Newsletter IconFacebook IconX IconThreads IconInstagram IconYouTube IconPinterest Icon
Giveaway: AVerMedia Creator Bundle (4K Webcam, Capture Card, Charging Hub, and Mouse Pad)

Hacking, Security & Privacy - Page 5

Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 5

Stay Updated

Follow TweakTown for breaking tech news, reviews, and daily updates.

Add TweakTown as a preferred source on GoogleFind TweakTown on Apple News

As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.

Kaspersky hits back at US government over the banning of its products

| Jul 19, 2024 1:03 AM CDT

In June the US government deemed the popular anti-virus software Kaspersky, which is used by millions of users around the world, a prohibited software as it was found to be a risk to national security.

Kaspersky hits back at US government over the banning of its products

In March 2022, the Federal Communications Commission (FCC) ruled that Kaspersky posed an "unacceptable risk to national security" due to its ties to the Russian government, which Kaspersky irrefutably denied. The anti-virus company denied having ties to any government and acts as an independent multinational company. Additionally, Kaspersky said the decision to ban its products across the United States was a purely political move.

The banning of Kaspersky by the Department of Homeland Security alleged the company has ties to the Russian government, presumably some kind of backdoor within its software that allows the Russian government access to devices running the Kaspersky software. Kaspersky responded by offering to reveal its source code to third parties for verification.

Continue reading: Kaspersky hits back at US government over the banning of its products (full post)

Microsoft officially approved this extremely dangerous door-opening malware

| Jul 19, 2024 12:31 AM CDT

A product that was originally marketed as a security product has been discovered to be malicious malware that injects a kernel-level infection that makes the device susceptible to further attacks.

Microsoft officially approved this extremely dangerous door-opening malware

A new investigative report into the malware called HotPages revealed researchers notified Microsoft of the malicious software on March 18, and it has since been removed from the Windows Server Catalog of where it was once approved on May 1. However, up until that point, HotPage was presumably delivered to its victims as a security product, masquerading as an ad blocker called DWAdsafe for internet cafes in China.

HotPage contained malicious code that dropped a vulnerable system-level driver that could enable any attacker with the highest level privilege to execute new malicious code within a device. Additionally, the malware didn't even remove ads; it instead intercepted web traffic and redirected and manipulated content within a victim's browser. The malware hooked Windows API functions to intercept and modify browser activity to collect information on the victim, which was then sent back to the HotPage creator's server.

Continue reading: Microsoft officially approved this extremely dangerous door-opening malware (full post)

FBI confirms its gained access to the phone of Trump's shooter

| Jul 17, 2024 3:33 AM CDT

The phone owned by Thomas Crooks, the man who shot and wounded former US president Donald Trump on July 13, has had his phone seized by the FBI, and now the US authorities have said they have gained access to the device.

FBI confirms its gained access to the phone of Trump's shooter

July 13 marked the failed assassination attempt of former US president Donald Trump, who dropped to the floor after a bullet wounded his ear. Authorities identified the shooter as Thomas Crooks, a 20-year-old registered Republican, and the FBI later announced it acquired his phone.

The now-deceased Crooks didn't leave behind any obvious motive for his actions against the former president, which is why the FBI is hoping its newfound access to his phone may reveal his reasoning behind his actions, if Crooks was working alone or as part of a bigger group, and if there are any other attempts such as the one at the Pennsylvania rally planned for the future.

Continue reading: FBI confirms its gained access to the phone of Trump's shooter (full post)

Alarms raised in security circles after largest password leak in hacking forum history

| Jul 9, 2024 7:34 AM CDT

Passwords may be one of the most annoying aspects of our daily lives, but they have become extremely important with the ever-growing adoption of the digital landscape. That is why it isn't good when nearly 10 billion unique plaintext passwords leak onto a hacking forum.

Alarms raised in security circles after largest password leak in hacking forum history

A user with the handle "ObamaCare," who has a history of leaking data such as employee databases sourced from law firms, and data acquired from colleges and casinos, posted on a hacking forum, "Xmas came early this year". The leaker added, "I present to you a new rockyou2024 password list with over 9.9 billion passwords!" ObamaCare is referencing a leak called "RockYou2021" where 8.4 billion passwords were leaked online.

Security experts over at Cybernews believe the leak could have extremely bad ramifications for users around the world, as the exposed users could see an increase in the number of online accounts being illegally accessed through brute force hacking. If you are interested in protecting yourself against such breaches, you can check if your password has been compromised using the Leaked Password Checker tool here.

Continue reading: Alarms raised in security circles after largest password leak in hacking forum history (full post)

Microsoft's new technology will use your eyes to decrypt secure documents

| Jul 8, 2024 1:57 AM CDT

Microsoft has filed an interesting patent for display technology that effectively decrypts documents in real-time based on a user's gaze. Yeah, so at a glance, the encrypted document would be unreadable to anyone apart from the document's owner. The technology would decrypt the document in real-time based on where the user is looking - and only the components or sections they're currently looking at.

Microsoft's new technology will use your eyes to decrypt secure documents

It takes the idea of the 'privacy screen' to a new level, as it isn't limited to hiding what's on screen for those sitting at an angle or behind someone in a public area but works in conjunction with document encryption and decryption.

As Windows Report spotted, the patent and documentation don't explain exactly how it will work. However, it will use a webcam and eye-tracking technologies to determine where you're looking and ensure that reading an entire document with this system isn't slow and laborious.

Continue reading: Microsoft's new technology will use your eyes to decrypt secure documents (full post)

The biggest password leak in history just happened: 10 BILLION passwords leaked by hacker

| Jul 6, 2024 8:51 PM CDT

On July 4 of all days, Independence Day for Americans, the largest password leak in history occurred, dubbed "RockYou2024" by the original poster "ObamaCare" on a leading hacking forum.

The biggest password leak in history just happened: 10 BILLION passwords leaked by hacker

There are an incredible 9,948,575,739 passwords compiled all in plain text, close to 10 billion passwords, posted by user "ObamaCare". The user registered on the hacking forum in late May 2024, previously sharing the employee database from law firm Simmons & Simmons, a lead from an online casino AskGamblers, and student applications from Rowan College at Burlington County.

The team cross-referenced the passwords in the huge "RockYou2024" leak with the data from Cybernews' Leaked Password Checker, which the site "revealed that these passwords come from a mix of old and new data breaches". Researchers said: "In its essence, the RockYou2024 leak is a compilation of real-world passwords used by individuals all over the world. Revealing that many passwords for threat actors substantially heightens the risk of credential stuffing attacks".

Continue reading: The biggest password leak in history just happened: 10 BILLION passwords leaked by hacker (full post)

The biggest ransomware attacks in recent history and the groups behind them

| Jul 3, 2024 1:15 PM CDT

Ransomware is a popular form of malware in which files on a device, server, or computer system are encrypted, and the actors (often a hacker group or syndicate) demand a ransom to decrypt the data - and it's on the rise. According to ExpressVPN, ransomware payments exceeded 1 billion USD in 2023, the highest amount ever. In the age of generative AI, increasingly sophisticated encryption methods will see this figure grow even higher.

The biggest ransomware attacks in recent history and the groups behind them

And then there's the rise of Ransomware-as-a-Service (RaaS), which is almost like a marketplace for ransomware tools and services - powered by the anonymity of cryptocurrency, the payment of choice for ransomware groups and hackers. The democratization of cyberattacks has opened the door to virtually anyone launching a cyberattack on unsuspecting individuals, businesses, or government bodies.

In recent years, large-scale ransomware attacks have targeted the healthcare industry, network security companies, Windows users, oil pipelines, and even Costa Rica. Here's a breakdown of the most notable.

Continue reading: The biggest ransomware attacks in recent history and the groups behind them (full post)

Man busted stealing passenger data from in-flight Wi-Fi with 'evil twin' strategy

| Jul 1, 2024 7:36 AM CDT

A man has been charged with stealing the credentials of people's social media and email services while on a commercial airline.

Man busted stealing passenger data from in-flight Wi-Fi with 'evil twin' strategy

The Australian Federal Police (AFP) charged a man who was carrying a "portable wireless access device, a laptop, and a mobile phone" in his luggage. The AFP claims the man was attempting to scrape sign-in information from passengers aboard a flight by running a fake Wi-Fi network on a plane. The alleged man was reportedly creating fake Wi-Fi hotspots with SSIDs that were very similar to the network names found on flights, or an "evil twin".

When a user joined the network, they were prompted to input their credentials, which included email addresses and passwords that were then saved to the man's device. At the moment, authorities charged the man with unauthorized access to devices, along with "possession or control of data with the intent to commit a serious offense," which alludes to the man having the intention of using the data nefariously.

Continue reading: Man busted stealing passenger data from in-flight Wi-Fi with 'evil twin' strategy (full post)

Microsoft hack was worse than it seems as more customers are told their emails were stolen

| Jul 1, 2024 4:43 AM CDT

Microsoft confirmed it was breached on January 12, 2024, by hackers that gained access to Microsoft's corporate email accounts, leading to the theft of federal government email accounts.

Microsoft hack was worse than it seems as more customers are told their emails were stolen

While the hack was considered extremely bad at the time, and it still is, it appears the breach may be worse than initially anticipated as more Microsoft customers are receiving emails their email account has become compromised, meaning it wasn't just federal email account data stolen, but also customer data.

Microsoft blamed the attack on a Russian government-sponsored hacking organization called Midnight Blizzard, and according to the software giant, they are providing notifications to customers who were exposed to the hack through email correspondence with compromised Microsoft corporate email accounts.

Continue reading: Microsoft hack was worse than it seems as more customers are told their emails were stolen (full post)

Microsoft faulted for massive hospital record data heist by former employee

| Jun 26, 2024 12:34 AM CDT

An American healthcare provider that serves more than 1.2 million people is concerned a former employee from the Microsoft-owned Nuance Communications stole sensitive data on more than a million patients.

Microsoft faulted for massive hospital record data heist by former employee

Geisinger, an American healthcare provider for more than a 1.2 million people across Pennsylvania announced a security breach took place last year that was traced back to a former employee of Nuance Communications, the Microsoft-owned IT provider. Geisinger discovered the security breach on November 29 and immediately contacted Nuance Communications, which discovered the individual removed his access before the authorities were notified.

Nuance Communications then launched its own investigation and discovered the former was terminated from their position and then two days later accessed the sensitive records, making copies of records on more than a million Geisinger patients. The data includes birth dates, addresses, hospital admissions, discharge records, medical data, and demographic information. Notably, financial and insurance information wasn't stolen, according to Geisinger.

Continue reading: Microsoft faulted for massive hospital record data heist by former employee (full post)

The United States Federal Reserve hacked: 33TB of data stolen by ransomware group LockBit

| Jun 24, 2024 8:08 PM CDT

Uhh... so the United States Federal Reserve has been hacked, with a new post on a Dark Web leak site associated with ransomware group LockBit, holding 33TB of incredibly confidential financial data from the Fed.

The United States Federal Reserve hacked: 33TB of data stolen by ransomware group LockBit

On June 23, 2024 at 8:27 UTC, LockBit announced it had hacked into the systems of the Federal Reserve, with 33TB of sensitive banking information taken. The data includes confidential details of American banking activities, which if veritified, would make this one of the largest breaches of financial data in history.

The post reads: "Federal banking is the term of a way the Federal Reserve of the United States distributes its money. The Reserve operates twelve banking districts around the country which oversee money distribution within their respective districts. The twelve cities which are home to the Reserve Banks are Boston, New York City, Philadelphia, Richmond, Atlanta, Dallas, Saint Louis, Cleveland, Chicago, Minneapolis, Kansas City, and San Francisco".

Continue reading: The United States Federal Reserve hacked: 33TB of data stolen by ransomware group LockBit (full post)

Notorious hacker leaks internal Apple source code following AMD breach

| Jun 20, 2024 12:05 AM CDT

A hacker has claimed to have breached Apple security and extracted the source for three internal Apple tools, only a day after the same hacker claimed to have breached AMD.

Notorious hacker leaks internal Apple source code following AMD breach

BreachedForums user "IntelBroker" announced yesterday they infiltrated AMD and stole customer databases, upcoming product specifications and plans, internal financials, source code, firmware and ROMs, and information on employees - names, user IDs, phone numbers, and other sensitive information. Notably, this isn't the first time IntelBroker has claimed responsibility for a high-profile hack.

Europol, Home Depot, and the Pentagon all admitted to experiencing a breach this year, all of which IntelBroker claimed responsibility for and placed the hacked information onto the dark web for sale. However, it's one thing to claim responsibility for a hack and another to have actually hacked who you are claiming and extracted valuable data.

Continue reading: Notorious hacker leaks internal Apple source code following AMD breach (full post)

World's most popular operating system threatened by new form of malware

| Jun 13, 2024 8:39 PM CDT

Hacking groups have been using a piece of weaponized code for nearly 10 years to access both Windows and Linux operating systems, and now security researchers have discovered it is not a variant of other malware but its own individual entity.

World's most popular operating system threatened by new form of malware

A new report published by Trend Micro has outlined a go-to form of malware used by Chinese-state-sponsored hacking groups such as Iron Tiger and Calypso. The piece of malware is believed to have been used since at least 2016, and was originally thought to be a variant of other famous malware such as Gh0st RAT and Rekoobe. Trend Micro reports the new malware isn't a variant of the aforementioned malware, but a "new type altogether".

The publication suspects its currently being used by many Chinese hacking groups performing espionage or cybercrime, and it has been dubbed "Noddle RAT". The new form of malware has been confirmed on both Windows and Linux machines, with some instances dating back as far as July 2016.

Continue reading: World's most popular operating system threatened by new form of malware (full post)

Ticketmaster just got hacked exposing more than half a billion users

| Jun 1, 2024 2:32 AM CDT

A hacking group has claimed to have stolen an astonishing 500 million Ticketmaster customers' data, which includes a treasure trove of sensitive user data.

Ticketmaster just got hacked exposing more than half a billion users

It was only last month Ticketmaster was slapped by the Department of Justice (DOJ), which filed an anti-trust lawsuit against Ticketmaster's parent company Live Nation Entertainment over its alleged monopoly on the entertainment industry. Now, Ticketmaster is reportedly suffering as a hacking group claimed to have stolen more than 500 million Ticketmaster customers' data in a recent attack, which the group is now turning around and attempting to sell for $500,000.

According to the hacker group the treasure trove of stolen data is approximately 1.3 terabytes and contains various sensitive user information such as full names of Ticketmaster customers, their addresses, phone numbers, email addresses, order history and ticket purchase details. It doesn't stop there. The group also claims to have scraped customers' payment data which includes names and the last four digits of their credit card numbers that were used at checkout of the ticketing service.

Continue reading: Ticketmaster just got hacked exposing more than half a billion users (full post)

US authorities arrest administrator behind 'likely world's largest botnet ever'

| May 31, 2024 10:01 PM CDT

United States authorities announced they have arrested the administrator behind what is likely the world's largest botnet, which included more than 19 million compromised Windows machines across multiple countries.

US authorities arrest administrator behind 'likely world's largest botnet ever'

The description of the world's largest botnet comes from FBI director Christopher Wray, who said the botnet was used to gather millions of dollars from people over the last 10 years. More specifically, the FBI director said to the Justice Department that a international cyber operation was conducted to identify the alleged administrator of the botnet known as "911 S5", who was found to be the individual Yunhe Wang. Wang was arrested and US authorities "seized infrastructure and assets, and levied sanctions against Wang and his co-conspirators," said Wray.

The infection of this botnet was truly global, with US officials writing the 911 S5 Botnet had infected PCs in nearly 200 countries and "facilitated a whole host of computer-enabled crimes, including financial frauds, identity theft, and child exploitation." Moreover, the US Treasury wrote in its announcement Wang didn't act alone in the venture, and named two more alleged perpetrators, Jingping Liu and Yanni Zheng. In total, the US authorities believe the botnet netted Wang and others involved $99 million.

Continue reading: US authorities arrest administrator behind 'likely world's largest botnet ever' (full post)

College students discover security flaw that could let millions do laundry for free

| May 20, 2024 4:32 AM CDT

Two college students discovered a security exploit within the API of a washing machine that is currently in use across several countries.

College students discover security flaw that could let millions do laundry for free

Alexander Sherbrooke and Iakov Taranenko discovered the security flaw within the API created by the company behind the washing machines, CSC ServiceWorks. The two students claim the vulnerability within the internet-connected API enabled them to remotely turn a machine on without payment, and update their laundry account to display millions of dollars. Reports indicate that CSC ServiceWorks has more than a million machines across college campuses, housing communities, and laundromats in the US, Canada, and Europe.

The two college students contacted CSC ServiceWorks about the security flaw and didn't receive a response from the company, but noticed shortly after their laundry account balance was changed from millions of dollars back to $0. The two students spoke to The Verge and said the lack of response from CSC ServiceWorks led them to tell other people about the vulnerability, which resulted in the posting of the list of commands that enables anyone to access CSC's network-connected laundry machines.

Continue reading: College students discover security flaw that could let millions do laundry for free (full post)

How to Stay Safe from Cybercrime While Traveling Abroad

| May 9, 2024 6:27 AM CDT

Traveling to a new country for work, leisure, or vacation can be as exciting as it can be daunting. You want to make the most of your time abroad, so everything from flights to accommodation to sites to see and food and beverages to consume happens online. However, at any point, do you stop and take a moment to consider cyberattacks and cybersecurity when traveling or planning a trip?

How to Stay Safe from Cybercrime While Traveling Abroad

The answer should be yes because cybercrime is as much of a threat as physical crime, especially when going on holiday or traveling to a new country.

According to ExpressVPN, a recent survey showed that 7% of travelers experienced some form of hacking or fell victim to a digital scam while traveling. This figure wasn't far off the 10% that experienced physical crime in the form of hotel room theft or pickpocketing.

Continue reading: How to Stay Safe from Cybercrime While Traveling Abroad (full post)

FBI confirms Chinese hackers have infested US water and energy systems

| Apr 19, 2024 10:46 AM CDT

FBI director Christopher Wray has said that a Chinese hacking group has infiltrated critical infrastructure systems in the US and is simply just waiting for the right moment to strike.

FBI confirms Chinese hackers have infested US water and energy systems

Wray revealed the news at the Vanderbilt Summit on Modern Conflict and Emerging Threats and said the group behind the attacks is called Volt Typhoon, and they have infested systems that are dedicated to controlling water, energy, and telecommunications. More specifically, Volt Typhoon has gained access to 23 pipeline operators, and according to the FBI director, China is developing the "ability to physically wreak havoc on our critical infrastructure at a time of its choosing."

Wray says China's plan is to attack critical civilian infrastructure to induce panic among the population. "Its plan is to land low blows against civilian infrastructure to try to induce panic," said Wray. Additionally, the FBI director said it was difficult to determine if these hacks are part of China's overall intention to push the US away from defending Taiwan.

Continue reading: FBI confirms Chinese hackers have infested US water and energy systems (full post)

US government blames Microsoft for hackers stealing federal email accounts

| Apr 12, 2024 12:38 AM CDT

Microsoft announced early last month that on January 12, 2024, it detected a security breach in its corporate email systems, which was traced back to the notorious hacking group Midnight Blizzard.

US government blames Microsoft for hackers stealing federal email accounts

The hacking group is known to be a Russia government-backed group that also goes by the name Nobelium, and the attack on Microsoft servers resulted in the group gaining access to federal government emails. Now, the US Cybersecurity and Infrastructure Security Agency (CISA), the cybersecurity arm of the US government, has confirmed via a statement published on Thursday that federal government emails were stolen "through a successful compromise of Microsoft corporate email accounts."

On April 2, the cybersecurity agency released an emergency directive ordering civilian government agencies to take action to secure their accounts, as the agency received new information that Russian-backed hackers were increasing the frequency of their attacks. CISA didn't specifically mention the US government agencies affected by the Microsoft hack.

Continue reading: US government blames Microsoft for hackers stealing federal email accounts (full post)

Apple sends threat notification to users about state-of-the-art spyware attacks

| Apr 11, 2024 12:53 AM CDT

Apple has issued a threat notification to users in 92 countries, warning them that they may have been an individual target of mercenary spyware attacks.

Apple sends threat notification to users about state-of-the-art spyware attacks

The company took to its support blog to explain its threat notifications are designed to inform users they may have been individually targeted by mercenary spyware attacks because of who they are or what they do. Notably, Apple states these attacks are "vastly more complex than regular cybercriminal activity and consumer malware" as mercenary spyware groups have "exception resources," and they target a small number of specific individuals and their devices.

Additionally, Apple says these mercenary groups apply "millions of dollars" to their hacking ventures, and they only have a "short shelf life," which makes them very hard to detect/prevent. Apple says that historically, these attacks can be traced back to state-sponsored groups or private companies performing the attacks on behalf of the state, and since 2021, the company has notified users in over 150 countries.

Continue reading: Apple sends threat notification to users about state-of-the-art spyware attacks (full post)

Join Our Newsletter

Join the TweakTown Newsletter for daily tech updates delivered to your inbox.

See previous giveaways.

Newsletter Subscription