Malwarebytes Privacy World

Taken from https://blog.malwarebytes.com/category/security-world/privacy-security-world/feed/

5th February 2016

DayZ in a Daze: Forum Breach Confirmed

Back in 2012, the team working on the DayZ mod had their forums and main email account compromised – with a piece of malware uploaded to “Less than 15 percent of game servers” being the final cherry on the zombie cake. In 2013, what might have seemed like a zombie curse struck again with a second bout of forum compromising action. By this point, DayZ was no longer a standalone mod maintained by an enthusiast but under the care of Bohemia Interactive and a fully fledged Alpha release videogame. Unfortunately, it appears that their run of “No hacks please, there’s zombies to deal with” has run aground and, once more, we have a breach. Usernames, passwords and emails are the name of the game, although they state that the passwords aren’t plaintext so that’s something. The notification email – which was actually preceded by a message posted to Twitter more than a week ago – reads as follows: Greetings, A security incident occurred on forums.dayzgame.com recently. According to our inves..
8th December 2015

Data Dissonance: Tunecore Breached

If you make music and distribute it via Tunecore, you may well have received a newsletter over the last few days warning of a security breach. Here’s the newsletter email in question: Salient information below, with certain passages bolded by yours truly: We recently discovered suspicious activity on TuneCore’s servers in November, and that on November 17th an individual illegally collected information from our servers. We are actively working with law enforcement to investigate this unlawful act, and we have retained a leading cybersecurity firm to help prevent this from happening again. It’s possible that the attacker may have had access to some of our customer data. The data on the compromised servers that we stored from customers like you included customers’ names, addresses, email addresses, TuneCore account numbers, and protected TuneCore passwords. Although TuneCore passwords were stored in a protected form, it is possible for a determined hacker with sufficient time, using a..
27th November 2015

Steam’s “Exploration Sale” Gamifies Security Settings

I’m always interested in seeing how companies deploy the gamification of security because it’s an easy way to get more people interested in locking things down, and with the launch of Steam’s latest sale they appear to be bringing back an old favourite: rewards for keeping your account secure. As we’ve mentioned in the past, Steam Guard is an additional level of security for your account which means if someone swipes your Steam login, they’d still need to be able to gain access from a trusted device of yours which is probably unlikely to happen, unless they have physical access (in which case you may have bigger problems to worry about). There have been one or two sneaky attempts to get around it in the past, but by and large with Steam Guard enabled you’re pretty much locked down solid. Back in 2012, Steam had their annual Christmas holidays sale and offered daily in-game challenges, alongside some tasks which weren’t game-centric. One of these was the below: I like that one of Ste..
20th July 2015

Ashley Madison Compromised, 37 Million Users Left Panicking

In an age where everyone wants to keep their private information…well…private, it seems strange that so many would place very personal details on websites which resemble gigantic emergency flares painting 50 foot “All your dox be here” messages in the sky. Sure enough, something like 34 million people may be waking up today to news of so-called “online cheating site” Ashley Madison being compromised, shortly before jumping on the next plane to [insert tropical paradise here]. The hackers, called The Impact Team, claim their issues with the website are based around charges to delete data. Asking users to pay for data deletion has been around for a while, in various forms – from revenge porn sites to pages which upload criminal “Mugshots” then ask you to pay to remove (often, you’ll find the mugshot simply pops up on a related site asking for more money). Whether there’s more to it than this, it’s too early to say but the hackers demand the site stays offline or customer data is going t..
15th June 2015

LastPass Security Notice Issued

Way back in 2011, LastPass had a bit of a security wobble as they noticed a “Network traffic anomaly” on one of their non critical machines. They took appropriate action, and posted an awful lot of words about what had happened. They’ve just published an advisory letting users know that there’s been a breach and the steps they should take to avert any potential threat to their accounts. ...we have found no evidence that encrypted user vault data was taken, nor that LastPass user accounts were accessed. The investigation has shown, however, that LastPass account email addresses, password reminders, server per user salts, and authentication hashes were compromised. On the off-chance you reused your LastPass master password on another site(s), you should alter all affected logins – password reuse is a major problem and not one to be taken lightly. This might also be a good time to remind everybody of the following: * Two factor authentication is available for LastPass users – Google ..