Today, Hipchat alerted its users that someone broke into one of its servers through a vulnerability in a third-party library. The chat service saw no evidence that other Atlassian systems or products like Jira or Trello were affected, but they’re forcing every user to reset their HipChat-connected account password as a precaution. According to the service’s blog post , the attacker might have gotten access to user information (including name, email and hashed password) of anyone using HipChat.com. There’s been no sign that over 99 percent of users’ messages or room content was compromised, though the attacker could have accessed that portion’s metadata. A small fraction (.05 percent) of instances might have been wide open to the hacker, who would have been able to see correspondence and content. Fortunately, no evidence has suggested that the attacker has accessed anyone’s financial or credit card information. “While HipChat Server uses the same third-party library, it is typically deployed in a way that minimizes the risk of this type of attack, ” the blog post said, but the service will roll a security update out for Hipchat Server just to be sure. Source: HipChat
View article:
HipChat resets all passwords after hackers break in
FossBytes reports: The whistleblower website Wikileaks has published another set of hacking tools belonging to the American intelligence agency CIA. The latest revelation includes a user guide for CIA’s “Weeping Angel” tool… derived from another tool called “Extending” which belongs to UK’s intelligence agency MI5/BTSS, according to Wikileaks. Extending takes control of Samsung F Series Smart TV. The highly detailed user guide describes it as an implant “designed to record audio from the built-in microphone and egress or store the data.” According to the user guide, the malware can be deployed on a TV via a USB stick after configuring it on a Linux system. It is possible to transfer the recorded audio files through the USB stick or by setting up a WiFi hotspot near the TV. Also, a Live Liston Tool, running on a Windows OS, can be used to listen to audio exfiltration in real-time. Wikileaks mentioned that the two agencies, CIA and MI5/BTSS made collaborative efforts to create Weeping Angel during their Joint Development Workshops. Read more of this story at Slashdot.