Newsletter IconFacebook IconX IconThreads IconInstagram IconYouTube IconPinterest Icon
Giveaway: AVerMedia Creator Bundle (4K Webcam, Capture Card, Charging Hub, and Mouse Pad)

Hacking, Security & Privacy - Page 35

Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 35

Stay Updated

Follow TweakTown for breaking tech news, reviews, and daily updates.

Add TweakTown as a preferred source on GoogleFind TweakTown on Apple News

As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.

Japan working to improve cybersecurity after Sony Pictures attack

| Dec 25, 2014 5:18 AM CST

Following a successful data breach targeting Sony Pictures, the Japanese government is increasingly weary of potential North Korea-based cyberattacks. Japan is used to China's ambitious cyberespionage campaigns, but North Korea has steadily improved its own ability to launch successful attacks.

Japanese Prime Minister Shinzo Abe wants to boost internal cybersecurity defense as the threat of foreign-based attacks reaches frightening levels. There is specific interest in ensuring critical infrastructure, such as its power grid, transportation networks, and gas supplies can continue to function even under continued attack.

"Japan is maintaining close contact with the United States and supporting their handling of this case," said Yoshihide Suga, Japanese Chief Cabinet Secretary, during a press conference. The Japanese government is relying on strong ties with Washington in a joint-cooperation to increase cybersecurity.

Continue reading: Japan working to improve cybersecurity after Sony Pictures attack (full post)

Sony Pictures releases 'The Interview' on streaming services

| Dec 24, 2014 12:55 PM CST

The long saga of the Sony hack is far from over, but Sony has finally taken the step of releasing "The Interview" for purchase on a variety of digital platforms. The Interview is available on Google Play, YouTube Movies, Microsoft's Xbox Video, and a Sony website. The movie was released at 1 PM EST today and is available to stream for $5.99, and for purchase at $14.99. Sony also announced that 300 theaters will play the movie on Thursday.

Sony has taken a considerable beating over the massive hack of the Sony Pictures outfit. The satirical film outlines an assassination attempt of North Korean leader Kim Jong-un. The pending release triggered strong condemnation from North Korea, which threatened action. Soon after, Sony Pictures was hacked, and the US government claims to have proof that North Korea was behind the attack. After the hacking attack, embarrassing internal Sony documents were released to the public, and the hacking group also threatened violence at any theaters showing the film. Several prominent film distribution companies refused to air the movie, leading Sony Pictures to pull the movie. That announcement met with widespread criticism, particularly from President Obama, who likened the move to cowing to terrorists.

The digital release of a mainstream movie is unprecedented, but provides Sony with an easy distribution method that also allows them to save face. The major film distribution companies are still refusing to show the film, and the 300 theaters that will be showing the film are all independent chains. The movie will undoubtedly garner much more interest due to the press coverage of the hacking attack. If demand is strong enough it might provide an interesting insight into the possibility of future mainstream movies being released on digital platforms.

Continue reading: Sony Pictures releases 'The Interview' on streaming services (full post)

South Korea wants China's cooperation into nuclear hack attack

| Dec 24, 2014 11:26 AM CST

South Korea hopes the Chinese government will be cooperative in a data breach investigation recently suffered by the Korea Hydro and Nuclear Power Co. just a few days ago. Some of the IP addresses used to compromise the Korean company are linked to a northeastern Chinese city close to the border with North Korea, according to an unnamed South Korean government official.

Despite its geographic location, there still isn't enough evidence to accuse China or North Korea of being directly involved in the cyberattack - although China is suspected of targeting the United States and its allies, while North Korea has been accused of previous cyber breaches suffered by South Korean companies.

"When we have the cooperation of the Chinese, where of course we don't have jurisdiction, we will be asking for checks or maybe a search of the location of the IP address," a South Korean official recently said. "As we're doing this, there is a possibility that the IP addresses in China are not the final source but used in a routing. It's possible (the network) in China was used (remotely) from some other location."

Continue reading: South Korea wants China's cooperation into nuclear hack attack (full post)

Want a job? Sony hiring cybersecurity director to work in Washington

| Dec 24, 2014 4:30 AM CST

Sony doesn't want a repeat of its data breach suffered by Sony Pictures, and hopes a new Director of Vulnerability Management Engineering will be able to lend a hand. The company is still trying to lick its wounds after foreign cyberattackers brought Sony Pictures to its knees, with corporate emails and movies stolen, along with employee personal information.

Applicants must have a minimum of 10 years information security experience and five years of experience in penetration testing/red teaming. The qualified candidate must have a Master's degree in computer science or another appropriate field, or have equivalent experience.

Sony also posted job listings for junior analysts on the "security operations team," a senior risk management analyst job, senior governance, and a risk and compliance analyst dedicated to security and privacy training.

Continue reading: Want a job? Sony hiring cybersecurity director to work in Washington (full post)

Companies should learn from Sony hack, work to improve cybersecurity

| Dec 23, 2014 11:21 PM CST

If companies needed another reminder on the importance of improving cybersecurity, they can learn from the current predicament tormenting Sony Pictures. C-level executives need to be more involved when it comes to being proactive ensuring cybersecurity strategies at their companies are being implemented properly.

It has been a brutal year for data breaches in the United States, with Sony Pictures joining the unfortunate list of Home Depot, Target, JPMorgan Chase, and multiple other companies that suffered high-profile, very public cybersecurity incidents. Trying to prevent these data breaches is much easier said than done, but many companies have either ignored security recommendations - or overlooked potential fallout - related to security.

"I think the scale of this impact on Sony is what's going to make a lot of C-suites sit up and say 'Wow, we really do need to take this seriously,'" said Rob Sloan, cyber data and content head at Dow Jones Risk & Compliance, in a statement published by Fortune. "They can see the damage being done and it's potentially career-threatening for them and business-ending if they don't have the funds to support them through their troubles."

Continue reading: Companies should learn from Sony hack, work to improve cybersecurity (full post)

Top congressional Democrat Elijah Cummings calls out Sony

| Dec 23, 2014 5:44 PM CST

Sony Pictures CEO Michael Lynton has received a letter from Rep. Elijah Cummings, the top Democrat of the US House Oversight and Government Reform Committee, asking the besieged company to turn over information regarding its catastrophic data breach. There has been an increased number of cyberattacks targeting US government infrastructure, and it has been difficult to collectively learn from these incidents.

The US government, which is learning valuable lessons regarding proper cybersecurity efforts, wants to use Sony's "knowledge, information and experience" to determine what types of new cybersecurity laws - and general practice steps - that can be used to help better defend consumer and government data.

"The increasing number and sophistication of cyberattacks on both public and private entities pose a clear and present danger to our national security and highlight the urgent need for greater collaboration to improve data security," Cummins wrote in his letter.

Continue reading: Top congressional Democrat Elijah Cummings calls out Sony (full post)

Sony Pictures was ravaged, but other cybersecurity questions remain

| Dec 22, 2014 6:17 PM CST

The catastrophic data breach of Sony Pictures helped reveal a major issue that many Americans often ignore: the important need for proper cybersecurity, as companies and government agencies are under attack. Most data breaches occur silently, with companies being breached and often not realizing for many months that data has been stolen.

"From a critical infrastructure and economic perspective, we've seen a lot worse than Sony," said Jeff Bardin, Treadstone 71 cyberintelligence training firm, in a statement to NBC News. "Let's put it in the context of the real issues: attacks on our power grid, our banks, are happening."

It might not matter how it occurs, as long as people become more aware that cybersecurity will remain a significant problem for years to come. Whether it's small hacker groups - or organized state-sponsored cybercriminal groups - they love stealing US data, which often means consumer personal information.

Continue reading: Sony Pictures was ravaged, but other cybersecurity questions remain (full post)

Report: South Korea nuclear facilities targeted in cyberattack

| Dec 22, 2014 5:38 PM CST

South Korea is under cyberattack from an unknown source, as its Korea Hydro and Nuclear Power Co. has been breached, with "non-critical" data being stolen. The country's nuclear installations and atomic reactors aren't at risk, but cybersecurity experts remain highly concerned the country's nuclear reactors could be at risk from future attacks.

"This demonstrated that, if anyone is intent with malice to infiltrate the system, it would be impossible to say with confidence that such an effort would be blocked completely," said Suh Kune-yull, from the Seoul National University, in a statement to reporters. "And a compromise of nuclear reactors' safety pretty clearly means there is a gaping hole in national security."

As organized cyberattacks from foreign states continue to launch attacks, stealing data from utility providers and other critical infrastructure remains high on the list.

Continue reading: Report: South Korea nuclear facilities targeted in cyberattack (full post)

Chinese hackers aiming to compromise Afghan government website

| Dec 22, 2014 4:47 PM CST

The "Operation Poisoned Helmand" operation, as part of the "Poisoned Hurricane" campaign, is reportedly targeting visitors to Afghan government websites, according to the ThreatConnect cybersecurity company. The attacks reportedly originated from China and looks to compromise Internet users visiting gov.af websites - using corrupted JavaScript files.

"We found continued activity from Chinese specific actors that have used the Afghan government infrastructure as an attack platform," said Rich Barger, ThreatConnect CIO, in a statement to Reuters.

As the United States and NATO slowly wind down operations in Afghanistan, it looks like China wants to step up and become more active in the volatile country. This isn't the first time Afghan ministry websites have been targeted, with malware found on justice, foreign affairs, commerce, industry and education ministry websites in the past.

Continue reading: Chinese hackers aiming to compromise Afghan government website (full post)

Internet in North Korea bounced offline due to suspected DDoS

| Dec 22, 2014 2:02 PM CST

North Korea is having Internet problems, as the country - which has limited and restricted Internet access - with problems dating back a few days, though the nation's infrastructure took a severe beating over the past few days.

"Their networks are under duress," said Doug Madory, Dyn Research Internet analysis director, in a published statement. "I haven't seen such a steady beat of routing instability and outages in KP before. Usually there are isolated blips, not continuous connectivity problems. I wouldn't be surprised if they are absorbing some sort of attack presently."

Internet access in North Korea typically is reserved for government and military users, and it's unknown who is behind the attack. Internet outages wouldn't impact normal citizens of the country, but could set a dangerous precedent if the United States is responsible for the attack.

Continue reading: Internet in North Korea bounced offline due to suspected DDoS (full post)

Sony's decision to rely on Mandiant helping FireEye's stock value

| Dec 22, 2014 8:19 AM CST

Sony Pictures is working to rebuild itself following a nasty cyberattack and subsequent data breach, courtesy of the Guardians of Peace. As such, the company has chosen cybersecurity firm FireEye's Mandiant to help clean up the mess - and FireEye likely couldn't be any happier with its decision.

Following the news, FireEye's stock value has increased, because of the high-profile nature of the data breach - and the fact that Sony Pictures could have chosen a few other large, high-profile firms. On the first day of news Mandiant was chosen, FireEye's shares increased 4.8 percent up to $32.39, and should continue to receive additional stability.

Here is what The Street Ratings recently offered: "We rate FireEye a SELL. This is driven by some concerns, which we believe should have a greater impact than any strengths, and could make it more difficult for investors to achieve positive results compared to most of the stocks we cover. The company's weaknesses can be seen in multiple areas, such as its feeble growth in its earnings per share and deteriorating net income."

Continue reading: Sony's decision to rely on Mandiant helping FireEye's stock value (full post)

Anonymous could release 'The Interview' for Internet users

| Dec 22, 2014 6:42 AM CST

The Anonymous hacker collective has criticized Sony Pictures for bowing down to the Guardians of Peace hacker group - and while Sony weighs its options to release "The Interview" - it appears Anonymous might be willing to do it for the company.

Anonymous released the following message (via Twitter): "You're gonna let Kim Junk Uno and his minions boss you, a multimillion dollar corporation responsible for billions of dollars in revenue? We're not with either side, we just want to watch the movie too... and soon you too will be joining us. Sorry, @sonypictures."

The hacker group also mentioned that it previously breached Sony Pictures' networks, and were surprised the company didn't work to improve its cybersecurity defenses.

Continue reading: Anonymous could release 'The Interview' for Internet users (full post)

China opposes cyberattack against Sony Pictures, don't place blame

| Dec 22, 2014 6:19 AM CST

The Chinese government, which has been blamed for organizing cyberattacks against foreign interests, spoke out against the cyberattack that crippled Sony Pictures. However, the country didn't specifically call out North Korea for its likely role in the breach, which stemmed because of the government's disdain for "The Interview."

"(China) opposes any country or individual using other countries' domestic facilities to conduct cyberattacks on third-party nations," according to a statement issued by Wang Yi, the Chinese Foreign Minister, when speaking to US Secretary of State John Kerry.

North Korea and China have a strong political friendship - as one of Kim Jong Un's only foreign allies - and would be an important asset for any future cyberattacks. Pres. Obama's administration is weighing potential options to retaliate against North Korea, though China would likely strongly condemn any future actions.

Continue reading: China opposes cyberattack against Sony Pictures, don't place blame (full post)

Pres. Obama says United States not in cyberwar with North Korea

| Dec 21, 2014 5:52 PM CST

President Obama has said the United States will respond "proportionately" against North Korea for its role in attacking Sony Pictures, but said the country is not engaged in a cyberwar against North Korea. Instead, the US may reintroduce North Korea to a list of countries accused of sponsoring terrorism, and will look for other methods to retaliate against the reclusive country.

"I don't think it was an act of war," Obama recently said on CNN's State of the Union. I think it was an act of cyber vandalism that was very costly, very expensive. We take it very seriously. We will respond proportionately, as I said. We've got very clear criteria as to what it means for a state to sponsor terrorism. And we don't make those judgments just based on the news of the day. We look systematically at what's been done and based on those facts, we'll make those determinations in the future."

There aren't many things the United States can do to attack North Korea with cyberattacks, as the US has much more to lose in an ongoing battle - and the US is more interested in trying to create generational change to help better the North Korean people, rather than directly fight with the government.

Continue reading: Pres. Obama says United States not in cyberwar with North Korea (full post)

Staples announces 1.6 million cards affected in previous data breach

| Dec 21, 2014 4:27 PM CST

Office retailer Staples recently issued an update to a data breach investigation that took place earlier in the year, targeting its retail point-of-sale (PoS) systems. The company said 115 of its stores nationwide were targeted, with 1.16 million customers affected, providing cybercriminals potential "access to some transaction data at affected stores, including cardholder names, payment card numbers, expiration dates, and card verification codes."

Retailers remain under fire from foreign cybercriminals targeting their PoS systems - and the problem likely won't suddenly go away anytime soon. Despite Staples' data breach much smaller than Target (40 million compromised) and Home Depot (56 million compromised), shows that major problems still exist.

Continue reading: Staples announces 1.6 million cards affected in previous data breach (full post)

North Korea not surprisingly shielding citizens from 'The Interview'

| Dec 21, 2014 4:23 AM CST

The North Korean government has reportedly orchestrated a major cyberattack to cripple Sony Pictures - and prevent "The Interview" from being shared - but the regular North Korean citizen likely has no idea about the data breach or movie. The North Korean government strictly regulates the Internet and media in the country, so it wouldn't be surprising if the population has no knowledge of the movie, or its contents.

"North Koreans will probably never know what this film was about," noted Leonid Petrov, from the Australian National University, as noted by BusinessWeek. "If there was a film about Kim Jong Un, it would only be explained in the most laudatory, sycophantic way. Foreigners made a film about our great leader, presenting the greatness of the great leader."

As such, trying to even get copies of the movie would be extremely difficult. There have been attempts to send balloons into North Korea with copies of movies, books and other banned materials into the country - but the balloons are routinely shot down. North Korean citizens who stumble across any of the contraband is ordered to turn it over, or they face potential torture, imprisonment, and other forms of punishment.

Continue reading: North Korea not surprisingly shielding citizens from 'The Interview' (full post)

Cybersecurity expert warns against retaliating against North Korea

| Dec 20, 2014 12:25 AM CST

The United States pointed towards North Korea being behind the massive Sony Pictures data breach, and many have argued for some type of retaliation against the country. However, trying to determine how to seek revenge on the North Korean government, in regards to cyberattacks, remains difficult. Trying a cyberattack in response would be risky, as the US has significantly more to lose if the North Koreans, along with its allies, decide to escalate the issue further.

"Nothing more," said Christopher Budd, online security communications professional, in a post published by GeekWire. "Yes, you read that right: nothing more. I believe that the U.S. should do nothing more in response to this situation than they already have: naming North Kore clearly as being behind this."

It seems more likely the US government will impose further sanctions on North Korea - and perhaps find ways to hurt the country's economy even further. Another idea is to find a way to distribute "The Interview" inside of North Korea, along with distributing "Team America" into the country - but that seems rather far-fetched.

Continue reading: Cybersecurity expert warns against retaliating against North Korea (full post)

McAfee says cyber espionage attacks will only increase in 2015

| Dec 19, 2014 9:59 PM CST

Cyber espionage is a growing underworld business, with small nation states and foreign terror groups continuing to launch cyberattacks against enemies, according to a report released by McAfee Labs. Everything from distributed denial of service (DDoS) attacks to malware being delivered via social engineering techniques are being added to cyber arsenals, used by increasingly sophisticated groups.

Established nations with cyber warfare programs will look for stealthier methods to gather intelligence and cripple political and military rivals - and developing cyber espionage programs remain dedicated to stealing finances and causing disruptions.

"Of particular note, McAfee Labs now sees sophisticated Eastern European cybercriminals shifting from quick, direct attacks on financial-institution customer credentials (leading to financial theft) to a more sophisticated advanced persistent threat (APT) approach in which they collect intelligence that they can either sell or use at a later date," according to the McAfee report.

Continue reading: McAfee says cyber espionage attacks will only increase in 2015 (full post)

Obama: Sony 'made a mistake' in its decision to pull 'The Interview'

| Dec 19, 2014 4:15 PM CST

The decision by Sony Pictures Entertainment to pull "The Interview" due to a cyberattack and subsequent terror attacks has drawn criticism from actors and President Obama.

"Sony is a corporation. It suffered significant damage," Obama said during a press conference. "There were threats against its employees. I'm sympathetic to the concerns that they faced. Having said all that, yes I think they made a mistake. We cannot have a society in which some dictator in some place can start imposing censorship in the United States. I wish they'd spoken to me first. I would have told them: 'Do not get into the pattern in which you are intimidated.'"

However, Sony is defending itself from Pres. Obama's statement and criticism from actors, many American citizens, and others criticizing the company.

Continue reading: Obama: Sony 'made a mistake' in its decision to pull 'The Interview' (full post)

ISIS allies reportedly stepping up cyberattacks against media, rivals

| Dec 19, 2014 4:11 PM CST

Cybercriminals with alleged ties to ISIS recently tried to spread malware onto a Syrian citizen media group after posing as Syrian-Canadian citizens, according to a report from Citizen Lab. The social engineering attack took place in late November, and shows the group is continually putting more effort into its cybercriminal abilities. The attempted malware attack was targeted to the Raqqah is Being Slaughtered Silently (RSS) group, and the email was worded in a manner to trick organization members.

"This bears little resemblance to anything we've seen from the usual suspects," said John Scott-Railton, the report's co-author, noted in a statement given to CBC. "That, combined with who they are targeting... gives us pause and makes us think that maybe we're looking at ISIS malware."

ISIS has used the Internet, specifically social media, as a tool to recruit and spread propaganda. However, the group has run into problems, as the Anonymous hacker collective and other groups have disrupted their online operations.

Continue reading: ISIS allies reportedly stepping up cyberattacks against media, rivals (full post)

Join Our Newsletter

Join the TweakTown Newsletter for daily tech updates delivered to your inbox.

See previous giveaways.

Newsletter Subscription