Newsletter IconFacebook IconX IconThreads IconInstagram IconYouTube IconPinterest Icon
Giveaway: AVerMedia Creator Bundle (4K Webcam, Capture Card, Charging Hub, and Mouse Pad)

Hacking, Security & Privacy - Page 21

Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 21

Stay Updated

Follow TweakTown for breaking tech news, reviews, and daily updates.

Add TweakTown as a preferred source on GoogleFind TweakTown on Apple News

As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.

US tech companies don't want Obama to interfere with encryption

| Jun 10, 2015 12:00 PM CDT

President Barack Obama has received a letter from the Information Industry Association and Information Technology Industry Council not to mess with encryption. The US government wants backdoors created so law enforcement can access information when needed, but Silicon Valley companies warned that would also create opportunities for cybercriminals.

"We are opposed to any policy actions or measures that would undermine encryption as an available and effective tool," said the letter. The Information Industry Association represents companies such as Microsoft, Facebook, Google and Apple - with executives from each company previously speaking out against various government interference in security.

The FBI and other agencies support the Obama administration's efforts to help bypass encryption, but in a manner that wouldn't allow hackers and cybercriminals to exploit the encryption backdoor.

Continue reading: US tech companies don't want Obama to interfere with encryption (full post)

OPM knew its computer system was at risk from hacker attacks

| Jun 9, 2015 6:20 AM CDT

The Office of Personnel Management knew that its computer security system could be exploited by outside act, but the issue still wasn't spotted in time. The OPM is expected to roll out two-step authentication to better protect its networks.

It was still too late - tens of thousands of files were already stolen before the inspector general's report last November. After a breach was detected last summer, cybercriminals were able to launch a broader attack that likely began in December. So far, more than 4 million people have been exposed by the breach, and it's likely that number will rise.

Cybercriminals tend to be very patient while browsing compromised networks, especially organized cyber hackers. It's possible the OPM hack was carried out by those responsible for breaching Anthem, as personal information is lucrative.

Continue reading: OPM knew its computer system was at risk from hacker attacks (full post)

President Obama: Cybersecurity vulnerabilities will accelerate

| Jun 8, 2015 5:37 PM CDT

Cybersecurity issues are getting worse, President Barack Obama admitted recently, as the United States remains a lucrative target of foreign cybercriminals. Obama wants Congress to pass new cybersecurity legislation to help address mounting digital threats.

"We have known for a long time that there are significant vulnerabilities, and that these vulnerabilities are going to accelerate as time goes by, both in systems within government and within the private sector," Pres. Obama said during a Group of Seven summit.

It's a stark realization that the US government has been aware of cybersecurity issues, but favored the need on bulk surveillance activities. If nothing else, it looks like some private sector security firms and defense contractors will make a fortune helping the government upgrade.

Continue reading: President Obama: Cybersecurity vulnerabilities will accelerate (full post)

Security experts say US government must make cybersecurity changes

| Jun 5, 2015 1:12 PM CDT

The US government has confirmed that records of current and former federal employees are at risk, following news that the Office of Personnel Management (OPM) suffered a series of cyberattacks. Despite reportedly beginning in late 2014, it took until April before the intrusions were detected.

Here is some expert cybersecurity input regarding the breach:

There is a changing cybercriminal landscape that the United States has been relatively slow to adapt to:

Continue reading: Security experts say US government must make cybersecurity changes (full post)

Foreign breach of US data exposes 4 million employees

| Jun 4, 2015 8:01 PM CDT

Authorities believe that a breach in US government data was thanks to a "foreign entity" and the Federal Bureau of Investigation has launched a full inquiry into who exactly stole the data on approximately four million workers.

This hacking spree took place through the US's Office for Personnel Management (OPM) and began in April 2015, with The Department of Homeland Security concluding that this attack had finished by the beginning of May - announcing the data as compromised.

Despite the implementation of EINSTEIN, private information on four million employees was stolen directly from the human resource systems, affecting OPM IT systems as a whole.

Continue reading: Foreign breach of US data exposes 4 million employees (full post)

SmartHome aims to keep you safe through technology by ASUS

| Jun 2, 2015 6:29 PM CDT

Computex 2015 - Adding something a little different to the Computex 2015 trade show is the ASUS series of SmartHome devices, designed to keep yourself and your technology safe at home.

SmartHome aims to keep you safe through technology by ASUS

Also winning a BC award as per the ASUS ROG GR6 mini gaming PC, these products are coupled with the tagline "Smart, Simple, Secure" and are aimed at everyone from the general consumer to the complete computer mastermind.

Pictured is the black circle-like object named the ASUS Smart Home Gateway, this sets out to let you control your home through one simple app installed on a smartphone or tablet and can work with third-party products - meaning you aren't locked into ASUS branded components only.

Continue reading: SmartHome aims to keep you safe through technology by ASUS (full post)

Researchers: Identifying Tor users isn't as hard as many think

| May 31, 2015 1:44 PM CDT

Independent researcher George Tankersley and CloudFlare security team member Filippo Valsorda again showed how Tor users are not as secure as they wish.

Speaking during the Hack in the Box conference in Amsterdam, the researchers said motivated users can subvert anonymous access to the service. Hackers can identify the original location of users by operating rogue HSDir (hidden service directory) nodes that are required - with two sets of three needed to connect to the hidden service - with four days of operation to be marked as a "trusted" HSDir node.

A malicious HSDir instead of an exit node can be used in the process, making it easy to attack hidden service users.

Continue reading: Researchers: Identifying Tor users isn't as hard as many think (full post)

IRS still using Windows XP, and has more than 300 cybersecurity staff

| May 30, 2015 3:40 PM CDT

The IRS recently suffered a data breach that left thousands of Americans at risk, and more attention is now focused on government mismanaged. Utilizing a $10.9 billion budget, either the agency is greatly mismanaged and/or the IRS just isn't ready to try to protect taxpayer information.

There seems to be a lot of problems with the IRS, and that has certainly trickled down to its cybersecurity protocols. The agency still uses Microsoft Windows XP - and while the IRS originally paid Microsoft for support - that support has ended. To make matters worse, some fraud identification software is almost 20 years old.

The IRS previously had 410 cybersecurity team personnel, but that has been slashed down to 363 workers. The idea that IRS personnel are unable to keep up with identity theft is a huge problem, especially as cybercriminals get cleverer.

Continue reading: IRS still using Windows XP, and has more than 300 cybersecurity staff (full post)

Apple scrambles to release fix for widespread iMessage glitch

| May 30, 2015 4:20 AM CDT

It didn't take long for Apple to provide a temporary fix for a bug that allows users to crash an iPhone, iPad or Apple Watch via text message. The company was reportedly working on a fix anyway, but had to speed things up when users started sharing details about the problem on YouTube and social media outlets.

The problem stemmed from the way Arabic text is rendered by an iOS device, and the device's RAM ends up full, forcing a restart.

iOS users can have Siri read unread messages, and have Siri respond to the malicious message. Once that is done, users can open Messages again. Once in messages, users must swipe left to delete the entire conversation thread - or tap, hold, and delete the malicious message.

Continue reading: Apple scrambles to release fix for widespread iMessage glitch (full post)

United States tried a Stuxnet-like attack targeting North Korea

| May 29, 2015 9:30 PM CDT

The United States reportedly attempted to launch a Stuxnet-like cyberattack aimed at the nuclear weapons program in North Korea, but the cyberespionage attempt failed. Launched at the same time when Stuxnet hit Iran in 2009 and 2010, the US wanted to also set North Korea's nuclear efforts back, according to a recent Reuters report.

US cybersecurity specialists couldn't directly access systems responsible for controlling nuclear ambitions in Pyongyang - and the reclusive country's extreme secrecy and isolation helped make the attack more difficult. Similar to Iran, North Korea likely uses Microsoft Windows to power the PCs, which use control software from Siemens AG.

Cyberespionage among nations is nothing new, with nations specifically concerned regarding the nuclear ambitions of Iran, North Korea, and other nations. However, North Korea - which extremely limits access to the Internet - reportedly has an increasingly sophisticated cyberespionage program that can be used to target South Korea, the US, and other political rivals.

Continue reading: United States tried a Stuxnet-like attack targeting North Korea (full post)

Hackers finding innovative ways to commit identity theft

| May 29, 2015 6:20 AM CDT

Cybercriminals want to victimize people in any way possible, including even collecting unemployment checks directly from the government. As much as $5.6 billion is taken in federal benefits fraud, stemming from identity theft and data breaches.

Individual states and the federal government provide unemployment benefits directly to citizens, but if a person's personal information is purchased on the black market - and the fraudsters are able to file paperwork to collect the benefits. Each state must create their own system to identify - and stop - fraudulent claims, with thousands of suspected false forms submitted.

"The fact that this is so easy to commit is something that has been a real challenge to law enforcement because the fraudsters keep evolving, and they always find a new way to steal our identities," said Wifredo Ferrer, US Attorney for the Southern District of Florida, in a statement to CNN. "And all you need sometimes is a name, a date of birth and a Social Security number. And sometimes, you don't even need that to commit this crime."

Continue reading: Hackers finding innovative ways to commit identity theft (full post)

AP: IRS believes tax data thieves came from Russia

| May 28, 2015 1:56 PM CDT

The Internal Revenue Service (IRS) has confirmed more than 100,000 American taxpayer records were compromised in a recent data theft. The breaches took place thousands of times from February to mid-May, and the "Get Transcript" service was the one reportedly vulnerable.

Information taken included tax returns and other data stored on the IRS website, with more than 200,000 reported attempts made to access the agency.

"We're confident these are not amateurs, these are actually organized crime syndicates that not only we but everyone in the financial industry are dealing with," said John Koskinen, IRS Commissioner, during a recent conference call.

Continue reading: AP: IRS believes tax data thieves came from Russia (full post)

Former CIA director says United States faces threat of cyberterrorism

| May 26, 2015 4:53 PM CDT

Barry Royden, the CIA's former Director of Counterintelligence, thinks cyberterrorism poses a significant threat to the United States. Royden retired more than 10 years ago after 40 years working at the CIA, and has watched the international landscape continually change drastically.

Unfortunately, the United States has been slow to try to respond to cyberattacks - and the country's infrastructure is more vulnerable from outside attack. Rogue hacker groups, foreign state actors, and small hacker groups could pose significant problems when they find vulnerabilities to critical infrastructure.

"The trouble is, it's extremely difficult, in fact, it's impossible - everyone is connected to everyone, and as long as you're connected you're vulnerable," said Royden while speaking to Business Insider. "And there are firewalls, but every firewall is potentially defeatable, so it's a nightmare in my mind. You have to think that other governments have the capability to bring down the main computer systems in this country, power grids, hospitals or banking systems - things that could cause great economic upheaval and paralyze the country."

Continue reading: Former CIA director says United States faces threat of cyberterrorism (full post)

NSA wants to give you malware through mobile app stores

| May 22, 2015 9:30 AM CDT

Edward Snowden is back in the news, talking about a plan that the NSA had to have malware in various app stores, like the Google Play Store, and Apple iTunes Store.

The NSA program was called IRRITANT HORN, with the US spy agency wanting to find the path of web traffic to and from mobile application severs that are owned by Google and Samsung. Once the NSA found this traffic, it would place an attack in the middle, where it could silently inject malware and spying tools into a mobile device of its choice.

After it had planted this software, it could pull out e-mails, texts, search history, call records, videos, photos and anything else you have on your device. Thanks to the user thinking they're on an official app store, they would be unaware that they're being attacked by the US government in the form of the NSA.

Continue reading: NSA wants to give you malware through mobile app stores (full post)

Tech companies don't want police to receive encrypted phone data

| May 20, 2015 7:30 PM CDT

In an open letter to President Obama, more than 140 civil society groups, tech companies and tech leaders signed a statement showing concern regarding the US government's desire to view decrypted smartphone data. Both the FBI and Justice Department claim they support encryption, but want to create backdoors so law enforcement can gain access - but that seems unlikely without creating avenues that cybercriminals and foreign governments can also exploit.

Not surprisingly, law enforcement complain they will lose access to data and communications as more data can be encrypted - with Google and Apple providing ways to prevent outside snooping.

"Strong encryption is the cornerstone of the modern information economy's security," the open letter reads. "Encryption protects billions of people every day against countless threats - be they street criminals trying to steal our phones and laptops, computer criminals trying to defraud us, corporate spies trying to obtain our companies' most valuable trade secrets, repressive governments trying to stifle dissent, or foreign intelligence agencies trying to compromise our and our allies' most sensitive national security secrets."

Continue reading: Tech companies don't want police to receive encrypted phone data (full post)

Aussie cloud service gets the tick to serve its government

| May 18, 2015 6:07 AM CDT

In a world of leaked information and hacking sprees, Australian cloud services provider Macquarie Telecom has been the first ever of its kind to be approved on the government's list of providers thanks to its performance in the security standards testing.

With this accreditation approved by the Australian Signals Directorate (ASD), Macquarie Telecom's Managing Director Aiden Tudehope stated "the ASD was detailed and thorough and Macquarie is proud that out hard work has been recognized in this way." Tudehope added that the motive for this accreditation is quite reasonable as "our analysis shows governments are increasingly looking for a range of cloud computing services for different data classification use cases."

Further privatization of Government services can be good or bad depending on which way the situation is assessed and it's up to you to decide if you're happy with this movement or not. Either way, congratulations Macquarie Telecom for being the first of a kind.

Continue reading: Aussie cloud service gets the tick to serve its government (full post)

Kim Dotcom: Julian Assange will be Hillary Clinton's 'worst nightmare'

| May 14, 2015 10:34 PM CDT

Kim Dotcom has come out swinging, with the Megaupload founder announcing that the 2016 US presidential elections will see some heat coming up with WikiLeaks' founder Julian Assange having some "potential roadblocks" for Hillary Clinton.

Dotcom recently spoke with Bloomberg, where he said that Julian Assange will be Hillary Clinton's "worst nightmare" next year, and that he was "aware of some of the things" that would stop Clinton's rise to the Presidency. We could see a future where Dotcom and Assange work together, with Dotcom saying: "If I can can provide some transparency with these people and make them part of what the Internet Party stands for, then I will be happy to do that".

Later on in the interview, Dotcom added that "Hillary hates Julian, she's just an adversary of, I think, Internet freedom". Bloomberg's Emily Chang added "and she signed your extradition request", to which Dotcom replied with "Yeah, you know the crazy thing is I actually like Hillary, I like Obama... it's just so crazy that all of this happened".

Continue reading: Kim Dotcom: Julian Assange will be Hillary Clinton's 'worst nightmare' (full post)

The hunt for ISIS, other terrorists using Dark Web effectively

| May 13, 2015 12:23 PM CDT

An international coalition and ground troops are giving ISIS fits in Iraq and Syria, but the terror group is still finding success online. Using a blend of social media and the Dark Web, the group is able to spread propaganda, recruit new members, and communicate with one another - but the Pentagon is working harder to interrupt ISIS's digital efforts.

For example, DARPA hopes its MEMEX technology, which has the ability to serve as a unique search engine, is able to track down Dark Web sites.

"Everything above the water is what we would call the surface web that can be indexed through Google or you can find through a search engine," said Lillian Ablon, researcher at Rand, in a statement published by CNN. "But below the water that huge iceberg up to 80% times bigger than what's above the water, that's the deep web, that's the part of the web that's not indexed. There is so much of the web that we can't just Google for; it's dark to us, it's dark to Google."

Continue reading: The hunt for ISIS, other terrorists using Dark Web effectively (full post)

Federal appeals court rules NSA telephone surveillance program illegal

| May 7, 2015 5:33 PM CDT

The 2nd US Circuit Court of Appeals in Manhattan has asked Congress to find a middle ground between national security and citizens' privacy, after saying the National Security Agency's phone surveillance program went too far.

The court's ruling will put added pressure on Congress to either scrap the program entirely, or make major changes. Using the Patriot Act as a front for its massive data collection, the NSA reportedly collected information on almost every call made in the United States - with data entered into a national database. It remained secret until former NSA contractor Edward Snowden unveiled the illegal phone data sweeps.

"In light of the asserted national security interests at stake, we deem it prudent to pause to allow an opportunity for debate in Congress that may (or may not) profoundly alter the legal landscape," said Judge Gerard E. Lynch, as he announced the decision.

Continue reading: Federal appeals court rules NSA telephone surveillance program illegal (full post)

Lenovo criticized yet again for a major security vulnerability

| May 6, 2015 1:41 PM CDT

Lenovo, the No. 1 PC manufacturer based on units sold, is being accused of a "massive security risk" that allows hackers to utilize a man-in-the-middle attack to download malware onto victims' systems. Security researchers at IOActive say the vulnerability allows hackers to download malware or hijack the systems themselves.

The flaw takes aim at ThinkPad, ThinkStation and ThinkCenter products, and B, E, K, and V-series models. Lenovo was first alerted to the issue in February, and was given time to release a patch - which was made available last month - before IOActive shared the news publicly.

"An attacker can create a fake [certificate authority] and use it to create a code-signing certificate, which can then be used to sign executables," according to the advisory. "Since the System Update failed to properly validate the certificate authority, the System Update will accept the executables signed by the fake certificate and execute them as a privileged user."

Continue reading: Lenovo criticized yet again for a major security vulnerability (full post)

Join Our Newsletter

Join the TweakTown Newsletter for daily tech updates delivered to your inbox.

See previous giveaways.

Newsletter Subscription