Hacking, Security & Privacy - Page 34
Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 34
Stay Updated
Follow TweakTown for breaking tech news, reviews, and daily updates.
As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.
Korean nuclear operator removes low-risk worm from its servers
South Korean security officials have removed a "low-risk" worm that was installed on devices linked to the country's nuclear plant control systems. Nothing harmful was discovered on reactor controls, according to officials, despite the recent data breach.
"We will prepare fundamental improvement measures by enhancing nuclear power's safe operation and hiking information security systems to the highest level following this cyber attack case," the Korea Hydro and Nuclear Power company said in a statement.
Korean officials want cooperation from the Chinese government during its investigation of the cyberattacks - with China or North Korea on the short list of foreign states that could be involved. A hacker threatened to close three reactors via Twitter, though only non-critical data was stolen as part of the breach.
Continue reading: Korean nuclear operator removes low-risk worm from its servers (full post)
FBI confirms it is investigating Lizard Squad for DDoS attacks
The FBI is now investigating the Lizard Squad for its participation in bringing down Microsoft Xbox Live and Sony PlayStation Network via distributed denial of service (DDoS) attacks over Christmas. Published media statements say "Ryanc," a Finnish teenager identified as Julius Kivimaki, as one reported member of the Lizard Squad group - but identifying other members has proven difficult.
"The FBI is investigating the matter," according to a bureau spokesperson when speaking to GamesBeat. "Given the pending nature of the case, we cannot comment further."
Continue reading: FBI confirms it is investigating Lizard Squad for DDoS attacks (full post)
Following data breach, Sony Pictures embraced BlackBerry devices
Sony Pictures was having a decent year until the crippling cyberattack that made the company's operations go sideways to end the year. To help keep things operating, Sony embraced its old stash of BlackBerry smartphones to support day-to-day operations moving ahead. It's possible, following the breach, some executives will begin embracing BlackBerry smartphones because of the enhanced security protocols.
Despite losing steam among consumers - and in the business workplace - BlackBerry smartphones still rely on a secure infrastructure, making it a popular device for government employees, even with the domination of Apple iPhone and Google Android devices.
"CEO Michael Lynton routinely received copies of his passwords in unsecure emails for his family and his family's mail, banking, travel, and shopping accounts," according to the Associated Press. "Experts say such haphazard practices are common across corporate America." Using a BlackBerry device, however, could help alleviate some of the poor cybersecurity practices suffered by many company executives.
Continue reading: Following data breach, Sony Pictures embraced BlackBerry devices (full post)
Experts: Insider attack may have played major role in Sony breach
The FBI believes North Korea played a major role in the breach of Sony Pictures, while the reclusive North Korean government not surprisingly denied any involvement. The Norse cybersecurity firm spoke with the FBI at the start of the week, and believe a piracy group and disgruntled insiders, at least one laid-off Sony Pictures employee, were more likely the cause of the data breach.
"We are very confident that this was not an attack master-minded by North Korea and that insiders were key to the implementation of one of the most devastating attacks in history," said Kurt Stammberger, Norse senior vice president, in a statement to CBS News.
In a statement meant to Reuters, the FBI offered the following statement: "The FBI has concluded the government of North Korea is responsible for the theft and destruction of data on the network of Sony Pictures Entertainment."
Continue reading: Experts: Insider attack may have played major role in Sony breach (full post)
NSA releases documents stating it spied on Americans on Christmas Eve
The NSA responded to an ACLU FOIA request by releasing a bunch of documents to the public, but waited until the cover of Christmas Eve when everyone was busy with their families, admitting it had spied on normal, ordinary American citizens.
Considering the NSA has stood before Congress, claiming more than once that it was not abusing its very broad intelligence gathering operations and technologies, but now we know, for a fact, they did, and probably still are. The reports state "The heavily-redacted reports include examples of data on Americans being e-mailed to unauthorized recipients, stored in unsecured computers and retained after it was supposed to be destroyed, according to the documents. They were posted on the NSA's website at around 1:30 p.m. on Christmas Eve."
In a case back in 2012, an NSA analyst "searched her spouse's personal telephone directory without his knowledge to obtain names and telephone numbers for targeting," but don't worry, the NSA analyst in question "has been advised to cease her activities." Then there's this: "In 2012, an analyst conducted surveillance "on a U.S. organization in a raw traffic database without formal authorization because the analyst incorrectly believed that he was authorized to query due to a potential threat," according to the fourth-quarter report from 2012. The surveillance yielded nothing."
Continue reading: NSA releases documents stating it spied on Americans on Christmas Eve (full post)
Hackers copy politicians fingerprint from press conference photos
Biometric security just took a big blow to the chin. Fingerprint scanners are increasingly used for security in Apple and Samsung devices, along with many others, and are even used for voter identification in some countries. At a recent conference in Hamburg, the Chaos Computer Club (CCC) hacker network revealed they had copied German Defense minister Ursula von der Leyens' fingerprint from publically available photos of a press conference she held.
The photos were taken from standard cameras, and several images were used to stitch together the copied thumbprint. One fingerprint may have taken a bit of work to accomplish, but now that the proof-of-concept experiment has succeeded it would be relatively easy to refine the process. This isn't the best news for politicians and others who are regularly photographed, and it might be wise to move to other technologies to secure access to devices.
Biometric scanning isn't considered the safest of identification verification technologies, chiefly because most systems can be fooled with replicas. There are new technologies emerging that provide better verification techniques, such as vein scanning. New finger scanners actually look for the unique vein patterns inside the finger, which would be impossible to replicate through photos. This also has the great side-benefit of requiring a living human to work, so copies are not a feasible approach to defeating these systems.
Continue reading: Hackers copy politicians fingerprint from press conference photos (full post)
MasterCard running "Masters of Code" hacking competition - $100k cash
Roll up Lizard Squad and Anonymous members, it's time to put your skills to the test. MasterCard has just announced through a press release that they will be running massive hacker collective competition across 10 cities with the ultimate prize being $100,000 in cold, hard cash.
Conducted through the use of MasterCard-supplies APIs, the entrants will compete to "create innovative prototypes that demonstrate artful coding and design skills while also articulating clear business use cases - all focused on driving the next generation of commerce applications" as according to their release.
If you fancy yourself as a computer security expert and think you have what it take to get to round two - the winning team from each region will be sent to Silicon Valley to compete in the Grand Finale Masters of Code 'hackathon'. This event features the $100k grand-prize and a few extras up for grabs:
Continue reading: MasterCard running "Masters of Code" hacking competition - $100k cash (full post)
Snowden leak reveals which encryptions NSA cannot decipher
The compilation of sensitive data secreted out of the NSA by Edward Snowden continues to be a big thorn in the side of spying agencies. Recent disclosures in Der Spiegel, the newspaper that has leaked the majority of the Snowden information, reveals several programs that the NSA has found to be very difficult, or totally impossible, to decipher. The information is complete as of late 2012, so the NSA may have already overcome these limitations, but the information is interesting.
Some emails are still indecipherable, notably the Zoho encrypted email service. The NSA has also noted that following targets across the Tor network is difficult to impossible, which means it works as advertised. The NSA has been very proactive in their dealings with encryption programs, primarily by working with vendors and committee's to have backdoors installed into the major encryption programs before they are even released to the public. One of the most surprising findings is that TrueCrypt, an open-source program, is largely safe for encrypting data. The NSA apparently didn't have as much luck penetrating an open-source project, which isn't entirely surprising considering the peer-reviewed nature of open source programs. It would be hard to insert a secret back door into a program that is actively worked on by a large group of people without company/government affiliations. PGR encryption tools and OTR chat encryption were also notable exceptions to the NSA's decryption schemes.
The revelations also contained some information on services that are easy prey for the NSA. VPN's are of little help, and the agency has already outwitted the HTTPS system. The NSA was grappling with AES encryption in late 2012, but were yet to make a breakthrough. The NSA's focus on AES means it is likely they have since cracked it, so users beware.
Continue reading: Snowden leak reveals which encryptions NSA cannot decipher (full post)
State hacking operation used commercial software to compromise targets
Military targets in Europe and Israel have been hit by cyberespionage attacks that could have been aided by commercial security-testing software released by Core Security, according to a report from the Computer Emergency Response Team (CERT). Israeli officials are unsure who launched the attack, but Iran is on the short list of suspects - as the Iranian government routinely tries to conduct surveillance and steal information from Israel.
"The most likely answer is they didn't have the capability to do it on their own," said Tilmann Werner, CrowdStrike analyst, in a statement, also adding "there is no risk of leaving tool-marks."
Cybercriminals trying to compromise government and military departments, corporations, and other major targets are greatly improving their attack capabilities. Iran has invested a large amount of resources in developing internal cyberespionage efforts, with Israel a popular target for new attacks.
Continue reading: State hacking operation used commercial software to compromise targets (full post)
South Korea nuclear facilities still under cyberattack, officials say
South Korea reported cyberattacks against its nuclear power operator are still underway, with non-critical operations being targeted - but the Korean nuclear power plants are safe and secure. The company faced a cyberattack and data breach last week, but hackers were able to only steal non-critical data, while reactors and other critical infrastructure were untouched.
"We cannot let cyberattacks stop nuclear power operation," said Cho Seok, Korea Hydro & Nuclear Power Co. President and CEO, during a press conference. "We will continue operating nuclear plants safely against any attempted foul play, including cyberattacks. Cyberattacks on KHNP's (headquarters) operations and administration are still continuing now."
The Korean government currently has an investigation underway, and is asking for cooperation from China, as it's possible North Korea was responsible for the incident.
Continue reading: South Korea nuclear facilities still under cyberattack, officials say (full post)
Norse provides mesmerizing real-time view of global hacking attacks
Norse has developed a network of 8 million sensors worldwide designed specifically to absorb various types of internet attacks. These sensors analyze the malicious traffic and trace it back to its source. This vast network of global trackers is called the DarkMatter Platform, and it delivers real-time threat tracking and intelligence within five seconds.
Norse provides this service to companies to protect their web services, but they also provide an amazing real-time view for everyone of malicious traffic at their comprehensive monitoring site. The view of ongoing attacks is amazing due to the sheer scale of the attacks, and their continuing nature highlights the intense threats companies face every day. The site identifies each type of attack, and DDoS attacks are easily visible as attacks from multiple locations worldwide converge on a single target.
The DarkMatter platform analyzes malicious traffic, including IRC, Tor, P2P, DNS, SSH, VPN, private IP and SOCKS proxies, assigned and unadvertised address spaces, among others. This covers the entire range of threats, and Norse crunches terabytes of data per day, and takes up to four years of historical data into account, to assign threat levels to provide a complete threat analysis.
Continue reading: Norse provides mesmerizing real-time view of global hacking attacks (full post)
Hackers enter large-name online portals, releasing usernames and more
Right about now you've really got to feel sorry for Sony. Alongside numerous hacking scandals surrounding their pictures department, they've been targeted by the infamous North Korea and even had their PlayStation Live Network service taken down on the 26th of December thanks to a timely DDoS. Just when you thought it couldn't get worse, hackers have released 13,000 username-and-password combinations alongside stolen credit card details, claiming these were stolen from large-scale websites like Sony's PlayStation Network, XBOX Live and Amazon plus more.
Released via the Twitter account "@AnonymousGlobo", this hack is also said to target some of the largest porn websites alongside these gaming and retail web portals. This gives the hack yet another tie to the group known as Anonymous, who have been involved in recent Klu Klux Klan altercations alongside many other large-scale operations in recent years.
This recent mission saw their explanation read "we did it for the lulz," a common claim among the hacker collective. Translated this basically means "we did it because we could" or "we did it for a laugh".
Continue reading: Hackers enter large-name online portals, releasing usernames and more (full post)
North Korean Internet infrastructure suffers another outage
For the second time in less than one week, it appears the fragile North Korean Internet infrastructure has been dropped offline from cyberattacks. Reports from Chinese media indicate the Internet and 3G mobile phone networks in North Korea have gone offline, following the US government's accusations that Pyongyang had a direct hand in breaching Sony Pictures.
In the incident reported earlier in the week, it appears a distributed denial of service (DDoS) attack stopped Internet access for a brief period. Most Internet access in North Korea is reserved for high-ranking government officials and military personnel, reports indicate.
Despite countries focusing on developing cyberespionage weapons able to target foreign companies and governments, clearly not enough is being done to help improve cybersecurity. The United States, UK, North Korea, China, Russia, Iran, and other nations have greater cyberattack capabilities - but fall prey to their own data incidents on a frequent basis.
Continue reading: North Korean Internet infrastructure suffers another outage (full post)
US government warns Sony breach tactics could be used in other attacks
The malware software and cybercriminal technique demonstrated against Sony Pictures could be used in additional attacks targeting US companies, according to a recent alert from the U.S. Computer Emergency Readiness Team (US-CERT). Specifically, the malware, which is similar to code used to target South Korean companies, is able to communicate with operators while spreading quickly and conducting brute-force password attacks against systems.
"Due to the highly destructive functionality of this malware, an organization infected could experience operational impacts including loss of intellectual property and disruption of critical systems," the US-CERT warning stated. It's true that next-generation malware, written by increasingly skilled cybercriminal groups, has a wide variety of different purposes. Although stealing and compromising infected PCs remains lucrative, cyberespionage would be better served by disrupting day-to-day operations of necessary systems.
North Korea has been blamed by the US government for the attack against Sony Pictures, a charge it vehemently denies - has dedicated resources to improving its cyberattack capabilities.
Continue reading: US government warns Sony breach tactics could be used in other attacks (full post)
Lizard Squad stop DDoS of PSN and Xbox Live thanks to Kim Dotcom
Thanks to the "Lizard Squad", many bright-eyed youngsters were left out of luck - being unable to connect their new Santa-given PlayStation's and XBOX's to their respective online gaming and content networks.
This group of hackers targeted both of these large-scale online mediums on the 25th of December, seeing Kim Dotcom come in as some kind of savior - offering them 3,000 lifetime premium Mega accounts worth $99 each in return for PSN and XBOX Live's safety. The squad accepted, stopping the DDoS atacks instantly, vowing never to return.
According to a Twitter post, this deal is only made true if "they don't attack Xbox Live & PSN again. #ThatsTheDeal," in the words of Dotcom himself.
Continue reading: Lizard Squad stop DDoS of PSN and Xbox Live thanks to Kim Dotcom (full post)
Iran plans to expand its 'smart filtering' for Internet users
The Iranian government will move ahead with an effort to use "smart filtering" of the Internet for Iranian users, with "undesirable" content censored - Iran has some of the strictest regulation and controls of the Internet, with many foreign websites blocked.
Despite Facebook, Twitter, YouTube and other populations blocked, a growing number of Iranian users access these websites with virtual private networks (VPNs). However, Tehran wants to filter the content, hoping it's a more effective method of preventing some blocked content - and President Hassan Rouhani previously promised to begin opening up technology access.
"Presently, the smart filtering plan is implemented only on one social network in its pilot study phase and this will process will continue gradually until the plan is implemented on all networks," said Mahmoud Vaezi, Iranian Communications Minister, in a statement to the IRNA news agency.
Continue reading: Iran plans to expand its 'smart filtering' for Internet users (full post)
Report: North Korea's Bureau 121 scarier than previously thought
The North Korean government has steadily increased capabilities of its secretive Bureau 121 cyberespionage unit, but very little is known about how it operates. A North Korean defector recently shed light on the division of specialized "cyber warriors," with specific training of programming languages, operating systems research, and IT network security vulnerabilities.
By the time hackers are officially hired by Bureau, some candidates have almost nine years of training, according to Jang Se-yul, a graduate of the top North Korean engineering college. Bureau 121 cybercriminals - and their families - are moved to Pyongyang and become among the country's top 1 percent, including a high salary, free apartment, and free Internet access.
The US and other western nations are focused more on limiting cyberespionage, especially from North Korea, Iran, China and Russia - but the cybercriminals have had a step up on us for quite some time. North Korea understands it wouldn't be able to win a conventional war against political rivals, but is able to cause chaos using their hacker branch.
Continue reading: Report: North Korea's Bureau 121 scarier than previously thought (full post)
Japanese banks being targeted by Chinese hackers, tension growing
Cybercriminals from China are increasingly targeting Japanese bank account holders, with more than $16 million stolen from the Sumitomo Mitsui Financial Group and Mitsubishi UFJ Financial Group during the first six months of 2014. Japanese police officials report a rising number of Chinese nations being arrested for cyber-related crimes, and security experts point towards Chinese-based IP addresses.
The chaos begins by a phishing attack that tricks users into providing their passwords. Money is transferred out of Japan and people are recruited to visit ATMs and withdraw as much money as they can. Products are purchased in Japan and the stolen items are shipped and re-sold in China.
Earlier in the year, Japanese government websites were compromised by suspected Chinese hackers, with most of the sites temporarily dropped by distributed denial of service (DDoS) attacks. However, other websites were defaced with political messages related to Japan-China sociopolitical propaganda - as both countries continue their efforts to rebuild an extremely tumultuous relationship.
Continue reading: Japanese banks being targeted by Chinese hackers, tension growing (full post)
Hackers cause damage at German factory with malware attack
Cybercriminals compromised a German factory and caused "massive" damage to a blast furnace inside of the facility, according to a Federal Office for Information Security report made available by the German government. The company impacted remains unknown, but it looks like they fell victim to a phishing attack that led to malware installation on company computers - and it didn't take long before PCs and factory systems to suffer.
Since the company's employees were not able to maintain control of the blast furnace, there was "massive damage to [the] plant." "The attackers were knowledgeable in conventional IT security and had extensive knowledge of applied control and production processes," according to a recently published report.
As cybercriminals find new methods to conduct cyberespionage, there is growing concern that they can breach critical infrastructure - and cause significant damage - and this German foundry incident is a worrying sign. It's unknown if the hackers intended to just steal data, or cause physical damage, but show how vulnerable computer systems can be.
Continue reading: Hackers cause damage at German factory with malware attack (full post)
Hackers take credit for downing Xbox Live, PlayStation Network
The Lizard Squad reportedly has taken credit for dropping Microsoft's Xbox Live and Sony's PlayStation Network on Christmas Eve and Christmas day. It's not a complete surprise to hear of the cyberattacks, with the group promising them all month long. Lizard Squad used a distributed denial-of-service (DDoS) attack, with the FBI and other hacker groups reportedly targeting them.
Unfortunately, the group demanded 10,000 retweets of a message posted on Twitter, so gamers will be able to access Xbox.com, Xbox Live and other services - and regain playability on PSN. Both Microsoft and Sony are working on connectivity issues, with spotty service available in North America.
It's not a surprise to hear they wanted to target the attack for Christmas, as many gamers plug in their consoles for the first time - or hit the power switch to begin playing a new title.
Continue reading: Hackers take credit for downing Xbox Live, PlayStation Network (full post)


