Hacking, Security & Privacy - Page 17
Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 17
Stay Updated
Follow TweakTown for breaking tech news, reviews, and daily updates.
As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.
Windows Defender works against Dell adware certificate
While Dell recently admitted that a dangerous vulnerability was pre-installed on their systems, they refused to believe that it was created by them but still pledged to remove it.
In a great move my Microsoft, its Windows Defender security system has now begun locating and removing the certificate itself, as long as you've updated your Windows OS. Discovered by ZDNet in a routine action just this morning, Windows Defender identified a threat named "Win32/CompromisedCert.D" and removed it from the system.
Dell has reportedly started issuing updates to its maintenance utility to also rid this issue for all concerned, but it doesn't hurt to update Windows Defender to be safe.
Continue reading: Windows Defender works against Dell adware certificate (full post)
Security experts say Australia is a very easy hacker target
"Malicious hackers already know us to be weaker than the rest of the world," the director of Hacklabs, Chris Gatford, told News.com.au in an interview. He believes that without much effort, Australia's water and electricity supply lines could become a complete shambles with a single hacker attack.
Gatford went on to draw the comparison between Australia's national infrastructure and your mothers Microsoft Surface, stating: "It would only take a skilled individual to breach these computer systems, because more often than not they are not patched as frequently as corporate or home systems which have automated updates." While he did comment mainly on security concerns within Australia, Gatford also made mention of other technical mishaps around the world, touching on "historical examples of traffic lights being overtaken, denial-of-service attacks at airports and organisations in Wall Street coming under attack to see its 100 per cent possible."
The whole situation isn't quite as dire as it may initially seem though, the Hacklabs director did reassure us that these necessary utilities would recover quickly from attack, rather than send Australia into a Fallout 4-like existence.
Continue reading: Security experts say Australia is a very easy hacker target (full post)
Dell admits fault, promises to remove preinstalled security flaw
Described as an "unintended security vulnerability," Dell has admitted that a root certificate preinstalled on some of its models exists and promises to remove it.
A Dell spokesperson explained that "to address this, we are providing our customers with instructions to permanently remove the certificate from their systems via direct email, on our support site, and technical support," further commenting that the computer giant does not install malware on user systems pre-delivery.
While Dell claims no responsibility for this flaw, a security blogger by the name of Hanno Bock disagrees. He says that this root certificate is not only shipped within these pre-built machines, but it's under the name 'eDellRoot' and is linked to 'Dell Foundation Services' drivers.
Continue reading: Dell admits fault, promises to remove preinstalled security flaw (full post)
Anonymous vows revenge against ISIS for Paris terror attacks
Hacktivist collective Anonymous has reportedly declared war against the terrorist group ISIS, vowing revenge against the Islamic State following the recent terror attacks in Paris.
On the Saturday following the brutal attacks that saw more than 129 people murdered, ISIS took responsibility for the wave of terror that swept over the city of Paris. President François Hollande then confirmed the Islamic State's involvement. The terrorist group boasted that this wast just "the first of the storm" and called Paris a "capital of prostitution and obscenity."
Anonymous has now stood up to promise retribution, and has already begun wreaking havoc across the Islamic State's online network as part of the #OpParis campaign. "These attacks cannot be left unpunished. That's why Anonymous worldwide will track you," a recent Anonymous video proclaimed. "Yes, we are going to track you down, like we have since the Charlie Hebdo attacks. Wait, then, for a massive response from Anonymous. Know that we will find you, and we will hold nothing back."
Continue reading: Anonymous vows revenge against ISIS for Paris terror attacks (full post)
Hacker team remotely jailbreaks iPhone, wins $1 million
An anonymous hacker group has remotely jailbroken a new iPhone running iOS 9.1, winning themselves a cool $1 million from startup Zerodium (self-described as a "premium exploit acquisition platform"). The winnings are pending final verification of the exploit, but results at this stage look good.
To put the difficulty of this feat in context: a chain of zero-day bugs needed to be found, the hack needed to be remote (much more difficult -- Chinese hacking team Pangu already hacked the new iPhone, but couldn't do it remotely) and made through Safari, Chrome, or a text or multimedia message, and full system access needed to be obtained. An iPhone has not been remotely jailbroken for over a year, since iOS 7. Zerodium says Apple will likely patch these bugs "in a few weeks to a few months".
The winning team was one of two to take on the challenge. Both found themselves stuck, but eventually one found a way via Chrome and iOS, just a few hours before the challenge was to end.
Continue reading: Hacker team remotely jailbreaks iPhone, wins $1 million (full post)
256 iOS apps outed for privacy violations, to be removed from store
Researchers have discovered there are 256 apps on the App Store that have found their way around Apple's vetting process and violated privacy rights. All of them use the Chinese-developed Youmi SDK. In total, approximately one million people use the apps in question.
To be clear, the developer of any of these apps is not necessarily to blame at all. It appears Youmi is the one interested in acquiring your data, and has insidiously worked gathering tools into its development kit, thereby attempting to cover its tracks and pass the blame onto developers, should the scheme be uncovered.
Nate Lawson, founder of security analytics startup SourceDNA (which uncovered the violations), says this is "definitely the kind of stuff that Apple should have caught."
Continue reading: 256 iOS apps outed for privacy violations, to be removed from store (full post)
Intel says that it want to 'eliminate all passwords from computing'
It looks like Intel is on a mission, where the chipmaker wants to see facial recognition or fingerprint scanners to replace the traditional, and easily penetrated passwords we all use for countless services, websites, bank accounts, and more.
Intel not only things it's a possibility, but that it's something it can get into motion very quickly. Kirk Skaugen, Senior VP and General Manager of Intel's Client Computer Group said at the Citi Global Technology Conference earlier this week: "We want to eliminate all passwords from computing. I can confidently say today, you can eliminate all your passwords today, if you buy a 6th Generation Core system".
So the company is saying that its Skylake architecture is capable of true facial recognition security thanks to Windows 10, where you can use the entire feature set of Windows Hello. This, mixed with Intel's RealSense 3D camera, we could see true facial recognition security that is much more secure than the traditional password. Skaugen added: "You can do everything from measure blood pressure, blink detection, all these kinds of things... In fact, in Berlin, one of my funniest demos in my 23 years at Intel is when I brought two identical twins out on stage and I mixed them up and only one could log in with the PC, and it actually worked". Now that, is some exciting stuff.
Continue reading: Intel says that it want to 'eliminate all passwords from computing' (full post)
Report: Prior to breach, no one wanted to purchase Ashley Madison
Avid Life Media was unable to find a willing suitor for Ashley Madison, and trying to generate new funds proved extremely difficult.
Avid Life sent a letter to investors that it was interested in purchasing $10 million worth of shares, amid pressure to improve the company's liquidity. Any aspirations for an IPO would be crippled in a "doomsday scenario," according to bankers speaking to Reuters prior to the massive data dump.
"Over the last couple of years, we have not been successful in exploring various alternatives including a sale of the business and seeking debt from third parties," a letter from the board of directors confirmed.
Continue reading: Report: Prior to breach, no one wanted to purchase Ashley Madison (full post)
Julian Assange urged Edward Snowden to pick Russia over Latin America
Julian Assange knows a little something about trying to avoid extradition, and urged former NSA contractor Edward Snowden to select Russia over Latin America. Not only was reaching Latin America a difficult journey, but Snowden's personal safety would have been at risk, Assange noted.
Assange urged Snowden to disregard "negative PR consequences" about choosing Russia, where his physical safety has been provided by the Russian government - a guarantee that would have been significantly less likely if he ended up somewhere in Central or South America.
Sarah Harrison, one of Assange's most trusted senior staff members, actually met with Snowden while the American was in Hong Kong - at a time when it was unknown where Snowden would end up.
Continue reading: Julian Assange urged Edward Snowden to pick Russia over Latin America (full post)
FBI demanded Scandinavian countries extradite Snowden if he visited
Before former NSA contractor Edward Snowden fled to Russia, the FBI demanded the immediate arrest - and extradition - of Snowden if he went to any Scandinavian nations. Snowden applied for asylum in Norway, but once FBI officials heard he would try to head to a Scandinavian country, they began pressuring Denmark, Sweden, Norway and Finland. Trying to leave Moscow, however, wouldn't be an easy task:
"The US Department of Justice is prepared to immediately draft the necessary paperwork to request the extradition of Snowden to the US from whichever country he travels to from Moscow," according to the letter. "The FBI expresses its gratitude... for any assistance that can be provided on this important matter."
It's likely the FBI and other government officials sent similar requests to many other European nations, which prevented Snowden from traveling outside of Russia.
Continue reading: FBI demanded Scandinavian countries extradite Snowden if he visited (full post)
Ashley Madison CEO stepping down after devastating data breach
Avid Life Media announced that CEO Noel Biderman has stepped down, following the company's embarrassing public data breach.
Senior management will be responsible for day-to-day operations of the company, until a permanent replacement can be identified. It's going to be a confusing time for Avid Life Media, after a "criminal intrusion" that reportedly occurred over years by unknown hackers.
"This change is in the best interest of the company and allows us to continue to provide support to our members and dedicated employees," Ashley Madison noted in a statement. "We are steadfast in our commitment to our customer base."
Continue reading: Ashley Madison CEO stepping down after devastating data breach (full post)
Report: 40% of Americans impacted by healthcare data breaches
Almost 45 percent of Americans have suffered from a cyberattack targeting sensitive health information, according to a recent iSheriff white paper.
It has been an absolutely atrocious year for healthcare data breaches, with the likes of Anthem, Premera, CareFirst, and UCLA Health Systems suffering breaches - totaling a whopping 143 million patient records.
"When more than forty percent of the US population has been a victim of a data security breach, we must recognize this is an epidemic that can and will hit any healthcare provider," said Paul Lipman, CEO of iSheriff. "These breaches not only cost time and money, they risk compromised medical records that could impact health diagnoses and outcomes. Cybercrime is the new healthcare crisis."
Continue reading: Report: 40% of Americans impacted by healthcare data breaches (full post)
Lawsuits over Ashley Madison data dump will be a challenge to win
Avid Life Media, the operator of Ashley Madison, is facing multiple lawsuits following a massive data dump that included around 37 million records.
"I'd be surprised if you get a lot of traction here," said Scott Vernick, partner and head of data security and privacy at the Fox Rothschild LLP law firm, in a statement published by the Associated Press. Even with the data finding its way from the dark web to the regular Internet, trying to win lawsuits against breached companies doesn't tend to end up well for plaintiffs.
A Canadian law firm recently filed a $578 million class-action lawsuit on behalf or Ashley Madison users, and there are at least four active lawsuits against Avid Life in the United States. One was filed in Missouri, one was filed in Texas, and two others were filed in California - and all have anonymous plaintiffs listed.
Continue reading: Lawsuits over Ashley Madison data dump will be a challenge to win (full post)
Avid Life Media offers more than $375,000 bounty to identify hackers
Avid Life Media is still trying to deal with a major PR disaster after The Impact Team breached Ashley Madison, and the company has offered up a $500,000 CAD ($377,000) bounty.
"You know The Impact Team has crossed the line," said Bryce Evans, acting staff superintendent of the Toronto Police, during a Monday morning press conference. "This hack is one of the largest data breaches in the world. The social impact behind this leak, we're talking about families, we're talking about children, we're talking about wives, we're talking about their male partners. It's going to have impacts on their lives... this is affecting all of us."
Evans also asked for the hacking community to "do the right thing" and help Avid Life Media and the police identify the hackers. Even if members of The Impact Team are identified, however, trying to bring them to justice could be extremely difficult - depending where they are located in the world.
Continue reading: Avid Life Media offers more than $375,000 bounty to identify hackers (full post)
Florida State Attorney Jeff Ashton apologizes for using Ashley Madison
After the Ashley Madison data dump, which featured more than 33 million accounts, it was no surprise that the fallout would ensnare plenty of people that would need to explain themselves. One political leader already claimed he used the site for "opposition research," and now Florida State Attorney Jeff Ashton publicly apologized after his name was discovered on Ashley Madison.
Ashton described his decision to sign up for Ashley Madison as a "bad, childish, stupid error" and he "did not commit a crime" by using the site. Ashton claims he typically logged in using a personal laptop and through public Wi-Fi networks. He reportedly didn't meet anyone via the site, and didn't have an affair.
"While I indulged my curiosity about the site it never went beyond that," Ashton said during a press conference. "These were incredibly stupid choices." In addition, Ashton won't step down and plans to return back to work: "I think I've humiliated myself enough for one weekend. Tomorrow morning I go back to work."
Continue reading: Florida State Attorney Jeff Ashton apologizes for using Ashley Madison (full post)
Looks like Ashley Madison site operator should prepare for lawsuits
Avid Life Media and Avid Dating Life are not going to have a fun time following the fallout of Ashley Madison's data being publicly dumped to the Internet. Thousands of Canadians had their privacy violated following the breach, which included personal names, email addresses, home addresses, and message history - and the lawsuits are going to roll in.
Charney Lawyers and Sutts, Strosberg LLP filed a $578 million class-action lawsuit on behalf of Ashley Madison members located in Canada. The lawyers won't try to include the Impact Team in the class-action lawsuit, as seeking damages from a foreign-based hacker group would be difficult.
"Numerous former users of AshleyMadison.com have approached the law firms to inquire about their privacy rights under Canadian law," the law firms said. "They are outraged that AshleyMadison.com failed to protect its users' information. In many cases, the users paid an additional fee for the website to remove all of their user data, only to discover that the information was left intact and exposed."
Continue reading: Looks like Ashley Madison site operator should prepare for lawsuits (full post)
Political leader: Used Ashley Madison for 'opposition research'
Louisiana GOP Executive Director Jason Dore confirmed his name was one of millions exposed in the Ashley Madison data dump.
The Republican Party statewide director used his full name and former personal credit card billing address, but claims he was doing a bit of research for his Doré Jeansonne law firm:
"As the state's leading opposition research firm, our law office routinely searches public records, online databases and websites of all types to provide clients with comprehensive reports," Doré; told The Times-Picayune. "Our utilization of this site was for standard opposition research. Unfortunately, it ended up being a waste of money and time."
Continue reading: Political leader: Used Ashley Madison for 'opposition research' (full post)
DARPA interested in helping develop DDoS protection systems
DARPA wants to help develop new solutions to defend against distributed denial of service (DDoS) attacks, with foreign cybercriminals launching large volumes of attacks against US military and government targets.
The Extreme DDoS Defense (XD3) aims to provide a DDoS countermeasure system that is able to identify incoming attacks, and help defend networks. Depending on the attack sophistication, DARPA wants to have a response time of 10 seconds or less - a difficult challenge, but an important one that could be used in the private sector and by the government/military.
"In general, the program aims to thwart DDoS attacks by dispersing cyber assets (physically and/or logically), disguising the characteristics and behaviors of those assets, and mitigating the attacks (especially low-volume attacks) that still penetrate the targeted environment," according to the DARPA Broad Agency announcement, asking for applicants.
Continue reading: DARPA interested in helping develop DDoS protection systems (full post)
Extortionists emailing Ashley Madison members demanding payment
Well, it didn't take long before the scam artists and extortionists started taking advantage of the recent Ashley Madison data dump. People with email addresses exposed are receiving shady looking emails that demand payment in exchange for secrecy so their spouses and partners aren't informed.
Here is one email that was shared with Brian Krebs from Krebs on Security:
Hello,
Continue reading: Extortionists emailing Ashley Madison members demanding payment (full post)
Avid Life Media sending takedown notices following data dump
Avid Life Media has gone on the offensive following the Ashley Madison data dump, sending takedown notices to social networking websites and file-sharing services.
Stolen data includes data of up to 33 million users, and while removing data from Twitter, Facebook, Reddit, and other sites has been successful, it's going to be nearly impossible to scrub the data dump from the Internet.
The data is out there, and there are plenty of links to anyone looking for a searchable database - yielding everything from names, usernames, email addresses, and sexual preferences - as Avid Life Media tries a desperate effort to fix its PR disaster.
Continue reading: Avid Life Media sending takedown notices following data dump (full post)



