Over 1,800 MongoDB Databases Held For Ransom By Mysterious Attacker

An anonymous reader writes: “An attacker going by the name of Harak1r1 is hijacking unprotected MongoDB databases, stealing and replacing their content, and asking for a 0.2 Bitcoin ($200) ransom to return the data, ” reports Bleeping Computer. According to John Matherly, Shodan founder, over 1, 800 MongoDB databases have had their content replaced with a table called WARNING that contains the ransom note. Spotted by security researcher Victor Gevers, these databases are MongoDB instances that feature no administrator password and are exposed to external connections from the internet. Database owners in China have been hit, while Bleeping Computer and MacKeeper have confirmed other infections, one which hit a prominent U.S. healthcare organization and blocked access to over 200, 000 user records. These attacks are somewhat similar to attacks on Redis servers in 2016, when an unknown attacker had hijacked and installed the Fairware ransomware on hundreds of Linux servers running Redis DB. The two series of attacks don’t appear to be related. Read more of this story at Slashdot.

More here:
Over 1,800 MongoDB Databases Held For Ransom By Mysterious Attacker

BlackBerry’s Latest Experiment: a $2,300 ‘Secure’ Tablet

An anonymous reader writes: After missing the boat on smartphones, BlackBerry has been throwing everything they can at the wall to see what sticks. From making square phones to insisting users want physical keyboards, their only standard is how non-standard they’ve become. Now they’re expanding this strategy to the tablet market with a security-centric tablet that costs $2, 300. And they’re not doing it alone — the base device is actually a Samsung Galaxy Tab S 10.5. The tablet runs Samsung Knox boot tech, as well as software from IBM and encryption specialist Secusmart (which BlackBerry recently purchased). The device will be targeted at businesses and organizations who have particular need for secure devices. “Organizations deploying the SecuTablet will be able to set policies controlling what apps can run on the devices, and whether those apps must be wrapped, said IBM Germany spokesman Stefan Hefter. The wrapping process—in which an app is downloaded from a public app store, bundled with additional libraries that encrypt its network traffic and intercept Android ‘intents’ for actions such as cutting or pasting data, then uploaded to a private app store—ensures that corporate data can be protected at rest, in motion and in use, he said. For instance, it can prevent data from a secure email being copied and pasted into the Facebook app running on the same device—yet allow it to be pasted into a secure collaboration environment, or any other app forming part of the same ‘federation, ‘ he said.” Read more of this story at Slashdot.

More:
BlackBerry’s Latest Experiment: a $2,300 ‘Secure’ Tablet

Independent Researchers Test Rossi’s Alleged Cold Fusion Device For 32 Days

WheezyJoe (1168567) writes The E-Cat (or “Energy Catalyzer”) is an alleged cold fusion device that produces heat from a low-energy nuclear reaction where nickel and hydrogen fuse into copper. Previous reports have tended to suggest the technology is a hoax, and the inventor Andrea Rossi’s reluctance to share details of the device haven’t helped the situation. ExtremeTech now reports that “six (reputable) researchers from Italy and Sweden” have “observed a small E-Cat over 32 days, where it produced net energy of 1.5 megawatt-hours, “far more than can be obtained from any known chemical sources in the small reactor volume.”… “The researchers, analyzing the fuel before and after the 32-day burn, note that there is an isotope shift from a “natural” mix of Nickel-58/Nickel-60 to almost entirely Nickel-62 — a reaction that, the researchers say, cannot occur without nuclear reactions (i.e. fusion).” The paper (PDF) linked in the article concludes that the E-cat is “a device giving heat energy compatible with nuclear transformations, but it operates at low energy and gives neither nuclear radioactive waste nor emits radiation. From basic general knowledge in nuclear physics this should not be possible. Nevertheless we have to relate to the fact that the experimental results from our test show heat production beyond chemical burning, and that the E-Cat fuel undergoes nuclear transformations. It is certainly most unsatisfying that these results so far have no convincing theoretical explanation, but the experimental results cannot be dismissed or ignored just because of lack of theoretical understanding. Moreover, the E-Cat results are too conspicuous not to be followed up in detail. In addition, if proven sustainable in further tests the E-Cat invention has a large potential to become an important energy source.” The observers understandably hedge a bit, though: The researchers are very careful about not actually saying that cold fusion/LENR is the source of the E-Cat’s energy, instead merely saying that an “unknown reaction” is at work. In serious scientific circles, LENR is still a bit of a joke/taboo topic. The paper is actually somewhat comical in this regard: The researchers really try to work out how the E-Cat produces so much darn energy — and they conclude that fusion is the only answer — but then they reel it all back in by adding: “The reaction speculation above should only be considered as an example of reasoning and not a serious conjecture.” Read more of this story at Slashdot.

View the original here:
Independent Researchers Test Rossi’s Alleged Cold Fusion Device For 32 Days

China’s Secret Scientific Megaprojects

An anonymous reader writes “The Diplomat reports on the 2006 National Medium to Long-term Plan (MLP) for the Development of Science and Technology, China’s most ambitious national science and technology plan to date. The MLP consists of sixteen megaprojects — both civilian and military — that serve as ‘S&T vanguard programs designed to transform China’s science & technology capabilities in areas such as electronics, semiconductors, [and] telecommunications.’ Thirteen of the megaprojects are listed in the MLP, while three are classified for national security reasons. The three classified megaprojects are likely the military components of the Shenguang Laser Project (used for thermonuclear weapons), the Beidou 2 Satellite Navigation System, and the Hypersonic Vehicle Technology Project.” Read more of this story at Slashdot.

View original post here:
China’s Secret Scientific Megaprojects