Friday, 30 September 2016
Yahoo whodunnit: Mystery surrounds hackers behind massive breach
A week after Yahoo said it was subjected to the worst data breach in history, details about who nabbed info on 500 million email accounts remain sketchy.
At least one firm says it wasn’t a “state-sponsored actor” as Yahoo claimed, but like many things related to hacks, cybersecurity and the dark web, even that claim is impossible to verify.
“The group responsible for the Yahoo hack are cybercriminals,” said Andrew Komarov, chief intelligence officer at InfoArmor. The companyposted a report on Wednesday detailing the involvement of “Group E,” a hacking syndicate that InfoArmor says it has been monitoring in dark corners of the internet for some time.
The FBI is currently investigating the data breach but hasn’t put forward a theory publicly about who is behind it. For the full article click here
from hacker samurai http://ift.tt/2dcwCUM
via IFTTT
FDA data open to hackers, lacks security features | hacker samurai
FDA data open to hackers, lacks security features
The United States Government Accountability Office (GAO) reported that the public health data is at risk to potential hackers after discovering that the computer systems of the Food and Drug Administration (FDA) lack security features.
The FDA is an agency under the Department of Health and Human Services (HHS). The GAO analyzed the agency’s seven information systems and found a total of 87 weaknesses including in its access controls, configuration management, contingency planning, and media protection. The report indicated that the FDA did not have adequate protection to the boundaries of its network, did not identify and authenticate systems users consistently and did not limit users’ access to the duties that they only required to perform. The agency also failed to encrypt system, audit and monitor system activity consistently and conduct physical security reviews of its facilities. For the full article click here
from hacker samurai http://ift.tt/2dgMeWh
via IFTTT
Thursday, 29 September 2016
Yahoo Claims Hackers Are State-Sponsored, But Security Experts Say Criminals Are Behind Data Breach
The massive data breach that Yahoo revealed last week is said by the company to have been carried out by a state-sponsored group. However, an information security firm has refuted the claim, stating that there is no evidence that the hackers acted on behalf of any government.
Yahoo has blamed a “state-sponsored actor” for the security breach that leaked the account information of 500 million users, including names, email addresses, phone numbers, encrypted passwords and security questions. According to Yahoo, the attack occurred in late 2014.
However, Yahoo has not stated how it arrived at the conclusion that the data breach was sponsored by a government, nor has it shown any evidence for such a claim. Yahoo has previously stated that it has systems in place to be able to detect state-sponsored attacks. For the full article click here
from hacker samurai http://ift.tt/2cY2j1L
via IFTTT