Microsoft Announces Windows 10 BlackBerry Launches Passport in India for Rs. 49,990 The World's Slimmest SmartPhone : Gionee Elife S5.1 iOS 8 Has Finally Arrived Apple Unveils iPhone 6 and iPhone 6 Plus

Showing posts with label cyber. Show all posts

Facebook's 'Color Change' Malware is Back


The color change scam tricks users into downloading malware via a site that claims to let users change the colors of their Facebook profile. The latest iteration of the scam has already affected more than 10,000 people around the world, according to Cheetah Mobile, a Chinese Internet company that highlighted the most recent appearance of the scam in its blog.

The malware begins by advertising an app that tells Facebook users they can change the color theme of their profile. Download the app and you're directed to a malicious phishing site, according to Cheetah Mobile's security researchers.

The website targets users in two ways. First it steals the users' Facebook Access Tokens by asking them to view a color changer tutorial video. Temporary access to the tokens allows hackers to connect to the user’s Facebook friends. If a user doesn’t view this video, the site then tries to get them to download the malicious application. If a user is on a PC, the site leads them to download a pornographic video player. If the user is on an Android device, the site issues a warning saying the device has been infected and advises users to download a suggested app.

The problem, according to Cheetah Mobile, stems from "a vulnerability that lives in Facebook’s app page itself, allowing hackers to implant viruses and malicious code into Facebook-based applications that directs users to phishing sites." Anyone who has already fallen victim to the scam should uninstall the app immediately (this can be done from the "app" menu in your Facebook settings) and change their Facebook password.
Monday, 11 August 2014
Posted by Unknown

Yahoo, Google Envision Spy-Free Emails

 
Yahoo said Thursday it will join an effort by rival Google Inc. Google to create a secure email system by next year that could make it nearly impossible for hackers or government officials to read users' messages. Even the email providers themselves won't be able to decrypt messages.

Google in June announced plans to develop spy-proof email. The addition of Yahoo is notable because the two have access to so many email users and Yahoo shed new details on the project. Google counts 425 million unique Gmail users, Yahoo 110 million.

Microsoft, which offers the free Web email service Outlook.com, has previously said it is working to incorporate encryption technologies into the service formerly known as Hotmail. Microsoft says there are more than 400 million active accounts in Hotmail and Outlook.com. Yahoo and Google say the encryption tool will be an optional feature that users will have to turn on. Engineers at the technology firms—bitter competitors in many fields—frequently talk to each other about the project, people at both companies say.

The tool will rely on a version of PGP encryption, a long-tested way of scrambling data that hasn't yet been cracked. Unlike traditional webmail services that rely on tech companies holding passwords and usernames for consumer accounts, PGP relies on users having their own encryption key stored on laptops, tablets and smartphones.

Mr. Soghoian said Yahoo and Google are taking early steps toward making the technology easier for normal consumers. Executives at both companies expect few users to adopt the technology immediately. Yahoo has altered its email process so users adopting encryption type messages in a separate window, preventing even Yahoo from reading the messages as they are typed. Mr. Stamos said his team is testing ways to get encryption keys on mobile devices. Yahoo also has to explain to users how PGP works and that it isn't a panacea for privacy concerns. For instance, it only encrypts the content of messages—not the data on who sends and receives the messages or the subject line.

Russian Hacker Group Steals 1.2 Billion Internet User Passwords


A U.S. security firm has uncovered what appears to be the largest Internet security breach in recent memory, conducted by a group of Russia-based hackers. According to Milwaukee-based firm Hold Security, which conducted an 18-month investigation into the breach, the online gang stole 1.2 billion username and password combos, as well as more than 500 million email addresses.

The hackers pulled off the data heist, which ultimately scooped up 4.5 billion records, using unsuspecting systems of botnet network victims (in this case, computers with viruses that allowed a single operator to control a large group of affected systems) to test websites for SQL vulnerabilities. When a vulnerability was discovered, the hackers were then able to execute SQL injections, enabling them to send malicious commands to a website and steal its data, including usernames and passwords.
The group managed to steal information from 420,000 web and FTP sites, Hold Security said.

Hold Security's blog post, which details the data breach, also promotes its own services. However, an independent security expert hired by The New York Times confirmed its findings. "Your data has not necessarily been stolen from you directly," the blog post said. "It could have been stolen from the service or goods providers to whom you entrust your personal information, from your employers, even from your friends and family."

The Russia-based cyber gang is comprised of a dozen men in their 20s who began as amateur spammers by buying information on the online black market back in 2011, The New York Times reported. Ironically, the hacking revelation has come during the Black Hat computer-security conference in Las Vegas, which takes place from Aug. 2 to 7.

The Times said Hold Security is trying to develop an online tool to help individual users identify whether or not they were impacted by the data breach. Those who use the Internet for online banking and shopping will likely be the most troubled by the company's report. As for businesses, they are advised to immediately run a check to see if their websites are vulnerable to SQL injections.
"If you haven’t updated your password recently, now would be the time," Adam Kujawa, head of malware intelligence at security company Malwarebytes Labs, told Mashable. "Make sure it’s a strong password containing capital and lowercase letters, numbers and special characters. Also, don’t use the same username and password combo for every site. This is especially true for sites that have personal information like the site to your bank or credit card."

Courtesy : Mashable
Thursday, 7 August 2014
Posted by Unknown

Categories

Designed by Cyber Freak

News Flash


Blog Archive

Powered by Blogger.

Copyright © Cyber Era News. All rights reserved.- Powered by Eravations - Designed by Shantanu Chauhan -