Microsoft Word Zero-Day Used In Targeted Attacks

wiredmikey (1824622) writes “Microsoft warned on Monday of a remote code execution vulnerability (CVE-2014-1761) in Microsoft Word 2010 that is being actively exploited in targeted attacks. If successfully exploited, an attacker could gain the same user rights as the current user, Microsoft said, noting that users whose accounts are configured to have fewer user rights on the system could be less impacted than accounts with administrative privileges. ‘The vulnerability could allow remote code execution if a user opens a specially crafted RTF file using an affected version of Microsoft Word, or previews or opens a specially crafted RTF email message in Microsoft Outlook while using Microsoft Word as the email viewer, ‘ Microsoft explained Microsoft did not share any details on the attacks that leveraged the vulnerability, but did credit Drew Hintz, Shane Huntley, and Matty Pellegrino of the Google Security Team for reporting it to Microsoft.” Read more of this story at Slashdot.

See original article:
Microsoft Word Zero-Day Used In Targeted Attacks

Cisco Plans $1B Investment In Cloud

itwbennett (1594911) writes “Cisco Systems said Monday it plans to invest over $1 billion to expand its cloud business over the next two years, including building a global, OpenStack-based ‘network of clouds’ that it has dubbed the ‘intercloud’. The Intercloud will support any workload, on any hypervisor and interoperate with any cloud, both private and public, according to Cisco.” Read more of this story at Slashdot.

Read this article:
Cisco Plans $1B Investment In Cloud

Navy Database Tracks Civilians’ Parking Tickets, Fender-Benders

schwit1 (797399) writes with this excerpt from the Washington Examiner: “A parking ticket, traffic citation or involvement in a minor fender-bender are enough to get a person’s name and other personal information logged into a massive, obscure federal database run by the U.S. military. The Law Enforcement Information Exchange, or LinX, has already amassed 506.3 million law enforcement records ranging from criminal histories and arrest reports to field information cards filled out by cops on the beat even when no crime has occurred.” Read more of this story at Slashdot.

More here:
Navy Database Tracks Civilians’ Parking Tickets, Fender-Benders

Python 3.4 Released

New submitter gadfium writes: “Python 3.4 has been released. It adds new library features, bug fixes, and security improvements. It includes: at standardized implementation of enumeration types, a statistics module, improvements to object finalization, a more secure and interchangeable hash algorithm for strings and binary data, asynchronous I/O support, and an installer for the pip package manager.” Read more of this story at Slashdot.

Excerpt from:
Python 3.4 Released

Project Morpheus: Sony’s Oculus Rift Competitor Looks Incredible

It was only a matter of time. The Oculus Rift has caught so much attention—deservedly so—that of course one of the big dogs was going to start honing in on its virtual reality territory. Tonight, that’s Sony. And its Project Morpheus VR headset sounds fantastic. Read more…        

Read the original post:
Project Morpheus: Sony’s Oculus Rift Competitor Looks Incredible

Firefox 28 Arrives With VP9 Video Decoding, HTML5 Volume Controls

An anonymous reader writes “Mozilla today officially launched Firefox 28 for Windows, Mac, Linux, and Android. Additions include VP9 video decoding, Web notifications on OS X, and volume controls for HTML5 video and audio. Firefox 28 has been released over on Firefox.com and all existing users should be able to upgrade to it automatically. The full release notes are available. As always, the Android version is trickling out slowly on Google Play (Android release notes).” Mozilla also announced tools to bring the Unity game engine to WebGL and asm.js. Read more of this story at Slashdot.

See more here:
Firefox 28 Arrives With VP9 Video Decoding, HTML5 Volume Controls

Is DIY Brainhacking Safe?

An anonymous reader writes “My colleague at IEEE Spectrum, Eliza Strickland, looked at the home transcranial direct current stimulation (tDCS) movement. People looking to boost creativity, or cure depression, are attaching electrodes to their heads using either DIT equipment or rigs from vendors like Foc.us. Advocates believe experimenting with the tech is safe, but a neuroscientist worries about removing the tech from lab safeguards…” Read more of this story at Slashdot.

View original post here:
Is DIY Brainhacking Safe?

43,000-Year-Old Woolly Mammoth Remains Offer Strong Chance of Cloning

EwanPalmer sends a followup to a story from last year about a team of Siberian scientists who recovered an ancient wooly mammoth carcass. It was originally believed to be about 10, 000 years old, but subsequent tests showed the animal died over 43, 000 years ago. The scientists have been surprised by how well preserved the soft tissues were. They say it’s in better shape than a human body buried for six months. “The tissue cut clearly shows blood vessels with strong walls. Inside the vessels there is haemolysed blood, where for the first time we have found erythrocytes. Muscle and adipose tissues are well preserved.” The mammoth’s intestines contain vegetation from its last meal, and they have the liver as well. The scientists are optimistic that they’ll be able to find high quality DNA from the mammoth, and perhaps even living cells. They now say there’s a “high chance” that data would allow them to clone the mammoth. Read more of this story at Slashdot.

See more here:
43,000-Year-Old Woolly Mammoth Remains Offer Strong Chance of Cloning

Weak Apple PRNG Threatens iOS Exploit Mitigations

Trailrunner7 writes “A revamped early random number generator in iOS 7 is weaker than its vulnerable predecessor and generates predictable outcomes. A researcher today at CanSecWest said an attacker could brute force the Early Random PRNG used by Apple in its mobile operating system to bypass a number of kernel exploit mitigations native to iOS. ‘The Early Random PRNG in iOS 7 is surprisingly weak, ‘ said Tarjei Mandt senior security researcher at Azimuth Security. ‘The one in iOS 6 is better because this one is deterministic and trivial to brute force.’ The Early Random PRNG is important to securing the mitigations used by the iOS kernel. ‘All the mitigations deployed by the iOS kernel essentially depend on the robustness of the Early Random PRNG, ‘ Mandt said. ‘It must provide sufficient entropy and non-predictable output.'” Read more of this story at Slashdot.

View original post here:
Weak Apple PRNG Threatens iOS Exploit Mitigations

XKCD Author’s Unpublished Book Has Already Become a Best-Seller

destinyland writes “Wednesday the geeky cartoonist behind XKCD announced that he’d publish a new book answering hypothetical science questions in September. And within 24 hours, his as-yet-unpublished work had become Amazon’s #2 best-selling book. ‘Ironically, this book is titled What If?, ‘ jokes one blogger, noting it resembles an XKCD comic where ‘In our yet-to-happen future, this book decides to travel backwards through time, stopping off in March of 2014 to inform Amazon’s best-seller list that yes, in our coming timeline this book will be widely read…’ Randall Munroe’s new book will be collecting his favorite ‘What If…’ questions, but will also contain his never-before published answers to some questions that he’d found ‘particularly neat.'” Read more of this story at Slashdot.

More:
XKCD Author’s Unpublished Book Has Already Become a Best-Seller