Newsletter IconFacebook IconX IconThreads IconInstagram IconYouTube IconPinterest Icon
Giveaway: AVerMedia Creator Bundle (4K Webcam, Capture Card, Charging Hub, and Mouse Pad)

Hacking, Security & Privacy - Page 28

Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 28

Stay Updated

Follow TweakTown for breaking tech news, reviews, and daily updates.

Add TweakTown as a preferred source on GoogleFind TweakTown on Apple News

As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.

Closer look at North Korea's cyber army tasked with cyberespionage

| Feb 15, 2015 3:08 PM CST

North Korea isn't a cyberespionage powerhouse like Russia or China, but the country has a budding cyber warfare program that could cause major headaches for the United States and South Korea. Pyongyang is investing more resources into its cyber capabilities, evolving attack habits to be highly disruptive.

"A prime example could be if we're imagining that North Korea was under attack from South Korea, which was being supported by the US Army," said Egle Murauskaite, trainer at the US National Consortium for the Study of Terrorism and Responses to Terrorism, in a statement to the Christian Science Monitor. "North Korea could attack satellites to disrupt communication between the US and allies and imped the US ability to reach targets."

Along with satellites, precision guided missiles largely rely on electronics, so there are fears that attacks would be able to effectively disrupt these signals.

Continue reading: Closer look at North Korea's cyber army tasked with cyberespionage (full post)

US government greatly concerned of insider threat attacks

| Feb 15, 2015 1:08 PM CST

Companies and government agencies understand the need for improved cybersecurity to help defend against attacks and insider threats. It's a confusing mix of trying to defend against outside threats, and keeping reckless and improperly trained employees from causing harm.

Fifty-three percent of federal IT professionals believe insider threats, whether from intentional threats or untrained employees, remains the largest threat, according to a report from IT software firm SolarWinds. Furthermore, 64 percent of those surveyed think insider threats can be as damaging - or more damaging - than malicious external threats posed by hackers and cyberespionage.

"Contrasting the prevalence of insider IT security threats against a general lack of threat prevention resources and inconsistently enforced security policies, federal IT pros absolutely must gain visibility into insider actions to keep their agencies protected," said Chris LaPoint, group VP of product management at SolarWinds. "However, given the unpredictability of human behavior, the 'Why?' of those actions is an elusive query."

Continue reading: US government greatly concerned of insider threat attacks (full post)

ABI Research: Biometrics industry to reach $13.8 billion in 2015

| Feb 15, 2015 10:20 AM CST

The surging biometrics market is predicted to reach $13.8 billion in 2015, largely due to government adoption, however, there could be growing interest in the private sector, according to the ABI Research group.

The United States and European Union nations will continue to adopt biometrics, with fingerprint recognition still the leading solution. Consumer and private sector biometrics spending could outpace government spending in 2018, according to ABI, as wearables and smartphones implement enhanced security protocols.

The healthcare industry is still trying to cope with news that Anthem suffered a major data breach - and there are increased talks regarding cybersecurity technologies that can be utilized to prevent future incidents. As more companies transition to electronic health records, biometrics supporters hope that it will present a great opportunity for hardware and software adoption.

Continue reading: ABI Research: Biometrics industry to reach $13.8 billion in 2015 (full post)

Hackers tricked bankers into installing malware, stole $300 million

| Feb 14, 2015 11:25 PM CST

According to some security researchers at Kaspersky, a group of hackers have used tricky malware to steal at least $300 million from bankers throughout 30 countries across the world.

The hackers tricked bank staff into installing a virus, or malware, through a spoofed email, where they spied on staff to learn their behavior. From there, they were able to mimic bank staff, to learn telltale signs that money is being taken from the bank, and transferred to various accounts. The attacks did just that, transferring money to other bank accounts, but some of it is sent to ATMs where criminals are monitoring specific ATMs.

The banks that were hit are now aware of the attack, but Kaspersky cannot name the banks due to non-disclosure pacts. Some of the firms don't want to admit they were hit, as they would be looked at as victims, and that their security has failed them. As for the breaches of security, the hackers injected malware into banks in the United States, Russia, Japan and many more countries.

Continue reading: Hackers tricked bankers into installing malware, stole $300 million (full post)

Recent data breaches forcing companies to rethink cybersecurity fight

| Feb 14, 2015 4:06 PM CST

Companies are scrambling to defend against cyberattacks in an effort to prevent data breaches, but are struggling to find success. Cybersecurity experts warn they must realize that hackers will likely enter their systems, and have to find ways to defend attacks after unauthorized access already occurs.

Worldwide IT security spending was around $70 billion in 2014, according to Gartner research group estimates - but that figure will top $109 billion by 2020 for just banks, energy and defense contractors. Spending is going to keep increasing with the number of attacks also reaching new levels, experts warn.

"Once an attack has made it past those defenses they're in the gooey center, and getting around is relatively simple," said Ryan Wagner, director of product management at vArmour, in a statement to Reuters. "You need to make sure that when you close the door, the criminal is actually on the other side of the door."

Continue reading: Recent data breaches forcing companies to rethink cybersecurity fight (full post)

Companies must expect cybersecurity attacks, prepare for problems

| Feb 14, 2015 11:23 AM CST

Insurance companies and other healthcare-related businesses can expect additional cybersecurity scrutiny in the future, after Anthem suffered a major data breach.

To better fight against cyberattacks - and subsequent data breaches - companies should conduct cyber vulnerability risk assessments and penetration testing. Just a few years ago, these types of activities were seen as luxuries that very few companies engaged in, but now business leaders must look to ensure their networks are secure.

Cybercriminals are extremely opportunistic and look for any opportunity they can manipulate for their benefit:

Continue reading: Companies must expect cybersecurity attacks, prepare for problems (full post)

Obama wants an open debate regarding encryption security

| Feb 14, 2015 10:05 AM CST

President Barack Obama claims he supports strong computer data encryption more than many law enforcement agencies, though sided with them regarding the need to keep the public safe.

To help address the issue, Obama wants a "public conversation" to discuss encryption and security efforts.

"And so this is a public conversation that we should end up having," Obama told Re/code. "I lean probably further in the direction of strong encryption than some do inside of law enforcement. But I am sympathetic to law enforcement because I know the kind of pressure they're under to keep us safe. And it's not as black and white as it's sometimes portrayed."

Continue reading: Obama wants an open debate regarding encryption security (full post)

Nexusguard: Expect DDoS cyberattacks aimed at the Internet of Things

| Feb 13, 2015 5:57 PM CST

The Internet of Things (IoT) offers great connectivity for consumers, but is becoming a soft target for cyberattacks, according to the Nexusguard "2015 Internet Security Trend" report. Of note, distributed denial of service (DDoS) attacks greatly concern cybersecurity researchers, with criminals hoping to interrupt access to connected technology.

The current IoT infrastructure largely relies on shared libraries and a fast development cycle, with security sometimes included as an afterthought. To make matters worse, cybercriminals can hijack poorly secured "Things" and help use them in botnet attacks against other targets.

"With the Internet of Things, people are posting personal or commercially sensitive information," said Terrence Gareau, Chief Scientist of Nexusguard. "It's a very complex question how people are going to secure that data, especially with increasingly sophisticated attacks. Furthermore, hackers may be incentivized to infect IoT devices and use them as an army for botnet attacks. Additionally, the smokescreen of DDoS attacks used for covering up data exfiltration, market manipulation and extortion, are ever more present."

Continue reading: Nexusguard: Expect DDoS cyberattacks aimed at the Internet of Things (full post)

Visa will use smartphone tracking that will help clamp down on fraud

| Feb 13, 2015 4:09 PM CST

Credit card company Visa plans to release a new location-based feature that will give cardholders the chance to update their location via smartphone. Banks will include the Visa software in their smartphone apps starting in April, and cardholders will have a chance to opt into the program.

When the cardholder's smartphone enters a new city or country, the app updates Visa so they are aware if credit card transactions take place in the new geographic location. This will prevent charges from being declined - and members won't have to call to confirm their whereabouts.

"We will be able to compare the merchant's location to the most recent cellphone location to show it's a less risky transaction," said Mark Nelsen, executive at Visa, in a statement published by the AP.

Continue reading: Visa will use smartphone tracking that will help clamp down on fraud (full post)

Apple increases iCloud security with two-step verfication security

| Feb 13, 2015 4:33 AM CST

Apple has today announced a two-step verification process for iMessage and FaceTime applications, announced in the wake of the massive celebrity leak uncovered late last year.

This new system means that users will be asked to supply their username and password alongside a verification code that Apple will send to a device with granted access to these services. This process has been recommended by computer security experts, with them stating the obvious - a hacker gaining control to your username and password is much easier than doing the former and stealing your phone.

The username and password issues most commonly seen are due to people using the same email and password combination for numerous accounts. This means that if a hacker has access to your iCloud, they likely have access to your Facebook, email, Twitter and more.

Continue reading: Apple increases iCloud security with two-step verfication security (full post)

Cybercriminals want to compromise your identity, steal personal data

| Feb 12, 2015 4:20 PM CST

Cybercriminals have their pick of vulnerable targets to compromise, and want to focus more on conducting identity theft over just stealing payment information.

After a data breach, especially if a debit or credit card information has been stolen, compromised users ask their banks to cancel cards. However, a data breach in which names, addresses, Social Security numbers and other personal data are stolen give criminals the ability to take their time to launch future attacks.

"We're clearly seeing a shift in the tactics of cybercriminals, with long-term identity theft becoming more of a goal than the immediacy of stealing a credit card number," said Tsion Gonen, VP of strategy for identity and data protection of Gemalto. "Identity theft could lead to the opening of new fraudulent credit accounts, creating false identities for criminal enterprises, or a host of other serious crimes."

Continue reading: Cybercriminals want to compromise your identity, steal personal data (full post)

Damballa: Majority of antivirus solutions fail to detect malware

| Feb 12, 2015 3:30 PM CST

Antivirus products missed almost 70 percent of malware infections within the first hour of submission, according to Damballa's "Q4 2014 State of Infections Report." In addition, only 66 percent of malware signatures were accurately identified when rescanned within 24 hours of infection - with that number going up to 72 percent within seven days.

Antivirus security companies share malicious file findings with one another, but it takes time for new discoveries to be integrated into their own programs.

"What's clear from these figures is that we have to turn the table on infection 'dwell' time," said Brian Foster, CTO of Damballa. "In much that same way that a flu vaccine hinges on making 'best-guess' decisions about the most prevalent virus strains - AV is only effective for some of the people some of the time. Viruses morph and mutate and new ones can appear in the time it takes to address the most commonly found malware."

Continue reading: Damballa: Majority of antivirus solutions fail to detect malware (full post)

Anthem breach could help create focus on cybersecurity for insurers

| Feb 12, 2015 11:53 AM CST

Anthem's recent data breach should be a startling wakeup call to other insurance carriers and companies operating in the medical world.

Up to 80 million of the company's members could be at risk of identity theft, with hackers able to make off with client names, physical mailing addresses, birth dates, email addresses, Social Security numbers and medical ID data.

The cost of the breach could top $100 million, as Anthem's cyberinsurance policy will likely be exhausted following this incident.

Continue reading: Anthem breach could help create focus on cybersecurity for insurers (full post)

Report finds automakers failing to secure connected cars

| Feb 11, 2015 7:10 PM CST

Automakers want to embrace connected technology in new vehicles, but have failed to ensure proper cybersecurity protocols are available, according to Sen. Edward Markey (D - Mass.). The Senator believes almost all connected vehicles are vulnerable to some type of security risk, according to Markey's staff.

Following a number of security-related incidents showed connected cars are vulnerable, Markey wants to know what safeguards are being put in place to keep car owners secure. The report indicated "there is a clear lack of appropriate security measures to protect drivers against hackers who may be able to take control of a vehicle or against those who may wish to collect and use personal driver information."

"Drivers have come to rely on these new technologies, but unfortunately the automakers haven't done their part to protect us from cyberattacks or privacy invasions," Sen. Markey said in a statement.

Continue reading: Report finds automakers failing to secure connected cars (full post)

Will 2015 be the 'year of the healthcare hack' wonder security pros

| Feb 11, 2015 6:20 PM CST

The recent breach of Anthem was a brutal wakeup call that cybercriminals want personal records, and healthcare data is near the top of their list. UnitedHealth Group, Aetna and other groups have issued cybercrime-related warnings since 2011, but it didn't seem like a major concern among members until recently.

"A name, address, social and a medical identity... that's incredibly easy to monetize fairly quickly," said Bob Gregg, CEO of ID Experts, in a statement published by Reuters. Cybersecurity experts have warned that health-related data tends to be extremely lucrative on the black market.

Organized groups will try to target healthcare providers in an effort to compromise insurance companies, hospitals, doctor's offices, and medical equipment makers - with companies urged to improve their cybersecurity protocols.

Continue reading: Will 2015 be the 'year of the healthcare hack' wonder security pros (full post)

Popular Android dating apps pose cybersecurity risks

| Feb 11, 2015 2:43 PM CST

More than 60 percent of popular dating mobile apps pose significant cybersecurity risks, with personal user information and corporate data at risk.

Twenty six of 41 dating apps available for Google Android had medium or high severity vulnerabilities, according to the IBM Security researchers. In addition, dating apps are being used to download malware, along with credit card data stolen and GPS information used to track movements.

"Many consumers use and trust their mobile phones for a variety of applications," said Caleb Barlow, VP of IBM Security. "It is this trust that gives hackers the opportunity to exploit vulnerabilities like the ones we found in these dating apps. Consumers need to be careful not to reveal too much personal information on these sites as they look to build a relationship."

Continue reading: Popular Android dating apps pose cybersecurity risks (full post)

Smartphone kill switch legislation has led to drop in phone theft

| Feb 11, 2015 11:10 AM CST

The introduction of smartphone kill switches by manufacturers and wireless carriers helped reduce the number of device thefts in New York City, San Francisco, and London, supporters say. Apple iPhone theft in San Francisco dropped 40 percent, reported incidents slid 25 percent in New York, and thefts in London were cut in half.

The software kill switch allows phone owners to lock lost or stolen devices, along with bricking devices so they cannot be used or sold on the black market.

"The huge drops in smartphone theft have occurred since the kill switch has been on the market are evidence that our strategy is making people safer in our cities, and across the world," said Eric Schneiderman, New York State Attorney General, in a statement.

Continue reading: Smartphone kill switch legislation has led to drop in phone theft (full post)

Nation states launching cyberespionage attacks becoming normal

| Feb 11, 2015 10:25 AM CST

It's not just the United States and UK launching sophisticated cyberespionage attacks against foreign government states, with China, Russia, Iran, North Korea, and other nations increasingly jumping into the fun. Groups in China and Russia have been linked to major data breaches, such as Target, The Home Depot, Anthem and Sony Pictures, with future breaches expected to happen.

China is the most active country involved in launching cyberattacks, routinely targeting US infrastructure - and other lucrative targets, such as financial institutions and government departments. As witnessed by CrowdStrike, skilled Chinese hacker groups are able to adapt their strategies while avoiding detection.

The Obama administration has publicly criticized China for its cyberespionage activities, but has been unable to launch any meaningful political crackdowns.

Continue reading: Nation states launching cyberespionage attacks becoming normal (full post)

Ransomware attacks increasing, as cybercriminals perfect their skills

| Feb 11, 2015 9:15 AM CST

Consumers and business users face a wide variety of different cyberattacks, and security experts are increasingly concerned about ransomware. Ransomware, a custom form of malware designed to hijack computers and work files, typically encrypt vital documents - unless a ransom is paid.

Microsoft Windows PC users face the largest threat from CryptoWall, a ransomware variation that has uncrackable encryption and uses anonymity networks to avoid detection.

Another nasty form of ransomware recently discovered is Invincea, which delivers the payload straight to system memory instead of targeting files on a hard drive.

Continue reading: Ransomware attacks increasing, as cybercriminals perfect their skills (full post)

Companies should focus on neutralizing hackers once they are inside

| Feb 10, 2015 5:58 PM CST

Cybersecurity incidents are going to occur, and companies should rethink their current security strategies. Instead of focusing on preventing criminals from accessing their data - which has become increasingly difficult - decision leaders should have a plan in place for when a breach finally does occur.

The median length cybercriminals have inside a compromised victim's network is 229 days, which gives them a significant amount of time to access data, find additional loopholes, and plan what information they will take. Companies often are unaware a breach has taken place, and don't have an appropriate strategy to boot the hackers and secure their networks.

Typical cybersecurity defenses need to focus on having "a description of the bad guys before they can help you find them," said Dave Merkel, CTO of FireEye, in a statement published by the San Jose Mercury News. "That's just old and outmoded. And just doesn't work anymore. There's no way to guarantee that you never are the victim of a cyberattack."

Continue reading: Companies should focus on neutralizing hackers once they are inside (full post)

Join Our Newsletter

Join the TweakTown Newsletter for daily tech updates delivered to your inbox.

See previous giveaways.

Newsletter Subscription