Posts

Showing posts from July, 2015

If you don’t want to give your photos to Google anymore, it’ll steal them

Google’s new Google Photos app has a bunch of new features users may appreciate, including automatic categorization and unlimited storage and backup, but the service is far from perfect. On top of the odd software issues you may encounter with face recognition or upload limits, there’s also a more annoying problem you should be aware of: Google Photos keeps uploading pictures to Google’s servers even after if you uninstall the app from your Android phone. Arnott provided a video demonstration showing that after uninstalling the Google Photos app from his Samsung smartphone, the photograph he took off his coffee mug still wound up being synced into his account on the web.     "Months ago, I downloaded the [Photos] app to play with it, but I did not like it and so un-installed the app after just a few days," Arnott tweeted Wednesday.     "This evening, I went back to Google Photos on my laptop and found a crap-ton of pictures I'd taken in the interim. It seems t

Local WhatsApp, Viber, Skype calls may no longer be free

A high-level government committee has upheld the concept of net neutrality, but its recommendations have raised some major concerns for consumers and startups. Those hooked to applications like WhatsApp, Skype and Viber may no longer be able to make free domestic calls (barring negligible data charges) through these voice over internet protocol (VoIP) services. However, instant messaging and international calls through these services will remain free, if these recommendations are implemented. The Department of Telecommunications (DoT) has now released a much-awaited report [PDF] on the Net Neutrality issue, recommending the Telecom Regulatory Authority of India (TRAI) to regulate the voice calls conducted by the Internet users of over-the-top (OTT) services. Over 100 pages-long report details the DoT's understanding of Net Neutrality Principles, which has been criticized by consumer groups because it could End Free domestic voice calls offered by apps like WhatsApp and Skype. The

Remote Code Execution Vulnerability In Microsoft: Fixed Now

On Monday, Microsoft released Security Updates for all Windows versions including Windows Vista, Windows 7, 8, 8.1 and Windows RT are all affected, including those running Windows Server 2008 and later. According to report: Microsoft spokesperson confirmed in an emailed statement that Windows 10 Insider Preview is also affected. What is Remote Code Execution Vulnerability? Remote code execution is a security vulnerability that allows an attacker to execute codes from a remote server. Microsoft Released Update This security update resolves a vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a specially crafted document or visits an untrusted webpage that contains embedded OpenType fonts. This security update is rated Critical for all supported releases of Microsoft Windows. For more information, see the Affected Software section. Patch: Rename ATMFD.DLL For 32-bit systems: Enter the following commands

NASA Discover Another Earth By Kepler Space Telescope : Scientists Discover Another Earth!

NASA is going to announce of another earth discovery. NASA is organizing Teleconference by today and will share about its Kepler space telescope latest discovery. The first exoplanet orbiting another star like our sun was discovered in 1995. Exoplanets, especially small Earth-size worlds, belonged within the realm of science fiction just 21 years ago. Today, and thousands of discoveries later, astronomers are on the cusp of finding something people have dreamed about for thousands of years - another Earth. About the Mission: Launched in March 2009, Kepler is the first NASA mission to detect Earth-size planets orbiting distant stars in or near the habitable zone -- the range of distances from a star in which the surface temperature of an orbiting planet might sustain liquid water. The telescope has since confirmed more than 1,000 planets and more than 3,000 planet candidates spanning a wide range of sizes and orbital distances, including those in the habitable zone. What does this m

Apple Criticised for Not Patching OS X Yosemite Zero-Day Vulnerability

A serious vulnerability present in every iteration of Apple's desktop operating system since OS X 10.7 — one which allows any user process to gain root privileges — was disclosed to the public on Thursday following the release of OS X 10.10.3, which addresses the issue, and users are urged to update as older OS X versions will remain susceptible to attack. The privilege-escalation vulnerability initially reported on Tuesday by German researcher Stefan Esser, could be exploited by to circumvent security protections and gain full control of Mac computers. The most worrying part is that this critical vulnerability is yet to be fixed by Apple in the latest release of its operating system. Users who unwittingly install malware containing exploit code could hand over complete control of their Mac to the attacker, no matter what other security precautions they may have taken. As a result, OS X users are urged to upgrade to Yosemite version 10.10.3 as soon as possible. Apple will not pat

Four Zero Day Vulnerabilities Discovered in Internet Explorer!

How many Zero-Days do you think could hit Microsoft today? Neither one nor two; this times its Four. Hewlett-Packard’s Zero-Day Initiative greeted Microsoft today with not one but four zero day vulnerabilities located in Internet Explorer, allowing hackers to remotely execute a malicious code on target machine. At first it was thought that these vulnerabilities would affect only desktop version of Microsoft’s very own web browser, however later it was reported that even mobile versions are vulnerable. All the four zero-days originally were reported to Microsoft, affecting Internet Explorer on the desktop. However, later it was discovered that the zero-day vulnerabilities affected Internet Explorer Mobile on Windows Phones as well. Four Zero-day vulnerabilities Disclosed by ZDI Here are the zero-day vulnerabilities, as reported by ZDI:     ZDI-15-359: AddRow Out-Of-Bounds Memory Access Vulnerability     ZDI-15-360: Use-After-Free Remote Code Execution Vulnerability     ZDI-15-361: Use

WordPress 4.2.3 is a Critical Security Release, Fixes an XSS Vulnerability

WordPress users in the Americas woke this morning to find update notices in their inboxes due to a critical security vulnerability. WordPress 4.2.3 was released today and automatically pushed out to sites that have auto-updates enabled. Because this is a security release for all previous versions of WordPress, those who do not have automatic update enabled will need to manually update their sites immediately. Core contributor Gary Pendergast explained the severity of the bug in the release post:     WordPress versions 4.2.2 and earlier are affected by a cross-site scripting vulnerability, which could allow users with the Contributor or Author role to compromise a site. This was reported by Jon Cave and fixed by Robert Chapin, both of the WordPress security team.     We also fixed an issue where it was possible for a user with Subscriber permissions to create a draft through Quick Draft. Pendergast thanked all parties reporting vulnerabilities for responsibly disclosing them to

Ashley Madison users details hacked: 37 Million Accounts Affected

A huge amount of information has been stolen from an online cheating site called Ashley Madison, owned by Toronto-based Avid Life Media (ALM), and portions of information have been posted online by a group or individual identified as Impact Team. The hack was confirmed last week, as reported in Krebsonsecurity.com. The information leak has put users' identities, as well as financial records and other personal information in jeopardy. "We're not denying this happened," Ashley Madison's Chief Executive Officer Noel Biderman said. "Like us or not, this is still a criminal act." The information continues to leak and it will definitely damage the 37 million account holders who frequent the adultery website, which has a slogan, "Life is Short. Have an Affair." Reason behind the Ashley Madison Hack The Impact Team of hackers appears to be upset over a website's service called "Full Delete" that promises to erase a customer&