Showing posts with label CyberSecurity. Show all posts
Showing posts with label CyberSecurity. Show all posts

Wednesday, September 6, 2017

6 Million Instagram Accounts Hacked! Is Yours Among?

6 Million Instagram Accounts Hacked! Is Yours Among?

Instagram
If you are an Instagram user, your account may be among the six million accounts that have been hacked. The hack was made known to the public after celebrity star, Selena Gomez’s account was illegally accessed last week and naked pictures of her ex Justin Bieber were exposed online

Initially, Instagram said the bug had only affected a few celebrities but now it seems to be far more than that.

How Hackers had Access to the Instagram Accounts

Hackers were able to exploit a loophole in the app that opened details when a user was asked to reset their password.

This bug gave them access to intercept email addresses and phone numbers after sending false password reset requests.

According to the The Daily Beast, six million accounts could have been hacked and hackers would have created a database of details on the dark web using these accounts.

Instagram has now warned users to be on the look out for any suspicious activity and to report if they find any. It also emphasized that users should double check their security details and change them if necessary.

Mike Krieger, the company’s Chief Technology Officer (CTO), said: ‘We quickly fixed the bug, and have been working with law enforcement on the matter.

‘Although we cannot determine which specific accounts may have been impacted, we believe it was a low percentage of Instagram accounts.’

Mr Krieger, who also co-founded Instagram, added: ‘Out of an abundance of caution, we encourage you to be vigilant about the security of your account, and exercise caution if you observe any suspicious activity such as unrecognized incoming calls, texts, or emails.

‘Additionally, we’re encouraging you to report any unusual activity through our reporting tools. You can access those tools by tapping the ‘…’ menu from your profile, selecting “Report aProblem” and then ‘Spam or Abuse’.’

How to fix your Instagram account if it had been hacked

According to Kaspersky, you need to update your application to the latest version and change your password details to a stronger one as the bug only affected 2016 versions of the Instagram app.

Saturday, August 26, 2017

New Faketoken Virus Access Private Data By Copying Ridesharing Apps

New Faketoken Virus Access Private Data By Copying Ridesharing Apps

Faketoken virus steals private data
Hello everyone! This is to inform you about a Trojan Virus currently active online called "Faketoken".

Faketoken has been distributed and affected some Android devices through Ridesharing apps so you should be careful and more proactive when using such apps on your devices.

It is quite certain that Malware creators will continue creating and distributing their dangerous viruses as there is no sign of them stopping. Some of them has made thousands and millions of dollars through these malicious activities and while you can't stop them completely, you can protect your devices and always be very careful when dealing with some sensitive online activities.

How Faketoken Operates on Mobile Phones

Some Ridesharing apps have been discovered to be harboring mobile Trojan horses. These malwares steal bank data by impersonating the interfaces of these ridesharing apps.

According to Kaspersky Labs, if your ridesharing app asks you to re-enter your credit card information after you have already input it upon installation, you should proceed with caution. The malware responsible for this is known as the Faketoken Trojan, and apparently it has been around for a while now but more active and taking toll on many phones at the moment.

According to Kaspersky, the latest version of the Faketoken Trojan is called Faketoken.q. The company revealed that the malware infects phones through bulk SMS , where it prompts the user to download images. Once the user downloads the image, the Faketoken Trojan installs all its necessary parts, and begins to monitor everything done on the phone. Now, once the malware detects an app whose interface it can simulate, it overlays the app with its own screen. Then, instead of proceeding as usual, the app prompts you to enter your credit card information.

Some sensitive apps like mobile banking apps, Android Pay, the Google Play Store, and of course ridesharing apps has been infected already. However, the Virus is more popular in Russia but I am spreading this information globally as it could be unleashed to other parts of the world to cause more havoc.

Safety Tips to Prevent Faketoken Virus

Kaspersky recommends that you go to Android settings and prevent the installation of apps from unknown sources.

✔ Simply go to Settings
✔ Tap on Security
✔ Then uncheck Unknown Sources.

On a more serious note, you need to be aware of the permissions an app requests before installation, even if you download the app from a presumably safe source, like Google Play Store. Also, it would be prudent to install an antivirus app on your phone.

It is highly recommended that you read app permission and requests to know what the app can do on your phone before installing it. Some apps that requires the permission to access sms, call log, override other apps, galleries and some other sensitive information should be carefully examined before installation proceeds. So always feel free to apply this principle and you should at least minimize the chances of being attacked by this dangerous and malicious malware currently in circulation.

Wednesday, August 16, 2017

Ransomware Attack Costs World Biggest Container Ship Company Over $200M

Ransomware Attack Costs World Biggest Container Ship Company Over $200M

Maersk, the world's biggest container shipping company
The June cyberattack that paralyzed the computer systems in companies around the world is estimated to have cost Maersk, the world's biggest container shipping line between $200 million and $300 million US, A.P. Moller-Maersk said Wednesday.

The Copenhagen-based group, which was particularly severely affected by the attack, says the impact will first be reflected in its third-quarter results as revenue was mainly lost in July.

The company says the June 27 malware attack was distributed through Ukrainian accounting software with back doors into the networks of users. It was contained the following day.

"In the last week of the quarter, we were hit by a cyberattack, which mainly impacted Maersk Line, APM Terminals and Damco. Business volumes were negatively affected for a couple of weeks in July," CEO Soeren Skou said. The businesses "were significantly affected," but there was "no data breach or data loss."

It said it made a loss of $264 million in the second quarter, against a profit of $118 million a year earlier. Revenue rose to $9.6 billion from $8.7 billion.

Its full-year forecast for an underlying profit above the 2016 figure, which was $711 million, "is unchanged despite expected negative impact from the June cyber-attack," the group said. It added the gross capital expenditure for 2017 is still expected to be around $5 billion.

It said the guidance for 2017 excludes the acquisition of Hamburg Sud, the German container shipping company and the world's seventh largest container line, which the Danish conglomerate bought last year.

Maersk shares increased nearly 0.8 per cent to the equivalent of $2,074 in morning trading in Copenhagen.

Thursday, August 10, 2017

Russian Hacker Sentenced To 4 Years in Prison For Spreading Linux Malware

Russian Hacker Sentenced To 4 Years in Prison For Spreading Linux Malware

Hacker in Action
A Russian man accused of infecting tens of thousands of computer servers worldwide to generate millions in fraudulent payments has been imprisoned for 46 months (nearly four years) in a United States' federal prison.

41-year-old Maxim Senakh, of Velikii Novgorod, was arrested by Finnish police in August 2015 for his role in the development and maintenance of the infamous Linux botnet called Ebury that siphoned millions of dollars from victims worldwide.

Senakh was extradited to the United States in February 2016 to face charges and pleaded guilty in late March this year after admitting of creating a massive Ebury botnet and personally being profited from the scheme.

First spotted in 2011, Ebury is an SSH backdoor Trojan for Linux and Unix-style operating systems, such as FreeBSD or Solaris, which gives attackers full shell control of an infected machine remotely even if the password for affected user account is changed regularly.

Senakh and his associates used the malware to build an Ebury botnet network of thousands of compromised Linux systems, which had the capacity of sending over 35 million spam messages and redirecting more than 500,000 online visitors to exploit kits every day.

Senakh fraudulently generated millions of dollars in revenue running spam campaigns and committing advertising click frauds.

Working within a massive criminal enterprise, Maxim Senakh helped create a sophisticated infrastructure that victimized thousands of Internet users across the world," said Acting U.S. Attorney Brooker.
"As society becomes more reliant on computers, cyber criminals like Senakh pose a serious threat. This Office, along with our law enforcement partners, is committed to detecting and prosecuting cyber criminals no matter where they reside.


Ebury first came into headlines in 2011 after Donald Ryan Austin, 27, of El Portal, Florida, installed the Trojan on multiple servers owned by kernel.org and the Linux Foundation, which maintain and distribute the Linux operating system kernel.

Austin, with no connection to the Ebury criminal gang, was arrested in September last year and was charged with 4 counts of intentional transmission causing damage to a protected computer.

Senakh was facing up to a combined 30 years in prison, after pleading guilty to conspiracy to commit wire fraud as well as violate the Computer Fraud and Abuse Act.

However, a US judge on Thursday sentenced Senakh to 46 months in prison, the Department of Justice announced on Thursday. The case was investigated by the Federal Bureau of Investigation's field office in Minneapolis.

Senakh will be deported back to Russia following his release from the U.S. prison

Monday, July 31, 2017

Defcon Hackers Penetrate US Election Machines In 90 Minutes To Show Electronic Voting Loopholes

Defcon Hackers Penetrate US Election Machines In 90 Minutes To Show Electronic Voting Loopholes

Hacker on mask
Hackers attending the flagship cybersecurity conference Defcon this year were able to break into a wide variety of voter legislation and ballot machines in roughly 90 minutes, leading to fears that the outcomes of presidential elections could be influenced by cybercriminals in the near future.

Ever since the 2016 US presidential poll, when hackers linked to Russia were accused of tampering with voting machines in a slew of States, so-called "election hacking" has hit the headlines. To test for flaws, Defcon officials brought in 30 separate voting machines.

US election voting machine
One "WinVote" machine, from a now-defunct US company called Advanced Voting Solutions, had a hardcoded password of "ABCDE", Cnet reported .

Another machine could be hacked via its Wi-Fi connection using a known Windows XP exploit that was more than four years old, but left unpatched.

The old machines, used for registrations, were purchased on eBay or bought from government auctions. Shockingly, reports suggested that some were still storing hundreds of thousands of records.

In one case 600,000 records linked to citizens living in Tennessee were allegedly discovered.

"Our voting systems are weak and susceptible," Jake Braun, a former White House advisor and now-cybersecurity lecturer at the University of Chicago, told The Register. "Thanks to the contributions of the hacker community today, we've uncovered even more about exactly how."

He continued: "The scary thing is we also know that our foreign adversaries – including Russia, North Korea, and Iran – possess the capabilities to hack them too, in the process undermining principles of democracy and threatening our national security."

In one instance, a hacker was able to crack the WinVote machine's operating system, Windows XP, and install Windows Media Player to then blast Rick Astley's "Never Gonna Give You Up" from the built-in speakers. That was certainly in line with the playful ethos of Defcon.

Some hackers were able to crack the machines within an hour-and-a-half, with many more sitting for hours tinkering with the hardware and software to locate vulnerabilities.

There remains little independent research into the digital protections of such machines.

While each US state will have its own system (meaning it is highly-unlikely an entire presidential election could be hijacked on a national scale) experts fear that cybercriminals could target key battleground states to swing the results. To date, this remains largely hypothetical.

TJ Horner, an Android developer and student, tampered with the ExpressPoll 5000 voting machine during Defcon and found that he was able to exfiltrate data and even falsify voter information. "Your imagination is the limit," he noted in a blog post published on 30 July after the event.

According to Cnet, a security firm called Synack was able to exploit one machine via its USB ports. Without needing any type of authentication, the white-hat hackers plugged in a mouse and keyboard and took over the operating system by pressing "control-alt-delete".

"The exposure of those devices to the people who do bug bounties or actually look at these kind of devices has been fairly limited," Brian Knopf, an internet of things (IoT) researcher with cybersecurity firm Neustar told the publication, which attended the event.

He added: "Defcon is a great opportunity for those of us who hack hardware and firmware to look to these kind of devices and really answer that question: 'Are they hackable?'"

Source: ibtimes