Showing posts with label Hackers. Show all posts
Showing posts with label Hackers. Show all posts
Thursday, August 16, 2018
Researchers find new security flaw in Intel chips
WASHINGTON, United States – Researchers have discovered a new security flaw that could let hackers pry information from supposedly secure virtual vaults in Intel chips, the company warned on Tuesday.
Intel said software updates are already available and it did not appear anyone had taken advantage of the “Foreshadow” vulnerability, which has been likened to troubling “Meltdown” and “Spectre” flaws exposed in computer chips early this year.
“If used for malicious purposes, this class of vulnerability has the potential to improperly infer data values from multiple types of computing devices,” Intel said on its website.
“Intel has worked with operating system vendors, equipment manufacturers, and other ecosystem partners to develop platform firmware and software updates that can help protect systems from these methods,” it said.
The “Meltdown” and “Spectre” flaws roiled the Silicon Valley chip maker, prompting a series of lawsuits and a congressional inquiry about Intel’s handling of the matter
“We are not aware of reports that any of these methods have been used in real-world exploits, but this further underscores the need for everyone to adhere to security best practices,” Intel executive vice president and general manager of product assurance and security said of “Foreshadow” in a post on Intel’s website.
“Once systems are updated, we expect the risk to consumer and enterprise users running non-virtualized operating systems will be low.” /cbb
source: technology.inquirer.net
Monday, January 12, 2015
Key US military command’s Twitter, YouTube sites hacked
WASHINGTON—Hackers claiming to work on behalf of Islamic State militants seized control of the Twitter and YouTube sites of the military’s US Central Command on Monday. The Pentagon swiftly suspended the sites and said it appears that no classified material was breached.
The hacker group appears to be the same one that is under FBI investigation for hijacking the websites or Twitter feeds of media outlets in the last month, including a Maryland television station and a New Mexico newspaper.
The Central Command Twitter site was filled with threats that said “American soldiers, we are coming, watch your back.” Other postings appeared to list names, phone numbers and personal e-mail addresses of military personnel as well as PowerPoint slides and maps.
Most of the material was labeled “FOUO,” which means “For Official Use Only,” but none of it appeared to be classified or sensitive information, suggesting the hackers did not breach classified material.
One of the documents appeared to be slides developed by the Massachusetts Institute of Technology’s Lincoln Laboratory, a federally funded research and development center focused on national security. The slides appeared to depict what it called “scenarios” for conflict with North Korea and China.
An ‘annoyance’
“This is little more than a prank or vandalism. It’s inconvenient and it’s an annoyance. But that’s all it is,” said Col. Steve Warren, a Pentagon spokesman. “It in no way compromises our operations in any way shape or form.”
Warren said Pentagon officials are in contact with Twitter and YouTube to ensure that military passwords and other security for such public websites are adequate.
The tweets came shortly after US Central Command posted its own tweets about the US and partner nations continuing to attack Islamic State terrorists in Iraq and Syria and one repeating a report that said France will deploy an aircraft carrier to the fight.
The hackers titled the Central Command Twitter page “CyberCaliphate” with an underline that said “i love you isis.” And the broader message referred to the ongoing airstrikes against the Islamic State group in Iraq and Syria and threatened, “We broke into your networks and personal devices and know everything about you. You’ll see no mercy infidels. ISIS is already here, we are in your PCs, in each military base.”
It added: “US soldiers! We’re watching you!”
The intrusion on the military Twitter account carried the same logo, CyberCaliphate name and photo that appeared on the Albuquerque Journal’s website in late December when one of its stories was hacked. And earlier this month, it appeared that the same hackers breached the Journal’s Twitter account and also took over the website and Twitter feed of WBOC-TV in Salisbury, Maryland.
The FBI at the time acknowledged it was looking into the Albuquerque case, and WBOC said it was also in contact with the agency.
Some IS militant videos also were posted on the Central Command’s YouTube site, purporting to show military operations and explosions.
“This is something we’re obviously looking into, and something we take seriously,” White House spokesman Josh Earnest said. But he cautioned against comparisons to the broader hack attack against Sony. “There’s a pretty significant difference between what is a large data breach and the hacking of a Twitter account,” he said.
A senior defense official confirmed that the two accounts were compromised and said US Central Command was taking appropriate measures to address the matter. The official spoke on condition of anonymity because the official was not authorized to speak about it publicly on the record.
The military suspended the Central Command Twitter site and terminated the YouTube site. This is not the first time that US government websites or other accounts have been hacked. It was not clear whether the site was attacked by the insurgent group or by sympathizers.–Lolita C. Baldor with Josh Lederman
source: technology.inquirer.net
Saturday, October 4, 2014
Hackers hit bank. Is your money safe anywhere?
NEW YORK — Hackers stole personal information from millions of JPMorgan Chase customers this summer, in one of the biggest breaches of a financial company.
The bank says only non-financial data was taken — names, addresses, telephone numbers and email. But that’s still a lot, and experts warn that customers need to be vigilant about identity theft in the next several months.
The theft — involving 76 million households and seven million small businesses — raises questions about the safety of personal information, especially at banks. What risks do people face? Will this keep happening? And can bank customers reduce the threat of identity or financial theft?
Q: How concerned should I be if the hackers didn’t get Social Security numbers, bank account or credit card information?
A: We may not yet know the full scope of what the hackers were able to steal, says Eric Chiu, president of HyTrust, a cloud security company based in Mountain View, Ca. “They can sit on your network for months, siphoning off data before being detected,” says Chiu. He says that customers’ addresses and phone numbers could be used or sold to others who might combine that information with other stolen data. It could then be used to access accounts or even to open new accounts in the unwitting customers’ names.
Q: How close did the hackers get to stealing customers’ money or more sensitive financial data?
A: We don’t really know. The hackers may not have been looking to siphon funds, says Chiu because “data is what’s gold now.” Other security experts say the bank’s public statements suggest that its defenses were partly successful, because hackers weren’t able to get other information.
Q: So is this a partial win for the bank?
A: It might be, says Mike Lloyd, chief technology officer at Sunnyvale, Ca.-based RedSeal Networks. But the bank shouldn’t declare victory — especially since cybersecurity is “a never-ending war” against new and evolving threats.
Q: What else could happen?
A: One concern is that this breach was a reconnaissance mission in preparation for a bigger hack, says Craig Carpenter, chief strategist at AccessData, a cybersecurity firm. “They don’t have to crack the entire system tomorrow,” he says. “They could have simply been mining for data, or looking to leave something behind that would allow them to get into (JPMorgan’s servers) easier next time.”
Q: What else should banks do to protect customer data?
A: The financial industry is already doing more than other industries, says Dwayne Melancon, chief technology officer for the cybersecurity firm Tripwire, in Portland, Oregon. Chase in particular is known for using advanced security technology, says Avivah Litan, an analyst with Gartner, a technology research firm based in Stamford, Connecticut. But she also says that most companies have trouble keeping up with constant threats, and one big vulnerability lies with employees. While businesses tend to spend more on defending against outside attacks, many hacks begin with a compromised employee account. Litan says companies must do more to screen workers and also train them in security precautions.
Q: Should I close my account at JPMorgan?
A: At this point, there’s no indication that’s necessary. Steve Weisman, a Boston attorney and author of several books and articles about identity theft says, “it won’t do any good” because other banks may be equally vulnerable to hacking. “There’s no place to run and hide. You should monitor your account regularly and don’t trust any communications you receive.”
Q: After big attacks against retail chains and now Chase, should we expect more breaches?
A: The size and scope of the breaches are going to get worse, not better. Target, Home Depot and JPMorgan Chase are just the beginning, says Darren Hayes, a professor and expert in cybersecurity at Pace University in New York. It’s safe to presume that hackers have been sitting inside these banks and business networks for months, even years, sometimes not doing anything. “Hackers these days are patient … and are extremely effective at just gathering a lot of data over time.”
Q: Is there any way to protect myself if they’re this sophisticated?
A: Change your passwords regularly, don’t click on links in suspicious emails, they could be phishing attempts by scammers, and check online statements for charges you don’t recognize. Be wary of calls requesting personal information.
Q: How bad is the fallout so far?
A: The New York-based bank says there’s no evidence of financial fraud associated with the breach.
source: buiness.inquirer.net
Friday, January 3, 2014
Snapchat hackers post phone numbers of 4.6M users online
PARIS—Hackers broke into Snapchat, the hugely popular mobile app, accessing the phone numbers and usernames of 4.6 million users and publishing them online, tech news website TechCrunch has announced.
The numbers were partially masked when they were briefly published on SnapchatDB.info, and the unidentified hackers told TechCrunch they had done this “to convince the messaging app to beef up its security.”
Snapchat, which allows people to send smartphone photos or video snippets timed to self-destruct 10 seconds or less after being opened, has become hugely popular among teenagers who are easing away from Facebook.
But Australian firm Gibson Security warned last week that glitches in the application could be exploited by hackers.
“Our motivation behind the release was to raise the public awareness around the issue,” the hackers said in a statement, published on TechCrunch late Wednesday.
“It is understandable that tech startups have limited resources but security and privacy should not be a secondary goal. Security matters as much as user experience does.
“You wouldn’t want to eat at a restaurant that spends millions on decoration, but barely anything on cleanliness.”
Created by students at Stanford University in 2011, Snapchat reportedly rejected a $3 billion takeover offer from Facebook last year.
source: technology.inquirer.net
Subscribe to:
Posts (Atom)




