There is a list of attacks conducted on Elasticsearch databases in the past few years by bad actors. The new one raises more tension among security experts due to its complexity and use of different tactics to evade security system and carry forward the attack successfully.
Source: LXer – Cyberattack On Elasticseach Databases Turns DBs Into Zombies/Botnets
Monthly Archives: July 2019
MediaTek's latest phone CPUs are built for gaming
MediaTek’s mobile processors are more commonly associated with budget smartphones than gaming, but it’s determined to change your mind. The chip designer has introduced a Helio G90 family of processors with performance and features intended with cut…
Source: Engadget – MediaTek’s latest phone CPUs are built for gaming
Debian Outs First Linux Kernel Security Update for Debian GNU/Linux 10 "Buster"
The first Linux kernel security update for the recently released Debian GNU/Linux 10 “Buster” operating system series is now available to address a local privilege escalation flaw.
Source: LXer – Debian Outs First Linux Kernel Security Update for Debian GNU/Linux 10 “Buster”
What's on TV this week: 'Avengers: Endgame'
If you loved its record-breaking theater run but would rather watch the three-hour epic at home where you can take as many bathroom breaks as you like, then we have good news: Marvel Studios’ Avengers: Endgame is available across various digital movi…
Source: Engadget – What’s on TV this week: ‘Avengers: Endgame’
A Hacker Stole Capital One Data on 106 Million Customers, and the FBI Says She Tweeted About It

A hacker swiped credit card applications, Social Security numbers, and bank account information affecting more than 100 million people from Capital One’s server, the bank announced Monday. Authorities say they arrested a suspect, Seattle software engineer Paige Thompson, after she posted about the incident on social…
Source: Gizmodo – A Hacker Stole Capital One Data on 106 Million Customers, and the FBI Says She Tweeted About It
Capital One Says Hacker Breached Accounts of 100 Million People; Ex-Amazon Employee Arrested
CaptainDork shares a report from Forbes: Capital One said Monday that sensitive financial information — including social security and bank account numbers — from over 100 million people were exposed in a massive data breach that led to the arrest of former Amazon employee Paige Thompson, a hacker who lives in Seattle. The information was taken from credit card applications submitted to the Virginia-based bank from 2005-2019. These included names, addresses, zip codes/postal codes, phone numbers, email addresses, dates of birth and self-reported income. Additionally, Capital One said that 140,000 Social Security and 80,000 linked bank account numbers were compromised as well as fragments of transaction data from a total of 23 days during 2016, 2017 and 2018. No credit card account numbers or log-in credentials were exposed. Individuals whose information was compromised in the breach will be notified by Capital One. According to court documents, Paige Thompson was arrested for hacking into cloud computer servers rented by Capital One. Investigators say Thompson previously worked at the cloud computing company whose servers were breached, but did not name the company.
“Thompson’s resume, which is still online, and her LinkedIn profile indicate that she worked at Amazon, which operates the popular cloud computing business Amazon Web Services, from 2015-2016,” reports Forbes. “Thompson allegedly posted the information from the hack on her Github profile, which included a link to her resume, leading the FBI to her. The hack occurred on March 22 or 23, the court documents say, but no one at Capital One knew the bank had been breached until four months later when an anonymous security researcher alerted them.”
Read more of this story at Slashdot.
Source: Slashdot – Capital One Says Hacker Breached Accounts of 100 Million People; Ex-Amazon Employee Arrested
RadeonSI Gallium3D Gets Wired For Compute-Only Arcturus To Handle Video Decode
In addition to new patches coming out on Monday for addressing power management with AMD’s unreleased “Arcturus” GPU, a set of Mesa patches were merged for adding RadeonSI Gallium3D driver support…
Source: Phoronix – RadeonSI Gallium3D Gets Wired For Compute-Only Arcturus To Handle Video Decode
Linux Mint 19.2 "Tina" to Launch This Week, Cinnamon 4.2 Coming to LMDE 3 Soon
Linux Mint project leader Clement Lefebvre announced today that the forthcoming Linux Mint 19.2 “Tina” operating system will launch later this week for all supported editions.
Source: LXer – Linux Mint 19.2 “Tina” to Launch This Week, Cinnamon 4.2 Coming to LMDE 3 Soon
Hacker Claims to Be in Possession of Personal Info on Up to 20,000 LAPD Applicants

The Los Angeles Police Department has warned that a hacker is claiming to be in possession of the personal information of roughly 2,500 “officers, trainees, and recruits,” as well as 17,500 other LAPD applicants, NBC Los Angeles reported on Monday.
Source: Gizmodo – Hacker Claims to Be in Possession of Personal Info on Up to 20,000 LAPD Applicants
Scientists create contact lenses that zoom on command
Nosebleed seats may soon be a thing of the past. Scientists at the University of California San Diego have created a prototype contact lens that is controlled by the eye’s movements. Wearers can make the lenses zoom in or out by simply blinking twice…
Source: Engadget – Scientists create contact lenses that zoom on command
LLVM 9.0-RC1 Arrives For Testing
While LLVM 9.0 was branched nearly two weeks ago and it was anticipated that the release candidate would immediately follow, only yesterday did 9.0-RC1 materialize…
Source: Phoronix – LLVM 9.0-RC1 Arrives For Testing
Python's Mypy: Callables and Generators
It’s important to remember that Python, the language, isn’t changing,and it isn’t becoming statically typed. Mypy is a separate program, runningoutside Python, typically as part of a continuous integration (CI)system or invoked as part of a Git commit hook. The idea is that Mypyruns before you put your code into production, identifying where thedata doesn’t match the annotations you’ve made to your variables andfunction parameters.
Source: LXer – Python’s Mypy: Callables and Generators
In a 1st, Doctors In US Use CRISPR Tool To Treat Patient With Genetic Disorder
An anonymous reader quotes a report from NPR: For the first time, doctors in the U.S. have used the powerful gene-editing technique CRISPR to try to treat a patient with a genetic disorder. “It is just amazing how far things have come,” says Victoria Gray, 34, of Forest, Miss. “It is wonderful,” she told NPR in an exclusive interview after undergoing the landmark treatment for sickle cell disease. Gray is the first patient ever to be publicly identified as being involved in a study testing the use of CRISPR for a genetic disease. “I always had hoped that something will come along,” she says from a hospital bed at the Sarah Cannon Research Institute in Nashville, Tenn., where she received an infusion of billions of genetically modified cells. “It’s a good time to get healed.” But it probably will take months, if not years, of careful monitoring of Gray and other patients before doctors know whether the treatment is safe and how well it might be helping patients. “For the study, doctors are using cells taken from patients’ own bone marrow that have been genetically modified with CRISPR to make them produce a protein that is usually only made by fetuses and by babies for a short time following birth,” the report adds. “The hope is this protein will compensate for the defective protein that causes sickle cell disease and will enable patients to live normally for the rest of their lives.”
Read more of this story at Slashdot.
Source: Slashdot – In a 1st, Doctors In US Use CRISPR Tool To Treat Patient With Genetic Disorder
Rich People Now Just Signing Over Custody of Their Kids to Score Financial Aid, Apparently

As if one major college-related scandal weren’t enough in a year, there comes this news: wealthy parents in Illinois are reportedly scamming financial aid for their college-bound children by transferring guardianship to someone else, freeing up said children to claim financial independence. Is this pretty unethical?…
Source: Gizmodo – Rich People Now Just Signing Over Custody of Their Kids to Score Financial Aid, Apparently
Campaign Aides Let the UAE Screen Trump's 'America First' Energy Speech, Made Changes at Their Request

Aides to now-President Donald Trump let senior United Arab Emirates officials look at and edit a 2016 campaign trail speech in which he laid out his “America First” energy policy, ABC News reported on Monday.
Source: Gizmodo – Campaign Aides Let the UAE Screen Trump’s ‘America First’ Energy Speech, Made Changes at Their Request
Data breach compromises info for 20,000 LAPD officers and applicants
Los Angeles police officers are the victims of what appears to be a serious data breach. The city’s Personnel Department has warned the LAPD that intruders stole personal information for roughly 2,500 officers and 17,500 officer applicants, includin…
Source: Engadget – Data breach compromises info for 20,000 LAPD officers and applicants
Sonic Redesigned Evangelion
Canonical Outs Linux Kernel Security Patch for Ubuntu 16.04 LTS to Fix Six Flaws
Canonical releases a new Linux kernel security update for its long-term supported Ubuntu 16.04 LTS (Xenial Xerus) operating system series to address several vulnerabilities.
Source: LXer – Canonical Outs Linux Kernel Security Patch for Ubuntu 16.04 LTS to Fix Six Flaws
Scientists Create Contact Lenses That Zoom When You Blink Twice
Scientists at the University of California San Diego have created a contact lens, controlled by eye movements, that can zoom in if you blink twice. “In the simplest of terms, the scientists measured the electrooculographic signals generated when eyes make specific movements (up, down, left, right, blink, double blink) and created a soft biomimetic lens that responds directly to those electric impulses,” reports CNET. “The lens created was able to change its focal length depending on the signals generated.” From the report: Incredibly, the lens works regardless of whether the user can see or not. It’s not about the sight, it’s about the electricity produced by specific movements. The researchers believe this innovation could be used in “visual prostheses, adjustable glasses, and remotely operated robotics in the future.”
Read more of this story at Slashdot.
Source: Slashdot – Scientists Create Contact Lenses That Zoom When You Blink Twice
Feds: former cloud worker hacks into Capital One and takes data for 106 million people
Enlarge (credit: Tdorante10)
A former systems engineer has been arrested on charges that she hacked into Capital One’s network and stole sensitive data for about 106 million people, according to an FBI court filing and a statement from the Virginia-based bank.
Paige A. Thompson, 33, of Seattle was an employee of an unnamed cloud-computing company from 2015 to 2016, FBI Special Agent Joel Martini wrote in a criminal complaint filed on Monday. A GitHub account belonging to her showed that, earlier this year, someone exploited a firewall vulnerability in Capital One’s network that allowed an attacker to execute a series of commands on the bank’s servers.
Capital One has confirmed the intrusion and said it affected about 100 million individuals in the US and 6 million people in Canada. Personal information taken included names, incomes, dates of birth, addresses, phone numbers, and email addresses. Social security numbers for 140,000 people were also obtained, and about 80,000 bank account numbers were accessed. Social Insurance numbers for about 1 million Canadians were also obtained. No credit card numbers or login credentials were compromised. It’s unlikely the stolen data was used in fraud or was widely disseminated, bank officials said.
Read 7 remaining paragraphs | Comments
Source: Ars Technica – Feds: former cloud worker hacks into Capital One and takes data for 106 million people



