Newsletter IconFacebook IconX IconThreads IconInstagram IconYouTube IconPinterest Icon
Giveaway: AVerMedia Creator Bundle (4K Webcam, Capture Card, Charging Hub, and Mouse Pad)

Hacking, Security & Privacy - Page 44

Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 44

Stay Updated

Follow TweakTown for breaking tech news, reviews, and daily updates.

Add TweakTown as a preferred source on GoogleFind TweakTown on Apple News

As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.

P.F. Chang's restaurant latest to be hit by data breach

| Jun 11, 2014 1:00 PM CDT

Popular restaurant P.F. Chang's reportedly suffered a data breach and customer debit and credit card information is at risk, the restaurant chain recently confirmed. The information was stolen between March and May, however, it's uncertain how many of the restaurant's locations have been affected in the breach.

Law enforcement and financial institutions have contacted P.F. Chang's and a full investigation is currently underway.

"P.F. Chang's takes these matters very seriously and is currently investigating the situation, working with the authorities to learn more," said Anne Deanovic, P.F. Chang's spokesperson, said in a statement. "We will provide an update as soon as we have additional information."

Continue reading: P.F. Chang's restaurant latest to be hit by data breach (full post)

Anonymous plans to attack World Cup sponsors with cyberattacks

| Jun 9, 2014 12:40 PM CDT

The hacker collective Anonymous is preparing to attack World Cup 2014 sponsors, in response to the Brazilian government spending outlandish amounts of money to prepare for the soccer tournament. It is unknown which specific companies will be hit, but World Sponsor companies include Adidas, Coca-Cola, Emirates Aireline, and Budweiser.

"We have already conducted late-night tests to see which of the sites are more vulnerable," a hacker known as "Che Commodore" told Reuters. "We have a plan of attack. This time we are targeting the sponsors of the World Cup."

The hacker group has already hit the Brazilian Foreign Ministry, compromising at least three hundred documents before the email system was shut down. A phishing attack was used to compromised the ministry, but cyberattacks on World Cup sponsors will likely rely on distributed denial-of-service (DDoS) attacks.

Continue reading: Anonymous plans to attack World Cup sponsors with cyberattacks (full post)

U.S. government warns of traffic-sign hackers, as incidents increase

| Jun 7, 2014 12:15 PM CDT

After a few road signs were hacked, the government is warning cities and highway operators using signs manufactured by Daktronics of possible cyberattacks. The United States Department of Homeland Security Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) released a statement saying operators should prepare "defensive measures" against these types of attacks. The ICS-CERT team said hackers have published a guide on how to compromise Daktronics systems to alter the normal message.

"CIS believes it is likely that a small percent of Watch Dog players will experiment with compromising computers and electronic systems outside of game play," according to a recent report from the Center for Internet Strategy (CIS).

Years ago, vandals would write messages such as, "Warning, Zombies Ahead!" on road signs - and only small number of incidents have been reported. However, authorities were immediately concerned, because changing road signs can be a serious public safety issue, and the signs often help drivers deal with possible traffic and road issues.

Continue reading: U.S. government warns of traffic-sign hackers, as incidents increase (full post)

Microsoft warns against registry hack to update Windows XP

| Jun 7, 2014 11:25 AM CDT

Current Microsoft Windows XP users making tweaks to the registry to receive support for XP until April 9, 2019 was quickly discovered by Microsoft. A registry hack is available for both the 32-bit and 64-bit copies of XP, though Microsoft and security experts still recommend migrating to Windows 7 or 8/8.1.

The registry hack tricks traditional desktop versions of Windows XP into thinking it's really a copy of Windows Embedded POSReady 2009, a version of Windows designed for point-of-sale machines. However, Microsoft warns the security update won't make XP fully secure, and it's still advisable to upgrade to a newer OS.

"We recently became aware of a hack that purportedly aims to provide security updates to Windows XP customers," a Microsoft statement said. " The security updates that could be installed are intended for Windows Embedded and Windows Server 2003 customers and do not fully protect Windows XP customers. Windows XP customers also run a significant risk of functionality issues with their machines if they install these updates, as they are not tested against Windows XP."

Continue reading: Microsoft warns against registry hack to update Windows XP (full post)

KnowBe4 promises to pay ransoms if employees get compromised

| Jun 6, 2014 11:22 PM CDT

Security firm KnowBe4 is so confident that its Kevin Mitnick Security Awareness series is so beneficial, the company will pay a ransom if a client is compromised due to employee error. The new generations of ransomware typically can slip by traditional anti-virus software, and end-users are responsible for accidentally installing software on work PCs. The security awareness training is ongoing and the KnowBe4 offer to pay ransoms via bitcoin is valid until June 30.

"Many employees take work home and access the network on personal laptops or devices shared with family members," said Stu Sjouwerman, KnowBe4 CEO, in a statement. " KnowBe4 recognizes the need to help users stay secure in a variety of environments and we offer our clients a separate Home Internet Security Course for their whole family as an extra bonus. We are so confident our training works, we'll pay your ransom in Bitcoin if you get hit with ransomware while you are a customer and your employees stepped through our training."

It's a bold decision by KnowBe4, as 234,000 people have been hit with some type of ransomware, such as CryptoLocker, CryptoDefense or CryptoBit, according to the FBI. These data breaches led to $20 million in ransom fees during a four-month span in 2013 alone, according to the report.

Continue reading: KnowBe4 promises to pay ransoms if employees get compromised (full post)

Kaspersky Lab outlines major phishing threat facing companies in April

| Jun 6, 2014 3:20 PM CDT

Cybercriminals trying to compromise users continued to find new and innovative ways to target unsuspecting users in April, launching malicious attachments and conducting well-coordinated phishing attacks, according to security company Kaspersky Lab.

Email and search engines were the most popular targets, accounting for 31.9 percent of attacks, with social media in second with 23.8 percent, and financial and payment organizations slotted in third with 13 percent. The most notable target in April was Chinese telecommunications company Tencent, with criminals seizing user logins and passwords.

"Last month, we saw a new wave of so-called pump and dump spam," said Tatyana Shcherbakova, Kaspersky Lab Senior Spam Analyst, in a press statement. " The scammers behind these mailings advertised offers to buy stock in a certain company at super low prices, which were allegedly meant to increase considerably in the near future. As a result, the demand for the stock in the company rose, the prices became artificially inflated - and the scammers would then sell off their stock in said company. The stock prices would then begin to fall, and the bamboozled investors were left with depreciated shares and lost their investments."

Continue reading: Kaspersky Lab outlines major phishing threat facing companies in April (full post)

Simplelocker ransomware targets Android, encrypts your SD card

| Jun 5, 2014 1:49 PM CDT

A recently discovered Trojan targeting Google Android turns out to be a nasty piece of ransomware, encrypting files on a compromised user's device. The Android/Simplelocker ransomware demands a small payment of about $22 in that must be paid to the Eastern European cybercriminals behind the malicious software.

The Trojan scans for the following file formats on a phone's SD card: jpeg, jpg, png, bmp, gif, pdf, doc, docx, txt, avi, mkv, 3gp, mp4, which will be encrypted and made inaccessible.

"File-encrypting malware has proved to be a lucrative criminal enterprise so it is unsurprising that Android has become a new target," said Dr. Steven Murdoch, University of Cambridge security researcher, in a statement. "Smartphone users should be very cautious of installing software from sources other than the operating system-provided application store, and should pressure their phone supplier to promptly provide security updates to defend against known vulnerabilities."

Continue reading: Simplelocker ransomware targets Android, encrypts your SD card (full post)

Privacy campaigner creates Google Glass jamming device

| Jun 4, 2014 8:11 PM CDT

A privacy campaigner for "Stop The Cyborgs" has come up with a novel way to prevent being recorded by a Google Glass wearing Glasshole - a simple program that knows when Glass is being used and prevents it from connecting to a network.

The program will no doubt be to the chagrin of the Valley's Glass-wearing enthusiasts, as it prevents it from connecting to the cloud completely. But Stop The Cyborg's Julian Oliver claims it's a hassle-free approach to gaining some privacy in public places.

"To say 'I don't want to be filmed' at a restaurant or playing with your kids is perfectly OK," he said, speaking with Wired. "But how do you do that when you don't even know if a device is recording? This steps up the game. It's taking a jammer-like approach."

Continue reading: Privacy campaigner creates Google Glass jamming device (full post)

NCA claims UK has just two weeks to prepare for Cryptolocker onslaught

| Jun 2, 2014 8:39 PM CDT

Britain's National Crime Agency has taken the unusual step of posting an "urgent alert" for UK netizens - claiming they have "two weeks" to protect against an impending surge of botnet activity, by way of the GoZeuS and Cryptolocker malware.

Through Get Safe Online - the official British web safety group - the organization warned in conjunction with American authorities that this upcoming onslaught is part of "one of the largest industry and law enforcement collaborations attempted to date".

It's thought that pretty much everyone running any kind of Windows OS is at risk. According to the NCA, GoZeuS - AKA Gameover ZeuS - has already pocketed hundreds of millions the world over. What's next is a massive worldwide lockdown using CryptoLocker as ransomware. In fact, according to a recent study, as many as 40 percent of those hit by the ransomware pay the fee.

Continue reading: NCA claims UK has just two weeks to prepare for Cryptolocker onslaught (full post)

Reddit, others pledge support for anti-NSA Reset The Net campaign

| Jun 2, 2014 7:04 PM CDT

Major websites such as Reddit, Imgur and DuckDuckGo are to take part in the June 5 "Reset The Net" anti-NSA spying online campaign.

They have pledged their support for the day, backed by household-name nonprofits like Amnesty International and Greenpeace, and look like they will promote the effort by offering a splash screen and a push notification that sends users towards a mobile privacy pack. Website owners are being encouraged to begin folding encryption such as SSL, HSTS and PFS into their websites, with a view to making collecting user data more difficult.

The underlying message of the campaign, as described on the official website, is not to "ask for your privacy" but to "take it back".

Continue reading: Reddit, others pledge support for anti-NSA Reset The Net campaign (full post)

After Heartbleed, 'Cupid' could hit Wi-Fi routers & Android devices

| May 30, 2014 7:27 PM CDT

Weeks after it became evident Heartbleed was one of the biggest security threats to the internet ever, one security researcher has released a proof of concept that could deploy the same vulnerability over Wi-Fi.

Luis Grangeia has called his concept 'Cupid', and it would operate in a similar way to Heartbleed. But rather than being hidden on the web, it would run over Wi-Fi and take data from routers or Android devices. Android Jelly Bean 4.1.1 devices are particularly vulnerable.

There's not quite cause for panic over this vulnerability just yet, as although there's a proof of concept the attack would have to be carried out over Wi-Fi range, which would limit potential targets, the Verge reports.

Continue reading: After Heartbleed, 'Cupid' could hit Wi-Fi routers & Android devices (full post)

Wireless payments struggle, as near field communication interest grows

| May 30, 2014 6:45 PM CDT

Near Field Communication (NFC) is common in Europe and Asia, but still has struggled to gain mainstream acceptance in the United States. Security remains a major concern, but continued growth in trusted service management (TSM) provides companies interested in wireless payments the opportunity to become more inventive. The TSM market is expected to jump from $280 million in 2014 up to $550 million in 2015, according to Frost & Sullivan, as more vendors utilize it for NFC-related transactions.

Almost 25 percent of U.S. consumers will carry a smartphone with NFC technology by 2016, according to Forrester Research, which will give banks, credit card companies, and payment startups a unique opportunity.

Moving forward, phone manufacturers are expected to embrace NFC built directly into new smartphones, as the technology becomes more common place in the United States. Apple has rejected NFC for quite some time now, though that could change with the iPhone 6, according to reports.

Continue reading: Wireless payments struggle, as near field communication interest grows (full post)

Whopping 47% of Americans have been hit by hackers in past 12 months

| May 30, 2014 3:46 PM CDT

Hackers have successfully compromised around 110 million Americans in the past 12 months alone, nearly half of all adults in the country, as companies struggle to keep up with growing cyber threats. It's hard to identify exact numbers, with larger companies not providing precise data of affected users following a large-scale data breach.

The compromised information typically includes various forms of personal information, including names, addresses, phone numbers, Social Security numbers, debit and credit card information, or bank account numbers. Companies such as Target and eBay suffered massive data breaches, while other companies are compromised to a smaller degree.

Collecting a lot of information about an individual is more valuable [for attackers]," said Larry Ponemon, Ponemon Institute head, in a statement to SCMagazine. "They'll take the data, and wait patiently. Then, two or three years after the breach, [the impacted] become the victim of identity theft."

Continue reading: Whopping 47% of Americans have been hit by hackers in past 12 months (full post)

TrueCrypt reportedly developers jump ship, free tool reportedly done

| May 30, 2014 3:16 PM CDT

The open source and free TrueCrypt full-disk encryption project is likely over after developers jumped ship, abruptly ending what was a popular asset for PC users. There are rumors circulating that TrueCrypt was compromised, though that hasn't been confirmed and still seems rather unlikely at this point in time.

In what was a rather cheeky way to throw in the towel, the truecrypt.org website redirects users to sourceforge.net, and current TrueCrypt users are being transitioned to BitLocker. This message also was posted:

"WARNING: Using TrueCrypt is not secure as it may contain unfixed security issues" -

Continue reading: TrueCrypt reportedly developers jump ship, free tool reportedly done (full post)

Owner and operator of BlackShades pleads not guilty, faces 15 years

| May 30, 2014 12:17 AM CDT

The owner and operator of BlackShades has plead not guilty to computer hacking charges, for his role in selling malware software. Alex Yucel, 24, was arrested last November and extradited to the United States, and now faces up to 15 years if convicted of conspiring to commit access device fraud and access to device fraud, among other charges.

The group reportedly sold its Remote Access Tool (RAT) to thousands of customers across the world since 2010, authorities noted.

Recently, authorities announced 100 people have been arrested in multiple countries for their participation in BlackShades. Federal authorities are trying to clamp down on cybercrime groups, though tend to only make arrests following major incidents - and have been largely unable to stop groups before they compromise users.

Continue reading: Owner and operator of BlackShades pleads not guilty, faces 15 years (full post)

FireEye suggests link between malware growth and Ukraine conflict

| May 29, 2014 2:02 PM CDT

As the situation grew more tense in the Ukraine and Russia over the annexing of Crimea, so did malicious activity between the two states in cyberspace.

According to a new report from security company FireEye, malware "callbacks" - where communications from compromised machines go back to the attacker's first stage server- increased dramatically over the period. Although the reasons cannot be known for sure, FireEye says it sees a "likely correlation" between the number of callbacks to Russia and Ukraine and the intensification of the crisis.

For 2013, Russia was seventh place in the amount of malware callbacks but in March 2014 it jumped to third place - at the same time its parliament authorized the use of force in Ukraine and Putin incorporated Crimea into the Russian Federation.

Continue reading: FireEye suggests link between malware growth and Ukraine conflict (full post)

Most data breach victims located in the U.S., Trustwave finds

| May 24, 2014 12:50 PM CDT

The United States had 59 percent of cybercrime victims, a whopping lead over the United Kingdom at 14 percent and Australia in third with 11 percent, according to security firm Trustwave. Cybercriminals are making big money with successful data breaches, as customer information and medical records generating lucrative amounts on the black market.

Retail stores also tend to be attacked the most, with 35 percent of overall attacks investigated by Trustwave during 2013. The food and beverage industry was second with 18 percent and hospitality had just 11 percent of the overall number of attacks. In addition to traditional cyberattacks, retailers need to pay closer attention to sophisticated point-of-sale attacks targeting in-store technologies.

"Security is a process that involves foresight, manpower, advanced skillsets, threat intelligence and technologies," noted Robert McCullen, Trustwave CEO, in a press statement. "If businesses are not fully equipped with all of these components, they are only increasing their chances of being the next data breach victim. As we have seen in our investigations, breaches are going to happen. However, the more information businesses can arm themselves with regarding who are their potential attackers, what those criminals are after and how their team will identify, react and remediate a breach if it does occur, is key to protecting their data, users and overall business."

Continue reading: Most data breach victims located in the U.S., Trustwave finds (full post)

Improving cybersecurity still likely won't be a company priority

| May 23, 2014 2:17 PM CDT

Even though companies are becoming increasingly aware of cyberattacks and the rising threat they pose, many decision makers are hesitant to spend money to improve security - until a data breach or theft occurs. If an attack doesn't lead to massive financial losses, cybersecurity experts warn, cyberattacks are still being shrugged off. Unfortunately, companies don't think the cost of building a stronger cybersecurity defense is a worthwhile expense, instead focusing on more pressing business matters.

"Until it hits them at home, it won't matter much," said Scott Goldman, security company TExtPower CEO, in a statement. "The very fact that people are becoming numb to the constant stream of breaches indicates the pathetic level of security provided by most online services."

U.S. defense contractor Lockheed Martin said the attacks it faces has quadrupled since 2007, and public utilities also are being caught up in the chaos. Security typically won't lead to increased revenue or profit, and despite looming cyberthreats, it will continue to take a major incident before change is made.

Continue reading: Improving cybersecurity still likely won't be a company priority (full post)

University of California, Irvine breached, student information at risk

| May 22, 2014 5:08 PM CDT

The University of California, Irvine student health center was reportedly compromised, with a form of keylogger malware running for at least six weeks. In the breach, student ID numbers, contact information and bank numbers of up to 1,800 students and a small number of others at risk, according to UC Irvine spokespeople.

No UC Irvine medical records were compromised, with the malware operating from February 14 to March 27, according to officials.

Universities are having a hard time trying to keep their networks secure, with cybercriminals finding large amounts of information that is increasingly easy to compromise. The University of Pittsburgh Medical Center was recently hit by a data breach, while Iowa State University also suffered a data breach as criminals tried to mine for bitcoins. University of California at San Francisco also suffered a breach, and University of Hawaii officials are warning of increasingly clever phishing attacks.

Continue reading: University of California, Irvine breached, student information at risk (full post)

Company CEOs need to pay closer attention to cybersecurity

| May 21, 2014 7:14 PM CDT

More companies face cyberattacks and potential data theft, with many C-level executives unsure how to combat these types of growing threats. CEOs should be extremely proactive to try and prevent cyberattacks, which will help protect employee and customer data from theft.

CEOs should try to join an information-sharing organization, with additional cybersecurity-focused groups starting, and run security audits. It's also important - yet typically overlooked - to monitor what access third-party vendors have, especially when it comes to sensitive information.

As popular retailer Target learned, a massive data breach can have a major ripple effect for future business efforts. Former Target CEO Gregg Steinhafel resigned just five months after the data breach, while the company also shuffled its IT team around.

Continue reading: Company CEOs need to pay closer attention to cybersecurity (full post)

Join Our Newsletter

Join the TweakTown Newsletter for daily tech updates delivered to your inbox.

See previous giveaways.

Newsletter Subscription