Cybersecurity and IT risk budgets continue to grow. Here’s how they’ll be spent.
from Dark Reading: https://ubm.io/2Gm8tv6
via IFTTT
Cybersecurity and IT risk budgets continue to grow. Here’s how they’ll be spent.
from Dark Reading: https://ubm.io/2Gm8tv6
via IFTTT
The decision to award the bug has been welcomed but one security researcher has said that they need to do more to compensate those who find bugs
The post Apple to pay teenager who uncovered FaceTime bug appeared first on WeLiveSecurity
from WeLiveSecurity http://bit.ly/2TP2CBK
via IFTTT
Email provider VFEmail has suffered what the company is calling “catastrophic destruction” at the hands of an as-yet unknown intruder who trashed all of the company’s primary and backup data in the United States. The firm’s founder says he now fears some 18 years’ worth of customer email may be gone forever.
Founded in 2001 and based in Milwaukee, Wisc., VFEmail provides email service to businesses and end users. The first signs of the attack came on the morning of Feb. 11, when the company’s Twitter account started fielding reports from users who said they were no longer receiving messages. VFEmail’s Twitter account responded that “external facing systems, of differing OS’s and remote authentication, in multiple data centers are down.”
Two hours later, VFEmail tweeted that it had caught a hacker in the act of formatting one of the company’s mail servers in The Netherlands.
“nl101 is up, but no incoming email,” read a tweet shortly thereafter. “I fear all US based data my be lost.”
“At this time, the attacker has formatted all the disks on every server,” wrote VFEmail. “Every VM [virtual machine] is lost. Every file server is lost, every backup server is lost. Strangely, not all VMs shared the same authentication, but all were destroyed. This was more than a multi-password via ssh exploit, and there was no ransom. Just attack and destroy.”
In an update posted to the company’s Web site, VFEmail owner Rick Romero wrote that new email was being delivered and that efforts were being made to recover what user data could be salvaged.
“At this time I am unsure of the status of existing mail for US users,” Romero wrote. “If you have your own email client, DO NOT TRY TO MAKE IT WORK. If you reconnect your client to your new mailbox, all your local mail will be lost.”
Reached by KrebsOnSecurity on Tuesday morning, Romero said he was able to recover a backup drive hosted in The Netherlands, but that he fears all of the mail for U.S. users may be irreparably lost.
“I don’t have very high expectations of getting any U.S. data back,” Romero said in an online chat.
John Senchak, a longtime VFEmail user from Florida who also has been a loyal reader and commenter at this blog, told KrebsOnSecurity that the attack completely wiped out his inbox at the company — some 60,000 emails sent and received over more than a decade.
“I have a account with that site, all the email in my account was deleted,” Senchak said.
Asked if he had any clues about the attackers or how they may have broken in, Romero said the intruder appeared to be doing his dirty work from a server based in Bulgaria (94.155.49[9], username “aktv.”)
“I haven’t done much digging yet on the actors,” he said. “It looked like the IP was a Bulgarian hosting company. So I’m assuming it was just a virtual machine they were using to launch the attack from. There definitely was something that somebody didn’t want found. Or, I really pissed someone off. That’s always possible.”
This isn’t the first time criminals have targeted VFEmail. I wrote about the company in 2015 after it suffered a debilitating distributed denial-of-service (DDoS) attack after Romero declined to pay a ransom demand from an online extortion group. Another series of DDoS attacks in 2017 forced VFEmail to find a new hosting provider.
In December 2018, Romero tweeted that service had been disrupted by a DDoS attack that he attributed to “script kiddies,” a derisive reference to low-skilled online hooligans.
“After 17 years if I was planning it shut it down, it’d be shut down by me – not script kiddies,” Romero wrote on Dec. 8.
Attacks that seek to completely destroy data and servers without any warning or extortion demand are not as common as, say, ransomware infestations, but when they do occur they can be devastating (the 2014 Sony Pictures hack and the still-unsolved 2016 assault on U.S.-based ISP Staminus come to mind).
It’s not clear how or whether VFEmail will recover from this latest attack, but such actions are an unsettling reminder that although most cybercriminals have some kind of short- or long-term profit motive in mind, an intruder with privileged access to a network can just as well virtually destroy everything within reach as they can plant malware or extortion threats like ransomware.
from Krebs on Security http://bit.ly/2BwakcM
via IFTTT
Xiaomi, que se ha convertido en el principal fabricante de teléfonos inteligentes, por delante de Samsung, en uno de los mayores países tecnológicos, sigue creciendo con el paso del tiempo. La firma ha perdido ventas en China, pero ha logrado crecer más de un 50% en un año en la India. Así lo apunta un informe de IDC, en el que se informa que el mercado indio de teléfonos inteligentes
Entra en Andro4all para leer el artículo completo
Puedes unirte a nosotros en Twitter, Facebook o en Google+
¡Suscríbete a nuestro canal de YouTube!
Publicado recientemente en Andro4all
from Andro4all http://bit.ly/2WYMTC3
via IFTTT
El Samsung Galaxy A8s se convertía en diciembre en el primer terminal de la firma coreana en llegar con la que, parece, será la nueva moda durante buena parte de este 2019. El agujero en la pantalla. Hace algunos días te contamos que Samsung estaba preparando unos curiosos degradados de colores para su nuevo dispositivo, y hoy hemos podido saber más. El nuevo y colorido Galaxy A8s llegará con colores
Entra en Andro4all para leer el artículo completo
Puedes unirte a nosotros en Twitter, Facebook o en Google+
¡Suscríbete a nuestro canal de YouTube!
Publicado recientemente en Andro4all
from Andro4all http://bit.ly/2RV5Y4k
via IFTTT
In rural India, where the stigma of menstruation persists, women make low-cost sanitary pads on a new machine and stride toward financial independence.
from New On Netflix USA http://bit.ly/2DxMIVc
via IFTTT
El Samsung Galaxy Note8 vio la luz hace prácticamente 1 año y medio, pero como buen gama alta, debería disfrutar de unos cuantos meses más de actualizaciones. Es lo mínimo que podemos esperar de un terminal que alcanza los 1000 euros. Si tienes la suerte de contar con el gigante de Samsung estás de enhorabuena, ya que parece que las actualizaciones seguirán llegando, al menos por ahora. Ya puedes descargar
Entra en Andro4all para leer el artículo completo
Puedes unirte a nosotros en Twitter, Facebook o en Google+
¡Suscríbete a nuestro canal de YouTube!
Publicado recientemente en Andro4all
from Andro4all http://bit.ly/2I9xsDE
via IFTTT
Nokia está ultimando los detalles de su nuevo teléfono inteligente, el Nokia 9 PureView que destaca por sus cinco cámaras en la parte posterior. El dispositivo ha ido ofreciendo detalles a cuentagotas a través de las filtraciones, incluso se ha podido ver su diseño al completo gracias a una imagen en alta calidad. Una nueva filtración ha revelado las características del nuevo smartphone de la firma, que destaca por ser
Entra en Andro4all para leer el artículo completo
Puedes unirte a nosotros en Twitter, Facebook o en Google+
¡Suscríbete a nuestro canal de YouTube!
Publicado recientemente en Andro4all
from Andro4all http://bit.ly/2N1M1bc
via IFTTT
LayerBB 1.1.2 – Cross-Site Scripting
from Exploit-DB.com RSS Feed http://bit.ly/2BHn1ld
via IFTTT
Russia’s major ISPs plan to temporarily disconnect servers from the internet, effectively cutting the country off from the outside world.
from Naked Security http://bit.ly/2I86Lzg
via IFTTT