Showing posts with label hack. Show all posts
Showing posts with label hack. Show all posts

Wednesday, January 15, 2020

Yes, the NSA discovered a major security threat in the Windows 10 operating system. No, the Russians are not suddenly hacking you.

The IT world was waiting on pins and needles yesterday for a high profile Microsoft Windows 10 security patch, and the US National Security Agency (NSA) has enlightened us as to why. Apparently the government agency has discovered a serious flaw in Windows 10 that could expose users to surveillance or serious data breaches.

The NSA confirmed (link) that the vulnerability affects Windows 10 and Windows Server 2016. It said that it flagged the dangerous bug because it "makes trust vulnerable." However, it wouldn't say when it found the flaw and declined to discuss it further until Microsoft released a patch.

The vulnerability was found in a Windows component called crypt32.dll, which handles "certificate and cryptographic messaging functions," according to Microsoft. An exploit in that area could affect authentication on Windows desktops and servers, sensitive data on Microsoft's Internet Explorer and Edge browsers and many third-party applications. Hackers could also use it to spoof digital signatures, making malware look like a legitimate app.

A software patch was released yesterday to critical Windows 10 clients including the US military and managers of key internet infrastructure. Microsoft has since released updates for all customers, urging them to install them "as quickly as practical." as this flaw is being noted the second most severe in Microsoft's rating system. Microsoft has confirmed it has not yet been exploited, but is still a major security issue.

Wednesday, May 30, 2018

FBI warning: Russians hacked hundreds of thousands of routers.

The FBI warned on Friday that Russian computer hackers had compromised hundreds of thousands of home and office routers and could collect user information or shut down network traffic.

The U.S. law enforcement agency urged the owners of many brands of routers to turn them off and on again and download updates from the manufacturer to protect themselves.

Infections were detected in more than 50 countries, though the primary target for further actions was probably Ukraine, the site of many recent infections and a longtime cyberwarfare battleground.

In obtaining the court order, the Justice Department said the hackers involved were in a group called Sofacy that answered to the Russian government.

Sofacy, also known as APT28 and Fancy Bear, has been blamed for many of the most dramatic Russian hacks, including that of the Democratic National Committee during the 2016 U.S. presidential campaign.

Earlier, Cisco Systems Inc said the hacking campaign targeted devices from Belkin International’s Linksys, MikroTik, Netgear Inc, TP-Link and QNAP.

An FBI official told Reuters that the kinds of devices known to be affected by the hack were purchased by users at electronic stores or online.

However, the FBI was not ruling out the possibility that routers provided to customers by internet service companies could also be affected, the official added.

If you own one of the above brand of routers you MUST restart it. To restart it, unplug your router for 30 seconds and then plug it back in.

We have no indication currently that routers from Verizon, Comcast or Cox have this vulnerability, but it wouldn't hurt to restart them anyway.

Monday, October 16, 2017

Security Notice: Key Reinstallation Attack

Background

On October 16, a WPA2 exploit was disclosed known as Key Reinstallation Attack (KRACK) that affects all WPA2 protected WiFi networks. This exploit could lead to user's WiFi traffic becoming compromised.

Impact

  • This exploit affects any wireless product using WPA2 encryption, which includes all IES access point products.
  • Those using 802.11r or mesh repeaters are most susceptible.
  • Client devices that have not received a security update specifically addressing this issue are also susceptible.
  • The exploit requires physical proximity to the network.

Fix

  • A new firmware version is currently under test, and we expect to qualify and publish the new version of 6.3 by end of day Tuesday, October 17. An update to 6.4 will be available at that time or shortly after.
  • Once new firmware is available, all networks will begin upgrading during their scheduled maintenance window automatically
  • We will also be patching older versions of our WiFi software, including 481, 590, 6.1 & 6.2, with availability end of this week.

Mitigation

  • In the meantime, we have turned off 802.11r on all IES WiFi devices until they have received the firmware update
  • End users should contact their WiFi client device manufacturers for security updates related to their specific client devices.

Questions / Feedback

If you have any questions or concerns about this vulnerability or the upgrade process, please reach out to IES support

Sunday, September 10, 2017

Welcome to 2017 where hacking is what seems like an everyday occurrence. Cough, cough - Equifax.

Target, CNN, HBO, Chipotle, Gamestop, Equifax - what do all these companies have in common? They have all been hacked this year.

But why, in our opinion, is the Equifax hack the worst? Well, many know Equifax as one of the top three credit reporting agencies. Ever applies for a home loan or an auto loan? Chances are the bank you are using has run your credit through Equifax. Equifax is reporting that sensitive information, such as Social Security numbers and addresses, of up to 143 million Americans has been exposed. The data breach is among the worst ever because of the amount of people affected and the sensitive type of information exposed.

Unlike other data breaches, those affected by the breach may not even know they're customers of the company, as the company gets its data from credit card companies, banks, retailers and lenders - sometimes without you knowing.

When did this happen?
Equifax said the breach happened between mid-May and July. It discovered the hack on July 29. It informed the public on September 7.

How did this happen?
Equifax said criminals "exploited a U.S. website application vulnerability to gain access to certain files."

Am I at risk, and what is Equifax doing to help?
Equifax is proposing that customers sign up for credit file monitoring and identity theft protection. It is giving free service for one year through its TrustedID Premier business, regardless of whether you've been impacted by the hack.

To enroll and / or check whether you were affected, visit www.equifaxsecurity2017.com and click on the Check Potential Impact tab. You'll need to provide your last name and the last six digits of your social security number. Once submitted, you will receive a message indicating whether you've been affected. (Giving your personal information to a company that was just hacked...ironic, we know). Then, you have the option to enroll in the program, but you can't actually sign up for the service until next week. Each customer is provided an enrollment date starting earliest on Monday.

Can I sue Equifax?
If you sign up for Equifax's offer of free identity theft protection and credit file monitoring, you may be limiting your rights to sue and be forced to take disputes to arbitration. But you can opt out of that provision if you notify the company in writing within 30 days. In addition, some attorneys argue that even if you don't opt out, the arbitration provision does not cover suits related to this breach.

It seems like companies are getting hacked a lot. Is this the biggest ever?
The Equifax breach is one of the largest breaches ever. Another high-profile examples include two breaches at Yahoo - the bigger one involved 1 billion accounts, the lesser impacted 500 million.

Wednesday, August 2, 2017

The FBI has issued a security warning about IoT toys.

IoT toys have the potential to violate children’s privacy and safety, given the amount of pertinent information the toys can collect and store, the Federal Bureau of Investigation (FBI) warned this week in an advisory.

The sensors, microphones, data storage capabilities, cameras and other features of Internet of Things (IoT) toys are able to vacuum up extensive details about a child’s name, school, activities and even their physical location.

And if those toys are hacked, criminals could use the stolen information to harm a child, the FBI warned.

What Makes IoT Toys Vulnerable?

Data collected from interactions or conversations between children and toys are typically sent and stored by the manufacturer or developer via a server or a cloud service. In some cases, data are also collected by third party companies that manage the voice recognition software used in the toys.

Voice recordings, toy Web application passwords, home addresses, WiFi information, and sensitive personal data could be exposed if the security of the data is not sufficiently protected with the proper use of digital certificates and encryption when it is being transmitted or stored.

Smart toys connect to the Internet either directly, through WiFi to an Internet connected wireless access point; or indirectly, via Bluetooth to an Android or iOS device that is connected to the Internet.
Key factors affecting the user’s security include: the cyber security features, the toy’s partner applications and the WiFi network through which the toy connects.

Superior communications connections - where data is encrypted between the toy, WiFi access points, and Internet servers that store data or interact with the toy - are crucial to mitigate the risk of hackers exploiting the toy or eavesdropping on conversations or audio messages.

The FBI notes that Bluetooth connected toys that do not have authentication requirements (such as PINs or passwords) pose risks for unauthorized access, enabling criminals to communicate with children.

What You Can Do To Protect Your Child
  • Choose IoT toys very carefully by doing lots of research. Look for any known reported security issues regarding a toy.
  • Find out if a toy can receive firmware or software updates and security patches - and ensure the toy is running on the latest version.
  • Closely monitor your child’s activities with each toy through the toy’s parent application, if such a capability exists.
  • Ensure the toy is turned off when it is not in use.
  • Create a strong and unique login password when establishing a user account. For extra strong passwords, use lower and upper case letters, numbers and special characters.
  • Provide only what is minimally required for creating a user account.

Tuesday, January 17, 2017

A warning to all the selfie queens out there: you can be hacked!

Next time someone poses for a selfie with their fingers held up in a peace sign, maybe tell them to leave it at a smile.

An ordinary photo of the universal sign of goodwill might be enough for a thief to copy a fingerprint, thanks to the high quality of digital photos these days. And since Touch ID and similar technologies turn fingerprints into keys that unlock our devices and the data we keep in them, that’s cause for concern.

Just by casually making a peace sign in front of a camera, fingerprints can become widely available.

A team at the NII’s Digital Content and Media Sciences Research Division, Japan was able to reconstruct fingerprints spotted in pictures taken from up to 3 meters away.

“Fingerprint data can be re-created if fingerprints are in focus with strong lighting in a picture.” - Isao Echizen, a professor at Japan’s National Institute of Informatics

The peace sign is a common expression in social media pictures, but this technique could conceivably be applied to other common gestures like waving or giving a thumbs up. Matched with a person’s face, that makes for a significant amount of biometric data that identity thieves could do real damage with.

How Thieves Could Get Fingerprints From Selfies

The technique described by Echizen uses no special software, but does require good lighting - so for the moment you can feel free to flash whatever signs you like when the light is low. As mobile cameras become more and more powerful, though, selfies will become a bigger security liability.

The better alternative might be to make sure you aren’t relying on fingerprint security measures whenever possible. Or just avoid selfies altogether.

Tuesday, January 19, 2016

The list is in! Here are the top 25 most common / dumbest passwords used in 2015.

People are still using really bad passwords to secure online accounts, despite constant advice to the contrary. As reported by Engadget, SplashData has revealed its list of the worst passwords of 2015, drawn from the 2 million passwords that leaked last year.

This year’s list is very similar to last year’s list:
  1. 123456
  2. password
  3. 12345678
  4. qwerty
  5. 12345
  6. 123456789
  7. football
  8. 1234
  9. 1234567
  10. baseball
  11. welcome
  12. 1234567890
  13. abc123
  14. 111111
  15. 1qaz2wsx
  16. dragon
  17. master
  18. monkey
  19. letmein
  20. login
  21. princess
  22. qwertyuiop
  23. solo
  24. passw0rd
  25. starwars
The sets of contiguous numbers are dumb for obvious reasons, and single words without any numbers are never going to be particularly secure. And then there are the likes of "password," "qwerty," and "letmein."

As these passwords all belonged to accounts that were hacked or otherwise compromised, these are essentially the most popular bad passwords. Suffice to say anyone who wants to stay safe online should avoid using these under any and all circumstances.

Source:  Engadget

Monday, June 1, 2015

The hackers are coming! The hackers are coming!

Hacking: it’s not just for Anonymous and the U.S. government anymore.

Cybercrime is ever-encroaching and can happen to anyone. Including you and your business. In fact, it’s cost the global economy more than $400 billion, and it’s increasingly hurting smaller operations.

The problem goes far beyond the leaking of sensitive emails and sexy selfies. Targeted attacks against small businesses nearly doubled in 2013. And of the one in five that experience a cyber attack annually, 60% will close their doors within six months as a result (source: Symantec).

But not you. Protect your business with these three tips:

1. Be password savvy. If your password is still “Password123,” it’s time to get serious. Create unique codes for each of your accounts, and make sure they’re at least 8 characters long (with a few special ones thrown in). Use password managers like LastPass 3.0 or Dashlane 3 to keep track.

2. Encrypt emails and valuable information. If a hacker does breach your system, encryption makes it that much harder to get away with critical data. Voltage, DataMotion, and Proofpoint are industry leaders worth checking out. 

3. Back up your data. Copying your key company data onto a cloud based system, such as Dropbox or Carbonite, or a USB hard drive takes minutes, and will save you time and anxiety if your system is ever compromised.

For professional help, call IES today at 781-816-9437. We can have you safe and secure in hours, not days!

Friday, January 16, 2015

Jimmy Kimmel shows just how easy it is to steal someone's password.

Did you know that "password123" is the most common password used in the US?
 
Even though we all know better, human beings will forever insist on using insecure, awful passwords. Awful passwords that, apparently, we are more than happy to broadcast on national television.
 
Jimmy Kimmel's producers went around the streets of LA under the guise of assessing people's password security, which they were able to do by getting them to reveal their super secret passwords directly into the microphone. We don't know their email address or anything, so it's not the worst thing in the world. But perhaps they should go home and at least turn two-factor authentication on?
 

Source: YouTube

Tuesday, December 23, 2014

Confirmed: 1.16 million credit card numbers stolen in Staples breach.

Staples said that malware infected the checkout stations at 115 of its 1,400 U.S. stores. It began removing the software in mid-September. Investigations in the meantime revealed that shoppers who made purchases at these stores across the country going back as far as July may have had their credit card numbers, expiration dates, verification codes and their names stolen in the hack.

In a statement, Staples said that 1.16 million credit and debit cards may have been affected.
Michael Regal, editor at large for Bloomberg News said on "CBS This Morning: Saturday" that consumers should not be held responsible for any fraudulent charges following the breach, but urged anyone who's shopped at the store in recent months to check their credit card statements carefully for any unusual activity.

Staples is offering free credit monitoring, identity theft insurance and a free credit report to any customers who used a credit or debit card at the affected stores during the breach. It posted the specific locations and dates online.

Friday, June 27, 2014

Here are five tips to protect your identity online.

1. Change passwords once a month. Passwords are the keys into your life. If a criminal gets access to your email or any of your online accounts, it's surprisingly easy for them to worm their way into other aspects of your life.

Assume your passwords will periodically get compromised. Adobe, AOL, eBay, Kickstarter and Yahoo have all had major security glitches in the past few months.

2. Give the wrong contact information at checkout. Recent data breaches, like last year's Target hack, show that companies aren't responsible enough to safeguard that information. Every time a store clerk asks for your zip code or phone number, that data gets aggregated. So retailers not only have databases that show where you live. They can find out much more about you, like your salary, credit history and birthday.

3. Need photo ID? Don't show your driver's license. This is a general rule for privacy. Don't reveal more than you have to. A driver's license shows your birthday and address.

Next time your doctor's office asks for identification with a photo, show them something else, like your office building badge.

4. No banking apps. Be particularly careful about access to your bank accounts. Although most credit cards have fraud protection, your checking and savings accounts don't.

Because of how easy it is for a computer to get infected with a malware that spies on you, we don't recommend shopping and banking on the same computer.

5. Keep one email account for junk mail only. When companies demand an email address, give them a dummy address. That way you don't have to be bothered with all the spam and annoying advertisements; and it shields your real email from junk. Plus, if those companies get hacked, your real account remains safe.

Wednesday, June 4, 2014

Google now testing super secure email.

It's called "End-to-End" encryption, and it's the best way to stop anyone from snooping on your emails. Google would turn your emails into jumbled code, and the only person who can see the email in plain text is the trusted person on the other end.

Hackers don't stand a chance. In fact, neither does the National Security Agency. It's the kind of encryption ex-NSA contractor Edward Snowden used to communicate with journalists before he went public last year with damning documents proving the extent of U.S. government surveillance. It's what spies use...it's that good.

But End-to-End is not available just yet. In a blog post, Google said the program is in a public testing phase. After that, you'll be able to download the app and add it to your Google Chrome Web browser. If you use the browser, it'll work with any Web-based email provider.

"We recognize that this sort of encryption will probably only be used for very sensitive messages or by those who need added protection," wrote Stephan Somogyi, a Google product manager who oversees security and privacy, in the blog. "But we hope that the End-to-End extension will make it quicker and easier for people to get that extra layer of security should they need it."

Here's how Google's super encryption would work: Imagine you want to send a sensitive letter by mail. You can't just lick the envelope shut. Postal workers might open it. But they can't open a lock.
Your friend buys a padlock, opens it and sends it to you. He keeps the key. You receive his lock, place your letter inside a box and close it with your friend's lock. You send it. Now only he can open it with his private key, which never left his possession.

Google will let you share locks, but never keys. So far, End-to-End encryption has proven tamper-proof.

This is only the latest move by Silicon Valley giants to beef up their security since last year's revelations that the U.S. government is gathering our emails and phone calls without warrants. In December, executives at the world's largest technology firms called on the U.S. government to respect Internet privacy rights, dial back its intelligence gathering and make spying programs more transparent.

Since then, Microsoft and Yahoo have been working on encrypting the information they house and transmit. Facebook CEO Mark Zuckerberg called President Obama directly to complain about the NSA. And they've all shed light on the scope of secret data requests.

Source: CNN Money

Wednesday, April 16, 2014

A tip for a much stronger password.

Use a passphrase: a sentence you can remember. Then replace each word of the phrase with its initial, a similar digit or symbol, or, at random, use a whole word.

For example: My Dad Bob Yelled At My Idiot Brother
m d b y @ m ! b

The new password is mdby@m!b.

That may still be tough to remember. If you need to, write a reminder and hide the paper somewhere safe. But write the phrase or a hint, not the password.

Generally, if you have a strong password, you don't need to change it unless you suspect you've been hacked. But don't use the same one for different services.

Friday, August 30, 2013

New York Times hit with malicious attack.

A tweet from the official Times Twitter account was directing readers to an alternative website, news.nytco.com, if they were having difficulties accessing the main site at nytimes.com. Readers in Europe and Asia were reporting problems Wednesday.

Marc Frons, chief information officer at the Times, told employees Tuesday that the outage was the result of an attack on Melbourne IT, the company's domain name registrar, according to the New York Times.

Frons told the Times that the hacktivist group Syrian Electronic Army was responsible for the attack, "or someone trying very hard to be them." The Syrian Electronic Army is a group of hackers aligned with Syrian President Bashar al-Assad.

The group sent a tweet claiming responsibility for the Times attack, and SEA also claimed that it took over Twitter's own domain on Tuesday afternoon.

The Federal Bureau of Investigation has begun looking into the website disruption, a law enforcement official told CNN. The "preliminary inquiry" is still in its early stages, the official said.
The Times did not reply to a request for comment.

Two weeks ago, Syrian Electronic Army claimed responsibility for hacking Outbrain, a news recommendation engine that appears on websites including The Washington Post, CNN and Time. The hacked news links were redirecting to a site controlled by the hacking group, which supports Syrian President Bashar al-Assad and has taken credit for several recent cyberattacks.

The New York Times' own website had suffered an outage the day before the Outbrain hack, prompting speculation that hackers were responsible, but a spokeswoman for the paper said that outage was the result of complications associated with a scheduled maintenance update.

Source: New York Time

Tuesday, July 2, 2013

Low on money? Know how to hack? Get on over to Facebook to "research" (a.k.a. hack).

Facebook has paid a $20,000 reward to a UK based security researcher for reporting a bug that hackers could've used to take over users' accounts. 

Last month, UK security researcher Jack Whitton found a way to hack into other users' Facebook accounts without their knowledge, simply by sending a text message to Facebook. 

The flaw, which Facebook has fixed, was in a Facebook service that lets users link their mobile phones with their accounts. This lets them log into Facebook using their phone number instead of their email address, and send profile updates via text message.

To activate this feature, a user sends a text message to Facebook, which texts back an authorization code. This code is what ties the user's device to their account. 

But Whitton found that Facebook's authorization code could be tweaked to work with other users accounts as well. This means a hacker could just change the password and gain complete control over the account.

Graham Cluely, an independent security analyst, says the bug could have had a widespread impact on Facebook users.

"This should – obviously – have been impossible, but due to a weakness in Facebook’s tangled nest of millions and millions of lines in code, potentially hundreds of millions of accounts were vulnerable to hijacking through the simple technique," Cluely said in a Friday blog post.

Whitton informed Facebook about the flaw May 23, and Facebook fixed it five days later. Facebook gave Whitton a shout-out on its list of "white hats," the term for researchers who find bugs and inform vendors instead of using them for financial gain.

Source:  Business Insider

Saturday, June 22, 2013

New Facebook bug exposes some contact information.

A newly discovered Facebook bug may have inadvertently compromised the contact information of 6 million users, the company says.

The bug, which has since been repaired, was part of the Download Your Information tool, which lets Facebook users export all the data from profiles, such as posts to their timeline and conversations with friends. People using the tool may have downloaded inadvertently the contact information for people they were somehow connected to.
 
Some people upload their contact lists or address books to Facebook, which the company then uses to suggest new friends they can connect with who are already using the service.
 
Though the number of people impacted is sizable, the actual spread of their contact information appears to be limited. The phone numbers and e-mail addresses were not exposed to developers or posted publicly. It is only shown to people they had at least a tentative connection with, and who may have already had their contact information. Even in that pool, it was only exposed to people who had used the data-exporting tool.

"For almost all of the email addresses or telephone numbers impacted, each individual email address or telephone number was only included in a download once or twice. This means, in almost all cases, an email address or telephone number was only exposed to one person," Facebook's security team said in a post.
 
The company says it has no evidence that the bug was "exploited maliciously" and that there have been no complaints so far.
 
The social media company announced the bug on Friday afternoon. The issue was discovered by a third-party security researcher who submitted it through Facebook's White Hat program.
 
Facebook's White Hat program is set up so that people such as security researchers can report any vulnerabilities they find on the social network and get a reward for $500 and up in return. These types of programs are common at Internet companies.
 
"Your trust is the most important asset we have, and we are committed to improving our safety procedures and keeping your information safe and secure," read the post.
People who were affected by the bug will receive an e-mail from Facebook.
 
Source: CNN

Tuesday, April 16, 2013

Cyberspies are now targeting small businesses as opposed to large corporations. Is your business protected?

­Cybercriminals are taking greater pains to infect the computers of certain employees at specific companies, and are increasingly targeting smaller organizations for sophisticated cyber espionage campaigns.

Those findings were released today by Symantec based on the security giant's analysis of malicious attacks that circulated globally on the Internet in 2012.

Symantec tracked a 42% increase targeted attacks over 12 months, with the greatest growth coming in network intrusions directed at companies with fewer than 250 employees.

Why are small businesses being targeted?
Small businesses often lack adequate security practices. Attackers are moving down the supply chain and choosing to breach the lesser defenses of a small business that may have business relationships with a larger company.

What can or should small businesses do?
The first step is knowing what information needs to be protected. Small businesses should look at where their important information is stored and how it is used, and should first look to protect those areas accordingly.

How can IES help?
We provide the best IT consulting services around! (Yes, that's what all of our competitors say too). But ask any of our current clients and they'll tell you the same. From basic virus protection to securing an entire network, IES technicians are there for our customers 24 hours a day, 7 days a week.

Give us a call today at 781-81-MY-IES (781-816-9437) to secure you business.

Source: Symantec, USA Today

Tuesday, February 19, 2013

Burger King has been hacked!

The Twitter account associated with the fast-food chain Burger King was suspended after an apparent hacking that defaced the page with messages that the account had been sold to rival McDonald's.

The @BurgerKing account name was changed today to "McDonalds" and the Golden Arches' familiar logo was added to the page, as was a message that the account had been sold to McDonald's "because the whopper flopped."

The page has since been taken down, but images of the defacement are still visible on Web cache.
Before the feed's suspension, hackers posted tweets that included racial epithets to Burger King's some 83,000 followers -- a tally that ballooned by about 25,000 to more than 108,000 after the hack.
The online hacktivist collective Anonymous appeared to take responsibility for the hack in a tweet that mentioned a new operation dubbed #OpMadCow, although it was not immediately clear what the aim of that campaign was.

Burger King said it shut down the feed when it learned of the hack and apologized for the unauthorized content tweeted from the account this morning.

"We have worked directly with administrators to suspend the account until we are able to re-establish our legitimate site and authentic postings," the company said in a statement. "We apologize to our fans and followers who have been receiving erroneous tweets about other members of our industry and additional inappropriate topics."

See a screenshot of the Twitter account below:

Tuesday, February 5, 2013

If it can happen to the government, it can certainly happen to you! Hackers have attacked the US Department of Energy.

"The Department of Energy has just confirmed a recent cyber incident that occurred in mid-January which targeted the Headquarters' network and resulted in the unauthorized disclosure of employee and contractor Personally Identifiable Information".

The agency said that it is working to figure out the "nature and scope of the incident" but that so far it believes no classified data was compromised. It's currently unclear which divisions within the Department of Energy were attacked or who was behind the hack.

Source: CNET