Posts

To Protect Your Devices, A Hacker Wants to Hack You Before Someone Else Does

Image
It should be noted that hacking a system for unauthorised access that does not belong to you is an illegal practice, no matter what's the actual intention behind it. Now I am pointing out this because reportedly someone, who has been labeled as a 'vigilante hacker' by media, is hacking into vulnerable 'Internet of Things' devices in order to supposedly secure them. This is not the first time when any hacker has shown vigilance, as we have seen lots of  previous incidents  in which hackers have used malware to compromise thousands of devices, but instead of hacking them, they forced owners to make them secure. Dubbed  Hajime , the latest IoT botnet malware, used by the hacker, has already infected at least 10,000 home routers, Internet-connected cameras, and other smart devices. But reportedly, it's an attempt to wrestle their control from Mirai and other malicious threats. Mirai  is an IoT botnet that threatened the Internet last year with recor...

Report: Commercial Software Riddled With Open Source Code Flaws

Image
Black Duck Software  on Wednesday released its 2017 Open Source Security and Risk Analysis, detailing significant cross-industry risks related to open source vulnerabilities and license compliance challenges. Black Duck conducted audits of more than 1,071 open source applications for the study last year. There are widespread weaknesses in addressing open source security vulnerability risks across key industries, the audits show. Open source security vulnerabilities pose the highest risk to e-commerce and financial technologies, according to Black Duck's report. Open source use is ubiquitous worldwide. An estimated 80 percent to 90 percent of the code in today's software applications is open source, noted Black Duck CEO Lou Shipley. Open source lowers dev costs, accelerates innovation, and speeds time to market. However, there is a troubling level of ineffectiveness in addressing risks related to open source security vulnerabilities, he said. "From the security...

Facebook Builds a VR Space, but Will Anyone Come?

Image
Facebook on Tuesday announced the beta launch of Facebook Spaces, a new app that allows users to connect with friends and colleagues in an interactive virtual reality environment. Facebook Spaces is available for  Oculus  Rift and Touch at the Oculus Store. The app provides a way for social media users to hang out as they might otherwise in person -- even bridging great distances -- noted Rachel Franklin, head of social VR at Facebook. An avatar represents each user in Facebook Spaces. Its appearance is based on the user's photo, but can be further modified with choices of eye color, hairstyle and facial features that best fit the person's identity. After creating a virtual persona, users can use Messenger to connect with friends, interact in 360-degree spaces, and utilize the app's selfie stick to further manipulate photos in the VR environment. Social VR Becomes a Reality Facebook acquired Oculus VR just over three years ago for a reported US$2 billion. The d...

The Cyber Attack Kill Chain: Where Threat Intelligence Can Help

Image
Key Takeaways Many people believe threat intelligence is primarily about identifying attacks before they happen. In reality, it’s much more about raising your organization’s security profile against all incoming attacks. Different types of threat actors select targets in very different ways. As a rule, the more specific their targeting process, the harder it will be to collect threat intelligence at the pre-planning stage. While threat intelligence can add value at every stage of the kill chain, it’s typically in the form of malicious IP/domain/hash lists and post mortem attack analyses. It’s not just about incident response. In order to add maximum value, threat intelligence should be made available across your security function. Without context, threat intelligence quickly becomes unmanageable. Ensure you’re providing your threat analysts with the tools they need to operate effectively. Before you start gathering threat intelligence, you must answer a simple question:...

Karmen Ransomware Variant Introduced by Russian Hacker

Image
On March 4, 2017, a member of a top-tier cyber criminal community with the username “Dereck1” mentioned a new ransomware variant called “Karmen.” Further investigation revealed that “DevBitox,” a Russian-speaking cyber criminal, was the seller behind the Karmen malware on underground forums in March 2017. However, the first cases of infections with Karmen were reported as early as December 2016 by victims in Germany and the United States. Background The Karmen malware derived from “ Hidden Tear ,” an open source ransomware project, available for purchase by anyone. As is typical for ransomware infections, Karmen encrypts files on the infected machine using the strong AES-256 encryption protocol, making them inaccessible to the user and may trigger a ransom note or instructions demanding that the user pay a large sum of money to obtain the decryption key from the attacker. A notable feature of Karmen is that it automatically deletes its own decryptor if a sandbox environ...

Russian Hacker Selling Cheap Ransomware-as-a-Service On Dark Web

Image
http://thehackernews.com/2017/04/ransomware-as-a-service.html Ransomware has been around for a few years, but it has become an albatross around everyone's neck, targeting businesses, hospitals, financial institutions and individuals worldwide and extorting millions of dollars. Forget about developing sophisticated banking trojans and malware to steal money out of people and organizations. Today, one of the easiest ways that can help cyber criminals get paid effortlessly is Ransomware. This threat became even worse after the arrival of ransomware as a service (RaaS) – a variant of ransomware designed to be so user-friendly that anyone with little or no technical knowledge can also easily deploy them to make money. Now, security researchers have uncovered an easy-to-use ransomware service that promises profit with just one successful infection. Dubbed  Karmen , the RaaS variant is based on the abandoned open-source ransomware building toolkit dubbed  Hidden Tear  ...

Phishing-attack

Image
A Chinese infosec researcher has reported about an "almost impossible to detect" phishing attack that can be used to trick even the most careful users on the Internet. He warned, hackers can use a known vulnerability in the Chrome, Firefox and Opera web browsers to display their fake domain names as the websites of legitimate services, like Apple, Google, or Amazon to steal login or financial credentials and other sensitive information from users. What is the best defence against phishing attack? Generally, checking the address bar after the page has loaded and if it is being served over a valid HTTPS connection. Right? Okay, then before going to the in-depth details, first have a look at this  demo web page  ( note: you may experience downtime due to high traffic on demo server ), set up by Chinese security researcher Xudong Zheng, who discovered the attack. If your web browser is displaying " apple.com " in the address bar secured with SSL, but the cont...