Hacking, Security & Privacy - Page 23
Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 23
Stay Updated
Follow TweakTown for breaking tech news, reviews, and daily updates.
As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.
SentryBay shows off anti-keylogging solution for mobile users
Enterprise security company SentryBay has unveiled a new anti-keylogging solution designed for smartphones, tablets, and other mobile products. To help keep mobile users secure, the product generates a dedicated secure keyboard, keystroke encryption, screen capture protection, and the generation of fake random characters.
Both Google Android and Apple iOS cache user keypad entries, providing savvy hackers with the ability to monitor and uplift what is entered.
"We are pleased to announce these latest innovations," said Dave Waterson, CEO of SentryBay. "For a long time we have been a leader in PC-based anti-keylogging technology, but after years of R&D we finally feel the solution we have developed for mobile can provide the strong data entry security that app developers are looking for."
Continue reading: SentryBay shows off anti-keylogging solution for mobile users (full post)
Cybersecurity in full display during RSA Conference in San Francisco
Cybersecurity experts from around the world will descend on the Moscone Center in San Francisco for RSA Conference 2015 this week. The growing security industry is expected to be worth up to $20 billion within the next three years, as the US government and private sector companies purchase new software and hardware.
"Seven or eight years ago you could hear a pin drop at RSA," said Dan Ives, analyst at FBR Capital Markets, in a statement to FT. "Now it is going to be like a Bon Jovi concert. It is the seminal event in cybersecurity: the new year's eve, the wedding, the bar mitzvah."
A number of high-profile security incidents in 2013, 2014 and so far in 2015 have shown the need for next-generation cybersecurity solutions. More than $1 billion in venture capitalist funds have been invested in cybersecurity during Q1 2015 alone - and it appears more investors are preparing to flock to the market.
Continue reading: Cybersecurity in full display during RSA Conference in San Francisco (full post)
Cyber officials concerned of limited US network defense
US lawmakers and military officials are worried that their cyber abilities are still not advanced enough, especially in regards to cybersecurity, and want to increase efforts to recruit cyber warriors. The top Pentagon cyber official, Eric Rosenbach, confirmed he is concerned that the Cyber Command doesn't have a strong command and control platform that can launch strong offensive cyber weapons.
"Today I think we are, we could be, an easy target," said Air Force Lt. Gen. James McLaughlin, deputy commander of the US Cyber Command, in a recent statement to Capitol Hill.
The US military wants to create a group of 6,200 'cyber warriors' by the end of next year, working in 133 operational teams. Along with increasing manpower, US military leaders want to invest in new hardware and software that will give it an advantage against foreign governments.
Continue reading: Cyber officials concerned of limited US network defense (full post)
Study: Iran increasing cyberattacks, developing new cyber arsenal
The Iranian government has a growing cyber arsenal capable of launching more attacks against political rivals and foreign governments, according to the Norse cybersecurity firm and the American Enterprise Institute. Even with international sanctions, the country has been able to create tools used for reconnaissance and intelligence collection from compromised targets.
"Cyber gives them a usable weapon, in ways nuclear technology does not," said Frederick Kagan, director of the American Enterprise Institute's Critical Threats Project, in a statement published by the New York Times. "And it has a degree of plausible deniability that is attractive to many countries."
There is concern that Iran would spend even more money to help develop its cyberweapons - but the country has already continually improved its current attack capabilities. China and Russia have developed capable cyberattack efforts, but cybersecurity experts show the most concern that North Korea and Iran are trying to improve their hacking tools.
Continue reading: Study: Iran increasing cyberattacks, developing new cyber arsenal (full post)
Report: 29 million healthcare records compromised in past four years
There were at least 29 million US healthcare records stolen between 2010 and 2013 in data breaches, according to the Journal of the American Medical Association (JAMA). More than 58 percent of data breaches occurred by theft, with two-thirds of the incidents caused by electronic data that was stored on laptops, USB drives, and other portable media.
Stanford University and Kaiser Permanente researchers studied data breaches that involved at least 500 victims or more, so the 29 million figure could actually be even higher. It's also worth noting that some healthcare patients could have been victimized more than once, as some data may have been duplicated.
Cybersecurity professionals believe 2015 could be the year of healthcare record chaos, as Anthem suffered a breach - and more could be on the way.
Continue reading: Report: 29 million healthcare records compromised in past four years (full post)
Small businesses plagued by successful ransomware cyberattacks
Small businesses are a lucrative target for cybercriminals trying to launch ransomware malware attacks, and the problem is only getting worse. Careless employees are tricked, typically using phishing emails, and the custom malware encrypts various files - demanding a ransom payment or the files will be permanently encrypted.
"They set the ransom so low that, as violated as I feel and as much as I wanted to fight, at the end of the day I realized I can pay and get back to work," said Mark Stefanick, president of Advantage Benefits Solutions, in a statement published by the Wall Street Journal. Stefanick chose to pay the $400 ransom so files were quickly decrypted and his company could get back to normal operation.
Around 30 percent of ransomware victims choose to pay the ransom to end the cyberattack, according to Trend Micro chief cybersecurity officer Tom Kellerman. There were at least 250,000 new ransomware samples studied by Intel Security during Q4 2014, a whopping 155 percent increase quarter-over-quarter.
Continue reading: Small businesses plagued by successful ransomware cyberattacks (full post)
Hacker group from China has launched coordinated attacks for a decade
A hacker group with support from the Chinese government has operated for more than 10 years without being detected, able to compromise information from companies and reporters, according to FireEye. Many of the attacks started with social engineering, with victims unknowingly installing the Mysterious Eagle malware onto PCs - so the hacker group could remotely monitor and control the compromised systems.
The APT30 group has been in operation from 2004 and was able to collect information "about journalists, dissidents and political developments in relation to China targeting government and military organizations, and targeting economic sectors of interest to China's economy."
The Chinese government has long been accused of funding cybercriminal groups aimed at compromising western targets - much of the attention is focused on the US government and companies with US customers.
Continue reading: Hacker group from China has launched coordinated attacks for a decade (full post)
Cybersecurity expert applauds work done by ethical hackers
Most headlines featuring hackers tend to focus on cybercriminals trying to breach security protocols for criminal gain - but there is a growing effort to support "white hat" hackers working in an ethnical manner to find security bugs.
"There are actually a lot of good hackers out there that are revealing vulnerabilities and bugs in technology that we all rely on," said Keren Elazari, analyst for GigaOM Research, while speaking during the Atlantic Security Conference, in a statement to CBC's "Mainstreet" program. "A lot of companies are still kind of reluctant to open their doors to hackers... that's something I'm trying to change."
Google, Facebook, Tesla, and other companies rely on so-called "bug bounty" programs that provide cash and other incentives for coders. It can be difficult for internal programmers to try to work out bugs and vulnerabilities in their own software, so having outside help can be critical.
Continue reading: Cybersecurity expert applauds work done by ethical hackers (full post)
Gartner: Security analytics could be crucial for breach detection
Even with companies spending more on cybersecurity efforts, data security breaches are at an all-time high, the Gartner research group recently said.
However, these high-profile breaches are finally sounding alarm bells among C-level executives - and they may be desperate to spend money - but aren't really sure what they are buying and trying to implement.
The number of security information and event management (SIEM) solutions leads the way in regard to cybersecurity, collecting, saving and analyzing security data. However, trying to sort through all of that data remains rather confusing, but security analytics technology is maturing.
Continue reading: Gartner: Security analytics could be crucial for breach detection (full post)
Former Canadian spy boss says cyberattacks are a 'weapon of war'
Cybersecurity is a complicated issue that has serious ramifications for the United States and other countries that aren't focusing enough attention on the matter. More national governments are developing programs to attack political rivals, in an effort to steal information and cause data breaches.
"Cyber is a weapon of war," said Ray Boisvert, former head of intelligence for the Canadian Security Intelligence Service (CSIS), in a statement to The Register. "The NASDAQ and Home Depot hacks are examples of this."
There are around 60 countries involved in various forms of cyberespionage, including terrorist groups like Hezbollah, according to US assistant secretary of defense for Homeland Defense and Global Security, Eric Rosenbach. Boisvert thinks that number is accurate, though much of the attention is focused on Russia and China.
Continue reading: Former Canadian spy boss says cyberattacks are a 'weapon of war' (full post)
Russian government giving cybercriminals advanced malware software
Russian intelligence agents are now sharing sophisticated malware created for cybercriminals and organized crime to use in their efforts to conduct cyberespionage.
"Russian nationalism and organized crime are being assisted by Russian state security," said Ray Boisvert, former assistant director and the head of intelligence for the Canadian Security Intelligence Service (CSIS), in a statement to The Register. "The red lines have gone because of Ukraine. Organized crime is being told they can disrupt Western interests."
Russia has been accused on multiple occasions of providing support to organized crime and hacker groups, willing to conduct cyberattacks against foreign targets. However, trying to catch perpetrators and hold them responsible for data breaches, cyberespionage, and other similar crimes is extremely difficult for US authorities.
Continue reading: Russian government giving cybercriminals advanced malware software (full post)
Symantec: Hackers had a great year in 2014, looking to improve in 2015
Cybercriminals had an extremely successful year in 2014, and are constantly looking for new ways to compromise businesses and users. Last year saw "far-reaching vulnerabilities, faster attacks, files held for ransom and far more malicious code than in previous years," according to the Symantec 2015 Internet Security Threat Report - and information security is becoming more important for companies.
There were 317 million new pieces of malware written in 2014, while ransomware attacks aimed at breaching user files increased 113 percent. Data breaches remained a major problem, with millions of US consumers compromised, as the total number of incidents increased 23 percent.
"The criminals are getting better," said Kevin Haley, director of security response at Symantec, in a statement published on NBC News. "Success breeds success and other criminals want to get into the game, so we need to step up our game in terms of protecting our information and keeping it safe."
Continue reading: Symantec: Hackers had a great year in 2014, looking to improve in 2015 (full post)
Aircraft could be vulnerable to cybercriminals, GAO report says
The Government Accountability Office (GAO) is showing increased concern that hundreds of commercial aircraft are vulnerable to possible cyberattack from remote operators. If done successfully, hackers would be able to possibly install malware on flight control computers, take over control of the aircraft, compromise navigation systems and warning systems.
Air traffic control also is increasing to support Internet-based solutions, giving criminals another pipeline to tamper with flights. The House Transportation and Infrastructure Committee and several senators wish to read over the full GAO report - and expect the Federal Aviation Administration (FAA) to make necessary security protocols mandatory.
"Modern communications technologies, including IP connectivity, are increasingly used in aircraft systems, creating the possibility that unauthorized individuals might access and compromise aircraft avionics systems," the GAO report says. That level of IP connectivity, however, is what could create a link between aircraft and cybercriminals - posing a threat to the aircraft, its crew and passengers.
Continue reading: Aircraft could be vulnerable to cybercriminals, GAO report says (full post)
Kaspersky Lab helps provide CoinVault ransomware victims more options
Victims of the CoinVault ransomware have another option when trying to retrieve information - and not paying a ransom to hackers. Cybersecurity company Kaspersky Lab has partnered with the National High Tech Crime Unit (NHTCU) of the Netherlands' police, providing decryption keys and a decryption application online.
Using information collected from a CoinVault command & control server, Kaspersky Lab, NHTCU and the Netherlands' National Prosecutors Office hope victims will be able to retrieve files without paying a ransom.
"If you get infected with the CoinVault ransomware, please check noransom.kaspersky.com," urged Jornt van der Wiel, security researcher for the global research and analysis team at Kaspersky Lab. "We have uploaded a huge number of keys onto the site. If we do not currently have records for a particular Bitcoin wallet, you can check again in the near future, because together with the National High Tech Crime Unit of the Netherlands' police we are continuously updating the information."
Continue reading: Kaspersky Lab helps provide CoinVault ransomware victims more options (full post)
Phishing is easy way for hackers to victimize users with cyberattacks
Phishing remains a successful social engineering tactic used by cybercriminals, taking just 82 seconds to catch the first victim, according to a new report compiled by Verizon. An unfortunately alarming number of 25 percent of phishing email recipients are likely to open the fraudulent email - and trying to educate employees remains difficult for companies.
Instead of worrying about using a complicated software exploit, it's easier - and extremely effective - for hackers to just phish a victim and get them to turn over usernames and passwords. Companies that properly teach their employees to identify and avoid phishing emails reduce their likelihood of falling victim from one in four down to one in 20, according to researchers.
"They should be treating employees as tools in the fight rather than as lambs to the slaughter," said Bob Rudis, lead author of the Verizon report, in a statement published by BBC.
Continue reading: Phishing is easy way for hackers to victimize users with cyberattacks (full post)
Pedophiles using 'dark net' to avoid police detection with success
Pedophiles are adapting their habits and using the so-called "dark net" to find children to exploit, while creating new business opportunities.
Even though most people use the dark net to avoid government detection, 80 percent of traffic to dark net sites were believed to be related to child pornography, according to a recent British research study. There is an increased effort to prevent this type of dark net use, but cybersecurity experts believe the problem is just getting worse.
"It was just an awful realization, discovering there were tens of thousands of people who are not only trading child pornography, but planning to exploit children," said Greg Virgin, a cybersecurity consultant, in a statement published by CBS News. "We found one site where users openly advertised the ages of the children they were interested in. The average youngest age they were seeking for girls was zero years old. And the average age for boys was one."
Continue reading: Pedophiles using 'dark net' to avoid police detection with success (full post)
US looking to re-establish technological edge, focus on cybersecurity
As part of the US Defense Department's "Better Buying Power 3.0" initiative, the government wants to see closer relationships forged with the private sector. The main goal of the program is to make sure the US doesn't lose a technological edge over foreign adversaries, as the DoD dumps money into new R&D efforts.
A major effort will focus on keeping next-generation weapons technology and defense systems secure from cyberattacks - something that is of major concern, especially from China, Russia, and other countries with sophisticated cyber militaries.
"It includes the industrial base that supports us and their databases and their information," said Frank Kendall, undersecretary of defense for acquisition, technology and logistics, in a statement. "It includes what we hold in government. It includes the logistics support information, the sustainment information, the design information, the tactical information. Everything associated with the product is a potential point of attack. And we are under attack in the cyber world, and we've got to do a better job protecting our things."
Continue reading: US looking to re-establish technological edge, focus on cybersecurity (full post)
Europol, FBI successfully shuts down Beebone malware
The Europol Cybercrime Centre and the FBI teamed up to bring down the Beebone botnet, a custom operation that installed malware on unknowing victims. At least 12,000 machines were infected - with an estimate up to 100,000 zombie PCs - hijacked by cybercriminals. The malware was used to collect stolen passwords and download third-party applications onto victim PCs, officials noted.
"The fact that it [the malware] is complicated suggests that it could be used for more targeted attacks," said Paul Docherty, director of Portcullis Security, recently told the BBC. "If those responsible were able to harness similar difficult-to-detect code they could potentially move the point of attack from home users to corporate users or other entities which typically hold large amounts of sensitive, valuable data."
The polymorphous malware utilized its unique ability to change its "shape" so it was better able to evade cybersecurity defenses - and continue hijacking new users.
Continue reading: Europol, FBI successfully shuts down Beebone malware (full post)
NSA boss now wants 'front door' access to your PC
The NSA has virtually got unrestricted access to most users data, but that doesn't stop the US spy agency from wanting more. NSA chief Michael Rogers has now called for a "front door" encryption key that would provide the NSA with access to your data, but the key would be broken into multiple parts so that no one agency or person could easily get in.
This method would theoretically stop thieves from getting in and taking your data, but it would let government officials access your data at any time, if they have 'permission'. The White House is considering the move, along with others like letting courts order the creation of mirror accounts, so that US agencies can access any and all messages as they arrive, or so that they can back up the data as it's unencrypted. President Obama is considering these new policies, where he should receive a report by the end of the month, with the possibility of a new policy revealed shortly after.
Rogers' solution isn't a one key fits all scenario, with fellow institutions like the National Institute of Standards and Technology against the idea. They note that any door that is introduced would arrive with security holes, even if a split key is created. US agencies like the FBI and NSA don't like widespread encryption because it works so well, but it only works as long as there are key holders that won't just provide the key when asked, or requested.
Continue reading: NSA boss now wants 'front door' access to your PC (full post)
Google is indexing files from some private network-connected HDDs
An investigation that CSO Online conducted has found that if you do not have your network-connected HDDs configured correctly, your files could be ending up in the wrong hands.
Their report stated that some personal cloud devices with external HDDs connected to routers with FTP enabled have been indexed by Google, which has seen personal files found on the Internet, and on search results. This includes very personal data such as emails, journal entries, passports, tax records, financial statements, mortgage documents, passwords, private photos and more.
The organization was able to map a family's personal and financial history all the way back to 2009 just by searching their name as their data was archived on a Western Digital HDD that they had connected through a Linksys WRT1900AC router. But when the family was warned about this, it was too late. The family noted: "I simply could not figure out how someone got the [card] info minutes after I'd activate them. My system was clean and secured more than the average person," said one member of the family. Now I know. [It's not] difficult when my backups were public and being indexed on Google".
Continue reading: Google is indexing files from some private network-connected HDDs (full post)


