Attacker Exploits 'Heartbleed' Against Major Corporation

Within 24 hours of the Heartbleed bug’s disclosure last week, an attacker used it to break into a major corporation, security experts said. Using Heartbleed, the name for a flaw in security that is used in a wide range of web servers and Internet-connected devices, the attacker was able to break into an employee’s encrypted virtual private network, or so-called VPN, session.

Record Companies Sue Pandora Over Older Songs

Several major record companies filed a lawsuit in New York State Supreme Court in Manhattan, accusing Pandora of violating the state’s common-law copyright protections by using recordings of older songs without permission. Along with a string of cases filed last year against Sirius XM Radio, the suit highlights an obscure legal issue that has come to the fore with the rise of streaming music online: that recordings made before Feb. 15, 1972, are not subject to federal copyright protection and may be missing out on tens of millions of dollars in royalties, according to industry estimates.

SEC Cited for Failing to Protect Its Data Network

The U.S. Securities and Exchange Commission has failed to protect its data network against possible breaches, to encrypt highly sensitive information, or to use strong enough passwords, the Government Accountability Office said. In addition to the cybersecurity failings, even the physical security in place to protect SEC data and equipment from being accessed or stolen is lax, a 25-page GAO report said, with workstations located in an area open to all agency staff.

Smartphone Companies to Provide Anti-Theft Tools

A trade group for wireless providers said that the nation's biggest mobile device manufacturers and carriers will soon put anti-theft tools on the gadgets to try to deter rampant smartphone theft. CTIA-The Wireless Association announced that under a "Smartphone Anti-Theft Voluntary Commitment," the companies including Apple, Samsung Electronics, Verizon Wireless, AT&T, U.S. Cellular, Sprint Corp. and T-Mobile US Inc. have agreed to provide a free preloaded or downloadable anti-theft tool on smartphones sold in the U.S. after July 2015.

Court Upholds Contempt in Secure E-mail Case

A federal appeals court has upheld a contempt citation against the founder of the defunct secure e-mail company Lavabit, finding that the weighty internet privacy issues he raised on appeal should have been brought up earlier in the legal process. The decision disposes of a closely watched privacy case on a technicality, without ruling one way or the other on the substantial issue: whether an internet company can be compelled to turn over the master encryption keys for its entire system to facilitate court-approved surveillance on a single user.

  • Read the article: Wired

Canadian Police Arrest Man in 'Heartbleed' Theft

Canadian police have arrested a 19-year-old man and charged him in connection with exploiting the "Heartbleed" bug to steal taxpayer data from a government website, the Royal Canadian Mounted Police (RCMP) said. In what appeared to be the first report of an attack using a flaw in software known as OpenSSL, the Canada Revenue Agency (CRA) said this week that about 900 social insurance numbers and possibly other data had been compromised as a result of an attack on its site.

Encryption Keys Vulnerable to Heartbleed Bug

Security professionals demonstrated last weekend that the recently disclosed Heartbleed bug can be exploited to allow criminals and intelligence agencies to make off with one of the most sought-after prizes in hacking: the private keys that websites rely on to decrypt sensitive information, including passwords, banking details and health data. At least six people were able to extract the private key of a website in a test of the bug’s viability organized by CloudFlare Inc., said Nick Sullivan, a security architect with the Internet security company.

Turkey Says Twitter to Close Some Accounts

Twitter will close some accounts in Turkey but will not for now set up an office there as the government wants, a senior Turkish official said late after talks over a dispute which saw the government ban the site for two weeks. Prime Minister Tayyip Erdogan's government blocked Twitter and YouTube in March, drawing international condemnation, after audio recordings, purportedly showing corruption in his inner circle, were leaked on their sites.

Bitcoin Entrepreneur Indicted in Silk Road Case

Prominent bitcoin entrepreneur Charlie Shrem has been indicted by a federal grand jury in New York on charges of funneling cash to the illicit online marketplace Silk Road. Shrem, known as one of the digital currency's most visible promoters, is accused of conspiring with a Florida man, Robert Faiella, to sell more than $1 million in bitcoins to the users of Silk Road despite knowing that it would be spent on illegal uses like drug trafficking.

Apple Antitrust Monitor Reports 'Improved' Relationship

Apple Inc. and its court-appointed monitor appear to have patched up their rocky relationship as the company re-vamps its policies to prevent antitrust violations. In his first report to the federal judge who appointed him, attorney Michael Bromwich said his relationship with Apple as the technology company’s monitor has “significantly improved” in recent months but added that his team still lacks a significant amount of the information needed to do the job.

Turkey's Prime Minister Accuses Twitter of Tax Evasion

Turkey's prime minister said he will "go after" Twitter, accusing the site of tax-evasion, after it was used to spread damaging leaks implicating his inner circle in corruption claims. In a televised speech, Recep Tayyip Erdogan also launched a tirade against the nation's highest court for ruling against a ban on Twitter, charging that it put the rights of businesses above that of Turkey's.

  • Read the article: AFP

Massachusetts Bill Would Ban Tech Noncompetes

Massachusetts Governor Deval Patrick proposed sweeping legislation to make it easier for workers in technology, life sciences, and other industries to move from job to job by banning the noncompete agreements companies use to prevent employees from jumping to rivals. The proposal is certain to inflame a battle within the state’s business community between larger, established corporations that say noncompete agreements prevent former employees from spreading business secrets and venture capitalists who contend they stifle innovation and undermine the state’s reputation as a haven for startups.

Shareholder Sues Microsoft Over EU Antitrust Fine

Microsoft Corp's board faces a lawsuit over the way it handled an error with its Internet Explorer browser that ended up costing the company a record-breaking $731 million fine by European antitrust regulators. The lawsuit, brought by shareholder Kim Barovic in federal court in Seattle, charges that directors and executives, including founder Bill Gates and former Chief Executive Officer Steve Ballmer, failed to manage the company properly and that the board's investigation was insufficient into how the miscue occurred.