Home Blog Page 322

Pentagon To Develop A New System Called Scorecard To Stay One-Step Ahead Of The Hackers

pentagon scorecard system protection

Cyber security is a serious matter and the U.S. Defense Department so Pentagon is going to create a massive database of all the vulnerabilities for the government to stay one-step ahead of the hackers. An electronic system “Scorecard” to help assess the department on what holes to plug in the government’s cyber security system. The said scorecard would rate and rank the government’s several networks and systems.

The Scorecard will first establish a database of all the [p2p type=”category” value=”vulnerability” attributes=”target=’_blank'”]vulnerabilities[/p2p] ever found with their corresponding CVE number, and then will assess all of the computers in the network to stop [p2p type=”category” value=”hacking-news” attributes=”target=’_blank'”]hackers from exploiting[/p2p] them.Scorecard would stay updated with the latest happenings of the cyber security world.

According to Pentagon, each of the United States’ major weapons system was vulnerable to skilled hackers. A number of cyber attacks that are originating from Russia and China were reported recently. And it is a serious problem, since cyber attacks can be launched in order to take control of their missiles and other weapons.

Also See : [p2p type=”slug” value=”indian-scientists-developed-a-new-algorithm-to-prevent-cybercrime” attributes=”target=’_blank'”]Indian Scientists Developed A New Algorithm To Prevent Cybercrime[/p2p]

The first phase or step of developing the scorecard system would be done manually by hand. However, later it may detect and add new vulnerabilities automatically to help the engineers respond to a newly discovered exploit quickly.Apart from this, the Pentagon is also looking forward to having a response team that would address a security breach. At about 6,200 officials will be trained to be a part of this project.These cyber response teams are expected to be operational by the end of next year.

The Scorecard system would initially focus on the largest threats and it would help the officials to determine which vulnerabilities to fix first based on how great the threat is. If a threat is found that is harmless, the Pentagon would leave it to the bottom of their tasks.

Also See : [p2p type=”slug” value=”indian-government-to-replace-microsoft-windows-with-boss” attributes=”target=’_blank'”]Indian Government To Replace Microsoft Windows With Its Own Operating System BOSS[/p2p]

Since the Scorecard will only have the vulnerabilities that have been found, however, the real gold for the hackers is the zero-day vulnerabilities. Zero Day is a technical term for the loopholes that are yet to discovered, and apparently many of them are on sale in the underground market. Russian black market is primarily the source where hackers get their hands on exploits selling for more than $50,000.

So the prime focus of the upcoming ‘Scorecard’ and the response team would be to combat some of the greatest threats that could harm the entire network.

Bug Reported : A Simple String Can Crash Google Chrome

Crash Google Chrome

Recently a new bug has been found in [p2p type=”post_tag” value=”chrome” attributes=”target=’_blank'”]Google Chrome[/p2p] browser, that Typing in a 16 character link and hitting enter, clicking on a 16-character link, or even just putting your cursor over a 16-character link, will crash Google Chrome.

The bug was reported by Andris Atteka who explained on his blog that all you to do to crash your Chrome is to add a null character in the URL string. And he also put an example in his blog post. His example was 26 characters long url, and you can check it through above link. You can see that Chrome freezes when ever you hover over that particular url. But not only that url, any url with simple strings can crash your chrome badly.

If you like to test, simply enter ” http://x/%%30%30 ” in your chrome address bar and hit Enter.Then either your Chrome tab or the whole Chrome browser will crash.

Crash Google Chrome

Also See: [p2p type=”slug” value=”all-available-google-chrome-shortcuts-list-for-windowsmac-and-linux-users” attributes=”target=’_blank'”]All Available Google Chrome Shortcuts List For Windows,Mac And Linux Users[/p2p]

Atteka reported the bug to Google today. They have given technical explanation for the reason of the bug that,

“It seems to be crashing in some very old code. In the Debug build, it’s hitting a DCHECK on an invalid URL in GURL, deep in some History code. Given that it’s hitting a CHECK in the Release build, I don’t think this is actually a security bug, but I’m going to leave it as such.”

Google Chrome crash is reported in both Windows and MAC paltforms.This isn’t the first time a link was discovered that could crash Chrome. A similar issue was discovered just for Mac in March and another was discovered for all desktop platforms in April. Both were quickly fixed.

Unfortunately Atteka will not receive any reward from Google since this was deemed  to be only a DOS vulnerability.Still, it’s easy to see how the bug could be abused and affect many Chrome users.

Facebook Plans To Launch Cheap Wi-Fi Service In India

facebook cheap Wi-Fi Service

Facebook, [p2p type=”post_tag” value=”social-network” attributes=”target=’_blank'”]Social Networking[/p2p] gaints are always working hard to deliver internet connectivity to each and every corner of the globe. In India, first they launched free internet service initiative Internet.org to provide connectivity through out the country without any cost.Now again Facebook Inc. came forward with a new moto – Cheap Wi-Fi Service in India.

Facebook vice president for mobile and global access policy Kevin Martin said at the India Economic Convention 2015 that the social-networking giant is planning to launch a special Wi-Fi service in India which would aid in subsidizing the cost of accessing internet.

“We are rolling out a kind of Wi-Fi service at a lower cost which is trying to adjust cost issue in other countries and looking out to do that in India,” — Martin said at the convention.

AlSO READ : [p2p type=”slug” value=”facebooks-connectivity-lab-developed-aquila-a-solar-powered-drone-for-internet-access-in-remote-areas” attributes=”target=’_blank'”]Facebook’s Connectivity Lab Developed Aquila – A Solar Powered Drone For Internet Access In Remote Areas[/p2p]

And the good part is Facebook’s this cheap Wi-Fi service will would come without advertisement and videos, thereby consuming lesser bandwidth and benefiting users.And he also said that Facebook Lab has been working with drones and unmanned aerial vehicles to lower the cost of service to people.

Martin also reiterated that the social networking giant supports the concept of net neutrality and Internet.org initiative is to enable people to realize the importance of internet by providing access to basic web service free of data cost.

Samsung Going To Power Next Generation Smartphones With 6GB RAM Chips

Samsung 6GB RAM

Many smartphones launching nowadays are with maximum 4GB RAM.And [p2p type=”post_tag” value=”samsung” attributes=”target=’_blank'”]Samsung[/p2p] was the first one to bring 4GB RAM access in the Android mobile phones with the Launch of Galaxy S6 and Galaxy S6 Edge. Now again Samsung Electronics, the [p2p type=”slug” value=”samsung-mobiles-is-the-most-attractive-brand-in-india” attributes=”target=’_blank'”]most trusted mobile manufactures[/p2p] are now come forward with a new surprise, 6GB mobile DRAM chips.

Recently company has started mass producing the industry’s first 6GB mobile DRAM chips ( 12Gb LPDDR4 ) which will power the upcoming [p2p type=”slug” value=”announced-iphone-6s-and-iphone-6s-plus-along-with-some-other-surprises” attributes=”target=’_blank'”]next generation smartphones[/p2p] and tablets.According to the reports, the latest DRAM Chips are based on the company’s 20-nanometer technology. The new high capacity mobile RAM consumes 20% less energy compared to the preceding 20-nanometer based 8Gb LPPDDR4. It’s also 30% faster reaching a read speed of 4.2Gbps. It’s also 30% faster reaching a read speed of 4.2Gbps.

Samsung says the new 12Gb mobile DRAM modules that form the 6GB package fit into the same space as the 3GB LPDDR4 packages, which is great news for phone manufacturers.And they aremalso expects that due to the exceptional benefits of its LPDDR4 mobile memory, application areas will expand beyond smartphones and tablets to include ultra-slim PCs, digital appliances and automotive devices, in the coming years.

So let’s wait to use super speedy next generation smartphones powered with 6GB RAM.

Microsoft Loves Linux : Microsoft Developed A Linux-Based Operating System

microsoft loves linux

Microsoft , the undisputed leader on the desktop operating system now developed its own Linux distribution – Azure Cloud Switch (ACS).Last year, Nadella announced support for container-friendly CoreOS distro, one of the five Linux distros Microsoft has embraced in the recent past. Now the company is taking one step further in its alliance with Linux by developing this OS.

Kamala Subramaniam, Principal Architect, Azure Networking, on Thursday wrote in a blog post that Microsoft has built Azure Cloud Switch (ACS), a cross-platform modular operating system for data center networking. This will power network components such as switches. The interesting thing about this operating system is that it is built on top of Linux.

According to blog post, Azure Cloud Switch will make debugging, testing, and fixing bugs much faster. “It also allows us the flexibility to scale down the software and develop features that are required for our data centre and our networking needs,” she wrote. She further noted that the move has already been getting overwhelming response from partnered vendors.ACS allows to use and extend Open Source, Microsoft, and Third Party applications.And it is designed to use the Switch Abstraction Interface (SAI), an OpenCompute effort that offers an API to program ASICs inside network devices.

Subramaniam’s post ends by letting us know: “We’re talking about ACS publicly as we believe this approach of disaggregating the switch software from the switch hardware will continue to be a growing trend in the networking industry and we would like to contribute our insights and experiences of this journey starting here.”

Under Satya Nadella’s rule, Microsoft is moving forward through a way where they are unafraid to use any technology if it gets the job done.Now we see why Microsoft Loves Linux for its next technology.

Also See: Cortana Embarrassed Microsoft CEO Satya Nadella

Google Glass To Reanimate Under New Team Called “Project Aura”

project aura

Google is going to reanimate its flagging Google Glass project by hiring three consumer electronics experts from Amazon’s secretive Lab 126.The project dubbed Project Aura,  is aimed at improving the current technology of the Google Glass and advancing the development of wearable technology.

Reports says that Project Aura appears to have gotten started in June and it will remain within Google rather than being a standalone company under the new Alphabet holding company or being folded into the the Nest smart appliances business.Nest CEO Tony Fadell will be able to have a high-level of supervision over the project but is unclear of what would happen within the project if Nest Labs become a company under Alphabet.

Google is on a roll to hire new innovative minds for its project and it has its own project recruiter which is dedicated to finding the right people for the project. Job positions were seen being posted in LinkedIn and other various job-seeking portals.Several LinkedIn profiles and job listings describing the Project Aura “Google Glass and Beyond.” One described it as “building cool wearables.”

By remaining withing Google, the Aura group will be able to collaborate more closely with other advanced technology efforts such as Soli, which allows consumers to control gadgets through gestures such as rubbing fingers together. While virtual reality technology is an growing area of focus within the technology industry, particularly as Facebook preps the release of its Oculus VR headset, the source said it is still too soon to know whether the Aura group will focused specifically on VR.

Google stopped selling the initial $1,500 version of Glass to consumers earlier this year following waning interest and criticism that the device was too expensive and clunky, without enough practical use cases. The head-mounted device, which allowed users to record video, also raised privacy concerns and caused a consumer backlash. Google continues to sell Glass to businesses for use in the workplace and is reportedly working on a new enterprise version of the device.

Cortana Embarrassed Microsoft CEO Satya Nadella During Live Keynote Presentation

cortana embarrassed microsoft ceo

Cortana – Personal Digital Assistant in Windows 10 operating system let down her boss Microsoft CEO Satya Nadella when he attempted to show off Cortana’s capabilities during a keynote speech at Salesforce’s annual Dreamforce conference.

He was demonstrating some productivity tools, and occasionally showed off what Windows 10 had to offer.And eventually he attempted to showcase Microsoft virtual assistant Cortana’s ability to understand voice commands and to deliver relevant results, but she embarrassed him by giving wrong results.

“Show me my most at-risk opportunities,” Nadella asked Cortana.

Cortana instead opened up a Bing search results page for “Show me to buy milk at this opportunity.”

Nadella’s next attempt got Cortana to open up reminders..After the third unsuccessful attempt, the embarrassed Microsoft CEO gave up.Fortunately, someone behind the scenes saved Nadella and managed to bring up the correct results. You can see it in below Youtube video.Just fast forward to 10:31 to witness how Cortana let down her Boss.

https://youtu.be/RLD0vL5sreQ

Since Microsoft co-founder and former CEO Bill Gates handling a more catastrophic failure during a 1997 demo of Windows 98. He laughed, quipped and moved on.

Microsoft has integrated its Cortana personal digital assistant app on Windows 10. It is currently available for only select locales and Microsoft is working to bring Cortana to other markets including India.

A Critical Apple AirDrop Vulnerability Allows Hackers To Install Malware Silently In Apple iOS and OSX

airdrop vulnerability

After the release of Apple’s latest operating system, iOS 9, a cyber security company has uncovered a bug in earlier versions of the software that can be exploited silently over AirDrop to install malware on iPhones and iPads.

The vulnerability affects any iOS versions supporting AirDrop from iOS 7 onwards, as well as Mac OS X versions from Yosemite onwards.The latest iOS 9 and Mac OS X El Capitan, version 10.11 includes a security update for this nasty AirDrop vulnerability that could be exploited to take full control of your iPhone or Macs, forcing most of the Apple users to download the latest update.

Australian security researcher Mark Dowd has disclosed the serious vulnerability in AirDrop, that the bug allows anyone within range of an AirDrop user to hack into their device and install malware on their operating system.Apple’s Airdrop is very similar to WiFi Direct – both technologies enable files and data to be shared between devices with minimal input from the user. The feature is available on both iPhones and Apple Macs, although it is switched off by default.This means it could be performed in public areas, such as coffee shops, stores, public transit or any other area where the phone is within wireless reach of the attacker.

To initiate the attack, all a hacker has to do is to send a file via AirPlay to an iOS or OS X user running iOS 7 or later, and Yosemite, respectively. It doesn’t even matter if the recipient accepts the incoming transfer, as the malware attack is initiated.The hacker would then have to wait patiently for the user to reset the iPhone or Mac for any reason so that the malware app can be installed. How can a non-App Store app be installed that easily you ask? Well, the hacker would use an Apple certificate to sign it, fooling the OS into believing it’s a genuine piece of software – the kind that enterprises would release to their fleet of Apple devices.

“The [malware] app is restricted by its sandbox.However since you sign the app, you can grant some entitlements that allow it to do things like read contacts, get location information, use the camera or whatever other entitlements legitimate apps can be allowed to have.” — Dowd told Forbes.

Dowd also provided a video demonstration showing the real time attack on his iPhone running iOS 8.4.1.

iOS 9 and OS X 10.11 fixes the problem, so get them as soon as possible. Also, you can just turn off AirDrop when you’re not using it, to avoid such potential issues in the near future, especially if you don’t plan to, or can’t, update to the latest iPhone and Mac software versions.

Earlier today it was reported that a security researcher has discovered a vulnerability in version 5 of Android (Lollipop) that allows an attacker to crash the lockscreen and gain access to a locked device, even if encryption is enabled.