Newsletter IconFacebook IconX IconThreads IconInstagram IconYouTube IconPinterest Icon
Giveaway: AVerMedia Creator Bundle (4K Webcam, Capture Card, Charging Hub, and Mouse Pad)

Hacking, Security & Privacy - Page 36

Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 36

Stay Updated

Follow TweakTown for breaking tech news, reviews, and daily updates.

Add TweakTown as a preferred source on GoogleFind TweakTown on Apple News

As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.

Survey: Company malware breaches not exactly uncommon these days

| Dec 19, 2014 10:21 AM CST

A reported 51 percent of companies suffered some type of malware breach during the past 18 months, with phishing emails and social engineering attacks able to circumvent security filters, according to a survey published by the OPSWAT IT solutions provider.

It's a frightening time for companies trying to keep their networks secure, especially as social engineering techniques - which rely on tricking employees to click fraudulent links or install the malware directly - prove difficult to defend against.

"With the sheer number of new viruses introduced every day, it is not surprising that 51% of the respondents experienced a malware breach, particularly since 39% only utilized one anti-malware solution," said Tony Berning, OPSWAT Metascan product manager. "By using only one or two anti-virus engines, companies are exposing themselves to malware threats, since no anti-virus engine can be accurate 100% of the time."

Continue reading: Survey: Company malware breaches not exactly uncommon these days (full post)

Sony's cyberattack likely to become most expensive for a U.S. company

| Dec 19, 2014 4:20 AM CST

Sony Pictures is facing a public relations nightmare after a major data breach orchestrated by North Korea, and company executives just can't stop the bleeding. The data breach could become the costliest suffered by a U.S. company, with fallout that will surely continue into 2015. Beyond the sensitive documents and personal information stolen, along with the cancellation of "The Interview," there is a strong possibility some actors will avoid Sony in the future.

It remains unclear how much Sony will lose because of the cyberattack, but lawsuits, lost revenue because of "The Interview" being pulled, and other problems will only complicate matters even further.

"This attack went to the heart and core of Sony's business and succeeded," said Avivah Litan, Gartner cybersecurity analyst. "We haven't seen any attack like this in the annals of U.S. breach history."

Continue reading: Sony's cyberattack likely to become most expensive for a U.S. company (full post)

North Korean hackers might set sights on US telecom, infrastructure

| Dec 19, 2014 4:03 AM CST

North Korea could be using the cyberattack against Sony Pictures as a test run to try out its budding cyber capabilities, with the reclusive government potentially taking aim at US energy companies and critical infrastructure. Despite much of the Western world ignoring its growing cyber ambitions, it looks like North Korea has been able to increase its cyber weapons.

"North Korea's ultimate goal in cyber strategy is to be able to attack national infrastructure of South Korea and the United States," said Kim Heung-kwang, a North Korean defector and former computer science professor. "The hacking of Sony Pictures is similar to previous attacks that were blamed on North Korea and is a result of training and efforts made with the goal of destroying infrastructure."

The North Korean government has poured resources into its Bureau 121 cyber warfare unit, recruiting some of the nation's best computer experts - with most of the department's agents originating from the North Korean military computer school. It has successfully attacked targets in South Korea on several occasions, as some networks remain vulnerable to attack.

Continue reading: North Korean hackers might set sights on US telecom, infrastructure (full post)

SS7 security flaw enables hackers to read your text messages

| Dec 18, 2014 11:05 PM CST

Signal System 7 (SS7) powers multiple phone carriers across the world including big names such as AT&T and Verizon - its global telecom network is used to route calls and text and in recent news, this technology has been reported to have some huge security issues associated inside. These issues come in the form of security holes that let hackers listen in to your calls and texts.

ACLU's Cheif Technologist has informed Gizmodo that this flaw is so serious that people should consider no longer using their mobile phone for calls until the problems are fixed.

SS7's outdated infrastructure is said to be the cause of this issue, with German research discovering this invasion of privacy, said to be publishing their full findings later this month at a conference in Hamburg (as according to the Washington Post).

Continue reading: SS7 security flaw enables hackers to read your text messages (full post)

ICANN hit by spear phishing attack, employee credentials compromised

| Dec 18, 2014 1:26 AM CST

ICANN employees have fallen victim to a suspected spear phishing cyberattack that began in late November 2014, the group confirmed in a blog post. The social engineering attack mimicked emails that closely resembled communications from its own domain and targeted ICANN employees. Unfortunately, the attack was successful and several ICANN staff members had their credentials compromised.

The compromised credentials were used to access ICANN's Centralized Zone Data System, providing criminals with access to names, postal addresses, email addresses, fax and phone numbers, usernames and passwords. The breach also hits the ICANN GAC Wiki, with only public information accessible to the cybercriminals.

Earlier in the year, ICANN boosted its cybersecurity, which the group said likely helped keep unauthorized access to a minimum from this attack.

Continue reading: ICANN hit by spear phishing attack, employee credentials compromised (full post)

Coolpad builds Android backdoor into devices sold in China

| Dec 18, 2014 12:25 AM CST

Chinese mobile manufacturer Coolpad is building backdoors into high-end Google Android-powered smartphones, according to Palo Alto Networks' Unit 42. The "CoolReaper" backdoor has been found on a variety of ROMs that were downloaded by security researchers. Coolpad is the No. 6 largest smartphone manufacture in the world, No. 3 inside of China, so this is an extremely troubling development.

CoolReaper is able to download, install, or activate Android applications without needing owner consent or notification. It can also clear user data, uninstall applications, and disable system applications. Researchers also found that it can dial arbitrary phone numbers and send SMS or MMS messages from the phone.

"CoolReaper is the first malware we have seen that was built and operated by an Android manufacturer," according to the Palo Alto Networks' Unit 42 blog. "The changes Coolpad made to the Android OS to hide the backdoor from users and anti-virus programs are unique and should make people think twice about the integrity of their mobile devices."

Continue reading: Coolpad builds Android backdoor into devices sold in China (full post)

Sony allowing movie theaters to pull 'The Interview' before release

| Dec 17, 2014 5:08 AM CST

The hacker group reportedly behind a major cyberattack against Sony Pictures Entertainment is getting what they want - as Sony tells theaters they don't need to show "The Interview" due to terror threats. The movie is scheduled for release on Christmas, Dec. 25, and it would appear some theaters have already said they won't show the controversial film.

Movie theaters that decide to still show the film plan to use additional security - even if there has been no credible evidence a plot is in place - with AMC, Cinemark, Regal and Carmike all suffering a drop in stock values because of the threat.

"Somebody is playing mind games with [Sony]," said Richard Clarke, cybersecurity expert and former White House counter-terrorism lead, in a statement published by Good Morning America. "I think North Korea has little or no capability to do any physical attacks, commando activity, or terrorism in the U.S. By saying it's coming, however, they hope to keep people from the theaters and, thereby, hurt Sony's revenue."

Continue reading: Sony allowing movie theaters to pull 'The Interview' before release (full post)

Sony hackers threaten terror attacks against movie theaters in US

| Dec 16, 2014 2:19 PM CST

The ongoing drama for Sony Pictures Entertainment took a dark turn on Tuesday, with the hacker group responsible issuing a terrorist threat when 'The Interview' hits theaters. It would seem the threat is working, as some movie theater operators are considering pulling the movie.

"We will clearly show it to you at the very time and places 'The Interview' [will] be shown, including the premiere, how bitter fate those who seek fun in terror should be doomed to," the hackers said in a statement. "Soon all the world will see what an awful movie Sony Pictures Entertainment has made. The world will be full of fear. Remember the 11th of September 2001."

The group also recommended people stay away from theaters after the movie is released.

Continue reading: Sony hackers threaten terror attacks against movie theaters in US (full post)

Cybercriminals with bulk stolen data finding new ways to cash out

| Dec 16, 2014 3:32 AM CST

Cybercriminals are compromising US consumers and business workers on a large scale, able to steal personal information and payment details in bulk. Home Depot was compromised and 56 million payment card numbers and 53 million email addresses were taken in a single breach alone, along with Target, Neiman Marcus, and a number of retailers also falling victim.

However, trying to make use of stolen information forces cybercriminals to act quickly - if 10,000 cards are compromised, only around 100 could cash out, with an estimated 10 cars actually working, according to Alex Holden, from Hold Security.

"Cybercriminals don't have enough resources to monetize stolen data in big volumes," said Andrew Komarov, IntelCrawler CEO, in a statement to PCWorld. "It really has a small margin, and it is pretty complicated to resell it in big amounts."

Continue reading: Cybercriminals with bulk stolen data finding new ways to cash out (full post)

Sony Pictures CEO says employees shouldn't be worried about the future

| Dec 15, 2014 11:05 PM CST

Sony Pictures Entertainment employees heard from company CEO Michael Lynton and co-chair Amy Pascal during an open town hall meeting on Monday. The company is still painfully suffering after a major data breach led to emails stolen, employee personal information leaked, and other disruptions to its business.

"This will not take us down," Lynton said during the town hall meeting in front of employees. "You should not be worried about the future of this studio."

Lynton apologized that employee personal information and medical records were stolen - and then posted online - by the cybercriminals. During the two sessions held on Monday, there were no question and answer segments for employees to ask questions to Lynton or Pascal.

Continue reading: Sony Pictures CEO says employees shouldn't be worried about the future (full post)

Mark Cuban warns that emails can become part of a data breach

| Dec 15, 2014 9:33 PM CST

Billionaire investor Mark Cuban was caught up in the data breach suffered by Sony Pictures Entertainment, as Sony Pictures Television President Steve Mosko, Cuban, and Cuban Companies attorney Robert Hart were discussing contract negotiations for "Shark Tank." Cuban was not pleased to be offered $30,000 per episode in season 5, $31,200 per episode in season 6, and $32,488 per episode in season 7.

Cuban now speaks directly with Mosko via Cyber Dust, Cuban's free texting app, providing a secure platform in which messages and photos are purged after 30 seconds. Similar to SnapChat, however, it would appear Cyber Dust messages can be captured - but indicates a growing trend among users looking for more secure communications.

"For those following the Sony hack situation, you may have seen one of my emails about my Shark Tank salary and deal emerge," Cuban recently said via Cyber Dust. "What they don't know is that I moved all the rest of my discussions to Cyber Dust! That's why there was only one email. Moral of the story is that the 'no big deal' email you send today can easily be part of tomorrow's big hack leak. No matter who you are, someone you know is getting hacked and it could impact you."

Continue reading: Mark Cuban warns that emails can become part of a data breach (full post)

Anonymous targeting Swedish government for sinking The Pirate Bay

| Dec 15, 2014 6:16 PM CST

The Anonymous hacker collective and Lizard Squad aren't happy with the Swedish government for dropping The Pirate Bay, and is launching cyberattacks to compromise government officials. Hackers provided the URL and IP addresses used by the Swedish police force, inviting other hackers to target its website. Additional attacks related to the remove of The Pirate Bay are expected to continue in coming weeks from a number of different groups.

Last week, Swedish ISP Telia also suffered cyberattacks, causing online services disruptions and connectivity issues for subscribers throughout the country. Usernames and passwords of numerous Swedish government officials were posted online by Anonymous. Hackers also targeted government email addresses for representatives in Argentina, Israel, India, Mexico and Brazil.

Trying to prevent these cyberattacks proves difficult for government agencies and companies, especially with Anonymous operating as an organized, decentralized collective of skilled hackers.

Continue reading: Anonymous targeting Swedish government for sinking The Pirate Bay (full post)

Cybercriminals turning their attention to attacks on PoS vendors

| Dec 15, 2014 2:34 PM CST

Point-of-Sale (PoS) vendors are facing an increasing number of cyberattacks, as organized hackers find new methods to compromise customer data. The Charge Anywhere payment gateway solution provider announced it was compromised, with the breach first occurring in 2009.

The PoS infrastructure, especially as more companies begin to test mobile payment services, will become a major target for criminals. In addition to Charge Anywhere, PoS system vendor Signature Systems also confirmed it suffered a data breach in September, with custom malware installed to steal data. Trying to crack down - and limit - these types of attacks will be extremely difficult, with a growing number of highly-organized cybercriminal groups trying to steal US consumer payment data.

"I would expect attacks like this to become more frequent and more widespread for the reason that seems to be underreported on this breach - the substantial increase in mobile payments due to ease of use, and the ability to accept payments equickly, especially to smaller businesses," said Tom Bain, CounterTack VP of security strategy, as noted by Dark Reading. "Users expect and have a blind trust in applications that support their business - and just expect that security measures are taken to protect them. In just a six-month span this year, mobile malware attacks have increased [by six times] globally."

Continue reading: Cybercriminals turning their attention to attacks on PoS vendors (full post)

Sony hackers pledge to withhold stolen employee data

| Dec 15, 2014 3:40 AM CST

The Guardians of Peace hacker group, which has taken credit for compromising Sony Pictures Entertainment, has offered to withhold compromising data: employees only need to email them their name and business title to be spared. The unique correspondence comes ahead of another promised round of published email correspondence between SPE employees.

Here is what the group said in an email: "Message to SPE staffers. We have a plan to release emails and privacy of the Sony Pictures employees. If you don't want your privacy to be released, tell us your name and business title to take off your data."

The message also has an ominous warning to SPE executives: "The sooner SPE accept our demands, the better, of course. The farther time goes by, the worse state SPE will be put into and we will have Sony go bankrupt in the end."

Continue reading: Sony hackers pledge to withhold stolen employee data (full post)

SPE attorneys want media to destroy received materials from breach

| Dec 14, 2014 10:13 PM CST

Sony Pictures Entertainment is still trying to recover from a nasty data breach, and now the company's attorneys are taking aim at the media. Hackers have released eight rounds of data, much of it embarrassing, as SPE's attorneys want journalists and bloggers to stop publicizing leaked data.

"We are writing to ensure that you are aware that SPE does not consent to your possession, review, copying, dissemination, publication, uploading, downloading or making any use of the stolen information," according to a letter written by attorney David Boies, and sent to several tech media outlets.

The Supreme Court previously found a radio not liable for broadcasting an illegally recorded conversation, as the station was a third-party and didn't participate in actively making the audio recording. It would seem unlikely the SPE can make any legal demands of journalists for posting the data - and outlets will continue to air SPE's dirty laundry in public.

Continue reading: SPE attorneys want media to destroy received materials from breach (full post)

Sony warned before hack that its networks were vulnerable to attack

| Dec 14, 2014 2:20 PM CST

Before Sony Pictures Entertainment was compromised in a significant cyberattack that crippled its computer systems and led to large amounts of data stolen, the company was warned of lapses in cybersecurity. SPE's firewall and at least 100 other devices were being monitored by the studio's in-house team instead of Sony's corporate security team, according to an audit done by PricewaterhouseCoopers (PwC).

"Security incidents impacting these network or infrastructure devices may not be detected or resolved [in a] timely [manner]," according to a PrincewaterhouseCoopers confidential report available in September. Re/code received a copy of the report and indicated SPE knew of significant security problems, but had a slow reaction time before trying to resolve problems.

Hollywood studios and other major corporations have the opportunity to learn from SPE's significant data breach, at Sony's expense.

Continue reading: Sony warned before hack that its networks were vulnerable to attack (full post)

Companies hiring hackers to test Internet of Things security efforts

| Dec 14, 2014 12:35 PM CST

The Internet of Things (IoT) is expected to explode in popularity in coming years, but trying to keep a growing number of connected devices secure from cybercriminals remains a major effort. To help get a step ahead of malicious criminals, companies are embracing white hat hackers specialized in finding and exploiting potential security loopholes - and then sharing details with the company.

"Source code analysis, integrating security testing into the normal test cycle, and penetration testing at the end," said Michael Murray, director of GE Healthcare cybersecurity consulting and assessment, in a statement published by Dark Reading. "I'm [still] breaking lots of stuff. I'm just breaking it before it gets to the customer to make sure bad things don't happen to people out in the world."

Connected devices are increasing to vehicles, our homes and apartments, medical devices, and virtually everywhere else - but keeping consumers and users secure is a major effort.

Continue reading: Companies hiring hackers to test Internet of Things security efforts (full post)

Hollywood can learn from Sony's mistakes, show caution while chatting

| Dec 14, 2014 8:18 AM CST

Despite major ramifications from its data breach suffered last month, with Sony still seeing bulk amounts of information leaked online, the company must continue moving forward. However, hopefully some people in the movie industry can now appreciate that public figures will remain a target of interest among hackers.

Agents, actors and movie studios in Hollywood can certainly learn from Sony's glaring mistakes, understanding that those emails with snide marks about others - which they expect to be confidential - shouldn't be sent, in fear potentially being leaked.

"[T]here's going to be consequences for senior people at the studio," said Sharon Waxman, founder and editor-in-chief of TheWrap, speaking to CNBC. "The studio has to go on with its business and it's drip drip drip everyday of an unknown damage hitting the studio - and embarrassment, another piece of information."

Continue reading: Hollywood can learn from Sony's mistakes, show caution while chatting (full post)

Chinese cybercriminals continue to ravage critical infrastructure

| Dec 14, 2014 7:36 AM CST

Chinese cybercriminals are finding success using social engineering attacks to easily compromise companies, with an increased focus on universities, financial institutions, defense contractors, and critical infrastructure. Likely state-sponsored cyberattackers were able to breach the Canadian National Research Council, searching around for scientific research information and possible trade secrets.

A spear-phishing attack, with the email including an attached piece of malicious code, found its way onto the organization's network. The Canadian government didn't disclose what type of information could have been compromised from the breach, which took place earlier in 2014.

It is also unclear as to whether any personal information has been compromised," said Tobi Cohen, a privacy commissioner spokeswoman, as noted by the CBC. "We are satisfied that the organization took appropriate steps to notify employees and other parties about the cyber-intrusion and that efforts are underway to update [information technology] systems and security procedures to prevent this from happening again."

Continue reading: Chinese cybercriminals continue to ravage critical infrastructure (full post)

Guardians of Peace threaten Sony, saying a 'Christmas gift' is coming

| Dec 14, 2014 5:23 AM CST

The Guardians of Peace released more information stolen from Sony, and promised a large "Christmas gift" of additional data taken in a breach Sony suffered that started late last month. The leaked content reportedly contained more email correspondence and information related to Crackle, the online video website.

Here is part of the post from hackers (via Pastebin): "We are preparing for you a Christmas gift. The gift will be larger quantities of data. And it will be more interesting. The gift will surely give you much more pleasure and put Sony Pictures into the worst state."

The cybercriminals behind the Sony breach have released seven waves of stolen data and movies to the Internet, and will continue to do so. The FBI and cybersecurity companies are helping Sony clean up the mess, but the damage has clearly already been done.

Continue reading: Guardians of Peace threaten Sony, saying a 'Christmas gift' is coming (full post)

Join Our Newsletter

Join the TweakTown Newsletter for daily tech updates delivered to your inbox.

See previous giveaways.

Newsletter Subscription