Hacking, Security & Privacy - Page 27
Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 27
Stay Updated
Follow TweakTown for breaking tech news, reviews, and daily updates.
As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.
Report: More than 1,500 international data breaches in 2014
There were 1,500 global data breaches in 2014, with the number rising almost 50 percent year-over-year, according to the Gemalto Breach Level Index (BLI) report. Of the 1 billion total compromised records, almost 800 million of them belong to US companies - a frightening figure that cybersecurity experts believe will rise.
Companies remain unsure how to address these sometimes sophisticated cyberattacks, while consumers are frustrated that their personal information is seemingly up for grabs. Banks and credit card companies are becoming more proactive in identifying - and informing customers - of fraud, but it can still be a chaotic process.
"Not only are data breach numbers rising, but the breaches are becoming more severe," said Jason Hart, VP of cloud services, identity and data protection at Gemalto. "Identity theft could lead to the opening of new fraudulent credit accounts, creating false identities for criminal enterprises, or a host of other serious crimes. As data breaches become more personal, we're starting to see that the universe of risk exposure for the average person is expanding."
Continue reading: Report: More than 1,500 international data breaches in 2014 (full post)
More Anthem data breach fallout, millions of kids at risk of ID theft
Millions of Anthem customers are at risk from the Anthem data breach, including tens of millions of children impacted from the data breach. Personal information ranging from names, date of brith, Social Security numbers and health care ID numbers were stolen, and some children could be at risk for decades, according to cybersecurity experts.
Information on children is tied to their parents, so attacks against adult account holders are expected to accelerate in the future as well. However, personal information of children is especially lucrative to criminals, as the data hasn't been tied to a credit file - so the government and credit reporting agencies aren't expecting fraud-related activities.
"Every terrible outcome that can occur as the result of an identity theft will happen to the children who were on that database," said Adam Levin, chairman and founder of IDentityTheft911, in a statement published by NBC News. "Criminals will use those stolen Social Security numbers to open accounts, get medical treatment, commit tax fraud, you name it."
Continue reading: More Anthem data breach fallout, millions of kids at risk of ID theft (full post)
NSA says North Korea definitely to blame for Sony attack
The National Security Agency (NSA) believes North Korea is behind the Sony Pictures attack because of software used to breach the company. SPE was targeted in November by a group calling itself the "Guardians of Peace," with emails, employee personal information, movies, and other data stolen - and posted online.
"We ultimately ended up generating the signatures to recognize the activity used against Sony," said NSA Director Admiral Michael Rogers, in a statement during a security conference in Canada. "From the time the malware left North Korea to the time it got to Sony's headquarters in California, it crossed four different commanders' lines or areas in the US construct."
Cyberattacks are causing confusion for government agents, unexpectedly spending more time investigating breaches against private sector companies - as attacks mount against critical infrastructure and government agencies.
Continue reading: NSA says North Korea definitely to blame for Sony attack (full post)
DHS recommends users uninstall Superfish adware from Lenovo products
The US Department of Homeland Security (DHS) recommended Lenovo customers remove the Superfish adware from their computers and laptops. The Chinese electronics company installed the software on machines beginning in 2010 until January 2015, and Lenovo is no longer installing it on consumer products.
Despite Lenovo saying there were no cybersecurity issues, the National Cyber Awareness System said customers are vulnerable to SSL spoofing attacks. "Systems that came with the software already installed will continue to be vulnerable until corrective actions have been taken," the DHS said in a statement published by Reuters.
"We should have known about this sooner," said Brion Tingler, Lenovo spokesman, in a statement to Reuters. "And if we could go back, we never would have installed this software on our machines. But we can't, so we are dealing with this head on."
Continue reading: DHS recommends users uninstall Superfish adware from Lenovo products (full post)
Hackers still have access to US State Department email system
US State Department officials confirmed the agency temporarily shut down its unclassified email system because of hacker activity three months ago - and it looks like security experts still haven't been able to boot the unwelcome guests from its network.
It remains unknown where the attacks originated, but specialists suggest it could be from Russia. No classified data has been accessed, but there is growing concern the hackers will be able to write false emails, delete emails and find a way to access classified networks.
"We have robust security to protect our systems and our information, and we deal successfully with thousands of attacks every day," said Marie Harf, State Department spokeswoman, in a statement to Bloomberg. "We take any possible cyber intrusion very seriously."
Continue reading: Hackers still have access to US State Department email system (full post)
Google puts FBI on blast for invasive privacy practices against users
Google doesn't like the idea of the FBI being able to easily access Internet-connected devices owned by consumers, with the company sending a 14-page letter to officials.
"Law-abiding citizens who were the target of an unconstitutional search but are not charged with a crime will almost certainly never learn of the search and therefore will not be able to challenge the search," said Richard Salgado, director of information security and law enforcement for Google, in a letter to the US government.
Not surprisingly, the federal government thinks it needs access to user data to bust criminals and for better national security:
Continue reading: Google puts FBI on blast for invasive privacy practices against users (full post)
NSA hacked into largest SIM card maker, accessing billions of phones
Just days after we reported that the NSA had backdoor access to the firmware level of major HDD manufacturers in Seagate and Western Digital, Edward Snowden is back with new information that the National Security Agency (NSA) and its British partner GCHQ hacked into Gemalto. Gemalto, is a Netherlands SIM card manufacturer, the largest in the world.
Gemalto makes two billion SIM cards each year, with the NSA hacking into the company and stealing its encryption keys, giving them access to secretly monitor both voice calls and data. The Intercept reported on the news, which has reportedly provided spy agencies with the ability of secretly monitoring gigantic portions of the world's cellular communications, which experts have said is a major violation of international laws. Considering Gemalto makes SIM cards for companies like AT&T, Sprint, T-Mobile and Verizon, you can begin to see the scope of this hack by the US government agency. Gemalto itself operates in some 85 countries around the world, providing SIM cards to over 450 wireless network providers.
With the NSA having these encryption keys in its hands, it has the power to monitor mobile communications "without the approval of telecom companies and foreign governments", reports The Guardian. This is something I talked about in my last OpEd, where the Obama administration needs to address it, and as I said "The NSA needs to be ripped apart, and its powers neutered". Most people think that 3G and 4G mobile networks have their calls encrypted, and while they might be, but with the keys that the NSA and GCHQ have, it's like they are living "in the phone".
Continue reading: NSA hacked into largest SIM card maker, accessing billions of phones (full post)
Movies nominated for an Oscar see surge in Internet piracy
Following news of which films are up for Oscars, online piracy of nominated movies increased 385 percent since January 15, according to the Irdeto piracy monitoring firm.
Irdeto uses a crawler to monitor torrent downloads, and saw increased interest following the Oscar nominations - largely due to increased media coverage - with screener films sometimes leaked online.
"Hollywood screeners specifically accounted for a substantial 31 percent of the total illegal downloads tracked between January 15 and February 14," according to Irdeto, as published by TorrentFreak. "Six nominated movies currently unavailable for retail purchase on Blu-ray, DVD, VOD or legal streaming/download sites saw the majority of piracy coming directly from these screeners: American Sniper, The Imitation Game, Wild, Selma, Whiplash and Still Alice."
Continue reading: Movies nominated for an Oscar see surge in Internet piracy (full post)
Lenovo will no longer pre-install controversial Superfish PC adware
Computer manufacturer Lenovo will no longer pre-install the controversial Superfish adware on PCs and laptops, due to growing public backlash from customers. Cybersecurity experts warned Superfish potentially left them vulnerable, after injecting advertisements to browsers.
"The way the Superfish functionality appears to work means that they must be intercepting traffic in order to insert ads," said Eric Rand, researcher for Brown Hat Security, in a statement to Reuters. "This amounts to a wiretap."
Lenovo must now answer questions regarding its use of Superfish, including how long it was pre-installed, and how much data was collected by the software. Superfish was installed on consumer PCs and notebooks only.
Continue reading: Lenovo will no longer pre-install controversial Superfish PC adware (full post)
Swedish man behind BlackShades malware pleads guilty in US court
Swedish citizen Alex Yucel, 24, has pleaded guilty for his role in being co-creator of the BlackShades malware, which infected more than 500,000 PCs across the world. Yucel pleaded guilty to one count of distribution of malicious software, and faces a maximum sentence of 10 years.
In exchange for his guilty plea, there is a stipulated agreement that will see Yucel receive a sentence ranging from 70 to 87 months. "I do actually want to plead guilty," Yucel said in his court appearance. "I knew that the program would be used to cause damage."
Yucel was arrested in November 2013 while in Moldova, and was extradited to the United States. As the operator of the criminal organization, Yucel hired administrators, marketing and customer support staff to interact with customers - generating upwards of $350,000 in revenue.
Continue reading: Swedish man behind BlackShades malware pleads guilty in US court (full post)
Software Advice: More than half of SMBs don't have data breach plan
Companies are under cyberattack, and many of them are being caught off guard when a data breach occurs. More than half of small and midsize businesses (SMBs) don't have an appropriate breach response plan currently in place, according to a survey from Software Advice.
There are 47 states with breach notification laws that force companies to disclose data breaches when personal information is impacted. However, just 33 percent of SMB decision makers feel "very confident" they understand their state laws regarding breach notification - and it remains a confusing matter.
"Most of the time, when [valuable] information leaks out of a company, it is instantly being monetized on underground forums," said Bogdan Botezatu, senior e-threat analyst of the Bitdefender antivirus firm. This data can be moved quickly, as cybercriminals tend to want to exploit data before changes are made - and companies must inform their clients and customers promptly.
Continue reading: Software Advice: More than half of SMBs don't have data breach plan (full post)
Russian citizen pleads not guilty to stealing 160M credit cards
Vladimir Drinkman, 34, has pleaded not guilty after being charged of allegedly serving as part of an international hacker ring responsible for stealing up to 160 million credit cards. The group is accused of installing malware on vulnerable computer systems, with stolen information sold on the black market.
Drinkman's specialty was penetrating networks to gain access to corporate databases that could later be mined.
The hacker group hit NASDAQ, 7-Eleven, Dow Jones, JetBlue, and other high-profile targets - with the "far-reaching" scheme responsible for compromising usernames, passwords, along with debit and credit card numbers.
Continue reading: Russian citizen pleads not guilty to stealing 160M credit cards (full post)
Corporate America in dire need of cybersecurity help to fight attacks
To help defend against cyberattacks, executives at private corporations need assistance from the US government and cybersecurity firms.
It took longer than experts would have liked, but it appears 90 percent of CEOs in the United States find cybersecurity strategically important, according to a PwC survey. The survey also found 87 percent are worried about cyberattacks, and 45 percent are extremely concerned about mounting attacks - many aimed at stealing employee and customer personal data.
President Barack Obama hosted a cybersecurity summit last week at Stanford University, seeking greater cooperation between the United States and Silicon Valley. "When you step back and look at the role of a company versus the role of a government, clearly if we're going to provide the safest possible [customer] experience in [the] aggregate, government and companies need to work together," said John Donahoe, CEO of eBay, in a statement to Fortune.
Continue reading: Corporate America in dire need of cybersecurity help to fight attacks (full post)
Researchers stumble across Arab-speaking cybercriminal group
The Operation Arid Viper campaign has successfully stolen more than 1 million files with current malware campaigns underway, though it's not the usual suspects, according to Kaspersky Lab and Trend Micro.
The Arab-speaking group, with ties to Gaza, have targeted foreign government offices, critical infrastructure, military, universities, and other high-profile targets. The attacks likely occurred starting in mid-2013 and a full investigation into their actions is underway.
"Whoever the real culprits are, it is clear that they are part of the Arab world, evidence of a budding generation of Arab hackers and malware creators intent on taking down their chosen adversaries," researchers said in a study. "Some of the black hats - be they mercenaries or cybersoldiers - are actively targeting countries such as Israel due to political motivations. We have seen all of the ingredients of a cyberskirmish guerrilla war that goes unnoticed by mainstream IT security media."
Continue reading: Researchers stumble across Arab-speaking cybercriminal group (full post)
Government: Japan endured 25 billion cyberattacks in 2014 alone
Japanese infrastructure endured 25.6 billion cyberattacks in 2014 alone, with 40 percent reportedly traced back to Chinese sources, according to Japan's National Institute of Information and Communications Technology (NICT).
It wouldn't be surprising to hear Japan faced a large number of cyberattacks tied to China, especially with political turbulence between Tokyo and Beijing. There were a number of attacks originating from the United States, South Korea and Russia - as cybersecurity efforts continue to grow.
When the survey was first conducted, in 2005, there were just 310 million cyberattacks detected by the Japanese government. The latest NICT report discovered a growing number of attacks aimed at compromising home and business routers, IoT-enabled systems, networks, and security cameras.
Continue reading: Government: Japan endured 25 billion cyberattacks in 2014 alone (full post)
Netgear routers allowing hackers to pass administrator authentication
A recent flaw has been discovered in multiple Netgear router models, reportedly allowing hackers to bypass administrator authentication and gain full access to the device as found by Network engineer, Peter Adkins.
Adkins discovered that routers in the popular Netgear 'WNDR' range are running a Simple Object Access Protocol (SOAP) service as part of the Netgear Genie device administration application. Seemingly secure, he was able to bypass filtering and authentication for the SOAP service over a Wi-Fi connection without much effort.
Once the connection had been established, Adkins was able to extract the admin password, Wi-Fi interface credentials, station identifiers, the device serial number and even information on connected clients. He then notified Netgear of this security issue, however was met with a response which included "the network should still stay secure" - apparently due to hidden built-in security features.
Continue reading: Netgear routers allowing hackers to pass administrator authentication (full post)
KnowBe4: Social engineering still extremely effective to victimize
Following news that millions of dollars have been stolen from banks by cybercriminals was yet another startling wakeup call for cybersecurity experts. Not surprisingly, hackers delivered the malware payload via social engineering phishing attacks targeted at reckless employees.
"Even after 20 years, social engineering is still the easiest way into a target's network and systems, and it's still the hardest attack to prevent," said Kevin Mitnick, legendary hacker and Chief Hacking Officer of KnowBe4.
Companies need to be aware that employees - in a number of different departments - are often untrained and rather careless when checking their emails. Spear-phishing tends to be a popular choice among cybercriminals, able to trick employees by using a customized approach.
Continue reading: KnowBe4: Social engineering still extremely effective to victimize (full post)
Kaspersky: the NSA has backdoors in Seagate and WD HDD firmware
Kaspersky has some damning claims against HDD giants Seagate and Western Digital, where it has said that the NSA has spying backdoors installed onto the HDD firmware of the leading HDD manufacturers products.
The cyber-security giant says that the US spy agency has full access to raw data, agnostic of partition method (low-level format), file system (high-level format), operating system, or even at the user access level. Kaspersky has said that it has found PCs in at least 30 countries with the spying programs installed, with the most infections found in Iran. After that, we have Russia, Pakistan, Afghanistan, China, Mali, Syria, Yemen and Algeria.
Kaspersky has said that the HDD firmware backdoors are used right now to spy on foreign governments, telecommunication giants, banks, nuclear researchers, the media, and many more. Kaspersky isn't outright naming the company that has designed the malware, but it has said that the company responsible has close ties with the development of Stuxnet. But it does get worse, as the company adds that each time you turn your PC on, the malware is activated, which means it has utter control to all of the critical OS components - possibly gaining access to your network, and file system.
Continue reading: Kaspersky: the NSA has backdoors in Seagate and WD HDD firmware (full post)
Report: 99% of malware-infected smartphones running Google Android
Mobile phones are under attack by cybercriminals, trying to steal personal data and possible financial information stored on devices. Studying information collected on cellular networks, 0.68 percent of mobile phones suffer from malware infection, according to Alcatel-Lucent.
Google Android devices - the No. 1 mobile OS across the world - make up 99 percent of the infected devices, with infection rates increasing. Adware.Uapush, Trojan.Ackposts and SMSTracker are the top three infections, commonly hidden in legitimate looking mobile applications.
"Most importantly is the fact that there is less control - you can download the apps from third-party app stores and there is very little checking of the digital signature that you sign the app with," said Kevin McNamee, director of Alcatel-Lucent's Motive Security Labs.
Continue reading: Report: 99% of malware-infected smartphones running Google Android (full post)
Data breaches leading to more cyberattack insurance adoption
Cybercriminals carrying out data breaches on organizations are helping create a suddenly booming cyberattack liability insurance market.
Traditional insurance companies - and a growing number of niche cyberattack insurance providers - are overwhelmed by an avalanche of new applications. The cyberattack insurance industry reached close to $2 billion in 2014, which is double the previous year, according to industry analysts.
"Think of a massive cyberattack as an intelligent hurricane," said Ty Sagalow, COO of the eBusiness division of AIG, in a statement published by the Los Angeles Times. "If it hits a house that doesn't fall down it learns why the house didn't fall and it changes. It is a scary thing... scary things sell insurance."
Continue reading: Data breaches leading to more cyberattack insurance adoption (full post)


