Hacking, Security & Privacy - Page 46
Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 46
Stay Updated
Follow TweakTown for breaking tech news, reviews, and daily updates.
As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.
Multi-state tax scam aimed at medical professionals causing headaches
Medical professionals have become victims of identity theft, with Social Security Numbers and other personal information used to help process fraudulent tax returns, according to recent reports. The victims, less than 1,000 total so far, didn't know about the breach until they tried to file their returns and found that someone else already had beaten them to the punch.
Victims were found in the following states: Colorado, Connecticut, Vermont, Massachusetts, Iowa, North Carolina, South Dakota, Maine, Indiana, and New Hampshire. The Indiana State Medical Association (ISMA) sent a memo to healthcare professionals in the state to be aware of the tax scam.
"The DOR is viewing this as a large problem and officials are very concerned," said Julie Reed, ISMA general council, during a recent conversation. "While their investigation has not yet identified the source of the presumed breach, they are tracking all the cases, looking for patterns, and actively investigating and pursuing leads."
Continue reading: Multi-state tax scam aimed at medical professionals causing headaches (full post)
Retail stores can use NEC technology to conduct facial recognition
NEC Hong Kong is currently developing a new facial recognition technology that can be used by stores, hotels, and other retail establishments to quickly identify customers. Retailers have tried to use smartphones to help monitor customer activity, especially if guests log onto free, open Wi-Fi hotspots, though customers found ways to disable such features.
When most people think of facial recognition, it's in regards to security and possible privacy issues - but NEC and companies have a more unique reasoning behind why stores, hotels, and other establishments might want to adopt the technology:
"Everyone loves to feel special. That's why any organization that can greet a customer by name and start helping them the minute they walk in to a shop, bank or hotel will have a tremendous advantage over one that relies on ID cards or other impersonal procedures," said Elsa Wong, NEC Hong Kong Managing Director, in a press statement.
Continue reading: Retail stores can use NEC technology to conduct facial recognition (full post)
Avast survey finds 27 percent of users don't plan to leave XP
More than one-quarter of Avast's current Microsoft Windows XP customers don't plan to leave behind the OS that is now no longer supported by Microsoft, according to a recent survey conducted by the security company.
Prior to the end of support date on April 8, XP users were already under increased threat of cyberattacks, and that trend is only expected to continue.
"XP users were not planning on doing anything," said Ondrej Vlcek, Avast Chief Operating Officer, in a blog post. "As Avast users they are protecting themselves since we will continue to support Windows XP users for at least the next three years."
Continue reading: Avast survey finds 27 percent of users don't plan to leave XP (full post)
IRS missed Windows XP deadline, pays millions to Microsoft for support
The US Internal Revenue Service (IRS) didn't migrate from Microsoft Windows XP before the April 8 end of support deadline, and will pay millions to Microsoft for extended support.
Microsoft pulled the plug on its popular 13-year-old operating system, urging users to migrate to Windows 7 or 8/8.1. However, millions of PCs are still running XP and haven't been migrated, including many business PCs.
"Now we find out that you've been struggling to come up with $30 million to finish migrating to Windows 7, even though Microsoft announced in 2008 that it would stop supporting Windows XP past 2014," said Rep. Ander Crenshaw (R-Fla), chairman of the House Financial Services and General Government subcommittee, in a statement. "I know you probably wish you'd already done that."
Continue reading: IRS missed Windows XP deadline, pays millions to Microsoft for support (full post)
Leading website compromised, turns users into "DDoS zombies"
A major global website was recently hit by cybercriminals, with the hacked website turning visitors into "zombies" that in turn launched distributed denial of service (DDoS) attacks. A Persistent XSS vulnerability gave cybercriminals the chance to embed malicious JavaScript code, according to enterprise security company Incapsula.
Each user that views a compromised profile image with the malicious code then ends up sending a GET request to targeted websites. The group responsible also posted comments on large quantities of other videos, to ensure the profile image was viewed as many times as possible.
"As a result, each time a legitimate visitor landed on that page, his browser automatically executed the injected JavaScript, which in turn injected a hidden according to Incapsula. "Obviously one request per second is not a lot. However, when dealing with video content of 10, 20 and 30 minutes in length, and with thousands views every minute, the attack can quickly become very large and extremely dangerous."
Continue reading: Leading website compromised, turns users into "DDoS zombies" (full post)
Avast: Smartphone owners are too careless about security
Smartphone users face a growing list of security problems, and many of them are simply ignoring the risks, according to a recent study completed by security company Avast.
Men are more likely than women to face vulnerabilities on their smartphones, 36 percent compared to 32 percent, with more than one-third surveyed saying they don't use any type of anti-theft or security software.
"The findings suggest an ongoing disconnect people have with their phone and computer when it comes to security protection," Avast said in a blog post. "Many smartphone users have not yet grown accustomed to thinking of their devices as small computers that store valuable, sensitive, and often priceless data. One can now perform the same functions on their phone as the trust PC or laptop, but the majority of people are still learning about the necessary to protect their phones from viruses and hacking."
Continue reading: Avast: Smartphone owners are too careless about security (full post)
KnowBe4: Ransomware threats goes beyond just Cryptolocker
Ransomware is becoming a major business for cybercriminals, and users can expect sophisticated attacks that go beyond just Cryptolocker, according to Web security company KnowBe4.
Cybercriminals are developing next-generation malware designed to infect users and steal information, or hijack the computer with ransom demands to unlock affected machines.
"There is furious competition between cybergangs," said Stu Sjouwerman, KnowBe4 CEO, in a press statement. "They did their test-marketing in countries like the UK, Canada and Australia and are now targeting the US. CryptoDefense doesn't seem to be a derivative of CryptoLocker as the code is completely different, confirming this is a competing criminal gang."
Continue reading: KnowBe4: Ransomware threats goes beyond just Cryptolocker (full post)
EFF urges websites to use HSTS protocol to be more secure
Not enough websites and Internet browsers utilize the HTTP Strict Transport Security (HSTS) policy to keep Internet users secure, according to the Electronic Frontier Foundation (EFF).
HSTS forces encryption by opening HTTPS sessions instead of just HTTP, so information to and from the website is encrypted. Using HSTS, websites never allow Internet users to interact with an HTTP session, with everything automatically converted.
The EFF believes not enough web developers know about HSTS, while browser support has also only increased slowly but surely. Google Chrome, Mozilla Firefox, and Opera have long-supported HSTS, while Microsoft said it will use the Web standard with Internet Explorer 12.
Continue reading: EFF urges websites to use HSTS protocol to be more secure (full post)
Music copyright holders sue Russian social networking site for piracy
The top social media network in Russia is now being sued by Sony Music, Warner Music and Universal Music, with vKontakte accused of "deliberately facilitating piracy on a large scale."
Each of the top three music labels filed individual suits against vKontakte, spearheaded by the International Federation of the Phonographic Industry (IFPI). In 2012, the social media site made $172 million in advertising revenue, but didn't pay the IFPI for copyrighted music shared through the site.
vKontakte says it allows copyright holders to submit removal requests of any content that violates copyright rules, but IFPI officials noted the process is too cumbersome. Both the US government and copyright holders have believed vKontakte provides large-scale music piracy - originally launched in 2006, vKontakte has 143 million global users, and 88 million Russian members.
Continue reading: Music copyright holders sue Russian social networking site for piracy (full post)
Two US men plead guilty for their role in global hacking operation
Two members of an international cybercrime, identity theft and credit card fraud ring pleaded guilty to one count of wire fraud conspiracy and one count of conspiracy to commit access device fraud and identity theft, the Department of Justice announced.
Robert Dubuc, 40, from Massachusetts along with Oleg Pidtergerya, 49, of New York, used information stolen from more than 12 banks, payroll processing companies, brokerage firms and government agencies - in their effort, more than $15 million in funds have been reportedly stolen.
"Both Dubuc and Pidtergerya were asked by leaders of the conspiracy to participate in a scheme to 'cash out' bank accounts and pre-paid debit cards opened in the names of others," according to the DoJ press release.
Continue reading: Two US men plead guilty for their role in global hacking operation (full post)
Feds, local law enforcement increasingly able to bust Tor users
Prior to former contractor Edward Snowden disclosing the NSA's mass surveillance efforts, many people turned to the Tor Web browser for anonymous Internet searching. However, the free and popular tool is no longer as secure, with law enforcement agencies also able to identify users they suspect of criminal activities.
"There's not a magic way to trace people [through Tor], so we typically capitalize on human error, looking for whatever clues people leave in their wake," said James Kilpatrick, Homeland Security Investigations agent, in a statement.
It was only a few years ago when law enforcement and federal agencies believed they couldn't crack Tor, but multi-agency efforts led to better data collection and social engineering patterns.
Continue reading: Feds, local law enforcement increasingly able to bust Tor users (full post)
Pentagon expands its effort to recruit workers for cyber defense roles
The United States military is boosting its cyber capabilities as the Defense Department has almost 1,800 employees as part of its Cyber Mission Force. By the end of 2016, that staffing figure is expected to increase up to 6,000 before the end of 2016, while the US government continues to support in cyberattacks.
To try and increase the staffing level in such a short amount of time, military officials hope to recruit current military personnel - Silicon Valley cybersecurity specialists are unlikely to leave behind high-paying jobs to join the government's new programs.
"We spent a lot of time in the last two years in particular figuring out what the [recruiting] model would be,"a senior defense official recently told reporters. "Initially sometimes people will think about recruiting highly skilled people from the outside, and that is one option... but quite honestly, the way we're going to be most successful is using people within the force [including those with no cyber background] and giving them the training."
Continue reading: Pentagon expands its effort to recruit workers for cyber defense roles (full post)
Banks withdraw from class-action lawsuit against Trustwave
Less than one week after two banks hit Target and credit card security service company Trustwave with a class-action lawsuit, the banks have pulled the lawsuit.
It seems Trustwave was inaccurately noted as a Target IT security contractor, which doesn't appear true - interestingly, the class-action lawsuit aims to try and expand responsibility of the data breach away from just Target.
"Contrary to the misstated allegations in the plaintiffs' complaints, Target did not outsource its data security or IT obligations to Trustwave," said Robert McCullen, Trustwave CEO, in a public statement. "Trustwave did not monitor Target's network, nor did Trustwave process cardholder data for Target."
Continue reading: Banks withdraw from class-action lawsuit against Trustwave (full post)
Medical identity theft amounted to 43% of identity theft cases in 2013
A rather shocking 43 percent of identity theft cases last year can be traced back to medical identity theft, as security experts and healthcare providers struggle to keep up with security challenges, according to a recent study.
Unfortunately, medical records are significantly more lucrative to cybercriminals, meaning it's a popular target for attacks.
"Despite concerns about employee negligence and the use of insecure mobile, 88 percent of organizations permit employees and medical staff to use their own mobile devices such as smartphones or tablets to connect to their organization's networks or enterprise systems such as email," according to the Ponemon Institute's Fourth Annual Patient Privacy and Data Security report.
Continue reading: Medical identity theft amounted to 43% of identity theft cases in 2013 (full post)
Report says 97% of mobile malware is targeting Android devices
Android had a greatly successful year in 2013, capturing around 87 percent of the international smartphone market - but during the same year, the Android community had to deal with a large amount of malware and security threats.
Ninety-seven percent of current mobile malware targets Android, and users will continue to face a large amount of threats moving forward.
Security company F-Secure recommends sticking to the Google Play Store to download apps, as one in every 1,000 apps might have had malware - while purchasing or downloading apps from other sources can easily lead to malware infection.
Continue reading: Report says 97% of mobile malware is targeting Android devices (full post)
Malware drains your battery and helps bad guys mine for cryptocurrency
The "Coinkrypt" malware is making its rounds, infecting Google Android devices, letting cybercriminals mine Litecoin, Casinocoin and Dogecoin courtesy of hijacked devices.
Most malware today is designed to either steal information or create some type of financial incentive for criminals - and Coinkrypt follows that same strategy, but with a rather unique twist.
Although it isn't prevalent at the moment, security researchers want users to be aware of the potential ramifications if they are infected - including potentially causing batteries to drain faster - or eventually leads to overheating.
Continue reading: Malware drains your battery and helps bad guys mine for cryptocurrency (full post)
Fareit Windows trojan also loads nasty piece of ransomware on PCs
In a double whammy, the Fareit Trojan targeting Microsoft Windows PCs also has been found to spread the Cribit ransomware, as security researchers transition to defend against sophisticated cyber threats.
There are two versions of Cribit in the wild - one version encrypts files on the infected PC and shows an English ransom, while the other version has messages also available in Chinese, French, Arabic and Spanish, researchers note.
"After all, cybercriminals are after one goal: to get a person's money," said Christopher Budd, Trend Micro threat communications manager, in a statement to SC Magazine. "Returning/decrypting a victim's files won't certainly be a priority or major concern for these people. Additionally, paying the ransom may encourage and help expand the operations of cybercriminals."
Continue reading: Fareit Windows trojan also loads nasty piece of ransomware on PCs (full post)
Microsoft charges the government up to $15,600 for your personal info
We all know by now that the FBI, CIA and NSA request information on us from big tech giants such as Apple, Microsoft, Facebook and Google, but did you know that Microsoft sends a massive invoice every time it gives away your private information? A newly released document shows that at least in one incident, Microsoft billed the government as much as $15,600 for information that was requested.
The Syrian Electronic Army hacker group has just leaked details that show Microsoft billing the US government more than $350,000 on September 5th of 2013. The invoice appears to show that more than 78 invoices for request were sent to the government, with the highest being shown set at a whopping $15,600.00.
The government agency in question is the FBI's Digital Intercept Technology Unit. The leaked documents show that Microsoft was billing the FBI more than $100,000 per month on average between 2012 and 2013, and that each individual request cost the FBI $100 during 2012 and into 2013 until Microsoft raised the price to $200 per request.
Continue reading: Microsoft charges the government up to $15,600 for your personal info (full post)
Android corruption bug frightening security researchers
The recent Google Android bug discovered by security researcher Ibrahim Balic reveals a common technique could compromise the popular OS due to memory corruption - resulting in the device crashing.
In extreme cases, it appears memory code corruption vulnerability could be boosted and lead to arbitrary code execution, with users at risk of operating a rooted device.
"Although it's true that this vulnerability is capable of crashing Android mobile devices, it's important to point out that at this time there are no known instances or infections of this particular vulnerability 'in the wild,'" said Ryan Smith, Mojave Networks Lead Threat Engineer, in a statement. "Mobile malware distributors are typically motivated by money and information, and are therefore unlikely to use their established distribution channels to disseminate malware an app that simply crashes the device and doesn't gain them anything."
Continue reading: Android corruption bug frightening security researchers (full post)
Pure Hacking: Windows XP users, networks at risk as deadline looms
Microsoft Windows XP remains an extremely popular and well-liked operating system, but the security benefits alone of Windows 7 and 8/8.1 haven't been enough to get users to migrate. However, Microsoft and security experts are strongly urging both users and companies to upgrade, or potentially face harmful cyberattacks.
Pure Hacking has a few tips regarding XP: Disable what users don't need on the OS, replace XP with Windows 7, segregate legacy installations, and implement application whitelisting control.
"Across Australia there are tens of thousands of machines still running Windows XP - just think POS terminals, let alone all those SMBs," said Gordon Maddern, Pure Hacking CTO, in a statement. "Anyone still on XP will be wide open to attack. All new vulnerabilities - and countless numbers of these are likely - will no longer be fixed by Microsoft. I cannot stress enough, it's time to migrate, migrate, migrate."
Continue reading: Pure Hacking: Windows XP users, networks at risk as deadline looms (full post)


