Hacking, Security & Privacy - Page 40
Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 40
Stay Updated
Follow TweakTown for breaking tech news, reviews, and daily updates.
As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.
EU practices cyberattack response ability during recent 24-hour event
Companies operating in the European Union (EU) recently held another round of cyberattack simulations, designed to help test cyberattack response ability. The European Network and Information Security Agency (ENISA) used white hat hackers to mock attack 200 companies located in 25 EU nations for a 24-hour period.
The Cyber Europe 2014 drill focused on financial institutions, security companies, government ministries, energy providers and Internet service providers (ISPs), with distributed denial of service (DDoS) attacks, data exfiltration, and Web defacement attacks.
"The outcome of today's exercise will tell us where we stand and identify the next steps to take in order to keep improving," said Udo Helmbrecht, ENISA executive director.
Continue reading: EU practices cyberattack response ability during recent 24-hour event (full post)
Pirate Bay co-founder Gottfrid Svartholm guilty of hacking charges
Pirate Bay co-founder Gottfrid Svartholm Warg was found guilty in the Danish Court of Fredriksberg, after facing charges of hacking and serious vandalism. Warg and a 21-year-old co-defendant broke into servers hosted by CSC in April 2012, and kept control of the mainframes until August. He accessed hundreds of thousands of records of Danish residents, including Social Security numbers, extradition agreements and criminal records, along with additional private data.
Since this is Warg's second high-profile, significant hacking conviction - he was already serving a one-year sentence for hacking a different IT consulting firm - Danish prosecutors hope for a minimum five-year prison sentence.
Luise Høj, Gottfrid's attorney, had this to say before the ruling: "My recommendation has always been that the investigation has focused on finding clues that point to my client, even though the tracks have also pointed in another direction. I have recommended that the court dismiss the case based on the remote access argument. It is clear that my client's computer has been the subject of remote control, and therefore he is not responsible."
Continue reading: Pirate Bay co-founder Gottfrid Svartholm guilty of hacking charges (full post)
CurrentC, rival to Apple Pay mobile payment system, suffers breach
The CurrentC mobile payment program, which has been selected by retailers as a viable rival to Apple Pay, confirmed the service has been breached. Best Buy, Rite Aid, CVS, Best Buy, and around 50 retailers back CurrentC under the Merchant Customer Exchange (MCX). Many compromised email addresses were dummy accounts and the CurrentC app wasn't breached, according to an MCX spokeswoman.
"In an abundance of caution, we wanted to make you aware of this incident and urge you not to open links or attachments from unknown third parties," MCX said in an email to CurrentC testers. "We take the security of your information extremely seriously, apologize for any inconvenience and thank you for your support of CurrentC."
CurrentC could be in more than 110,000 locations across the United States in 2015, and this is a significant setback - traditional point of sale (POS) systems have proven to be susceptible to cyberattacks - and any type of mobile payment system must ensure their systems aren't compromised.
Continue reading: CurrentC, rival to Apple Pay mobile payment system, suffers breach (full post)
'State sponsored' Russian hacker group is attacking geographic rivals
A likely Russian state-sponsored hacker group is being blamed for launching cyberattacks against NATO, Georgia, the Caucasus, Eastern Europe and Western European defense contractors, according to a report from FireEye. The APT28 group launches phishing attacks with links to websites that look like authentic news, with compromised information the type of data the Russian government would be interested in acquiring.
"The Sofacy group is using multiple malware families, including some that are not mentioned in the FireEye paper," said Aleks Gostev, Kaspersky Lab chief security expert of Global Research and Analysis. "They have been very active lately and have registered many domains in order to launch phishing attacks."
The FireEye report also notes APT28 sought "sensitive tactical and strategic intelligence" from governments in the region. Russia has been blamed for a number of coordinated cyberattacks against targets across Europe and in the United States, including a recent attack on the White House - and breaching point of sale (POS) machines of Home Depot.
Continue reading: 'State sponsored' Russian hacker group is attacking geographic rivals (full post)
White House suffered cyberattacks, but problem has been addressed
The White House, also known as the Executive Office of the President (EOP), is familiar with enduring cyberattacks on a frequent basis. However, a recent attack was found to be organized and significantly powerful, with the White House's networks enduring a few days of consistent downtime.
"In the course of assessing recent threats we identified activity of concern on the unclassified EOP network," an anonymous source recently told the media. "Any such activity is something that we take very seriously. In this case we took immediate measures to evaluate and mitigate the activity."
In addition to state-sponsored hacker groups in China and Russia, other nations have shown interest in advanced cyber espionage tactics. The computers and systems were not damaged, but suffered extended downtime that has been largely resolved by federal cybersecurity experts, according to reports.
Continue reading: White House suffered cyberattacks, but problem has been addressed (full post)
Gallup poll: Americans fear hackers more than any other crime
Americans are "occasionally" or "frequently" worried about having their credit card data stolen by hackers and having their PC or smartphone hacked more than any other crimes, according to a recent Gallup poll. A whopping 69 percent of poll respondents are worried about store data breaches leading to personal information being stolen, while 62 percent are worried about PC or smartphone security - significantly ahead of the 45 percent of people worried about their home being burglarized while away.
Consumers with salaries $75,000 or above are most concerned about potential debit and credit theft, as they spend more and are more likely to have multiple credit cards.
The high-profile data breaches of Target, Home Depot, and other major retailers helped finally wake up more Americans about the potential of data breaches. However, consumers and business users are still vulnerable to phishing and malware attacks, which haven't received the same amount of media attention.
Continue reading: Gallup poll: Americans fear hackers more than any other crime (full post)
Hacker given 21 month prison sentence for involvement in cybercrimes
Robert Dubuc was sentenced to 21 months in prison after pleading guilty for breaking into banks and government agencies while trying to steal $15 million. He pleaded guilty to wire fraud conspiracy, identity theft and conspiracy to commit access device fraud earlier in the year, as one of his co-defendants, Oleg Pidtergerya, will be sentenced later this year.
The ringleaders of the cybercriminal group have been indicted but haven't been arrested, likely in the Ukraine or elsewhere in Eastern Europe. They targeted the US Department of Defense, PayPal, JPMorgan Chase and Citigroup, among other companies - with stolen money transferred to their bank accounts.
The US federal government wants to take a more proactive approach against cybercrime - as the attacks continue to amount - but actually locking up prolific hackers remains extremely difficult.
Continue reading: Hacker given 21 month prison sentence for involvement in cybercrimes (full post)
Shoppers recommended to use credit instead of debit at stores
Consumers are going to take to the Internet and retail stores in a big way this holiday shopping season, but with numerous significant data breaches, there is concern over shopper security. For shoppers preparing to head out and visit local retailers, if you're not paying cash, then the next best thing is using a credit card if worried about security. "You're just better off by and large paying with a credit card because you have more rights and you're not out the money," said Susan Grant, Consumer Federation of America Director of Consumer Protection.
Credit card companies can cancel charges - with very little impact to consumers - while compromised debit card information often leads to major headaches. Beyond having data stolen, criminals are able to drain accounts, while also cloning the card and making ATM withdrawals. It's not uncommon for bank customers to have a hold placed on their account while an investigation is conducted, and shoppers are out their own money.
Financial intuitions are given up to 10 days before they need to refund fraud related to debit cards, and that sometimes leads to missed rent, utility bills, and other significant headaches. Retailers are under siege, and it seems cybercriminals are preparing to launch additional point of sale (POS) malware attacks, cybersecurity experts warn.
Continue reading: Shoppers recommended to use credit instead of debit at stores (full post)
Estonian hacker that stole $9.4M receives 11-year prison sentence
Estonian hacker Sergei Nicolaevich Tsurikov was sentenced to 11 years in prison, for his role in a cyberattack that stole $9.4 million in 2008. Tsurikov previously pleaded guilty to his role in hacking the Royal Bank of Scotland Group, creating fake payroll debit cards, and withdrawing funds from more than 2,100 ATMs in more than 280 cities.
Tsurikov and his team were described as "one of the most sophisticated cybercrime rings in the world," according to Sally Quillian Yates, Northern District of Georgia attorney. He will also have to pay $8.4 million in restitution.
Handing down actual prison sentences against cybercriminals has been difficult, but the US federal government wants to track down - and prosecute - as many of them as they can.
Continue reading: Estonian hacker that stole $9.4M receives 11-year prison sentence (full post)
Staples hit by data breach, with customers in Northeast hit
Office retailer Staples was the latest high-profile company hit by a data breach, with customers in the Northeastern United States affected. The US Secret Service is now investigating the incident, which involved debit and credit card data of an unknown number of customers. It appears retail locations in Pennsylvania, New Jersey and New York were hit, but it's possible stores in other states were also targeted.
"We take the protection of customers information very seriously, and are working to resolve the situation," Staples said in a statement. "If Staples discovers an issue, it is important to note that customers are not responsible for any fraudulent activity on their credit cards that is reported on a timely basis."
Retailers are struggling to keep data secure, as similar attacks have victimized Target, Home Depot, Kmart, Sears, with millions of customers across the country affected by these breaches.
Continue reading: Staples hit by data breach, with customers in Northeast hit (full post)
Hackers targeting free software, shaking confidence among consumers
Cybercriminals targeting free and open source software continue to rattle developers and consumers, with high-profile attacks hitting security flaws that should have been resolved. Specifically, the Heartbleed and Shellshock exploits have led to an increased demand from private companies and the U.S. government to step up programming assistance, but that hasn't been well received among many open source developers. However, it has provided a much-needed wakeup call that open source software should be monitored more closely to prevent such high-profile breaches.
"It's going to be a wake-up call for a lot of people to understand why we aren't auditing this software better," said Greg Martin, Threat Stream Inc founder and chief technology officer. "Everybody's been scratching their heads and saying, 'How could we miss this?'"
Hackers are increasingly organized - and well-funded - and that has made it difficult to defend against attacks, especially open source software. In theory, open source software provides a much larger pool of developers to help fix flaws, but others say proprietary software is more secure since the code is closed off from the public.
Continue reading: Hackers targeting free software, shaking confidence among consumers (full post)
Apple not too worried about FBI's interest in stopping encryption
Even with FBI Director James Comey speaking out against Google and Apple providing encryption security on smartphone devices, Apple shipped its Yosemite OS with FileVault by default. The FBI - and other government agencies - are worried that encryption will prevent law enforcement from cracking down on criminals... or so they say.
"With Apple's new operating system, the information stored on many iPhones and other Apple devices will be encrypted by default," Comey recently said. "Shortly after Apple's announcement, Google announced plans to follow suit with its Android operating system. This means the companies themselves won't be able to unlock phones, laptops, and tablets to reveal photos, documents, email, and recordings stored within."
It's impressive to see Google, Apple and other tech companies trying to put customers first - as many users become more concerned about security - and not listening to the FBI's rather questionable concerns.
Continue reading: Apple not too worried about FBI's interest in stopping encryption (full post)
Anonabox, the $45 privacy router misleads people, Kickstarter steps in
Just days ago, August Germar showed off his Anonabox privacy router on Kickstarter, quickly flying past his pledge goal of $7500. Germar was promising a router that would give users near ultimate privacy, routing your Internet access through the Tor network. Germar raised $585,549 before Kickstarter suspended his Kickstarter, citing Germar "broke Kickstarter rules".
The Anonabox ball of thread began to unravel when some of its backers began to ask questions about Anonabox's custom hardware, as well as the promised security of its software. It snowballed to the point of many asking for the project to be cancelled, and asked others to report the misleading information to Kickstarter staff. Kickstarter emailed the project investors, telling backers that "a review of the project uncovered evidence that it broke Kickstarter's rules". These rules include the company to prohibit "offering purchased items and claiming to have made them yourself, presenting someone else's work as your own" and "misrepresenting or failing to disclose relevant facts about the project or its creator".
It all started on Tuesday night, with users seeing issues with the router's hardware, with its designer claiming was custom-designed. The backers found that all of the parts could be acquired from Chinese suppliers on sites such as Alibaba. Germar even confirmed with WIRED that the Anonabox prototype he had was built from "off-the-shelf case and a nearly stock board tweaked to add more flash memory storage, both sourced from the Chinese manufacturer Gainstrong", according to Wired.
Continue reading: Anonabox, the $45 privacy router misleads people, Kickstarter steps in (full post)
Europol: Just 100 cybercrime kingpins worldwide, as threats increase
Around 100 cybercriminal kingpins help wreak havoc on the world, according to Troels Oerting, the head of the Europol Cybercrime Center. Trying to crack down on cybercriminals can be a daunting task, especially trying to bring them to justice, as Web-based attack activity largely remains a borderless bureaucratic nightmare.
"We roughly know who they are," Oerting recently said. "If we can take them out of the equation then the rest will fall down. This is not a static number, it will increase unfortunately. We can still cope but the criminals have more resources and they do not have obstacles. They are driven by greed and profit and they produce malware at a speed that we have difficulties catching up with."
Not surprisingly, many of the leading cybercriminal bosses are in Russian-speaking countries - though cybersecurity experts also warned of growing threats from China. Trying to bring these criminals to justice is near impossible, with Russia and other Eastern European nations ignoring the western world when it comes to apprehending these criminals, Europol noted.
Continue reading: Europol: Just 100 cybercrime kingpins worldwide, as threats increase (full post)
Mobile malware threats rising, but actual infection rates still low
Computer security companies have had their hands full keeping PCs and other devices secure from cyberattackers, and while mobile malware is still overlooked, the threats are continuing to grow. There is serious concern that hackers will infect smartphones and tablets using malicious programs that are able to act like legitimate apps - giving them access to a large amount of information on mobile devices.
"We think the threat is real; we think it's a growing threat," said Gary Davis, McAfee chief consumer security evangelist. "We think there's a laissez-faire attitude with consumers not giving it the same kind of attention they give other threats."
Despite the lack of mobile attacks, where Google Android devices receive 98 percent of total mobile threats found in the wild, other operating systems need to be aware of security problems. Furthermore, mobile malware still has a lot of room to grow, even with thousands of Android-based malicious threats already spotted by security researchers.
Continue reading: Mobile malware threats rising, but actual infection rates still low (full post)
Anonabox, a $45 router that routes your traffic through Tor
In this government-spies-on-everyone age, anonymity is hard to come by. But, a group of privacy-focused developers have taken to Kickstarter, asking for funding from the world for something they call, Anonabox. With a goal of $7500, they've blown past that with a huge $146,755 (at the time of writing), with another 28 days still to go.
Anonabox is an open-source router that automatically directs all of your data, with it connecting to your router through Wi-Fi or ethernet, through the Tor network. This hides users' IP addresses, and skips over censorship. Better yet, Anonabox is tiny - small enough that it could easily fit inside of your pocket, or be easily placed anywhere near your router.
Thanks to its tiny size, users can take it with them, plugging it into any router, making their work and Internet use completely anonymous. For people who travel, they could use it in their hotel rooms, or for people in China at an Internet cafe, they can skip over the Great Firewall of China. August Germar, who has spent four years working on Anonabox, explains: "Now all your programs, no matter what you do on your computer, are routed over the Tor network". Germar says that the idea behind Anonabox making the use of Tor easier, but for those who reside in Internet-repressive regimes. He added: "It was important to us that it be portable and small-something you can easily conceal or even throw away if you have to get rid of it".
Continue reading: Anonabox, a $45 router that routes your traffic through Tor (full post)
Kmart servers affected, credit and debit card details possibly stolen
Things do not look good as Sears Holding Corp said on Friday that its Kmart retail chains customer database may have been compromised last month. As a result, some of its customer's credit card and debit card details may have been stolen.
The company said on Friday that its Kmart's servers was affected by a malware. Kmart was not able to say how many customers are affected, and according to their investigation so far, no debit card pin numbers, email and phone contacts, social security number and personal information was stolen.
But, to be on the safe side, Kmart made an announcement that it will be providing a free credit-monitoring service for its customers who used a debit or a credit card during since last month until Thursday. Customers can then call Kmart customer service and report the unauthorized charges immediately. In the meantime, the company hired a security firm to look into the matter while working with its banking partners and federal authorities.
Continue reading: Kmart servers affected, credit and debit card details possibly stolen (full post)
Edward Snowden says 'get rid of Dropbox', Facebook, Google 'dangerous'
As part of his remote interview for the New Yorker Festival, Edward Snowden was asked various questions about what people can do about their privacy. His first reply was to cover the reform of government policies.
Snowden said that some people are fine with thinking along the lines of they "don't have anything to hide" but it's not about that according to the ex NSA contractor, who said "you're inverting the model of responsibility for how rights work". The full reply: "When you say, 'I have nothing to hide,' you're saying, 'I don't care about this right.' You're saying, 'I don't have this right, because I've got to the point where I have to justify it.' The way rights work is, the government has to justify its intrusion into your rights".
On an individual level, Snowden warns us all to find encrypted tools, and to stop using services that are "hostile to privacy". One of those services is Dropbox, where Snowden said "get rid of Dropbox", something that he said doesn't support encryption. Snowden did bring up Facebook and Google, both of which he said are "dangerous services". He also added to not send unencrypted text messages, but to instead of services like RedPhone and Silent Circle.
Continue reading: Edward Snowden says 'get rid of Dropbox', Facebook, Google 'dangerous' (full post)
Hackers to post thousands of stolen Snapchat photos to 4chan
Hackers aren't only interested in embarrassing celebrities, as thousands of pictures and videos were stolen from Snapchat users and will be posted online. The online service was quick to confirm its servers weren't breached, however, users of third-party Snapchat apps were targeted - and will be posted online in a searchable database.
Unfortunately for the users, they believed the images were quickly purged after being sent - instead, "The Snappening" will be posted on 4chan and other websites soon enough.
"We can confirm that Snapchat's servers were never breached and were not the source of these leaks," a Snapchat spokesperson recently said. "Snapchatters were victimized by their use of third-party apps to send and receive Snaps, a practice that we expressly prohibit in our Terms of Use precisely because they compromise our users' security. We vigilantly monitor the App Store and Google Play for illegal third-party apps and have succeeded in getting many of these removed."
Continue reading: Hackers to post thousands of stolen Snapchat photos to 4chan (full post)
Researchers: Electricity smart meters used in Spain can be hacked
Millions of network-connected electricity meters used in Spain are susceptible to cyberattack by hackers, according to security researchers. The vulnerabilities could lead to electricity being terminated - or billing fraud - if hackers are able to access the smart meters.
The Spanish government has relied on these electricity meters to improve national energy efficiency, but didn't put a large enough emphasis on security efforts. The memory chips in the smart meters are reprogrammable and include flawed code, though the researchers won't outline what they did specifically until the problems are fixed.
"Oh wait? We can do this? We were really scared," said Javier Vazquez Vidal, a security expert involved in the smart meter research. "We started thinking about the impact this could have. What happens if someone wants to attack an entire country?"
Continue reading: Researchers: Electricity smart meters used in Spain can be hacked (full post)


