Newsletter IconFacebook IconX IconThreads IconInstagram IconYouTube IconPinterest Icon
Giveaway: AVerMedia Creator Bundle (4K Webcam, Capture Card, Charging Hub, and Mouse Pad)

Hacking, Security & Privacy - Page 42

Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 42

Stay Updated

Follow TweakTown for breaking tech news, reviews, and daily updates.

Add TweakTown as a preferred source on GoogleFind TweakTown on Apple News

As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.

Current USB technology 'critically flawed,' security experts warn

| Aug 11, 2014 3:03 AM CDT

Cybersecurity experts Jakob Lell and Karsten Nohl have demonstrated a new vulnerability that makes it extremely difficult for users to defend against USB-based attacks. The current USB standard's vulnerability makes it hard to defend against attacks, even if manufacturers should begin developing additional security layers.

Specifically, empty USB flash drives can contain malware even if formatted - a troubling sign for many of the companies that rely on flash drives to transfer data.

"USB is ubiquitous across all devices," said Mike McLaughlin, First Base Technologies, in a statement to BBC. "It comes down to the same old saying - don't plug things in that you don't trust. Any business should always have policies in place regarding USB devices and USB drives. Businesses should stop using them if needed."

Continue reading: Current USB technology 'critically flawed,' security experts warn (full post)

Mozilla accidentally leaks the credentials of 76k devs

| Aug 4, 2014 5:23 AM CDT

The Mozilla Foundation has made a mistake that left the credentials of about 76,000 developers using its Mozilla Developer Network vulnerable to hackers. During a sanitation process on the server where the data was stored, some sort of error cause an emergency dump of the data on that server to be sent to a backup server.

That emergency dump is something that many servers do to prevent data loss. The catch is that the backup server where the data was dumped was unencrypted. That means that the details of those 76,000 developers were available to be copied by anyone along with 4,000 encrypted passwords.

Mozilla has removed the data now, but the information sat there for a month before developers noticed the issue. Mozilla says that the passwords would not work and that it hasn't seen any sort of breach using the data.

Continue reading: Mozilla accidentally leaks the credentials of 76k devs (full post)

Security company KnowBe4 warns of CryptoWall ransomware

| Jul 23, 2014 8:24 PM CDT

The federal government might have disrupted Cryptolocker ransomware operations, but the Benjamin F. Edwards & Co. brokerage house recently suffered an attack by the CryptoWall, the DOJ.NH website recently reported. The incident took place in late May, with the unauthorized third party compromising their computer systems - informing customers of the data breach.

Many companies are rolling out new security and try to educate users about safely and properly interacting with emails, online accounts, and other cloud-based services proves to be difficult. As users are compromised, critical work documents become unusable until a payment has been made to operators of the ransomware - and educating users to spot these social engineering techniques should be a first great step.

"We are seeing a new wave of ransomware created by Russian cybercriminals, and our recent survey shows that IT pros expect it to get worse the rest of the year," said Stu Sjouwerman, KnowBe4 CEO, in a press statement. "To add insult to injury, apart from the confidential files being encrypted and ransom extorted, the ransomware sends unidentified data out of the victim's network. That means the malware infection needs to be treated as a data breach with accompanying very high costs."

Continue reading: Security company KnowBe4 warns of CryptoWall ransomware (full post)

The fight to keep consumers safe online is important and difficult

| Jul 23, 2014 3:50 AM CDT

The lure of easy pickings in online cybercrime has drawn many criminals to the Internet, where they look to compromise users, steal debit and credit card information along with other personal data. The use of social engineering to manipulate victims remains popular, but many Internet users provide information to criminals too easily.

The basic tips apply: don't provide personal information when you don't have to, such Social Security numbers; always monitor bank accounts; avoid clicking links in unsolicited emails, or other suspicious messages; and choosing a secure password are important.

"Con artists are going online to steal your hard-earned money," said Bob Gallo, AARP Illinois State Director, in a press statement. "Common sense should tell us that if it sounds too good to be true, chances are it is. But AARP's nationwide Fraud Watch Network can also help you beat con artists at their own game and get critical information to fight back and protect your money."

Continue reading: The fight to keep consumers safe online is important and difficult (full post)

Cyberwar building between warring factions in Iraq as tensions build

| Jul 22, 2014 4:20 PM CDT

The continued political unrest in Iraq has led to armed conflict, but has led to a rise in something a bit more surprising: a cyberwar that has used social media and coordinated malware and other cyberattacks against rival political factions.

The use of the "Njrat" malware, to compromise PCs and create a rudimentary botnet, has drawn interest among cybersecurity experts - and other similar tactics are being deployed. The criminals are interested in stealing data and using hijacked microphones and cameras to see what is happening in select regions.

"The key parties are local groups within Iraq using malware for targeted intelligence on each other," said Andrew Komarov, Intel Crawler chief of security, in a statement. "It is very hard to confirm who is the author, as some of the malware is used from public sources, but it is very visible that it is used within Iraq, and not outside against foreign countries, which may explain the beginning of internal local cyberwar."

Continue reading: Cyberwar building between warring factions in Iraq as tensions build (full post)

US government hands Cisco counterfeiter 37 months in prison

| Jul 20, 2014 11:43 PM CDT

The owner of ConnectZone.com, Daniel Oberholtzer, has been sentenced for participating in conspiracy to traffic in counterfeit goods, receiving 37 months in federal prison. The company must forfeit $716,778 that was collected for selling counterfeit products, advertising the sale of network products that were promoted as Cisco products.

"Innovation and our economy demand that the intellectual property of businesses be protected," said Jenny Durkan, U.S. Attorney, in a statement. "Here, the defendants used the hard earned brands of others and slapped it on inferior products."

Business owners and law enforcement have stepped up civil and criminal complaints against Internet pirates and counterfeiters. Leaders of organized rings conducting illegal business are being indicted and face prison time if found guilty.

Continue reading: US government hands Cisco counterfeiter 37 months in prison (full post)

Edward Snowden wants hackers to design anti-surveillance tech

| Jul 20, 2014 5:09 AM CDT

Former NSA contractor Edward Snowden wants hackers to help develop new technologies that will help users access the Internet without government snooping. His plea for assistance was via video chat from Moscow, where he is becoming more vocal about snooping.

"You in this room, right now have both the means and the capability to improve the future by encoding our rights into programs and protocols by which we rely every day," Snowden recently told the Hackers On Planet Earth (HOPE) attendees. "That is what a lot of my future work is going to be involved in."

SecureDrop, a service so whistleblowers can leak documents to the media, is one new technology that is being discussed at the conference. There is a great opportunity for software development after Snowden gave a much better picture of some of the surveillance programs currently underway.

Continue reading: Edward Snowden wants hackers to design anti-surveillance tech (full post)

Snowden says NSA workers shared intercepted sexts, NSA defends itself

| Jul 18, 2014 11:43 AM CDT

Former NSA contractor Edward Snowden has revealed widespread spying and surveillance, but there has been a large amount of other revelations made by the American. Snowden recently said it's not uncommon for NSA workers to share "intimate nude photos of someone in a sexually compromising situation," including intercepted sexts sent among phone users.

"You've got enlisted guys 18-22 years old," Snowden said. They've suddenly been thrust into a position of extraordinary responsibility where they now have access to all your private records. During the course of their work, they stumble across something that is completely unrelated to their work in any sort of necessary sense, for example, an intimate nude photo of someone in a sexually compromising situation. But they're extremely attractive. So what do they do? They turn around in their char and show a coworker who says, 'Hey that's great. Send that to Bill down the way.' Then Bill sends it to George, who sends it to Tom."

An NSA official didn't deny the activities occurs, but said the organization "has zero tolerance for willful violations" of professional conduct and would address "credible allegations of misconduct." If true, it's not necessarily surprising to hear that this type of behavior happens, though certainly is inappropriate.

Continue reading: Snowden says NSA workers shared intercepted sexts, NSA defends itself (full post)

UN human rights commissioner says Snowden shouldn't face charges

| Jul 17, 2014 8:53 PM CDT

The highest ranking official of the United Nations humans rights department says former NSA contractor Edward Snowden should be celebrated and not hunted. The U.S. and British governments relying on mass surveillance is a "dangerous habit" with very little oversight, even following Snowden's whistleblowing activities.

Snowden is facing espionage charges in the United States, accused of theft of government property, wilful communication of classified communications and unauthorized communication of national defese information. If Snowden did return to the United States, he noted he's not necessarily afraid of a possible trip to Guantanamo Bay - but wants to face a jury trial - something that the federal government probably wouldn't agree to.

"Those who disclose human rights violations should be protected: we need them," said Navi Pillay, UN high commissioner for human rights, during a recent press conference. "I see some of it here in the case of Snowden, because his revelations go to the core of what we are saying about the need for transparency, the need for consultation. We owe a great deal to him for revealing this kind of information."

Continue reading: UN human rights commissioner says Snowden shouldn't face charges (full post)

Edward Snowden wants encryption, data protection used by journalists

| Jul 17, 2014 6:28 PM CDT

Former NSA contractor Edward Snowden wants professionals to utilize data protection and encryption to communicate, and is reportedly working on some type of "encryption tools" to help protect sources. Remaining in Russia, with his asylum status extended, it's mainly unknown what the American has been doing with his spare time.

Snowden also is working on funding for the project, which will be used to keep communications between journalists and their anonymous sources secure from government spying.

"Journalists have to be particularly conscious about any sort of network signaling, any sort of connection, any sort of license-plate reading device that they pass on their way to a meeting point, any place they use their credit card, any place they take their phone, any email contact they have with the source because that very first contact, before encrypted communications are established, is enough to give it all away," Snowden recently said in an interview.

Continue reading: Edward Snowden wants encryption, data protection used by journalists (full post)

Lookout: U.S. smartphone users being targeted by mobile ransomware

| Jul 17, 2014 2:11 AM CDT

A new form of malware dubbed 'ScarePakage' is targeting U.S. smartphone owners and can render devices inoperable, according to security firm Lookout. The mobile ransomware tricks users by claiming it's from the FBI, saying phone owners are being investigated for alleged crimes. Once a device is compromised, the ransomware demands "several hundred dollars" or the device will remain under control of ScarePakage.

The ScarePakage ransomware doesn't need root administrator access, and has been designed to be overly intrusive. It runs a Java TimerTask every 10 milliseconds to prevent any other applications or processes to shut down, and stops hijacked devices from going into sleep mode.

"Mobile ransomware in and of itself is a fairly new tactic from malware authors and this is one of the first we've seen targeting the U.S. specifically," said Jeremy Linden, Lookout Senior Security Product Manager, in a statement to TweakTown. "That said, we are less concerned about ScarePakage distributes itself and more concerned about how difficult to remove it is. Once the application has device administrator permissions, it is very hard to regain control of the device."

Continue reading: Lookout: U.S. smartphone users being targeted by mobile ransomware (full post)

Stolen laptop opens up 20,000 students in South Carolina to data theft

| Jul 16, 2014 5:27 PM CDT

Around 20,000 current and former students at the Orangeburg-Calhoun Technical College in South Carolina are at risk of data theft following a stolen laptop taken from a staff office. Data taken includes names, birthdates and Social Security numbers of both students and faculty going back at almost seven years.

The technical college will now use encryption software on all laptops and PCs, while those affected by the data breach are being contacted. The laptop was stolen on July 7 and an investigation is currently underway to try to identify those responsible.

"College officials were disappointed to learn that someone entered a staff member's office on campus and removed a computer," said Kim Huff, OC Tech VP of Business Affairs, in a statement. "We are evaluating our security controls to prevent further incidents."

Continue reading: Stolen laptop opens up 20,000 students in South Carolina to data theft (full post)

Chinese man in Canada arrested for hacking Lockheed Martin, Boeing

| Jul 16, 2014 3:44 PM CDT

A Chinese citizen living in Canada has been arrested and is accused of hacking into Boeing, Lockheed Martin, and other U.S. companies with government defense contracts. Su Bin, also known as Stephen Subin and Stephen Su, is accused of unlawfully accessing computers in the United States, according to the FBI, in an attempt to steal data on military projects.

Su allegedly worked with two other hackers to steal data between 2009 and 2013, with some stolen information offered for sale to Chinese companies. Specifically, they had an interest in F-22, F35, and C-17 U.S. military aircraft - along with weapons programs currently being developed.

"We remain deeply concerned about cyber-enabled theft or sensitive information, and we have repeatedly made it clear that the United States will continue using all the tools our government possesses to strengthen cyber security and confront cybercrime," said Marc Raimondi, U.S. Department of Justice spokesman, in a statement.

Continue reading: Chinese man in Canada arrested for hacking Lockheed Martin, Boeing (full post)

Google introduces 'Project Zero,' tasked with hunting down bugs

| Jul 16, 2014 1:46 PM CDT

Google publicly announced its Project Zero, a new effort aimed at tracking software bugs, with a public vulnerability database also in the works. The company also recruited George Hotz, responsible for hacking the Sony PlayStation 3 and Apple iPhone, among other claims to fame, as an intern to help with the bug hunt.

The Project Zero team will focus solely on tracking down bugs - not just for Google software - to help try to keep the Internet more secure. In addition, Google wants to better understand the techniques, targets and motivations of cybercriminals, as state-sponsored hacking becomes extremely prevalent.

"Once the bug report becomes public (typically once a patch is available), you'll be able to monitor vendor time-to-fix performance, see any discussion about exploitability, and view historical exploits and crash traces," said Chris Evans, responsible for leading Project Zero.

Continue reading: Google introduces 'Project Zero,' tasked with hunting down bugs (full post)

Germany considers using typewriters to stop the US from spying on them

| Jul 15, 2014 8:43 PM CDT

It was only a year ago that the German government considered the Xbox One to be a monitoring device, and this was at the time of NSA whistleblower Edward Snowden coming out about the NSA spying on the entire world.

Well, the German government is now considering shifting back to the old-fashioned way of writing documents: using a typewriter. The use of a typewriter would be used to type up confidential documents, so that they don't get typed up on a PC, that has an operating system that can be hacked, which is connected to a network. A typewriter can have someone type up a confidential document, finish it, and file it away - without the prying eyes of the NSA getting to it.

Chair of the German Parliament, Patrick Sensburg, has an enquiry into the alleged spying by the NSA, saying that committee members are considering new security measures and are thinking about ditching e-mail in favor of a serious move back to using typewriters. He told the ARD Morning Show Monday: "As a matter of fact, we already have [a typewriter], and it's even a non-electronic typewriter".

Continue reading: Germany considers using typewriters to stop the US from spying on them (full post)

Hacker involved in $14 million theft pleads guilty to bank fraud

| Jul 14, 2014 7:36 PM CDT

Qendrim Dobruna, 27, has pleaded guilty to bank fraud in a case stemming back to 2011, and could face up to 30 years in prison. Operating under the names "cL0sEd" and "cL0z," he played a part in an operation that lasted 48 hours and led to $14 million stolen - with criminals withdrawing the funds via ATMs in 20 different countries.

Dobruna initially decided to plead not guilty, but thought better of it before changing his plea to guilty - and will serve at least nine years. Dobruna and his accomplices chose to defraud "JPMorgan Chase, and to obtain moneys, funds, credits and other property owned by, and under the custody and control of said financial institution, by means of materially false and fraudulent pretenses, representations and promises," according to the federal government's indictment.

It took a growing number of cybercrime-related cases before the federal government jumped into action - but criminals conducting fraud and theft on a large scale are increasingly being targeted by police and federal agencies.

Continue reading: Hacker involved in $14 million theft pleads guilty to bank fraud (full post)

User's data can be extracted from smartphones post factory reset

| Jul 13, 2014 2:39 AM CDT

If you think that using the factory reset function on your smartphone will clear your data, you're in for a pleasant surprise! Czech-based security company Avast purchased several phones via eBay to evaluate if they can extract data from it, especially the ones that had a factory reset done by the previous owner.

The factory reset is supposed to be a one-touch feature which should secure erase all the data, settings and other user-related details from the photo and return it to a 'rolled out of the factory' state. But the experiment by Avast proved that this is not entirely true.

The company conducted this experiment by purchasing 20 smartphones from eBay. The experts at Avast were able to extract data from these smartphones, though the company didn't disclose if that was the case with all the smartphones. The experts were able to extract 40,000 photos, out of which 1,500 of those were family photos and others included selfies with their manhood.Other data included emails, text messages, Google search history and even browser history. Avast also added that the factory reset feature does not wipe out the data from the phone. Rather, it only erases the index information.

Continue reading: User's data can be extracted from smartphones post factory reset (full post)

Glenn Greenwald says there is a second NSA whisleblower

| Jul 10, 2014 11:28 PM CDT

It looks like Edward Snowden might not be the only NSA whistleblower according to Glenn Greenwald, with the tease coming from Greenwald who tweeted over the weekend that the fact of a second US whistleblower "seems clear at this point".

Greenwald believes there is a second US whistleblower that is leaking information about the NSA to media around the world. Greenwald added: "The lack of sourcing to Snowden on this & that last article seems petty telling". The tweet was made after a German site published an analysis of the NSA's XKEYSCORE code, which doesn't seem to have some from Snowden.

It was only after this that speculation of a second US whistleblower began, with experts agreeing that it looks like Snowden isn't alone. ARD, a German public broadcaster, said in a report last week that the NSA is using its XKEYSCORE program to track Internet users who search the web on how to stay hidden when on the Internet. Greenwald added: "I've long thought one of the most significant and enduring consequences of Snowden's successful whistleblowing will be that he will inspire other leakers to come forward".

Continue reading: Glenn Greenwald says there is a second NSA whisleblower (full post)

Germany boots CIA spy from country because of NSA-related spying

| Jul 10, 2014 3:45 PM CDT

The German government remains upset that the NSA snooped on German Chancellor Angela Merkel and other government leaders, requesting the top U.S. intelligence official in Germany to leave the country. It was an unexpected move by the German government, as the CIA official works at the U.S. embassy in Berlin - as parliamentary inquiries continue in Germany.

The German government wants to speak with Snowden, but the American turned down an in-person meeting that would have taken place in Russia. Even if German investigators are unable to chat with Snowden in the near future, there are obvious political tensions between Germany and the United States at the moment.

"The representative of the U.S. intelligence services as the Embassy of the United States of America has been requested to leave Germany," said Steffen Seibert, a Germany government spokesperson, in a statement. "The Federal Government takes these incidents very seriously. It remains vital for Germany, in the interest of the security of its citizens and its forces abroad, to cooperate closely and trustfully with western partners, in particular with the USA. To do so, however, mutual trust and openness are necessary. The Federal Government continues to be ready for this and expects the same from its closest partners."

Continue reading: Germany boots CIA spy from country because of NSA-related spying (full post)

Kaspersky Lab announces 2015 editions of security solutions

| Jul 8, 2014 7:42 PM CDT

Security company Kaspersky Lab today announced its updated product lineup for home consumers, including the Kaspersky Anti-Virus 2015, Kaspersky Internet Security 2015 and Kaspersky Internet Security - Multiple-Device 2015. Designed to protect Microsoft Windows, Apple OS X and Google Android devices from current threats in a rather complex security world.

New features include Webcam protection aimed at keeping built-in Web cameras safe and secure from outside hacking. Kaspersky also included a Wi-Fi security notification module that ensures public Wi-Fi hotspots are secure, informing users of vulnerable network connections or unsecured password transmission. Ransomware which encrypts files also is a major threat to PC users, so the Kaspersky Lab System Watcher module verifies all running processes to prevent criminals from encrypting files.

"Today's threat landscape is persistently evolving and at Kaspersky Lab we're continuously staying one step ahead of the cybercriminals," said Justin Priestley, Kaspersky Lab consumer sales SVP, in a statement. "We provide our customers with the most advanced protection tools available, like the innovative Webcam Protection and System Watcher features. Our 2015 suite of products, especially Kaspersky Lab Internet Security, is equipped with technologies that have proven to be effective not only in independent tests, but in the real-world, protection 300 million people across the globe."

Continue reading: Kaspersky Lab announces 2015 editions of security solutions (full post)

Join Our Newsletter

Join the TweakTown Newsletter for daily tech updates delivered to your inbox.

See previous giveaways.

Newsletter Subscription