Browsing category

Incidents

There’s a new way to take down drones, and it doesn’t involve shotguns

Not a jammer, device lets hackers fly drones and lock out original pilot.The advent of inexpensive consumer drones has generated a novel predicament for firefighters, law-enforcement officers, and ordinary citizens who encounter crafts they believe are interfering with their safety or privacy. In a series of increasingly common events—several of themchronicled by Ars—drones perceived as […]

Cellebrite digital forensics tools leaked online by a reseller

The firmware used by the Israeli mobile forensic firm Cellebrite was leaked online by one of its resellers, the McSira Professional Solutions. Do you know Cellebrite? It is an Israeli firm that designs digital forensics tools that are used by law enforcement and intelligence agencies to examine mobile devices in investigations. It became famous when […]

Chinese tech giant recalls webcams used in Dyn cyberattack

A number of the company’s US-sold products were used in the attack, which prevented millions of users from accessing dozens of high-profile websites. A Chinese manufacturer of internet-connected surveillance cameras has recalled a number of its products said to have been used in Friday’s cyberattack. The three-wave attack against Dyn, a managed domain name system […]

DDoS attack Friday hits Twitter, Reddit, Spotify and others

The East Coast was under siege on Friday morning from a large-scale distributed denial of service (DDoS) attack that brought down more than a dozen prominent websites, including Twitter, Spotify, Netflix, GitHub, Amazon and Reddit. The initial attack was followed later in the day by at least two more waves of attack. The attack against […]

Chinese hackers targeted US aircraft carrier

Cyber security group says attack launched against visitors to vessel in South China Sea. Chinese hackers targeted foreign government personnel who visited a US aircraft carrier the day before a contentious international court ruling on the South China Sea, according to a US cyber security company. The China-based group created an infected document impersonating an […]

DYN CONFIRMS DDOS ATTACK AFFECTING TWITTER, GITHUB, MANY OTHERS

Update DNS provider Dyn has confirmed two massive distributed denial of service attacks against its servers Friday impacting many of its customers including Twitter, Spotify and GitHub. The attacks came in two waves, one early Friday morning and a second just a few hours later. “This attack is mainly impacting U.S. East and is impacting Managed […]

Feds seized 50TB of data from NSA contractor suspected of theft

It’s still not clear if Harold Martin was connected to the “Shadow Brokers” NSA dump. In a new Thursday court filing, federal prosecutors expanded their accusations against a former National Security Agency contractor. Federal investigators seized at least 50 terabytes of data from Harold Thomas Martin III, at least some of which was “national defense information.” […]

Attackers use Discord VoIP chat servers to host NanoCore, njRAT, SpyRAT

Malicious actors are abusing a free VoIP service for gamers to distribute remote access Trojans, as well as infostealers and downloaders. Discord, a free VoIP service designed for gaming communities, has had its chat servers abused to host malware. Most of the malicious samples found distributed on the app were remote access Trojans (RATs), such […]

Russia-linked phishing campaign behind the DNC breach also hit Podesta, Powell

Bit.ly-based phishing links targeted former Sec. of State, Clinton campaign chair. The breach of personal e-mail accounts for Clinton presidential campaign chairman John Podesta and former Secretary of State Colin Powell have now been tied more closely to other breaches involving e-mail accounts for Democratic party political organizations. Podesta and Powell were both the victims of the […]

Flaw in Intel chips could make malware attacks more potent

“Side channel” in Haswell CPUs lets researchers bypass protection known as ASLR. Researchers have devised a technique that bypasses a key security protection built into just about every operating system. If left unfixed, this could make malware attacks much more potent. ASLR, short for “address space layout randomization,” is a defense against a class of widely […]

Czech Police Arrest Russian Hacker for Cyber-Attacks Against the US

FBI is asking for the suspects extradition. Following a collaboration with the US Federal Bureau of Investigation (FBI), Czech national police announced yesterday the arrested of a man on suspicion of hacking various entities in the US. The suspect, who’s name hasn’t been released yet, was arrested in Prague, the Czech Republic’s capital. The man is […]

Hackers Steal Research and User Data from Japanese Nuclear Research Lab

Spear-phishing and malware at the root of the intrusion.From November 2015 to June 2016, hackers targeted researchers at the University of Toyama’s Hydrogen Isotope Research Center, the University told Japanese media. Officials said the attacker managed to steal files on multiple occasions, taking both research data and the personal details of nuclear scientists. Malware infection […]

Defense contractor “white hat” tells FBI that Judicial Watch paid him to hunt for Clinton hack

Newt Gingrich brokered deal for moonlighting contractor to hunt for potential breach. More records from the Federal Bureau of Investigation’s review of Hillary Clinton’s e-mail practices have been released through the FBI’s Freedom of Information Act site, including interviews with a number of individuals related to the security of the server. One of them was […]

Some Netflix Passwords Have Been Hacked

Logins and passwords that match Netflix accounts have been released by a separate company, Netflix said today in an email to affected customers.  I found out via email, as I am a customer. They sent this warning: As part of our regular security monitoring, we discovered that credentials that match your Netflix email address and password […]

Beware of all-powerful DDoS malware infecting cellular gateways, feds warn

Sierra Wireless confirms that devices it manufactures were infected by Mirai. This week, the US government-backed ICS-CERT warned that the troubling new generation of computer attacks is powered by malware that can infect cellular modems used to connect automotive and industrial equipment to the Internet.  An advisory published Wednesday listed five industrial control devices manufactured by […]

Surge of email attacks using malicious WSF attachments

Ransomware attack groups among the most frequent users of new tactic. Symantec has seen a major increase in the number of email-based attacks using malicious Windows Script File (WSF) attachments over the past three months. Ransomware groups in particular have been employing this new tactic. In the past two weeks, Symantec has blocked a number […]

Clinton campaign chief’s iPhone was hacked and wiped, photos suggest

Podesta’s iPhone reportedly wiped within hours of his Twitter account being hacked. Unconfirmed evidence builds a strong case that an Apple iCloud account belonging to Hillary Clinton’s campaign chief, John Podesta, was accessed and possibly erased by hackers less than 12 hours after his password was published on WikiLeaks. So far, Clinton campaign officials have […]

DISAPPEARING MESSAGES ADDED TO SIGNAL APP

The Signal encrypted messaging application on Tuesday added disappearing messages to its array of privacy features. Disappearing messages gives users the ability to designate how long conversations live on respective devices. And while developer Moxie Marlinspike said the feature won’t necessarily offer additional protection against adversaries conducting surveillance, it is a security enhancement that delivers […]

Microsoft Patches Four Zero-Days Used in Live Attacks

0-days affect IE, Edge, Office, and Windows’ GDI component. aaThese four zero-days affect Microsoft products such as Internet Explorer (CVE-2016-3298), Edge’s scripting engine (CVE-2016-7189), the Windows Graphics Component (CVE-2016-3393), and Office (CVE-2016-7193). Microsoft says that attackers exploited all vulnerabilities in the wild. CVE-2016-3298 CVE-2016-3298 is an information disclosure bug discovered in Internet Explorer by Proofpoint, who […]

A German nuclear plant suffered a disruptive cyber attack, the news was publicly confirmed by the IAEA Director Yukiya Amano.

According to the head of the United Nations nuclear watchdog, the International Atomic Energy Agency (IAEA) Director Yukiya Amano, a nuclear power plant in Germany was hit by a “disruptive” cyber attack two to three years ago. “This issue of cyber attacks on nuclear-related facilities or activities should be taken very seriously. We never know […]