Russian Hackers Stole $5 Million Per Day From Advertisers With Bots and Fake Websites

Russian hackers have used fake websites and bots to steal millions of dollars from advertisers. According to researchers, the fraud has siphoned more than $180 million from the online ad industry. CNNMoney reports: Dubbed “Methbot, ” it is a new twist in an increasingly complex world of online crime, according to White Ops, the cybersecurity firm that discovered the operation. Methbot, so nicknamed because the fake browser refers to itself as the “methbrowser, ” operates as a sham intermediary advertising ring: Companies would pay millions to run expensive video ads. Then they would deliver those ads to what appeared to be major websites. In reality, criminals had created more than 250, 000 counterfeit web pages no real person was visiting. White Ops first spotted the criminal operation in October, and it is making up to $5 million per day — by generating up to 300 million fake “video impressions” daily. According to White Ops, criminals acquired massive blocks of IP addresses — 500, 000 of them — from two of the world’s five major internet registries. Then they configured them so that they appeared to be located all over the United States. They built custom software so that computers (at those legitimate data centers) acted like real people viewing those ads. These “people” even appeared to have Facebook accounts (they didn’t), so that premium ads were served. Hackers fooled ad fraud blockers because they figured out how to build software that mimicked a real person who only surfed during the daytime — using the Google Chrome web browser on a Macbook laptop. Read more of this story at Slashdot.

Read More:
Russian Hackers Stole $5 Million Per Day From Advertisers With Bots and Fake Websites

Amazon Is Secretly Building an ‘Uber For Trucking’ App, Setting Its Sights On a Massive $800 Billion Market

Amazon is building an app that matches truck drivers with shippers, a new service that would deepen its presence in the $800 billion trucking industry, a person with direct knowledge of the matter told Business Insider. From the report: The app, scheduled to launch next summer, is designed to make it easier for truck drivers to find shippers that need goods moved, much in the way Uber connects drivers with riders. It would also eliminate the need for a third-party broker, which typically charges a commission of about 15% for doing the middleman work. The app will offer real-time pricing and driving directions, as well as personalized features such as truck-stop recommendations and a suggested “tour” of loads to pick up and drop off. It could also have tracking and payment options to speed up the entire shipping process. Read more of this story at Slashdot.

Continue Reading:
Amazon Is Secretly Building an ‘Uber For Trucking’ App, Setting Its Sights On a Massive $800 Billion Market

Linux Mint 18.1 ‘Serena’ Is Here For Christmas

Long time reader BrianFagioli writes: if you love Linux Mint and use it regularly, I have very good news — version 18.1 ‘Serena’ is finally here. There are two desktop environments from which to choose — Cinnamon and Mate. Regardless of which version you choose, please know that it is based on Ubuntu 16.04, which offers long-term support (LTS). In other words, Linux Mint 18.1 will be supported until 2021. Linux Mint 18.1 comes with the updated Cinnamon 3.2 which looks to be wonderful. The Mint team touts a new screensaver/ login screen in the desktop environment, and yeah, it looks good. Read more of this story at Slashdot.

Read More:
Linux Mint 18.1 ‘Serena’ Is Here For Christmas

A $300 Device Can Steal Mac FileVault2 Passwords

An anonymous reader writes: Swedish hardware hacker Ulf Frisk has created a device that can extract Mac FileVault2 (Apple’s disk encryption utility) passwords from a device’s memory before macOS boots and anti-DMA protections kick in. The extracted passwords are in cleartext, and they also double as the macOS logon passwords. The attack requires physical access, but it takes less than 30 seconds to carry out. A special device is needed, which runs custom software (available on GitHub), and uses hardware parts that cost around $300. Apple fixed the attack in macOS 10.12.2. The device is similar to what Samy Kamker created with Poison Tap. Read more of this story at Slashdot.

Continue Reading:
A $300 Device Can Steal Mac FileVault2 Passwords

Microsoft Will Soon Start Bundling Drivers With Windows Store Games

Microsoft will start bundling drivers with Windows Store games to improve the performance of the game once downloaded. A report on Thurrott adds: This will work by the game download trigging Windows Update to acquire the minimum driver requirements to make sure that application works as intended. This may perturb some users who like having complete control over the driver updates for their hardware as this auto-download mechanism will overwrite the existing installation of the driver. Of course, you can still roll-back the update but hopefully Microsoft gives us a way to stop the auto-download of the driver via the Windows Store when this feature arrives. Read more of this story at Slashdot.

Excerpt from:
Microsoft Will Soon Start Bundling Drivers With Windows Store Games

First Version of Sandboxed Tor Browser Available

An anonymous reader writes: To protect Tor users from FBI hacking tools that include all sorts of Firefox zero-days, the Tor Project started working on a sandboxed version of the Tor Browser in September. Over the weekend, the Tor Project released the first alpha version of the sandboxed Tor Browser. “Currently, this version is in an early alpha stage, and only available for Linux, ” reports BleepingComputer. “There are also no binaries available, and users must compile it themselves from the source code, which they can grab from here.” The report notes: “Sandboxing is a security mechanism employed to separate running processes. In computer security, sandboxing an application means separating its process from the OS, so vulnerabilities in that app can’t be leveraged to extend access to the underlying operating system. This is because the sandboxed application works with its own separate portion of disk and memory that isn’t linked with the OS.” Read more of this story at Slashdot.

Originally posted here:
First Version of Sandboxed Tor Browser Available

Disney IT Workers, In Lawsuit, Claim Discrimination Against Americans

dcblogs quotes a report from Computerworld: After Disney IT workers were told in October 2014 of the plan to use offshore outsourcing firms, employees said the workplace changed. The number of South Asian workers in Disney technology buildings increased, and some workers had to train H-1B-visa-holding replacements. Approximately 250 IT workers were laid off in January 2015. Now 30 of these employees filed a lawsuit on Monday in U.S. District Court in Orlando, alleging discrimination on the basis of national origin and race. The Disney IT employees, said Sara Blackwell, a Florida labor attorney who is representing this group, “lost their jobs when their jobs were outsourced to contracting companies. And those companies brought in mostly, or virtually all, non-American national origin workers, ” she said. The lawsuit alleges that Disney terminated the employment of the plaintiffs “based solely on their national origin and race, replacing them with Indian nationals.” The people who were laid off were multiple races, but the people who came in were mostly one race, said Blackwell. The lawsuit alleges that Disney terminated the employment of the plaintiffs “based solely on their national origin and race, replacing them with Indian nationals.” Read more of this story at Slashdot.

More:
Disney IT Workers, In Lawsuit, Claim Discrimination Against Americans

5-Year-Old Critical Linux Vulnerability Patched

msm1267 quotes Kaspersky Lab’s ThreatPost: A critical, local code-execution vulnerability in the Linux kernel was patched more than a week ago, continuing a run of serious security issues in the operating system, most of which have been hiding in the code for years. Details on the vulnerability were published Tuesday by researcher Philip Pettersson, who said the vulnerable code was introd in August 2011. A patch was pushed to the mainline Linux kernel December 2, four days after it was privately disclosed. Pettersson has developed a proof-of-concept exploit specifically for Ubuntu distributions, but told Threatpost his attack could be ported to other distros with some changes. The vulnerability is a race condition that was discovered in the af_packet implementation in the Linux kernel, and Pettersson said that a local attacker could exploit the bug to gain kernel code execution from unprivileged processes. He said the bug cannot be exploited remotely. “Basically it’s a bait-and-switch, ” the researcher told Threatpost. “The bug allows you to trick the kernel into thinking it is working with one kind of object, while you actually switched it to another kind of object before it could react.” Read more of this story at Slashdot.

View original post here:
5-Year-Old Critical Linux Vulnerability Patched

Paris Makes All Public Transportation Free In Battle Against ‘Worst Air Pollution For 10 Years’

Paris has barred some cars from its streets and has made public transportation free as it suffers from the worst and most prolonged winter pollution for at least 10 years, the Airparif agency said on Wednesday. The Independent reports: Authorities have said only drivers with odd-numbered registration plates can drive in the capital region on Wednesday. Drivers of even-numbered cars were given the same opportunity on Tuesday, but could now be fined up to 35 EUR if they are caught behind the wheel. More than 1, 700 motorists were fined for violations on Tuesday. Paris mayor Anne Hidalgo said images of smog blanketing the capital were proof of the need to reduce vehicle use in the city center. The air pollution peak is due to the combination of emissions from vehicles and from domestic wood fires as well as near windless conditions which means pollutants have not been dispersed, the Airparif agency said. “This is a record period (of pollution) for the last 10 years, ” Karine Leger of AirParif told AFP by telephone. For more than a week, Airparif has published readings of PM10 at more than 80 micrograms per cubic meter of air particles, triggering the pollution alert. Along with odd-numbered cars, hybrid or electric vehicles as well as those carrying three or more people will be allowed to roam the roads. Foreign and emergency vehicles will be unaffected. Read more of this story at Slashdot.

View post:
Paris Makes All Public Transportation Free In Battle Against ‘Worst Air Pollution For 10 Years’

Earth’s Day Lengthens By Two Milliseconds a Century, Astronomers Find

Researchers at Durham University and the UK’s Nautical Almanac Office compiled nearly 3, 000 years of celestial records and found that with every passing century, the day on Earth lengthens by two milliseconds as the planet’s rotation gradually winds down. The Guardian reports: The split second gained since the first world war may not seem much, but the time it takes for a sunbeam to travel 600km towards Earth can cost an Olympic gold medal, as the American Tim McKee found out when he lost to Sweden’s Gunnar Larsson in 1972. For those holding out for a whole extra hour a day, be prepared for a long wait. Barring any change in the rate of slowing down, an Earth day will not last 25 hours for about two million centuries more. Researchers at Durham University and the UK’s Nautical Almanac Office gathered historical accounts of eclipses and other celestial events from 720BC to 2015. The oldest records came from Babylonian clay tablets written in cuneiform, with more added from ancient Greek texts, such as Ptolemy’s 2nd century Almagest, and scripts from China, medieval Europe and the Arab dominions. The ancient records captured the times and places that people witnessed various stages of solar and lunar eclipses, while documents from 1600AD onwards described lunar occultations, when the moon passed in front of particular stars and blocked them from view. To find out how the Earth’s rotation has varied over the 2, 735-year-long period, the researchers compared the historical records with a computer model that calculated where and when people would have seen past events if Earth’s spin had remained constant. The astronomers found that Earth’s spin would have slowed down even more had it not been for a counteracting process. Since the end of the most recent ice age, land masses that were once buried under slabs of frozen water have been unloaded and sprung back into place. The shift caused the Earth to be less oblate — or squished — on its axis. And just as a spinning ice skater speeds up when she pulls in her arms, so the Earth spins faster when its poles are less compressed. Changes in the world’s sea levels and electromagnetic forces between Earth’s core and its rocky mantle had effects on Earth’s spin too, according to the scientists’ report in Proceedings of the Royal Society. Read more of this story at Slashdot.

Visit site:
Earth’s Day Lengthens By Two Milliseconds a Century, Astronomers Find