FDA warns that certain pacemakers are vulnerable to hacking

According to a cybersecurity notice from the Food and Drug Administration, certain pacemakers and cardiac devices are currently vulnerable to hacking. Although security researchers have warned about the security risks to medical devices for years now , this is the first time we’ve seen the government publicly acknowledge a specific threat. The vulnerable devices included under the FDA’s warning are not the pacemakers themselves, but rather the Merlin@home Transmitters made by St. Jude Medical. The transmitters are part of a home monitor that connects to pacemakers and other implanted cardiac devices using a wireless RF signal. The Merlin is designed to read the data stored on a pacemaker and then upload that data to its own cloud on the Merlin.net Patient Care Network, where a physician can access and monitor the device and the patient’s health. Although it doesn’t mention specifics of the threat, the government acknowledges that Merlin monitors could be hacked to send modified commands to a patient’s pacemaker or other device. With the right access, a hacker could do anything from deplete a pacemaker’s battery to shocking a patient or throwing off their heartbeat. On the bright side, the FDA says there have been no reported hacks and no patients have been harmed so far. To fix the problem, a software patch will be automatically applied over-the-air to affected Merlin@home devices starting today. Patients or their caregivers only need to ensure the devices are online and connected to get the fix. Source: FDA , St. Jude Medical

Original post:
FDA warns that certain pacemakers are vulnerable to hacking

How hackers made life hell for a CIA boss and other top US officials

Enlarge (credit: Flickr user Erica Zabowski ) A North Carolina man has pleaded guilty to a conspiracy that illegally accessed the e-mail and social media accounts of Central Intelligence Director John Brennan and other senior government officials and then used that access to leak sensitive information and make personal threats. Justin Gray Liverman, 24, of Morehead City, North Carolina, pleaded guilty to conspiracy to violate the Computer Fraud and Abuse Act, commit identity theft, and make harassing, anonymous phone calls, federal prosecutors said Friday . Among the 10 people targeted in the conspiracy were Brennan; then-Deputy FBI Director Mark Giuliano; National Intelligence Director James R. Clapper; Greg Mecher, the husband of White House Communication Director Jen Psaki; and other government officials. The group called itself Crackas with Attitude, and it was led by a co-conspirator going by the name of Cracka. “She talks mad shit abt snowden,” Liverman said on December 10, 2015 in an online chat with Cracka, referring to a target who is believed to be Psaki, according to a statement of facts signed by Liverman and filed in US District Court for the Eastern District of Virginia. (The document refers to Mecher and Psaki as Victim 3 and the spouse of Victim 3 respectively.) “If you come across anything related to [Victim 3’s spouse] let me know. If you find her cell or home number omg gimme.” Liverman went on to say he wanted to “phonebomb the shitt [sic] outta” Psaki. Read 7 remaining paragraphs | Comments

Visit link:
How hackers made life hell for a CIA boss and other top US officials

FTC Takes D-Link To Court Citing Lax Product Security, Privacy Perils

Reader coondoggie writes: The Federal Trade Commission has filed a complaint against network equipment vendor D-Link saying inadequate security in the company’s wireless routers and Internet cameras left consumers open to hackers and privacy violations. The FTC, in a complaint filed in the Northern District of California charged that “D-Link failed to take reasonable steps to secure its routers and Internet Protocol (IP) cameras, potentially compromising sensitive consumer information, including live video and audio feeds from D-Link IP cameras.” For its part, D-Link Systems said it “is aware of the complaint filed by the FTC.” According to the FTC’s complaint, D-Link promoted the security of its routers on the company’s website, which included materials headlined “Easy to secure” and “Advance network security.” But despite the claims made by D-Link, the FTC alleged, the company failed to take steps to address well-known and easily preventable security flaws such as “hard-coded” login credentials integrated into D-Link camera software — such as the username âoeguestâ and the password âoeguestâ — that could allow unauthorized access to the cameras’ live feed, etc. Read more of this story at Slashdot.

See the original article here:
FTC Takes D-Link To Court Citing Lax Product Security, Privacy Perils

Library Creates Fake Patron Records To Avoid Book-Purging

An anonymous reader writes: Chuck Finley checked out 2, 361 books from a Florida library in just nine months, increasing their total circulation by 3.9%. But he doesn’t exist. “The fictional character was concocted by two employees at the library, complete with a false address and driver’s license number, ” according to the Orlando Sentinel. The department overseeing the library acknowledges their general rule is “if something isn’t circulated in one to two years, it’s typically weeded out of circulation.” So the fake patron scheme was concocted by a library assistant working with the library’s branch supervisor, who “said he wanted to avoid having to later repurchase books purged from the shelf.” But according to the newspaper the branch supervisor “said the same thing is being done at other libraries, too.” Read more of this story at Slashdot.

View post:
Library Creates Fake Patron Records To Avoid Book-Purging

Bad Year For Piracy: 2016 Was The Year Torrent Giants Fell

From a report on TorrentFreak: 2016 has been a memorable year for torrent users but not in a good way. Over a period of just a few months, several of the largest torrent sites vanished from the scene. From KickassTorrents, through Torrentz to What.cd, several torrent giants have left the scene.Another notable website which vanished is TorrentHound. ThePirateBay is back, but is often facing issues. Not long ago, ExtraTorrent noted that it was on the receiving end of several DDoS attacks. Read more of this story at Slashdot.

Continued here:
Bad Year For Piracy: 2016 Was The Year Torrent Giants Fell

Russians Used Malware On Android Devices To Track and Target Ukraine Artillery, Says Report

schwit1 quotes a report from Reuters: A hacking group linked to the Russian government and high-profile cyber attacks against Democrats during the U.S. presidential election likely used a malware implant on Android devices to track and target Ukrainian artillery units from late 2014 through 2016, according to a new report released Thursday. The malware was able to retrieve communications and some locational data from infected devices, intelligence that would have likely been used to strike against the artillery in support of pro-Russian separatists fighting in eastern Ukraine, the report from cyber security firm CrowdStrike found. The hacking group, known commonly as Fancy Bear or APT 28, is believed by U.S. intelligence officials to work primarily on behalf of the GRU, Russia’s military intelligence agency. The implant leveraged a legitimate Android application developed by a Ukrainian artillery officer to process targeting data more quickly, CrowdStrike said. Its deployment “extends Russian cyber capabilities to the front lines of the battlefield, ” the report said, and “could have facilitated anticipatory awareness of Ukrainian artillery force troop movement, thus providing Russian forces with useful strategic planning information.” Read more of this story at Slashdot.

Continue Reading:
Russians Used Malware On Android Devices To Track and Target Ukraine Artillery, Says Report

Amazon Is Secretly Building an ‘Uber For Trucking’ App, Setting Its Sights On a Massive $800 Billion Market

Amazon is building an app that matches truck drivers with shippers, a new service that would deepen its presence in the $800 billion trucking industry, a person with direct knowledge of the matter told Business Insider. From the report: The app, scheduled to launch next summer, is designed to make it easier for truck drivers to find shippers that need goods moved, much in the way Uber connects drivers with riders. It would also eliminate the need for a third-party broker, which typically charges a commission of about 15% for doing the middleman work. The app will offer real-time pricing and driving directions, as well as personalized features such as truck-stop recommendations and a suggested “tour” of loads to pick up and drop off. It could also have tracking and payment options to speed up the entire shipping process. Read more of this story at Slashdot.

Continue Reading:
Amazon Is Secretly Building an ‘Uber For Trucking’ App, Setting Its Sights On a Massive $800 Billion Market

Disney IT Workers, In Lawsuit, Claim Discrimination Against Americans

dcblogs quotes a report from Computerworld: After Disney IT workers were told in October 2014 of the plan to use offshore outsourcing firms, employees said the workplace changed. The number of South Asian workers in Disney technology buildings increased, and some workers had to train H-1B-visa-holding replacements. Approximately 250 IT workers were laid off in January 2015. Now 30 of these employees filed a lawsuit on Monday in U.S. District Court in Orlando, alleging discrimination on the basis of national origin and race. The Disney IT employees, said Sara Blackwell, a Florida labor attorney who is representing this group, “lost their jobs when their jobs were outsourced to contracting companies. And those companies brought in mostly, or virtually all, non-American national origin workers, ” she said. The lawsuit alleges that Disney terminated the employment of the plaintiffs “based solely on their national origin and race, replacing them with Indian nationals.” The people who were laid off were multiple races, but the people who came in were mostly one race, said Blackwell. The lawsuit alleges that Disney terminated the employment of the plaintiffs “based solely on their national origin and race, replacing them with Indian nationals.” Read more of this story at Slashdot.

More:
Disney IT Workers, In Lawsuit, Claim Discrimination Against Americans

Google Says It Is About To Reach 100 Percent Renewable Energy

Google said today it will power 100 percent of its sprawling data centers and offices with renewable energy starting next year. The company said today it has bought enough wind and solar power to account for all the electricity it uses globally each year. In comparison, 44 percent of Google’s power supplies came from renewables last year. From a blogpost: To reach this goal we’ll be directly buying enough wind and solar electricity annually to account for every unit of electricity our operations consume, globally. And we’re focusing on creating new energy from renewable sources, so we only buy from projects that are funded by our purchases. Over the last six years, the cost of wind and solar came down 60 percent and 80 percent, respectively, proving that renewables are increasingly becoming the lowest cost option. Electricity costs are one of the largest components of our operating expenses at our data centers, and having a long-term stable cost of renewable power provides protection against price swings in energy. Read more of this story at Slashdot.

Read this article:
Google Says It Is About To Reach 100 Percent Renewable Energy

Virginia Police Spent $500K For An Ineffective Cellphone Surveillance System

Cell-site simulators can intercept phone calls and even provide locations (using GPS data). But Virginia’s state police force just revealed details about their actual use of the device — and it’s not pretty. Long-time Slashdot reader v3rgEz writes: In 2014, the Virginia State Police spent $585, 265 on a specially modified Suburban outfitted with the latest and greatest in cell phone surveillance: the DRT 1183C, affectionately known as the DRTbox. But according to logs uncovered by public records website MuckRock, the pricey ride was only used 12 times — and only worked seven of those times. According to Virginia’s ACLU director, “each of the 12 uses cost almost $50, 000, and only 4 of them resulted in an arrest [raising] a significant question whether the more than half million dollars spent on the device and the vehicle…was a wise investment of public funds.” Read more of this story at Slashdot.

Read the original post:
Virginia Police Spent $500K For An Ineffective Cellphone Surveillance System