Researchers from Georgia Tech have discovered an emerging class of C++ bugs, and Facebook has awarded them US$100,000 for their efforts. The bugs are rooted in a new method for identifying “bad casting” vulnerabilities in C++ programs casted dynamically or statically at runtime. The researchers, who presented their findings at the USENIX Security ’15 conference, … continue reading
Researchers from IBM’s X-Fore Application Security team have discovered a new serialization vulnerability that affect more than 55% of Android phones. According to the researchers, the vulnerability could allow attacks to perform arbitrary code execution and gain access to a user’s device. The vulnerability is nestled within the Android platform, and it affects Android Jelly … continue reading
Devpost, the hackathon platform formerly known as ChallengePost, has released its first Student Hacker Report for the 2014-2015 academic year, ranking the most popular platforms, programming languages, APIs, libraries, frameworks and more at hackathons over the past year. The report shows Android edging out iOS 38.2% to 22.7% for the most popular mobile platform, while … continue reading
Samsung open-source JavaScript Internet of Things engine Samsung has open-sourced JerryScript, a JavaScript engine for the Internet of Things. JerryScript is designed to run on microcontrollers and other Internet of Things devices with constrained RAM and ROM space. The engine supports on-device code compilation and execution, and provides access to peripherals from JavaScript. The project … continue reading
U.S. Senators have introduced a bill designed to improve vehicle security. The Security and Privacy in Your Car (SPY Car) Act, proposed by Senator Edward Markey and Senator Richard Blumenthal, intends to establish federal standards that would secure cars and protect drivers’ privacy. In addition, a rating system, also known as a cyber dashboard, would … continue reading
Microsoft has announced the Windows 10 Application Deployment tool (WinAppDeployCmd) in the latest release of its Windows 10 SDK preview. WinAppDeployCmd is a standalone tool designed to enable users to deploy universal Windows apps from a Windows 10 PC to a Windows 10 mobile device, according to the company. In addition, users can use it … continue reading
Google’s new prototypes of its autonomous vehicles have hit the road in Mountain View, Calif. The latest prototypes are designed to be fully self-driving, working without a steering wheel or pedals. During the testing process, safety drivers will be on board and will have the ability to take control of the car if needed. In … continue reading
FOVE has announced Samsung Ventures has invested in its virtual reality headset to help strengthen and advance its development. The news follows FOVE’s successful Kickstarter project, which raised more than US$450,000. “With this new investment and from our Kickstarter community, we will work diligently in making FOVE development possible on a larger scale,” said Yuka … continue reading
LinkedIn has open-sourced Pinot, its real-time distributed analytics and datastore infrastructure for low-latency data scaling. More than 30 internal software products at LinkedIn are powered by Pinot, including the XLNT platform for A/B testing. The infrastructure also supports Big Data sources such as Apache Kafka and Hadoop. Pinot technical lead Kishore Gopalakrishna explained the logic … continue reading
Atlassian has announced the release of Connect for Bitbucket, a new solution that turns Bitbucket into a development platform. Bitbucket is the company’s source code-management and collaboration solution, and Connect for Bitbucket allows developers to build and embed add-ons right into the Bitbucket UI. Add-ons can be built in any programming language and can include … continue reading