Solidot | 奇客

Attacker stole 100,000 npm user account login information

GitHub disclosed that hackers stole nearly 100,000 npm user account logins in a mid-April attack that leveraged OAuth application tokens issued to Heroku and Travis-CI. The attackers accessed a 2015 archive of user information that contained nearly 100,000 npm usernames, password hashes, and email addresses. Although hashed passwords are generated with weak hashing algorithms such […]

Attacker stole 100,000 npm user account login information Read More »

Russia investigates tech companies like Google over data storage

Russia’s communications regulator Roskomnadzor on Friday announced an administrative lawsuit against foreign tech companies such as Ggogle, alleging they violated personal data retention laws. Russia’s data retention laws require that the personal data of users in the country be stored on domestic servers. Roskomnadzor, which fined Google 3 million rubles last year on the same

Russia investigates tech companies like Google over data storage Read More »

Scientists finally know why octopuses abuse themselves after mating

“She” would even eat her own arm. Many species die after reproduction. But in the case of mother octopuses, the situation is particularly worrisome: in most octopus species, “she” stops eating when the eggs are close to hatching. “She” then leaves her protective companion during the incubation period and becomes obsessed with her own destruction.

Scientists finally know why octopuses abuse themselves after mating Read More »

100-year-old new battery

Tesla’s Advanced Battery Research Group in Canada, in collaboration with Dalhousie University, has published a paper exploring a new 100-year-old nickel-based battery that outperforms lithium iron phosphate (LFP) in charging and energy density. )Battery. The paper introduces a nickel-based battery chemistry designed to compete with LFP batteries in terms of lifespan, while retaining the favored

100-year-old new battery Read More »

Hackers Fake Windows Updates to Attack Russian Government Targets

Hackers are targeting Russian government agencies with phishing emails posing as Windows Updates to trick victims into installing a Remote Access Tool (RAT). The attack, from a previously unknown APT group, ran from February to April 2022, targeting installations of RATs for subsequent espionage. The APT group’s first wave of attacks began in February, with

Hackers Fake Windows Updates to Attack Russian Government Targets Read More »

F-Droid upgrade build infrastructure

F-Droid, the free and open source software Android app store , has upgraded its build and distribution infrastructure . F-Droid’s infrastructure is all based on Debian, but previously all application builds were done on the older version Debian 9 “stretch” released in 2017, F-Droid is now being upgraded to the latest Debian 11 “bullseye”. Upgrading

F-Droid upgrade build infrastructure Read More »

Mozilla fixes Firefox and Thunderbird 0day exploited on Pwn2Own

Mozilla has released an emergency update that fixes a Firefox and Thunderbird 0day exploited by security researchers at the Pwn2Own 2022 hacking challenge. Firefox 100.0.2, Firefox ESR 91.9.1, Firefox for Android 100.3, and Thunderbird 91.9.1 fix two high-severity vulnerabilities. Security researcher Manfred Paul won a $100,000 bounty for demonstrating the exploit on Pwn2Own. The first

Mozilla fixes Firefox and Thunderbird 0day exploited on Pwn2Own Read More »