-
Weak Encryption Faulted in TJX Breach
"TJX’s failure to upgrade its encryption system allowed the electronic eavesdropping beginning in July 2005 and continuing for a year and a half, the report says. At least 45 million credit and debit cards were exposed to potential fraud, according to an Associated Press story" Article Link: http://www.itbusinessedge.com/blogs/hdw/?p=945
-
Blackhat SEO faces 3 years in prison for insulting the president
From the nypost " A hacker faces up to three years in prison for making the Polish president's Web page turn up in searches for the slang word for "penis." Marek W., 23, has been charged with insulting President Lech Kaczynski. Marek created a program that caused the official home page of the president to…
-
Ameritrade leaks over 6million customer records
"TD Ameritrade Holding Corp. said Friday one of its databases was hacked and contact information for more than 6.3 million customers was stolen. A spokeswoman for the Omaha-based brokerage firm said more sensitive information in the same database, including Social Security numbers and account data, does not appear to have been taken. The company would…
-
Ad-based Trojan hits MySpace, Bebo and others
Another article on malware being served up via advertising companies. "Users of high profile sites including MySpace, The Sun, Bebo and PhotoBucket have been exposed to a Trojan hidden within adverts. The sites all ran advertising in recent weeks from the Right Media online ad exchange which were unknowingly infected with the Downloader.VBS.Agent.n Trojan." Article…
-
Yahoo accidentally dishes out trojans via banner ads
"An ad company that Yahoo owns, Right Media, served up some particular advertisements several million times that ended up being loaded with Trojans. These ads, while all over the Internet, were most prominently featured on MySpace and PhotoBucket – not shady warez sites. The issues began last month, and according to ScanSafe the articles were…
-
Warcraft.net and Battle.net get hacked by polite hacker
As a Diablo2 fan I just had to post this. " Blizzard's Warcraft.net and Battle.net websites have recently come under attack from an Algerian hacker who went by the name of "LeHackeur". This hacker added an extra file on the sites' main servers, which displayed an image of a skull, as well as a message…
-
Chinese military hacked into Pentagon
"The Chinese military hacked into a Pentagon computer network earlier this year in the most successful cyber attack ever on the US defence department, according to US officials. The Pentagon acknowledged shutting down part of a computer system serving the office of Robert Gates, the defence secretary, in June, but refused to say who it…
-
New Zealand Herald website defaced via XSS to promote hacker con
"The New Zealand Herald's website fell victim to a page spoofing stunt earlier today, by hackers wanting to publicise their upcoming Kiwicon security conference in November. In this case, the spoofing meant the hackers displayed a parody of a Herald article to users, rather than a real one, when surfers called up an article on…
-
China Government 1, Germany Government 0
"CHINESE spies have hacked into German government department computer systems, media reports say. The reports emerged as German Chancellor Angela Merkel arrived in China. The Chinese Foreign Ministry reacted by saying China prohibited attacks on computer networks. "The Chinese Government has always opposed and prohibited any criminal activity that breaks down computer networks, including hacker…
-
Monster attack steals user data
"US job website Monster.com has suffered an online attack with the personal data of hundreds of thousands of users stolen, says a security firm. A computer program was used to access the employers' section of the website using stolen log-in credentials. Symantec said the log-ins were used to harvest user names, e-mail addresses, home addresses…
-
Facebook source code leaked
"Facebook source code has been leaked on the Web, and that's raising some serious issues about the site's security and data privacy. Source code from the social networking site's main index page appeared on a blog called Facebook Secrets recently and remained there Tuesday. The blog does not contain any other postings. "A small fraction…
-
USA Today fun with XSS
clpwn.com has found an XSS vulnerability in USAToday and has been having fun with it to *post* fake news stories. First a description of the group "Hardcore WEB HACKING and 0day browser security stuff from wannabe elite hackers TEAM CLPWN…" Now about the vuln "The underground hacker team CLPWN has exposed a zero-day content injection…
-
UN Hacked via SQL Injection
The UN was defaced with a political message and hackademix has published it was via a sql injection vulnerability. "While most of us may agree with the message, many will object to the spelling, and specifically to the dont used instead of don.t. There.s a technical reason for the missing apostrophe, though, because messing with…
-
Undercover reporter ousted at defcon, probably pretty f@!ked
UPDATE: Her myspace page was linked off of defconpics.org and shortly after has been removed from myspace. No word on how it was removed at this time. An NBC reporter (Michelle Madigan Associate Producer of NBC Dateline) was found to be trying to find hackers for hire and recording them with a video camera. Jeff…
-
Hackers Can Now Deliver Viruses via Web Ads
"Web ads are becoming a delivery system of choice for hackers seeking to distribute viruses over the Internet. In a development that could threaten the explosive growth of online advertising, hackers have started to exploit security holes in the online-advertising chain to slip viruses into ads. Just going to a site that shows such an…
-
Fox News Pwned
""While browsing around the Fox News website, I found that directory indexes are turned on. So, I started following the tree up, until I got to /admin. Eventually, I found my way into /admin/xml_parser/zdnet/, in which, there is a shell script. Seeing as it's a shell script, and I use Linux, I took a peek.…
-
Greek spies plant rootkit in a phone exchange
"A highly sophisticated spying operation that tapped into the mobile phones of Greece's prime minister and other top government officials has highlighted weaknesses in telecommunications systems that still use decades-old computer code. The spying case, where the calls of around 100 people using Vodafone’s network were secretly tapped, remains unsolved and is still being investigated.…
-
MPack Reveals Stingy Web Hosts
"According to reports, thousands of Web sites, predominantly in Italy, were recently compromised using the MPack malware kit, which contained iframe tags that pointed surfers towards hacker-controlled Web sites. A security researcher at the SANS Institute's Internet Storm Centre says that only one of the Web sites hosted on the machine had to contain a…
-
CIA legend claims Belfast and Dublin major centres of industrial espionage
"A former top CIA agent has claimed Belfast and Dublin are world centres of industrial espionage where top corporations can buy secret information on their rivals. Bob Baer, whose life inspired the spy movie Syriana starring George Clooney, said Ireland was "just like Berlin during the Cold War". In an interview for RTE radio documentary…
-
UCD School of Medicine hacked
"According to officials, 1,120 applicant records for the 2007-2008 class at the UC Davis School of Veterinary Medicine have been hacked, in what marks the first time an example of unauthorized access to the university's computer systems has been coupled with evidence of attempted fraud. According to the university, the incident was discovered on June…
-
Hacker Defaces Microsoft U.K. Web Page
"A hacker managed a rare feat Wednesday, successfully attacking a Web page within Microsoft’s U.K. domain and replacing the page with several graphics related to Saudi Arabia. The hacked page was a U.K. events page here. It has since been fixed. According to the security site Zone-h, a SQL injection attack is the likely culprit.…
-
Quicken Backdoor Discovered
"A Russian firm that provides password-recovery services says it has found a backdoor in the encryption mechanism that Quicken uses to secure password-protected files, a feature that makes millions of users of the personal finance program more vulnerable to government spooks or other highly determined snoops. Elcomsoft, which made waves in 2001 after it circulated…
-
Department of Homeland Security gets Pwned, and pwned, and pwned
"The Homeland Security Department, the lead U.S. agency for fighting cyber threats, suffered more than 800 hacker break-ins, virus outbreaks and other computer security problems over two years, senior officials acknowledged to Congress. In one instance, hacker tools for stealing passwords and other files were found on two internal Homeland Security computer systems. The agency’s…
-
Gangs infect 10,000 websites to steal users’ bank details
"Hackers have launched an assault on websites in Italy and around the world dubbed the Italian Job in a move seen by internet security experts as the next step in the escalating problem of cyber crime. Gangs presumed to be based in eastern Europe have probably infected more than 10,000 web pages on popular websites…
-
New security breach revealed: Los Alamos National Labs
"Reports of a major breach of security involving the board of directors of the corporation managing Los Alamos National Laboratory came to light Thursday. The chairman of the House Energy and Commerce Committee that oversees the nuclear complex wrote to Energy Secretary Samuel Bodman citing information obtained by committee staff from sources outside the department.…