Friday, 21 June 2019

Hit by Ransomware Attack, Florida City Agrees to Pay Hackers $600,000

MIAMI — The leaders of Riviera Beach, Fla., looking weary, met quietly this week for an extraordinary vote to pay nearly $600,000 in ransom to hackers who paralyzed the city’s computer systems.

Riviera Beach, a small city of about 35,000 people just north of West Palm Beach, became the latest government to be crippled by ransomware attacks that have successfully extorted municipalities and forced them to dig into public coffers to restore their networks. A similar breach recently cost Baltimore $18 million to repair damages.

The city council in Riviera Beach, Fla., voted quietly to authorize a nearly $600,000 ransom payment after hackers paralyzed the city’s computer systems.

Friday, 14 June 2019

Cybersecurity giant Symantec plays down unreported breach of test data

The American cybersecurity giant Symantec has downplayed a data breach that allowed a hacker to access passwords and a purported list of its clients, including large Australian companies and government agencies.

The list extracted in the February incident, seen by Guardian Australia, suggests that all major federal government departments were among the targets of a hacker who also claimed to be responsible for Medicare data being available for sale on the dark web.

Cybersecurity and anti-virus malware software developed by Symantec Corporation, with a hacker in the background

Tuesday, 11 June 2019

Traveler, License Plate Images Breached in Cyber Attack: CBP

U.S. Customs and Border Protection said that as of Monday no traveler or license plate image data accessed during a May 31 cyber attack has appeared on the dark web or internet.

According to CBP, a subcontractor transferred copies of traveler and license plate images to their company network which was subsequently breached.

Traveler, License Plate Images Breached in Cyber Attack: CBP

Sunday, 2 June 2019

We asked a cyber security expert to rate hacking gameplay

The concept of hacking gets bandied about a lot in games, even if it’s as simple as “press X to hack.” The pipe-swapping challenge in Bioshock and controller-vibrating word-scrambles in Batman: Arkham Knight provide a nice break in otherwise combat-heavy gameplay. Even a simple matching game can provide a nice change of pace.

While the hacking mechanics aren’t really meant to replicate the experience of actually hacking, we couldn’t help but wonder — do any of them get it right anyway?

We talked to Russell Brandom, cyber security expert and policy editor at The Verge, to learn the real-deal on hacking gameplay. From the circuit-board meddling in Mass Effect 2 to the automatic hacking app used by Miles Morales in Spider-man on PS4, we’ve got the details on which games manage to capture some of the hacking experience.

We asked a cyber security expert to rate hacking gameplay

Monday, 27 May 2019

Hackers reportedly used a tool developed by the NSA to attack Baltimore’s computer systems

Since May 7th, the Baltimore’s city government has been dealing with a ransomware attack that has shut down everything from its email to the systems that allow residents to pay water bills, purchase homes, and other services. According to a report in The New York Times, the tool that has crippled the city is a National Security Agency creation called EternalBlue, which has been used in other high-profile cyberattacks.

According to security experts, hackers used EternalBlue, which exploits a vulnerability in certain versions of Microsoft’s Windows XP and Vista systems, allowing an external party to execute remote commands on their target. The tool was leaked by hacking group The ShadowBrokers in April 2017, and within a day, Microsoft had released a patch to fix the exploit. But patching a system doesn’t mean that those vulnerabilities are entirely closed: users must first apply the patch. Hackers using EternalBlue have since been responsible for several major cyberattacks, including Wannacry in May 2017, and the NotPetya attacks against Ukranian banks and infrastructure in June 2017.

Sunday, 19 May 2019

Global co-operation on cyber security is long overdue

Security researchers recently revealed that a previously unknown hacker group carried out a series of attacks on government agencies in 13 countries by redirecting agency computers to hacker-controlled servers. This happened through the manipulation of domain name system (DNS) infrastructure. And it followed a US Department of Homeland Security alert disclosing a global campaign, subsequently linked to Iran, to redirect internet traffic and steal sensitive information also by compromising DNS infrastructure.

The DNS is an attractive target because it serves as a global address book, translating internet names we know into IP addresses that computers can recognise. The infrastructure supporting DNS is maintained by a number of core companies that administer internet domains, register new domain names, and host DNS “lookup” services which convert those domain names into IP addresses.

Sunday, 12 May 2019

‘Unhackable’ Biometric USB Offers Up Passwords in Plain Text

A simple Wireshark analysis was enough to subvert the gadget, which uses iris identification to protect the drive.

A USB stick dubbed eyeDisk that uses iris recognition to unlock the drive claims to be “unhackable” – only, it isn’t. In fact, a simple Wireshark analysis revealed the device’s password – in plain text.

Cyber Security in the Context of International Security

 Cyber security is everyone’s responsibility. What are the current trends in threats, risks, and vulnerabilities? How do threat actors explo...