Hacking, Security & Privacy - Page 4
Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 4
Stay Updated
Follow TweakTown for breaking tech news, reviews, and daily updates.
As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.
Anonymous hacker charged with seeking to kill after cyberattacks hit hospitals globally
The US Department of Justice has charged two brothers who were allegedly behind a series of cyberattacks launched at hospitals across various countries.
Reports indicate the Sudanese brothers are behind the hacktivist group Anonymous Sudan, which the US Department of Justice believes is behind a series of cyberattacks launched at various hospitals around the world. The Department of Justice recently unsealed the charges against the brothers, accusing them of launching more than 35,000 distributed denial-of-service (DDoS) attacks against hundreds of organizations. The targets of these attacks were websites, network systems, services, media companies, airports, and government agencies such as the Pentagon, FBI, and Department of Justice.
The indictment revealed the brothers had their own ideological reasons behind the attacks but were also making their services available for hire. This would include launching cyberattacks against entities on behalf of clients, and according to US prosecutors and the FBI, their victims include Microsoft's Azure cloud services, OpenAI's ChatGPT, video game companies, and even hospitals. The last point is a particular point of interest for the prosecution as the brothers are accused of launching attacks on Cedars-Sinai Health Systems in Los Angeles, which resulted in multiple hours of downtime and patients having to be moved to different hospitals.
Cybersecurity firm sounds alarm on data breaches after global account leaks almost double
A global quarterly analysis conducted by cybersecurity company Surfshark has revealed global data breaches have almost doubled in Q3 2024 compared to Q2 2024.
In an email to us, Surfshark explained that globally leaked accounts have almost doubled in Q3 2024 compared to Q2 2024, as the company's analysis indicated leaked accounts spiked from 215 million to 423 million. These statistics were acquired by Surfshark's global data breach monitoring tool, which also reveals the ten most breached companies in descending order. Those stats can be found below.
Moreover, Emilija Kucinskaite, Senior Researcher at Surfshark, provided a statement to us, saying that leaked account data still remains a "significant issue" and that zooming out on the data and looking at it over 20 years reveals an even more troubling statistic - there have been 68 billion data points exposed since 2004. Of those data points, 18 billion are email addresses, and on average, each leaked email address also comes with three additional leaked data points, such as passwords or phone numbers.
Internet Archive hit by 'catastrophic' hack private user data of millions now exposed
The Internet Archive was hit with a Distributed Denial-of-Service (DDoS) Attack on Wednesday afternoon, resulting in the service being knocked offline on Thursday.
Brewster Kahle, the founder and digital librarian of the Internet Archive, confirmed the platform experienced a major outage due to DDoS attacks, which resulted in the "defacement of our website" and a major breach that exposed 31 million user accounts. The breach exposed the usernames, emails, and bcrypt password hashes of 31,081,179 archive users, with Kahle confirming the news in a new X post that stated the Internet Archive suffered from "defacement of our website via JS library; breach of usernames/email/salted-encrypted passwords."
As for the defacement Kahle referenced, the hacker/s injected this message into the platform, "Have you ever felt like the Internet Archive runs on sticks and is constantly on the verge of suffering a catastrophic security breach? It just happened. See 31 million of you on HIBP!" HIBP is a reference to the website "Have I Been Pwned," which informs users if their account details have been leaked online due to a data breach. Moreover, HIBP did confirm the Internet Archive data breach, writing that 31 million records from Internet Archive users were stolen.
Casio confirms its suffering from a cyberattack forcing internal shutdowns
It was only a year ago that Casio was forced to repel cyberattackers that were probing its digital infrastructure, but now according to the company it has detected a breach.
The company took to its Japanese website to officially announce that it had detected a security breach after conducting an internal investigation. The breach was detected on October 5, 2024, and the investigation found that the unauthorized access had caused a system failure, "resulting in the inability to provide some services." Casio has already reported the breach to authorities and brought in a third-party security firm to investigate the breach and determine if customer data was stolen.
Judging by the hiring of a third-party security firm to look for any stolen files, it appears the breach may have been a ransomware attack. However, Casio hasn't confirmed that any data was stolen. Additionally, no ransomware groups have claimed responsibility for the hack.
Google Pixel smartphone busted sending private user data back to Google every 15 minutes
UPDATE - "User security and privacy are top priorities for Pixel. You can manage data sharing, app permissions and more during device setup and in your settings. This report lacks crucial context, misinterprets technical details and doesn't fully explain that data transmissions are needed for legitimate services on all mobile devices regardless of the manufacturer, model or OS, such as software updates, on-demand features and personalized experiences," emailed a Google spokesperson
A new report from Cybernews has focussed on the web traffic between Google and its latest flagship smartphone, the Google Pixel 9 Pro XL.
The report states that cybersecurity researchers at Cybernews analyzed the Pixel 9 Pro XL's web traffic and determined that even before any app is installed, the smartphone sends private user data back to Google servers. More specifically, the analysis found "Every 15 minutes, Google Pixel 9 Pro XL sends a data packet to Google" and within this packet of data is private information such as a users email address, phone number, location, network status, and other telemetry data.
Warnings issued after world-first Google Play Store app drains $70,000 from victims
Keeping an ear to the ground in the world of scams can really benefit people whose lives are plugged into the digital world, particularly if they are involved in storing/trading digital assets such as cryptocurrency.
The cryptocurrency community is no stranger to scams of various kinds, but now researchers are sounding the alarm on a new type of scam that's been described as a world first. According to a report from investigators at Check Point Researchers (CPR), an app called WalletConnect appeared on the Google Play Store. WalletConnect assumed the identity of the legitimate app with the same name, but did come with some adjustments.
The fraudulent WalletConnect app was marketed to consumers as able to solve many of the problems voiced about the legitimate WalletConnect app. Additionally, the legitimate app wasn't on the Google Play Store, which meant when users when to search for WalletConnect they were presented with the malicious app. More than 10,000 people downloaded the app, and according to CPR approximately 150 wallet addresses were drained of their contents.
FBI scares Chinese government-linked botnet operators into burning down their own network
The Federal Beureua of Investigations (FBI) has said that it's pursuit of a China-based botnet resulted in Chinese operators of the botnet "burning down" their network once they figured out the FBI was on to them.
The botnet consisted of 260,000 various internet-connected devices that were used to gather intelligence on critical US infrastructure, government operations, academics, and more. Notably, the botnet was operated by the "Integrity Technology Group," who FBI director Christopher Wray said is linked to the People's Republic of China.
More than half of the total devices within the botnet were located in the United States, and following its discovery, the National Security Agency (NSA) and the FBI were called in to intervene. Wray said it was "all hands on deck" and after gaining court authorization, US officials took control of the botnet servers, which prompted a response by the People's Republic of China-linked group.
Planned Parenthood hack may expose millions of people's sensitive health data
A branch of Planned Parenthood has confirmed a ransomware group has gained access to it systems and stolen millions of people's sensitive data.
The CEO and president of Planned Parenthood of Montana, Martha Fuller, said in a recent statement to Recorded Future News the attack was internally discovered on August 28. Following the discovery the IT team at Planned Parenthood Montana responded by taking portions of their network offline, presumably as part of the investigation into the attack and to prevent any further known/unknown exploits in its system.
Fuller added that the organization is aware of the ransomware group known as RansomHub, which, upon a quick Google search, you will discover, is quite prolific in the space despite it only first appearing earlier this year. Reports indicate the hackers made off with 93GB of data, but when a spokesperson from Planned Parenthood was asked what the contents of that data were, they declined to comment.
Hackers might have stolen social security data of ALL Americans, around 2.9 BILLION records
A member of a hacking group is selling the personal Social Security numbers and other sensitive data to ALL Americans, with 2.9 billion records available online... for free.
In a report from BleepingComputer, a hacking forum became active after a user posted on the forum saying they had a massive collection of documents from the data brokerage National Public Data (NPD). NPD, which doesn't disclose how it collects data on its website, reportedly gathers information from publicly available records to create individual profiles that are usually used by private investigators for things like background and criminal record checks.
It's not just US residents that have to worry, but the hack of 2.9 billion files includes private information on citizens living in the United Kingdom and Canada, including personal information from all three of those countries. 2.9 billion files is a LOT of data, we don't need to underline that, but we will.
200,000 students, staff and parents personal data exposed in recent hack
An Arizona tech school has informed Maine's attorney general in a recently filed report that nearly 209,000 individuals' data was potentially compromised in a hacking incident earlier in the year.
The tech school is East Valley Institute of Technology (EVIT), and according to the filing, the data of the 209,000 individuals is of current and former students, parents, guardians, and faculty. As for what data was leaked, reports indicate the compromised data included personal, health, and financial information.
The Register reports that nearly 50 types of personal information were stolen, such as student ID numbers, date of birth, race/ethnicity, grades, home phone numbers, email addresses, driver's license, health insurance information, medical information, allergy information, medical record number, passport numbers, prescription information and more.
Historic Donald Trump and Elon Musk interview on X hit by 'massive' DDOS attack
Elon Musk teased an upcoming interview with former US President Donald Trump in X Spaces, and according to Musk the social media platform has been hit with a DDOS attack ahead of the interview going live.
Ahead of the historic interview, Musk said he was performing system scaling tests to ensure that X servers could host all of the expected listeners. The interview is currently live at the time of writing, but it didn't go live until 40 minutes after the scheduled time of 8 pm ET, as the site was showing "not available" even though Musk said X tested its servers for 8 million concurrent listeners earlier in the day.
It was presumed that X went down from the massive traffic spike for the interview, but Musk, less than 10 minutes later, posted that X was experiencing a DDOS (distributed denial-of-service) attack. Musk said the interview would continue but with a "smaller number of concurrent listeners." It appears X was a victim of a targeted DDOS attack to prevent Musk and Trump from having their conversation. At the moment, there are 1.2 million people listening in on the conversation.
4.3 million Americans are at risk of fraud after savings account data breach
The Office of the Maine Attorney General has been informed of a data breach that has exposed sensitive data of 4.3 million customers.
According to HealthEquity, the data breach exposed the below sensitive data that of millions of Americans, with the fintech firm saying that not all of the categories listed contained data for every person. Reports indicate the breach occurred on March 9, 2024, and that it was detected on March 25. After the breach was discovered HealthEquity conducted an internal investigation on the origin of the hack, tracing it back to an online data storage location that became compromised.
The compromised location led to the unauthorized party gaining access to a "limited amount of data stored in a storage location outside our core systems." HealthEquity doesn't believe the stolen customer information has been used nefariously, and as compensation to affected customers, HealthEquity is offering a two-year complimentary credit identity, monitoring, insurance, and restoration services.
Qualcomm's Adreno GPU vulnerability found: Snapdragon chips join problematic Intel, AMD CPUs
It started with Intel... then AMD... and now Qualcomm has been hit with multiple vulnerabilities inside of its Adreno GPU.
Google researchers have found vulnerabilities inside Qualcomm's Adreno GPU, which is the integrated GPU inside of its Snapdragon processors. The GPU has kernel privileges, which means the security flaws found could be significant, as it would allow hackers full control over your Qualcomm-powered device.
The researchers focused on GPU drivers because untrusted apps can access them without additional permissions, making them an easy target for hackers. The drivers complexity with the operating system makes things worse for users, but great (and easier) for hackers.
Russia-affiliated criminals use Sitting Duck technique to bag 30,000 domains
Since 2019, Russian-affiliated hackers have hijacked an estimated 30,000 domains since 2019, with the cybercriminals exploiting a flaw in DNS.
The vulnerability was detailed by security researcher Matt Bryant in 2016, who looked at how the vulnerability led to the hijacking of 120,000 domains. The same problem reared its head again in 2019 with GoDaddy, an internet domain registry, domain registrar, and web hosting company. The 2019 issue led to sextortion attempts and bomb threats.
The technique being used is called Sitting Ducks. It essentially exploits gaps in administrative privileges, enabling cybercriminals to alter domain records without any validation from the owner. Unfortunately, the hijacked domain isn't just damaging for the owner of the domain but also for any visitor to that domain, as hijacked domains are commonly used for phishing, scams, spam, and other illegal activity.
Microsoft confirms an attack brought down Microsoft 365 and Azure services
Microsoft confirmed via an update on its Azure Status website that a 9-hour outage was a result of a DDoS attack that affected its Microsoft 365 and Azure services.
The distributed denial-of-service (DDoS) attack affected the services globally, and within the blog post, Microsoft didn't specify where or who the attack came from. More specifically, the post states that while the initial DDoS attack did trigger the event, it was responded to by Microsoft's protection mechanisms, but following investigations, Redmond discovered "the implementation of our defenses amplified the impact of the attack rather than mitigating it."
Furthermore, Microsoft said that customer impact began at 11:45 UTC, and by 14:10 UTC, the fix was already rolled out, and the majority of the impact was successfully mitigated. The only details we have on how the outage occurred was Microsoft's description of the outage being caused by an "unexpected usage spike" that "resulted in Azure Front Door (AFD) and Azure Content Delivery Network (CDN) components performing below acceptable thresholds, leading to intermittent errors, timeout, and latency spikes."
Hackers steal and leak documents from Pentagon, Homeland Security, NASA, other US gov agencies
Hackers have leaked internal documents stolen from one of the largest IT services providers to the US government, Leidos Holdings.
Leidos Holdings recently learned of the hack, believing that the documents stolen were in a previously disclosed breach of a Diligent Corp. system it used, according to Bloomberg's sources, who asked not to be identified because the information isn't public. Leidos is reportedly investigating the issue now, the person added.
Now, the customers of Leidos are important: it includes the US Defense Department (DOD), the Department of Homeland Security (DHS), NASA, and other US and foreign agencies and commercial businesses. Leidos used the Diligent system to host information gathered from internal investigations, according to a June 2023 filing in Massachusetts.
Enterprise software provider exposed nearly a billion records in data breach
A non-password-protected database containing 769 million records was discovered to be exposed to the public, revealing critical information such as secret keys, bank account numbers, tax identification numbers, and email addresses.
Cybersecurity researcher Jeremiah Fowler discovered and reported on the database through a post on Website Planet, where he explained the database was owned by ClickBalance, one of Mexico's largest enterprise resource planning (ERP) technology providers. The database contained access tokens, API keys, secret keys, bank account numbers, tax identification numbers, and 381,224 email addresses. After informing ClickBalance about the database exposure, it promptly implemented restrictions.
Notably, ClickBalance is a software company that offers ERPs as a suite of cloud-based applications to enterprise organizations that enable those organizations to access those applications whenever they like across any device. These ERPs are typically used to manage different processes of an enterprise, such as finance, human resources, supply chains, manufacturing, sales, and other business operations.
Airline avoids CrowdStrike chaos because its systems run on Windows 3.1 and Windows 95
One industry that experienced the brunt of the recent CrowdStrike global IT outage, which put millions of Windows systems into a Blue Screen of Death loop, was air travel. In the U.S., nearly every flight was grounded once systems began to fail; however, one major airline was unaffected.
According to reports, Southwest Airlines systems were untouched by the CrowdStrike error because its various systems run on outdated versions of Windows.
Outdated is putting it mildly. Most of Southwest Airlines' systems run on Windows 3.1 - a version of Microsoft's operating system from 1992. Not only that, but the airline's most advanced system, its staff scheduling system, runs on Windows 95 - so it, too, was unaffected.
What caused the CrowdStrike Windows BSOD issue, and why it led to total system crashes
The world is still recovering from one of history's most disruptive IT outages. Millions of critical Windows-based systems across the globe are experiencing the dreaded Blue Screen of Death (BSOD). The system crashes affect banks, airlines, emergency services, supermarkets, and businesses, putting computers into an endless boot loop with no immediate recovery means.
The issue was quickly traced to CrowdStrike, which creates security software. An update to its popular security platform, Falcon, broke, leading to one of history's most extensive IT failures. The 'Falcon Sensor' component critically failed, resulting in no access to Windows. Critical systems used for point of sale, emergency services like 911, and airlines managing flights were rendered useless.
With the affected systems being Windows PCs, many have pointed fingers at Microsoft. However, the issue looks specific to CrowdStrike software and its update to 'Falcon Sensor.' So then, how did this crash Windows when other apps that fail Crash to Desktop (CTD)? And how can you fix the CrowdStrike BSOD issue? Let's dig in.
Breaking - Global IT outage grounds planes, closes banks, and disrupts services everywhere
A global outage is currently causing havoc, grounding planes, grinding public transportation systems to a halt, disrupting banking services, and affecting everything from streaming services to supermarkets. The cause is the dreaded Windows 'Blue Screen of Death' or BSOD, bringing down systems that countless people, businesses, and critical services rely on.
Based on reports, the culprit appears to be a CrowdStrike update for its CrowdStrike Falcon threat checker, which is currently causing systems to crash and fail.
This is one of the most significant outages we've seen in a while, it's gotten to the point where airlines like American Airlines, United, and Delta have stopped flights taking off. Emergency services are also apparently down in some areas.





















