Google Search

Showing posts with label blamed. Show all posts
Showing posts with label blamed. Show all posts

Thursday, July 4, 2013

Uncool hacker blamed for unrevealing swimsuit photos of singer Victoria Justice

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Victoria JusticeAmerican singer Victoria Justice is not happy that someone (she blames a hacker) has leaked swimsuit photos of her onto the internet.

I've never heard of Victoria Justice, which may mean that the 20-year-old singer isn't targeting my particular demographic, but she's clearly famous enough to make headlines when she claims that the photos published of her were stolen by a hacker.

Media who covered the story described the leaked photos as "semi-racy... but nothing of the R-rated variety, showing Victoria fully clothed but in a bathing suit".

Clearly, however, Justice - who has her own show on Nickelodeon called "Victorious" - was not amused and is seeking, err, justice.

Hacking & stealing is NOT COOL. #RespectPeoplesPersonalProperty #Karma

And she's right, of course, hacking into someone's private accounts and stealing photos is *not* cool. And it's even less cool for websites to take the stolen images and to publish them on the net.

And yet it seems to keep on happening, and the websites appear to get away with it Scott free.

For instance, we've seen "news" websites publishing intimate snaps of Scarlett Johansson, Mila Kunis, Christina Aguilera, and many other celebrities in the past without any apparent consequences.

Although hackers can receive harsh penalties for accessing celebrity accounts and stealing photos, we don't hear anything about the gossip websites that willingly went public with the stolen material.

So I was at least pleased to see Victoria Justice take the magazine that published the snaps of her in her swimsuit to task via Twitter, and was pleased to hear that the magazine subsequently removed the pics from their site.

Follow @gcluley

Image of Victoria Justice courtesy of jake.auzzie/Flickr (Creative Commons)


View the original article here

Thursday, April 25, 2013

China blamed for EADS and ThyssenKrupp hack attacks

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Two more major organisations have gone public about, what they claim, were attempts by Chinese hackers to infiltrate their networks and steal sensitive information.

EADS, the European Aeronautic Defense and Space company, and steelmaker ThyssenKrupp are said to have become the targets of hack attacks originating in China, according to Der Spiegel.

EADS - who makes the Eurofighter jet, as well as spy drones, surveillance satellites, and even rockets for French nuclear weapons - are said to have contacted the German government last year to warn them that the military contractor's computer network has been hacked.

Eurofighter

Officially, EADS have described the attack as "standard" and insisted that no harm has been done.

However, the attacks is against a backdrop created over the last few years of of other hacks against the defence industry including the likes of Lockheed Martin, L-3 Communications and Northrop Grumman.

And, of course, it's only 18 months since the then US Deputy Defense Secretary William Lynn claimed that a foreign intelligence agency was behind a hack attack that stole classified information about a top secret weapons system.

Meanwhile, ThyssenKrupp has also said to have confirmed that it was attacked by hackers - adding the detail that the attack occurred in the United States, and appeared to originate from a Chinese internet address.

According to Der Spiegel, the attacks against ThyssenKrupp were described as "massive" and of "a special quality", and the company was not sure of what (if any) information had been stolen by the hackers.

It is becoming increasingly clear that organisations need to defend themselves not only from the day-to-day financial-orientated cybercrime attacks which can impact anyone with a computer, but also from sophisticated targeted attacks that may be designed to spy and surreptitiously steal information.

BlueprintThe truth is that these hacking stories aren't really describing a technological problem. They're describing a human problem. It's remarkably easy to dupe someone into clicking on a link or opening an attachment in an email, and for their computer to become compromised.

You can reduce the chances of a targeted attack working by keeping your software (such as your PDF reader, your web browser, your word processor, as well as your operating system) up-to-date with the latest patches.

Furthermore, you should run a layered defence - that means not just running up-to-date anti-virus software, but also firewalls, email filtering technologies, vulnerability assessment, using DLP (data loss protection) technology and strong encryption to secure your most sensitive data.

Also, it's amazing how many people re-use passwords, and use the same weak password in multiple places. That means if you get hacked in one place, and your password is compromised, it may also unlock accounts elsewhere on the net. It's shocking how many people don't use different passwords for different places.

All of these methods can reduce your chances of suffering from a targeted attack.

But ultimately, there's no 100% technological solution as human beings can still make bad decisions. And that's why it's important to train users about threats, and warn them to be suspicious of unsolicited links and attachments and to always report suspicious activity.

Follow @gcluley

View the original article here

Wednesday, January 4, 2012

Lax security blamed for 100,000+ sensitive files found on Manning's PC

Over 100,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Manning in courtroom - courtesy of wired.comFeeble computer security dominated the third day of a pretrial military hearing for Army Pfc. Bradley Manning.

The fourth pretrial hearing day, on Monday, put the spotlight on more than 100,000 sensitive documents and conversation logs between Manning and a former hacker, according to news reports.

The 24-year-old Manning stands accused of passing a trove of government documents to WikiLeaks while working as an intelligence analyst in Iraq in 2009 and 2010.

If found guilty, he could face the death penalty, although the Army has indicated it would not, in fact, press for his execution.

According to USA Today, investigators testified that Manning downloaded thousands of diplomatic cables; Guantanamo assessment documents; video from a controversial 2007 airstrike in Baghdad; and military records of a 2009 U.S. airstrike in Gerani, Afghanistan, in which dozens of civilians were killed.

Fifteen military staff have been disciplined in the wake of the scandal, according to the Defense Department.

Two witnesses called to testify on Sunday—Sgt. 1st Class Paul Adkins and Warrant Officer Kyle Bolonek—refused to answer questions, invoking their right to remain silent.

According to CNN, the Army has slashed Adkins's rank, from master sergeant to sergeant first class.

Prior to the WikiLeaks affair, the Army had no technology to block soldiers from downloading and transferring massive amounts of data.

Here's how Capt. Thomas Cherepko described the pre-WikiLeaks days, according to CNN's Larry Shaugnessy:

Capt. Thomas Cherepko said intelligence analysts like Manning could move information back and forth from their official computers and a shared computer hard drive. Testifying by telephone, he said there was nothing preventing a soldier from burning a CD of classified information, taking the CD, and then distributing whatever files were on it.

"The only thing preventing that is trust," said Cherepko, who served with Manning at the same base in Iraq.

Since Manning was last deployed to Iraq, the military has restricted the number of people authorized to download secret information, a military computer expert said on Sunday. New rules also require two people to authorize downloads, while mass information transfer sets off alerts.

That's certainly an improvement over an utter lack of oversight on what staff download and transfer. After all, you may be able to fend off attackers with firewalls, antivirus software and intrusion detection tools, but rogue insiders are a whole 'nuther kettle of fish.

How do you contain the considerable risk presented by rogue employees? Encrypt everything, as an enterprise key and certificate management vendor like Venafi would recommend?

Institute audit trails for access to encryption keys? Use different passwords to secure different keystores, and then rotate those passwords?

Maybe. But at the very least, you do what the Army is belatedly doing: set up some type of process that ensures that somebody, somewhere—optimally, a number of somebodies—is aware that your intellectual property/sensitive documents are on the move when they're on the move.

If we all paid more attention to the potential risk, perhaps somebody like Pfc. Manning—an allegedly gender-confused, confrontational underdog of an employee—would be prevented from getting into the hot water he's now in.

Image source of Army Pfc. Bradley Manning courtesy of wired.com
Follow @LisaVaas


View the original article here

Tuesday, November 22, 2011

Int'l hackers blamed in water pump attack

Published: Nov. 18, 2011 at 7:19 PM

WASHINGTON, Nov. 18 (UPI) -- Hackers outside the United States were responsible for damaging the municipal water system in Springfield, Ill., an expert says.

Joe Weiss provided information from a report on the Illinois attack to The Washington Post. A Department of Homeland Security spokesman confirmed the damaged water pump in Springfield and said federal agents were trying to determine if it was the result of a computer attack, the newspaper said.

The report said the pump burned out after the system powered up and down unpredictably. Weiss said a municipal water district employee noticed the problems Nov. 8, and a technician determined the system had been hacked into from a computer in Russia.

Computer hackers made a two-stage attack, Weiss said. The first was hacking into a software company data base to obtain the passwords needed for later attacks.

The report said investigators do not know if the hackers succeeded in getting into other systems.

"This is a big deal," Weiss said.

The computer used by the hackers is believed to be physically located in Russia.


View the original article here