Misstänkt mördare till rättspsyk SvD Inrikes(cached at December 4, 2013, 11:32 pm)

Den 39-årige man som misstänks för mordet på en 25-årig student på Swartlings ridskola för 17 år sedan har flyttats till rättspsykiatrisk avdelning.
Vuln: OWASP ESAPI CVE-2013-5960 Authentication Bypass Vulnerability (SecurityFocus V SANS ISC SecNewsFeed(cached at December 4, 2013, 11:30 pm)

Microsoft Will Encrypt Traffic Between Data Centers (November 27, 2013) (SANS Newsb SANS ISC SecNewsFeed(cached at December 4, 2013, 11:30 pm)

The Cloud ERP Market Heats Up - FinancialForce Makes Two Strategic Acquisitions (For SANS ISC SecNewsFeed(cached at December 4, 2013, 11:30 pm)

Moar Pawnies (Reddit) SANS ISC SecNewsFeed(cached at December 4, 2013, 11:30 pm)

Famo.us To Open Source Rendering Engine Replacement JavaScript Framework Slashdotby Soulskill on opensource at January 1, 1970, 1:00 am (cached at December 4, 2013, 11:02 pm)

snydeq writes "Famo.us has announced it will be open sourcing its framework for achieving native app performance within the browser, InfoWorld reports. 'Why so much fuss over another JavaScript framework? Mainly because it is unlike any other framework out there: Famo.us replaces the browser's rendering engine with its own, which is written entirely in JavaScript, and fuels it with the GPU acceleration provided by CSS's 3D transformation functions. Most any device these days that can run a modern browser — even a modest smartphone — has some kind of GPU supporting it, so why not leverage that? Armed with Famo.us, developers can maintain a single code base that performs well across many platforms.' Demo code is available on Codepen. Famo.us is also partnering with Firebase, a database as a service for mobile and Web apps."

Read more of this story at Slashdot.








Ask Slashdot: Application Security Non-existent, Boss Doesn't Care. What To Do? Slashdotby Soulskill on security at January 1, 1970, 1:00 am (cached at December 4, 2013, 11:02 pm)

An anonymous reader writes "I am a senior engineer and software architect at a fortune 500 company and manage a brand (website + mobile apps) that is a household name for anyone with kids. This year we migrated to a new technology platform including server hosting and application framework. I was brought in towards the end of the migration and overall it's been a smooth transition from the users' perspective. However it's a security nightmare for sysadmins (which is all outsourced) and a ripe target for any hacker with minimal skills. We do weekly and oftentimes daily releases that contain and build upon the same security vulnerabilities. Frequently I do not have control over the code that is deployed; it's simply given to my team by the marketing department. I inform my direct manager and colleagues about security issues before they are deployed and the response is always, 'we need to meet deadlines, we can fix security issues at a later point.' I'm at a loss at what I should do. Should I go over my manager's head and inform her boss? Approach legal and tell them about our many violations of COPPA? Should I refuse to deploy code until these issues are fixed? Should I look for a new job? What would you do in my situation?"

Read more of this story at Slashdot.








Gov't Puts Witness On No Fly List, Then Denies Having Done So Slashdotby Soulskill on government at January 1, 1970, 1:00 am (cached at December 4, 2013, 11:02 pm)

cathyreisenwitz sends word of a San Francisco trial in which the U.S. government appears to be manipulating the no-fly list to its advantage. The court case involves a Stanford Ph.D. student who was barred from returning to the U.S. after visiting her native Malaysia. She's one of roughly 700,000 people on the no-fly list. Here's the sketchy part: the woman's eldest daughter, who was born in the U.S. and is a U.S. citizen, was called as a witness for the trial. Unfortunately, she mysteriously found herself on the no-fly list as well, and wasn't able to board a plane to come to the trial. Lawyers for the Department of Justice told the court that she simply missed her plane, but she was able to provide documents from the airline explaining that the Department of Homeland Security was not allowing her to fly.

Read more of this story at Slashdot.








Flying hacker contraption hunts other drones, turns them into zombies. (Reddit) SANS ISC SecNewsFeed(cached at December 4, 2013, 11:00 pm)

Utklädda prinsessor under klubban SvD Utrikes(cached at December 4, 2013, 10:33 pm)

Bilder på en tonårig Elizabeth II och hennes syster där de har klätt ut sig för att spela upp pantomimer av Askungen och Aladdin går snart under klubban i Storbritannien.
”Behövs en tydlig spärr mot byråkrati” SvD Inrikes(cached at December 4, 2013, 10:33 pm)

Göran Hägglund vill ge läkarna mer tid med patienterna.
Två anhållna för grov benskada SvD Inrikes(cached at December 4, 2013, 10:33 pm)

Två män anhölls för synnerligen grov misshandel i kväll i Gävle.
Several feared dead in Iraq gunfight AL JAZEERA ENGLISH (AJE)(cached at December 4, 2013, 10:30 pm)

Shooting can be heard at a shopping centre in Kirkuk.
Vuln: Microsoft Windows Kernel 'NDProxy.sys' Local Privilege Escalation Vulnerabilit SANS ISC SecNewsFeed(cached at December 4, 2013, 10:30 pm)

2 arrested, bitcoins seized in German fraud probe (Yahoo Security) SANS ISC SecNewsFeed(cached at December 4, 2013, 10:30 pm)