FDIC was hacked by China, and CIO covered it up

Insuring deposits, but not your identity. Thanks, FDIC. (credit: Matthew G. Bisanz ) A report published by the House Committee on Science, Space and Technology today found that hackers purported to be from China had compromised computers at the Federal Deposit Insurance Corporation repeatedly between 2010 and 2013. Backdoor malware was installed on 12 workstations and 10 servers by attackers—including the workstations of the chairman, chief of staff, and general counsel of FDIC. But the incidents were never reported to the US Computer Emergency Response Team (US-CERT) or other authorities, and were only brought to light after an Inspector General investigation into another serious data breach at FDIC in October of 2015. The FDIC failed at the time of the “advanced persistent threat” attacks to report the incidents. Then-Inspector General at FDIC, Jon Rymer, lambasted FDIC officials for failing to follow their own policies on breach reporting. Further investigation into those breaches led the committee to conclude that former FDIC CIO Russ Pittman misled auditors about the extent of those breaches, and told employees not to talk about the breaches by a foreign government so as not to ruin FDIC Chairman Martin Gruenberg’s chances of confirmation. The cascade of bad news began with an FDIC Office of the Inspector General (OIG) investigation into the October “Florida incident.” On October 23, 2015, a member of the Federal Deposit Insurance Corporation’s Information Security and Privacy Staff (ISPS) discovered evidence in the FDIC’s data loss prevention system of a significant breach of sensitive data—over 1,200 documents, including Social Security numbers from bank data for over 44,000 individuals and 30,715 banks, were copied to a USB drive by a former employee of FDIC’s Risk Management Supervision field office in Gainesville, Florida. The employee had copied the files prior to leaving his position at FDIC. Despite intercepting the employee, the actual data was not recovered from him until March 25, 2016. The former employee provided a sworn statement that he had not disseminated the information, and the matter was dropped. Read 3 remaining paragraphs | Comments

Read More:
FDIC was hacked by China, and CIO covered it up

Virulent auto-rooting malware takes control of 10 million Android devices

Security experts have documented a disturbing spike in a particularly virulent family of Android malware, with more than 10 million handsets infected and more than 286,000 of them in the US. Researchers from security firm Check Point Software said the malware installs more than 50,000 fraudulent apps each day, displays 20 million malicious advertisements, and generates more than $300 million per month in revenue. The success is largely the result of the malware’s ability to silently root a large percentage of the phones it infects by exploiting vulnerabilities that remain unfixed in older versions of Android. The Check Point researchers have dubbed the malware family “HummingBad,” but researchers from mobile security company Lookout say HummingBad is in fact Shedun, a family of auto-rooting malware that came to light last November  and had already infected a large number of devices. For the past five months, Check Point researchers have quietly observed the China-based advertising company behind HummingBad in several ways, including by infiltrating the command and control servers it uses. The researchers say the malware uses the unusually tight control it gains over infected devices to create windfall profits and steadily increase its numbers. HummingBad does this by silently installing promoted apps on infected phones, defrauding legitimate mobile advertisers, and creating fraudulent statistics inside the official Google Play Store. Read 7 remaining paragraphs | Comments

Visit site:
Virulent auto-rooting malware takes control of 10 million Android devices

Fossil fuel use in US is at its lowest percentage in over a century

(credit: US EIA ) With the 4th of July weekend about to begin, the US Energy Information Administration decided to look back to our nation’s founding. So it plotted the country’s energy use starting from 1776 . Most of the result isn’t a surprise: biomass had a long run before fossil fuels took over and stayed on top. But recent years have seen the biggest change since nuclear was added to the mix. Biomass spent nearly a century on top of the US energy mix before being displaced by coal, although it never went above providing four quadrillion Btus (each Btu is a bit over 1,000 Joules). But biomass never entirely went away, and its resurgence this century puts it at its highest level ever. With nuclear holding steady and renewables surging to nearly the same level as hydropower, fossil fuels are on the verge of dropping below 80 percent of the US’ energy mix. Fossil fuels haven’t been that low a percentage for over a century. Read 2 remaining paragraphs | Comments

Original post:
Fossil fuel use in US is at its lowest percentage in over a century

Porn studio that sued thousands for piracy now fighting its own lawyer

(credit: Getty Images) For years now, a porn studio called Malibu Media has filed more copyright lawsuits than any other company. Each month, Malibu, which produces adult content under the brand name X-Art, sues hundreds of “John Doe” Internet users, accusing particular IP addresses of illegally downloading their movies using BitTorrent networks. Malibu’s owners, Brigham Field and Collette Pelissier Field, have said the flood of lawsuits is necessary to deter piracy. Now, though, they’re targeting the very lawyer who headed up their giant copyright enforcement campaign, Florida-based Keith Lipscomb. Earlier today, Malibu filed suit against Lipscomb and his firm, Lipscomb, Eisenberg & Baker, in federal court. The lawsuit claims Lipscomb didn’t provide them the proper paperwork for their cases and related finances, and that he was negligent in his representation. The  complaint (PDF) discloses that Lipscomb sued Malibu in Florida state court on June 10 and alleges that confidential information was revealed in the lawsuit. Read 17 remaining paragraphs | Comments

Originally posted here:
Porn studio that sued thousands for piracy now fighting its own lawyer

Instagram will start automatically translating image captions soon

(credit: Instagram) On the heels of announcing that it has reached 500 million active monthly users, Instagram says it will soon add a translation feature to its app. Through a post on the image-sharing app, the company announced that within a month, users will be able to translate image captions, comments, and profile bios using a new translate button. The Facebook-owned social media app will structure its translations similarly to its parent company. When you come across a post you want to translate into a language that isn’t your default language, you can hit the “See Translation” button to convert it into the language you’ve chosen in your profile’s language settings. Both Facebook and Twitter have translation features already, so this addition brings Instagram up to par with its competition in that respect. Considering that  80 percent of Instagram’s user base lives outside the United States, this feature will likely be welcomed by many. There’s no word on how many languages Instagram will support with the first rollout of this feature. The company does explain on its Help website that if a translation isn’t showing up, it might be because the app doesn’t currently support that language or couldn’t detect the initial language being used. It also warns users that translations may not be available for older posts. The full translation feature should be ready for most users by July. Read on Ars Technica | Comments

See more here:
Instagram will start automatically translating image captions soon

Xbox Play Anywhere: buy the game once, play on Xbox One and PC (multiplayer too)

(credit: Microsoft) When announcing  Gears of War 4 at its E3 event today, Microsoft unveiled a new gaming feature called Xbox Play Anywhere. Essentially, this initiative allows a gamer to purchase a title once but still have the option to play on console  and  PC. As perhaps the headlining feature of Xbox Play Anywhere, multiplayer across platform will become a reality. With  Gears of War 4 , for instance, the co-op modes will support this crossplay between Windows 10 and Xbox One users. Progress and achievements will be shared on Xbox Live across these platforms at no additional cost. In addition to Gears of War 4,  Microsoft announced that  Forza Horizons 3  will be another upcoming Xbox Play Anywhere title. Additionally, the game will allow for four player campaign co-op for the first time. And this version of the game will feature “the largest car roster ever seen in Horizon ,” according to Ralph Fulton from Playground Games. Read 2 remaining paragraphs | Comments

See more here:
Xbox Play Anywhere: buy the game once, play on Xbox One and PC (multiplayer too)

Risky stem cell treatment reverses MS in 70% of patients in small study

MS brain lesion as seen on an MRI. (credit: James Heilman, MD ) By obliterating the broken immune systems of patients with severe forms of multiple sclerosis, then sowing fresh, defect-free systems with transplanted stem cells, researchers can thwart the degenerative autoimmune disease—but it comes at a price. In a small phase II trial of 24 MS patients, the treatment halted or reversed the disease in 70 percent of patients for three years after the transplant. Eight patients saw that improvement last for seven and a half years, researchers report in the Lancet . This means that some of those patients went from being wheelchair-bound to walking and being active again. But to reach that success, many suffered through severe side effects, such as life threatening infections and organ damage from toxicity brought on by the aggressive chemotherapy required to annihilate the body’s immune system. One patient died from complications of the treatment, which represents a four percent fatality rate. Moreover, while the risks may be worthwhile to some patients with rapidly progressing forms of MS—a small percentage of MS patients—the researchers also caution that the trial was small and did not include a control group. Read 7 remaining paragraphs | Comments

Visit link:
Risky stem cell treatment reverses MS in 70% of patients in small study

“Bluetooth 5” spec coming next week with 2x more range and 4x better speed

Bluetooth 5.0, the latest version of the ubiquitous wireless standard, is set to be announced on June 16, according to an e-mail sent by Bluetooth SIG Executive Director Mark Powell. The update will apparently be called “Bluetooth 5” without a point number in an effort to “[simplify] marketing.” It’s primarily of interest because the update promises to double the range and quadruple the speed of Bluetooth 4.2. It also adds “significantly more capacity to advertising transmissions,” which is more exciting than it sounds because it doesn’t necessarily have anything to do with what you normally think of when you think of “advertising.” In the Bluetooth spec, an “advertising packet” allows Bluetooth devices to send small snippets of information to other Bluetooth devices even if the two aren’t actually paired or connected to one another. For instance, when you go to pair a Bluetooth keyboard or speaker with one of your devices, advertising packets can let you see the name of the device before you’ve paired it so you can distinguish it from all the other Bluetooth devices that are within range. The same technology is used by wireless beacons to transmit information about the location you’re in and by Apple’s AirDrop and Handoff features to let your Macs and iDevices know what your other Macs and iDevices are up to. Read 2 remaining paragraphs | Comments

Excerpt from:
“Bluetooth 5” spec coming next week with 2x more range and 4x better speed

University pays almost $16,000 to recover crucial data held hostage

Canada’s University of Calgary paid almost $16,000 ($20,000 Canadian) to recover crucial data that has been held hostage for more than a week by crypto ransomware attackers. The ransom was disclosed on Wednesday morning in a statement issued by University of Calgary officials. It said university IT personnel had made progress in isolating the unnamed ransomware infection and restoring affected parts of the university network. It went on to warn that there’s no guarantee paying the controversial ransom will lead to the lost data being recovered. “Ransomware attacks and the payment of ransoms are becoming increasingly common around the world,” Wednesday’s statement read. “The university is now in the process of assessing and evaluating the decryption keys. The actual process of decryption is time-consuming and must be performed with care. It is important to note that decryption keys do not automatically restore all systems or guarantee the recovery of all data. A great deal of work is still required by IT to ensure all affected systems are operational again, and this process will take time.” Read 2 remaining paragraphs | Comments

More:
University pays almost $16,000 to recover crucial data held hostage

Verizon could rule the ’90s cyberscape as owner of both AOL and Yahoo

Yahoo’s once-iconic San Francisco billboard, pictured here in 2011. (credit: Scott Schiller ) Verizon is submitting a $3 billion (£2 billion) bid to purchase Yahoo’s core Internet business, according to   The Wall Street Journal , which cites an anonymous source. Though at least one more round of bidding is expected, Verizon is reportedly the leading contender. A Verizon spokesperson declined comment when contacted by Ars this morning. Yahoo has been shopping itself around for months  in an attempt to sell off just about everything except its valuable stake in Chinese e-commerce company Alibaba. Yahoo is also looking to sell other assets including real estate and patents, but Verizon reportedly isn’t interested in buying those. Read 2 remaining paragraphs | Comments

More:
Verizon could rule the ’90s cyberscape as owner of both AOL and Yahoo