US state’s pot dealer database pwned after security goes up in smoke

The US state of Washington says a miscreant was able to access the system it uses to track the manufacturing and sale of marijuana. The Evergreen State’s Liquor and Cannabis Board – a job that sounds way cooler than it actually is – yesterday admitted that last weekend someone was able to exploit a vulnerability Read more about US state’s pot dealer database pwned after security goes up in smoke[…]

You can resurrect any deleted GitHub account name. If you depend on that account you may find yourself in trouble

The individual identifying himself as Jim Teeuwen, who maintained GitHub repository for a tool called go-bindata for embedded data in Go binaries, recently deleted his GitHub account, taking with it a resource that other Go developers had included in their projects. The incident echoes the more widely noted 2016 disappearance of around 250 modules maintained Read more about You can resurrect any deleted GitHub account name. If you depend on that account you may find yourself in trouble[…]

The Equifax hack could be worse than we thought

In its original announcement of the hack, the company had revealed that some driver’s license numbers were exposed. The new documents show that the license state and issue date might have also been compromised. Equifax spokesperson Meredith Griffanti told CNNMoney Friday that the original list of vulnerable personal information was never intended to represent the Read more about The Equifax hack could be worse than we thought[…]

Wish you could log into someone’s Netgear box without a password? Summon a &genie=1 – get patching!

Some 17 Netgear routers have a remote authentication bypass, meaning malware or miscreants on your network, or able to reach the device’s web-based configuration interface from the internet, can gain control without having to provide a password. Just stick &genie=1 in the URL, and bingo. That’s pretty bad news for any vulnerable gateways with remote Read more about Wish you could log into someone’s Netgear box without a password? Summon a &genie=1 – get patching![…]

Robot learns to mimic simple human motions

Researchers from the University of California, Berkeley, in the USA, have made some progress on this front by teaching code controlling a robot arm and hand to perform three tasks: grabbing an object and placing it in a specific position; pushing an object; and pushing and pulling an object after seeing the same action performed Read more about Robot learns to mimic simple human motions[…]

SpaceX Roadster skips Mars, steers to asteroids, central core booster explodes

During a press conference after liftoff, Musk said it was dicey whether the second stage would power up at all. The fuel could have frozen, the oxygen boiled off, or the avionics failed, as the rocket spent more than five hours in our planet’s high-radiation Van Allen belts before firing up. Usually spacecraft punch through Read more about SpaceX Roadster skips Mars, steers to asteroids, central core booster explodes[…]

Cheddar Man: Britains’ first men were black. And so were Europes’.

New research into ancient DNA extracted from the skeleton has helped scientists to build a portrait of Cheddar Man and his life in Mesolithic Britain.The biggest surprise, perhaps, is that some of the earliest modern human inhabitants of Britain may not have looked the way you might expect.Dr Tom Booth is a postdoctoral researcher working Read more about Cheddar Man: Britains’ first men were black. And so were Europes’.[…]

PinMe: Tracking a Smartphone User around the World with GPS and WiFi off

We describe PinMe, a novel user-location mechanism that exploits non-sensory/sensory data stored on the smartphone, e.g., the environment’s air pressure, along with publicly-available auxiliary information, e.g., elevation maps, to estimate the user’s location when all location services, e.g., GPS, are turned off. Source: [1802.01468] PinMe: Tracking a Smartphone User around the World

The gender pay gap at Uber is small and has a reason

Specifically, the study stated, drivers who make runs for Uber more frequently are more likely to know where and when to operate in order to get the highest-paying fares. Thus, because women, on average, spend less time driving for Uber than their male counterparts, they are less likely to be around to grab the highest-paying Read more about The gender pay gap at Uber is small and has a reason[…]

Bug in Grammarly browser extension exposes virtually everything a user ever writes

The Grammarly browser extension, which has about 22 million users, exposes its authentication tokens to all websites, allowing any to access all the user’s data without permission, according to a bug report from Google Project Zero’s Tavis Ormandy. The high-severity bug was discovered on Friday and fixed early Monday morning, “a really impressive response time,” Read more about Bug in Grammarly browser extension exposes virtually everything a user ever writes[…]

Japan successfully launches world’s smallest satellite-carrying rocket

KAGOSHIMA – Japan successfully launched on Saturday the world’s smallest satellite-carrying rocket following a failed attempt in January last year, the nation’s space agency said. The rocket about the size of a utility pole, measuring 10 meters in length and 50 centimeters in diameter, lifted off from the Uchinoura Space Center in Kagoshima Prefecture and Read more about Japan successfully launches world’s smallest satellite-carrying rocket[…]

Exoplanets from another galaxy spotted

The Kepler Space Telescope has found oodles of exoplants, but now astroboffins have spotted the first exoplanets outside our galaxy. A group of astroboffins from the University of Oklahoma has become the first to demonstrate exoplanet observations in another galaxy – one that’s 3.8 billion light years away, or one-third of the distance across the Read more about Exoplanets from another galaxy spotted[…]

Can’t login to Skype? You’re not alone. Chat app’s been a bit crap for five days now

A bunch of Skype users are unhappy that they’re been unable to sign into the VoIP service for several days.The yakkity-yak app has fallen flat since January 24, leaving a number of punters with two-factor authentication enabled unable to get back into the software after signing out.”Skype users who are signed in are not affected,” Read more about Can’t login to Skype? You’re not alone. Chat app’s been a bit crap for five days now[…]

Crooks make US ATMs spew million-plus bucks in ‘jackpotting’ hacks

ash machines in the US are being hacked to spew hundreds of dollar bills – a type of theft dubbed “jackpotting” because the ATMs look like slot machines paying out winnings.A gang of miscreants have managed to steal more than $1m from ATMs using this attack, according to a senior US Secret Service official speaking Read more about Crooks make US ATMs spew million-plus bucks in ‘jackpotting’ hacks[…]

Maybe you should’ve stuck with NetWare: Hijackers can bypass Active Directory controls

“The idea of a rogue domain controller is not new and has been mentioned multiple times in previous security publications but required invasive techniques (like installing a virtual machine with Windows Server) and to log on a regular domain controller (DC) to promote the VM into a DC for the targeted domain.”That’s easily spotted, so Read more about Maybe you should’ve stuck with NetWare: Hijackers can bypass Active Directory controls[…]

UK.gov mass data slurping ruled illegal – AGAIN

In a judgment handed down this morning, judges backed a challenge brought by deputy Labour leader Tom Watson in a long-running battle against state surveillance rules.These laws allow for ISPs and telcos to retain communications data for up to a year and for public authorities to get access to this information. But campaigners have argued Read more about UK.gov mass data slurping ruled illegal – AGAIN[…]

AutoSploit searches shodan for weak machines and metasploit to hack them for you

https://github.com/NullArray/AutoSploitAs the name might suggest AutoSploit attempts to automate the exploitation of remote hosts. Targets are collected automatically as well by employing the Shodan.io API. The program allows the user to enter their platform specific search query such as; Apache, IIS, etc, upon which a list of candidates will be retrieved. After this operation has Read more about AutoSploit searches shodan for weak machines and metasploit to hack them for you[…]

Stupid Truck Driver Drove Right Over the Nazca Lines

Argentine newspaper Clarín reports that the driver said he didn’t know the area because he had never traveled there before and that he left the road because of a mechanical problem. The newspaper speculated that the driver actually drove off the Pan-American Highway to avoid paying a toll. Flores Vigo left tire tracks in a Read more about Stupid Truck Driver Drove Right Over the Nazca Lines[…]