Newsletter IconFacebook IconX IconThreads IconInstagram IconYouTube IconPinterest Icon
Giveaway: AVerMedia Creator Bundle (4K Webcam, Capture Card, Charging Hub, and Mouse Pad)

Hacking, Security & Privacy - Page 38

Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 38

Stay Updated

Follow TweakTown for breaking tech news, reviews, and daily updates.

Add TweakTown as a preferred source on GoogleFind TweakTown on Apple News

As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.

Sony recruits Mandiant to help clean up cybersecurity mess

| Nov 30, 2014 6:54 PM CST

Sony Pictures Entertainment has tasked cybersecurity firm Mandiant with helping it clean up after a vicious cyberattack that knocked its computer networks offline last week. The "Guardians of Peace" claimed responsibility for the attack, saying they stole terabytes of data from SPE, with SPE's IT team unable to defend against the attack.

The SPE email system is expected to be restored by end of business tomorrow, while Sony executives remain relatively quiet about the incident.

It is a lucrative time to be in cybersecurity, as companies are turning to private sector companies for additional consultations - as cyberattacks are on the rise, with criminals able to steal internal data, disrupt daily work activities, and compromise customers.

Continue reading: Sony recruits Mandiant to help clean up cybersecurity mess (full post)

North Korea could be behind Sony Pictures hack, investigation underway

| Nov 29, 2014 2:28 PM CST

Forget China and Russia - Sony Pictures Entertainment is investigating a major cyberattack that could have originated from North Korea. The attack crippled SPE's email and computer systems since Monday, interrupting employee operations throughout the short holiday week. Several movies being promoted by SPE were also impacted, as Twitter feeds were disrupted by the cyberattack.

The "Guardians of Peace" group claimed responsibility for the attack, and said it has a large amount of internal Sony data that it has taken. GOP is reportedly preparing a "volume of the data" to the Internet in the immediate future.

SPE is the studio behind "The Interview," a geopolitical satire that features James Franco and Seth Rogen as a talk show host and producer turned American operatives tasked with killing Kim Jong Un.

Continue reading: North Korea could be behind Sony Pictures hack, investigation underway (full post)

Panda Security finds more than 20 million new malware samples in Q3

| Nov 29, 2014 5:24 AM CST

Panda Security collected 20 million new malware samples created worldwide, with an average of 227,747 new samples per day during Q3. The global infection rate increased from 36.87 percent up to 37.93 percent year-over-year, and Trojans are the most common type of malware. Trojans accounted for 78.08 percent of malware types, with viruses (8.89 percent) and worms (3.92 percent) also making an appearance.

Internet users face a cybersecurity threat from hackers, state-sponsored cybercriminals, and national government spy agencies - and trying to stay secure is rather difficult. China (49.83 percent), Peru (42.38 percent) and Bolivia (42.12 percent) are the three countries most targeted by cyberattacks, with nine European countries in the top ten most secure nations: Norway (23.07 percent), Sweden (23.44 percent), and Japan (24.02 percent) are the top three most secure.

"Over recent months cybercrime has continued growing," said Luis Corrons, PandaLabs Technical Director at Panda Security. "Cyber-crooks are still creating malware in order to infect as many computers as possible and access confidential data - but corporate environments have also come under attack. For example, over the last three months large companies have been the subjects of some scandals, such as the infamous 'Celebgate,' in which photos of actresses and models hosted on Apple's iCloud service were leaked, or the theft of Gmail and Dropbox passwords."

Continue reading: Panda Security finds more than 20 million new malware samples in Q3 (full post)

Home Depot spent up to $43M on data breach during just one quarter

| Nov 28, 2014 1:47 PM CST

Following a massive data breach that left 56 million debit and credit card details stolen, along with 53 million email addresses, the company spent $43 million during Q3 to deal with the aftermath. The company expects to receive $15 million reimbursement as part of a $100 million network liability insurance policy - and must now work to ensure the problem doesn't occur again.

Meanwhile, the company faces multiple lawsuits and will "incur significant legal and other professional services expenses" due to the incident. The company's payment card data network was complaint in fall 2013, and was undergoing 2014 certification when the breach occurred, according to an independent auditor.

"The forensic investigator working on behalf of the payment card networks may claim the company was not in compliance with those standards at the time of the data breach," Home Depot noted.

Continue reading: Home Depot spent up to $43M on data breach during just one quarter (full post)

Former GCHQ leader concerned over smartphone biometrics security

| Nov 28, 2014 12:08 PM CST

Former GCHQ boss Sir John Adye believes current generation biometrics need more control, as he has concerns related to fingerprint scanners used by the Apple iPhone 6 and other devices. Despite believing the use of biometrics is a positive step toward device security, Sir John also is concerned about what happens to people's data when using these devices.

Sir John called out Apple specifically, with Apple Pay now allowing users to make payments simply with their fingerprint.

"I think Apple has done some good things. They appear to have a good system at the moment for protecting their operating system so it's difficult for anyone outside to penetrate it and retrieve data from it. But how long will that last, because the criminals... are very inventive at finding ways in, and although you can protect it in that way on the device itself, what happens if the device is lost or stolen?"

Continue reading: Former GCHQ leader concerned over smartphone biometrics security (full post)

FBI pose as Internet technicians to secure evidence on a hotel guest

| Nov 27, 2014 11:25 PM CST

The FBI stepped over its boundaries with this particular case, where the US agency wanted to gain entry into a particular hotel guest's room, all without a warrant. When they couldn't secure one, they did the next best thing: posed as Internet technicians, gaining access to the hotel room, all without a warrant.

From the motion to suppress, we find out: "The next time you call for assistance because the internet service in your home is not working, the "technician" who comes to your door may actually be an undercover government agent. He will have secretly disconnected the service, knowing that you will naturally call for help and -- when he shows up at your door, impersonating a technician -- let him in. He will walk through each room of your house, claiming to diagnose the problem. Actually, he will be videotaping everything (and everyone) inside. He will have no reason to suspect you have broken the law, much less probable cause to obtain a search warrant. But that makes no difference, because by letting him in, you will have "consented" to an intrusive search of your home".

The FBI agents secured evidence from the hotel room, and submitted it to a magistrate to get a warrant. Kind of the reverse of what should happen, but they obviously wouldn't have told the judge that they posed as the Internet technicians in order to get into the room to secure the evidence they required to obtain the warrant in the first place.

Continue reading: FBI pose as Internet technicians to secure evidence on a hotel guest (full post)

Hacker avoids maximum 440-year sentence, hit with misdemeanor instead

| Nov 27, 2014 1:23 PM CST

The Southern District of Texas offered a misdemeanor plea deal to hacker Fidel Salinas, 28, just a few months after the hacker was charged with 44 felony counts of computer fraud and cyberstalking. Each count had a maximum 10-year prison sentence, totaling a potential 440 years in prison.

Instead, the suspected Anonymous-linked hacker plead guilty to one misdemeanor count of computer fraud and abuse - and must also pay $10,000. He faces up to one year in prison when sentenced on February 2, 2015, and his attorney will argue the monetary restitution is enough.

Salinas reportedly tried to access the Hidalgo County administrative website, using a script that racked up more than 14,000 access attempts. The brute force attack led county IT administrators to be locked out of the system themselves.

Continue reading: Hacker avoids maximum 440-year sentence, hit with misdemeanor instead (full post)

Anonymous releases dox with KKK leader's credit card info, SSN

| Nov 27, 2014 12:12 AM CST

Anonymous has continued its #OPKKK campaign against members of the Ku Klux Klan in Missouri, after the group brazenly challenged the hacker collective online. The @KuKluxKlanUSA Twitter account was compromised last week, and the hacking fun was only beginning for Anonymous.

I won't link directly to the dox page, but it doesn't take much imagination into how one would easily find the information posted online, courtesy of Anonymous. Frank Ancona, the "KKK Imperial Wizard," had his address, phone number, Social Security number, credit card information, and other personal information - with the dox also targeting his wife - posted online.

Anonymous also might target government websites and infrastructure in Missouri to respond for the Grand Jury failing to indict Officer Darren Wilson: "We find it disturbing that you, the grand jury, have chosen this patch as everyone will not choose to stand calm and let you choose to let him walk free. As you've seen all the riots and businesses, police cars, etc., being burned down while Anonymous shall target any Missouri government or bank sites now, so you better increase your security because we're here and we're not going to stand by and watch you let this man walk free."

Continue reading: Anonymous releases dox with KKK leader's credit card info, SSN (full post)

Experts still claim Edward Snowden data leaks cost lives

| Nov 26, 2014 5:43 PM CST

Former NSA contractor Edward Snowden was disgusted by NSA and GCHQ mass surveillance activities, and disclosed the questionable actions of both agencies. However, multiple lawmakers and politicians have spoken out against his actions, saying he has put military personnel and intelligence agents at risk.

British lawmakers hope to push the Communications Data Bill, which would force ISPs and mobile service carriers to keep Internet browsing activity, social media, email correspondence, voice calls, Internet gaming activity, texting, and other records on file for a minimum of 12 months. Phone and email contact data is already retained due to the Data Retention Regulations 2014 bill.

"Consequently there are people dying who actually would now be alive," said Lord West, a former UK security minister and Navy admiral. "It is now critical that we move forward the Communications Data Bill that was paused so unreasonably because there is a very real danger that unless we do this, I think it is not exaggerating to say that people will die in this country who would have been safe if that had been in place."

Continue reading: Experts still claim Edward Snowden data leaks cost lives (full post)

Vodafone admits it accidentally sent too much information to police

| Nov 26, 2014 2:59 PM CST

The British government requested data on one journalist as part of Operation Elveden, focused on alleged bribes made to public officials for information, and "accidentally" received data on 1,000 News UK staff. Vodafone said there was some type of human error that led to the extra data being supplied, while police officials said they returned the information.

Police wanted information focused on one journalists that worked for News UK from 2005 to 2007, and used the Regulation of Investigatory Powers Act (RIPA) to receive the data - and the information was returned back to Vodafone after about four months.

"Unfortunately, there was a human error during the processing of this information - which was drawn manually from a legacy system - as a consequence of which the Met Police were supplied with a corrupted dataset containing a significantly higher volume of metadata than had been the focus of the warrant received by Vodafone. The metadata in question relates to call logs and other information, such as pricing data, not the content or location of any communications."

Continue reading: Vodafone admits it accidentally sent too much information to police (full post)

Insight into the mind of a former NSA programmer/hacker

| Nov 26, 2014 4:35 AM CST

Many cybersecurity specialists working for the NSA and GCHQ tend to get burned out, and then head to the private sector. It provides a unique opportunity to hear more about some of the efforts the US government have employed to conduct organized cyberespionage against foreign governments.

For regular Internet users, it doesn't matter whether it's the government or a foreign cybercriminal, cybersecurity must be appreciated and not overlooked. As former government programmers and security experts abandon their government jobs in favor of the private sector, companies want to rely on technology advice from intelligence officials - providing valuable insight into how governments are conducting increased surveillance.

"Whether they're cybercriminals or state sponsored actors, I think a lot of times they can get into a network using a less sophisticated approach or a variant of a known piece of malware... it's a lower risk operationally for them," said Jim Penrose, former NSA employee and part of the department's Tailored Access Operations (TAO) group. "They don't want to fire silver bullets unless it's absolutely necessary; like a zero day or something like that, or a previously unseen piece of malware. Those are really high quality and you want to save those for a time when it's absolutely critical."

Continue reading: Insight into the mind of a former NSA programmer/hacker (full post)

CoinVault ransomware allows victims to decrypt one file for free

| Nov 25, 2014 8:18 AM CST

The CoinValut ransomware victimizes businesses, encrypting critical work files - but there is an added twist with this particular piece of software. The criminals provide one free decrypt, providing access to a file, trying to provide additional faith in victims.

CoinVault uses 256-bit AES encryption, and the decryption keys are stored on remote servers - and Windows files cannot be recovered unless the bitcoin payment is submitted to cybercriminals. Victims are ordered to pay 0.5 bitcoins, around $200 at current market prices, with the price increasing every 24 hours.

Ransomware attacks typically rely on employees falling prey to social engineering techniques, designed to trick users into clicking suspicious links or downloading unknown files.

Continue reading: CoinVault ransomware allows victims to decrypt one file for free (full post)

Intel, McAfee working to eliminate passwords by using biometrics

| Nov 25, 2014 6:14 AM CST

The future of passwords could be under pressure if Intel-owned McAfee can develop new biometric authentication technology that can be supported. The average user has around 18 passwords, so using some type of biometrics would be able to help reduce that chaos.

"Your biometrics basically eliminate the need for you to enter passwords for Windows log in and eventually all your websites ever again," said Kirk Skaugen, Intel SVP and GM of the PC Client Group.

Despite passwords being under threat to be eliminated - for several years now - it still remains the most common security procedure for email, online banking, and other user accounts. However, passwords paired with other security procedures prove to be significantly more secure, though consumers are still waiting to learn more before abandoning all of their passwords.

Continue reading: Intel, McAfee working to eliminate passwords by using biometrics (full post)

Sony Pictures targeted in attack, as cybercriminals try to get to Sony

| Nov 24, 2014 5:49 PM CST

Sony Pictures Entertainment was forced to warn employees not to access corporate networks or check their email, because the company is under cyberattack and being blackmailed to prevent "secrets" from being released. It's unknown what information, if any, the hackers were able to steal from the Sony network.

An image that says SPE was "Hacked by #GOP" was published on the company's computers - and issued the following message: "Warning: We've already warned you, and this is just the beginning... We have obtained all your internal data including secrets and top secrets."

"Sony deserves praise for going offline while they figure out what is happening rather than allow further damage," said Hemanshu Nigam, Internet cybersecurity expert. "Hackers are always-on the hunt for holes in a network, which can happen when a system isn't updated properly or a feature change is made. It is critical for companies to conduct self-hacking exercises on a continuous basis to find and patch these vulnerabilities before the hackers find them."

Continue reading: Sony Pictures targeted in attack, as cybercriminals try to get to Sony (full post)

NSA, GCHQ seemingly linked to the frightening Regin stealth malware

| Nov 24, 2014 2:19 PM CST

The sophisticated Regin stealth malware, which has been in operation since at least 2008, was likely created by the US and UK governments to spy on other governments and businesses. Specifically, the NSA and GCHQ most likely spearheaded the project, with the malware's first target against the European Union (EU).

"Having analyzed this malware and look at the [previously published] Snowden documents," said Ronald Prins, security expert. "I'm convinced Regin is used by British and American intelligence services."

Russia was the most heavily infected nation, racking up 28 percent of Regin's wrath, while 24 percent was in Saudi Arabia, Ireland (9 percent), Belgium (5 percent), and Austria (5 percent) rounded out the list of most infected nations.

Continue reading: NSA, GCHQ seemingly linked to the frightening Regin stealth malware (full post)

Watch out for fraud as consumers head online to order Christmas gifts

| Nov 23, 2014 4:22 PM CST

Numerous data breaches throughout 2014 forced American consumers to be more vigilant and proactive of their own personal accounts. As shoppers head online and into local stores to purchase Christmas gifts, more security experts are providing a friendly reminder to look after their own financial safety.

A recent survey found 55 percent of shoppers will head to a local store or mall to purchase items, while 36 percent will be searching for and purchasing gifts online. Specifically, 55 percent of consumers will use their credit cards, and 24 percent will use debit cards, checks, mobile payments, and other forms of payments to make purchases.

"Unfortunately, the threat of fraud is a reality, but it doesn't mean you're helpless," said Phil Hatfield, Capital One Vice President of Fraud. "Ensuring that you're monitoring your accounts and getting alerts to make you aware of unauthorized activity are simple steps and things you should do year-round and especially during the hectic holiday shopping season."

Continue reading: Watch out for fraud as consumers head online to order Christmas gifts (full post)

Sony denies its PlayStation Network was hacked, but will watch closely

| Nov 23, 2014 11:22 AM CST

Sony doesn't believe its PlayStation Network was hacked, despite a recent report from a hacker group that they "released a log of customer logins" of usernames and passwords for PSN, Windows Live and Origin. It's possible the user logins were repurposed from previous security breaches, so it would appear gamer PSN accounts are still secure.

"We have investigated the claims that our network was breached and have found no evidence that there was any intrusion into our network," Sony said in a statement. "Unfortunately, Internet fraud including phishing and password matching are realities that consumers and online networks face on a regular basis. We take these reports very seriously and will continue to monitor our network closely."

Even though data breaches are something consumers are increasingly more aware of, there also has been an increase in the amount of fake reported attacks.

Continue reading: Sony denies its PlayStation Network was hacked, but will watch closely (full post)

Made in China e-cigarette apparently can also be infected by malware

| Nov 23, 2014 7:16 AM CST

The rise in popularity of e-cigarettes in the United States and Western Europe has led to the potential of malware infection from e-cigarettes made in China, according to recent reports. Cybercriminals have become more creative in their attempts to compromise devices, and ensuring devices from Chinese production facilities are pre-loaded with malware has become increasingly popular.

"The Made in China e-cigarette had malware hardcoded into the charger, and when plugged into a computer's USP port the malware phoned home and infected the system," according to a report posted on Reddit.

Trend Micro security consultant Rik Ferguson seems to agree with the assessment: "Production line malware has been around a for a few years, infecting photo frames, MP3 players and more. For consumers it's a case of running up-to-date anti-malware for the production line stuff and only using trusted devices to counter the threat."

Continue reading: Made in China e-cigarette apparently can also be infected by malware (full post)

Employees using work-issued tech for social media, online shopping

| Nov 22, 2014 5:15 PM CST

Companies are struggling to try to teach their employees appropriate use of work-owned PCs and laptops, as they struggle to keep their networks secure. During typical business hours, 36 percent of survey respondents say they browse social media, while 34 percent enjoy online shopping. Meanwhile, 42 percent play online games and 36 percent use their work laptops to search for a job - all while at home.

"People seem to understand that at work there's a little bit more protection," said Sergio Galindo, GFI Software general manager, while speaking to SCMagazine. "They don't do riskier stuff at the office. They're doing riskier stuff (at home) and then bring this equipment that was exposed at home back to the office."

Companies are more focused on trying to keep employees safe from social engineering-based phishing attacks, which lead systems and networks to be compromised by malware and other threats.

Continue reading: Employees using work-issued tech for social media, online shopping (full post)

Amnesty anti-spyware app informs users if government is snooping

| Nov 21, 2014 5:17 PM CST

Amnesty International's Detekt is a free, open source tool that will help allow journalists and human rights activists if they are being targeted by surveillance spyware. This is the first time Amnesty International and several non-profit coalitions have released something publicly.

"Governments are increasingly using dangerous and sophisticated technology that allows them to read activists and journalists' private emails and remotely turn on their computer's camera or microphone to secretly record their activities," said Marek Marczynski, Amnesty International Head of Military, Security and Police, in a press statement. "They use the technology in a cowardly attempt to prevent abuses from being exposed."

The global market for surveillance technologies is estimated to be worth $5 billion per year, and is climbing even higher.

Continue reading: Amnesty anti-spyware app informs users if government is snooping (full post)

Join Our Newsletter

Join the TweakTown Newsletter for daily tech updates delivered to your inbox.

See previous giveaways.

Newsletter Subscription