Saturday, December 21, 2013
Hackers Hit Servers at The Washington Post for a 3rd Time
Tuesday, August 13, 2013
Sunday, June 9, 2013
U.S. Helps Allies Trying to Battle Iranian Hackers
Friday, May 24, 2013
Bronx Officer Accused of Hiring E-Mail Hackers
Monday, May 20, 2013
Hunting for Syrian Hackers’ Chain of Command
This article has been revised to reflect the following correction:
Correction: May 17, 2013
An earlier version of this article based on previous reporting referred incorrectly to a representative of The Financial Times, Ryann Gastwirth. She is a spokeswoman, not a spokesman.
Sunday, May 19, 2013
Times Site Is Attacked by Hackers
Archives at the New York Public Library cross-referenced with long-awaited 1940 data provide eye-opening results.
Stuck without a lyric in sight, a songwriter ponders the intricacies of a little bird’s brain.
Monday, April 8, 2013
Op-Ed Contributor: Closing the Door on Hackers
Marc Maiffret is the chief technology officer of BeyondTrust, an enterprise security management company.
Sunday, March 17, 2013
Media Decoder: Editor Charged With Aiding Hackers Group
8:30 p.m. | Updated Matthew Keys, a 26-year-old deputy social media editor at Thomson Reuters, has been charged with assisting the hacking collective Anonymous in an attack on the Web site of The Los Angeles Times, the Justice Department said Thursday.
A federal indictment of Mr. Keys, formerly a Web producer at KTXL Fox 40, which, like The Los Angeles Times, is owned by the Tribune Company, said that he went by a user name of “AESCracked” and assisted in a cyberattack on the newspaper’s Web site. The attack reportedly allowed the group to gain access and alter a news feature.
The three-count indictment includes charges that Mr. Keys provided Anonymous with login information for computers owned by the Tribune Company. The indictment also states that he encouraged the hackers, with whom he worked from Dec. 10 to Dec. 15, 2010, to log on to the Tribune Company server “to make unauthorized changes to Web sites” owned by the company and “to damage computer systems” used at the Tribune Company.
A Los Angeles Times news article with the headline “Pressure Builds in House to Pass Tax-Cut Package” was renamed “Pressure Builds in the House to Elect CHIPPY 1337,” according to the indictment.
If convicted, Mr. Keys could face up to 10 years in prison for each substantive count and three years of supervised release and a fine of $250,000 for each count, the Justice Department said in a news release. A spokesman for Reuters said that the news organization was aware of the charges against Mr. Keys and that the alleged misconduct occurred before Mr. Keys joined Reuters in 2012. A spokesman for Tribune Company declined to comment.
The charges came as a shock in social media circles where Mr. Keys, considered a wunderkind of new media, cut a popular presence, including being named one of Time Magazine’s 140 best Twitter feeds. But the tsunami of social media also appeared to have taken a toll on Mr. Keys.
After posting more than 46,000 Twitter messages, Mr. Keys publicly took a break from the social media Web site. In an interview with Ad Week in July, he said Twitter had kept him up at night. “I got sucked into that. I loved it. I still love it. But at some point you have to take a break,” Mr. Keys said. (In a Twitter post on Thursday, Mr. Keys again said he intended to take a break.)
The length of his potential sentence reignited online protests on Thursday over the way federal prosecutors approached the Internet. Those protests from open Internet proponents like the Electronic Frontier Foundation, exploded in January after the computer programming prodigy Aaron Swartz, also 26 and facing federal charges related to hacking, committed suicide.
The charges against Mr. Keys came as other media organizations were facing computer threats. Chinese hackers have compromised the computer systems of several major United States media organizations, including The New York Times and The Wall Street Journal. The Ministry of National Defense of China has denied any involvement in the attacks.
On Wednesday, President Obama met with chief executives to discuss digital security legislation. In an interview with ABC News on Wednesday, he acknowledged the “ramping up of cybersecurity threats.”
Anonymous, a nebulous and global collective of so-called hactivists, often use computers in protesting or supporting political causes. The group demanded Christmas dinner be provided to Pfc. Bradley Manning, the former Army intelligence officer arrested in 2010 on accusations of leaking classified documents to WikiLeaks.
In a Twitter message posted last year, Hector Xavier Monsegur, a hacker known as “Sabu” who led a hacking collective and worked as an F.B.I. informant, accused Mr. Keys of playing a part in hacking into The Los Angeles Times.
Mr. Keys has written about Sabu and Anonymous for Reuters and been associated with hacking groups in the past, including in a Gawker article that identified him as a “journalist who infiltrated” Anonymous.
“I identified myself as a journalist during my interaction with top-level Anonymous hackers,” Mr. Keys wrote on his personal blog in response to the Gawker article.
The charges against Mr. Keys were first reported by The Huffington Post.
This post has been revised to reflect the following correction:
Correction: March 16, 2013
An earlier version of this post erroneously included Bloomberg News among media organizations whose computer systems were compromised by Chinese hackers. Bloomberg News said its computer systems were targeted, but not compromised.
Wednesday, December 26, 2012
Hackers of Steubenville Football Team’s Web Site Demand Apology in Rape Case
Wednesday, December 12, 2012
Saudi Aramco Says Hackers Took Aim at Its Production
Friday, October 5, 2012
Bits Blog: Hackers Breach 53 Universities and Dump Thousands of Personal Records Online
Hackers published online Monday thousands of personal records from 53 universities, including Harvard, Stanford, Cornell, Princeton, Johns Hopkins, the University of Zurich and other universities around the world.
The group of hackers, calling themselves Team GhostShell, claimed responsibility for the attack on Twitter and published some 36,000 e-mail addresses and thousands of names, usernames, passwords, addresses and phone numbers of students, faculty and staff, to the Web site Pastebin.com. In most cases the data was already publicly available, but in some instances the records included additional sensitive information such as students’ dates of birth and payroll information for university employees.
Typically, hackers seek such information because it can be used to steal identities, crack bank accounts or can be sold on the black market. Universities make ripe targets because they store vast numbers of personal records, often in decentralized servers. The records can be a gold mine because students often have pristine credit reputations and do not monitor their account activity and credit scores as vigilantly as adults.
Dozens of universities have been plagued by breaches recently. Last August alone, the University of Rhode Island warned that students and faculty that their information may have been exposed. And at the University of Arizona, a student discovered a breach after a Google search exposed her personal information — and that of thousands of others at the university. Smaller computer breaches at Queens College and Marquette University were also reported.
In this case, the hackers said they were not motivated by profit but to “raise awareness towards the changes made in today’s education.” In a message accompanying the stolen data, they bemoaned changing education laws in Europe and spikes in tuition fees in the United States. But they also noted that in many cases, the servers they breached had already been compromised.
“When we got there, we found that a lot of them have malware injected,” the hackers wrote on Pastebin.
To breach servers, the hackers used a technique known as an SQL injection, in which they exploit a software vulnerability and enter commands that cause a database to dump its contents. In the case of some universities, the hackers breached multiple servers.
IdentifyFinder, a firm that works to prevent identify theft from security breaches, analyzed the published data and said it appeared to be legitimate. The company analyzed the data and found 36,623 unique e-mail addresses and tens of thousands of student, faculty and staff names as well as thousands more usernames and passwords, some encrypted but many stored in plain text.
Aaron Titus, a spokesman for IdentityFinder, said that in analyzing the hackers’ attack methods, there was evidence that in many cases they had been inside the universities’ systems for “at least four months.”
Lisa Ann Lapin, a spokeswoman for Stanford University, said that the university discovered the breach Tuesday evening. She confirmed that two departmental Web sites belonging to the university had been accessed, but said the servers “have been secured.”
“Our information security officers consider the breaches to be minor in nature,” Ms. Lapin said. “No restricted or prohibited data was compromised, nor was any sensitive or other personal information that could lead to identity theft.”
At colleges across the country, some students set up sites that allowed students and faculty to search the leaked data for their information. For instance, at the University of Pennsylvania, Matt Parmett, a junior, created a Web site that made it possible for classmates to search the leaked data by name.
Sunday, September 30, 2012
Bits Blog: Hackers May Have Had Help With Attacks on U.S. Banks
The hackers claiming responsibility for cyberattacks on American banks over the past week must have had substantial help to disrupt and take down major banking sites, security researchers say.
Bank of America, JPMorgan Chase, Citigroup, U.S. Bancorp, Wells Fargo and PNC all experienced disruptions and delays on their banking sites over the past week because of denial of service or DDoS attacks, in which hackers clog a Web site with data requests until it slows or collapses under the load.
A hacker group, which calls itself the Izz ad-Din al-Qassam Cyber Fighters, took credit for the attacks in online posts. They enlisted volunteers for the attacks with messages on various sites. On one blog, they called on volunteers to visit two Web addresses that would cause their computers to instantly start flooding targets — including the New York Stock Exchange, Nasdaq and Bank of America — with hundreds of data requests each second. This week, hackers asked volunteers to attack banks according to a defined timetable: Wells Fargo on Tuesday, U.S. Bancorp on Wednesday and PNC on Thursday.
Representatives for Wells Fargo, U.S. Bank and PNC all confirmed Wednesday that their Web sites had experienced disruptions because of unexpected volumes of traffic. Both the New York Stock Exchange and Nasdaq saw a slowdown, but no serious disruption, on their Web sites.
Security researchers say the attack methods being peddled by hackers — the custom-built Web sites — were too basic to have generated the disruptions.
“The number of users you need to break those targets is very high,” said Jaime Blasco, a security researcher at AlienVault who has been investigating the attacks. “They must have had help from other sources.”
Those additional sources, Mr. Blasco said, would have to be a well-resourced group, like a nation state, or botnets — networks of infected zombie computers that do the bidding of cybercriminals. Botnets can be rented via black market schemes that are common in the Internet underground, or loaned out by cybercriminals or governments.
Last week, Senator Joseph I. Lieberman, chairman of the Senate Homeland Security Committee, said in an interview that he believed the attacks on the banks were being sponsored by Iran’s government.
Mr. Blasco said security researchers had noticed an increase in the use of botnets out of Iran recently. But he said he had not been able to track the origin of the attack to Iran. Attacks can be routed through various I.P. addresses to mask their true origin, making attribution “nearly impossible,” Mr. Blasco said.
In the hackers’ post, they said their attacks were not sponsored by Iran, and said they “strongly reject the American officials’ insidious attempts to deceive public opinion.”
They said they conducted the attacks in retaliation for a video, made by amateur filmmakers in the United States, that mocks the Prophet Muhammad.
“Insult to the prophet is not acceptable, especially when it is the last prophet Muhammad,” the hackers said in their post.
They pledged to continue to attack American banking sites and targets in other countries, including France, Israel and the United Kingdom, until the video was pulled offline.