Click here to read more ....
Cyberspace has become all pervasive. Every facet of a modern life has elements of cyberspace embedded in it. Therefore securing the cyberspace has become a necessity, which can no more be wished away. This space collate the news and views affecting the security of our cyberspace.
07 June 2013
Chinese hacked Obama, McCain campaigns, took internal documents, officials say
Click here to read more ....
Microsoft and FBI strike blow against $500m cyber crime ring
The Citiadel botnet ring was made up of 1,400 individual botnets - networks of malware-infected PCs
....The ring had amassed some 5 million infected machines in over 90 countries. Organisations affected include American Express, Bank of America, Citigroup, Credit Suisse, PayPal and HSBC......
.....Citadel was developed using augmented source code from the Zeus toolkit. .....
....“Creating successful public-private partnerships –in which tools, knowledge and intelligence are shared– is the ultimate key to success in addressing cyber threats and is among the highest priorities of the FBI," McFeeley said......
Click here to read more ....
06 June 2013
Hackers to be denied US entry under House cyber security Bill
....This is putting a face to the criminals, Knight said in an interview. If you’re a foreign agent working on behest of a nation and participating in cybercrime, you will not be allowed a visa into the country, nor will your family.....
Click here to read more..
05 June 2013
Researchers prove that light, sound can activate mobile malware
....Researchers have discovered a way to trigger and control malware on smartphones using sensory channels, like light, vibrations, music or other sounds...
.....The paper, titled “Sensing-Enable Channels for Hard-to-Detect Command and Control of Mobile Devices,” described one example in which music that blares from a speaker could cause compromised smartphones to carry out malicious activities at a sports event.
Drupal breach compromises nearly one million accounts
......In a Wednesday blog post, Ross said usernames, email addresses, country information, and hashed passwords were exposed in the incident. All passwords were hashed, while only some were salted, an additional security layer where a sequence of symbols is added to passwords before they're hashed......
04 June 2013
Cyber War: U.S. Electric Grid is Riddled With Cyber Security Holes
......A computer worm has the ability to replicate itself, allowing the worm to create hundreds or even thousands of copies of itself. However, consuming too much system memory could lead to network servers, Web servers, and the like to becoming unresponsive....
.....To control this issue, he says to "install firewalls, apply patches and to always perform upgrades." If something isn't done soon, the nation could be at risk for a massive power outage, resulting in millions going without the basic needs that electricity satisfies.....
Click here to read more ....
McAfee: Cyber criminals using Android malware and ransomware the most
.....the company witnessed a 40 increase in Android malware, a near-300-percent jump in instances of Facebook-threat Koobface, and a steady rise in ransomware and reported infections. Add to that an increase in AutoRun malware, malware that attacks MBRs (master boot records), and a doubling of spam worldwide, and the state of security looks bleak.....
....Among the key findings in report, McAfee revealed that it now has a total of 50,926 mobile malware samples in its database, 28 percent of which arrived this year.....
.....McAfee has witnessed more instances of malicious spyware being combined with botnets. Among them is Android/Ssucl.A, a Trojan that poses as a system cleanup utility but is really a botnet client. It not only steals user and SMS data, it also launches phishing attacks for Dropbox and Google log-ins. It tries to infect PCs using an autorun.inf attack too.....
....... "Within the enterprise, we see password-stealing Trojans evolving to become information-gathering tools for cyber espionage attacks. Whether they target login credentials or intellectual property and trade secrets, highly targeted attacks are achieving new levels of sophistication.".....
Click here to read more ....
Now LinkedIn rolls out two-factor authentication
LinkedIn is the latest website to add two-factor authentication as a measure to prevent account takeovers....
.....The feature works similarly to the two-step verification recently pushed out by Twitter, which had been experiencing high-profile account compromises......
.......The site's more than 200 million members can enable the capability by visiting "Settings," then selecting the "Account" tab and clicking "Manage Security Settings.".......
Click here to read more.
28 May 2013
Google cyber-knight lances Microsoft for bug-hunter 'hostilities'
......After documenting the bug, he posted his initial findings to the Full Disclosure mailing list, and published a complete dossier last week.
24 May 2013
CNN International Breached, Accounts Leaked, Fake Articles Claim to be Posted By @Reckz0r
.....In the post comes a short statement which states that CNN has been hacked for false news reports and also makes further claims that they have published 4 fake articles, which i could not locate or distinguish on the site and the leak also comes with small amount of data leaked from the websites database with claims that anyone who can figure out the 4 fake articles is able to obtain the complete database from them (the hacker)....
.....The site breached as you can see is the International Edition site for CNN and the leaked data that has been published to paste bin is 9 administrator accounts with usernames, user IDs and encrypted passwords along with a list of database tables......
Click here to read more ...
DHS employees' info possibly compromised due to system flaw
The flaw was apparently found in the software used by a DHS vendor to process personnel security investigations and has been immediately addressed. "
There is no evidence that the information contained in the system - names, social security numbers, date of birth - were actually stolen or accesses at all, but potentially affected employees, contractors, inactive applicants, and former employees. ...
Click here to read more ....
A spotlight on grid insecurity
Drawing from responses from more than 100 utilities across America, a new report shows that the nation’s electric grid remains highly vulnerable to attacks from Iran and North Korea, or other threats like geomagnetic storms from solar activity.
The electric grid is the target of numerous and daily cyber attacks. One utility said that there were 10,000 attempted attacks each month, and others describe the level of potential incursions as “daily”, “constant”, “malicious” and “seeking to gain access to internal systems.”
...Most utilities comply with mandatory standards only, not additional voluntary ones, and do so unevenly. For example, while almost all utilities said they complied with mandatory Stuxnet standards, only 21 percent of industry-owned utilities, 44 percent of municipally- or cooperatively-owned utilities and 62.5 percent of federal entities reported compliance with voluntary Stuxnet recommendations that industry did not agree to mandate.
Most utilities have not taken concrete steps to reduce the vulnerability of the grid to geomagnetic storms and it is unclear whether the number of available spare transformers is adequate...
Click here to read more ....
Microsoft decrypts Skype comms to detect malicious links
..encrypted communication must be decrypted in order for the links to be scanned, and according to its Privacy Policy, Skype can record and retain links and other content sent over Skype.
"There's a widely held belief—even among security professionals, journalists, and human rights activists—that Skype somehow offers end-to-end encryption, meaning communications are encrypted by one user, transmitted over the wire, and then decrypted only when they reach the other party and are fully under that party's control. This is clearly not the case if Microsoft has the ability to read URLs transmitted back and forth," points out Ars Technica's Dan Goodin.
17 May 2013
LulzSec cyber hackers jailed in Britain
The group hacked into Pentagon computers, crashed the website of the US Central Intelligence Agency (CIA), as well as targeting British institutions - including websites belonging to the National Health Service and the Serious Organized Crime Agency.
In one attack, the group targeted the website of Rupert Murdoch's The Sun newspaper, redirecting visitors to a spoof story that Murdoch had committed suicide. The group also carried out distributed denial of service (DDoS) attacks, using linked networks of up to one million computers to crash websites.
Click here to read more ....
Is Microsoft reading your Skype communications?
That conclusion has been reached after The H's German associates at heise Security have been notified, and then independently confirmed, that every HTTPS URL sent over Skype gets checked from an IP address registered to Microsoft headquarters in the U.S...
When asked why that is, the company has replied that they are indeed accessing all sent URLs so that they could spot and remove spam and phishing links.
But the researchers remain unconvinced...
Click here to read more ....
Private messages of Bloomberg clients end up online
Financial Times reports that the messages in question were found by a unnamed financial markets professional via a simple Google search, and that they were online for a number of years, accessible to anyone who knew what to look for. After the FT inquired about them, they were taken down.
“This work was done with client consent, where emails were explicitly forwarded to us to a dedicated email account and released by the person responsible for the email so that we could conduct internal testing to improve our technology for the client,” a Bloomberg spokesman stated.
Click here to read more ....
Info-stealing Dorkbot worm spreading on Facebook
The worm is delivered to potential victims via a chat message that appear to be coming from a friend and, at first glance, the link looks like it should take users to a regular JPG image file hosted on MediaFire...
According to Bitdefender, over 9,000 malicious links pointing to the malware have been detected in 24 hours, but Facebook is reacting quickly and blocking them.
Click here to read more
16 May 2013
IT security jobs: What's in demand and how to meet it
The information security job market continues to expand. In fact, according to a report by Burning Glass Technologies, over the past five years demand for cybersecurity professionals grew 3.5 times faster than that for other IT jobs..
Employment in the occupational group that includes information security analysts is projected to grow 22 percent from 2010 to 2020, faster than the average for all occupations, according to Eric Presley, CTO at CareerBuilder
Read more: IT security jobs: What's in demand and how to meet it
22 March 2013
TeamSpy snooped on governments, big biz undetected for 10 years
......
....
Click here to read more ....
SOUTH KOREA UNDER CYBER ATTACK
Click here to read more ....
Other Links of same story :
http://english.yonhapnews.co.kr/
http://www.northkoreatech.org/
http://www.scmagazine.com
http://www.symantec.com