Hacking, Security & Privacy - Page 7
Stay informed with the latest hacking, cybersecurity, and privacy news, including data breaches, leaks, cyber attacks, and tips to stay safe online. - Page 7
Stay Updated
Follow TweakTown for breaking tech news, reviews, and daily updates.
As an Amazon Associate, we earn from qualifying purchases. TweakTown may also earn commissions from other affiliate partners at no extra cost to you.
Denuvo Anti-Tamper DRM creators want to prove it doesn't impact performance in PC games
It's a common belief that DRM in PC game releases, specifically the popular Denuvo Anti-Tamper anti-piracy software, adversely impacts performance. If a PC game is rocking DRM, you're looking at a noticeable drop-off in performance compared to a version of the same PC game without DRM-a pirated copy.
The Denuvo platform is owned by digital security company Irdeto, who bought Denuvo in 2018. In an interview with Ars Technica, Irdeto Chief Operating Officer of Video Games Steeve Huin, said, "There is no perceptible impact on gameplay because of the way we do things." Adding that anti-piracy measures are a benefit to both game publishers and players as it ensures that it protects investments and leads to more games in the future.
"Whether people want to believe it or not, we are all gamers, we love gaming, we love being part of it," Steeve Huin says. "We develop technologies with the intent to make the industry better and stronger." Translation, the people behind Devuno have a different take and want to prove it.
Starfield allows players to sell planet survey data, set up interstellar economies
One of the best ways to make money in Starfield is to sell data from planets that you survey.
Starfield has 1,000 planets, and while only about 100 of them have life, that doesn't mean the rest of the 900 planets are complete barren wastelands with nothing to do. Bethesda has outlined an interesting player motivation loop that will keep you busy and reward you for venturing into the unknown and discovering planets.
In a very real sense, Starfield will make players into a kind of interstellar data analyst. You'll land on a planet, survey its life and resources, and then sell that data to a group in the game. This also brings lots of interesting implications--can you sell the data to the highest bidder? What happens if you sell it to the the pirates at the Crimson Fleet...will they start landing on the planets more often? Hmm...
Own an ASUS router? Then you might need to patch it right away
Some ASUS routers need a firmware update applied as soon as possible, as it contains important security fixes.
ASUS published a security advisory urging owners to upgrade to a new firmware release that delivers various resolutions for a raft of vulnerabilities, as Bleeping Computer spotted.
This includes a fix for nine security holes, including some severe ones - such as CVE-2022-26376, which is a memory corruption vulnerability, and CVE-2018-1160. The latter is an out-of-bounds write Netatalk flaw that can be leveraged to carry out arbitrary code execution.
Continue reading: Own an ASUS router? Then you might need to patch it right away (full post)
Nintendo Switch homebrew project shutdown after new Zelda game leaks
Lockpick is a tool used to legitimately play Nintendo Switch games on PC, in that it's designed to work with games you own via accessing the physical files and keys. With the upcoming The Legend of Zelda: Tears of the Kingdom leaking ahead of its launch, the creators of Lockpick have reportedly received a DMCA takedown notice from Nintendo.
One of Lockpick's programmers/contributors took to Twitter to confirm this by stating, "Nintendo has just issued multiple DMCA takedown requests to GitHub, including for Lockpick, the tool for dumping keys from your own Switch."
He argues that pirates that emulate software do not use keys from their own copies of games, though emulation has always been a legal grey area regarding what and what you cannot do with the physical copies of games you own.
Continue reading: Nintendo Switch homebrew project shutdown after new Zelda game leaks (full post)
Google Authenticator one-time passwords will now sync with your Google account
Google Authenticator is a popular app that gives your accounts an additional layer of two-step authentication security and is widely used by millions. But, it's the sort of app that is limited to a single Android or iOS device, which puts a lot of pressure on people to ensure that they don't lose their smartphone where Authenticator is installed.
It's a potential issue that Google is well aware of, and it is looking to remedy it by making the one-time passwords backup and sync to your Google Account.
"One major piece of feedback we've heard from users over the years was the complexity in dealing with lost or stolen devices that had Google Authenticator installed," writes Christiaan Brand, Google's Group Product Manager, in a new blog post. "Since one-time codes in Authenticator were only stored on a single device, a loss of that device meant that users lost their ability to sign in to any service on which they'd set up 2FA using Authenticator."
Patch Chrome now, as Google's browser has a nasty security flaw
Google has pushed out an update for its Chrome browser to patch up a serious vulnerability.
This is a fix for a zero-day security flaw (CVE-2023-2136), so it's been deployed in a fair old hurry by Google, which acknowledged that it was aware that an exploit for the vulnerability exists in the wild (meaning malicious actors out there have already leveraged this flaw to their advantage).
Bleeping Computer reports that running the new version of Chrome, 112.0.5615.137 (or 138), ensures that this problem is cured, and indeed a bunch of other vulnerabilities - eight of them in total.
Continue reading: Patch Chrome now, as Google's browser has a nasty security flaw (full post)
Hackers discover they can remotely make Tesla's honk uncontrollably
A team of security researchers found a slew of vulnerabilities within Tesla's that give them control over a few different parts of the vehicle.
The security researchers work for Synacktiv, a security research firm that supported the team presenting their findings at the Pwn2Own conference in Vancouver last week. The researchers explained that a string of three vulnerabilities within the software allowed them to take control system to turn off the car lights, honk the horn, open the trunk, activate the windshield wipers, and play with the infotainment system.
Notably, the researchers explained the first security vulnerability was discovered in the vehicle's Bluetooth settings, and the second vulnerability gave the hackers enough vulnerability to become root, or in layman's terms, obtain the highest level of administrative access to the system. Once the security researchers gained root access, they were able to execute code in the infotainment system that gave them control of the security gateway, a component that sends specific commands to the vehicle.
Continue reading: Hackers discover they can remotely make Tesla's honk uncontrollably (full post)
There's now a fix for Windows 11's nasty 'acropalypse' security flaw
Microsoft has swiftly deployed emergency fixes for a security flaw in Windows 11 that affected the Snipping Tool (and the Snip & Sketch app in Windows 10, too).
Those screenshot-grabbing and editing utilities were blighted by an issue whereby cropped data in PNG image files wasn't being properly overwritten, playfully named the "acropalypse" bug.
In other words, when users crop a file, the part of the picture discarded could potentially be recovered and scrutinized by someone exploiting the flaw.
Continue reading: There's now a fix for Windows 11's nasty 'acropalypse' security flaw (full post)
Listen up, Google: Here's what YouTube should do to prevent channel hijacking
Over the past couple of days, the big news was that Linus Tech Tips, a huge YouTube channel with over 15 million subscribers, was hacked. The hackers were able to change the channel name and live stream a fake Elon Musk video trying to get viewers to send Bitcoin to them.
Thankfully, Google helped Linus and his team recover his channel. Still, I can only imagine it would have been an incredibly stressful and nightmare-type situation while the recovery was in process. And it's not just Linus Tech Tips that was hacked. A few weeks ago, Andy from eTeknix suffered the same fate after being conned by a fake video sponsorship scheme where the victim is tricked into opening what appears to be an agreement PDF - the "PDF" file is the malware.
Once opened, the malware sends the user's data to the hacker. It does not matter how strong your password is or if you have enabled two-factor authentication. It's not entirely clear which data is sent, but the critical data we know that is sent includes the user's browser data, including actively logged-in session tokens and cookies. Once obtained, the hacker can carefully plan an attack on the unsuspecting victim, usually when they are asleep.
Linus Tech Tips, one of the most popular tech YouTube channels, got hacked
UPDATE: It looks like the Linus Tech Tips channel has been restored, with the channel re-appearing literally moments after this story went live. Here's the original article.
Popular and long-running tech-focused YouTube channel Linus Tech Tips (and those associated with the Linus Media Group) was hacked overnight and used as a platform to promote crypto scams. After a few tumultuous hours, the account was ultimately delisted.
The channel is still down, though a statement released by channel owner Linus Sebastian notes that "we are now on top of it with Google's team now." Adding that "we are getting to the bottom of the attack vector with the (hopeful) goal of hardening their security around YouTube accounts and preventing this sort of thing from happening to anyone in the future."
Basketball fans, take note: NBA warns of personal details leaked in data breach
The NBA has warned about a data breach that has resulted in the theft of some personal details.
That personal data was stolen from what's described as a third-party newsletter service. Those affected have reportedly been contacted by the NBA and notified of the breach, and that some personal info was leaked, including names and email addresses.
However, the NBA clarified that its own systems had not been hacked, and that usernames, passwords, and suchlike have not been compromised.
Massive ACER data breach sees hacker putting up 160GB of data for sale
Taiwanese computer company Acer has confirmed that it has experienced a massive data breach. However, its investigation into the hack indicates that customer data has not been stolen and is limited to things found on a server for repair technicians. The confirmation arrives after a hacker put up the data for auction on a popular hacker forum - claiming that 160GB of data had been stolen.
The hacker claims that the data includes "confidential" internal slides and presentations, staff documentation for technical support, Windows images, product information across various devices, "tons of BIOS stuff," and other files. The threat actor shared screenshots of schematics for an Acer display and other confidential documents to prove the data theft was real.
There isn't a price set other than the data will go to the highest bidder with the condition that payment is made via the hard-to-trace cryptocurrency Monero.
Continue reading: Massive ACER data breach sees hacker putting up 160GB of data for sale (full post)
Windows 11 just got some vital security updates, so don't hang around, patch now
Windows 11 just got a raft of security fixes in the latest round of monthly patching from Microsoft, including some crucial ones.
In fact, there are three fixes for zero-day vulnerabilities provided, meaning bugs in Windows 11 which are public knowledge. And in this case, these security flaws are being actively exploited by nefarious types - so they represent a clear potential danger to Windows 11 users.
In total, there are 77 vulnerabilities fixed by Microsoft's February patch for Windows 11 PCs, and nine are labeled as 'critical.'
Federal 'No Fly List' exposed by US airline hacker reveals heavy biases
The US airline CommuteAir reportedly left a federal "No Fly List" on an unsecured server that was then accessed by a Swiss hacker.
The exclusive report comes from The Daily Dot that claims US airline CommuteAir left an unsecured server open that contained a large quantity of sensitive information. This server was accessed by a Swiss hacker that goes by "maia arson crimew" who wrote a blog post titled "how to completely own an airline in 3 easy steps," where they explained that they stumbled across the sensitive server by accident and through boredom.
Essentially, the hackers were just looking around through a search engine called Shodan when they discovered the server and a file titled "NoFly.csv". The file was opened, and the hackers discovered a 2019 version of a federal No Fly list that includes first and last names as well as dates of birth. The Daily Dot reports the list contained the names and aliases of many high-profile people, such as the recently-freed Russian arms dealer Viktor Bout and his 16 aliases.
The FBI recommends using an adblocker to protect you from cyber criminals
Malware in the form of an advertisement in Google or other search engine results is not uncommon. We recently reported on a case involving a shady ad impersonating AMD for a user simply looking to update their graphics driver.
As spotted by a user on the Linus Tech Tips forums, the FBI posted a new Public Service Announcement (PSA) earlier this month, explicitly calling out this issue.
As per the PSA.
Norton announces thousands of its customer accounts have been hacked
Norton LifeLock, a very well-known provider of identity protection and cybersecurity services, recently revealed in an announcement that thousands of its customers had their accounts compromised.
The parent company of Norton LifeLock, Gen Digital, states that the likely cause of the hack was a "credential stuffing" attack, which is when previously exposed or breached credentials of accounts are used to break into other accounts on different sites and services that have the same passwords. The company notes that it detected a "large volume" of failed logins to customer accounts on December 12, which led them to discover that the intruders had compromised accounts dating back to December 1.
The company sent notices to about 6,450 Norton customers whose accounts were affected by the breach. In the data breach notice, Gen Digital states that the unauthorized third party may have viewed customers' first names, last names, phone numbers, and mailing addresses. The company also said that it could not rule out that the intruders also accessed some customers' saved passwords.
Continue reading: Norton announces thousands of its customer accounts have been hacked (full post)
Google serves up malware for user looking to update their AMD Graphics Drivers
A few days ago, on the popular PCMR subreddit, a user warned others that when he searched for "amd driver" the top result was an advertisement for a malicious website claiming to offer precisely that.
Of course, this wasn't a legitimate search result, but appearing above their search results, it was an ad made to look like the real thing. In our testing, it seems like the search result and site have both been removed, which is good to see.
Still, according to multiple sources, it was host to a dubious .exe download titled "Auto-Detect and Install Driver Updates for AMD Radeon Series Graphics and Ryzen Chipsets", which sounds legitimate. Until you take a closer look at the URL and realize it would definitely not do that. The site even featured AMD branding and AMD IP, a tactic that isn't new in the world of malware.
An easy way to protect your kids while browsing the net with Google Chrome
It wasn't until recently that I discovered Chrome has an in-built feature to help protect your kids (and anyone, actually) while browsing the web with Google's popular web browser. A recent Facebook post from the Google Chrome page alerted me to its "Enhanced Protection" security mode and family DNS feature, which we dive into below.
In the simplest terms, when turned on, this feature proactively monitors the user's behavior in Chrome and blocks bad websites, downloads, and extensions before they can cause a problem on your device. For example, you or your child might be about to enter a harmful website that attempts to steal important information. Chrome blocks the website and presents a very obvious red screen warning you.
A little discussion with your kids would go a long way, alerting them if they see this obvious red screen, reminding them it's a bad site and they shouldn't visit it. Chrome can also scan any downloads before the files are executed for malware. Privacy advocates may not be impressed by the feature since some of your data and activity need to be processed by Google. Still, it should be a suitable compromise for most if security concerns you. Considering this free feature doesn't slow down your devices as external security monitoring software and apps can, it's well worth it.
Hackers target US public airports sparking response from US officials
A group of hackers that are suspected of being Russian targeted more than a dozen US airport websites on Monday.
According to reports from ABC News and several other publications, a group of hackers believed to be located in Russia targeted fourteen US airport websites on Monday, with some of the websites being LaGuardia, O'Hare and LAX. The hack brought down the website for approximately fifteen minutes and sparked a response from a US government official that stated air traffic control, along with internal airport communications and other critical operations, weren't impacted by the hack.
However, travelers that were interested in wait times or any other information found on the website would have experienced an inconvenience. Furthermore, a spokesperson for LAX said that the attack didn't compromise internal airport systems and that there were no operational disruptions to report.
Continue reading: Hackers target US public airports sparking response from US officials (full post)
Student psychological profiles released in 500GB of stolen school data
In what appears to be the largest education breach in the last couple of years, a large amount of student data has been released by a group of hackers that infiltrated a school system last month.
The hacking group named Vice Society claimed responsibility for the ransomware attack on Los Angeles Unified School District (LAUSD), which resulted in the bad actors gaining access to emails, computer systems, applications, and more. Reports indicate that hundreds of gigabytes of student data was stolen and that the hacker group demanded an undisclosed amount of money for the return of the data. Unfortunately, as expected by U.S. authorities, the data was released online as the October 4 deadline was not met.
According to Tech Crunch, the stolen data was posted to Vice Society's dark website and contains extremely sensitive data on students, such as personal identification information, passport details, Social Security numbers, and tax documents. Additionally, the half a terabyte of leaked sensitive information also contains confidential information in the form of documents, contracts, health information on students/staff, COVID-19 test data, conviction reports, and psychological assessments on students.
Continue reading: Student psychological profiles released in 500GB of stolen school data (full post)






















