Wenatchee Valley College - CTS Discussion Board

You are not logged in. Would you like to login or register?



10/08/2019 11:14 am  #1


Security Class Article #2 - Due Monday October 14th --REPLY HERE

Find a good article.  READ it.... Summarize and post a link to the article.  Don't forget your name....Reply to this article for your post...

 

10/10/2019 10:30 am  #2


Re: Security Class Article #2 - Due Monday October 14th --REPLY HERE

Incident Of The Week: Multiple Yahoo Data Breaches Across 4 Years Result in a $117.5 Million Settlement

Between 2012 and 2016, data security intrusions occurred in which yahoo.com users accounts and information were compromised. According to the article, the attackers didn’t behave in the same fashion each time they attacked. During one intrusion, they simply hacked into Yahoo’s online infrastructure without taking anything. During another attack, they maliciously took records which totaled to about 3 million accounts. Yahoo claims they are working with law enforcement officials in working out a solution to the data breach. This just goes to show, no matter how big the company, vulnerability still exists. 

Jesse Kilthau 

https://www.cshub.com/attacks/articles/incident-of-the-week-multiple-yahoo-data-breaches-across-4-years-result-in-a-1175-million-settlement

Last edited by jkilthau2856 (10/10/2019 10:31 am)

 

10/10/2019 10:47 am  #3


Re: Security Class Article #2 - Due Monday October 14th --REPLY HERE

Pump Up, a Canadian Fitness App hacked in 2018
An estimated 6 million users of the mobile app, had their private information and linked accounts hacked. The breach was due to an Amazon back end server, not being fully secure.
https://evolvemga.com/pumpup/

 

10/12/2019 11:06 am  #4


Re: Security Class Article #2 - Due Monday October 14th --REPLY HERE

New Phishing Attack for Amazon customers
Recently, Amazon customers have been getting phished in a new way that makes them believe that Amazon blocks their accounts and makes them think they owe something. Therefore they enter their credentials into a phishing site and takes their credentials. 
https://latesthackingnews.com/2019/10/11/new-phishing-attack-sends-fake-aws-account-suspension-emails/
 

Last edited by AlMendoza22 (10/14/2019 10:04 am)


Alvaro Mendoza
 

10/13/2019 10:30 am  #5


Re: Security Class Article #2 - Due Monday October 14th --REPLY HERE

Apple iTunes Bug Actively Exploited in BitPaymer/iEncrypt Campaign It’s a new attack pattern that was difficult to detect, security researchers have stated. Researchers from Morphisec Labs in August identified the abuse of the flaw, which exists in the Bonjour updater that comes packaged with iTunes for Windows, to deliver ransomware in an attack on an unidentified enterprise in the automotive industry.Even if a system uninstalled iTunes years ago, the Bonjour component remains silently un-updated and still working in the background, researchers said.The attackers were even able to target companies with this method of their files and much more.

https://threatpost.com/apple-itunes-bug-bitpaymer-iencrypt/149075/

Cristian Villanueva
 

 

10/13/2019 1:21 pm  #6


Re: Security Class Article #2 - Due Monday October 14th --REPLY HERE

So last week I found this article that suggested that there was a fake Apple Light cable that would charge your phone but as soon as you hooked it to computer a hacker could have control over it. Well they have mass produced them and they are. They are being produced by MG and Hack5 has helped them with production. There is so many different directions you can look at this chasing this down it could drive you crazy. Apples suggestion and mine would be only buy Apple manufactured products. Who knows Apple could be behind the whole thing to keep people buying products directly through them?
Things that make you go HMM
James Florom
https://www.vice.com/en_us/article/3kx5nk/fake-apple-lightning-cable-hacks-your-computer-omg-cable-mass-produced-sold

 

10/13/2019 5:54 pm  #7


Re: Security Class Article #2 - Due Monday October 14th --REPLY HERE

Found a article related to vulnerability on the WhatsApp, A bug Which in result would have been able to see your private chats you have been texting to. So basically this bug was inside the GIF that who ever clicked on it got access to remote access to do what ever he or she wants. The WhatsApp vulnerability only affects android devices not iPhones . They highly suggest to update the WhatsApp app and your phone system as possible so be carefull
They give full demo on how the Gif worked 

https://latesthackingnews.com/2019/10/06/whatsapp-exploit-poc-allows-attackers-to-hijack-chat-sessions-via-malicious-gifs/

JuanCarlosMendezJr

 

10/13/2019 8:18 pm  #8


Re: Security Class Article #2 - Due Monday October 14th --REPLY HERE

Google play store apparently has gaming and photo apps that install malware onto users phones. Some of the malware was using Android.Banker and also Android.HiddenAds and Android.DownLoader, all of which are virus libraries to carry out malicious activities in the coding area. Google is accepting decently strict policies, but it's good to keep in mind there is less of a check to get an app on the google store than it is the apple store, Not that I condone Apple use by no means.
https://latesthackingnews.com/2019/10/13/multiple-gaming-and-photo-apps-on-play-store-found-to-be-infected-with-android-malware/
-Devin Baughman


Hello, I am Devin Baughman.
There is a discord server with links to online PDF's of course textbooks, there are general chats for each course and nerd-banter, please come in and talk computers! Invite: https://discord.gg/H65RH2g
 

10/13/2019 11:36 pm  #9


Re: Security Class Article #2 - Due Monday October 14th --REPLY HERE

https://gcn.com/articles/2019/10/07/hacking-for-good.aspx
They talked about how white hat hackers and it security industry groups are improving digital security in the public and private sector and that we need more people like that to keep people safe. to defend organizations that are doing good to public good, they said.  Hacking is seen bad through the public but the hacking ethos and broader security research community are good and beneficial. 

 

10/14/2019 12:07 am  #10


Re: Security Class Article #2 - Due Monday October 14th --REPLY HERE

I found this article https://www.nytimes.com/2019/07/29/business/capital-one-data-breach-hacked.html about an Amazon Web Services server hack carried out by Paige Thompson in which she bypassed Capital Ones web application firewall to access the personal data of over 100 million Capital One customers. The data taken included Social Security numbers, Canadian social insurance numbers, which are equivalent to American SS numbers, bank account numbers, and millions of credit card applications. Thankfully, the lady doing the hacking was pretty dumb, leaving behind a trail of crumbs that easily identified her. According to the F.B.I agent who investigated the breach, Ms. Thompson was able to breach Amazon Web Services and access Capital One records through a "Misconfiguration" of the firewall on a web application, which was actually produced internally by Capital One, but is hosted on Amazon servers. By bypassing the firewall in Capital Ones web application, it allowed her to directly access the server/s where customer information was stored. Lesson of the day, make sure your firewall is properly configured.


Ỵ̵͝'̸̰̋a̴̟̿l̴̘̓l̶̖̊ ̶̮̀g̷̬̈o̶̯͂t̴̺̚ ̷̢̌a̸͚̅ṋ̶̂y̶̙͝ ̴̙̾q̶̛͇u̶̢̔ï̵̳c̵͉̈́ķ̶̐ ̷͓͝b̶̡̚i̸̹͆t̴̠̀ṣ̷͝?̴̼̄
 

Board footera

 

Powered by Boardhost. Create a Free Forum