Sunday, July 14, 2013

Defcon to feds: 'We need some time apart' | cnet.com

In the wake of revelations about the NSA's PRISM program, Defcon's founder asks federal government employees to skip this year's hacker convention.


(Credit: Screenshot by Lance Whitney/CNET)

The federal government is persona non grata at this year's Defcon.
For the first time in the 21-year history of the famed hacker's convention, government employees are being asked to stay away, albeit in a polite fashion.
Defcon founder Jeff Moss, aka The Dark Tangent, posted the following request late Wednesday on the event's site:

Malware In Your Car - How Hackers Kill You | eHacking.net

While we may not be headed for a dystopian era where our automobiles are our overlords, forcing us to do their bidding or they'll crush us to death with their mega-ton bodies. It sort of sounds like a transformers meets Armageddon situation. While this scenario is very far-fetched and improbable, there are some equally terrifying things that people have and can do remotely to your car.
  
Researchers at the University of California recently exposed flaws in a car's braking system. They were able to hack in and manipulate the car while it was in motion. They were able to selectively brake the wheels, which allowed them to steer the car. Just to add even more fear and nail-biting suspense to the car hacks, it was noted that none of the driver's manual commands had any impact on the vehicle. This means that no matter how hard they slammed on the brakes, steered the wheel, or even tried to unlock the door, the car was an uncontrollable death trap.

Tuesday, June 25, 2013

Facebook Data-Leaking Bug Exposes 6 Million Users' Data | infosecurity-magazine.com

Facebook has admitted to a bug in its system that has given users of the Download Your Information (DYI) tool "additional email addresses or telephone numbers for their contacts or people with whom they have some connection."

Facebook apologized, stating that it has notified regulators in the US, Canada and Europe, and that it is contacting affected users by email. Security commentators, meanwhile, are trying to work out exactly what happened, and how.

Facebook has admitted that the bug caused the phone numbers and email addresses of six million users to be shared unintentionally. The number of UK users affected by the bug is believed to be around 200,000 according to the Telegraph.

Saturday, June 8, 2013

White-hat hacker fights cyber intrusions on NATO systems | NATO News


Cyber attacks around the world are becoming more frequent, alarming and complex. Our interconnected societies depend on new technologies, which are constantly being probed for vulnerabilities to exploit. NATO calls on the skills of cyber-security experts to assess its computer networks and takes measures to avert and defend against cyber attacks.


"I put myself in the mindset of a hacker and simulate cyber attacks so that I can identify potential weak points in our systems and then set up appropriate defences," explains Nuri Fattah, Senior Security Consultant, at the NATO Communications and Information Agency.

NSA has direct access to Google, Facebook, Apple servers | Help Net Security

After yesterday's news that Verizon is compelled to share all phone call metadata with the NSA on a daily basis comes the incendiary revelation that the spy agency has direct access to the servers - and the data contained on them - of a host of big U.S. Internet companies, including Microsoft, Facebook, Google, Yahoo, Apple, AOL, YouTube, Skype and PalTalk.

The Guardian and The Washington Post have both managed to get their hands on a top secret PowerPoint presentation that is used to inform intelligence operatives about the capabilities of the so-called PRISM program. It apparently allows access to email and chat content, videos, photos, stored data, transferred files, notifications, online social networking details, and more.

According to the presentation, the companies in question are knowingly participating in the program, but several of them (Google, Apple, Microsoft) have already denied it and knowing anything about it.

Microsoft, Feds Take Down Citadel Botnets | eSecurity

How did Microsoft shut down the notorious Citadel botnet ring, which stole more than $500 million from victims?
By Sean Michael Kerner

For over a year, Microsoft and its partners in the financial services community watched a big botnet operation siphon millions of dollars from victims. On Wednesday night, Microsoft announced that in coordination with the FBI, it had moved in to disrupt the massive botnet-based crime ring known as Citadel.

Richard Boscovich, assistant general counsel in the Microsoft Digital Crimes Unit, told eSecurity Planet that there were more than 1,400 botnets associated with this malware. As such, it took Microsoft and its partners a significant amount of time to locate all of the Citadel botnets operating around the world.

"This was a lengthy process and we relied heavily on our financial services and technology industry partners to ensure that we would be able to take aggressive action against this threat," Boscovich said.

The Citadel malware infected PCs with a keylogger that monitored user activity on financial websites. The malware infected more than five million people across 90 countries and stole more than $500 million in assets.