Scientist-developed malware covertly jumps air gaps using inaudible sound

Topology of a covert mesh network that connects air-gapped computers to the Internet. Hanspach and Goetz Computer scientists have developed malware that uses inaudible audio signals to communicate, a capability that allows the malware to covertly transmit keystrokes and other sensitive data even when infected machines have no network connection. The proof-of-concept software—or malicious trojans that adopt the same high-frequency communication methods—could prove especially adept in penetrating highly sensitive environments that routinely place an “air gap” between computers and the outside world. Using nothing more than the built-in microphones and speakers of standard computers, the researchers were able to transmit passwords and other small amounts of data from distances of almost 65 feet. The software can transfer data at much greater distances by employing an acoustical mesh network made up of attacker-controlled devices that repeat the audio signals. The researchers, from Germany’s Fraunhofer Institute for Communication, Information Processing, and Ergonomics , recently disclosed their findings in a paper published in the Journal of Communications . It came a few weeks after a security researcher said his computers were infected with a mysterious piece of malware that used high-frequency transmissions to jump air gaps . The new research neither confirms nor disproves Dragos Ruiu’s claims of the so-called badBIOS infections, but it does show that high-frequency networking is easily within the grasp of today’s malware. Read 6 remaining paragraphs | Comments        

More:
Scientist-developed malware covertly jumps air gaps using inaudible sound

Anti-GMO crop paper to be forcibly retracted

Chiot’s Run Last year, a French researcher made waves by announcing a study that suggested genetically modified corn could lead to an increased incidence of tumors in lab animals. But the way the finding was announced seemed designed to generate publicity while avoiding any scientific evaluation of the results. Since then, the scientific criticisms have rolled in, and they have been scathing. Now, the editor of the journal that published it has decided to pull the paper despite the objections of its primary author. The initial publication focused on corn that had been genetically engineered to carry a gene that allowed it to break down a herbicide. French researchers led by Gilles-Eric Séralini fed the corn, with and without herbicide, to rats. Control populations were given the herbicide alone or unmodified corn. The authors concluded that the genetically-modified corn led to an elevated incidence of tumors and early death. But even a cursory glance at the results suggested there were some severe problems with this conclusion. To begin with, there were similar effects caused by both the genetically engineered crop and by the herbicide it was designed to degrade. None of the treatments showed a dose effect; in some cases, the lowest doses had the most dramatic effect. And, if the treatment populations were combined, in some cases they were healthier than the controls. Tests of whether the results were statistically significant were completely lacking. Read 8 remaining paragraphs | Comments        

More:
Anti-GMO crop paper to be forcibly retracted

New Linux worm targets routers, cameras, “Internet of things” devices

Wesley Fryer Researchers have discovered a Linux worm capable of infecting a wide range of home routers, set-top boxes, security cameras, and other consumer devices that are increasingly equipped with an Internet connection. Linux.Darlloz , as the worm has been dubbed, is now classified as a low-level threat, partly because its current version targets only devices that run on CPUs made by Intel, Symantec researcher Kaoru Hayashi wrote in a blog post published Wednesday . But with a minor modification, the malware could begin using variants that incorporate already available executable and linkable format (ELF) files that infect a much wider range of “Internet-of-things” devices, including those that run chips made by ARM and those that use the PPC, MIPS, and MIPSEL architectures. “Upon execution, the worm generates IP addresses randomly, accesses a specific path on the machine with well-known ID and passwords, and sends HTTP POST requests, which exploit the vulnerability,” Hayashi explained. “If the target is unpatched, it downloads the worm from a malicious server and starts searching for its next target. Currently, the worm seems to infect only Intel x86 systems, because the downloaded URL in the exploit code is hard-coded to the ELF binary for Intel architectures.” Read 4 remaining paragraphs | Comments        

More:
New Linux worm targets routers, cameras, “Internet of things” devices

Always-on voice search from your desktop: “Ok Google” comes to Google.com

Google Smartphones have changed the computing landscape quite a bit, and it often seems like desktop computers and laptops get left behind. “Always-on” voice search is going to completely change the way we interact with computers, but, until now, it has been strictly-mobile only. Today, Google released a Chrome extension that enables always-on voice search from a desktop. With the extension installed, voice search works just like it does on the Nexus 5. When Google.com is open, just say “Ok Google” and then your search term. This happens when you say “Ok Google” from the search results. Google The hotword even works when you’re already on a search page. You can just say “Ok Google” again and search for something else. It all feels like a step closer to the Star Trek future Google keeps promising us . Read 1 remaining paragraphs | Comments        

Original post:
Always-on voice search from your desktop: “Ok Google” comes to Google.com

Google launches Play Newsstand: a hybrid magazine store and RSS reader

The long-rumored Google Play Newsstand for Android has finally launched , and it’s not at all what we were expecting. Early reporting and investigation pinned it as a newspaper section of the Play Store, but it’s much more than that. Google is selling newspapers and magazines under a single banner, and  there’s a visual-heavy RSS reader, sort of like Flipboard. This means Newsstand is replacing two of Google’s existing apps: Google Play Magazines and Google Currents. Google is pitching it as “all your subscriptions in one place.” Like most things “Google” these days, calling it an “app” isn’t really the whole story. There’s also a new section of the desktop Play Store, and some magazines and newspapers are even viewable in the browser. RSS is strictly confined to the app, though. Just like the old Play Magazines, paid content is available as a subscription or on a per-issue basis, and 30-day trials are available for some premium content. RSS feeds, magazines, and newspaper can be downloaded for offline reading later, and there’s also a bookmark function. Read 1 remaining paragraphs | Comments        

See the original post:
Google launches Play Newsstand: a hybrid magazine store and RSS reader

GitHub resets user passwords following rash of account hijack attacks

GitHub is experiencing an increase in user account hijackings that’s being fueled by a rash of automated login attempts from as many as 40,000 unique Internet addresses. The site for software development projects has already reset passwords for compromised accounts and banned frequently used weak passcodes, officials said in an advisory published Tuesday night . Out of an abundance of caution, site officials have also reset some accounts that were protected with stronger passwords. Accounts that were reset despite having stronger passwords showed login attempts from the same IP addresses involved in successful breaches of other GitHub accounts. “While we aggressively rate-limit login attempts and passwords are stored properly, this incident has involved the use of nearly 40K unique IP addresses,” Tuesday night’s advisory stated. “These addresses were used to slowly brute force weak passwords or passwords used on multiple sites. We are working on additional rate-limiting measures to address this. In addition, you will no longer be able to login to GitHub.com with commonly used weak passwords.” Read 3 remaining paragraphs | Comments        

See the article here:
GitHub resets user passwords following rash of account hijack attacks

MediaPortal 1.6.0 Pre Release ready!

MediaPortal 1.6.0 Pre Release Attached to this news you will find the Pre Release version of MediaPortal 1.6.0. Pre Releases are provided as a way for the community to test and give feedback on all the exciting things we have lined up for the next release. We allocate about one month for Pre Release testing. In that time we only do bug fixes… and then comes the final release! Highlights of this release Update to MySQL 5.6 to increase stability Due to performance and stability improvements we decided to switch from MySQL 5.1 to MySQL 5.6 which comes with InnoDB as default database engine. It is more reliable than  MyISAM  which was the default database engine in MySQL 5.1 and the cause of many TV database crashes.  MySQL 5.6 gets only installed if you do a  clean installation. If you perform an update, MySQL 5.1 will be kept. This is because users might still want to use MySQL 5.1 for other purposes than just MediaPortal. Enhanced TV experience There were quite some improvements like fix stuttering/dropped frame problems with H.264 video streams which use mixed field/frame (interlaced/progressive) encoding e.g. UK Freeview HDTV channels aswell as handle some NZ Freeview channels which were causing problems. Recognition of DolbyDigital+ streams was added and a deadlock was fixed which leads to TV Server crashes or can cause a BSOD quite frequently on some setups.  Music improvements   A lot of things have been fixed and worked on in the Music section since our last release. Below you find the most important enhancements. Hopefully you will enjoy them!    Last.FM rework Because Last.FM changed their API, the Last.fm Radio & scrobbling functions (last.fm account needed for both!) are rewritten. As a bonus an awesome new AutoDJ function is added, which will attempt to play music forever, and you don’t even need a Last.fm account for it! Music Visualisations Music Visualisations got fixed and are now correctly listening to the beat. Furthermore while on the NowPlaying screen, you can now switch to (fullscreen) visualisations by pressing X on your keyboard. PageUp/PageDown are used to cycle through the available visualisations. Allmusic.com scraper update As you might have noticed, the Album/Artist scraping was broken in MediaPortal 1.5 because allmusic.com changed their layout. For your convenience, this has been fixed now. Gapless playback Gapless playback is working now and can be enabled through MediaPortal configuration. MyVideos scraper rework for better maintainability Not only Album/Artist scraping was broken in MediaPortal 1.5 but also Fanart/Poster scraping in MyVideos because of the TMDB API change . This has been completely fixed and was improved in a way that the MyVideos scraper can now be updated outside the MediaPortal release cycle which means we are more flexible when it comes to fix scraper issues. Other small improvements Besides the switch to .NET4 we also modified our core to support plugins like the amazing Auto3D plugin or the great Atmolight plugin. Furthermore we fixed a DPI scaling issue for Win 8.1 users and RefreshRate changing on multi monitor setups was fixed too.  Full list of changes You can review the complete change log for 1.6.0 Pre Release by using the link below: Changelog: MediaPortal Documentation of new features can be found at the following link: What’s new for MediaPortal 1.6.0 Compiled Plugin related changes Community Plugin Developers should have a look at the following page to find out about the changes which will effect their extensions. Some of these changes are mandatory to become 1.6.0 compatible: changes which affect plugins Installation, Upgrade, Download and Feedback Installation Since we switched to .NET4 you need to make sure you got .NET4 installed on your computer (not needed if you are on Windows 8 because it comes with .NET4). Otherwise you are not able to install MediaPortal and the installer just quits. Download-Link: Microsoft .NET Framework 4 (Standalone Installer) Aside from that when doing a clean installation of 1.6.0 Pre Release there is nothing else special to worry about. Upgrade Upgrading from 1.2.x, 1.3.0 Alpha/Beta/RC/Final, 1.4.0 or 1.5.0 to 1.6.0 Pre Release All MediaPortal 1.2.x, 1.3.0 Alpha/Beta/RC/Final, 1.4.0 and 1.5.0 installations can be upgraded to 1.6.0 Pre Release, without losing your settings. Plugins: If you are running MediaPortal 1.5.0 or earlier , then it is possible that some of your previously installed plugins will be shown as incompatible after the upgrade to 1.6.0 Pre Release ! Whether or not a plugin is incompatible depends on the MediaPortal subsystems the plugin uses. Skins: Warning ! Due to the new features and changes introduced in 1.4.0 , none of the 1.3.x skins are compatible with 1.6.0 Pre Release ! Please contact the author of the skin you use for further information and updates. Upgrading Extensions: The easiest way to upgrade your extensions is by launching the MediaPortal Extension Installer , and let it check for updated versions. However this only works for extensions that use our MPEI system. If the author of the extension releases it as a stand alone installer, you must contact them for an updated version. Upgrading from 1.2.0 Alpha or earlier to 1.6.0 Pre Release All MediaPortal installations starting with 1.1.0 RC1 can be upgraded to 1.6.0 Pre Release, without losing your settings. If you are running MediaPortal 1.2.0 Alpha or earlier, then none of your extensions (plugins and skins) will work after the upgrade to 1.6.0 Pre Release! You must update your extensions after the upgrade!  So, please make sure that 1.6.0 Pre Release compatible versions of your extensions are available before you start the upgrade! General note about Upgrades Manually stop TV-Service! On some systems our installer is not able to update the TV-Server installation because its files are locked or the service can not be stopped. For upgrades to 1.6.0 Pre Release we recommend that you manually stop the TV-Service and make sure, via Windows Task Manager (enable the “all users” option), that the TvService.exe process is really gone before starting to upgrade. Custom TV-Service properties If you manually changed the properties of the TV-Service (like restart on error options) , then you must redo these changes after the upgrade. The installer is not able to save and restore your custom service properties when it installs the new version of the TV-Service.  Feedback Bugs If you think you found a bug then please post a detailed report in our Bug Reports Forum . Make sure your report includes all the required information . Incomplete reports will be removed to keep the forum clean.  Download Finally – the download. We hope that you took the time to read this release news entirely because it includes vital information about the major changes.   If you would like to support MediaPortal, we would be happy to receive a small donation ! The Team wishes you a lot of fun with this new release! .::. Download – MediaPortal 1.6.0 Pre Release .::.   :: Post a Comment ::

Continue Reading:
MediaPortal 1.6.0 Pre Release ready!

Feds arrest ATM thieves after discovering $800,000 stuffed in a suitcase

Noah Coffey Federal authorities have arrested five more men accused of taking part in a 21st-century bank heist that siphoned a whopping $45 million out of ATMs around the world in a matter of hours. Prosecutors said the men charged on Monday were members of the New York-based cell of a global operation and contributed to the $45 million theft by illegally withdrawing $2.8 million from 140 different ATMs in that city. The arrests came after the defendants sent $800,000 in cash proceeds in a suitcase transported by bus to a syndicate kingpin located in Florida, US Attorney for the Eastern District of New York Loretta E. Lynch said . Photos seized from one defendant’s iPhone showed huge amounts of cash piled on a hotel bed and being stuffed into luggage, she said. The heists took place during two dates in December 2012 and targeted payment cards issued by the National Bank of Ras Al-Khaimah PSC in the United Arab Emirates and the Bank of Muscat in Oman respectively. Prosecutors dubbed the heists “unlimited” operations because they systematically removed the withdrawal limits normally placed on debit card accounts. These restrictions work as a safety mechanism that caps the amount of loss that banks normally face when something goes wrong. The operation removed the limits by hacking into two companies that processed online payments for the two targeted banks, prosecutors alleged in earlier indictments. Prosecutors didn’t identify the payment processors except to say that one was in India and the other was in the United States. Read 3 remaining paragraphs | Comments        

Visit link:
Feds arrest ATM thieves after discovering $800,000 stuffed in a suitcase

Qualcomm’s Toq wants to be your platform-agnostic color smartwatch

Qualcomm Qualcomm became a surprise entrant in the wearable computing race when it announced its Toq smartwatch. Designed as a showcase for some of Qualcomm’s latest technology, the $349.99 Toq will go on sale on December 2nd through its own portal. From a function perspective, Toq follows somewhat worn paths with notifications sent from your phone, music playback controls, and additional data pushed from an on-phone app. Where Toq differs is less in interactions than hardware features. The display Qualcomm chose is its own Mirasol MEMS-based display. In effect, Mirasol is like a mash-up of E Ink and LCD displays, providing a low-power, static color image where appropriate, with video and animation capabilities that exceed those of traditional E Ink displays. Charging your Toq occurs through Qualcomm’s own WiPower LE wireless charging protocol, and the included charger serves as a case as well. Most smartwatches connect primarily through Bluetooth LE; Qualcomm’s Toq also includes access to its open source AllJoyn protocol, which offers a platform-agnostic approach to device-to-device communications. AllJoyn-enabled devices and software can interact with your Toq over WiFi-Direct or Bluetooth. Read 1 remaining paragraphs | Comments        

View original post here:
Qualcomm’s Toq wants to be your platform-agnostic color smartwatch

California shuts down 10 “fraudulent” health care websites

This is the real McCoy. Covered California In a move rarely seen by state authorities, California has shut down 10 domain names that the Golden State claims were fraudulent imitations of Covered California, the state’s own version of the Affordable Care Act. On Thursday, the state’s attorney general announced that it had forced 10 domain names to either redirect to the bona fide Covered California website, or to remove their sites entirely. California also sent cease and desist letters to the operators of those sites. As California’s attorney general, Kamala Harris, wrote in a statement : Read 5 remaining paragraphs | Comments        

Read the original post:
California shuts down 10 “fraudulent” health care websites