Showing posts with label Internet Security. Show all posts
Showing posts with label Internet Security. Show all posts

Tuesday

AOL Mail suffers security breach, users advised to change passwords

 
Users of America Online (AOL) Mail were advised this week to change their passwords soonest, after a security breach hit the email service.
 
In a blog post, the AOL Security Team said it is investigating the "security incident" that it said involved "unauthorized access" to its systems.
 
"We are writing to notify you that AOL is investigating a security incident that involved unauthorized access to AOL's network and systems. AOL is working with best-in-class external forensic experts and federal authorities to investigate this serious criminal activity," it said.
  
 

It said it noticed a "significant" increase in the amount of spam mail spoofing AOL Mail addresses, to trick recipients into opening the spam messages.
 
AOL added its investigation so far indicates an "unauthorized access to information regarding a significant number of user accounts."
 
"This information included AOL users' email addresses, postal addresses, address book contact information, encrypted passwords and encrypted answers to security questions that we ask when a user resets his or her password, as well as certain employee information. We believe that spammers have used this contact information to send spoofed emails that appeared to come from roughly 2% of our email accounts," it said.
 
However, it said there is no sign the attackers broke the encryption on the passwords or the answers to security questions.
 
There is also no sign so far the attack had led to the disclosure of users' financial information, including debit and credit cards, which it said is also fully encrypted.
 
Still, it urged users to change passwords as a precaution.
 
"Although there is no indication that the encryption on the passwords or answers to security questions was broken, as a precautionary measure, we nevertheless strongly encourage our users and employees to reset their passwords used for any AOL service and, when doing so, also to change their security question and answer," it said.
 
In the meantime, AOL said its security team has enhanced protective measures and is notifying potentially affected users.
 
Protection
 
Meanwhile, AOL urged users to take precautions against cyber risks, including:
 
  • Not responding to suspicious email, or clicking on any links or attachments in the email.
  • Contacting the sender to confirm that he or she actually sent an email, when in doubt about the authenticity of an email.
  • Not providing personal or financial information in an email to someone you do not know.
source: gmanetwork.com

Wednesday

Apple beset by Angry Birds malware


It may take no less than these Angry Birds to remind users of Apple computers running OS X that their machines are not invulnerable to malware.

A new wave of malware is disguising itself as cracked versions of Angry Birds, as well as popular apps such as Pixelmator, security researcher Graham Cluley said.

"(M)alware experts at ESET labs have also seen OSX/CoinThief spread through torrents as cracked versions of (several) popular Mac OS X applications," Cluley, who had worked for security firms including Sophos, said in a blog post.

He said OSX/CoinThief, first discovered earlier this month by SecureMac researchers, threatens to steal Bitcoin-related login credentials via malicious browser add-ons.

On the other hand, he said ESET researchers had warned Mac users against downloading pirated software from file-sharing peer-to-peer networks lest these contain similar malware.

"There is clearly strong evidence that the trojan was specifically designed to profit from the current Bitcoin craze and fluctuating exchange rates," he added.

Cluley said the malware disguised as cracked apps other than Angry Birds include:

BBEdit: an OS X text editor
Pixelmator: a graphics editor
Delicious Library: a media cataloguing application

Citing data from ESET, Cluley said the threat is particularly active among Mac users based in the United States.

"Whether you’re a Bitcoin-enthusiast or not, it’s essential that you protect your Mac with an up-to-date anti-virus product, and resist the temptation to download cracked and pirated software," he said. — TJD, GMA News

source: gmanetwork.com

Friday

After hacking, Yahoo Mail users advised to reset passwords, heed security tips


Following an attack on January 30, Yahoo Mail prompted affected users to reset the passwords of their email accounts.

The attack was billed as “coordinated effort to gain unauthorized access to Yahoo Mail accounts.” Yahoo Senior Vice President of Platforms and Personalization Products Jay Rossiter has since stated in the company's official blog that a list of usernames and passwords were likely collected from a compromised third-party database, and that they have “no evidence that they were obtained directly from Yahoo’s systems."

“Our ongoing investigation shows that malicious computer software used the list of usernames and passwords to access Yahoo Mail accounts. The information sought in the attack seems to be names and email addresses from the affected accounts’ most recent sent emails,” he said.

Aside from resetting passwords of hacked accounts, Yahoo Mail has also prompted second sign-in verification to “allow users to re-secure their accounts.”

Users may also receive an email notification or a text message asking them to chage their passwords if they have not yet been already prompted.

Rossiter also said that Yahoo has implemented additional measures to block attacks against its systems. Yahoo also sought assistance from federal law enforcement to find and prosecute the perpetrators of the attack.

Rossiter advised users to adopt better password practices like changing passwords regularly and using different variations of symbols and characters to help keep their accounts secure. He also advised them never to use the same password on multiple sites or services since these make users vulnerable to attacks of this kind.

“We regret this has happened and want to assure our users that we take the security of their data very seriously,” he said. — Kim Luces / KDM, GMA News

source: gmanetwork.com