Newsletter IconFacebook IconX IconThreads IconInstagram IconYouTube IconPinterest Icon
Giveaway: AVerMedia Creator Bundle (4K Webcam, Capture Card, Charging Hub, and Mouse Pad)

Hacking, Security & Privacy - Page 49

Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 49

Stay Updated

Follow TweakTown for breaking tech news, reviews, and daily updates.

Add TweakTown as a preferred source on GoogleFind TweakTown on Apple News

As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.

British Spy Agency considered using Microsoft Kinect for Surveillance

| Mar 1, 2014 4:29 AM CST

Edward Snowden leaked new documents which shows that a UK spy agency GCHQ were exploring a way to use Microsoft Kinect camera to conduct mass surveillance. It was revealed that GCHQ ran a program called 'Optic Nerve' which would target 1.8 million Yahoo users and mass collect their webcam images.

According to the news report, Optic Nerve project started with a prototype in 2008 and started by using Yahoo webcam to collect images. It also contained information about GCHQ considered using Kinect for a similar form of surveillance. Though the concept never came into play, many documents indicated that Kinect camera can provide 'fairly normal webcam traffic' as a part of Optic Nerve Program.

GCHQ was also involved in a controversy earlier when they disrupted an IRC network that belonged to anonymous individuals by DDoSing the servers. There were documents which pointed out GCHQ's 'social manipulation' plan to discredit 'enemies' via propaganda.

Continue reading: British Spy Agency considered using Microsoft Kinect for Surveillance (full post)

Just 48% of RSA attendees surveyed think NSA overstepped boundaries

| Feb 28, 2014 11:42 PM CST

Just 48 percent of those surveyed during the RSA Conference 2014 in San Francisco believe the NSA overstepped boundaries with its widespread spying activities, according to account management company Thycotic Software.

Most of the focus during the conference was on vendors showing off their software and hardware security solutions - but it was inevitable to hear former NSA contractor Edward Snowden's name - and constant conversations around the NSA booth in the Moscone South Expo hall.

"Regardless of where you stand on the issue, the attention around Edward Snowden's alleged disclosures last year has raised major concerns worldwide around the risk posed by insiders who have access to privileged account passwords," said Jonathan Cogley, Thycotic Software founder in CEO, in a press statement. "Regardless of intention, data breaches always have the potential to devastate a company's reputation and create a significant drain on resources."

Continue reading: Just 48% of RSA attendees surveyed think NSA overstepped boundaries (full post)

Formula 1 race car team tripped up by virus, loses day of testing

| Feb 28, 2014 8:48 PM CST

A computer virus reportedly took down a Formula 1 race car team was supposed to be on the track, helping mechanics and drivers lock things down. Instead, the Marussia team was downed for almost an entire day of driving due to an unexplained computer virus that will be investigated to prevent future issues.

"It started off with the first disaster, which was a computer Trojan-type virus in the racks, which cost us the best part of the day," Marussia team principal John Booth recently told AUTOSPORT. "So that set the tone for the week."

Modern Formula 1 cars have a large amount of electronics, with team managers able to carefully track vehicle performance during practice laps and throughout a race.

Continue reading: Formula 1 race car team tripped up by virus, loses day of testing (full post)

Oh the irony, RSA Conference mobile app users exposed

| Feb 28, 2014 5:34 PM CST

Either just bad luck or a cruel practical joke, it turns out the RSA Conference 2014 mobile app designed to help attendees get through the show mistakenly had a security hole potentially exposing user data.

IOActive found that there were two major vulnerabilities in the app, including a flaw that reveals name, surname, job title, employer, and nationality of the mobile app users. The second flaw opened up the door to man-in-the-middle attackers able to inject code into the app's login, so login credentials could be exposed.

"The RSA Conference 2014 application downloads a SQLite DB file that is used to populate the visual portions of the app (such as schedules and speaker information) but, for some bizarre reason, it also contains information of every registered user of the application - including their name, surname, title, employer, and nationality," said Gunter Ollmann, IOActive CTO, in a blog post.

Continue reading: Oh the irony, RSA Conference mobile app users exposed (full post)

Target, other retailers trying to come to terms with data breaches

| Feb 28, 2014 1:46 PM CST

Popular retailer Target is still dealing with continued fallout from a data breach in late 2013 that left more than 70 million customers affected. The malware targeting Target's point-of-sale solutions should have raised immediate alarm bells for other retailers trying to prevent similar attacks.

Target is now being sued by a handful of smaller banks that accuse the store of not doing a good job of protecting customer data.

"So far, seven financial institutions have filed class action suits against Target alleging the retailer didn't adequately protect customer data," according to the Wall Street Journal's Joel Schectman. Other banks could join the class action suit, accusing one of the largest U.S. brick and mortar retailers of not boosting its security defenses when warned of possible malware threats.

Continue reading: Target, other retailers trying to come to terms with data breaches (full post)

Secunia: 1,208 vulnerabilities in the 50 most popular programs

| Feb 28, 2014 1:16 PM CST

Third-party applications are responsible for 76 percent of vulnerabilities now plaguing the 50 most popular programs, according to IT security firm Secunia. The company's research looked at the top 50 programs used on private PCs - including solutions approved and maintained by IT experts - with vulnerabilities largely stemming from non-Microsoft applications.

Of the 1,208 total vulnerabilities found in 2013, 76 percent were sourced to third-party applications - even though they account for just 34 percent of the top 50 programs.

Despite continually improving security, many users still blame Microsoft for a wide variety of security loopholes - but Secunia's research indicates it's these downloaded and installed third-party apps that continue to cause problems.

Continue reading: Secunia: 1,208 vulnerabilities in the 50 most popular programs (full post)

Alleged British hacker wants to stay in UK, avoid US extradition

| Feb 28, 2014 12:41 PM CST

Alleged British hacker Lauri Love is accused of hacking into US Federal Reserve computers, and his lawyers will "vehemently oppose" all attempts to extradite him. If convicted in the United States, Love faces up to 12 years in federal prison, according to FBI officials anxious to have him land on U.S. soil.

The UK national Crime Agency also is looking into Love's alleged hacking behavior, though the UK court system wants to see the "sophisticated hacker" stay in the UK.

"If there is an extradition request from the United States it will be vehemently opposed," said Karn Todner, Love's legal advisor, in a statement to the BBC. "We believe that if Mr. Love is to face charges that they should be, and will be, in the UK."

Continue reading: Alleged British hacker wants to stay in UK, avoid US extradition (full post)

Variety of malware stealing bitcoins using exploited apps

| Feb 28, 2014 12:16 PM CST

RSA 2014 - The bitcoin currency is extremely popular, and has become a great target for cybercriminals trying to steal a quick payday. Targeting Apple's OS X applications, the CoinThief Trojan is designed to steal bitcoins when hidden in pirated versions of mobile apps.

The CoinThief malware was discovered earlier in the month, and works by installing a browser plugin that remotely steals login information used on bitcoin wallet and exchange sites.

There are currently more than 100 forms of bitcoin-stealing malware in the wild, available for purchase starting around $25, according to security experts. Underground forums provide an ideal location for cybercriminals to show their wares - and if you are able to gain access and become a trusted member of the community - it's possible to purchase customized malware for next to nothing.

Continue reading: Variety of malware stealing bitcoins using exploited apps (full post)

MasterCard wants to use your phones location for security

| Feb 26, 2014 4:25 AM CST

Let's face it, whenever you're shopping and using your credit card, you'll have your smartphone on you, too. Well, now MasterCard is working with network company Syniverse in order to reduce fraud when using your credit cards overseas.

The companies are working on tying your credit card to your smartphone, so that the card is only capable of working when your smartphone is near. Hany Fam, president of global strategic alliances at MasterCard explains: "There have been many attempts to help prevent credit card fraud, but this is the first solution that works globally and without the need for new devices or infrastructure".

If you end up using this new system, you won't feel it in everyday use. Your smartphone will just need to be turned on and kept with you. Syniverse acts on the phone operator's side of things, interconnecting between different networks reaching more than 5 billion mobile devices globally. The company is capable of locating users' phones on their signal alone, without mobile data being enabled, or used.

Continue reading: MasterCard wants to use your phones location for security (full post)

Mobile malware in 2013 at least doubled when compared to year before

| Feb 25, 2014 6:13 AM CST

Cybercriminals enjoy using mobile malware to create vulnerabilities, with around 100,000 new malicious programs introduced in 2013 - more than double the 40,059 samples that went live in 2012.

Russia (40%), India (8%), Vietnam (4%), Ukraine (4%) and the United Kingdom (3%) led the list with users under attack the most, and the majority of mobile malware threats are aimed towards stealing money. Banks and mobile customers are under fire and need to be vigilant, ensuring some type of anti-malware solution is being used to better protect smartphones and tablets.

"Today, the majority of banking Trojan attacks target users in Russia and the CIS, said Victor Chebyshev, Kaspersky Lab Virus Analyst, in a press statement. "However, that is unlikely to last for long: given cybercriminals' keen interest in consumer bank accounts, the activity of mobile banking Trojans is expected to grow in other countries in 2014. We already know of Perkel, an Android Trojan that attacks clients of several European banks, as well as the Korean malicious program Wroba."

Continue reading: Mobile malware in 2013 at least doubled when compared to year before (full post)

Hewlett-Packard, Trend Micro team up to defend against attacks

| Feb 25, 2014 3:16 AM CST

RSA 2014 - PC and server maker Hewlett-Packard and security solutions company Trend Micro have teamed up to introduce new software to defend against targeted attacks. The new effort combines Trend Micro's Deep Discovery with HP's TippingPoint, with the new solution aimed at effectively detecting, reporting, and blocking data breaches.

HP relies on software and vendor products to help keep its PCs, servers, and other products protected - and creating custom partnerships will allow for a great opportunity to keep products more secure.

"Cyber criminals are going well beyond traditional malware and conventional attack vectors, and enterprise need protection that keeps pace and adapts faster than the adversaries," said Rob Greer, HP TippingPoint Enterprise Security Products, in a statement. "Collaborating with pioneering security companies like Trend Micro supports our mission to deliver the most comprehensive solutions on the market to block and remediate advanced threats."

Continue reading: Hewlett-Packard, Trend Micro team up to defend against attacks (full post)

Dell ramps up 'BYOD' security efforts for business IT administrators

| Feb 24, 2014 8:51 PM CST

To help companies trying to embrace the "bring your own device" craze, Dell has launched its SonicWall mobile security platform for managed and unmanaged tablets and smartphones.

Dell included SonicWall Mobile Connect 3.0 and SonicWall secure remote access (SRA) 7.5 with its latest software update, giving administrators new abilities to ensure their networks are as secure as possible.

"In today's mobile workplace, it is vitally important to enable remote and mobile employees to maintain their productivity without compromising network security," said Patrick Sweeney, Dell Security Products Director of Product Management, in a press statement. "The co-mingling of business and personal applications and data on mobile devise presents an even greater challenge to IT when it comes to providing users with mobile access to everything they need to do their jobs, but still protecting corporate data - in-flight, at rest on the device, and on the network - from the multitude of threats posed by mobile devices."

Continue reading: Dell ramps up 'BYOD' security efforts for business IT administrators (full post)

Hewlett-Packard wants companies to team up in security battle

| Feb 24, 2014 4:45 PM CST

Hewlett-Packard wants to push the boundaries of cyber threat collaboration, hoping to bring organizations together in an effort to share threat intelligence.

In 2013 alone, companies across the world spent an estimated $46 billion to counter cyberthreats - but the number of attacks actually increased 20 percent - and HP hopes to reduce the number of attacks.

"Collaboration is fueling unprecedented innovation in the criminal marketplace, enabling the ecosystem of adversaries to stay ahead of our defenses," said Art Gilliland, HP Enterprise Security Products SVP, in a press statement. "Crow-sourced threat intelligence from our vast community of customers, partners and researchers is essential in this battle against cyercrime; we need to stop chasing silver bullet technologies and start sharing actionable intelligence through our solutions, expertise and best practices if we are going to compete and win."

Continue reading: Hewlett-Packard wants companies to team up in security battle (full post)

80 percent of wireless routers for small offices face vulnerabilities

| Feb 24, 2014 3:48 PM CST

Around 80 percent of the top 25 small office/home office (SOHO) wireless routers available on Amazon are susceptible to security vulnerabilities that put users at risk, according to research recently compiled by security and compliance company Tripwire.

The Tripwire Vulnerability and Exposure Research Team (VERT) also found that 34 percent of the top 50 best-selling routers have publicly documented exploits out in the wild.

"Unfortunately, users don't change the default administrator passwords or the default IPs in these devices and this behavior, along with the prevalence of authentication bypass vulnerabilities, opens the door for widespread attacks through malicious web sites, browser plugins, and smartphone applications," said Craig Young, Tripwire security researcher, in a press statement.

Continue reading: 80 percent of wireless routers for small offices face vulnerabilities (full post)

NSA spying revelations cause stir in privacy and security markets

| Feb 22, 2014 5:00 PM CST

Following former NSA contractor Edward Snowden's disclosure of widespread spying by the U.S. government, there has been a massive push to develop privacy-centric software and hardware. During the 2014 RSA Conference, which begins on Monday in San Francisco, data security and privacy solutions will be demonstrated at a frantic time in the industry.

In addition to the "Blackphone" being publicly unveiled, Google Android apps to better protect smartphones and tablets from sophisticated malware will also be shown off. Software security company AVG plans to release a "privacy fix" to identify what information companies can easily find about individual users.

If government snooping wasn't enough, the Android OS is being targeted with malicious apps, while PC users are under fire from advanced malware.

Continue reading: NSA spying revelations cause stir in privacy and security markets (full post)

Security measures like one-time passwords are becoming more common

| Feb 22, 2014 7:20 AM CST

Companies searching for new methods to keep networks safe and defend against cyberattacks are increasingly turning to strong authentication and one-time passwords, according to market research firm Frost & Sullivan.

Strong authentication is the technique used by banking and financial institutions, while one-time passwords are single-use passwords that better protect against phishing and other security breaches.

Smaller boutique security vendors have popped up to help fill the void in a booming security market. Since more companies and consumers are scrambling for security solutions this will lead to a market of acquisitions as larger companies gobble up smaller, niche security firms.

Continue reading: Security measures like one-time passwords are becoming more common (full post)

Malicious apps in Google Play store increased almost 400 percent

| Feb 20, 2014 5:34 PM CST

Mobile app infections in the Google Play app store have increased almost 400 percent from 2011 to 2013, according to online security group RiskIQ. Just three years ago, there were around 11,000 malicious apps available in the store, but that drastically increased to at least 42,000 by 2013, with Google trying to continue to fight back.

Around 12.7 percent of apps in the store are said to be compromised, with less than a quarter of the apps removed. The following categories were targeted the most: personalization, entertainment, education/books, media/audio video, and sports apps, according to RiskIQ.

"The explosive growth of mobile apps has attracted a criminal element looking for new ways to distribute malware that can be used to commit fraud, identity theft and steal confidential data," said Elias Manousos, RiskIQ CEO, in a press statement. "Malicious apps are an effective way to infect users since they often exploit the trust victims have in well known brands and companies they do business with like banks, insurance companies, healthcare providers and merchants."

Continue reading: Malicious apps in Google Play store increased almost 400 percent (full post)

Google acquired SlickLogin to replace passwords with inaudible sounds

| Feb 17, 2014 7:03 AM CST

Google recently acquired an Israel based startup called 'SlickLogin', which indicates that the company is making plans to replace passwords and even two-factor authentication methods with an inaudible sound unique to your phone and Google login.

SlickLogin has a patented technology where your passwords and two-factor authentication setups can be replaced with a unique and inaudible sound. Once enabled, the website's login page would typically listen to this inaudible sound via your phone and then granting access to your account. This could solve a lot of problems and overcome the possibility of your email account being hacked by someone. All you have to do is hold your smartphone near your PC with the website's login page, and the access will be granted.

The startup's team seem to be excited to work with Google, as they said that the company has been working on some great ideas to make internet safer for everyone.

Continue reading: Google acquired SlickLogin to replace passwords with inaudible sounds (full post)

Unnamed U.S. law firm caught up in NSA spying, report states

| Feb 16, 2014 7:19 PM CST

American attorneys were caught up with the NSA's global surveillance program, as an unnamed U.S. law firm representing an overseas client currently in a bitter legal battle with the U.S. government. Specifically, the Australian and U.S. governments agreed to share information on a law firm that was retained by the Indonesian government - and information protected under attorney-client privilege was likely included.

Attorney-client privilege isn't protected from NSA eavesdropping, though the American Bar Association demands attorneys to "make reasonable efforts" so confidential information isn't shared with others.

There has been growing concern that governments conducting spying and surveillance could breach attorney-client privilege with little recourse.

Continue reading: Unnamed U.S. law firm caught up in NSA spying, report states (full post)

Former NSA analyst creates encryption tool to prevent snooping

| Feb 11, 2014 4:26 AM CST

Former NSA analyst Will Ackerly and his brother, John Ackerly, are the co-founders of Virtru, a startup security company helping users encrypt e-mails and digital communications. Unlike other encryption solutions, Virtru allows users to encrypt information - and send it - and has an extremely easy user interface to ensure neither user needs to be overly tech savvy.

The Virtru plugin easily and quickly encrypts e-mails and other contents using AES 256 encryption standard, and senders must have the plugin installed. However, recipients only need to authenticate their identity with an e-mail address, and Virtru holds the decryption key.

"What we've tried to do - and what's different from what a lot of encrypted communication tools out there have done - is really spend time to integrate the encryption technology directly into Gmail, Yahoo, Outlook.com," John Ackerly, Virtru CTO, in a statement to the media.

Continue reading: Former NSA analyst creates encryption tool to prevent snooping (full post)

Join Our Newsletter

Join the TweakTown Newsletter for daily tech updates delivered to your inbox.

See previous giveaways.

Newsletter Subscription