Showing posts with label Hackers. Show all posts
Showing posts with label Hackers. Show all posts

Thursday, October 7, 2021

Popular live video streaming site Twitch confirms hack

Amazon's popular live video streaming platform Twitch said Wednesday hackers had broken into its network after reports of exposed confidential company data surfaced online.

The service, where users often stream live video game play, confirmed the break-in on Twitter.

"We can confirm a breach has taken place," Twitch said in post from its verified Twitter account.

"Our teams are working with urgency to understand the extent of this."

The statement came after reports emerged that a massive dump of Twitch data had been posted on fringe anonymous message board 4Chan. 

A post at 4Chan served up 125 gigabytes of data reported to include Twitch source code, records of payouts to streamers, and a digital video game distribution service being built by Amazon Game Studios.

It did not appear that personal Twitch user data was in the dump, but the extent of the hack was still being investigated.

Google searches for "how to delete Twitch" rocketed eightfold as news of the hack spread, according to marketing analysts firm N. Rich.

"With such a concerning data breach from a platform as widespread and global as Twitch, users are naturally wanting to protect themselves and their data as soon as possible," an N.Rich spokesperson said.

The person who posted the trove of stolen data left a message claiming the break-in was performed to foster competition in video streaming, and because the Twitch community "is a disgusting toxic cesspool," according to media reports.

Users of Twitch, the world's biggest video game streaming site, staged a virtual walkout last month to voice outrage over barrages of racist, sexist and homophobic abuse on the platform.

The phenomenon of "hate raids" -- torrents of abuse -- has seen the platform become increasingly unpleasant many for Twitch streamers who are not white or straight.

A Twitter hashtag, #TwitchDoBetter, has become a magnet for complaints over the past month, largely from female, non-white and LGBTQ players saying that Twitch is failing to stop internet trolls running amok -- all while taking 50 percent of streamers' earnings.

Twitch has maintained that it is working to improve tools for protecting accounts from abuses.

The service is suing two users in US federal court, accusing them of orchestrating the so-called "hate raids."

Agence France-Presse

Wednesday, March 10, 2021

Hackers breach cameras at banks, jails, Tesla and more

SAN FRANCISCO, United States - A US hacker collective on Tuesday claimed to have tapped into footage from 150,000 security cameras at banks, jails, schools, carmaker Tesla and other sites to expose "the surveillance state."

Images captured from hacked surveillance video were posted on Twitter with an #OperationPanopticon hashtag.

"What if we just absolutely ended surveillance capitalism in two days?" a purported member of a group called APT-69420 Arson Cats asked amid a string of tweeted images.

"This is the tip of the tip of the tip of the iceberg."

The hacker group claimed to have ferreted out credentials of a high level administrator account at Silicon Valley firm Verkada, which runs a platform operating security systems online.

"We have disabled all internal administrator accounts to prevent any unauthorized access," a Verkada spokesperson said in response to an AFP inquiry.

"Our internal security team and external security firm are investigating the scale and scope of this issue, and we have notified law enforcement."

Verkada added that it has notified companies that rely on its platform.

Surveillance camera imagery posted on Twitter included a jail cell block and a man wearing a fake beard dancing in a bank storage room.

The Verkada breach shows the risk of outsourcing security surveillance to companies in the internet cloud, according to Rick Holland, chief information security officer at Digital Shadows, a risk protection firm.

"Verkada positions itself as a 'more secure, scalable' alternative to on-premises network video recorders," Holland said.

"You don't always get more secure when you outsource your security to a third party."

He said he expected the breach to trigger investigations by privacy regulators in the US and Europe.

Agence France-Presse

Sunday, November 1, 2020

Ransomware surge imperils hospitals as pandemic intensifies

WASHINGTON - Hackers are stepping up attacks on health care systems with ransomware in the United States and other countries, creating new risks for medical care as the global coronavirus pandemic accelerates. 

Alerts from US authorities and security researchers highlight a wave of cyberattacks on hospitals coping with rising virus infections.

An unusual warning this week from the FBI with the Departments of Homeland Security and Health and Human Services, underscored the threat.

The three agencies "have credible information of an increased and imminent cybercrime threat to US hospitals and health care providers," said the alert issued Wednesday, calling on health systems to "take timely and reasonable precautions to protect their networks from these threats."

Media reports have cited several US hospitals hit by ransomware. 

One of them, the University of Vermont Medical Center, said in a statement Thursday it was working with law enforcement on "a now confirmed cyberattack that has affected some of our systems" which has had "variable impacts" on patient care.

Daniel dos Santos of the computer security firm Forescout said cash-strapped medical centers are particularly attractive targets for hackers and that at least 400 hospitals had been hit in the past few weeks in the US and Britain.

Hackers are aware that "health care is the most likely to pay the ransom because their services are critical," dos Santos said.

"Stopping services means that people will literally be dying."

For hospitals unable or willing to pay, "it would mean going back to pen and paper, which can cause huge slowdowns," he added.

Forescout said in a report that while many hospitals have upgraded computer systems, most use a variety of connected devices such as patient monitors or CT scanners which "act as the weak links in the network" because they transmit data over insecure channels.

In one sign of the troubles looming, dos Santos and fellow researchers said they discovered data on some three million US patients online, "unprotected and accessible to anyone who knows how to search for it.," the Forescout report said.


 Most targeted 


Ransomware is a longstanding security issue and health care has been a frequent target. A September attack disrupted Universal Health Services, which operates hospitals in the US and Britain.

But security experts say the attacks are accelerating as the pandemic worsens.

Researchers at the security firm Check Point said its survey showed health care has been the most targeted industry by ransomware, with a 71 percent jump in attacks on US providers in October from a month earlier.

Check Point said there have been significant rises in ransomware attacks on hospitals in Asia, Europe and the Middle East as well. Globally, the firm said ransomware attacks were up 50 percent in the third quarter compared with the first half of this year.

Many of the attacks use a strain of ransomware known as Ryuk, which security researchers say may be tied to North Korean or Russian cybercriminals.

The US government warning said health organizations are being targeted by phishing attacks to get access to the systems, with hackers using sophisticated tools including TrickBot software which can harvest credentials and exfiltrate data.

The Canadian government's Cyber Centre issued a similar warning in early October, warning of Ryuk ransomware "affecting multiple entities, including municipal governments and public health and safety organizations in Canada and abroad."

"The ransomware problem is steadily worsening and a solution desperately needs to be found," said Brett Callow of the security firm Emsisoft.

"We believe that solution is a prohibition on the payment of demands. Ransomware exists only because it's profitable. If the flow of cash stops, the attacks will stop and hospitals will no longer be at risk."

Agence France-Presse

Friday, January 17, 2020

2 arrested for 12 billion password sale attempt in Netherlands, Northern Ireland


THE HAGUE - Police arrested two men in the Netherlands and Northern Ireland suspected of trying to sell some 12 billion stolen user names and passwords via an online website, Dutch police said Friday.

A 22-year-old man was arrested in the eastern Dutch city of Arnhem when police raided his house on a tip-off by a Dutch cyber crime unit working with Britain's National Crime Agency, the FBI and the German police.

A second suspect, also aged 22, was arrested in Northern Ireland, Dutch police said in a statement.

During the raid in Arnhem police found professional equipment which made it possible to sell the suspects' offered services via the 'We leak info' website," police said.

The Dutch suspect "is involved in the possession and offering hacked user names and passwords and played a facilitating role in regards to cyber crime," law agents added.

When searched by AFP Friday the website displayed a disclaimer saying: "This domain has been seized" by the FBI in conjunction with the other European law enforcement agencies.

Dutch police declined to give further information, saying the investigation was ongoing.

WeLeakInfo.com allegedly offered unlimited access to all information on its site for two dollars a day or 25 dollars a month, the NOS public broadcaster said.

The information was a collection of leaks and stolen passwords from popular websites and apps such as LinkedIn and MyFitnessPal.

"In theory, you could search hundreds or even thousands of leaked passwords to try and gain access to people's emails, their social media and other accounts," the NOS said.

Dutch and British police in 2018 led an operation in which they shut down a website linked to more than four million cyber attacks around the world.

source: news.abs-cbn.com

Wednesday, January 15, 2020

Microsoft issues critical Windows security fix after tipoff from US NSA


WASHINGTON - Microsoft Corp on Tuesday rolled out an important security fix after the US National Security Agency tipped off the company to a serious flaw in its widely used Windows operating system, officials said.

Microsoft said the flaw could allow a hacker to forge digital certificates used by some versions of Windows to authenticate and secure data. Exploiting the flaw could have potentially serious consequences for Windows systems and users.

The NSA and Microsoft said they had not seen any evidence that the flaw had previously been abused, but both urged Windows users to deploy the update as soon as possible. NSA official Anne Neuberger noted that operators of classified networks had already been prodded to install the update and everyone else should now "expedite the implementation of the patch."

The Microsoft patch marks the first time the NSA has publicly claimed credit for prompting a software security update, although the agency said it has alerted companies in the past to flaws in their products. Neuberger said the agency was striving for more transparency with the information security research community.

"Part of building trust is showing the data," she told reporters in a call just minutes before the patch went live.

Experts said the move was unprecedented.

"I have never seen this before," said Tenable Chief Executive Amit Yoran, who previously served as founding director of the U.S. Computer Emergency Readiness Team.

"I cannot think of a single instance where government shared a zero-day with a vendor and took credit for it," he said in an email.

The NSA faces a balancing act when it comes across such vulnerabilities. The agency had been criticized after its cyberspies took advantage of vulnerabilities in Microsoft products to deploy hacking tools against adversaries and kept the Redmond, Washington-based company in the dark about it for years.

When one such tool was dramatically leaked to the internet in 2016, it was deployed against targets around the globe by hackers of all stripes.

In the most dramatic case, a group used the tool to unleash a massive malware outbreak dubbed WannaCry in 2017. The data-wiping worm wrought global havoc, affecting what Europol estimated was some 200,000 computers in more than 150 countries.

Neuberger did not directly address that controversy in her call but said that the NSA hoped to be "a good cybersecurity partner."

"We're working to evolve our mission," she said.

source: news.abs-cbn.com

Friday, January 10, 2020

Hackers cripple airport currency exchanges, seek $6 million ransom


The numbers that usually glow with exchange rates on Travelex boards in airports worldwide have gone dark, after the London-based currency exchange company was forced to go offline after it discovered a ransomware attack on Dec. 31.

The disruption has also affected banks like Barclays, Royal Bank of Scotland and HSBC, which have been unable to fulfill foreign currency orders for their customers.

Travelex said it had contained the threat and had no evidence that customer data had been removed. It has been offering only over-the-counter services since New Year’s Eve, when it discovered that it had been compromised by ransomware known as Sodinokibi, or REvil.

The hackers told the BBC on Wednesday that they had downloaded 5 gigabytes of sensitive customer data since gaining access to Travelex six months ago and intended to sell it if there was no response by Jan. 14. They have demanded $6 million for the data’s return.

Travelex, which has more than 1,200 stores, kiosks and counters in at least 70 countries, said in an online statement that it did not have a “complete picture” of what had happened to its data.

The company declined to provide details on how many customers had been affected, what data was at risk or when it expected the problem to be resolved.

“We take very seriously our responsibility to protect the privacy and security of our partner and customers’ data,” Tony D’Souza, the Travelex chief executive, said in the statement.

Travelex is still changing money, but must do the calculations by hand, based on rates issued each morning from its headquarters. At a central London branch of Travelex on Thursday, its ATMs permitted withdrawals only in pounds and the screens that usually show the exchange rates offered for each currency were blank.

The episode raised questions about how many more parts of the financial system could be at risk, said Bob Sullivan, a cybersecurity expert.

“We would not normally think of a company like Travelex as infrastructure, but clearly it is,” Sullivan said. “A big payment company that has tentacles into hundreds of institutions: It’s a reminder of how fragile these systems are.”


2020 The New York Times Company

source: news.abs-cbn.com

Tuesday, December 31, 2019

Microsoft seizes web domains used by North Korean hackers


Microsoft said Monday it obtained a court order allowing it to seize web domains used by North Korean hacking groups to launch cyberattacks on human rights activists, researchers and others.

The US technology giant said a federal court allowed it to take control of 50 domains operated by a group dubbed Thallium, which tricked online users by fraudulently using Microsoft brands and trademarks.

"This network was used to target victims and then compromise their online accounts, infect their computers, compromise the security of their networks and steal sensitive information," said Tom Burt, Microsoft's vice president for customer security and trust.

"Based on victim information, the targets included government employees, think tanks, university staff members, members of organizations focused on world peace and human rights, and individuals that work on nuclear proliferation issues. Most targets were based in the US, as well as Japan and South Korea," he added.

Microsoft, which had been investigating the group through its Digital Crimes Unit and Threat Intelligence Center, said the hacking group sent spoofed emails that appeared to come from Microsoft which tricked users into revealing their login credentials, a technique known as spear phishing.

"By gathering information about the targeted individuals from social media, public personnel directories from organizations the individual is involved with and other public sources, Thallium is able to craft a personalized spear-phishing email in a way that gives the email credibility to the target," Burt said.

After getting the victim's credentials, the hackers can access emails, contact lists, calendar appointments and other data and often forwards any new emails to the attackers.

The hackers also used malicious software which can access other data on a victim's computer.

An order from a US federal court in Virginia allowed Microsoft to take control of the domains, meaning "the sites can no longer be used to execute attacks," Burt said.

Microsoft said this was the fourth nation-state group it has acted against and follows similar moves against operations from China, Russia and Iran, dubbed Barium, Strontium and Phosphorus, respectively.

source: news.abs-cbn.com

Tuesday, October 29, 2019

Microsoft: Russia-linked hackers target sports organizations


Microsoft Corp. said it has tracked "significant" cyberattacks coming from a group it calls "Strontium" or "Fancy Bear", targeting anti-doping authorities and global sporting organizations.

The group, also called APT28, has been linked to the Russian government, Microsoft said in a blog post.

At least 16 national and international sporting and anti-doping organizations across three continents were targeted in the attacks which began on Sept. 16, according to the company.

The company said some of these attacks had been successful, but the majority had not. Microsoft has notified all customers targeted in these attacks. 

source: news.abs-cbn.com

Tuesday, January 8, 2019

German, 20, confesses ‘annoyance’ spurred massive data hack


German authorities on Tuesday said a 20-year-old hacker had confessed to stealing and leaking private data from hundreds of politicians, including Chancellor Angela Merkel, because he was "annoyed" by some of their public statements.

The young German, who lives with his parents, was taken into custody after police searched the family home in the western state of Hesse on Sunday. 

The suspect was not remanded in custody however because he was fully cooperating with the enquiry and not deemed a flight risk, said Georg Ungefuk, a spokesman for the Frankfurt prosecution service's internet crime office ZIT.

"The accused said he published the data because he had been annoyed by certain statements made by those affected," Ungefuk told a press conference in Wiesbaden.

The suspect, who because of his young age falls under juvenile law in Germany, told police he acted alone.

Ungefuk added that the young man had shown "clear remorse" about the stunning cyber security breach which affected around 1,000 German politicians, journalists and celebrities and piled political pressure on the government.

The information leaked online comprised home addresses, mobile phone numbers, letters, invoices and copies of identity documents. The data was first released via Twitter in December but its spread gathered pace last week.

Among those hit were members of the Bundestag lower house of parliament and the European Parliament as well as regional and local assemblies.

Deputies from all parties represented in the Bundestag were targeted with the exception of the far-right Alternative for Germany (AfD), the largest opposition group in parliament.

Speaking at the same press conference, the head of cyber security at Germany's Federal Police Office (BKA), Heiko Loehr, said it was too soon to say whether the suspect was acting out of far-right sympathies.

"We are still investigating his motives and whether they may have been criminal or politically motivated," he told reporters, adding that police were also working to confirm whether the suspect did indeed work alone.

Investigators have seized computers and hard drives from the scene that were now being combed over by experts, Ungefuk added.

He confirmed media reports that the suspect had tried to destroy a computer before the raid, but said investigators were still able to retrieve data from the damaged device. 

- 'Attack on democracy' -

Although the leak was sweeping, there is no evidence that sensitive information reached the public, investigators and the interior ministry have said.

In the vast majority of cases, only basic contact information was made available. 

The leak has nevertheless been deeply embarrassing for the political class, exposing a naive and sometimes reckless use of computer networks, and turned up the heat on the unpopular interior minister, Horst Seehofer.

Critics said the ministry and relevant authorities were slow in informing affected politicians of the leak and moving to stop it. 

Seehofer is due to speak to reporters in the afternoon. 

Beyond politicians, the leak also exposed the private data of celebrities and journalists, including chats and voicemail messages from spouses and children of those targeted.

The information derived both from social media and private "cloud" data.

The Twitter account @_0rbit published the links last month, along the lines of an advent calendar with each link to new information hidden behind a "door".

The account, which calls itself G0d and has now been suspended by Twitter, was opened in mid-2017 and purportedly has more than 18,000 followers. 

It described its activities as "security researching", "artist" and "satire and irony" and said it was based in Hamburg.

Justice Minister Katarina Barley, who last week had labelled the data dump an attack on "our democracy and its institutions", called on internet service providers and social networks "to shut down accounts as soon as they have been hacked".

German politicians and lawmakers have repeatedly fallen victim to cyberattacks in recent years.

In 2015, the Bundestag network was hit by a malware attack later blamed on Russian hackers.

In March last year, computer networks belonging to the German government came under sustained attack and data from foreign ministry staff was stolen.

At the time, Moscow denied that Russian hackers were involved.

source: news.abs-cbn.com

Wednesday, July 26, 2017

6 billion records hacked so far this year: researchers


WASHINGTON - A surge in computer hacking has led to the breach of more than six billion records so far this year, topping the total for 2016, security researchers said Tuesday.

Virginia-based Risk Based Security said in its mid-year report that it identified 2,227 publicly disclosed data compromise events through June 30 affecting business, government, medical and educational data.

"It is stunning to see the steady increase in the number of breaches impacting one million or more records," said Inga Goddijn, Executive Vice President for Risk Based Security.

The report said hackers are increasingly targeting employment and tax records. Some attacks successfully used "phishing" or spoofing or emails to obtain tax information from US citizens. Other targets included human resources departments, employment agencies and aggregators of employment data.

"While news of politically motivated foreign interference in election systems continues to dominate the headlines, the breach activity we are tracking this year is a stark reminder of just how many data compromise incidents are motivated by financial gain," Goddijn said.

"As long as information can be quickly monetized and systems remain vulnerable to attack, we should not expect to see any slowdown in breach activity.”

source: news.abs-cbn.com

Tuesday, March 15, 2016

Chinese hackers behind U.S. ransomware attacks - security firms


Hackers using tactics and tools previously associated with Chinese government-supported computer network intrusions have joined the booming cyber crime industry of ransomware, four security firms that investigated attacks on U.S. companies said.

Ransomware, which involves encrypting a target's computer files and then demanding payment to unlock them, has generally been considered the domain of run-of-the-mill cyber criminals.

But executives of the security firms have seen a level of sophistication in at least a half dozen cases over the last three months akin to those used in state-sponsored attacks, including techniques to gain entry and move around the networks, as well as the software used to manage intrusions.

"It is obviously a group of skilled of operators that have some amount of experience conducting intrusions," said Phil Burdette, who heads an incident response team at Dell SecureWorks.

Burdette said his team was called in on three cases in as many months where hackers spread ransomware after exploiting known vulnerabilities in application servers. From there, the hackers tricked more than 100 computers in each of the companies into installing the malicious programs.

The victims included a transportation company and a technology firm that had 30 percent of its machines captured.

Security firms Attack Research, InGuardians and G-C Partners, said they had separately investigated three other similar ransomware attacks since December.

Although they cannot be positive, the companies concluded that all were the work of a known advanced threat group from China, Attack Research Chief Executive Val Smith told Reuters.

The ransomware attacks have not previously been reported. None of the companies that were victims of the hackers agreed to be identified publicly.

The security companies investigating the advanced ransomware intrusions have various theories about what is behind them, but they do not have proof and they have not come to any firm conclusions.

Most of the theories flow from the possibility that the Chinese government has reduced its support for economic espionage, which it pledged to oppose in an agreement with the United States late last year. Some U.S. companies have reported a decline in Chinese hacking since the agreement.

Smith said some government hackers or contractors could be out of work or with reduced work and looking to supplement their income via ransomware.

It is also possible, Burdette said, that companies which had been penetrated for trade secrets or other reasons in the past were now being abandoned as China backs away, and that spies or their associates were taking as much as they could on the way out. In one of Dell's cases, the means of access by the team spreading ransomware was established in 2013.

The cyber security experts could not completely rule out more prosaic explanations, such as the possibility that ordinary criminals had improved their skills and bought tools previously used only by governments.

Dell said that some of the malicious software had been associated by other security firms with a group dubbed Codoso, which has a record of years of attacks of interest to the Chinese government, including those on U.S. defense companies and sites that draw Chinese minorities.

PAYMENT IN BITCOIN

Ransomware has been around for years, spread by some of the same people that previously installed fake antivirus programs on home computers and badgered the victims into paying to remove imaginary threats.

In the past two years, better encryption techniques have often made it impossible for victims to regain access to their files without cooperation from the hackers. Many ransomware payments are made in the virtual currency Bitcoin and remain secret, but institutions including a Los Angeles hospital have gone public about ransomware attacks.

Ransomware operators generally set modest prices that many victims are willing to pay, and they usually do decrypt the files, which ensures that victims will post positively online about the transaction, making the next victims who research their predicament more willing to pay.

Security software companies have warned that because the aggregate payoffs for ransomware gangs are increasing, more criminals will shift to it from credit card theft and other complicated scams.

The involvement of more sophisticated hackers also promises to intensify the threat.

InGuardians CEO Jimmy Alderson said one of the cases his company investigated appeared to have been launched with online credentials stolen six months earlier in a suspected espionage hack of the sort typically called an Advanced Persistent Threat, or APT.

"The tactics of getting access to these networks are APT tactics, but instead of going further in to sit and listen stealthily, they are used for smash-and-grab," Alderson said.

source: www.abs-cbnnews.com

Tuesday, September 22, 2015

Apple App Store suffers 'worst' malware attack


WASHINGTON, United States - Hackers infiltrated the vaunted Apple ecosystem by injecting malicious software into popular Chinese mobile apps, potentially affecting hundreds of millions of users and raising security concerns as the US tech giant prepares its newest iPhone launch.

The company said Monday it had removed tainted applications from its App Store, days after security researchers revealed the breach of Apple's normally secure system which aims to weed out infected applications.

In China, more than 300 apps including the hugely popular instant messaging service WeChat and ride-hailing app Didi Kuaidi were infected with the "XcodeGhost" malware, potentially allowing access to private user data including passwords, Chinese state-run media said.

The reports were a blow to the US firm, which has Greater China as its second-largest market.

Apple told AFP that it had removed the affected apps from its online store.

"To protect our customers we've removed the apps from the App Store that we know have been created with this counterfeit software and we are working with the developers to make sure they're using the proper version of (Apple software) Xcode to rebuild their apps."

"To protect our customers we've removed the apps from the App Store that we know have been created with this counterfeit software and we are working with the developers to make sure they're using the proper version of (Apple software) Xcode to rebuild their apps."

Apple's reaction came days after US-based cybersecurity firm Palo Alto Networks uncovered the flaw, saying the malware came from computer code uploaded to Baidu's cloud file-sharing service used by Chinese app developers.

Anti-censorship group Greatfire.org, which tracks Chinese Internet restrictions, called the news "the most widespread and significant spread of malware in the history of the Apple app store, anywhere in the world."

Apple, which reviews and approves each application, has generally kept its apps malware-free, analysts say.

But Alan Cockerill at the US security firm Lookout said "there are no perfect systems."

In a blog post, Cockerill said that "while Apple has traditionally done an excellent job of keeping malware out of its App Store, malicious actors are always looking for new ways to break through."

"The malicious code may have hundreds of millions of victims," Cockerill said.


Apple checks failed

Johannes Ullrich at the SANS Technology Institute said that "the real problem here is this malicious code made it past the Apple App Store check-in process."

"Apparently there is some trust between Apple and some of these developers of large applications like WeChat so these applications aren't necessarily tested as carefully if they are coming from a name-brand company," Ullrich said.

Palo Alto Networks said the malware was hidden in the Xcode software required for apps and made its way into applications without the knowledge of developers.

But once installed, the malware could allow a third party to gain access to private and personal information on an Apple device.

The malware can issue a fake dialog alert to gain access to passwords, or hijack a browser to direct users to a fake website. It can also read and write data in the user's clipboard, which could be used to get passwords, according to Palo Alto.

Only Chinese apps were known so far to have been infected -- although some of those, including WeChat, are also used outside China.

Chinese apps are thought to be vulnerable because developers often bypass the official, more secure, Apple channels, which can be slowed by Chinese Internet monitoring.

Tencent, which makes the WeChat software -- used by 500 million in China -- said it had repaired the flaw and that there had been "no theft (or) leakage of users' information or money."

The makers of app Didi Kuaidi, which claims 200 million regular users, also reported a fix and said no user privacy was compromised.


Bad timing

Independent security consultant and researcher Graham Cluley said the incident is not all bad for Apple.

"It suggests that Apple's security is pretty good," Cluley said in a blog post.

"After all, this was quite a complicated way to get malware into the App Store."

Cluley said Apple "has a much much better track record than Google's Android one for security."

But Thomas Reed at the software firm Malwarebytes said it may hurt Apple at a delicate time.

Apple is set to release its new iPhone 6S and 6S Plus handsets on Friday in the US, China and several other key markets.

"There is little doubt that there will be some revision of the app review process at Apple as a result, but it's also certain that this incident will erode consumer confidence in the App Store as a (mostly) unassailable malware-free fortress," he wrote in a blog.

source: www.abs-cbnnews.com

Wednesday, July 29, 2015

How hackers can control Android phones via text message


Cyber security firm Zimperium on Monday warned of a flaw in the world's most popular smartphone operating system that lets hackers take control with a text message.

"Attackers only need your mobile number, using which they can remotely execute code via a specially crafted media file delivered via MMS (text message)," Zimperium Mobile Security said in a blog post.

"A fully weaponized successful attack could even delete the message before you see it. You will only see the notification."

Android code dubbed "Stagefright" was at the heart of the problem, according to Zimperium.

Stagefright automatically pre-loads video snippets attached to text messages to spare recipients from the annoyance of waiting to view clips.

Hackers can hide malicious code in video files and it will be unleashed even if the smartphone user never opens it or reads the message, according to research by Zimperium's Joshua Drake.

"The targets for this kind of attack can be anyone," the cyber security firm said, referring to Stagefright as the worst Android flaw discovered to date.

"These vulnerabilities are extremely dangerous because they do not require that the victim take any action to be exploited."

Malicious code executed by hackers could take control of smartphones and plunder contents without owners knowing.

Stagefright imperils some 95 percent, or an estimated 950 million, of Android phones, according to the security firm.

Zimperium said that it reported the problem to Google and provided the California Internet firm with patches to prevent breaches.

"Google acted promptly and applied the patches to internal code branches within 48 hours, but unfortunately that's only the beginning of what will be a very lengthy process of update deployment," Zimperium said.

It did not appear as though hackers had taken advantage of the Stagefright vulnerability, according to Zimperium.

Updating Android software powering mobile devices is controlled by hardware makers and sometimes telecommunication service carriers, not Google.

While Apple controls the hardware and software in iPhones, iPads, and iPods powered by its mobile operating system, Google makes Android available free to device makers who customize the code and update it as they see fit.

More about Drake's research was to be disclosed at a Black Hat computer security conference taking place in Las Vegas early in August.

source: www.abs-cbnnews.com

Tuesday, July 21, 2015

Cheating website relieved it is not being judged after hack


TORONTO - Cheating spouses website AshleyMadison.com, facing hackers' threats to leak clients' nude photos and sexual fantasies, said it is heartened by some initial public response that sees the site as a victim.

The website's Canadian parent, Avid Life Media, confirmed a breach of its systems that has put the real names, credit card information and other details of as many as 37 million customers at risk. Avid Life said it has since secured the sites and closed unauthorized access points.

The dating website company has hired UK cybersecurity firm Sycura to investigate the breach, first reported by the KrebsonSecurity blog, and is working with police to trace those behind the attack, spokesman Paul Keable said.

AshleyMadison.com, which uses the slogan "Life is short. Have an affair," has been planning to raise up to $200 million through an initial public offering on the London Stock Exchange.

A group calling itself Impact Team said it had taken over Avid Media systems, including customer databases, source code, financial records and emails, according to a screen grab shown on the KrebsOnSecurity blog.

"Shutting down AM (Ashley Madison) and EM (Established Men) will cost you, but non-compliance will cost you more," the hackers said. Established Men, widely described as a "sugar daddy site," is another Avid Media property.

The hackers leaked snippets of the compromised data online and warned that they would release customers' real names, profiles, nude photos, credit card details and "secret sexual fantasies" unless AshleyMadison and EstablishedMen.com are taken down, Krebs said.

CUSTOMER PRIVACY CRUCIAL

"There's a very strong narrative that criminal activity, vigilantism, is not the way forward, because who gets to be the judge and jury?" Keable said at Avid Life's midtown Toronto offices, citing articles in what he called "major media outlets."

The hackers said that a "paid delete" function will not remove all information about a member's profile and communications.

Avid Life said that claim is untrue and it would offer the function free of charge following the breach. The dating website owner has about 160 employees, mostly in Toronto but also in Cyprus, Brazil, Japan and elsewhere.

Keable said it was too early to estimate the damage to the company's business model or IPO plans from the breach.

But one Canadian investment banker, who asked not to be named, said the breach could put those plans at risk.

"There are a lot of risqué websites that are looking to go public, the problem here is that the way Ashley Madison works is it puts customer privacy as tantamount, the fact that you have a hacking scandal at least temporarily puts the kibosh on any IPO plans for them," the banker said.

In an interview with KrebsOnSecurity, Avid Life Chief Executive Noel Biderman was cited as saying the company suspected someone who had access to internal networks as being behind the breach.

"It was definitely a person here that was not an employee but certainly had touched our technical services," he said.

Unauthorized posts and images on the website detailing the hacker's demands have since been removed.

"We apologize for this unprovoked and criminal intrusion into our customers' information," Avid Life said.

The breach comes about two months after dating site Adult FriendFinder was compromised. That site has an estimated 64 million members.

source: www.abs-cbnnews.com

Monday, November 17, 2014

US State Department network shut amid reports of cyber breach


WASHINGTON - The US State Department had to shut down its unclassified computer network over the weekend after evidence emerged that it could have been hacked, the US media reported late Sunday.

The State Department said in an email late Friday that the shutdown came as scheduled routine maintenance to its main unclassified network, and would impact email traffic and access to public websites.

But on Sunday reports emerged that there was evidence a hacker may have breached the security in portions of the system handling non-classified emails.

A senior official told the Washington Post there had been "activity of concern" but that none of the departments classified systems had been compromised.

If hacked, the State Department would be the latest in a series of government agencies to face cyber security breaches -- though it is not clear if there is any link between the incidents.

Last week, the US Postal Service said hackers stole sensitive personal information from its employees in a large data breach this year, and got some customer data as well.

A USPS spokesman said the breach affected as many as 800,000 people who are paid by the agency, including employees and private contractors.

The statement said hackers also penetrated payment systems at post offices and online where customers pay for services.

The agency was working with the FBI and other law enforcement in an investigation.

And last month, the White House reported an intrusion in its unclassified computer network.

In the course of addressing the breach, some White House users were temporarily disconnected from the network, an official said, but the computers and systems were not damaged.

The Washington Post quoted sources as saying hackers believed to be working for the Russian government were believed to be responsible.

source: www.abs-cbnnews.com

Thursday, March 28, 2013

Hackers deface IT site of Manila Bulletin


MANILA – Hackers claiming to be members of “Anonymous” defaced the information technology section of Manila Bulletin’s website on Thursday.

The hackers defaced the whole section, leaving a message for “fake anons,” or those who use the handle “Anonoymous” for their own gain.

“It may already have come to your attention the issue about those fake anons who, for themselves use the handle anonymous for their own individual purpose. You may also already know about the fast-spreading Operation called #OpFakeAnons,” the message read.

“#OpFakeAnons will eliminate those who hack and use the handle of 'Anonymous' for their own gain. WE Will DEFAME you. We will DIRTY your name. We will end your 'Hey-Look-I-Hacked-A-Website-I'm-A-Star' era. For those self-proclaimed hacking groups bragging the name of anonymous are fake,” the group added.

The message also contained Facebook links to pages of other hacker groups.

source: abs-cbnnews.com

Wednesday, March 13, 2013

Hackers post 'private data' of Michelle Obama, FBI head


WASHINGTON - US authorities were investigating Tuesday after hackers posted personal financial data belonging to First Lady Michelle Obama, the head of the FBI and several A-list celebrities online.

Hackers using a Russian web address published the credit reports and social security numbers for Obama, Federal Bureau of Investigation Director Robert Mueller, US Attorney General Eric Holder, and Los Angeles Police Chief Charles Beck.

They also posted social security numbers and other personal information relating to Vice President Joe Biden and former first lady and secretary of state Hillary Clinton.

Entertainment stars Beyonce and husband Jay-Z, Paris Hilton, Kim Kardashian and Britney Spears also saw details leaked, as did tycoon Donald Trump, former Alaska governor Sarah Palin and bodybuilder-turned-actor and former California governor Arnold Schwarzenegger.

President Barack Obama was asked about the alleged incident during an interview with ABC News, and while not confirming the details, said that hacking was a growing problem.

"We should not be surprised that if we've got hackers that want to dig in and have a lot of resources, that they can access this information," he said.

"It is a big problem. I'm not confirming that that's what happened, but you've got websites out there right now that sell people's credit cards that have been stolen."

The three leading personal credit-rating agencies acknowledged the files were accessed illegally, but said it was done through other firms by someone using the personal data of the victims, and not by hacking their own computers.

"This looks to be an isolated situation in which criminals accessed personal credential information through various outside sources, which provided them with sufficient information to illegally access a limited number of individual reports from some US credit reporting agencies," said Experian.

"Upon learning of the situation, we took immediate action to freeze the credit files of those victimized by this malicious attack in an effort to minimize impact to those individuals."

Transunion, the source of Michelle Obama's credit report, said its own systems "were not hacked or compromised in any way."

The perpetrators "had considerable amounts of information about the victims, including social security numbers and other sensitive, personal identifying information that enabled them to successfully impersonate the victims over the Internet," it said.

The data also came from two others services, Equifax and CreditKarma.

The FBI and the US Secret Service, which protects the president and his family, both said they were investigating the matter.

FBI spokeswoman Jennifer Shearer said she could not provide any details on the probe or confirm the identities of the victims.

Although they are supposed to be restricted, financial companies vetting individuals for loans and credit cards have easy access to the records.

Individuals can also obtain their own credit records online.

It was not clear who posted the details. The data was placed on a website with a web address with the ".su" root indicating the Soviet Union -- an address still controlled by Russia.

The website led with a quote from the US cable television series "Dexter" about a policeman-turned-serial killer: "If you believe that God makes miracles, you have to wonder if Satan has a few up his sleeve."

source: abs-cbnnews.com

Monday, March 4, 2013

Google hacked over Malaysia-Filipino standoff


KUALA LUMPUR - Supporters of an armed bid by Filipino intruders to lay claim to a Malaysian state took their campaign to cyberspace on Monday, manipulating Google search listings to show a message backing the incursion.

A Google search for the word "Sabah", the state at the centre of Malaysia's biggest security crisis in years, came back with a search results page that quotes "Wikipedia" calling Malaysian control of the state "illegitimate."

"Sabah is illegitimately considered one of the 13 member states of Malaysia, and is said to be its easternmost state but in fact, it is part of the Sultanate of Sulu," the passage read, shown in a box previewing the Wikipedia entry for Sabah.

Malaysians have been shocked by the militant incursion, which began when an estimated 100-300 people landed on the shores of Sabah on February 12, claiming the state for the heir to a former Philippine sultanate.

The website of Stamford College in Malaysia was apparently hacked at the weekend, its front page replaced by a message that said: "The time has come to reclaim what is truly ours."

"Sabah is owned by the Philippines, you illegally (sic) claiming it," it said.

Philippine news portals have said a number of sites in the country were hit by pro-Malaysia hackers.

A tense stand-off between the intruders and security forces who have them pinned down in the farming village of Tanduo erupted in a bloody firefight Friday that left 12 gunmen and two police officers dead.

Another gun battle erupted Saturday in Semporna, hours away from Tanduo by road, dramatically escalating tensions and raising the overall toll of reported dead to at least 18 militants and eight police officers.

Followers of the 74-year-old Manila-based Islamic leader, Jamalul Kiram III, say the gunmen are ready to die to defend his claim to Sabah, which was once controlled by the now-defunct sultanate.

source: abs-cbnnews.com

Wednesday, October 3, 2012

Palace denies President's website was hacked

MANILA, Philippines – A Palace spokesman denied Thursday that President Benigno Aquino III’s official website (www.president.gov.ph) was shut down by hacktivists on Wednesday.

 In a statement, Presidential Communications Operations Office Secretary Herminio “Sonny” Coloma said the President’s website was inaccessible for 5 hours in the morning of October 3, Wednesday, due to scheduled systems maintenance.

“During this period, Facebook fans and Twitter followers of the President were duly re-directed and were able to use these social media channels without any interruption,” Coloma said.

He also denied that the website of the Philippine Information Agency (pia.gov.ph) was defaced or hacked since last week

“There was no actual defacement of the PIA website and at no time was there a service disruption. In the morning of 2 October, a hacker apparently got into the personal email account of one of the online editors and inserted a link that appeared in one of the posted stories,” he said.

He said the specific irregularity was addressed immediately. He added the PCOO continues to adopt appropriate security measures to ensure the integrity of government websites.

Various government websites have been under attack after so-called hacktivists protested the passage of the Cybercrime Prevention Act of 2012.

Justice Secretary Leila de Lima, who was given broad powers under the Anti-Cybercrime Law, gave the National Bureau of Investigation (NBI) a standing order to run after groups or persons responsible for the defacing of government websites right smack on the day the controversial law became effective.

"They will trace who the hackers are and apprehend them. For this purpose, they need to coordinate with the intel units of other investigative bodies," she told reporters.

source: abs-cbnnews.com

Vigilantism harms freedom of expression – Palace

De Lima warns hackers: You can be criminally liable

MANILA, Philippines - Malacanang said online vandalism or hacking also harms freedom of expression.

In a statement released on the first day of the implementation of the Anti-Cybercrime Law, Presidential Spokesperson Edwin Lacierda called on the law’s critics to “speak out against online vandalism and bullying with as much vigor and passion as they have expressed in their objections to certain provisions of this law. If our freedoms have been hard won, it would do us all well to remember that in the end, vigilantism harms the cause of freedom of expression and civil liberties for all netizens.”

He said the government understands criticisms on the law, specifically the provision on libel. He said, however, that these should be via constitutional processes.

Lacierda said that there is still a legal and reasonable way of discourse, which is via the drafting of the implementing rules and regulations of the law. “We urge the fullest and widest participation of stakeholders in this process.”

He said the public should remember that the Constitution is still the greatest element in binding everyone and in guaranteeing their civil liberties.

“The administration is equally adamant in upholding these liberties, which were regained at such high cost by our people. As the President said on September 27, the vigorous exchange of ideas that is the hallmark of a vibrant democracy, requires those who disagree not to oppress others,” he said.

The past weeks saw “hacktivists” deface several government websites. They are in opposition to the law’s provisions, which supposedly curtail freedom of expression.

In a separate interview with dzMM, Justice Secretary Leila de Lima warned hackers they can be criminally liable.

The National Bureau of Investigation is already looking into ways on how to stop the hacking activities.

De Lima said: "I think the means that they are adapting is foul. They should not do that. They should be reminded that they are committing a crime."

She noted critics should show protest via lawful means. "Kung naniniwala sila na mali 'yung ibang probisyon diyan sa Cybercrime Law, then you cannot right a wrong with another wrong. It is wrong to do the hacking."

source: abs-cbnnews.com