Shared posts

14 Jun 22:08

ISIS drone swarms targeting US troops in Syria...

Jeffrey J. Bloom

Unlike Mosul--where U.S. forces deployed an array of drone countermeasures--troops in Raqqa are operating with fewer resources & have limited defense against off-the-shelf drones. Sometimes used in swarms, they are often rigged to drop small 40mm grenade-sized munitions with a relatively high degree of accuracy.
https://www.washingtonpost.com/news/checkpoint/wp/2017/06/14/isis-drones-are-attacking-u-s-troops-and-disrupting-airstrikes-in-raqqa-officials-say/


ISIS drone swarms targeting US troops in Syria...


(Third column, 9th story, link)


14 Jun 21:29

FACEBOOK gives bots ability to negotiate...

Jeffrey J. Bloom

In some cases, bots "initially feigned interest in a valueless item, only to later 'compromise' by conceding it--an effective negotiating tactic [used by people]."
*However, the behavior was NOT programmed, "but was discovered by the bot as a method for trying to achieve its goals." #GhostInTheMachine
https://www.yahoo.com/news/facebook-gives-bots-ability-negotiate-compromise-175629309.html


FACEBOOK gives bots ability to negotiate...


(Second column, 12th story, link)


14 Jun 17:14

Industroyer is more dangerous than Stuxnet

Jeffrey J. Bloom

"Industroyer" exploits outdated protocols used by industrial systems. Originally created for off grid use, they're now connected & vulnerable.
https://betanews.com/2017/06/13/industroyer-bigger-than-stuxnet/

Remember Stuxnet, the worm that wreaked havoc across Iran's nuclear facilities? Security researchers from ESET say that they have discovered an ...
14 Jun 17:07

Tew: NSA site troubling for personal freedom

Jeffrey J. Bloom

Are the employees inside utilizing supercomputers to vacuum up billions of e-mails, social media posts and phone calls from American heroes or deplorable violators of our rights? Without oaths and warrants based on probable cause that a crime has been committed to justify their vacuuming of our private information don’t they continuously and daily violate the 4th Amendment prohibitions against such a vast collection of private data from Americans?

Tew: NSA site troubling for personal freedom ... from the airport, I sometimes drive by the seven NSA concrete fortress abominations in Draper, Utah.
14 Jun 17:03

Russia's Power Trip

Jeffrey J. Bloom

*Power disruption tools are nothing new, on March 4, 2007, the Department of Energy conducted the Aurora Generator Test, to see whether a hacker could destroy physical objects through strictly cyber means.
*This after a few years of studying vulnerabilities in increasingly automated critical infrastructure--banking & finance, transportation, telecommunications, gas & oil, water supply, & electrical power.
http://www.slate.com/articles/news_and_politics/war_stories/2017/06/russia_s_power_grid_cyberweapon_is_scary.html

The workings of these assets were increasingly run by automated control systems, which several commissions had warned were vulnerable to cyber ...
14 Jun 16:43

US: North Korea's been hacking everyone since 2009

Jeffrey J. Bloom

Hidden Cobra commonly target & exploit older Windows platforms, Flash & Silverlight. The best way to keep hackers out is using newer OSs that receive security upgrades. Homeland Security recommends removing Flash & Silverlight if they're not necessary.
https://www.engadget.com/2017/06/14/us-issues-alert-north-korea-cyber-attack-hidden-cobra/

US: North Korea's been hacking everyone since 2009 ... in the incidents, though they certainly sounded glad someone hacked Sony, ... The best way to keep the hackers out is to use newer OS that's still receiving security upgrades.
14 Jun 15:42

US issues alert over North Korean hacking group 'Hidden Cobra' and warns more attacks are likely

Jeffrey J. Bloom

Hidden Cobra (aka Lazarus Group & Guardians of the Peace) has compromised a range of victims since 2009 with DDOS, keyloggers, remote access tools & several variants of malware.
https://www.thesun.co.uk/news/3797609/us-warning-north-korea-hacking-group-hidden-cobra-cyber-attacks/

THE US has warned of a shadowy group of North Korean cyber hackers dubbed “Hidden Cobra” responsible for launching attacks on the West.
13 Jun 17:23

The “Internet of Things” is way more vulnerable than you think—and not just to hackers

Jeffrey J. Bloom

The problem, Weiss claims, is using the internet to control devices that it was never intended to control. Among these are industrial systems in power plants or factories, devices that manage the flow of electricity through the energy grid, medical devices in hospitals, smart-home systems, and many more.

... confirmed in Oct. 2016, when over 100,000 video surveillance cameras connected to the internet were compromised by a hacking group, turned into ...
13 Jun 17:19

Russian hackers infiltrated voter databases in dozens of states

Jeffrey J. Bloom

The cyberattack targeted software used by poll workers on Election Day, accessed a campaign finance database in at least one state and tried to delete or alter voter data in Illinois

Russian hackers infiltrated voter databases and software systems in 39 states during the 2016 presidential election, an incursion so brazen it ...
13 Jun 17:17

Government Cyber-security Experts have Insecure Website

Jeffrey J. Bloom

"The way I see it is, the FBI has to do something to catch criminals, and at least in this case they didn't resort to draconian methods such as mass surveillance without a warrant. Instead, they used a simple procedure with a warrant that doesn't need much technical ability."

This is exactly what I got by clicking on the NSA site shown above! Maybe it's just the NSA that's screwed up. DHS probably has a better link, since ...
13 Jun 17:13

Feds Hacked A Dark Web Shopper Plotting A Mail Bomb Hit

Jeffrey J. Bloom

"The way I see it is, the FBI has to do something to catch criminals, and at least in this case they didn't resort to draconian methods such as mass surveillance without a warrant. Instead, they used a simple procedure with a warrant that doesn't need much technical ability."

What does it take to catch those using dark web markets for illicit purchases? These days, feds rely on various hacking methods to uncover those ...
11 Jun 19:57

TippingPoint Threat Intelligence and Zero-Day Coverage – Week of June 5, 2017

Jeffrey J. Bloom

It’s better late than never if you haven’t had the chance to read one of the latest white papers from the Zero Day Initiative. Their paper, “Transforming Open Source to Open Access in Closed Applications,” sheds light on both old and new vulnerabilities found in Adobe Reader’s XSLT engine, including several that needed to be patched more than once. It focuses on techniques for auditing the source code of Sablotron to find corresponding bugs in Adobe Reader. The paper also presents a new source-to-binary matching technique to help researchers pinpoint the vulnerable conditions within Sablotron that also reside in the assembly of Reader. You will also see real-world application of these techniques demonstrated in the paper through a series of code execution vulnerabilities discovered in Adobe Reader’s codebase.

Zero-Day Filters

There are 16 new zero-day filters covering three vendors in this week’s Digital Vaccine (DV) package. A number of existing filters in this week’s DV package were modified to update the filter description, update specific filter deployment recommendation, increase filter accuracy and/or optimize performance. You can browse the list of published advisories and upcoming advisories on the Zero Day Initiative website

It's better late than never if you haven't had the chance to read one of the latest white papers from the Zero Day Initiative. Their paper, “Transforming ...
11 Jun 19:52

Stupidly easy for hackers to attack Eskom

Jeffrey J. Bloom

It's ridiculously easy for hackers to compromise Eskom’s central electricity distribution network, their systems have no "space break" or physical separation. Any virus could propagate through all systems without resistance, as happened to UK’s National Health Service when WannaCry hit.
https://mybroadband.co.za/news/security/214928-stupidly-easy-for-hackers-to-attack-eskom.html

It is ridiculously easy for hackers to attack Eskom's central electricity distribution network, said Jacques van Heerden of Global Technology Security ...
11 Jun 19:33

The verdict on stories of Russian hacking in the 2016 election

Jeffrey J. Bloom

There are two larger reasons to be skeptical of these stories. First, the Russian hacking stories have far more government support than most bouts of American hysteria. They have provided only flimsy evidence supporting their claims (the story will change if they release hard evidence). But before we take the intel agencies’ assurances as gospel, look at the Big List of Lies by US government officials since 1960(it is a big list, not remotely a complete list). How many times must they lie to us before we become skeptical?

Second, “extraordinary claims require extraordinary proof”. Saying that Russia has been conducting so many and such poorly constructed cyberattacks on the US — attacks in which they have little or nothing to gain — certainly qualifies as an “extraordinary claim”.

This is a relative small matter, but indicative of a larger problem for us. We have become a gullible people, making political reform difficult or impossible. Unless we fix this, the best we hope for is a change of rulers.

https://fabiusmaximus.com/2017/06/11/conclusions-on-russian-hacking-of-the-election/

The attributions of the various cyberattacks during campaign 2016 to Russia are familiar to readers of the US media during the past four decades.
11 Jun 19:16

Hackers Hold Projekt Red for Ransom

Jeffrey J. Bloom

"An unidentified individual or individuals have just informed us they are in possession of a few internal files belonging to CD PROJEKT RED. Among them are documents connected to early designs for the upcoming game, Cyberpunk 2077."
https://geekreply.com/geek-culture/2017/06/11/hackers-hold-projekt-red-ransom

Holy cow, this is the kind of story that writes itself. Video game developer Projekt Red, is being held for ransom over there game CyberPunk 2077.
11 Jun 19:11

SpaceX Releases Ultra-HD 4K Footage Of Falcon 9 Landing

by EditorDavid
Jeffrey J. Bloom

Last week SpaceX shared remarkable 4K UHD footage of their Falcon 9 landing, which seems almost Hollywood-level surreal, especially since it happens so quickly and accurately. 
https://www.youtube.com/watch?v=GrP3jHuLQ9o

An anonymous reader quotes 4K.com: On June 3, SpaceX's Falcon 9 rocket was placed into low-orbit for the sake of launching its Dragon spacecraft into their eleventh Commercial Resupply Services mission (CRS-11) to the International Space Station... Last week SpaceX shared on their Youtube channel the remarkable 4K UHD footage of the landing, and since many of us are not used to watching this kind of footage except for Sci-Fi movies or video games, the landing seems almost Hollywood-level surreal, especially since it happens so quickly and accurately. You can watch the video at 4k and 60 fps here if you happen to own a 4K TV or UHD PC monitor with the right hardware specs... The footage above isn't SpaceX's first 4K video of one of its launches. The company has also previously released other videos of even more impressive landings directly onto the surfaces of drone ships. The article also reminds readers that "If you are by any chance looking to send something or someone out of space, Elon Musk's company offers reasonable prices for their launching services, starting at $62 million for its Falcon 9 and $90 million for the Falcon Heavy."

Share on Google+

Read more of this story at Slashdot.

10 Jun 15:26

Fireball Malware Infects Millions - Threat Wire

by shannonmorse
Jeffrey J. Bloom

Fireball malware infects millions of computers worldwide, a OneLogin breach creates headaches for users, & Wikileaks is back with another Vault7 leak. All that coming up now on Threat Wire.
https://www.youtube.com/watch?v=fngjYO6DMvE

Fireball malware infects millions of computers worldwide, a OneLogin breach creates headaches for users, and Wikileaks is back with another Vault7 leak. All that coming up now on Threat Wire.

-------------------------------Shop: http://www.hakshop.com Support: http://www.patreon.com/threatwire Subscribe: http://www.youtube.com/hak5 Our Site: http://www.hak5.org Contact Us: http://www.twitter.com/hak5 Threat Wire RSS: https://shannonmorse.podbean.com/feed/ Threat Wire iTunes: https://itunes.apple.com/us/podcast/threat-wire/id1197048999 Help us with Translations! http://www.youtube.com/timedtext_cs_panel?tab=2&c=UC3s0BtrBJpwNDaflRSoiieQ ------------------------------

Links:http://blog.checkpoint.com/2017/06/01/fireball-chinese-malware-250-million-infection/ http://www.ibtimes.co.uk/fireball-malware-could-spark-global-catastrophe-after-infecting-250-million-computers-already-1624286 https://www.wired.com/2017/06/hack-brief-dangerous-fireball-adware-infects-quarter-billion-pcs/ https://thehackernews.com/2017/06/fireball-computer-virus.html https://www.onelogin.com/blog/august-2016-incident https://www.onelogin.com/blog/may-31-2017-security-incident https://krebsonsecurity.com/2017/06/onelogin-breach-exposed-ability-to-decrypt-data/ https://arstechnica.com/security/2017/06/onelogin-data-breach-compromised-decrypted/ https://motherboard.vice.com/en_us/article/identity-manager-onelogin-has-suffered-a-nasty-looking-data-breach https://thehackernews.com/2017/06/windows-hacking-implant.html https://arstechnica.com/security/2017/06/wikileaks-says-cias-pandemic-implant-turns-servers-into-malware-carriers/ https://wikileaks.org/vault7/releases/#Pandemic   Youtube Thumbnail credit:http://apocageddon.com/wp-content/uploads/2016/10/10b017_f7f33fe3dd4942bab14c189e089aed9b-mv2_d_2800_2000_s_2-1024x731-2800x2000.jpg  

10 Jun 03:25

Pulling The Pin On 'Russian' 'Hacking'

Jeffrey J. Bloom

Not one US senator asked former FBI Director James Comey to account for the sinister fact that the source of the explosive determination that “Russia hacked the DNC” computer system is a DNC contractor, not the FBI.

BURR: And the FBI, in this case, unlike other cases that you might investigate — did you ever have access to the actual hardware that was hacked?
10 Jun 03:22

AI App Identifies Plants and Animals In Seconds

Jeffrey J. Bloom

Using NVIDIA GPUs & cuDNN with the TensorFlow deep learning framework, iNaturalist trained neural networks using their massive database of images that have been labeled by the site’s community of experts. Currently, they're able to identify 10,000 different species & are adding new species to the model every 1.7 hours. An online demo is now live & you can help train the models by uploading & classifying images.
http://www.inaturalist.org/computer_vision_demo

The popular website for nature lovers, iNaturalist.org is launching a deep learning-based app that automatically identifies plants and animals down to ...
10 Jun 02:56

Scientists May Have Found a Way to Combat Quantum Computer Blockchain Hacking

Jeffrey J. Bloom

*bump* From May 25 CowNinja post:
The Russian Quantum Center said it secures the blockchain by combining quantum key distribution (QKD) with post-quantum cryptography, making it essentially "un-hackable." The technology creates special blocks that are signed by quantum keys generated by a QKD network.

Steve Conway: "Efforts like [this] are underway around the world. It’s difficult to assess this one in comparison with any other without having any technical details about what they’re doing."

Addison Snell: "It is still early in the development of quantum computing & difficult to compare the efficacy of the Russians’ approach versus efforts we have seen from companies like D-Wave & IBM."

Google appears to be at the forefront of this work – the company’s quantum-AI team has set for itself the goal of making a quantum annealer with 100 qubits by the end of this year.

"It’s interesting because the challenges with creating a quantum computer increase dramatically with the number of qubits," said Conway. "It’s a whole lot easier to do something with a couple of qubits than it is with hundreds or thousands of qubits. But in fact if you want to get serious about this you have to get to the thousands of qubits.. I’d be surprised if this were in the thousands of qubits range, which is what you’d really need for serious cybersecurity."
https://www.hpcwire.com/2017/05/25/russian-researchers-claim-first-quantum-safe-blockchain/


If the advent of quantum computing could be the apocalypse for blockchain, it is therefore crucially important that we begin thinking about how to protect these system before entire countries & currencies could be subject to hacks from the abusers of quantum computers.
https://futurism.com/scientists-may-have-found-a-way-to-combat-quantum-computer-blockchain-hacking/

While quantum computers could improve the world by decreasing processing times, they could also be the ideal tool for hackers, which is a true threat ...
10 Jun 02:27

How tech sleuths cracked the mysterious code that turns your printer into a spying tool

Jeffrey J. Bloom

PC World was among the first to cover the use of dots in 2004, when a senior Xerox researcher described the hidden markings in detail. Developed ~20 years prior (to allay government officials’ fears of counterfeit money or forge documents), Xerox created an in-house encoding system, shared it with authorities & other companies followed suit.
https://www.washingtonpost.com/news/morning-mix/wp/2017/06/09/how-tech-sleuths-cracked-the-mysterious-code-that-turns-your-printer-into-a-spying-tool/?utm_term=.6a8b89875302

According to court records, the Intercept received a printed version of the NSA report in the mail. The Intercept said it came from an anonymous source.
10 Jun 02:14

Westworld creators want to make a show about AI without 'going straight to Skynet'

Jeffrey J. Bloom

Jonathan Nolan & Lisa Joy spoke about the message they were trying to get across with the show’s first season during a conference hosted by Wired. Nolan said that one of the tropes they wanted to avoid was turning AI into a terrifying enemy just because the rise of technology seemed scary. Nolan said that they never wanted their AI to be Skynet, the main antagonist & AI death machines from the Terminator films.

“Until now, AI has tended to lean into a dystopian perspective,” Nolan said. “It goes straight to Skynet, with the exception of Spike Jonze's Her, which is a beautiful movie. What's becoming increasingly clear is that's not how it's going to play out.”
https://www.polygon.com/tv/2017/6/9/15771510/westworld-ai-skynet

“Until now, AI has tended to lean into a dystopian perspective,” Nolan said. “It goes straight to Skynet, with the exception of Spike Jonze's Her, which is ...
10 Jun 02:07

Apple just offered a 'dead giveaway' that it's building an AI chip for iPhones, expert says

Jeffrey J. Bloom

*Google introduced TensorFlow in Nov '15 & 6 months later their custom Tensor Processing Unit (TPU) was unveiled. Apple may be doing something similar with Core ML, "All those converters & everything, it's a dead giveaway there's going to be some intense [processor] available down the line." - Reza Zadeh, CEO Matroid
*Meanwhile Startups like Deep Vision & Mythic are working on mobile processors for smaller devices, as opposed to data centers, where Google's TPUs are located. Another startup, Movidius (acquired by Intel in 2016), is touting a vision processing unit for drones & other gadgets.
http://www.cnbc.com/2017/06/09/apples-core-ml-software-suggests-ai-chip-coming.html

One machine learning practitioner sees Core ML as analogous to the TensorFlow software Google released before introducing its TPU chip.
10 Jun 01:49

5 Reasons Why We Should Study and Embrace Artificial Intelligence!

Jeffrey J. Bloom

Artificial intelligence, machine learning & deep learning may still be in their infancy, but they're already transforming heavily regulated industries, such as “financial services & trading industry” and “healthcare & life sciences industry”. Soon the various technological & security issues surrounding them will be solved & solutions will be accelerated by development of other related technology.
https://hackernoon.com/5-reasons-why-we-should-study-and-embrace-artificial-intelligence-8ba31c4d0c7f

The technology behind artificial intelligence and deep learning is intriguing. But what fascinates me is how AI algorithms and applications force us to ...
09 Jun 19:23

How toxic! Russian hackers are using Britney Spears' Instagram to spread malware

Jeffrey J. Bloom

Malware disguised as a Firefox browser extension searched for hidden links in order to connect back to its control server

Malware scanned comments on Spears' Instagram photo & computed "hashes" for each one, all while looking for a specific hash. When found, it would grab the letters that came after the hash & turn them into a URL pointing to the c2 server. This method allows changing malware comms on-the-fly, w/o changing the malware itself.

ESET Security said they thought this particular post was just a test & linked the malware scheme to a group called Turla.
https://www.engadget.com/2017/06/07/russian-malware-hidden-britney-spears-instagram/


According to an article on Gizmodo, BritBrit’s Insta page is being targeted by a group known as Turla, which the site describes as “a hacking group that specializes in using malware for the purposes of espionage.” Eek!

Researchers from the security group ESET are said to have discovered a backdoor trojan that has been created by the group, although it appears that this hasn’t been deployed yet. These appear under the singer’s photos as spam comments, with ESET providing an example.

http://hellogiggles.com/toxic-russian-hackers-using-britney-spears-instagram-spread-malware/

According to an article on Gizmodo, BritBrit's Insta page is being targeted by a group known as Turla, which the site describes as “a hacking group that ...
09 Jun 18:57

Should CYBERCOM Split From the NSA?

Jeffrey J. Bloom

Since 2009 CYBERCOM has occupied a unique position within the DoD. On one hand, it was a subordinate combatant command of US STRATCOM--responsible for military affairs in space & the nuclear arsenal. On the other hand, it has & is still headed by the NSA director--an intelligence organization separate from conventional military hierarchy.
https://intpolicydigest.org/2017/06/02/should-cybercom-split-from-the-nsa/

What came as a shock was the news that US Cyber Command (CYBERCOM) would be elevated to the unified command plan (UCP) as the fourth ...
09 Jun 18:45

How an office printer may have led to arrest of alleged NSA leaker Reality Winner

Jeffrey J. Bloom

According to San Francisco-based Electronic Frontier Foundation (EFF), a digital rights group, the printed code is known as DocuColor & is printed in a rectangular grid of 15 by eight yellow dots on every color page. The printer reproduces the same grid of dots over the entire page.
http://globalnews.ca/news/3515812/officer-printer-code-reality-winner/

The NSA is accusing Winner, a U.S. intelligence contractor, of leaking a top secret National Security Agency report on Russia's interference with the ...
09 Jun 18:41

'DoubleSwitch' is a new hacking tactic for Twitter accounts

Jeffrey J. Bloom

"DoubleSwitch" involves taking over an account, changing the username & creating a new account using the original username, profile picture & display name.

Users are unable to recover their accounts, as they don't know the old account's new account name & their original account name is now registered to the hacker.
http://mashable.com/2017/06/09/twitter-hack-doubleswitch-venezuela-fake-news/

Hackers are taking over Twitter accounts and spreading misinformation in a new kind of attack, The Verge reported, citing digital rights group Access ...
09 Jun 18:12

Rosie O'Donnell Gives Large Sum Of Money To NSA Leaker

Jeffrey J. Bloom

Rosie O’Donnell donated $1,000 to a crowd funding site set up for Reality Winner, after being indicted on Monday for leaking Top Secret NSA documents to The Intercept.
http://www.msn.com/en-us/tv/celebrity/rosie-o%E2%80%99donnell-gives-large-sum-of-money-to-nsa-leaker/ar-BBCkhQU

(Video provided by Veuer). Rosie O'Donnell donated a $1,000 to Reality Winner, the woman who has been charged with stealing and leaking “Top ...
09 Jun 18:06

Quantum Computers Analyze Every Financial Model at Once

Jeffrey J. Bloom

Computerized High-frequency trading was born from complex quantitative buy-sell algorithms & accounts for over 50% of trading. Quantum computing will allow instantaneous discovery of the best portfolios overall & throughout time. Digital computing was simply an evolution, quantum computing will be a revolution.

Quantum computers harness the laws of nature & are coming sooner than you think. This isn’t going to take 20, or even 10 years. It’ll be here in 3-5 years. So, now is the time to start thinking about what quantum will do for you.
https://singularityhub.com/2017/06/08/quantum-computers-will-analyze-every-financial-model-at-once/

Consider building a portfolio out of all the stocks in the S&P 500, Fursman said. Given expected risk and return at various points in time, your choice is ...