10 February 2012

Changes in IT Act crucial for fighting cyber crime: IT experts

Mobile devices have more computing power than most sophisticated PCs. We have become dependent on them to the extent that once they conk out, we are utterly helpless. These vital devices store a lot of critical information. However, they are not governed by clearly laid out laws. The need of the hour is to enact a new legislation or amend the existing act, say cyber security experts.

“If you list out the top five important laws passed in this country post independence, the IT Act of 2000 would definitely be one of them. Information technology now governs every aspect of our lives,” says Pavan Duggal, advocate of the Supreme Court of India, who was part of the team that drafted the act. “However, what we now have is a grossly lopsided act. The law was amended in 2008 when there was no social media. Mobile usage was also not that prevalent. Today mobile phone plays a part in a large number of common crimes. The need of the hour is to have a law for communication devices and social media.”

Click here to read more .... 

Solutions : www.xcyss.in

'Anonymous' hacker group threatens 'reign of terror' against Israel


The hacker group “Anonymous” released a video Friday threatening to begin a ‘reign of terror’ against Israel, in the latest round of cyber warfare between pro-Palestinian and pro-Israeli hackers.
The video blamed Israel for committing 'crimes against humanity,' and criticizing it for its treatment of Palestinians.
The video also makes reference to the possibility of an Israeli strike on Iran, claiming that Israel has “taken steps to ensure a nuclear holocaust,” and that it will not be allowed “to attack a sovereign country based upon a campaign of lies.”........

Click here to read more .... 

Solutions : www.xcyss.in

09 February 2012

Terrorism acts vs cyber threats, new offense scenarios

By Pierluigi Paganini 9a824a3f55b26adad5431f6715dbec2e


We are at an historical turning point today in U.S., and the situation is similar all over the world, threat of terrorist acts have been surpassed by cyber threats, this is the opinion of FBI Director Robert Mueller. Cyber crime, cyber-espionage, massive attacks, hacktivism, usage of cyber weapons against critical infrastructure are all phenomena that are increasing in frequency and able to induce more terrible damages of a pure act of terrorism. Consider also that cyber crime are difficult to identify and can be perpetrated for a long time with in silent mode with terrifying consequence.
.......
MCAfeeeCyberSituation 258x300 Terrorism acts vs cyber threats, new offense scenarios
...
Russia and China are the nations responsible for the major number of attacks moved to steal foreign intellectual property, trade secrets and national security information, that is the new frontier of espionage. From cyber security perspective we observed  an exponential grow of the threats, consider that every day more than 60,000 new malware are identified and with the same trend of growth we recorded continuous attacks of hacking groups to the main structures of a nation like the U.S.
.....


During the last couple of years we had a long list of cyber attacks really striking like the data breach of RSA and Symantec companies, don’t forget also the operations made by the Anonymous groups like the intrusion and the data breach in the systems of cyber-security firm HB Gary with more af 50,000 emails were exposed.
Regarding the cyber security there is an open debate on global scale, cyber threats have no countries, have no names, are an invisible enemy that could be dammed only with cooperation and awareness of entire populations.

Click here to read more ....
 Solutions : www.xcyss.in

Trojan gang targets BT, Talk Talk and Sky customers

Criminals using a dangerous variant of the Zeus bank Trojan have started hacking BT, Talk Talk and Sky phone accounts as a way of redirecting phone calls from bank fraud services away from victims.


Malware gangs are wary of post-transaction verification and will typically test the system to work out the fraud threshold for different institutions and customers.


...



"Faudsters are increasingly turning to these post-transaction attack methods to hide fraudulent activity from the victim and block email and phone communication from the bank," said Trusteer CTO, Amit Klein.
"This allows attackers to circumvent security mechanisms that look for anomalies once transactions have already been executed by the user."
....


Click here to read more ....

 Solutions : www.xcyss.in

Hacking Ukraine: Govt retreats after massive cyber-siege

Ukrainian government websites have suffered a two-day cyber attack after the authorities closed a popular file-sharing service. The police have withdrawn the blocking order, but their investigation into alleged piracy is very much ongoing.
Users lost access to dozens of official websites in Ukraine after they came under attack on Tuesday. Websites belonging to the president, the government, Ukraine’s security service, the national bank, and the interior ministry were among those affected.
....
Click here to read more ....
 Solutions : www.xcyss.in

UK Government Response to the Intelligence and Security Committee’s Annual Report 2010–2011

.....

d. the Committee is disappointed that government departments and agencies
do not view investment in Information  assurance as important, and that this
has led to GChQ having to subsidise CesG by several million pounds per year.
We are concerned that there appears to have been little progress in achieving a
resolution since last year. the deputy national security adviser must prioritise the
development of an effective funding model, which should be implemented within the
next six months.
The Government welcomes the Committee’s recognition of the importance of Information
Assurance (IA) across government. IA is fully represented in the work of the Cabinet
Office, which co-ordinates work on cyber security. The Government supports fully the
Committee’s recommendation and the Deputy National Security Adviser will continue to
work with the Communications-Electronics Security Group (CESG) to develop a suitable
funding model that will ensure the long-term sustainability of their IA work.
.....

e. We are concerned about GCHQ’s inability to retain a suitable cadre of
internet specialists to respond to the threat. We therefore urge GCHQ to investigate
what might be done within existing pay constraints to improve the situation. We
also recommend that the Cabinet Office – as lead department for cyber security –
considers whether a system of bonuses for specialist skills, such as exists in the
united states, should be introduced.
The Government shares the Committee’s concerns regarding maintaining a highly skilled
cadre of internet security specialists and is taking a number of proactive steps to address
the issue.
Policies for the recruitment and retention of specialist staff are the responsibility of
individual departments; however, under the National Cyber Security Programme the
Government will support individual departments and agencies in developing cyber
security training and skills programmes for their staff.

......


The full report

 Solutions : www.xcyss.in

Defendant Ordered to Decrypt Laptop May Have Forgotten Password

A Colorado woman ordered to decrypt her laptop so prosecutors may use the files against her in a criminal case might have forgotten the password, the defendant’s attorney said Monday.
......

“It’s very possible to forget passwords,” the woman’s attorney, Philip Dubois, said in a telephone interview. “It’s not clear to me she was the one who set up the encryption on this drive. I don’t know if she will be able to decrypt it.”
The decryption case is a complicated one, even if solely analyzed on the underlying Fifth Amendment issue. Such decryption orders are rare, and they have never squarely been addressed by the Supreme Court.
.....
The judge refused Friday to suspend his order to allow time for an appeal to the Denver-based 10th U.S. Circuit Court of Appeals.
Dubois, Fricosu’s attorney, said Monday he would petition the appeals court anyway in hopes that it agrees with his position that Judge Blackburn’s order breaches Fricosu’s Fifth Amendment right against compelled self-incrimination.


Click here to read more ....
 Solutions : www.xcyss.in

How IT is making govt responsive

The government is seen as slow, bureaucratic and corrupt. But in recent times, in several services, it has dramatically transformed itself with the use of technology, sometimes in partnership with the private sector. 

It started with the spectacularly successful railway online reservation system, but has since moved to newer areas, thereby substantially reducing hassles, paper work and corruption, and accelerating the speed of delivery of services. In some cases, the scale of the service is so massive that it is lowering the prices of IT services and products, and generating new lessons for the global IT industry. 
Click here to read more .... 

Solutions : www.xcyss.in

Sexting could become a crime


Sexting may not be too smart but should it be against the law?  Senate Bill 2222 prohibits adults from asking minors for nude pictures and it would also outlaw minors from sending nude pictures of themselves to adults or other kids. 
The idea is to protect the child because once the image is sent out there is little control over it going public.  The photos can be used as blackmail and have led to suicide in other states..........

Click here to read more ....

Solutions : www.xcyss.in

Cyberbullying leaves itsvictims close to suicide


HUNDREDS of thousands of young people are being subjected to cyberbullying with many being victimised for more than a year, new research has shown.
A study by the charity Beatbullying reveals the long-term impact of cyber abuse, with youngsters reluctant to go to school, living in fear of their safety and even resorting to self-harming or attempting suicide.
Cyberbullying is the bullying of another person through technology, such as mobile phones or the internet.

Click here to read more .... 

Solutions : www.xcyss.in

Suspect in Teacher’s Murder was Convicted Stalker

An intense manhunt is underway for a Painesville man accused of shooting to death a teacher, 40-year-old Stacey Sutera in Mahoning County. The gunman is 64-year-old Robert McLaughlin, of Painesville.


Stacey was a science teacher at the Mahoning County Career and Technical Center in Canfield. According to court records, she had known McLaughlin since 2000 and he began stalking her in 2010.


Police say last year, they searched McLaughlin’s Painesville home and found pictures of Stacey as well as pornography and dozens of guns. Stacey filed a lawsuit against him, claiming he was sending her pornographic emails and sending obscene fliers and letters to schools, government offices and other places around Mahoning, Trumbull and Columbiana counties.
Click here to read more .... 

Solutions : www.xcyss.in

08 February 2012

New virus takes over PC without opening infected mails


Now, a new class of cyber attack has emerged that can infect you computer even if you do not open virus-infected email attachments.

In the new form of cyber attack, users will not even be warned this is happening, the only message that appears is ‘loading’. The email then automatically downloads malware into your computer from elsewhere the moment a user clicks to open it.

The emails themselves are not infected, therefore will not ‘set off’ many web-security defence packages.

Previous generations of email-borne viruses and trojans required users to click on an attachment, often an office document such as a PDF but the new generation of e-mail-borne malware consists of HTML e-mails, which automatically downloads malware when the e-mail is opened.


Click here to read more .... 

Solutions : www.xcyss.in

BEWARE! World War III report is a Facebook scam

A new virus scam is circulating on Facebook that tricks people into downloading malware by asking them to open a fake CNN report about World War III. The story, using CNN logos, offer video footage of a breaking news story, but says users need to upgrade their Flash video software to watch.

The fake news page says that US attacks Iran and Saudi Arabia, and begins of World War III. When users ‘upgrade’, their PC gets infected with a trojan. Videos are often used as ‘bait’, because computer users are used to upgrading video software such as Flash, so installing software does not set off alarm bells.


Click here to read more .... 

Solutions : www.xcyss.in

07 February 2012

VeriSign SEC Report Reveals 2010 Data Breaches

VeriSign, the company responsible for the .com, .net and .gov domain spaces, acknowledged in a recent filing with the Securities and Exchange Commission that it was hacked several times in 2010. The company had not disclosed the incidents at the time they occurred.
....


The SEC recommended companies disclose any security issues that pose a risk for operations or incidents that can have material impact on the business.
"In 2010, the Company faced several successful attacks against its corporate network in which access was gained to information on a small portion of our computers and servers," VeriSign reported in the quarterly filing.
The attackers successfully stole data during the breaches, and the company was "unable to assure" that the information was not or could not be used by the attackers. VeriSign claimed it has implemented new defensive measures to prevent similar incidents.
.......
It also appears the security team hid the breaches from VeriSign senior management when they occurred in 2010, and were not reported up the chain of command until September 2011, according to the SEC filing. "The occurrences of the attacks were not sufficiently reported to the Company's management at the time they occurred for the purpose of assessing any disclosure requirements," VeriSign claimed.


Click here to read more ....

 Solutions : www.xcyss.in

Your deleted facebook pics remain accessible

It may come as a rude shock, butFacebook users should not feel surprised if tomorrow they come across their photos existing in the webworld despite having deleted them personally long ago. 

The photos do not disappear even after they are deleted but can still be accessed by anyone with a link to the images themselves. The company admits that its systems "do not always delete images in a reasonable period of time".

Deleted images vanish from 'normal' views of the site, meaning if you log in to Facebook and look on somebody's photo page, they won't be visible. But they would still remain visible to anyone with a direct URL link to the picture. 
That means that if, for instance, a picture has been circulated by email, the image will still be there for anyone who clicks the link.
Click here to read more .... 

Solutions : www.xcyss.in

NBN website hacked by anti-Assad activist

The NBN television station's website was hacked Monday by one "DarkCoder," who claims to represent the "free people of Hama."
The main webpage of the National Broadcasting Network, which is affiliated with Parliament Speaker Nabih Berri, now features a picture of a poster commemmorating the Hama Massacre of 1982, as well as a condemnation of NBN.

The hacking attack by "DarkCoder" is the first of its kind against a Lebanon-based TV station following former Libyan leader Moammar Gadhafi's blocking the broadcast of a number of Lebanese stations, including NBN, for their coverage of the Libyan uprising against his rule.

Click here to read more .... 

Solutions : www.xcyss.in

06 February 2012

Hackers seize NSW Government-run website

A mysterious band of cyber pirates has hijacked a NSW Government sailing website, re-directing users to a page of threatening messages written in Turkish.


The group took control of the government-run Sydney International Regatta Centre website, redirecting customers away from the homepage to a site filled with cryptic messages in Turkish.A message on the homepage translated into English says that "each of you will feel fear", followed by what appears to be gloating by the hackers about their conquest..
Click here to read more .... 

Solutions : www.xcyss.in

Scamsters using I-T Dept website to dupe people: experts


Cyber experts have warned Internet users of phishing scamsters who are luring people with government domain names and sending unscrupulous e-mails to collect financial and personal information.
Mail boxes of people are being hit by an e-mail sent from "ref.init@incometaxindia.gov.in", informing them of a tax refund pending with the department which can be collected by entering their financial and bank-related information by clicking on a given hyperlink in the mail. The Income Tax Department's web link also has the address "www.incometaxindia.gov.in." which gives the scamsters' email a genuine image and even prompts people to share the information.

According to private cyber security firm XCySS, such e-mails show that the department had not properly secured its server.

Mukesh Saini, chairman of the firm, said, "It seems that the website has an open proxy domain which allows anyone to assume the name of the Income Tax Department domain and send mails from it and it can be changed if the mandarins of the department instruct their service providers". If someone received an e-mail or found a website to be pretending of the I-T Dept, the e-mail or website URL could be forwarded to phishing@incometaxindia.gov.in with a copy to incident@cert-in.org.in.

"This is a very serious mistake on part of the I-T Dept and service providers which are maintaining their servers. There are some settings which need to be done in the the server on which the web site of the department of hosted," Saini said.

According to Saini, a former Naval commander, open proxy can be misused for sending notices, if not phishing messages, and extortions can be made by unscrupulous elements.

Click here to read more .... 

Solutions : www.xcyss.in

03 February 2012

Hackers publish names, addresses of hundreds of Texas police officers

The hacking group known as 'Anonymous' has published the names, addresses and police departments of more than 700 officers across the state, including dozens in North Texas, after stealing the data from the Texas Police Association's web site.

The hacking is apparently in response to a story News 8 broke last week about a Wylie policeman put on administrative leave while he's investigated for child pornography.
'Anonymous' has become notorious for cyber crime after hacking and attacking high-profile websites.


Click here to read more .... 

Solutions : www.xcyss.in

Beware of phishing scams during tax season


As tax season approaches, everyone is preparing and gathering information. With all of the important personal documents circulating, be careful not to allow others access to that information.
When tax time comes around, crooks follow. A big problem this time of year is phishing e-mails. Scammers use the phony messages in attempts to obtain personal information.....

Click here to read more .... 

Solutions : www.xcyss.in