Sophisticated botnet steals more than $47M by infecting PCs and phones

Behold—the Eurograbber, visualized. Aurich Lawson / Thinkstock A new version of the Zeus trojan—a longtime favorite of criminals conducting online financial fraud—has been used in attacks on over 30,000 electronic banking customers in Europe, infecting both their personal computers and smartphones. The sophisticated attack is designed to circumvent banks’ use of two-factor authentication for transactions by intercepting messages sent by the bank to victims’ mobile phones. The malware and botnet system, dubbed “Eurograbber” by security researchers from Check Point Software and Versafe, was first detected in Italy earlier this year. It has since spread throughout Europe. Eurograbber is responsible for more than $47 million in fraudulent transfers from victims’ bank accounts, stealing amounts from individual victims that range from 500 Euros (about $650) to 25,000 Euros (about $32,000), according to a report published Wednesday (PDF) . The malware attack begins when a victim clicks on a malicious link, possibly sent as part of a phishing attack. Clicking on the link directs them to a site that attempts to download one or more trojans: customized versions of Zeus and its SpyEye and CarBerp variants that allow attackers to record Web visits and then inject HTML and JavaScript into the victim’s browser. The next time the victim visits their bank website, the trojans capture their credentials and launch a JavaScript that spoofs a request for a “security upgrade” from the site, offering to protect their mobile device from attack. The JavaScript captures their phone number and their mobile operating system information—which are used in the second level of Eurograbber’s attack. Read 3 remaining paragraphs | Comments

Visit site:
Sophisticated botnet steals more than $47M by infecting PCs and phones

Review: 3M Streaming Projector is good, but not perfect

What happens when you combine a 4.3 x 4.2 x 2 inch projector with a wealth of streaming content services? You get the handheld, portable Streaming Projector by 3M and Roku. The two companies have teamed up to offer the best of each of their worlds in one compact package. While overall it’s a useful device, it does have a couple of kinks that need to be worked out. The 3M Streaming Projector is a neat idea, especially in a world overrun by set-top boxes. Pocket projectors have been around for a while now, so this isn’t an entirely new concept. But rather than having to connect the projector to an external device—like a smartphone or computer, the included Roku streaming stick provides the content. The projector also features dual-band Wi-Fi, so it has the same functionality as a Roku box, though its output is blown up all over the wall. Design The projector is rated at 60 lumens. The 3M Streaming Projector is easy to cart around. It’s small enough stick in a laptop bag or a purse to bring over to a friend’s house. The device features two volume buttons, as well as buttons to power on the device, sift through settings, and check on things like battery power and brightness. On one side of the projector, there’s a plug for the power supply, as well as an audio out to plug in headphones or an external speaker system. On the other side, there’s a wheel to adjust the focus of the picture to ensure that movies and slide shows aren’t blurry. The Streaming Projector can be mounted on a tripod via a ventral screw-hole, should there be a lack of tables high enough to properly display the picture on a blank wall. Read 13 remaining paragraphs | Comments

Continue Reading:
Review: 3M Streaming Projector is good, but not perfect

Review: Ubuntu 12.10 Quantal Quetzal a mix of promise, pain

Tux shares a perch with Ubuntu 12.10’s namesake bird Aurich Lawson / Thinkstock Write this down: Ubuntu 12.10, the late-year arrival from Canonical’s six-month standard release factory, marks the first new release within the company’s current long-term support cycle. Got it? Good, because it may be the best takeaway from the latest Ubuntu release, codenamed Quantal Quetzal. After that, it’s a bit of a rocky ride. The product’s development lineage is important to note from more of a business/adoption side perspective. The release of Ubuntu 12.04 LTS in April was Canonical’s fourth long-term support product and signaled the end of one full two-year development cycle. Quantal Quetzal is the first standard release on the road to pushing out Ubuntu 14.04 LTS in Spring 2014 (undoubtedly to be codenamed “Uber-rocking Unicorn” if the pattern holds), and it sets up themes and directions which will mature over the next two years. Standard releases aren’t terribly different from the bi-annual LTS products, though they tend to be slightly less conservative in code offerings. The Ubuntu development community lets off the brakes a little and sticks some shiny back in. Read 63 remaining paragraphs | Comments

Originally posted here:
Review: Ubuntu 12.10 Quantal Quetzal a mix of promise, pain

Apple’s stock price falls to lowest point in six months

On Friday Apple’s stock price closed at $527.68 per share , the lowest it’s been in six months . Since September, the company has lost about 25 percent of its value from its peak of $702 per share. So what’s gone wrong? Analysts say that Apple has had a string of misfortunes lately, ranging from missed  earnings estimates ,  management shakeups , missteps on mapping software , supply chain problems , and increased pressure from competitors. “I think it’s the perfect storm for Apple,” Van Baker, an analyst with Gartner Research, told Ars. “There’s a combination of a lot of things, and add to that, people are starting to think that Apple won’t bring out something that’s truly innovative every few years.” Read 20 remaining paragraphs | Comments

Excerpt from:
Apple’s stock price falls to lowest point in six months

Apple’s @me and @mac e-mail users now have @icloud, too

Owners of @me.com and @mac.com e-mail addresses—relics of Apple’s past attempts at offering cloud services—now own an @icloud address too. The company began sending out e-mails to those who have accounts on the old domains on Tuesday, letting them know they can now take advantage of Apple’s latest e-mail service in the form of iCloud. But worry not: if you’ve been using your old addresses but moved your account to iCloud earlier this year, you’ll still be able to keep using them (whether or not you choose to use the new @icloud.com address). The move was foreshadowed earlier this year as part of an iOS 6 prerelease beta to developers. In the iOS 6 Beta 3 changelog, Apple stated those signing up for new Apple IDs, as well as those enabling Mail on iCloud for the first time, would automatically receive an @icloud.com address. But if you had an existing @me.com address from the MobileMe days, or even a @mac.com address from the .Mac days, you would receive an iCloud address that matched the username you previously had. That appears to be the case now with Apple alerting users to the change. As pointed out by our friends at TidBITS , there’s no difference in implementation—if you want to make use of the new address, you just have to add it to your mail client. If you don’t want to use the new address, however, you don’t have to. You can stick to the old ones, as long as you weren’t one of the stubborn few who didn’t move your MobileMe account to iCloud before the beginning of August. Read on Ars Technica | Comments

Read more here:
Apple’s @me and @mac e-mail users now have @icloud, too

Google infringes old Lycos patents, must pay $30 million

Vringo is a little company that’s made a huge bet on suing Google over patents. Today that bet paid off, although to a much lesser degree than its investors hoped earlier. After a two-week trial in Virginia, a jury found that Google’s advertising system infringes two old Lycos patents purchased by Vringo in 2011, and that those patents are valid. Google and several of its advertising partners were ordered to pay a total of about $30 million. That’s a lot of money, but far less than the $493 million Vringo was seeking. According to a report  just published in the Virginian-Pilot , the jury found that Google will have to pay $15.9 million. Its advertising partners must pay smaller amounts: $7.9 million in damages for AOL, $6.6 million for IAC Search & Media, $98,800 for Target, and $4,000 for Gannett. The jury also said Google should pay an ongoing royalty; but whether that ultimately sticks is up to the judge. The Vringo case is remarkable for two reasons: first, it’s rare to see a high-profile patent attack played out directly in the stock market, with investors speculating on each move in court. Second, demonstratives submitted in Vringo’s case show a fascinating story in pictures of how a company that’s more or less a “patent troll” tries to convince a jury to shower it with money. Some of those visuals are posted below. Read 11 remaining paragraphs | Comments

View the original here:
Google infringes old Lycos patents, must pay $30 million

Kim Dotcom now plans to give New Zealand free broadband pipe to US

The route of the proposed trans-Pacific fiber link. Pacific Fibre On the heels of the announcement of Megaupload’s pending resurrection as Me.ga , Kim Dotcom has come up with a yet another way to promote himself, annoy the US and New Zealand governments, and rally public support in his battle to stop his extradition and end the copyright infringement case against him: he wants to give everyone in New Zealand free broadband service. The core of the plan is to revive the failed Pacific Fibre , an effort to create a broadband link from Australia and New Zealand directly to the US by way of a submarine cable to Los Angeles. The effort went bankrupt in August before reaching its goal. Dotcom’s plan is to complete the link, and to sell high-speed connections to government, businesses and foreign telecommunications companies—while giving New Zealand ISPs free access to provide connectivity for individual residents. “For every foreign user downloading from NZ (paid),” Dotcom posted on Twitter, “a Kiwi can download from outside NZ (free). The key: Storing data foreign users want in NZ.” Dotcom contends that the high-speed link would make New Zealand an attractive location for data centers; the country’s current shortage of global connectivity makes it an “Internet backwater,” he said. Read 9 remaining paragraphs | Comments

See the original article here:
Kim Dotcom now plans to give New Zealand free broadband pipe to US

How Georgia doxed a Russian hacker (and why it matters)

Aurich Lawson On October 24, the country of Georgia took an unusual step: it posted to the Web a 27-page writeup  (PDF), in English, on how it has been under assault from a hacker allegedly based in Russia. The paper included details of the malware used, how it spread, and how it was controlled. Even more unusually, the Georgians released pictures of the alleged hacker—taken with his own webcam after the Georgians hacked the hacker with the help of the FBI and others. The story itself, which we covered briefly earlier this week , is fascinating, though it remains hard to authenticate and is relayed in a non-native English that makes for some tough reading. But what caught my eye about the whole cloak-and-dagger tale is the broader points it makes about hacking, jurisdiction, and the powerful surveillance devices that our computers have become. It’s also an example of how hacks and the alleged hackers behind them today play an increasing role in upping geopolitical suspicions between countries already wary of one another. Georgia and Russia have of course been at odds for years, and their conflict came to a head in a brief 2008 war; Russia still maintains a military presence in two tiny breakaway enclaves that Georgia claims as its own. Read 29 remaining paragraphs | Comments

See more here:
How Georgia doxed a Russian hacker (and why it matters)

Sharp says there is “material doubt” over its corporate survival

Sharp , the century-old stalwart of Japanese electronics, is in deep trouble . On Thursday, the company said it sustained a ¥249.1 billion ($3.12 billion) loss for its latest quarter, the second year it had suffered record deficits. The company still has about $10 billion of debt. “As operating and net loss for the six months ended September 30, 2012 were huge, continuing from the previous year, cash flows from operating activities were negative,” the company wrote in its quarterly earnings report (PDF). Read 5 remaining paragraphs | Comments

See more here:
Sharp says there is “material doubt” over its corporate survival

Facebook tries cloaking probe into data leak involving 1 million accounts

Facebook officials told a blogger to keep their discussions with him private as they investigate claims he acquired names and e-mail addresses belonging almost one million account holders for $5 through a publicly available service online. “Oh and by the way, you are not allowed to disclose any part of this conversation,” member’s of Facebook’s platform policy team said during a tape-recorded telephone conversation, according to a blog post published by Bogomil Shopov, who describes himself as a “community and technology geek” who lives in Prague, Czech Republic. “It is a secret that we are even having this conversation.” Shopov said Facebook officials set up the conversation after an earlier blog post claiming he purchased data for one million Facebook users online for just $5. The blogger said it was impossible for him to determine exactly how recent the data was, although several of the entries he checked contained accurate e-mail addresses for people he knew. In addition to containing names and e-mail addresses, the cache he purchased also contained profile IDs. In an e-mail to Ars, Shopov said he suspects the data came from a third-party developer. The website selling the information has since removed the post that advertised the data, but for the time being it’s still available in Google cache . Read 6 remaining paragraphs | Comments

Read the original post:
Facebook tries cloaking probe into data leak involving 1 million accounts