Newsletter IconFacebook IconX IconThreads IconInstagram IconYouTube IconPinterest Icon
Giveaway: AVerMedia Creator Bundle (4K Webcam, Capture Card, Charging Hub, and Mouse Pad)

Hacking, Security & Privacy - Page 50

Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 50

Stay Updated

Follow TweakTown for breaking tech news, reviews, and daily updates.

Add TweakTown as a preferred source on GoogleFind TweakTown on Apple News

As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.

FBI collecting its own malware library to study cyber threats

| Feb 8, 2014 9:32 PM CST

In the continued battle against cyber warfare, the FBI recently opened the door to security experts willing to share information about malware. Specifically, the Investigative Analysis Unit (IAU) wants to create "global awareness of the malware threat" in anticipation of what lies ahead in the future. The request for quote (RFQ) is a unique effort to purchase malware so the FBI intelligence services are able to try and reverse-engineer the security threats.

The FBI is currently seeking security firms to submit malware samples for federal computer teams to learn more about how the malicious software is made and distributed. Executive files, digital media files, exploited code, and Office documents will be collected, though security experts are welcome to try and stump the FBI with select malware.

Sophisticated malware continues to plague desktop and mobile users, with malware targeting Microsoft Windows, Linux, and Apple OS X/iOS.

Continue reading: FBI collecting its own malware library to study cyber threats (full post)

Malwarebytes will now cost $25 per year following extensive update

| Feb 3, 2014 4:25 PM CST

For many years now, Malwarebytes has been a staple in many Windows users anti-virus / anti-malware toolbox. It gained this position not only because it works so well, but because it was a powerful solution that was completely free. Today the company announced that Malwarebytes 2.0 will be moving away from its free to download model be moving away from a lifetime licence model, and will instead move to an annual subscription licensing model.

The company says that Malwarebytes 2.0 will cost users $24.95 per year with a licensing covering three separate PCs, a fee that is much cheaper than many of the big-name anti-virus programs on the market. "As more and more people have come to rely on us for malware protection and cleanup, our costs in bandwidth, hosting fees, infrastructure, salaries of our researchers, QA department, and more have grown immensely," explained Kleczynski, CEO of Malwarebytes. "Though our company is about more than just making money, we are a company and we do have to make money to pay our staff to continue doing what they love, which is fighting malware. The subscription model will help us to be sustainable for the future while staying true to our roots that we will always make malware cleanup free for everyone"

Malwarebytes says that its customers who have already purchased lifetime licenses will not need to pay the annual subscription fee, and the company will continue to offer lifetime licenses for a short period to ease the transition for those users who have wanted to take the lifetime plunge, but have yet to do so. What do you think about Malwarebytes moving to a paid version only model to a annual subscription over lifetime license model, and will you be jumping in to grab one of the few lifetime licenses left?

Continue reading: Malwarebytes will now cost $25 per year following extensive update (full post)

Chewbacca point-of-sale threat steals your debit, credit card info

| Feb 2, 2014 8:07 AM CST

A point-of-sale malware designed to steal debit and credit card information has been found on systems in 11 different countries, according to security company RSA. Dubbed ChewBacca, the malware was first discovered in late October, and has been found on in-store POS, directly blamed for stealing at least 49,000 account numbers to date.

The Tor-based malware threat communicates with the Command and Control (C&C) server using the anonymous Internet network - protecting the IP addresses of controllers. ChewBacca has proven successful in encrypting traffic and slipping through network-level detection, despite being a relatively simple piece of malware.

In-store POS threats, typically malware to steal customer information, typically go unnoticed, but consumers are becoming more aware of current threats. Criminals want to do whatever is necessary to steal data that they can either use, trade, or sell to other criminals - at the expense of retailers and consumers.

Continue reading: Chewbacca point-of-sale threat steals your debit, credit card info (full post)

U.S. officials think reporters are Edward Snowden's "accomplices"

| Jan 30, 2014 11:14 AM CST

U.S. officials are still trying to come to terms with former NSA analyst Edward Snowden's spying disclosures, with James Clapper, the Director of the National Intelligence, demanding his journalist "accomplices" return leaked documents.

Clapper didn't place blame on specific "accomplices," but reporters at The Guardian, for example, would likely be an obvious choice.

Clapper's spokespeople later clarified and said the U.S. official "was referring to anyone who is assisting Edward Snowden to further threaten our national security through the unauthorized disclosure of stolen documents related to lawful foreign intelligence collection programs."

Continue reading: U.S. officials think reporters are Edward Snowden's "accomplices" (full post)

SpyEye malware creator pleads guilty, prepares for time in prison

| Jan 29, 2014 10:26 AM CST

The founder of the SpyEye malware, Aleksandr Andreevich Panin, recently pleaded guilty to federal conspiracy and bank fraud charges. The Russian citizen was extradited to the United States early last year, and will be sentenced on April 29, where he will almost certainly receive a prison sentence.

SpyEye was reportedly created in 2009 and remotely infected PCs so cyber criminals could access personal information, including bank accounts, usernames and passwords. Panin sold licenses to the software from $1,000 up to $8,500, with more than 150 global clients using the malware to steal information.

"As several recent and widely reported data breaches have shown, cyber attacks pose a critical threat to our nation's economic security," said Sally Yates, U.S. Attorney of the Northern District of Georgia, in a statement. "Today's plea is a great leap forward in our campaign against those attacks."

Continue reading: SpyEye malware creator pleads guilty, prepares for time in prison (full post)

Craft store Michaels investigating possible credit card data breach

| Jan 26, 2014 1:20 PM CST

Arts and crafts store Michaels is the latest to suffer a data breach, with the Secret Service now lending a hand in the follow-up investigation, the store confirmed over the weekend. Suspected cyber criminals have stolen credit and debit card numbers, immediately sharing news of the breach once it was confirmed.

At least four financial institutions have identified fraudulent activity for card holders after recently shopping at Michaels.

"We are concerned there may have been a data security attack on Michaels that may have affected our customers' payment card information and we are taking aggressive action to determine the nature and scope of the issue," said Chuck Rubin, Michaels CEO, in a statement. "While we have not confirmed a compromise to our systems, we believe it is in the best interest of our customers to alert them to this potential issue so they can take steps to protect themselves, for example, by reviewing their payment card account statements for unauthorized charges."

Continue reading: Craft store Michaels investigating possible credit card data breach (full post)

Russia snubs U.S. wishes, not in big hurry to end Snowden's asylum

| Jan 25, 2014 8:59 AM CST

Former National Security Agency (NSA) IT contractor Edward Snowden could be able to stay in Russia for more than one year, as the Russian government said they don't plan to send him packing.

Snowden, currently in Russia on a temporary one-year asylum, has offers from Brazil and several Central American countries interested in taking him in - but Alexy Pushkov, the Russian Foreign Affairs Committee legislator, noted that Snowden could stay longer. The 30-year-old American is now free to stay in Russia, working for private Russian companies, until he is ready to return back to the U.S.

During a recent online chat, Snowden said he would like to one day return to the United States, but that cannot happen unless he's granted protection under the federal Whistleblower Protection Act - which doesn't apply to former government contractors. Meanwhile, Snowden continues to claim he didn't carry out actions for Russia or any other foreign government, though some U.S. lawmakers still aren't so sure about that.

Continue reading: Russia snubs U.S. wishes, not in big hurry to end Snowden's asylum (full post)

Edward Snowden says he can't get a fair trial if he returns to the US

| Jan 23, 2014 11:07 PM CST

Edward Snowden, the former National Security Agency (NSA) IT contractor now living in Russia following his high-profile data leak, won't return to the United States until current laws are changed. The federal Whistleblower Protection Act isn't applicable to former government contractors, which means he could face significant legal trouble if he returns to the United States.

"Returning to the U.S., I think, is the best resolution for the government, the public, and myself, but it's unfortunately not possible in the face of current whistleblower protection laws," Snowden said in response to a question about getting a fair shake if he one day returns to the United States.

It seems highly unlikely Snowden will return to the U.S. unless he's offered immunity by the U.S. government, which is something the White House hasn't recently discussed publicly. It seems that the NSA and other government agencies would be able to learn from Snowden, but he won't touch U.S. soil just to face possible espionage charges.

Continue reading: Edward Snowden says he can't get a fair trial if he returns to the US (full post)

U.S. lawmaker claims Edward Snowden had outside help to steal data

| Jan 20, 2014 3:03 PM CST

The United States government believes National Security Agency (NSA) whistle blower Edward Snowden possibly received support from the Russian government.

"I don't think Mr. Snowden woke up one day and had the wherewithal to do this all by himself," said Rep. Michael McCaul (R-Teaxas), in a recent TV interview. "To say definitively I can't answer that, but I personally believe he was cultivated by a foreign power to do what he did. Again, I can't give a definitive statement on that, but I think given all the evidence I know Mige Rogers has access to, that I've seen, that I don't think he was acting alone."

Snowden has evolved into an enigma since his public data breach last year, as the former CIA technical assistant received a GED and dropped out of a Maryland community college. Described as a "geek," it seems shocking that he would eventually find his way to the U.S. government contractor Booz Allen Hamilton - and would remain there until he quickly left for Hong Kong in 2013.

Continue reading: U.S. lawmaker claims Edward Snowden had outside help to steal data (full post)

Cyber security threats growing against users, companies, Cisco says

| Jan 19, 2014 5:47 AM CST

Cyber security threats continue to plague users and businesses trying to defend against increasingly sophisticated and well-executed attacks, according to the Cisco 2014 Annual Security Report. Cyber security is a major business as Cisco and other companies develop cyber security efforts to protect end-users and businesses.

Overall cyber attacks increased 14 percent in 2013, with select industries facing a staggering number of attacks designed to steal information and disrupt day-to-day operations. The pharmaceutical, agriculture, mining, chemicals and electronics industries all saw an increase in malware aimed at compromising systems - a whopping growth of 600 percent - while energy, oil and gas industries saw a 400 percent increase in malware and cyber attacks.

"Although the Cisco Annual Security Report paints a grim picture of the current state of cyber security, there is hope for restoring trust in people, institutions and technologies - that that starts with empowering defenders with real-world knowledge about expanding attack surfaces," said John Stewart, Cisco Chief Security Officer, noted in a press release. "To truly protect against all of these possible attacks, defenders must understand the attackers, their motivations and their methods - before, during and after an attack."

Continue reading: Cyber security threats growing against users, companies, Cisco says (full post)

President Obama will announce massive NSA reform this Friday

| Jan 13, 2014 7:48 PM CST

The White House has announced that President Obama will on Friday, announce plans for NSA reform. Obama is expected to leverage a mix of executive orders and actions that will fundamentally change the way the NSA can gather information. One of the biggest actions that will be put into motion is the extension of privacy rights to non American citizens.

Other actions include the creation of a so-called "Privacy Advocate" which will argue on the peoples behalf in front of the Foreign Intelligence Surveillance Court, which now only hears arguments for spying on behalf of the government. Obama is also expected to call for a complete restructuring of the phone-data program, and will state that data collected should be held by phone companies or a third party as to offer a barrier from unwarranted access to private files.

Personally, I caution everyone to remember that most of this is still smoke and mirrors, and true reform would involve ceasing any and all collection of information on American citizens without a court order. Furthermore, Obama would have never acted to reform these policies if it would not have been for Edward Snowden and his very loud whistle blowing. While this may seem like a small victory, more work will need to be done before the NSA can truly be given the title of "reformed."

Continue reading: President Obama will announce massive NSA reform this Friday (full post)

Snapchat user database hacked, 4.6M users compromised

| Jan 1, 2014 9:30 PM CST

Snapchat is one of the most popular image sharing services in the mobile ecosystem, and today more than 4.6 million users are learning that their contact information has been hacked by unknown persons. A website called SnapchatDB.info has popped up that list out usernames and phone numbers of each account that was compromised.

Originally thought of as a hoax, SnapchatDB.info has been confirmed as real and its creators say that they stole the information and created the website to raise awareness around the security issues surrounding Snapchat. SnapchatDB.info did censor the last two digits of each phone number to reduce spam, and unwanted messages to users, but with only 10 numbers per spot, it would only take a few minutes to figure out which is correct. The full statement from SnapchatDB.info has been pasted below.

Continue reading: Snapchat user database hacked, 4.6M users compromised (full post)

DROPOUTJEEP - the NSA program that backdoors every iPhone

| Dec 30, 2013 9:14 PM CST

According to security researcher Jason Appelbaum, and German news magazine Der Spiegel, the NSA has the ability to spy on virtually every iPhone, and users' digital communication sent from said iPhone.

The NSA reportedly has a program called DROPOUTJEEP, which allows the US spy agency to intercept most things - including SMS messages, contact lists, the physical location of the iPhone (and its user) through cell phone data, and even the ability to access the iPhone's microphone, and camera. Leaked documents have helped put the picture together, with the NSA claiming a 100% success rate when it comes to getting spyware into iOS-based devices.

Then comes the scary part: that the NSA requires physical access to the device, which the US spy agency reportedly reroutes shipments of iPhone's purchased online, but it is also working on a remote version, which is even worse. Appelbaum says: "Either [the NSA] have a huge collection of exploits that work against Apple products, meaning they are hoarding information about critical systems that American companies produce, and sabotaging them, or Apple sabotaged it themselves."

Continue reading: DROPOUTJEEP - the NSA program that backdoors every iPhone (full post)

Users more worried about identity theft than privacy

| Dec 27, 2013 11:35 PM CST

Despite fallout from former IT specialist Edward Snowden, it appears more U.S. voters are interested in security over privacy-related issues. Seventy-five percent of users are worried about personal information theft over 54 percent of those users worried about browsing history being tracked.

"By wide margins this survey clearly shows that ID theft has touched the majority of consumers in some way, and that hacking is more worrisome to consumers than tracking, and that voters want the government to more aggressively go after cyber criminals," said Ed Black, CCIA President and CEO, in a statement. "Safeguarding users online must become a higher priority for companies and also for the regulators and policymakers charged with protecting consumers."

Even though security is more thought about by U.S. citizens, privacy concerns have caused a major backlash against the National Security Agency (NSA), other US federal branches, and a handful of major corporations.

Continue reading: Users more worried about identity theft than privacy (full post)

Security researchers warn of cross-platform DDoS botnet

| Dec 27, 2013 7:10 PM CST

A new DDoS Botnet has the ability to infect both Microsoft Windows along with Linux-based systems, according to the Poland Computer Emergency Response Team (CERT). Unlike many cyber-based attacks, this botnet is only interested in launching DDoS attacks to knock certain servers and websites offline.

The Linux-based botnet reportedly handles dropping servers, while the Windows-based botnet easily hijacked consumer PCs. "Most servers that are injected with these various scripts are then used for a variety of tasks, including DDoS, vulnerability scanning, and exploiting," according to security expert Andre Dimino, in a blog post. "The mining of virtual currency is now often seen running in the background during the attacker's 'downtime.'"

Seeing DDoS attacks to turn zombie PCs into an effective botnet isn't Earth-shattering news, but this cross-platform attack is relatively unique. As bitcoin mining and launching attacks to impact certain companies is easily done when using unsuspecting machines.

Continue reading: Security researchers warn of cross-platform DDoS botnet (full post)

Researchers indicate MacBook webcams can be compromised

| Dec 19, 2013 12:30 PM CST

Researchers from Johns Hopkins University confirmed it's possible to turn on a laptop's web camera without turning on a light that informs users the camera is on. Just a few years ago, it didn't seem possible to hack a webcam like this, but it's something consumers need to be somewhat vigilant about.

The team focused on Apple MacBook and iMac models available before 2008, but said the exploit can be used on a variety of different models. Although Apple initially opened up communication with Johns Hopkins University to discuss the problem, there reportedly haven't been any further updates.

Using a Remote Administration Tool (RAT), for example, works around the computer's security and remotely controls the computer webcam.

Continue reading: Researchers indicate MacBook webcams can be compromised (full post)

Researchers use NSA tricks to see just how much data it collects

| Dec 1, 2013 12:21 AM CST

We know that the NSA's PRISM system scoops up unimaginable amounts of data, so a couple of researchers created an Android app to see just how much metadata is collected from a smartphone, which was compared to basic information on Facebook.

The two Stanford researchers, Jonathan Mayer and Patrick Mutchler, created MetaPhone, using it to see how revealing the metadata was. Mayer told MIT Technology Review: "Some defenders of the NSA's bulk collection programs have taken the position that metadata is not revealing. We want to provide empirical evidence on the issue.... Our hypothesis is that phone metadata is packed with meaning."

You can grab MetaPhone yourself, a free app from the Google Play Store, with the app capable of collecting call and text logs, and asks for basic information from Facebook. Early research points to the fact that the metadata definitely includes some juicy data on you, with early results showing that phone metadata can predict whether someone is in a relationship with around 60% accuracy.

Continue reading: Researchers use NSA tricks to see just how much data it collects (full post)

Google Nexus devices are at risk of DDoS attacks through SMS messages

| Nov 30, 2013 12:36 AM CST

Bogdan Alecu, a system administrator at Dutch IT services company, Levi9, has discovered an issue that leaves Google Nexus devices open to DDoS attacks that would reboot the smartphone, or fail to connect to mobile Internet services.

Alecu discovered the issue in all Android 4.x firmware versions of Google's Nexus, Nexus 4 and Nexus 5 smartphones. If a Nexus smartphone was to receive the message, it would display itself on top of every other active window, and is surrounded by a semi-transparent black overlay that has a dimming effect on the screen. If this message isn't saved, or dismissed, a second message is received, which is placed on top of the first message, and the dimming effect continues.

These messages will hit the Nexus phones without a notification, so if they're being sent when you're asleep, or the phone is in your pocket, you'll be none the wiser. Most of the time, Alecu says the phone will reboot, and if a PIN is required to unlock the SIM card, the phone won't connect back to the network for hours. During this time, the phone is useless, as it is unable to receive messages, phone calls, or any other notifications.

Continue reading: Google Nexus devices are at risk of DDoS attacks through SMS messages (full post)

New Snowden leaks show the NSA captures Google data center traffic

| Oct 31, 2013 1:31 AM CDT

According to some documents supplied to the Washington Post by Edward Snowden, Google and Yahoo data centers across the world are intercepted directly by the NSA and GCHQ. The program is known as "Muscular" and can tap into the main communications link that connect Google and Yahoo data centers.

A documented dating back to January 9, 2013 says that the NSA captured millions of records from the search giants each and every day, sending them to NSA data warehouses. Within a 30-day period, over 180 million records were collected, all of which included metadata, text communications, audio and video, too.

The Washington Post did say that the NSA doesn't keep everything, which should help you sleep at night (so much sarcasm intended). Both search giants maintain multiple data centers around the world for redundancy reasons, with data shared between the data centers all the time. Google has said that it was not aware of the NSA activity, with a Yahoo spokesperson saying that it has strict controls in place to protect the security of their data centers, and that it has not given the NSA or anyone else access to their data centers.

Continue reading: New Snowden leaks show the NSA captures Google data center traffic (full post)

Anonymous: US gov't is using Apple's TouchID to collect fingerprints

| Oct 2, 2013 10:29 PM CDT

Most are impressed with the NSA's Apple's TouchID fingerprint scanner, being the only real change on the iPhone 5S, but hacking collective Anonymous has come out with quite the claim: the US government is using the TouchID database to collect citizens' fingerprints.

Anonymous has released a video, above, with several documents supporting its claim. Anonymous claims to have uncovered evidence of a "corrupt alliance" between the US government and a bunch of its contractors. AuthenTec, the company who made Apple's TouchID technology, reportedly has strong ties to "the most powerful and corrupt Defense Department and Intelligence Community contractors and figures." This is an interesting quote from the piece:

Continue reading: Anonymous: US gov't is using Apple's TouchID to collect fingerprints (full post)

Join Our Newsletter

Join the TweakTown Newsletter for daily tech updates delivered to your inbox.

See previous giveaways.

Newsletter Subscription