Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts

Wednesday, April 1, 2026

BREAKING NEWS: Second Life Hacked, Iranian "Cyberwarriors" Claim Responsibility

 
 ** Update : April Fool's! **
 
If you had trouble staying online yesterday, or couldn't access the website, you were not alone. The website was down for a short time, and for some time afterwards hard to access. People were also crashing more often and having trouble getting back online. 
 
But that wasn't the only trouble. Whole sims were hacked and covered with Iranian flags. There were also signs with pictures of hot dogs & ham and pictures of dogs, with the international "not allowed" sign over them. 
 
*Addition*: There are stories of a few women whom when knocked offline and finally able to log back in found themselves wearing a burka and found themselves unable to remove it until they relogged using another viewer. 
 
A group of self-proclaimed Iranian "cyberwarriors" took responsibility, saying this was part of their fight against America. 
 
There has been no official comment from Linden Lab, though there were some comments from individual Lindens. To read them, head to the forum thread here.  
 
 

Friday, October 24, 2025

Reader Submitted: Fake SL Login Screen

 

 From The Orange Floof (FriendlyDaWusky Resident). This is an image of what looks like an SL login screen. But checking the Internet address, one can see this is a fake. This was almost certainly meant to to was to get passwords and account names as a "phishing" scheme, then hack the account and swipe all their Lindens.
 
A reminder to be careful when clicking on strange links, and double check what you're logging into.
  
 
 
 

Friday, October 11, 2024

Internet Archive "Wayback Machine" Hacked

 
For users of the Internet Archive, also called the "Wayback Machine," Thursday October 10 was an unpleasant surprise when users discovered the site was offline.  What happened was the website was hacked. When people logged on, instead of the normal page, they saw this message:

Have you ever felt like the Internet Archive runs on sticks and is constantly on the verge of suffering a catastrophic security breach? It just happened. See 31 million of you on HIBP!
 
Bleeping Computer would say, "The text 'HIBP' refers to the Have I Been Pwned data breach notification service created by Troy Hunt, with whom threat actors commonly share stolen data to be added to the service."
 
The nature of the hack seems to be in dispute. Some are calling it a Directed Denial of Service attack. Others are calling it a data breach that "stole a user authentication database containing 31 million unique records."
 
Forbes quoted a cybersecurity expert as saying, "“Hacking the past is usually technically impossible but this data breach is the closest we may ever come to it. ... The stolen dataset includes personal information but at least the stolen passwords are encrypted."
 
Forbes would also say "While the identity behind the data breach exposing 31 million users remains unclear, the pro-Palestinian hacktivist group Black Meta has claimed responsibility for the DDoS attacks that took down The Internet Archive." 


Bixyl Shuftan

Wednesday, September 4, 2024

EOTB: Linden Lab Reminds Residents To Be Wary of Scammers and Hackers

 
 

You may see viewer download links shared in local chat, DM, or even group chat. These links are usually unsafe and link to software that compromises your Second Life account or installs additional hidden software that gives a stranger control of your computer. Be wary of downloadable software links. Strangers may claim that their link is an early fix, a special version of the viewer, or an early release of an anticipated product. Don’t be fooled!

If you see a link advertising a Third-Party Viewer, don’t click it directly. Always check our Third Party Viewer Directory for a list of safe download locations. All approved third-party viewers are included here, and the official Second Life Viewer is available from the Second Life site. To help keep others safe, share this blog post and submit an Abuse Report if you see a suspicious link shared in world. 

 They would also offer five suggestions
 
Be wary of unsolicited messages or emails. If you receive a message from an unknown sender or even a friend (you never know if their account was compromised), be cautious before clicking any links. It’s always best to err on the side of caution. 

Check the website’s URL. Before logging into the website, ensure you’re on a legitimate site. A phishing website will often have a similar-looking URL, but with slight variations. Check for spelling errors or subtle changes in the website’s address. 

Look for security indicators. Legitimate websites will often have security indicators, such as a padlock icon or “https” in the URL. This indicates that your information is being transmitted securely. If you are unsure if a URL is legitimate, you can always send in a support ticket and ask for clarification. 
 
Use strong passwords. A strong password is at least 8 characters long and combines uppercase and lowercase letters, numbers, and symbols. You should also use a different password for each online account to reduce the risk of multiple accounts being compromised if one password is stolen. 

Enable Multi-Factor Authentication (MFA). This will add an extra layer of security to your account by requiring a second form of identification to access your account to make account changes.

 To see the blog post in full, Click Here
 
Bixyl Shuftan
 

Friday, April 1, 2022

BREAKING NEWS: Hackers Redirecting Residents From Second Life to "Putin World"

* Update - April Fool's*

In what is either an escilation in the growing tensions between Russia and the West, a massive troll by pro-Putin hackers, or perhaps both, residents of Second Life are getting re-routed to the wrong virtual world.

Starting at 1 PM SL time March 31 (Midnight Moscow time), a few residents in Russia, Turkey, and east Africa were finding trying to login to Second Life, they ended up in another virtual world entirely. The entry area looked like Red Square in Moscow, complete with the Kremlin and Lenin's tomb. As time went on, more and more residents in more and more countries, starting when their own region reached Midnight, found themselves in this place as well. As of the writing of this article, a few residents in Eastern Standard Time in the Eastern US, Quebec & Ontario, and Columbia & Peru are posting on Facebook that they've somehow logged onto there. Logging out and logging back in, they end up back in this other virtual world.

This copy of Second Life is called "Putin World." Going beyond the Red Square area, there's a much smaller number of sims than Second Life. There are Russian cities with cheerful workers, Russian towns with happy locals, Russian farms with happy peasants, slums with banks flying American and European flags, with unhappy masses, WW2 battle scenes showing retreating German soldiers fleeing from T-34 tanks, and woods with builds of a bare-chested Putin riding a bear. Everywhere are signs describing Putin as the "glorious leader" who made Russia great again, and that anyone opposed to him is either a fool needing institutionalization, or a criminal needing prison.

So far, only a tiny fraction of residents have been re-routed. But the number has been growing as time goes on. Linden Lab is investigating the hacking, and trying to come up with a solution.

Update. Linden Lab has announced that they've come up with a patch that will prevent residents from being sent to Putin World, and should fix affected accounts and send them back to Second Life.

To read more on the patch and to download it, Click Here.

Bixyl Shuftan
 

Friday, February 22, 2019

Announcement: This Week At The Science Circle : Cyber Security


"Cyber Security"
Saturday February 23 at 10 AM PST

Moderator: Matthew Burr – Beragon Betts

Anyone who is interested in his security on the internet will soon come across worrying reports about phishing e-mails, cybercrime, industrial espionage, governments stealing each other’s data and cyber-terrorism. Closer to home, data mining affects us via Facebook, Google and Microsoft.

What started as a free sharing of data has gradually turned into an unsafe, lawless space where everyone is a target for malicious parties.

More information Harvard Cybersecurity Wiki

The Science Circle (61/127/32)

Sunday, April 1, 2018

Breaking News: Hacker Renames Hundreds of Accounts Trump and Clinton


*Update - April Fool's*

In a shocking move, a hacker was somehow able to gain access to Linden Lab's computers and rename several hundred accounts. It is believed he or she was about to seize control of the renaming process and used it to change the names of the residents. There were a number of males in motorcross clubs given names such as "Kissyfur" and "Cuddlebaby." And there were several professors in science groups given insulting names such as "Dunderhead" and "Flatearther." But the majority of the affected residents were accounts that were created after 2010, given the surnames "Trump" and "Clinton." This includes a few dozen in political groups, given the name of the political figure in the party opposite theirs.

Numerous residents have already spoken out in various forums, demanding Linden Lab fix their accounts. Several have already stated they will not return until their accounts are fixed. Linden Lab in response has stated they are considering activating the ability for residents to change their names early, though has not spoken on whether or not the residents affected by the hacking will have their account names restored for free.

For the official statement by Linden Lab, Click Here.

Saturday, September 23, 2017

Eye on the Blog: "An Important Reminder About Account Security"


The following was posted by Linden Lab yesterday.

It has come to our attention that some Residents are sending messages - which may appear as popup windows in some viewers - informing other Residents that their accounts have been compromised and encouraging them to contact Support, using a phone number that is not associated with Linden Lab.
 
These messages are phishing attempts to gain access to your Second Life account. Neither Linden Lab, nor Second Life Customer Support, would attempt to contact you in this manner. You can always find Linden Lab’s official customer support contact methods within the following links:
 
 
As always, please be wary of suspicious messages and contact from other users. If you believe your account has been compromised, please contact us via support case at https://support.secondlife.com/

Hat Tip: Fuzzball Ortega 

Saturday, March 1, 2014

Word on the Street: Hack Attacks


Lately, we've been hearing of a number of groups passing out warnings of people getting hacked after checking a link posted by a friend, which ends up leading to disaster. They usually go something like the following.

*WARNING* Multiple hacking going on in SL today and it involves Market Place. your "friend" will send you a link to market place, you log in giving your name and password and your are hacked. They immediately change your password and then send the same invite to all your friend's....DO NOT follow any links to Market Place today whether the offer came from a friend or not. LL is aware of it and have shut many accounts down today.

These warnings aren't just idle threats.  Some months ago, one of the residents of the Sunweavers was the victim of a similar hacking attack. So be careful about what links  you click on.

Friday, July 6, 2012

DNSChanger Malware Could Knock Thousands of Computers Offline July 9

Thousands of computers are at risk of being unable to use the Internet because of malware from online criminals in a scam last year. Despite an effort to get the word out, as many as 277,000 computers worldwide still cary the hostile software known as DNSChanger.

DNSChanger was discovered in 2007, and may have infected millions of computers over time. The malware worked by detecting what websites its victims browsed, then redirected them to sites under the control of a cybercrime enterprise working from the small Eastern European country of Estonia, where ads were pushed onto the viewers. The criminals were netting millions before the FBI worked with Estonian police to break up the crime ring and confiscated the servers. Six were arrested with a seventh in Russia still at large.

To avoid disrupting those with infected computers, the servers were kept online as word was spread about the malware infections. In January, it was estimated a half million computers had the malware. But on Midnight July 8, the servers will be turned off, and those computers still infected will be unable to get online, at least without taking certain steps. In January, it was estimated a half million computers had the malware. As many as 277,000 computers across the world may still be infected, including as many as 4500 in the United States. Messages, such as the one Google has been showing to users of computers it detected the malware on (shown below), have helped to get the word out.

For those computers still infected, there are a number of places one can go. Among them is a website that a group of security groups and experts set up: www.dcwg.org. Others include:

Hitman Pro (32bit and 64bit versions)

Kaspersky Labs TDSSKiller

McAfee Stinger

Microsoft Windows Defender Offline

Microsoft Safety Scanner

Norton Power Eraser

Trend Micro Housecall

MacScan

Avira


For computers knocked offline, they can still get to Google by typing "173.194.34.72" into their address bar, or to Microsoft with "64.4.11.37".

Internet security company Internet Identity reported at least 60 companies on the Fortune 500 still have infected computers. At the beginning of the year, they believed the number was 250. or 50 percent. For US Government agency computers, the amount infected went down from an estimated 49 percent to 4.

Sources: http://www.dcwg.org/, Forbes, Reuters, Internet News , Google


Bixyl Shuftan