. We have received comment from the CESG that indicates BlackBerry 10 has not yet undergone required testing. We have included the group's statement in this … Read more

Feds said to probe Microsoft over foreign bribery claims

Federal regulators are looking into an alleged bribery scheme involving Microsoft and its partners in China, Italy, and Romania, according to a Wall Street Journal report.

According to the report, lawyers at the Justice Department and the Securities and Exchange Commission are focused on allegations of kickbacks in China, as well as the company's relationship with resellers and consultants in Romania and Italy.

While Microsoft did not directly acknowledge the investigation, it said in a statement provided to CNET that it takes such allegations "seriously" and cooperates with government inquiries "fully."

"Like other large … Read more

Intellectual Ventures sues Symantec over patents, again

Intellectual Ventures, the controversial patent and technology firm founded by former Microsoft executive Nathan Myhrvold, has sued security company Symantec once again.

In a new complaint (PDF), filed in the U.S. District Court of Delaware, Intellectual Ventures accused Symantec of infringing on three of its patents in some of its products.

The complaint targets Symantec's Replicator, Veritas Volume Replicator, and ApplicationHA products specifically, and claims the company "actively, knowingly, and intentionally" infringed on IV's patents with those products.

"We have been unable to reach an agreement with Symantec, and, in addition to their infringement … Read more

What 420,000 insecure devices reveal about Web security

A researcher used a simple, binary technique to take control of more than 420,000 insecure devices including Webcams, routers, and printers running on the Internet -- and says that's just a hint of the potential for real trouble to get started.

In a SecLists posting yesterday, the unnamed researcher describes how he was able to take control of open, embedded devices on the Internet. The researcher did so by using either empty or default credentials such as "root:root" or "admin:admin", indicating how a surprisingly large number of devices connected to the Web … Read more

Update OS X to ensure Java security

With the latest round of OS X updates Apple has addressed a number of bugs in its Mac operating systems; however, in addition one update is particularly pertinent for those who wish to maintain security with their Java installations.

Java has received some hard knocks recently with a number of security vulnerabilities that could potentially lead to malware execution on exploited systems, and as such, while uninstalling Java has been a preferred recommendation, one common recommendation for those who do need it is to just disable the Java Web plug-in; however, recent developments suggest doing this may not always render … Read more

Cyberthreats a top topic in Obama's call with Chinese president

President Barack Obama had a digital agenda in his call to new Chinese President Xi Jinping congratulating him on his new position, according to a new report.

According to The New York Times, Obama and his Chinese counterpart spoke quite a bit about cyberattacks and their impact on each other's nations. The Times, which obtained the information from White House officials, didn't specifically say what was said during the conversation. But the fact that the presidents are having an open discussion on cyberattacks indicates just how far the issue has gone.

For years now, both China and the … Read more

Get Norton AntiVirus 2013 (3 PCs) free after rebate

Funny thing about Symantec's security programs: Lots of people still hate them. Like, really hate them. I guess the bloated, sluggish, more-harm-than-good versions of yesteryear were enough to turn some users off Symantec forever, even though the products have improved dramatically in the past several years.

Indeed, several of the company's Norton tools are perennial award-winners, and have been since the early days of Windows 7. And yet I know that at least some readers will see this deal and write, "Norton AntiVirus? No way, never again."

More on that in a bit. For now, Newegg … Read more

Obama hosts meeting on cybersecurity with CEOs

President Barack Obama met with 13 chief executives yesterday to dig deeper into cybersecurity.

According to The New York Times, which first reported on the meeting, the discussion took place in the White House Situation Room and was a "two-way" exchange of information between the president and the chief executives.

AT&T CEO Randall Stephenson, along with chief executives at Exxon Mobil, Bank of America, and JPMorgan Chase, were all in attendance, according to the Times.

Over the last several weeks, a slew of companies has been hit with cyberattacks. Online banking sites have also been targeted. … Read more