New evidence suggests DNC hackers penetrated deeper than previously thought

The suspected hacking of a Democratic National Committee consultant’s personal Yahoo Mail account provides new evidence that state-sponsored attackers penetrated deeper than previously thought into the private communications of the political machine attempting to defeat Republican nominee Donald Trump. According to an article published Monday by Yahoo News, the suspicion was raised shortly after DNC consultant Alexandra Chalupa started preparing opposition research on Trump Campaign Chairman Paul Manafort. Upon logging in to her Yahoo Mail account, she received a pop-up notification warning that members of Yahoo’s security team “strongly suspect that your account has been the target of state-sponsored actors.” After Chalupa started digging into Manafort’s political and business dealings in Ukraine and Russia, the warnings had become a “daily occurrence,” Yahoo News reported, citing a May 3 e-mail sent to a DNC communications director. (credit: Yahoo News) It was one of more than 19,000 private DNC messages posted to WikiLeaks on Friday. The massive e-mail dump came five weeks after DNC officials said hackers with backing from the Russian government had breached its network and made off with opposition research into Trump and almost a year’s worth of private e-mail. The airing on WikiLeaks, which included messages in which DNC officials derided Democratic candidate Bernie Sanders, has already led to the resignation of Chair Debra Wasserman Schultz. Now, the revelations about Chalupa’s Yahoo account suggest the hack may have gone deeper than previously reported. Read 3 remaining paragraphs | Comments

Read the article:
New evidence suggests DNC hackers penetrated deeper than previously thought

Russian Hackers Reportedly Stole Donald Trump Opposition Research From The DNC

Russian hackers were able to snatch all of the Democratic National Committee’s opposition research on Donald Trump, according to US officials who spoke to the Washington Post . The hackers were able to read emails and instant messages as a result of the breach. Read more…

Continue Reading:
Russian Hackers Reportedly Stole Donald Trump Opposition Research From The DNC

Uber Takes $3.5 Billion from Country Where Driving While Female Is Illegal

Uber, Silicon Valley’s moral compass, just accomplished perhaps the greatest-ever feat of brand synergy: The New York Times reports that the transit company just banked a $3.5 billion funding round from the Saudi Arabian government, which prohibits women from driving under penalty of lashing . Read more…

Continue reading here:
Uber Takes $3.5 Billion from Country Where Driving While Female Is Illegal

Fiverr Suffers Six-Hour DDoS Attack After Removing DDoS-For-Hire Listings

Two days after Fiverr, a marketplace for digital services, removed user listings from its website that advertised DDoS-for-hire services, the company’s website suffered a six-hour long DDOS attack. Softpedia reports: The incident took place on the morning of May 27 (European timezones), and the service admitted its problems on its Twitter account. At the time of writing, Fiverr has been back up and functioning normally for more than two hours. Fiverr’s problems stem from an Incapsula probe that found DDoS-for-hire ads on its marketplace, available for $5. Incapsula reported the suspicious listings to Fiverr, who investigated the issue and removed the ads. Fiverr first removed all listings advertising blatantly illegal DDoS services, but later also removed the ads offering to “test” a website for DDoS “protection” measures. Read more of this story at Slashdot.

Taken from:
Fiverr Suffers Six-Hour DDoS Attack After Removing DDoS-For-Hire Listings

Ethical Hackers Donate 1,000,000 Air Miles To Charity

An anonymous reader writes:Certified ethical hackers at Offensi.com identified a bug allowing remote code execution on one of United Airlines’ sites, and submitted their findings to the airline’s “bug bounty” program. After a fix was placed into production, their team was awarded 1, 000, 000 Mileage Plus air miles, which they say was accompanied by an email informing them that the IRS would consider their award as $20, 000 of taxable income. “If after evaluating the taxable amount you choose not to accept your award, you are also able to donate your award to charity, ” the e-mail explained. The hackers ultimately chose to distribute their air miles among three charities — the Ronald McDonald house, the Muscular Dystrophy Association, and the Casa de Esperanza de los Ninos Organization. Another security researcher complained in November that United failed to close a serious vulnerability he’d identified for almost six months. Read more of this story at Slashdot.

Visit site:
Ethical Hackers Donate 1,000,000 Air Miles To Charity

Hackers tried and failed to steal a billion dollars from bank

Hackers stole $80 million from a bank, but it could have been a lot worse if they had just Googled the name of a company, according to Reuters . Thieves got inside servers of the Bangladesh Bank, stealing the credentials used to make online transfers. They then bombarded the Federal Reserve Bank in New York with up to 13 money transfer requests to organizations in the Philippines and Sri Lanka. The Fed allowed four to go through totaling $81 million, but the next one was flagged by a routing bank in Germany because the hackers misspelled “foundation” as “fandation.” Once alerted, officials put a stop to the the remaining transfers, which amounted to nearly $850 million. The $81 million theft is still one of the largest ever, but if all the transfers had gone through, it would have been one of the biggest heists on record. Last year, Russian hackers reportedly got away with up to $1 billion from 100 banks using malware. Meanwhile, Bangladeshi officials are trying to lock down their systems and figure out how the attack happened, but say there’s little hope the hackers and money will be recovered. As with many large-scale attacks , experts told Reuters that the thieves likely targeted and spied on employees to gain access to servers. While the bank blames the US Federal Reserve Bank for not stopping the transfers, Fed officials say that it’s systems were not breached and that it has been cooperating in the investigation. Luckily, hackers are just as bad at spelling in large fraud attempts as they are in basic spear-phishing attacks. Source: Reuters

More:
Hackers tried and failed to steal a billion dollars from bank

Hackers hold Hollywood hospital’s systems for ransom

A Hollywood hospital is having to rely on pencil and paper after a ransomware attack. For more than a week, the computer systems at Hollywood Presbyterian Memorial Medical Center have been down at the hands of hackers . In addition to having to keep registration and logs on paper, staff is without email access and unable to use some patient records. Patients have been transported to other facilities as the computers needed to complete lab work, pharmacy tasks and CT scans are all unavailable. Hospital officials say they’re working with LAPD and the FBI on the investigation, but they’ve yet to determine who is responsible for the attack. President and CEO Allen Stefanek said the attack was random, and local news outlets report that the breach shows signs of a ransomware-style bug. Details on the intrusion are still quite scarce, but the culprits are demanding 9, 000 bitcoin or just under $3.6 million in exchange for the key to restore the facility’s systems. Source: CSO

Taken from:
Hackers hold Hollywood hospital’s systems for ransom

Hackers get Linux running on a PlayStation 4

In the two years since the PlayStation 4 first went on sale, hackers have enjoyed limited success in their efforts to open up the console. In June, a Brazilian team claimed the first PS4 “jailbreak, ” which involved the cumbersome process of copying the entire hard drive of a hacked machine using a Raspberry Pi, but it took until this month for a tinkerer to fully circumvent Sony’s content protections . With a proper exploit in the wild, homebrew group fail0verflow took on the challenge of installing a full version of Linux on the system. It achieved its goal this week, giving the homebrew community hope that the PlayStation 4 will soon become a worthy tool in their arsenal. Although exact details of the exploit have yet to be disclosed, it appears that the fail0verflow team took a WebKit bug recently documented by GitHub user CTurt and then turned things up a notch. CTurt’s workaround focuses on the PlayStation 4’s Webkit browser, which is tricked into freeing processes from the core of the console’s operating system by an improvised webpage. The PS4 is powered by Sony’s Orbis OS, which is based on a Unix-like software called FreeBSD and is therefore susceptible to common exploits. With a route into the console’s system, fail0verflow then identified weaknesses in the PlayStation 4’s GPU. Engineers from semiconductor company Marvell were called out specifically and accused of “smoking some real good stuff” when they built the PlayStation 4’s southbridge chip. Before you start dreaming up your next DIY computing project, you should know that this proof-of-concept relies on PS4 firmware 1.76. Sony recently issued firmware 3.11 to consoles. While the bug has now been patched, it’s believed the jailbreak could be altered to achieve the same outcome on more recent firmwares. Incidentally, the WebKit bug identified here is the exact same one that affected Apple’s Safari browser, which put iOS 6.0 and OS X 10.7 and 10.8 at risk in 2013. It shows just how common WebKit-based software now is. While PS4 owners won’t be able to install pirated games anytime soon, fail0verflow’s achievement shouldn’t be dismissed. Sony went to a lot of trouble to ensure that unsigned code could not be run on the console. The company requires that the machine runs on the very latest software, meaning hacker groups still have a long way to go before the PlayStation 4 is made truly open to hobbyists — just like the PlayStation 3 officially was when it first hit shelves almost a decade ago. Via: VentureBeat

See the article here:
Hackers get Linux running on a PlayStation 4

APT Speed For Incremental Updates Gets a Massive Performance Boost

jones_supa writes: Developer Julian Andres Klode has this week made some improvements to significantly increase the speed of incremental updates with Debian GNU/Linux’s APT update system. His optimizations have yielded the apt-get program to suddenly yield 10x performance when compared to the old code. These improvements also make APT with PDiff now faster than the default, non-incremental behavior. Beyond the improvements that landed this week, Julian is still exploring other areas for improving APT update performance. More details via his blog post. Read more of this story at Slashdot.

View post:
APT Speed For Incremental Updates Gets a Massive Performance Boost

The Horrifying Vtech Hack Let Someone Download Thousands of Photos of Children

The latest details about a recent security breach at a kids’ toy company are in, and they are disturbing. A couple weeks ago, hackers successfully broke into the servers of connected toy maker Vtech and stole the personal information of nearly 5 million parents and over 200, 000 kids. What we didn’t know until now: The hackers stole pictures of kids, too. Read more…

View post:
The Horrifying Vtech Hack Let Someone Download Thousands of Photos of Children