As reported by a subscriber to the incidents mailing list at . "It appears that perhaps tens of thousands of username/passwords for valid shell logins ALL ACROSS THE NET may have been compromised at CCBILL, a large internet credit card/check processor used for e-commerce and adult sites, read carefully!!". . . . As reported by a subscriber to the incidents mailing list at . As reported by a subscriber to the incidents mailing list at. reported, subscriber, incidents, mailing, appears, perhaps. . LinuxSecurity.com Team
A German privacy regulator has issued its first GDPR fine after a hacker stole unencrypted data on hundreds of thousands of customers of a local chat app.. The Baden-Württemberg Data Protection Authority (LfDI) fined Knuddels just €20,000 ($22,700) despite the firm having stored user passwords and emails in plain text. As a result, hackers were able to make off with 330,000 legitimate credentials, publishing them in September 2018 on Pastebin and Mega. The link for this article located at InfoSecurity is no longer available. . A French authority's initial GDPR enforcement action underscores gaps in security protocols that resulted in a compromise affecting 500,000 user accounts.. GDPR Compliance, Data Protection, Privacy Regulations. . LinuxSecurity.com Team
A website dedicated to discussion of the Ubuntu Linux distribution was breached on Saturday, with hackers gaining access to encrypted passwords and email addresses.. The site, Ubuntuforums.org, will remain offline until it can be fixed, wrote Jane Silber, CEO of Canonical, a company that develops and provides services for the free, open-source operating system.. A significant leak at Ubuntuforums.org resulted in the exposure of user information, prompting the site to go offline for maintenance. Stay updated with the newest information.. Ubuntu Breach, Forum Security Issue, User Data Leak. . LinuxSecurity.com Team
Phandroid, a popular Android news site, has confirmed that its Android Forums web site was compromised and that private user data has been accessed. According to Phandroid's notice about the security breach, the user table of Android Forum's database was accessed by unknown intruders using a known exploit, which has since been fixed.. The link for this article located at H Security is no longer available. . The link for this article located at H Security is no longer available.. android, phandroid, popular, confirmed, forums, compromis. . LinuxSecurity.com Team
The Web front end for a Free Software Foundation software repository remains down after the server it was hosted on was attacked last week.. The repository holds the pages for the organization's Gnu.org website, which the attackers altered last weekend. They also downloaded all the user names and encrypted passwords. None of the Gnu software projects on the server have been compromised as part of the attack, said Matt Lee, FSF's campaign manager. As a precaution, the Savannah server's administrators eliminated any changes to the server contents since Nov. 23, a day before the first attack. Developers using the repositories can upload changes from their local copies, and as they are signed onto the system, they will be required to change their password. The link for this article located at InfoWorld is no longer available. . The repository holds the pages for the organization's Gnu.org website, which the attackers altered l. software, front, foundation, repository, remains, server. . LinuxSecurity.com Team
We've got 12 . . . wait, 13. Another just came in!'' On the hunt for 30 seconds, Gary Morse is jazzed. We've walked about 45 feet down Avenue of the Americas in Midtown Manhattan, and he has been counting . . . . We've got 12 . . . wait, 13. Another just came in!' On the hunt for 30 seconds, Gary Morse is jazzed. We've walked about 45 feet down Avenue of the Americas in Midtown Manhattan, and he has been counting the number of chirrups coming from the speaker of his hand-held computer. Each represents potential prey: wireless networks in the offices and apartments above us. So far, we have had more than a dozen chances to sneak Internet access, reap user ID's and passwords and otherwise peer into the private affairs of individuals and businesses. Morse is an expert -- president of Razorpoint Security Technologies Inc., a computer security consulting firm that helps companies find their weak spots and fix them -- and a self-described 'professional hacker.' He knows dozens of tricks to ease his way into any of the networks he has found. Most users don't realize that left untended, the wireless technology that can quickly connect computers will literally broadcast every bit of transmitted information to anyone with a computer and a $40 wireless networking card. The link for this article located at NYTimes is no longer available. . In urban settings, the surge of unauthorized wireless access points leads to notable security threats, especially in crowded public areas like cafes and libraries.. Wireless Security, Urban Hacking, Network Penetration Risks. . Anthony Pell
supposed to be securely stored on ZKey's award-winning information storage portal. All he needed was a little JavaScript. A new security hole, discovered Aug. 14 by a hacker who calls himself "Blue Adept," allows ZKey users on Internet Explorer 5.5 . . . . supposed to be securely stored on ZKey's award-winning information storage portal. All he needed was a little JavaScript. A new security hole, discovered Aug. 14 by a hacker who calls himself "Blue Adept," allows ZKey users on Internet Explorer 5.5 with a ZKey account to easily steal the user names and passwords of other ZKey users simply by sending an email that includes a specific JavaScript code embedded in the body of the message. The link for this article located at Wired is no longer available. . A recent vulnerability found in ZKey demonstrates that user passwords can be swiftly compromised through a malicious JavaScript embedded in emails.. ZKey Security, Data Protection, JavaScript Exploit. . LinuxSecurity.com Team
A reader was somewhat surprised by his ISP's apparent disregard for security when he received an email requesting his username and password. The request came as part of an update email from themutual.net, telling him what news features had been . . . . A reader was somewhat surprised by his ISP's apparent disregard for security when he received an email requesting his username and password. The request came as part of an update email from themutual.net, telling him what news features had been added, what its "partners" could offer them and why themutual.net was the only ISP he should even consider. Fair enough. The link for this article located at The Register is no longer available. The link for this article located at The Register is no longer available. . A service provider's solicitation for login credentials through email generates considerable trust issues for consumers.. Email Security, ISP Threats, Cyber Hygiene. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.