Hacking, Security & Privacy - Page 25
Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 25
Stay Updated
Follow TweakTown for breaking tech news, reviews, and daily updates.
As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.
Mobile app security is a threat, but companies are still confused
Eighty-two percent of IT professionals are concerned that using mobile apps in the office "significantly" or "very significantly" increase cybersecurity concerns - but more than half of companies still lack mobile app use policy rules.
Millions are being spent on mobile app development, but a fraction of those overall investments are related to security. Companies are increasingly testing mobile apps, including security vulnerabilities, and 30 percent of apps are found to have at least a single vulnerability.
"It's just an indicator that we [the security community] have a problem, [or] a risk issue that isn't necessarily being met, at least not with respect to training and awareness," said Larry Ponemon, chairman and founder of the Ponemon Institute, in a statement to SCMagazine.com
Continue reading: Mobile app security is a threat, but companies are still confused (full post)
Cybersecurity experts show concern over wearable security
The Apple Watch will be released on April 24 and should bring immediate attention to the wearables market - but that has some cybersecurity experts concerned. More users will rely on their smartwatches to make payments, conduct business communications, and save sensitive information for easier access.
Even though this will make it easier to incorporate wearables into our daily lives, it opens the door to hackers looking for new cybercriminal opportunities.
"The more ways we make data more convenient, the more risk there is to access the data and access things without your knowledge," said Kevin Mahaffey, chief technology officer of the Lookout cybersecurity firm, in a statement published by CNBC. "Just like adding another door to your house, it's just adding another way for bad guys to get in."
Continue reading: Cybersecurity experts show concern over wearable security (full post)
Target will pay $10 million after class-action lawsuit
Following its massive 2013 data breach, which led to customer payment data being stolen, Target will pay $10 million in a class-action lawsuit settlement. The attack took place between Nov. 27 and Dec. 15 2013, with up to 40 million credit and debit cards compromised.
If approved by a federal district court judge, individual victims would be paid up to $10,000 - but is just one of 15 lawsuits that were filed against Target within a short period following the data breach.
"We are pleased to see the process moving forward and look forward to its resolution," said Molly Snyder, Target spokesperson, in a statement to CBS News.
Continue reading: Target will pay $10 million after class-action lawsuit (full post)
Microsoft introduces Windows Hello biometric sign-in for Windows 10
Microsoft plans to offer the Windows Hello biometric sign-in feature for its upcoming Windows 10 operating system. Users will have the chance to scan their face, fingerprint or iris, which can be used to unlock PCs, laptops, or smartphones.
Windows Hello can be used to access protected content, authenticate apps, and other "online experiences," Microsoft says.
Meanwhile, Intel said all systems that utilize its RealSense F200 sensor can support Windows Hello. All data will be stored locally on each PC or device, and will remain anonymous in case hackers compromise it.
Continue reading: Microsoft introduces Windows Hello biometric sign-in for Windows 10 (full post)
Premera Blue Cross hacked, putting 11M customers at risk
The Premera Blue Cross health insurer has confirmed it suffered a data breach, putting 11 million customers at risk. Compromised data includes financial information and medical information, including names, bank account data, Social Security numbers, and clinical information.
The FBI is now working with Premera to gauge the seriousness of the data breach, with compromised records dating back as far as 2002. The company is now offering two years of free credit monitoring and identity theft protection services, Premera said on a special website designed to discuss the issue.
"All of us here at Premera have been by affected by this attack and we understand and share your concerns," said Jeff Roe, President and CEO of Premera. "Please know that we're committed to making sure you get the tools and assistance you need to help protect you."
Continue reading: Premera Blue Cross hacked, putting 11M customers at risk (full post)
Banks must work to improve cybersecurity defense to prevent fraud
Improving cybersecurity is a major effort by government agencies and the private sector, with security incidents still occurring at a frightening rate. Financial institutions have focused more on keeping attackers out of their networks, while trying to defend against a large number of attacks.
Most bank-related fraud tends to occur because of the use of false or anonymous identities. However, there is more focus on trying to keep malware from being installed, and to prevent distributed denial of service (DDoS) attacks from being so successful.
"It is no longer acceptable to simply apologize for a security breach and send a letter out to affected customers," said Dorean Kass, VP at Neustar. "Customers expect businesses, especially banks, to identify fraud and maintain cybersecurity, all while ensuring a convenient experience for its clients."
Continue reading: Banks must work to improve cybersecurity defense to prevent fraud (full post)
Pentagon plans to 'hack-proof' future military weapons systems
The United States faces a "pervasive" issue regarding cyberattacks against physical weapons systems and private defense contractors - and cybersecurity to help protect assets is gaining more traction. The Department of Defense Instruction 5000.02, the Pentagon's guidelines for military acquisitions, will include a category focused specifically on cybersecurity.
"It's about the security of our weapons systems themselves and everything that touches them," said Frank Kendall, Defense Undersecretary, speaking to Reuters. "It's a pervasive problem and I think we have to pay a lot more attention to it."
The US government deciding to embrace cybersecurity, especially for the military, will likely generate more revenue for Lockheed Martin, General Dynamics and other contractors tasked with creating defensive cybersecurity programs.
Continue reading: Pentagon plans to 'hack-proof' future military weapons systems (full post)
Kaspersky: complexity versus functionality in cyberespionage war
Countries interested in conducting cyberespionage campaigns are using increasingly sophisticated methods, carefully targeting users with modular tools, according to Kaspersky Lab.
To increase stealth and reduce their visibility from cybersecurity experts, hackers are diversifying the components used in their malicious programs. One specific platform has at least 116 different plugins that can be customized depending on expected victim and what type of information they have access to.
"Nation-state attackers are looking to create more stable, invisible, reliable and universal cyberespionage tools," said Costin Raiu, director of global research and analysis at Kaspersky Lab. "They are focused on creating frameworks for wrapping such code into something that can be customized on live systems and provide a reliable way to store all components and data in encrypted form, inaccessible to regular users."
Continue reading: Kaspersky: complexity versus functionality in cyberespionage war (full post)
Wikipedia is suing the NSA over its mass surveillance of the Internet
We all know that the NSA has stepped over some pretty serious privacy boundaries, but now Wikipedia is suing the US spy agency over the constitutionality of its mass surveillance program.
Wikipedia has slapped the NSA with a lawsuit with the Justice Department, claiming that its mass surveillance regine threatens the freedom of speech under the First Amendment and the Fourth Amendment's protection against the unreasonable search and seizures. Executive Director of the Wikipedia Foundation, Lila Tretikov, explains: "By tapping the backbone of the Internet, the NSA is straining the backbone of democracy. Wikipedia is founded on the freedoms of expression, inquiry, and information. By violating our users' privacy, the NSA is threatening the intellectual freedom that is central to people's ability to create and understand knowledge".
Wikipedia's founder Jimmy Wales, along with Tretikov, argued in a op-ed in The New York Times on Tuesday that "pervasive surveillance" of Wikipedia's hundreds of millions of users had a scary effect that "stifles freedom of expression and the free exchange of knowledge". The duo continued, writing: "Whenever someone overseas views or edits a Wikipedia page, it's likely that the N.S.A. is tracking that activity-including the content of what was read or typed, as well as other information that can be linked to the person's physical location and possible identity. These activities are sensitive and private: They can reveal everything from a person's political and religious beliefs to sexual orientation and medical conditions".
Continue reading: Wikipedia is suing the NSA over its mass surveillance of the Internet (full post)
Edward Snowden hopes for possible asylum in Switzerland
Former NSA contractor Edward Snowden, currently residing in Russia, says he would like if the Swiss government granted him asylum. Snowden once lived in Geneva while working undercover for the CIA, and enjoyed his time in the European country.
In addition to Switzerland preferring a neutral stance on current military wars and other issues, the country also boasts a high quality of life and treatment of citizens. Unfortunately, current Swiss laws dictate someone applying for asylum must already be in Switzerland - and it's unknown if the government is willing to make an exception for Snowden.
"I would love to return to Switzerland, some of my favorite memories are from Geneva," Snowden recently said during the International Film Festival and Forum on Human Rights. "It's a wonderful place. I do think Switzerland would be a sort of great political option because it has a history of neutrality."
Continue reading: Edward Snowden hopes for possible asylum in Switzerland (full post)
Wikimedia Foundation suing NSA to protect millions of Wikipedia users
The NSA and US Department of Justice are being sued by the Wikimedia Foundation, accusing the US organizations of violating US laws related to freedom of speech. The American Civil Liberties Union (ACLU) is representing Wikimedia, which was joined by Amnesty International, Human Rights Watch, and several other major organizations in the lawsuit.
The NSA's use of "upstream" surveillance, which "taps the Internet's 'backbone' to capture communications with 'non-US persons,'" is available for a large amount of possible uses - however, it is believed to ultimately collect data not involved in their investigations. Wikimedia and other groups are concerned that journalists, clients, foreign government officials and others won't be as willing to turn over information and discuss sensitive topics with them.
"Our lawsuit says that the NSA's mass surveillance of Internet traffic on American soil - often called 'upstream' surveillance - violates the Fourth Amendment, which protects the right to privacy, as well as the First Amendment, which protects the freedoms of expression and association," according to a Wikipedia op-ed published by the New York Times. "We also argue that this agency activity exceeds the authority granted by the Foreign Intelligence Surveillance Act that Congress amended in 2008."
Continue reading: Wikimedia Foundation suing NSA to protect millions of Wikipedia users (full post)
Javelin Strategy: New identity fraud victim every two seconds in 2014
Criminals took $16 billion from 12.7 million US consumers last year, with a new identity fraud victim every two seconds, according to a new report from Javelin Strategy & Research. Two-thirds of identity fraud victims last year received notification that their personal information was compromised in a data breach, which took over headlines as major retailers were hit.
On the bright side, new account fraud, which is when a criminal opens up an account in a victim's name, dropped to a record low in 2014. In addition, new monitoring and protection systems saw the amount lost due to fraud dropping 11 percent year-over-year, from $18 billion in 2013 down to $16 billion in 2014.
"Despite the headlines, the occurrence of identity fraud hasn't changed much over the past year, and it is still a significant problem," said Al Pascual, director of fraud & security at Javelin Strategy & Research. "Consumers, financial institutions and retailers are all taking aggressive steps, yet we must remain vigilant. The criminals will continue to find new ways to commit fraud, so taking advantage of available technology and services to protect against, detect and resolve identity fraud is a must for all individuals and corporations."
Continue reading: Javelin Strategy: New identity fraud victim every two seconds in 2014 (full post)
Lawyer: Edward Snowden wants to return to US if given fair trial
Former NSA contractor Edward Snowden wants to return to the United States in the future, but needs guarantees of a fair trial. The only promise he has been given is that he wouldn't face the death penalty if he is convicted - and privacy advocates believe the US government, which wants to do anything to get him into custody, cannot be trusted.
"He is thinking about it," said Anatoly Kucherena, a Russian lawyer representing Snowden, during a recent news conference. "He has a desire to return and we are doing everything we can to make it happen. Snowden is ready to return to the United States, but on the condition that he is given a guarantee of a legal and impartial trial."
Kucherena also noted that he is working with a group of international lawyers to determine the best method for Snowden's potential return to the United States. Snowden has a three-year Russian residency, but would likely face immediate arrest if he tried to leave Russia.
Continue reading: Lawyer: Edward Snowden wants to return to US if given fair trial (full post)
Concern in rising number of tax-related scams and cybercrime
The US federal government is worried about a growing number of cases related to Stolen Identity Refund Fraud (SIRF), with criminals filing state and federal taxes - and making off with the tax refunds. Tax-related identity theft was the most reported type of fraud submitted to the Federal Trade Commission (FTC) in 2014, with the agency receiving 109,063 complaints.
Recently, the Internal Revenue Service (IRS) issued another public advisory to remind people that any telephone calls or emails claiming to be the IRS are fraudulent. In these scams, criminals ask victims to provide personal information or transfer money to them.
"It is a massive problem," said Brian Krebs, independent cybersecurity investigative reporter, in a statement published by the Milwaukee Journal Sentinel. "It's probably going to emerge as the biggest identity theft problem this year."
Continue reading: Concern in rising number of tax-related scams and cybercrime (full post)
US regulator worried of major 'Armageddon' cyberattack targeting banks
Ben Lawsky, a New York financial regulator and head of the New York Department of Financial Services, is reportedly considering new regulation to help prevent against "an Armageddon-type" cyberattack. There is concern that a coordinated cyberattack would be able to hit the "broader economy" of the United States.
"We are concerned that within the next decade, or perhaps sooner, we will experience an Armageddon-type cyber event that causes a significant disruption in the financial system for a period of time," Lawsky said while speaking at Columbia Law School.
To help prevent against a "cyber 9/11," Lawsky wants financial institutions and insurance companies be graded by the DFS. The legislation may also require multifactor authentication and other requirements to keep data secure. Banks also must be proactive in their effort to keep data secure, as foreign-based hackers continue their attempts to disrupt Wall Street.
Continue reading: US regulator worried of major 'Armageddon' cyberattack targeting banks (full post)
Report: Lenovo only collected $250,000 from Superfish installations
Lenovo likely only collected $200,000 up to $250,000 for its Superfish adware installations on consumer PCs, according to a report from Forbes. Previous estimates predicted higher figures - but considering the company's major earnings - the low sum likely won't be worth the legal and public relations headaches.
It is alarming Lenovo, which finalized a deal in summer 2014 to pre-install Superfish, received such a small amount for jeopardizing so much. In addition to promising no more Superfish installations, the company's website was reportedly compromised by the Lizard Squad hacker group last week.
It looks like Lenovo is learning from its mistakes, promising to be more transparent about pre-installed software in the future. For new machines running Microsoft Windows 10, the Lenovo standard image will only include the OS, security software, Lenovo applications, and software/drivers required to make hardware work well.
Continue reading: Report: Lenovo only collected $250,000 from Superfish installations (full post)
Report: 5 billion Google Android apps are vulnerable to cyberattack
More than five billion downloaded Google Android apps could be targeted by hackers, according to cybersecurity experts. Most forms of malware (96 percent) are focused on compromising Android, according to data from the FireEye cybersecurity firm.
Android is open source and allows more developers to contribute to the OS, but that also gives hackers a great opportunity to create sophisticated malware. Malware targeting Android drastically increased from 240,000 samples in 2013 up to 390,000 unique samples last year - and the problem seems to be accelerating.
"You can get all the code and then you can insert additional instructions and make it look and feel like the original app and no way for a consumer to tell the difference when they download it," said Jason Steer, director of technology strategy at FireEye, in a statement given to CNBC.
Continue reading: Report: 5 billion Google Android apps are vulnerable to cyberattack (full post)
Cyberattacks top threat to United States, intelligence agencies say
Cyberattacks from foreign states and rogue hacker groups have become the top threat to the United States, according to US intelligence experts. Director of National Intelligence, James Clapper, is especially concerned of potential attacks from Russia, China, Iran and North Korea - saying low-to-moderate level cyberattacks pose a long-term threat against critical infrastructure.
In addition to cyberespionage from foreign governments, there is rising concern of hacker groups able to infiltrate government agencies and companies - sometimes with support from foreign governments - with the goal of interrupting business operations, stealing money, and compromising employee and customer personal data.
Unfortunately, the US government has focused more on its cyber surveillance programs while largely neglecting cybersecurity. Even though it's effective to have offensive weapons, the United States has a lot more to lose than other countries if a major data breach occurs - and there is growing focus on being able to identify and defend against attacks.
Continue reading: Cyberattacks top threat to United States, intelligence agencies say (full post)
Companies transitioning to better detection, response of cyberattacks
By 2018, 40 percent of large enterprises will have some type of plan to respond to aggressive cybersecurity business disruptions, a drastic increase from zero percent in 2015, according to the Gartner research group.
Gartner describes an aggressive business disruption attack as a coordinated and sophisticated effort to interfere with and damage business operations - wiped data, servers knocked offline, intellectual property stolen.
"Entirely avoiding a compromise in a large complex enterprise is just not possible, so a new emphasis toward detect and respond approaches has been building for several years, as several attack patterns and overwhelming evidence support that a compromise will occur," said Paul Proctor, VP and distinguished analyst at Gartner. "Preventive controls, such as firewalls, antivirus and vulnerability management, should not be the only focus of a mature security program."
Continue reading: Companies transitioning to better detection, response of cyberattacks (full post)
Kaspersky: 28% of mobile users don't have knowledge of malware attacks
Twenty-eight percent of consumers know nothing or very little about mobile malware, while another 26 percent said they are aware of cyber threats but aren't worried, according to the "Consumer Security Risk" survey from Kaspersky Lab.
In addition, 31 percent of Google Android smartphones and 41 percent of tablets aren't password-protected, while 58 percent of Android smartphones and 63 percent of tablets have some form of anti-virus software.
"It is not surprising that mobile users are facing online threats more often now: devices are capable of doing so much more, and many more people are using them, so of course they will attract fraudsters," said Victor Yablokov, head of mobile product line at Kaspersky Lab. "To avoid falling victim to scams, users are advised to protect their devices against cyber threats and be especially careful with any sensitive data store on them."
Continue reading: Kaspersky: 28% of mobile users don't have knowledge of malware attacks (full post)


