FireSale HackBoy

Knowledge Shared By FireSale HackBoy...

Hacking

The Art Of Exploitation...

Ethical Hacking

Security Experts...Same Techniques To Make Hacker's Stuff Useless.

Black Hat Hacking

Dark Side Of Hacking... In Short Destruction Of Cyber Stuff.

Digital Stuff

All The Digital Stuff Is Under The Influence Of Cyber Attacks... Be Safe

Thursday, January 23, 2020

Ransomware attack on Tampa Bay Times

Tampa Bay Times, which happens to be one of the renowned American newspapers has admitted formally that it has become a recent victim of a ransomware attack. However, the good news is that no data related to the publication was compromised in the incident and the IT staff are busy cleaning up the malicious file-encrypting code.

 

For those who don’t know much about the existing cyber threats, Ransomware is a kind of malware that infiltrates into a computer network and locks down data until a ransom is paid. Earlier, hackers used to just indulge in this activity. But from the past 6 months, they are also stealing data before encrypting a database so that they could sell that stolen data on the dark web to make money if the victim fails to pay or threaten the victim to sell the data to extract more sum. Furthermore, in recent times, hackers are seen devising ransomware in such a way that it also starts extracting credentials from the web browsers which includes passwords and other sensitive information stored in the cache.

 

Times digital officer Conan Gallaty has confirmed the news and assured that no card details and customer email addresses were accessed by the hackers in the incident.

 

Gallaty also confirmed that their publication is not going to entertain the hackers in any way and will just rely on backups for data restoration.

 

Sources from the Tampa Bay Times said that the daily newspaper was hit by a Ryuk ransomware which was developed by a state-funded hacking group named “Wizard Spider” from Russia. Security firms CrowdStrike and Malwarebytes have endorsed the incident. However, Malwarebytes has added in one of its recent statements that Ryuk evolution is also associated with another Russian group named CryptoTech.

 

Apart from the Tampa Bay Times, Chicago Tribune also became a victim of the same cyberattack in 2018 which infected other publications such as South Florida Sun-Sentinel, The Los Angeles Times and San Diego Tribune as all of them shared a common printing network.

 

Note- The FBI issued a warning in Oct’19 to report any incidents at www.IC3 dot gov. Initially, it also discouraged victims from paying the ransom to the hackers. However, in Dec’19 it changed its statement and urged victims to act accordingly and pay if the situation demands.

 

The post Ransomware attack on Tampa Bay Times appeared first on Cybersecurity Insiders.


January 24, 2020 at 11:23AM

Albany County hit by second Cyber Attack in January 2020

News is out that Albany County of New York was hit by a second cyberattack in just three weeks of January 2020. However, officials are confident that they will recover from this attack as soon as possible and will put an end to all their cyber sufferings by this month’s end.

 

Earlier this month the Albany County Airport Authority was in the news for becoming a victim of a ransomware attack on the Christmas day of last year. As the IT staff of the airport were helpless, they paid a 5 figure ransom to the hackers in Bitcoin to free up their data from the file-encrypting malware.

 

Phillip Calderone, the CEO of Albany Airport latest released a press statement that the hackers infiltrated its network through a third party company named LogicalNet, which was supposed to look into the Cybersecurity services of the airport. As it failed to render its services on an efficient note, Phillip clarified that the airport authorities were seeking a recovery of $25,000 deductible to be paid to the insurance provider as the next premium.

 

Now, Albany County is back in news for the reason of a similar sort. Reports are in that the Albany County Town of Colonie was hit by a Cyberattack on January 15th of this year and turned the town’s computer system and email systems offline.

 

Sara West, the spokesperson of the town confirmed the news and stated that the backup data will be used for data continuity purposes and stated that only a small portion of services was disrupted by the incident.

 

However, the communication system is reported to have been hit severely and so the county has chosen to practice old communication methods till the situation comes under complete control.

 

No critical information was compromised in the incident and all precautions to prevent such incidents taking place in the future were being taken.

 

Note- In March 2019, the City of Albany was hit by a ransomware attack after which Mayor Kathy Sheehan and other officials decided to spend $300,000 on new hardware and software including servers, firewalls, and threat monitoring solutions. As the county had resorted to back up data for critical applications, at that time they decided to pay no ransom to hackers.

 

Meanwhile, in another news related to a malware incident, officials from Tillamook County located in the US State of Oregon report that their websites and phone lines were disrupted by a cyber incident from the afternoon of Thursday. However, the officials are yet to confirm the details related to the kind of cyber attack. Only the 911 dispatch center and the emergency services are working fine as of now as the services run through a different server. The rest of the services including those related to the Sheriff’s office and the Justice court are reported to be down. So, the dockets related to the Justice Court are being processed on a manual note.

The post Albany County hit by second Cyber Attack in January 2020 appeared first on Cybersecurity Insiders.


January 24, 2020 at 11:22AM

Five key takeaways from European Utility Week 2019

This year’s European Utility Week represented an exciting opportunity for manufacturers and service providers to showcase the latest developments in the utilities spaceWith so much of the world’s attention rightfully focused on the climate crisis, and especially on reducing the impact of household emissions on the environment, the most recent event detailed numerous innovative technologies that are helping to mitigate environmental impact at home – as well as interesting developments in the provision of data and grid management, among others. Here are five key takeaways from this year’s event, which took place in Paris, France.  

Benchmarking the shift to renewable energy  

The move to renewable energy has already been well underway for the last few years, but this year’s EUW event was a chance to showcase just how much the industry has moved in that direction. The environmental reasons behind this move are more than compelling, especially looked at through the lens of utilities provision – in fact in the UK, 40% of emissions now come from households. Then there’s the added consideration of limitation of non-renewable sources, which make this move an absolute must. 

In light of this, much of this year’s event centred on new sources of energy, as well as innovations in those fields – from solar panels and windmills to electric cars. There was also a look at how we can make better use of our current resources by leveraging well-balanced grid management, which is improving all the time thanks to increased transparency around supply and demand. 

Francis D’Souza, VP Strategy – Analytics & IoT at Thales, speaks at this year’s EUW

Effective grid management needs transparency and security

Grid management is a key part of making sure energy provision is both efficient and more environmentally friendly – which is a topic that repeatedly cropped up at this year’s event. Those in charge of the grid need to see who is producing what, as in the future, energy production will be judged by what is required at the individual household level. This then allows grid controllers to see whether there is any excess in terms of the energy supplied, and if there is something left to be sold once the household’s needs are completed.

This should be combined with a very transparent view of the needs of the people to make sure that production loads map as closely to demand as possible. They also need to give a clear indication to people on what they are spending and when energy is available, so that households can better consume and spread their energy usage.

In light of this, grid managers should receive accurate data from household and buildings’ electricity needs, in real-time, to best adjust. This means that devices need 24/7 reliable connectivity. Device connectivity and performance should be monitored carefully, to ensure that devices are working optimally, and according to highly demanding SLAs. Connected meters and the data they generate should also be protected to make their way to the grid manager, in a secure and efficient manner.

Giving consumers more control

As consumers become more environmentally conscious, they are also becoming more engaged with their own energy consumption. While some are physical participants in determining where they source their energy from, such as those who have installed solar panels at home, the wider populace is equally becoming more conscious of when and what they should consume.

This year’s EUW sought to tackle the question of how to handle more control to consumers – and bridge this prevailing knowledge gap. The availability of resources at a point in time should be transparent to consumers, allowing them to make choices about when to best consume more energy, or if their energy consumption can wait a bit until the demand is slowing down.

Smart meters as a service

This year’s event also addressed another key trend in the utilities space – namely that of smart meter providers offering end-to-end services, rather than just the provision of the unit itself.

This is an interesting and important shift, not least because it looks set to improve the total user experience of smart meter ownership. As a result, it will mean that smart meter manufacturers are also responsible for providing the right connectivity and making sure the continued connectivity performance levels are satisfactory. It will also mean that they respect SLA (service level agreements) and that the costs are at or below the business case calculation. From a consumer point of view, it will also mean that the providers are integral in making sure the Total Cost of Ownership doesn’t increase.

Leveraging cellular networks for high-quality data capture

To achieve the above trends, grid managers are looking at getting more accurate data in real-time to effectively manage the grid and make the best decisions for a good balance of energy demand and supply.

With the widespread uptake of smart meters, devices should be able to generate data and alerts in case something is suspicious or going wrong; if grid managers have implemented the right predictive and prescriptive analytics tools, they will be able to react quickly – such as if a strange device behaviour is highlighted, or if a software update is needed. They should be able to retrieve accurate data from the smart meters in real-time and analyse it in an efficient way. This will help them to push any requested updates to their fleet of meters, remotely, to avoid costly truck roll replacements or repairs.

The provision of real-time, accurate data is key if smart meter manufacturers are to make the jump to becoming service providers. But even more importantly, the data that is generated needs to be protected to make sure that what the grid receives isn’t manipulated – which could lead grid managers making the wrong decisions. As EUW highlighted, meters therefore need to be designed with security as a top priority to make sure the infrastructure is always secure. Thales’ Trusted Key Manager, which we showcased at the event, can help secure smart meters by ensuring mutual digital authentication of key energy actors and encryption of all data.

To find out more about European Utility Week and how your smart energy device can achieve end-to-end security, connect with Francis D’Souza

The post Five key takeaways from European Utility Week 2019 appeared first on Cybersecurity Insiders.


January 24, 2020 at 09:09AM

Healthcare security: How can blockchain help?

This is part 2 of a blog on healthcare security. For more info, check out part 1. An independent guest blogger wrote this blog.
When it comes to data security, there is no more important place than the healthcare industry. When people go to the doctor, they provide all of their most sensitive information, from their health issues to their phone number, to a doctor they trust. When a medical office or database is hacked or damaged, and that information is released, it can be catastrophic to everyone involved.
Patient security is not only good practice, but it is also the law. Guidelines are in place to protect patient data, and it is up to health professionals and administrators to ensure that proper protections are made. Here are some best practices for now and advanced security platforms to look forward to in the future.
The rise of blockchain technology
While the…

Devin Morrissey Posted by:

Devin Morrissey

Read full post

      

The post Healthcare security: How can blockchain help? appeared first on Cybersecurity Insiders.


January 23, 2020 at 09:12PM

How could the IoT impact the world of work?

The digital transformation occurring in all parts of our lives has also brought many benefits to the office environment that we now couldn’t imagine living without. The pace of this digitisation is something that has been snowballing over the past 50 years, especially since the introduction of computers at work. It wasn’t so long ago that we had to dial-in to network via a modem, faxing clients or using floppy disks to transfer files.

Nowadays, the big changes in workplace technology are less about office mobility and more towards creating the best possible work environment, where the hours spent doing admin are reduced, employee wellbeing is at the center of company policy and monetary and environmental costs are minimised. Implementing smart devices and systems is at the heart of this business transformation, but IoT security needs to be front of mind when embarking on this journey.

With data breaches and GDPR fines at an all-time high, adding more devices that use swathes of data into the office environment certainly needs to be taken seriously. However, it is also worth knowing the benefits the IoT can bring to a business, so companies can make informed choices whether or not to use this technology.

Digital Assistants

One of the most familiar uses of the IoT is digital assistants, which nowadays many people use in their home. However, these devices are still not widespread in the office environment. The obvious use-case of a digital assistant in the office is to help employees with their personal tasks and making calls. However, they have much greater potential than this.

Digital office assistants can, for example, tell you which meeting rooms are free, control conference room equipment settings and order supplies based on the frequency of your order history. In addition, it is possible for a digital assistant to know you have a meeting coming up in your calendar, mine the dial-in information, dial into the conference provider, and start the meeting, all without you having to worry about finding the conference ID and international country code number. Then, once you are in the meeting room, the assistant can turn on the smart TV or screen and dim the lights automatically, without you having to lift a finger.

Smart Buildings

In the traditional sense, smart buildings are those that use IoT systems, such as smart meters and smart security systems for cost savings and for remote operation. A smart heating system, for example, can understand how the temperature in the office changes with different weather conditions and can adjust the air conditioning or heating accordingly. However, with more recent developments IoT smart buildings systems can be linked to the number of people using the computers. Using this data, the system would be able to tell exactly which section of the office may need more air conditioning than another and can therefore more precisely direct heat/air to these areas. For building operators this represents a huge cost saving as money is no longer spent on heating an empty floor.

Using IoT in office buildings would also mean reducing the disruption from the time spent searching for empty spaces around the office, providing a smoother and more personalised experience for clients or employees alike. For example, a customer or supplier that often comes to your office could be greeted by a personalised welcome message with their name and company logo at reception, as soon as they enter the building. Today, many companies are adopting hotdesking policies where employees no longer have their own desks but share the same space with colleagues. Digital assistants could help navigate this by sending employees notifications on their smartphones to let them know which desks are free as soon as they go in the lift.

IoT could also reduce ‘office congestion’ at peak periods like lunch. To do this the IoT would need to be connected to a specific device, such as a smart phone or a wearable device. Then, this object would collect data related to your behavior, for example what floor you usually get off on. It could then use this information to send you a notification about which lift was next going to that floor and when to expect it. Not only would this keep people moving around smoothly but it could cut energy consumption. While it can be expensive to put these measures in place, the cost benefit analysis shows that these measures are often worth the overhead, in the long-term.

Smart desk objects and wellbeing

The U.S. Occupational Safety and Health Administration (OSHA) estimates that employers pay almost $1 billion per week treating the effects of poor office ergonomics, including bad posture, heavy lifting and burnout. And while many companies now have policies in place to educate their workforce the IoT can also be used to help prevent these problems by providing up-to-date analytics on employee health and wellbeing.

Smart desks for example, can warn you if you’ve been sitting too long and smart chairs have sensors to alert employees when their posture is bad and can even provide recommendations for improvement. What’s more, wellness wearables can be given to employees to alert the users when they need to take a walk, change the light settings on their computer or even drink a glass of water. Using up-to-date analytics in this way can help optimise the working environment for employees, increasing concentration levels and helping people be more productive.

With the smart office industry predicted to be worth $57 billion by 2025 we are only at the beginning of the curve for smart products in the office. Innovative IoT tools have the power to help employees and businesses make better decisions about their day-to-day activities and long-term operations. Not only can these devices help create efficiencies in the workforce, but they can also cut down environmental and monetary costs for businesses.

How might our offices look like in 2050?

Creating the best possible work environment using smart tech solutions is critical to the future of work. If you don’t believe this is the case, just think back to life without laptops 30 years ago and how having them impacted your working mobility. With significant opportunities in the IoT market, in another 30 we could be looking at a completely different office environment again. For example, we won’t need to use a pass or to sign in into the building, but will be recognised by behavioral patterns such as the way we walk and the tone of our voice, when we get to reception we would be greeted by robots and when we enter a meeting we would be able to project a 3D hologram of a colleague who works in another country. The opportunities are endless!

Do you use the IoT at your office? Let us know by tweeting us @Gemalto

The post How could the IoT impact the world of work? appeared first on Cybersecurity Insiders.


January 23, 2020 at 09:09PM

Sodinokibi Ransomware attack on GEDIA

German automobile spare parts maker GEDIA is in news for wrong reasons. A hacking group related to Sodinokibi is threatening to publish data which it procured after encrypting the database of Gedia with the file-encrypting malware.

 

News is out that the hacker’s group related to Sodinokibi wants to prove their stand and so are threatening the automotive company to publish a portion of data that has been encrypted for ransom.

 

 

Going deep into the details, the Sodinokibi group has announced yesterday that a Microsoft Excel sheet containing over 50GB data of the company’s Active Directory is with them and was stolen before their team encrypted the entire database.

 

Security experts believe that the infiltration and malware induction took place with the open-source AdRecon Tool.

 

Note 1- GEDIA which has its business operations in the United States, Hungary, India, Mexico, Spain, Poland along with Germany is yet to confirm details of the ransomware attack. But Sodinokibi reported on a Russian hacking forum that they now hold ownership for data related to drawings, employees and customers which will be published onto the internet if Gedia fails to pay them a demanded sum in Cryptocurrency.

 

Note 2- Sodinokibi has indulged in similar tactics earlier as it infiltrated the database of Artech Information Systems and published their data when the diversity supplier failed to bow down to the demands of the hackers.

 

Note 3- No More ransom project which is being backed by Law enforcement agencies, IT and Cybersecurity firms like Barracuda, Kaspersky, Europol, and McAfee promises to offer a free decryption tool for such malware in near future.

 

Note 4- And the companies need to know that the only preventive measure to avoid this malware is to create awareness among the staff to not click on phishing emails and keep the OS & security software updated with the latest patches.

The post Sodinokibi Ransomware attack on GEDIA appeared first on Cybersecurity Insiders.


January 23, 2020 at 08:49PM

Wednesday, January 22, 2020

FTCODE Ransomware steals credentials and passwords

A Ransomware strain named FTCODE which has been in prevalence since 2013 is now been reintroduced into the web world by hackers with some new features and tools. Security experts claim that this file-encrypting malware is now capable of stealing passwords and other credentials stored in web browsers and email clients which can push the victims into serious trouble when targeted.

 

Almost 7 years ago, this ransomware first emerged into the web by infecting some computers in Russia. And is now seen spreading to western countries by already targeting victims in Paris, Italy and some parts of the UK.

 

According to the analysis made by Zscalar ThreatLabz, researchers have found that the FTCODE has the ability to steal passwords from popular browsers such as Firefox, Chrome, Explorer and Microsoft Outlook.

 

Currently, information on how many victims were hit by the ransomware is yet to be known, but the evolution of FTCODE from just a file-encrypting malware to passwords stealing maleficent software is confirmed.

 

Note 1- SOPHOS was the first cybersecurity firm to spot FTCODE in 2013 and added in their discovery report that the ransomware strain uses Powershell to help develop Crypto-locking malware.

 

Note 2- All these days we have seen hackers first stealing a portion of data from the encrypted database to later sell that stolen info if their negotiations with victims in getting a ransom to fail. Now, the developers of the ransomware seem to have evolved further by stealing password credentials from the browsers loaded on the infected device.

 

The post FTCODE Ransomware steals credentials and passwords appeared first on Cybersecurity Insiders.


January 23, 2020 at 11:12AM