Posts

Showing posts from January, 2018

Ransomware virus attack: in India

Image
Ransomware virus attack: India faces unique threat, here is how Modi government is tackling the menace Ransomware virus attack: Smart power grid systems in India are vurnerable to deadly virus Wannacry ransomware. It has been learnt that aftermath of the deadly Ransomware virus attack last year, Central Electricity Authority (CEA) has advised an 'urgent' need to develop a cyber security framework   January 24, 2018  Ransomware virus attack:  After that the Wannacry ransomware attack in May 2017 had affected computers and systems in 150 countries, including India. Ransomware virus attack:  Smart power grid systems in India are vurnerable to deadly virus Wannacry ransomware. It has been learnt that aftermath of the deadly Ransomware virus attack last year, Central Electricity Authority (CEA) has advised an ‘urgent’ need to develop a cyber security framework to resolve the security issues in the power sector, accordng to Indian Express report. Notably, on Decemb

Hackers Hijack Millions of PCs

Image
Critical Flaw in All Blizzard Games Could Let Hackers Hijack Millions of PCs January 22, 2018 A Google security researcher has discovered a severe vulnerability in Blizzard games that could allow remote attackers to run malicious code on gamers’ computers. Played every month by half a billion users—World of Warcraft, Overwatch, Diablo III, Hearthstone and Starcraft II are popular online games created by  Blizzard Entertainment . To play Blizzard games online using web browsers, users need to install a game client application, called ' Blizzard Update Agent ,' onto their systems that run JSON-RPC server over HTTP protocol on port 1120, and " accepts commands to install, uninstall, change settings, update and other maintenance related options. " Google's Project Zero team researcher Tavis Ormandy  discovered  that the Blizzard Update Agent is vulnerable to a hacking technique called the " DNS Rebinding " attack that allows any website to ac

Norway Population Exposed in HealthCare Data Breach

Image
Nearly Half of the Norway Population Exposed in HealthCare Data Breach Cybercriminals have stolen a massive trove of Norway's healthcare data in a recent data breach, which likely impacts more than half of the nation's population. An unknown hacker or group of hackers managed to breach the systems of Health South-East Regional Health Authority (RHF) and reportedly stolen personal info and health records of some 2.9 million Norwegians out of the country's total 5.2 million inhabitants. Health South-East RHA is a healthcare organisation that manages hospitals in Norway’s southeast region, including Østfold, Akershus, Oslo, Hedmark, Oppland, Buskerud, Vestfold, Telemark, Aust-Agder and Vest-Agder. The healthcare organisation  announced  the data breach on Monday after it had been alerted by HelseCERT, the Norwegian CERT department for its healthcare sector, about an "abnormal activity" against computer systems in the region. HelseCERT also sa

OnePlus 40,000 users Credit Card Breach

Image
OnePlus confirms up to 40,000 customers affected by Credit Card Breach   Friday, January 19, 2018 OnePlus has finally confirmed that its online payment system was breached, following several complaints of  fraudulent credit card transactions from its customers who made purchases on the company's official website. In a statement  released  today, Chinese smartphone manufacturer admitted that credit card information belonging to up to 40,000 customers was stolen by an unknown hacker between mid-November 2017 and January 11, 2018. According to the company, the attacker targeted one of its systems and injected a malicious script into the payment page code in an effort to sniff out credit card information while it was being entered by the users on the site for making payments. The malicious script was able to capture full credit card information, including their card numbers, expiry dates, and security codes, directly from a customer’s browser window. " The malici

Russian hackers targeting US email accounts:

Russian hackers targeting US Senate email accounts: Report A hacking group allegedly associated with the Russian government is actively targeting the US Senate's internal email system since June 2017, a cyber security firm claimed on Saturday. January 13, 2018 4:44 PM According to Japanese cybersecurity firm Trend Micro, this is the same group that hacked into the Democratic National Committee (DNC) in 2016. (Reuters) Earlier this week, BuzzFeed News said that “Fancy Bear” released a set of emails between International Olympic Committee (IOC) employees and third parties discussing the Russian doping conspiracy. The leaks were apparently done in a retaliation for the decision taken in December 2017, to bar Russia from participating in the Games in Pyeongchang, South Korea by the IOC. A hacking group allegedly associated with the Russian government is actively targeting the US Senate’s internal email system since June 2017, a cyber security firm claimed on Saturday

macOS USers data Hijacking

Image
Warning: New Undetectable DNS Hijacking Malware Targeting Apple macOS Users   Friday, January 12, 2018 This attack target is macOS users A security researcher has  revealed  details of a new piece of undetectable malware targeting Apple's Mac computers—reportedly first macOS malware of 2018. Dubbed  OSX/MaMi , an unsigned Mach-O 64-bit executable, the malware is somewhat similar to DNSChanger malware that infected millions of computers across the world in 2012. DNSChanger malware  typically changes DNS server settings on infected computers, allowing attackers to route internet traffic through malicious servers and intercept sensitive information. First appeared on the Malwarebytes forum, a user posted a query regarding unknown malware that infected his friend's computer that silently changed DNS settings on infected macOS to  82.163.143.135  and  82.163.142.137  addresses. After looking at the post, ex-NSA hacker Patrick Wardle analysed the malware and found t

WPA3 Security

Image
Wi-Fi Alliance launches WPA3 protocol with new security features   Tuesday, January 09, 2018 New security launched in wifi The Wi-Fi Alliance has finally  announced  the long-awaited next generation of the wireless security protocol—Wi-Fi Protected Access (WPA3). WPA3 will replace the existing WPA2—the network security protocol that has been around for at least 15 years and widely used by billions of wireless devices every day, including smartphones, laptops and Internet of things. However, WPA2 has long been considered to be insecure due to its common security issue, that is " unencrypted " open Wi-Fi networks, which allows anyone on the same WiFi network to intercept connections on other devices. Most importantly, WPA2 has also recently been found vulnerable to  KRACK (Key Reinstallation Attack)  that makes it possible for attackers to intercept and decrypt Wi-Fi traffic passing between computers and access points. The new standard of Wi-Fi security, w