Showing posts with label Cyber attack. Show all posts
Showing posts with label Cyber attack. Show all posts

Tuesday, November 1, 2016

Microsoft: Russia-linked hackers Using Windows Flaw in Attacks

A hacking group earlier connected to the Russian government and U.S. political hacks was responsible for recent cyber attacks that manipulated a newly exposed Windows security flaw, Microsoft Corp said on Tuesday.

The software developer in an advisory on its website named the hacking group as “Strontium”. It is more famously known as “Fancy Bear” or APT 28 and used “spear phishing” emails in some attacks. However, the company did not identify any victims.

Microsoft’s revelation of the current attacks and the connection to Russia came after Washington accused Moscow of unleashing an unprecedented hacking campaign. These attacks were intended for discrediting and disrupting the upcoming U.S. election.

Last month, The U.S. government formally accused the Russian government of the election-season cyber attack of Democratic Party emails. The Russians were also blamed for the emails’ ensuing release thru WikiLeaks and other entities. Russia has denied those accusations.

A patch to safeguard Windows users against the recently discovered threat will be released on Nov. 8, Election Day, Microsoft said. Nevertheless, it was unclear whether the Windows vulnerability had been exploited in any of the recent U.S. political hacks.

Representatives of the Department of Homeland Security and the FBI could not immediately be reached for comment.

A U.S. intelligence specialist on Russian cyber activity said that Fancy Bear principally works for or on behalf of the GRU, Russia’s military intelligence agency. According to U.S. intelligence officials, the GRU was responsible for hacks of Democratic Party emails and databases.

In spear phishing, an attacker sends targeted messages, usually thru email. These messages manipulate familiar information to deceive victims into clicking on malicious links or open infected attachments.

hackersMicrosoft said the hacks used a vulnerability in Adobe Systems’ Flash software and one in the Windows operating system.

On Monday, Adobe released a patch for that vulnerability when security researchers with Google announced the details of the attack.

Google chided by Microsoft

Microsoft rebuked rival Google for going public with facts of the vulnerabilities before it had time to prepare and test a patch to remedy them.

“Google’s decision to disclose these vulnerabilities before patches are broadly available and tested is disappointing, and puts customers at increased risk,” Microsoft said.

A Google representative refused to comment on Microsoft’s statement.

Google held to its standing policy of going public seven days after uncovering “critical vulnerabilities” that are being actively used by hackers. Hence, the company revealed the flaw on Monday.

Companies are given 60 days by Google to patch less serious bugs.

 

The post Microsoft: Russia-linked hackers Using Windows Flaw in Attacks appeared first on Newsline.

Friday, October 21, 2016

Cyber Attacks Interrupt Access to Several Websites

Cyber attacks disrupted access to dozens of websites on Friday, blocking some users from accessing Twitter, Spotify and PayPal. The attack targeted Dyn, a slightly known internet infrastructure company.

Dyn said the outages that started in the Eastern United States spread to other parts of the country and overseas. The company, whose customers comprise some of the world’s most commonly visited websites, said it did not know who was responsible for the attack.

The outages were sporadic, making it difficult to identify all the victims. However, technology news site Gizmodo named a number of sites that the attack impinged on. They included Mashable, HBO Now, CNN, the New York Times, Yelp, People.com, and the Wall Street Journal.

Attacks were emanating from tens of millions of Internet-connected devices such as printers, thermostats, and webcams, Dyn said. They were infected with malicious software that converts them into “bots” that are capable of massive distributed denial of service attacks.

The U.S. Department of Homeland Security released an alert last week concerning this powerful new approach. The agency remarked its concern about the potential for fresh attacks following code for malware used in these attacks was posted on the internet.

Dyn said on Friday that it was fending off the third major wave of attacks. The attacks were getting harder to fight since they were being launched from sites scattered across the globe.

“The complexity of the attacks is what’s making it very challenging for us,” said Kyle York, Dyn’s chief strategy officer.

The Federal Bureau of Investigation and the U.S. Department of Homeland Security said they were investigating the case.

The disruptions happened at a time of unparalleled concerns about the cyber threat in the United States, where hackers have violated political organizations and election agencies.

Dyn said an earlier attack, which interrupted operations for about two hours, had been resolved. However, a second attack a few hours later caused further disruptions.

The outage was restricted to the Eastern United States, Dyn said early on Friday. But Amazon later reported that the incident was affecting users in Western Europe. Some users in London could not access twitter and some news sites late on Friday evening.

PayPal Holdings Inc said that the outage inhibited some customers in “certain regions” from doing payments. It said that its networks had not been hacked and apologized to customers for the inconvenience.

Amazon.com Inc’s web services division also reported a related outage but was resolved early Friday afternoon, the company said

Dyn is a provider of services for managing domain name servers (DNS), which function as switchboards connecting internet traffic. DNS servers direct requests to access sites that are transmitted through them to computers that host websites. The company is based in Manchester, New Hampshire.

Dyn said it was still investigating how the attack led to the outage but that its first priority was restoring service.

Attacking a large DNS provider can produce substantial disruptions because such companies are responsible for redirecting huge amounts of internet traffic.

 

 

The post Cyber Attacks Interrupt Access to Several Websites appeared first on Newsline.

Thursday, September 29, 2016

Clinton Promises to Hit Back Against Foreign Hackers

The United States will act in response to foreign hacking the same as any other attack to its sovereignty, vows Hillary Clinton.

cybertank

There are legitimate questions as to how the US government should defend itself after a cyber attack. As of the moment, the Obama administration is still writing its rulebook.

Identifying who’s responsible remains to be a challenge as there are a number of usual suspects. These range from bored teenagers to cybercriminals and foreign hackers. Making it more difficult is the fact that experienced hackers can cover their tracks and also lead security experts astray.

Cybersecurity experts were surprised when Clinton made aggressive remarks about retaliating with political, economic or even military measures. Her aggressive strategy propositions ran against the State Departments policy of avoiding open conflict since it may muddle diplomatic efforts.

When asked during the presidential debate how she would respond to cyberattacks, Clinton said, “We’re going to have to make it clear that we don’t want to use the kinds of tools that we have. We don’t want to engage in a different kind of warfare. But we will defend the citizens of this country.”

Cybersecurity was at the forefront of the national security segment of the presidential debate for the first time. This thereby proves its current political significance. It also highlights the fact that the next president will influence the 21st century cyberwarfare policies. This includes establishing rules on how the US responds to foreign hackers.

While Trump has not issued any official position on the subject, Clinton confronts the matter in one and a half pages of her 288-page campaign book.

Just recently, in the midst of the presidential race, there were a rash of hacks on government sites. Cybersecurity firms, Democrats and Clinton blamed these attacks on Russia. The White House is struggling over how to counter hacking. Some officials said it was an attempt to undermine voter confidence in the election.

Still learning the ropes

Former general counsel for the National Security Agency said that they are in the very early stages of developing the rules by the benefit of the attacks that they saw.

He added that responding is a challenge: “How do you know who’s responsible for the attack and to what extent are the cyber actors even susceptible to the normal responses like economic or diplomatic pressure?”

Clinton’s stand on cybersecurity started while she was with the State Department. At that time, she created the Office of the Coordinator for Cyber Issues to handle diplomacy and cyber rules.

According to Christopher Painter, who served as the office’s coordinator since its launch, there was no other office in the world like it when it was created 5 years ago.
Now there are 25 counterparts around the world and more on the way.

The post Clinton Promises to Hit Back Against Foreign Hackers appeared first on Newsline.