Powerful backdoor found in software used by >100 banks and energy cos.

(credit: Jeremy Brooks ) For 17 days starting last month, an advanced backdoor that gave attackers complete control over networks lurked in digitally signed software used by hundreds of banks, energy companies, and pharmaceutical manufacturers, researchers warned Tuesday. The backdoor, dubbed ShadowPad, was added to five server- or network-management products sold by NetSarang , a software developer with offices in South Korea and the US. The malicious products were available from July 17 to August 4, when the backdoor was discovered and privately reported by researchers from antivirus provider Kaspersky Lab. Anyone who uses the five NetSarang titles Xmanager Enterprise 5.0, Xmanager 5.0, Xshell 5.0, Xftp 5.0, or Xlpd 5.0, should immediately review posts here and here from NetSarang and Kaspersky Lab respectively. Covert data collection The attack is the latest to manipulate the supply chain of a legitimate product in hopes of infecting the people who rely on it. The NotPetya worm that shut down computers around the world in June used the same tactic after attackers hijacked the update mechanism for tax software that was widely used in Ukraine . Supply-chain attacks that targeted online gamers included one used to spread the PlugX trojan in 2015 and the malware dubbed WinNTi in 2013 . Read 8 remaining paragraphs | Comments

Read the article:
Powerful backdoor found in software used by >100 banks and energy cos.

Yahoo confirms new security breach affecting over one billion accounts

Yahoo just revealed that in August 2013, someone stole data linked to more than one billion accounts. Back in September, the company announced a 2014 security breach affecting some 500 million users, however, it believes these two incidents are “likely distinct.” Additionally, the company says that it believes the same hackers from the 2014 breach dug into its code and figured out how to forge cookies to target specific accounts. It has invalidated the forged cookies and notified holders of the accounts they were used to access in 2015 or 2016. Need a spreadsheet or a chart to keep track of all the ways your Yahoo account info is probably floating around right now? There is an FAQ to try and help users figure out what has been stolen, when and how they might be affected. Still, the massive size of this breach means that for Yahoo users information including “names, email addresses, telephone numbers, dates of birth, hashed passwords (using MD5) and, in some cases, encrypted or unencrypted security questions and answers” is potentially out there. The company is reaching out to potentially affected users, so there should be a message coming your way soon, while the security questions and answers have been invalidated. Of course, if you’ve used the same information for a security answer somewhere else, then whoever has it could use those answers against you — change them. Yahoo’s ongoing security investigation and users left scrambling to reset passwords and security questions (again) is just one part of the puzzle. It’s unclear how these new revelations affect its $4.83 billion acquisition by (Engadget and AOL parent company) Verizon . Previous reports indicated the carrier could be looking for a discount or way out of the deal altogether , and this bad news probably won’t help. Source: Yahoo , FAQ

Read the article:
Yahoo confirms new security breach affecting over one billion accounts

Making brains transparent

Stanford University researchers developed a process to make a mouse brain totally transparent. The brain has to be, er, removed from the mouse first but it’s still an amazing process that enables scientists to see the entire brain in great detail, without chopping it up. Brilliant bioengineer, Karl Deisseroth, a pioneer in the field of optogenetics, postdoc Kwanghun Chung, and their colleagues have used the same technique, called CLARITY, to make fish and, yes, bits of human brains transparent as well. The process involves replacing the fatty molecules, called lipids, with a hydrogel. As a result, the brain can be studied with visible light and chemical markers with unprecedented clarity and resolution. Check out the stunning fly-through of the rodent’s brain above. ” Getting CLARITY: Hydrogel process developed at Stanford creates transparent brain ”        

Link:
Making brains transparent