Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Friday, March 2, 2012

Hackers Will Replace Terrorists as Top Threat, Says FBI

Could Anonymous be the next al-Qaeda?
FBI Director Robert Mueller warned a group of cybersecurity experts on Thursday that online attacks will replace terrorism as the most serious threat facing the U.S., according to The Associated Press.
Mueller pressed private businesses and Internet security firms to secure American digital infrastructure from rogue hackers and attacks sponsored by foreign governments.
“We are losing data, we are losing money, we are losing ideas and we are losing innovation,” Mueller said at the RSA Digital Security Conference in San Francisco. “Together we must find a way to stop the bleeding.”
Counterterrorism is still the FBI’s top priority, but the agency is working to better equip itself against online attacks. Trained cyber defense divisions are now in every FBI field office. They’re watching for all kinds of digital crimes — such as mortgage fraud, terrorist recruitment drives and Internet attacks.

Mueller isn’t the only government official making such warnings. The FCC chairman recently highlighted the threat of cyberattacks. The U.S. Senate is also debating the proper approach to combating cybercrime.
Two competing bills both call for beefing up the security of government networks and increasing the amount of cybersecurity information-sharing done between government and private businesses.
The bills differ, however, on whether or not the Department of Homeland Security should be allowed to set cybersecurity standards which private companies must meet. A bill sponsored by Sens. Joe Lieberman (I-Conn.) and Susan Collins (R-Maine), gives that power to the DHS, while the other bill, backed by Sen. John McCain (R-Ariz.) and five other Republican senators, does not.

Thursday, February 23, 2012

YouPorn User Emails and Passwords Exposed

Thousands of user emails and passwords from pornographic site YouPorn were exposed in a security breach, the Associated Press reports.
The security breach was allegedly caused by a third-party chat service, which “failed to take the appropriate precautions in securing its user data,” according to Kate Miller, spokeswoman of YouPorn parent company Manwin Holding SARL. YouPorn has shut down the breached server and notified its users about the security breach.
To make matters worse, a list of user emails and accompanying passwords (in plain text) is already circulating online. The list contains some 6,400 passwords, and it’s already been widely publicized, looked over and analyzed – for example, a word cloud of the most popular passwords from the site has been created by researcher Ashkan Soltani.
YouPorn is one of top 100 visited websites on the internet according to Alexa, which makes this security breach a high profile one. It’s also highly embarassing for users, many of which probably do not want to be publicly associated with a pornography site.
The lesson to be learned from the incident is the usual one: do not use the same login credentials for multiple sites. Additionally, if you use services such as this one, choose an e-mail and/or login and password that cannot easily identify you.

Sunday, January 29, 2012

Computer viruses infecting worms to create hybrid 'Frankenmalware,' says BitDefender

Most computer users are all too aware of the threat of viruses and worms infecting their machines, but according to security research firm BitDefender different types of malware may now be infecting each other to create a new breed of security risk. Dubbed "Frankenmalware," the hybrids are created when a virus infects a machine that has already been compromised by a worm. The virus attaches itself to executable files on the host system — including the worm — and when the latter spreads it carries the virus along with it. BitDefender claims it analyzed a sample of 10 million pieces of malware and discovered 40,000 different examples of the new breed. Code from the Virtob virus, for example, was found inside both the OnlineGames and Mydoom worms.
While the notion is frightening, it's important to keep the threat in perspective. Symantec product manager John Harrison told MSNBC that his company has seen no examples of this kind of malware mash-up, and it's impossible to know if the discovered examples were the true result of malware breeding in the wild, or simply the work of malicious programmers combining previous efforts into new creations. Fortunately, BitDefender notes that the multiple signature code elements within a hybrid may make it even easier for anti-virus software to detect the mutant strains and remove them from your system.