Sunday, September 11, 2016

Issue 81- Week of Sep 5th


1.      Russia's largest portal hacked; nearly 100 million plaintext passwords leaked: Another data breach from 2012, and this time, it's Russia's biggest internet portal and email provider Rambler.ru. The portal suffered a massive data breach in 2012 in which an unknown hacker managed to steal nearly 100 Million user accounts, including their unencrypted plaintext passwords. The leaked user records in the database included usernames, email addresses, social account details & passwords. Rambler.ru is the latest victim to join  the list of "Mega-Breaches" revealed in recent months, when Millions of online credentials from years-old data breaches on popular services, including LinkedIn, MySpace, VK.com, Tumblr, and Dropbox were exposed online.

2.      MedSec sued over St. Jude pacemaker vulnerability report: Last issue, we discussed this case. Now, St. Jude Medical is taking allegations of serious security vulnerabilities in the firm's medical devices to heart with a lawsuit designed to "set the record straight." The medical device maker claimed on last week that MedSec and Muddy Waters falsely issued warnings about insecure medical devices in order to intentionally drop the share value of St. Jude and profit from a short-selling scheme, in which investors sell stock with the belief that values will soon drop -- allowing them to buy them back at a lower price and make a profit.

3.      Just an Image can hack your Android phone — Patch now: Similar to last year's Stagefright bug that allowed hackers to hijack Android devices with just a simple text message without the owners being aware of it, a bug has been discovered that Google has now patched. The bug allows attackers deliver their hack hidden inside an innocent looking image via social media or chat apps. In fact, there is no need for a victim to click on the malicious photo because as soon as the image’s data was parsed by the phone, it would quietly allow a remote attacker to take control over the device or simply crash it. Given the shaky history of handset manufacturers and carriers rolling out security patches, it is not known how long the companies will take to update vulnerable Android devices.

4.      FBI arrests two hackers who hacked US Spy Chief, FBI and CIA Director: US authorities have arrested two men on charges that they were part of the notorious hacking group "Crackas With Attitude." A 16-year-old British teenager suspected of being part of the group was arrested in February. These men had hacked into Intelligence chief's and CIA directors email accounts and Phone. They also leaked the personal details of 31,000 government agents belonging to nearly 20,000 FBI agents; 9,000 Department of Homeland Security (DHS) officers and some number of DoJ staffers. The hacking group used social engineering in order to trick the victims into revealing their account number, password, and other details.

5.      US law enforcement throw online scam artists behind bars: US law enforcement has sentenced seven criminals who were part of an online fraud ring which duped victims out of their cash through romance, shopping and job opportunity scams. Scams, phishing emails and job opportunities which land in our inbox are now commonplace. While email providers usually do a good job of keeping these schemes in our spam box, there are still many who fall for such schemes. All the seven criminals will spend five years behind bars.

6.      USB kill to destroy any computer within seconds: A Hong Kong-based technology manufacturer is selling a USB thumb drive called USB Kill 2.0 that can fry any unauthorized computer it's plugged into by introducing a power surge via the USB port. It costs $49.95. The company claims to have developed USB Kill 2.0 stick for the sole purpose of allowing companies to test their devices against USB Power Surge attacks but looks like it can be misused for other purposes as well.

7.      New cross-platform Malware can hack Windows, Linux and OS X Computers: Cyber attackers have started creating cross-platform malware for wider exploitation. One such malware family dubbed as Mokes, has recently been discovered by researchers, which runs on all the key operating systems, including Windows, Linux, and Mac OS X. The malware can capture audio-video, obtain keystrokes as well as take screenshots every 30 seconds from a victim’s machine.

8.      Microsoft Window’s name resolution services abused to steal passwords: A Security researcher has discovered a unique attack method that can be used to steal credentials from a locked computer (but, logged-in) and works on both Windows as well as Mac OS X systems. He modified the firmware code of USB dongle in such a way that when it is plugged into an Ethernet adapter, the plug-and-play USB device installs and acts itself as the network gateway, DNS server, and Web Proxy Auto-discovery Protocol (WPAD) server for the victim's machine. The computer automatically shares Windows credentials with the connected device as it is the default behavior of Microsoft Window’s name resolution services, which can be abused to steal authentication credentials.

9.      Another hack developed for air gapped computers: Researchers have discovered a way to extract sensitive information from air-gapped computers using a combination of a malware + USB. The secure Air gapped computers first need to be infected with a malware, after which when 'any' USB is plugged into that computer, the malware turns the  USB into an RF transmitter. This is a software-only method for short-range data exfiltration using electromagnetic emissions from a USB. Dubbed USBee - this method can transmit data at about 80 bytes per second, which is fast enough to steal a 4096-bit decryption key in less 10 seconds.


10.   NCRB data: India’s cyber criminals are mostly business rivals: The National Crime Records Bureau’s 2015 data shows a wide range of profiles making up the cybercriminal, the most prolific among them being business rivals (20%) followed by 'neighbors, friends or relatives' (15%), Hackers (13%) & Students (10%). Overall, cybercrimes in 2015 - witnessed an increase of 20.5 per cent since 2014. A total 11,592 cases of cybercrime were registered across the country.

Sunday, September 4, 2016

Issue 80- Week of Aug 29th

1.      Dropbox hacked: Hackers have obtained credentials for more than 68 Million accounts of online cloud storage platform Dropbox from a known 2012 data breach. Last week, Dropbox sent out emails alerting its users that a large chunk of its users’ credentials that was obtained in 2012 data breach, may soon be seen on the Dark Web marketplace, prompting them to change their password if they hadn't changed since mid-2012. Dropbox is the latest to join the list of "Mega-Breaches," which includes LinkedIn, MySpace, VK.com and Tumblr.

2.      Kimpton Hotels hit by Point-of-Sale breach: Kimpton Hotels & Restaurants is alerting payment card customers of a payment card breach at more than 60 of its hotels and restaurants that occurred between February 16 and July 7 of this year. The hotel chain said in a message on its website that it first got word of unauthorized charges on guests' payment cards in mid-July. An ensuing investigation uncovered malware on PoS servers at the front desks and restaurants of some of its hotels. "The malware searched for track data read from the magnetic stripe of a payment card and routed it through the affected server. Kimpton's POS woes follow that of Eddie Bauer and HEI Hotels & Resorts, which operates Marriott, Hyatt and Sheraton and Westin hotels.

3.      Music website hacked: UK based - Music website called Last.fm, was hacked in March 2012 and three months after the breach, the company admitted to the incident and issued a warning, encouraging its users to change their passwords. Now, four years later the stolen data has surfaced in the public. The leaked records include usernames, hashed passwords, email addresses, the date when a user signed up to the website, and ad-related data. Last.fm stored its users’ passwords using MD5 hashing – which has been considered outdated even before 2012 – and that too without any Salt. (Salt is a random string added to strengthen encrypted passwords that make it more difficult for hackers to crack them.)

4.      St. Jude says Muddy Waters, MedSec video shows security feature, not flaw: St. Jude Medical, is a medical device company which makes pacemakers. MedSec is a Cyber security firm that specializes in security flaws in medical devices. Muddy Waters Research is a due diligence based investment firm. After a yearlong research by Medsec, it was found that St Jude's products had severe issues. Medsec did not responsibly disclose its findings to St Jude but instead joined hands with Muddy waters to profit in the stock market with this information. St. Jude has refuted the allegations and has issued a statement saying the supposed “flaw” was actually a “security feature. If attacked, the pacemakers place themselves into a 'safe' mode to ensure the device continues to work.

5.      Double Whammy - Ransomware steals data before Encrypting: Betabot, the first known weaponized password-stealing malware that also infects victims with ransomware in a second stage of attack. In many instances it is still able to evade detection, it uses the Neutrino exploit kit, which uses infected documents disguised as CVs to ask the victim to enable macros. If they do, the malware is able to steal login data and passwords from web browsers. The Trojan then downloads and installs the Cerber ransomware onto the victim's computer, demanding the user pays up in order to regain access to their compromised machine.

6.      ‘Guccifer’ gets 52-month Jail term: Romanian hacker “Guccifer,” who pleaded guilty in May this year to hacking and identity theft of around 100 high-profile Americans, has been sentenced to 52 months in prison by a US court. Guccifer hacked the email and social media accounts of his victims between October 2012 and January 2014 and made public confidential emails, photographs and private medical and financial data. Not to confuse with Guccifer 2.0, the hacker behind the DNC hack.

7.      Suspect arrested for 2011 Linux Kernel organization breach: In September 2011, kernel.org site that hosts the core development infrastructure behind the Linux kernel was breached. For the last five years, not many details about the attack were revealed and the attacker remained at large—that is, until he was picked during a traffic stop in Miami - last week. The hacker had managed to steal login credentials of one of the Linux Kernel Organization system administrators in 2011 and used them to install a hard-to-detect malware backdoor, dubbed Phalanx, on servers belonging to the organization. Using this backdoor, he installed malware on various Linux installations. He faces a possible sentence of 40 years in prison as well as $2 Million in fines. Threat protection for Linux can help in such situations.

8.      California may soon treat Ransomware as extortion: Ransomware may soon be regarded as a form of extortion in California once legislation is approved by governor. The Bill if passed, could land culprits in jail for two to four years. The move has received widespread support from different quarters that want ransomware attacks to be treated as a felony. The state’s law enforcement unit and the tech sector all support the legislation.

9.      SWIFT reveals new hacking attempts on member Banks: SWIFT has revealed new hacking attempts on several member banks following its June disclosure of the $81-million Bangladesh Bank heist and is pushing members to comply with new safety features. "The threat is persistent, adaptive and sophisticated - and it is here to stay," SWIFT told the banks. SWIFT members have been warned that failure to meet a November 19 deadline for installing latest security software would be reported to banking regulatory bodies and partners.


10.   India registers 350 percent rise in cybercrime in last three years: According to a study, in India, there has been a surge of approximately 350% in cybercrime cases registered under the Information Technology (IT) Act, from the year of 2011 to 2014. The Indian Computer Emergency Response Team (CERT-In) has also reported a surge in the number of incidents handled by it, with close to 50,000 security incidents in 2015. Bangalore leads in the number of cybercrime cases, the city recorded 1,041 cybercrime cases in 2015, the highest among the country's 53 mega cities, and a 42% increase over the 2014 figures. State-wise data shows the worst states to be: Maharashtra (2,195 cases) and Uttar Pradesh (2,208). Most cases relate to credit card fraud, email hacking and online cheating, including fake lottery scams. Use of technology and building awareness can reduce cybercrime.
Image source: Times of India

Sunday, August 28, 2016

Issue 79- Week of Aug 22nd


1.      Scorpene leak: The Scorpene-class submarines are developed a French company called DCNS. A former French Navy officer who quit the service in the early 1970s and worked for French defense companies for more than 30 years before becoming a subcontractor to DCNS - copied sensitive data from DCNS along with a French colleague and took it to a Southeast Asian country, where they were employed in a private company. This 22,400 page sensitive data was then stored in one of the company servers. In 2013, they both were sacked and the company found their replacement in Australia, with whom the company shared this data over the internet. Last week, the information on the Scorpene submarine and excerpts have been released by 'The Australian' newspaper.  The person plans to surrender the disk to the Australian government on Monday. Indian Defense Minister Manohar Parrikar played down the leak, saying it is "not a big worry".

2.      Apple releases 'Emergency' patch after advanced spyware targets human rights Activist: Apple has released iOS 9.3.5 update for iPhones and iPads to patch three zero-day vulnerabilities after a piece of spyware was found targeting the iPhone used by a renowned UAE human rights defender. NSO Group, which sells spying and surveillance software, has been exploiting three zero-day security vulnerabilities in order to spy on dissidents and journalists. The zero-day exploits have allowed the company to develop sophisticated spyware tools that can access the device location, contacts, texts, calls logs, emails and even microphone. Apple fixed these three vulnerabilities within ten days after being informed. Apple had recently announced a bug bounty reward of up-to US$200K.

3.      ATMs in Thailand hacked; 12 Million Baht stolen; 10,000 ATMs prone to hackers: An Eastern European gang of criminals has stolen over 12 Million Baht (approx. US$350k) from a total of 21 ATMs in Bangkok and other five provinces by hacking a Thai bank's ATM network. Hackers were able to infect the GSB (Govt. Savings Bank)'s ATM machines by inserting malware infected cards into it and then making it spew out up-to 40k Bhat for every transaction.

4.      Mail.ru forums hacked: Over 25 million accounts associated with forums hosted by Russian internet giant Mail.ru have been stolen by hackers. The databases were stolen in early August, according to breach notification site LeakedSource.com, which obtained a copy of the databases. The hackers' names aren't known, but they used known SQL injection vulnerabilities found in older vBulletin forum software to get access to the databases. In the recent past, using outdated software has led to hacking of Steam Game Forums and Clash of Kings Forums.

5.      Wildfire Ransomware code cracked: Victims of the Wildfire Ransomware can get their encrypted files back without paying hackers the ransom, after the ‘No More Ransom’ initiative released a free decryption tool. ‘No More Ransom’ runs a web portal that provides keys for unlocking files encrypted by various strains of ransomware, including Shade, Coinvault, Rannoh, Rakhn and, most recently, Wildfire. The Ransom was for 1.5 Bitcoins (1 Bitcoin = US$575) and the victims were Dutch speakers from Netherlands and Belgium. Meanwhile in India - Shri Dhanvantari Herbals - An Indian Ayurvedic pharmaceutical company based in Punjab has been hit by Ransomware.

6.      Dropbox prompts users to reset old passwords: Dropbox is asking users to change their old passwords as part of a "preventative measure". In a blog post, the file-sharing and cloud storage company called out to users who haven't changed their passwords since mid-2012, saying the login credentials are potentially at risk and should be updated. As is often the case, some people reuse their usernames and passwords across different web services, when anyone of them is compromised like LinkedIn or MySpace did, it leads to Password reuse attacks.

7.      Opera browser reports breach: The company revealed that attackers gained access to Opera Sync, a service that lets users synchronize their browser data and settings across multiple platforms. It is investigating the incident, but initially believes the attack may have compromised user data, including passwords and login names. Opera counts 350 million users across its range products with 1.7 million Sync users. The company has reset all passwords and emailed all registered Opera sync users with details.

8.      Leaked Exploits are Legit and belong to NSA- Cisco & Fortinet confirm: Last issue we discussed about the NSA hack and its leaked hacking tools. NSA was systematically spying on customers of big technology companies like Cisco, Fortinet, and Juniper for at least a decade. After a thorough investigation, Cisco confirmed the authenticity of these exploits, saying that these hacking tools contain exploits that leverage two security vulnerabilities affecting Cisco ASA software designed to protect corporate and government networks and data centers.  Fortinet, also warned of a high-risk vulnerability leaked in the NSA hack, which affects older versions of its FortiGate firewalls. The identity of the hackers-'The Shadow Brokers' is still
8.a mystery.

9.      GozNym Trojan spreads to attack German banks: Last week, Researchers confirmed that the financial malware, a Trojan discovered in April this year, has recently targeted 13 German banks and their local subsidiaries. The hybrid malware (Gozi ISFB Malware + Nymaim malware), includes an exploit kit dropper, web-injection capabilities, encryption, anti-VM, and control flow obfuscation, making the malware persistent, difficult to detect, and also very powerful. The malware sends victims to fraudulent, carbon-copy websites of financial institutions in order to lure them into parting with their online banking details.

10.   170 cyber frauds in 7 months in Visakhapatnam: In the past seven months, Vizag has registered 170 cyber fraud cases, of which 110 are related to siphoning off of money from bank accounts. The spurt in one-time passwords (OTP) frauds has left the police befuddled. “Despite several warnings, citizens fall prey to conmen and share confidential details. NIST (US National Institute of Standards and Technology) has declared -SMS-based Two-Factor Authentication (2FA), to be insecure.


Image Courtesy: The Australian

Sunday, August 21, 2016

Issue 78- Week of Aug 15th


1.       NSA's hacking group hacked! Bunch of private hacking tools leaked online: Last week, unknown hackers calling themselves "The Shadow Brokers,"  hacked into NSA (US Intelligence agency)-- and dumped a bunch of its hacking tools (malware, private exploits, and hacking tools) online. The hackers are offering to sell more private "cyber weapons" to the highest bidder. The files mostly contained installation scripts, configurations for command-and-control (C&C) servers, and exploits allegedly designed to target routers and firewalls from American manufacturers. Last year, a company called Hacking Team was hacked and its tools were similarly leaked.

2.       Retailer says point of sales system was infected with malware: US retailer Eddie Bauer had said that hackers may have accessed customers' payment card information after infecting its point-of-sale systems with malware. The company says it's in the process of identifying customers whose payment information may have been stolen and will notify those who've been affected and is also working with payment card networks so that they can coordinate with card issuing banks to monitor for fraudulent activity. Wendy’s is the another recent example of such PoS attacks.

3.       Insider attack at Sage: Last week, Sage - a provider of accounting and business software for companies worldwide, admitted to a data breach caused by someone accessing internal systems with employee credentials rather than an external cyber attacker. A female Sage employee has been arrested from London Airport, following the data breach which may have exposed information belonging to hundreds of business customers. Cyber-attacks are on the rise, and now, businesses not only have to deal with the threat of external attackers but insider threats as well. According to experts, 55 percent of all corporate cyber-attacks are either caused by malicious employees or through accidental, human error on the inside.

4.       Another site hacked because it was not patched: DLH.net which provides Steam game related news, reviews, cheat codes, and forums, was breached using a known vulnerability found in older vBulletin forum software, which powers the site's community. The data stolen from the forum includes full names, usernames, scrambled passwords, email addresses, dates of birth, join dates, avatars, Steam usernames, and user activity data. The company is denying any breach though it is asking its users to change their passwords. Clash of Kings forum was hacked recently for similar reasons.

5.       Ransomware in Ranchi: Ransomware has become a modern form of extortion, with a small town like Ranchi reporting more than 3 dozen Ransomware cases in the past fortnight. Till date, the victims have been automobile companies, Software consultants providing services to the Govt. of Jharkhand, Medical establishments and few small wholesale traders. In its advisory, the Govt. of India  has advised not to pay ransom, as it doesn't guarantee the release of the files. Affected users should report such instances of fraud to computer emergency response team (CERT) and law agencies. India continues to be one of the top Victim countries and last week the Finance minister revealed that a major attack on the public banking system in India was averted. In May this year - there was a major Ransomware attack in Maharashtra’s Mantralaya. Other news from India - Websites of Sagar university and Goa Institute of Management were defaced by Pakistani hackers.

6.       Clinton Foundation suspected to have been hacked: Bill and Hillary Clinton's charitable foundation hired experts to examine its data systems after seeing indications they might have been hacked. Though no message or document hacked from the New York-based Clinton Foundation has surfaced in public, Democrats are worried that leaked info may be used to attempt damage the campaign. The hack is very similar to the techniques used in the DNC hack and DCCC hack.

7.       'Massive' Locky Ransomware campaign targets hospitals: A 'massive' cybercriminal campaign is targeting hospitals with the notorious Locky Ransomware and is using a new technique in an effort to infect systems with the file encrypting software. Hospitals are an appealing target for cybercriminals to infect with Ransomware not only because of the crucial role of IT in healthcare, but also because the data held by hospitals is so vital. Earlier this year a Los Angeles hospital paid a $17,000 Bitcoin ransom after a Locky infection took down its network.

8.       VeraCrypt security audit is being spied upon: VeraCrypt is an open-source freeware utility used for on-the-fly encryption. OSTIF (The Open Source Technology Improvement Fund) announced at the beginning of this month that it had agreed to audit VeraCrypt independently. Last week, the OSTIF announced that its confidential PGP-encrypted communications with the auditors were mysteriously intercepted and it suspects some outsiders are attempting to listen in on and/or interfere with the VeraCrypt security audit process.

9.       Post Bitfinex hack; Bitcon.org is worried: Recently, Hong Kong based crypto currency exchange-Bitfinex, was hacked resulting in a loss of around $72 Million worth of Bitcoins. Last week, Bitcoin.org, the website that hosts downloads for Bitcoin Core, posted a message on its website warning users that the next version of the Bitcoin Core wallet, one of the most popular bitcoin wallets used to store bitcoins, might be replaced with a malicious version of the software offered by government-backed hackers. The advisory also went on to say that one should securely verify the signature and hashes before running any Bitcoin Core binaries.

10.   Chat service can be hacked: Omegle is a free online chat website that allows users to socialize with others without the need to register. The service randomly pairs users in one-on-one chat sessions where they chat anonymously. The anonymity encourages users to talk dirty and sometimes share identifiable info. Unfortunately, the chat conversations are recorded and stored on their servers. An Indian bug bounty hunter, found a way to hack into these servers to access these conversations. One should be careful with what identifiable information you are sharing over such online service while chatting with strangers. The more personal information you share, the more chances there are for others to blackmail or misuse the information.



Sunday, August 14, 2016

Issue 77- Week of Aug 8th


1.       Data Breach — Oracle's Micros payment systems hacked: Oracle has confirmed that its Point-of-Sale (MICROS) division has suffered a security breach. Hackers had infected hundreds of computers at the division, infiltrated the support portal used by customers, and potentially accessed sales registers all over the world.  It is likely that hackers installed malware on the troubleshooting portal in order to capture customers' credentials as they logged in. These usernames and passwords can be used to access customer accounts and remotely control their MICROS point-of-sales terminals. POS terminals have emerged as the favorite target for cybercriminal gangs- Two of the best-known victims to be hit by POS malware are Target and Home Depot.

2.       DNC hacker leaks personal info of nearly 200 Congressional Democrats: The hacker behind the DNC hack has claimed responsibility for hacking into the Democratic Congressional Campaign Committee (DCCC) as well. Last week, to prove his claims, the hacker dumped a massive amount of personal information belonging to nearly 200 Democratic House members onto his blog. The dumped data also contains passwords to access multiple DCCC accounts. The hacker goes by the name Guccifer 2.0

3.       Pune based Indian Manufacturing Co. loses $175k: Very similar to the modus operandi of ONGC scam, hackers send an email to Kinetic Electrical Company that looked like, it had originated from its Taiwan based supplier (Typosquatting). The fake email informed the company about supplier's new bank account and asked the next advance payment to be transferred to new account. Pune company officials promptly transferred $175k (1.18 Crore) to the account and were waiting shipment. After three months when the shipment did not arrive they called Taiwan to realize the scam. Ronnie Screwvala's NGO lost $50k recently in similar fashion. Finance and purchase departments should call the recipients of funds (Suppliers or CEO) whenever there is bank change request. This hack is also called BEC - Business Email Compromise.

4.       Pakistan-based hacker defaces Canara Bank site, tries to block e-payments: According to a statement issued by Canara bank, a Pakistani hacker defaced the bank’s home page and also tried to block certain online transactions but failed to access any data or transactions. Within hours of the attack, the Reserve Bank of India, alerted all banks to double check the SWIFT payments. With the recent $81 Million hack on Bangladesh bank - one should not take any chances.

5.       United Airlines pays bug bounty in Air Miles: Two computer hackers have earned more than 1 Million frequent-flyer miles each from United Airlines for finding and reporting multiple security vulnerabilities in the Airline's website. Last year - United Airlines had rewarded 1 Million Air Miles to a vulnerability researcher for identifying remote  code execution (RCE) vulnerabilities in its web properties. Many companies including Apple, Twitter, Pentagon, Pronhub etc offer bug bounties.

6.       Blackhat Firm Offers $500,000 for Zero-day iOS Exploit; Double Than Apple’s Highest Bounty: Issue 76, we discussed Apple's $200k bug bounty Reward. A blackhat company is now offering more than double Apple's maximum payout for zero-day vulnerabilities affecting the newest versions of iOS 9.3 and above. Last year, a security firm paid $1 Million to a group of hackers for an iPhone hack. The zero-day market has long been a lucrative business because governments, law enforcements, criminals, and the private sector shop for zero-days. In recent times, we have seen FBI paying more than $1M to hack into a terrorist's phone.

7.       Over 900 Million Android Phones vulnerable to new 'QuadRooter' attack: A high security alert for Android devices was issued last week. Dubbed "Quadrooter," the set of four vulnerabilities discovered in devices running Android Marshmallow and earlier that ship with Qualcomm chip could allow an attacker to gain root-level access to any Qualcomm device. An attacker needs to trick a user into installing a malicious app to exploit one of the four vulnerabilities which will give the attacker full access to the device, including its data, camera and microphone. Last year, 1 Billion Android phones were under risk due to the Stagefright vulnerability. Users getting their Android OS updated is a messy affair as it involves Google, Device manufacturer and Telcos.

8.       Linux TCP flaw allows Hackers to hijack Internet traffic and Inject Malware remotely: Linux is used widely across the Internet, from web servers to Android smartphones, tablets, and smart TVs. Researchers have uncovered a serious Linux flaw, which if exploited, could allow attackers to terminate or inject malware into unencrypted communication between any two vulnerable machines on the Internet. The flaw resides in the design and implementation of the Request for Comments: 5961 (RFC 5961) – a relatively new Internet standard that's designed to make commonly used TCP more robust against hacking attacks.

9.       Car Thieves can unlock 100 Million Volkswagens with a simple wireless hack: Every car that Volkswagen group has sold since 1995 can be unlocked using a simple $40 device. The device first listens to the rolling code values used by keyless entry systems whenever the driver presses the key fob's buttons. These codes along with the cryptographic key that was extracted from the Volkswagen network, are used to clone the key fob and access to the car. In past 20 years, only four common keys are used in all the 100 Million cars sold by Volkswagen.

New hack uses Hard Drive's noise to transfer stolen data from Air-gapped Computer: For security reasons, many super sensitive networks like that of Defense and research organizations have computers that are not connected to internet (Air-Gapped computers). Now, researchers have devised a new method to steal data from such Air Gapped computers. The first step is that such computers are infected with a malware which is capable of transmitting data like passwords, cryptographic keys, etc, via covert Hard Drive noise. The malware manipulates the movements of the Hard drive coil in very specific way to generate acoustic noise (like morse code) that is interpreted into binary data using a smartphone app from six feet away.




Sunday, August 7, 2016

Issue 76 - Week of Aug 1st