. | . |
Thousands of websites infected by 'crypto mining' malware by Staff Writers Washington (AFP) Feb 12, 2018 Thousands of websites around the world, including many operated by governments, have been infected by hackers using the sites' computing power to "mine" cryptocurrencies, security researchers said. The attack is the first major incident made public in which a new breed of hackers took over a large numbers of websites to effectively create currencies like bitcoin which are generated by using computing power. The attacks made public over the weekend by British security researcher Scott Helme showed more than 4,000 website were infected in this manner, including those of the British data protection and privacy watchdog and the US federal courts system. Unlike traditional attacks, these infections do not contain "ransomware" or steal data, but operate in stealth mode to make profits from the shadowy world of cryptocurrencies. Helme said in a blog post Sunday that the hackers were able to reach large numbers of websites by infecting a commonly used "plug-in," or software which helps a site run better. In this case, the hackers used the malicious software to create Monero, one of several new cryptocurrencies which are making a splash in financial markets. "If you want to load a crypto miner on 1,000+ websites you don't attack 1,000+ websites, you attack the 1 website that they all load content from," he said. The creator of the plug-in, the British software firm TextHelp, said it took the affected software offline after it discovered the "attempt to illegally generate cryptocurrency. " "This was a criminal act and a thorough investigation is currently underway," the company said in a statement. Researchers have been warning in recent weeks about this kind of malware, which can deliver profits without being obvious to users. Security researchers at Cisco Talos warned last month that this kind of hacking activity "has exponentially increased." Because of the huge financial gains in cryptocurrencies, Cisco researchers said this has become a prime target for hackers. "At a high level mining is simply using system resources to solve large mathematical calculations which result in some amount of cryptocurrency being awarded to the solvers," Cisco researchers wrote in a research note. Security researcher Graham Cluley said the latest attack highlights vulnerabilities in websites which may have weaknesses in third party components. "Things could have been much worse," Cluley said in a blog post. "Imagine if the plug-in had been tampered with to steal login passwords rather than steal CPU resources from visiting computers."
China orders microblog companies to ramp up censorship Beijing (AFP) Feb 2, 2018 China Friday ordered the country's microblog operators to establish mechanisms to remove false information, in the latest move by authorities to tighten policing of the web. The Cyberspace Administration of China said the Twitter-like microblog platforms have allowed the spread of pornographic, vulgar and fraudulent content. In addition to making sure to remove such content, companies should also keep a copy of what users post for at least six months, the CAC said in an online statement. "Mi ... read more
|
|
The content herein, unless otherwise known to be public domain, are Copyright 1995-2024 - Space Media Network. All websites are published in Australia and are solely subject to Australian law and governed by Fair Use principals for news reporting and research purposes. AFP, UPI and IANS news wire stories are copyright Agence France-Presse, United Press International and Indo-Asia News Service. ESA news reports are copyright European Space Agency. All NASA sourced material is public domain. Additional copyrights may apply in whole or part to other bona fide parties. All articles labeled "by Staff Writers" include reports supplied to Space Media Network by industry news wires, PR agencies, corporate press officers and the like. Such articles are individually curated and edited by Space Media Network staff on the basis of the report's information value to our industry and professional readership. Advertising does not imply endorsement, agreement or approval of any opinions, statements or information provided by Space Media Network on any Web page published or hosted by Space Media Network. General Data Protection Regulation (GDPR) Statement Our advertisers use various cookies and the like to deliver the best ad banner available at one time. All network advertising suppliers have GDPR policies (Legitimate Interest) that conform with EU regulations for data collection. By using our websites you consent to cookie based advertising. If you do not agree with this then you must stop using the websites from May 25, 2018. Privacy Statement. Additional information can be found here at About Us. |