New Scotland Yard has confirmed that it has arrested a 19-year old suspected hacker in Essex, UK, in connection with a series of hacks and denial-of-service attacks against a number of organisations.
It is being widely speculated that the arrest is in connection with the high-profile attacks by the LulzSec hacking group, which has claimed amongst its victims Sony, the CIA, the FBI, and the Serious Organised Crime Agency (SOCA).
Some news, views and musing about things going on in the Information Security World.
Tuesday, June 21, 2011
Monday, June 20, 2011
Japan Criminalizes Creation, Acquisition or Storage of Computer Viruses
A new law in Japan makes creation or distribution of a computer virus without reasonable cause punishable by up to three years in prison, and acquisition or storage of a virus punishable by up to two years.
I am not sure how stringent their definition of "reasonable cause" is in this case, but it sounds like a good start.
I am not sure how stringent their definition of "reasonable cause" is in this case, but it sounds like a good start.
Key Words:
0-day,
computer viruses,
hacking,
security controls,
trojan
Sunday, June 19, 2011
Quantum Cryptography Not All It's CRACKED Up To Be.
This story is an easy-to-read easy-to-understand description of a flaw in quantum cryptography that allows an observer to determine the quantum key. Until now, this was theoretically impossible. If my 20 years in information security has taught me one thing, it is that hackers love impossibilities.
Key Words:
0-day,
encryption,
privacy,
security controls,
spying
Saturday, June 18, 2011
The Amazing Orgasm Facebook scam
Sophos details the latest Facebook social engineering attack. A link purporting to be a woman having an exceptionally enthusiastic orgasm turns out to be a series of survey questions that once completed, makes money someone apparently in Finland. You'll never get to see the video. The survey questions are of the same ilk you find in connection with fake torrents.
Cleverly, the Age Verification prompt asks if you are above the age of 18 with the word "Jaa" written on the button. While Jaa appears to mean "Yes", it is actually Finnish for "Share". The trouble begins right about there.
Cleverly, the Age Verification prompt asks if you are above the age of 18 with the word "Jaa" written on the button. While Jaa appears to mean "Yes", it is actually Finnish for "Share". The trouble begins right about there.
PC World Confuses LulzSec with Batman
Why on earth is PC World thanking LulzSec? This article is far too similar to subplots in the Batman or Spiderman movies. Talk about mixed messages... PC World has lost any credibility they may have once had.
Read this article for a more appropriate response to LulzSec's behavior.
Read this article for a more appropriate response to LulzSec's behavior.
Con artists pose as security companies in growing scam
Criminals posing as computer security engineers are having success in calling victims at home and stealing their money, according to a survey issued Thursday by Microsoft. Fifteen percent of 7,000 computer users polled in the United States, Canada, U.K. and Ireland said they have been been contacted by a phone scammer, and 22 percent of those were tricked into following the fraudsters' directions, which included giving them remote access to a computer or providing credit card information. Seventy-nine percent of those suffered a financial loss as a result. Victims were out an average $875 in the United States, the survey found.
Key Words:
credit card fraud,
passwords,
scam,
security controls,
social engineering
Thursday, June 2, 2011
Hackers stole secret Canadian government data
Hackers who attacked two of Canada's federal departments stole classified information before being discovered last January.
Hackers sent malicious emails to staff that appeared to be coming from senior managers. When staff opened the attachments, hackers found a path into the federal network, providing access to classified information.
The linked article contains a chronology of the attack.
Hackers sent malicious emails to staff that appeared to be coming from senior managers. When staff opened the attachments, hackers found a path into the federal network, providing access to classified information.
The linked article contains a chronology of the attack.
Subscribe to:
Posts (Atom)