Marlborough Express

Hackers may be cashing in on tech flaws

-

BRITAIN: Criminals may already be cashing in a recently discovered microchip flaw that has left billions of computers and other electronic devices across the globe vulnerable to hacking.

Advertisem­ents claiming to belong to notorious hacking group the Shadow Brokers have appeared on a hacking-for-sale site, offering to retrieve passwords and personal informatio­n from victims’ smartphone­s or computers in return for $US8900 ($12,400) - or the equivalent in Bitcoin.

The microchip bugs, which affect almost every computer processor in the world, were disclosed earlier this week despite technology giants knowing about them for a year. Apple has warned that more than a billion iPhones, iPads and Mac computers remain vulnerable thanks to a microchip flaw. Computers running Microsoft Windows and Android smartphone­s are also at risk.

Since the announceme­nt of the bug, it was feared that criminals would seize the opportunit­y to exploit it to steal passwords for online services, or personal and confidenti­al files. The authentici­ty of the advert has yet to be confirmed but it is likely to be the first of many claimed sales across the dark web, as thieves look to profit from the flaws.

‘‘The advert is enough to show that attackers are trying to exploit and monetise on it. If not from the Shadow Brokers, then other practical exploits will likely surface soon,’’ said Michael Hickey, security consultant and co-founder of My Hacker House.

As software giants work around-the-clock to send out updates that could protect customers devices, criminal gangs are likely to be tapping the keyboard full speed to profit.

‘‘I’m sure there are people attempting to exploit these vulnerabil­ities for real, right now,’’ said Michael Marriott, a research analyst at Digital Shadows, which monitors the dark web.

Marriott said hackers have taken to the dark web and notorious hacking forums to find ways to target the public and businesses. Some may just be an attempt at defrauding people out of money. ‘‘Criminals like to scam other criminals, so in the next couple of months we should see more of this.’’

In June 2017, security researcher­s warned Intel, AMD and ARM that a flaw in their chips could leak sensitive informatio­n stored on the devices that use them. This included passwords, web history and encryption keys. The issue was not disclosed to the public until Wednesday, reportedly to give companies time to find a fix for the issue. Apple has admitted that all of its devices except for the Watch were affected, and that it had already put some fixes in place but that customers should still be wary of untrustwor­thy apps or websites and wait for further updates.

Google said it is working on an update to its Chrome browser and Android phones and Microsoft will be sending out patches for its operating system Windows 10.

The vulnerabil­ities allow attackers to extract informatio­n from a computer that was previously believed to be inaccessib­le. This includes passwords and encryption keys - potentiall­y making all online transactio­ns insecure. - Telegraph Group

 ??  ?? Michael Marriott says hackers have taken to the dark web to find ways to target the public and businesses.
Michael Marriott says hackers have taken to the dark web to find ways to target the public and businesses.

Newspapers in English

Newspapers from New Zealand