New Stegano Exploit Kit Hides Malvertising Code In Banner Pixels

An anonymous reader quotes a report from BleepingComputer: For the past two months, a new exploit kit has been serving malicious code hidden in the pixels of banner ads via a malvertising campaign that has been active on several high profile websites. Discovered by security researchers from ESET, this new exploit kit is named Stegano, from the word steganography, which is a technique of hiding content inside other files. In this particular scenario, malvertising campaign operators hid malicious code inside PNG images used for banner ads. The crooks took a PNG image and altered the transparency value of several pixels. They then packed the modified image as an ad, for which they bought ad displays on several high-profile websites. Since a large number of advertising networks allow advertisers to deliver JavaScript code with their ads, the crooks also included JS code that would parse the image, extract the pixel transparency values, and using a mathematical formula, convert those values into a character. Since images have millions of pixels, crooks had all the space they needed to pack malicious code inside a PNG photo. When extracted, this malicious code would redirect the user to an intermediary ULR, called gate, where the host server would filter users. This server would only accept connections from Internet Explorer users. The reason is that the gate would exploit the CVE-2016-0162 vulnerability that allowed the crooks to determine if the connection came from a real user or a reverse analysis system employed by security researchers. Additionally, this IE exploit also allowed the gate server to detect the presence of antivirus software. In this case, the server would drop the connection just to avoid exposing its infrastructure and trigger a warning that would alert both the user and the security firm. If the gate server deemed the target valuable, then it would redirect the user to the final stage, which was the exploit kit itself, hosted on another URL. The Stegano exploit kit would use three Adobe Flash vulnerabilities (CVE-2015-8651, CVE-2016-1019 or CVE-2016-4117) to attack the user’s PC, and forcibly download and launch into execution various strains of malware. Read more of this story at Slashdot.

Read the original post:
New Stegano Exploit Kit Hides Malvertising Code In Banner Pixels

Google Is Rolling Out Android 7.1.1

Google is rolling out Android 7.1.1 for Pixel and Nexus smartphones, including the Nexus 6, Nexus 5X, Nexus 6P, Nexus 9, Pixel, Pixel XL, Nexus Player, Pixel C and General Mobile 4G (Android One). You can download it over-the-air when it becomes available “over the next several weeks” or flash it yourself. Engadget details some of the new features found in Android 7.1.1: As for what you can find from a feature perspective, Google has added support for its “image keyboard” that lets you easily find and send pictures and GIFs without leaving your messaging app of choice. Google says it’ll work inside of Hangouts, Allo, and the default Messaging app. Ironically enough, the feature has been available in the Gboard iOS keyboard that Google launched in the spring, but it’s good to see it coming to more Android phones now. Android 7.1.1 also includes Google’s latest set of more diverse emoji, specifically focused on showing a “wider range of professions” for women. And it also contains the excellent app shortcut feature that originally launched on the Pixel — if you press and hold on an app’s icon, a sub-menu of shortcuts will show up. You’ll be able to quickly send a message to a specific contact or navigate to a saved location using these shortcuts, for example. They’re very much like the “force touch” shortcuts found on the iPhone, but that doesn’t make them any less useful. Read more of this story at Slashdot.

See original article:
Google Is Rolling Out Android 7.1.1

Lisa From TSA Wants You to Pick Up Your Laptop, Thanks

In October and November, around 70 people left their laptops at a single airport security checkpoint at the Newark Airport. It’s not only the cheap stuff that’s gets abandoned—a fair amount of Macbooks are getting left behind as well. Read more…

View the original here:
Lisa From TSA Wants You to Pick Up Your Laptop, Thanks

Hackers Steal $31 Million at Russia’s Central Bank

The Bank of Russia has confirmed Friday that hackers have stolen 2 billion rubles ($31 million) from correspondent accounts at the Russian central bank. Central bank security executive Artiom Sychev said it could’ve been much worse as hackers tried to steal 5 billion rubles, but the central banking authority managed to stop them. CNNMoney reports: Hackers also targeted the private banks and stole cash from their clients, the central bank reported. The central bank did not say when the heist occurred or how hackers moved the funds. But so far, the attack bears some similarity to a recent string of heists that has targeted the worldwide financial system. Researchers at the cybersecurity firm Symantec have concluded that the global banking system has been under sustained attack from a sophisticated group — dubbed “Lazarus” — that has been linked to North Korea. But it’s unclear who has attacked Russian banks this time around. Earlier Friday, the Russian government claimed it had foiled an attempt to erode public confidence in its financial system. Russian’s top law enforcement agency, the FSB, said hackers were planning to use a collection of computer servers in the Netherlands to attack Russian banks. Typically, hackers use this kind of infrastructure to launch a “denial of service” attack, which disrupts websites and business operations by flooding a target with data. The FSB said hackers also planned to spread fake news about Russian banks, sending mass text messages and publishing stories on social media questioning their financial stability and licenses to operate. Read more of this story at Slashdot.

See more here:
Hackers Steal $31 Million at Russia’s Central Bank

Lawyer Sues 20-Year-Old Student Who Gave a Bad Yelp Review, Loses Badly

20-year-old Lan Cai was in a car crash this summer, after she was plowed into by a drunk driver and broke two bones in her lower back. She didn’t know how to navigate her car insurance and prove damages, so she reached out for legal help. Things didn’t go as one would have liked, initially, as ArsTechnica documents:The help she got, Cai said, was less than satisfactory. Lawyers from the Tuan A. Khuu law firm ignored her contacts, and at one point they came into her bedroom while Cai was sleeping in her underwear. “Seriously, it’s super unprofessional!” she wrote on Facebook. (The firm maintains it was invited in by Cai’s mother.) She also took to Yelp to warn others about her bad experience. The posts led to a threatening e-mail from Tuan Khuu attorney Keith Nguyen. Nguyen and his associates went ahead and filed that lawsuit, demanding the young woman pay up between $100, 000 and $200, 000 — more than 100 times what she had in her bank account. Nguyen said he didn’t feel bad at all about suing Cai. Cai didn’t remove her review, though. Instead she fought back against the Khuu firm, all thanks to attorney Michael Fleming, who took her case pro bono. Fleming filed a motion arguing that, first and foremost, Cai’s social media complaints were true. Second, she couldn’t do much to damage the reputation of a firm that already had multiple poor reviews. He argued the lawsuit was a clear SLAPP (strategic Lawsuit Against Public Participation). Ultimately, the judge agreed with Fleming, ordering the Khuu firm to pay $26, 831.55 in attorneys’ fees. Read more of this story at Slashdot.

Read the article:
Lawyer Sues 20-Year-Old Student Who Gave a Bad Yelp Review, Loses Badly

Netflix Adds Offline Viewing for Phones and Tablets

Starting today, Netflix will let you download select shows so that you can watch offline. That means you can queue up your favorite shows to watch while you’re traveling or don’t want to use up your data plan. Read more…

Read the original:
Netflix Adds Offline Viewing for Phones and Tablets

Vegans Are Pissed That Britain’s New Money Contains Meat

England recently introduced a new £5 note with high-tech, anti-counterfeit features. But some animal rights activists in the Land of Brexit™ are swearing off the bill completely. Apparently the new notes are made using just a dash of animal fat. Read more…

Continued here:
Vegans Are Pissed That Britain’s New Money Contains Meat

Google Asked to Remove a Billion ‘Pirate’ Search Results in a Year

Copyright holders asked Google to remove more than 1, 000, 000, 000 allegedly infringing links from its search engine over the past twelve months, TorrentFreak reports. According to stats provided in Google’s Transparency Report for the past one year, Google was asked to remove over one billion links — or 1, 007, 741, 143 links. From the article: More than 90 percent of the links, 908, 237, 861 were in fact removed. The rest of the reported links were rejected because they were invalid, not infringing, or duplicates of earlier requests. In total, Google has now processed just over two billion allegedly infringing URLs from 945, 000 different domains. That the second billion took only a year, compared to several years for the first, shows how rapidly the volume of takedown requests is expanding. At the current rate, another billion will be added by the end of next summer. Most requests, over 50 million, were sent in for the website 4shared.com. However, according to the site’s operators many of the reported URLs point to the same files, inflating the actual volume of infringing content. Read more of this story at Slashdot.

More here:
Google Asked to Remove a Billion ‘Pirate’ Search Results in a Year

VLC Media Player Previews 360-degree Video Support

VideoLAN has released a technical preview of VLC Media Player 3.0 with 360-degree video support. The new build handles videos following the Spatial Video format, and photos and panoramas following the Spherical spec (the official test page has sample files). From an article on SoftwareCrew:The files play back just like any other video, but you can now left-click and drag within the screen or use the numeric keypad arrows to look around. VideoLAN says there are multiple display modes — Zoom, Little Planet and Reverse Little Planet — although we couldn’t immediately see how they were activated. This initial release is only available for Windows and Mac, but eventually 360-degree support will arrive for Android, iOS and Xbox One, with VR headset support likely to arrive in 2017. Read more of this story at Slashdot.

Read More:
VLC Media Player Previews 360-degree Video Support

For the First Time, Living Cells Have Formed Carbon-Silicon Bonds

From a ScienceDaily alert: Scientists have managed to coax living cells into making carbon-silicon bonds, demonstrating for the first time that nature can incorporate silicon — one of the most abundant elements on Earth — into the building blocks of life. While chemists have achieved carbon-silicon bonds before — they’re found in everything from paints and semiconductors to computer and TV screens — they’ve so far never been found in nature, and these new cells could help us understand more about the possibility of silicon-based life elsewhere in the Universe. After oxygen, silicon is the second most abundant element in Earth’s crust, and yet it has nothing to do with biological life. Why silicon has never be incorporated into any kind of biochemistry on Earth has been a long-standing puzzle for scientists, because, in theory, it would have been just as easy for silicon-based lifeforms to have evolved on our planet as the carbon-based ones we know and love. Not only are carbon and silicon both extremely abundant in Earth’s crust – they’re also very similar in their chemical make-up. Read more of this story at Slashdot.

Excerpt from:
For the First Time, Living Cells Have Formed Carbon-Silicon Bonds