| 

What you need to know about BERserk and Mozilla

  • Post author: Omid Farhang
  • Post published: September 25, 2014
  • Reading Time: 1 min
  • Word Count: 193 words

The Intel Security Advanced Threat Research Team has discovered a critical signature forgery vulnerability in the Mozilla Network Security Services (NSS) crypto library that could allow malicious parties to set up fraudulent sites masquerading as legitimate businesses and other organizations. The Mozilla NSS library, commonly utilized in the Firefox web browser, can also be found in Thunderbird, Seamonkey, and other Mozilla products.Ā Dubbed ā€œBERserkā€, this vulnerability allows for attackers to forge RSA signatures, thereby allowing for the bypass of authentication to websites utilizing SSL/TLS.Ā Given that certificates can be forged for any domain, this issue raises serious concerns around integrity and confidentiality as we traverse what we perceive to be secure websites. ...

Continue Reading What you need to know about BERserk and Mozilla

Iranian Hackers targeting US oil, gas, and electric companies

  • Post author: Omid Farhang
  • Post published: May 26, 2013
  • Reading Time: 2 min
  • Word Count: 336 words

The Hacker News reported:Ā For all the talk about China and the Syrian Electronic Army, it seems thereā€™s another threat to U.S. cyber interests i.e. Iran. Series of potentially destructive computer attacks that have been targeting American oil, gas and electricity companiesĀ tracked back to Iran. Iranian hackers were able to gain access to control-system software that could allow them to manipulate oil or gas pipelines. Malware have been found in the power grid that could be used to deliver malicious software to damage plants.Ā The targets have included several American oil, gas and electricity companies, which government officials have refused to identify. ...

Continue Reading Iranian Hackers targeting US oil, gas, and electric companies

LulzSec Hacker Gets A Year For Sony Hack

  • Post author: Omid Farhang
  • Post published: April 20, 2013
  • Reading Time: 2 min
  • Word Count: 317 words

A former LulzSec hacker has been jailed for a year for ransacking Sony Pictures Entertainmentā€™s computer systems. Cody Kretsinger, 25, from Decatur, Illinois ā€“ better known to his fellow LulzSec cohorts as ā€œRecursionā€ ā€“ was also ordered to carry out 1,000 hours of community service, and a year of home detention, following his release from prison. He was sentenced by a Los Angeles court on Thursday, Reuters reports. Kretsinger had pleaded guilty to a single count of conspiracy and unauthorized impairment of a protected computer (i.e. computer hacking) in a plea-bargaining agreement. Kretsinger admitting breaking into the Sony Pictures website and extracting information which he passed on to other members of LulzSec, who leaked the data in order to embarrass Sony, a hated enemy of the hacktivist group. ...

Continue Reading LulzSec Hacker Gets A Year For Sony Hack

Anonymous-linked groups hack Israeli websites, release personal data

  • Post author: Omid Farhang
  • Post published: March 25, 2013
  • Reading Time: 3 min
  • Word Count: 540 words

An anti-Israel hacking collective affiliated with Anonymous says it has initiated a widespread cyber attack against the Jewish state, penetrating websites affiliated with the Mossad security service and a slew of related entities. The hackers claimed late Friday that they have obtained and released personal information relating to 35,000 Israeli government officials, including politicians, military leaders, and police officers, according to a Twitter feed associated with the hackers. ...

Continue Reading Anonymous-linked groups hack Israeli websites, release personal data

Emma Stoneā€™s twitter hacked

  • Post author: Omid Farhang
  • Post published: March 25, 2013
  • Reading Time: 1 min
  • Word Count: 186 words

3/22/2013: Emma Stone revealed that she was not behind the ambiguous tweets concerning boyfriend Andrew Garfield and co-star Shailene Woodley that sparked cheating rumors. Speculation surrounded Stoneā€™s mysterious ā€œtweet and deleteā€ spree over the past few months. Emma addressed the rumors on an On Air with Ryan Seacrest radio interview. One tweet in particular on her Twitter appeared to be an anagram that solved to read, ā€œAndrew and Shailene sitting in a tree.ā€ ...

Continue Reading Emma Stoneā€™s twitter hacked

Evernote is suspect of a hack, change your password

  • Post author: Omid Farhang
  • Post published: March 2, 2013
  • Reading Time: 2 min
  • Word Count: 415 words

Cross-posted from Evernote blog: Evernoteā€™s Operations & Security team has discovered and blocked suspicious activity on the Evernote network that appears to have been a coordinated attempt to access secure areas of the Evernote Service. As a precaution to protect your data, we have decided to implement a password reset. Please read below for details and instructions. In our security investigation, we have found no evidence that any of the content you store in Evernote was accessed, changed or lost. We also have no evidence that any payment information for Evernote Premium or Evernote Business customers was accessed. ...

Continue Reading Evernote is suspect of a hack, change your password

Facebook Got Hacked Last Month and Is Just Telling You Now

  • Post author: Omid Farhang
  • Post published: February 15, 2013
  • Reading Time: 2 min
  • Word Count: 273 words

Cross-posted from Gizmodo: Facebook just announced that it was hacked last month in a short statement on its website. Apparently, an unknown number employees visited a compromised developer site and were infected with malware. Facebookā€™s being very cagey about all this, but weā€™ve been able to scrounge up some details. According to the statement, the company reacted swiftly with an investigation and remediation following the ā€œsophisticated attack.ā€ The company wonā€™t say which law enforcement agencies itā€™s working with. It claims no user data was compromised. ...

Continue Reading Facebook Got Hacked Last Month and Is Just Telling You Now

1 million Apple Device IDs leaked, claim hackers

  • Post author: Omid Farhang
  • Post published: September 4, 2012
  • Reading Time: 2 min
  • Word Count: 255 words

According to the AntiSec hacker group, they claim to hold more than 12 million Apple iOS Unique Device IDs, in addition to other personal information from device owners. As a move to back up such a claim, the AntiSec hacker group is said to have released slightly more than a million Apple Device IDs to the masses. This particular expose was unveiled on Pastebin, which is said to hold a detailed description of the method that the hacking group were said to have obtained the IDs from the FBI. ...

Continue Reading 1 million Apple Device IDs leaked, claim hackers

AMD Blog Hacked, Database leaked on Internet

  • Post author: Omid Farhang
  • Post published: August 20, 2012
  • Reading Time: 1 min
  • Word Count: 136 words

TheHackerNews: A team of Hackers called, ā€œr00tBeer Security Teamā€ today hack into official blog of Advanced Micro Devices (AMD) which is a American multinational semiconductor company. AMD is the second-largest global supplier of microprocessors based on the x86 architecture and also one of the largest suppliers of graphics processing units. Hacker deface the blog page (http://blogs.amd.com/wp-content/r00tbeer.html) [Dead Link ā€“ Screenshot blow] and also leak the complete user database of blog on his twitter account. Leaked database SQL file uploaded on Mediafire by Hackers which include 200 AMD userā€™s Emails, WordPress Blog Usernames and Passwords. ...

Continue Reading AMD Blog Hacked, Database leaked on Internet

Bogus anti-hacking tool targets Syrian activists

  • Post author: Omid Farhang
  • Post published: August 19, 2012
  • Reading Time: 1 min
  • Word Count: 179 words

h-online: Syrian activists, journalists and opposition group members are reportedly under attack by malware claiming to be a security tool that will help protect them against hackers. The fake ā€œAntiHackerā€ tool is being spread through targeted phishing emails and via sites such as Facebook, and claims to provide ā€œAuto-Protect & Auto-Detect & Security & Quick scan and analyzingā€ functionality. ...

Continue Reading Bogus anti-hacking tool targets Syrian activists