NYU Accidentally Exposed Military Code-breaking Computer Project To Entire Internet

An anonymous reader writes: A confidential computer project designed to break military codes was accidentally made public by New York University engineers. An anonymous digital security researcher identified files related to the project while hunting for things on the internet that shouldn’t be, The Intercept reported. He used a program called Shodan, a search engine for internet-connected devices, to locate the project. It is the product of a joint initiative by NYU’s Institute for Mathematics and Advanced Supercomputing, headed by the world-renowned Chudnovsky brothers, David and Gregory, the Department of Defense, and IBM. Information on an exposed backup drive described the supercomputer, called — WindsorGreen — as a system capable of cracking passwords. Read more of this story at Slashdot.

View original post here:
NYU Accidentally Exposed Military Code-breaking Computer Project To Entire Internet

NYU Accidentally Exposed Military Code-breaking Computer Project To Entire Internet

An anonymous reader writes: A confidential computer project designed to break military codes was accidentally made public by New York University engineers. An anonymous digital security researcher identified files related to the project while hunting for things on the internet that shouldn’t be, The Intercept reported. He used a program called Shodan, a search engine for internet-connected devices, to locate the project. It is the product of a joint initiative by NYU’s Institute for Mathematics and Advanced Supercomputing, headed by the world-renowned Chudnovsky brothers, David and Gregory, the Department of Defense, and IBM. Information on an exposed backup drive described the supercomputer, called — WindsorGreen — as a system capable of cracking passwords. Read more of this story at Slashdot.

View original post here:
NYU Accidentally Exposed Military Code-breaking Computer Project To Entire Internet

NYU Accidentally Exposed Military Code-breaking Computer Project To Entire Internet

An anonymous reader writes: A confidential computer project designed to break military codes was accidentally made public by New York University engineers. An anonymous digital security researcher identified files related to the project while hunting for things on the internet that shouldn’t be, The Intercept reported. He used a program called Shodan, a search engine for internet-connected devices, to locate the project. It is the product of a joint initiative by NYU’s Institute for Mathematics and Advanced Supercomputing, headed by the world-renowned Chudnovsky brothers, David and Gregory, the Department of Defense, and IBM. Information on an exposed backup drive described the supercomputer, called — WindsorGreen — as a system capable of cracking passwords. Read more of this story at Slashdot.

View article:
NYU Accidentally Exposed Military Code-breaking Computer Project To Entire Internet

Encrypted WhatsApp Message Recovered From Westminster Terrorist’s Phone

Bruce66423 brings word that a terrorist’s WhatsApp message has been decrypted “using techniques that ‘cannot be disclosed for security reasons’, though ‘sources said they now have the technical expertise to repeat the process in future.'” The Economic Times reports: U.K. security services have managed to decode the last message sent out by Khalid Masood before he rammed his high-speed car into pedestrians on Westminster Bridge and stabbed to death a police officer at the gates of Parliament on March 22. The access to Masood’s message was achieved by what has been described by security sources as a use of “human and technical intelligence”… The issue of WhatsApp’s encrypted service, which is closed to anyone besides the sender and recipient, had come under criticism soon after the attack. “It’s completely unacceptable. There should be no place for terrorists to hide. We need to make sure that organisations like WhatsApp, and there are plenty of others like that, don’t provide a secret place for terrorists to communicate with each other, ” U.K. home secretary Amber Rudd had said. Security sources say the message showed the victim’s motive was military action in Muslim countries, while the article adds that though ISIS claimed responsibility for the attack, “no evidence has emerged to back this up.” Read more of this story at Slashdot.

Originally posted here:
Encrypted WhatsApp Message Recovered From Westminster Terrorist’s Phone

A Database of Thousands of Credit Cards Was Left Exposed on the Open Internet

A US online pet store has exposed the details of more than 110, 400 credit cards used to make purchases through its website, researchers have found. From a report on ZDNet: In a stunning show of poor security, the Austin, TX-based company FuturePets.com exposed its entire customer database, including names, postal and email addresses, phone numbers, credit card information, and plain-text passwords. Several customers that we reached out to confirmed some of their information when it was provided by ZDNet, but did not want to be named. The database was exposed because of the company’s own insecure server and use of “rsync, ” a common protocol used for synchronizing copies of files between two different computers, which wasn’t protected with a username or password. Read more of this story at Slashdot.

Read the original:
A Database of Thousands of Credit Cards Was Left Exposed on the Open Internet

Holiday Inn Cops to Massive Credit Card Data Breach

It seems like every day there’s news of another significant data breach, so here’s today’s: An internal investigation by the InterContinental Hotel Group, which owns Holiday Inn, has revealed that guests at more than a thousand of their hotels had their credit card details stolen. The company identified malware on… Read more…

See more here:
Holiday Inn Cops to Massive Credit Card Data Breach

NSA-Leaking Shadow Brokers Just Dumped Its Most Damaging Release Yet

An anonymous reader quotes a report from Ars Technica: The Shadow Brokers — the mysterious person or group that over the past eight months has leaked a gigabyte worth of the National Security Agency’s weaponized software exploits — just published its most significant release yet. Friday’s dump contains potent exploits and hacking tools that target most versions of Microsoft Windows and evidence of sophisticated hacks on the SWIFT banking system of several banks across the world. Friday’s release — which came as much of the computing world was planning a long weekend to observe the Easter holiday — contains close to 300 megabytes of materials the leakers said were stolen from the NSA. The contents (a convenient overview is here) included compiled binaries for exploits that targeted vulnerabilities in a long line of Windows operating systems, including Windows 8 and Windows 2012. It also included a framework dubbed Fuzzbunch, a tool that resembles the Metasploit hacking framework that loads the binaries into targeted networks. Independent security experts who reviewed the contents said it was without question the most damaging Shadow Brokers release to date. One of the Windows zero-days flagged by Hickey is dubbed Eternalblue. It exploits a remote code-execution bug in the latest version of Windows 2008 R2 using the server message block and NetBT protocols. Another hacking tool known as Eternalromance contains an easy-to-use interface and “slick” code. Hickey said it exploits Windows systems over TCP ports 445 and 139. The exact cause of the bug is still being identified. Friday’s release contains several tools with the word “eternal” in their name that exploit previously unknown flaws in Windows desktops and servers. Read more of this story at Slashdot.

Read this article:
NSA-Leaking Shadow Brokers Just Dumped Its Most Damaging Release Yet

This Nest Security Flaw Is Remarkably Dumb

The internet has made it supremely easy to install connected security cameras wherever you want. Unfortunately for Nest, that easy connectivity makes it simple for hackers to disable its cameras with just a few keystrokes. And that’s a very bad feature for a security camera. Read more…

View post:
This Nest Security Flaw Is Remarkably Dumb

Some Hackers Figured Out How to Take Control of Any WhatsApp Account

Security researchers just announced the discovery of major vulnerabilities in WhatsApp and Telegram, two popular messaging apps with end-to-end encryption, when used in an internet browser. In related news, you can use WhatsApp and Telegram in an internet browser. Read more…

See more here:
Some Hackers Figured Out How to Take Control of Any WhatsApp Account

How to Run Windows on an iPhone, No Jailbreak Required

Are you tired of using your iPhone to do all kinds of iPhone stuff? Then check out this boredom cure that lets you install and run Windows XP on an iPhone 7 without jailbreaking the device. It’s just silly fun! Read more…

See the original article here:
How to Run Windows on an iPhone, No Jailbreak Required