Tuesday, January 14, 2014

Buy of the Week: SAMSUNG 840 EVO SSD – Solid State Drive for only $357 + tax!


samsung-840-evo-ssd

Samsung unveiled high-performance, high-density SSDs that offer over large memory storage. Among the highlights were the 840 EVO, a consumer-oriented entry-level, high-performance SATA based SSD.

- Ultra low power consumption for longer battery life
- Keep your data safe with Self-Encrypting Drive (SED) technology
- Unbeatable performance with up to 300 % upgraded speed


The Samsung SSD 840 EVO line-up makes use of the industry’s most compact 10-nanometer class high-performance NAND flash memory, which Samsung began mass producing in April. With these chips and Samsung’s proprietary multi-core controller, the Samsung SSD 840 EVO achieves unrivaled value for performance with improved sequential read and write speeds.

Samsung has released the entry-level SSD ’840 EVO’ line-up with significantly higher sequential write performance. Utilizing the industry’s most compact 10 nm-class 128 Gb high-performance NAND, Samsung proprietary controller and turbo write drive, the Samsung SSD 840 EVO boasts superior performance. The Samsung SSD 840 EVO also has flexible product supply capacity, making it the most competitive device on the market today.

For a limited time, you can buy the SAMSUNG 840 EVO SSD from Hyphenet, for only $357!


 about-samsung

 

Don’t miss out on this Buy of the Week! Call (619) 325-0990 to order your Samsung 840 EVO SSD – Solid State Drive today!

Buy of the Week offer valid through January 17, 2014.

Note: Shipping and taxes apply.

Looking for something else? Check out our monthly deals or contact us to get a quote on the product you’re searching for.

Monday, January 13, 2014

Yahoo malvertising is linked to a larger malware scheme


malware-advertisement

With a look into Cisco Systems, the cyberattack that infected Yahoo users with malware is showing a link between the attack and a suspicious affiliate with Ukraine, in a traffic scheme.

Yahoo said on Sunday that European users have seen malicious advertisements, or “malvertisements,” between December 31st to January 11th.

If the advertisement is clicked, the user is directed to a website with the intention to install malicious software.
Cisco has seen malicious website victims linked to hundreds of ongoing cyberattacks.

The malicious domains all start with a series of numbers, they contain anywhere from two to six cryptic sub-domain labels and end with two random words in the second-level domain.

 domain_IP_neighborhood

Hosted domains with a large IP block that researchers observed, shows Yahoo victims were redirected to finding 393 others that matched a pattern.

The domains seem to be a part of a scheme designed to direct people to malware.  The group behind the scam infects legitimate websites with code that redirects people to malicious sites.

Most of these malicious domains redirect to two other domains that scans data to a partner program called Paid-To-Promote.net.  People who sign up for the program are paid fees to push traffic to other websites.
It is still not clear whether the program is directly linked to the Yahoo attack.

malware-table

Research has shown that the traffic traced by the affiliate program, shows the domains are used for suspicious purposes ever since November 28th.  Some of these domains are hosted in Ukraine and Canada.
These malvertisements have been put into Yahoo’s advertising network successfully.

With Yahoo’s high traffic, more people have seen the malicious advertisements, in turn a higher rate of infection.

Online advertising networks screen advertisements to ensure they are not malicious, but bad ones do sneak in occasionally.


References:

Yahoo malvertising attack linked to larger malware scheme – ComputerWorld
http://www.computerworld.com/s/article/9245325/Yahoo_malvertising_attack_linked_to_larger_malware_scheme

Friday, January 10, 2014

Has Google gone too far by sending people to jail?

 arms-handcuffs

Google+ notifications are convenient for some. An alert automatically goes out to your friends with an invite for Google+.  Google does the work for you, so you don’t have to, right?

Some are calling this “convenience” a worst case scenario for a Massachusetts man that was jailed for an email invitation to his ex-girlfriend who put a restraining order on him.

Thomas Gagnon is saying he did not send this invitation to his ex-girlfriend, which he ended up in jail for. Police arrested him with a $500 bail.

When Gagnon’s ex-girlfriend received the invitation, she went to the police to complain that Gagnon violated his restraining order by sending her the email.

Microsoft attacks Google

A hearing for this case has been sent on Feburary 6, 2014. Gagnon’s attorney, Neil Hourihan, told the media his client has no idea how the invitation got sent.

ABC News has tried to contact both Hourihan and Gagnon but has not been successful.

Attorney Bradley Shear of Bethesda, Md., told ABC News it is likely Gagnon is telling the truth. If he didn’t send the invitation to his ex-girlfriend, Google could face a major liability for sending the invite without his permission.

Google+ allows users to connect their email contacts into various groups like; school classmates, professional contacts, and personal friends. If one contact is moved to a certain group, it will trigger Google to send an email inviting them to join Google+.

Shear pointed out that a Google product forum from 2011 and 2012 titled “Prevent automatic email invitations to Google+?” that involved many angry complaints by Google+ users about the automatic invitation feature.


One customer wrote:
“As soon as I add an email to a circle, Google seems to send an email automatically asking that person to join Google Plus. Is there any way of turning this off? I don’t want Google to send any email on my behalf without my permission. At least I would expect some sort of warning.”

Gmail practices

Google is making a case that Gmail practices do not violate privacy law.

Shear stated, “Google is going through every one of your contacts and sending them an invitation, weather its your doctor, your lawyer, your mistress, or your ex-fiancee who’s got a restraining order against you”.

This situation is a perfect example of what happens when a company oversteps its bounds.

What do you think about Gmail automatically sending out invites to your contact? Let us know what you think?

Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet,  “Like” us on Facebook or add us to your circle on Google+.

References:

Man Jailed for Gmail Invite to Ex-Girlfriend – Yahoo News
http://news.yahoo.com/man-jailed-gmail-invite-ex-girlfriend-111716107–abc-news-topstories.html

Thursday, January 9, 2014

Malware advertising on Yahoo?



Malware advertising on Yahoo.com has infected thousands of website visitors through desktops and mobile devices.

This is done through an iframe Web attack throughout online communities.

The Internet security firm Fox-IT broadcast the malware infection on Jan. 3rd, which entailed malicious ads being served by ads.yahoo.com using cross-site scripting.  The iframes from the ads were directed to infect files on non-Yahoo servers.

Visitors were redirected to an exploit kit called “Magnitude.”

For the malware ads to be downloaded, the visitors did not have to click on the specific malware ad.  The iframe-based attack also shows Web ad servers need not be compromised.  So just by seeing the ad you are at risk of being infected!

Oscar Marquex, the chief product officer at Redwood City, California based cloud security provider Total Defense, has predicted larger attacks as a way of infecting as many systems as possible.

Marquez believes the party involved with the Yahoo.com attack was just “testing the water”.  It is forecasted more intricate exploits will be seen as hackers seek to establish a “distribution model” based on effective iframe attacks.


yahoo-malvertisement

China-based hackers are copying security breaches like the Yahoo malware ad attack to develop new exploits.

The enterprise customers will seek every possible security angle to see what advantage hackers have on vulnerabilities.

After detecting the malicious ads on Yahoo.com, Fox-IT said it investigated the infection of its clients’ systems that visited the website.  Based on the traffic, Fox-IT estimated the number of visits to the malicious site is about 300,00 per hour.  That is an infection rate of 9%, and is projected to have about 27,000 infections an hour.

The Yahoo attack raises concerns about third-party security, especially with ad networks.  The attack displays a “thriving marketplace” for malware atacks and security threat.

Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet,  “Like” us on Facebook or add us to your circle on Google+.

References:
Malvertising attacks via Yahoo ads may precede broader iframe attacks – Search Security
http://searchsecurity.techtarget.com/news/2240212218/Malvertising-attacks-via-Yahoo-ads-may-precede-broader-iframe-attacks

Wednesday, January 8, 2014

Scams to watch out for


Scam Alert
http://www.hyphenet.com/blog/2014/01/08/scams-to-watch-out-for/

There are plenty of scams to look out for. Travel scams, phone scams, make money fast scams, disaster relief scams, and phishing scams to name a few.

Not all scams are directly associated to malware, many of them intend to persuade the victim to click on a malicious link or fall into the trap of handing out your hard earned cash.

Here are some scams that succeeded in 2013 and we will most likely see in 2014.

Domain Name Scams

The social engineering scam is two-fold.  Here is the letter:
(Mail to the brand holder, thanks)
Dear CEO,
Sorry to bother you inexplicably. We are a China’s domain name registration supplier, and there is one thing we would like to confirm with your company. On December 4, 2013,  we received an application form online from a company called “XinHua Trading Co.,Ltd”  who wants to apply for some domain names and brand name related to “eset”. In order to avoid confusion and  adverse impact on your company, we need to verify whether this company is a subsidiary of you or did you authorize them to register the related brand name and domain names? Currently, we have not formally accepted the application of that company, we need to get your company’s confirmation. Please give us a timely response within 7 work days. So that we can better deal with this case. Thank you.
Best regards,

The scammer is not exactly asking “is it OK if we accept this application?”  He will suggest that  if you  don’t accept the application, you will have to purchase the domain yourself.

Other domain name scams will send you a letter saying your domain is about to expire.  Even though it isn’t, most people buy domains for 3-5 years at a time and may forget to re-purchase the domain.

PC Tech Support Scams


Scammers have been soliciting bogus software for years.  Fake websites are setup, and alarming messages are sent to you to try to convince you that your computer is infected.  The software purchased to fix the problem is worthless or available some else for free.  Or the software purchased and downloaded to your computer could be malicious and infect your computer.

Most people aren’t too technical and feel vulnerable when it comes to fixing their computer.  So when you get a call from someone that appears to know-it-all and wishes to help you, people are willing to pay for the supposed problem to go away.

 Job Scams


Job scams advertise to you the “job of a lifetime” and for easily sued-ed people, it works.

The mule is often required to open an account to facilitate moving funds from a phished account with the same institution.  Scammers will go to extreme lengths to make the mail look like a serious job offer, backed up by a website.

chuoo@hotmail.com, however, is positively chatty. In a message with the subject “F.S.A” invites us enthusiastically to:
Work with us to start your stable future.
You’re close to join a unique place and see inspirational things.
If you are seeking for a challenging opening with a bright future, come work with us.
We would like to offer you a new career of FSA which is untaken for now. Your CV was provided and reviewed by a recruitment agency. An opening that may fit your experience is being offered.
Earnings:
Your salary scale during the probationary period will be 1500 Pounds per month plus 8% commission from each transaction completed. Your total income could easily be about 2500.00 pounds. After the probationary period, your base wage will be 1800.00 Pounds per month, plus 8% commission.
Employee Reimbursements (only after probationary period) Contain:
- Wage plus bonus
- Includes health and dental insurance
- Paid Leave
To apply for the F.S.A. position, please respond to hrdepartment.test@gmail.com.
Thanks,
Bobbi Power
HR Manager

These are well thought out seriously dangerous scams.  Please be mindful of who you are trusting with your information and bank account.

References:

2013: a View to a Scam – We Live Security
http://www.welivesecurity.com/2014/01/06/2013-a-view-to-a-scam/

Tuesday, January 7, 2014

How hacks are costing you



hackers-steal-identity

Hackers have obtained millions of usernames, passwords and credit cards.  You may be asking yourself, why is this happening?

When someone hacks into your account, it will end up costing you money, time, and distress.
When accounts get hacked and the owner of that account doesn’t find out about it until their credit is already damaged, it takes effort to make thing right again.

The damage done depends on the hacker and how much access they had with your accounts.

In the recent case with Target, 40 million stolen credit cards and debit card accounts were hacked into.

Hackers are able to access your account and even make fraudulent cards.

Consumers sometimes don’t suffer much from the hacks, but sometimes they do.

Individuals cancel their accounts and wait for replacement cards, so the banks end up taking the financial hit.
When hackers get a hold of usernames and passwords, the problem gets much bigger.

Experts say that makes it easier to break into you email, seeing people use the same usernames and passwords for multiple accounts.

For help on creating a great password for your accounts see our recent post, Long passwords don’t offer “safe option”.

Smart hackers attempt to use your stolen passwords to access your email attached to your account.
It is proven that more than half of us keep the same password for most websites.  Among that half, many use passwords such as, “password”, “123456″, or “welcome”.

These easy to guess passwords are not secure and routinely make you vulnerable to attacks.


Tricky Tricksters

Criminals can ruin your credit history by taking out bank loans in your name.  The clean up is messy, because to get this fixed, you must work with all three major credit reporting agencies and the federal government.

The main way to steal your identity is to use your Social Security number.

Criminals sometimes pose as you and send emails to your doctor and accountant requesting documents that show your Social Security number.  Many other records are easily obtained online.

If someone is using your Social Security number, they can take loans out and make purchases beyond what you would expect.

Identity theft will wreak havoc with your finances, credit history, and reputation.

You may have to change your social security number and to do so you need to convince the Social Security Administration that identity theft has happened and you’ve exhausted all options for stopping the criminals.

Hackers may even act as you towards your friends or family.  They will request money due to an emergency.

If you experience identity theft, it can take time, money, and patience to resolve.

Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet,  “Like” us on Facebook or add us to your circle on Google+.

References:

How hack attacks can cost you money – CNN Money
http://money.cnn.com/2014/01/06/technology/security/hack-cost/
January 6, 2014

Thursday, January 2, 2014

Skype’s social media accounts attacked, Syrian Electronic Army takes responsibility

syrian-electronic-army


Skype’s social media was targeted by the Syrian Electronic Army over the week.

“You may have noticed our social media properties were targeted today,” Skype said in a Twitter message late Wednesday.  “No user info was compromised.  We’re sorry for the inconvenience.”

All of Skype’s social media accounts appeared to have been attacked by the SEA, including their Twitter, blog and Facebook page.

The Skype blog was inaccessible late Wednesday and redirected users to the Skype homepage.  At least it was redirected back to home instead a malicious site.

The SEA also created a Twitter message that looked as followed:


Syrian-electronic-army



The message read: “Don’t use Microsoft emails(hotmail,outlook),They are monitoring your accounts and selling the data to the governments.More details soon #SEA.”

The SEA then posted on Twitter to contact information purportedly of Microsoft CEO Steve Ballmer, Stating: “You can thank Microsoft for monitoring your accounts/emails using this details.”

Similar messages were posted on Skype’s Facebook page, but it was deleted very quickly, according to TheNextWeb.

facebook-broken

The attack on Skype’s accounts appears to link to the same disclosures through newspapers by former U.S. National Security Agency contractor Edward Snowden that Internet companies have provided the agency real-time access to content on their servers for watchful purposes.

The SEA has aimed for high-profile websites and Twitter accounts.  In August, an attack was supposedly by SEA on Melbourne IT, and Australian domain registrar.  This affected websites of The New York Times, Twitter and other companies.


A long run

Since the rise of the SEA in 2011, the organization has denied association with the Syrian government.
They claim to not be associated with the government, and are not acting on its behalf.

In 2013 the SEA claimed responsibility for hacking into a number of media outlets including the New York Times, The Washington Post, The Huffington Post and Thomson Reuters.  Everyone was taken back when they penetrated the Associated Press twitter account and posted President Barack Obama has been injured in a White House attack.

The exploration into Microsoft’s collaboration on data sharing with the NSA discovered that the transfer of some data to affiliate companies from these attacks seems “to take place lawfully” under a so-called Safe Harbor agreement.

What do you think about the Syrian Electronic Army?  Have you seen these attacks on your social media sites?  Please leave your comments below, we would love to hear from you!

Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet,  “Like” us on Facebook or add us to your circle on Google+.


References:
‘Stop spying on people!’: Syrian Electronic Army hacks Skype – RT
http://rt.com/news/syrian-electronic-army-skype-072/

Skype’s social media accounts hijacked by Syrian Electronic Army – PC World
http://www.pcworld.com/article/2083540/skypes-social-media-accounts-targeted…