Newsletter IconFacebook IconX IconThreads IconInstagram IconYouTube IconPinterest Icon
Giveaway: AVerMedia Creator Bundle (4K Webcam, Capture Card, Charging Hub, and Mouse Pad)

Hacking, Security & Privacy - Page 39

Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 39

Stay Updated

Follow TweakTown for breaking tech news, reviews, and daily updates.

Add TweakTown as a preferred source on GoogleFind TweakTown on Apple News

As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.

Survey: One-third of IT failures caused by employee browsing habits

| Nov 21, 2014 11:25 AM CST

At least 38.6 percent of companies suffered a major IT disruption due to employees visiting non-work related websites and other questionable material on work-owned electronics, leading to malware and other IT issues, according to a survey conducted by GFI Software.

Almost half of employees, 48 percent, report using Dropbox, OneDrive, Box, or some other personal cloud-based solution to store company information - something that isn't necessarily shocking, but a concern for companies trying to keep data secure. If their employment ended, 35.8 percent admitted they would try to save company data, including customer lists and confidential data, despite knowing it is illegal to do so.

"Data protection is a big problem, and one that has been exacerbated by the casual use of cloud file sharing services that can't be centrally managed by IT," said Sergio Galindo, GFI Software general manager. "Content controls are critical in ensuring data does not leak outside the organization and doesn't expose the business to legal and regulatory compliance penalties. Furthermore, it is important that policies and training lay down clear rules on use and reinforce the ownership of data."

Continue reading: Survey: One-third of IT failures caused by employee browsing habits (full post)

US government worried China could down US power grids with cyberattack

| Nov 21, 2014 8:23 AM CST

China is on the short list of countries that have the ability to launch a cyberattack that would be able to shut down the US power grid along with other critical infrastructure, US government officials believe. It would appear these countries already launch reconnaissance probes that have found gaping security holes they can exploit in cyber defenses.

"We see them attempting to steal information on how our systems are configured, the very schematics of most of our control systems, down to engineering level of detail so they can look at where are the vulnerabilities, how are they constructed, how could I get in and defeat them," said Admiral Michael Rogers, NSA head and US Cyber Command head. "We're seeing multiple nation-states invest in those kinds of capabilities."

Beyond China, Admiral Rogers didn't publicly disclose other nation states believed to be sponsoring cyberattacks, though Russia almost certainly is on the list.

Continue reading: US government worried China could down US power grids with cyberattack (full post)

FBI becoming more active in fight against malware, cybercrime efforts

| Nov 18, 2014 6:48 PM CST

The Interactive Advertising Bureau's Anti-Malware Working Group has teamed up with the FBI and US Department of Justice in their effort to fight malware and cybercrime. There has been an increase in organized cyberattacks targeting the IAB, and federal partnerships could help limit future widespread issues.

The FBI and other government agencies want to increase proactive behavior to clamp down on cybercrime, and this marks the first industrywide relationship they have created. The IAB Anti-Malware Group formed in September and has generated widespread interest, including from the US government, as cybercriminals make millions from compromising companies and users.

"We have become such a target of organized crime that we think this is the only way to truly be successful long-term," said Mike Zaneis, IAB executive vice president. "In the advertising space, what we're particually worried about is the type of malware that will basically make your computer a zombie, or a bot, and will begin to generate non-human traffic back to criminal websites or just selling traffic on networks or exchanges."

Continue reading: FBI becoming more active in fight against malware, cybercrime efforts (full post)

81% of enterprise security staff ready to 'guarantee' data security

| Nov 18, 2014 5:39 PM CST

There were a number of major data breaches reported in 2014, but it would appear companies have higher hopes for data security in 2015, according to a study published by ThreatTrack Security. In its "2015 Predictions from the Front Lines," 81 percent of enterprise security staffers said they would be willing to "personally guarantee that their company's customer data will be safe in 2015."

Hearing that eight out of 10 security staff would be willing to guarantee customer data sounds absolutely ridiculous - but might be a necessary leap of faith to win over customers, increasingly concerned their personal information could be leaked.

Millions of US consumers faced debit and credit card fraud from the Home Depot and Target breaches alone, with a number of other companies also breached in between.

Continue reading: 81% of enterprise security staff ready to 'guarantee' data security (full post)

Kaspersky wants to keep the world secure going into the future

| Nov 18, 2014 8:09 AM CST

Kaspersky is imagining the future of the world, with the increase in use of technology, the increase of threats are there too. Infrastructure attacks, financial system attacks, governments being hit, and much more. The video below does an incredible job of showing us how Kaspersky view the future.

One of the scarier things Kaspersky says in its video, is "will a single click trigger a global economic crisis", but follows it by a "world where technology works for us", or "controls us". The video continues, sayign "could it be a truly connected universe, where we'll be able to express the full power and imagination. Or one where those connections make our critical infrastructure vulnerable to attack".

The ad makes you really think about the many, many possibilities we as a human race have to face - as the world is constantly changing around us. Not only are we dealing with things at a personal level, but societal level, and then infrastructure level. Are the governments of the world prepared for these attacks, or simply taking our freedoms away with far-reaching government agencies like the NSA and GCHQ spying on all citizens at once. What do you think?

Continue reading: Kaspersky wants to keep the world secure going into the future (full post)

Senator Markey demands DoJ offer details regarding phone snooping

| Nov 18, 2014 5:19 AM CST

The Department of Justice (DOJ) program that reportedly uses cell-tower mimicking equipment during airplane flights that allows the federal government to snoop on mobile phones has drawn an angry response from many Americans.

Senator Ed Markey (D-Mass) wants Attorney General Eric Holder to provide details about the DOJ operation, such as mission length, additional surveillance programs, and which cities were impacted.

"Americans are rightfully disturbed by just how pervasive collection of mobile phone information is, even of innocent individuals. While this data can be an important tool for law enforcement to identify and capture criminals and terrorists, we must ensure the privacy rights of Americans are protected," Sen. Markey said in a public statement. "We need to know what information is being collected, what authority is being used to collect it, and if and how this information is retained and stored."

Continue reading: Senator Markey demands DoJ offer details regarding phone snooping (full post)

Bitcoin security moving forward, and BitStash hopes to lead the way

| Nov 17, 2014 4:15 PM CST

The rise and fall of the Mt. Gox bitcoin exchange took just a few years, but left a serious black mark on the budding cryptocurrency market. More consumers and retailers are willing to experiment using bitcoins as currency and potential investments, despite continued security concerns.

The actual bitcoin protocol hasn't been breached by cybercriminals, and thieves have found ways to compromise bitcoin storage solutions, exchanges, and bitcoin owners directly. With no government regulation and very little insurance of recouping lost funds, some have shied away from jumping into the bitcoin market.

"It's important to remember that Bitcoin as a protocol and the blockchain, the record of transactions, has no known security vulnerabilities," said Trevor Murphy, Chief Technology Officer of bitcoin storage solution company BitStash. "It's impossible to counterfeit bitcoin and an impossibility with current computing power to modify a transaction that has been confirmed, say five or six times on the blockchain. This is very important. In fact, bitcoin marks the first time in human history that a currency has these attributes. People have been counterfeiting money, bouncing checks and chipping little bits off gold coins since time began."

Continue reading: Bitcoin security moving forward, and BitStash hopes to lead the way (full post)

DarkHotel targets vulnerable Wi-Fi networks, victimizing company execs

| Nov 17, 2014 1:46 PM CST

A new advanced persistent threat (APT), known as DarkHotel, is now targeting C-level executives of major businesses. Instead of trying to compromise governments to steal state secrets, Dark Hotel is cleverly engineered to conduct corporate espionage, likely for a foreign state-sponsored group, utilizing poor wireless hotel security - a rather clever technique for when business leaders are staying in hotels.

Utilizing Flash zero-day exploits and using spear-phishing to compromise users, DarkHotel has been found to steal and re-use digital certificates that inject malicious code. The attacks have taken aim at business visitors in the United States, Japan, South Korea, India, mainland China, Russia, Germany, Hong Kong and Ireland.

"Just think about the playing field IT security professionals have to deal with, and why they need all the help they can get," said Joe Caruso, Global Digital Forensics (GDC) CEO and CTO. "There are mobile devices like smartphones and tablets being used more than ever before, all with seemingly endless choices of software and applications, and all providing a potential threat vector for cross-platform intrusions and attacks."

Continue reading: DarkHotel targets vulnerable Wi-Fi networks, victimizing company execs (full post)

World of Warcraft servers targeted by DDoS, causing serious headaches

| Nov 17, 2014 12:12 PM CST

The recent launch of World of Warcraft: Warlords of Draenor, the fifth expansion for the popular MMORPG game series, received a large amount of attention. The game launched in Europe and the number of players trying to enter Draenor caused problems, and Blizzard added multiple entrance points to the game - and while this initially helped - North American users were met by a distributed denial of service (DDoS) attack.

"While that solution helped a ton for our North American launch, we ran into a few other issues, including a distributed denial of service attack, that resulted in increased latency," the company confirmed.

Blizzard was able to recover from the DDoS attack, which no group has claimed responsibility for, though there are still problems related to server load. The game company will continue to work on server time outs and other improvements to help ease server load - and make sure gamers are able to log in and play with minimal interruptions.

Continue reading: World of Warcraft servers targeted by DDoS, causing serious headaches (full post)

US State Department computers hacked, email system shut down

| Nov 16, 2014 10:02 PM CST

The US State Department is now the fourth US federal government agency to be attacked by organized hackers, with hackers targeting unclassified computer systems. The "activity of concern" did not impact any classified systems, and shows foreign state-sponsored cybercriminals are having success attacking the US federal government.

"This has impacted some of our unclassified email traffic and our access to public websites from our main unclassified system," according to a senior State Department official. The State Department tried to avoid saying it was compromised, and said routine "maintenance" would be carried out, but the Associated Press was able to verify it was a cyberattack.

In previous weeks, the National Weather Service, US Postal Service and White House have all been targeted - and likely originated from Russian-sponsored cyberattackers.

Continue reading: US State Department computers hacked, email system shut down (full post)

Department of Banking and Securities concerned over bitcoin security

| Nov 16, 2014 9:15 PM CST

The adoption of virtual currencies, mainly bitcoin, has continued to expand in 2014 - with a growing number of businesses accepting bitcoin payments - but legitimate securities offerings showing greater interest in virtual currencies face cybersecurity problems.

In addition to currency volatility, which has scared some investors away, associated anonymity and growing risk of cyber theft from hackers is increasing.

"We are living in an age where traditional financial and investing relationships are being transformed rapidly and sometimes in confusing fashion by technology and innovation," said Glenn Moyer, Secretary of Banking and Securities. "It is especially important that investors fully understand where they are putting their money, and with whom they are investing it."

Continue reading: Department of Banking and Securities concerned over bitcoin security (full post)

Chinese authorities arrest three suspects for creating WireLurker

| Nov 16, 2014 12:06 PM CST

Police authorities in Beijing have detained three suspects accused of creating the "WireLurker" malware targeting Apple iOS and OS X computers and mobile devices in China. The Chinese security firm Qihoo 360 Technology provided a tip that led to the arrest of three suspects, Chen, Wang and Li, and all three have been charged with the creation and distribution of WireLurker. It appears WireLurker was created to generate monetary profits for the organizers, which wouldn't be a surprising confirmation that cybercriminals are racking up large amounts of profits from cybercrimes.

Apple moved quickly to block the WireLurker malware from spreading any further, and recommended users only download apps from trusted sources.

It's ironic that China, believed to be one of the largest state sponsors of organized cyberattacks against the Western world, moved so quickly to arrest the creators of WireLurker - the malware victimized Chinese users only, and didn't have a widespread presence outside of the country.

Continue reading: Chinese authorities arrest three suspects for creating WireLurker (full post)

Survey: Nine out of 10 IT professionals have lost company data

| Nov 15, 2014 7:00 PM CST

Security threats continue to give IT professionals headaches, but hardware failure, lost data, and other potential problems are often overlooked. Even though almost nine out of 10 IT professionals have lost data, half of respondents don't back up data because they forgot to do it, according to a new survey published by the CloudBerry Lab backup and management solutions company.

Furthermore 88 percent of IT professionals suffered lost data due to hardware failure, data corruption, malware or accidental deletion. In a rather surprising finding, 38 percent have never bothered to test recoverability of backed up data, while 47 percent end up waiting up to one month before backing up data.

Depending on the type of business, IT professionals recommend at least weekly data backups - though some industries should have critical information backed up on a daily basis. CloudBerry Lab found 32 percent of IT professionals understood they weren't protected or were unsure if their backups were secured with encryption, password protection, or some other type of security protocol.

Continue reading: Survey: Nine out of 10 IT professionals have lost company data (full post)

FBI confirms arresting cybercriminals difficult, but fight isn't over

| Nov 14, 2014 3:11 PM CST

The FBI is aware of state-sponsored cyberattacks, with a large volume of attacks blamed on the Chinese and Russian governments, but finding ways to arrest and prosecute hackers overseas is difficult. Companies are struggling to keep their networks secure, as more employees and customers are at risk of data breaches with these groups evolving into better organized, well-funded cybercriminals.

"Since cybercrime is not found in only one country and is globally dispersed, law enforcement agencies must work together on identifying and arresting the actors perpetrating the crimes," a Special Agent from the FBI recently said during a webinar. "The biggest challenge is when these actors live in countries where the cybercrime laws are not distinct, or in some cases non-existent. There have been cases where these actors have traveled through cooperative regions of the world and arrests have been made."

Realistically, many of the state-sponsored cybercriminals will remain out of the reach of the FBI - and other Western European governments - but China, Russia, and select other countries are the largest perpetrators of attacks.

Continue reading: FBI confirms arresting cybercriminals difficult, but fight isn't over (full post)

Apple urges consumers to download apps only from authorized sources

| Nov 14, 2014 8:30 AM CST

Apple hasn't heard reports of any users that have been compromised by the "Masque Attack," but cybersecurity experts are still asking Apple engineers to develop new protections to ensure enterprise users are more secure.

"We designed OS X and iOS with built-in security safeguards to help protect customers and warn them before installing potentially malicious software," an Apple spokesman recently said. "We're not aware of any customers that have actually been affected by this attack."

Cybercriminals want to hijack OS X and iOS users - and have largely struggled to find security loopholes - but are increasing their efforts into malware development.

Continue reading: Apple urges consumers to download apps only from authorized sources (full post)

Report says DoJ uses airplane flights to help better snoop on citizens

| Nov 14, 2014 5:30 AM CST

Airplane flights have given the US Department of Justice (DoJ) the perfect opportunity to snoop on American citizens with a custom surveillance program operated by the US Marshals Service. The covert program originally started in 2007 and uses "dirtboxes," portable cell towers, that can secretly collect identity and phone locations on subscribers.

The flights leave from five different airports across the United States, and can snoop on thousands of citizens during any given flight. Specific details regarding the program remain unclear, but the US Marshals conduct these missions "on a regular basis" - and not surprisingly, the DoJ is refusing to comment. The phones are in continuous communication with local cell towers, providing a great opportunity to snoop while being discreet.

Following former NSA contractor Edward Snowden's mass surveillance disclosures, American citizens have become more concerned of government spying.

Continue reading: Report says DoJ uses airplane flights to help better snoop on citizens (full post)

US needs to treat cyber warfare as a real threat to security

| Nov 13, 2014 7:07 PM CST

Cybersecurity experts continue to have concerns over state-sponsored hacking activity, with China and Russia typically blamed for organized cyberattacks. There were a number of significant data breaches throughout 2014, and it would appear many of them were conducted by state-sponsored hacking programs orchestrated by organized, knowledgeable computer specialists.

Following troubling news that Chinese-sponsored hackers breached the National Oceanic and Atmospheric Administration (NOAA), there has been more attention on hackers that are well-paid and well-organized.

"Whether or not China perpetrated this particular hack or not, the fact remains that nation states are sometimes our enemy," said Robert Twitchell, Jr., President and CEO of Dispersive Technologies, in a statement. "Many of them, including China and Russia, will engage in hacking to steal corporate secrets (for economic advantage), military secrets (for national defensive AND offensive purposes), to embarrass the US and show their technical superiority, and to divert our attention from other activities."

Continue reading: US needs to treat cyber warfare as a real threat to security (full post)

Pew research finds many users don't trust Internet privacy anymore

| Nov 12, 2014 1:21 PM CST

Online privacy is something that most Americans believe they have lost control of, as governments and companies collect and use even more personal information, according to a survey from the Pew Research Internet Project.

"It's a bundle of concerns," said Lee Rainie, a Pew researcher involved in the project. "It's party surveillance, it's partly tracking, and this generalized sense that I'm losing control of my identity and my data."

The survey also found that 91 percent of adults "agree" or "strongly agree" that consumers no longer have control over how their personal information is collected and used by companies - and with the government collecting even more data about citizen phone calls and Internet communications, 80 percent of adults "agree" or "strongly agree" that Americans should be concerned about the government monitoring.

Continue reading: Pew research finds many users don't trust Internet privacy anymore (full post)

Cybercriminals taking interest in targeting Apple iOS, Mac OS X

| Nov 9, 2014 2:14 PM CST

The recent report from Palo Alto Networks that disclosed the WireLurker malware targeting Apple iOS and Mac OS X was a sudden wakeup call to users. Even though it was isolated to China, and Apple has blocked the malware, cyberattackers are finding new ways to compromise iPhones and Mac OS systems. The company has done a great job to keep its software ecosystem secure, especially if devices aren't jailbroken, but cybercriminals are becoming more sophisticated in their research strategies.

Here is what Ryan Olson, Palo Alto Networks intelligence director, recently told eWeek: "We will continue to see new malware for both Mac OS X and iOS, and they will incrementally get better and better. I would be most worried about high-value targets," with a focus on government officials and political rivals.

Cyberattacks targeting Google Android and Microsoft Windows will remain more prevalent, but Apple users - many of them used to being relatively secure - could also be caught off guard when major security issues are released in the wild.

Continue reading: Cybercriminals taking interest in targeting Apple iOS, Mac OS X (full post)

Apple blocks WireLurker malware that has victimized users in China

| Nov 8, 2014 5:49 PM CST

Just a couple days after Palo Alto Networks spilled the beans on the WireLurker malware targeting Apple iOS and Mac OS devices, Apple has blocked infected apps so they will be unable to run on devices. The company didn't provide specifics into how the malware is being blocked, but did recommend users run anti-malware security software - and only download apps from the official Apple App Store.

The company confirmed it is "aware of malicious software available from a download site aimed at users in China, and we've blocked the identified apps to prevent them from launching."

WireLurker is the first known malware that spread to a large number of users that didn't jailbreak their devices - and shows cybercriminals are just as anxious to compromise Apple products as Google Android and Microsoft Windows.

Continue reading: Apple blocks WireLurker malware that has victimized users in China (full post)

Join Our Newsletter

Join the TweakTown Newsletter for daily tech updates delivered to your inbox.

See previous giveaways.

Newsletter Subscription