Showing posts with label Security News. Show all posts
Showing posts with label Security News. Show all posts
Wednesday, June 27, 2012

U.S. arrests 24 suspected hackers in a major sting operation

U.S. law enforcement officials have claimed to have arrested 24 suspected hackers ageing between 18 to 25 involved in online financial fraud of stolen credit cards and bank information.

In a two-year investigation, FBI agents posed as hackers on Internet forums, watching as other hackers swapped methods for breaching data security walls and creating fake credit cards that would work for Internet and in-person purchases.

The probe prevented $205 million in possible losses on over 411,000 compromised consumer credit and debit cards, U.S. authorities in New York said.

Eleven people were arrested in the United States, the Federal Bureau of Investigation and the Manhattan U.S. Attorney's office said. The thirteen others were arrested in countries from Britain to Japan, the authorities said. Officials in Australia also conducted searches.

"Clever computer criminals operating behind the supposed veil of the Internet are still subject to the long arm of the law," Manhattan U.S. Attorney Preet Bharara said.

During the operation, the FBI said, it not only monitored the hackers' activities but also contacted "multiple" people and institutions hit by the hackers and showed them how to repair their security breaches and protect themselves in the future. No credit card companies or banks were named in Tuesday's court documents. Some face up to 40 years or more in prison if convicted on conspiracy to commit wire fraud charges and access device fraud charges.

The FBI operation centered around a "carding forum" that it had secretly created in June 2010, and was in charge of running unbeknownst to its participants, authorities said.

The forum, called "Carder Profit," was essentially an online market for registered users to exchange stolen account numbers. It was shut down in May.

Two people were arrested in the New York area and were later released on bail after appearing in Manhattan federal court.

One of the men, Mir Islam, known online as "JoshTheGod," was charged with trafficking in 50,000 stolen credit card numbers. Authorities said Islam had admitted to helping emerging hacker outfit UgNazi, which said it had launched a cyber attack against the microblogging platform Twitter last week.

Islam, 18, who lives in the New York borough of the Bronx, appeared before U.S. Magistrate Judge James Francis in flip-flop sandals and jeans. His parents, who are from Pakistan, watched the proceeding from a back bench. Islam was released on a $50,000 bond.

Fellow Bronx resident Joshua Hicks, 19, also known as "OxideDox," was charged with one count of access device fraud. Wearing red basketball shorts, Hicks was released on a $20,000 bond after a brief hearing before the same judge. Read more here.

Sunday, January 29, 2012

Android Apps found to be Distributing Malware

A new variation of an Android malware identified by Symantec engineers has infected around one to five million downloads — "the highest distribution of any malware identified so far this year."

The combined total downloads of those apps could be as high as five million. You can see the malicious apps above. Reported by Symantec official blog, Symantec has identified 13 apps on the Android Market that are all hiding Android.Counterclank, a Trojan horse that steals information. This malware could also download more files and even display ads on the device.

Per symantec, "The combined download figures of all the malicious apps indicate that Android.Counterclank has the highest distribution of any malware identified so far this year."

Wednesday, January 25, 2012

eIQnetworks Webinar on How to Address Advanced Persistent Threats without Increasing Budgets or Personnel

eIQnetworks’ Unified Situational Awareness Platform Provides Comprehensive Approach to Dealing with Increasingly Complex Cyber and Insider Threats.

Acton, Mass. – Jan. 25, 2012 – eIQnetworks®, Inc., the only global provider of a unified situational awareness solution, today published a webinar entitled, “Proactive Threat Discovery and Risk Mitigation Demands Situational Awareness,” featuring leading analyst firm, Gartner. John Pescatore, vice president and research fellow in Gartner Research and John Linkous, vice president, chief security and compliance officer at eIQnetworks, discuss why unified situational awareness is critical to detecting and mitigating today’s advanced threats including advanced persistent threats (APTs) and WikiLeaks-style insider threats.
“To effectively and efficiently deal with both advanced targeted threats and changing business demands, enterprises need to proactively evolve their security controls and monitoring,” commented John Pescatore, vice president in Gartner Research. “Security programs need to move from reactively monitoring log events to developing situational awareness that supports rapid reaction and threat analysis along with continuous monitoring of security status.”

“We believe eIQnetworks’ SecureVue® is the only solution that delivers on all the capabilities that Gartner outlined for situational awareness in its most recent research note on the topic [“Delivering Situational Awareness” - ID# G00214313],” commented John Linkous, eIQnetworks’ vice president, chief security and compliance officer. “This is because SecureVue has been designed to deliver a more proactive approach by cross-correlating all security, threat and compliance data into one platform, rather than the limited security data analysis used by SIEM and SIEM Plus vendors that results in data gaps. The outcome is a single console, yielding a real-time, unified view of the entire enterprise’s security, risk and compliance posture.”  To view the webinar, “Proactive Threat Discovery and Risk Mitigation Demands Situational Awareness,” visit: http://www.eiqnetworks.com/resources/gartnerandeiqnetworks_webinar.php. 

For more information on situational awareness, visit: http://www.eiqnetworks.com/solutions/situational_awareness.php. 

About eIQnetworks: eIQnetworks is the only global provider of a unified situational awareness solution, serving the largest enterprises around the world including government, financial, telecommunications, retail, pharmaceutical and healthcare. The company’s unified situational awareness platform, SecureVue®, delivers an accurate, timely and coherent view of the threat, compliance and risk posture via a single console. SecureVue provides real-time continuous security monitoring, compliance automation, configuration auditing and forensic analysis, all in a single solution. Vital to the protection of an organization’s infrastructure, SecureVue helps global enterprises proactively protect against cyber attacks, advanced persistent threats (APTs), data breaches and policy violations, so they can respond to incidents and implement security best practices. eIQnetworks is a privately held company headquartered in Acton, Mass.

Monday, December 26, 2011

Hacking Group hit US security firm Stratfor

An internet hacking group is claiming to have stolen a wealth of emails and credit-card information about clients of US-based security company Stratfor.

The group, Anonymous, says the company's clients include the US defence department, army, air force, law enforcement agencies, top security contractors and technology firms such as Apple and Microsoft.
The activists say they were able to obtain the information because the company did not encrypt it.

In an email to its members, Stratfor said it was suspending its email and servers, and was working closely with law enforcement to identify those responsible.

It also said the disclosure was "merely a list of some of the members that have purchased our publications and does not comprise a list of individuals or entities that have a relationship with Stratfor".

Anonymous has been involved in scores of hacking exploits, including the recent defacing of a website of Syria's Ministry of Defence to protest against a bloody crackdown on anti-government protesters. Last year, it launched retaliatory attacks on companies perceived to be enemies of the anti-secrecy website WikiLeaks.

Source: http://www.radionz.co.nz/news/world/94713/hackers-hit-us-security-firm

Wednesday, November 9, 2011

iPhone apps vulnerability discovered, researcher faces 1 year ban

Some news from smartphone security arena. iPhone is the first that comes in mind when talking about smartphone and with iPhone comes iPhone apps.

Apple’s iPhone apps have always been considered the safe alternative to Android. Unlike the Android marketplace, Apple screens all its apps before posting them for use. One researcher, however, discovered a bug in their screening process that would potentially allow hackers access to your phone. And, what he gets in return is punishment from Apple!

Charlie Miller, a researcher at Accuvant and one of the world's best-known Apple hackers, said,

Until now, you could just blindly trust and download as many apps as you wanted and not worry about it, but until they fix this, you really should think twice about any apps you're downloading, because they could be malicious.

Miller said he told Apple about the issue and the company told him that a fix was impending. He says he exposed the bug so that Apple could fix the issue before a malicious hacker started stealing information from customer’s iPhones. What did he get in return for his help? Apple banned him from the iOS developer program for a year.

I think it's pretty rude. If you think about what I'm doing- I'm pointing out a flaw that would affect everybody and that the bad guys could use to install malware (malicious software). And they're not paying me, I'm just doing it to be nice.

If hackers found the flaw and exploited it, the results could be disastrous.

Read more here: http://electricego.crinz.com/634/iphone-bug-for-hackers