Newsletter IconFacebook IconX IconThreads IconInstagram IconYouTube IconPinterest Icon
Giveaway: AVerMedia Creator Bundle (4K Webcam, Capture Card, Charging Hub, and Mouse Pad)

Hacking, Security & Privacy - Page 13

Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 13

Stay Updated

Follow TweakTown for breaking tech news, reviews, and daily updates.

Add TweakTown as a preferred source on GoogleFind TweakTown on Apple News

As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.

TIO Network suffers data breach, affecting 1.6 million users

| Dec 5, 2017 5:41 AM CST

TIO Networks is a telecom, wireless, cable and utility network operator in North America that also offers bill payment services, earlier this year PayPal purchased this company for $233 million and now it has come out that TIO network has had their data compromised. PayPal announced on November 10th that there was a potential breach in the TIO network but now has later confirmed that they "identified a potential compromise of personally identifiable information for approximately 1.6 million customers."

TIO Network suffers data breach, affecting 1.6 million users

Thankfully PayPal's systems are not linked in anyway to that of TIO Networks as PayPal reassures customers that their data remains in secure hands.

"A review of TIO's network has identified a potential compromise of personally identifiable information for approximately 1.6 million customers. The PayPal platform is not impacted in any way, as the TIO systems are completely separate from the PayPal network, and PayPal's customers' data remains secure."

Continue reading: TIO Network suffers data breach, affecting 1.6 million users (full post)

Former NSA worker admits to stealing Russian hacked data

| Dec 4, 2017 2:16 AM CST

Nghia Pho, a former NSA employee has pleaded guilty to taking home classified information that was soon after linked to a hack from Russian intelligence. Pho will be sentenced on April 6th and has had his maximum penalty capped at 8 years, which would usually be 10 years.

Former NSA worker admits to stealing Russian hacked data

According to sources of The New York Times, Pho stole the information both in physical and digital form between 2010 and 2015, then proceeded to intentionally use this information to then rewrite his resume. The hack came through exploited Kaspersky anti-virus software which the company was not aware of at the time. Kaspersky was aware that it has held NSA data but it is not clear whether it was that specific data or not.

Recently the NSA has had to deal with many leaks, scrambling to fix all these leaks could either motivate others to come forward and blow the whistle, or they could see Pho be made an example of, putting fear into others that were considering coming forward because of the penalty.

Continue reading: Former NSA worker admits to stealing Russian hacked data (full post)

Canadian hacker pleads guilty in Yahoo hack, helped Russia

| Dec 1, 2017 3:29 AM CST

Back in 2014 Yahoo experienced a hack that exposed close to 500 million accounts, and now a Canadian citizen has just recently pleaded guilty to assisting a Russian intelligence officers in the hack. 22-year-old Karim Baratov has been arrested while another three individuals are facing charges back in Russia.

Canadian hacker pleads guilty in Yahoo hack, helped Russia

Prosecutors have stated that two of the Russian hackers are working for the Russian spy agency FSB, while the third is known Russian hacker Alexsey Belan. Dmitry Dokuchaev and Igor Sushchin are believed to have directed the attack and are also the ones that contacted Baratov when their targets were compromised with email accounts outside of Yahoos system. California's U.S Attorney's Office dives deeper into the details of the case, fleshing out the scope of abundant charges.

"According to his plea agreement, Baratov's role in the charged conspiracy was to hack webmail accounts of individuals of interest to the FSB and send those accounts' passwords to Dokuchaev in exchange for money. As alleged in the indictment, Dokuchaev, Sushchin, and Belan compromised Yahoo's network and gained the ability to access Yahoo accounts. When they desired access to individual webmail accounts at a number of other internet service providers, such as Google and Yandex (based in Russia), Dokuchaev tasked Baratov to compromise such accounts."

Continue reading: Canadian hacker pleads guilty in Yahoo hack, helped Russia (full post)

NSA leaves secret docs on the cloud, WITHOUT A PASSWORD

| Nov 28, 2017 8:42 PM CST

For a spy agency that has the word 'security' in its title, the National Security Agency seems to be worse than a teenager downloading MP3s from LimeWire. The NSA has been busted again exposing top secret data to people, this time on the cloud.

NSA leaves secret docs on the cloud, WITHOUT A PASSWORD

UpGuard Director of Cyber Risk Research Chris Vickery discovered back on September 27 an Amazon Web Services S3 cloud storage bucket that was configured for totally open public access. This means that anyone can enter the URL and see what's inside of trhe bucket, which was located on the AWS subdomain "inscom". This folder had 47 viewable files and other folders inside, three of which could be downloaded.

INSCOM is the intelligence command that is controlled by both the US Army, and the NSA. The worst part of this news is that the folder wasn't password protected, which seems awfully stupid (there are worse words) of the NSA.

Continue reading: NSA leaves secret docs on the cloud, WITHOUT A PASSWORD (full post)

Imgur hit with data breach, affects 1.7 million accounts

| Nov 28, 2017 5:13 AM CST

Imgur has fallen victim to a data breach attack, following the recent hack and cover up from Uber, usernames and passwords have been compromised, totaling to 1.7 million user accounts.

Imgur hit with data breach, affects 1.7 million accounts

This breach on Imgur has been reported to of happened in 2014 and only has just come to company's attention now. Responding quickly, Roy Sehgal, Chief Operating Officer released a statement on behalf of Imgur, saying that the company is investigating the origin of the hack and that it is possible that the hack occurred due to an "old algorithm that was used at the time."

"We are still investigating how the account information was compromised. We have always encrypted your password in our database, but it may have been cracked with brute force due to an older hashing algorithm (SHA-256) that was used at the time. We updated our algorithm to the new bcrypt algorithm last year. We recommend that you use a different combination of email and password for every site and application. Please always use strong passwords and update them frequently."

Continue reading: Imgur hit with data breach, affects 1.7 million accounts (full post)

T-Mobile hacked, 76 million users' data leaked

| Oct 11, 2017 10:34 PM CDT

It seems we can't go a week without a major breach in security at a huge company, with T-Mobile's website now reportedly hacked and the data from 76 million of its users could be exposed.

T-Mobile hacked, 76 million users' data leaked

Security researcher Karak Saini discovered the bug in the wsg.t-mobile.com API, where if someone searched for someone else's number, the API sending back the data would include that users' data. The data in question included users' email addresses, IMSI network code, billing account data, and more. All hackers had to do was know, or guess a user's phone number, and they could have virtually all of that person's information, and more.

Saini spoke with Motherboard, where he said: "T-Mobile has 76 million customers, and an attacker could have ran a script to scrape the data (email, name, billing account number, IMSI number, other numbers under the same account which are usually family members) from all 76 million of these customers to create a searchable database with accurate and up-to-date information of all users".

Continue reading: T-Mobile hacked, 76 million users' data leaked (full post)

Yahoo now admits 3 billion accounts were breached

| Oct 3, 2017 11:37 PM CDT

The massive breach of Yahoo looks like it was worse than the original stories, which were already bad, but now Yahoo has said that all 3 billion users had their accounts breached.

Yahoo now admits 3 billion accounts were breached

Yahoo first reported 1.5 billion accounts had been breached in 2013, something that was announced just days before Verizon acquired the search giant. Verizon, which now owns Yahoo, has said that the attack had breached every Yahoo account... which means 3 billion accounts were attacked.

Verizon disclosed the new findings after an internal investigation into the 3 billion account breach, working with the SEC. The filing reads: "Subsequent to Yahoo's acquisition by Verizon, and during integration, the company recently obtained new intelligence and now believes, following an investigation with the assistance of outside forensic experts, that all Yahoo user accounts were affected by the August 2013 theft".

Continue reading: Yahoo now admits 3 billion accounts were breached (full post)

Lifetime VPN for just $89 hits Kickstarter

| Jul 17, 2017 7:53 PM CDT

VPNs are used in all different ways with all sorts of different people, but 4TFY has hit Kickstarter offering itself as an "easy-to-use, cost-effective VPN service".

Lifetime VPN for just $89 hits Kickstarter

The Kickstarter page for 4TFY continues, saying that their VPN service "allows you to hide your browsing activity from both your government and internet service provider, bypass government-imposed censorship, access geo-blocked content, mask your IP address, hide your physical location, and encrypt your internet traffic for greater browsing security".

The reason 4TFY caught my attention is that it is just $89 for a lifetime VPN service, blowing other VPN services out of the water that charge $89 per year on average. 4TFY is very aware of the "mass government surveillance is now the norm", offering the lifetime VPN service so that "your activities are not recorded and that you are able to access any content, anywhere, anytime. We do this by masking your IP address, by encrypting your internet traffic, and by passing this traffic through one on our highly secure servers".

Continue reading: Lifetime VPN for just $89 hits Kickstarter (full post)

Biggest data breach in India affects 120 million users

| Jul 10, 2017 9:34 AM CDT

Jio, a mobile network operator in India, is currently experiencing what could be the biggest data breach in India.

Biggest data breach in India affects 120 million users

Jio is one of the fastest growing carriers in India and the whole world and was made famous by their launch of a nationwide LTE network for a very low price. They launched their network in September of last year, and have over 120 million users in less than a year. However, it appears that their speedy launch may have come at a cost.

Jio's customer's data has been leaked revealing many sensitive details, including customer's names, last names, phone numbers, emails, SIM Activation Date and even their Aadhaar Number. Aadhaar is a 12 digit unique identification number issued to all Indian residents based on their biometric and demographic data, and the world's largest biometric ID system, with over 1.154 billion enrolled members as of 11 June 2017.

Continue reading: Biggest data breach in India affects 120 million users (full post)

Microsoft gives NSA backdoor, complains about exploits

| May 14, 2017 9:30 PM CDT

I'm sure that you've heard about the "WannaCry" ransomware that is attacking hundreds of thousands of computers across hundreds of countries, and now Microsoft is chiming in with some fighting words against the NSA, CIA, and other spy agencies.

Microsoft gives NSA backdoor, complains about exploits

Microsoft President Brad Smith said that the NSA, CIA, and other spy agencies have been collecting security vulnerabilities, instead of telling Microsoft so they can fix them. Smith said there's an "emerging pattern" of these stockpiles leaking out, adding that some of themt can cause "widespread damage" when that happens. Smith even likened it to a physical weapons being leaked or stolen, comparing it to if the US military had "some of its Tomahawk missiles stolen".

But before we get too deep into this, remember that Microsoft built a freakin' backdoor into Outlook.com for the NSA, with Microsoft working for months to provide the NSA with full access to encrypted chats on Outlook.com, something we reported about in July 2013. Microsoft also worked with the NSA on giving them a backdoor into SkyDrive, their cloud-based storage service. At the time, I reported: "Microsoft worked tightly with the NSA in order to give them access, with the NSA reporting on April 8 of this year that the Redmond-based slave of the NSA built PRISM access into SkyDrive that removes the need for the NSA analysts to request permission to search SkyDrive".

Continue reading: Microsoft gives NSA backdoor, complains about exploits (full post)

Huge security flaw: Keylogger found on HP laptops

| May 11, 2017 3:23 PM CDT

Swiss cyber-security company Modzero discovered some worrying security flaws in certain HP laptops and made them public.

Huge security flaw: Keylogger found on HP laptops

According to their report, some HP laptops come with an audio driver that includes a feature which would be best described as a keylogger. This feature records all the user's keystrokes and saves the information into a local file, which is accessible to third-party software or malware.

The keylogger feature was discovered in the Conexant HD Audio Driver Package version 1.0.0.46 and earlier. The audio driver in question is preinstalled on the HP laptops.

Continue reading: Huge security flaw: Keylogger found on HP laptops (full post)

Bose headphones app sends all your info back to Bose

| Apr 20, 2017 3:27 AM CDT

Bose are one of the biggest high-end audio companies in the world, a brand that has trust associated with it - but, were we foolish to think so? According to a new lawsuit filed by Kyle Zak in Chicago, Bose's current $350 wireless headphones are spying on you.

Bose headphones app sends all your info back to Bose

The headphones in question require an app to "get the most" out of them, but the app monitors everything you listen to - including the names of the podcasts, the music, videos, and more. It then sends all of that information back to Bose, according to Zak's claim and lawsuit. According to Christopher Dore, Zak's lawyer: "People should be uncomfortable with it. People put headphones on their head because they think it's private, but they can be giving out information they don't want to share".

According to Reuters: "Zak is seeking millions of dollars of damages for buyers of headphones and speakers, including QuietComfort 35, QuietControl 30, SoundLink Around-Ear Wireless Headphones II, SoundLink Color II, SoundSport Wireless and SoundSport Pulse Wireless". Not just that, but Zak also "wants a halt to the data collection, which he said violates the federal Wiretap Act and Illinois laws against eavesdropping and consumer fraud", Reuters reports.

Continue reading: Bose headphones app sends all your info back to Bose (full post)

NSA spying tools can hack the global financial system

| Apr 15, 2017 6:05 AM CDT

We all know the NSA has the tools to spy on virtually everyone, but now hacking group Shadow Brokers has released a data dump that has allegedly come from the NSA, which details that the US spy agency can hack international banks - and more important,yl the SWIFT network through Windows PCs and servers that are used during global financial transfers.

NSA spying tools can hack the global financial system

What is the SWIFT? It's used by banks as a security measure for fraud, as it's used to validate ones back account - and vica versa. There are trillions of dollars per day that get transferred through SWIFT, with over 11,000 banks and securities organizations in over 200 countries using SWIFT. The NSA allegedly claimed in its now hacked and released article that the "box has been implanted and we are collecting", which Wired explains as the "jargon used by the NSA to indicate spyware has been successfully implanted on a computer".

Security researcher Matt Suiche said that the IP addresses that are next to the financial institutation in the documents do not line up with the real IP addresses of the machines at the institutions. The IP addresses that were listed were to machines at EastNets, which is the largest SWIFT branch in the Middle East, which manages all of the payments for financial clients. Suiche explains: "This is the equivalent of hacking all the banks in the region without having to hack them individually".

Continue reading: NSA spying tools can hack the global financial system (full post)

WikiLeaks: Apple Mac, iPhone firmware hacked by CIA

| Mar 23, 2017 9:48 PM CDT

So, it looks like most of Apple's products are bugged by the CIA - if the latest claims from WikiLeaks are to be believed. The new "Dark Matter" release from "Vault 7" has documentation for "several CIA projects that infect Apple Mac firmware (meaning the infection persists even if the operating system is re-installed) developed by the CIA's Embedded Development Branch (EDB). These documents explain the techniques used by CIA to gain 'persistence' on Apple Mac devices, including Macs and iPhones and demonstrate their use of EFI/UEFI and firmware malware".

WikiLeaks: Apple Mac, iPhone firmware hacked by CIA

WikiLeaks has exposed the interestingly named "Sonic Screwdriver" project, something that CIA calls a "mechanism for executing code on peripheral devices while a Mac laptop or desktop is booting". This hack provides its attacker, so in this case the CIA, to deploy its attack software from a USB flash drive - and scarily "even when a firmware password is enabled".

The CIA's "Sonic Screwdriver" infector is reportedly stored on the modified firmware of an Apple Thunderbolt-to-Ethernet adapter, says WIkiLeaks.

Continue reading: WikiLeaks: Apple Mac, iPhone firmware hacked by CIA (full post)

Yahoo: Over 1 billion accounts have been compromised

| Dec 15, 2016 3:09 AM CST

Yahoo has confirmed that over 1 billion user accounts have been compromised, with the breach dating back to August 2013.

The stolen user data includes names, email addresses, phone numbers, dates of birth, hashed passwords, and even unencrypted security questions. Thankfully, financial information such as bank account and credit card data is held in a different server, with Yahoo saying that server was not affected - hopefully.

The company is now in the process of notifying all affected users, asking them to change their passwords - but as for the unencrypted security questions, Yahoo has invalidated them. It was only back in September that we reported over 500 million Yahoo account details were leaked in a breach in 2014, with forensic experts stating that the two hacks aren't related.

Continue reading: Yahoo: Over 1 billion accounts have been compromised (full post)

US Navy hacked, 130,000+ sailors' personal data leaked

| Nov 27, 2016 8:12 PM CST

The US Navy has waited until Thanksgiving to announce news that one of their employees had their laptop "compromised", with personal data of 130,000 sailors being stolen, back on October 27.

Chief of Naval Personnel Vice Admiral Robert Burke said in the US Navy's press release: "The Navy takes this incident extremely seriously - this is a matter of trust for our Sailors. We are in the early stages of investigating and are working quickly to identify and take care of those affected by this breach".

The Navy continued in its press release: "For those affected by this incident, the Navy is working to provide further details on what happened, and is reviewing credit monitoring service options for affected Sailors".

Continue reading: US Navy hacked, 130,000+ sailors' personal data leaked (full post)

Qualcomm announces vulnerability bounty program

| Nov 17, 2016 6:30 AM CST

Qualcomm announced they are launching a vulnerability rewards program (also known as a bounty) designed to expand their collaboration with invited white hat hackers. The company firmly believes that these type of hackers will help to improve the security of their Snapdragon family and LTE modems by finding the vulnerabilities and then reporting them to Qualcomm to fix.

The program is the first of its kind to be announced by a major silicon vendor. The program will be administered in collaboration with vulnerability coordination platform HackerOne. This also takes Qualcomm another step towards becoming one of the most secure silicon vendors in the industry.

Qualcomm says that they will offer up to $15,000 per vulnerability. By comparison, Google has numerous vulnerability bounties that range from $500 to $20,000. Apple, on the other hand offers up to $200,000 per vulnerability discovered on its devices.

Continue reading: Qualcomm announces vulnerability bounty program (full post)

Huge cyber attack involved 10s of millions IP addresses

| Oct 23, 2016 10:33 AM CDT

Tens of millions of IP addresses were used to take down popular websites like Twitter, Spotify and Netflix on Friday by so far unknown sources. The DDoS attack on the DynDNS started on Friday morning, but the service was restored around 9:30 AM ET. However, around Friday noon, another attack began. Service was restored at approximately 1:00 PM ET same day, but many users had reported they had issues with certain websites.

Dyn reported there was an attempt of a third attack wave, but the were able to successfully mitigate it without customer impact.

Dyn issued a statement saying they are continuing their investigation.

Continue reading: Huge cyber attack involved 10s of millions IP addresses (full post)

Major cyber attack knocks out popular websites

| Oct 21, 2016 2:29 PM CDT

Twitter, Spotify, Amazon, Netflix, Reddit, Etsy and many other popular websites went offline earlier today due to a massive cyber attack on the DynDNS, a world renowned Domain Name Servers (DNS) service provider.

Dyn issued a statement acknowledging the attack.

The DDoS attack began this morning, but the service was restored around 9:30 AM ET. However, around noon, another attack began. According to DownDetector's outage map, the DDoS attack is primarily targeting US users.

Continue reading: Major cyber attack knocks out popular websites (full post)

Facebook named privacy villain of the year

| Oct 7, 2016 4:03 PM CDT

The Belgian Big Brother Awards 2016 yesterday unanimously granted the title of 'ultimate privacy villain of the year' to Facebook, as decided by the public and a professional jury.

"We nominated Facebook for the award because their default settings are noxious for privacy," explained Joe McNamee, Executive Director of European Digital Rights. He later remarked, "Facebook is a multi-billion dollar company that has one commodity - you!"

Digital rights and freedoms association EDRi describes Facebook as having "access to a wide range of personal data, and it tracks your movements across the web, whether you are logged in or not."

Continue reading: Facebook named privacy villain of the year (full post)

Join Our Newsletter

Join the TweakTown Newsletter for daily tech updates delivered to your inbox.

See previous giveaways.

Newsletter Subscription