Showing posts with label cyber. Show all posts
Facebook's 'Color Change' Malware is Back
The color change scam tricks users into downloading malware via a site that claims to let users change the colors of their Facebook profile. The latest iteration of the scam has already affected more than 10,000 people around the world, according to Cheetah Mobile, a Chinese Internet company that highlighted the most recent appearance of the scam in its blog.
The malware begins by advertising an app that tells Facebook users they can change the color theme of their profile. Download the app and you're directed to a malicious phishing site, according to Cheetah Mobile's security researchers.
The website targets users in two ways. First it steals the users' Facebook Access Tokens by asking them to view a color changer tutorial video. Temporary access to the tokens allows hackers to connect to the user’s Facebook friends. If a user doesn’t view this video, the site then tries to get them to download the malicious application. If a user is on a PC, the site leads them to download a pornographic video player. If the user is on an Android device, the site issues a warning saying the device has been infected and advises users to download a suggested app.
The problem, according to Cheetah Mobile, stems from "a vulnerability that lives in Facebook’s app page itself, allowing hackers to implant viruses and malicious code into Facebook-based applications that directs users to phishing sites." Anyone who has already fallen victim to the scam should uninstall the app immediately (this can be done from the "app" menu in your Facebook settings) and change their Facebook password.
Monday, 11 August 2014
Posted by Unknown
Yahoo, Google Envision Spy-Free Emails
Yahoo said Thursday it will join an effort by rival Google Inc. Google to create a secure email system by next year that could make it nearly impossible for hackers or government officials to read users' messages. Even the email providers themselves won't be able to decrypt messages.
Google in June announced plans to develop
spy-proof email. The addition of Yahoo is notable because the two have
access to so many email users and Yahoo shed new details on the project.
Google counts 425 million unique Gmail users, Yahoo 110 million.
Microsoft,
which offers the free Web email service Outlook.com, has previously
said it is working to incorporate encryption technologies into the
service formerly known as Hotmail. Microsoft says there are more than
400 million active accounts in Hotmail and Outlook.com. Yahoo
and Google say the encryption tool will be an optional feature that
users will have to turn on. Engineers at the technology firms—bitter
competitors in many fields—frequently talk to each other about the
project, people at both companies say.
The
tool will rely on a version of PGP encryption, a long-tested way of
scrambling data that hasn't yet been cracked. Unlike traditional webmail
services that rely on tech companies holding passwords and usernames
for consumer accounts, PGP relies on users having their own encryption
key stored on laptops, tablets and smartphones.
Mr. Soghoian said Yahoo and Google are taking early steps toward making
the technology easier for normal consumers. Executives at both companies
expect few users to adopt the technology immediately. Yahoo
has altered its email process so users adopting encryption type
messages in a separate window, preventing even Yahoo from reading the
messages as they are typed. Mr. Stamos said his team is testing ways to
get encryption keys on mobile devices. Yahoo
also has to explain to users how PGP works and that it isn't a panacea
for privacy concerns. For instance, it only encrypts the content of
messages—not the data on who sends and receives the messages or the
subject line.
Russian Hacker Group Steals 1.2 Billion Internet User Passwords
The hackers pulled off the data heist, which ultimately scooped up 4.5 billion records, using unsuspecting systems of botnet network victims (in this case, computers with viruses that allowed a single operator to control a large group of affected systems) to test websites for SQL vulnerabilities. When a vulnerability was discovered, the hackers were then able to execute SQL injections, enabling them to send malicious commands to a website and steal its data, including usernames and passwords.
The group managed to steal information from 420,000 web and FTP sites, Hold Security said.
Hold Security's blog post, which details the data breach, also promotes its own services. However, an independent security expert hired by The New York Times confirmed its findings. "Your data has not necessarily been stolen from you directly," the blog post said. "It could have been stolen from the service or goods providers to whom you entrust your personal information, from your employers, even from your friends and family."
The Russia-based cyber gang is comprised of a dozen men in their 20s who began as amateur spammers by buying information on the online black market back in 2011, The New York Times reported. Ironically, the hacking revelation has come during the Black Hat computer-security conference in Las Vegas, which takes place from Aug. 2 to 7.
The Times said Hold Security is trying to develop an online tool to help individual users identify whether or not they were impacted by the data breach. Those who use the Internet for online banking and shopping will likely be the most troubled by the company's report. As for businesses, they are advised to immediately run a check to see if their websites are vulnerable to SQL injections.
"If you haven’t updated your password recently, now would be the time," Adam Kujawa, head of malware intelligence at security company Malwarebytes Labs, told Mashable. "Make sure it’s a strong password containing capital and lowercase letters, numbers and special characters. Also, don’t use the same username and password combo for every site. This is especially true for sites that have personal information like the site to your bank or credit card."
Courtesy : Mashable







