Thursday, September 1, 2016
Hackers stole over 43 million Last.fm accounts in 2012 breach
New details about a historical hack of music website Last.fm have come to light.
Last.fm, owned by CBS (which also owns ZDNet and sister-site CNET), suffered a data breach back in 2012, but details of the attack were not disclosed. Reports suggested the service had an estimated 40 million users at the time.
On Thursday, breach notification site LeakedSource, which obtained a copy of the database and posted details of the hack in a blog post, said more than 43.5 million accounts were stolen.
LeakedSource was able to confirm that usernames, email addresses, join date, and other internal records, such as newsletter sign-ups and ad-related data, were stolen in the breach
The database also contained hashed passwords, scrambled with the MD5 algorithm that nowadays is easy to crack. LeakedSource said that the algorithm is "so insecure" that it was able to decipher over 96 percent of passwords in just two hours.
ZDNet was able to independently verify the legitimacy of the data.
LeakedSource added the breached site and forum data into its database, which lets possible victims of the breach search their data.
A spokesperson for CBS was unavailable for comment at the time of writing. We'll update when we hear back.
from Latest Topic for ZDNet in... http://ift.tt/2bXAmsw
Advanced Security, Simple Management: Kaspersky Lab Empowers SMBs with its New Business Solution
Kaspersky Lab announces a new Software-as-a-Service solution that will provide small and medium-sized businesses with multi-layered IT security – Kaspersky Endpoint Security Cloud. The solution offers advanced functionality and proven protection[1]that can be managed easily via simple cloud-based console with an intuitive and user-friendly interface.
Despite the wide range of security products on the market today, small and medium-sized businesses (SMBs) may struggle to find a comprehensive solution they can implement and afford. Kaspersky Endpoint Security Cloud has been developed to meet the evolving needs of SMBs and their under-resourced IT teams, as well as the Managed Service Providers (MSP) who support them.
The solution provides businesses with effective protection for Windows workstations, file servers, Android and iOS mobile devices, all through a simple and intuitive console. Based on advanced, multi-layered security technologies, Kaspersky Endpoint Security Cloud leverages industry leading protection features, including Kaspersky Security Network and System Watcher[2], to protect users from both known and emerging threats.
The centralized cloud management console does not require advanced IT skills, significantly reducing the burden on over-stretched IT professionals. It can be used at any time and from any location to remotely distribute software, and to monitor and manage the security of up to one thousand corporate users.
Further, using the cloud console means that companies do not need to purchase additional server hardware or software in order to manage their IT security. Kaspersky Endpoint Security Cloud offers SMBs a choice of annual license or monthly subscription[3], making it convenient to budget for capital or operational expenses.
“Kaspersky Endpoint Security Cloud provides SMBs with sophisticated technologies that block known and emerging threats, while providing simple and convenient management. It allows SMBs to make the most of limited budgets whether they have their own IT headcount, or whether they outsource their security management,” said Vladimir Zapolyansky, Head of SMB Marketing at Kaspersky Lab.
“Our products are also known as the industry’s most tested and awarded, so we can give SMBs the peace of mind they need to concentrate on building their businesses, whilst knowing that they are protected from cyber dangers,” he added.
To start using Kaspersky Endpoint Security Cloud, SMBs need to register at http://ift.tt/2ct6dV3
[1] http://ift.tt/1TOzUMA
[2] http://ift.tt/11fty9V
http://ift.tt/1IsFiMm
http://ift.tt/2bT7G1O
[3] Monthly billing availability should be checked with regional partners
from Corporate News http://ift.tt/2ct6PKq
Tonight Mr. Robot is Going to Reveal ‘Dream Device For Hackers’
is the rare show that provides a realistic depiction of hacks and vulnerabilities that are at the forefront of cyber security. This is the reason it’s been the most popular TV show of its kind.
Throughout season 1 and season 2, we have seen that connected devices are the entry point of choice of Elliot and
fsocietyto breach networks and traditional security controls.
In this week’s episode, Elliot uses a
Pwnie ExpressPwn Phone, which he describes as “
a dream device for pentester,” to run a custom script he has written to take over someone else’s phone.
Security pros have long know about the Pwn Phone as a powerful mobile platform for penetration testing and security assessments, so it is not surprising to see it on Mr. Robot.
The coolest part is that Pwnie Express is
giving away a Pwn Phone, just like the one used in the show.
The Pwn Phoneis a mobile pentesting device that makes it incredibly easy to evaluate wired, wireless and Bluetooth networks. It is built on
Kali Linuxthat comes pre-packaged with over 100 built-in and ‘one-click’ tools, and it can run third-party scripts.
The Pwn Pad exists for security pros who want a tablet version, and it’s also available via the Android Open Pwn Project.
The Pwn Phone is the latest in a series of connected device hacks on Mr. Robot that have included a Femtocell, a Raspberry Pi, and Bluetooth sniffers, along with the hack of an E-Corp exec’s connected home and the crucial meltdown of E-Corp’s data center by using a connected HVAC system.
These are real threats that are being exploited by criminals to gain unauthorized access and steal data from companies today.
In the past, Pwnie has made it clear that they do not condone the criminal use of penetration testing tools and devices. But pentesting is important, and having the tools to do it properly is part of that process.
Sometimes you need to break things to find and fix serious security vulnerabilities in the devices and networks that permeate nearly every facet of our daily lives. The bad guys have every tool available to them; white hats should be equally well-equipped.
And as for what Elliot does in the show?
He’s a pretty well-established gray character. Is he good? Or is he bad?
Either way, it was pretty cool.
from The Hacker News http://ift.tt/2c6Rc7V