IMF kritiserar Argentina SvD Utrikes(cached at February 1, 2013, 11:32 pm)

Internationella valutafonden (IMF) har riktat skarp kritik mot Argentina.
Details of Chinese Spacecraft's Asteroid Encounter Slashdotby Soulskill on china at January 1, 1970, 1:00 am (cached at February 1, 2013, 11:32 pm)

the_newsbeagle writes "Chinese aerospace engineers have revealed, for the first time, details about their Chang'e-2 spacecraft's encounter with the asteroid Toutatis last month. They have plenty to boast: The asteroid flyby wasn't part of the original flight plan, but engineers adapted the mission and navigated the satellite through deep space (PDF). Exactly how close Chang'e-2 came to Toutatis is still unclear. The article states that the first reports 'placed the flyby range at 3.2 km, which was astonishingly—even recklessly—tight. Passing within a few kilometers of an asteroid only 2 to 3 km in diameter at a speed of 10,730 meters per second could be described as either superb shooting or a near disaster.' If the Chinese spacecraft did pass that near, it could provide a "scientific bonanza" with data about the asteroid's mass and composition."

Read more of this story at Slashdot.



US job report pushes US stocks higher AL JAZEERA ENGLISH (AJE)(cached at February 1, 2013, 11:30 pm)

US employers added 157,000 jobs in January and hiring was stronger over past two years than previously thought.
CVE-2012-5961 (portablesdkforupnp) (Natl. Vulnerability Database) SANS ISC SecNewsFeed(cached at February 1, 2013, 11:30 pm)

Osynlig blixt kan ha slagit ned SvD Inrikes(cached at February 1, 2013, 11:02 pm)

Vad var det egentligen för märkligt som hände år 774?
Rackspace Flips, Won't Support Third-Party OpenStack Distros Slashdotby Soulskill on cloud at January 1, 1970, 1:00 am (cached at February 1, 2013, 11:02 pm)

itwbennett writes "Last year, Rackspace planned to support third-party OpenStack distributions as part of its private cloud offering. That was then. 'Things have evolved quickly as enterprises start evaluating their options in the cloud generally and the OpenStack market specifically,' said Jim Curry, general manager of Rackspace Private Cloud. Customers, it seems, want to run a cloud model internally that 'looks and feels like what Rackspace delivers in the public cloud. To deliver that experience, we needed to develop software that deploys an OpenStack cloud that Rackspace can operate and support.'"

Read more of this story at Slashdot.



Facebook Re-enables Tag Suggestions Face-Recognition Feature In the US Slashdotby Soulskill on facebook at January 1, 1970, 1:00 am (cached at February 1, 2013, 11:02 pm)

An anonymous reader writes "Facebook has brought back its photo Tag Suggestions feature to the U.S. after temporarily suspending it last year to make some technical improvements. Facebook says it has re-enabled it so that its users can use facial recognition 'to help them easily identify a friend in a photo and share that content with them.' Facebook first rolled out the face recognition feature across the U.S. in late 2010. The company eventually pushed photo Tag Suggestions to other countries in June 2011, but in the US there was quite a backlash. Yet Facebook doesn't appear to have made any privacy changes to the feature: it's still on by default."

Read more of this story at Slashdot.



"Path Computation Element Communication Protocol (PCEP) Extensions for remo SANS ISC SecNewsFeed(cached at February 1, 2013, 11:00 pm)

Sick software nasty uses child abuse pics to extort victims (The Register) SANS ISC SecNewsFeed(cached at February 1, 2013, 11:00 pm)

Valve Sued In Germany Over Game Ownership (Slashdot) SANS ISC SecNewsFeed(cached at February 1, 2013, 11:00 pm)

More Headaches for Java (January 30, 31, & February 1, 2013) (SANS Newsbites) SANS ISC SecNewsFeed(cached at February 1, 2013, 11:00 pm)

Cisco: E-Commerce Sites More Likely to Deliver Malware Than Malicious Ones (E-Week S SANS ISC SecNewsFeed(cached at February 1, 2013, 11:00 pm)

Vuln: Oracle MySQL Server CVE-2012-1705 Remote Security Vulnerability (SecurityFocus SANS ISC SecNewsFeed(cached at February 1, 2013, 11:00 pm)

CVE-2012-5960 (portablesdkforupnp) (Natl. Vulnerability Database) SANS ISC SecNewsFeed(cached at February 1, 2013, 11:00 pm)

Oracle quitely releases Java 7u13 early, (Fri, Feb 1st) SANS Internet Storm Center, InfoCON: green(cached at February 1, 2013, 11:00 pm)


First off, a huge thank you to readers Ken and Paul for pointing out that Oracle has released Java 7u13. As the CPU (Critical Patch Update) bulletin points out, the release was originally scheduled for 19 Feb, but was moved up due to the active exploitation of one of the critical vulnerabilities in the wild. Their Risk Matrix lists 50 CVEs, 49 of which can be remotely exploitable without authentication. As Rob discussed in his diary 2 weeks ago, now is a great opportunity to determine if you really need Java installed (if not, remove it) and, if you do, take additional steps to protect the systems that do still require it. I havent seen jusched pull this one down on my personal laptop yet, but if you have Java installed you might want to do this one manually right away. On a side note, weve had reports of folks who installed Java 7u11 and had it silently (and unexpectedly) remove Java 6 from the system thus breaking some legacy applications, so that is something else you might want to be on the lookout for if you do apply this update.

References:

http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html

http://www.oracle.com/technetwork/topics/security/javacpufeb2013verbose-1841196.html

Recent Java diaries:

https://isc.sans.edu/diary/Java+0-day+impact+to+Java+6+%28and+beyond%3F%29/14917

https://isc.sans.edu/diary/Java+7+Update+11+Still+has+a+Flaw/14983

https://isc.sans.edu/diary/When+Disabling+IE6+%28or+Java%2C+or+whatever%29+is+not+an+Option.../14947

---------------

Jim Clausing, GIAC GSE #26

jclausing --at-- isc [dot] sans (dot) edu
(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.