Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts

Chinese hacking team caught taking over decoy water plant

A hacking group accused of being operated by the Chinese army now seems to be going after industrial control systems.

http://www.technologyreview.com/news/517786/chinese-hacking-team-caught-taking-over-decoy-water-plant/
Chinese hacking team


A Chinese hacking group accused this February of being tied to the Chinese army was caught last December infiltrating a decoy water control system for a U.S. municipality, a researcher revealed on Wednesday.

The group, known as APT1, was caught by a research project that provides the most significant proof yet that people are actively trying to exploit the vulnerabilities in industrial control systems. Many of these systems are connected to the Internet to allow remote access (see “Hacking Industrial Systems Turns Out to Be Easy”). APT1, also known as Comment Crew, was lured by a dummy control system set up by Kyle Wilhoit, a researcher with security company Trend Micro, who gave a talk on his findings at the Black Hat conference in Las Vegas.

Feds Identify the Young Russians Behind the Top U.S. Cyber Thefts in Last 7 Years

http://www.wired.com/threatlevel/2013/07/albert-gonzalez-conspirators/
Cyber thefts
Four Russians and one Ukrainian have been charged with masterminding a massive hacking spree that was responsible for stealing more than 160 million bank card numbers from companies in the U.S. over a seven-year period.

The alleged hackers were behind some of the most notorious breaches for which hacker Albert Gonzalez was convicted in 2010 and is currently serving multiple 20-year sentences simultaneously. The indictments clear up a years-long mystery about two hackers involved in those attacks who were known previously only as Grig and Annex and were listed in indictments against Gonzalez as working with him to breach several large U.S. businesses, but who have not been identified until now.

The hackers continued their activities long after Gonzalez was convicted, however. According to the indictment, filed in New Jersey, their spree ran from 2005 to July 2012, penetrating the networks of several of the largest payment processing companies in the world, as well as national retail outlets and financial institutions in the U.S. and elsewhere, resulting in losses exceeding $300 million to the companies.

Security Researcher Takes Credit For Apple Developer Website Hack

Access to the developer site has been partially restored, but the iOS and Mac Dev Centers remain down

http://www.darkreading.com/attacks-breaches/security-researcher-takes-credit-for-app/240158670
Apple Developer website hack
A security researcher has taken credit for a hack of a website for Apple developers last week that exposed user data and led Apple to take portions of the site offline.

The website's iOS and Mac Dev centers remain down as of publication. In the aftermath of the disclosure, a security researcher named Ibrahim Balic took credit for the hack, and claimed he was only attempting to alert Apple to the presence of vulnerabilities on the site. In a statement to developers on Sunday, Apple warned that its website had been taken down after the hack, and that personal data belonging to users may have been stolen by the culprit.

"Last Thursday, an intruder attempted to secure personal information of our registered developers from our developer website," according to a note posted on the website. "Sensitive personal information was encrypted and cannot be accessed, however, we have not been able to rule out the possibility that some developers’ names, mailing addresses, and/or email addresses may have been accessed. In the spirit of transparency, we want to inform you of the issue. We took the site down immediately on Thursday and have been working around the clock since then."

The Value of a Hacked Email Account

This post aims to raise awareness about the street value of a hacked email account, as well as all of the people, personal data, and resources that are put at risk when users neglect to properly safeguard their inboxes.

Sign up with any service online, and it will almost certainly require you to supply an email address. In nearly all cases, the person who is in control of that address can reset the password of any associated services or accounts –merely by requesting a password reset email.

Hacking Routers for Fun and Profit – Virgin Superhub CSRF Exploit

This could be quite an dangerous attack if used on a high profile page, (particularly in the UK where superhubs are used). Attackers could gain access to many routers.