Drupalgeddon hits Warframe – nearly 800,000 gamers’ account details being sold on the net.

Are you a fan of Warframe? Is so, Digital Extremes, the company behind the popular online game for the XBox One, Playstation 4 and PC, has some bad news for you. Last week we were made aware of a potential web server breach that occurred in November 2014. At the time, we believed this to […]… Read More

The post Drupalgeddon hits Warframe – nearly 800,000 gamers’ account details being sold on the net. appeared first on The State of Security.

Continue reading Drupalgeddon hits Warframe – nearly 800,000 gamers’ account details being sold on the net.→

Salesforce will only support Nexus and Samsung Galaxy phones to avoid Android fragmentation

Ina Fried at Recode writes:

One of the big challenges for Android app developers is the fact that there are just so many different phones out there using a variety of versions of Google’s operating system.

That often means a lot more time and money spent testing and supporting Android than Apple’s iOS, but with Android running on the majority of smartphones out there, what’s a large developer to do?

Salesforce is taking a rather unusual stance in an effort to avoid this problem. Starting with an update to its Salesforce1 app later this year, the company will offer support for its app only to those using certain Google Nexus or Samsung Galaxy devices.

When I have friends and family who ask me which Android they should buy, I normally answer by saying “Get an iPhone instead.”

Because security updates matter.

When they continue to insist they *really* do want an Android, I tell them to get a Google Nexus. Or, maybe at a stretch, a Samsung. But personally I would steer clear of anything else because of this fragmentation issue.

Seems like I was right.

When popular apps like Salesforce basically throw in the towel and admit it’s too hard to properly support the multitude of different devices running Android, you know you’ve got a problem.

Continue reading Salesforce will only support Nexus and Samsung Galaxy phones to avoid Android fragmentation→

Russian security firm linked to cybercrime gang

Brian Krebs has been doing what he does best, following a trail of clues scattered across the internet and joining the dots.

This week he followed-up on information shared with him by security researcher Ron Guilmette, who uncovered “interesting commonalities” in website registration records, revealing strange links between a Russian security firm called Infocube (also known as Infokube) and the notorious Carbanak cybercrime gang.

Carbanak, of course, has been blamed for stealing hundreds of millions of dollars, after targeting e-payment systems and installing malware on ATM infrastructure that resulted in theft from cash machines.

Infokube, meanwhile, claims to work with some of the best known firms in computer security.

Krebs reached out to Artem Tveritinov, Infokube’s apparent CEO, to ask if he had any explanation for the website registration details showing such similarities:

“Our company never did anything illegal, and conducts all activities according to the laws of Russian Federation,” Tveritinov said in an email. “Also, it’s quite stupid to use our own personal data to register domains to be used for crimes, as [we are] specialists in the information security field.”

Krebs reports that as he sent Tveritinov questions by email, the Russian deleted his social media presence:

“I noticed that the Vkontakte social networking profile that Tveritinov had maintained regularly since April 2012 was being permanently deleted before my eyes. Tveritinov’s profile page and photos actually disappeared from the screen I had up on one monitor as I was in the process of composing an email to him in the other.”

Read the whole fascinating story on Krebs on Security.

Continue reading Russian security firm linked to cybercrime gang→

Apple fixes FaceTime eavesdropping bug, other other flaws may remain

Although it’s good that Apple has apparently fixed this FaceTime snooping vulnerability, it’s alarming to hear that there may be other as-yet-unpatched vulnerabilities still to be addressed
Read more in my article on the Hot for Security blog.
Continue reading Apple fixes FaceTime eavesdropping bug, other other flaws may remain→