Friday, August 17, 2012

Shamoon virus targets energy sector infrastructure

The attack, known as Shamoon, is said to have hit "at least one organisation" in the sector.
Shamoon is capable of wiping files and rendering several computers on a network unusable.
On Wednesday, Saudi Arabia's national oil company said an attack had led to its own network being taken offline.
Although Saudi Aramco did not link the issue to the Shamoon threat, it did confirm that the company had suffered a "sudden disruption".

the company said it had now isolated its computer networks as a precautionary measure.
The disruptions were "suspected to be the result of a virus that had infected personal workstations without affecting the primary components of the network", a statement read.
It said the attack had had "no impact whatsoever" on production operations.
Rendered unusable On Thursday, security firms released the first detailed information about Shamoon.
Experts said the threat was known to have had hit "at least one organisation" in the energy sector.
"It is a destructive malware that corrupts files on a compromised computer and overwrites the MBR (Master Boot Record) in an effort to render a computer unusable," wrote security firm Symantec.

Seculert, an Israel-based security specialist, also analysed the malicious code and concluded that it had unusual characteristics compared with other recent attacks.
"The interesting part of this malware is that instead of staying under the radar and collect information, the malware was designed to overwrite and wipe the files," the company said.
"Why would someone wipe files in a targeted attack and make the machine unusable?"
Shamoon is the latest in a line of attacks that have targeted infrastructure.
One of the most high-profile attacks in recent times was Stuxnet, which was designed to hit nuclear infrastructure in Iran.
Others, like Duqu, have sought to infiltrate networks in order to steal data.


(Source)

Friday, August 10, 2012

Steam Not Just For Games, Anymore!

Valve , today announced the first set of Software titles are heading to Steam, marking a major expansion to the platform most commonly known as a leading destination for PC and Mac games.

The Software titles coming to Steam range from creativity to productivity. Many of the launch titles will take advantage of popular Steamworks features, such as easy installation, automatic updating, and the ability to save your work to your personal Steam Cloud space so your files may travel with you.

More Software titles will be added in an ongoing fashion following the September 5th launch, and developers will be welcome to submit Software titles via Steam Greenlight.

"The 40 million gamers frequenting Steam are interested in more than playing games," said Mark Richardson at Valve. "They have told us they would like to have more of their software on Steam, so this expansion is in response to those customer requests."

For more information, please visit www.steampowered.com .

(Source)

OTA Update Center brings over-the-air updates to any ROM developer

The folks at the OTA Update Center have worked out the supporting infrastructure and methods to offer a free OTA service to any ROM developer, so that hackers and modders can enjoy that fuzzy feeling an update brings as well. An app will be installed into the system that communicates with the servers to pass out OTA updates to anyone using the ROM. For the end-user, it's a simple and impressive way to keep the OS on your phone up-to-date.

The real difference here is to the developers. They no longer need to host files or insert framework for an FOTA system into their ROM, and instead can use the supplied tool with a few edits. This will get everything up and running with  minimum of extra code, and provide a sort of standard that all developers can follow. We like standards. Developers like standards. Users like things that "just work", and standards allow that to happen easier. Devs can goto OTA Update Center .

(Source)

Blizzard's Battle.net Was Hacked

If you’re a PC gamer and play World of Warcraft, Diablo or Starcraft, you might want to log into Battle.net and change your password immediately. The company behind it, Blizzard, has confirmed that the site has been hacked.


Here’s what Blizzard’s co-founder and President Michael Morhaime had to say about the hack:
This week, our security team found an unauthorized and illegal access into our internal network here at Blizzard. We quickly took steps to close off this access and began working with law enforcement and security experts to investigate what happened.
At this time, we’ve found no evidence that financial information such as credit cards, billing addresses, or real names were compromised. Our investigation is ongoing, but so far nothing suggests that these pieces of information have been accessed.
The company says that a list of email addresses for gamers outside of China were accessed. For those in the US, Australia, New Zealand and Latin America, your personal security question and mobile and dial-in authentication information was also accessed. Crap. Luckily, no credit card information was thieved…that Blizzard knows of yet.
Blizzard doesn’t seem overly concerned: “Based on what we currently know, this information alone is NOT enough for anyone to gain access to Battle.net accounts.” it said in its release. I think it’s too early to be so sure, considering that its investigation has just begun.
The company will be asking users to change their secret question information as well, but the first step is to change your password immediately:
We also know that cryptographically scrambled versions of Battle.net passwords (not actual passwords) for players on North American servers were taken. We use Secure Remote Password protocol (SRP) to protect these passwords, which is designed to make it extremely difficult to extract the actual password, and also means that each password would have to be deciphered individually. As a precaution, however, we recommend that players on North American servers change their password.


(Source)

Wednesday, August 8, 2012

Secuirty Updates Part 3 - Flash & Silverlight...

People please make sure to update your flash software, there is a MAJOR Security Flaw out there! I provided the link @ http://get.adobe.com/flashplayer/

Also it wouldn't hurt to also update your Silverlight Software you can get this @ http://www.microsoft.com/silverlight/

One more thing if your using Internet Explorer please don't you'll be asking for trouble, Try Google Chrome @ https://www.google.com/chrome/index.html
You can also get a Great addon for your web browser called 'Web of trust' @ http://www.mywot.com/en/download.

Thanks for keeping the internet more Secure!

Security Updates Part 2 - Java

If you run java or not even sure what it is and you might even have it, to make sure it updated, on your pc or mac and Linux please check this website to make sure your safe! http://www.isjavaexploitable.com/

Security Updates Part 1 - Adobe Shockwave

PLEASE! Make sure you update your Adobe Shockwave, if you dont know what this is, or not sure if you have it. If you play games on the web you have it for sure, and it can come preinstalled with store bought PCs update here: http://get.adobe.com/shockwave/