Posts

Bluetooth security: Flaw could allow nearby attacker to grab your private data

Image
Patches are on the way for a Bluetooth bug that could affect Apple, Intel, Broadcom, and some Android devices. A cryptographic bug in many Bluetooth firmware and operating system drivers could allow an attacker within about 30 meters to capture and decrypt data shared between Bluetooth-paired devices. The flaw was found by Lior Neumann and Eli Biham of the Israel Institute of Technology, and  flagged today  by Carnegie Mellon University CERT. The flaw, which is tracked as CVE-2018-5383, has been confirmed to affect Apple, Broadcom, Intel, and Qualcomm hardware, and some Android handsets. It affects Bluetooth's Secure Simple Pairing and Low Energy Secure Connections. Fortunately for macOS users, Apple released a  patch for the flaw in July. As the CERT notification explains, the vulnerability is caused by some vendors' Bluetooth implementations not properly validating the cryptographic key exchange when Bluetooth devices are pairing. The flaw slipped into the Bluetooth

IoT hacker builds Huawei-based botnet, enslaves 18,000 devices in one day

Image
A hacker has taken only 24 hours to build a botnet which is at least 18,000-devices strong. How long does it take to build a botnet? Not long, if you consider Anarchy's 18,000-device-strong creation, brought to life in only 24 hours. First spotted by researchers from NewSky Security, as reported  by Bleeping Computer , other security firms including  Rapid7  and  Qihoo 360 Netlab  quickly jumped on the case and confirmed the existence of the new threat. The security teams realized there has been a huge recent uptick in Huawei device scanning. The traffic surge was due to scans seeking devices vulnerable to  CVE-2017-17215 , a critical security flaw which can be exploited through port 37215.Scans to find routers vulnerable to the issue began on 18 July. If a Huawei router is exploited in this fashion, attackers can send malicious packets of data, launch attacks against the device, and remotely execute code -- which can be crafted in order to control, enslave, and a

Tableau takes next steps toward smart analytics after acquisitions

Image
Tableau's Empirical acquisition is its latest move toward machine-augmented analytics. Here's a look at the company's 'smart' features. Tableau last month announced the acquisition of Empirical Systems, an artificial intelligence (AI) startup with an automated discovery and analysis engine designed to spot influencers, key drivers, and exceptions in data. It was Tableau's second acquisition over the last year aimed at accelerating so-called "smart" capabilities and part of a larger push that began in 2016. Despite the embrace and success of self-service over the last decade, it's increasingly clear that this approach alone is not enough to truly democratize data-driven decision-making. Self-service tools aren't always intuitive for nontechnical business users. Even more data-savvy users sometimes need help when selecting data, determining how to analyze that information, and deciding how best to visualize and share insights. To make thi

Samsung Q2 profit halts seven-quarter record streak

Image
Samsung Electronics expects a solid 14.8 trillion won operating profit for the second quarter, a rise of 5.2 percent from a year ago. But it brings a halt to its seven-quarter-straight streak of record profits. Samsung expects operating profits of 14.8 trillion won in the second quarter of this year, it has said in its earnings guidance. The results mark a rise of 5.2 percent from 14.67 trillion won a year ago. But it is a fall of 5.4 percent from the previous quarter's 15.64 trillion won, the company's highest on record. Samsung's profits had been on a record-setting seven quarter straight streak of rising profits. In sales, the firm expects 58 trillion won, a drop of 4.9 percent from last year's 61 trillion won.A decline in smartphone sales and price drops of Liquid Crystal Display (LCD) likely dented profits. But high demand for memory chips and strong sales of premium TVs thanks to the 2018 FIFA World Cup likely offset a huge decline. Analysts es

Western Digital adds NVMe, flash heft to data center storage lineup

Image
Western Digital is going after big and fast data workloads. Western Digital expanded its data center portfolio to include an object storage system, new all-flash arrays and hybrid platforms. Here's a look at the Ultrastar system The company, which has expanded its enterprise focus via acquisitions, rolled out the following as it looks to enable big data and analytics workloads. Active Scale 5.3 Object Storage System. The system, which is Western Digital's ActiveScale P100 and X100 systems, is designed for petabytes of unstructured data. Additions include the ability to ingest and manage mixed file and object use cases. Integration with Amazon Web Services, more storage density and support for Docker containers were also added. IntelliFlash NVMe Flash Arrays via Western Digital's N Series of systems. The N Series systems can scale from 19TB to 1.3PB of solid-state storage. The systems are available later this year. Ultrastar Serv60+8 Hybrid Storage Server Pl

Microsoft buys machine-learning startup Bonsai

Image
Microsoft is buying one of the AI companies in which it has invested: Bonsai, a deep reinforcement platform for enterprise/industrial applications. After buying  GitHub ,   four gaming companies   and an   educational video-discussion vendor , Redmond purchased on June 20 another artificial intelligence (AI) vendor. Microsoft officials announced the company had  signed an agreement to acquire Bonsai. Bonsai , based in Berkeley, Calif., is one of the companies that Microsoft's Ventures unit (now known as M12) had invested.Bonsai officials describe the company as delivering "the world's first deep reinforcement learning platform for the enterprise." Bonsai officials said the company has been integrating machine-learning and developer tools from Microsoft, Uber, Google and Apple to build its software and services to  build AI for industrial applications , according to Bonsai's web site. (Cue Microsoft's "intelligent edge"campaign.) Bonsai u

Google makes G Suite's App Maker generally available

Image
The low-code environment is targeted at IT departments that don't have the budget for custom apps. Google on Thursday is bringing App Maker, its developer tool for G Suite, into general availability . App Maker is a low-code environment for developers who can use to build custom business apps. It launched in beta in late 2016. As it moves into GA, App Maker is also getting a couple of updates: First, G Suite administrators will have visibility over these custom apps, including oversight of owners, usage metrics and OAuth permissions. Admins will also be able to prevent apps from running without their approval. Additionally, for customers who also have a Google Cloud Platform (GCP) account, App Maker is offering built-in support for Cloud SQL. It also supports a "Bring Your Own Database" model so customers can connect to their own database using the JDBC API or a REST API. App Maker also enables developers to connect their apps to data and services from Gmail, C

GitHub rivals gain from Microsoft acquisition but it's no mass exodus, yet

Image
GitHub competitors have picked up thousands of new developers but in relative terms the numbers are small.   Rivals of now Microsoft-owned code host GitHub are touting gains from developers who aren't happy with the acquisition and what it could mean.GitLab and Atlassian's BitBucket are both playing up to negative reactions towards the acquisition and uncertainty among developers about the future. Both sites say developers are migrating in larger numbers to their respective sites. GitLab said yesterday it had imported over 100,000 repositories from GitHub since news of the deal was confirmed on Monday.Microsoft said it is paying $7.5bn in stock for GitHub as part of an effort to win developers and give a boost to Azure and the other developer tools it offers. Despite losing some developers, these numbers migrating are minuscule compared with the 85 million repositories on GitHub. BitBucket also claims to have seen a noticeable spike in GitHub migrations sin

How Blockchain could change how we buy music, read news, and consume content

Image
It's feverishly hyped and often misunderstood, but blockchain technology is on track to become a major source of disruption across media and entertainment. Blockchain, best known as the technology behind Bitcoin , is a secure, encrypted database architecture that logs and links all transactions on a tamper-proof ledger distributed among multiple parties. In effect, a blockchain creates an immutable golden record of time-stamped transactions related to any product that can be bought and sold. In the context of buying music, news, and other digital content, the promise of blockchain is to provide decentralized control, trust, and transparency when transacting virtual property. For the creators of digital content and virtual property, this means enforceable copyrights, transparency around royalty payments, and payments made securely without an intermediary. In the music and news media industries in particular, the blockchain could be key to rights management, procuring

Finally, a power bank specifically designed for GoPro Hero users

Image
Summary: There are no shortage out there of power banks for iPhone and Android devices, but Ugreen introduces a portable charger for GoPro Hero 5/6 owners. GoPro cameras are great fun and capable of capturing some amazing shots, but I do find that they burn through batteries at quite a rate. While you can charge a GoPro direct from a power bank, you can't use the GoPro as a camera while it's charging the internal battery. But accessories maker Ugreen has come out with a power bank that can be used to recharge GoPro batteries directly without going through the camera. The  Ugreen 10,000mAh portable battery charger  not only features the regular USB-A 5.1V/2.4A port, but also has a slot that can take a single GoPro Hero 5/6 battery for recharging. The 10,000mAh battery pack has enough power for the following: iPhone X: 2.7 times iPhone 8: 4 times Samsung Galaxy S8: 2.4 times iPad mini 4/Nintendo Switch: 1.4 times GoPro Hero 5/6battery: 6 times The power b