Hacking, Security & Privacy - Page 29
Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 29
Stay Updated
Follow TweakTown for breaking tech news, reviews, and daily updates.
As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.
United States creates cybersecurity center to help study cyber threats
The United States publicly unveiled its Cyber Threat Intelligence Integration Center (CTIIC), a new program designed to study cyber threats facing government agencies.
The idea of increased communication between federal government agencies, law enforcement and private sector corporations seems like a wise idea - but is going to be extremely difficult. The CTIIC wants to create a first step towards that goal, with government agencies and law enforcement coordinating to discuss current cyberattack patterns.
Even though the US government is being pressured to become more proactive in the fight against cyberattacks, some have questioned if the CTIIC will be an effective tool. "In principle, having a single 'belly button' is a nice idea," said Jeff Williams, CTO and founder of Contrast Security, in a statement to NBC News. "But in reality, it's just one more agency with cybersecurity responsibility."
Continue reading: United States creates cybersecurity center to help study cyber threats (full post)
The 'CyberCaliphate' hacks Newsweek, other Twitter feeds
The main Twitter page for Newsweek was hacked by CyberCaliphate, a mysterious pro-ISIS group, with a new profile picture, main image and number of tweets posted. A series of tweets also took aim at the first lady Michelle Obama and her family, threatening them - and the FBI is now investigating the matter.
"We apologize to our readers for anything offensive that might have been sent from our account during that period, and are working to strengthen our newsroom security measures going forward," said Kira Bindrim, Managing Editor of Newsweek, in response to the data breach.
Newsweek was able to regain control of its Twitter account in 20 minutes, but the hijacked Twitter messages were tweeted and shared among the news organization's 2.51 million followers.
Continue reading: The 'CyberCaliphate' hacks Newsweek, other Twitter feeds (full post)
Chipotle apologizes after cyberattack leaves Twitter page defaced
Popular fast casual restaurant Chipotle has issued an apology to its Twitter followers, after being hacked over the weekend. Insensitive tweets were published to more than its 634,000 followers, including racist messages aimed at President Obama - before Twitter could suspend the account. A separate tweet claimed the company would be shutting restaurants before the end of the year.
The attack also reportedly hit the official Chipotle website, which led visitors to a different website.
"Our Twitter account was hijacked overnight for about two hours during which a series of offensive tweets was posted to the account," said Chris Arnold, communications director of Chipotle. "We apologize for the nature of the posts that were made during that time, and we are now conducting an investigation to try to determine what happened and who might have been involved."
Continue reading: Chipotle apologizes after cyberattack leaves Twitter page defaced (full post)
New York plans to conduct cybersecurity audits of insurers
In the aftermath of the Anthem data breach last week, the New York Financial Services Department said it plans to conduct cybersecurity audits of insurance companies. The "regular" and "targeted assessments" will be a part of its examination process, and enhanced regulations should keep New York insurance members safer from future data breaches.
The Anthem data breach could affect upwards of 80 million people, as personal information was taken during the sophisticated cyberattack.
"We're still in the process of finalizing and determining the enhanced requirements, but we are moving quickly and expect to begin putting them forward in the coming weeks," said Matt Anderson, spokesman of the New York Financial Services Department, in a statement published by Reuters. "These requirements are specific to New York, but we're of course always willing to discuss these issues with other states."
Continue reading: New York plans to conduct cybersecurity audits of insurers (full post)
Anonymous calls ISIS a 'virus,' promises to disrupt group online
The Anonymous hacker collective is taking aim at ISIS in Syria and Iraq, launching attacks to disrupt the group's social media accounts. As part of its #OpISIS campaign, Anonymous has taken down hundreds of Twitter, Facebook, and other social media accounts linked to ISIS - used to spread propaganda and woo potential recruits.
"ISIS: We will hunt you, take down your sites, accounts, emails and expose you," Anonymous pledges. "From now on, no safe place for you online... you will be treated like a Virus, and we are the cure. We own the Internet. We are Anonymous; we are Legion; we do not forgive, we do not forget. Expect us."
In addition to listing Twitter and Facebook accounts - of both compromised accounts and possible targets - Anonymous has revealed email addresses, IP addresses, VPN connections and websites used by the extremist group.
Continue reading: Anonymous calls ISIS a 'virus,' promises to disrupt group online (full post)
Expert: Trying to keep companies, data secure from cyberattack is hard
The recent data breach suffered by Anthem is further proof that companies are under cyberattack - and find it difficult to keep up with increasing numbers of sophisticated attacks. Many corporations understand they face cybersecurity threats, but can do very little to prevent crippling data breaches.
"For any given unit of time that goes by, the probability of an organization being compromised is trending to 100 percent," said John Hering, co-founder of the Lookout security firm, in a statement to CNBC. "We need to move to a world where security is not reactive, but proactive and predictive."
Financial institutions and medical companies typically have more stringent security protocols in place, but still find it difficult to prevent attacks. Late last year, JPMorgan Chase suffered a data breach that affected millions of customers, with phishing attacks and other threats targeting compromised victims.
Continue reading: Expert: Trying to keep companies, data secure from cyberattack is hard (full post)
Syrian forces targeting rebel forces with social engineering attacks
Opposition fighters trying to overthrow the regime of Syrian President Bashar al-Assad have fallen prey to one of the oldest social engineering tactics: hackers use fake Facebook and Skype profiles of young, beautiful women to target rebels, inviting them to chat. Pictures are exchanged, though the hackers load images with malware able to copy chat logs and steal strategic information.
The tactic continues to work on oblivious Syrian fighters, continually chatting with pro-Assad hackers - and the results have been devastating. A FireEye report revealed 7.7GB of data has been compromised, along with more than 12,000 contacts and 31,000 Skype conversations.
"We are really seeing the convergence of traditional methods of espionage and Internet communication tools," said Richard Turner, EMEA VP of FireEye, told CNBC. "The evidence of that is the use of the attractive lady avatar to generate interest and open up individuals to deliver malware and compromise their communication."
Continue reading: Syrian forces targeting rebel forces with social engineering attacks (full post)
Pres. Obama wants $14 billion to boost nation's cybersecurity defenses
In an effort to protect federal and private computer assets from cyberattacks, President Barack Obama wants to receive $14 billion in the 2016 fiscal year to put towards cybersecurity. The US government has increasingly called upon defense contractors and the private sector to provide next-generation software and hardware designed to help keep critical infrastructure safer from attack.
As part of his multi-billion-dollar cybersecurity effort, Obama wants to include additional intrusion detection and prevention solutions, along with increased intelligence sharing between the government and private sector.
"Cyber threats targeting the private sector, critical infrastructure and the federal government demonstrate that no sector, network or system is immune to infiltration by those seeking to steal commercial or government secrets and property or perpetrate malicious and disruptive activity," according to a White House summary.
Continue reading: Pres. Obama wants $14 billion to boost nation's cybersecurity defenses (full post)
RansomWeb appears to be emerging new cyberattack against victims
A new cyber threat victimizing users is the 'RansomWeb' attack, which leaves compromised websites encrypted - and they will remain that way until the victim pays a ransom to cyberattackers. The threat was first detected by cybersecurity firm High-Tech Bridge, investigating a client website, which displayed a database error.
The cybercriminals demanded a $50,000 ransom in exchange for decrypting the database, despite it being compromised six months prior. A closer inspection found that several server scripts were edited so data was encrypted before it was submitted to the database, and data was decrypted after being pulled from the database.
Instead of an immediate ransom demand - like ransomware attacks against business users - the cybercriminals patiently waited until backups were also overwritten.
Continue reading: RansomWeb appears to be emerging new cyberattack against victims (full post)
Recent fake Facebook porn links infecting systems with a Trojan virus
Don't ever click porn links on Facebook - it's a very good rule to follow in general, however if you're looking to get a porn fix through this popular social media, you need to be extremely alert and aware. Reportedly infecting over 110,000 Facebook users within two days, not everyone is as smart as you might have hoped.
Disguised as a Flash update, this disguised-malware post will tell you to quickly download and run an update in order to see a withheld porn video - doing so will download a Trojan directly onto your system, allowing a hacker to take control of your keyboard and mouse. This virus will then start linking multiple similar links on your wall and tagging up to 20 friends with each post.
Facebook have released an official statement on the matter, saying "we use a number of automated systems to identify potentially harmful links and stop them from spreading. In this case, we're aware of these malware varieties, which are typically hosted as browser extensions and distributed using links on social media sites." In order to cull the wave of infections, Facebook is "blocking links to these scams, offering cleanup options, and pursuing additional measures to ensure that people continue to have a safe experience on Facebook."
Continue reading: Recent fake Facebook porn links infecting systems with a Trojan virus (full post)
Report: Single DDoS attack could cost an organization $400,000
Companies are under cyberattack, and a single distributed denial of service (DDoS) attack could cost companies from $52,000 up to $444,000 depending on how large the company is. Enduring downtime due to a DDoS cyberattack also hurts the company's public relations image, with disclosures made to customers and federal regulatory bodies.
Following a DDoS attack, 61 percent of victims lost access to critical business information, while 38 percent were unable to conduct day-to-day business operations. As cybercriminals are becoming more organized - and finding new strategies to launch cyberattacks - volumetric attacks tend to be increasing, outnumbering application-layer attacks.
"A successful DDoS attack can damage business-critical services, leading to serious consequences for the company," said Eugene Vigovsky, head of the Kaspersky DDoS protection at Kaspersky Lab. "For example, the recent attacks on Scandinavian banks caused a few days of disruption to online services and also interrupted the processing of bank card transactions, a frequent problem in cases like this."
Continue reading: Report: Single DDoS attack could cost an organization $400,000 (full post)
ACLU: DEA conducting massive license plate reader operation
The Drug Enforcement Agency (DEA) is currently engaged in a widespread license plate reader program nationwide, and millions of license plates have been collected, according to a report from the American Civil Liberties Union (ACLU). The campaign started in 2008 and focused on taking pictures of vehicles, occupants and license plates, in an effort to identify and better track suspected criminals smuggling drugs and money to and from Mexico.
"It's not the kind of information government should be compiling," said Jay Stanley, a policy analyst for the ACLU, in a statement to the media. "Location data is very powerful information."
The following states were targeted, based on popular drug smuggling routes on highways: California, Arizona, New Mexico, Nevada, Texas, Georgia, Florida and New Jersey. Once collected and archived, the DEA shared information with local and state policy officials. Data was stored on record for two years until 2012, when program officials dropped it down to six months, the ACLU report found.
Continue reading: ACLU: DEA conducting massive license plate reader operation (full post)
Taylor Swift fights back at hackers who claim they have naked pictures
Hackers hijacked Taylor Swift's Twitter and Instagram accounts today, threatening to release naked pictures of the popular singer. Swift has bitten back, announcing on her Twitter that there are no 'nudes' to be had and the only way they could 'uncover' anything would be to use Photoshop.
After stating that her Twitter had been compromised though Tumblr, she later announced that her Instagram had also fallen victim. People are questioning if the superstar has been using the same password for multiple social media accounts, as it's uncommon to see a small amount of accounts compromised like this - usually its a singular service taken or its everything in one go.
The hacker-made tweets have now been deleted from her account and everything has gone back to normal. Seemingly Swift has been able to shake it off quite well - laughing in the face of the hackers.
Continue reading: Taylor Swift fights back at hackers who claim they have naked pictures (full post)
Cyberattacks expanding, with hacktivists, others enjoying DDoS attacks
Launching cyberattacks against targets once was a time intensive, difficult and costly effort, but it has become easier and inexpensive to launch distributed denial of service (DDoS) attacks.
Groups such as Anonymous and Lizard Squad are able to launch devastating attacks against large corporations and major targets using botnets of hijacked computers and routers. However, companies are becoming better at identifying these types of cyberattacks, but prove to be hugely inconvenient when the attacks succeed.
"There's been a massive jump in the number of very large attacks going on out there," said Darren Anstee, senior analyst at Arbor, while speaking to BBC. "In 2014 we saw more volumetric attacks, with attackers trying to knock people offline by saturating their access to the Internet."
Continue reading: Cyberattacks expanding, with hacktivists, others enjoying DDoS attacks (full post)
US Justice Department tracking location of millions of vehicles
The US government is no stranger to casting a large net in hopes of catching a few fish, so news of a new vehicle tracking database isn't entirely surprising. The Justice Department has a sophisticated database to track vehicle movements, and several other agencies are already using the data.
Several US law enforcement agencies already use automated license plate scanners mounted to police vehicles, and there also stationary systems that monitor highways and also take pictures of the vehicles. Some of these systems can actually be used to identify individuals inside of the vehicles.
The Justice Department has noted that there are already 343 million records in the database. This data includes the vehicle, time, and direction of travel. The primary intention is to find trafficking offenders for the DEA, but the Justice Department plans to expand the system to search for vehicles involved in rapes and murders. There is no word if the system will be expanded to encompass even more types of crime.
Continue reading: US Justice Department tracking location of millions of vehicles (full post)
Deutsche Telekom: Mobile devices weak spot in fight against cybercrime
Companies have struggled against cyberattacks and distributed denial of service (DDoS) attacks, while mobile devices remain "the perfect target for attackers," said Thomas Tschersich, Deutsche Telekom's computer security chief.
Cybercriminals are able to easily compromise mobile devices, and with connection speeds via mobile topping many home broadband connections, can be exploited to launch attacks against targets. To counter this threat, Deutsche Telekom informs around 20,000 German subscribers per month about malware infection - and urges them to remove the malware.
Despite Deutsche Telekom's proactive efforts, attack bandwidth is estimated at several gigabytes per hour from these mobile devices. For just a couple hundred euros, criminals are able to launch attack and generate an impressive return on investment (ROI) for their efforts.
Continue reading: Deutsche Telekom: Mobile devices weak spot in fight against cybercrime (full post)
Israeli cybersecurity expert says business leaders need more knowledge
Business leaders need to become more computer literate so they are better able to understand evolving threats posed by cybercriminals. Criminals are using the digital equivalent of an F-16 fighter jet to launch attacks against governments and corporations, finding surprising levels of success, according to an Israeli cybersecurity expert.
"The breakers in cyber are one step ahead of the makers... we're out of equilibrium," said Nadav Zafrir, former Israel Defense Force tech commander and founder of Team8 Cyber Security Venture Creation, during a recent meeting with corporate leaders. "You have to redefine control. You have to let go, and it's scary. It's too important to leave it to the cyber experts. You [the CEO] have to become cyber literate."
Business leaders are confused in their efforts to defend against cyberattacks, often unsure how to prevent data breaches - and what to do if one occurs. However, analysts and experts recommend companies focus on preventing insider attacks, try to clamp down on outside threats, and have a recovery plan in case a breach does take place.
Continue reading: Israeli cybersecurity expert says business leaders need more knowledge (full post)
Dennis Rodman doesn't believe his friends in Pyongyang hacked Sony
Dennis Rodman doesn't believe North Korea is responsible for attacking Sony Pictures, with the former NBA champion thinking Pyongyang wouldn't lash out against Sony Pictures just for making "The Interview."
"If the North wanted to hack anything in the world, anything in the world, really, they are going to go hack a movie? Really?!" Rodman recently said in an interview with The Hollywood Reporter. "How many movies have there been attacking North Korea? And they never hacked those. North Korea is going to hack a comedy, a movie that is really nothing? I can't see that happening. Of all the companies... really? Over a movie?
It's worth noting, however, North Korea has been blamed for attacking South Korean infrastructure, including financial institutions - and has a budding cybercriminal unit that is well-trained and financed by Pyongyang. Furthermore, if North Korea actually is responsible for breaching SPE, it was likely done to further develop its cyberespionage abilities that could be used against future targets.
Continue reading: Dennis Rodman doesn't believe his friends in Pyongyang hacked Sony (full post)
Mojang: Minecraft passwords compromised by phishing, not hacking
Reports were published within the past week that more than 1,800 Minecraft accounts were hacked, with passwords leaked online - but the company has defended itself, and it looks like phishing attacks are to blame.
"No! We haven't been hacked," said Owen Hill, Chief World Officer at Mojang, in a published blog post. " No one has gained access to the Mojang mainframe. Even if they did, we store your passwords in a super encrypted format. Honestly, you don't need to panic."
Affected Minecraft players have been emailed and will now need to reset their passwords. If you want to change your password just in case, head to Minecraft.net/resetpassword.
Continue reading: Mojang: Minecraft passwords compromised by phishing, not hacking (full post)
Companies must 'update their security' plans to improve security
Business leaders are paying attention to cybersecurity more than they were in recent years, but struggle to find methods to keep networks secure. Trying to determine what steps to take remains a complicated issue, especially with some companies discovering data breaches months after the initial incident occurs.
There are a number of potential problems for companies trying to keep their networks secure, as potential attacks originate from a variety of sources. Much focus is dedicated to preventing a breach, but business leaders also need to focus on the likelihood that a cyberattack was successful:
"The role of organized crime and government-sanctioned hacking will continue to thwart cybersecurity efforts [in 2015]," said JF Roy, CTO of TIBCO LogLogic, in a statement to TweakTown. "Breaches will continue to be discovered after the fact, which means that businesses must update their security and risk management plans to include incident response policies with contingencies for involvement of federal law enforcement."
Continue reading: Companies must 'update their security' plans to improve security (full post)


