Showing posts with label Hackers. Show all posts
Showing posts with label Hackers. Show all posts

Tuesday, June 22, 2021

McDonald’s In South Korea And Taiwan Breached By Hackers


McDonald’s has been hit by a data breach in South Korea and Taiwan which compromised some customer and employee information. The world’s largest fast food chain now joins a rapidly growing list of companies worldwide that have fallen victim to hackers.

According to Reuters, the company said that the hackers accessed e-mails, phone numbers, and delivery addresses, but not customer payment information. As one would expect, McDonald’s will be notifying regulators and affected customers.

Information about the breach apparently came from an investigation involving external consultants that was initiated after unauthorised activity was discovered on the company’s network.


“While we were able to close off access quickly after identification, our investigation has determined that a small number of files were accessed, some of which contained personal data,” McDonalds reportedly said in a statement.

Cyberattacks have been increasing at an alarming rate, with their targets and consequences growing exponentially bigger. Last month, a ransomware attack on Colonial Pipeline in the US crippled fuel supplies in a large swath of the country for days. Later, hackers using ransomware struck at the world’s largest meat supplier JBS, temporarily paralysing some company operations in Australia, Canada, and the US.

Unsurprisingly, the ability of cybercriminals to attack critical infrastructure and critical industries is a top worry in Washington and other Western capitals right now. Many of these cyberattacks have been linked to Russia or hackers based in Russia – a country that has undoubtedly poor relations with America.

Wednesday, June 9, 2021

Microsoft Says Russian Hackers Going After Govt Agencies, Think Tanks, NGOs


Microsoft said that the Russia-based hacker group designated Nobelium has this week targeted government agencies, think tanks, consultants, and non-governmental organisations. Nobelium is also blamed for the notorious SolarWinds cyberattacks that breached multiple departments of the US federal government last year.

In a blog post, the Redmond-based software giant revealed that the hackers went after 3,000 email accounts at over 150 different organisations in at least 24 countries – although the organisations in the US took the brunt of the cyberattacks. At least a quarter of the affected organisations worked on international development, humanitarian, and human rights issues.

The hackers apparently began their attacks by obtaining access to the Constant Contact account of USAID, the US government agency responsible for foreign aid and developmental assistance. Then they sent out phishing emails with a link that, when clicked, installs a backdoor that Microsoft calls NativeZone, which can be used for a variety of actions like stealing data or infecting other computers on a network.


Hackers backed by the Russian government have been blamed for quite a few high-profile breaches in the US. For example, they’re suspected to have stolen thousands of emails from the US State Department, and penetrating the National Nuclear Security Administration – which oversees the US nuclear weapons stockpile.

Earlier in the year, Microsoft blamed China-backed hackers for compromising its mail server software Microsoft Exchange in order to access email accounts. That breach was so serious that the FBI eventually decided to access private computers in the US to purge them of backdoors.

Tuesday, April 20, 2021

Old CS:GO Vulnerability Allows Hackers To Take Control Of Your PC

A group of white hat hackers known as the Secret Club recently took to Twitter to point out what seems to be a critical security flaw, found within Source 3D, the game engine of Valve’s popular Counter-Strike: Global Offensive (CS:GO).

According to the group, the bug can be exploited by less-than-savoury hackers to trick gamers who play the game, by sending them a fake Steam invite. Upon accepting the invite, the hackers can then proceed to take over a user’s PC or laptop, effectively locking them out of their machine.

While the existence of the bug is troubling, it isn’t the most alarming aspect of it. Secret Club says that the exploit was reported by one of its members, Florian, back in 2019. Florian said that they had reported the bug to Valve via HackerOne, a bug bounty platform used by the studio that owns Steam. Florian was paid the bounty for its discovery but as per the report, the bug is still there. And it seems that little or next-to-nothing has been done about it.


To that end, the Secret Club accuses Valve of ignoring the problem outright, even after a more recent report this month was filed once more. At the time of writing, Valve still has not commented on the matter.

Thursday, March 25, 2021

Acer Breached By Ransomware; Hackers Demand US$50 Million In Largest Ransom Ever


Taiwanese tech giant Acer has been breached by a ransomware attack and hackers are demanding the largest known ransom ever of US$50 million (~RM205.6 million), Bleeping Computer reported.

REvil, the hacker group responsible for the attack, reportedly announced the breach on their data leak site and showed images of allegedly stolen files as proof – documents including financial spreadsheets, bank balances, and bank communications.

Bleeping Computer’s report suggested that hackers may have exploited a Microsoft Exchange vulnerability to carry out their attack. Recently, Microsoft blamed China-backed hackers for breaching their Exchange servers, resulting in tens of thousands of victims around the world.

Attacks using that route reportedly spiked dramatically since Microsoft’s announcement.

In response to enquiries, Acer issued a generic statement to Bleeping Computer and other media outlets, saying that the company constantly monitors its IT systems and that it has “reported recent abnormal situations observed to the relevant law enforcement and data protection authorities in multiple countries.”


The company did add that there was an ongoing investigation and that it couldn’t comment further due to security reasons.

At US$50 million, the ransom is the largest on record, surpassing REvil’s previous US$30 million (~RM123.3 million) demand for the cyberattack on Dairy Farm, a multinational retail chain operator.

Ransomware attacks have become startlingly frequent in recent times. CD Projekt Red, developer of The Witcher games and Cyberpunk 2077, was hit with a ransomware attack in February, resulting in its employees being reportedly locked out of their work VPN. The company refused to pay the ransom.

Saturday, March 13, 2021

Hackers Gain Access To 150,000 Security Cameras, Including At Tesla Premises


A hacker collective has obtained access to live feeds of 150,000 surveillance cameras installed at businesses including Tesla and website security company Cloudflare, Bloomberg and Reuters reported. This stunning breach of security also affected jails, hospitals, police departments, and schools.

All the victims were customers of a Silicon Valley startup called Verkada, which sells security cameras and provides users with remote viewing through the cloud. That last bit appears to have backfired badly – a fact made worse by how easily the hackers pulled off their heist.

Tillie Kottmann, one of the hackers, told Bloomberg that they found the username and password of a Verkada “Super Admin” account lying exposed on the Internet. Using that account, they were able to view the camera feeds of all of the company’s customers.

Among camera footage provided by Kottmann, Bloomberg said it saw inside a Tesla warehouse in Shanghai, a hospital in Florida, and a police station in Massachusetts. Since learning of the intrusion, Verkada has disabled all internal administrator accounts.


Kottmann told Bloomberg that the hack “exposes just how broadly we’re being surveilled, and how little care is put into at least securing the platforms used to do so, pursuing nothing but profit.”

Funnily enough, easy access to video feeds may have been the point.

Reuters noted that Verkada CEO Filip Kaliszan once said the company intentionally made it easy for many organisational users to view live video and share it when necessary – for example, with emergency responders.

As always, this seems to be a case of technological utility butting heads against security and privacy. What’s the right balance? We doubt there are easy answers.

Sunday, February 14, 2021

CDPR Hackers Allegedly Auctioning Hacked Files


It’s been well over 48 hours since CD Projekt got hacked. And it looks like the hackers are making good on their threat of selling the codes and documents they stole. In fact, they’ve already started taking bids for the source codes.

Twitter user @vxunderground tweeted images showing the ransomed data appearing online. In the tweet thread, they also mentioned that the hackers are auctioning the source codes of Witcher 3 and Cyberpunk 2077, among other CDPR games, with a starting bid of US$1 million (~RM4.045 million). They’re also selling them outright for US$7 million (~RM28.315 million).


According to Tom’s Hardware, leaked Gwent files have also appeared on forums like 4Chan, with the main download hosted on Mega. They have since been removed, which should limit the spread of the leak somewhat.

So far, it looks like the trickling of leaked data from CDPR are in the form of games source codes. It means that, for now at least, company documents are still safe. But it wouldn’t be long before it’s the documents’ turn to trickle out of the leaks pipeline. CD Projekt previously said that no personal information of users have been leaked, which is at least a silver lining for the company’s fans.

Monday, February 1, 2021

Google Says North Korea Hackers Are Targeting Cybersecurity Research Via Social Media


Google recently made a startling discovery revolving around North Korean hackers and cybersecurity researchers. According to the search engine’s Threat Analysis Group, the former is targeting the latter and going after them via a variety of social media platforms.

The alleged hackers supposedly work their con by posing as researchers, while also created several fake social media profiles on platforms that include Twitter and LinkedIn. If that wasn’t enough, they also set up fake blogs that they then get the unsuspecting researcher to write guest posts about software bugs that they’ve encountered.

The deception doesn’t stop there either. Once enough trust has been gained, the hacker would then make the step to ask the researcher if they would work together. If they agreed, the hacker would then share “collaboration tools” with them; unbeknown to the researcher, those tools actually contain malicious codes that, once opened, installs malware on to the researcher’s system.

Google says that one likely reason behind North Korea’s decision to target cybersecurity researcher is also one of the most obvious: it’s so that the country and its team of hackers can gain insight into security vulnerabilities and then exploit them for their own nefarious purpose.

It goes without saying and we’re sure that you all know, that this isn’t North Korea’s first time both under the spotlight and on the cybersecurity stage. The company has proven its cyber prowess in the past, the most prominent case in recent memory being the hacking of Sony Pictures in 2014. Because of the movie, The Interview, which featured a satirical adaptation of Kim Jong Un, the current communist dictator and ruler of the country.


The country has also been known to engage in cyber thievery, the most common among them having been the alleged theft of Bitcoin over the past several years.

Xiaomi Shows Off Physical Concept Of Vision Gran Turismo

At the very tail end of last month, Xiaomi unveiled the Vision Gran Turismo. The car was revealed as a digital hypercar, and one that’s made...