security

  1. AlphaAtlas

    DriveSavers Charges Around $3,900 to Unlock Password Protected Devices

    Today, DriveSavers announced a new service that can allegedly unlock and recover data from password protected computers. Devices from Apple, Samsung, Huawei, LG and other running iOS, Android, Windows, or Blackberry are said to be supported. Interestingly, the company claims they don't offer the...
  2. AlphaAtlas

    The FBI Impersonated FedEx to Catch Cybercriminals

    After uncovering some interesting court records, Motherboard wrote up an article on how law enforcement is using "network investigative techniques" to catch cybercriminals. In one particular case, attackers used a fake email address and a bit of social engineering to get a $82,000 check from...
  3. AlphaAtlas

    U.S. Allegedly Asks Allies to Drop Huawei

    According to a report by the Wall Street Journal, the U.S. government has asked its allies to persuade "wireless and internet providers in these countries to avoid telecommunications equipment from China's Huawei Technologies Co." The same sources also claim the U.S. is considering extra...
  4. AlphaAtlas

    USPS Vulnerability Exposed 60 Million Users

    The U.S. Postal Service recently fixed a gaping hole in their website's API that would give potential attackers access to package transit information, email addresses, usernames, account numbers, street addresses, phone numbers, and other information tied to USPS accounts. KrebsOnSecurity says...
  5. cageymaru

    Amazon Exposes Customer Names and Email Addresses Due to a Technical Error

    BetaNews is reporting that Amazon has sent emails to customers to inform them that a technical issue caused their names and email addresses to be revealed. Affected customers do not have to take action as the issue was taken care of. In response to our request for a statement Amazon's PR...
  6. cageymaru

    How the Dropbox Offensive Testing Security Team Discovers Zero-Day Vulnerabilities

    Dropbox has multiple security teams to make sure that your data is secure and safe. They also conduct red team training exercises where the red team takes on the role of an attacker, and the other teams have to respond to the threat. During a recent offensive training exercise with Syndis; a...
  7. AlphaAtlas

    Adobe Issues Yet Another Emergency Flash Update

    Yesterday, Adobe pushed out an emergency update to Flash. According to Adobe, the "critical" vulnerability could lead to arbitrary code execution, putting any browser that autoruns flash plugins at serious risk. In a deviation from their usual policy of issuing security updates on patch Tuesday...
  8. AlphaAtlas

    Over 560,000 Tricked Into Downloading Malware from Google Play

    Even though Google is rejecting and removing Play Store apps at a furious pace, some malware is still getting through with relative ease. Forbes reports that more than 560,000 users have downloaded at least one of 13 malicious apps from a developer called "Luiz O Pinto." These apps masqueraded...
  9. AlphaAtlas

    Data Centers Consume 2% of the World's Energy

    According to a report by the Silent Partner Group of Companies, data centers eat about 2% of humanity's global energy production, and that rising figure is starting to create security and logistical issues. The release points to brief AWS power outages in March and May of this year that knocked...
  10. AlphaAtlas

    Fake Google Analytics Script Exposes Vision Direct Customer Info

    The BBC reports that Vision Direct, a European contact lens store, suffered a data breach that exposed the financial info of over 6,600 customers, as well as other personal data of 9,700 more customers. Some of the leaked data includes credit card numbers, expiration dates and CVV codes...
  11. AlphaAtlas

    How A Hacker Obtained Motorola Source Code with a Few Phone Calls

    Motherboard uploaded a video showing how Kevin Mitnick managed to obtain a Motorola cell phone's source code with a couple of phone calls. And, just for fun, he hacked Motorola's network afterwards, and obtained older versions of the source code as well. This just goes to show that, no matter...
  12. AlphaAtlas

    2015 White House OPM Hack is Still Largely Unfixed

    Back in 2015, the White House Office of Personnel Management was hit by a big hack, and the government response was pretty slow. The Government Accountability Office, which recently released a scathing report on the security of U.S. weapon systems, issued several recommendations after the hack...
  13. AlphaAtlas

    MiSafes Children Tracking Watches Can be Easily Hacked

    The BBC reports that a location tracking watch "worn by thousands of children" can be easily infiltrated by anyone with internet access. While the BBC report calls it "easy to hack", and is light on technical details, the security researcher's own words make it sound even worse. Ken Muro said...
  14. AlphaAtlas

    Steam Bug Allowed Games to be Downloaded for Free

    Researcher Artem Moskowsky found a bug in Steam that let users download "previously-generated CD keys for a game which they would not normally have access." The bug was submitted to Valve on August 7, quickly fixed on August 10, and publicly disclosed on October 31. Valve was quick to point out...
  15. AlphaAtlas

    Notorious Steam Hacker DerpTroll is Facing Prison Time

    If your PSN, 2K or Windows Live account info got leaked in 2014, you may finally be getting justice. Notorious hacker Derptroll has just plead guilty to denial of service attack charges. Among other things, 23 year old Utah resident Austin Thompson was responsible for taking Steam, Origin and...
  16. AlphaAtlas

    Intel Drafts Model Data Privacy Bill

    Amid a number of recent security and privacy scandals, tech-related privacy issues are getting more attention than usual. Intel itself doesn't mine as much data as Google, Facebook, Amazon and others do, but they do sell the hardware to do it, hence they have a stake in the issue. Intel told...
  17. AlphaAtlas

    GPUs can be Used to Steal Passwords and Leak Data From Cloud Instances

    Researchers from The University of California, Riverside, published a paper detailing how an Nvidia GPU can be used to orchestrate a variety of attacks. In one attack, the researchers fed GPU memory allocation and performance counter data to a "machine learning based classifier," which...
  18. AlphaAtlas

    HSBC Bank Breach Leaks Account Numbers and Balances

    HSBC bank was reportedly hit by a credential stuffing attack, which allowed attackers to gain access to "full name, mailing address, phone number, email address, date of birth, account numbers, account types, account balances, transaction history, payee account information, and statement...
  19. AlphaAtlas

    Scammers Mimic Elon Musk on High Profile Twitter Accounts

    According to a BBC report, scammers who hacked their way into several high profile Twitter accounts used Musk's likeness to scam people out of some Bitcoin. High profile accounts like Matlan, Pathe UK, and Pantheon Books had their handles and profile images changed to resemble Elon Musk or...
  20. AlphaAtlas

    Researchers Find Vulnerabilities in Self Encrypting SSDs

    Researchers from Radboud University in the Netherlands found severe security vulnerabilities in several popular, self-encrypting SSDs from Samsung and Crucial. These SSDs can encrypt and decrypt data coming in and out on the fly, which is seen as a "hardware encyption" option in Bitlocker on...
  21. cageymaru

    Hackers Are Selling Access to Private Facebook Data for 10 Cents per Account

    Often politicians, researchers, corporate entities and citizens discuss the human toll of social media hacks and fierce debates ensue from those crimes, pertaining to what private account data is worth. Hackers in Russia have attached a price tag of 10 cents per account as they attempt to sell...
  22. cageymaru

    The GSA Has Elected New Leadership to Expand the Initiative of the Organization

    AMD CEO and President Dr. Lisa Su has been appointed as Chair of GSA Board of Directors and ARM CEO Simon Segars has been appointed Vice Chair of the global semiconductor organization. The GSA seeks to expand its scope of interest to include systems, software, solutions and services. The...
  23. cageymaru

    Google Sign-In Page Requires JavaScript Be Turned on for Security

    A recent post on the Google Security Blog says that the internet giant will require that users enable JavaScript to use the Google sign-in page. This will allow Google to run a risk assessment and only allow a sign-in if nothing looks suspicious. The blog post also discusses new Google account...
  24. AlphaAtlas

    Researchers Find That Your Browsing History is Vulnerable

    Techxplore reports that researchers from UC San Diego and Stanford found a new technique to expose a victim's browser history. According to the researchers, the attack works in recent version of Chrome, Edge, Firefox, and a number of other browsers. "History Sniffing" attacks work by probing the...
  25. AlphaAtlas

    Renewed DMCA Exemptions Protect Security Researchers

    The Digital Millennium Copyright Act is often criticized for its overreaching potential for abuse, but fortunately, "Section 1201" allows lawmakers to change or renew specific exemptions every three years. Motherboard reports that the feds just renewed an exemption that protects security...
  26. Cerulean

    Scalable management of non-default SNMP for 10-100k devices?

    Howdy! I am on an adventure to disable SNMPv1 (unless required by vendor) and configure SNMPv2c/3 (only highest and most secure possible) on 100-300 clients or 20k-100k devices that are SNMP capable. This includes ensuring devices do not use default SNMP strings and credentials. Does anyone...
  27. AlphaAtlas

    China Is Hijacking the US Internet Backbone

    According to a report published by researchers Chris C. Demchak and Yuval Shavitt, China Telecom is redirecting sensitive internet traffic between the U.S. and other countries through China. China itself only has 3 major access nodes that connect to other countries, leaving China's network...
  28. AlphaAtlas

    Company Plans Quantum Network Between Boston and Washington D.C.

    TechCrunch reports that Quantum Xchange made a deal with Zayo to use 800km of existing fiber optic cable for the U.S's first quantum network. The fiber stretches between Boston and Washington D.C, and will use quantum key distribution for secure end-to-end encryption. High profile investors seem...
  29. cageymaru

    Cathay Pacific Airways Announces Hackers Have Given Customer Data Wings

    Cathay Pacific Airways has announced that a 'data security event' occurred (hack) in March and 9.4 million people are affected. The airline says that there is no evidence that personal information has been misused and reassured passengers that the flight operations are on a separate system...
  30. AlphaAtlas

    Android Security Updates are Now Mandatory

    According to a contract obtained by The Verge, Google is forcing Android device makers to issue security patches for at least 2 years after their products hit the market. "At least four security updates" must be provided within a year of the phone's launch, while requirements for subsequent...
  31. cageymaru

    Apple iOS 12 Disables 'GrayKey' iPhone Hack Used by Governments Around the World

    Apple has successfully blocked the "GrayKey" hack that allowed law enforcement and governments around the world unfettered access to passcodes on Apple devices running iOS. Devices running iOS 12 and above can only have metadata such as file structure and unencrypted files accessed by Grayshift...
  32. AlphaAtlas

    Supermicro is Investigating Bloomberg's Allegations

    Reuters reports that Supermicro is looking for spy chips on their motherboards. In a letter to customers, the manufacturer denies the allegations Bloomberg made over two weeks ago, claiming that such a device would be "technically implausible." There are safeguards in Supermicro's supply chain...
  33. AlphaAtlas

    Tesla Model S Stolen with a Tablet

    A UK Tesla Model S was hacked and stolen in just under three minutes. The car jackers used a tablet to find the distant key fob's signal. Once that got the car open, they struggled trying to unplug the car's charger for about a minute, jumped inside, disabled Tesla's Remote Access system, and...
  34. AlphaAtlas

    Facebook is Looking for a Cybersecurity Firm to Buy

    A report by The Information claims that Facebook is looking for a cybersecurity firm to buy. According to four anonymous insiders, Facebook approached multiple companies with talks about an acquisition, but the report didn't mention any companies by name. Facebook suffered from a big security...
  35. AlphaAtlas

    MIT's DAWG Mitigates Spectre and Meltdown

    Researchers at MIT have built a new security measure on top of Intel's Cache Allocation Technology. Dynamically Allocated Way Guard, or DAWG, is built to isolate programs from each other without the performance overhead of Intel's CAT. The technology only requires "minor modifications to the...
  36. cageymaru

    Some Citizens Are Concerned About New Robotic Patrols in NYC

    New York City has begun experimenting with allowing robots to patrol areas. Rosie the robot has 5 cameras, thermal imaging, artificial intelligence, self-driving car technology, analytics and is directly connected to law enforcement. Her job is to observe people walking on the streets, record...
  37. AlphaAtlas

    Medtronic Disables Pacemaker Software Updates Over Security Concerns

    Following an independent investigation by security experts, and an FDA review, Medtronic disabled software updates for the Medtronic CareLink and CareLink Encore Programmer models 2090 and 29901, which are used in pacemakers, implantable defibrillators, cardiac resynchronization devices, and...
  38. cageymaru

    Facebook Estimates That Only 30 Million Accounts Compromised by Hackers

    Facebook has issued a new statement about the recent "View As" hack of the company where up to 90 million customers were affected. Now Facebook is certain that only 30 million users had their personal information exposed to the hackers. This personal information includes Facebook Messenger...
  39. AlphaAtlas

    FitMetrix Leaks User Information

    Another day, another massive user data leak, this time from FitMetrix. The fitness company, which makes software for institutions like Crossfit and SoulCycle, reportedly hosted user data on AWS instances, but forgot to use a password to secure that data. Security researcher Bob Diachenko claims...
  40. AlphaAtlas

    Swiss Researchers Find 5G Security Gaps

    Swiss security researchers exposed gaps in the 5G AKA standard. Using a security protocol verification tool called Tamarin, the researchers ran the new wireless communication standard through a series of tests. Ralf Sasse, a senior scientist at ETH in Zurich, said their research "showed that the...
Back
Top