Tag: hack

  • Russia offers its support to North Korea amid the Sony Hack

    Russia offers its support to North Korea amid the Sony Hack

    EWT is following the Sony Hacks, North Korea’s internet outages, and all other related topics as they develop. See bottom of article for further reading.


    MOSCOW –  Russia on Thursday offered sympathy to North Korea amid the Sony hacking scandal, saying the movie that sparked the dispute was so scandalous that Pyongyang’s anger was “quite understandable.”

    Washington failed to offer any proof to back its claims of Pyongyang’s involvement in the hacking, Russian Foreign Ministry spokesman Alexander Lukashevich said at a briefing, adding that the U.S. threats of retaliation were “counterproductive.”

    The U.S. has blamed Pyongyang for the recent cyberattack on Sony Pictures, which produced “The Interview,” a comedy depicting the assassination of North Korean leader Kim Jong Un. Pyongyang has denied a role in the hacking, but also praised it as a “righteous deed.”

    Sony initially decided not to release the film because of threats against U.S. cinemas, but released the movie online Wednesday.

    Russia’s ties with the communist North soured after the 1991 Soviet collapse, but have improved under President Vladimir Putin’s watch. Moscow has taken part in international efforts to help mediate the standoff over Pyongyang’s nuclear and missile programs, although its diplomatic efforts have had little visible effect.

    Last week, the Kremlin said that it had invited Kim to Moscow in May to attend festivities marking the 70th anniversary of the victory over Nazi Germany.

    Commenting on the Sony hack scandal, Lukashevich said that “the concept of the movie is so aggressive and scandalous, that the reaction of the North Korean side, and not just it, is quite understandable.”

    He went on to say that Pyongyang had offered to conduct a joint investigation into the incident, adding that the proposal could help ease tensions and reflected a “sincere desire of the North Korean side to study the issue in detail.”

    “We perceive the U.S. threats to take revenge and calls on other nations to condemn the Democratic People’s Republic of Korea as absolutely counterproductive and dangerous, as they only would add tensions to the already difficult situation on the Korean Peninsula and could lead to further escalation of conflict,” Lukashevich said.

    Further Reading:
    North Korea’s Internet is Offline     –     Sony Hack: U.S President Vows Responsibility for FBI Claims

    via Foxnews

  • PlayStation Network, Xbox LIVE offline due to Attacks

    PlayStation Network, Xbox LIVE offline due to Attacks

    The two most popular gaming networks, PSN and Xbox Live, have been offline most of Christmas day due to a DDoS (distributed denial of service) attack. A group named the Lizard Squad has taken credit for the attack. This is the same group that credited themselves for an attack on the PlayStation network and MMO games World of Warcraft and League of Legends back in August.

    Both service status pages for the Xbox and PSN state (at the time of this writ) that they’re offline. This definitely caps off a rough Holiday for Sony, who recently had their Sony Pictures subsidiary get attacked and sourced as one of the biggest tech topics over the past week and a half. During which, a group of hackers named the Guardians of Peace (GOP) threatened a 9/11 style attack on theaters that would show the leaked Sony Pictures movie “The Interview.”

    Sony had decided to pull the film when the U.S. government determined that North Korea had been behind the hack, but recently decided to put the film on services like Google Play and show it in cinemas in the U.S. on Christmas day. The film can be purchased on other services like YouTube and, on Xbox Live.

    We’re aware that some users are having issues logging into PSN – engineers are investigating
    — PlayStation (@PlayStation) December 25, 2014

  • Don’t Fall for this: Classic Facebook “Color Changer” Scam makes a Big Return

    Don’t Fall for this: Classic Facebook “Color Changer” Scam makes a Big Return

    COMMENT: While the idea of changing the Facebook default blue header to your custom color seems great, Cheetah Mobile has warned that you might end up getting more than what you bargained for.

    IDG NEWS NETWORK – On Facebook, some scams are so alluring that they seem to live forever.

    So it goes with “Facebook Color Changer,” a new malware attack that masquerades as a way to change the appearance of Facebook’s Website. Security firm Cheetah Mobile claims that the latest scam has affected more than 10,000 people around the world.

    Don’t fall for this.

    According to Cheetah Mobile, the app advertises the ability to “select your favourite color scheme for facebook layout,” and appears to direct users to “apps.facebook.com/themsandcolors.” But instead, the app sends users to a phishing site.

    Once there, the site asks users to view a tutorial video. Launching the video supposedly provides temporary access to the user’s Access Tokens, letting the malicious site connect to the user’s Facebook friends. If the user doesn’t view the video, the site then attempts to download a pornographic video player on PCs or a bogus malware scanner on Android devices.

    Cheetah Mobile blames a “a vulnerability that lives in Facebook’s app page itself, allowing hackers to implant viruses and malicious code into Facebook-based applications directs users to phishing sites.”

    As Mashable points out, color-changing capabilities have been a popular hook for Facebook malware peddlers in the past. At least two previous scams have gained traction by inviting users to switch the color of Facebook’s blue menu bar. The color changer joins a number of other recurring scams that pose as oft-requested features, including the fabled ”dislike” button and ability to see who viewed your profile.

    What if you need a real Facebook Color Changer?

    There is a legitimate way to change the color of Facebook’s menu bar, using an extension in the Chrome Web Store, but in general it’s best to treat these “feature enhancements” with extreme caution. Just because a friend posts a link your feed doesn’t mean it’s safe to click.

  • Yahoo acknowledges Yahoo Mail hack

    Yahoo acknowledges Yahoo Mail hack

    Have your friends recently texted you about spam originating from your Yahoo Mail account? If so, that may be because you (and many of your friends) were hacked.

    Yahoo acknowledged Thursday that attackers now own an undisclosed number of usernames and passwords to Yahoo Mail accounts. In a blog post, Jay Rossiter, the senior vice president in charge of Yahoo’s platforms and personalization products, wrote that the attackers had most likely hacked an external, third-party database and obtained the information there.

    “We regret this has happened and want to assure our users that we take the security of their data very seriously,” Rossiter wrote.

    Yahoo did not say how many accounts had been compromised, nor when the attacks had taken place. However, the company says it began notifying users that the attacks had taken place, and had begun using second sign-in verification to allow users to re-secure their accounts. Users who have been affected, unsurprisingly, will be asked to change their password, and may receive an SMS text to that effect, Yahoo said.

    Yahoo said that it was working with federal law enforcement to find the culprits and would take further precautions to prevent this from happening again.

    Finally, Rossiter stated the obvious: “In addition to adopting better password practices by changing your password regularly and using different variations of symbols and characters, users should never use the same password on multiple sites or services,” he wrote. “Using the same password on multiple sites or services makes users particularly vulnerable to these types of attacks.”

    In December, Yahoo Mail went down for several days, stranding about 1 million users of the service without email—or word from the company. While the outage began on Monday, it was Friday before CEO Marissa Mayer apologized on behalf of the company.

    However, this week Mayer touted Yahoo Mail and services like Flickr as “a strong foundation for revenue growth,” even as that revenue fell by 6 percent compared with a year ago.

  • Apple device IDs hacked: What you need to know

    Apple device IDs hacked: What you need to know

    A hacker collective known as AntiSec has published over a million Apple device IDs that it claims were captured from the laptop of an FBI agent. If you own an iPhone or iPad, you might be wondering what this hack means to you, and you might also be curious about why the FBI had your Apple UDID in the first place. The information was acquired and released by the hackers as a political statement. The lengthy diatribe posted on Pastebin along with the hacked Apple ID info rants about government oppression and hypocrisy.
    Why does the FBI have 12 million Apple device UDIDs on a laptop?While the group has published one million and one hacked Apple device IDs, it should be given at least a little credit for restraint. The details stolen from the FBI laptop included more personal information as well—such as full names, cell phone numbers, addresses and zip codes.
    According to the letter from AntiSec, there were approximately 12 million Apple device IDs stored in the file on the FBI laptop. It chose to release just a portion rather than publishing all 12 million. AntiSec could have simply published the data it acquired without scrubbing it first, but the point it’s trying to make is against the government and the FBI—not the individuals whose information happened to be in the hands of the FBI.

    Andrew Storms, director of security operations for nCircle, stresses that the Apple device UDID information itself doesn’t really pose a risk to users. “UDIDs in isolation aren’t a big deal. In fact, Apple used to permit apps to spew UDIDs all over the place, so there’s a lot of UDID data already in the public domain. For a while, there were a lot of apps using UDID and personal data to track users activity and selling it to advertisers.”
    But, the hack of an FBI laptop yielding information on 12 million Apple devices does bring up another very valid question. As Storms puts it, “This release does make you wonder what the heck the FBI and the DOJ were doing with 12 million UDIDs. Are they working on a case involving Apple or an app maker? And, assuming there is a legitimate reason for the FBI to have this data, why wasn’t it better protected?”
    I have reached out the FBI Office of Public Affairs seeking an official explanation or statement regarding why the FBI was in possession of the Apple device UDID information at all, as well as whether or not there should have been stronger protection in place to guard such sensitive data. As of this moment, the FBI has not yet responded.
    [Update]
    The FBI has issued a statement flatly denying that the hacked Apple device IDs published by AntiSec came from an FBI computer, or that the FBI is in any way involved in collecting such data in the first place:
    “The FBI is aware of published reports alleging that an FBI laptop was compromised and private data regarding Apple UDIDs was exposed. At this time, there is no evidence indicating that an FBI laptop was compromised or that the FBI either sought or obtained this data.”
    The FBI statement puts the ball back in AntiSec’s court. One side or the other isn’t being completely honest here. AntiSec does seem to be in possession of vast quantity of Apple device ID data. The question is, if the data didn’t come from a hacked FBI laptop, where did the information come from and how did AntiSec acquire it?