Drupal abstracts aperture exposes abstracts of 1 actor users


A Drupal abstracts aperture was appear by the official Drupal Association, that Passwords for about one actor accounts on the Drupal.org website are getting displace afterwards hackers acquired crooked admission to acute user data.
The aegis of the accessible antecedent agreeable administration arrangement has been compromised via third-party software installed on the Drupal.org server infrastructure, and was not the aftereffect of a vulnerability aural Drupal itself. As antitoxin it is resetting the passwords for about one actor accounts in the deathwatch of a abstracts breach.
Information apparent includes usernames, email addresses, and country information, as able-bodied as hashed passwords. The Drupal.org hasn't appear the name of the third-party appliance exploited during the attack.
Evidence of the Drupal abstracts aperture was begin during a accepted aegis audit:
“Upon advertent the files during a aegis audit, we shut down the association.drupal.org website to abate any accessible advancing aegis issues accompanying to the files,” “The Drupal aegis aggregation again began argumentative evaluations and apparent that user annual advice had been accessed via this vulnerability.”
“The Drupal.org Aegis Aggregation and Basement Aggregation accept apparent crooked admission to annual advice on Drupal.org and groups.drupal.org.
This admission was able via third-party software installed on the Drupal.org server infrastructure, and was not the aftereffect of a vulnerability aural Drupal itself. This apprehension applies accurately to user annual abstracts stored on Drupal.org and groups.drupal.org, and not to sites active Drupal generally.”
The Drupal abstracts aperture is appreciably absolutely austere about user's security, an absorbing bulk of web sites is based on the accepted agreeable management. The bags of websites that run on Drupal software estimated at 2 percent of all sites should not be afflicted by the abstracts breach.
The Drupal.org Aegis Aggregation accepted the “unauthorized access” to their system, highlighting that there’s no affirmation that any advice was in fact stolen. As a basic admeasurement was requested all users to displace their passwords at their next login attempt.
Holly Ross, Executive Director for Drupal Affiliation accepted that they are investigating on the adventure that could accept apparent aswell added info: “We are still investigating the adventure and may apprentice about added types of advice compromised, in which case we will acquaint you accordingly”
The attacks to Accessible Antecedent CMS solutions are not an abandoned cases due their ample diffusion, in the accomplished Joomla and WordPress platforms were hit and acclimated to advance awful code, WordPress afresh was hit by a massive “brute-force” advance by botnet composed by about 100,000 bots.
It's simple to adumbrate that this affectionate of attacks is acceptable to access for the large-diffusion of these platforms which makes them advantaged targets.

Firefox 21 Launched For Windows And Mac





There’s no official Firefox 21 changelog as of yet, but the beta absolution addendum should serve as a appropriate guideline (remember that appearance are sometimes added or removed afore the abiding adaptation is released):

  • NEW: Enhanced three-state UI for Do Not Track (DNT).
  • NEW: Firefox will suggest how to improve your application startup time if needed.
  • NEW: Preliminary implementation of Firefox Health Report (see FAQ).
  • CHANGED: Ability to Restore removed thumbnails on New tab Page.
  • CHANGED: Add-ons History API removals in Places.
  • CHANGED: CSS -moz-user-select:none selection changed to improve compatibility with -webkit-user-select:none (bugs 816298).
  • CHANGED: Graphics related performance improvements (bugs 809821).
  • CHANGED: Removed E4X support from SpiderMonkey.
  • DEVELOPER: Implemented Remote Profiling.
  • DEVELOPER: Integrated, Add-on SDK loader and API libraries into Firefox.
  • HTML5: Added support for <main> element.
  • HTML5: Implemented scoped stylesheets.
  • FIXED: Some function keys may not work when pressed (833719).
  • FIXED: Browsing and Download history clearing needs unification to avoid confusion on clearing download history
    (847627).
Firefox 21 for Android hasn’t been pushed out yet, but keep checking for app updates over on Google Play. Our coverage of the beta is here, and again, the beta changelog is as follows:
  • NEW: Shipping Open Sans and Charis fonts for Web Content.
  • NEW: Ability to save media files on long tap.
  • CHANGED: Polished UI based on Holo theme.
  • CHANGED: CSS -moz-user-select:none selection changed to improve compatibility with -webkit-user-select:none (bugs 816298).
  • CHANGED: Graphics related performance improvements (bug 809821).
  • CHANGED: Removed E4X support from SpiderMonkey.
  • DEVELOPER: Implemented Remote Profiling.
  • DEVELOPER: Integrated, Add-on SDK loader and API libraries into Firefox.
  • DEVELOPER: DOM/content implementation for <input type=’time’> Associated bugs.
  • HTML5: Added support for <main> element.
  • HTML5: Implemented scoped stylesheets.
  • FIXED: Download Manager page is not updated after clearing private data
    (777639).
  • FIXED: In content UI cut off on small screens
    (840593).
We will update you with more information (including the official changelog) when Firefox 21 officially launches. In the meantime, if you’re a Web developer, you may want to check out the Firefox 21 for developers page.

Box to Acquire Web Document Company Crocodoc


carton, the fast-growing IPO-bound enterprise cloud file-sharing and collaboration service has acquiesced to acquire Crocodoc, a Web-based article sharing and embedding service.

CEO Aaron Levie just broadcast the deal in a corporate blog mail. Crocodoc is a seven-person team hailing from the Massachusetts Institute of expertise. Its technology has driven the article distributing and embedding capabilities of Yammer, LinkedIn and SAP.

The business had increased a little amount of capital from Y Combinator and Dave McClure, amidst other ones. Box isn’t revealing the economic periods of the deal, though Levie just notified me in a phone conversation that “everyone concerned is happy with the deal.”

Crocodoc, Levie said, has gone deeper into the experience of rendering documents on the world wide web and on mobile devices utilising HTML5 than other businesses that are engaged in presenting and distributing articles, like, state, Scribd and DocStoc.

If you think of Scribd as sort of a YouTube for documents, then Crocodoc, Levie says, is comparable to Brightcove. Where YouTube presents video in a consumer amicable way, Brightcove forces video experiences for other businesses. “They’re going out and powering the experience of giving documents. We do this now when it comes to collaboration and content, but we don’t do it yet for documents.”

Crocodoc CEO Ryan Damico will become Box’s controller of platform, and the rest of the Crocodoc group will be connecting Box. finally the Crocodoc emblem will fade away inside Box, Levie said.

The deal is Box’s second acquisition. In 2009 it came by Incredo, a business focused on article and media examining. Levie said that as carton continues to expand, it will rarely make opportunistic acquisitions of little businesses.

It can probably pay for to do more agreements. carton has raised a combined total of $312 million. Its most latest around was $150 million, led by personal equity firm General Atlantic. It also has strategic investments from Salesforce.com and SAP. Levie has said publicly that carton is eyeing an IPO one time in 2014.

Samsung Galaxy S4 Costs $237 to Build, Teardown Analysis Shows

A gaze interior Samung’s new high-profile smartphone, the Galaxy S4, shows that the South Korean electronics monster is utilising numerous components produced by its diverse internally belongs to subsidiaries.


 
A teardown analysis conducted by the market research firm IHS, due to be released tomorrow, has pegged Samsung’s cost of components and manufacturing to produce the U.S. type of the 32 gigabyte model of the S4 at somewhat overhead $237 per unit. Without a agreement grant, the entry-level 16GB version of the phone charges $639 when sold by AT&T Wireless.

The cost is somewhat higher than that of Apple’s iPhone 5, the groundwork model of which charges $205 to construct for a 16GB version, according to an IHS investigation conducted last fall. It’s also well overhead the cost of Nokia’s Lumia 900, which costs $209 to build, IHS discovered at the time.

The S4 cost is not far below the cost of Samsung’s bigger Galaxy Note tablet, the cost of which IHS approximated last year to be $270.



  Most phone manufacturers source their constituents from many distinct suppliers. But Samsung, a large, diversified manufacturer of many different types of electronic constituents, has used its important capabilities to provide itself with numerous of the key components inside most versions of the S4 phone traded around the world.

“Samsung’s power is this proficiency to in-source to itself,” IHS analyst Vincent Leung said in an interview. “They just hold adding to the register of constituents that they can provide to themselves.”

One key constituent that Samsung did not supply to itself for versions of the teletelephone being sold in the U.S. was the major applications processor. U.S. versions of the phone comprise a Snapdragon processor from Qualcomm, which assists $20 to the general cost.

Versions of the telephone sold in Korea and other markets round the world comprise a Samsung-made portion called the Exynos 5 Octa that charges $28. Samsung is known to be constructing at smallest four variations of the phone for distinct market geographies round the world, encompassing at least two being traded in the U.S., one going to AT&T and T-Mobile, and another going to Verizon Wireless and Sprint, said Andrew Rassweiler, another IHS analyst.

“Samsung is illustrating its ability to match the flavours of carriers in different regions of the world,” Rassweiler said. “It comes down to what the market is willing to spend on the features offered.”



  The fact that Samsung used the Qualcomm-made portion is a testament to the U.S. chipmaker’s prowess. “Even with all the vertical integration it’s doing, it’s not like Samsung has given up on Qualcomm,” Rassweiler said.

One interesting difference between the U.S. and Korean versions produced from the distinction in the alternative of processor. U.S. versions of the telephone comprise an image-processing portion made by Japan’s Fujitsu that added $1.50 to the total cost. Leung states that in the Korean versions, some of the image processing is presented off to Samsung’s Exynos portion.

Samsung also supplied the flash recollection utilised to shop facts and figures on the apparatus. IHS approximates that 16GB of recollection supplemented $28 to the cost of the apparatus.

The Korean giant furthermore provided itself with a brandish and touchscreen components, which supplemented $75 to the cost of components. The blended brandish bundle also includes Gorilla Glass, a powerful glass material made by U.S.-based Corning.

Samsung is also thought to have provided itself with several unlabeled components, encompassing the camera module and some wireless baseband chips.

A couple of non-Samsung suppliers encompass Broadcom, which provided Bluetooth and Wi-Fi chips; Maxim, which provided a power-management portion; and Triquint Semiconductor, which provided some wireless chips.