Newsletter IconFacebook IconX IconThreads IconInstagram IconYouTube IconPinterest Icon
Giveaway: AVerMedia Creator Bundle (4K Webcam, Capture Card, Charging Hub, and Mouse Pad)

Hacking, Security & Privacy - Page 31

Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 31

Stay Updated

Follow TweakTown for breaking tech news, reviews, and daily updates.

Add TweakTown as a preferred source on GoogleFind TweakTown on Apple News

As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.

No surprise: Worst passwords of 2014 are still quite terrible

| Jan 20, 2015 12:38 PM CST

SplashData has published its list of the most common passwords used on the Internet, compiling data mainly from Internet users in North America and Western Europe. The top 10 worst passwords, per the SplashData list: 123456, password, 12345, 12345678, 1234, baseball, dragon, football.

Simple numerical passwords remain common, with nine of the top 25 passwords consisting of numbers only. However, passwords such as "iloveyou" have disappeared, which was prevalent on the 2013 list, has dropped from the top 25 list for 2014.

"The bad news from my research is that this year's most commonly used passwords are pretty consistent with prior years," said Mark Burnett, an online security expert. "The good news is that it appears that more people are moving away from using these passwords. In 2014, the top 25 passwords represented about 2.2 percent of passwords exposed. While still frightening, that's the lowest percentage of people using the most common passwords I have seen in recent studies."

Continue reading: No surprise: Worst passwords of 2014 are still quite terrible (full post)

US police have deployed radar that peers into homes

| Jan 20, 2015 9:28 AM CST

Troubling news is coming to light. Under a cloak of secrecy over 50 U.S. law enforcement have deployed radars that allow them to see through walls. These agencies include the FBI and the U.S. Marshals Service, and the project began over two years ago. These radars run afoul of a Supreme Court ruling that bans the use of high-tech sensors probing the inside of someone's home without a warrant, which helps to explain the total silence on the new radars.

The sensors are effective out to 50 feet and can detect human movement via radio waves. They are so sensitive they can even pick up human breathing. The new technology came to light during a December federal appeals trial of a parole absconder in Denver. During the trial officials revealed they used the device to locate the man, and the presiding judges sounded off that "the government's warrantless use of such a powerful tool to search inside homes poses grave Fourth Amendment questions."

The devices are manufactured by L-3 Communications under the Range-R product family. Each device costs $6,000 and over 200 devices have been sold to US law enforcement agencies. The radar displays if there is movement on the other side of the wall, and displays how far away the movement is. The Range-R doesn't actually show the inside of the building, but there are other models that do. There are similar radar devices that feature 3-D displays of the location of people in a building, and the Justice Department is already funding development systems that can map entire buildings and locate people, so they surely have no qualms with deploying these devices.

Continue reading: US police have deployed radar that peers into homes (full post)

Obama Administration also doesn't want encryption to interfere

| Jan 19, 2015 4:12 PM CST

Not surprisingly, President Barack Obama has sided with UK Prime Minister David Cameron's demand that computer companies provide a backdoor to governments, even of encrypted communications. The US government has relied on a mix of warrants, wiretaps and direct access from technology companies so they have access to phone calls, social media, and other communications.

Simply demanding access to encrypted communication isn't worthwhile, so Obama played to emotions with his justification: "If we find evidence of a terrorist plot... and despite having a phone number, despite having a social media address or email address, we can't penetrate that, that's a problem," Obama recently said.

Obama wants to ensure a way to keep data private from cybercriminals, but not from police authorities and federal investigators.

Continue reading: Obama Administration also doesn't want encryption to interfere (full post)

Universities trying to close cybersecurity research gap

| Jan 19, 2015 3:42 PM CST

The FBI and other US government departments want to recruit cybersecurity specialists, while the private sector also is throwing big money at qualified job candidates. To help fill this jobs void, a growing number of universities are creating programs to develop the next wave of security specialists.

Cybersecurity jobs soared 74 percent from 2007 to 2013, and there are a number of appealing opportunities for candidates. With such fierce competition for the current crop of security specialists, universities are broadening security-themed offerings from one or two courses to minor and major programs, or certifications.

"The demand is very high. I've had students get into cyberspace companies with just one security class, never mind an entire major," said Kenneth Knapp, IT management professor at University of Tampa and head of its cybersecurity program. "With all of the high-profile breaches over this last year or so, more focus has been on security than I've ever seen, and I've been doing it since I was 21 years old in the Air Force."

Continue reading: Universities trying to close cybersecurity research gap (full post)

Edward Snowden leaks confirm China stole Aussie F-35 JSF plans

| Jan 19, 2015 1:42 PM CST

Chinese cybercriminals stole data related to the B-2 stealth bomber, F-22 Raptor, a nuclear submarine, and Australia's new F-35 Lighting II aircraft, according to data taken by former NSA contractor Edward Snowden. The Australian government plans to purchase 58 F-35 fighter jets for $12 billion, which will bring its JSF fleet up to 72 total.

Using a mix of its own research and development, along with data stolen from western political rivals, China continues to develop its own Shenyang J-31 and Chengdu J-20 aircraft. The J-31 is the most advanced Chinese fighter jet, while the J-20 is the country's first effort to develop a stealth fighter.

The Chinese government has been accused on numerous occasions of running sophisticated cyberespionage attacks against the United States - and its key allies - to steal software code, hardware designs, and military technology.

Continue reading: Edward Snowden leaks confirm China stole Aussie F-35 JSF plans (full post)

US reportedly penetrated North Korean computer networks in 2010

| Jan 19, 2015 12:34 PM CST

It would appear the National Security Agency (NSA) is responsible for breaching North Korea's computer systems years ago, before North Korea's alleged role in attacking Sony Pictures. With help from select allies, the NSA targeted North Korea's links to the outside world, such as China and Malaysia.

US security officials installed malware so they were able to monitor the online movements of North Korea's Bureau 121 hackers - a group growing in sophistication - as cyberespionage becomes more popular.

When the FBI was so quick to conclude North Korea was responsible for attacking SPE in late 2014, the cybersecurity industry was skeptical. FBI Director James Comey previously said the hackers got sloppy and forgot to mask their IP addresses. "We could see that the IP [Internet protocol] addresses that were being used to post and to send the emails were coming from IPs that were exclusively used by the North Koreans."

Continue reading: US reportedly penetrated North Korean computer networks in 2010 (full post)

Lizard Squad's DDoS attack service hacked, as pressure mounts

| Jan 18, 2015 3:32 PM CST

Unknown cybercriminals breached the Lizard Squad's LizardStresser distributed denial of service (DDoS) service, which serves customers as an attack-for-hire tool. There are more than 14,000 registered users, with $11,000 collected via bitcoin to help pay for DDoS attacks against thousands of website URLs and IP addresses.

The Lizard Squad reportedly brought down Microsoft Xbox Live and Sony PlayStation Network (PSN) to promote its service.

Lizard Squad appears to have a number of younger members contributing to its cybercriminal operation, though several reported members have been arrested across the world. However, core members of the group still haven't been identified and arrested, so future cyberattacks are expected to continue against higher-profile targets.

Continue reading: Lizard Squad's DDoS attack service hacked, as pressure mounts (full post)

Hackers List helps you search for your most suitable candidate

| Jan 17, 2015 2:23 AM CST

"It could be used for legitimate reasons, right?" was the first thought that went through my head when looking at this website - well that's apparently not the case. If you're looking to seek revenge or hold a grudge and have money to spend - Hackers List will enable you to list up your task and a price - helping you search for the most suitable hacker for your needs.

As described by the New York Times, there are potential clients on here including a Sweedish man offering up $2,000 for someone to hack into his landlord's website and even a lady from California ready to pony up $500 for someone to gain access to his Facebook and Gmail accounts - talk about a healthy relationship!

With over 500 jobs currently listed, everything is completed completely anonymously, with the website working as the 'middle man' when it comes to jobs, correspondence and payment.

Continue reading: Hackers List helps you search for your most suitable candidate (full post)

John McAfee says North Korea isn't responsible for SPE data breach

| Jan 16, 2015 5:26 PM CST

The FBI insists North Korea is responsible for breaching Sony Pictures, while some cybersecurity experts aren't so sure. John McAfee, an eccentric cybersecurity pioneer, says he knows what group is responsible for breaching SPE - and it wasn't the North Koreans.

"I can guarantee they are wrong,"McAfee recently told IBTimes UK, while speaking about the FBI's assertion that North Korea is involved. "It has to do with a group of hackers - I will not name them - who are civil libertarians and who hate the confinement the restrictions the music industry and the movie industry has placed on art and so they are behind it."

McAfee spent much of his career defending users and companies against hackers - but has a mutual respect for hackers today, saying "they want freedom, freedom of expression, freedom to live unobserved."

Continue reading: John McAfee says North Korea isn't responsible for SPE data breach (full post)

North Korea's hackers seek theft, retribution against targets

| Jan 16, 2015 3:59 PM CST

Kim Jong-un became "supreme leader" of North Korea at a young age, and has shown political instability since his reign began in 2011. The North Korean government, meanwhile, has steadily invested time and resources into its Bureau 121 hacker division, aiming to compromise political rivals.

"In the case of the DPRK, the paranoia is amplified to the extreme," according to a commentary written about North Korea's cyberattack motivations on InformationWeek's Dark Reading. It's true that the North Korean government, which strives to maintain full control of its citizens, is suspicious of all outsiders - and launching cyberattacks to steal information has evolved into a valuable asset.

The FBI continues to say North Korea is behind the major data breach of Sony Pictures - and whether the reclusive government is responsible - foreign governments and cybersecurity companies are paying attention to Pyongyang's rising cyberattack capabilities.

Continue reading: North Korea's hackers seek theft, retribution against targets (full post)

NSA, GCHQ plan to step up cybersecurity cooperation efforts in 2015

| Jan 16, 2015 1:46 PM CST

The US National Security Agency (NSA) and British GCHQ intelligence agencies plan to step up their cybersecurity cooperation, as both governments face increasing numbers of cyberattacks. The agencies plan to launch cyber war games to test the cybersecurity of financial institutions, hoping to defend against the "biggest modern threats that we face."

"We have got hugely capable cyber defenses, we have got the expertise and that is why we should combine as we are going to, set up cyber cells on both sides of the Atlantic to share information," said British Prime Minister David Cameron during a press conference.

Following mass surveillance operations detailed by former NSA contractor Edward Snowden, critics said the US and UK government should focus on beefing up cybersecurity efforts - instead of spying on citizens, residents, and foreign governments - as cyberespionage campaigns target both countries.

Continue reading: NSA, GCHQ plan to step up cybersecurity cooperation efforts in 2015 (full post)

Police make arrest in PlayStation and Xbox Live attacks

| Jan 16, 2015 11:03 AM CST

The Lizard Squad made waves with their massive DDoS attacks on PlayStation and Xbox Live networks over the Christmas holiday. These attacks spoiled Christmas for untold millions of people as the DDoS attacks crippled servers and left shiny new game consoles unable to connect to online services. These attacks appear to be part of a larger marketing scheme for the Lizard Squad's DDoS-for-hire services.

The Lizard Squad isn't afraid to taunt authorities and that has drawn even more scrutiny. However, they have been very successful at remaining in the shadows, until now. UK police with the South East Regional Organized Crime Unit (SEROCU) cyber crime unit apprehended an 18-year-old male connected with the recent PlayStation and Xbox Live DDoS attacks. The man was also charged with several swatting incidents, in which a fake police call is made to instigate police raids against others.

The Lizard Squad has also been connected with a bomb threat issued to an airline. This threat was made on an aircraft in the air that had a Sony executive among the passengers. This type of escalation has likely led to a heightened sense of urgency for officials to find those behind the shadowy Lizard Squad. The SEROCU worked closely with the FBI to apprehend the suspect, which suggests that The Lizard Squad is high on the FBI's priority list.

Continue reading: Police make arrest in PlayStation and Xbox Live attacks (full post)

Companies need assistance with their efforts to defend cyberattacks

| Jan 16, 2015 10:16 AM CST

Cybercriminals want to breach US companies, stealing data and customer records, and have found surprising levels of success. Some breached companies eventually discover that criminals spent months poking aroun compromised systems, taking their time before stealing large amounts of data.

The US government wants companies to be more forthcoming about data breaches once they are discovered, but some companies - if they actually know about it - remain quiet. Companies will be given some leeway if they inform the Department of Homeland Security (DHS) about cybersecurity incidents after they do occur, according to changes the Obama Administration plans to put in place.

"There is an element of embarrassment at work here," said Robert Cattanach, partner at the Dorsey & Whitney law firm, in a statement published by reporters. "But hacking is not a problem that any one company can solve alone."

Continue reading: Companies need assistance with their efforts to defend cyberattacks (full post)

Report reveals DHS is a cybersecurity mess, with numerous problems

| Jan 16, 2015 5:35 AM CST

The Department of Homeland Security (DHS) is a bureaucratic mess when it comes to cybersecurity - and would be inefficient and overmatched trying to protect citizens and other federal branches. This news comes as part of the "A Review of the Department of Homeland Security's Missions and Performance" report, which heavily scrutinized DHS activities.

"Widespread weaknesses in the federal government's information security practices represent a significant vulnerability that could be exploited by adversaries, creating a potential threat to national security and American citizens," according to the report.

It's not just hacktivists trying to breach US infrastructure, but foreign states with sophisticated cyberespionage programs. The DHS itself has failed in maintaining its own security protocols, let alone trying to secure other departments from potential cyberattack.

Continue reading: Report reveals DHS is a cybersecurity mess, with numerous problems (full post)

French cyberdefense says 19,000 French websites under attack

| Jan 16, 2015 2:58 AM CST

The French government announced there are 19,000 civilian websites now under cyberattack by unknown sources, in a wide-ranging attack. The French Defense Ministry recently faced a targeted distributed denial of service (DDoS) attack, according to officials discussing the ongoing cyber operation.

"These attacks have no effect on the conduct of our operations," said Rear Admiral Arnaud Coustilliere, in a statement to CNNMoney. Reportedly, the attacks are targeting websites while hoping for weak cyber defenses, though the top visited French websites appear to be working fine.

Over the past week, cybercriminals have posted pro-Islamic images and messages on various religious groups websites and other sites. The Anonymous hacker group temporarily downed a jihadist website last week and the Charlie Hebdo magazine released a new edition that has sold millions of copies.

Continue reading: French cyberdefense says 19,000 French websites under attack (full post)

Lookout: Mobile malware skyrocketed 75 percent in 2014 alone

| Jan 15, 2015 2:04 PM CST

The threat of mobile malware continues to increase, with rates jumping 75 percent in 2014, according a report published by Lookout. Mobile users are urged to run some type of anti-virus and anti-malware security platform on their smartphones and tablets, as threats rise.

There are a number of different types of attacks, but ransomware has cybersecurity firms extremely anxious, especially as users download apps and other files from unknown sources. It may be harder to infect users with ransomware, but payouts are larger, as victims have to turn over a ransom for full control of their devices again.

"It all goes back to monetization, what's the endgame?" pondered Kevin Mahaffey, co-founder and CTO of Lookout, in a statement published by CNBC. "While it can be complicated it can generate a huge amount of money. The bad guys aren't stupid and they wouldn't do this if they weren't making money."

Continue reading: Lookout: Mobile malware skyrocketed 75 percent in 2014 alone (full post)

Microsoft wireless keyboards targeted by new $10 DIY sniffing device

| Jan 15, 2015 10:42 AM CST

A security researcher has developed a USB wall charger that can intercept, log, and decrypt signals sent from Microsoft's wireless keyboards. The KeySweeper was developed by Samy Kamkar, a giving sort, who has released instructions on how to build the device online.

The KeySweeper can be built for as little as $10 and simply appears to be a typical, and functional, USB wall charger. The charger monitors all Microsoft keyboards in range. The transmissions are encrypted, but the researcher has found multiple bugs that enable easy decryption. The design also includes optional features, such as an internal rechargeable battery that keeps the device working even after being unplugged, and SMS notification when keywords are typed into the keyboard.

There is a detailed build log on GitHub, and also a video on YouTube. Microsoft has fired back by insisting that all models manufactured after 2011 feature AES encryption, which isn't decoded by the system, but Samy Kamkar has recently purchased a vulnerable model from Best Buy last month.

Continue reading: Microsoft wireless keyboards targeted by new $10 DIY sniffing device (full post)

JPMorgan Chase asked to turn over data regarding cybersecurity hack

| Jan 14, 2015 8:36 PM CST

Numerous states are now investigating a major data breach suffered by JPMorgan Chase in 2014, asking the company to turn over details regarding its security practices. Customer records that included names, addresses and phone numbers of up to 83 million members were stolen, though account numbers, passwords and Social Security numbers weren't impacted.

"Critical facts about the intrusion remain unclear, including details concerning the cause of the breach and the nature of any procedures adopted or contemplated to prevent further breaches," according to the letter obtained by Reuters, which more than one dozen states sent to JPMorgan Chase.

States also asked if the bank received reports of fraud, and a description of its past and current security protections.

Continue reading: JPMorgan Chase asked to turn over data regarding cybersecurity hack (full post)

Cybercriminals will follow users to Apple Pay, other mobile systems

| Jan 14, 2015 5:11 PM CST

Apple Pay is helping lead a mobile payment revolution, with consumers and retailers seeing a wider number of payment options at checkout. Mobile security is expected to reach upwards of $11 billion in 2015 alone, industry analysts forecast, and trying to keep mobile payment platforms will need special attention.

Upwards of 30 million smartphones could be used for mobile payments worldwide, according to Deloitte, with five percent of NFC-equipped devices estimated to be used for in-store transactions. If interest is accelerating in mobile payment adoption, then it's likely cybercriminals will adapt their attack strategies.

"It's very easy to predict that as the adoption of mobile payment systems like Apple Pay increases, that attacks will grow to follow that," said Chris Doggett, North American managing director at Kaspersky Lab, in an interview with the Washington Post. "It's like that famous saying, 'Why do you rob banks? Because that's where the money is.' If Apple Pay becomes a big, pervasive system for payments, you can be sure that the criminals are going to be right behind, figuring out how to breach Apple's security and how to steal money."

Continue reading: Cybercriminals will follow users to Apple Pay, other mobile systems (full post)

Report: Employees pose biggest IT cybersecurity threat to companies

| Jan 14, 2015 4:09 PM CST

Even with cybercriminals using sophisticated attack methods to compromise companies, business leaders must deal with employees recklessly clicking links and installing unknown software, according to the "2015 State of the Endpoint" study.

Seventy-eight percent of surveyed IT professionals believe careless employees are the biggest threat, 68 percent blame personal devices in the workplace, and 66 percent cite commercial cloud apps used at work.

"Respondents in this year's study have shifted their thinking and are now also attributing endpoint risk to human behavior in addition to particular device vulnerabilities," said Chris Merritt, director of solution marketing at Lumension. "This is a significant cultural shift to note because it illustrates how IT is starting to look at cybersecurity holistically. In addition to technology solutions, in 2015 IT must also take into account company policies and control processes, user awareness and overall employee education."

Continue reading: Report: Employees pose biggest IT cybersecurity threat to companies (full post)

Join Our Newsletter

Join the TweakTown Newsletter for daily tech updates delivered to your inbox.

See previous giveaways.

Newsletter Subscription