Fahmida Y. Rashid

Black Hat Organizer Touts Value of Publicizing Cyber-Security Research

LAS VEGAS-The threat landscape is increasingly sophisticated, complex and volatile, but there are some promising trends on how organizations are meeting the threat, a Black Hat organizer said as he kicked off the annual security conference. Organizations and international governments are now more aware of the necessity of cyber-security and are exerting a more concerted […]

Aerial Drone Sniffs, Attacks Wireless Networks at Black Hat

Two security researchers demonstrated how to outfit a radio-controlled model airplane with a computer and 4G connectivity to create a nearly undetectable aerial hacking device. Mike Tassey and Richard Perkins released the specifications for Wireless Aerial Surveillance Platform that can attack systems from air on Aug. 4 at the annual Black Hat security conference in […]

Chinese Android App Acts Like Trojan to Stealthily Record Mobile Calls

Researchers recently uncovered a new Android app sold in Chinese app stores that has the capability to surreptitiously record phone conversations. Once installed on the victim’s Android device, the app downloads a “configuration” file containing the parameters for a remote server and proceeds to record and store phone conversations entirely without the phone owner’s knowledge, […]

Ex-CIA Official Warns Black Hat Attendees of Coming Cyber-War

LAS VEGAS-The former U.S. counter-terrorism official who raised the alarm that a major terrorist attack was coming before 9/11 is now warning that cyber-war is an imminent threat. The security community needs to influence and educate government decision makers about the potential threats from cyber-criminals and nation-states, Cofer Black, former director of the Central Intelligence […]

Microsoft to Fix 22 Software Flaws in Its August Patch Tuesday Update

Microsoft plans to patch 22 vulnerabilities in Internet Explorer, Windows, Visio and Visual Studio as part of the August Patch Tuesday release. Microsoft will release 13 security bulletins, two of which are rated “critical,” the company said Aug. 4. Nine were rated as “important” and the final two were listed as “moderate” according to the […]

War Texting Remotely Unlocks, Starts Cars at Black Hat

Modern automobiles are increasingly becoming more like computers, with features such as the in-car navigation system and multiple sensors tracking the fuel tank and overall health of the engine. Don Bailey and Matthew Solnik, two senior security researchers from iSEC, showed how text messages sent over the GSM network could be used to unlock and […]

Massive Five-Year Cyber-Attack Hit UN, US Government, Defense Contractors

Hackers penetrated the United Nations, technology companies, defense contractors as well as the United States and foreign government networks as part of a massive five-year cyber-spying campaign, according to a stunning report by McAfee researchers. Dubbed “Operation Shady RAT,” the attackers penetrated 72 target networks since July 2006, McAfee disclosed on Aug.3. Government agencies in […]

Huge Shady RAT Cyber-Attack Likely Targeted ‘Thousands’ More Victims

LAS VEGAS-While McAfee identified 72 organizations hit by Operation Shady RAT, researchers believe it’s possible “thousands” more organizations or individuals have been attacked. McAfee has been aware of the attacks since 2009 but did not know the actual scope of the attacks until this March when researchers found a command-and-control server used to launch and […]

Facebook Joins Google, Mozilla, Barracuda in Paying Bug Bounties

Facebook has joined the handful of companies who pay bug bounties to researchers who discover vulnerabilities. Most Website flaws, such as cross-site scripting, cross-site request forgery and remote code injection, would net the discoverer $500, Facebook said July 29. The company said it will pay more for serious issues but declined to specify the maximum […]

Security Tips to Not Get Hacked at Black Hat

Writing about information security, I tend to be very paranoid. This is a good thing as it means I am creating complicated passwords, regularly clearing out my browser history and cookies, and never click on links in my e-mail, even when it’s my company’s HR department demanding I fill out a survey about my benefits. […]