ie8 fix

Cybercrime

How the Spamhaus DDoS attack could have been prevented

Nearly 13 years ago, the wizardly band of engineers who invented and continue to defend the Internet published a prescient document they called BCP38, which described ways to thwart the most common forms of distributed denial-of-service attack.

BCP38, short for Best Current Practice #38, was published soon after debilitating denial of service attacks crippled eBay, Amazon, Yahoo, and other major sites in February 2000. If those guidelines to stop malcontents from forging Internet addresses had been widely adopted by the companies, universities, and government agencies that operate the modern Internet, this week's electronic onslaught targeting Spamhaus would have been … Read more

Top Chinese university linked to alleged military cybercrime unit

The People's Liberation Army unit (PLA) allegedly responsible for cyberspying on Western targets has collaborated with a top Chinese university on networking and security research papers.

In a finding uncovered by Reuters, Shanghai Jiaotong's School of Information Security Engineering (SISE) and the People's Liberation Army Unit 61398 have worked in partnership on at least three papers in recent years. PLA Unit 61398 is well-known for its alleged links to cyberattacks on the West, after a report was released by security firm Mandiant which stated that an "overwhelming" number of cyberattacks originate from the single unit … Read more

Security reporter hit by 'swatting' attack

"Swatting" is what you do to a fly that's buzzing around your head. But when that fly is respected security reporter Brian Krebs, swatting is what you do to him when you want to scare him and possibly cause him serious physical harm.

As recounted by Ars Technica this morning and later today by Krebs himself, the reporter was at home and cleaning his house when he opened his front door to come face-to-barrel with at least three guns, including a shotgun, handgun, and semiautomatic rifle; numerous police officers; and a half dozen police cars.

The term &… Read more

Obama hosts meeting on cybersecurity with CEOs

President Barack Obama met with 13 chief executives yesterday to dig deeper into cybersecurity.

According to The New York Times, which first reported on the meeting, the discussion took place in the White House Situation Room and was a "two-way" exchange of information between the president and the chief executives.

AT&T CEO Randall Stephenson, along with chief executives at Exxon Mobil, Bank of America, and JPMorgan Chase, were all in attendance, according to the Times.

Over the last several weeks, a slew of companies has been hit with cyberattacks. Online banking sites have also been targeted. … Read more

White House demands China cease alleged hacking activity

The White House warned China today to end a campaign of cyberespionage against U.S. companies, saying in its toughest language yet on the issue that the hacking activity threatens to derail efforts to build stronger ties between the two countries.

U.S. companies are increasingly complaining that intellectual property is being stolen through attacks "emanating from China on an unprecedented scale," Tom Donilon, the president's national security adviser, said during a speech at the Asia Society in New York.

"The international community cannot afford to tolerate such activity from any country," Donilon said. "… Read more

Sudden death of U.S. engineer in Singapore linked to cyber espionage?

For years, the U.S. intelligence community has warned that cyber attacks from China and other countries are the biggest threat to our national security. Now, some are wondering whether the death of an engineer from California could be linked to cyber espionage.

In 2010, 29-year-old Shane Todd moved to Singapore for an engineering job with a government research firm called the Institute of Micro Electronics or IME.

"He was a young man that wanted an adventure and thought it would be super-cool to live in a foreign country and he really liked it when he first got there,&… Read more

Feds strike a deal with alleged illegal streaming site operator

After taking down Channelsurfing.net and arresting its alleged owner in 2011, the feds now seem to be easing up. Before going to trial, the government struck a deal earlier this month with the alleged site owner Brian McCarthy.

In a "Deferred Prosecution" memo filed on February 11, which was obtained by TorrentFreak, U.S. Attorney Preet Bharara writes that "after a thorough investigation, it has been determined that the interest of the United States and your own interest will best be served by deferring prosecution in this District. Prosecution will be deferred during the term of … Read more

Sentencing of LulzSec double agent postponed

Hector Xavier Monsegur, better known by his nom de plume "Sabu," was slated to face sentencing in New York City today for his role hacking into public and private Web sites as one of the hacktivists operating under the LulzSec label. All told, he faces a maximum time behind bars of 124 years associated with his guilty plea on ten counts of bank fraud and one count of identity theft.

But Monsegur, who subsequently worked as a double agent for the FBI, still awaits his fate. The authorities abruptly postponed his sentencing. No explanation was offered.

His cooperation … Read more

Apple: Employee computers were targeted in hack attack

Apple today said it too was targeted as part of the string of hacking efforts on companies and news agencies.

The iPhone and Mac maker told Reuters that hackers targeted computers used by its employees, but that "there was no evidence that any data left Apple."

In a statement, Apple said it discovered malware that made use of a vulnerability in the Java plug-in, and that it was sourced from a site for software developers:

Apple has identified malware which infected a limited number of Mac systems through a vulnerability in the Java plug-in for browsers. The malware … Read more

Ransomware cybercrime ring dismantled in Europe

A cybercrime ring that infected millions of computers with ransonmware to extort possibly millions of dollars from people in 30 nations has been broken up, the European police agency said today.

Masquerading as police agencies, the suspects paralyzed computers with a virus and told their owners that illegal online activity had been detected and that a fine would have to be paid to unlock their computers, Europol announced in Madrid.

Investigators said they had identified up to 48 variants of the virus, which typically installs itself by tricking users into downloading a malicious executable filed via a socially engineered message. … Read more