Newsletter IconFacebook IconX IconThreads IconInstagram IconYouTube IconPinterest Icon
Giveaway: AVerMedia Creator Bundle (4K Webcam, Capture Card, Charging Hub, and Mouse Pad)

Hacking, Security & Privacy - Page 32

Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 32

Stay Updated

Follow TweakTown for breaking tech news, reviews, and daily updates.

Add TweakTown as a preferred source on GoogleFind TweakTown on Apple News

As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.

NSA: Snowden approached government with questions, not concerns

| Jan 14, 2015 1:17 PM CST

Former NSA contractor Edward Snowden recently said he went through the "channels" to inquire about oversight and compliance regarding NSA activities, but was shut down by big bureaucracy.

However, the NSA said they conducted an investigation and "have not found any evidence to support Mr. Snowden's contention that he brought these matters to anyone's attention," the NSA noted.

"The email, provided to the committee by the NSA on April 10, 2014, poses a question about the relative authority of laws and executive orders - it does not register concerns about NSA's intelligence activities, as was suggested by Snowden in an NBC interview this week," said Sen. Dianne Feinstein (D - Calif), chair of the Senate Intelligence Committee, in a statement.

Continue reading: NSA: Snowden approached government with questions, not concerns (full post)

Cybercriminal underground allows for custom modes of future attacks

| Jan 14, 2015 2:11 AM CST

Cybercrime is maturing while those interested in launching attacks are better organized and skilled with their ability to breach networks. There are a growing number of paid cyberattack tools available on the black market, which can be custom scripted for additional payments, broadening the scope of these attacks.

Following its success of dropping the Microsoft Xbox Live and Sony PlayStation Network on Christmas, the Lizard Squad hacker group showed off its distributed denial of service (DDoS) tool. The DDoS-for-hire attack service, dubbed Lizard Stresser, put the for-pay cyberattack market in front of a larger audience - and it appears people are interested.

"I really feel Lizard Squad has upped the ante on the DDoS for hire market," said Terrence Gareau, Chief Scientist at NexusGuard, in a statement to SiliconANGLE. "They have taken an approach much like Silicon Valley startups that focuses on marketing and media to push a product and make their stresser appear better than competitors."

Continue reading: Cybercriminal underground allows for custom modes of future attacks (full post)

CENTCOM Twitter, YouTube accounts being hacked is an 'embarrassment'

| Jan 13, 2015 1:11 PM CST

The US Central Command Twitter and YouTube accounts were compromised on Monday morning, with hackers posting threatening messages and officer contact information. CENTCOM servers and classified data remained intact, and the FBI and Department of Defense (DoD) are now investigating the issue. If nothing else, this is a rather embarrassing issue for the US military, as cybersecurity protocols are being taken more seriously.

"It's embarrassing as all get-out for CENTCOM," said Matthew Aid, a cybersecurity specialist, in a statement to the USA Today. "It looks like rather low-level classified documents. They came off a protected network. Regardless of the low level of sensitivity, the fact that it was done should scare the crap out of people."

However, CENTCOM officials note that the account's username and password were compromised, but its networks were not breached in the incident: "This is little more, in our view, than a cyber-prank," said Army Col. Steve Warren, a spokesman for the Pentagon. "It's an annoyance. We wish it wouldn't happen because we have to spend our time on it. But in no way compromises our operations in any way shape or form."

Continue reading: CENTCOM Twitter, YouTube accounts being hacked is an 'embarrassment' (full post)

Obama outlines new cybersecurity legislative proposal for companies

| Jan 13, 2015 12:13 PM CST

President Barack Obama wants cybersecurity to have a more prominent role among companies and federal agencies, including cybersecurity information sharing. As part of the proposal, Obama wants streamlined threat intelligence sharing between the private sector and government agencies.

In addition, Obama wants to disrupt botnet operators - including the sale or rental of botnets for criminal use - to be investigated, disrupted and prosecuted by federal courts.

Obama yesterday announced an updated proposal so national data breach reporting is modified following a cyberattack and data breach. Instead of a mix of state laws, a single federal statute would be created, so businesses better understand their responsibilities while informing customers.

Continue reading: Obama outlines new cybersecurity legislative proposal for companies (full post)

Australians warned of ISIS attack email scam

| Jan 12, 2015 6:25 PM CST

The Australian Communications and Media Authority is warning everyone to be careful when receiving emails that have anything to do with an "ISIS threat," after numerous reports of people becoming infected when opening emails containing the subject "ISIS attacks in Sydney?" have surfaced.

The Australian Government's Stay Smart Online service statement reads "new emails referring to ISIS terrorism activities carry a malicious attachment that can be used to infect your computer," further commenting that "clicking on the attachment could result in malicious code being installed that allows an attacker to take control of your computer."

The body of the email in question goes on to mention "ISIS has warned Australian Police today about new attacks in Sydney," further stating that "attached the places in word file which ISIS planning to attack in Sydney this year 2015."

Continue reading: Australians warned of ISIS attack email scam (full post)

Russian spy agency tried to recruit Edward Snowden to join its ranks

| Jan 12, 2015 3:09 PM CST

The Russian FSB intelligence security service reportedly tried to recruit former NSA contractor Edward Snowden, approaching him while he was stranded in the Sheremetyevo International Airport in 2013. The American fugitive declined the offer.

Snowden was reportedly approached only once and he "didn't give anything to the Russians at all," according to WikiLeaks staffer Sarah Harrison, a close friend to the stranded American.

Snowden was granted temporary asylum to stay in Russia in August 2013, and he remains inside of Russian borders.

Continue reading: Russian spy agency tried to recruit Edward Snowden to join its ranks (full post)

Criminals victimize compromised United Airlines MileagePlus accounts

| Jan 12, 2015 2:19 PM CST

United Airlines says it wasn't breached as several MileagePlus members have discovered fraudulent activity on their accounts. It appears usernames and passwords were compromised from a third-party, and the unauthorized purchases began sometime in December 2014, the airline has confirmed. The California Office of the Attorney General was notified about the incident last week.

United is still trying to determine how the information was compromised, as criminals have increasingly targeted loyalty programs for airlines, hotels and other travel industry businesses. The accrued points are easy to cash out for restaurants, rental cars, air travel, hotels, and other perks.

Cybercriminals are finding new methods to find usernames and password credentials to steal - and the fraudulent activity suffered by MileagePlus members is an indication that trend will continue.

Continue reading: Criminals victimize compromised United Airlines MileagePlus accounts (full post)

Islamic State reportedly hacks US Central Command Twitter, YouTube

| Jan 12, 2015 1:03 PM CST

It appears the US Central Command Twitter and YouTube accounts were hacked by the Islamic State, corresponding with President Obama preparing to deliver a speech regarding cybersecurity. Both accounts have been temporarily suspended, as threatening messages were posted aimed at US soldiers.

One of the messages posted on the US Central Command Twitter page included: American soldiers, we are coming, watch your back. ISIS. #CyberCaliphate" and included a link to a Pastebin link.

This effort was designed to be an annoyance to the US government and US Central Command systems remain secure from attack. Meanwhile, US officials are looking into the breach, including extent of the incident and any messages that may have been sent from the hijacked accounts.

Continue reading: Islamic State reportedly hacks US Central Command Twitter, YouTube (full post)

US says it didn't attack North Korea, and Pyongyang's security is poor

| Jan 11, 2015 10:29 PM CST

The FBI continues to say North Korea is responsible for a crippling cyberattack and data breach of Sony Pictures, and the Obama Administration vowed revenge, but Washington didn't drop the North Korean Internet, sources claim. However, those responsible for hitting North Korea likely didn't need to work very hard, and future attacks could be imminent.

"It looks more like the result of an infrastructure attack than an infrastructure failure," said James Cowie, chief scientist of Dynamic Network Services, in a statement to the AP. "There's nothing you can point to that says it has all the hallmarks of an attack by a nation state. It could have been anybody."

The entire country of North Korea only has four principal access point to the Internet, and while the US government has the capabilities to impact them, so do multiple other nation states - and smaller hacker groups.

Continue reading: US says it didn't attack North Korea, and Pyongyang's security is poor (full post)

Ransomware, cyberespionage continuing to plague companies

| Jan 11, 2015 10:13 PM CST

Before Sony Pictures had its data released to the Internet, the Guardians of Peace offered to simply disappear if they were paid a ransom - an extortion attempt that Sony promptly denied. However, this type of criminal activity is overshadowed by the new forms of malware customized to encrypt files and demand payment from compromised victims.

Ransomware attacks tend to get the most attention when a new piece of malware hits the Web, infecting end-users and corporations. The ransoms range from as low as $200 up to thousands of dollars, with a short deadline before the files are permanently encrypted.

Cybersecurity experts warn these types of attacks will continue to increase in popularity, as many victims provide payment to the criminals.

Continue reading: Ransomware, cyberespionage continuing to plague companies (full post)

Anonymous plans to retaliate against Islamic groups for terror attack

| Jan 11, 2015 2:59 AM CST

The Anonymous hacker collective has publicly launched a campaign against Islamic extremists tied to the attacks on Charlie Hebdo, which has killed 12 people. The group plans to target al-Qaeda, ISIS and other terrorists, with a focus on bringing down their social media accounts and websites used to spread propaganda.

"We, Anonymous around the world, have decided to declare war on you the terrorists," the group declared in a YouTube video. "We intend to take revenge in their name, we are going to survey your activities on the net, we are going to shut down your accounts on all social networks."

#OpCharlieHebdo has already claimed one victim, though the victimized website returned to service after an hour or two of downtime. However, distributed denial of service (DDoS) attacks and other cyberattacks are expected to target the terrorist groups operating in Iraq, Syria, and elsewhere in the Middle East.

Continue reading: Anonymous plans to retaliate against Islamic groups for terror attack (full post)

South Korea says North Korea is advancing its cyber army

| Jan 10, 2015 5:55 PM CST

The North Korean Bureau 121 cyber warfare unit has continued to recruit new computer experts to its unit, with potential long-term plans of conducting wide-scale cyberespionage operations. Despite additional sanctions levied against Pyongyang, it hasn't slowed momentum of the secretive cyber unit.

"North Korea is currently running its 6,000 (-member) workforce for cyber warfare and performing cyberattacks for physical and psychological paralysis inside South Korea such as causing troubles for military operations and national infrastructures," said the South Korean Defense Ministry, in a statement published by Reuters.

The North Korean government has denied it was involved in breaching Sony Pictures Entertainment - but details of its hacker group continue to be published. Bureau 121 has been blamed for several notable breaches targeting South Korean banks and other infrastructure, with the unit's skills reportedly developing.

Continue reading: South Korea says North Korea is advancing its cyber army (full post)

UCF captures Collegiate Cybersecurity Championship Cup

| Jan 10, 2015 3:11 PM CST

Based on its success during cybersecurity-based competitions, the University of Central Florida (UCF) has won the 2014 Collegiate Cybersecurity Championship Cup.

"The Cybersecurity Championship Cup program is designed to encourage collegiate participation in all cybersecurity-based competitions - not just specific events," said Dr. Gregory White, Director of the Center for Infrastructure Assurance and Security. "The program is similar to the FedEx or Sprint Cups - teams gain points for participation in placement in disparate cybersecurity competitions."

The cup competition is supported by a grant from the Department of Homeland Security Science and Technology Director Cyber Security Division, and is managed by the Center for Infrastructure Assurance and Security at the University of Texas at San Antonio. There is a growing need for cybersecurity specialists - both by the private sector and the federal government - as foreign cyberattacks continute to warrant great concern.

Continue reading: UCF captures Collegiate Cybersecurity Championship Cup (full post)

Lynton: Cost of data breach 'far less' than published estimates

| Jan 10, 2015 5:06 AM CST

Sony Pictures is still dealing with the aftermath of its data breach originally suffered seven weeks ago, and it has been a major headache. However, the incident will be covered by SPE's insurance, and likely won't require the company to endure additional cost-cutting measures, according to SPE CEO Michael Lynton.

"I would say the cost is far less than anything anybody is imaging and certainly shouldn't be anything that is disruptive to our budget," Lynton recently told Reuters.

The financial cost related to post-breach cleanup may be covered, but Sony Pictures must now work on its public relations image. Employee morale is reportedly high, and payroll has been managed, but leaked email conversations between SPE executives embarrassed the company. It will take time and effort, but Lynton acknowledge rebuilding trust with company employees and Hollywood partners already is being worked on.

Continue reading: Lynton: Cost of data breach 'far less' than published estimates (full post)

Michael Lynton says Sony Pictures had no 'playbook' for cyberattack

| Jan 9, 2015 1:37 PM CST

Sony Pictures managed to release "The Interview" to the Internet on Christmas Eve and in theaters on Christmas, but it continues to be a bumpy road for the movie studio. The Guardians of Peace hacker group compromised SPE servers, took all the data, and then "wiped them clean" so Sony no longer had backups.

The initial breach took place shortly before Thanksgiving, and the movie studio's networks are still down - and likely won't be back online for a few more weeks, at the earliest.

"We are the canary in the coal mine, that's for sure," said Michael Lynton, Sony Pictures CEO, in an interview with the Associated Press. "There's no playbook for this, so you are in essence trying to look at the situation as it unfolds and make decisions without being able to refer to a lot of experiences you've had in the past or other peoples' experiences. You're on completely new ground."

Continue reading: Michael Lynton says Sony Pictures had no 'playbook' for cyberattack (full post)

Cybersecurity experts urge companies not to try to hack back

| Jan 9, 2015 12:28 PM CST

Companies struggle to keep their networks secure, and are becoming frustrated by cyberattacks and data breaches. Despite some interest in launching retaliatory attacks, there are a number of hurdles that make it difficult, legal issues aside - not only would it be ineffective because it could escalate the matter further, but there are concerns victims would launch cyberattacks against the wrong targets.

The topic came back to life after JPMorgan Chase may have recruited hackers to launch attacks in retaliation for a cyberattack. Cybersecurity experts and the US government don't recommend companies seek revenge, as US infrastructure has the most to lose - and it'll likely end poorly for the victim either way.

"The technical sector is the backbone of the American economy, and if we start engaging in these kind of behaviors, in these kind of attacks, we're setting a standard, we're creating a new international norm of behavior that says this is what nations do," said former NSA contractor Edward Snowden, in a an interview that PBS Nova will publish soon.

Continue reading: Cybersecurity experts urge companies not to try to hack back (full post)

Snowden says government cyberattacks changing to be more destructive

| Jan 8, 2015 5:42 PM CST

Former NSA contractor Edward Snowden answered questions for a video interview with NOVA, from June 2014, discussing cyber warfare programs on the national level.

The Regin malware, likely created by the American NSA or British GCHQ, is an example of how clever governments have become in their effort to spy on one another. Unfortunately, there is growing concern that these types of cyberattacks could have real militaristic consequences, though countries tend to deny any and all attributions of their crimes.

"Now, this is something that people don't understand fully about cyberattacks, which is that the majority of them are disruptive, but not necessarily destructive," Snowden said. "One of the key differentiators with our level of sophistication and nation-level actors is they're increasing pursuing the capability to launch destructive cyberattacks, as opposed to the disruptive kinds that you normally see online, through protestors, through activists, denial of service attacks, and so on. And this is a pivot that is going to be very difficult for us to navigate."

Continue reading: Snowden says government cyberattacks changing to be more destructive (full post)

Sony CEO doesn't think cyberattack will cause 'upheaval' for company

| Jan 8, 2015 4:31 PM CST

Sony CEO Kazuo Hirai complemented employees and partners for their support and patience following a late 2014 cyberattack. Hirai is optimistic that Hollywood actors and companies will continue to choose to work with the company in 2015 and later down the road - despite how damning some of the information leaked was, likely hurting SPE's reputation.

"We are still reviewing the effects of the cyber attack," Hirai told reporters during CES. "However, I do not see it as something that will cause a material upheaval on Sony Pictures business operations."

Meanwhile, the company is still analyzing full effects of the attack and data breach, which revealed former and current employee personal information, leaked emails, unreleased films, and other company-related information.

Continue reading: Sony CEO doesn't think cyberattack will cause 'upheaval' for company (full post)

FTC worries about privacy, security related to connected devices

| Jan 8, 2015 11:31 AM CST

CES 2015 - Smart and connected technologies accessing the Internet of Things (IoT) have generated significant interest during CES 2015. Manufacturers mainly promoted the benefits of their connected devices, though cybersecurity experts and government regulators want consumers to be aware of potential risks.

Security and privacy concerns could become major headaches for consumers, manufacturers, and security experts embracing connected devices. Collection of personal data with - and often times without - consumer consent, how that information is used, and the theft of data currently are the biggest security concerns.

"Any device that is connected to the Internet is at risk of being hijacked," said Edith Ramirez, Federal Trade Commission (FTC) chairwoman, in a statement made during CES. "Moreover, the risks that unauthorized access create intensify as we adopt more and more devices linked to our physical safety, such as our cars, medical care and homes."

Continue reading: FTC worries about privacy, security related to connected devices (full post)

Tips for Cyber Security: A Look at Payment Processing Online

| Jan 7, 2015 8:35 PM CST

If you've ever heard someone guarantee 100 percent security to you in cyberspace then you know you've got yourself a liar - and not a very good one. Of course, cyberspace will never be truly secure according to Martin Giles. This is why cyber security is becoming increasingly complex and as threats do as well. Huge compromises to data occur in rare events, but the biggest day-to-day threats come in the form of crooks attempting to steal financial data from businesses and individuals.

The hackers best at what they do are certainly making life more difficult for cyber security professionals. Simply put, however, the most common breaches of security are often the result of the most obvious mistakes. For example, an employee can physically write down a password on paper only to have it fall into the wrong hands, or customer information is available to those that have no business with such confidential information. Because of this, it appears that some businesses are not able to anticipate incoming cyber attacks.

In fact, there are reports that argue there is a great need to actually provide businesses with incentives to take cyber security more seriously than they already are. Here are some simple tips for prevention:

Continue reading: Tips for Cyber Security: A Look at Payment Processing Online (full post)

Join Our Newsletter

Join the TweakTown Newsletter for daily tech updates delivered to your inbox.

See previous giveaways.

Newsletter Subscription