In association with heise online

    Top News

    The H Roundup - Skype surveillance, Linux exploit & Android Studio

    The H Roundup logo In the week ending 18 May – Microsoft is reading what you type in Skype's chat, an exploit for the Linux kernel is discovered, Google unveils its new IDE for developing Android applications, and the International Space Station is using more Linux more »

    Top Feature

    Skype's ominous link checking: facts and speculation

    Skype Listening In icon Our associate's discovery that URLs sent through Skype are then visited by Microsoft has caused quite a stir. A little more information has now emerged and leads to even more questions more »

    Top Open News

    Linux Mint 15 "Olivia" gets release candidate

    Linux Mint logo The Linux Mint developers have announced a release candidate for Linux Mint 15. The "most ambitious release since the start of the project" includes a custom control centre application, a new screensaver tool and a number of other features more »

    Top Open Feature

    Location, location, location

    Location, location, location The rapid rise in the number of mobile devices has led to a concomitant rise in the amount of location data available. Proprietary services are emerging to take advantage of that data, but open source has a strong foothold in the form of OpenStreetMap more »

    Top Security News

    Microsoft closes 33 security holes in May

    Microsoft patch logo The company has fixed a critical hole in Internet Explorer that is already being exploited by attackers, and patched vulnerabilities in all versions of Windows, in Office, in Windows Essentials, and in other components more »

    Top Security Feature

    Skype's ominous link checking: facts and speculation

    Skype Listening In icon Our associate's discovery that URLs sent through Skype are then visited by Microsoft has caused quite a stir. A little more information has now emerged and leads to even more questions more »

    Top Developer News

    Go 1.1 brings better performance and a race detector

    Google Go logo The latest version of Google's Go programming language includes major performance improvements, a race detector for finding memory synchronisation problems and new functionality in the standard library of the language more »

    Top Developer Feature

    Unit testing with Node.js

    Unit testing with Node.js Consistent unit testing is a basic quality requirement in modern software rdevelopment. Mocha is a framework for writing and executing such tests in Node.js more »

    Security news and features

    News & Features

    Saturday, 18 May 2013

    The H Roundup - Skype surveillance, Linux exploit & Android Studio

    The H Roundup logo In the week ending 18 May – Microsoft is reading what you type in Skype's chat, an exploit for the Linux kernel is discovered, Google unveils its new IDE for developing Android applications, and the International Space Station is using more Linux more »

    Friday, 17 May 2013

    Lost+Found: Hacking Smart TVs, scammer hotlines and Vaccination

    Lost+Found icon On The H's radar over the last seven days: Samsung's Smart TV software, phone scammers with their own hotline, tricking malware with Vaccination, Qualcomm is pre-installing Kaspersky on Android phones and Twitter account security more »

    Mac spyware takes screenshots

    Gatekeeper icon A newly found item of Mac malware appears to have been signed by its creator but is apparently unable to deliver its cache of screenshots to the two command and control servers it is meant to connect to more »

    Alert!ownCloud fixes critical security vulnerabilities

    OwnCloud logo The ownCloud developers have released versions 5.0.6, 4.0.15, and 4.5.11 to fix a number of serious vulnerabilities in their software including SQL injection, code execution and privilege escalation problems more »

    Thursday, 16 May 2013

    LulzSec trial: sentence handed down for UK hackers

    LulzEnd icon Four hackers from the infamous group LulzSec were sentenced in the UK today. Three of them are facing prison, while the fourth got a suspended sentence more »

    Catching hackers with virtual industrial plants

    SCADA icon What is someone scanning the internet for easily accessible industrial plants actually up to? The SCADA honeypot Conpot can help supply answers to that question more »

    zPanel hacked after support team member insults forum user

    **** The zPanel server is unavailable at the moment, most likely as a result of a hacker attack brought on by a member of the support team who swore at a forum user more »

    RIPE: Attacks on domain name systems are on the increase

    RIPE 66 logo At the meeting of the RIPE IP address registry, discussions revolved around how to get black sheep to implement overdue security measures more »

    Fraunhofer FOKUS institute releases Fuzzino fuzzing library

    FOKUS logo To avoid the need to develop new fuzz testing tools, researchers at Fraunhofer FOKUS institute have created the Fuzzino open source fuzzing library that can be used to add fuzzing features to existing test tools more »

    Wednesday, 15 May 2013

    Exploit for local Linux kernel bug in circulation - Update

    Tux icon A bug that was fixed in the development branch of the kernel back in April was not identified as being security relevant and can therefore still be exploited on many systems more »

    New Yorker opens Strongbox - a Tor-based anonymous drop site

    Strongbox logo The magazine's anonymous drop site is based on DeadDrop, developed by the late Aaron Swartz. Anonymity is in part ensured by only accepting connections via the Tor project's network more »

    Alert!Mozilla's Firefox update fixes three critical holes

    Mozilla icon Critical holes are also closed in Mozilla's Firefox ESR, Thunderbird and Thunderbird ESR, along with fixes for high severity issues; one of the high severity issues is a local privilege escalation through Mozilla's Maintenance Service more »

    Oracle to change Java version numbers

    Java Security icon With an increase in security updates and a need to schedule non-security changes predictably, Oracle has decided to rework how Java updates get a version number more »

    Alert!Urgent security patches for ColdFusion, Adobe Reader, Acrobat and Flash

    Adobe patch day Adobe's May Patch Tuesday brings a flurry of security updates that close various critical security holes. Administrators who manage ColdFusion servers should act immediately; the remaining updates should also be installed as soon as possible more »

    Tuesday, 14 May 2013

    Skype with care – Microsoft is reading everything you write

    Skype snooping logo If you thought Skype messaging was private, think again. The H's associates at heise Security have discovered that Skype/Microsoft analyses all data sent using the service more »

    AP news agency spied on by US government

    Associated Press Associated Press has accused the US government of secretly and illegally obtaining phone records for 20 of the news agency's phone lines more »

    Deutsche Telekom launches online code vulnerability scanner

    Developer Garden logo The Developer Garden Code Analyzer enables developers to find security vulnerabilities in their web applications and mobile apps. It supports many different languages and is available in three pricing tiers more »

    Monday, 13 May 2013

    Name.com domain registrar hacked

    Name.com logo dot Unknown intruders gained access to the registrar's customer database, including customers' credit card details. Name.com is thought to manage around 500,000 domains more »

    Microsoft warns of Facebook-hijacking extensions

    Facebook logo Browsers are being hijacked by extensions delivered with trojan droppers that are using victim's Facebook accounts to like and comment on behalf of criminals with more »

    Saturday, 11 May 2013

    The H Roundup - Debian 7, Blender 2.67 and your next language

    The H Roundup logo In the week ending 11 May – Your next programming language, Debian Wheezy is released, Blender now renders models in cartoon style, hackers gain access to all .edu domains, and Linux is the "benchmark of quality" more »

    Friday, 10 May 2013

    CSRF hole in OpenVPN Access Server

    OpenVPN Technology An attacker could manipulate a CSRF hole in the OpenVPN Access Server to take control of the administration interface. An updated version of the software is now available to close the hole more »

    Lost+Found: failed extortionists, Google hack and OAuth security

    Lost+Found icon On The H's radar over the last seven days: Cain & Abel on Windows 8, Google hacked, failed extortionists, untangling the web, OAuth security issues, and vulnerabilities in NetApp and SAP ERP. more »

    Critical Microsoft and Adobe fixes to arrive on Patch Tuesday

    Adobe and Microsoft patch icon Microsoft announces ten security bulletins for next Tuesday to close critical holes in Internet Explorer. Adobe is to update its Reader, Acrobat and ColdFusion products on the same day more »

    Credit card criminals arrested after multimillion-dollar theft - Update

    Credit card security icon A global-scale fraud ring is thought to have stolen a total of $45 million. Now, the police have busted the ring's New York cell more »

    Thursday, 09 May 2013

    The Onion details SEA/Twitter compromise

    The Onion logo Details of how recent hijackings of high-profile news site Twitter accounts were carried out have been scarce, but The Onion, itself a victim, has now detailed the timeline of phishing and hijacking that took place when it lost control of its tweets more »

    Got news? Let us know!


    • May's Community Calendar






    The H Open

    The H Security

    The H Developer

    The H Internet Toolkit