Home Blog Page 408

Less than 10 French companies hit by cyberattack

Cyber-Crime

Fewer than 10 companies have fallen victim to the global hacking attack that hit hospitals, car factories, and other organizations in more than 150 countries. The announcement was made by French government cybersecurity agency ANSII.

French automaker Renault had to stop production of vehicles at various sites to prevent the spread of the ransomware cyberattack.

Fortunately, France, Romania and Slovenia had already undertaken preventive measures to stop the spread of the ransomware. Due to this, more than 90 percent of factories in France were running normally.

Renault also resumed production within a few days. All Renault factories are back to normal including northern France plant in Douai, a Renault spokesman said.

UK strengthens defense against cyber attacks

cyber-attacks

With the spike in the menace of digital attacks—the latest one being ransomware attack carried out by ‘WannaCry’, a group of hackers, which almost led to a global crash in the economy; suggesting the vulnerable cyber security in place, nine of the world’s biggest weapon makers and telecoms providers are teaming up with Britain to strengthen their country’s cyber security to thwart such attacks.

The teams who are involved in this project include: BAE Systems, Rolls-Royce, Lockheed Martin and Hewlett Packard along with few others, informed the Ministry of Defense.

According to GCHQ, the government spy center, who are also part of project, the Britain’s government and industry networks suffer from about 70 sophisticated cyberattacks every month, with 15 percent of them against the defense sector.

This Defense Cyber Protection Partnership will look to implement controls and share threat intelligence to increase the security of the defense supply chain.

“This is a clear demonstration that government and industry can work together – sharing information, experience and expertise,” said Minister for Defense Equipment, Support and Technology Philip Dunne.

It must be noted that Britain has made cyber security as one of its top national defense priorities in 2010, owing to the cyber-attacks.

Other companies in the partnership are Finmeccanica’s SIFI.MI Selex unit, EADS’s Cassidian arm, etc.

John Oliver tells viewers to gofccyourself

john-oliver

The Federal Communications Commission (FCC) reported a DDos attack after celebrity presenter John Oliver asked his viewers to gofccyourself.com.

Yes, you read it right. Campaigning for free internet, John Oliver asked his viewers to submit comments in favor of net neutrality. Soon after the segment was aired, the FCC website crashed. Many felt the show to be held responsible, as this isn’t the first time John had voiced for free internet and the reaction was this mammoth. Like always, he broke down boring words into simpler facts. He went on to say that net neutrality is important because it mandates that internet service providers (ISPs) “should not be able to engage in any sort of mockery that limits or manipulates the choices you make online.” He asked the viewer to use the domain gofccyourself.com registered by him to directly reach out to the FCC website’s comments page.

He also took a dig at the new FCC chairman Ajit Pai, and his obsession to huge Rees’s jugs. Meanwhile, FCC stated this statement on a release.

“Beginning on Sunday night at midnight, our analysis reveals that the FCC was subject to multiple distributed denial-of-service attacks (DDos). These were deliberate attempts by external actors to bombard the FCC’s comment system with a high amount of traffic to our commercial cloud host. These actors were not attempting to file comments themselves; rather they made it difficult for legitimate commenters to access and file with the FCC. While the comment system remained up and running the entire time, these DDos events tied up the servers and prevented them from responding to people attempting to submit comments. We have worked with our commercial partners to address this situation and will continue to monitor developments going forward.”

Now, it’s really unknown whether there was a genuine DDos attack or if there was a massive amount of traffic on the page. And like always, John Oliver is going to wash his hands off saying, “I didn’t do anything, it’s the masses.”

UHD Movie Surfaces On Torrent

uhd-on-torrent

The crackdown on Torrentz and the related sites haven’t yielded the desired results. Most of them continues to be access directly or using a proxy server. So, this may come as a good news for the fans of Torrent sites, it looks like Advanced Access Content System (AACS) 2.0 have been cracked and the first 4K Ultra High Definition (UHD) Blu-Ray movie has apparently surfaced online.

“While there is no shortage of pirated films on the Internet, Ultra-high-definition content is often hard to find. Not only are the file sizes enormous, but the protection is better than that deployed to regular content. UHD Blu-Ray Discs, for example, are protected with AACS 2.0 encryption which was long believed to unbreakable. A few hours ago, however, this claim was put in doubt. Out of nowhere, a cracked copy of a UHD Blu-Ray Disc surfaced on the HD-focused BitTorrent trackers UltraHDclub and IPT,” reported Torrentfreak.

Now, if you are part of the distribution wing of WB, Sony, or even the founding investors of AACS, this news can grind your ears. The file stands at a whopping 53.30 GB, this means it will has quite a substantial quality. Now, what might scare you is the level of compression that might go. Torrent now gives you compressed 720p files in less than 700 MB size, which is bit of an overkill in every way. Another reason is the name of the file which is “The Smurfs 2(2013) 2160p Blu-ray HEVC Atmos 7.1-THRONE,” very clearly implies that it’s the same 2013 movie, just a preposterously better version. But, would you be willing to download this huge file and even seed it? We’d suggest you to skip this one.

IBM flash alert, literally

ibm-flash-alert

What could possibly go wrong if you order a dozen on two USB sticks from one of the most renowned and secure manufactures in the world? It might be infected.

IBM has issued an alert after it was found that the USB flash drives shipped were infected with malware. “IBM has detected that some USB flash drives containing the initialization tool shipped with the IBM Storwize V3500, V3700 and V5000 Gen 1 systems contain a file that has been infected with malicious code,” IBM Support stated in a post.

When the initialization tool is launched from the USB flash drive, the tool copies itself to a temporary folder on the hard drive of the desktop or laptop during normal operation. With that step, the malicious file is copied with the initialization tool to the following temporary folder – on Windows systems: %TMP%\initTool, on Linux and Mac systems -/tmp/initTool. While the malicious file is copied onto the desktop or laptop, the file is not executed during initialization.

The Initialization Tool on the USB flash drive with the partnumber 01AC585 that shipped with the following System models may have an infected file. These were IBM Storwize V3500 – 2071 models 02A and 10A, IBM Storwize V3700 – 2072 models 12C, 24C and 2DC, IBM Storwize V5000 – 2077 models 12C and 24C, IBM Storwize V5000 – 2078 models 12C and 24C.

It stated that the IBM Storwize Systems with serial numbers starting with the characters 78D2 are not affected, “Neither the IBM Storwize storage systems nor data stored on these systems are infected by this malicious code.”

The company is recommending to either destroy the flash drives or securely wipe the drives so that they can be reused.

Father of labyrinth

drone-hijacker

Gone in 11 milliseconds.

Drones have become a new fad. They are all over the place. From filmmakers to YouTube channels, they all use it, and these indubitably do take some really attractive shots. Even Amazon delivers packages by drones. And that’s one reason why enthusiasts do not mind shelling out a couple of hundred dollars on these. But, make sure your drones are miles away from Icarus, the father of labyrinth (literally).

PacSec researcher Jonathan Andersson has developed a hardware that is capable of hijacking drones. Dubbed as the Icarus (creator of Labyrinth) from the Greek mythology, the hardware module only needs to be with the range of a drone to hijack it with commands. This is the kind of drone hijacker you saw in Christopher Nolan’s sci-fi magnum opus, Interstellar, only ten times faster.

A new video posted by Kaspersky Labs shows Icarus taking control of a drone mid-air within 11 milliseconds of launch. In fact, it can affect any radio controlled device which uses the popular DSMx radio platform.

Andersson had earlier demonstrated the hardware at the PacSec conference in Japan. “It’s not a jamming system so I am not competing for control via RF power,” Andersson told Vulture South.

“Full flight control is achieved with the target experiencing a complete loss of control — it’s a clean switch-over. The range of my proof of concept implementation is equal to a standard DSMx radio transmitter, though standard 2.4GHz ISM band amplification can be applied to extend the range.”

Picture this scenario, you are out on the playground with your new $500 toy drone. You launch it to the air and watch it fly out of your sight, ignoring the controller. That’s just sad. But it can get even worse. We live in an era where remote controlled military drones strike mid-air. Do you see the possibility?

1 in 8 Brits are victims of medical data breach

healthcare-data

Not even a day goes by that a news of a leak or data breach is not reported. Most often banks and corporations are targeted, hackers have realized that the healthcare sector is also a potential goldmine.

The findings, from a survey of 7,580 people carried out by Accenture in seven countries, revealed that more than half (56%) of data breaches in England concerned medical identity theft and that people who have experienced a breach lost an average of £172 ($220) as a result.

Now, UK pharmaceutical sector has emerged as a key weak spot for data breaches.

Pharmacies were the most likely to be the weak link in security, according to respondents, with 35% claiming that a breach happened at a pharmacy. This compared with 29% who blamed a hospital, 21% an urgent care clinic, and 19% a doctor’s office.

A quarter of victims had their NI number compromised and 18% saw their biometric identifiers compromised. The stolen data was used for fraud, according to 82% of victims.

Aimie Chapple, managing director of Accenture’s UK health practice and client innovation said, “Patients must remain more vigilant than ever in keeping track of personal information – including credit card statements and health records – that could alert them to breaches,” while talking to Computer Weekly.

“Similarly, health organisations must monitor patient information more carefully and remain transparent with those affected in the event of a breach to swiftly resolve the issue without losing consumers to competitors.”

Southeast Asia houses 9000 infected servers

Data breach in 100 U.S. cities

The cybercrime wing of the Interpol has revealed that seven southeast Asian nations have nearly 9000 malware-laden servers. Apart from these, the Interpol also noted that the nations also house hundreds of compromised websites.

The types of malwares in these nation are capable of spreading ransomware, target fintech organizations, launch Distributed Denial of Service (DDos) attacks, and even distributes spams.

“This operation helped participants identify and address various types of cybercrime which had not previously been tackled in their countries,” said Francis Chan, head of the Hong Kong Police Force’s cybercrime unit and chairman of Interpol’s Eurasian cybercrime working group while talking to Reuters.

The international police body has also roped in experts from seven private firms for the operation run from the Singaporean Interpol Global Complex for Innovation (IGCI). Comment about DDoS attacks it saidm that it has been among the most common methods of hacks on the internet. It makes use of hijacked and infected systems to target websites overloading them with requests until the website is overwhelmed and can no longer cope with the amount of traffic inflow.

The IGCI identified nearly 300 websites infected with numerous virus and malware codes. And many of these were government websites that had personal data of the citizens.

The drill was majorly due to a breach earlier this year where the Singapore’s Ministry of Defense was compromised, leaking the personal details of almost 900 national servicemen and staff. The defense ministry called it a ‘targeted and carefully planned attack’.

Germany sees 80% increase in cybercrimes

Germany-cybercrimes

As many as 82,649 cases of cyberattacks were reported in 2016. These vary from computer fraud, espionage and other similar cyberattacks. The figure is almost 80 percent more than what the state had reported in 2015.

German Interior Minister Thomas de Maiziere is due to release the new statistics, part of the government’s annual crime report, on Monday, according to Die Welt newspaper.

In addition to cybercrime, German police also registered 253,290 cases of crimes carried out with the help of the internet, an increase of 3.6 percent from 2015, the newspaper reported.

This may come as a surprise. The proliferation of technology and connected devices has increased to a tremendous extent. Also, among criminals. Here is a thing about crime through web, it is convenient, faster and safer for the attackers.

The amount of internet connected users is greater than ever before. The staggering number of crimes poses a huge question to internet security. Here, the need of the hour is cybersecurity literacy. This is an evolving space and so are the criminal. It has moved beyond college dropouts hacking computers from basements. There have been rise in the number of attacks perpetrated from nations. The world awaits a day when there is no news on cybersecurity, a dead ringer on the BBC News, a few decades ago.

Cyber security is a major concern for Berlin as a Sept. 24 federal election approaches. German intelligence agencies said in December Russia was seeking to use propaganda, cyber attacks and other means to destabilize German society before the vote.

“Cyber is what keeps me up at night,” Deputy Defense Minister Katrin Suder told reporters at an event hosted by the Federal Academy for Security Policy, a government training body. “This is not science fiction anymore … It is a topic of immense and growing importance.”

Suder said the German military was making progress with a new cyber command that starts operations on Wednesday, and control over cyber functions that had been scattered across the military had become more centralized.

(with agency inputs)

HipChat hacked, co. invalidates all passwords as countermeasure

hipchat-hacked

Workplace chat platform HipChat has become the newest victim of cyberattack. The Atlassian company announced the news on the weekend. According to the reports, the attack was due to a vulnerability in a third-party library used by HipChat.com

The attack affected a server in the HipChat Cloud web tier, though at a meager level. But evidence suggest that content and messages in the rooms may have been accessed, these include details like names, email addresses and even hashed passwords.

HipChat Chief Security Officer Ganesh Krishnan noted that HipChat hashes passwords using bcrypt with a random salt. “As a precaution, we have invalidated passwords on all HipChat-connected user accounts and sent those users instructions on how to reset their passwords,” said HipChat chief security officer Ganesh Krishnan.

“If you are a user of HipChat.com and do not receive an email from our Security Team with these instructions, we have found no evidence that you are affected by this incident.”

There’s no evidence the breach impacted other Atlassian systems, like Jira, Confluence or Trello. “We are confident we have isolated the affected systems and closed any unauthorized access,” Krishnan wrote.

“While HipChat server uses the same third-party library, it is typically deployed in a way that minimizes the risk of this type of attack,” said Krishnan. “We are preparing an update for HipChat Server that will be shared with customers directly through the standard update channel.”