Thursday, June 30, 2011

Security firm RSA attacked using Excel-Flash one-two sucker punch

RSA attacked using Flash vulnerability
It has emerged that the underlying cause of RSA's SecurID gaffe was the recently-reported zero-day vulnerability found in Adobe's Flash Player.

The exploit, which used specially-crafted Flash embedding in Excel spreadsheets, was first reported on March 15 and has since been fixed. RSA was hacked sometime in the first half of March when an employee was successfully spear phished and opened an infected spreadsheet. As soon as the spreadsheet was opened, an advanced persistent threat (APT) -- a backdoor Trojan -- called Poison Ivy was installed. From there, the attackers basically had free reign of RSA's internal network, which led to the eventual dissemination of data pertaining to RSA's two-factor authenticators.

The attack is reminiscent of the APTs used in the China vs. Google attacks from last year -- and indeed, Uri Rivner, the head of new technologies at RSA is quick to point out that that other big companies are being attacked, too: "The number of enterprises hit by APTs grows by the month; and the range of APT targets includes just about every industry. Unofficial tallies number dozens of mega corporations attacked [...] These companies deploy any imaginable combination of state-of-the-art perimeter and end-point security controls, and use all imaginable combinations of security operations and security controls. Yet still the determined attackers find their way in."

What we'd like to know, though, is whether the attack on RSA was caused by Adobe's lackadaisical approach to patching Flash -- or was it the other way around? Was it the RSA attack that first brought the zero-day vulnerability to Adobe's attention?

Security firm RSA attacked using Excel-Flash one-two sucker punch originally appeared on Download Squad on Wed, 06 Apr 2011 06:55:00 EST. Please see our terms for use of feeds.

Permalink | Email this | Comments

Source: http://downloadsquad.switched.com/2011/04/06/security-firm-rsa-attacked-using-excel-flash-one-two-sucker-punc/

Sra International Spss Spansion Sonus Networks Sonic Automotive Skyworks Solutions

Balance is a challenging mouse-based physics game

balance
Years of computer use have taught us that the mouse cursor is "above" the windows. It doesn't push anything around; at least not without you clicking anything.

Balance takes that ingrained bit of knowledge and cancels it out. Suddenly your cursor (a blue dot) is solid - and if it touches the blue block, it pushes it around.

Your job is to use your cursor to nudge the blue block over to the orange block. You will have to push it, lift it and even flip it on its side, and then balance it. It's a very tricky game - one I wouldn't recommend tackling with a laptop trackpad.

Still, if you have a mouse and a hankering for a little physics gameplay, this is a cute little game. I like how the blue block never stops smiling, it makes me feel better about the world.

Balance is a challenging mouse-based physics game originally appeared on Download Squad on Thu, 10 Mar 2011 18:30:00 EST. Please see our terms for use of feeds.

Permalink | Email this | Comments

Source: http://downloadsquad.switched.com/2011/03/10/balance-is-a-challenging-mouse-based-physics-game/

Unisys Triquint Semiconductor Trimble Navigation Limited Trident Microsystems Transaction Systems Architects Total System Services

RIM Responds to 'Open Letter' Criticisms with More Nonsensical Business Jargon [Smartphones]

Why is it that RIM, when faced with legitimate criticisms about the state of its company, can only spit out garbled bullshit in response? The latest example lies within their retort to an open letter from a supposed senior-level RIM employee. More »


Source: http://feeds.gawker.com/~r/gizmodo/full/~3/MTlC97ydu40/rim-responds-to-open-letter-criticisms-with-more-nonsensical-business-jargon

Mobile Telesystems Nanya Technology Nii Holdings Nikon Nintendo Nokia

Security firm RSA attacked using Excel-Flash one-two sucker punch

Security firm RSA attacked using Excel-Flash one-two sucker punch
RSA attacked using Flash vulnerability
It has emerged that the underlying cause of RSA's SecurID gaffe was the recently-reported zero-day vulnerability found in Adobe's Flash Player.

The exploit, which used specially-crafted Flash embedding in Excel spreadsheets, was first reported on March 15 and has since been fixed. RSA was hacked sometime in the first half of March when an employee was successfully spear phished and opened an infected spreadsheet. As soon as the spreadsheet was opened, an advanced persistent threat (APT) -- a backdoor Trojan -- called Poison Ivy was installed. From there, the attackers basically had free reign of RSA's internal network, which led to the eventual dissemination of data pertaining to RSA's two-factor authenticators.

The attack is reminiscent of the APTs used in the China vs. Google attacks from last year -- and indeed, Uri Rivner, the head of new technologies at RSA is quick to point out that that other big companies are being attacked, too: "The number of enterprises hit by APTs grows by the month; and the range of APT targets includes just about every industry. Unofficial tallies number dozens of mega corporations attacked [...] These companies deploy any imaginable combination of state-of-the-art perimeter and end-point security controls, and use all imaginable combinations of security operations and security controls. Yet still the determined attackers find their way in."

What we'd like to know, though, is whether the attack on RSA was caused by Adobe's lackadaisical approach to patching Flash -- or was it the other way around? Was it the RSA attack that first brought the zero-day vulnerability to Adobe's attention?

Security firm RSA attacked using Excel-Flash one-two sucker punch originally appeared on Download Squad on Wed, 06 Apr 2011 06:55:00 EST. Please see our terms for use of feeds.

Permalink�|�Email this�|�Comments


iPhone Live 158: Sherlocked

iPhone Live 158: Sherlocked
iPhone Live 158: SherlockedOur podcast feed Download Directly Subscribe via iTunes Rene, Seth, Ally, and Georgia talk iPhone turning 4, iOS 5 beta 2, “Sherlocking” apps, SHSH blobs, tiered pricing, and Google+. This is iPhone Live! Show notes Hosts Rene Ritchie (@reneritchie) Seth Clifford (@sethclifford) Ally Kazmucha (@iMuggle) Georgia (@GeorgiaTiPb) Credits Thanks to the TiPb iPhone accessory store [...]

iPhone Live 158: Sherlocked

Rene, Seth, Ally, and Georgia talk iPhone turning 4, iOS 5 beta 2, “Sherlocking” apps, SHSH blobs, tiered pricing, and Google+. This is iPhone Live!

Hosts

  • Rene Ritchie (@reneritchie)
  • Seth Clifford (@sethclifford)
  • Ally Kazmucha (@iMuggle)
  • Georgia (@GeorgiaTiPb)
  • Credits

    Thanks to the TiPb iPhone accessory store for sponsoring the podcast, and to everyone who showed up for the live chat!

    Our music comes from the following sources:



    CrunchGear Week in Review: Trajectory Edition

    Here are some stories from the past week on CrunchGear: Japanese Robot Company Proves Even The Weirdest, Biggest Mechs Can Sell Angry Birds Games And Videos Coming To A Roku Near You Idea Flight Turns iPads Into Presentation Platform We?re (Almost) Live At E3 2011 In Los Angeles George Plimpton?s Video Falconry Is A Real [...]

    Source: http://www.crunchgear.com/2011/06/06/crunchgear-week-in-review-trajectory/

    Ikon Office Solutions Idt Ibasis Hypercom Hewlett Packard Co Heartland Payment Systems

    Olympus PEN EP3 Improves Almost Everything

    A big day for photography news today, thanks to the folks at Olympus. First up is the Pen EP3, the fifth iteration of its PEN Micro Four Thirds line, which manages to mix up pretty much everything while keeping it in the original PEN’s retro-style body.
    First, the basics. The 12.3MP sensor is almost the same, [...]

    Source: http://www.wired.com/gadgetlab/2011/06/olympus-pen-ep3-improves-almost-everything/

    Emulex Ems Technologies Emc Electronics For Imaging Electronic Data Systems Electronic Arts

    Burrito Bison is a simple game for gummy bear lovers

    burritobison
    Burrito Bison is a pretty simple game, but if you're into gummy bears you might find it addictive.

    As you may have guessed from the name, you're a bison (not a burrito, though). In the course of your day-to-day grocery shopping, you're abducted into a bag of gummy bears, and must now fend for yourself.

    At the beginning of each round you launch yourself onto the marching gummy (gummi?) bears, while you're being watched by a huge crowd of even more gummy bears. Your goal is to keep bouncing on the bears and earn more and more money while you do it. Every time you hit a gummy bear, you lose some momentum. If you hit the floor, you basically lose all of it.

    But don't give up just yet! You have an emergency thrust which you can use to gain some momentum and keep bouncing on those bears. This extra thrust gets refilled as you hit more bears.

    There are also special gummy bears that give you extra thrust or extra money. The money comes in handy at the end of each round, when you can shop for cool stuff to make your bison even more effective against those gummy bears.

    It's a fun and colorful game that kept my interest for quite some time, and almost sent me running to the closest store to get some gummy bears!

    Burrito Bison is a simple game for gummy bear lovers originally appeared on Download Squad on Sat, 26 Mar 2011 14:30:00 EST. Please see our terms for use of feeds.

    Permalink | Email this | Comments

    Source: http://downloadsquad.switched.com/2011/03/26/burrito-bison-is-a-simple-game-for-gummy-bear-lovers/

    Epicor Software Emulex Ems Technologies Emc Electronics For Imaging Electronic Data Systems

    Scrabble Helper helps you improve your Words With Friends gameplay

    scrabblehelper
    If you play Scrabble (or a scrabble-like game) from time to time, you may want to check out Scrabble Helper. This simple website is a godsend when you're at a loss for words. Simply enter whatever letters you have, and the word you'd like to connect with. Scrabble helper comes up with a whole bunch of suggestions sorted by score.

    The site lets you select one of five dictionaries - Scrabble International/US, Lexulous International/US, and Words With Friends. Some people might say this constitutes cheating -- I think if the other side knows you're doing it, it's definitely not cheating. And it doesn't take the challenge out of the game, because implementing Scrabble Helper's suggestions and deciding which words you'd like to connect with still takes a fair bit of thought.

    Very handy, though perhaps not one for the Scrabble puritans in the crowd.

    Scrabble Helper helps you improve your Words With Friends gameplay originally appeared on Download Squad on Mon, 14 Mar 2011 18:00:00 EST. Please see our terms for use of feeds.

    Permalink | Email this | Comments

    Source: http://downloadsquad.switched.com/2011/03/14/scrabble-helper-helps-you-improve-your-words-with-friends-gamepl/

    Osi Systems Oracle Openwave Systems On Semiconductor Nvidia Nuance Communications

    Mac OS X Lion Available in July from Mac App Store

    Mac OS X Lion Available in July from Mac App Store
    Apple today announced that Mac OS X Lion — the eighth major release of the world’s most advanced desktop operating system — will be available to customers in July as a download from the Mac App Store for $ 29.99. OS X Lion offers more than 250 new features, including Multi-Touch gestures; systemwide support for [...]

    Apple today announced that Mac OS X Lion — the eighth major release of the world’s most advanced desktop operating system — will be available to customers in July as a download from the Mac App Store for $ 29.99. OS X Lion offers more than 250 new features, including Multi-Touch gestures; systemwide support for full-screen apps; Mission Control, a bird’s-eye view of everything running on your Mac; Launchpad, a new home for all your apps; and a completely redesigned Mail app.
    Apple Hot News


    Wedding photo and video shoot done entirely with an iPhone 4 camera [video]

    Wedding photo and video shoot done entirely with an iPhone 4 camera [video]
    A couple’s wedding day is said to be the most important day of their lives. One particular couple decided to risk their special day’s memories by only shooting the photographs and video using an iPhone 4. Sure the iPhone 4 has a very good quality camera but is this taking it a little too far? [...]

    A couple’s wedding day is said to be the most important day of their lives. One particular couple decided to risk their special day’s memories by only shooting the photographs and video using an iPhone 4. Sure the iPhone 4 has a very good quality camera but is this taking it a little too far?

    Well it is not quite as risky as it seems. the couple brought in professional photographers and videographers for the big day and the results are quite impressive. Of course more than one iPhone 4 was used in gathering all the footage and the final editing we assume wasn’t done on the iPhone either. Either way it is apparently the first time that this has been done.

    Take a look at the video after the break. Let us know what you think of the final result. Would you risk an important occasion such as a wedding solely to the iPhone 4’s camera?

    [YouTube]



    Google+ for Android app (hands-on)

    Given the number of apps Google's made available for smartphones, it shouldn't be much of a surprise that it's taken its suite of social networking services direct to the mobile world as well. As soon as Google+ was officially announced, an app was ready for download in the Android Market and a web app became available for Safari for iOS (with its full offering to the App Store coming soon). As usual, we couldn't resist the urge to play around with it, but how does the mobile iteration fare against the competition? Continue past the break to get a peek of the larger-than-life service squeezed into a 4.3-inch (or smaller) display.

    Continue reading Google+ for Android app (hands-on)

    Google+ for Android app (hands-on) originally appeared on Engadget on Thu, 30 Jun 2011 09:35:00 EDT. Please see our terms for use of feeds.

    Permalink   |   | Email this | Comments

    Source: http://www.engadget.com/2011/06/30/edit-google-for-android-app-hands-on/

    Automatic Data Processing Avnet Bharti Airtel Bt Group Canon Memc Electronic Materials

    LED Moon shines message of hope, no dark side to see

    Scale models of manmade wonders are usually the stuff of gimmicky travel souvenirs, but could you resist a faithful replica that was a topographic clone of our closest celestial body? We didn't think so. Dedicated to the super moon that brought his catastrophe-stricken nation comfort, Japanese designer Nosigner culled imagery taken by the lunar orbiter Kaguya to create a hope-swelling, LED-lit copy of Earth's favorite satellite. Recently on display at the Dwell on Design exhibit in LA, this spherical lamp of lunar love doesn't yet appear to be available for order -- but then again, how do you put a price on hope?

    LED Moon shines message of hope, no dark side to see originally appeared on Engadget on Thu, 30 Jun 2011 08:43:00 EDT. Please see our terms for use of feeds.

    Permalink Inhabitat  |  sourceNosigner Newsletter  | Email this | Comments

    Source: http://www.engadget.com/2011/06/30/led-moon-shines-message-of-hope-no-dark-side-to-see/

    Insight Enterprises Ingram Micro Informatica Infocus Zoran Zions Ban

    Microsoft files antitrust complaint against Google in Europe, showdown imminent

    Bill Gates and Paul AllenMicrosoft, citing Google's tyrannical 95% share of the European search market, has lodged a formal complaint with the European Commission. It's not like Microsoft is breaking any ground here -- the European Commission has been investigating Google's alleged violation of European competition law since November 2010 -- but there's no doubt that the addition of Microsoft's gravitas will affect the proceedings.

    Microsoft's complaint reads like a sincere and plaintive cry for help against the Google Overlord. Microsoft lists no less than six damning reasons why Google's behavior is anti-competitive -- from Windows Phone 7's incompatibility with YouTube, to its nefarious handling of Google Books -- and finishes with a wide-eyed plea to the European Commission to please find Google guilty.

    For those of you that have been following Microsoft's own antitrust troubles over the last decade, don't worry: MS is quick to point out the irony in the situation. "There of course will be some who will point out the irony in today's filing. Having spent more than a decade wearing the shoe on the other foot with the European Commission, the filing of a formal antitrust complaint is not something we take lightly. This is the first time Microsoft Corporation has ever taken this step. More so than most, we recognize the importance of ensuring that competition laws remain balanced and that technology innovation moves forward."

    It sounds like Microsoft, having well and truly gone through the wringer, wants Google to be held similarly accountable. That's fair enough, right?

    Microsoft files antitrust complaint against Google in Europe, showdown imminent originally appeared on Download Squad on Thu, 31 Mar 2011 05:50:00 EST. Please see our terms for use of feeds.

    Permalink | Email this | Comments

    Source: http://downloadsquad.switched.com/2011/03/31/microsoft-files-antitrust-complaint-against-google-in-europe-sh/

    Sonic Automotive Skyworks Solutions Silicon Laboratories Si International Seagate Technology Scientific Games

    Best Buy sucks at product recognition: Wireless Keyboard for TouchPad, iPad sold separately

    Oh, really Best Buy --you don't say? Too bad... that $69.99 price tag would be so much easier to swallow if you threw in the whole kit and kaboodle.

    [Thanks, Kevin]

    Continue reading Best Buy sucks at product recognition: Wireless Keyboard for TouchPad, iPad sold separately

    Best Buy sucks at product recognition: Wireless Keyboard for TouchPad, iPad sold separately originally appeared on Engadget on Thu, 30 Jun 2011 02:35:00 EDT. Please see our terms for use of feeds.

    Permalink   |   | Email this | Comments


    Source: http://feeds.engadget.com/~r/weblogsinc/engadget/~3/wcMMxUbaYU4/

    Interdigital Communications Intel Insight Enterprises Ingram Micro Informatica Infocus