Hacking, Security & Privacy - Page 43
Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 43
Stay Updated
Follow TweakTown for breaking tech news, reviews, and daily updates.
As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.
Chinese hacker group Deep Panda targets US think tanks for Iraq data
A team of researchers at CrowdStrike is claiming China's "Deep Panda" cyber offensive group has begun targeting, and has now compromised, US national security think tanks. In an alarming statement, co-founder Dmitri Alperovitch asserted that the attacks seem to be tied into monitoring activity from the newly founded Islamic State of Iraq and the Levant (ISIS).
In a blog post, CrowdStrike's co-found Dmitri Alperovitch outlined the company's work with human rights groups and security think tanks. Former senior government officials frequently work in organizations like these, and so are a natural target of hostile intelligence services, Alperovitch said, adding that he has "great confidence" the Deep Panda group is affiliated with the Chinese government. It's one of 30 CrowdStrike closely follows in China, but the company points out it is also one of the most sophisticated.
As the armed ISIS faction launched an attack on an oil refinery, Alperovitch claims Deep Panda began a hunt for files from US thinktank employees. He pointed out that China is the top foreign investor in Iraq's oil infrastructure, and so espionage fits in with the country's national interests. "It wouldn't be surprising if the Chinese government is highly interested in getting a better sense of the possibility of deeper US military involvement that could help protect the Chinese oil infrastructure in Iraq," Alperovitch wrote. "In fact, the shift in targeting of Iraq policy individuals occurred on June 18, the day that ISIS began its attack on the Baiji oil refinery."
Continue reading: Chinese hacker group Deep Panda targets US think tanks for Iraq data (full post)
Dailymotion hit by attack, leaving video viewers vulnerable
The popular video website Dailymotion was compromised by cybercriminals able to inject malicious code, redirecting visitors and secretly installing malware. The iframe first appeared on June 28 and installed the Sweet Orange Exploit Kit, targeting Oracle Java, Microsoft Internet Explorer and the Adobe Flash Player.
It seems only a small number of users were compromised, and Dailymotion quickly restored videos and ensured they were safe again.
"If the kit successfully exploited any of these vulnerabilities, then Trojan.Adclicker was downloaded onto the victim's computer," according to Symantec researchers. "This malware forces the compromised computer to artificially generate traffic to pay-per-click Web advertisements in order to generate revenue for the attackers."
Continue reading: Dailymotion hit by attack, leaving video viewers vulnerable (full post)
In May, spammers found success sending education-related emails
May spam email traffic averaged 69.8 percent, a 1.3 percent drop from April, but security experts continue to tell Internet users to be weary of sometimes rather clever spam. There was a large amount of mass mailings for schools and universities, along with "offers" for student loan repayment plans also popular phishing techniques.
Email search sites were the most popular targets (32.2 percent) ahead of social media websites (23.9 percent), and financial and payment organizations were in the No. 3 spot (12.8 percent). Spammers rely on unsuspecting and gullible Internet users to click compromising links that install malware - or otherwise steal credentials.
"Spammers are constantly thinking up new tricks or turning to old favorites to catch out their victims," said Tatyana Shcherbakova, Kaspersky Lab Senior Spam Analyst, in a statement. "It's not just about advertising: this month we came across a number of mass mailings imitating official notifications from various services and companies. The attachments in these emails contained malware from the Andromeda family. This family consist of backdoors that allow attackers to silently control infected computers, which often become part of a botnet."
Continue reading: In May, spammers found success sending education-related emails (full post)
Pew: Government interference on Internet is a great threat to users
The rise of hackers and cybercrime are problematic, but national governments maintaining security and political control on the Internet will remain the biggest threat. Specifically, there will be a rise in blocking, filtering, segmentation and balkanization of the Internet, according to a study published by the Pew Research group.
Thirty-five percent of those surveyed said they expected significant changes "for the worse" in regards to accessing and sharing online content by 20125 - a troubling concern as more people begin to access the Internet.
"Governments worldwide are looking for more power over the Net, especially within their own countries," said Dave Burstein, Fast Net News editor, in a statement. "Britain, for example, has just determined the ISPs block sites the government considers 'terrorist' or otherwise dangerous. There will usually be ways to circumvent the obstruction but most people won't bother."
Continue reading: Pew: Government interference on Internet is a great threat to users (full post)
Tor users are being targeted by the NSA for surveillance
When Edward Snowden blew the lid on the NSA's spying last year, everything changed. The NSA has asid that even though it intercepts pretty much every single person's communications, it only "targets" a very small number of these people.
This smaller percentage of traffic is flagged as a pattern, or suspicious by the NSA, which then starts their data retention. These targets don't see their data flushed from NSA databases on a 48-hour or 30-day basis like the rest of the world, instead their data is kept forever. This news comes from German site Tagesschau, where Lena Kampf, Jacob Appelbaum and John Goetz reported the NSA's rules on what is deemed a "target" to the US spy agency.
They report that the NSA targets anyone who searches for online articles about Tails, or Tor. Anyone who even uses Tor becomes an instantly target for long-term surveillance and data rentention. Both Tor and Tails have been part of the mainstream discussion for online security, surveillance and privacy for quite sometime. For the NSA to just instantly put surveillance and retention on these people is yet another step of unbelievable, in an already unbelievable breach of users' privacy and rights.
Continue reading: Tor users are being targeted by the NSA for surveillance (full post)
Microsoft battles against malware crime groups in Algeria, Kuwait
Malware linked back to cybercriminals in Algeria and Kuwait was disrupted when Microsoft named several parties in a civil suit accused of creating malicious code that infected millions of victims. The strategy is a unique new method by Microsoft, attempting to disrupt communication channels used by cybercriminals and the infected PCs they've compromised.
The foreign nationals, Naser Al Mutairi and Mohamed Benabdellah, along with the Vitalwerks Internet Solutions domain hosting company - almost 94 percent of compromised machines used Vitalwerks servers so the criminals were able to control the machines - in a rather clever method to try to stay under the radar.
Meanwhile, Vitalwerks claims millions of Internet users have suffered disrupted service because of the legal proceedings. Microsoft didn't directly say Vitalwerks was involved in the cybercriminal activities, but said the company didn't do enough to prevent it.
Continue reading: Microsoft battles against malware crime groups in Algeria, Kuwait (full post)
College student faces multiple felony charges after hacking classmates
Allen Lockser, 21, faces 11 felony computer fraud charges after allegedly accessing student accounts, though didn't compromise any personal information. However, he reportedly submitted quizzes and deleted submitted homework assignments from the school network, first gaining access by trying random passwords until he was successful.
Lockser is accused of hacking into 20 student accounts on Canvas, the Pasco-Hernando State College online portal, which is used for submitting homework assignments and assessments. He was easy to track because he used the static IP address at his home, so sheriff's deputies were able to quickly identify him.
The school boosted security and students must now use passwords with a combination of letters, numbers and special characters. In addition to criminal charges, Lockser will also face a school disciplinary inquiry. After being arrested for his charges, Lockser was booked and later released on $1,100 bail.
Continue reading: College student faces multiple felony charges after hacking classmates (full post)
Cybercriminals update Pony Loader malware to steal your bitcoins
The Pony Loader malware has been updated to v2.0 and has nasty new tricks to help compromise users and steal bitcoins. The updated version is able to compromise a large group of different cryptocurrency wallets, including Litecoin, Namecoin, Terracoin, Goldcoin, Junkcoin, and Anoncoin.
To counter this new malware threat, it's recommend users update to the newest bitcoin client, which gives users a way to encrypt private keys with passphrases.
"Given the capability to steal stored credentials from a wide variety of software, users should consider storing their passwords and bitcoin private keys using these programs risky," said Isaac Palmer, Damballa malware reserve engineer, in a blog post.
Continue reading: Cybercriminals update Pony Loader malware to steal your bitcoins (full post)
Companies should be more transparent and open about data breaches
Businesses struggle to keep their data secure, but find it even harder to deal with data breaches once they already happen. Companies that try to bury their heads in the sand and keep breaches secret could be harming themselves more than anything else, and should be more transparent.
Some companies try hiding data breaches or only confirm the news after security incident details are released. That can lead to major problems from shareholders, customers, and law enforcement officials.
"It's brought it to a point now where businesses have to pay attention," said Al Pascual, Javelin Strategy & Research senior analyst, in an interview with journalists. "Before, it was more of a concern for folks in the back office. They may have had some minor concerns about regulators or government officials, but now they have to worry about being punished by their shareholders, being punished by consumers who are pretty likely not to come back or to reduce their patronage."
Continue reading: Companies should be more transparent and open about data breaches (full post)
Medical device company Medtronic compromised by data breach
Medical company Medtronic said it was breached by cyberattacks in separate incidents last year, with some patient records compromised. A number of medical records in the diabetes business unit was taken, but the company didn't disclose how many patients were affected, or what information was at risk.
Medtronic is the biggest standalone medical device maker in the world, and is a significant problem that rivals should pay attention to.
"Medtronic, along with two other large medical device manufacturers, discovered an unauthorized intrusion to our systems that was believed to originate from hackers in Asia," Medtronic confirmed in a filing to the Securities and Exchange Commission (SEC).
Continue reading: Medical device company Medtronic compromised by data breach (full post)
RIAA copyright take down notices topped 50 million sent to Google
The Record Industry Association of America (RIAA) has been busy submitting reporting pirate links for removal on Google, recently topping its 50 millionth URL. The RIAA and music studios report millions of links each month - most of them directed to Google - with the filestube.com search engine receiving two million requests alone.
Google acts quickly to remove infringing links from the massive search engine's index, but the RIAA has voiced numerous complaints about the process. It's a difficult battle to deal with for the RIAA, because foreign websites ignore takedown notices, or slightly alter the URL and go back online immediately.
Just a few months ago, the RIAA take down requests number sat at 10 million, with the trade group always scanning for online music piracy locations.
Continue reading: RIAA copyright take down notices topped 50 million sent to Google (full post)
MPAA wants to invest $20,000 for 'unbiased' piracy research reports
The Motion Picture Association of America (MPAA), the leading movie copyright group in the United States, wants to invest $20,000 in research towards an "unbiased" report focused on online piracy. Following past published reports that claimed piracy harms sales, there was a public backlash that the trade group reportedly wasn't expecting.
"We want to enlist the help of academics from around the world to provide new insight on a range of issues facing the content industry in the digital age," said Chris Dodd, former U.S. Senator and MPAA CEO, in a statement. "We need more and better research regarding the evolving role of copyright in society. The academic community can provide unbiased observations, data analysis, historical context and important revelations about how these changes are impacting the film industry and other IP-reliant sectors."
It's refreshing to hear the MPAA wants to better analyze the current state of online piracy - a shift in strategy, when just a few years ago the MPAA was hesitant to embrace online solutions. However, past efforts to crack down on piracy only led to confusing legal legislation and ineffective, costly strategies.
Continue reading: MPAA wants to invest $20,000 for 'unbiased' piracy research reports (full post)
United States most popular target of online banking malware attacks
The United States accounted for 23 percent of online banking malware attacks during the first quarter of 2014, according to security company Trend Micro's "TrendLabs 1Q 2014 Security Roundup" report. It's not a surprise to find the U.S. is the most popular target, with a growing number of malware-related bank attacks.
Joining the United States were the following countries: Japan (10 percent), India (9 percent), Brazil (7 percent), Turkey (4 percent), France, Malaysia, Mexico, Vietnam, and Australia all with three percent. Online bankers are warned to make sure they run anti-virus and anti-malware security, along with directly accessing their bank accounts - and to avoid clicking on suspicious emails.
Security experts struggle to keep up with the large volume of overly sophisticated attacks targeting their networks - and customers are increasingly finding themselves in the cross-hairs.
Continue reading: United States most popular target of online banking malware attacks (full post)
GCHQ boss attacks British media over Snowden leaks
Sir Iain Lobban, the chief of British spy agency GCHQ, has publicly attacked the Guardian over its role in publishing information leaked by ex-NSA agent Edward Snowden.
He asserted that GCHQ and its sister agencies in British intelligence are protecting the UK "despite the best efforts of some of the media." According to the Telegraph, Lobban said at the IA14 cyber security conference: "GCHQ has some world-class intellectual property but you'll understand that even in these revelatory times we really do need major parts of that to remain secret. But we are working to share where we can, including contributing it to the open source community to encourage further development."
He went on to claim GCHQ's reputation - despite the role the media has played in exposing its part in the worldwide, online surveillance dragnet - is "helping UK industry." "Allies around the world want to talk to us about cyber security and they want to do business with companies that we can vouch for," he said.
Continue reading: GCHQ boss attacks British media over Snowden leaks (full post)
Irish court raises questions on Facebook's relationship with NSA
Ireland's high court has passed a request on to the European Court of Justice to examine Facebook's compliance with data protection rules after its alleged role in providing data to the USA's National Security Agency.
Ireland's High Court has conceded it is not able to force an investigation from the country's data commissioner, which acts as watchdog to companies all across Europe. High Court Justice Gerard Hogan did say this application for review is likely to fail, as the European commission already ruled the USA has provided an "adequate level of data protection." However, the application does bring about questions on whether the EU data protection directive is in line with the EU's Charter of Fundamental Rights.
"The critical issue which arises is whether the proper interpretation of the 1995 directive and the 2000 Commission decision should be re-evaluated in the light of the subsequent entry into force of article 8 of the EU charter," Hogan said, in a statement which appeared to suggest laws were in dire need of an update for the technology age.
Continue reading: Irish court raises questions on Facebook's relationship with NSA (full post)
eBay pulls plug on Chinese-made devices with pre-installed spyware
Auction house eBay has banned the sale of smartphones from Chinese manufacturer Star, as the company's N9500 cheap Google Android-powered device ships with the Usupay.D Trojan malware pre-installed. The device tracks phone user activity and cybercriminals can remotely control and manipulate the phone, if necessary.
The only app shown running on the device is the Google Play Store icon, and the malware is completely hidden. After reports showed the phone was compromised, eBay decided to pull all sales of the Star N9500, which has become popular due to its low cost and close design to the Samsung Galaxy S4 smartphone.
"The options with this spy program are nearly unlimited," said Christian Geschkat, G DATA Product Manager of Mobile Solutions, in a press statement. "Online criminals have full access to the smartphone. G DATA customers reported a detection by our security solutions and thus alerted us to this criminal tactic."
Continue reading: eBay pulls plug on Chinese-made devices with pre-installed spyware (full post)
Growing number of apps let parents control children's smartphones
Children at younger ages are frequently using smartphones or tablets, and that has led to some problems for parents trying to limit technology use. Since 2011, children smartphone and tablet use has tripled, according to Common Sense Media, and that number is expected to only accelerate further.
The DinnerTime Parental Control app, designed for both Apple iPhones and Google Android devices, will let parents pause activity - giving children the chance to finish schoolwork, exercise, finish chores, or other activities. There also is a feature so parents are able to purchase app usage details, giving them a better look at how much time kids are using certain apps on their devices.
However, critics say parents should speak with their children about appropriate and inappropriate use of their devices - but that won't slow down the market for apps that provide parents with a better ability to limit technology use.
Continue reading: Growing number of apps let parents control children's smartphones (full post)
Healthcare industry working on stronger cybersecurity standards
The medical industry is under increasing threat of cyberattacks, with hackers compromising patient records that can be sold on the black market. Medical identity theft amounted to 43 percent of identity theft cases, according to research released earlier this year, as security experts warn of sophisticated attacks.
"Although you can't stop criminals from attempting a cyberattack, you can take several steps to reduce your risk of having your personal information stolen, misused, or deleted," according to Experiant Health. "Start by using strong passwords, avoiding malware and viruses, and protecting yourself against scams and security breaches."
Experiant urges the following practices: don't use the same password for multiple accounts; passwords should not be dictionary words; install antivirus security software; scan all drives for viruses or malware; never email personal information; and be careful not to click on links or download attachments from unknown/suspicious contacts.
Continue reading: Healthcare industry working on stronger cybersecurity standards (full post)
School ends entire reading programme over fears book promotes hacking
A US school has shut down a reading programme because it's scared a book on the reading list will encourage hacker culture.
When Little Brother, by Boing Boing blog editor Cory Doctorow, made the One School/One Book list, Florida's Booker T Washington Public High School decided it would rather cancel the programme instead of let in an allegedly subversive book.
Now Doctorow has responded in a blog post, Ars Technica reports, where he suggests the school's move is political.
Continue reading: School ends entire reading programme over fears book promotes hacking (full post)
TweetDeck back online after XSS attack caused users to RT mystery code
Tweetdeck has been compromised by an XSS vulnerability, causing some users to retweet a mysterious line of code.
At first, Tweetdeck said the vulnerability had been fixed but users later reported continuing attacks, such as the code retweets, leading to it being taken offline. It has since returned.
"We've temporarily taken TweetDeck services down to assess today's earlier security issue," the company said. "We'll update when services are back up."
Continue reading: TweetDeck back online after XSS attack caused users to RT mystery code (full post)


