Newsletter IconFacebook IconX IconThreads IconInstagram IconYouTube IconPinterest Icon
Giveaway: AVerMedia Creator Bundle (4K Webcam, Capture Card, Charging Hub, and Mouse Pad)

Hacking, Security & Privacy - Page 37

Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 37

Stay Updated

Follow TweakTown for breaking tech news, reviews, and daily updates.

Add TweakTown as a preferred source on GoogleFind TweakTown on Apple News

As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.

The Pirate Bay have been taken down, but didn't drop piracy levels

| Dec 13, 2014 5:34 PM CST

It very well could have been a symbolic victory and nothing else, after The Pirate Bay was shuttered, but digital piracy levels didn't significantly drop. Piracy torrent statistics have been made available courtesy of the anti-piracy Excipio firm, which tracks movie, TV shows, music, video games, and software torrent downloads - and on Dec. 8, the day before Pirate Bay servers were seized, there were 101.5 million IP addresses engaged in torrent downloads.

The number dropped to 99 million on Dec. 9, then down to 95 million on Dec. 10, and 95.6 million downloads on Dec. 11, according to Excipio. However, the number again topped 100 million on Dec. 12, which noted that the daily average of torrent downloads worldwide since Nov. 1 was 99.99 million.

For interested Internet users, there are dozens of other websites that allow access to torrent downloads, and Internet piracy will continue to be a thorn in the side to governments and copyright holders.

Continue reading: The Pirate Bay have been taken down, but didn't drop piracy levels (full post)

FBI warns US companies to be aware of potential cyberattacks from Iran

| Dec 13, 2014 4:14 PM CST

US companies need to be aware of increasingly sophisticated Iranian cyberespionage operations, according to the FBI, with targets ranging from educational institutions, energy firms, defense contractors, and additional critical infrastructure.

As part of Operation Cleaver, there have been 50 victims in 16 countries reported so far, according to cybersecurity company Cylance. The FBI's "Flash" report also included technical details about sophisticated malware and attack strategies that are likely being used by Iranian cybercriminals. "It underscores Iran's determination and fixation on large-scale compromise of critical infrastructure," Cylance CEO Stuart McClure reportedly noted.

Potential victims have been asked by the FBI to speak with them, especially if potential links point towards foreign cybercriminals.

Continue reading: FBI warns US companies to be aware of potential cyberattacks from Iran (full post)

Apple OS X users in the United States faced largest number of attacks

| Dec 13, 2014 2:35 AM CST

Apple OS X users in the United States faced a large number of cyberattacks, with almost 100,000 users being targeted, according to a Kaspersky Lab report. Not surprisingly, that accounted for 39 percent of total Mac OS X cyberattacks - largely because the US has the largest number of Apple product owners - as cybercriminals pay more attention to iOS on smartphones and tablets, along with OS X on desktop computers and laptops.

AdWare programs were the most popular method of attack against OS X users, accounting for almost half of the top 20 list, according to Kaspersky.

OS X users are strongly urged to install some type of anti-virus and anti-malware software solution, as cybercriminals pay more attention to compromising Apple products.

Continue reading: Apple OS X users in the United States faced largest number of attacks (full post)

A VMWare AirWatch bug allowed users to access others sensitive data

| Dec 12, 2014 9:06 PM CST

AirWatch's on-premise mobile device management solution has recently received a major update - patching a flaw that enabled users who manage MDM solutions in multi-tenant environments to access other users data and information.

The patch was issued this week, closing the 'information disclosure hole' in its services. iTnews reported that the published security advisory VMSA-2014-0014 addressed the issue, with them claiming this was due to "AirWatch On-Premise having direct object reference vulnerabilities which could allow a manager of an MDM deployment in a multi-tenant environment to see organisational information and statistics of other tenants."

These direct object reference vulnerabilities will allow criminals to bypass user authentication and access all of your databases and sensitive files directly - rendering any security measures in place as useless. According to the Open Web Application Security Project this flaw is quite common and widespread, seeing it exploited by hackers globally in the past and present. Due to this flaw, there have been previous reports of up to 500 Dodo Power and Gas customer information being compromised two years ago, alongside Australia Post removing its Send and Click service due to a similar discovery.

Continue reading: A VMWare AirWatch bug allowed users to access others sensitive data (full post)

FBI says cyberattack that hit Sony would have worked against others

| Dec 12, 2014 8:19 AM CST

The FBI is still unsure what hacker group successfully compromised Sony Pictures Entertainment, but said 90 percent of companies would likely fall victim to the same tactics. FBI officials also have reportedly met with Sony employees to explain how to protect themselves due to personal information being stolen as part of the breach.

"[T]he malware that was used would have gotten past 90 percent of the Net defenses that are out there today in private industry and [would have been] likely to challenge even state government," said Joe Demarest, assistant director of the FBIU cyberdivision, at a Senate Banking Committee hearing.

Sony is working with Mandiant, a cybersecurity forensics company, and CEO Kevin Mandia confirmed that this type of attack would be difficult to prepare for. The Guardians of Peace took credit for the attack, with purported GOP members emailing the media additional details of the breach.

Continue reading: FBI says cyberattack that hit Sony would have worked against others (full post)

Amazon denies Sony is using its AWS to launch DDoS cyberattacks

| Dec 11, 2014 5:16 PM CST

Sony has been accused of launching distributed denial of service (DDoS) attacks against websites hosting its stolen content, using Amazon Web Service as a launch pad, according to unnamed sources speaking with Re/code. It would seem extremely unlikely - and easily identifiable - if Sony decided to use AWS to launch any form of DDoS attacks, with network monitoring company CloudFlare suggesting Sony didn't launch any counter-attacks.

Amazon sent the following statement to TweakTown:

"AWS employs a number of automated detection and mitigation techniques to prevent the misuse of our services. In cases where the misuse is not detected and stopped by the automated measures, we take manual action as soon as we become aware of any misuse. Our terms are clear about this. The activity being reported is not currently happening on AWS."

Continue reading: Amazon denies Sony is using its AWS to launch DDoS cyberattacks (full post)

Sony takes a page from hackers, attacking sites hosting its movies

| Dec 11, 2014 2:40 PM CST

Sony is still reeling from its major cyberattack and brutal data breach, now deciding to use the Amazon Web Services (AWS) to allegedly launch distributed denial of service (DDoS) attacks against websites. Movie studios have tried to counter piracy hubs by flooding them with fake files - and launch cyberattacks against them - with varying levels of success.

"The AWS acceptable usage policy explicitly prohibits initiating denial of service attacks from their service; it's unlikely that Amazon would let this activity continue," said Tim Erlin, Tripwire director of security and risk. "Taking the step to 'hack back' against perceived legitimate targets, based on their own assessment of guilt, presents a myriad of potential legal problems."

If these accusations are true, trying to launch attacks against websites hosting stolen Sony movies isn't the best idea.

Continue reading: Sony takes a page from hackers, attacking sites hosting its movies (full post)

Tech companies largely relying on hackers to find exploits for them

| Dec 11, 2014 7:14 AM CST

Major technology companies want to hire hackers to help identify potential software vulnerabilities before products are released - and real cybercriminals are able to exploit any problems. The "bug bounties" program is being embraced by Facebook, Mozilla, Google and other major Silicon Valley companies, providing thousands of dollars to help identify bugs.

"The trajectory we're on now is completely unsustainable," said Vikram Phatek, NSS Labs CEO, when discussing the current cybersecurity landscape. "There will not be a person in the country who will not have a compromised computer if this goes on. We are ripe for having a major catastrophe."

Despite some resistance from companies weary of paying outside sources to identify security flaws, trying to prevent cybersecurity data breaches will remain a major effort. However, compromising widely used software is a lucrative effort for cybercriminals, with more money seemingly available on the black market.

Continue reading: Tech companies largely relying on hackers to find exploits for them (full post)

Sabu, former Anonymous member turned informant, speaks out publicly

| Dec 10, 2014 5:21 AM CST

The FBI has tried to crack down on the Anonymous hacker collective, including turning a former high-ranking member into an informant - but the group is still alive and well. Hector Monsegur, operating under the hacker name of "Sabu," admits to a large number of attacks against select targets.

Since being flipped by the FBI, Sabu spent three years communicating with Anonymous and LulzSec members, with the government listening in. His actions reportedly helped prevent more than 300 major cyberattacks against government and NASA PCs and networks.

Sabu says he didn't identify Anonymous members and turn them over to the FBI - and cooperated to help identify attacks, and work to prevent them in the future. "It wasn't a situation where I identified anybody. I didn't point my fingers at nobody. My cooperation entailed logging and providing intelligence. It didn't mean, 'Can you please tell me the identity of one of your mates?'"

Continue reading: Sabu, former Anonymous member turned informant, speaks out publicly (full post)

Sony's hacking woes increase as PlayStation store suffers attack

| Dec 8, 2014 10:42 AM CST

Things just don't seem to be getting better for Sony. Hot on the heels of a shocking data theft at Sony Pictures, a new attack occurred today on the PlayStation store. Suspicions are centered around North Korea for the Sony Pictures hack, and the custom malware designed for that hack is now on the loose, threatening the world at large with a devastating over-write malware.

A group called The Lizard Squad is taking responsibility for the latest attack on the PlayStation Store this morning via a Twitter message that simply reads: "PSN Login #offline". This latest attack appears to be a denial-of-service attack, which overruns the website and prevents users from logging in. However, the full scope of the attack is not yet known, and Sony is currently investigating the breadth of the assault. Word on whether there was a data breach associated with the attack will come forward in the next few days. Sony and The Lizard Squad have a contentious history, to say the least. Earlier this year Lizard Squad issued a warning there were explosives on a domestic flight, resulting in its diversion. There just so happened to be a Sony executive on the flight.

Lizard Squad also claimed responsibility for a recent attack on the PlayStation network earlier this year. This attack was another denial-of-service attack that shuttered the large PlayStation network. The PlayStation network has been the constant target of attacks, in 2011 more than 70 million user accounts were compromised, and the associated data was stolen. Sony has since invested an untold amount of money on reducing their vulnerabilities, but from the looks of it that effort isn't going well.

Continue reading: Sony's hacking woes increase as PlayStation store suffers attack (full post)

Sony hackers have reportedly been traced back to a hotel in Bangkok

| Dec 8, 2014 2:30 AM CST

The hack against Sony has been all over the news for a couple of weeks now, but it has reportedly all been tracked back to a single, posh hotel in Bangkok. North Korea has stepped up saying that it was not responsible for the hack, which had people thinking the country had attacked Sony over its movie "The Interview" with Seth Rogen and James Franco.

The hackers were traced back to St. Regis Bangkok, which is a 4.5-star resort where even the most basic rooms cost over $400 per night. We don't know if the hack was done from inside of one of these hotels, or outside in a public area of the hotel, but we do know they came from the St. Regis Bangkok. The investigations into the breach of Sony Pictures Entertainment servers took place on December 2, at 12:25AM local time.

Continue reading: Sony hackers have reportedly been traced back to a hotel in Bangkok (full post)

North Korea says its supporters could be behind Sony cyberattack

| Dec 8, 2014 1:25 AM CST

Pro-North Korean hackers could be responsible for a cyberattack that crippled Sony Pictures, according to a statement broadcasted on a state-run television channel. The successful breach will likely cost SPE millions from interrupted business operations, data theft, and screener versions of the movie that have leaked online.

The KCNA news agency said that the "hacking into Sony Pictures Entertainment might be a righteous deed of the supporters and sympathizers with the DPRK in response to its appeal."

There are digital fingerprints that point towards North Korea, and cybersecurity experts and the FBI are helping SPE investigate the incident. Despite extreme poverty that most of the country's citizens endure, the controlling government has reportedly invested a great deal into developing hackers with developed cyberattack capabilities.

Continue reading: North Korea says its supporters could be behind Sony cyberattack (full post)

Apple must continue to improve cybersecurity as attacks increase

| Dec 7, 2014 12:31 AM CST

Several high-profile cyberattacks launched against Apple have revealed OS X and iOS aren't as secure anymore, with criminals trying to compromise both operating systems. Enterprise workers are at risk because of Apple taking a "whack-a-mole" approach to security, which is a major threat with sophisticated spear-phishing attacks.

"Apple's responses to the WireLurker and Masque Attack operations illustrate that iOS is entering the 'whack-a-mole' era of malware defense, similar to that experienced during the last decade with PCs," said Dave Jevans, Marble Security founder and CTO. "Being proactive rather than reactive is essential in preventing these ioS vulnerabilities and exploits from affecting enterprise networks, and implementing mobile device security solutions is a huge step in achieving this."

Sophisticated cyberattacks target most major technology companies, but Apple previously was left relatively unscathed from most malicious code. However, cybercriminals want to find strategies to steal information and conduct data breaches, with a specific focus on compromising iPhones and iPads in the workplace.

Continue reading: Apple must continue to improve cybersecurity as attacks increase (full post)

The Sony Pictures hack is much more in-depth than originally known

| Dec 5, 2014 7:08 PM CST

Remember the Sony Pictures hack that saw employee's computers compromised and in-cinemas movies be released to the public? Well, according to recent news - this hack is even more in depth that originally thought.

Thanks to Gizmodo we were able to learn some more information regarding the whole ordeal, including various issues that Sony may face in the near future. As according to BuzzFeed, the 40 gigabytes of data released by these hackers contained everything from medical records to unreleased movie scripts - being claimed as one of the worst corporate hacks in history.

Members of the public have been questioning Sony's security and precautions surrounding this event taking place, some asking why Sony would have this information stored on an open network if it is so sensitive. Continuing with the bad news, BuzzFeed confirmed that the Sony leak included "employee criminal background checks, salary negotiations, and doctors' letters explaining the medical rationale for leaves of absence." This came alongside the release of a "script for an unreleased pilot written by Breaking Bad creator Vince Gilligan to the results of sales meetings with local TV executives."

Continue reading: The Sony Pictures hack is much more in-depth than originally known (full post)

Consumer payment data, healthcare record theft threats loom in 2015

| Dec 4, 2014 10:32 AM CST

Data breaches have become an unfortunate reality for US consumers, and the problem seems likely to accelerate in 2015 while cybercriminals perfect their craft. Cybercriminals are aware banks are increasingly issuing chip-and-PIN credit cards - as retailers also switch to support the more secure cards - and will try to compromise companies as fast as they can in early 2015.

"There will absolutely be more breaches in 2015 - possibly even more than we saw in 2014 due to the booming underground market for hackers and cybercriminals around both credit card data and identity theft," said Kevin Routhier, Coretelligent founder and CEO. "This growing market, coupled with readily available and productized rootkits, malware and other tools will continue to drive more data breaches in the coming years as this is a lucrative practice for enterprising criminals."

In addition to consumer payment data, medical records will continue to prove lucrative to cybercriminals. Healthcare providers and companies hosting confidential payment information will have to prepare for an increase in attacks designed to steal this data.

Continue reading: Consumer payment data, healthcare record theft threats loom in 2015 (full post)

Cybersecurity efforts improving, but data breaches will continue

| Dec 3, 2014 7:16 PM CST

The Target breach was a nasty wakeup call for retailers, cybersecurity experts and consumers, as criminals were able to compromise millions of American shoppers. Since the incident, there has been a reported eight percent increase in IT security spending, but that still hasn't been able to slow down a tidal wave of follow up breaches.

"The reality is that companies that have taken these steps are treating the symptoms but not the underlying problems," said Dr. Barbara Rembiesa, CEO of the International Association of Information Technology Asset Managers (IAITAM). "By focusing only on narrowly focused and superficial IT security 'solutions,' companies are putting the cart before the horse and they're going nowhere."

In fact, security issues will continue to plague retailers in 2015, with companies too focused on trying to fix IT security gaps while not looking at the big picture. Dr. Rembiesa recommends companies to be fully aware of their PC systems and networks, as they cannot defend against a breach if they didn't know which systems are working on their networks.

Continue reading: Cybersecurity efforts improving, but data breaches will continue (full post)

FBI issues warning over disk-wiping malware used in Sony hack

| Dec 3, 2014 1:27 PM CST

The Sony Pictures hack has had an immediate impact in the form of several soon-to-be-released movies popping up on torrents, and Sony's employee personal records and passwords have also been leaked. Sony has been placed into a lockdown of sorts, and employees are not being allowed to login to their computers. The long-term effects may be even more devastating, as the FBI is warning that the malware used to execute the Sony attack is on the loose. The FBI's five-page flash warning was issued to major US corporations on Monday. The malware was specifically created to attack Sony, but other hackers often modify existing malware for their own purposes. There is an increasing threat of hackers creating a large number of mutations now that the exceptionally virulent bug is on the loose.

The nefarious bug not only steals data, but it also eventually overwrites all information on the storage device. This is particularly devastating. Once overwritten, the data is almost surely unrecoverable. The malware even overwrites the Windows master boot record (MBR), which makes any hope of salvaging data even harder. The warning from the FBI is targeted at businesses, but as with any malware, it will soon trickle out to the wider world at large. Nation-state developed malware is on the rise as shadowy global cyber-warfare campaigns continue unabated. Nations have many more resources at their disposal to create these electronic arms of mass destruction, but completely ignore the fact that these sophisticated hacks eventually spread to the public.

Components of the insidious malware have been tracked back to North Korea, which was very upset over a pending Sony movie that outlines an assassination attempt of the oft-ridiculed Kim Jong-un. Surprisingly, North Korea has a sophisticated cyber-warfare unit that has been linked to other large scale attacks in the past. A North Korean spokesperson offered a weak denial in the attack, but added in the comment that "I kindly advise you to just wait and see" if they were behind the attack.

Continue reading: FBI issues warning over disk-wiping malware used in Sony hack (full post)

Report claims Iranian hackers focused on airlines, energy utilities

| Dec 2, 2014 3:26 PM CST

Iranian hackers continue to develop their cyberattack capabilities, and have breached some of the leading energy infrastructure and transport companies, potentially leading to physical damage, the Cylance cybersecurity firm warned.

As part of the widespread campaign, companies in the United States, China, Israel, Germany, France, India and Saudi Arabia have been hit - with industries ranging from aerospace research companies, universities, energy firms, telecommunications operators and hospitals being compromised.

"We believe that if the operation is left to continue unabated, it is only a matter of time before the team impacts the world's physical safety," the Cylance report claimed.

Continue reading: Report claims Iranian hackers focused on airlines, energy utilities (full post)

North Korea doesn't claim responsibility over crippling Sony hack

| Dec 2, 2014 4:17 AM CST

North Korea is not surprisingly denying its involvement in the Sony Pictures Entertainment cyberattack last week that brought the company to a grinding halt. The country previously showed displeasure at SPE's movie The Interview, which will be released later this month, featuring a plot by two Americans to assassinate North Korean leader Kim Jong-Un.

"The hostile forces are relating everything to the DPRK. I kindly advise you to just wait and see," a North Korean spokesperson recently said. I do not know anything about this."

Some cybersecurity experts don't believe North Korea has significant infrastructure to launch cyberattacks - but could have called upon China or Russia - to launch the attack on its behalf. Some organized cybercriminal groups are willing to offer their services to the highest bidder, especially if it involves targeting high-profile attacks targeting companies in the United States.

Continue reading: North Korea doesn't claim responsibility over crippling Sony hack (full post)

Unreleased Sony films hit Internet after cyberattack last week

| Nov 30, 2014 11:51 PM CST

Four different movies from Sony Pictures Entertainment, including Annie, Fury, Mr. Turner and Still Alice, have leaked online via peer-to-peer file sharing networks. The company suffered a major cyberattack last week, which is now being investigated by law enforcement, Sony confirmed. The digital copies are watermarked and were likely caused by the SPE network intrusion, sources have confirmed.

"The theft of Sony Pictures Entertainment content is a criminal matter, and we are working closely with law enforcement to address it," a Sony spokeswoman recently said.

Fury made its appearance on file sharing networks on Nov. 27, and has been downloaded at least 888,000 times. This is the largest leak since July, after the Expendables 3 movie was released online almost one month before release in theaters.

Continue reading: Unreleased Sony films hit Internet after cyberattack last week (full post)

Join Our Newsletter

Join the TweakTown Newsletter for daily tech updates delivered to your inbox.

See previous giveaways.

Newsletter Subscription