Hacking, Security & Privacy - Page 6
Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 6
Stay Updated
Follow TweakTown for breaking tech news, reviews, and daily updates.
As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.
Microsoft fixes a record-breaking number of security vulnerabilities
Microsoft has fixed a record-number of security vulnerabilities in an April 9, 2024 update that the company has classified as critical.
The 147 security vulnerabilities have now been fixed, with three of them being in Microsoft Defender for IoT, and all but two of them considered "high risk". The company says that none of the security vulnerabilities have been exploited, and it hasn't provided any details on the vulnerabilities themselves.
According to reports the large number of the vulnerabilities that are now patched are in response to a number of Remote Code Activation (RCE) exploits found in the OLE DB driver for SQL Server (38), DHCP and DNS servers (9) and SFB vulnerabilities within Secure Boot (24).
Continue reading: Microsoft fixes a record-breaking number of security vulnerabilities (full post)
Google paid $10 million to people finding issues with its products in 2023
Google has taken to its blog to share a 2023 Year in Review for its Vulnerability Reward Program, a community-driven security effort that Google pays decent money for.
Google has rewarded 632 security researchers from 68 different countries with $10 million for all of the bugs discovered in the company's products such as Android and Google-powered devices. Notably, the maximum payout per issue was $15,000, and the biggest payout for a vulnerability report throughout 2023 was $113,337. During 2023 Google added generative AI platforms such as Gemini were added to the Vulnerability Reward Program, and throughout the year 35 reports were paid out for a total of $87,000.
More specifically, Google writes that for Android and Google's own devices it paid out $3.4 million for bugs discovered, with bugs found in its Wear OS and Android Automotive operating systems generating $70,000 across 20 critical bug discoveries. Google Chrome security researchers earned a hefty chunk of money pulling in $2.1 million for 359 vulnerability reports. If you are interested in reading more about this story, check out Google's blog post here.
Microsoft responds to 'holy grail' of Windows vulnerabilities
Microsoft has finally addressed what has been described as the "holy grail" of Windows security vulnerabilities after being informed about it six months ago.
Cybersecurity researchers from Avast informed Microsoft of the "holy grail" of security vulnerabilities in Windows that was used by the North Korean hackers Lazarus Group. The rootkit vulnerability was an admin-to-kernel exploit that was associated with a driver for AppLocker, which is an app that is designed for whitelisting software built into Windows. Notably, the vulnerability was discovered in the input/output dispatcher of appid.sys.
Furthermore, Avast claims that Lazarus Group used this specific vulnerability to gain access to read/write primitive on the Windows kernel that was later used to install their FudModule rootkit. Avast said that Microsoft's belated response to the vulnerability demonstrates the company's opinion on the severity of the vulnerability.
Continue reading: Microsoft responds to 'holy grail' of Windows vulnerabilities (full post)
Microsoft officially announces its under attack by hackers being paid by Russia
Microsoft has taken to its blog to officially announce that it is currently under attack by hackers sponsored by Russia.
In its blog post, the company explains that on January 12, 2024, Microsoft's security team detected an attack on its corporate email systems, which triggered an immediate response by Microsoft and an investigation. The company identified the hackers as "Midnight Blizzard," a Russian state-sponsored actor that is also known as Nobelium. Since then, Microsoft has been conducting its investigation and has reported back that Midnight Blizzard is using information that it obtained through its hack on Microsoft's corporate email systems to "gain, or attempt to gain, unauthorized access."
More specifically, Microsoft writes that these attempts have resulted in "some of the company's source code repositories and internal systems" being accessed. Notably, Microsoft writes that it hasn't discovered any evidence of Microsoft-hosted customer-facing systems being compromised. Furthermore, Microsoft writes that Midnight Blizzard has increased its volume of attacks by as much as 10 times in February compared to the attacks it was experiencing in January.
Google engineer faces 10 years in prison for stealing AI secrets for China
Many nations around the world are concentrating their efforts toward creating the most powerful artificial intelligence system, with the main goal being achieving Artificial General Intelligence (AGI), or a system that is capable of achieving the same level as sophistication as a human brain.
With the AI arms race fully underway, the two main countries competing are the United States and China. According to a report from The Verge, China has just gained a bunch of trade secrets from one of the biggest players in the game, Google. The report states that one Google engineer, Linwei Ding, also called Leon Ding, has been indicted by a federal jury and accused of stealing trade secrets regarding Google's AI chip software and hardware.
The former Google engineer has been accused of stealing 500 confidential files containing these AI secrets and being involved with China-based AI companies. Notably, the majority of the contents within the files is about Google's tensor processing unit (TPU), which is the hardware that powers many AI workloads such as the company's Gemini project.
Windows and Android users warned against growing Russian cybersecurity threat
A new malware campaign launched in December is beginning to gain steam, with researchers now putting out a warning to Windows and Android users.
The emerging cybersecurity threat targets corporate users, and according to researchers from Zcaler's ThreatLabz, which penned a new blog post discussing the threat, the attackers are specifically using fake online meeting hosting requests on a single IP address. These URLs are convincing enough to get corporate officials to kick on them to join the meeting as they are masquerading as Skype, Google Meet, and Zoom meeting requests.
Notably, the malware that is infected into the device is capable of stealing sensitive user data, or even company information. With this information the bad actor could then initiate ransomware, which is when bad actors threaten the company they stole the information from with either permanently locking the stolen data or releasing it online by a certain date - unless a substantial payment is made.
Malwarebytes software blocked malware from infecting a PC... from a vibrator connected via USB
Recently, a Redditor posted a strange but funny incident surrounding malware being discovered using Malwarebytes software on a PC. Apparently, they connected a vibrator (yes, the pleasure toy) to their PC to charge when Malwarebytes Premium prompted them that it blocked malware from trying to infect the PC via the USB port.
The, err, Sexology Pussy Power 8-Function Rechargeable Bullet Vibrator from Spencer was reportedly infected with something called Lumma - which steals information related to cryptocurrency, browser extensions, two-factor authentication, and more. Malwarebytes confirmed the story via its blog, noting Lumma is often associated with email, so spreading it via USB is less common but not unheard of.
To make the situation a little more on-the-nose, to avoid getting an STCV (sexually transmitted computer virus), Malwarebytes recommends the use of USB condoms. An actual device that sits on a USB port that prevents data exchange when a device is connected.
Epic Games reportedly attacked by ransomware group that stole nearly 200GB of data
A hacking group has claimed they have infiltrated Epic Games servers and stolen nearly 200GB of data from the company.
The Fortnite developer has reportedly been hacked by ransomware group Mogilevich, which WCCFTech and Cyber Daily report is a relative newcomer to the hacking scene. Regardless of its purported reputation, or lack of it, Mogilevich has claimed they have infiltrated Epic Games servers and stolen 189GB of data, which includes emails, passwords, full names of accounts, payment information, source code, and much more. Notably, the stolen data is reportedly up for sale, but there is currently no price attached, with a deadline set for March 4.
It should be noted the group has not provided any proof of their claims, which reasonably leads to the assumption of the possibility no data was actually stolen, especially considering that Epic Games hasn't confirmed nor denied the hack. While it's currently up in the air whether the hack took place or not, I would be recommended to change your Epic Games account as a precautionary measure.
Cyber attacks are on the rise, and global costs will reach up to $18 trillion by 2030
Technology has advanced so rapidly that most devices in a 2024 household are always online smart devices perpetually connected to the cloud. Beyond this, no workforce, industry, or government agency exists without a complex and interconnected web of users, systems, and online technologies. Is it any wonder that cyber-attacks are on the rise and have cost the world $8 trillion USD in 2023?
According to ExpressVPN, the cost of cyber-attacks has increased steadily in recent years. With the rise of generative AI and more sophisticated technologies, the $8 trillion figure will hit $9.5 trillion in 2024 and effectively double to $17.9 trillion by 2030. Last year alone, the cost of cyber attacks would have made it the third-largest economy in the world behind the United States and China.
As for who bears the brunt of the cost, if you answered 'us,' you're correct. Looking into over 550 organizations hit by data breaches, IBM's 2023 Cost of Data Breach report arrived at this conclusion - additional costs passed onto consumers in various ways. So, the next time you see a subscription fee increase, one of the main reasons could very well be cybersecurity costs.
Three million smart toothbrushes infected by malware were used in a massive DDoS attack
UPDATE: Turns out the following story was just a hypothetical situation and not real, an error in translation. "To clarify, the topic of toothbrushes being used for DDoS attacks was presented during an interview as an illustration of a given type of attack, and it is not based on research from Fortinet or FortiGuard Labs," Fortinet confirmed in a statement. "It appears that due to translations, the narrative on this topic has been stretched to the point where hypothetical and actual scenarios are blurred." The original story follows.
In the age of every household object doubling as a smart device, this headline might not be as strange as it sounds - and could soon become the norm. It seems that recent Swiss DDoS attacks that caused millions in damage resulted from - get this - three million smart toothbrushes infected by hackers with malware forming a botnet. Yeah, it is not exactly something you can (apologies in advance) brush off - as it highlights some of the dangers of smart devices like toothbrushes connecting to a network for seemingly simple tasks like tracking oral hygiene habits.
Apparently, there was a vulnerability in the Java-based OS, but the report doesn't indicate which online toothbrush brands were involved in the attacks. Probably all of them when you consider that next to no one is sitting there updating the firmware and monitoring the network traffic on their toothbrush.
Your webcam might be shuttered, but an ambient light sensor is also a risk for being spied on
If you were worried about your webcam being a privacy threat, well, here's some bad news - there's something else to be concerned about that snoopers could leverage on your devices, namely the ambient light sensor.
These light sensors are present with many pieces of hardware - from phones and tablets through to laptops, or indeed TVs - and as the name suggests, they detect ambient light levels in order to adjust screen brightness appropriately.
However, there's a dark side to the light sensor, in that it can be compromised to spy on you, rather like a webcam (which these sensors are often placed near in laptops), if not to quite the same extent in terms of the invasion of your privacy.
Fortnite maker Epic Games lays off 870 workers, CEO says Epic is 'far short' of sustainability
Epic Games, the company who has spent millions of dollars fighting Apple in court, today announced it has laid off hundreds of employees.
2023 is a year of exceptional volatility in the games industry, and not even the world's biggest companies are safe. Today Epic Games announced it would lay off around 870 workers in an effort to reduce costs. Epic's decision follow thousands of tech sector layoffs made throughout 2023, including gaming jobs that were pared back at Xbox, Electronic Arts, Activision, and the Embracer Group.
Epic Games CEO Tim Sweeney says the company is simply "far short of financial sustainability," and confirms that Epic is spending more than it makes. Epic will divest--or sell off--recently-acquired subsidiary Bandcamp and spin off most of its SuperAwesome media division.
Ransomware group claims to have hacked all of Sony's systems, company 'currently investigating'
According to a new report at Cyber Security Connect, a ransomware group called Ransomed.vc claims that it has compromised all of Sony's system and is putting up all of the company's data for sale.
It's a bold claim and could be one of the biggest security breaches in a long time, especially when you factor in the size and scope of Sony's operations - which includes over 40 million PlayStation 5 owners and gamers.
Ransomed.vc announced the breach on its leak sites, adding that Sony isn't willing to pay for the data it's up for sale. The extent of the breach and the validity of the claim haven't been confirmed, with Sony offering a statement to IGN that says it is " "currently investigating the situation" though it offers "no further comment at this time."
Microsoft AI researchers accidentally expose 38TB of data to GitHub
A staggering 38 terabytes of data was accidentally leaked by Microsoft AI researchers on the website called GitHub, according to a cloud security company report.
The new report released by Wiz, a cloud security company, among the leaked files, were two entire backups of workstation computers that contained confidential Microsoft information such as company "secrets, private keys, passwords, and over 30,000 internal Microsoft Teams messages". The incredibly large data exposure may result in Microsoft's AI systems being vulnerable to attack or any other Microsoft-related systems. So, how did this happen?
Unfortunately, it was a simple yet critical mistake that occurred when Microsoft AI researchers were trying to publish a "bucket of open-source training material" and "AI models for image recognition" to GitHub. The files' SAS token was misspelled, resulting in the public's storage permissions switching to the entire storage account rather than the AI material that developers were attempting to publish. Unfortunately, the bad news doesn't stop there.
Continue reading: Microsoft AI researchers accidentally expose 38TB of data to GitHub (full post)
Hackers claiming responsibility for shutting down MGM Resorts say it took just a 10 minute call
The company wrote in a statement that it identified a cybersecurity threat in some of its systems that has resulted in its website being temporarily shut down.
MGM Resorts released a statement that confirmed its systems powering a selection of its casinos along the Las Vegas stripe detected a cybersecurity issue that caused some slot machines being taken offline, with other gambling systems also being temporarily shut down. The company said it took "prompt action to protect our systems and data," but isn't sure how widespread the vulnerability is and what systems have been affected by the attack.
The ALPHV/BlackCat ransomware group have claimed responsibility for the attack in a forum post, where it boasts that it was extremely easy to gain access to MGM Resort's systems. The ransomware group claims they used basic social engineering tactics to gain the necessary information to access the systems in order to obtain data that would force MGM Resorts to pay a ransom. However, MGM Resort refuses to pay the group.
Good-guy hackers destroy spyware across 75,000 phones
A group of unnamed hackers have gained access to spyware firm WebDetetive to delete device information in a move to protect 10s of thousands of people from being surveilled.
Spyware is exactly what it sounds like - a piece of software that grants remote access to an individual's device to spy on them. Through this access, users can listen in on victims' phone calls, read messages, track locations, send/receive data such as photos/videos, view screens in real-time, and much more. Typically, this type of software is used by nefarious people who are interested in tracking individuals, monitoring there whereabouts and to gather intelligence that is typically used to blackmail the victim.
However, spyware is also used by government agencies to catch criminals. WebDetetive was one of these types of spyware until a group of unnamed hackers accessed their system and removed the device information from 76,000 devices, along with more than 1.5 gigabytes of data stored on the spyware service's servers. It should be noted that these are claims from a group of hackers and are yet to be independently verified.
Continue reading: Good-guy hackers destroy spyware across 75,000 phones (full post)
WinRAR version 6.23 patches up a very serious security flaw, so make sure you update now
If you're one of them any PC users out there that use WinRAR to handle their compression-related tasks (it's still one of the most popular archive utilities), then you might want to make sure you update to WinRAR version 6.23. Grab it here.
The latest version of the shareware app patches a rather significant security flaw dubbed CVE-2023-40477, allowing hackers to access memory beyond the allocated buffer.
The flaw would give hackers code execution on the target system, though only after opening a malicious RAR file. Still, you're looking at a very serious vulnerability when someone can execute commands on your PC simply because you opened a RAR file, let alone extracted its contents. The fact that it requires the user to open a specific RAR file dropped the security flaw's severity rating to 7.8.
AMD Ryzen CPUs affected by 'Inception' vulnerability and the fix could impact performance
Most modern Ryzen CPUs built using the Zen 3 and Zen 4 architectures (including the latest Ryzen 7000 series) are affected by the 'Inception' vulnerability. A new speculative side-channel attack that can expose sensitive or otherwise secure data - per AMD's description that you can read in full here.
The current understanding of 'Inception' is that the vulnerability is local, meaning you'd need to download malware containing the exploit for a potential issue. AMD notes that older Ryzen CPU hardware using the original Zen and Zen 2 architectures remain unaffected.
Regarding exploits, Inception is similar to the well-known Spectre attack, where secure data is accessed within memory via features in modern CPUs - going as far as to grab passwords, keys, and other secure data. The good news is that the exploit is being addressed in an upcoming AGESA Firmware update due for release later this month.
Microsoft vulnerability causes government emails to be hacked, officials launch investigation
A Microsoft cloud breach that resulted in China state-backed hackers breaking into U.S. government emails has led the Cyber Security Review Board to launch an investigation.
The Cyber Security Review Board (CSRB) announced on Friday that its investigation will look into cloud-based identity and authentication infrastructure, which will lead to a wider review of all potential and current problems.
This investigation was launched following U.S. government official email accounts being infiltrated by China state-backed hackers that gained access to U.S. Commerce Secretary Gina Raimondo's inbox, several other officials at the U.S. State Department, and officials at a few different government agencies.
US military detects hidden Chinese malware on multiple systems that has an unusual intent
US officials have claimed they have discovered what they suspect is Chinese malware designed to perform a specific task.
A new report from The New York Times has revealed that US officials have found Chinese malware across several military systems and that this malware isn't like the typical Chinese malware as it has a specific purpose - to disrupt. According to the report from the NYT, the malware isn't designed for surveillance, which is the typical form of malware that's discovered on US military and government systems.
Experts claim the recently discovered malware is simply to disrupt US military and civilian operations, and according to National Security Agency deputy director George Barnes, "China is steadfast and determined to penetrate our governments, our companies, our critical infrastructure." Notably, Rob Joyce, the director of cybersecurity at the NSA, said last month that the capabilities of the malware are "really disturbing" as it's able to shut off water and power and disable communications for both military bases and civilians.






















