Hacking, Security & Privacy - Page 33
Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 33
Stay Updated
Follow TweakTown for breaking tech news, reviews, and daily updates.
As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.
Morgan Stanley employee stole data on 350,000 of the firm's clients
A former employee with Morgan Stanley was canned after being accused of stealing and looking to sell personal information of 350,000 of the firm's clients.
Wealth Management clients are now being informed that the employee took partial client data - and there is no evidence of economic loss - but client information of up to 900 clients, including account names and numbers, were posted on the Internet.
"Morgan Stanley takes extremely seriously its responsibility to safeguard client data, and is working with the appropriate authorities to conduct and conclude a thorough investigation of this incident," the company said in a public statement.
Continue reading: Morgan Stanley employee stole data on 350,000 of the firm's clients (full post)
Sony CEO Kazuo Hirai blasts 'malicious' cyberattack against company
CES 2015 - The annual Consumer Electronics Show (CES) is supposed to be all about announcing and launching new, innovative products, but it wasn't all fun for Sony. Kazuo Hirai, president and CEO of Sony, spoke out against the cyberattack that hit Sony Pictures, while applauding employees for their resolve.
The Guardians of Peace made it a rough end of the year for Sony Pictures, crippling the company, leaking embarassing emails, stealing data, and terrorizing former and current employees - and it remains a rather trying time for employees.
Both Sony, former employees and current employees were the victim of one of the most vicious and malicious cyberattacks in recent history," Hirai said. "I have to say that I'm very proud of all the employees, and certainly the partners who stood up against the extortionist efforts of criminals, and worked tirelessly, sometimes for days on end to bring you 'The Interview,'"
Continue reading: Sony CEO Kazuo Hirai blasts 'malicious' cyberattack against company (full post)
Bitcoin exchange BitStamp hit by hackers, crooks make off with $5M
The bitcoin exchange BitStamp has suspended operation following a significant data breach in which 19,000 bitcoins - valued at more than $5 million - were stolen from the company. BitStamp has frozen user accounts, blocked deposits and suspended all trades as an investigation and security audit are reportedly underway.
The company has a public disclaimer informing customers of the breach on its website: "Upon learning of the breach, we immediately notified all customers that they should no longer make deposits to previously issued bitcoin deposit addresses," part of the message reads. "To repeat, customers should NOT make any deposits to previously issued bitcoin deposit addresses."
Bitcoins endured a turbulent growth period in 2014, with more consumers and businesses expanding adoption - but the currency remained volatile, and overall value has dipped. These type of incidents could be catastrophic for future growth of bitcoins, at a time when consumers already are skeptical of long-term potential.
Continue reading: Bitcoin exchange BitStamp hit by hackers, crooks make off with $5M (full post)
IBM: Overall cyberattacks against retailers dropped, 61M records taken
There was a 50 percent decline in cyberattacks against U.S. retailers in 2014, but a whopping 61 million records were taken in the data breaches that did occur, according to a recent IBM Security report. In 2013, there were 4,200 recorded daily cyberattacks, and that number dropped to 3,043 in 2014.
Cybercriminals are perfecting their craft and using newer, more sophisticated techniques to compromise retailers. Despite increased concern that criminals would target Black Friday and Cyber Monday, but they instead waited it out and are carefully choosing how they launch attacks.
"The threat from organized cybercrime rings remains the largest security challenge for retailers," said Kris Lovejoy, GM of the IBM Security Services, in a press statement. "It is imperative that security leaders and CISOs in particular, use their growing influence to ensure they have the right people, processes and technology in place to take on these growing threats."
Continue reading: IBM: Overall cyberattacks against retailers dropped, 61M records taken (full post)
Cybercriminals increasingly spending months poking around networks
Cybercriminals are finding new methods to compromise corporate and government networks, and are increasingly spending more time doing reconnaissance without being detected. These longer-lasting operations are difficult to prevent with many corporations focusing on perimeter-based cybersecurity defense, not considering the idea that criminals may already be inside.
Companies such as Sony Pictures, Home Depot, Target and other major corporations are first breached using spear-phishing attacks or stolen third-party user login credentials - and the problems only get worse from there. Cybersecurity experts recommend creating protocols so companies are able to identify who is accessing data, from where, and how they are interacting with the accessed data. If a cybersecurity audit is completed, then following through with recommended improvements should also be carried out as quickly as possible.
"We are beginning to realize in some cases that the situation is far worse than we realized," said Stephen Hulquist, chief evangelist at RedSeal Networks, in a statement published by Dark Reading. "In some cases attackers have been inside networks for months and even years without being discovered."
Continue reading: Cybercriminals increasingly spending months poking around networks (full post)
Malware attacks will continue, with sophistication increasing
Malware threats garnered major media attention throughout 2014, but cybersecurity experts are concerned that casual users and business decision leaders aren't going to proactive enough to prevent breaches.
There will be more attention directed towards ransomware, which typically begin with a successful phishing attack. Ransomware demands monetary payments for criminals to turn over control of systems and data back to the victim, and evasion techniques used to deliver payloads are becoming increasingly sophisticated.
"In 2014 we saw a number of significant wins against malware with the dismantling of several major botnets. This type of takedown will be much harder in 2015 with malware becoming stealthier," said Andy Avanessian, VP of professional services at endpoint security company Avecto, in a statement published by Forbes. "In the coming months, we will see increased use of p2p, darknet and tor communications, forums selling malware and stolen data will also retreat further into hidden corners of the internet in an attempt to avoid infiltration."
Continue reading: Malware attacks will continue, with sophistication increasing (full post)
iDict is a password-hacker tool released to nab your iCloud acocunt
Password length, complication and changes are something that many companies, news outlets and IT whizz-kids often drum into the general consumer. One of the best ways to prevent yourself falling victim to your 'general hacker' is to keep your passwords fresh, long and complicated.
iDict is a basic password-guesser that has just been pushed to GitHub. Containing a list of 500 passwords in its library, it will try to guess your accounts password based solely upon the list it has at hand. If your password looks anything like those of this list, we suggest you change them immediately for all services and never look back.
These types of simple passwords are often seen in the 'most popular password lists', with password1 or 12345 often ranking quite highly.
Continue reading: iDict is a password-hacker tool released to nab your iCloud acocunt (full post)
A full FBI investigation thanks to a Pastebin joke against the CNN
Remember how children these days are taught not to 'joke' about security when in an airport? The same should go for online mediums. Homeland Security blogger, David Garrett Jr., spent his new years day being questioned by the FBI - thanks to an apparent joke in which he 'threatened' CNN, posing as a GOP member and leading the FBI to believe the threats to be real.
Thankfully for Garrett, this was poised as a joke and he 'came clean' straight away. In a statement to Fusion, Garrett claimed that a FBI investigator wisely told him "in the future, it's a good idea not to pretend to be someone they're investigating."
In the end everyone has come out unharmed with the only cost being a waste of the FBI's time. Take note kids, sometimes the feds can press charges and make arrests even for what you might think is a joke - luckily in this case, Garrett was let go without prosecution.
Continue reading: A full FBI investigation thanks to a Pastebin joke against the CNN (full post)
Expert: Cybercriminals will only advance their attack strategies
Cybersecurity experts believe 2015 will be another busy year, as sophisticated attacks against users and businesses continue. Criminals will rely on working attacks to compromise victims, while also working to advance their weapons, making them harder to spot.
"Hackers are a diverse bunch, from lone wolves, to nation-state cyber warriors and organized cybercrime rings," said Joe Caruso, founder, CEO and CTO of the cybersecurity Global Digital Forensics (GDF) firm, in a press release. "But one thing they all have in common is they are more than willing to let it ride on a winning horse until it quits paying off. SO expect the favorites, phishing and spear-pshing, RATs (Remote Access Tools), ransomware, watering hole attacks and other third-party compromises, to keep getting ridden hard in 2015."
Numerous point-of-sale (POS) data breaches and the cyberattack against Sony Pictures should serve as painful reminders as to the importance of proper cybersecurity - but won't lead to decision makers acting urgently enough, many security specialists warn. As such, companies need to become proactive in conducting cybersecurity audits, and then following through to improve security protocols - in an attempt to make it more difficult for successful attacks to occur.
Continue reading: Expert: Cybercriminals will only advance their attack strategies (full post)
It's possible hackers still have access and control to SPE computers
Sony Pictures Entertainment was compromised in a big way by the Guardians of Peace hacker group, and there is uncertainty if the hackers were properly removed from the company's network. SPE could be back to enjoying a fully operational network within the next two months if security holds, but would face lingering problems if hackers still have backdoors into the network.
"It took me 24 or 36 hours to fully understand that this was not something we were going to be able to recover from in the next week or two," Sony Entertainment CEO Michael Lynton said in a statement published by the Wall Street Journal. The company began using an old fleet of BlackBerry smartphones to communicate and conduct day-to-day business, following the data breach.
Since being released on Christmas, "The Interview" has collected more than $18 million in digital and box-office revenue - and has proven popular among Internet pirates. However, Lynton and other executives continue to apologize to movie actors and other industry bigwigs following leaked email conversations.
Continue reading: It's possible hackers still have access and control to SPE computers (full post)
FBI on the hunt for qualified cyber special agent candidates
The FBI wants skilled and qualified cybersecurity experts to help lend a hand in cyber-based investigations. Interested candidates must be skilled in computer science and similar fields, while also passing a fitness test, medical exam, extended background check and a polygraph test, according to the FBI.
A brief look at the FBI Cyber Careers page indicates a number jobs for cyber special agents, computer science specialists, information technology forensic examiners, and qualified candidates for cyber internships. The FBI is increasingly helping companies following major data breaches, cyberattacks from hacker groups and suspected foreign states, cyber forensics, and other roles following a major incident.
"Cyber agents will be integrated into all the different violations that we work," said Robert Anderson Jr., FBI cyber crimes branch executive assistant director, in a recruitment video. "So whether it's a counterterrorism or counterintelligence investigation, they could be the lead agent in the case."
Continue reading: FBI on the hunt for qualified cyber special agent candidates (full post)
Possible revenge hacking by banks has led to FBI investigation
Cybercriminals are having a field day targeting US companies, financial institutions and government agencies, with numerous campaigns in recent years. However, some frustrated victims, instead of solely focusing on improving cybersecurity defense, are interested in trying to get vigilante justice on hackers.
It doesn't matter the motives behind revenge hacking, it's still illegal - and the FBI is investigating a report by J.P. Morgan that target Iranian servers following a 2012 cyberattack. As the FBI improves its ability to determine what country or group could be responsible for attacks, they don't want banks and other victims to try their hand at launching attacks.
"Right now the situation is that companies are on defense," said Bloomberg News reporter Michael Riley. "They have to try and keep hackers out of their networks, and the hackers only have to win once. They are incredibly frustrated, they are incredibly vulnerable, and they are looking for other options, and some of those options may be going after the hackers."
Continue reading: Possible revenge hacking by banks has led to FBI investigation (full post)
South Korean users downloading 'The Interview' face malware threat
South Korean Internet users interested in downloading copies of "The Interview" should be worried, as people are having their devices infected while trying to download the movie. Specifically, a Google Android mobile app, available for smartphones and tablets, has been circulating promising access to a pirated copy of the movie - but is instead stealing banking details, according to researchers from McAfee Labs, Center for Advanced Security Research Darmstadt, and Technische Universitate Darmstadt.
"It contains an Android Trojan detected by McAfee products as Android/Badaccents," according to cybersecurity expert Graham Cluley. "Android/Badaccents claims to download a copy of 'The Interview' but instead installs a two-stage banking Trojan onto victims' devices."
The malware targets Korean banks and Citi Bank, with stolen credentials then sent to a Chinese server. The app was reportedly hosted using the Amazon Web Service (AWS), but Amazon has denied the claim. Researchers say the malicious app has been downloaded more than 20,000 times.
Continue reading: South Korean users downloading 'The Interview' face malware threat (full post)
FBI still blames North Korea behind crippling attack of Sony Pictures
Even with a growing number of cybersecurity experts thinking an insider attack is more likely in the demise of Sony Pictures earlier this year, the FBI continues to blame North Korea. US government officials said there are no alternate leads in who was behind attacking Sony, despite arriving at the conclusion North Korea was behind the attack.
The FBI issued the following statement: "The FBI has concluded the government of North Korea is responsible for the theft and destruction of data on the network of Sony Pictures Entertainment. Attribution to North Korea is based on intelligence from the FBI, the US intelligence community, DHS, foreign partners and the private sector. There is no credible information to indicate that any other individual is responsible for this cyber incident."
However, cybersecurity experts were amazed how quickly the FBI was able to point fingers towards North Korea, as noted by a Norse cybersecurity official: "When the FBI made the announcement so soon after the initial hack was unveiled, everyone in the [cyber] intelligence community kind of raised their eyebrows at it, because it's really hard to pin this on anyone within days of the attack."
Continue reading: FBI still blames North Korea behind crippling attack of Sony Pictures (full post)
Email security becomes a priority after Sony Pictures breach
Companies must learn from the mistakes made by Sony Pictures leading up to a data breach carried out by the Guardians of Peace - and that should translate to increased network security and better training for employees. In addition to the stolen movies and leaked employee personal information, embarrassing emails sent and received among executives at the company caused an additional layer of an expanding public relations nightmare.
"Now you have to operate under the mindset that my email is not confidential," said Frank Mong, GM of enterprise security solutions with Hewlett-Packard, in a recent interview published by the San Jose Mercury News. "We should all live with a little more paranoia when we do these things - ask, 'Is this really legitimate?' Should I really be clicking that?"
While the SPE breach is an ideal learning opportunity, many companies will refuse to make adjustments and could be next in line to suffer an incident. Companies need to create guidelines that force employees to use more complicated passwords, and hire third-party cybersecurity firms to educate employees on identifying phishing and spear-phishing attacks.
Continue reading: Email security becomes a priority after Sony Pictures breach (full post)
FBI investigating GOP cyber threats against media organizations
The Guardians of Peace, the cybercriminal group behind crippling Sony Pictures, reportedly sent threats to a U.S.-based news organization. The FBI bulletin refers to the company as "USPER2," so it remains unknown which company was targeted.
The posted threat was published on Pastebin, taunting the FBI and the unnamed media organization "for the 'quality' of their investigations," according to the GOP statement. Unfortunately, many ad servers don't support newer encryption technologies, so media outlets are vulnerable to potential hijacking - and it's something that clever cybercriminals are clearly aware of.
"As part of our ongoing public-private partnerships, the FBI and DHS routinely share information with the private sector and law enforcement community," according to an unnamed military source, speaking to journalists. "The FBI and DHS are not aware of any specific credible information indicating a threat to entertainment or news organizations, however, out of an abundance of caution, we will continue to disseminate relevant information observed during the course of our investigations."
Continue reading: FBI investigating GOP cyber threats against media organizations (full post)
WordPress-based websites still vulnerable to cyberattacks
Third-party WordPress plugins, extremely popular among millions of WordPress users, leave the door open for cybercriminals to exploit threats. Unfortunately, many people install new plugins and simply leave them be - without installing updates or ensuring security protocols are met - and that makes it even easier to compromise websites, databases, and users.
"WordPress is extremely powerful, and while the popularity creates a lot of opportunities for development, it also attracts hackers,"said Tony Baker, Internet Assure director, in a press statement. "There are thousands of extremely popular plugins that create vulnerabilities within these sites, and quite frankly, most WordPress self-hosted websites are set up without any thought to security."
As security becomes significantly more important for WordPress websites, vulnerabilities and code exploits will remain major security concerns. It's recommended for inexperienced website owners to rely on GoDaddy, BlueHost, Site5, and established hosting services to help host the site, as they have internal security protocols in place to keep track of security threats.
Continue reading: WordPress-based websites still vulnerable to cyberattacks (full post)
GOP hackers reportedly received Sony login data from Lizard Squad
A member of the Lizard Squad hacker group, saying his name was "Ryan Cleary," told the Washington Post that his group played a role in handing over usernames and credentials used by Sony Pictures.
"Well, we didn't play a large part in that. We handed over some Sony employee logins to them. For the initial hack. We came by them ourselves. It was a couple."
Unfortunately, the interviewer didn't press the Lizard Squad member any more regarding the breach, which the FBI and cybersecurity experts can't seem to agree upon who is truly behind the attack.
Continue reading: GOP hackers reportedly received Sony login data from Lizard Squad (full post)
UK Lizard Squad member arrested for computer misuse abuses
The Lizard Squad hacker group had a member arrested by the South East Regional Organized Crime Unit (SEROCU), with additional reports indicating the member is 22-year-old Vinnie Omari. His house was raided on Monday and police searched for "email addresses, usernames, passwords, documents containing names associated with PayPal fraud."
Police also want to tie him to recent Lizard Squad attacks, including distributed denial of service (DDoS) attacks suffered by Microsoft's Xbox Live and Sony's PlayStation Network. His laptops, Xbox One game console, smartphone, and USB memory drives were confiscated.
"The South East Regional Organised Crime Unit has arrested a 22-year-old man from Twickenham on suspicion of fraud by false representation and Computer Miseuse Act offences," according a press release. "The arrest yesterday is in connection with an ongoing investigation in to cyber fraud offenses which took place between 2013 and August 2014 during which victims reported funds being stolen from their PayPal accounts."
Continue reading: UK Lizard Squad member arrested for computer misuse abuses (full post)
Cyberespionage efforts will only accelerate in 2015 and beyond
It took a number of data breaches and cybersecurity incidents throughout 2014, many of them suspected of being funded and supported by foreign government states, for American Internet users to realize the great threat of cyberattacks. Looking ahead to 2015, however, cybersecurity experts believe so-called cyberwars will accelerate as additional nations begin to flex their digital muscle.
"Experts have been calling it a 'cyber Cold War' for some time, and that's only ramping up quickly," said Chris Peterson, co-founder and CTO of the LogRhtym security intelligence company, in a statement published by NBC News. "Nation-states both weak and strong see cyberattacks as a weapon to counter the global influence of the U.S."
Cyberespionage attacks will surge in 2015, especially becoming smaller nation states and terror groups, according to McAfee. Smaller countries with less-established military power hope to use cyberattacks to help try to level the playing field, while stealing data and interrupting operations of political rivals.
Continue reading: Cyberespionage efforts will only accelerate in 2015 and beyond (full post)


