Security

Chinese Hackers Have Unleashed a Never-Before-Seen Linux Backdoor (arstechnica.com) 35

Researchers have discovered a never-before-seen backdoor for Linux that's being used by a threat actor linked to the Chinese government. From a report: The new backdoor originates from a Windows backdoor named Trochilus, which was first seen in 2015 by researchers from Arbor Networks, now known as Netscout. They said that Trochilus executed and ran only in memory, and the final payload never appeared on disks in most cases. That made the malware difficult to detect. Researchers from NHS Digital in the UK have said Trochilus was developed by APT10, an advanced persistent threat group linked to the Chinese government that also goes by the names Stone Panda and MenuPass.

Other groups eventually used it, and its source code has been available on GitHub for more than six years. Trochilus has been seen being used in campaigns that used a separate piece of malware known as RedLeaves. In June, researchers from security firm Trend Micro found an encrypted binary file on a server known to be used by a group they had been tracking since 2021. By searching VirusTotal for the file name, ââlibmonitor.so.2, the researchers located an executable Linux file named "mkmon." This executable contained credentials that could be used to decrypt the libmonitor.so.2 file and recover its original payload, leading the researchers to conclude that "mkmon" is an installation file that delivered and decrypted libmonitor.so.2.

The Linux malware ported several functions found in Trochilus and combined them with a new Socket Secure (SOCKS) implementation. The Trend Micro researchers eventually named their discovery SprySOCKS, with "spry" denoting its swift behavior and the added SOCKS component. SprySOCKS implements the usual backdoor capabilities, including collecting system information, opening an interactive remote shell for controlling compromised systems, listing network connections, and creating a proxy based on the SOCKS protocol for uploading files and other data between the compromised system and the attacker-controlled command server.

United States

US Federal Agencies Seek to Streamline 'Hodgepodge' of Cyber Reporting Rules (bloomberg.com) 7

The Department of Homeland Security wants Congress and other federal agencies to help it streamline 52 different cyber reporting requirements to protect critical infrastructure and ease regulatory burdens on hacking victims. On Tuesday, it released a 107-page report that it hopes will serve as a road map to smooth that process. From a report: More than 30 federal agencies and departments, including the Nuclear Regulatory Commission, Comptroller of the Currency and US Secret Service, have met since June 2022 to hammer out how to reduce regulatory overlap as the federal government grapples with the messy state of cyber reporting rules. They are among members of the Cybersecurity Incident Reporting Council, which was set up as part of a new cyber reporting law passed last year and developed the report recommendations.

"Everybody is desperate for some harmonization and standardization here," Robert Silvers, DHS's under secretary for strategy, policy and plans who chairs the council, told Bloomberg News in an interview. "This is a first-of-its-kind effort." Federal agencies know well that cyber reporting requirements have become "too much of a patchwork," Silvers added. There are already 45 existing reporting requirements administered by 22 federal agencies, spanning national and economic security concerns to consumer and privacy protections, according to the report. Seven more requirements are expected, including the reporting law that created the council, and a further five are under consideration, according to the report.

Cloud

37 Signals Says Cloud Repatriation Plan Has Already Saved It $1 Million (theregister.com) 82

David Heinemeier Hansson, CTO of SaaS project management outfit 37Signals, has posted an update on the cloud repatriation project he's led, writing that it's already saved the company $1 million. The Register: Hansson has previously revealed that his company spent $3.2 million a year on cloud computing, most of it at Amazon Web Services. His repatriation plan called for the company to spend $600,000 on eight meaty servers that each pack 256 virtual CPUs, and have them hosted at an outfit called Deft. That plan was projected to save $7 million over five years. In his Saturday post, Hansson wrote he now thinks he can find $10 million of savings in the same period.

"Our cloud spend is down by 60 percent already... from around $180,000/month to less than $80,000," he wrote, qualifying that the number excludes the cost of Amazon Web Services's Simple Storage Service. "That's a cool million dollars in savings at the yearly run rate, and we have another big drop coming in September, before the remaining spend will petter out through the rest of the year," he added. The CTO revealed that the 37 Signals ops team remains the same size even though it now tends its own hardware, which cost "about half a million dollars."

Security

Clorox Products In Short Supply After Cyberattack (cnn.com) 37

An anonymous reader quotes a report from CNN: A cyberattack at Clorox is causing wide-scale disruption of the company's operations, hampering its ability to make its cleaning materials, Clorox said Monday. Clorox said some of its products are now in short supply as it has struggled to meet consumer demand during the disruption. Clorox didn't specify which of its products are affected.

The company on Monday revealed in a regulatory filing that it detected unauthorized activity in some of its information technology systems in August. Clorox said it immediately took action to stop the attack, including reducing its operations. It now believes the attack has been contained. Still, Clorox has not been able to get its manufacturing operations back up to full speed. The company said it is fulfilling and processing orders manually. The company doesn't expect to begin the process of returning to normal operations until next week.

"Clorox has already resumed production at the vast majority of its manufacturing sites and expects the ramp up to full production to occur over time," the company said. "At this time, the company cannot estimate how long it will take to resume fully normalized operations." The company said the cyberattack and the delays will hurt its current-quarter financial results materially, although Clorox said determining any longer-term impact would be premature, "given the ongoing recovery."

IT

Google Domains Halts Registrations as It Waits for the Google Grim Reaper (arstechnica.com) 30

Google Domains has registered its last domain. From a report: Google announced in July that the service was getting shut down and that it had struck a deal with Squarespace to sell off the existing customer base. Part of that transition process means winding down the existing Google Domains functionality. 9to5Google was the first site to notice that you can no longer buy a domain through the service while it waits for the Google Grim Reaper to arrive. Google Domain's homepage has a notice explaining that this all apparently went down a few days ago, saying, "On September 7, 2023 Squarespace acquired all domain registrations and related customer accounts from Google Domains. Customers and domains will be transitioned over the next few months." You can still manage existing domains on Google Domains, but that's it.
Windows

Paint App For Windows Update Adds Support for Layers and Transparency (windows.com) 32

Windows blog: Today we are beginning to roll out an update for the Paint app to Windows Insiders in the Canary and Dev Channels (version 11.2308.18.0 or higher). With this update, we are introducing support for layers and transparency! You can now add, remove, and manage layers on the canvas to create richer and more complex digital art. With layers, you can stack shapes, text, and other image elements on top of each other. To get started, click on the new Layers button in the toolbar, which will open a panel on the side of the canvas. This is where you can add new layers to the canvas. Try changing the order of layers in this panel to see how the order of stacked image elements on the canvas changes. You can also show or hide and duplicate individual layers or merge layers together.

We are adding support for transparency as well, including the ability to open and save transparent PNGs! When working with a single layer, you will notice a checkerboard pattern on the canvas indicating the portions of the image that are transparent. Erasing any content from the canvas now truly erases the content instead of painting the area white. When working with multiple layers, if you erase content on one layer, you will reveal the content in layers underneath.

Crime

Las Vegas Still Struggling to Recover from Last Sunday's Cyberattack (go.com) 46

"Chaos and Concern in Sin City," read this morning's headline on a video report from ABC News about "the massive cyberattack in Las Vegas crippling several hotels and casinos, and putting a damper on getaways for thousands of tourists there." "Today marks a week since that cyberattack hit Las Vegas, and MGM hotels and casinos are still working on getting systems back up and running.. The online reservation site for MGM is still down, ATMs not working, and those playing the slot machines or even video poker having to wait for attendants to pay them out in cash. All of this fiasco leading to long lines at check-in, and now a cyber investigation with the FBI...

Other gaming resorts also having issues. Caesar's entertainment says they too were a victim of a cyberattack, but their online operations were not impacted. Then this weekend at the Venetian, an outage shutting down some slots, but the resort says they're back up, and that at least thankfully was not due to a cyber attack.

They report MGM properties were affected as far away as Atlantic City, New Jersey.
IT

'Feedback' Is Now Too Harsh. The New Word is 'Feedforward' (livemint.com) 324

The Wall Street Journal reports that more companies are phasing out "feedback" bosses give to workers — and replacing it with "feedforward."

"The idea is that 'feedforward' gives people less anxiety," the Journal's reporter said in a video interview. "It's a little bit gentler. When people hear 'feedback', they think immediately, 'What have I done wrong? What are the bad things my boss is going to tell me to fix?'" And another reason that we're hearing "feedforward" at these companies over and over is employees are younger. Younger employees make up a larger percentage of the workforce today, and a number of experts with whom we spoke said that younger employees are more comfortable with gentler terms like "feedforward"...

Q: So they're trying to appeal to the younger employees who are sensitive to harsher reviews, feedback or criticism. But do the employees need to learn how to better receive this type of constructive criticism, regardless of what you call it?

A: Some experts say that younger employees do need to be prepared for negative feedback. And just the rebranding or replacing of a word could have a negative effect, and perhaps managers won't be as comfortable providing negative feedback if they're just thinking about this as a way to tell an employee what they've done well...

Certain companies are really revamping their entire review process, trying to make it so that employees and managers are more communicative and really addressing any issues or concerns, so that they can work more productively. In some cases if companies are just rebranding "feedback" with "feedforward" or other terms, people with whom I spoke were concerned that this is just a hollow effort.

And there is a possibility that younger generations won't learn about what they're doing wrong and how to improve... [W]e did speak with an expert who said that baby boomers learned to suck it up and perform. And this trend really is generational.

From the Journal's article: At Microsoft, managers are encouraged to use the word "perspectives" instead of traditional feedback, according to current and former employees. Reviews, meanwhile, have been branded as "connect" conversations. The company also recently stopped including anonymous comments from peers in employee reviews, instead showing the names of the colleagues in question... Jennifer Solomon-Baum, a former Microsoft marketing director who left early this year, says she understands why the company chose to rethink its approach to feedback, which she feels may have made employees more open to giving feedback. On the other hand, she says Microsoft's recent decision to put an end to anonymous peer feedback in reviews completely backfired. In the wake of the change, "we didn't get the richness of constructive criticism," says Solomon-Baum, who is now consulting and leading marketing for a new ballet company in Los Angeles. "It became a praise festival...."

The divide on the issue is partially generational, several HR specialists say... Many younger employees entered the workforce while managers had loosened expectations on productivity and performance, and may have had less stringent grading in college amid remote classes, making the postpandemic adjustment more difficult. "It's the first time that they have not just gotten professional feedback, but it might be the first time in quite a while that somebody said, 'You know, this isn't good enough,'" says Megan Gerhardt, a management professor at Miami University and the author of a book on leading intergenerational workforces.

"I refuse to believe this is true," writes Apple blogger John Gruber, "and if it is true, my feedback is that any company that encounters an employee who bristles at the word feedback should fire them on the spot."
AI

What Will the Next Tech Rebellion Look Like? Ask the Luddites (fastcompany.com) 61

In 1811 working men felt threatened by the arrival of wooden, water-powered looms. And yet "The Luddite rebellion came at a time when the working class was beset by a confluence of crises that today seem all too familiar..." writes Los Angeles Times technology columnist Brian Merchant. In an upcoming book called Blood in the Machine, he writes that "amid it all, entrepreneurs and industrialists pushing for new, dubiously legal, highly automated and laborâsaving modes of production."

Fast Company has an excerpt from the book asking whether history is now repeating itself. Its headline? "A new tech rebellion is taking shape. What we can learn from the Luddites." The reason that there are so many similarities between today and the time of the Luddites is that little has fundamentally changed about our attitudes toward entrepreneurs and innovation, how our economies are organized, or the means through which technologies are introduced into our lives and societies. A constant tension exists between employers with access to productive technologies, and the workers at their whims...

The biggest reason that the last two hundred years have seen a series of conflicts between the employers who deploy technology and workers forced to navigate that technology is that we are still subject to what is, ultimately, a profoundly undemocratic means of developing, introducing, and integrating technology into society. Individual entrepreneurs and large corporations and nextâwave Frankensteins are allowed, even encouraged, to dictate the terms of that deployment, with the profit motive as their guide. Venture capital may be the radical apotheosis of this mode of technological development, capable as it is of funneling enormous sums of money into tech companies that can decide how they would like to build and unleash the products and services that shape society.

Take the rise of generative AI...

Among other things, the author argues that the unending writer's strike in Hollywood illustrates "the hunger that executives have for automating even creative work, and the lengths to which their workers will go to have some say in that disruption."

And they ultimately conclude that in the end the "disrupted lives" will include more than gig workers...

Thanks to Slashdot reader tedlistens for sharing the article.
Software

Apple Will Update iPhone 12 in France After Regulators Said It Emitted Too Much Radiation (apnews.com) 46

Apple has agreed to install updates for the iPhone 12 in France after French regulators ordered the company to stop selling the model because it emits electromagnetic radiation levels that exceed European Union standards. From a report: The company, which just unveiled its newest generation of iPhones, insists the 12 model is safe and the phones have been certified in countries around the world since its introduction in 2020. It says the problem raised by the French government agency that manages wireless communications frequencies is "related to a specific testing protocol."

The French agency said the iPhone 12 recently failed one of two types of tests for electromagnetic waves capable of being absorbed by the body. On Tuesday, France's government ordered a halt to sales of the iPhone 12 and told Apple to issue a software update to address the problem or face a recall. Apple said in a statement Friday that it "will issue a software update for users in France to accommodate the protocol used by French regulators." It did not elaborate.

Security

Lina Khan Got Stuck in the Fallout of the MGM Hack at Las Vegas (bloomberg.com) 51

Among the hotel patrons snarled in the fallout of MGM Resorts' cyberattack was -- unfortunately for the company -- one very high-profile figure: Lina Khan, the chair of the US Federal Trade Commission. Bloomberg News: On Tuesday night, she was among the 45 people waiting to check in at the MGM Grand along the Las Vegas strip as staff worked to manually fulfill everyone's reservation, according to people familiar with the matter. When Khan and her staff got to the front of the line, an employee at the desk asked them to write down their credit card information on a piece of paper.

As the leader of the federal agency that, among other things, ensures companies protect consumer data wrote down her details, Khan asked the worker: How exactly was MGM managing the data security around this situation? The desk agent shrugged and said he didn't know, according to a senior aide who was traveling with Khan and described the experience to Bloomberg as surreal. Khan was among the thousands of MGM hotel patrons inconvenienced in the aftermath of the hack, which was said to be orchestrated by a group of hackers known as Scattered Spider. Days after the incident, many of the company's websites -- including its reservation system -- were still displaying error messages, some slot machines at its casinos across the country are still out of service and employees were handling processes manually.

Security

Iranian Hackers Target Satellite and Defense Firms, Microsoft Says (axios.com) 4

Iranian hackers have hacked dozens of companies in the defense, satellite and pharmaceutical sectors this year using a fairly unsophisticated, blunt hacking technique, Microsoft warned in a new report. From a report: Many of these companies are based in the U.S., and the breaches come amid heavy U.S. sanctions targeting Iranian oil and petrochemical sales. Microsoft said Thursday that Iranian hacking group Peach Sandstorm -- which other firms also refer to as APT33, Elfin or Refined Kitten -- has been breaking into these companies by trying to guess multiple user accounts' passwords.

The password-spraying campaign took place between February and July this year, Microsoft found. In some cases, the hackers were able to exfiltrate data, and in others, they just lurked on the networks to see what intelligence they could gather. The Iranian group targeted thousands of companies as part of this monthslong campaign -- but was able to access only a small percentage of those organizations, Microsoft said.

Google

How Google Authenticator Made One Company's Network Breach Much, Much Worse (arstechnica.com) 79

A security company is calling out a feature in Google's authenticator app that it says made a recent internal network breach much worse. ArsTechnica: Retool, which helps customers secure their software development platforms, made the criticism on Wednesday in a post disclosing a compromise of its customer support system. The breach gave the attackers responsible access to the accounts of 27 customers, all in the cryptocurrency industry. The attack started when a Retool employee clicked a link in a text message purporting to come from a member of the company's IT team. It warned that the employee would be unable to participate in the company's open enrollment for health care coverage until an account issue was fixed. The text arrived while Retool was in the process of moving its login platform to security company Okta.

Most of the targeted Retool employees took no action, but one logged in to the linked site and, based on the wording of the poorly written disclosure, presumably provided both a password and a temporary one-time password, or TOTP, from Google authenticator. Shortly afterward, the employee received a phone call from someone who claimed to be an IT team member and had familiarity with the "floor plan of the office, coworkers, and internal processes of our company." During the call, the employee provided an "additional multi-factor code." It was at this point, the disclosure contended, that a sync feature Google added to its authenticator in April magnified the severity of the breach because it allowed the attackers to compromise not just the employee's account but a host of other company accounts as well.

Google

Google Won't Repair Cracked Pixel Watch Screens (theverge.com) 27

If you crack the screen on the Pixel Watch, getting it officially repaired by Google isn't on the cards. From a report: Several Pixel Watch owners have vented their frustrations about the inability to replace cracked screens, both on Reddit and in Google support forums. The Verge has also reviewed an official Google support chat from a reader who broke their Pixel Watch display after dropping the wearable. In it, a support representative states that Google "doesn't have any repair centers or service centers" for the device. "At this moment, we don't have any repair option for the Google Pixel Watch. If your watch is damaged, you can contact the Google Pixel Watch Customer Support Team to check your replacement options," Google spokesperson Bridget Starkey confirmed to The Verge.
IT

Activist Investor To GoDaddy: Cut Costs and Improve Sales, or Sell 66

GoDaddy needs to cut more jobs, reduce the tech budget, and address why it is falling short of financial targets outlined at its shareholder day in 2022, or the board should consider exploring a sale of the business. From a report: This is the view from activist investor Starboard Blue LLP, GoDaddy's third largest shareholder and one which is agitating for change and a seat on the corporation's board, something it has so far failed to secure. An open letter [PDF] to GoDaddy's top brass starts off friendly enough, with Starboard Value managing member Peter Feld describing the business as a "one-stop shop for micro- and small-businesses looking to develop a web presence."

Feld says Starboard Value invested in the stock, a move it made public in early 2022, on the basis of opportunities for strong revenue growth, "meaningful margin expansion" and a "more appropriate capital allocation strategy." "Unfortunately, despite each of these opportunities remaining, over the last 18 months we have been disappointed by GoDaddy's operational, financial and stock price performance," the letter adds. At the investor day, GoDaddy projected compound annual growth in revenue of 10 percent between 2022 and 2024, as well as 15 percent EBITDA, 20 percent free cashflow per share and $3 billion in share buybacks.
Further reading: Alphabet Selling Google Domains Assets To Squarespace.
Security

Hackers Claim It Only Took a 10-Minute Phone Call To Shut Down MGM Resorts (engadget.com) 51

An anonymous reader quotes a report from Engadget: The ALPHV/BlackCat ransomware group claimed responsibility for the MGM Resorts cyber outage on Tuesday, according to a post by malware archive vx-underground. The group claims to have used common social engineering tactics, or gaining trust from employees to get inside information, to try and get a ransom out of MGM Resorts, but the company reportedly refuses to pay. The conversation that granted initial access took just 10 minutes, according to the group.

"All ALPHV ransomware group did to compromise MGM Resorts was hop on LinkedIn, find an employee, then call the Help Desk," the organization wrote in a post on X. Those details came from ALPHV, but have not been independently confirmed by security researchers. The international resort chain started experiencing outages earlier this week, as customers noticed slot machines at casinos owned by MGM Resorts shut down on the Las Vegas strip. As of Wednesday morning, MGM Resorts still shows signs that it's experiencing downtime, like continued website disruptions.
In a statement on Tuesday, MGM Resorts said: "Our resorts, including dining, entertainment and gaming are currently operational." However, the company said Wednesday that the cyber incident has significantly disrupted properties across the United States and represents a material risk to the company.

"[T]he major credit rating agency Moody's warned that the cyberattack could negatively affect MGM's credit rating, saying the attack highlighted 'key risks' within the company," reports CNBC. "The company's corporate email, restaurant reservation and hotel booking systems remain offline as a result of the attack, as do digital room keys. MGM on Wednesday filed a 8-K report with the Securities and Exchange Commission noting that on Tuesday the company issued a press release 'regarding a cybersecurity issue involving the Company.'" MGM's share price has declined more than 6% since Monday.
Privacy

Password-Stealing Linux Malware Served For 3 Years and No One Noticed (arstechnica.com) 54

An anonymous reader quotes a report from Ars Technica: A download site surreptitiously served Linux users malware that stole passwords and other sensitive information for more than three years until it finally went quiet, researchers said on Tuesday. The site, freedownloadmanager[.]org, offered a benign version of a Linux offering known as the Free Download Manager. Starting in 2020, the same domain at times redirected users to the domain deb.fdmpkg[.]org, which served a malicious version of the app. The version available on the malicious domain contained a script that downloaded two executable files to the /var/tmp/crond and /var/tmp/bs file paths. The script then used the cron job scheduler to cause the file at /var/tmp/crond to launch every 10 minutes. With that, devices that had installed the booby-trapped version of Free Download Manager were permanently backdoored.

After accessing an IP address for the malicious domain, the backdoor launched a reverse shell that allowed the attackers to remotely control the infected device. Researchers from Kaspersky, the security firm that discovered the malware, then ran the backdoor on a lab device to observe how it behaved. "This stealer collects data such as system information, browsing history, saved passwords, cryptocurrency wallet files, as well as credentials for cloud services (AWS, Google Cloud, Oracle Cloud Infrastructure, Azure)," the researchers wrote in a report on Tuesday. "After collecting information from the infected machine, the stealer downloads an uploader binary from the C2 server, saving it to /var/tmp/atd. It then uses this binary to upload stealer execution results to the attackers' infrastructure."

Mozilla

Mozilla Patches Firefox, Thunderbird Against Zero-Day Exploited in Attacks (bleepingcomputer.com) 15

Mozilla has released emergency security updates to fix a critical zero-day vulnerability exploited in the wild, impacting its Firefox web browser and Thunderbird email client. From a report: Tracked as CVE-2023-4863, the security flaw is caused by a heap buffer overflow in the WebP code library (libwebp), whose impact spans from crashes to arbitrary code execution. "Opening a malicious WebP image could lead to a heap buffer overflow in the content process. We are aware of this issue being exploited in other products in the wild," Mozilla said in an advisory published on Tuesday. Mozilla addressed the exploited zero-day in Firefox 117.0.1, Firefox ESR 115.2.1, Firefox ESR 102.15.1, Thunderbird 102.15.1, and Thunderbird 115.2.2. Even though specific details regarding the WebP flaw's exploitation in attacks remain undisclosed, this critical vulnerability is being abused in real-world scenarios.
China

China Flags 'Security Incidents' With Apple's iPhones (bloomberg.com) 40

China flagged security problems with iPhones while saying it isn't barring purchases, the government's first comments on the topic after news reports that authorities are moving to restrict the use of Apple products in sensitive departments and state-owned companies. From a report: "We noticed that there have been many media reports about security incidents concerning Apple phones," Chinese Foreign Ministry spokeswoman Mao Ning told a regular press briefing in Beijing on Wednesday, without elaborating. China plans to expand a ban on the use of iPhones to a plethora of state-backed companies and agencies, Bloomberg News has reported, a sign of growing challenges for Apple in its biggest foreign market and global production base. Several agencies have begun instructing staff not to bring their iPhones to work. "China has not issued laws and regulations to ban the purchase of Apple or foreign brands' phones," Mao said, adding that the government attaches "great importance" to security and that all companies operating in China need to abide by its laws and regulations.
Security

Zara Finds Shoplifters Outsmarted Its New Security System (bloomberg.com) 97

Inditex is racing to iron bugs out of a new anti-shoplifting system for its Zara stores, slightly delaying its rollout partly because the security tags were easy to identify and remove in initial tests, Bloomberg reported Tuesday, citing people familiar with the matter. From the report: Chief Executive Officer Oscar Garcia Maceiras unveiled the new technology in March and pledged to roll it out for tests in all Zara stores worldwide over the summer. The system relies on tiny chips known as RFID, doing away with the hard plastic tags on garments that require checkout clerks to remove them. The new technology has run into teething issues. Staff in several countries have raised concerns to management that the technology may actually make theft easier, according to the people, who asked not to be identified.

Slashdot Top Deals