Posts

Showing posts with the label hacking news

Hacking Groups Found Exploiting SMB Flaw Weeks Before WannaCry

Image
Hacking Groups Found Exploiting SMB Flaw Weeks Before WannaCry Since the Shadow Brokers released the zero-day software vulnerabilities and hacking tools – allegedly belonged to the NSA's elite hacking team Equation Group – several hacking groups and individual hackers have started using them in their own way. The April's data dump was believed to be the most damaging release by the Shadow Brokers till the date, as it publicly leaked lots of Windows hacking tools, including dangerous Windows SMB exploit. After the outbreak of WannaCry last week, security researchers have identified multiple different campaigns exploiting Windows SMB vulnerability (CVE-2017-0143), called  Eternalblue , which has already compromised hundreds of thousands of computers worldwide. I have been even confirmed by multiple sources in hacking and intelligence community that there are lots of groups and individuals who are actively exploiting Eternalblue for different motives...

FBI Looks Into Chinese Hack Targeting Federal Insurance

Image
The US’ Federal Deposit Insurance Corporation hasn’t had an easy time of things in recent years: it’s been the subject of numerous hacks in recent years, starting in 2010. And now, the FBI wants answers. Reuters sources understand that the law enforcement agency is investigating how the intruders got in, and that the FDIC believes the Chinese military sponsored the attacks. While the full details of the initial hack aren’t available, it took a while to recover. The FDIC took until “at least” 2012 to make sure that its systems were clean, according to an internal probe. The FBI isn’t commenting, and the Chinese government tells Reuters that it’s “very hard” to determine where an attack came from without evidence. You’re not about to get firm answers about those hacks, we’re afraid. However, there’s no doubt that online security is still an ongoing problem. Official disclosures show that there were 159 instances of unauthorized access in the FDIC’s fiscal 2015, 20 of which were data b...

Wi-Fi can be turned into IMSI Catcher to Track Cell Phone Users Everywhere

Image
Wi-Fi can be turned into IMSI Catcher to Track Cell Phone Users Everywhere Here's a new danger to your sma rtphone security: Your mobile device can be hijacked and tracked without your knowledge. Remember  Stingrays ? The controversial cell phone spying tool, also known as " IMSI catchers ," has long been used by law enforcement to track and monitor mobile users by mimicking a cellphone tower and tricking their devices to connect to them. Sometimes it even intercepts calls and Internet traffic, sends fake texts, and installs spyware on a victim's phone. Setting up such Stingrays-type  surveillance devices , of course, is expensive and needs a lot of efforts, but researchers have now found a new, cheapest way to do the same thing with a simple Wi-Fi hotspot. Yes, Wi-Fi network can capture IMSI numbers from nearby smartphones, allowing almost anyone to track and monitor people wirelessly. IMSI or international mobile subscriber identity is a unique 15-digit number used ...

MBR Filter — Open Source Tool to Protect Against 'Master Boot Record' Malware

Image
MBR Filter — Open Source Tool to Protect Against 'Master Boot Record' Malware    Ransomware threat has risen exponentially so much that ransomware authors have started abusing the MBR in their attacks to lock down your entire computer instead of just encrypting your important files on hard drive. Talos team at Cisco Systems has released a free, open-source tool that protects the master boot record (MBR) sector of computers from modification by bootkits, ransomware, and other malicious attacks. Master Boot Record (MBR)  is the first sector (512 bytes) on your Hard drive that stores the bootloader, a piece of code that is responsible for booting the current Operating System. Technically, Bootloader is first code that gets executed after system BIOS that tells your computer what to do when it start. An advanced malware program, such as rootkit and bootkit, leverages this process to infect computers by modifying the MBR. A boot malware or  bootkits  has the ability ...

Dirty COW — Critical Linux Kernel Flaw Being Exploited in the Wild

Image
Dirty COW — Critical Linux Kernel Flaw Being Exploited in the Wild A nine-year-old critical vulnerability has been discovered in virtually all versions of the Linux operating system and is actively being exploited in the wild. Dubbed " Dirty COW ," the Linux kernel security flaw (CVE-2016-5195) is a mere privilege-escalation vulnerability, but researchers are taking it extremely seriously due to many reasons. First, it's very easy to develop exploits that work reliably. Secondly, the Dirty COW flaw exists in a section of the Linux kernel, which is a part of virtually every distro of the open-source operating system, including RedHat, Debian, and Ubuntu, released for almost a decade. And most importantly, the researchers have discovered attack code that indicates the Dirty COW vulnerability is being actively exploited in the wild. Dirty COW potentially allows any installed malicious app to gain administrative (root-level) access to a device and completely hijack it. Why is...

Massive DDoS Attack Against Dyn DNS Service Knocks Popular Sites Offline paypal twitter

Image
Massive DDoS Attack Against Dyn DNS Service Knocks Popular Sites Offline Cyber attacks are getting evil and worst nightmare for companies day-by-day, and the Distributed Denial of Service (DDoS) attack is one such attacks that cause a massive damage to any service. Recently, the Internet witnessed a record-breaking largest  DDoS attack of over 1 Tbps  against France-based hosting provider OVH, and now the latest victim of the attack is none other than Dyn DNS provider. A sudden outage of popular sites and services, including Twitter, SoundCloud, Spotify, and Shopify, for many users, is causing uproar online. It's because of a DDoS attack against the popular Domain Name System (DNS) service provider Dyn, according to a post on  Ycombinator . DNS act as the authoritative reference for mapping domain names to IP addresses. In other words, DNS is simply an Internet's phone book that resolves human-readable web addresses, like thehackernews.com, against IP addresses. Dyn DNS i...
Image
Opera Browser Sync Service Hacked; Users' Data and Saved Passwords Compromised Opera has reset passwords of all users for one of its services after hackers were able to gain access to one of its Cloud servers this week. Opera Software reported a security breach last night, which affects all users of the sync feature of its web browser. So, if you’ve been using   Opera’s Cloud Sync service , which allows users to synchronize their browser data and settings across multiple platforms, you may have hacked your passwords, login names, and other sensitive data. Opera confirmed its server breach on Friday, saying the "attack was quickly blocked" but that it "believe some data, including some of [their] sync users’ passwords and account information, such as login names, may have been compromised." Opera has around 350 Million users across its range products, but around 1.7 Million users using its Sync service had both their synchronized passwords as well as their authen...