Showing posts with label hack. Show all posts
Showing posts with label hack. Show all posts

2/02/2017

Xbox and PlayStation hacked 2.5 million user information exposed


  A data breach of two popular gaming forums, Xbox and PlayStation has exposed the account details of 2.5 million users, potentially opening up their other online accounts to attack by hackers.

Both forums offered a way for gamers to share links to download free versions of games.

Even if users didn't have financial details stored on the sites, the information could be used to break into other sites, if users have the same password for different accounts.

If you use one of these forum, change your password of other sites, if they are same as fast as possible.

1/28/2017

Dark web marketplace AlphaBay hacked


The web of illegality, web hidden behind TOR, Dark Web has it's own websites, one of the best known marketplace AlphaBay, where one can buy sell from gums to drugs, has got hacked and over 200,000 messeges compromised.

Earlier this week, the hacker known as Cipher0007, had found "high-risk" bug in AlphaBay witch allows him to copy over 200,000 private messeges between sellers & buyers. In a forum post the hacker said the two security flaws could be exploited to snatch private messages.

The hacker was able to read firstname, lastname, addresses, nicknames and tracking ID's. He also reviled number of screenshots as proof.

After that AplhaBay awarded that hacker for finding such a risky bug. The attacker was paid for disclosing the flaws rather than selling them on or releasing the stolen information to the public. In return, Cipher0007 revealed his methods and several hours later AlphaBay developers were able to close the loopholes.

1/23/2017

The New York Times twitter account hacked


The New York Times Video Twitter account posted a fake news tweet about Russia planning to launch a missile attack on the United States.

Two follow up tweets on the account — which has more than 259,000 followers — claimed to come from OurMine, a hacker group that has breached high-profile Twitter accounts for Marvel, Netflix and Twitter founder Jack Dorsey.

Another tweet claimed the Times tweet came from the same hacker who posted a fake announcement about Britney Spears’ death last month on the Sony Music account.

“We deleted a series of tweets published from this account earlier today without our authorization. We are investigating the situation,” the account wrote in a subsequent tweet.

 According to reports from August 2016, hackers thought to be working for Russia broke into the email accounts of New York Times reporters earlier that year. The FBI investigated the reports.

source : NY daily news

1/20/2017

Clash of Clans creator Supercell Hacked


Supercell, which created Clash of Clans and other games such as Clash Royale, Boom Beach and Hay Day, has revealed that an attack on its member forums leaked user details online.

Over a million user accounts were compromised in the breach, Motherboard reported, with usernames, email addresses, IP addresses and hashed passwords among the leaked information passed on by breach notification site LeakBase.

Supercell confirmed that it had suffered a breach, which apparently occurred back in September 2016, and urged users to change their passwords immediately.

The company told Motherboard that, “Our preliminary investigation suggests that the breach happened in September 2016 and it has since been fixed.”

In a statement posted on its user forums, Supercell added, “We take any such breaches very seriously and we follow very strict policies when it comes to security. Please note that this breach only affects our Forum service. Game accounts have not been affected.”

Source :Express

1/12/2017

Hello Kitty Database Hacked, 3.3 Million User Details Breached


Hello Kitty parent company Sanrio, has been breached including 3.3 million user credentials.

 The breach was originally reported in December 2015, but at the time Sanrio denied any data was stolen as part of the breach. The breach was tied to a misconfigured MongoDB installation that was discovered by security researcher Chris Vickery.

 On Sunday a website that specializes in harvesting leaked credentials called LeakedSource, said the Sanrio database of 3,345,168 million users has surfaced. The disclosure was part of the website’s January 2017 update.

 Unfortunately, someone did copy the database before the configuration error was fixed. It just isn’t clear when that copy was made. On Sunday, Salted Hash learned that the Sanrio database was added to The LeakedSource index.

1/11/2017

Brother-sister duo accused of hacking Italy's 18,000 email accounts of elite


A brother-sister hacker duo has been arrested by Italian police for developing a customised malware and hacking into email accounts of Italy's elite.

Giulio Occhionero, 45, a nuclear engineer, and his sister Francesca Maria Occhionero, 48, both of whom reside in Rome, have been charged with launching a massive cyberespionage campaign that targeted two former Italian prime ministers, a Vatican cardinal, the president of the European Central Bank and thousands of others, according to reports.

The siblings have been accused of hacking at least 18,000 email accounts, which belonged to Italian businessmen, bankers, and politicians, including former prime ministers Matteo Renzi and Mario Monti.

The FBI said it had provided support to the Italian probe into the cyberespionage campaign that targeted victims in Europe and the US. The Italian police confirmed that US authorities would help determine how the hackers infiltrated systems and stole data. Police added that the data sought by the hackers had financial value.

1/08/2017

FBI hacked! Hacker leaks FBI usernames & passwords online



The premier investigative agency of United States of America, Federal Bureau of Investigations (FBI) had its website content management system hacked. A hacker with Twitter handle of CyberZeist claimed that he had managed to breach into Plone CMS used by FBI for its website. CyberZeist also leaked around 150 logins, including email addresses and encrypted passwords online.

 CyberZeist said he breached the Plone CMS, also being used by the FBI, in late December using a zero-day that was discovered by somebody else. CyberZeist stated that the zero-day can be used against several other organizations including the EU Agency for Network Information and Security along with Intellectual Property Rights Coordination Center.

CyberZeist exploited the flaw on 22nd December. The hacker exploited a zero-day vulnerability in the Plone CMS, an Open Source Content Management software used by FBI to host its website, and leaked personal data of 155 FBI officials to Pastebin, including their names, passwords, and email accounts.

Additionally, the hacker says that the zero-day he used to compromise the CMS website is already being sold on Tor, so he won’t share more details until the exploit is no longer available for purchase.


The attack is “devoted to the Anonymous movement,” and CyberZeist says that he was already contacted by various sources to sell the zero-day, but he declined.