Hacking, Security & Privacy - Page 26
Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 26
Stay Updated
Follow TweakTown for breaking tech news, reviews, and daily updates.
As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.
Official: Cyber doomsday less likely as continued low-level attacks
Even with the rising sophistication of cyberespionage campaigns, US critical infrastructure is less likely to suffer from a single major incident - and faces a higher risk of continued low-to-medium attacks.
"Rather than a 'cyber-Armageddon' scenario that debilitates the entire US infrastructure, we envision something different," said James Clapper, director of national intelligence, in a recent report. "We foresee an ongoing series of low-to-moderate level cyberattacks from a variety of sources over time, which will impose cumulative costs on US economic competitiveness and national security."
Clapper's statements were made as part of a report submitted to the Senate committee, with growing concern regarding cybersecurity.
Continue reading: Official: Cyber doomsday less likely as continued low-level attacks (full post)
FireEye: Breach detection time is dropping, averages 205 days
FireEye's Mandiant found that the average data breach was discovered in 205 days, dropping from 229 days (2013) and 243 days (2012). Enterprises were only able to self-detect 31 percent of breaches, with third-parties and the government helping identify cybersecurity incidents.
Companies are becoming more vigilant in detecting cybercrime-related activity, such as credit card companies noticing fraudulent behavior.
"Over the last several years, organizations like the Federal Bureau of Investigation (FBI) have gotten increasingly involved in notifying US businesses that they have been identified as being compromised," said Ryan Kazanciyan, technical director at Mandiant, in a statement to eWEEK. "The result of the FBI's efforts has led to increasing numbers of victim notifications."
Continue reading: FireEye: Breach detection time is dropping, averages 205 days (full post)
Europol cripples Ramnit botnet, helping free millions of hijacked PCs
Europol's European Cybercrime Center is actively dismantling the Ramnit botnet, which relies on up to 3 million malware-infected zombie PCs. Twenty-seven percent of Ramnit infections were identified in India, with Indonesia (18 percent), Vietnam, the United States, Bangladesh and the Philippines also impacted.
Europol didn't say if any arrests were made at this stage of the investigation, but offered this public statement:
"This successful operation shows the importance of international law enforcement working together with private industry in the fight against the global threat of cybercrime," said Wil van Gemert, Deputy Director of Operations at Europol. "We will continue our efforts in taking down botnets and disrupting the core infrastructures used by criminals to conduct a variety of cybercrimes."
Continue reading: Europol cripples Ramnit botnet, helping free millions of hijacked PCs (full post)
Anthem confirms data breach could hit up to 19 million non-members
Anthem confirmed millions of non-Anthem customers are at risk, and 8.8 million up to 18.8 million customers could be at risk. Following discovery of the breach on Jan. 29, Anthem began contacting customers, but found millions of incomplete data records in its database.
The estimate counts 14 million incomplete records:
"While Anthem is not able to match incomplete records to a specific member, it does have valid mailing addresses for some of these records," an Anthem spokesperson told ABC News. "Anthem will distribute member notifications to the valid address on file as part of its effort to notify every potentially impacted member."
Continue reading: Anthem confirms data breach could hit up to 19 million non-members (full post)
FBI says it is "close" to identifying group behind Anthem data breach
The FBI says it is "close" to identifying the cybercriminal group responsible for breaching Anthem, but didn't confirm if a public announcement would be made. The targeted attack against Anthem, the No. 2 health insurance company in the United States, left up to 80 million members compromised.
China is suspected in the breach, with Beijing reportedly improving its cyberespionage capabilities.
"We're close already," said Robert Anderson, head of the FBI's cybercrime branch, during a recent media briefing. "But we're not going to say it until we're absolutely sure. I don't know if it's China or not, by the way."
Continue reading: FBI says it is "close" to identifying group behind Anthem data breach (full post)
Mobile security issues open the door to compromise users
Millions of smartphones and mobile devices are vulnerable due to mobile app developers being lackadaisical issuing patches and security updates, according to a report from McAfee Labs.
Last year, it was discovered that at least 20,000 mobile apps have an easily exploitable SSL vulnerability, according to the Carnegie Mellon University computer emergency response team. McAfee tested the 25 most popular apps listed by Carnegie Mellon, and found that "poor programming practices" were prevalent - putting app users at risk.
"A lot of the discussion right now is about the value of data on your device, in this case your cellphone," said Gary Davis, McAfee spokesman, in a statement published by CBC. "Addresses, dates of birth, these are all data elements you'd need to in essence steal somebody's identity, or perhaps conduct insurance fraud, and it's all being made available through different applications."
Continue reading: Mobile security issues open the door to compromise users (full post)
FBI aware of at least 60 state-sponsored cyberthreat groups
The FBI is aware of at least 60 cybercriminal groups with state-sponsored support, according to Joseph Demarest, senior bureau chief and head of the FBI cybercrime division.
Demarest also said the FBI was able to trace the Sony Pictures Entertainment hack was tied to North Korea within one month - showing that the unstable country has increasingly sophisticated cyberattack capabilities. State-sponsored cyberespionage is a booming business, with the FBI and other departments suspecting China, Russia, Iran, and other countries of relying on hackers.
In addition, the FBI announced a $3 million reward for the arrest or conviction of Evgeniy Bogachev, operator of GameOver Zeus. The bounty is the largest offered for a cybercriminal, and the Russian has been charged with computer hacking, conspiracy, wire fraud, bank fraud and money laundering - and faces a federal charge of bank fraud conspiracy.
Continue reading: FBI aware of at least 60 state-sponsored cyberthreat groups (full post)
LinkedIn offering $1 to previously compromised users
Do you remember when 6.5 million LinkedIn user's passwords were leaked in 2012 by Russian hackers? We leaned that apparently some people log-in to their professional social media with passwords like 'swampass' and 'squirter'.
A class action lawsuit has seen this company brought to their knees, offering a massive $1 each to the 800,000 Premium Users who joined up the fight. Just in case you were wondering if this might have been a typing error or mistake, it's not - they're giving $1 of cold-hard US dollar to each of the 800,000 Premium Users in which joined this lawsuit.
A LinkedIn spokesperson said to the New York Times that the purpose of this move is "to avoid the distraction and expense of ongoing litigation," even though they deny that they are at fault for the breach.
Continue reading: LinkedIn offering $1 to previously compromised users (full post)
Yahoo clashes with NSA regarding encryption backdoor demands
The National Security Agency (NSA) still has a fragile relationship with Silicon Valley companies, and both sides are trading shots at one another. In the most recent incident, a Yahoo executive challenged the NSA regarding its demand for encryption backdoors.
"If we're going to build defects, backdoors or golden master keys for the US government, do you believe we should do so for the Chinese government, the Russian government, the Saudi Arabian government, the Israeli government, the French government?" said Alex Stamos, CISO of Yahoo.
NSA Director Adm. Michael Rogers initially tried to deflect the question, and then offered the following answer: "I think that we're lying that this isn't technically feasible - now, it needs to be done within a framework. I'm the first to acknowledge that," Adm. Rogers said.
Continue reading: Yahoo clashes with NSA regarding encryption backdoor demands (full post)
NSA director says 'backdoors' into tech companies doesn't harm privacy
It was only last week that it was revealed that the National Security Agency hacked into Gemalto, the largest SIM card maker in the world, which broke just after we wrote about the NSA reportedly having access to backdoors in Western Digital and Seagate firmware.
The NSA is back in the news once again, with its director, Mike Rogers, wanting to see calmer action in regards to the government's plans to keep its backdoors operating smoothly. Rogers said that maintaining these "backdoors" would not be harmful to citizens' privacy, would not "fatally compromise encryption and would not ruin international markets for US technology products", reports The Guardian. Rogers said: "If you look at the topology of that attack from North Korea against Sony Pictures Entertainment, it literally bounced all over the world before it got to California. Infrastructure located on multiple continents, in multiple different geographic regions".
Rogers wasn't too clear on how legal or technological protections could be installed so that the various government agencies wouldn't take advantage of having all of this data. The White House is working directly with tech giants like Apple, Yahoo and Google on their encryption for the government to access their mobile data, cloud computing and more.
Continue reading: NSA director says 'backdoors' into tech companies doesn't harm privacy (full post)
Companies hiring hackers to help test their network cybersecurity
Companies nervous about their cybersecurity defenses are relying on white hat hackers to test systems and help identify security flaws. Offering a bounty allows additional skilled users outside of a company's software and IT team to help track down anything that may have unknowingly fallen through the cracks.
"We're curious, we want to test our skills, we want to help these companies," said Mike Santillana, white hat hacker for Bugcrowd, in a statement published by CBS News. "I've found several bugs where you can completely compromise another user's account."
Additional companies are paying security experts and programmers as part of increasingly lucrative bug bounty programs. These hackers enjoy the monetary incentive and the challenge of identifying security flaws that could pose problems for companies and their customers.
Continue reading: Companies hiring hackers to help test their network cybersecurity (full post)
Snowden regrets not coming forward sooner about NSA surveillance
Former NSA contractor Edward Snowden would have liked to come forward sooner regarding NSA surveillance, but had to wait until the appropriate time.
"I would have come forward sooner... [but] these programs would have been a little less entrenched, and those abusing them would have felt a little less familiar with and accustomed to the exercise of those powers," Snowden said during a Reddit "Ask Me Anything" session. "This is something we see in almost every sector of government, not just in the national security space, but it's very important. Once you grant the government some new power or authority, it becomes exponentially more difficult to roll it back."
Snowden knowingly sacrificed himself to help reveal NSA surveillance and spying activities, which has opened an international debate. In addition, Apple, Google and other companies are modifying their behaviors, including adding encryption and other technologies, to help keep user data more secure from outside snooping.
Continue reading: Snowden regrets not coming forward sooner about NSA surveillance (full post)
Head of NSA says spyware operation compliant with national law
The National Security Agency (NSA) is under fire for claims it used sophisticated spyware loaded on hard drives for surveillance, with the head of the agency saying his agency complies with national law.
"Clearly I'm not going to get into the specifics of allegations," said US Navy Admiral Michael Rogers, refusing to speak out regarding NSA spyware accusations, while at the Washington forum. "But the point I would make is, we fully comply with the law."
The latest controversy stems from a Kaspersky Lab report that says the NSA embedded spyware on Western Digital, Toshiba and Seagate hard drives, giving them the ability to eavesdrop on users.
Continue reading: Head of NSA says spyware operation compliant with national law (full post)
DDoS-for-hire cyberattacks are effective and cost-effective
Distributed denial of service (DDoS) cyberattacks have plagued consumers and businesses for quite some time, but the rising number of DDoS attacks available as a paid service is troubling. Clients can pay from $2 up to $5 per hour to launch DDoS attacks, or pay a subscription for prices as low as $800 per month.
The Lizard Squad hacker group helped draw increased scrutiny to the underground cybercriminal activity - demonstrating its LizardStresser DDoS service in successful attacks against the Sony PlayStation Network and Microsoft Xbox Live. Meanwhile, the Gwapo DDoS service has been publicly advertised via social media and YouTube posted videos, with attacks starting at $2 per hour.
"Since their inception in 2010, DDoS-for-hire capabilities have advanced in success, services and popularity, but what's most unnerving is booters have been remarkably skilled at working under the radar," according to the "Distributed Denial of Service Trends" report from Verisign. "Given the ready availability o DDoS-as-a-service offerings and the increasing affordability of such services, organizations of all sizes and industries are at a greater risk than ever of falling victim to a DDoS attack that can cripple network availability and productivity."
Continue reading: DDoS-for-hire cyberattacks are effective and cost-effective (full post)
Obama failing to create security relationships in Silicon Valley
Tech executives aren't impressed by President Obama's current efforts to streamline cybersecurity, with a strong lack of trust after increased knowledge of government surveillance operations. It's a fragile relationship that must be improved, especially if Obama is serious about Silicon Valley companies sharing threat data with the US government.
"I think we missed an opportunity," said Jason Healey, former director of cyber infrastructure protection for the White House, in a statement published by The Hill. "Real leaders focus on privacy and they don't compromise on that."
There will need to be an open discussion from the Obama Administration regarding encryption, privacy, and other matters - but trying to boost cybersecurity efforts appears to be a more pressing matter.
Continue reading: Obama failing to create security relationships in Silicon Valley (full post)
Ransomware cyberattacks rack up victims, creating millions in revenue
Ransomware cyberattacks are on the rise, and businesses must be ready to address the threat head on, with law enforcement constantly one step behind.
The FBI previously issued a warning regarding ransomware attacks, especially as cybercriminals tweak their malware code. Similar to statements issued by cybersecurity experts, the FBI says users should be extremely careful when opening email attachments - the most popular infection method to compromise business users.
The authors of the CryptoLocker ransomware were able to quickly generate at least $3 million in revenue from ransomware attacks, collecting hundreds of dollars in ransom at a time. Cybercriminals are opportunistic and will continue to rely on ransomware attacks as long as they easily find victims installing the malware on PCs and laptops.
Continue reading: Ransomware cyberattacks rack up victims, creating millions in revenue (full post)
Police department forced to pay $500 bounty in ransomware cyberattack
The Midlothian Police Department paid $500 after being compromised with the Cryptoware ransomware, encrypting files on one computer. A spear-phishing email likely is the culprit behind the Cryptoware infection, with Midlothian Police Chief Harold Kaufman confirming a cybersecurity incident.
The police department spent a total of $606 to rid itself of the infection, following the addition of bank fees and subsequent surcharges.
Cybersecurity experts recommend business users routinely back up their data - and that is often left to IT administrators - with urgent need to train employees so they can spot social engineering attempts.
Continue reading: Police department forced to pay $500 bounty in ransomware cyberattack (full post)
Revenge porn king, Hunter Moore, pleads guilty to hacking charges
Hunter Moore, 28, the founder of revenge porn website IsAnyoneUp.com, has pleaded guilty and faces years in prison. Moore pleaded guilty to identity theft, unauthorized access to a computer, and aiding and abetting unauthorized access of a computer. Unlike other revenge porn website operators, Moore paid a hacker to access email accounts looking for photos to steal.
Each charge carries a maximum prison sentence of two to five years, and Moore should be sentenced in a few months. Moore was once called "the most hated man on the Internet" for creating IsAnyoneUp.com, which served as one of the most popular revenge porn websites.
The infamous revenge porn website generated up to $10,000 per month in advertising revenue - and featured nude images and videos of ex-boyfriends and ex-girlfriends. The person's full name, city of residence, social media profile and profession were prominently listed on the website.
Continue reading: Revenge porn king, Hunter Moore, pleads guilty to hacking charges (full post)
After data breaches, companies still nonchalant about cybersecurity
Company executives have observed Target, JPMorgan Chase, Home Depot, Anthem, and other major companies suffer devastating data breaches - and understand they need stronger cybersecurity protocols - but actually deploying new methods has been rather slow.
Seventy eight percent of company tech executives have not been briefed regarding internal security strategies within the past 12 months, according to a Raytheon survey. In addition, 75 percent said cybersecurity is a necessary cost, but only 25 percent of survey respondents said security is a strategic priority.
"The Target hack was very interesting," said Jack Harrington, VP of cybersecurity and special missions of Raytheon, in a statement published by the Christian Science Monitor. "It raised awareness across the entire retail industry certainly," but demand for chief information security officer (CISO) positions wasn't' a priority. "That tells you they felt they didn't even need that position. They just didn't feel at risk."
Continue reading: After data breaches, companies still nonchalant about cybersecurity (full post)
Politics could get in the way of improved US national cybersecurity
It took several high-profile data breaches before the United States publicly discussed the need for improved cybersecurity protocols. Democrats and Republicans agree that something must be done, but security experts hope politics don't get in the way of necessary change.
However, cybersecurity efforts could receive bipartisan support from the Obama Administration and the Republican-led Congress - and politics hopefully won't get in the way.
"In order to improve cybersecurity, it is critical to facilitate the sharing of cyberattack information," said Sen. Ron Johnson (R-Wisc), in the GOP weekly address. "By sharing threat signatures, vulnerabilities and other indicators of network compromise, within and between the private sector and government, many cyberattacks can be prevented."
Continue reading: Politics could get in the way of improved US national cybersecurity (full post)


