Hacking, Security & Privacy - Page 41
Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 41
Stay Updated
Follow TweakTown for breaking tech news, reviews, and daily updates.
As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.
Home Depot breach leads to stolen customer payment information
Home Depot is now working with banks and law enforcement to investigate a data breach that led cybercriminals to steal customer payment information, including debit and credit card data. The Home Depot breach could have started in April or May, and reportedly affected a large number of customers. The data made its way to an underground forum and was called "American Sanctions," reportedly in response to further U.S. and European sanctions against Russia.
"Protecting our customers' information is something we take extremely seriously, and we are aggressively gathering facts at this point while working to protect customers," said Paula Drake, Home Depot spokesperson.
Consumers are urged to use cash or credit card payments in retail stores - debit card payments can be risky, forcing shoppers to closely track their bank statements. Hackers taking a political stance, trying to retaliate against the U.S. for further sanctions in a tense situation between Russia and the Ukraine, adds another layer of chaos to data breaches.
Continue reading: Home Depot breach leads to stolen customer payment information (full post)
Celebrity hacker responsible for leaking nude photos hunted by FBI
The FBI is now investigating the celebrity hacker that posted numerous photos of celebrities on the Internet over the weekend. Many of the images, originally posted on 4chan and later shared on Reddit, Twitter and Imgur, featured celebrities such as Jennifer Lawrence, Kate Upton, Jenny McCarthy, and Mary Winstead.
Here is what the FBI noted: "The FBI is aware of the allegations concerning computer intrusions and the unlawful release of material involving high profile individuals, and is addressing the matter," said Laura Eimiller, FBI spokesperson, in a statement. "Any further comment would be inappropriate at this time."
Apple also is investigating the incident, as many of the images were reportedly stored online using its iCloud service.
Continue reading: Celebrity hacker responsible for leaking nude photos hunted by FBI (full post)
Hacker unleashes a treasure trove of celebrity nude photos and videos
A hacker is claiming to have completed a massive hack, where he has said that he has leaked out photos of some of the biggest female celebrities in the world, including Jennifer Lawrence, Kim Kardashian, and many more. Lawrence's reps have confirmed that the nude photos of her are indeed real, allegedly stolen from her Apple iCloud account.
A spokesperson told HuffPost: "This is a flagrant violation of privacy. The authorities have been contacted and will prosecute anyone who posts the stolen photos of Jennifer Lawrence." The hacker claims to have videos of celebrities too, and not just nude photos, as he is offering to release more of his treasure trove in exchange for money.
Representatives for many of the celebrities are coming out claiming that the photos are "completely fake," but there are some that are real, and in this instance, Jennifer Lawrence's reps coming out and confirming the images, proves that this hack has happened and at least some of the pictures are real.
Continue reading: Hacker unleashes a treasure trove of celebrity nude photos and videos (full post)
NOAA Joint Polar Satellite System ground station vulnerable to attack
The National Oceanic and Atmospheric Administration (NOAA) is being pressured by the U.S. Department of Commerce Office of Inspector General to fix several vulnerabilities currently found in the Joint Polar Satellite System (JPSS). There are at least a few different high-risk vulnerabilities found in the JPSS ground stations that could be exploited by clever cyberattacks.
Some of the issues would only require software updates or new security patches, but the NOAA is taking 11 to 14 months in some cases to fix the problems - the JPSS system requirements have 30 days to fix security problems, with the inspector general saying it shouldn't take more than three months to resolve problems.
"The remediation of high-risk vulnerabilities is critical to the continued success of the JPSS mission and should have a high priority," according to the report. "The more high-risk vulnerabilities that exist in the system, the higher the probability is that an attacker could compromise it. This could lead to a disruption of NOAA's ability to command and control the Suomi NPP satellite and to provide data that is used in numerical weather models that support weather predictions and climate monitoring."
Continue reading: NOAA Joint Polar Satellite System ground station vulnerable to attack (full post)
The NSA has its own Google-like internal search engine
For quite a while now, we've known that the NSA has been spying on millions of citizens within the United States. But with its ICREACH search engine, the US spy agency has a Google-like internal search engine that can quickly flick through some 850 billion files that it keeps on citizens, not just in the US, but across the world.
The Intercept, the new site from Glenn Greenwald, who broke the story on NSA whistleblower Edward Snowden, says that these records are available to 23 agencies. These 23 agencies include the likes of the FBI, the DEA and much more, who can easily access ICREACH. This means that the government can search for very specific bits of data of a target citizen, such as their phone number or email address, with it displaying a list of emails both two and from that person over a certain period of time, analysts can then work out a pattern of who that person is in contact with.
This is achieved thanks to metadata, but don't worry ICREACH doesn't include what was said within a phone call, but it does include who the person was talking to, who called them, and what time the call took place. This data can then be used to determine the target's pattern of behavior, so that if the target was calling a certain person at a particular time, they could plan for that time and listen in.
Continue reading: The NSA has its own Google-like internal search engine (full post)
Kaspersky Lab outs "Machete" malware targeting Spanish speakers
The "Machete" cyberattack targeted Spanish speaking residents of Colombia, Ecuador and Venezuela, and the malware was recently noted by security firm Kaspersky Lab. The targeted attack campaign likely launched in 2010 and was improved in 2012, with the Machete operation still potentially active. The malware is sent as a RAR file attachment that includes a PowerPoint presentation, researchers noted.
The malware can log keystrokes, capture geolocation data, capture screenshots, record audio from PC microphone, take photos via Web camera, and copy files to a remote server, among other similar cybercriminal activities.
There were 85 victims in Colombia, 282 victims in Ecuador, and 372 victims in Venezuela, though also found 45 victims in Russia and small numbers of victims in the United States and Europe. Much like other malware distribution, the criminals rely on social engineering to trick users to unknowingly install it on their machines.
Continue reading: Kaspersky Lab outs "Machete" malware targeting Spanish speakers (full post)
Diaspora social networking site can't stop Islamic State messages
Social media service Diaspora, an open source, decentralized service consisting of individual nodes, utilizes thousands of private servers. Unfortunately, there isn't a way for the Diaspora project team to edit or remove content from a network node, and that's likely why IS chose it.
After being booted from Twitter and other social networking sites, the Islamic State is looking for new alternatives. In an attempt to spread images, videos and published propaganda to shock the west and appeal to new recruits, IS wants to have a collection of social media accounts to use.
"As many of the members of the core team are pod administrators ourselves, we know it can be hard to detect such users," the Diaspora blog reads. "We rely on our community members to use the report function to alert their podmin to any post or comment they believe to be a cause for concern. However, because this is such a crucial issue, we have also accumulated a list of accounts related to IS fighters, which are spread over a large number of pods, and we are in the process of talking to the podmins of those pods."
Continue reading: Diaspora social networking site can't stop Islamic State messages (full post)
Universities struggle with cybersecurity efforts to keep data safe
U.S. universities face a bigger threat of security data breaches than the retail and healthcare sectors, according to a recent study published by BitSight. As the school year begins again, hackers are preparing to target universities once again, the report said.
Using data based on major athletic conferences, including the Pacific-12, Big 10, Big 12, Southeastern Conference, Atlantic Coast Conference and Ivy League from July 2013 to June 2014, all divisions saw a drop in cybersecurity performance.
"From Social Security and credit card numbers to health records and intellectual property produced by research departments, colleges and universities house a vast amount of sensitive data," said Stephen Boyer, BitSight co-founder and CTO, in a statement to FierceCIO. "While not surprising given the unique challenges universities face securing open campus networks, it's concerning to see that they are rating so far below other industries that we've seen plagued by recent security problems."
Continue reading: Universities struggle with cybersecurity efforts to keep data safe (full post)
Pro-Syrian hackers using malware to launch attacks against rivals
Pro-Syrian hackers are using WhatsApp, Facebook, YouTube and Viber to share malware that is aimed at activists fighting for a regime change in Syria. In addition to Syrian Internet users, people were also targeted in the United States, France, Saudi Arabia, United Arab Emirates, Turkey, Palestine, Israel, Morocco and Lebanon, security researchers noted.
The malware is using remote access tools (RATs) and being shared to groups that support Syrian President Bashar al-Assad. The RAT technology are able to compromise PCs and systems in which they are installed, with attackers stealing credentials, remotely turning on microphones and video cameras, and controlling the infected PCs.
"Total Network Monitor (which is a legitimate application) is inside another sample found, being used with embedded malware for spying purposes," according to Kaspersky Lab researchers. "Offering security applications to protect against surveillance is one of the many techniques used by malware writing groups to get users desperate for privacy to execute these dubious programs."
Continue reading: Pro-Syrian hackers using malware to launch attacks against rivals (full post)
Edward Snowden says he would go to jail in order to return home
Former NSA contractor Edward Snowden would "volunteer" for prison but only under the right circumstances, he said in a recent interview with Wired Magazine. Considering he faces charges that include conveying classified information to an unauthorized party, theft of government property and disclosing communications intelligence information, he would likely face significant prison time if convicted.
"I told the government I'd volunteer for prison, as long as it served the right purpose," Snowden told Wired earlier this month. "I care more about the country than what happens to me. But we can't allow the law to become a political weapon or agree to scare people away from standing up for their rights, no matter how good the deal is. I'm not going to be part of that."
Earlier in the month, Russian officials announced Snowden's asylum was extended for an additional three years - allowing him to remain in a safe location as he tries to figure out what to do long-term. Most U.S. politicians have been less than kind when describing Snowden's actions, and it seems unlikely he would receive a fair trial if he returns back to the United States. However, they are still keen to see him return home, because they certainly seem to have a lot of questions they would like him to answer.
Continue reading: Edward Snowden says he would go to jail in order to return home (full post)
Repeated cyberattacks targeting French site Rue89, website staff
Repeated cyberattacks against French news website Rue89 has drawn criticism from the Committee to Protect Journalists (CPJ), with staff and their families being harassed after publishing a story related to a "militant Zionist" cybercriminal. The person in question, Gregory Chelli, lives in Israel, and reportedly attacked people he thought were against Israel.
The official Rue89 website suffered multiple distributed denial-of-service (DDoS) attacks, according to Pierre Haski, website editorial director. An official complaint has been filed with the French public prosecutor's office, and Chelli already faced a suspended sentence in France, but it's unsure what will happen this time around.
"We call on French and Israeli authorities to launch a thorough investigation into these attacks on Rue89 and to ensure its staff members' safety," said Nina Ognianova, CPJ Europe and Central Asia Program Coordinator, in a statement. "Such intimidation tactics against journalists and their families must not be tolerated, lest they lead the media to self-censor."
Continue reading: Repeated cyberattacks targeting French site Rue89, website staff (full post)
Hackers could compromise smartphones by using device's gyroscope
Hackers can compromise a smartphone user and eavesdrop by using the device's internal gyroscope, according to a study from Stanford University and the Rafael Advanced Defense Systems technology company. Instead of directly listening to a phone conversation, this is remote eavesdrop exploit so users can be snooped on when in the immediate area of a device.
"Whenever you grant anyone access to sensors on a device, you're going to have unintended consequences," said Dan Boneh, Stanford security professor, in a statement to Wired. "In this case the unintended consequence is that they can pick up not just phone vibrations, but air vibrations."
The gyroscope in smartphones use a small plate that vibrates around 200 hertz, which is fast enough to recognize human voices. Using customized speech recognition software allowed the researchers to accurately determine 65 percent of "numeric digits" of a specific speaker. Eavesdropping levels aren't quite the same as using a compromised smartphone's microphone, but shows the potential threat level of current data security efforts.
Continue reading: Hackers could compromise smartphones by using device's gyroscope (full post)
Report: SuperValu, Albertson's grocery stores hit by data breaches
Cybercriminals successfully breached Albertson's and SuperValu, which are two of the largest and most popular grocery store chains in the United States. The massive data breach also impacts their umbrella companies, including Acme, Jewel-Osco, Shaw's, Star Market, Cub Foods, Farm Fresh, Shop 'N Save, Hornbacher's, and Shoppers Food & Pharmacy.
The SuperValu breach might have affected customers between June 22 and July 17 in Illinois, Maryland, Minnesota, Virginia and Missouri. It's unknown how many Albertson's customers might be affected from the data breach.
"The safety of our customers' personal information is a top priority for us," said Sam Duncan, SuperValu President and CEO, in a statement. "The intrusion was identified by our internal team, it was quickly contained, and we have had no evidence of any misuse of any customer data. I regret any inconvenience that this may cause our customers but want to assure them that it is safe to shop in our stores."
Continue reading: Report: SuperValu, Albertson's grocery stores hit by data breaches (full post)
Rady Children's Hospital facing lawsuit related to data breach
Following a data breach suffered by Rady Children's Hospital in June 2013, a mother has filed a lawsuit against the company related to a security breach that led her daughter's medical records to be exposed.
The Rady data breach occurred when an employee emailed a spreadsheet containing patient admittance records from July 1, 2012 to June 30, 2013 to four job applicants. The records included patient names, birth dates, primary medical diagnoses, medical record numbers, insurance carrier information, and admittance and discharge dates.
"This is not one or two records dropped in the parking lot," said David A. Miller, an attorney representing the mother, in a statement to the media. "The people they gave this information to didn't even work there. They were job applicants."
Continue reading: Rady Children's Hospital facing lawsuit related to data breach (full post)
Amobile Spy unveils Android spy app so you can snoop on your kids
Amobile Spy recently launched the iKeyMonitor Android Spy App, a custom app designed to help parents track what their children do using their smartphones.
The app has the ability to log passwords and keystrokes, monitor WhatsApp message recording, Web history tracking, capture screenshots, log email reporting and 2-side SMS/call logging. The keylogger monitors everything from Facebook, Twitter, Gmail, Skype, Yahoo Messenger and other popular social media or communication apps.
"iKeyMonitor Android Keylogger offers simple, secure, and secret ways to record the activities on Android devices with incredible monitoring features," said Kyle Davis, Amobile Development Department Manager, in a press statement. "We're also giving users smart features to review the logged data remotely."
Continue reading: Amobile Spy unveils Android spy app so you can snoop on your kids (full post)
Jailbroken iOS devices being targeted, exploited by new theft malware
A new Chinese malware infected more than 75,000 jailbroken Apple iPhones, with the malware hijacking 22 million advertisements. AdThief, also known as Spad, is the iOS malware and was able to covertly operate around four months - and only works on jailbroken devices. Although originally found by researcher Claud Xiao in March, Fortinet senior mobile researcher Axelle Apvrille took a closer look at AdThief.
Operating on 15 different mobile adkits, the malware changed a developer or affiliate ID so the attacker would collect the revenue. Eight of the adkits are Chinese, and jailbreaking devices is a rather common technique among Chinese consumers. Security experts continually warn users that jailbroken smartphones and tablets pose significant threats to users.
The Chinese hacker, known as Rover12421 did contribute to the code, but denied saying he or she is behind the entire project.
Continue reading: Jailbroken iOS devices being targeted, exploited by new theft malware (full post)
Malware increasingly targeting virtual machines as threats evolve
Newer generations of malware are finding their way to virtual machines - and instead of fleeing like before - are still executing when on VM. At least 70 percent of companies plan to utilize server virtualization by the end of 2015, so malware reaching the virtual machines could prove problematic.
In a study of 200,000 malware samples, analyzed on both VM and non-VM machines by Symantec, only 18 percent wouldn't operate on a virtual machine.
"The host server, as well as any virtual machine running on it, needs to be protected against malware," said Liam O'Murch, Symantec Security Response researcher, in a statement to SCMagazine. "To achieve this, advanced malware protection with proactive components that go beyond the classical static antivirus scanner needs to be in place. This can be agentless on the hypervisor or in the guest image themselves."
Continue reading: Malware increasingly targeting virtual machines as threats evolve (full post)
Author of Android "Heart App" malware arrested in just 17 hours
An unnamed 19-year-old software engineering student, identified only as "Li," was arrested just 17 hours after his "Heart App" Google Android malware infected more than 100,000 phones. The malware was able to spread so quickly by relying on the contact lists of compromised devices, with users downloading the fake app, which then sent out a text urging users to download the app as well.
Chinese wireless carriers were quick to block more than 20 million infected messages from being sent out to new users. The 19-year-old will be identified following completion of the investigation by Shenzhen police, where the student went for vacation. It seems the custom malware was designed just as proof of his ability to write code.
To uninstall the malware, Sophos recommends the following: head to Settings | Apps | Downloaded and uninstall XXshenqi app.
Continue reading: Author of Android "Heart App" malware arrested in just 17 hours (full post)
Blackphone responds to claim it was hacked in under five minutes
The Blackphone was announced as a way for security conscious consumers to use their device in peace, without the fear of their communications being compromised - and it has now been 'hacked' at the Black Hat event in under five minutes.
@TeamAndIRC managed to gain root access to the Blackphone at the DefCon hacking conference within five minutes by going through the Android Debugging Bridge, and without using a bootloader to boot. Blackphone still seems to be solidly secure on the surface nonetheless, and now the company has responded to the discovery.
Blackphone said it is perhaps not as big of a disaster as it sounds: the company underplayed getting access through ADB, claiming it is just a part of the Android OS that the firm opted to turn off, and that a patch is on the way. But another vulnerability uncovered by TeamAndIRC, the company said in a blog post, is "accurate" - and a patch was released in three days of its initial discovery. Blackphone went on to congratulate the hacker for finding the bug.
Continue reading: Blackphone responds to claim it was hacked in under five minutes (full post)
Underground markets for stolen data as organized as real businesses
Criminals that compromise networks and steal large amounts of information are finding easier and more organized methods to quickly get rid of the data. Data dumps are one of the most popular products found on these underground forums, where buyers and sellers communicate in an organized fashion similar to an official business from the legitimate world.
Many cybercriminal groups are trying to steal bulk data, such as the Target and eBay breach, looking to offload the information as quickly as possible. Using organized underground hacker forums, many based in Eastern Europe and China, they are able to sell and trade the data.
"When we think about the markets themselves they are organized in a unique fashion," said Tom Hold, Michigan State University associated professor specializing in cybercrime. "At the individual level, we're talking about a process where we're seeing peers and colleagues; at the formal forum level, we're seeing a more formal organization that takes place."
Continue reading: Underground markets for stolen data as organized as real businesses (full post)


