Hacking, Security & Privacy - Page 47
Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 47
Stay Updated
Follow TweakTown for breaking tech news, reviews, and daily updates.
As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.
Time Warner Cable received less than 250 national security orders
Time Warner Cable processed almost 12,000 government requests in 2013, with 82 percent subpoenas, 12 percent court-ordered incidents, 4 percent were search warrants, 2 percent were emergency requests, and 0.3 percent were wiretap orders.
TWC says the company received between 0 and 249 National Security Orders, though cannot identify an exact number. The company wants to become more open about customer information requests, especially after Edward Snowden's spying disclosures made last year.
We will issue future Transparency Reports on a semi-annual basis," TWC said in a statement. "We have also provided answers to frequently asked questions related to the practices we follow to strengthen protections for the privacy of customer information."
Continue reading: Time Warner Cable received less than 250 national security orders (full post)
Updated BlackOS software available to cybercriminals for $3,800
The malicious BlackOS software package has been updated and is now available on the cybercriminal underground for $3,800 per year.
As noted by Trend Micro, the updated software is better suited to process and manage website exploitation, providing a great return-on-investment for cybercriminals. A custom Web interface allows for better web traffic management and access to features that lead to redirected traffic and iframes injection.
"They do a mass attack, there are no specific targets as these websites are just a launch pad to perform their malicious attacks," said Chris Budd, Trend Micro threat communications manager, in a statement to SC Magazine. "They are usually looking for an easy access, once they are inside they will try to level up the privileges to gain root access on the machine and therefore be able to [make] use of the BlackOS features, which is inject a malicious IFrames in all web pages."
Continue reading: Updated BlackOS software available to cybercriminals for $3,800 (full post)
Homeland Security busts child abuse ring that relied on Tor
An online predator group targeting children as young as three years old utilizing Tor was recently busted by the US Department of Homeland Security. So far, 14 members accused of leading the child pornography website were arrested and face charges related to conspiracy to operate an organized child exploitation enterprise.
Operating from June 2012 to June 2013, the group had more than 27,000 members across the world, with access to at least 2,000 videos.
"These indictments represent a strong coordinated strike - by Homeland Security, the U.S. Postal Inspection Service, and several U.S. Attorney's Office around the country - against child pornography and those who allegedly seek to harm our most vulnerable citizens, our young children," said Kenneth Allen Polite, Jr., U.S. Attorney, in a press statement.
Continue reading: Homeland Security busts child abuse ring that relied on Tor (full post)
Report from CA Attorney General notes cybercrime as real threat
Following years of burying their heads in the sand, lawmakers in the United States are finally taking cybercrimes seriously. As noted in the "Gangs Beyond Borders: California and the Fight Against Transnational Organized Crime" report released by California Attorney General Kamala Harris.
The state of California led all states in organized attacks, with computer systems under threat from malware.
"With the rise of a global society connected by the Internet, criminal rings organized to commit hacking, fraud, pirating and other high-tech crimes across borders have rapidly profilerated," the report notes. "These rings operate frequently from Eastern Europe, but also from places as diverse as West Africa and China, and specifically target the citizens, computer networks, and companies of prosperous countries like the U.S."
Continue reading: Report from CA Attorney General notes cybercrime as real threat (full post)
NSA might roll out transparency reports to try and ease spying scare
The NSA wants to be engaged in the continued global discussion of security and secrecy in the digital age, forced to the table following countless complaints of violating user privacy, according to NSA deputy director Richard Ledgett.
The NSA continues to face pressure from Internet users, foreign citizens, political leaders and tech companies, forcing the intelligence agency to go on the defensive. To help try and appear more transparent, there is a current proposal for the NSA to release transparency reports helping give insight into NSA operations.
Ironically, Ledgett said the NSA wanted to share a public point of view during TED to help counter the "half-truths and distortions" made public by Snowden. Ledgett also said Snowden put lives at risk, showing "the bad guys" some of the NSA's cybersecurity and snooping methods.
Continue reading: NSA might roll out transparency reports to try and ease spying scare (full post)
Miss Teen USA hacker sent to slammer for 18 months
Convicted teenage hacker Jared James Abrahams has been sentenced to 18 months in federal prison following two years of compromising online accounts of women he later blackmailed. The 19 year old pleaded guilty last November to one count of unauthorized access of a computer and three counts of extortion, and reportedly broke into around 150 online accounts.
Abrahams grabbed headlines after he compromised Miss Teen USA 2013 winner Cassidy Wolf, in which he accessed her computer and used their webcams to photograph them.
"As digital devices, email accounts, and social media accounts now contain the most intimate details of the public's daily lives, the impact of this type of hacking and extortion becomes more pronounced, troubling, and far-reaching," the U.S. Department of Justice noted. "In some cases, this type of criminal behavior can be life-changing for the victims - especially for vulnerable victims who may feel it is impossible to rebuild their tarnished reputations."
Continue reading: Miss Teen USA hacker sent to slammer for 18 months (full post)
Australia wants to increase spying on citizens after Snowden leaks
Edward Snowden has changed the world with his revelations of the NSA spying on virtually everyone, where Down Under, multiple Australian law enforcement agencies and the Australian Security Intelligence Organization (ASIO) have submitted proposals asking the Australian Senate for more surveillance power.
State police have even gone as far as asking the government to log citizens' Web browsing history. After the Snowden leaks on the NSA's spying programs and Australia's cooperation in sharing information with other countries, the Australian Senate opened an inquiry on whether Australia's Telecommunications (Interception and Access) Act of 1979 should be revised, in order to better protect Australian citizens' privacy.
Since then, ASIO as well as multiple state police, submitted commentary asking for even more data retention, but offering no added protection for citizens' data. ASIO added that the Snowden leaks will make it harder for the organization to gather meaningful data about a person, so it thinks it should have more power to perform its surveillance duties.
Continue reading: Australia wants to increase spying on citizens after Snowden leaks (full post)
NSA's MYSTIC program records entire nation's worth of phone calls
Edward Snowden's latest leak is quite interesting, with the NSA whistleblower talking about the US spy agency's MYSTIC voice interception program, which is capable of collecting the entire nation's "every single" phone call, storing the voice recordings for a month.
MYSTIC began back in 2009, with the NSA developing a RETRO tool that is capable of accessing any voice call from the selected nation, for a period of 30 days. The first nation to have their phone calls recorded by MYSTIC and RETRO started in 2011, with as many as six more countries possibly being spied upon. The Washington Post was asked by US officials to note reveal which countries MYSTIC was operating on.
The program was quite successful, with the NSA bringing in "high-stakes intelligence that would not have existed under traditional surveillance programs in which subjects were identified for targeting in advance," according to The Washington Post. "Unlike most of the government's public claims about the value of controversial programs, [highly classified] briefings supply names, dates, locations and fragments of intercepted calls in convincing detail."
Continue reading: NSA's MYSTIC program records entire nation's worth of phone calls (full post)
Metadata reveals a large amount of information about users: study
Mobile phone metadata is more valuable than the National Security Agency (NSA) tries to imply, and it's possible to find sensitive information with phone metadata, using social media, and pattern matching, according to Stanford University researchers.
Computer science graduate students learned, using 546 volunteers, that 57 percent of volunteers made at least one medical-related call, with 40 percent calling financial services. In total, the callers made 33,688 unique numbers and were able to make corroborations related to medical conditions and firearm ownership.
"At the outset of this study, we shared the same hypothesis as our computer science colleagues - we thought phone metadata could be very sensitive," the researchers found.
Continue reading: Metadata reveals a large amount of information about users: study (full post)
Users are first line of PC security defense, but fail miserably
Both consumers and business users face a tremendous amount of security threats, despite next-generation security solutions trying to keep PCs and mobile devices protected.
Malware is increasingly sophisticated and slipping by traditional anti-virus software, with software creators finding low risk and high reward for their behaviors.
"As often as not, malware gets into your systems become you invited it by clicking a link without thinking," said Bruce Campbell, VP of Marketing at Clare Computer Solutions, in a statement to TweakTown. "Take the dreaded CryptoLocker ransomware... most commonly, it was introduced as an attachment to an e-mail that said it was from UPS. The attachment looked like a PDF file and the e-mail said - Track Information, see attached."
Continue reading: Users are first line of PC security defense, but fail miserably (full post)
Archdiocese of Seattle targeted by data theft, causes annoyances
A data breach suffered by the Archdiocese of Seattle is now being investigated by the FBI and IRS, as personal information stolen has reportedly been used for false tax returns, so criminals can take the refunds.
Students from the Seattle Bishop Blanchet High School were released early on Friday, with school administrators hoping to give faculty and volunteers the ability to go home and check their IRS and credit reports. Students at the O'Dea High School had Friday off so administrators could try to further evaluate the data breach.
The Archdiocese of Seattle has created an online portal for those concerned following the data breach. Also, they recommend calling the IRS Identity Protection Specialized Unit: 1-800-908-4490, ext. 245 to learn if tax identity theft has occurred.
Continue reading: Archdiocese of Seattle targeted by data theft, causes annoyances (full post)
Russian government blocks four opposition sites criticizing Putin
President Vladimir Putin's government has reportedly banned four websites operated by Kremlin opponents and critics. Opponent Alexei Navalny had his website blocked for Russian Internet users, along with online newspaper Grani, an opposition information website, and a radio station website (despite it being state-operated).
The Russian government defended its actions by saying the websites helped organize "illegal" protests, according to reports in the region. Navalny is serving a two-month house arrest punishment because he violated five-year probation for an embezzlement-related charge.
Over the past two years, Putin has continually put the squeeze on media outlets located in his country - most recently, the editor of Lenta.ru, a major Russian independent news site, resigned due to increased pressure from Moscow.
Continue reading: Russian government blocks four opposition sites criticizing Putin (full post)
McAfee makes Antivirus & Security free for Android and iOS
Intel-owned McAfee wants to keep mobile users more secure by offering its Antivirus & Security suite available to Apple iOS and Google Android users.
There are plenty of free software products available designed for smartphones and tablets, but paid versions provide a more complete suite. The McAfee Labs collected 2.47 million Android malware samples in 2013, with 744,000 in Q4 alone.
"With India placed on the tip of mobile device explosion, there is an overwhelming need of adoption of security and privacy protection in our digital lives," said Jagdish Mahapatra, McAfee Managing Director in India, in a statement. "With free access to our award-winning mobile security product, Indian consumers will be empowered to access all the benefits of this connected world and enjoy a safe mobile life."
Continue reading: McAfee makes Antivirus & Security free for Android and iOS (full post)
Target missed multiple warnings of major data breach underway
Popular retailer Target had multiple warnings that a credit and debit card breach was underway, but still didn't do enough to try and stop the problem.
A recent series of interviews with more than 10 former Target employees, and a handful of people familiar with the attack indicate the company was aware of a data breach underway - and the alert system worked - signaling malware was installed before being publicly disclosed.
"I don't think it is about not paying attention to the technologies as much as fine tuning for actionable, relevant information from the technology," said Joe Schumacher, Neohapsis security consultant, in a statement to SCMagazine. "Many security systems (e.g. Web application firewall, log monitoring, intrusion Detection/Prevention Systems, etc.) correlate large amounts of data into a single repository. Unfortunately, a lot of companies and professional services stop here."
Continue reading: Target missed multiple warnings of major data breach underway (full post)
Universities slow to inform students, faculty of data breaches
Colleges and universities are popular targets for cybercriminals trying to compromise a large amount of users, stealing as much personal information as possible. However, university officials, after learning of a breach, often are unsure what to do - and struggle to alert students and faculty members in a streamlined manner.
Most recently, hackers compromised North Dakota University and Johns Hopkins University, with hackers stealing personal information.
In the Johns Hopkins University breach, hackers stole information on 850 current and former students, though no Social Security Numbers or highly sensitive information was taken. The breach reportedly took place sometime towards the end of 2013, but university officials didn't publicly report the incident until early March.
Continue reading: Universities slow to inform students, faculty of data breaches (full post)
'Internet of things' needs anti-virus and security measures
Security experts are keen to try and help traditional anti-virus software evolve into a layer of added defense for breach detection systems (BDS), though the industry is having trouble finding its way there.
If hackers are unable to gain access to PCs, they are finding success targeting voice over Internet protocol (VoIP) phones in the office - which sometimes leads to direct access to computer networks.
Red Balloon, founded by researchers from Columbia University, are interested in developing security for embedded devices, helps companies keep devices more secure.
Continue reading: 'Internet of things' needs anti-virus and security measures (full post)
NSA allegedly poses as Facebook to help spread its malware
The National Security Agency (NSA) reportedly wants to infect millions of computers with malware, and the TURBINE program is based on hacking routers, impersonating Facebook, and other shady practices. Not surprisingly, the information was made public based on revelations released by former NSA contractor Edward Snowden.
The NSA posed as a fake Facebook server, and successfully infected a user's computer to gain access to stored files on a HDD, according to a report posted on The Intercept. Previously, the NSA would use this tactic for a small number of select targets that couldn't be tracked with regular wiretaps, but greatly expanded use over the past 10 years.
Security experts are disheartened by yet another data snooping case from the NSA, potentially opening up additional security issues by intentionally infecting computers with malware.
Continue reading: NSA allegedly poses as Facebook to help spread its malware (full post)
Banks, financial institutions increasingly researching biometrics
Banks and other financial institutions are embracing biometrics as a next-level security platform, helping prevent against fraud and theft, according to a report published by the Global Industry Analysts (GIA) research group.
Fingerprint recognition is the most popular form of biometrics security, with high accuracy and relatively low deployment costs.
Most common biometric security tend to be fingerprint verification, hand-geometry recognition, speech recognition, and iris and retina scanning technologies. Each has significant advantages and disadvantages, leading some companies to adopt multiple types of biometrics. However, it's not cost-effective to install and maintain multiple layers of security, unless necessary, with each different solution needing a complex infrastructure.
Continue reading: Banks, financial institutions increasingly researching biometrics (full post)
Cybercriminals show no shame, try to extort non-profit group
Most cybercriminals want to exploit vulnerable networks and make a profit as quickly and easily as possible - and that includes compromising non-profit groups, even trying to conduct organized extortion. Hackers recently hijacked the crisis line of The Bridge for Youth, a Minnesota non-profit aimed at helping homeless adolescents in the state.
It seems The Bridge was hit with phone spam that was able to hijack phone lines and Internet access - and criminals will hold the lines for ransom, in exchange for monetary payment. Instead of paying the criminals, under police guidance, they refused - and then redirected the line to an answering machine - and worked with other non-profits to set up a new phone line.
"We had to shut down our crisis number of 35 years last Tuesday," said Dan Pfarr, The Bridge for Youth Executive Director, in a statement to the Minneapolis Star Tribune. "The guys who took over our crisis line wanted money. We told them we work with distressed families and kids at the low point of their lives. That we deal with lives. We can't have abused kids or parents... calling in and getting a busy signal."
Continue reading: Cybercriminals show no shame, try to extort non-profit group (full post)
168,000 at risk after computers stolen, health data compromised in LA
Up to 168,500 patients of the Los Angeles County Department of Health Services are at risk after thieves broke into the Sutherland Healthcare Solutions (SHS) office and stole PCs with personal information.
Included in the data breach: Names, Social Security Numbers, birthdates, addresses, medical diagnoses, medical and billing information. The Southern California SHS office was broken into on February 5, and the company is now working with law enforcement - and reviewing its internal policies to try and prevent a similar breach from happening in the future.
"We take this incident very seriously and are taking the necessary precautions to protect all patient related information from theft or criminal activity," SHS said in an open memo. "We and Los Angeles County are actively working with law enforcement."
Continue reading: 168,000 at risk after computers stolen, health data compromised in LA (full post)


