Hacking, Security & Privacy - Page 48
Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 48
Stay Updated
Follow TweakTown for breaking tech news, reviews, and daily updates.
As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.
Google was attacked by the Chinese, NSA according to its chairman
During his speech at the SXSW technology conference in Austin, Texas, Google chairman Eric Schmidt had some damning words to say about the Chinese, and the NSA. SChmidt said that government attacks from China, and the US, forced Google to boost its security protocols.
Schmidt said that governments around the world have come to the realization that trying to block Internet access to its citizens are futile, and that they have moved onto other methods of control. He said: "You don't turn off the Internet: you infiltrate it. The new model for a dictator is to infiltrate and try to manipulate it. You're seeing this in China, and in many other countries."
The Google chairman was pressed about the role of technology in uprisings, such as the one in the Ukraine right now, where he said that the spread of mobile devices has allowed people to organize much more easily, but although "revolutions are going to be easier to start," they'll also be "harder to finish."
Continue reading: Google was attacked by the Chinese, NSA according to its chairman (full post)
Study: Forty percent of those hit with Cryptolocker ransomware pay up
Companies infected with the Cryptolocker ransomware are willing to pay up, with 40 percent of companies hit sending around $500 to recover files.
Cryptolocker is plaguing companies, encrypting certain file formats that cause workplace disruption, which is likely why companies are so quick to make a payment to cybercriminals overseas.
"If the results reported on the rate of Cryptolocker victims who pay a ransom are to be strengthened by further research, these figures would be extremely troubling, netting criminals behind the ransomware hundreds of millions." said Dr. Julio Hernandez-Castro, University of Kent School of Computing professor, said in a statement. "This would encourage them to continue with this form of cybercrime, potentially prompting other criminal gangs to jump into an extremely profitable cybercrime market."
Continue reading: Study: Forty percent of those hit with Cryptolocker ransomware pay up (full post)
Target CIO Beth Jacob resigns due to chaos following data breach
Target is restructuring following a massive data breach in which the retailer was warned of security issues beforehand, and cybercriminals were able to deploy malware on the company's in-store point-of-sale machines.
"It's a decision that should have been made by the CEO on January 1, not through the resignation of an employee that overlooked critical weakness in the operating model," said Brian Sozzi, Belus Capital Advisors CEO, in a statement to Reuters.
Jacob is the first Target executive to resign - and it's possible others will either receive walking papers, or "quit" - and an interim CIO will be chosen to help move Target's cybersecurity forward. It seems shocking that Jacob didn't quit earlier, or that CEO Gregg Steinhafel didn't show her the door earlier, but expect the company to find an external hire next.
Continue reading: Target CIO Beth Jacob resigns due to chaos following data breach (full post)
Mobile difficulties plague workers in the office, no easy choices
Tablets and smartphones helped force users into a mobile lifestyle, in which e-mails, content, work, and entertainment need to be optimized for non-PC devices.
Businesses risk downtime, lost productivity, legal problems, and possible customer backlash if data is compromised, especially due to negligence, and presents a unique problem.
"I haven't seen a lot of good products to add to tablets and smartphones - yet," said Bruce Campbell, Clare Computer Solutions VP of Marketing, in a statement to TweakTown. "While malware for these devices is on the rise, the more common problem is these devices being lost or stolen with personal or company data. Software that will enable the device to be 'wiped' clean if stolen or lost is a good idea."
Continue reading: Mobile difficulties plague workers in the office, no easy choices (full post)
Israel wants to turn country into cybersecurity "global center"
Israeli Prime Minister Benjamin Netanyahu recently discussed his country's budding cybersecurity industry, which is tasked with stopping attacks from Islamist militant organizations and cybercriminal groups.
During the interview, Netanyahu was asked about companies purchasing Israeli technologies and whether they should be worried of NSA-like spying behavior.
"My point is that to build in Israel a global center for cybersecurity, in other words to prevent this spying to prevent the piracy, to prevent sabotage" Netanyahu said in an interview transcribed by BloomBerg. "You have user accounts. You have to protect them. You have bank accounts. You have to protect them. You have electricity grids. You have to protect them, traffic systems and aviation systems. All of these can be both individually and national infrastructures could be imperiled by cyber-attacks, are imperiled by cyber-attacks."
Continue reading: Israel wants to turn country into cybersecurity "global center" (full post)
Court finds man guilty for "webcam" fix that spied on users
Andrew Meldrum, a 30-year-old British citizen, has been found guilty of three counts of unauthorized access to computer material after "fixing" webcams so he could remotely watch as many as three victims.
Meldrum was first suspected after one of the victims reported her computer was acting strangely, and it snowballed from there - one victim spoke with someone else, and victim 2 contacted a third victim - all three had the convicted creeper work on their PCs.
"I would like to thank all witnesses in this investigation but especially the three victims who game evidence on matters that were clearly of a private, intimate and personal nature to them," said Nick Pailthorpe, Southwark Borough CID, in a press statement. "I hope that they can take some consolation in the guilty verdict that sends out a clear message to anyone that this type of intrusion into a person's private life is not acceptable and the Metropolitan Police will support all victims and pursue all suspects."
Continue reading: Court finds man guilty for "webcam" fix that spied on users (full post)
Smucker's online store compromised, company apologizes to customers
Fruit jam and jelly company Smucker's reportedly suffered an online store data breach, with customer names, mailing addresses, e-mail, phone numbers, credit and debit card numbers, expiration dates, and verification codes at risk.
Security experts believe a sophisticated Trojan is likely to blame for Smucker's issues, with information siphoned from online web server applications.
"We are extremely disappointed this incident occurred and sincerely apologize for any inconvenience this may cause," Smucker's officials said in an online state. "Please be assured, we continue to thoroughly investigate this matter with federal authorities, and have taken steps to rectify the cause of this incident with the Online Store website."
Continue reading: Smucker's online store compromised, company apologizes to customers (full post)
Clare Computer Solutions details basic steps to PC defense
Trying to keep PCs and devices safe from increasing numbers of cyberattacks hasn't been easy, with sophisticated malicious code targeting PCs.
Even with elevated malicious attacks in the wild, there are a few basic steps that can be done to boost defenses before something critical occurs.
The first step: "Make sure you have up-to-date Anti-Virus software - preferably not the freeware versions," said Bruce Campbell, IT outsourcing company Clare Computer Solutions, in a statement to TweakTown. "For home users, make sure you activate the Norton or McAfee that comes with the computer, and renew it every year."
Continue reading: Clare Computer Solutions details basic steps to PC defense (full post)
Mt. Gox sees its source code and customer data leaked by hackers
Things just got a lot worse for former Bitcoin exchange, Mt. Gox. Today a Russian leakster announced that he has accessed then entire source code that ran Mt. Gox's operations. The code is only 1,700 lines long, so it is highly unlikely that the entire thing is there, but it does provide enough information to show how Mt. Gox handled Bitcoin transactions, and the methods used to transmit and receive Bitcoin hashes.
Along with the source code, the leakster / hacker claims to have a 20GB data dump of customer and employee information that includes passport scans, and every piece of contact information customers and employees entered into the system. With a breach this big, it leaves us to wonder how many other exchanges were using a part of this source code, and how many are now venerable to even more attacks now that the information is public? If you are interested, the source link below has links to the stolen code.
It's incidents like this that further undermine the security and trustworthiness of Bitcoins as a viable digital currency. This is the exact reason that US Congressmen are calling for Bitcoin trading to be banned in the us. With such a large economy growing around the virtually unregulated Bitcoin market, a simple crash like Mt. Gox experienced, or major Bitcoin heist like Flexcoin experienced over the weekend could send the entire market crashing down and millions of people would lose everything they have invested in Bitcoins.
Continue reading: Mt. Gox sees its source code and customer data leaked by hackers (full post)
New malware makes anti-virus software 'totally useless'
There is a security transition from defending against various virus and Trojan formats to sophisticated malware, and anti-virus programs are "totally useless," according to Mohammad Mannan, Concordia Institute for Information Systems Engineering assistant professor.
In a recent survey from Visa, almost 92 percent of respondents said they have been targeted by attempted phishing attempts - and the complexity of these attacks continues to evolve.
Just a few years ago, if a user was infected with malware, it was a major disruptive problem that directly led to PCs running poorly. However, malware is largely being written by cybercriminals aiming to either hijack compromised devices, or steal personal information and make money, so malware runs in the background a lot more efficiently.
Continue reading: New malware makes anti-virus software 'totally useless' (full post)
Hackers compromised more than 300,000 SOHO wireless routers
Researchers have discovered a large number of comprised small office and home wireless routers. Hackers attacked more than 300,000 wireless router devices manufactured by D-Link, Micronet, Tenda, TP-Link and more. This discovery was made by researchers from a security firm 'Team Cymru' who has also disclosed a cross-site request forgery (CSRF) where attackers can access TP-Link routers using a blank password.
The idea is that hackers use multiple techniques to take over the wireless routers. Once the hackers get access, they change the domain name system (DNS) servers that's used to translate 'human-friendly' domain names into IP addresses for computers to track down web servers. The router re-directs to a fake website via the DNS where the unsuspecting victims insert login credentials. Once the credentials are inserted, the attackers use it to log into victims' accounts and uses socially engineering sms to induce the victim to unknowingly approve a transfer of funds to the attackers online banking account.
The hackers have attacked more than 300,000 routers located in multiple countries such as Vietnam, India, Colombia, etc. These compromised devices can now re-direct all of its end users to a malicious website to steal banking passwords. There is also a series of attacks that targets bank customers in Poland. It was found that fake DNS was used on the home and small office router which redirect computers, tablets and smartphones to a website made to collect online banking credentials from unsuspecting customers.
Continue reading: Hackers compromised more than 300,000 SOHO wireless routers (full post)
Netflix phishing scam tricks subscribers to steal data from their PC
There's a new phishing scheme which involves Netflix and using the fear of having your account suspended unless you call the company's 'tech support'. Jerome Segura of Malwarebytes Unpacked uncovered 'Tech Support' scammers where they try to use Netflix account suspicion scare to steal its victims' photos, name, address, passwords and even credit cards.
Segura said that the error from Netflix urged him to call the 1-800 number on the screen, which was not the official support number and therefore prompted deeper investigation. Upon contacting the fake tech support, the representative made him download a 'Netflix Support Software' which turned out to be Teamviewer. After the remote connection was made, the scammer said that his account was suspended because of 'illegal activity' and showed 'proof' using a 'Foreign IP Tracer' which was a custom-made Windows batch script.
What was strange is that the tech support scammer advised him to connect with a Microsoft Certified technician. He also went ahead and transferred the call to a certified technician (fake, of course) who already had Teamviewer access. The fake support explained the issue and drafted a bill for installing network firewall, AVG antivirus cleanup followed by a $50 fake Netflix discount coupon and offered a discount. What was later found out that the scammer was trying to buy time and distract the victim. In the meantime, the scammer was going through his personal files and stealing data of his interest, as found in TeamViewer file transfer eventlog.
Continue reading: Netflix phishing scam tricks subscribers to steal data from their PC (full post)
Popular event notification site, Meetup, down for days due to DDoS
Meetup is one of those websites that almost everyone has used at some point, and with more than 12 years of an online presence it is no surprise that many have grown to depend on the service for spreading the word about their meetings. Unfortunately for the last several days, Meetup has been experiencing a massive Distributed Denial of Service attack (DDoS) that has crippled its servers and rendered the service unusable.
While the attack lessens from time to time, I have only noticed the service up twice over the last 4 days with it being back down within an hour of it coming back online. The attack is non political, and is purely designed to extort money from the company behind Meetup. An email arrived in CEO, Scott Heiferman's, inbox shortly after the attack began that read; "A competitor asked me to perform a DDoS attack on your website. I can stop the attack for $300 USD. Let me know if you are interested in my offer."
Meetup chose not to pay the extortionist even though the amount demanded was extremely small as it has a policy not to negotiate with criminals. At the time of this writing Meetup was back up, but has been down on and off for most of the day. The company says that it is working on restoring stability, and hopes that things will return to normal shortly.
Continue reading: Popular event notification site, Meetup, down for days due to DDoS (full post)
Security company FireEye lists most targeted countries, industries
PC and mobile users are under constant threat from increasingly advanced types of malware, with attack servers handing out malware attack commands in 206 countries across the world, according to security company FireEye.
The United States, South Korea, Canada, Japan, and United Kingdom lead all countries targeted with advanced persistent threats (APTs). The government, services/consulting, and technology verticals most targeted, as cyberattacks are increasingly used to spy on rivals and steal information.
"The increasing frequency at which cyber attacks are happening illustrates the allure of malware to those with malicious intentions," said Dr. Ken Geers, FireEye senior global threat analyst, in a press statement. "Across the board, we are seeing a global expansion of APTs, malware, CnC infrastructure, and the use of publically available tools to facilitate the attack process. The global scale of threat has put cyber defenders in the very difficult position of not having any clue where the next attack will come from."
Continue reading: Security company FireEye lists most targeted countries, industries (full post)
Outgoing NSA chief General Keith Alexander calls for reform
After being exposed by former IT contractor Edward Snowden last year, the NSA has the difficult task of trying to regain trust among the American people.
It's not impossible for the NSA and federal government to earn trust back, but without a sign of good faith, people will likely remain skeptical.
"I think we need to step back, set a framework for discussion with the American people," outgoing NSA chief Gen. Keith Alexander said during a recent Senate Armed Services Committee. "This is going to be absolutely important in setting up what we can and cannot do in cyberspace to protect this country. And from my perspective, that's going to be one of the big issues that we move forward. I think a precursor to that is getting the NSA issues resolved. We have to get those resolved because, ironically, it operates in the same space."
Continue reading: Outgoing NSA chief General Keith Alexander calls for reform (full post)
Hackers compromised RT.com to replace the word 'Russian' with 'Nazi'
Russia's news website RT.com was recently compromised, and hackers have changes multiple articles with the word 'Russian' to 'Nazi'. Currently there's tension going between the country and Ukraine as Russia decides to move its troops towards the border and planning many military exercises.
The hack was reported at about 11 pm EST, which lead to changed in many news headlines such as 'Thousands rally again 'illegitimate govt', raise Nazi flags in eastern Ukraine' and 'up to 143,000 Nazis requested asylum in Russia in two weeks'.
After some time, RT.com was able to revert the headlines and made an announcement about the hack via Twitter. The reason RT.com became involved in this controversy is that their media reports were being heavily criticized for being allegedly bias and was funded entirely by Russia.
Continue reading: Hackers compromised RT.com to replace the word 'Russian' with 'Nazi' (full post)
Struggling retailer Sears now dealing with a reported cyber breach
Struggling retailer Sears is the latest company to suffer a security data breach that is now being investigated by the U.S. Secret Service, according to unnamed resources.
Details regarding the reported attack haven't been released, including time of the breach or how many customers could have been affected.
"There have been rumors and reports throughout the retail industry of security incidents at various retailers and we are actively reviewing our systems to determine if we have been a victim of a breach," said Howard Riefs, Sears spokesperson, in a statement. "We have found no information based on our review of our systems to date indicating a breach."
Continue reading: Struggling retailer Sears now dealing with a reported cyber breach (full post)
Security firm blames Russian government for making Uroburos malware
Security experts like to point fingers at various sources of cyberattacks and malware creation, and quite a bit of attention is focused on Russia and Eastern Europe. The most recent example comes as German security firm G Data Security blames the Russian government for creating the "Uroburos" malware.
G Data Security blog author "MN" believes the Russian government was behind the malware due to its sophistication - Uroburos is a rootkit that has a driver and encrypted virtual file system, with the rootkit hijacking infected machines while running commands anonymously.
"According to all indications we gathered from the malware analyses and the research, we are sure of the fact that attacks carried out with Uroburos are not targeting John Doe but high profile enterprises, nation states, intelligence agencies and similar targets," the company's blog reads.
Continue reading: Security firm blames Russian government for making Uroburos malware (full post)
Chinese government continues to plague U.S. with cyberattacks
During his RSA Conference 2014 keynote last week, FireEye COO Kevin Mandia again said the Chinese government is a "nation-state sponsoring intrusions into businesses in the U.S.," continuing an increasingly popular tactic used by governments.
China is notorious for using cyberattacks to try and gain trade secrets and private information which can then be used in China. In addition to rogue hacker groups, the Chinese government has been accused of secretly paying hackers to conduct cyber surveillance of networks and servers.
Of note, the Chinese government's Unit 61398, part of the national military, has launched more than 1,000 organized cyberattacks against select Western targets, according to security firm Mandiant. Following a break in the attacks, it appears the Chinese government is again attacking US government, military, banks, and other critical infrastructure on a near-daily basis.
Continue reading: Chinese government continues to plague U.S. with cyberattacks (full post)
Will Mac OS X Snow Leopard be the next big target for cybercriminals?
After deciding not to release a security update in six months, it looks like Apple might not bother keeping its OS X Snow Leopard users secure, according to recent reports.
The OS is only four years old, so Apple trying to retire it so seen is a bit of a surprise, though Apple might want to avoid the need of continually supporting older OSes, which Microsoft has routinely done in the past.
If Apple is truly turning its back on Snow Leopard, that means the company also is leaving behind 19 percent of current Mac users - and cybercriminals, licking their chops over the upcoming Microsoft Windows XP end of support next month - could shift attention towards Snow Leopard. Apple has done a good job of keeping its products secure, but there is still belief that Apple products are fully secure, and this overconfidence could plague home users and businesses.
Continue reading: Will Mac OS X Snow Leopard be the next big target for cybercriminals? (full post)


