This is default featured slide 1 title

International Institute Cyber Security Mexico provides training for all type of data security.

This is default featured slide 2 title

Webiprints is one of the world famoous company for data security provider in world wide at lowest price with 100% secure.

This is default featured slide 3 title

Webiprints offers Mobile application development services at affordable price and also Mobile Hacking Course. Just visit our website and fill up your query.

This is default featured slide 4 title

Grow your business with us! We offers Digital Marketing including services such as SEO, SMO and PPC.

This is default featured slide 5 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.This theme is Bloggerized by Lasantha Bandara - Premiumbloggertemplates.com.

Wednesday, 2 January 2019

HACKERS TAKE CONTROL OVER ONLINE ACCOUNTS USING VOICEMAIL SERVICES

voicemail

An exploit proof of concept to hack multiple online services has been recently disclosed

According to cybersecurity and ethical hacking specialists from the International Institute of Cyber Security, voice mail systems (voicemailing) are highly vulnerable to brute force attacks against their main security measure, the four digits of the Personal identification Number (PIN) they own. According to reports from multiple experts, a malicious actor could access a voicemail system to take control over services such as WhatsApp, LinkedIn, Netflix or PayPal.

The cybersecurity and mobile security expert Martin Vigo recently presented an investigation in which he states that the PIN that protects these voicemailing services is much easier to crack than a traditional password, which can lead to accounts hacking in different services.

“Automated phone calls are commonly used to use functions such as password reset, account verification, and more. A hacker could compromise these functions, exploiting some old programming weaknesses with updated tools and intervening in a user’s voicemail.”

The cybersecurity expert resorted to the use of some simple hacking techniques for phone calls, this time applied to the hack of a voicemailing service. Once a service has been compromised, hackers can start listening to the messages the victim uses to reset their password. Hackers might even infer the user’s PIN if it is typed into the victims’ device.

Vigo wrote an automated script capable of violating most of the four-digit PIN used by voicemailing systems without the victims’ knowledge. The investigator published the code of his Voicemailcracker on GitHub (omitting the brute force function), hoping to help for the correction of this kind of weak points.

When carrying out a demonstration, Vigo showed how a voicemailing system works the same with the brute force function activated, verifying that it could access services such as PayPal or WhatsApp which have a PIN verification system.

“Voicemailcracker uses Twilio, a Voice Over Internet Protocol service that allows you to manage phone calls automatically. Voicemailcracker launches hundreds of phone calls at the same time to interact with voicemailing systems and use brute force against the PIN, all without the victim’s knowledge,” concluded the expert. The investigator also revealed other possible attack vectors, such as a backdoor to the voicemailing system, eliminating the need to make thousands of phone calls, an attack that requires minimal interaction from the victim.


CYBERCRIMINALS ATTACK HEWLETT PACKARD AND IBM NETWORKS AND SERVERS

Cyber attacks cost Aussie companies millions

Accusations against Chinese intelligence agencies continue

According to cybersecurity and ethical hacking experts from the International Institute of Cyber Security, alleged Chinese cybercriminals for-hire compromised the networks of Hewlett Packard and IBM enterprises, thus illegally accessing multiple customer devices of both companies.

IBM argues that, so far, it has no evidence to claim that a users’ personal information has been compromised. On the other hand, HP has refused to make any comments regarding these accusations.

This cyberattack campaign mentioned by the cybersecurity experts might be related in some way to the malicious campaigns sponsored by the Chinese government, according to the member countries of the Five Eyes group (United States, Canada, Great Britain, Australia and New Zealand).

Recently, U.S. secretary of State Mike Pompeo and national security officer Kirstjen Nielsen made a ‘serious calling’ to the Chinese government to “act responsibly after the detection of a broad campaign of cyberattacks against intellectual property and sensitive trade data on American territory, in addition to Europe and several parts of Asia”.

A few weeks ago, U.S. prosecutors formally charged two Chinese citizens, allegedly linked to an Asian espionage agency, pointing them as guilty of crimes such as espionage, theft of confidential data from the U.S. government and different companies around the world. In American territory, Chinese spies would have attacked NASA, the Navy, and the Department of Energy, as the experts in cybersecurity reported.

The two Chinese citizens, now accused of “conspiring to commit computer crimes against dozens of organizations in the United States and the rest of the world”, would be related to the Intelligence division of the Ministry of State Security of China, according to the U.S. Federal agencies.

FBI director Chris Wray recently stated: “There is no organization that represents a more severe threat to our economy and our computer systems than the Chinese government”. According to Wray, the Chinese government’s goal is to surpass America as a “world-leading superpower” at any costs. The Chinese government has already spoken out to deny the accusations of the U.S. authorities. According to various international media, China has described these allegations as “defamatory”, proceeding to file a new complaint against the U.S. government, the same measure that China adopted just a couple of months ago, due to the boycott against Chinese companies like Huawei and ZTE, driven by the United States and its allies.


RECORDS OF THOUSANDS OF CHILDREN AND TEENAGERS FOR SALE IN DARK WEB FORUMS

hacker

Cybercriminals obtain these records by compromising the systems of hospitals or academic institutions

According to cybersecurity experts from the International Institute of Cyber Security, several groups of cybercriminals are focused on stealing personal records of thousands of children, information stored by schools or children medical attention institutions, for the purpose of selling them in some market in the dark web.

The information is reported to include children full names, addresses, telephone numbers, social security numbers and birth dates.

The reports also emphasize that cybersecurity researchers found that hackers seek more personal information from children born between the years 2000 and 2010.

As for the value of this information in the dark web forums, it can be depending on the content. By individual records, a hacker can get up to $10 USD, while the larger volumes of information reach numbers of between $490 to $800 USD, depending on the forum in which these records are offered.

Emily Wilson, a cybersecurity specialist, has been warning multiple companies and organizations about this malicious activity for a while. However, most of the stolen records are already or have been available in a number of very popular dark web forums. In many of these markets, information is identified with the tag ‘USA KIDS FULLZ’.

“It is reasonable to think that cybercriminals gain access to these data through some point of access to the computer infrastructure of hospitals or government systems. In the case of the file identified as ‘USA KIDS FULLZ ‘, the seller claims that the records have been extracted from a hospital network,” said the specialist.

Wilson believes there is an enormous probability that stolen information will be used as part of a credit scam scheme. “Children affected by this data breach should be between 8 and 18 years of age, they may not be involved in any financial activity. Hackers take advantage of this to use their data and open bank accounts to their name”, she added.

In further details on this research, hackers post their ads on dark web forums promoting them as “information belonging to children of good families, who can provide and pay expensive medical services”.

According to specialists in cybersecurity, the trade in personal data of minors could become a serious problem in the future. As a child grows, their data begins to circulate more broadly, either on the Internet or in government services, so they are increasingly vulnerable to some form of fraud.


LINUX SERVERS INFECTED WITH NEW RANSOMWARE VARIANT

linux

A new type of ransomware has been infecting servers over unsecured IPMI cards

Cybersecurity and ethical hacking specialists from the International Institute of Cyber Security have reported the emergence of a new ransomware variant. The malicious program, called JungleSec, has been spread on victim systems via Intelligent Platform Management Interface (IPMI) cards. According to reports, this ransomware was recently discovered in mid-November.

IPMI is a set of computer interface specifications for a standalone computer subsystem that provides management and monitoring functions independently of the CPU, firmware (BIOS or UEFI), and host operating system. It is integrated into the server’s motherboards or could be installed as an additional card and allows remote computer management.

According to experts’ reports on cybersecurity, a misconfigured IPMI interface could allow an attacker to remotely access a system and control it using the factory access credentials. Thanks to evidence gathered by experts on cybersecurity, it was discovered that attackers installed JungleSec using the compromised server’s IPMI interface.

“In one of the infection cases we analyzed, sysadmins did not change the default passwords for the IPMI interface. Another victim claimed that the admin user function was disabled, but somehow the attackers got access by exploiting vulnerability”.

Experts noted that once the user gained access to the server, attackers would restart the computer in single-user mode to gain root access, then downloaded and compiled the ccrypt encryption program.

After encrypting the files, the attackers send the ransom note that contains the instructions for performing the transfer and restoring the files.

Attackers use the email address junglesec@anonymousspeech[.]com to communicate with victims and demand 0.3 Bitcoin. According to expert reports on cybersecurity, some victims have made the transfers, but never received a response from hackers.

Experts recommend protecting the IPMI interface by changing the default password and configuring ACLs that allow only certain IP addresses to access the IPMI interface.


Friday, 28 December 2018

NUEVA VERSIÓN DE WORDPRESS YA DISPONIBLE: FAVOR DE ACTUALIZAR SU SITIO WEB

wordpresssss

Al fin ha llegado la esperada versión WordPress 5

La quinta versión de WordPress fue lanzada hace ya algunos días, aunque no llega exenta de polémica, pues la comunidad de usuarios y expertos en WordPress consideraba que su lanzamiento se ha presentado de forma un tanto apresurada, lo que, según especialistas en ciberseguridad del Instituto Internacional de Seguridad Cibernética, podría generar múltiples errores en alguno de los sitios web que operan en esta plataforma.

WordPress 5, la nueva y esperada versión, introduce la edición por bloques, además de un nuevo tema, Twenty Nineteen, adaptado por completo a la nueva versión del editor, aunque todos los temas anteriores a la nueva versión serán compatibles con el nuevo editor. Según expertos en ciberseguridad, se incluye también la compatibilidad con php 7.3, mejoras en la REST API, optimización en la compatibilidad con dispositivos móviles, actualizaciones de seguridad, entre otras nuevas funciones.

Fernando Tellado, del equipo de ciberseguridad y soporte de WordPress, considera que habrá que esperar hasta inicios del 2019 para que los errores reportados en esta nueva versión sean solucionados por completo.

La actualización 5.0.2, considerada como un mantenimiento de la plataforma, corrige 73 errores centrados en el editor por bloques. De estos 73 errores, 45 se encuentran afectando al nuevo editor, 14 se enfocan en mejoras de rendimiento y 31 son errores de código. Además, se han solucionado 17 errores del editor que afectan a algunos de los diferentes temas incluidos. Acorde al equipo de WordPress, esto incrementará el rendimiento de la plataforma en alrededor de 300%.

Una lista detallada de los errores corregidos durante esta actualización está disponible en la página de soporte de WordPress.


CÓMO IDENTIFICAR Y ELIMINAR VIRUS DE REDES SOCIALES DESDE SUS DISPOSITIVOS

socialmediasecurity

Identifique el contenido malicioso en plataformas como Facebook, Twitter, etc.

La frecuencia con la que aparecen virus en plataformas de redes sociales ha incrementado al igual que la peligrosidad de esos programas maliciosos. La mayoría de los virus en Twitter, por ejemplo, se propagan a un ritmo acelerado a través de enlaces publicados en tweets que ofrecen descuentos o algún tipo de software atractivo para el usuario, acorde a especialistas en ciberseguridad del Instituto Internacional de Seguridad Cibernética.

Los problemas comienzan cuando se hace clic en alguno de esos enlaces, pues estos podrían traer adware, spyware o alguna variante de ransomware al dispositivo del usuario. A continuación se muestran algunos consejos de especialistas en ciberseguridad para mantenerse a salvo de esta clase de amenazas.

Métodos de distribución de virus en redes sociales

La principal forma de distribución de esta clase de software malicioso es a través de publicaciones, tweets, etc., que contienen enlaces adjuntos. Por ejemplo, un tweet puede ser publicado por cualquier cuenta de Twitter o ser enviado como mensaje directo (DM) a algunos usuarios desprevenidos. Usualmente las publicaciones tratan de atraer a los usuarios con mensajes como los que se presentan a continuación:

  • ¿Sabías que Google está contratando gente para trabajar desde casa? Suena bien, ¿no crees? {enlace malicioso}
  • Regístrate y descarga esta increíble app – Disponible sólo por hoy: {enlace malicioso}
  • Acabo de descubrir a los stalkers en mi perfil: {enlace malicioso}
  • WOW Puedes ver QUIÉN VISITA tu perfil de TWITTER: {enlace malicioso}

Acorde a expertos en ciberseguridad, los enlaces web más utilizados para propagar virus resultan ser URL aleatorias y acortadas, como:

  • Enlaces Bit.ly
  • Enlaces Vid.me
  • Enlaces Adf.ly
  • Sitios TinyURL

Estos sitios son utilizados para acortar las URL y no son riesgosos por sí mismos, sino que a menudo los hackers los usan para ocultar alguna variante de virus y distribuirla a través de enlaces maliciosos, agregando JavaScript y creando enlaces con descargas automáticas.

Tipos de virus en redes sociales

Acorde a expertos en ciberseguridad, existen diversos problemas que un usuario puede enfrentar después de hacer clic en algún enlace malicioso. A continuación se muestran algunos ejemplos.

Sitios de phishing

Páginas de inicio de sesión falsas, encuestas, o sitios de ofertas falsas, son diferentes clases de phishing, una de las técnicas de ciberataque más utilizadas en la actualidad. De las diferentes clases de phishing, el más extendido es el que anuncia el sitio web de alguna tienda con el propósito de engañar al usuario para que introduzca su información personal en un sitio falso. La imagen de empresas como Ray-Ban y Nike es muy utilizada en esta clase de ataques.

Enlaces maliciosos

Otra de las principales amenazas en el uso de redes sociales es la infección de malware. Estos enlaces podrían redirigir al usuario a sitios de descarga y ejecución automática de algún archivo de malware (descargas drive-by), corriendo el riesgo de infectar su sistema con alguna variante de software malicioso como:

  • Virus de minería de criptomoneda
  • Ransomware
  • Troyanos
  • Botnets

Recientemente, fue descubierta una gigantesca botnet que utilizaba más de 3 millones de cuentas de Twitter falsas y 100 mil bots distribuyendo enlaces por toda la red.

Falsos sitios de soporte técnico

Una de las variantes más utilizadas. En ocasiones, algún enlace incrustado en un post de Facebook o un tweet pueden redirigir al usuario a una página que afirma que el equipo del usuario está dañado.

La intención es convencer al usuario para que llame a un falso número de soporte técnico, desde donde el falso empleado de soporte solicitará al usuario información sensible, o incluso acceso a su equipo. Se recomienda no llamar a esos números bajo ninguna circunstancia.

Remover virus de redes sociales

Especialistas en ciberseguridad del Instituto Internacional de Seguridad Cibernética recomiendan que, antes de comenzar a remover un virus, los usuarios deben hacer una copia de seguridad de su información. Posteriormente, el usuario deberá seguir las recomendaciones enlistadas a continuación:

  • Inicie su PC en modo seguro para aislar y eliminar archivos y objetos maliciosos
  • Encuentre los archivos creados por los virus de redes sociales en su PC

Si no funciona, se recomienda usar un software avanzado de análisis anti malware, con lo que se podrá eliminar de forma automática cualquier archivo relacionado con el malware encontrado en las diversas plataformas de redes sociales.


ROBO DE DATOS DE MÁS DE 500 MIL ESTUDIANTES Y MAESTROS

databreachedit

Más de 500 mil alumnos y trabajadores han sido afectados por este incidente

Información personal perteneciente a más de 500 mil empleados y estudiantes de las instituciones académicas de San Diego, California, podría haber sido robada por actores maliciosos, informan expertos en ciberseguridad del Instituto Internacional de Seguridad Cibernética.

A través de un comunicado, el Distrito Escolar de San Diego informó que este incidente, calificado como un “acceso no autorizado”, fue llevado a cabo gracias a una simple campaña de phishing en la que se comprometieron las claves de acceso de alrededor de 50 empleados en diversas escuelas el pasado mes de enero. Personal de ciberseguridad de las instituciones académicas demoró cerca de 10 meses en detectar el incidente.

En el caso del Reglamento General de Protección de Datos de la Unión Europea (GDPR), se exige que las organizaciones reporten esta clase de incidentes dentro de las siguientes 72 horas a su descubrimiento. Por otra parte, la legislación estadounidense respecto al robo de datos establece que las organizaciones pueden solicitar una extensión de tiempo para realizar sus propias investigaciones, reportan expertos en ciberseguridad.

Aparentemente ya ha sido identificado uno de los sujetos responsables, además, todas las credenciales de acceso comprometidas han sido desechadas, aunque esto no significa que los atacantes no hayan conseguido acceso a la información personal resguardada por las escuelas.

Acorde a especialistas en ciberseguridad, los datos comprometidos incluyen nombres completos, fechas de nacimiento, números de seguridad social, claves de identificación de estudiantes del Estado de California, datos de los padres o tutores, información de nómina del personal de las escuelas, e incluso detalles fiscales e información salarial. Muchos de estos datos podrían ser de gran utilidad para algún delincuente cibernético.

Diversas firmas de seguridad reportaron que más de un millón de niños en Estados Unidos fueron víctimas de fraudes de identidad durante 2017, lo que resultó en pérdidas de alrededor de 2.6 millones de dólares. Acorde a expertos en ciberseguridad, dados los limitados o nulos registros financieros con los que cuenta un niño, es muy fácil para los criminales abrir cuentas bancarias falsas a nombre de los infantes, entre otras actividades similares.

En este incidente también destaca la importancia que tiene el phishing para los cibercriminales, pues, según estimaciones de múltiples firmas de seguridad, el phishing es un elemento en común en la mayoría de las violaciones de datos, pues cerca del 90% de estos incidentes comienzan con campañas fraudulentas por correo electrónico.