вторник, 12 июля 2016 г.

NATO sites downed as measures approved opposing Russian aggression

Three days after the North Atlantic Treaty Organization's Allied Transformation Command websites were knocked offline, the alliance has yet to release official comments over the cause of the outage that felled two military command websites.


The outages occurred during a NATO summit held in Warsaw last week, raising suspicions that Russian hackers could have attacked the websites in response to the summit's initiatives opposing Russian military aggression. “This is a suspicious timing for a technical failure,” a senior NATO official said, according to a Wall Street Journal report. “If this is a cyberattack, it would be no surprise.”
On Friday, NATO approved measures to place US, UK, Germany and Canada-led battalions along member nations' borders with Russia. The battalions are expected to be placed in Estonia, Latvia, Lithuania and Poland by early next year. The intergovernmental alliance also on Friday approved language that defines cyberspace as a domain of war.
Over the weekend, NATO approved an aid package to support the defense, security, and cybersecurity of Ukraine, a non-NATO-member that has been engaged in a prolonged cyber-conflict with Russia.
Earlier this month, a researcher discovered a campaign targeting Ukrainian officials. Login credentials of employees at the National Bank of Ukraine and the South Ukranian Nuclear Energy Complex, and other Ukrainian officials were dumped on Pastebin.

понедельник, 11 июля 2016 г.

Twitter CEO' twitter hacked!

Twitter CEO Jack Dorsey's accounts aren't protected from security hacks.


Earlier today, two tweets were sent from Jack Dorsey's Twitter account claiming to be from a group called OurMine. The tweets linked to a video on Dorsey's Vine account, which were cross posted to his Twitter account. Vine is also owned by Twitter.


The tweets has since been deleted and the videos has been deleted from Dorsey's Vine account. However, his Vine account bio still references OurMine team.


OurMine is the same group that had previously hacked into Google CEO Sundar Pichai's Quora acccount and Facebook CEO Mark Zuckerberg's Pinterest & Twitter accounts as well as Twitter accounts of Amazon CTO Werner Vogels, venture Capitalist Mark Suster and Spotify founder Daniel Ek to post similar messages.

Anonymous Hackers Threaten the U.S. with a 'Day of Solidarity' with Black Lives Matter

The activist computer hacker group Anonymous is calling for protests and cyber attacks during a "day of solidarity" with the Black Lives Matter movement around the country this week.




"Anonymous has declared a day of action in solidarity with the Black Lives Matter movement and the victims of Police Brutality as well as alongside the families of Alton Sterling and Philando Castile," the statement says, which appears under a video on YouTube. 

"We are calling on a collective day of rage," the statement reads. "A day of action centered around civil disobedience and the right to protest."

The statement links to a list of protests allegedly planned at 37 cities around the country on Friday.

Ukrainian hacker attacked a polish meiaa company "Netia"

A Ukrainian hacker going by the handle of Pravy Sektor has breached the servers of Poland’s telecom company Netia SA and stole a massive trove of data a couple of days ago and posted it for public access on an underground forum.


Netia SA has acknowledged that netia.pl faced a cyber attack from the hackers but claimed that only specific amount of data has been stolen. A press release from the company explains that passwords and logins of self-service portal NetiaOnline are safe while data of customers and cooperating companies are secured by the experts.
The attack was launched at 11:03 a.m. (0903 GMT) on Thursday and impeded access to Netia’s main web page netia.pl until late in the evening the same day, said spokeswoman Lidia Marcinkowska. She said hackers may have gained access to some data of its clients as they had accessed two types of forms sent via Netia’s website by people wanting to contact the company or sign a contract with it.

netia-hacked-6

Analysis:
The data was first discovered by Yogev Mizrahi, Head of cybersecurity team at Hacked-DB and analyzed by Oren Yaakobi who found the stolen data is far greater than what the company claims in their press releases. Here is a full and exclusive data analysis conducted by Hacked-DB:
Ukrainian hacker posted multiple SQL files that are compromised and extracted from investor.netia.pl domain. There are several database files including sales DB that contains records such as Blue Media transactions, device and product offers, IP Block Lead and IP TradeDoubler. There’s also an SQL file containing 342,000 lines and contains data such as first and last name, home address and IP address. The data was last updated in 2014.
netia-hacked-2
The leaked records also include data about clients and publication information such as email addresses, phone numbers, home address, IP details and full names. Another file in the database contains street address, city, area codes and IP addresses.
netia-hacked-3
Researchers have also found a 9GB file size Log file containing, session ID, IP address, agent type, browser and the operating system details of users.
netia-hacked-4
In total, the dumped data is about 14GB in size and last but not least, the hacker has also dumped 615,525 unique email addresses including 150,440 emails from Poland’s sixth-largest web portal Wirtualna, 118,989 Gmail emails addresses, 64,000 email address of O2 users. Here is a list of top 10 email domains compromised:
netia-hacked-5
Though the researchers did not obtain passwords from the data but they were able to detect logger database holding session IDs of users which basically means that a malicious user having access to the data can authenticate as another user based on this sensitive data. 
An important point to notice is that session ID is a very critical finding, this data allows direct connection to the website without authentication process with username and password, explains one of the researchers from Hacked-DB.
Recently, we have seen an increase in such offers where hackers have been offering highly confidential data from top social media giants including MySpace, LinkedIn, Twitter, Beautiful People and VK.com but when it comes to telecom giants, one of UK’s largest telecom companies TalkTalk faced a massive data breach when hackers stole personal data of 4 Million users.
At the moment it is unclear what flaw allowed hackers to bypass Netia’s server but based on previous data breaches a simple SQL flaw lets hackers make their way to protected data. However, Netia’s website which was down after the attack has been restored. Here is a screenshot showing the site was down for maintenance: 
netia-5

Patchwork" hackers attack South-Asian states

An advanced persistent threat tied to Southeast Asia and the South China Sea is targeting governments and entities around the world including the U.S. The attacks are unique, according to security experts, because the perpetrators are relying nearly 100 percent on computer code copied-and-pasted from sources on the web.
Cymmetria Research, which discovered the APT and today released a report on the attacks, calls those responsible for the attacks Patchwork because the group has piece-mealed computer code from sources such as open-source repository GitHub, the dark web and hidden criminal forums. “Those behind these attacks have copied, pasted and pieced together everything from penetration tools, malware and post-intrusion attack tools,” said Gadi Evron, founder and CEO of Cymmetria Research.


“This group shows how low the bar has been moved for a successful APT attack to take flight,” Evron said. “We are impressed that these attacks were able to infiltrate high-end organizations given the apparent low technical aptitude of the attackers,” he said.
Patchwork attackers are believed to be of Indian origin and gathering intelligence from influential parties tied to Southeast Asia and the South China Sea. Threat actors, Cymmetria said, were active during the Indian time zone. However, the report’s authors point out, it’s not possible to say conclusively that the attacks were originating in India. The report added, while it also can’t be said definitively, the attacks may be related to similar APT Hangover/Appin.
“Patchwork is a highly successful APT operation, infecting approximately 2,500 high-value targets worldwide,” the report states. Attacks began in the December timeframe. It’s unclear as to why the attackers relied on second-hand computer code. However, what might appear amateurish has been highly effective when it came to the attacker’s second stage toolsets – meant for persistence and to avoid detection.
According to Cymmetria the attacks target entities in the United States as well as Europe, the Middle East, South Asia and the Asia and Pacific regions. “It would be more accurate to say that targets were chosen worldwide with a focus on personnel working on military and political assignments – specifically, but not limited to, intelligence requirements concentrating on Southeast Asia and the South China Sea. Many of the targets were governments and government related organizations,” according to the report.
Evron said most infections on targeted systems were initiated via spear phishing campaigns that included emails that contained content related to Southeast Asia and the South China Sea. In one incident, Patchwork attackers enticed email recipients to download a presentation titled “Is China’s assertiveness in the South China Sea likely to affect Australia’s national interest over the next ten years?”
In that incident, the presentation, if opened, contained the Sandworm vulnerability (CVE-2014-4114), which infects unpatched versions of Microsoft Office PowerPoint 2003 and 2007. Targeted systems were also infected with sysvolinfo.exe (the first stage payload of the APT) and 7zip.exe (second stage malware), according to the report.
During the course of Cymmetria’s investigation, it managed to access to one of Patchwork’s command and control servers where it found a stash of infected Microsoft PowerPoint files used in spear phishing attacks along with additional malicious code packages. “Most of the spear phishing file content was directly related to China-related subjects, or pornographic in nature,” according to the report.
As part of the investigation, Cymmetria was able to pull back the curtain on some of the second stage tools used by attackers and identify how intruders moved laterally through the network. Those tools included a compiled AutoIt script to escalate privileges by exploiting the computer’s user account control system along with PowerSploit, Meterpreter and the well-known Metasploit framework.
The exfiltration of data to a command and control server, according to Cymmetria, was once again carried out using a second stage payload built from code taken from various online forums and resources, according to the report.
“Unlike other APT threat actors, India seems to be a relatively quiet locale for cyber espionage activity. The scope and scale of this operation are quite surprising. This suggests that additional geopolitical powers are actively developing offensive cyber capabilities whilst simultaneously making attempts to maximize return on investment by keeping development costs to a minimum,” wrote the report authors.

пятница, 8 июля 2016 г.

Hackers attack U.S. restaurant chain "Wendy's"

The Wendy’s Co. on Thursday acknowledged that a year-long attack on point-of-sale systems at franchisee-owned locations is far more widespread than initially reported, affecting 1,025 locations overall.
The Dublin, Ohio-based burger chain said that malware installed on terminals in several states targeted customers’ payment card data, including their name, debit or credit card number, expiration date, cardholder verification value and service code.
The list of affected restaurants, to be posted on the company’s site, was not yet available.
“We sincerely apologize to anyone who has been inconvenienced as a result of these highly sophisticated, criminal cyberattacks,” Wendy’s CEO Todd Penegor wrote in a letter to customers.
“We have conducted a rigorous investigation to understand what has happened and we are committed to protecting our customers and keeping you informed.”

The 1,000 restaurants represents less than one in five domestic Wendy’s locations — there are 5,144 franchise-operated domestic units, plus another 582 company-owned locations.
Wendy’s described the security breach as a pair of attacks. The first, according to the company, started at some franchisee locations in late fall, was first reported in January and affected less than 300 locations.
But in June the company said that, during its investigation, it discovered a second malware attack, similar to the first, which affected many more than 300 locations. The 1,000 number is the first quantification of the restaurants affected by the dual attacks.
Wendy’s is offering one year of fraud consultation and identity restoration services to customers who used a payment card at a potentially affected restaurant during the time it might have been affected.
“In a world where malicious cyberattacks have unfortunately become all too common for merchants, we are doing what is necessary to protect our customers,” Penegor wrote. “We will continue to work diligently with our investigative team to apply what we have learned from these incidents and further strengthen our data security measures.”
Wendy’s believes that criminals gained access to point of sale terminals by gaining remote access to the system by using compromised credentials from third party service providers.
That gave the criminals’ access to the central system, enabling them to place malware onto the terminals that read the credit card information.
The company says the attack has only affected franchisee outlets and not the 582 company locations. That’s important because Wendy’s is shifting to a single point-of-sale system, called Aloha, that’s installed at company-owned units.
Wendy’s said it worked with investigators to disable the malware.

четверг, 7 июля 2016 г.

ANOTHER celebrity nude photo hacker pleads guilty

For those interested in photos - You can see all the photos here.


Another hacker who illegally accessed hundreds of Hollywood entertainment industry accounts – including those of dozens of high-profile female actresses and singers – may be headed to the hoosegow.
It’s the latest development into the US government’s continuing investigation into the September 2014 “Celebgate” leaks of intimate images of celebrities such as Jennifer Lawrence, Kate Upton, Kirsten Dunst, Selena Gomez, Kim Kardashian, Vanessa Hudgens, Lea Michele and Hillary Duff.
This week, Illinois resident Edward Majerczyk agreed to plead guilty to a felony violation of the Computer Fraud and Abuse Act, admitting to “unauthorized access to a protected computer to obtain information.” Once the plea is official, he’ll be sentenced: the statutory maximum would be five years.
Per the Justice Department’s description, Majerczyk’s crime started like these so often do: with phishing…
He sent e-mails to victims that appeared to be from security accounts of internet service providers that directed the victims to a website that would collect the victims’ usernames and passwords.
After victims responded by entering information at that website, Majerczyk had access to victims’ usernames and passwords. After illegally accessing the iCloud and Gmail accounts, Majerczyk obtained personal information including sensitive and private photographs and videos.
As United States Attorney Eileen M. Decker put it:
Defendant’s conduct was a profound intrusion into the privacy of his victims and created vulnerabilities at multiple online service providers.
Top FBI investigator Deirdre Fike, Assistant Director in Charge of the FBI’s Los Angeles Field Office, put it a bit more personally:
This defendant not only hacked into e-mail accounts – he hacked into his victims’ private lives, causing embarrassment and lasting harm.
As Variety reports, this case follows on the recent guilty plea by Pennsylvanian Ryan Collins, 36, who’s still awaiting sentencing. According to Variety, “though the charges against both men are very similar, Collins and Majerczyk were apparently operating independently.”

The feds have consistently stressed that they “have no evidence that either Collins [or] Majerczyk posted the hacked material online.” They’re still trying to figure out who did that.
There’s been no public statement about how these guilty pleas might relate to the government’s confiscation of another Chicago man’s computers – a story we covered in detail at the time. And these cases don’t appear related to Alonzo Knowles’ guilty plea in New York for celebrity hacking (including theft of new screenplays as well as sex videos)… nor of the recent felony hacking conviction of Andrew Helton in Oregon for similar hacking of celebrity-owned Apple and Google accounts.
But all these cases do seem to have one thing in common: if you hack a celebrity’s email or iCloud account, you’re going to end up with the US Department of Justice coming after you.