Background

Background

Change your prefer background

  • image1
  • image2
  • image3
  • image4
  • image2
  • image1
  • image4
  • image3
Showing posts with label News. Show all posts
Showing posts with label News. Show all posts

Holiday Shopping season is really an excited time for both shoppers and retailers, but unfortunately it's a good time for cyber criminals and scammers as well.
With Black Friday (28th November 2014) and Cyber Monday (1st December 2014) comiing up, you need to be more careful while shopping. These are the two very busy shopping days where shoppers spend millions online.
Every eye will be on retailers to ensure that consumers' online shopping experiences are straightforward and, most importantly, secure. So, at the major part, retailers need to pay attention to extra security measures in order to prevent themselves from massive data breaches, like Target data breach that occurred last year during the Black Friday sales in which over 40 million Credit & Debit cards were stolen.
Not just Target alone, multiple retailers including Neiman Marcus, Michaels Store were also targeted during last Christmas holiday, involving the heist of possibly 110 million Credit-Debit cards, and personal information.
So, in an effort to secure yourself from scammers you need to be aware of some top scams and tips to keep yourself safe online.


1. COPYCAT & FAKE WEBSITES
In order to fraud an online account holder's financial information, scammers could pose their website as a legitimate one. Like you got an email from Amazan.com for the hottest deals, and not Amazon, make sure before providing your financial details.
Check properly thrice who emails are from and if it's an unknown, best way is to avoid the email and the so-called hottest deal. Always go for a website using an HTTPS URL, before entering a password or any information like address or credit card number.
There are thousands of websites that closely resemble legitimate domains like Amazon, Google, Apple, Facebook and Microsoft. Apart from these, there are so many new sites offering online shopping, that it's quite difficult for customers to say which one is legitimate and which is not.
Many of these websites host exciting contests or advertisements for dodgy services to gain your attention and force your finger to click it, while others host malware that can infect your system when you browse to these websites.
So, to be in safer side, always shop from websites which you or your friends know. Just keep one thing in mind while shopping online that Website ratings and security seals can be faked and the website could look too good to be true, but probably it's not.
2. PHISHING WEBSITES
Phishing scams are typically fraudulent email messages, masquerading as a well known and trustworthy entity in an attempt to gather personal and financial information from victims. However, phishing attacks have become more sophisticated recently.
Keep an eye on scams emails claiming to come from legitimate sources which will ask you to visit a website actually hosted by cyber crooks in order to steal your personal information like email addresses, passwords, credit card numbers, expiration date, verification code, and more.
Always type website name in Google Search Engine and then visit the particular website from those search results, instead visiting through any link provided in messages or emails. Don't go to websites you've never heard of.
3. UNEXPECTED GIFTS SCAM
A year ago during Black Friday, one of the major scams was the cyber criminals offering $1,000 Best Buy gift cards, which nobody won. But, a lot of people ended up in giving away their personal information for no reason at all.
Online users are recommended to avoid such "unexpected gifts" scams, just like your dear ones recommend you to not accept unexpected gifts from strangers. Emails could be a major medium to offer you unwanted gifts, so be careful when opening attachments you receive by email - that special delivery could end up costing you.
4. FAKE ADS AND COUPONS
Customers on holiday season are always on search for great deals, especially on Black Friday and Cyber Monday, but your just a small mistake can lead you to danger. Miscreants use your desires by creating 'click-bait' ads or posting links to 'the best deal ever', which will always lead to either a survey, a scam site or even drive-by exploits.
Customers are advised to treat such offers with skepticism, especially when the source is unknown and unfamiliar to you. You are also advised to keep an updated Antivirus software onto their systems, so if any convincing advert does trick you and gain your click, your AV protects you against infection.
In addition to fake ads for Best Buy, users also want to look out for fake online coupons in general. If it sounds too good to be true, visit directly to reputable websites, and, by some miracle, the offer is true because it's Black Friday sales, it's all yours.
 News: Source-- Computerworld.com

A Pennsylvania man who hacked into multiple corporate, university and government computer networks and tried to sell access to them -- including access to supercomputers from a U.S. national security laboratory -- has been sentenced to 18 months in prison.
Andrew Miller, 24, pleaded guilty in August to one count of conspiracy and two counts of computer fraud for actions committed between 2008 and 2011, when he was part of the Underground Intelligence Agency hacking group, the U.S. Department of Justice said Thursday. Miller was sentenced Wednesday.
Miller asked an undercover FBI agent in 2011 for $50,000 in exchange for access to two supercomputers at the Lawrence Berkeley National Laboratory, according to the DOJ.
The Oakland, California, lab belongs to the national laboratory system supported by the U.S. Department of Energy through its Office of Science and is managed by the University of California, according to its website. The supercomputers Miller claimed he had accessed were part of the lab's National Energy Research Scientific Computing Center (NERSC).
According to court documents, the FBI never "bought" the access credentials for the lab, but it did obtain from Miller proof that he had accessed two supercomputers that provide computing resources for the U.S. Department of Energy. He told the FBI got the access after breaking into a Japanese university with connections to the NERSC.
The FBI did buy from Miller access to computer servers from RNKTel.com, a Massachusetts telecommunications provider. Miller also sold to the undercover agents access to servers from Colorado ad agency Crispin Porter and Bogusky which hosted websites, databases and email servers from a variety of merchants, including from Domino's Pizza.
The FBI also bought from Miller what court documents describe as a "massive database of thousands of log-in credentials into hundreds of computer networks" which he said he obtained by hacking into servers from Layered Tech, a Texas Internet service provider.
Miller's modus operandi consisted of breaking into computer networks via a variety of methods, including targeting specific authorized network users and infecting their computers with malware, which allowed him to steal their log-in information.
Then, once inside the network, he would look for valuable information, such as log-in information from other users, and he would install "backdoors" with his own passwords. This allowed him to return to the networks while bypassing security and to potentially sell access to them to cybercriminals.
In computer chats with the undercover agents, Miller claimed to have hacked into servers from American Express, Yahoo, Google, Adobe, Wordpress, Cisco, Harvard University and the University of California at Davis. He also claimed to have accessed very sensitive U.S. government networks from agencies including NASA, Los Alamos National Laboratory, Oak Ridge National Laboratory and Argonne National Laboratory.

In a filing with the court in November, Massachusetts U.S. Attorney Carmen Ortiz called Miller's actions "widespread, persistent and pernicious hacking" and said he was aware he was breaking the law, but she also said it's not clear how much actual damage he caused.
"Likewise, he did not successfully monetize his hacking activities," Ortiz wrote, adding that the government is only aware of a $500 sale completed before the undercover agent got in touch with Miller.
Ortiz recommended an 18-month sentence, three years of supervised release and monetary penalties of about $16,000 to U.S. District Judge Mark Wolf of the District of Massachusetts.
However, in letters to the court, Miller and members of his family, including his mother and father, pleaded for him to be spared jail time, saying he was very sorry for his actions, is seeing a psychiatrist for depression, and is needed at home to help care for his mother, who is very ill.
Miller faced a maximum penalty of 15 years in prison and $500,000 in fines for the three counts in his indictment that he pleaded guilty to. He had previously been convicted in 2004, when he was a minor, of being involved in writing malicious software, according to Ortiz's filing.

News : Source by http://hackread.com

Chicago based Jeremy Hammond linked to the online hacktivist group Anonymous and has been sentenced on Friday to ten years in prison for cyber attacks against various government agencies of the U.S. government and financial giants, including Strategic Forecasting, Inc., more commonly known as Stratfor.
Jeremy Hammond, 28, was convicted of cyber attacks on he conducted on Stratfor in December 2011, which his lawyers claim to have been motivated by concerns about the role of private companies in collecting intelligence information at home and abroad.
Prosecutors said the attack on Strategic Forecasting, or Stratfor, resulted in the theft of 60,000 credit card numbers and data from 860,000 customers, which were later posted on the Internet.
In March 2012, FBI had changed AntiSec’s Jeremy Hammond with information equals $700,000 in Startfor hacking.
It all started with a ex-anonymous and a snitch SABU who sold out the personal details of Jeremy Hammond to FBI in 2012. 

News : Source -- http://www.techienews.co.uk/

A group of hackers linked with the notorious Anonymous hacking collective have pleaded guilty in the 2010 PayPal Distributed Denial of Service (DDoS) attack.
Out of the thirteen hackers, ten pleaded guilty to one count of conspiracy and one count of damaging a protected computer, while the remaining pleaded guilty to one count each related to the attack. The ten will be allowed to change their felony charges to misdemeanor next year if they comply with the terms of their agreement till their sentencing.
According to the statement released by U.S. Attorney Melinda Haag, District Judge D. Lowell Jensen will announce the sentences starting November.
The group was responsible attacking PayPal’s servers through a DDoS attack after eBay’s unit suspended account of WikiLeaks.
EBay chairman Pierre Omidyar has asked the government to show leniency while issuing sentences to all those who have plead guilty in the case. The Department of Justice might be looking for a serious jail time; however, Omidyar has appealed to the feds to go easy on the bunch.
Through an editorial on the Huffington Post, Omidyar said that he understood the reasons behind the protests and he “felt that they were simply participating in an online demonstration of their frustration.”
“That is their right, and I support freedom of expression, even when it’s my own company that is the target,” he said.
Omidyar acknowledged that DDoS are serious enough attacks, but there is a disparity in prosecuting and crime for this particular act. Omidyar said that instead of jail time backed by felony charges, the defendants should be asked to pay fines under misdemeanor charges.

News : Source -- Written by Niraj Kashyap

Google once again is #Hacked and #Defaced, this time the hack is done by Pakistani Hackers team, popularly known as”TeaM MADLEETS”.
The hackers have defaced both the domain  http://google.my/ and http://www.google.com.my/
Earlier Google Palestine was hacked and defaced by hacker known as Cold Z3ro. This time the hack is done by DNS poisoning and the name server of google Malaysia is changed to
  1. b0x4.madleets.com
  2. b0x3.madleets.com
We have attached two screenshots of google defacement

here is the details of google.com.my from who.is

Message by Hackers left on defaced google

Message! Google Malaysia STAMPED by PAKISTANI LEETS
We are TeaM MADLEETS
H4x0r HuSY – KhantastiC HaXor – H4x0rL1f3 – InvectuS – Shadow008 – r00x – Don – MindCracker – Dr.Z0mbie – phpBuGz – MaD GirL
MaDCoDe – Sn!p3r_GS – DeXter – Neo Haxor – Darksnipper – Pain006 – b0x – R3DL0F – Sahrawi – 3thicaln00b – Hmei7 – MakMan – Sniffer – AL.MaX HaCkEr – Ch3rn0by1
=======================
www.MaDLeeTs.com
| LeeTHaXor@Y7mail.com |
=======================
Pakistan Zindabad



Microsoft teamed up with law enforcement agencies and A10 Networks has disrupted one of the world's largest Botnet "ZeroAccess" that defrauded online advertisers.

ZeroAccess also known as Sirefef is a notorious malware which makes money for cyber criminals through Click fraud - Hijacking victim's search results and generating fake clicks on ads. It also installs Bitcoin miners in the infected machines.

Victims usually get infected by the ZeroAccess through drive by download attacks.

The malware has reportedly infected more than two million computers. It costs online advertisers around $2.7 million per month.

David Finn, executive director and associate general counsel of the Microsoft Digital Crimes Unit said the disruption "will stop victims’ computers from being used for fraud and help us identify the computers that need to be cleaned of the infection"

Microsoft said the action will not "fully eliminate the ZeroAccess botnet due to the complexity of the threat". However, it will significantly disrupt the botnet's operation and will bring loss of revenue for the cyber criminals who behind the ZeroAccess.

Tips : Source --  http://abcnews.go.com/
Any time you logged into Facebook, Google, Twitter, or a host of other popular web services the past month, there may have been a hacker peering over your digital shoulder, sneaking a peek at your password.
The information security company Trustwave has revealed that the passwords to 2 million different accounts have been compromised. The malware program Pony forwarded the vast majority of the passwords to a central server in the Netherlands.
John Miller, security research manager at Trustwave, said that the hack wasn't due to a flaw in any of those company's servers. "It was the individual users' computers that had the malware installed on their machine," he told ABC News. He adds that the unnamed hackers were most likely motivated by profit. "These passwords were never publicly posted. We can't say for sure, but [the hackers] were probably going to sell them."
Many of the services whose users were affected have already taken action. "They may not necessarily inform users with an email," said Miller. However, he adds that affected users will be asked to reset their password after logging into their account.
Trustwave analyzed the passwords that were compromised in the hack and saw some of the trends usually associated with bad password security. The most common password was 123456. In addition, nearly half of all passwords used a single character type, such as all lowercase letters or all numbers.
"For a better password, we recommend a mix of uppercase, lowercase, numbers, and special characters," said Miller. "We also recommend using longer passwords of 16 or more characters, as well as using different passwords on different websites."
But even the most secure password wouldn't have been safe from the Pony malware. To that end, Miller said to practice good browsing habits. "Keep your anti-virus software up to date and make sure your browsers are updated and patched to the latest version," he said.
And above all, don't click that suspicious looking link in your email. "Pony is sent through spam links," said Miller.