Showing posts with label Cyber Threats. Show all posts
Showing posts with label Cyber Threats. Show all posts

Saturday, 3 October 2015

Kaspersky Wins Test Malware Removal



Anti-virus software must be able to not only detect malware, including the removal of an infection is part of a good working virus scanner. The Austrian test lab AV-Comparatives therefore decided to test 16 security packages to consumers on malware removal.

In total, were used for the test 35 different malware instances that had to remove the packages. These criteria include being sought for leave of executable files, MBR or registry changes, custom host files and programs that were disabled by the malware and after disinfection is still not working, like Windows Task Manager and the Windows Registry Editor.

The packages were evaluated for the simplicity with which the malware was removed, like removing normal mode, safe mode, using a rescue disk or calling the help desk to remedy the infection. Eventually, the virus could score up to 100 points. Kaspersky Lab sets with 93 points, the highest score down just before Avast (89) and Bitdefender (89). Sophos (72) and Threat Track Viper (65) put the lowest score down. Microsoft Windows Defender ends up with 80 points in the middle.

Monday, 28 September 2015

US Navy Ships Will Protect Against Cyber Attacks


The US Navy is working on a system to protect ships against cyber attacks, as more and more physical systems accessible via the Internet. The system is called Resilient Hull, Mechanical and Electrical Security (Rhimes) and to prevent malicious attackers to take over or turn off the mechanical and electrical control systems.

"The purpose of Rhimes is to repel cyber attacks," said Rear-Admiral Mat Winter. "This technology helps the Navy to protect the ship's physical systems, but it can also have important applications in the protection of the physical infrastructure of our country." The system must eventually prevent attackers from accessing the programmable logic controllers (PLCs), which are in communication with the physical systems of the ship.

To protect the ship systems used different techniques Rhimes to stop entire classes of attacks. In addition, the security system ensures that every controller just slightly different. An exploit for one controller will then no longer work for the other controllers. This technique can be used according to the Navy also, for example, factories, automobiles and airplanes. When Rhimes will be launched was not disclosed.

Saturday, 26 September 2015

Malware Allows Criminals Through Proper Code Empty ATM


Researchers have discovered a new instance of malware that criminals, after entering the correct PIN, the ATM shows empty. In recent years, several malware specimens found that money can be stolen from ATMs. The now discovered Green Dispensing malware is however designed to leave no trace after the theft.

The malware is doted with an effective removal process, says digital security company Proofpoint. To install Green Dispenser is likely to require physical access to the ATM, where Proofpoint does not exclude employees who are responsible for the security or control of the machine also play a role in infections. Once Green Dispenser operates like any ATM malware, but it also has several distinct features.

Thus the malware works only if it is the year 2015 and the month earlier than September. In addition, a kind of two-factor authentication is applied. Indeed, there are two PINs required to access the malware. A fixed PIN and a dynamic PIN. The second PIN is obtained by scanning a QR code on the screen of the infected ATM. Only authorized people can empty the machine in this way. The malware can give an "out of service" message.

Another feature that stands out is how the malware deletes itself after the theft. For this it uses SDelete, a Microsoft program to permanently delete data. Green Dispenser is still observed only in Mexico, but that may change as Thoufique Haq of Proofpoint. "While current attack only to certain geographical areas such as Mexico are limited, it is only a matter of time before these techniques are used worldwide."

Hashes(SHA256):

Sunday, 22 March 2015

14,000 US Patients Data Stolen By Email Hacking


An American healthcare has warned 14,000 patients that their data is stolen after a third party that handles billing with was to create an e-mail hack. One of the employees of this company was last year, according to the carer the victim of an " email hacking attack , "where username and passwords were compromised.

The incident was on December 3 last year discovered by the billing company, while the caregiver was told that on February 2 this year. Then there was established a research which showed that in the e-mail account of the attacked employee was the personal information of 14,000 patients, including names, date of birth, diagnosis, procedure, treatment dates, account numbers, costs and names of doctors.

In the case of 40 patients it was also to social security numbers. The healthcare provider will notify all affected patients by mail. In addition, there will be the email provider to see whether the already "robust security" can be tightened and staff will "email hacking attacks" are informed.

Just Patched Flash Player Flaw In sight Cybercriminals



A critical vulnerability in Flash Player that last week was patched used to attack Windows users. Through the vulnerability an attacker can place malware on your computer, for example if the user visits a malicious or hacked website or see a banner gets infected.

Report that security company FireEye and anti-virus company Malwarebytes . The exploits of the leak abuse is added to the Nuclear Exploitkit. This makes it easy for cybercriminals to attack unpatched Flash Users via the vulnerability. In the case, the attack is successful, a Trojan horse is installed there.

Although the update is available for a week does not mean that everyone who has installed, says analyst Jerome Segura."We know that in some cases, consumers, but usually companies, can not immediately install patches. In many cases, there must first be internally tested so that the patch does not disturb any business processes." The analyst advises organizations in this case to shield these systems from other systems on the network.

Saturday, 21 March 2015

Kaspersky Denounces "Sensationalist Reporting" About KGB Ties



Eugene Kaspersky, founder of the Russian anti-virus company, has lashed out at a journalist from Bloomberg because of an article about alleged links between the virus fighter and Russian intelligence services. "It's a long time since I read an article from the first line felt so inaccurate," says Kaspersky.

The article by Bloomberg followed an article by Reuters , which stated that Kaspersky Lab kinds of American cyber-espionage operations would have revealed but would be reluctant to do this in Russian cyber operations. According to Kaspersky search journalists to conspiracy theories where the Kremlin is playing a role. However, the article by Bloomberg was full of false information, speculation and unfair conclusions is based on wrong facts.

"In their hunger for sensation journalists have turned things and ignored some obvious facts. Congratulations to the authors, they have scored well in bad journalism." The Russian fighter virus indicates that anti-virus company actually has unveiled espionage operations that have been attributed to Russian cyber spies. Furthermore, says Kaspersky he never worked for the KGB.

"I have studied mathematics at a school that was sponsored by the Department of Atomic Energy, the Ministry of Defence and the KBG. After I graduated, I worked for several years as a software engineer at Defence", let Kaspersky know. He also denies regular sauna visits with Russian intelligence officers. He also mentions the cooperation between Kaspersky Lab and all investigative agencies, such as Interpol and Europol.

According to Kaspersky, it is difficult for a company with Russian roots to become successful in Europe and the United States. "By default, we are trusted by no one. Our only strategy is to be 100% transparent and fair. It took years to explain who we were. Many people tried to find the" dirty laundry "and failed, because there is nothing to hide is. "

Politics

In response to the message sent by Reuters Kaspersky also been a reaction to various media. It let him know to choose a political side. "As governments and their spies treat the Internet as a battlefield, it is increasingly important for IT security to interfere in politics. There is no other way to examine all cyber threats and protect here. If you choose a side transfer your effectiveness at risk. If you ignore certain malware you are partially blind and unable to provide full protection. "

Monday, 16 March 2015

US Gets Email System Offline To Remove Malware


The US State Department has an unclassified e-mail system was taken offline to remove malware that already four months on the network would operate. The malware was discovered in November, when the e-mail system was taken offline and measures were taken.

Last month, however, there appeared a report in the Wall Street Journal that the malware still was not completely removed.Now let government officials across ABC News that a last attempt is made ​​to clean up the system. In a statement on their own website says the ministry because of several security enhancements to the network shortly maintenance will find the system. There were certainly no classified systems or financial consular or HR systems are compromised.

"The recent increase in news stories about cyber incidents shows that the Department on a list of public institutions and companies are having to deal with an increasing number of sophisticated cyber threats," the statement said. In addition to a team of experts from other ministries and the private sector to protect the data of the Ministry, would be a strategy simultaneously performed to better secure the infrastructure of the Ministry. How the malware on the e-mail system was able to get was not disclosed.