Newsletter IconFacebook IconX IconThreads IconInstagram IconYouTube IconPinterest Icon
Giveaway: AVerMedia Creator Bundle (4K Webcam, Capture Card, Charging Hub, and Mouse Pad)

Hacking, Security & Privacy - Page 12

Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 12

Stay Updated

Follow TweakTown for breaking tech news, reviews, and daily updates.

Add TweakTown as a preferred source on GoogleFind TweakTown on Apple News

As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.

NordVPN has been hacked, knew about the breach 'months ago'

| Oct 21, 2019 4:24 PM CDT

NordVPN has confirmed that it was hacked, after rumors began swirling that the virtual private network provider had an expired internal private key exposed. This means that the ones with that key could impersonate NordVPN, and you know how bad that could get.

NordVPN has been hacked, knew about the breach 'months ago'

While NordVPN says it has a "zero logs policy" by stating that the VPN provider doesn't "track, collect, or share your private data"... I'd dare say this is all in teh air right now. TechCrunch reached out to NordVPN, which spokesperson Laura Tyrell then explained: "One of the data centers in Finland we are renting our servers from was accessed with no authorization".

The hackers got into the NordVPN server by taking advantage of an insecure remote management system that was left open by the data center provider, NordVPN said that it was not aware of this system. NordVPN also didn't name the datacenter provider, for obvious reasons.

Continue reading: NordVPN has been hacked, knew about the breach 'months ago' (full post)

Wi-Fi, not cameras, will stop pesky home invaders and here is how

| Oct 9, 2019 4:12 AM CDT

As technology advances in cameras, motion sensors and every other form. Users are looking for better ways to protect themselves and their homes via security. Linksys could have the new best way to do it.

Wi-Fi, not cameras, will stop pesky home invaders and here is how

Just this pas Tuesday, Linksys announced a brand new service called "Linksys Aware" which allows users to monitor their home for potential intruders. Linksys will be able to this through the Velop mesh routers which can detect the motion of invaders in users' homes through Wi-Fi. Linksys Velop Tri-Band AC2200 router has the ability to be able to detect motion with its "Intelligent MeshTM" network, which could eliminate that use for camera setups in homes.

So how does it work? The service will send push notifications to the users phone via the Linksys Smart Wi-Fi app for both Android and iOS holders. I know what you are thinking, "I don't want to get spammed with notifications of the dog or cat moving around the house", Linksys has already thought of this issue and has equipped the service with a sensitivity setting that won't detect these kind of small movements. Linksys Aware comes in at a price of $24.99 per year, and at the moment the home security option is only available on the Velop routers. Linksys does plan on moving the service over to its other router variants, but no date has been announced for that yet.

Continue reading: Wi-Fi, not cameras, will stop pesky home invaders and here is how (full post)

Zynga mobile hack exposes 200 million personal user account details

| Oct 1, 2019 8:09 AM CDT

Zynga, the creators of the immensely popular Farmville, Draw Something and Zynga Poker have admitted to a data breach that has exposed 200 million accounts personal information.

A statement has recently been issued out by Zynga addressing the cyber attacks and it says that cyber attacks are "one of the unfortunate realities of doing business today." The statement also says that the company recently became aware that a "certain player account information" was possibly "illegally" acquired by "outside hackers".

Zynga has also said that they have launched an immediate investigate to how this hack occured and to assist them in their investigation they have brought in an outside forensic team. It is believed that no financial information was stolen throughout this hack and just "account information" was exposed. If you play any of the apps that fall under Zynga's massive umbrella I would advise you to change your passwords as soon as possible.

Continue reading: Zynga mobile hack exposes 200 million personal user account details (full post)

50 state attorneys general launch antitrust probe into Google

| Sep 10, 2019 12:45 AM CDT

Google is in some hot water right now, with 50 state attorneys general (had to Google that, it is indeed attorneys general and not attorney generals) launching a new antitrust probe into Google.

50 state attorneys general launch antitrust probe into Google

The leader of the 50 strong AGs is Texas Attorney General Ken Paxton, who has said the investigation will kick off looking into Google's advertising business, before it looks deeper into how the company operates itself. On the steps of the Supreme Court, Paxton said: "The facts will lead where the fact lead".

What happens from here? Well, the antitrust probe isn't a lawsuit just yet -- but if the company has broken US antitrust rules then Google could be broken up into smaller pieces. For example, YouTube has long been accused of censoring conservative voices, personalities, channels, and normal everyday people -- yet they can't be held accountable, yet.

Continue reading: 50 state attorneys general launch antitrust probe into Google (full post)

HackerOne has already rewarded bounty bug finders millions of dollars

| Aug 30, 2019 6:17 AM CDT

HackerOne has announced that they have now rewarded six individuals with over one million dollars each for their bounty bug finding efforts.

HackerOne has already rewarded bounty bug finders millions of dollars

The announcement has come via the official HackerOne Twitter account where they say that the ranks of 7-figure-earning hackers has now reached six people. First off, we have Santiago Lopez who is only 19-years old and was the first to cross the $1 million dollar mark.

Mark Litchfield from the UK was next, followed by Frans Rosen from Sweden, then Nathaniel Wakelam from Australia, Ron Chan from Hong Kong and finally Tommy DeVoss from the US. Each of these individuals have reached the 1 million dollar mark or above.

Continue reading: HackerOne has already rewarded bounty bug finders millions of dollars (full post)

Portland Public Schools almost got BEC scammed a HUGE $2.9 million

| Aug 23, 2019 7:06 AM CDT

Scamming is becoming more and more prevalent in this day and age, and the new form of scamming that is hitting the internet in waves is 'business email compromise' or BEC for short.

Portland Public Schools almost got BEC scammed a HUGE $2.9 million

What is a BEC scam? Well, its actually quite simple when you think about it. A BEC scam is when a criminal impersonates a third-party convinces someone at a business to wire them business funds. Usually the criminal will locate someone within the business that has access to the companies funds, once that person is located the criminal might compromise the email account holder or the companies supplier and request funds to be paid to them. Some cases of BEC scams have been based entirely on social engineering through spoofed email accounts.

In the case of Portland Public Schools, the scammer got two employee's at the schools to send him money as the scammer was posing as one of the institution's construction contractors. The employees unknowingly sent the scammer a staggering $2.9 million dollars, luckily Portland Schools moved extremely quickly and contacted the banks to freeze the transaction. The transaction was successfully frozen, and Portland Public School contacted the FBI for further investigation into the matter.

Continue reading: Portland Public Schools almost got BEC scammed a HUGE $2.9 million (full post)

Facebook is paying contractors to transcribe your audio chats

| Aug 13, 2019 10:01 PM CDT

Facebook has been paying contractors to listen to users audio clips and transcribe them, according to anonymous sources who spoke with The Associated Press.

Facebook is paying contractors to transcribe your audio chats

The sources state that the social networking giant has hired outside contractors to go over the audio clips, with every single word (good and bad, secret and explicit conversations) being transcribed. Worse yet, the contractors do not know why Facebook needs the voice clips transcribed.

But don't worry, because Facebook confirmed it had been transcribing users' audio calls but it wouldn't do it anymore. On Tuesday, Facebook said: "Much like Apple and Google, we paused human review of audio more than a week ago". Pegging them into the first week of August 2019 where they stopped transcribing voice chats.

Continue reading: Facebook is paying contractors to transcribe your audio chats (full post)

Hackers can use phone/device sound to damage human hearing

| Aug 13, 2019 5:09 AM CDT

In this day and age with so many devices being adopted by users across the world, many users are worried about their safety with this ever-evolving technology, and they have every right to do so.

Hackers can use phone/device sound to damage human hearing

According to researcher lead Matt Wixey, for the PwC UK Cyber Security practice, a doctoral student discovered an exploit in speaker and volume controls through a range of different devices. This exploit allowed for researchers to hack into the devices and access the volume controls to produce sounds at volume levels that would be detrimental to human hearing. The researchers also found that these sounds that could be produced by the device could not only damage the victims hearing, but also the device itself.

Wixey has now taken his findings to a range of different device manufactures and some of these manufactures have updated their firmware so the attacks weren't possible. Unfortunately, Wixey mentions that despite the firmware changes, sound attacks such as these are still open on a plethora of different devices (which he didn't name for obvious reasesons). He also mentions that instead of hackers hacking into devices for data foraging, they could hack into devices with the intent of possible physical harm.

Continue reading: Hackers can use phone/device sound to damage human hearing (full post)

Your printer isn't safe from Russian Spy hackers

| Aug 7, 2019 3:13 AM CDT

By now you would know that if it is on the internet then you should assume that it can basically be hacked. A new report has come out of Microsoft and even your printers aren't safe.

Your printer isn't safe from Russian Spy hackers

Microsoft announced on Monday that Russian hackers who go by the names; Strontium, Fancy Bear, and APT28 have been detected by Microsoft. These Russian hackers have also been linked to military intelligence agency GRU, and are known for their infiltration into the Democratic National Committee in 2016 and other well known hacks.

Since most PC's are using Windows at a corporate level, Microsoft has some of the best hacking detection software available and in April of 2019 Microsoft's Threat Intelligence Center detected an infiltration by Fancy Bear. According to Microsoft, Fancy Bear has used 'internet of things' devices such as phones, a connected office printer and a video decoder to access corporate networks.

Continue reading: Your printer isn't safe from Russian Spy hackers (full post)

100,000 college students personal data exposed in big breach

| Aug 2, 2019 1:00 AM CDT

A recent report has come out of the Wall Street Journal (WSJ) revealing that about 10,000 College students have had their personal information disclosed in a data breach.

100,000 college students personal data exposed in big breach

The WSJ has said that the FBI notified education software company Pearson that there servers were recently hijacked, revealing college students' dates of birth and email addresses. The report also says that one Nevada school district told the WSJ that around 114,000 students that attend schools in that area between 2001 and 2016 have been effected.

According to the notes in WSJ, the leaked information doesn't contain sensitive information like "social Security numbers, credit-card data or other financial information." A spokesperson from Pearson told Mashable via email that the "Pearson Clinical Assessments notified affected customers of unauthorized access to approximately 13,000 school and university AIMSweb 1.0 accounts. The exposed data was isolated to first name, last name, and in some instances may include date of birth and/or email address. Protecting our customers' information is of critical importance to us. We have strict data protections in place and have reviewed this incident, found and fixed the vulnerability."

Continue reading: 100,000 college students personal data exposed in big breach (full post)

100 million American's credit card data/info hacked & leaked

| Jul 31, 2019 3:00 AM CDT

A recent announcement has come out from Capital One, who has admitted that there servers experienced a breach recently that has disclosed roughly 100 million American's personal information.

100 million American's credit card data/info hacked & leaked

According to the announcement by Capital One, credit card information that they contained between the years of 2005 and 2019 has been disclosed. This potential of this information leak includes: "names, addresses, ZIP codes/postal codes, phone numbers, email addresses, dates of birth, and self-reported income, credit scores, credit limits, balances, payment history, contact information."

On top of that information leaking, the report also says that Capital One is also estimating that roughly 140,000 Social Security numbers were potentially compromised in the U.S, as well as 80,000 linked bank account numbers. The U.S Department of Justice has said that Seattle engineer, Paige A. Thompson has been arrested and indicted on accounts of having a connection to the breach.

Continue reading: 100 million American's credit card data/info hacked & leaked (full post)

Hackers disclose Russian deep-web 'Tor' data storing project

| Jul 22, 2019 3:00 AM CDT

A hacking group that goes by the nickname '0v1ru$' has disclosed some secret Russian spy projects, some of these projects were designed to store, monitor and decipher Tor users data.

Hackers disclose Russian deep-web 'Tor' data storing project

The company that got hacked by 0v1ru$ is SyTech, a contracting company to the Federal Security Service of the Russian Federation. SyTech had its servers hijacked and 0v1ru$ managed to extract a whopping 7.5TB worth of data. Within the extracted data was several different security projects, the most notable one that was found was a project called 'Nautilus-S'.

The goal of the Nautilus-S project was to deanonymize Tor traffic while also creating a database of Tor users and their data. The disclosure revealed that this project begun way back in 2012, and was initialized in 2014 when Swedish researchers discovered Russian Tor nodes attempting to sift Tor users data. Since the hack has taken place, SyTech has taken down their website and has refused to contact the press regarding these disclosed projects.

Continue reading: Hackers disclose Russian deep-web 'Tor' data storing project (full post)

Man hacks celebrity Apple IDs, pays for holidays & furniture

| Apr 1, 2019 4:00 AM CDT

A new report has been posted to the official United States Department of Justice website that has detailed a man who has pleaded guilty to the hacking of celebrities' Apple ID accounts.

Man hacks celebrity Apple IDs, pays for holidays & furniture

According to the Department of Justice report, Kwamaine Jerell Ford has said he is guilty of hacking to the Apple accounts of certain professional athletes such as NBA players, NFL players musicians such as rappers. The report says that Jerell managed to gain access to these peoples accounts through tricking his victims into handing over their personal information by posing as a Apple customer support worker.

Once the account was compromised, Ford attempted to change the sign-in details of the account and scrape the credit card details that are attached to it. Ford then proceeded to pay "thousands of dollars" of travel and furniture for himself and was then indicted on six counts of computer fraud and aggravated identity theft. Ford has only pleaded guilty to one of these counts and his sentencing is scheduled to take place on June 24th. The high-profile people that were victims of Ford was not disclosed within the report.

Continue reading: Man hacks celebrity Apple IDs, pays for holidays & furniture (full post)

NCIX servers sold on Craigslist with 15 years of user data

| Sep 24, 2018 12:25 AM CDT

NCIX is in some big effing trouble with a story breaking over the weekend that someone had access to their old servers that went for auction and were purchased, after the Canadian retailer went bankrupt in 2017.

NCIX servers sold on Craigslist with 15 years of user data

The servers that were previously owned by NCIX somehow ended up on Craigslist, with Travis Doering from Privacy Fly access the servers and pretending to be someone called "Jeff" for privacy (fly) reasons. Doering was after the data on the NCIX server, making is clear he was after the contents of the HDD alone and not the juicy server hardware. Doering met with the seller multiple times, confirming that they were ex-NCIX servers and that they indeed had NXIC user and business data on it.

The used servers were sold because NCIX reportedly didn't pay their warehouse storage bills in late-2017 with over $115,000 owed, where the servers were given to the warehouse owner to sell to recoup costs. Yeah well, the NCIX servers weren't wiped and millions of customers private detailed were exposed, as well as business customers who used to buy many millions worth of goods.

Continue reading: NCIX servers sold on Craigslist with 15 years of user data (full post)

Bitdefender BOX: Hardware Protection from IoT Attacks

| Jun 25, 2018 6:07 PM CDT

This is a hard one to explain because people think that most security is done either on your PC (with software) or on your router (hardware protection). But, this is where Bitdefender steps in with their hardware offering in the Bitdefender BOX 2, the successor to the original BOX device.

Bitdefender BOX: Hardware Protection from IoT Attacks

The new BOX is the same hardware security appliance that the original one was, which works with your modem or router, but it can also function as the router if you don't already have one.

BOX can protect your various devices that are running Windows, Mac OS or Android... but it can also protect iOS devices, Kindle-based devices, smart TVs, consoles, smart thermostats, and any other internet-connected device. It's not just a simple solution, it's an all-round security solution.

Continue reading: Bitdefender BOX: Hardware Protection from IoT Attacks (full post)

Amazon plan 1984-style facial recognition tech for US cities

| May 24, 2018 11:31 PM CDT

Amazon have their evil tentacles in as many places as you can imagine, including a huge $10 billion deal with The Pentagon, so the news of a 1984-style facial recognition technology system shouldn't surprise you, at all.

Amazon plan 1984-style facial recognition tech for US cities

The new surveillance system is reportedly called "Rekognition", with Amazon having a huge library of "tens of millions of faces" that will see it track up to 100 individuals in a given image, and then analyze their identity. Don't worry about your privacy as this is all for security and your personal safety.

Don't think that Amazon's super-secret Rekognition system is just a pipe dream, it is already deployed in some US cities. Washington County Sheriff's Office is already using Rekognition to reduce the time suspect identification takes, down from multiple days to a few minutes.

Continue reading: Amazon plan 1984-style facial recognition tech for US cities (full post)

Intel CPUs experiencing Spectre NG wave of security problems

| May 6, 2018 10:38 PM CDT

Intel is set to go through another battle with security holes in its CPUs with a revised version of Spectre found, with 8 new Spectre-like issues discovered.

Intel CPUs experiencing Spectre NG wave of security problems

Spectre Next Generation, or Spectre NG is what it's called, with Intel recently being notified of the security holes. 4 of them were rated high, while the remaining 4 were medium severity. The technical details behind Spectre NG haven't been announced, but we know that they will be similar or worse than the original Spectre, which was bad enough.

Intel is reportedly working on getting Spectre Next Generation problems fixed, with Microsoft and others working on OS level adjustments. There will reportedly be two new waves of updates, with the first coming soon and another reportedly in August, but these dates could vary depending on how bad Spectre NG really is.

Continue reading: Intel CPUs experiencing Spectre NG wave of security problems (full post)

Twitter urges all 330 million users to change passwords NOW

| May 4, 2018 7:36 PM CDT

Twitter has been hit in a big way today, with the social networking giant urging all of its 330 million users to change their passwords immediately after they were exposed in a bug in plain text.

Twitter urges all 330 million users to change passwords NOW

The company wasn't hacked at all, with Twitter recommending people change their passwords out of an "abundance of caution". Twitter wants you to change your password on the site itself, and anywhere else that you've used that password, including third-party Twitter apps.

How did it happen? Well, Twitter says that the bug occurred through an issue in the hashing process, where it masks passwords by replacing them with a random string of characters that then get sorted on Twitter's system. An error in this process happened, so the passwords were then saved in plain text to an internal log. Twitter says they found the bug on their own, and removed the passwords and is working on it so it doesn't happen again.

Continue reading: Twitter urges all 330 million users to change passwords NOW (full post)

Under Armour data breach effects 150 million accounts

| Mar 30, 2018 8:40 PM CDT

It looks like hackers have breached the armor of Under Armour, the athletic apparel brand, with the data breach exposing details of over 150 million MyFitnessPal users.

Under Armour data breach effects 150 million accounts

The data breach exposes MyFitnessPal users' usernames, email addresses, and hashed passwords. Government-issued identifiers such as social security numbers and drivers licenses weren't exposed, as the app doesn't collect that sort of data, including credit cards.

The intrusion was detected in late-February, but Under Armour began working with authorities on March 25. Under Armour purchased MyFitnessPal in 2015 for $475 million.

Continue reading: Under Armour data breach effects 150 million accounts (full post)

Japan's 2020 Olympics may use facial recognition as security

| Dec 31, 2017 1:56 AM CST

As we get closer to the next Olympics, Japan is searching for new ways to beef up the security of their facilities but at the same time make sure that the increase of security doesn't hinder the process of getting inside of the Olympic venues.

Japan's 2020 Olympics may use facial recognition as security

The Japan Times has reported that sources close to the Olympic committee have said that there is speculation of facial recognition type technology to be used as security for the expected 300,000 to 400,000 attendees. If chosen as the select approach it has been said that it will not be used on spectators but instead could reduce the wait time of attendees such as officials and coaches.

There has been no official confirmation of if this technology will be implemented, so all concerns revolving around privacy have not been addressed yet. As we move closer to the beginning of the 2020 Olympics it is assumed that we will be updated with a confirmation announcement for if facial recognition is go or not.

Continue reading: Japan's 2020 Olympics may use facial recognition as security (full post)

Join Our Newsletter

Join the TweakTown Newsletter for daily tech updates delivered to your inbox.

See previous giveaways.

Newsletter Subscription