Hacking, Security & Privacy - Page 22
Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 22
Stay Updated
Follow TweakTown for breaking tech news, reviews, and daily updates.
As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.
Hacker discusses his role in helping 'king of revenge porn'
Hunter Moore, the "king of revenge porn," hired Charlie Evens when he was 23-years-old to hack into women's social media and email accounts. Evens sold images and videos for Moore's website, IsAnybodyUp.com, making between $500 and $1,000+ a week for his services.
It wasn't anything personal against the women that made their way to IsAnyoneUp, as Evens was fresh out of rehab and needed money to fund partying: "It was enough. I mean, not that anything is enough, but it's just scary how quickly I would drop my morals for so little. How much those women were worth, it was like $500 a week, $1,000 a week. It was just pay. I mean it was really just my habit. Like I needed to drink... I know nobody wants to hear that, but it was a really shitty time for me," Evens told CNN.
Evens also discussed how hacking victims was "a little maneuvering and manipulating... lying and using people" to breach their email or social media. His crimes led him to be indicted by the FBI for conspiracy, unauthorized access to a protected computer, and aggravated identity theft. The former hacker says he still battles with how he can apologize to the countless people whose private information was posted online without their permission.
Continue reading: Hacker discusses his role in helping 'king of revenge porn' (full post)
Report: 1 out of every 5 Google Android apps are malware in disguise
Even though mobile malware targeting the Google Android operating system is increasing, actual infection rates are still relatively low, according to cybersecurity experts. Unfortunately, it looks like almost 1 out of every 5 Android apps were "malware in disguise," according to the newest Symantec Internet Security Threat Report.
Over one-third of all Android apps are "madware," or "grayware," designed to increase the number of ads that a mobile user sees. In addition, Symantec noted the first infection by mobile ransomware, which encrypts data on a victim's phone until a ransom is paid.
Android, the No. 1 mobile OS based on market share, has an open infrastructure that makes it even more flexible to use by each phone manufacturer - but also gives cybercriminals the ability to create better malicious apps.
Continue reading: Report: 1 out of every 5 Google Android apps are malware in disguise (full post)
Damballa: Mobile malware infections overhyped in US
There might be numerous instances of mobile malware in the wild, but the matter is overhyped and not as frightening as perceived, according to advanced threat detection firm Damballa. It turns out you're more likely to be struck by lightning than suffer a mobile malware infection.
In network traffic monitored in 2014, 9,688 of 151 million mobile devices tried to access black list domains from mobile devices. Mobile operators are focusing more on security for smartphones and tablets, which is making it more difficult for malicious apps to compromise devices.
"This research shows that mobile malware in the United States is very much like Ebola - harmful, but greatly over exaggerated, and contained to a limited percentage of the population that are engaging in behavior that puts them at risk for infection," said Charles Lever, senior scientific researcher at Damballa.
Continue reading: Damballa: Mobile malware infections overhyped in US (full post)
Criminals receiving bitcoin ransom payments converting money fast
Cybercriminals launching ransomware attacks typically demand immediate payment with very little paper trail - and that often means relying on bitcoin transactions. However, the anonymity of bitcoins is now being overlooked due to the volatility of the cryptocurrency, with hackers converting the funds quickly.
The cyber group responsible for infecting users across the world with Cryptolocker likely made over $3 million before it was targeted by investigators. Besides pre-paid cash cards, bitcoins - which were once valued at more than $1,100 each, but now worth less than $250 - make it less appealing for money laundering behavior.
"I've seen this discussion in underground forums among Russian criminals," said Etay Maor, senior fraud prevention strategist of IBM Security, in a statement to The Register. "They use Bitcoin for the money laundering part and take payment with it, but they'll move it out almost immediately. Most of them won't keep bitcoins - they don't like the valuations Bitcoin has - so they just use it as a layer of obfuscation, and move it to a different form of money."
Continue reading: Criminals receiving bitcoin ransom payments converting money fast (full post)
Cybersecurity market receiving strong boost from increasing VC funds
Venture capitalists are pouring money into cybersecurity companies, with high-profile data breaches still capturing headlines. Security companies supported by VCs in the United States generated a massive $1.77 billion in 2014, a figure higher than the previous record of $1.62 billion generated in 2000, according to statistics.
There is increased flexibility in the cybersecurity sector, with companies providing protection to consumers, corporations, hardware infrastructure, software, and specialized niche services.
As the Internet of Things (IoT) generates headlines for its beneficial flexibility for consumers, there is an underlying concern related to connected security. "It's a huge threat," said Alex Doll, founder of the TenEleven Ventures capital firm focusing on information security, in a statement to the Wall Street Journal. "It's great that everything is connected, but all that data is one click away" from being hacked.
Continue reading: Cybersecurity market receiving strong boost from increasing VC funds (full post)
Following more data breaches, consumers learning to pay attention
Continued cyberattacks against US residents rack up an impressive number of victims, with twice as many Americans reporting a breach following year-over-year statistics analysis. Unfortunately, one in five consumers say they suffered a credit score hit due to identity theft - and financial experts recommend shoppers request a credit report to check on any problems.
However, eight in 10 Americans note they have become more proactive in protecting their own personal information, as more than half of surveyed consumers aren't entirely sure if companies can keep personal data safe.
"The increase in data breaches affecting personal information has given consumers significant cause to be cautious about their activities, both online and off," said Ernie Almonte, chairman for the American Institute of CPA's National CPA Financial Literacy Commission, in a statement published by MoneyWatch.
Continue reading: Following more data breaches, consumers learning to pay attention (full post)
US government cracking down, says 'no more free passes' to hackers
The United States government understands it is a prime target for cybercriminals across the world, especially organized crime and state-sponsored hackers trying to conduct cyberespionage. John Carlin, Assistant Attorney General for National Security, spoke during RSA about the mentality of teaching foreign actors "that it is not okay to steal from American companies."
Even though the NSA has sophisticated cyberespionage capabilities, the government didn't pay enough attention to keeping critical infrastructure secure. The government is trying to catch up and will make changes, but is ready to put political and economic pressure on select governments for their cyber actions.
However, there are more aggressive tactics possible, including the indictment of five senior leaders of the People's Liberation Army (PLA) in China last year - and economic sanctions placed on North Korea for its reported involvement in hacking Sony.
Continue reading: US government cracking down, says 'no more free passes' to hackers (full post)
Federal government trying to compete with private sector for workers
The US government wants to improve its cybersecurity and recruit skilled workers, but is struggling because of lackluster recruitment programs leading to an underwhelming cybersecurity labor pool, according to the Partnership for Public Service and Booz Allen Hamilton.
In 2014, there were almost 70,000 cyber intrusions that negatively impacted the governments' networks and systems, the Government Accountability Office (GAO) reported earlier in the year.
"Our interconnected world requires a seamless team of cyber defenders to protect our networks," according to the report. "Those defenders must be able to operate quickly and collaboratively in ways that cut across both private and public organizations."
Continue reading: Federal government trying to compete with private sector for workers (full post)
reTXT Labs launches ultra secure, simple to use mobile messaging app
reTXT Labs recently launched reTXT, a secure and private mobile messaging app, so users have more control of text messages. The messaging service uses end-to-end encryption to help make sure outsiders are not likely to be able to snoop on messages. It's a unique offering for consumers, as most of the security-focused messaging services are designed more for the corporate world.
reTXT users can edit sent messages, delete sent messages, clarify any misunderstood messages, name group message threats, and opt in or out of group messages. In addition, it's even easier to send photo and video messages or use a device's microphone to send voice messages, the company noted.
"The tools we provide make texting and messaging easier for the person who communicates privately with family, friends and colleagues every single day," said Kevin Wooten, co-founder and CEO of reTXT Labs.
Continue reading: reTXT Labs launches ultra secure, simple to use mobile messaging app (full post)
FireEye: Becoming even harder to identify and track cybercriminals
Cybercriminals, largely motivated by breaching networks to steal money and collect personal information, are becoming more difficult to identify, according to a leading cybersecurity expert.
"In 2010, when responding to breaches, almost every time we'd look at the evidence and we kinda knew who [the hackers] were," said Kevin Mandia, president of FireEye, in a statement published by Re/Code. "Right now we're starting to get more groups that we're labeling unknown. We have like 400 of them."
There is increased focus on cybersecurity, but trying to accurately identify and track threat actors - while preventing them from breaching networks - is an extremely complex issue. Unfortunately, companies must realize that they are likely to suffer a data breach at some point, and should focus more on breach crisis to ensure they can bounce back as quickly as possible.
Continue reading: FireEye: Becoming even harder to identify and track cybercriminals (full post)
South Korea constantly battling North Korea in growing cyber war
The South Korean government believes they have found evidence that shows North Korea is behind cyberattacks aimed at its financial sector and nuclear operators. The malicious code was designed to delete files from infected PCs, which prevented banking customers from transferring money online or withdraw money in-person.
"The malicious codes used in the attack were same in composition and working methods as 'Kimsuky' codes known to be used by North Korea," according to the South Korean prosecutor's office, and noted by CNN. In addition, some IP addresses were traced back to Shenyang, China, which is along the border between China and North Korea - with North Korea reportedly relying on China's more established Internet infrastructure to launch attacks.
North Korea's growing cyber ability tends to be focused on South Korea, with financial institutions, nuclear power operators, and private sector companies all targeted in the past.
Continue reading: South Korea constantly battling North Korea in growing cyber war (full post)
The Media Trust shows off SaaS-based tool to identify malvertising
The Media Trust, a cybersecurity firm focused on monitoring and protecting the advertising ecosystem, has unveiled a new software as a service (SaaS) offering able to provide real-time data about malicious ads.
Resolution Services is designed for use by ad networks, publishers, ad exchanges, paid-content engines and demand platforms, and scans for malware detection - providing faster remediation time if something is detected.
"Every day the ad-network-and-exchange model proves its worth as evidenced by the millions of ads successfully served in just one 24-hour cycle, but the constant threat of malvertising requires continuous improvement and greater collaboration across the industry," said Chris Olson, co-founder and CEO of The Media Trust.
Continue reading: The Media Trust shows off SaaS-based tool to identify malvertising (full post)
Webroot: Cybercrime complexity increasing, making things even harder
There are 85,000 new malicious IPs launched daily, while technology companies and financial institutions endure the highest number of phishing attacks, according to the Webroot 2015 Threat Brief. The United States has the most malicious IP addresses with 31 percent, ahead of China (23 percent), and Russia (10 percent) - with half of all malicious IP addresses tracing back to Asia.
The United States hosts the most amount of phishing sites, accounting for three out of every four - even though experts believe foreign operators could be utilizing US-based sites for their operations.
"Webroot has seen a continued rise in the number of malicious URLs, IP addresses, malware, and mobile applications used to enable cybercriminals to steal data, disrupt services, or cause other harm," said Hal Lonas, CTO at Webroot.
Continue reading: Webroot: Cybercrime complexity increasing, making things even harder (full post)
Cybersecurity researchers say Israeli military networks breached
Unknown Arabic-speaking hackers have successfully breached Israeli military computer networks, in an ongoing cyberespionage campaign, according to enterprise cybersecurity firm Blue Coat Systems. The hackers pieced together an effective attack vector by using existing malware that was launched via social engineering attacks to compromise victims.
The use of social engineering and code that wasn't customized allowed the hackers to operate with low overhead, while still being able to complete their mission. The phishing emails were sent to publicly listed military addresses, promising a breaking military news update, or a video clip of the "Girls of the Israel Defense Forces."
Israel has a strong private sector focused on cybersecurity, but faces a growing number of enemies improving their cyberattack abilities. Groups such as Hezbollah, for example, are able to launch surprisingly sophisticated cyber missions aimed at stealing information and interrupting military operations.
Continue reading: Cybersecurity researchers say Israeli military networks breached (full post)
Report: Need better breach crisis? IT manager may not be best bet
Companies must have a strategy in place when a data breach occurs, and it looks like IT managers may not be best to handle a breach crisis, according to a new report by Booz Allen Hamilton. Instead, a business savvy leader at the company is better prepared to handle the problem, as they will be prepared to address crisis communications, legal issues, disaster recovery, and other strategic decisions that must be made.
A skilled executive that has a high-level view of the company's complete operation will be able to react more efficiently instead of an IT or security manager.
"They may have to shut the systems down, reconfigure things, and do other things that will affect the business," said Bill Stewart, executive vice president of Booz Allen Hamilton, in a statement published by CSO Online. "And they might not be in a situation where they understand the broader business objectives. Having someone who understands the broader business, helps them make better decisions."
Continue reading: Report: Need better breach crisis? IT manager may not be best bet (full post)
The race is on to help develop cybersecurity for Internet of Things
There are more than 16 billion connected computing devices in use across the world today, with even more Things expected to utilize the Internet of Things (IoT) in the future.
Cybersecurity experts are concerned about a large number of threats, with 83 percent worried about rogue or unauthorized devices operating undetected in their networks, according to a recent survey by Pwnie Express. To make matters even worse, 69 percent of cybersecurity professionals cannot access full wireless visibility of devices, so it's difficult to identify what is actually connected.
As more companies and users embrace IoT, there is concern that the Internet of Evil Things (IoET) will find countless vulnerabilities to exploit in the future.
Continue reading: The race is on to help develop cybersecurity for Internet of Things (full post)
Cheetah Mobile: 99% of Android phone users faced a potential threat
A whopping 99 percent of Google Android phone owners faced a potential threat from cybersecurity loopholes, according to the Cheetah Mobile 2014 Mobile Security Report.
Mobile users faced a number of different phishing scams, malware attacks, and data leaks in 2014 - and social network phishing is evolving, posing even more threats that users should be aware of.
Android, the most popular mobile operating system, has been applauded for its open source ecosystem - which also gives cybercriminals the ability to easily create malicious tools. Cybersecurity experts recommend running an anti-malware scanner, at the very least, to help identify potential threats that could be avoided.
Continue reading: Cheetah Mobile: 99% of Android phone users faced a potential threat (full post)
Report: Better cybersecurity, safety standards needed for patient data
Cybercriminals find healthcare data to be an appealing target, as medical records contain a large amount of personal information. There is a drastic need for better cybersecurity protocols - and how hospitals and other medical agencies handle paper and electronic records.
Thirty four percent of reported medical data breaches over the past three years took place in California, Florida, Texas, New York and Illinois - with a mix of healthcare system partners, insurers, and other third parties helping contribute to the problem.
"News of hacking incidents and cybersecurity [breaches] have been in the news so much lately, [that] both for industries inside and outside healthcare, one might get the impression that hacking is the most common reason for data breaches," said Dr. Vincent Liu, from the division of research for Kaiser Permanente, in a statement to Medpage Today. "In fact, we found that theft of paper or electronic records accounted for the majority - protecting the security and privacy of patient data needs to be a priority in many different venues, and with all types of patient data, including paper records."
Continue reading: Report: Better cybersecurity, safety standards needed for patient data (full post)
Cryptzone: Insider threats still pose biggest threat to companies
Insider threats remain a significant threat to corporations, causing the most actual damage and harm, according to a recent survey published by the Cryptzone cybersecurity firm.
"It's remarkable that many organizations are still utilizing network security technologies developed in the nineties - a time when the Internet was still in its infancy," said Kurt Mueffelmann, president and CEO of Cryptzone. "The cyberattacks we have seen over the last few years have demonstrated that it's far too easy for hackers to steal user credentials, and then use those credentials to traverse the enterprise network in search of the most valuable data."
Forty-eight percent of respondents said IT departments are main controllers related to cybersecurity policy, 36 percent said information security owns policy control, and 12 percent noted compliance or risk management teams are responsible for security policies.
Continue reading: Cryptzone: Insider threats still pose biggest threat to companies (full post)
Expert: Cyberattacks on nuclear power plants could be next 9/11
Cybercriminals are finding security vulnerabilities that allow them to target critical infrastructure like electric grids, and could also begin targeting nuclear power plants, according to a cybersecurity specialist in Israel.
"The disruption and possible infiltration of critical infrastructure is the most severe form of cyberattack," said Col. Dr. Gabi Siboni, director of the cyber security program at the Institute for National Security Studies program, in a statement to the Jerusalem Post. "Such attacks on airplanes or air traffic control towers, for instance, means that hackers could cause accidents, or even paralyze entire flight systems. As of now, this area of capabilities is the exclusive domain of developed states."
The United States, UK, Israel, South Korea, and other nations have expressed concern related to critical infrastructure cybersecurity. Recently, South Korea - which has blamed North Korea - suffered a breach at its national nuclear plant operator, though quickly confirmed its 23 atomic reactors weren't at risk.
Continue reading: Expert: Cyberattacks on nuclear power plants could be next 9/11 (full post)


