Showing posts with label Security News.. Show all posts
Showing posts with label Security News.. Show all posts

Banking Malware Distributed via YouTube Ads.

Malvertising attacks are becoming more and more common and it appears that not even YouTube users are safe.
Security researchers from Bromium Labs recently found that YouTube advertising network has been used by cyber criminals to distribute malware. According to experts, cyber criminals compromised an ad network and were redirecting users to malicious websites, hosting the 'Styx Exploit Kit' and infect users computer with Caphaw Banking Trojan..
This particular exploit kit is designed to exploit java vulnerability (CVE-2013-2460) in outdated versions, once in the targets computer system the malware detects the Java version installed on the operating system and based upon it loads suitable exploit compatible with the installed java version.
The command and control server (C&C) used by the cyber criminals appears to be hosted in Europe and it relies on a domain generation algorithm (DGA). Researcher has notified Google of the attack, but so far, they still do not know how the cyber criminals have pulled it off to evade Google’s internal advertisement security checks.And how many users had become victim of this attack is yet a question.
Google has confirmed that a rogue advertiser was behind this malvertisment and also said it has taken this campaign off and is beefing up internal procedures to prevent such events from occurring again.

EC Council hacked again,website defaced.


EC-Council, an organization that offers Certified Ethical Hacker(CEH) has been hacked by a hacker named Eugene Belford (A character from the 1995's movie "Hackers").
Passport and photo ID details of more than 60,000 security professionals who have obtained or applied for the EC-Council's Certified Ethical Hacker certification are at risk after the breach, many of whom work in sensitive political and military positions. They include members of the US military, FBI, United Nations, and National Security Agency.
The hacker left the EC-Council website with the Passport of Edward Snowden and documents proving that Snowden attended the CEH classes in India.

The self-described "certified unethical software security professional" responsible for the attack reportedly used a DNS redirect to access those details, which were stored in an inadequately protected location.
When we take a look at the source code, we can see that the hacker has uploaded two pictures directly on to the EC-Council web server.
As of still it seems as though EC-Council has not gained control of their website.  An update was posted on the EC-Council site stating:
“owned by certified unethical software security professional
Obligatory link: http://attrition.org/errata/charlatan/ec-council/ -Eugene Belford

P.S It seems like lots of you are missing the point here, I’m sitting on thousands of passports belonging to LE (and .mil) officials”.

Snapchat vulnerability allows hackers to launch DDoS attack and remotely crash your smartphone.

A new security bug has been reportedly discovered in photo sharing app, Snapchat,which could launch a DDoS attack on users  smartphones and cause them to crash.
Jamie Sanchez, a Security researcher first reported the vulnerability .The bug could allow hackers to overload user's inbox with messages, and crash the iPhone, requiring the user to reset their device, and make Android devices noticeably slower.

demonstrated the vulnerability to LA Times reporter,With consent, he sent 1,000 messages in 5 seconds to reporter account, which crashed his iPhone. Android phones apparently won’t crash with the attack, but they will significantly slow down, and the app itself becomes crippled.
He declined to contact Snapchat with his findings as he believes the company has no respect for the cyber security research community which was proved recently when the company did not pay much heed to researchers' warning about a vulnerability that could expose user data and ultimately published phone numbers of about 4.6 million users to prove their point.

the bug could allow hackers to overload an inbox with messages, and crash the iPhone, requiring the user to reset their device, and make Android devices noticeably slower.  - See more at: https://www.authintmail.com/article/technology/snapchat-vulnerability-can-crash-your-smartphone#sthash.mpgzAVPJ.dpuf

Your laptop Camera could spy on you without lighting up the warning light.

If you own a MacBook or any other laptop, you should cover up it's webcam, because there’s a possibility someone could be watching you.
Most of the webcam have a tiny light lets you know that the webcam is active, but it's possible for malware to disable this important privacy feature.
Two Students from Johns Hopkins University  Matthew Brocker and Stephen Checkoway created a proof of concept app called “iSeeYou” that confirmed that MacBook iSight webcams can spy on their users without the warning light being activated.
A young man recently pleaded guilty in court to extortion after he performed a remote hack on Miss Teen USA’s webcam to secretly collect nude photos. It was revealed through court papers that the FBI has the ability to do the same thing with a variety of current laptops including Apple products.
Your laptop camera could Spy on You without lighting up

World's largest collaborative phone directory compromised.


True Caller,a popular app built by a Swedish company and world's largest collaborative phone directory compromised by Syrian Electronic Army.The hacker group claimed on its Twitter accounts and its website,that it has managed to get access into the databases containing a hundred of millions of phone numbers and its owners in addition of millions of Facebook/Twitter/Linkedin/Gmail accounts.

Syrian Electronic Army have also posted screenshots of the website's WordPress dashboard and database.

According to the hackers about 560 GB of data was downloaded from Truecaller servers.
In another tweet they have also leaked the login credentials for the site's database.

TrueCaller confirmed the security breach in their official blog. However, they denied the hacker's claim that they had access to the social network's access codes.

PayPal denies to pay Bug Bounty reward to teenager.


A 17-year-old German student contends PayPal has denied him a reward for finding a vulnerability in its website.Robert Kugler said he notified PayPal of the vulnerability on May 19. He said he was informed by email that because he is under 18 years old, he did not qualify for its Bug Bounty Program.

Many companies such as Google and Facebook have reward programs. The programs are intended to create an incentive for website users to report problems and create fixes before hackers can take advantage.
Google pays from $100 up to $20,000 depending on the severity of the issue and Facebook pays a minimum of $500 for qualifying bugs. Neither company has age restrictions listed on their websites.

Australia's top spy agency headquarters blueprints stolen by Chinese hackers.


Australian Broadcasting Corp. television reported that the plans for the 630 million Australian dollar ($608 million) Australian Security Intelligence Organization building in Canberra had been stolen through a cyberattack on a building contractor.
Australian officials refused to confirm or deny whether Chinese hackers had stolen the blueprints of a new spy agency headquarters as a news report claims.
According to ABC's Four corners the blueprints setting out the building's cable layouts and security systems had been illegally accessed by a server in China.
Under this hacking operations the Prime Minster's Office, the Defence Ministry and the Department of Foreign Affairs had been breached.

iPhone has most vulnerabilities, so why is Android the most attacked?



The biggest story in malware right now is mobile malware. The shift from traditional mobile phones that simply made phone calls to smartphones containing gigabytes of data has made the
pocket-sized computers a prime target for attackers.
There was a 32 percent increase in the number of documented vulnerabilities for mobile operating systems and, not surprisingly, a 58 percent increase in mobile malware and
Android smartphones and tablets are the hottest targets. 
       Virtually all mobile malware samples detected are intended for Android, ranging from malware that sends out SMS messages, or fraudulent SMS payments, mobile botnets, spyware, and Trojans that can capture or destroy data from Android devices.
      There has been biggest spike in malware samples detected in four years, and the growing threat faced by mobile devices—particularly Android mobile devices.

Android app SwiftKey Keyboard turned into a Keylogger app.


One of the best 3rd party Android Mobile Keyboard called 'SwiftKey' turned into a Keylogger Trojan by an Android developer to show the possible security threat of downloading pirated cracked apps from non-official App Stores and websites , "anyone pirating Swiftkey is taking a serious risk" developer said.


 He demonstrated how to inject a Keylogger snippets of code into a legitimate Android Keyboard application that infected a mobile device with Trojan, connected with a remote server and transmitted data from the device inducing your all key logs.
Android apps are coded in Java and compiled to byte code that is run on the Dalvik VM and this byte code is not that hard to edit and insert back into an APK." he explained.

He developed a keylogger from SwiftKey(APK Download), a malicious Java program designed to collect and send all key logs to a remote server (Check Keylogs) Along with the host IP address. He explained the complete code also on his blog.
Android malware is growing at a far more rapid pace than for other mobile platforms. For a Cyber Criminals, it is not important to develop their own malware program from scratch, Reversing ready-mate apps and inserting malware code can easily make their job more easy.

 Be careful from where you are downloading apps and think about the permissions and consider what the app is asking to do, and