Nearly 3,000 Bitcoin Miners Exposed Online Via Telnet Ports, Without Passwords

An anonymous reader quotes a report from Bleeping Computer: Dutch security researcher Victor Gevers has discovered 2, 893 Bitcoin miners left exposed on the internet with no passwords on their Telnet port. Gevers told Bleeping Computer in a private conversation that all miners process Bitcoin transactions in the same mining pool and appear to belong to the same organization. “The owner of these devices is most likely a state sponsored/controlled organization part of the Chinese government, ” Gevers says, basing his claims on information found on the exposed miners and IP addresses assigned to each device. “At the speed they were taken offline, it means there must be serious money involved, ” Gevers added. “A few miners is not a big deal, but 2, 893 [miners] working in a pool can generate a pretty sum.” According to a Twitter user, the entire network of 2, 893 miners Gevers discovered could generate an income of just over $1 million per day, if mining Litecoin. Read more of this story at Slashdot.

View original post here:
Nearly 3,000 Bitcoin Miners Exposed Online Via Telnet Ports, Without Passwords

Hacker Claims To Have Decrypted Apple’s Secure Enclave Processor Firmware

According to iClarified, a hacker by name of “xerub” has posted the decryption key for Apple’s Secure Enclave Processor (SEP) firmware. “The security coprocessor was introduced alongside the iPhone 5s and Touch ID, ” reports iClarified. “It performs secure services for the rest of the SOC and prevents the main processor from getting direct access to sensitive data. It runs its own operating system (SEPOS) which includes a kernel, drivers, services, and applications.” From the report: The Secure Enclave is responsible for processing fingerprint data from the Touch ID sensor, determining if there is a match against registered fingerprints, and then enabling access or purchases on behalf of the user. Communication between the processor and the Touch ID sensor takes place over a serial peripheral interface bus. The processor forwards the data to the Secure Enclave but can’t read it. It’s encrypted and authenticated with a session key that is negotiated using the device’s shared key that is provisioned for the Touch ID sensor and the Secure Enclave. The session key exchange uses AES key wrapping with both sides providing a random key that establishes the session key and uses AES-CCM transport encryption. Today, xerub announced the decryption key “is fully grown.” You can use img4lib to decrypt the firmware and xerub’s SEP firmware split tool to process. Decryption of the SEP Firmware will make it easier for hackers and security researchers to comb through the SEP for vulnerabilities. Read more of this story at Slashdot.

Read the article:
Hacker Claims To Have Decrypted Apple’s Secure Enclave Processor Firmware

Salesforce Fires Red Team Staffers Who Gave Defcon Talk

Josh Schwartz, Salesforce’s director of offensive security, and John Cramb, a senior offensive security engineer, have been fired by the company after they gave talk at the Defcon security conference talk in Las Vegas last month, reports ZDNet. Schwartz and Cramb were presenting the details of their tool, called Meatpistol, a “modular malware implant framework (PDF)” similar in intent to the Metasploit toolkit used by many penetration testers. The tool, “pitched as taking ‘the boring work’ out of pen-testing to make red teams, including at Salesforce, more efficient and effective”, was anticipated to be released as open source at the time of the presentation, but Salesforce has held back the code. From the report: The two were fired “as soon as they got off stage” by a senior Salesforce executive, according to one of several people who witnessed the firing and offered their accounts. The unnamed Salesforce executive is said to have sent a text message to the duo half an hour before they were expected on stage to not to give the talk, but the message wasn’t seen until after the talk had ended. The talk had been months in the making. Salesforce executives were first made aware of the project in a February meeting, and they had signed off on the project, according to one person with knowledge of the meeting. The tool was expected to be released later as an open-source project, allowing other red teams to use the project in their own companies. But in another text message seen by Schwartz and Cramb an hour before their talk, the same Salesforce executive told the speakers that they should not announce the public release of the code, despite a publicized and widely anticipated release. Later, on stage, Schwartz told attendees that he would fight to get the tool published. Read more of this story at Slashdot.

Read the original post:
Salesforce Fires Red Team Staffers Who Gave Defcon Talk

AMD Ryzen Threadripper Launched: Performance Benchmarks Vs Intel Skylake-X

Reader MojoKid writes: AMD continues its attack on the desktop CPU market versus Intel today, with the official launch of the company’s Ryzen Threadripper processors. Threadripper is AMD’s high-end, many-core desktop processor, that leverages the same Zen microarchitecture that debuted with Ryzen 7. The top-end Ryzen Threadripper 1950X is a multi-chip module featuring 16 processor cores (two discrete die), with support for 32 threads. The base frequency for the 1950X is 3.4GHz, with all-core boost clocks of up to 3.7GHz. Four of the cores will regularly boost up to 4GHz, however, and power and temperature permitting, those four cores will reach 4.2GHz when XFR kicks in. The 12-core Threadripper 1920X has very similar clocks and its boost and XFR frequencies are exactly the same. The Threadripper 1920X’s base-clock, however, is 100MHz higher than its big brother, at 3.5GHz. In a litany of benchmarks with multi-threaded workloads, Threadripper 1950X and 1920X high core-counts, in addition to strong SMT scaling, result in the best multi-threaded scores seen from any single CPU to date. Threadripper also offers massive amounts of memory bandwidth and more IO than other Intel processors. Though absolute power consumption is somewhat high, Threadrippers are significantly more efficient than AMD’s previous-generation processors. In lightly-threaded workloads, Threadripper trails Intel’s latest Skylake-X CPUs, however, which translates to lower performance in applications and games that can’t leverage all of Threadripper’s additional compute resources. Threadripper 1950X and 1920X processors are available starting today at $999 and $799, respectively. On a per-core basis, they’re less expensive than Intel Skylake-X and very competitively priced. Read more of this story at Slashdot.

View original post here:
AMD Ryzen Threadripper Launched: Performance Benchmarks Vs Intel Skylake-X

Amazon Suspends Sales of Blu Android Phones Due To Privacy Concerns

CNET reports: Amazon just put budget phone maker Blu in the penalty box. The online retailing giant told CNET that it was suspending sales of phones from Blu, known for making ultra-cheap Android handsets, due to a “potential security issue.” The move comes after security firm Kryptowire demonstrated last week how software in Blu’s phones collected data and sent it to servers in China without alerting people. Blu defended the software, created by a Chinese company called Shanghai Adups Technology, and denied any wrongdoing. A company spokeswoman said at the time it “has several policies in place which take customer privacy and security seriously.” She added there had been no breaches. Blu said it was in a process of review to reinstate the phones at Amazon. Read more of this story at Slashdot.

Originally posted here:
Amazon Suspends Sales of Blu Android Phones Due To Privacy Concerns

CNET Pranked By Web Site’s Fake ‘All Out War’ Hack During DEFCON

In a piece describing the paranoid vibe in Las Vegas during the DEFCON convention, CNET reported Friday that the Wet Republic web site “had two images vandalized” with digital graffiti. But their reporter now writes that “my paranoia finally got the best of me, and it turned out to be an ad campaign.” The images included a scribbled beard and eye patch on a photo of bikini model, along with the handwritten message “It’s all out war.” CNET’s updated story now reports that “It looked like a prank you’d see from a mischievous hacker…” When I spotted the vandalism on the Wet Republic site Friday morning, it looked like other attacks I’d seen throughout the week, such as a Blue Screen of Death on a bus ticket machine… Hakkasan, which hosts the event at MGM Grand, said the “vandalism” was part of the cheeky advertisements for a seasonal bikini contest it’s been running since 2015. The “all-out war” is between the models in the competition, not between hackers and clubs. Hakkasan’s spokeswoman said nothing on its network has been compromised. So maybe not everything online in Las Vegas is getting hacked this week, and this n00b learned to calm down the hard way. For that matter, maybe that blue screen of death was also just another random Windows machine crashing. CNET’s reporter made one other change to his article. He removed the phrase “when hackers are in town for Defcon, everything seems to be fair game.” Read more of this story at Slashdot.

Visit link:
CNET Pranked By Web Site’s Fake ‘All Out War’ Hack During DEFCON

Fourth Ethereum Platform Hacked This Month: Hacker Steals $8.4 Million From Veritaseum Platform

An anonymous reader writes: “Veritaseum has confirmed today that a hacker stole $8.4 million from the platform’s ICO on Sunday, July 23, ” reports Bleeping Computer. “This is the second ICO hack in the last week and the fourth hack of an Ethereum platform this month. An ICO (Initial Coin Offering) is similar to a classic IPO (Initial Public Offering), but instead of stocks in a company, buyers get tokens in an online platform. Users can keep tokens until the issuing company decides to buy them back, or they can sell the tokens to other users for Ethereum. Veritaseum was holding its ICO over the weekend, allowing users to buy VERI tokens for a product the company was preparing to launch in the realm of financial services.” The hacker breached its systems, stole VERI tokens and immediately dumped them on the market due to the high-demand. The hacker made $8.4 million from the token sale, which he immediately started to launder. In a post-mortem announcement, Middleton posted online today, the Veritaseum CEO said “the amount stolen was miniscule (less than 00.07%) although the dollar amount was quite material.” The CEO also suspects that “at least one corporate partner that may have dropped the ball and [might] be liable.” Previous Ethereum services hacks include Parity, CoinDash, and Classic Ether Wallet. Read more of this story at Slashdot.

See the original post:
Fourth Ethereum Platform Hacked This Month: Hacker Steals $8.4 Million From Veritaseum Platform

SoundCloud Has Enough Money To Survive Only 80 Days, Report Claims

Last week, SoundCloud announced it is cutting about 40 percent of its staff and closing two offices. Now, a report from TechCrunch claims “the layoffs only saved the company enough money to have runway ‘until Q4’ — which begins in just 80 days.” From the report: That seems to conflict with the statement Ljung released alongside the layoffs, which noted that, “With more focus and a need to think about the long term, comes tough decisions.” The company never mentioned how short its cash would still last. We reached out to Ljung and SoundCloud for this story and PR responded to the request reiterating Ljung blog post. After being presented with the leaked information from the all-hands, SoundCloud PR admitted that, “We are fully funded into Q4, ” though it says it’s in talks with potential investors. But further funding would require faith in SoundCloud that its own staff lacks. When asked about morale of the remaining team, one employee who asked to remain anonymous told TechCrunch “it’s pretty shitty. Pretty somber. I know people who didn’t get the axe are actually quitting. The people saved from this are jumping ship. The morale is really low.” Read more of this story at Slashdot.

Read More:
SoundCloud Has Enough Money To Survive Only 80 Days, Report Claims

Germany Says Cyber Threat Greater Than Expected, More Firms Affected

From a Reuters report, shared by a few readers on Twitter: Germany’s BSI federal cyber agency said on Friday that the threat posed to German firms by recent cyber attacks launched via a Ukrainian auditing software was greater than expected, and some German firms had seen production halted for over a week. Analyses by computer experts showed that waves of attacks had been launched via software updates of the M.E.Doc accounting software since April, the BSI said in a statement. Read more of this story at Slashdot.

Read more here:
Germany Says Cyber Threat Greater Than Expected, More Firms Affected

Chinese Court Seizes Millions in Assets of LeEco Founder as Conglomerate’s Troubles Grow

Chinese Internet tycoon and LeEco founder Jia Yueting’s ambition to challenge the likes of Apple and Tesla looks even more in doubt after $182 million of his assets were frozen by a Shanghai court following unpaid loans. From a report: Jia and LeEco came in for stinging criticism from Chinese media Wednesday, which warned that the Internet streaming company and hardware manufacturer was set to fall into further trouble, with the asset freeze as only the beginning. LeEco’s development “is too big, too quick and too reckless, ” Beijing Business Today wrote. “Developing TV [programs and TV sets], mobile phones, [electric] cars and sports programs all consume too much cash at the same time. Not only can the capital not sustain these developments; fractures are inevitable in areas ranging from human resources, technology and management.” According to the official Xinhua news agency, the Shanghai High People’s Court last week ruled in favor of China Merchants Bank’s application to freeze $182 million in assets belonging to Jia, his wife and three LeEco affiliates. Further reading: LeEco Said To Lay Off Over 80 Percent of US Workforce, LeEco’s CEO Jia Yueting Says Company Overstretched, Now Running Out of Cash, and China’s LeEco Calls Off Its $2 Billion Purchase of TV Maker Vizio. Read more of this story at Slashdot.

View the original here:
Chinese Court Seizes Millions in Assets of LeEco Founder as Conglomerate’s Troubles Grow