Hacking, Security & Privacy - Page 24
Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 24
Stay Updated
Follow TweakTown for breaking tech news, reviews, and daily updates.
As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.
Cyber Caliphate hacks French TV network TV5Monde
TV5Monde in France suffered a major cyberattack that led to hijacked websites and social media accounts, along with causing a three-hour broadcast blackout. The Cyber Caliphate, a pro-ISIS hacker group, didn't take public responsibility for the attack - but pro-ISIS images and "hacked by an Islamist group" markings were left on compromised accounts.
"We are no longer able to broadcast any of our channels. Our websites and social media sites are no longer under our control and are all displaying claims of responsibility by Islamic State," said Yves Bigot, TV5Monde director general, told the AFP.
France's culture minister will host an emergency meeting with major French media groups so they are able to study their cybersecurity protocols. A terrorism investigation has been opened by the Paris prosecutor's office following the cyberattack, which is the most sophisticated shown by the Islamic State.
Continue reading: Cyber Caliphate hacks French TV network TV5Monde (full post)
Businesses struggle to fight against ransomware cyberattacks
Ransomware infections tend to be a frightening scenario for businesses often caught off-guard when an employee mistakenly compromises a workplace machine.
Cybersecurity experts are increasingly worried about ransomware, one of the fastest rising hacker-related crimes, which demands a ransom payment in exchange for files held hostage. The traditional method of infection is a malicious file attached to an email, but criminals are finding ways to point victims to hijacked websites.
Unless home users or companies have data backed up, and are careful of emails opened and websites visited, ransomware can prove especially catastrophic. Even though US government and private sector cybersecurity experts warn against paying ransoms, many companies choose to pay the ransom and move on.
Continue reading: Businesses struggle to fight against ransomware cyberattacks (full post)
Russian government blamed for hacking White House in cyberattack
The Russian government is being blamed for hacking into a computer system used by the White House, and the hackers were able to view classified information. It's possible the cyber intrusion, with alleged ties to the US State Department breach, was in retaliation for sanctions against Russia.
However, White House officials didn't specifically single out Russia for launching the cyberattack - but there is an active investigation by the Secret Service, FBI and US intelligence agencies. "In this case, as we made clear at the time, we took immediate measures to evaluate and mitigate the activity," said Mark Stroh, National Security Council spokesman. "As has been our position, we are not going to comment on [this] article's attribution to specific actors."
Not surprisingly, the Kremlin has issued a statement saying Russia is a constant scapegoat for organized cyberattacks: "In regard to CNN's sources, I don't know who their sources are," said Dmitry Peskov, spokesman for Russian President Vladimir Putin, in a statement published by RT. "We know that blaming everything on Russia has already turned into some sort of sport."
Continue reading: Russian government blamed for hacking White House in cyberattack (full post)
Potential US president Rand Paul unveils his "NSA spy cam blocker"
Senator Rand Paul has announced that he is intending to run for the position of the President of the United States in 2016, but the video of his announcement has been removed from YouTube because it contained a song that had a copyright claim filed on it.
Between now and then, Rand supporters can get behind the Senator with the usual yard signs, bumper stickers and more, but he has something that has never been seen before: an "NSA spy cam blocker". The NSA spy cam blocker is a $15 device with a huge "RAND" logo on it, with the listing on it explaining it as "That little front-facing camera on your laptop or tablet can be a window for the world to see you-whether you know it or not!"
The NSA spy cam blocker is 1.5mm thick, and is "made with high-grade plastic" and is designed for anything with a front-facing camera on it such as a laptop, smart TV and Xbox Kinect. It sports a plastic slider that will block the camera from working on your laptop for example, and then when you need it back, you slide the NSA spy cam blocker to the right to use your webcam once again.
Continue reading: Potential US president Rand Paul unveils his "NSA spy cam blocker" (full post)
The government has control of your naughty selfies, Snowden says
In a discussion on Last Week Tonight, Edward Snowden told comedian John Oliver about how we can think about the governments surveillance of citizens in a more relatable manner.
It is often discussed that the general population isn't up in arms about breaches of sensitive data as they can't closely relate with exactly whats going on. In an attempt to educate some, Oliver took a new approach as spotted on News.com.au.
Talking to Americans on the street, Oliver showed us that there was quite a number of people who weren't exactly sure who Snowden was - often confusing him for Wikileaks founder Julian Assange. He then asked how people would feel if their naughty 'nudes' were available for the taking.
Continue reading: The government has control of your naughty selfies, Snowden says (full post)
MI6 admits the difficulties of trying to keep up with cybercriminals
There is a technology arms race currently underway between the US and UK governments trying to compete against cybercriminals and terrorists using the Internet effectively. Cybercriminals are increasingly organized, some of them state-funded, and able to launch sophisticated attacks easily.
During a recent speech, MI6 officials said agents are trying to battle against opponents "unconstrained by consideration of ethics and law," able to more easily put the UK at risk. Although espionage can be easier to track due to technological footprints, it also opens the door to cyber mercenaries able to share and launch coordinated attacks.
"Using data appropriate and proportionately offers us a priceless opportunity to be even more deliberate and targeted in what we do, and so be better at protecting our agents and this country," said Alex Younger, chief of the Secret Intelligence Service (MI6).
Continue reading: MI6 admits the difficulties of trying to keep up with cybercriminals (full post)
IBM outs cybercriminal group running 'Dyre Wolf' scam
A well-organized Eastern European cybercriminal group is using social engineering that includes phishing and phone calls paired with malware to steal money from US businesses. IBM, which discovered the surprisingly sophisticated operation, call it "The Dyre Wolf" - and while the group has netted just $1 million so far - the organization of the group is rather alarming.
Once victims click on a fraudulent link or attachment, the malware is installed and waits for users to access a bank website. Instead of going to the bank's website, a fake screen says the bank website is down, so victims have to call a phone number. Once dialed, victims turn over bank information and a large money wire transfer is initiated by the criminals.
"What's very different in this case, is we saw a pivot of the attackers to use a set of social engineering techniques that I think are unprecedented," said Caleb Barlow, VP of IBM Security, in a statement to Reuters. "The focus on wire transfers of large sums of money really got our attention."
Continue reading: IBM outs cybercriminal group running 'Dyre Wolf' scam (full post)
NSA finding it harder to recruit specialists following Snowden leaks
The National Security Agency (NSA) should be able to find itself 1,600 new recruits in 2015, with a heavy focus in computer science and math, but the task is getting harder. A combination of rising Silicon Valley tech employment/salaries mixed with Edward Snowden's intelligence leaks have damaged trust in the NSA from the public - and possible job recruits.
The NSA has around 35,000 employees across the country, and trying to compete against tech companies to recruit employees from leading universities is proving difficult. A lack of trust is a major issue that is making some people think-twice before trying to land a job with a security clearance.
"Before the Snowden leaks we looked at the NSA as being a spy agency, and they did what they were supposed to do," said Matthew Green, assistant research professor at the Johns Hopkins Information Security Institute, in a statement to NPR. "But we've learned that they've been collecting this incredible amount of information. And they're not shy about doing whatever they have to do to get access to that information."
Continue reading: NSA finding it harder to recruit specialists following Snowden leaks (full post)
Details how Pakistan arrested one of the most wanted cybercriminals
Following an international manhunt dating back two-and-a-half years, the FBI's most wanted cybercriminal was captured in Pakistan earlier this year. Noor Aziz Uddin, a 52-year-old responsible for spearheading a global phone fraud ring, was one of the FBI's most wanted cybercriminals.
Despite traveling between the United Arab Emirates, Malaysia, Pakistan, Italy and New Jersey, Uddin's ability to hide began to unravel after federal Pakistani authorities received a phone number reportedly linked to him. The Federal Investigation Agency in Pakistan was able to use the phone's GPS coordinates, with help from Uddin's wireless service carrier, to pinpoint his exact location.
The arrest occurred successfully without any violence.
Continue reading: Details how Pakistan arrested one of the most wanted cybercriminals (full post)
Survey: 30% of companies would pay ransom to cybercriminals
Employees infected with ransomware often panic and paying a ransom to the cybercriminals typically is easier than trying to restore files. The problem is a tad bit more complicated, because criminals are hacking files and forcing companies to choose between paying or suffering a data breach. Thirty percent of organizations would pay or negotiate a release of encrypted data, according to ThreatTrack.
Interestingly, that number goes up to 55 percent for companies that have suffered a similar incident in the past - revealing the need for proper employee education.
It's unknown how many companies actually suffer an extortion scheme, with many companies likely not reporting issues to the public or to law enforcement, said Stuart Itkin, SVP of ThreatTrack. Cyber extortionists are becoming better skilled, so trying to figure out how to negotiate with them is a struggle.
Continue reading: Survey: 30% of companies would pay ransom to cybercriminals (full post)
Free-speech group says China has weaponized its 'Great Firewall'
The GreatFire free-speech group says the Chinese government is using its incredible Internet infrastructure to launch cyberattacks. Many national governments are modernizing their cyberattack capabilities, and China is notorious for targeting political opponents.
GreatFire itself suffered a major distributed denial-of-service (DDoS) attack, and now GitHub and other companies are facing sophisticated cyberattacks. Not surprisingly, the Chinese government didn't respond to GreatFire accusations, though officials previously accused the group of being "anti-China."
If true, this is a new strategy from the Chinese government, which has been long suspected of organized cyberespionage. "The last couple months, we've seen a real sea change in Chinese Internet policy, where they've become more assertive about blocking Western sites and pushing back on their citizens' ability to access information from outside the country," said James Lewis, senior fellow of the Center for Strategic and International Studies.
Continue reading: Free-speech group says China has weaponized its 'Great Firewall' (full post)
Cybersecurity firm outs computer spying campaign from Lebanon
Researchers from Check Point Software Technologies in Israel have found a surprising computer spying operation that "likely" originated from a government agency or political group operating inside of Lebanon.
The spy software, once installed via hijacked public websites, could steal personal and corporate information from victims.
"They are not 'script kiddies,'" said Shahar Tal, a researcher at Check Point Software Technologies, in a statement published by Reuters. "But we have to say in terms of technical advancement, this is not NSA-grade. They are not replacing hard drive firmware."
Continue reading: Cybersecurity firm outs computer spying campaign from Lebanon (full post)
Europol says encryption making it harder to fight terrorism
It's getting more difficult to identify and track terror groups online, with the Dark Web and file encryption proving effective.
It's up to tech companies to think about the supposed damage facing police agencies and federal investigators, said Rob Wainwright, director of Europol, while speaking to 5 Live Investigates. Using forms of encrypted communications helps terrorists avoid detection while corresponding with one another.
"With the right resources and cooperation between the security agencies and technology companies, alongside a clear legal framework for that cooperation, we can ensure both national security and economic security are upheld," said a spokesperson with TechUK, a UK technology trade organization.
Continue reading: Europol says encryption making it harder to fight terrorism (full post)
Malware trap turns PCs into zombies for expanding global botnet
A single Command and Control server could be responsible for running a botnet using a number of different malware programs to infect users. It appears the cybercriminals are infecting as many machines as possible, and the botnet can be sold or rented to clients - spreading via manipulated Word documents attached to emails.
Security firm G DATA found a fake rail card invoice is one tactic criminals are using to help infect new victims. Instead of being an actual rail card invoice, however, the installed malware builds up a botnet, as criminals are able to remotely hijack infected PCs.
"The malware behaves like a matryoshka doll on the system," said Ralf Benzmuller, head of G DATA SecurityLabs. "It gradually reveals its potential and actual aim. We suspect that the infected systems are intended for use as zombie PCs in the Andromeda/Gamarue botnet."
Continue reading: Malware trap turns PCs into zombies for expanding global botnet (full post)
North Korea denies hacking South Korean nuclear power company
Despite South Korea blaming North Korea for hacking its nuclear power operator, officials in Pyongyang have denied their involvement. In a data breach in late 2014, hackers were able to steal employee personal information, physical designs and manuals of the Korea Hydro and Nuclear Power Co.
The Korean Central News Agency said Seoul fabricated evidence saying Internet protocol addresses were linked to the north - even though the recent data breaches were "believed to have been caused by an [unidentified] group of North Korean hackers."
North Korea is believed to have a budding cyberespionage program, with most of its efforts targeted at South Korean banks and other critical infrastructure.
Continue reading: North Korea denies hacking South Korean nuclear power company (full post)
More advanced ransomware attacks could pop up in 2015
Ransomware attacks, relying on custom malware able to encrypt files, continues to pose a significant threat to business users.
New ransomware types are popping up, including Crypto Wall and Torrent Locker, being distributed via email spam, watering hole attacks, and malvertising. Due to the financial benefit of compromising victims, hackers are always on the lookout for new methods to infect victims.
"One researcher likens it to turning on the kitchen light and having the cockroaches scatter," said Andrew Conway, research analyst at Cloudmark, in a statement published by Baseline. "Now, instead of one ransomware package, there are three or four of them out there. Occasionally, there will be a bug on ransomware that will enable people to get their data back. But, if you don't have another copy of that data, pay the ransom if you need [the data]."
Continue reading: More advanced ransomware attacks could pop up in 2015 (full post)
Chinese military rejects accusations it hacked Register.com
Web.com's Register.com was reportedly victimized by a coordinated cyberattack, and the Chinese military was reportedly responsible, according to a story published by the Financial Times. The hackers had access for around one year, though it doesn't appear client data was taken or there was a significant disruption to day-to-day activities.
However, Chinese officials deny being linked to the attack: "The relevant criticism that Chinese military participated in Internet hacking is to play the same old tune, and is totally baseless," according to a statement released to the Chinese Defense Ministry, submitted to Reuters.
The Chinese government has a sophisticated cyberattack program, and enjoys launching a number of cyberespionage campaigns against the United States and other western targets. Meanwhile, the Chinese government reports being a victim of international cyberattack, including many attacks that reportedly originate from the United States.
Continue reading: Chinese military rejects accusations it hacked Register.com (full post)
ISPs offer up home routers that pose serious security threats
Internet service providers (ISPs) are being criticized for distributing routers that are known for having security vulnerabilities that leave users vulnerable. A whopping 14 supplier provided ADSL routers that have firmware released in 2007 or newer, so hackers are able to gain overwhelming control of home networks.
Up to 80 million devices that are used in households and small offices can be compromised simply because new users don't bother to change default passwords - and it's even easier to find Internet-exposed routers. In addition to Internet scans, some websites are known for publishing which devices are vulnerable to outside tampering.
"Wide swathes of IP space are being made vulnerable through ISPs in developing countries distributing routers with default passwords that can be easily found on the Internet," said Kyle Lovett, Cisco consultant, while speaking at CrestCon & IISP Congress 2015.
Continue reading: ISPs offer up home routers that pose serious security threats (full post)
FireEye: People, not technology, to blame in online cyberattacks
A rise in cyberattacks can be attributed as an attack by people, as companies spend even more on boosting endpoint security. Many IT experts and business leaders see cyberattacks as a technology issue, but it's really a focus on people.
Cybersecurity experts are increasingly focused on educating employees on spotting phishing attempts, and fighting against attacks that rely on employees being rather naive and reckless.
"When you do think of it that way, then you tend to do a bunch of bad things," said Dave Merkel, CTO of FireEye, in a statement to ZDNET. "Such as ask bad questions to your security team like, 'What product can I buy to make this go away?' The answer is you can't just buy a product that is going make the bad guys go away forever."
Continue reading: FireEye: People, not technology, to blame in online cyberattacks (full post)
Auxiliary NYPD officer accused of hacking police, FBI networks
NYPD auxiliary police officer Yehuda Katz was charged with allegedly hacking into NYPD and FBI databases as part of his fraud scheme. Katz even installed a hidden camera in the traffic safety office, which was eventually discovered by precinct officers.
Katz used 15 compromised usernames and passwords, searching for more than 6,000 license plates stemming from auto accidents. Once he had personal information, he contacted victims and posed as an attorney who would be able to collect on their behalf.
"The threat posed by those who abuse positions of trust to engage in insider attacks is serious, and we will continue to work closely with our law enforcement partners to vigorously prosecute such attacks," said US Attorney Loretta Lynch, in a public statement.
Continue reading: Auxiliary NYPD officer accused of hacking police, FBI networks (full post)


