Decade-old bug in Linux world’s sudo can be abused by any logged-in user to gain root privileges

Security researchers from Qualys have identified a critical heap buffer overflow vulnerability in sudo that can be exploited by rogue users to take over the host system. Sudo is an open-source command-line utility widely used on Linux and other Unix-flavored operating systems. It is designed to give selected, trusted users administrative control when needed. The Read more about Decade-old bug in Linux world’s sudo can be abused by any logged-in user to gain root privileges[…]

Fedora’s Chromium maintainer suggests switching to Firefox as Google yanks features in favour of Chrome

Fedora’s maintainer for the open-source Chromium browser package is recommending users consider switching to Firefox following Google’s decision to remove functionality and make it exclusive to its proprietary Chrome browser.The comments refer to a low-key statement Google made just before the release of Chrome 88, saying that during an audit it had “discovered that some Read more about Fedora’s Chromium maintainer suggests switching to Firefox as Google yanks features in favour of Chrome[…]

Apple hit with another European class action over throttled iPhones

A third class action lawsuit has been filed in Europe against Apple seeking compensation — for what Italy’s Altroconsumo consumer protection agency dubs “planned obsolescence” of a number of iPhone 6 models.The action relates to performance throttling Apple applied several years ago to affected iPhones when the health of the device’s battery had deteriorated — Read more about Apple hit with another European class action over throttled iPhones[…]

Dutch COVID-19 patient and testing data sold on the criminal underground

Dutch police have arrested two individuals on Friday for allegedly selling data from the Dutch health ministry’s COVID-19 systems on the criminal underground. The arrests came after an investigation by RTL Nieuws reporter Daniel Verlaan who discovered ads for Dutch citizen data online, advertised on instant messaging apps like Telegram, Snapchat, and Wickr. The ads consisted of Read more about Dutch COVID-19 patient and testing data sold on the criminal underground[…]

Myopia correcting ‘smart glasses’ from Japan to be sold in Asia – Snake Oil or …?

Can a pair of unique spectacles banish nearsightedness without surgical intervention? Japan’s Kubota Pharmaceutical Holdings says its wearable device can do just that, and it plans to start releasing the product in Asia, where many people grapple with myopia. The device, which the company calls Kubota Glasses or smart glasses, is still being tested. It Read more about Myopia correcting ‘smart glasses’ from Japan to be sold in Asia – Snake Oil or …?[…]

A Telegram Bot Is Selling Stolen Facebook User Info (500m of them1) for $20 a Pop

The phone numbers (and corresponding site IDs) of some 500 million Facebook users now appear to be for sale on a dark web cybercrime forum. The criminal or group of criminals responsible have constructed a Telegram bot to act as a search function for the data. Potential buyers can now use the bot to sift Read more about A Telegram Bot Is Selling Stolen Facebook User Info (500m of them1) for $20 a Pop[…]

Tucows closes its once-popular software download site

It was inevitable, really. In the early days of the internet, Tucows was known as a reliable place to find and download new software. Today, however, most people are happy to use a modern App Store — Microsoft and Apple both run their own — or navigate to developer websites directly. And if you’re looking Read more about Tucows closes its once-popular software download site[…]

Apple warns against putting an iPhone 12 too close to your pacemaker

You probably don’t need someone to tell you that magnets and life-saving medical devices don’t mix, but Apple wants to make that patently clear. MacRumors has learned that Apple recently updated a support document to warn against keeping the iPhone 12 and MagSafe accessories too close to pacemakers, defibrillators and other implants that might respond Read more about Apple warns against putting an iPhone 12 too close to your pacemaker[…]

Clop ransomware gang clips sensitive files from Atlantic Records’ London ad agency The7stars, dumps them online

A London ad agency that counts Atlantic Records, Suzuki, and Penguin Random House among its clients has had its files dumped online by a ransomware gang, The Register can reveal. The7stars, based in London’s West End, filed [PDF] revenues of £379.36m up from £326m, gross billing of £426m and net profit of £2.1m for the Read more about Clop ransomware gang clips sensitive files from Atlantic Records’ London ad agency The7stars, dumps them online[…]

GameStop Stock Breaks Records As Reddit Traders War With Short Sellers

Struggling retailer GameStop’s stock curiously hit an all time high today. But it’s not because Sony, Microsoft, and Nintendo suddenly decided to stop selling their games digitally. And it’s not because a new set of Funko Pops has taken the internet’s imagination by storm. No, the stock price jumped to an all-time high because some Read more about GameStop Stock Breaks Records As Reddit Traders War With Short Sellers[…]

Hackers Leak Data of 2.28 Million MeetMindful Users

Millions of users of the dating site MeetMindful got some unpleasant news on Sunday. ZDNet reported that the hacker group ShinyHunters, the same group who leaked millions of user records for the company that listed the “Camp Auschwitz” shirts, has dumped what appears to be data from the dating site’s user database. The leak purportedly Read more about Hackers Leak Data of 2.28 Million MeetMindful Users[…]

£30-million injection for UK’s first uncrewed fighter aircraft

The uncrewed combat aircraft will be designed to fly at high-speed alongside fighter jets, armed with missiles, surveillance and electronic warfare technology to provide a battle-winning advantage over hostile forces. Known as a ‘loyal wingman’, these aircraft will be the UK’s first uncrewed platforms able to target and shoot down enemy aircraft and survive against Read more about £30-million injection for UK’s first uncrewed fighter aircraft[…]

DNSPOOQ breaks dnsmasq allowing for cache poisoning, remote code execution and more

The JSOF research labs are reporting 7 vulnerabilities found in dnsmasq, an open-source DNS forwarding software in common use. Dnsmasq is very popular, and we have identified approximately 40 vendors whom we believe use dnsmasq in their products, as well as major Linux distributions. The DNS protocol has a history of vulnerabilities dating back to Read more about DNSPOOQ breaks dnsmasq allowing for cache poisoning, remote code execution and more[…]

This site posted every face from Parler’s Capitol Hill insurrection videos

Late last week, a website called Faces of the Riot appeared online, showing nothing but a vast grid of more than 6,000 images of faces, each one tagged only with a string of characters associated with the Parler video in which it appeared. The site’s creator tells WIRED that he used simple, open source machine-learning Read more about This site posted every face from Parler’s Capitol Hill insurrection videos[…]

WhatsApp Private Groups + user phone numbers Were Accessible Again to Anyone Searching on Google – a yearly event now

WhatsApp groups are showing up on Google search yet again. As a result, anyone could discover and join a private WhatsApp group by simply searching on Google. This was first discovered in 2019, and was apparently fixed last year after becoming public. Another old issue, which also appeared to have been fixed but seems to Read more about WhatsApp Private Groups + user phone numbers Were Accessible Again to Anyone Searching on Google – a yearly event now[…]

AWS has been doing things that are ‘just NOT OK since 2015,’ says Elastic as firm yanks Apache 2.0 licence – FOSS blues

Elastic CEO and co-founder Shay Banon has attacked AWS for what he claims is unacceptable use of the open-source Elasticsearch product and trademark. Banon’s post is part of the company’s defence of its decision to drop the open-source Apache 2.0 licence for its ElasticSearch and Kibana products and instead use the copyleft SSPL or restrictive Read more about AWS has been doing things that are ‘just NOT OK since 2015,’ says Elastic as firm yanks Apache 2.0 licence – FOSS blues[…]

Laptops given to British schoolkids came preloaded with malware and talked to Russia when booted

A shipment of laptops supplied to British schoolkids by the Department for Education to help them learn under lockdown came preloaded with malware, The Register can reveal. The affected laptops, supplied to schools under the government’s Get Help With Technology (GHWT) scheme, which started last year, came bundled with the Gamarue malware – an old Read more about Laptops given to British schoolkids came preloaded with malware and talked to Russia when booted[…]

Prostate Cancer can be precisely diagnosed using a urine test with artificial intelligence

Prostate cancer is one of the most common cancers among men. Patients are determined to have prostate cancer primarily based on PSA, a cancer factor in blood. However, as diagnostic accuracy is as low as 30%, a considerable number of patients undergo additional invasive biopsy and thus suffer from resultant side effects, such as bleeding Read more about Prostate Cancer can be precisely diagnosed using a urine test with artificial intelligence[…]

Elon Musk to offer $100 million prize for ‘best’ carbon capture tech

Elon Musk on Thursday took to Twitter to promise a $100 million prize for development of the “best” technology to capture carbon dioxide emissions. Capturing planet-warming emissions is becoming a critical part of many plans to keep climate change in check, but very little progress has been made on the technology to date, with efforts Read more about Elon Musk to offer $100 million prize for ‘best’ carbon capture tech[…]

Chinese hackers stealing everything from flight passenger data to IP for past 3 years

NCC Group and Fox-IT have been tracking a threat group with a wide set of interests, from intellectual property (IP) from victims in the semiconductors industry through to passenger data from the airline industry. In their intrusions they regularly abuse cloud services from Google and Microsoft to achieve their goals. NCC Group and Fox-IT observed Read more about Chinese hackers stealing everything from flight passenger data to IP for past 3 years[…]

Valve, Bandai, Capcom, Focus Home, Koch Media, Zenimax fined $9.4M by EU for illegal geo-blocking, antitrust collusion

A lengthy antitrust investigation into PC games geo-blocking in the European Union by distribution platform Valve and five games publishers has led to fines totalling €7.8 million (~$9.4 million) after the Commission confirmed today that the bloc’s rules had been breached.The geo-blocking practices investigated since before 2017 concerned around 100 PC video games of different Read more about Valve, Bandai, Capcom, Focus Home, Koch Media, Zenimax fined $9.4M by EU for illegal geo-blocking, antitrust collusion[…]

Beware This Text String That Can Crash Windows and ‘Corrupt’ Your Drive

Hackers are exploiting a strange bug that lets a simple text string ‘corrupt’ your Windows 10 or Windows XP computer’s hard drive if you extract a ZIP file, open a specific folder, or even click on a Windows shortcut. The hacker adds the text string to a folder’s location, and the moment you open it, bam—hard Read more about Beware This Text String That Can Crash Windows and ‘Corrupt’ Your Drive[…]