Hacking, Security & Privacy - Page 45
Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 45
Stay Updated
Follow TweakTown for breaking tech news, reviews, and daily updates.
As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.
Lavabit founder explains why he shut down service after Snowden leaks
Lavabit founder Ladar Levison recently opened up about why he was forced to shutter his secure email service following the fallout of former NSA contractor Edward Snowden. The Lavabit email service had 410,000 users, Snowden included, and with Levison rejecting U.S. government access to encrypted email accounts, he was found in contempt of court.
When federal investigators wanted private encryption keys and user passwords of Lavabit users, Levison immediately rejected the idea. It only took a few weeks of legal proceedings that would ultimately lead to the company unraveling, and then eventually shuttering.
Here is what Levison said in an op-ed posted by The Guardian: " If my experience serves any purpose, it is to illustrate what most already know: courts must not be allowed to consider matters of great importance under the shroud of secrecy, lest we find ourselves summarily deprived of meaningful due process. If we allow our government to continue operating in secret, it is only a matter of time before you or a loved one find yourself in a position like I did - standing in a secret courtroom, alone, and without any of the meaningful protections that were always supposed to be the people's defense against an abuse of the state's power.
Continue reading: Lavabit founder explains why he shut down service after Snowden leaks (full post)
eBay's user records have been hacked, change your passwords ASAP
This morning, eBay announced that its internal and customer databases were compromised earlier this year. Sometime between February and March of 2014, hackers managed to compromise a number of employee accounts and were able to obtain log-in credentials that allowed them to access eBay's internal and customer databases. eBay says that the security breach remained undetected until just two weeks ago.
Customer information was stolen, and included log-in information, email addresses, encrypted passwords, physical addresses, phone numbers and date of birth information. Fortunately, the database that stores customer financial information was not compromised, and all of that information remains secure. eBay is however urging every account holder to change their passwords as soon as possible, and personally, I would suggest changing your PayPal password as well even though it was not part of the breach.
"Information security and customer data protection are of paramount importance to eBay Inc., and eBay regrets any inconvenience or concern that this password reset may cause our customers. We know our customers trust us with their information, and we take seriously our commitment to maintaining a safe, secure and trusted global marketplace," eBay said in a statement. "Beginning later today, eBay users will be notified via email, site communications and other marketing channels to change their password. In addition to asking users to change their eBay password, the company said it also is encouraging any eBay user who utilized the same password on other sites to change those passwords, too. The same password should never be used across multiple sites or accounts."
Continue reading: eBay's user records have been hacked, change your passwords ASAP (full post)
CryptoLocker increases attack levels, using spear-phishing techniques
The CryptoLocker ransomware continues to plague PC users in the United States and throughout the western world, with spear-phishing techniques now used to spread the payload. Specifically, companies with CraigsList postings that receive emails with attached files are being compromised, as CryptoLocker is infecting company executives, company owners, or human resources personnel.
CryptoLocker has proven to be extremely successful for cybercriminals, with forty percent of those affected reportedly paying the ransom. Unfortunately, simply removing the malware once it has been installed doesn't work - CryptoLocker is installed, but the encrypted files remain in control of the criminals.
Here is what Stu Sjouwerman, KnowBe4 CEO, said in a statement: "These methods pose a high risk for companies looking to hire as well as for individual Internet users. The cybergangs running these Crypto-variants will try any number of things to outdo each other and extort your hard earned money. Since the weakest point in any security model is the person who touches the keyboard, it is vital to educate users what to look for. Stepping them through effective Security Awareness Training will make them think twice before clicking on a link, or open a possibly infected attachment."
Continue reading: CryptoLocker increases attack levels, using spear-phishing techniques (full post)
McAfee announces free instant protection scan for mobile apps
In an effort to help keep mobile users more secure, McAfee today announced the newest version of the McAfee Mobile Secure program that gives Google Android users a way to check apps that use data collection techniques. There is a growing need to try and keep mobile devices secure, especially with users granting access to a wide variety of personal information when installing apps.
Around 80 percent of mobile apps used today collect user location information, 82 percent know device ID information, and 57 percent track when devices are used, according to the McAfee Consumer Mobile Security Report. After a scan is complete, users are informed regarding how much information each app accesses and shares, and ranks the apps by privacy sensitivity.
"The personal data some apps collect can be beneficial to enhancing your mobile experience, however many apps are collecting more information than they need, putting your privacy and personal security at risk," noted Gary Davis, McAfee VP of consumer marketing, in a press statement. "McAfee Mobile Security is empowering users by letting them know exactly what information their apps are accessing, and helps them safeguard their identity and personal information."
Continue reading: McAfee announces free instant protection scan for mobile apps (full post)
Symantec's Norton Small Business aims to protect SMBs from threats
Symantec has released another product designed to keep small and midsized businesses (SMBs) secure from cyberthreats, with Norton Small Business marketed for companies with less than 20 employees. The software has 100 percent virus removal assurance and a friendly user interface to make it even easier to utilize in case IT staff aren't available to lend a hand.
The Norton Small Business also has mobile security technology, providing device scanning, remote locate, locking and wiping capability to protect bring your own device (BYOD) supporters. Symantec also has the ability to scan Google Android applications to remove any malicious software, with the majority of mobile malware aimed at Android devices.
"According to the Symantec Internet Security Threat Report, small businesses were targeted in 30 percent of all cyberattacks in 2013," noted Brian Burch, Norton VP of Global Consumer and Small Business Marketing. "While the risks are real, small business owners with fewer than 20 employees often wear multiple hats and don't have the time or resources to manage IT needs. Running a small business is hard work, but Symantec wants to make securing it the easy part."
Continue reading: Symantec's Norton Small Business aims to protect SMBs from threats (full post)
New phishing scam targets Bank of America Merrill Lynch customers
Another day, another phishing scam targeting online banking users. This time around, cybercriminals are targeting Bank of America Merrill Lynch customers, tricking users to install malware designed to steal personal information. The scam email includes a PDF attachment which has a malware link that initiates a download of a "SecureMessage.zip" file - packaged with the Spyware/Win32.Zbot Trojan.
Similar to other phishing attacks, the "secure message" includes a zip file, and users open the attachment inside of a Web browser. Users end up clicking a Dropbox download link where the malware is installed - another stark reminder for Internet users to be careful when clicking links from unknown users.
One-third of phishing attacks are aimed at financial institutions, and because of the large amount of attacks, banks have to follow new guidelines to better defend against distributed denial-of-service (DDoS) attacks.
Continue reading: New phishing scam targets Bank of America Merrill Lynch customers (full post)
Kaspersky Lab helps offer basic security tips to smartphone users
Mobile security is a major effort from handset manufacturers, wireless carriers, and security companies, though many smartphone and tablet users remain blissfully unaware. A lot of users don't have any type of additional security software on their devices, or conduct activities which open themselves up to additional threats, researchers previously noted.
To help share methods on how users can keep themselves better protected, TweakTown asked Roberto Martinez, a Kaspersky Lab researcher with the Global Research and Analysis Team: "There are several ways that the users can be protected. It's recommended to not perform procedures of 'rooting' or 'jailbreaking' in devices because this eliminates protection features of the operative systems. It's also recommended to regularly update any OS and applications."
In addition to avoiding jailbreaks, there are other tips and techniques for users to avoid being compromised: "Users should be very careful with the applications that are installed in devices, especially those that are offered for free and don't come from reliable sources. Additionally, users should be careful when connecting to public Wi-Fi networks, and if applicable, use VPN tools instead. And of course, always use anti-malware and encryption protection tools."
Continue reading: Kaspersky Lab helps offer basic security tips to smartphone users (full post)
US Senate report says online advertising poses security risks
The Federal Trade Commission should be tasked with enforcing security protocols to protect Internet users from security threats posed by online advertising, according to a recent report from the Permanent Subcommittee on Investigations of the Senate's Committee on Homeland Security and Government Affairs.
"Consumers can incur malware attacks [through online ads] without having taken any action other than visiting a mainstream website," the report notes. "Similar attacks have struck across many online advertising platforms."
It seems significantly more likely for users to be infected with malware or security threats when visiting piracy websites, for example, though third-party advertisers have been hacked in the past. Malware creators are getting more creative in their efforts to compromise users, as they find many security loopholes and very little risk.
Continue reading: US Senate report says online advertising poses security risks (full post)
New phishing scam targets Google users, tries to steal passwords
Google account owners are being targeted by a new round of phishing attack, with cybercriminals targeting uniform resource identifiers (URIs) that helps display data in Google Chrome. The attack is mainly targeted at Chrome users, but has also reportedly succeeded against Mozilla Firefox users as well, according to security researchers.
The initial introduction email mimics something sent from Google, with email subjects of "New Lockout Notice" or "Mail Notice" in the subject line. The email itself is written poorly, with bad grammar and odd capitalizations, though that hasn't stopped users from being tricked due to the email.
"With access to users' Google accounts, hackers can buy apps on Google Play, hijack Google+ accounts and access confidential Google Drive documents," said Catalin Cosoi, Bitdefender chief security strategist, in a statement to Infosecurity. "The scam starts with an email allegedly sent by Google, with 'Mail Notice' or 'New Lockout Notice' as a subject."
Continue reading: New phishing scam targets Google users, tries to steal passwords (full post)
House approves USA Freedom Act amendment, showing serious reform goals
The U.S. House Judiciary Committee has voted 32-0 in approval of a modified version of the USA Freedom Act, requiring the National Security Agency (NSA) to receive approval from the Foreign Intelligence Surveillance Court before seizing phone records. The bill will now have to be approved by the House floor, and would help clamp down on ulk phone collection programs.
Despite political efforts to ensure the NSA - or any other U.S. government agency - is able to illegally collect data on citizens, privacy experts warn more legislation in the future will be needed.
The EFF had this to say: "The new version of the USA FREEDOM ACT is a strong first step to undoing the damage of the government's tortured interpretation of the PATRIOT ACT. The Judiciary Committee should be commended for moving the conversation on reforming the NSA's activities forward. We urge Congress to support this bill and to support additional privacy protections to address outstanding issues, whether through amendments or other legislative vehicles."
Continue reading: House approves USA Freedom Act amendment, showing serious reform goals (full post)
Accused UFC pirate suffers from mental illness, can't pay up fines
After learning he's the target of a $32 million lawsuit from the Ultimate Fighting Championship (UFC), accused pirate Steven Messina says he suffers from mental illness and can't afford the significant civil lawsuit. The parent company of the UFC, Zuffa, is now seeking $150,000 for every act of infringement, $110,000 for using UFC content without permission, and $60,000 for intercepting UFC content, plus legal fees.
The UFC says Messina made money from the pirated streams, though he refutes the accusation: "Most of the time I barely had enough to cover an event's cost after donations and would use my own money saved from medication and doctors. In total, I've probably made no more in a year than $450-$550 in donations. But that just helped me pay for a few months of medical expenses, as well as maybe four or five fight cards. I always ended up paying out of my own pocket though, as I've had money from my previous job saved in my checking account."
Zuffa will continue to fight against organized piracy that streams its events, especially pay-per-view fight cards, and is currently interested in targeting websites that host the events. Regardless of what happens from this outcome, there are numerous ways to illegally stream content.
Continue reading: Accused UFC pirate suffers from mental illness, can't pay up fines (full post)
Microsoft says malware infection tripled in 2013, as threats evolve
The overall number of Microsoft Windows vulnerabilities has increased 12.6 percent year-over-year, according to the Microsoft Security Intelligence Report (SIR), covering July to December 2013. During Q3 2013, 5.8 of every 1,000 Windows computers reportedly suffered from malware infection - and jumped to a whopping 17 computers per 1,000 during Q4.
However, severe Windows vulnerabilities reportedly declined 70 percent between 2010 and 2013 - as Microsoft continues to increase security - but the sophistication of current threats are giving computer security companies fits. Cybercriminals are using social engineering to get users to click on malicious links, or install malware bundled with legitimate software, the report also indicates.
Malware authors are finding a great market, in which they can launch mass attacks for a low price and little risk of being prosecuted. To make matters worse, next-generation malware is able to easily circumvent anti-virus software that traditionally kept PCs more secure.
Continue reading: Microsoft says malware infection tripled in 2013, as threats evolve (full post)
Leaked email shows close working relationship between NSA, Google
Google remains an outspoken critic of mass surveillance operations by the National Security Agency (NSA), but it appears both sides were exchanging a large amount of emails. NSA Director Gen. Keith Alexander and Google executives Sergey Brin and Eric Schmidt exchanged emails - including personal meetings and invitations to briefings and meetings.
At least one meeting, between U.S. government departments and Silicon Valley tech leaders, was focused on Enduring Security Framework - with a focus on mobile security.
Despite the emails, Google gave the Huffington Post this statement: "We work really hard to protect our users from cyberattacks and we talk to outside experts, including occasionally in the US government, to ensure we stay ahead of the game."
Continue reading: Leaked email shows close working relationship between NSA, Google (full post)
Data breach costs increasing, as companies left clueless
The average cost of a data breach to U.S. companies averaged $3.5 million and is a 15 percent increase year-over-year, according to a new study conducted by the Ponemon Institute and sponsored by IBM. Each lost record reportedly cost $201 each, an increase from $188 per record in 2013, as cybercriminals find success targeting select industries.
Not only are companies finding data breaches to be more costly, but retailers need to worry about customers possibly leaving if a security issue occurs. Everything from university and medical records to debit and credit card information have value among criminals, trying to steal information which can later be exploited, sold, or traded in underground forums.
From the Ponemon press release: "As a preventive measure, companies should consider having an incident response and crisis management plan in place. Efficient response to the breach and containment of the damage has been shown to reduce the cost of breach significantly. Other measures include having a CISO in charge and involving the company's business continuity management team in dealing with the breach."
Continue reading: Data breach costs increasing, as companies left clueless (full post)
Microsoft warns users of 'tech support' call scam
Microsoft is again warning Internet users of a sophisticated scam, with the company most notably discussing tech support scams. In this particular type of scam, a caller will be informed of an infected laptop or PC, which can be cleaned up if the user pays a "hefty fee" for service.
A scammer that ran this type of Microsoft tech support scam operation in the UK and received a four-month suspended sentence - a lenient sentence that he likely wouldn't have received in the United States - with many scammers going unchecked by law enforcement.
"What's really alarming is that this type of scam shows no signs of slowing down," Microsoft said in a blog post. "Increasingly, we hear via our frontline support team, and even from friends and family, that these scammers are getting bolder, targeting not only individuals but also businesses. It is appalling that they're taking advantage of your trust in Microsoft in an attempt to steal your money. It's immoral, it's disrespectful and it's certainly illegal."
Continue reading: Microsoft warns users of 'tech support' call scam (full post)
UFC targets Internet pirate with massive $32 million lawsuit
The Ultimate Fighting Championship (UFC), currently the No. 1 mixed martial arts (MMA) promotion in the world, has sued an alleged Internet pirate, seeking $32 million in damages. Steven Messina, 27, is accused of uploading 141 UFC pay-per-view (PPV) events to The Pirate Bay and other online websites - and even included a PayPal donation link for his troubles.
Messina was able to operate below the radar until he started claiming to be the "Provider of Best MMA & Boxing rips online!," which is when the UFC began to take notice.
UFC President Dana White has talked sternly against Internet piracy, and seems ready to share the same Draconian approach that music and movie copyright holders held years ago. However, people trying to monetize on pirated PPV events should expect to be busted eventually, especially if their operation continues to grow at a rapid pace.
Continue reading: UFC targets Internet pirate with massive $32 million lawsuit (full post)
Want some malware? Visit a piracy website and have fun, report says
Research indicates a whopping 90 percent of the top 30 most visited Internet piracy websites in the United Kingdom contained some form of malware or "Potentially Unwanted Programs" (PUPs) to compromise user systems.
The piracy sites often rely on social engineering techniques to trick users into clicking fraudulent links: "These fake play buttons, and that sort of thing, are very much driven by the desire of people to download content," said according to the group. "We view it as a kind of social engineering attack on the users who are tricked into downloading stuff."
In an ongoing effort to combat piracy, copyright holders might have more success trying to inform users of the security threats they open themselves up to when downloading content - it would be a unique twist on sometimes rudimentary scare tactics.
Continue reading: Want some malware? Visit a piracy website and have fun, report says (full post)
Russian sanctions might lead to increased cyberattacks against U.S
United States security officials are concerned that Russian-based hackers could retaliate for stricter sanctions, launching cyberattacks against the U.S. government and large corporations. Whether directly from the Russian government, or splinter support groups, there will continue to be an increased urgency to defend US infrastructure from foreign attack.
"A cyberattack is a real concern that we all need to have," said Paul Smocer, head of the industry Financial Services Roundtable, in a statement to the press. "Nation states' ability to launch the cyberattacks is certainly real nowadays, and so in any conflict, I think that the possibility exists as we worry about escalation."
The political situation between Russia and Ukraine already has led to cyberattacks, with the Kremlin being attacked in retaliation for targeted attacks against Ukrainian infrastructure. Unfortunately, the U.S. Department of Homeland Security has greatly struggled to try and recruit cybersecurity experts, while other government branches have voiced similar concerns.
Continue reading: Russian sanctions might lead to increased cyberattacks against U.S (full post)
McAfee: Online gambling provides method to commit money laundering
An increase in the popularity of online gambling has created a successful underground market for money laundering, according to a new McAfee study.
To make matters worse, Internet anonymity and such a wide variety of payment options gives criminals the chance to exchange stolen funds, bitcoins, and currency.
"As a result, illegal proceeds can be laundered by wagering them on one end of a transaction and receiving the payouts as gambling wins on the other end," according to the McAfee report. "Gambling wins can also be exchanged as payment for illegal goods or services changing hands elsewhere."
Continue reading: McAfee: Online gambling provides method to commit money laundering (full post)
Boston Children's Hospital website targeted by cyberattackers
The Boston Children's Hospital was recently targeted in a wave of cyberattacks trying to bring down its website, though cybercriminals were unsuccessful, and no patient data was taken in the attempted breach.
"Over the weekend and through today, Boston Children's Hospital's website has been the target of multiple attacks designed to bring down the site by overwhelming capacity," said Rob Graham, hospital spokesperson, in a statement.
Hospital officials have reported police authorities and an investigation is currently underway - no hacker or hacker groups have stepped forward to take credit for the attempted breach.
Continue reading: Boston Children's Hospital website targeted by cyberattackers (full post)


