
By VINDU GOEL
India opened a formal investigation into Jeff Bezos’ Amazon and its leading rival, Flipkart, just before his first visit in five years.
Published: January 12, 2020 at 06:00PM
from NYT Technology https://ift.tt/2sl8qdw
via IFTTT

By VINDU GOEL
India opened a formal investigation into Jeff Bezos’ Amazon and its leading rival, Flipkart, just before his first visit in five years.
Published: January 12, 2020 at 06:00PM
from NYT Technology https://ift.tt/2sl8qdw
via IFTTT
By REUTERS
Microsoft Corp’s India-born Chief Executive Officer Satya Nadella said he was saddened by a new citizenship law based on religion that was recently implemented in his home country, BuzzFeed News reported on Monday.
Published: January 12, 2020 at 06:00PM
from NYT Technology https://ift.tt/3a9zL3i
via IFTTT
Sources tell KrebsOnSecurity that Microsoft Corp. is slated to release a software update on Tuesday to fix an extraordinarily serious security vulnerability in a core cryptographic component present in all versions of Windows. Those sources say Microsoft has quietly shipped a patch for the bug to branches of the U.S. military and to other high-value customers/targets that manage key Internet infrastructure, and that those organizations have been asked to sign agreements preventing them from disclosing details of the flaw prior to Jan. 14, the first Patch Tuesday of 2020.
According to sources, the vulnerability in question resides in a Windows component known as crypt32.dll, a Windows module that Microsoft says handles “certificate and cryptographic messaging functions in the CryptoAPI.” The Microsoft CryptoAPI provides services that enables developers to secure Windows-based applications using cryptography, and includes functionality for encrypting and decrypting data using digital certificates.
A critical vulnerability in this Windows component could have wide-ranging security implications for a number of important Windows functions, including authentication on Windows desktops and servers, the protection of sensitive data handled by Microsoft’s Internet Explorer/Edge browsers, as well as a number of third-party applications and tools.
Equally concerning, a flaw in crypt32.dll might also be abused to spoof the digital signature tied to a specific piece of software. Such a weakness could be exploited by attackers to make malware appear to be a benign program that was produced and signed by a legitimate software company.

This component was introduced into Windows more than 20 years ago — back in Windows NT 4.0. Consequently, all versions of Windows are likely affected (including Windows XP, which is no longer being supported with patches from Microsoft).
Microsoft has not yet responded to requests for comment. However, KrebsOnSecurity has heard rumblings from several sources over the past 48 hours that this Patch Tuesday (tomorrow) will include a doozy of an update that will need to be addressed immediately by all organizations running Windows.
Will Dormann, a security researcher who authors many of the vulnerability reports for the CERT Coordination Center (CERT-CC), tweeted today that “people should perhaps pay very close attention to installing tomorrow’s Microsoft Patch Tuesday updates in a timely manner. Even more so than others. I don’t know…just call it a hunch?” Dormann declined to elaborate on that teaser.
It could be that the timing and topic here (cryptography) is nothing more than a coincidence, but KrebsOnSecurity today received a heads up from the U.S. National Security Agency (NSA) stating that NSA’s Director of Cybersecurity Anne Neuberger is slated to host a call on Jan. 14 with the news media that “will provide advanced notification of a current NSA cybersecurity issue.”
The NSA’s public affairs folks did not respond to requests for more information on the nature or purpose of the discussion. The invitation from the agency said only that the call “reflects NSA’s efforts to enhance dialogue with industry partners regarding its work in the cybersecurity domain.”
Stay tuned for tomorrow’s coverage of Patch Tuesday and possibly more information on this particular vulnerability.
from Krebs on Security https://ift.tt/2t5z9vd
via IFTTT
El malware es el gran problema de cualquier plataforma informática, y siendo Android una de las plataformas móviles más utilizadas del mundo es lógico que sea también una de las más afectadas por el software malicioso. No en vano, Google eliminó hace poco 104 apps con más de 4 millones de descargas que contenían malware, e incluso hemos visto felicitaciones de Navidad que no querían sólo alegrarnos las fiestas. Hay
Entra en Andro4all para leer el artículo completo
Puedes unirte a nosotros en Twitter, Facebook o en Google+
¡Suscríbete a nuestro canal de YouTube!
Publicado recientemente en Andro4all
La entrada Fraudulento y muy escurridizo: conócelo todo sobre ‘Joker’, uno de los malwares más agresivos de Android, de la mano de Google se publicó primero en Andro4all.
from Andro4all https://ift.tt/37YVSYk
via IFTTT
The attack may have compromised donors’ payment information.
from Dark Reading: https://ift.tt/2FMDxC4
via IFTTT
Organizations need to apply mitigations for vulnerability in Citrix Application Delivery Controller and Citrix Gateway ASAP, security researchers say.
from Dark Reading: https://ift.tt/2tUA9SU
via IFTTT
If you can answer these six questions, you’ll be off to a great start.
from Dark Reading: https://ift.tt/2tUJRVd
via IFTTT
Windows 7 and Server 2008 will continue to work after Jan. 14, 2020, but will no longer receive security updates.
from Dark Reading: https://ift.tt/35Q67gr
via IFTTT
Xiaomi, que recientemente actualizó el Mi A2 a Android 10 y confirmó la llegada oficial de MIUI 12, está celebrando actualmente su décimo aniversario. Con motivo de estas fechas, y tras enseñar su nuevo logo conmemorativo, el fabricante asiático ha revelado los dos nombres que Xiaomi pudo llegar a tener. La compañía china cumple diez años, por lo que ha decidido que sea el momento ideal para revelar algunos de
Entra en Andro4all para leer el artículo completo
Puedes unirte a nosotros en Twitter, Facebook o en Google+
¡Suscríbete a nuestro canal de YouTube!
Publicado recientemente en Andro4all
La entrada “Xuande Mi 9”: el CEO de Xiaomi revela los dos nombres que Xiaomi pudo llegar a tener se publicó primero en Andro4all.
from Andro4all https://ift.tt/2Nops1D
via IFTTT
Nueva semana, nuevas ofertas. Como cada lunes, un buen número de desarrolladores de apps y juegos para Android han decidido tirar la casa por la ventana y ofrecernos algunas de sus mejores creaciones con interesantes descuentos, que en algunos casos suponen hasta el 100% del precio original. De este modo, durante solo unas horas, será posible conseguir aplicaciones y juegos Android de pago totalmente gratis o con grandes rebajas. Recuerda
Entra en Andro4all para leer el artículo completo
Puedes unirte a nosotros en Twitter, Facebook o en Google+
¡Suscríbete a nuestro canal de YouTube!
Publicado recientemente en Andro4all
La entrada Nuevas ofertas en Google Play: apps y juegos que puedes conseguir gratis o con grandes descuentos se publicó primero en Andro4all.
from Andro4all https://ift.tt/2tgXEp3
via IFTTT