Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
A security research team that has alerted Oracle to a series of security flaws in Java in the past, says that it has uncovered new zero-day vulnerabilities in the software.
According to Polish firm update posted by Security Explorations, it has sent proof-of-concept code to Oracle's security team - so they can investigate the issue.
The concern is that the flaws could be exploited to completely bypass Java's security sandbox and infect computers in a similar fashion to the attacks which recently troubled the likes of Facebook, Apple and Microsoft.
In those cases, cybercriminals hacked legitimate websites and planted code which exploited Java vulnerabilities when developers visited using web browsers that had a vulnerable version of the Java plugin.
Softpedia reports Security Explorations CEO Adam Gowdiak as saying:
"Both new issues are specific to Java SE 7 only. They allow to abuse the Reflection API in a particularly interesting way... Without going into further details, everything indicates that the ball is in Oracle's court. Again."
So, many computer users find themselves in what is becoming a disturbingly familiar situation - looking to see when Oracle will confirm that the flaws exist, and then waiting for the inevitable security update for Java.
Here's the best piece of advice we can give you right now:
Many people who have Java enabled in their browser simply do not need it (By the way, don't mix up Java with JavaScript - they're different things), so the best solution for many folks is to rip Java out of their browser entirely.
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
Score one for the little guy. Or gal in this case.
The cloud-based hosting firm MediaFire has reversed a decision to suspend the account of virus researcher Mila Parkour after Naked Security raised questions about copyright violation complaints made against her by the mysterious firm LeakID.
In an email to Parkour on Friday, MediaFire's director of customer support, Daniel Goebel, said that the company was restoring Parkour’s access to her MediaFire account and apologized for the interruption in service.
MediaFire also said it was asking LeakID, the Paris-based firm that accused Parkour of sharing copyrighted material, to “confirm the status of the counterclaim [Parkour] submitted.” However, the firm is still blocking access to files that LeakID alleged were violating the US Digital Millennium Copyright Act (DMCA), a strict copyright enforcement law in the U.S.
As reported by Naked Security, LeakID flagged three files for what the company considered three copyright violations:
a link to a Microsoft Office patch file related to an August 2011 Contagio blog posttwo encrypted ZIP files containing malicious PDFs used in online phishing scams examined in April and August 2010.
The reversal follows a public protest by Parkour on her Contagio malware blog, a respected resource for virus researchers and security experts.
In his email, Goebel said that the company regretted the inconvenience for Parkour, but that the company had its hands tied.
The circumstances of your case related to a 3rd party notice are unfortunate. Like all online service providers, we are compelled by law to suspend content upon the receipt of a complete DMCA Notice.
Parkour isn’t so sure. Writing on her blog on Friday, she notes that MediaFire took action against her even though LeakID, a Paris-based firm, hadn’t fulfilled key requirements of the DMCA in its request. Namely: the firm failed to identify the copyrighted work that was infringed, or prove that it was authorized to act on behalf of the copyright owner.
Parkour filed a counterclaim with LeakID and said the company has ten days to respond to it. If the company fails to do so, she said that the DMCA claim will be dropped and the blocked files restored. Writing on Friday, she said she suspected that the quick reversal from MediaFire was the result of press attention to the curious copyright claims from Naked Security and other sites.
That prompted a direct response from MediaFire CEO Derek Labian. In it, he said that the company investigates all claims of copyright violations and has a team to handle the claims and counterclaims from customers. Accounts are closed solely on the basis of complaints under DMCA, he said.
He said MediaFire complied with the complaints as stipulated by DMCA and that any mistake, if one was made, was on LeakID’s part.
Labian said Parkour didn’t give MediaFire time to complete its investigation and that he admired the ways in which Parkour was using MediaFire to support her research, according to a copy of the email viewed by Naked Security.
Labian also expressed skepticism about LeakID’s claims, which included a charge of copyright violation for a Microsoft Office patch that Parkour had reposted on her blog.
Labian wrote:
Personally, I find it strange that Microsoft would not want a security patch for one of its products freely distributed to as many users as possible. We think it's more likely at this point that the submissions are inaccurate.
In an email to Naked Security, Parkour said that LeakID’s use of automated scanning and complaint filing tools makes it more likely that those accused will have their accounts suspended. She also suggests many of those targeted don’t go through the hassle of protesting the take down orders.
MediaFire and LeakID did not respond to requests for comment prior to publication.
Parkour’s situation is not unique. In recent weeks, both the Democratic National Convention in the U.S. and the HUGO Awards have had broadcasts blocked by automated copyright scanners.
In March, the Electronic Frontier Foundation (EFF) filed an amicus brief in a similar case, contesting media giant Warner Brothers Entertainment’s use of automated tools to spot copyright infringement.
The brief, filed in a case in U.S. District Court for the Southern District of Florida concerned similar takedown notices affecting users of the hosting firm HotFile.
The EFF said that firms using the automated tools are aware that they make mistakes, and that the firms should be held responsible for denying legitimate users access to their content.
Warner and other firms were undermining DMCA provisions intended to protect internet users from overbroad and indiscriminate take-downs, the EFF argued.
Follow @paulfroberts
Megaphone, copyright symbol and cloud image courtesy of ShutterStock.
Tags: Adobe, Contagio, copyright, DMCA, internet security, LeakID, malicious PDF, malicious software, Malware, Microsoft, Mila Parkour, Patch, PDF
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
A host of Facebook accounts belonging to US baseball teams were hacked yesterday, and defaced with messages in dubious taste, including one which claimed that New York Yankees captain Derek Jeter was undergoing a sex change.
"We regret to inform our fans that Derek Jeter will miss the rest of the season with sexual reassignment surgery. He promises to come back stronger than ever in 2013 as Minnie Mantlez"
Other clubs affected included the Miami Marlins, San Diego Padres, Chicago White Sox, Washington Nationals, Chicago Cubs and San Francisco Giants.
Here is a selection of the messages that were posted:
Clearly an unauthorised party had managed to gain admin access to the Facebook pages in order to post the messages - and the first thought is that it would be a very strange coincidence to have the Facebook pages of so many clubs compromised at the same time.
However, it turns out that the clubs run the Facebook pages in conjunction with MLB Advanced Media.
One possible scenario is that an MLB Advanced Media employee was sloppy with their password (maybe they weren't using a hard-to-guess password, or maybe they were using a password that they had also been using elsewhere on the net), allowing a hacker to gain access and post the inappropriate content.
A spokesperson for the baseball league told the Wall Street Journal that they were working with Facebook and law enforcement to see if they could identify what had happened, and who might have been responsible:
"For a brief moment today, a few MLB Club Facebook accounts were hacked and inappropriate material was briefly on display from those Clubs' pages on Facebook. MLB Advanced Media oversees these Facebook pages on behalf of the Clubs and regrets this occurrence. We are working with Facebook, Major League Baseball Security and, where appropriate, legal authorities to determine the circumstances surrounding this situation."
I guess everyone should be grateful that the hacker didn't exploit their access to the baseball clubs' Facebook pages by posting something more malicious - such as links to malware-infected pages - that could have impacted thousands of sports fans.
This isn't, of course, the first time that Facebook fan pages have been hacked and unauthorised posts made. There have been a wide variety of victims in the past, ranging from Viagra manufacturer Pfizer, Nicolas Sarkozy, and last year the rapper Soulja Boy who blamed a hacker for a series of racist and homophobic rants.
Perhaps the most embarrassing incident of this nature was when Facebook's own CEO, Mark Zuckerberg, had his official fan page hacked via an API bug.
Make sure that you keep informed about the latest security and privacy issues on Facebook. Join the Sophos page on Facebook, where over 190,000 people regularly share information on threats and discuss the latest security news.
Follow @gcluley
Baseball player image from Shutterstock.
Tags: baseball, Chicago Cubs, Chicago White Sox, Derek Jeter, Facebook, hacking, Miami Marlins, MLB, New York Yankees, San Diego Padres, San Francisco Giants, Washington Nationals
SPRINGFIELD, Mo. • Springfield officials are offering 2,100 people free identity theft protection for a year after an internationally known group claimed it hacked into the city's website and stole residents' personal information.
KYTV reports the city's website was compromised Feb. 17, and a day later a group known as Anonymous tweeted that it had hacked Missouri government websites.
The group says it will not release information from private citizens, such as Social Security numbers, birth dates and cell phone numbers. But Springfield City Manager Greg Burris says the city is offering one year of ID theft protection insurance to affected residents, just in case.
Burris says the protection will cost a little less than $50,000 to the city, which also is reviewing security measures to prevent future hacking.
People identifying themselves as activists in the Anonymous hacker movement said Wednesday it wasn't technical prowess but police infiltration that yielded 25 arrests in a sweep in Europe and South America.
In conversations in an online chat room where Spanish-speaking activists in the Americas and Spain regularly gather, they said nearly all of those arrested had been active on a single website used by the group.
Among those detained were a Spaniard known by the online nickname "Pacotron" or "Thunder," according to Spanish police and a communique issued by Anonymous Iberoamerica, which said he lives in Malaga.
The statement by the loosely organized collective's Spanish-language branch identified another of those arrested as a Spaniard known as "Troy" who it said owned computer servers in "such distant places as Slovakia and Romania."
Interpol, which announced the arrests Tuesday, did not say how it encountered the 25 suspects, who it says were involved in cyberattacks originating from Argentina, Chile, Colombia and Spain that targeted sites including Colombia's defense ministry and presidency and Chile's Endesa electricity company and national library.
Activists encountered in the chat room said some of those arrested belonged to a group of hackers called Sector404 while others were unsophisticated activists who took part in denial-of-service attacks, which overwhelm websites with data requests.
"The GREAT majority of those implicated were people inhabiting the servers of anonworld.info, something that disconcerts us," said the activist "Skao," who identified herself as a law student.
In the communique released on its blog, Anonymous Iberoamerica said the 25 were snared not through "inteligence work or informatics strategy" but rather through "the use of spies and informants within the movement."
The activists said many of those arrested had been careless, leaving digital tracks.
A spokeswoman for Chile's chief prosecutor, Marlis Pfeiffer, told The Associated Press on Wednesday that authorities had released the five people arrested there in the sweep, two of whom were 17-year-olds. Anonymous Iberoamerica said three of them were computer science students, one a programmer and one a Colombian.
Pfeiffer said investigators were examining computers confiscated from the five to determine if criminal charges will be filed but were encountering difficulties, presumably encrypted data.
An Argentine police official said Wednesday that 10 adults were still being detained. The official said he had no further information and spoke on condition he not be further identified. Anonymous Iberoamerica said those arrested in Argentina included Colombians and that many were minors.
The arrests followed an investigation begun in mid-February and also led to the seizure of 250 items of IT equipment in 15 cities, according to Interpol, the international police agency that announced them.
Anonymous activists deface websites, carrying out denial-of-service attacks and publish data obtained in computer break-ins.
They are engaged in a number of political causes, including opposition to the global clampdown on file-sharing sites and defense of the secret-spilling site WikiLeaks. The Vatican has also been a target.
In Brazil, Anonymous hacktivists attacked nine banks last month.
Elsewhere in Latin America, they have targed government agencies and ministries they claim are corrupt.
"We hope you understand and reveal that we are not hackers on steroids. We are activists and what happens in the world matters to us," said Skao.
Authorities in Europe, North America and elsewhere have made dozens of arrests of Anonymous activists. In response, the group has increasingly attacked law enforcement, military and intelligence-linked targets.
Anonymous has no real membership structure. Hackers, activists, and supporters can claim allegiance to its freewheeling principles at their convenience, so it's unclear what impact the arrests will have.
———
Associated Press writer Raphael Satter in London contributed to this report.
Hackers who said they attacked Stratfor Global Intelligence service, a security research group based in Austin, Tex., over the weekend have claimed a second target: Special Forces, a veterans-owned Web site that sells military-inspired merchandise and gives away a portion of profits to charity.
The hackers, who claim to be members of the collective known as Anonymous, said they had breached the SpecialForces.com server Tuesday and stolen customers’ credit card details and passwords, in what they said was stage two of a “week long celebration of wreaking utter havoc on global financial systems, militaries and governments.”
In a posting online , the hackers said they were able to steal customer credit card information even though the site’s data was encrypted, and claimed to have 14,000 passwords and details for 8,000 credit cards belonging to Special Forces’ customers. They said they breached the Special Forces’ site months ago.
By Wednesday, IdentityFinder, a maker of data protection software, confirmed that SpecialForces.com had been compromised and determined that hackers had taken 7,277 unique credit card numbers, 40,854 e-mail addresses and released 36,368 usernames and passwords.
In a statement, Special Forces said its servers were hacked by Anonymous last August but added that it had “no evidence of any further security breaches and we believe that the recent Stratfor incident is being used to bring this old news back into the spotlight.”
WASHINGTON (Reuters) - Hackers took control of a FoxNews.com Twitter account on Monday and sent six false tweets saying that U.S. President Barack Obama had been shot dead, prompting an investigation by the Secret Service.
"Hackers sent out several malicious and false tweets that President Obama had been assassinated," Foxnews.com said in a statement about the latest in a wave of high-profile cyber security breaches around the world.
"Those reports are incorrect, of course, and the president is spending the July 4 holiday with his family."
The media outlet, owned by Rupert Murdoch's News Corp, said the incident was being checked.
"The hacking is being investigated, and FoxNews.com regrets any distress the false tweets may have created," it said.
Obama is celebrating the July 4 Independence holiday with his family at the White House and was due to host military families to watch Fourth of July fireworks in the evening.
The White House declined to comment. The Secret Service, which is charged with protecting the president, said it was looking into the incident.
"The Secret Service is investigating the matter and will conduct the appropriate follow-up," spokesman George Ogilvie said.
The first hacked tweet appeared around 2 a.m. and said: "@BarackObama has just passed. The President is dead. A sad 4th of July, indeed. President Barack Obama is dead."
The next one, "@BarackObama has just passed. Nearly 45 minutes ago, he was shot twice in the lower pelvic area and in the neck; shooter unknown. Bled out."
The false tweets were removed around noon today, a Fox News spokeswoman said, after Twitter suspended the account.
Fox News Digital Vice President and General Manager Jeff Misenti said FoxNews.com was working with Twitter to address the situation as quickly as possible.
"We will be requesting a detailed investigation from Twitter about how this occurred, and measures to prevent future unauthorized access into FoxNews.com accounts," Misenti said.
In an email statement to Reuters, a spokesman for Twitter said, "while Twitter does monitor accounts for brute-force log-in attempts and similar methods of attack, we're unable to anticipate compromises that take place due to off-site behavior."
The Twitter spokesman also said that Fox News indicated its account had been compromised.
CYBER BREACHES
A group calling itself The ScriptKiddies claimed responsibility for sending the tweets -- including "#ObamaDead, it's a sad 4th of July" -- from the "FoxNewspolitics" news feed before Twitter suspended its access.
In all some six false tweets were issued, saying Obama had been shot at a restaurant in Iowa while campaigning.
Obama was not in Iowa this weekend. He returned on Sunday to the White House from a brief trip to Camp David in neighboring Maryland.
The Foxnews.com account hacking followed a wave of highly publicized cyber security breaches, including attacks on the bank Citigroup, Sony Corp., Apple and the U.S. Senate and Brazilian presidential websites.
The FoxNews.com hacking came two days before Obama's first "Twitter town hall" where he will field tweeted questions about the economy and jobs.
Twitter's co-founder and executive chairman, Jack Dorsey, is due to moderate that Wednesday session at the White House.
Fox.com, another Fox Entertainment Group website, was the target of an attack by hacker group Lulz Security in May.
LulzSec has also made assaults on Sony, the U.S. Central Intelligence Agency (CIA) and other targets. The attacks have mostly resulted in temporary disruptions to websites and the release of user credentials.
(Additional reporting by Ilaina Jonas, Tom Doggett, Jeff Mason and Nadia Damouni; Editing by Sandra Maler and Steve Orlofsky)
WASHINGTON (Reuters) - Hackers took control of a FoxNews.com Twitter account on Monday and sent six false tweets saying that U.S. President Barack Obama had been shot dead, prompting an investigation by the Secret Service.
"Hackers sent out several malicious and false tweets that President Obama had been assassinated," Foxnews.com said in a statement about the latest in a wave of high-profile cyber security breaches around the world.
"Those reports are incorrect, of course, and the president is spending the July 4 holiday with his family."
The media outlet, owned by Rupert Murdoch's News Corp, said the incident was being checked.
"The hacking is being investigated, and FoxNews.com regrets any distress the false tweets may have created," it said.
Obama is celebrating the July 4 Independence holiday with his family at the White House and was due to host military families to watch Fourth of July fireworks in the evening.
The White House declined to comment. The Secret Service, which is charged with protecting the president, said it was looking into the incident.
"The Secret Service is investigating the matter and will conduct the appropriate follow-up," spokesman George Ogilvie said.
The first hacked tweet appeared around 2 a.m. and said: "@BarackObama has just passed. The President is dead. A sad 4th of July, indeed. President Barack Obama is dead."
The next one, "@BarackObama has just passed. Nearly 45 minutes ago, he was shot twice in the lower pelvic area and in the neck; shooter unknown. Bled out."
The false tweets were removed around noon today, a Fox News spokeswoman said, after Twitter suspended the account.
Fox News Digital Vice President and General Manager Jeff Misenti said FoxNews.com was working with Twitter to address the situation as quickly as possible.
"We will be requesting a detailed investigation from Twitter about how this occurred, and measures to prevent future unauthorized access into FoxNews.com accounts," Misenti said.
In an email statement to Reuters, a spokesman for Twitter said, "while Twitter does monitor accounts for brute-force log-in attempts and similar methods of attack, we're unable to anticipate compromises that take place due to off-site behavior."
The Twitter spokesman also said that Fox News indicated its account had been compromised.
CYBER BREACHES
A group calling itself The ScriptKiddies claimed responsibility for sending the tweets -- including "#ObamaDead, it's a sad 4th of July" -- from the "FoxNewspolitics" news feed before Twitter suspended its access.
In all some six false tweets were issued, saying Obama had been shot at a restaurant in Iowa while campaigning.
Obama was not in Iowa this weekend. He returned on Sunday to the White House from a brief trip to Camp David in neighboring Maryland.
The Foxnews.com account hacking followed a wave of highly publicized cyber security breaches, including attacks on the bank Citigroup, Sony Corp., Apple and the U.S. Senate and Brazilian presidential websites.
The FoxNews.com hacking came two days before Obama's first "Twitter town hall" where he will field tweeted questions about the economy and jobs.
Twitter's co-founder and executive chairman, Jack Dorsey, is due to moderate that Wednesday session at the White House.
Fox.com, another Fox Entertainment Group website, was the target of an attack by hacker group Lulz Security in May.
LulzSec has also made assaults on Sony, the U.S. Central Intelligence Agency (CIA) and other targets. The attacks have mostly resulted in temporary disruptions to websites and the release of user credentials.
(Additional reporting by Ilaina Jonas, Tom Doggett, Jeff Mason and Nadia Damouni; Editing by Sandra Maler and Steve Orlofsky)
Hackers used a Fox News Twitter account, @foxnewspolitics, to post a series of messages Monday, claiming the president was shot and killed at Ross’ Restaurant in Bettendorf, the New York Times reported.
President Barack Obama visited the restaurant during his June 28 visit to the Quad-Cities for a tour and speech at Alcoa Davenport Works.
FoxNews.com later posted a brief statement saying that the reports were incorrect, and that it regretted “any distress the false Tweets may have created,” the Times reported.
Melissa Freidhof-Rodgers, manager of Ross’ Restaurant and daughter of owners Cynthia and Ron Freidhof, said Monday that she had no comment about the Twitter posts and added that she wants to maintain the positive experience of having the president visit the restaurant.
After the president’s visit, Freidhof-Rodgers appeared on MSNBC’s “Rachel Maddow Show,” to show viewers the two meals the president ordered during his stop — the Magic Mountain and Volcano.
The six messages posted on the Fox New Twitter account were removed about noon Monday, about 10 hours after they were first posted, the Times reported.
The paper also reported that senior Secret Service officials gathered Monday morning to discuss the Twitter posts. A spokesman for the Secret Service, George Ogilvie, told the paper, “We are investigating the matter and will be conducting appropriate follow-up.”
Jeff Misenti, the vice president and general manager of Fox News Digital, said in a later statement Monday that the news organization would be requesting “a detailed investigation from Twitter about how this occurred, and measures to prevent future unauthorized access into FoxNews.com accounts,” the Times reported.
Obama stopped at the restaurant to follow up on a pledge he made to Cynthia Freidhof at a 2007 campaign event in the Quad-Cities. Friedhof asked Obama from the audience how he could help small businesses. Her husband, Ron, is “on the fence,” she said.
Obama said to get him on the phone, and she dialed her cell phone. As she was calling, Obama told the crowd that he advocates tax cuts that would help small businesses. She handed him the phone and he spoke briefly to her husband. Obama acknowledged that his call was coming during the busy lunch rush. “How’s lunch hour?” Obama asked. “I’ve got to try one of the Magic Mountains. I’ll talk to you soon.”
A customer types on a MacBook laptop at an Apple Store in San Francisco, U.S.A., on May 9.Incident part of wave of cyber attacks designed to embarrass big companiesPotential Apple breach was ppublicizedthrough a Twitter message from AnonymousIRC of cyberactivist collective AnonymousFBI inquiry into earlier incidents yields evidence of internal rifts
(FT) -- A hacking group has claimed it breached corporate security at Apple and has published what it said were two dozen administrator names and apparently encrypted passwords for a server at the US technology group.
The data was not linked to the more than 200m customer credit cards stored on the iTunes online store. The server collected survey information and therefore might have only limited use for criminals.
Nonetheless, the breach showed that a recent wave of cyberattacks designed in part to embarrass big companies would continue, even without Lulz Security , the pioneering group that drew wide attention for a similar, 50-day spree.
A potential Apple breach was publicized through a Twitter message from AnonymousIRC, one of many accounts associated with the cyberactivist collective Anonymous.
"Apple could be targeted, too. But don't worry, we are busy elsewhere", the Anonymous account wrote on Twitter.
When Lulz disbanded a week ago, it said some future attacks would be carried out by Anonymous and called on other hackers to continue the effort it calls AntiSec, for anti-security.
Apple declined to comment. On the surface, the breach at the largest music music would seem less serious than recent penetrations at big gaming groups such as Sony, which saw details of 100m online game players revealed.
Lulz drew big concern from the law enforcement authorities because it temporarily knocked offline public websites of the CIA and the UK Serious Organised Crime Agency and penetrated a joint venture between the FBI and the private sector.
In the UK, 19-year-old Ryan Cleary has been charged with denial-of-service attacks like that on Soca and is co-operating with authorities. Lulz has said that he played a tangential role in its operations.
In the past two weeks, the FBI searched two US residences in its probe, carting off computers from the homes of a teenager from Hamilton, Ohio, and a 29-year-old woman in Davenport, Iowa.
Material from the FBI's probe includes evidence of internal rifts, which are proving a fruitful source of information in the inquiry. Lulz published the Ohio teen's address and online nicknames this month as it blamed him for the arrest of Mr Cleary. The Iowa woman told the Financial Times she was outed after leaking records of the group's internal chats, which she did after they turned against a friend.
A group of hackers who have attacked a number of Web sites in recent months said Sunday that they had stolen a small number of internal passwords and usernames from an Apple server.
The information was supposedly taken from a server used by Apple for online surveys and did not belong to the public or Apple customers. The data was posted publicly on pastebin, a file-sharing Web site.
Anonymous, the group claiming responsibility for the attack, is believed to be working closely with hackers who were involved in Lulz Security, a hacker group that disbanded last week after attacking a number of sites over the past two months, including PBS.org, the United States Senate, the Arizona Department of Public Safety and the Web site of a company associated with the Federal Bureau of Investigation.
The latest breach, which only contains 27 internal Apple usernames and passwords, is a relatively small amount of data compared to attacks on other companies, but it underscores the potential for other attacks by Anonymous.
Apple could not be reached for comment to confirm whether the information was stolen from the company.
In the Twitter message about the data breach, hackers said Apple could become a larger target but that members were currently busy with other goals. “Apple could be target, too. But don’t worry, we are busy elsewhere,” the group wrote in the message.
Earlier this month Lulz Security claimed it had breached Apple’s iCloud servers, which are used for the company’s cloud music and photo service that is expected to launch later this year, but the group never posted any of this alleged information online.
This latest breach, and other recent attacks on corporate and government Web sites, is part of a growing movement by hackers called Anti Security, or AntiSec online. The public stated goal of this movement is to expose loopholes and software vulnerabilities on company and government Web sites and servers. Security experts and law enforcement see the string of AntiSec-labeled attacks as a justification by hackers to wreak havoc online.
Published: 6:53AM Tuesday July 05, 2011 Source: Reuters
Barack Obama - Source: Reuters
Hackers took control of a FoxNews.com Twitter account on Monday and sent six false tweets saying that US President Barack Obama had been shot dead.
"Those reports are incorrect, of course, and the president is spending the July 4 holiday with his family," Foxnews.com said in a statement about the latest in a wave of high-profile cyber security breaches around the world.
"Hackers sent out several malicious and false tweets that President Obama had been assassinated," said the conservative media outlet owned by Rupert Murdoch's News Corp.
"The hacking is being investigated, and FoxNews.com regrets any distress the false tweets may have created," it said.
Obama is celebrating the July 4 Independence holiday with his family at the White House and was due to host military families to watch Fourth of July fireworks in the evening.
The White House and Secret Service both declined to comment on the incident.
The first hacked tweet appeared around 2 a.m. and said: "BarackObama has just passed. The President is dead. A sad 4th of July, indeed. President Barack Obama is dead."
The next one, "BarackObama has just passed. Nearly 45 minutes ago, he was shot twice in the lower pelvic area and in the neck; shooter unknown. Bled out."
Fox News Digital Vice President and General Manager Jeff Misenti said FoxNews.com was working with Twitter to address the situation as quickly as possible.
"We will be requesting a detailed investigation from Twitter about how this occurred, and measures to prevent future unauthorized access into FoxNews.com accounts," Misenti said.
Cyber breaches
A group calling itself The ScriptKiddies claimed responsibility for sending the tweets - including "?ObamaDead, it's a sad 4th of July" - from the "FoxNewspolitics" news feed before Twitter suspended its access.
In all some six false tweets were issued, saying Obama had been shot at a restaurant in Iowa while campaigning.
Obama was not in Iowa this weekend. He returned on Sunday to the White House from a brief trip to Camp David in neighboring Maryland.
The Foxnews.com account hacking followed a wave of highly publicized cyber security breaches, including attacks on the bank Citigroup, Sony Corp., Apple and the US Senate and Brazilian presidential websites.
Monday's breach raised questions about the integrity of news feeds on Twitter, which is increasingly used by news outlets as well as government officials as a way to reach readers and supporters.
Twitter spokeswoman Jodi Olson declined to say whether the company would add more security as a result of the attack, but stressed it was important for users to shield their profiles.
"We don't comment on specific accounts. In general, though, it's always good to remind people of the importance of actively protecting their account credentials," Olson said, recommending that all users have a strong password as a "starting point."
The FoxNews.com hacking came two days before Obama's first "Twitter town hall" where he will field tweeted questions about the economy and jobs.
Twitter's co-founder and executive chairman Jack Dorsey is due to moderate that Wednesday session at the White House.
Fox.com, another Fox Entertainment Group website, was the target of an attack by hacker group Lulz Security in May.
LulzSec has also made assaults on Sony, the U.S. Central Intelligence Agency (CIA) and other targets. The attacks have mostly resulted in temporary disruptions to websites and the release of user credentials.
Technology News VideoEmail
Choose the news you want when you want it, all in one personalised daily e-mail.
Mobile Devices
TVNZ is available on mobile phones: Text TVNZ to 8869.
Social Media
TVNZ on Facebook and Twitter.
News Feeds
See when TVNZ have added new content. You can get the latest headlines anywhere.
Podcasts
Enjoy TVNZ on the move - a wide range of programmes and highlights are available.
Sony's turn as the whipping boy for Internet hackers continued over the weekend. Two hackers posted a list of e-mails they say they took from the Sony Pictures France Web site.
The two hackers who claim responsibility are a Lebanese student who goes by the handle Idahc, and a French friend of his who goes by Auth3ntiq. The two say they copied 177,172 e-mails from the entertainment company's site, but posted only 70 of them on the code-sharing site Pastebin. They say they will not be posting all of the e-mails they found.
Jim Kennedy, Sony Pictures executive vice president of communications, said in a statement, "We are currently investigating this claim."
The brief Pastebin posting says the pair managed to lift the e-mail addresses through an SQL injection.
It's the same method that was used to extract personal data of customers from SonyPictures.com, Sony Pictures Russia, Sony Ericsson, and Sony Music Entertainment Japan in recent weeks.
Idahc isn't a stranger to attacking Sony's sites. He was the one who claimed to have taken data from a Sony Ericsson eShop Web site last month, leaked a database from Sony Europe, and compromised a Sony Portugal site.
Idahc said in an interview with Forbes last week he began hacking for "justice," but now says he's trying to prompt companies like Sony to improve their security.
Attrition.org has been keeping track of the spate of attacks on Sony. It says this is the 20th breach of a Web site or network related to the company in two months, starting with the PlayStation Network breach in April that put the gaming service out of commission for more than three weeks.
This story was updated at 2:28 p.m. PT with comment from Sony.
HARTFORD, Conn. – Hackers who claimed responsibility for online attacks of Sony Corp. and the CIA said they compromised the security of more than 1,000 accounts of a Connecticut-based FBI partner organization, hours before releasing a web manifesto calling for "war" on governments that control the Internet.
The online collective Lulz Security said it attacked a local section of InfraGard, a partnership between the FBI and the private sector to share security information. Connecticut InfraGard's website was down Monday afternoon.
The FBI was aware of the attack and that the website had been shut down as a precaution, agency spokeswoman Jenny Shearer said. She declined to comment on the extent of any damage.
Lulz tweeted Sunday night that its Connecticut attack had "compromised 1000+ FBI-affiliated members." The group said it would not leak the user information but would embarrass the FBI with "simple hacks." It did not provide details on the information it said was compromised.
InfraGard is an association of businesses, academic institutions and law enforcement agencies dedicated to sharing information to prevent hostile acts against the United States, according to its website. Business representatives who participate get access to security information from government sources such as the FBI and Department of Homeland Security and can participate in discussions with others in the IT-security field.
This month, the Atlanta chapter of InfraGard said hackers stole 180 passwords from its members and leaked them online. Lulz also claimed responsibility for that attack, saying it was a response to a report that the Pentagon was considering whether to classify types of cyber-attacks as acts of war.
After announcing the Connecticut attack, the group issues its statement calling for a united hacker effort against governments and organizations that control the Internet.
"Our Lulz Lizard battle fleet is now declaring immediate and unremitting war on the freedom-snatching moderators of 2011," the group said in the statement, which was written in its characteristic rambling speech.
The group said it was teaming with another hacker collective, Anonymous, and encouraged others to fight corruption and attack any government or agency that "crosses their path" including banks and other "high-ranking establishments."
Anonymous is a group of online activists that has claimed responsibility for attacking companies online such as Visa, MasterCard and PayPal over their severing of ties with WikiLeaks following that group's release of troves of sensitive documents. Anonymous also led a campaign against the Church of Scientology.
Anonymous and similar hacker organizations are notable for their leaderless, diffuse construction that maximizes secrecy but can lead to mixed or unclear messages.
Lulz has taken credit for hacking into the PlayStation Network of Sony Corp., where more than 100 million user accounts were compromised, and defacing the PBS website after it aired a documentary seen as critical of WikiLeaks founder Julian Assange. The hackers also say they are responsible for attacks on the CIA webpage and the U.S. Senate computer system.
HARTFORD, Connecticut — Hackers who claimed responsibility for online attacks against Sony Corp. and the CIA said they compromised the security of more than 1,000 accounts of an FBI partner organization, hours before releasing a web manifesto calling for "war" on governments that control the Internet.
The online collective Lulz Security said it attacked a local section of InfraGard, a partnership between the FBI and the private sector to share security information. InfraGard's website was down Monday afternoon.
The FBI was aware of the attack and that the website had been shut down as a precaution, agency spokeswoman Jenny Shearer said. She declined to comment on the extent of any damage.
Lulz tweeted Sunday night that its Connecticut attack had "compromised 1000 (plus) FBI-affiliated members." The group said it would not leak the user information but would embarrass the FBI with "simple hacks." It did not provide details on the information it said was compromised.
InfraGard is an association of businesses, academic institutions and law enforcement agencies dedicated to sharing information to prevent hostile acts against the United States, according to its website. Business representatives who participate get access to security information from government sources such as the FBI and Department of Homeland Security and can participate in discussions with others in the IT-security field.
This month, the Atlanta chapter of InfraGard said hackers stole 180 passwords from its members and leaked them online. Lulz also claimed responsibility for that attack, saying it was a response to a report that the Pentagon was considering whether to classify types of cyber-attacks as acts of war.
After announcing the Connecticut attack, the group issued its statement calling for a united hacker effort against governments and organizations that control the Internet.
"Our Lulz Lizard battle fleet is now declaring immediate and unremitting war on the freedom-snatching moderators of 2011," the group said in the statement, which was written in its characteristic rambling speech.
The group said it was teaming with another hacker collective, Anonymous, and encouraged others to fight corruption and attack any government or agency that "crosses their path" including banks and other "high-ranking establishments."
Anonymous is a group of online activists that has claimed responsibility for attacking companies online such as Visa, MasterCard and PayPal over their severing of ties with WikiLeaks following that group's release of troves of sensitive documents. Anonymous also led a campaign against the Church of Scientology.
Anonymous and similar hacker organizations are notable for their leaderless, diffuse construction that maximizes secrecy but can lead to mixed or unclear messages.
Lulz has taken credit for hacking into the PlayStation Network of Sony Corp., where more than 100 million user accounts were compromised, and defacing the PBS website after it aired a documentary seen as critical of WikiLeaks founder Julian Assange. The hackers also say they are responsible for attacks on the CIA webpage and the U.S. Senate computer system.
More LulzSec news from msnbc.com:
Copyright 2011 The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.