• Preventing autonomous vehicles from being hacked

    Although autonomous vehicles are essentially large computers on wheels, securing them is not the same as securing a communication network that connects desktop computers and smartphones to large geographical areas due to the roles that the sensors and actuators play in the physical layer of the network. Researchers have developed an intelligent transportation system prototype designed to avoid collisions and prevent hacking of autonomous vehicles.

  • Network routers can covertly leak data

    Researchers have demonstrated for the first time that it is possible to covertly siphon sensitive files, passwords or other critical data from any common router. “Unlike network traffic that is heavily monitored and controlled by firewalls, this covert channel is currently not monitored,” one researcher says. “As a result, it enables attackers to leak data while evading firewalls, air-gaps (computers not hooked up to the internet) and other data-leakage prevention methods.”

  • "That is a big deal": Russia's effort to subvert American democracy

    Russia’s broad, systematic attacks on the U.S. political process, attacks which are only going to intensify in years to come, are of far greater, and lasting, importance relative to all other issues raised in James Comey’s Thursday testimony before the Senate Intelligence Committee. “We’re talking about a foreign government that, using technical intrusion, lots of other methods, tried to shape the way we think, we vote, we act. That is a big deal,” Comey said.

  • Protecting against online privacy attacks

    When Congress voted in March to reverse rules intended to protect internet users’ privacy, many people began looking for ways to keep their online activity private. One of the most popular and effective is Tor, a software system millions of people use to protect their anonymity online. But even Tor has weaknesses, and in a new paper, researchers recommend steps to combat certain types of Tor’s vulnerabilities.

  • Russian government hackers planted false news story which caused Gulf crisis: U.S. intelligence

    U.S. intelligence officials say Russian government hackers planted a false news story into the text prepared for release by the official Qatari news agency. The release of the Russian-manufactured story by the official Qatari news agency prompted Saudi Arabia and several of its regional allies to suspend diplomatic relations with Qatar and impose economic sanctions on it. U.S. officials say the Russian goal appears to be to cause rifts among the U.S. and its allies.

  • Russian government hackers hacked U.S. voting system manufacturer last August: NSA report

    The hacking by Russian government hackers of the DNC computers and the email accounts of senior Democrats during the campaign has been amply documented, but vote-tallying was believed to have been unaffected, despite the concerted effort exerted by the Russian hackers. A highly classified NSA report, published by the Intercept on Monday, offers evidence that Russian government agents hacked a U.S. voting systems manufacturer last August, three months before the November 2016 presidential election. Security experts say that the suggestion that Russian government hackers may have gained access – even if limited access — to electronic voting systems is likely to increase worries about Russian interference in the 2018 mid-term and 2020 presidential election, as well as worries about growing Russian meddling in the election processes in other countries.

  • Bolstering the credibility of attributing cyberattacks

    Even as major cyber incidents receive high-profile press coverage, many segments of the general public are coming to dispute and question the credibility of the attribution findings — the declared identities of the perpetrators. Researchers review the state of cyber attribution and consider how to bolster the credibility of the process by making it more standardized and transparent. In particular, the report recommends the creation of an independent, global organization to investigate and publicly attribute major cyber-attacks.

  • Preventing 3D printing hacks

    Additive manufacturing (AM), also called 3D printing, is growing fast. Worldwide, the AM market grew nearly 26 percent to more than $5 billion last year, versus 2015, and another 17.4 percent this year versus last. The rapid prototyping market alone is expected to reach $5 billion by 2020. But since the global supply chain for AM requires companies to share computer aided design (CAD) files within the organization or with outside parties via email or cloud, intellectual-property thieves and malefactors have many opportunities to filch a manufacturer’s design files to produce counterfeit parts.

  • Cybersecurity on the fly

    When we think of cybersecurity, we think of applying protection measures to our desktop computers such as installing antivirus programs and using passcodes and pin numbers. Just like our computers, aircraft systems are vulnerable and are not exempt from a cyber-attack. If hacked, some examples of possible cyber effects on aircraft systems can be anything from breakdowns in communication and navigation systems to the more critical systems such as collision avoidance and life support systems.

  • Training cybersecurity professionals to protect critical infrastructure

    Idaho National Laboratory and the Department of Homeland Security (DHS) announce the successful completion of the 100th iteration of the Industrial Control Systems Cybersecurity (301) training course; a course tailored to defending systems used across the critical infrastructure sectors. Since April 2007, over 4,000 cybersecurity professionals have participated in the advanced course.

  • Hackers could take control of missiles on U.K. subs, start a “catastrophic” nuclear war: Report

    Britain’s Trident nuclear weapons deterrent program consists of four Vanguard-class submarines, each carrying up to sixteen Trident II D5 ballistic missiles with a nuclear warhead. Hackers could take control of nuclear weapons-carrying Vanguard-class submarines and start a “catastrophic” nuclear war, a new report warns. The 38-page report warns a security breach could “neutralize operations, lead to loss of life, defeat or perhaps even the catastrophic exchange of nuclear warheads (directly or indirectly).” Des Browne, former U.K. Defense Secretary, said: “To imagine that critical digital systems at the heart of nuclear weapon systems are somehow immune or can be confidently protected by dedicated teams of network managers is to be irresponsibly complacent.”

  • World heading toward “permanent cyber war”: France’s cyber chief

    The world is heading towards a “permanent war” in cyberspace, Guillaume Poupard, director general of the National Cybersecurity Agency of France (ANSSI), has warned. Poupard said cyberattacks of growing frequency and intensity were coming from states which he did not name, as well as criminal and extremist groups. “We must work collectively, not just with two or three Western countries, but on a global scale,” he added, saying attacks could aim at espionage, fraud, sabotage, or destruction.

  • Cybercrime to cost global business more than $8 trillion in the next five years

    A new report by Juniper Research has found that criminal data breaches will cost businesses a total of $8 trillion over the next five years, due to higher levels of internet connectivity and inadequate enterprise wide security. The new research forecasts that the number of personal data records stolen by cybercriminals will reach 2.8 billion in 2017, almost doubling to five billion in 2020, despite new and innovative cybersecurity solutions emerging.

  • Putin: “Patriotic,” “private” Russian hackers may have interfered in 2016 U.S. election

    In a surprising shift, President Vladimir Putin for the first time admitted publicly that Russian hackers may have meddled in the 2016 U.S. elections. He said, however, that the hackers were not Russian government employees but rather “patriotically minded” private Russians. The U.S. intelligence community, and Western intelligence services more generally, have collected voluminous, and incontrovertible, evidence, based on both signal and human intelligence, that hackers and disinformation specialists working for the GRU and the FSB – Russia’s military and domestic intelligence services, respectively – have launched a broad disinformation and hacking campaign last year in order to influence the 2016 presidential election. The Russian leader seemed aware of the possibility that more information about the Russian government’ role in the hacking and disinformation campaign may be revealed, and was trying to get ahead of such disclosures by saying that digital technology can be manipulated.

  • Judy malware may be the largest malware campaign found on Google Play: Check Point

    Check Point researchers last week discovered a widespread malware campaign on Google Play, Google’s official app store. Check Point says that the malware, dubbed “Judy,” is an auto-clicking adware which was found on forty-one apps developed by a Korean company. The malicious apps reached an astonishing spread between 4.5 million and 18.5 million downloads.