Google

Google Mandates Workers Back To Silicon Valley, Other Offices From April 4 (reuters.com) 217

An anonymous reader quotes a report from Reuters: Alphabet's Google from April 4 will require employees back about three days a week in some of its U.S., U.K. and Asia Pacific offices, its first step to end policies that allowed remote work because of COVID-19 concerns. An internal email on Wednesday seen by Reuters told employees in the San Francisco Bay Area that "advances in prevention and treatment, the steady decline in cases we continue to see and the improved safety measures we have implemented ... now mean we can officially begin the transition to the hybrid work week."

Google expects most employees will be in offices about three days a week, with some variance by team and role. Everyone coming to the office must be fully vaccinated against COVID-19 or have an approved exemption, according to the email from John Casey, Google's vice president of global benefits. Unvaccinated workers without an exemption will be given an option to seek one or apply for permanent remote work. Fully vaccinated workers will not have to wear masks in Bay Area offices, Casey said. Employees not prepared to return April 4 also can seek a remote-work extension, Google said. Google largely has restored office perks such as free meals, massages and transit. But while business visitors and meetings are permitted, employees cannot yet bring back families or children to dine or visit with them.

The Military

Ukraine Might Have Leaked Data On 120,000 Russian Soldiers (theregister.com) 184

BrendaEM shares a report from The Register: Ukrainian news website Ukrainska Pravda says the nation's Centre for Defense Strategies think tank has obtained the personal details of 120,000 Russian servicemen fighting in Ukraine. The publication has now shared this data freely on its website. The Register and others have been unable to fully verify the accuracy of the data from the leak. The records include what appears to be names, addresses, passport numbers, unit names, and phone numbers. Some open source intelligence researchers on Twitter said they found positive matches, as did sources who spoke confidentially to El Reg; others said they couldn't verify dip-sampled data. Rumors swirled on the internet that activists were behind the disclosure. The Ukrainian news agency said the personnel records were obtained from "reliable sources." Whether or not the database's contents is real, the impact on Russian military morale -- knowing that your country's enemies have your personal details and can contact your family if you're captured, killed, or even still alive -- won't be insignificant.
Open Source

Hackers Demand NVIDIA Open Source Their Drivers Or They Leak More Data (videocardz.com) 75

New submitter briaguya shares a report from VideoCardz: Hackers that infiltrated NVIDIA systems are now threatening to release more confidential information unless the company commits to open sourcing their drivers. It is unclear what the stolen data contains, but the group confirmed that there are 250GB of hardware related data in their possession. Furthermore, the group confirmed they have evaluated NVIDIA position, which means that NVIDIA is might trying to communicate with the group to prevent future leaks. The group has already published information on NVIDIA DLSS technology and upcoming architectures. Yesterday, Nvidia reportedly retaliated against the hacker group known as "Lapsus$" by sneaking back into the hacker's system and encrypting the stolen data. The group claimed that it had a backup of the data, though.
Google

The Oddly Addictive Quality of Google Alerts (newyorker.com) 7

The imperfect, scattershot search tool delivers just enough usefulness and serendipity to keep one hooked. From a report: Google Alerts can cast a wonderful net, but mesh size matters: large holes and it catches nothing, too small and it catches everything. Consider the earliest and one of the most persistent reasons for setting these alerts: tracking yourself. All is vanity, perhaps especially on the Internet, so it's no surprise that one of the things that we're most eager to know is what the world is saying about us. The engineer who developed the alert system for Google told CNN that when he first presented the idea, twenty years ago, his manager was skeptical, worrying that it would starve the search-engine of traffic: rather than consumers constantly searching for fresh mentions of whatever topic interested them, they would wait for the alert, then follow its links not to Google but to outside Web sites, leaching away potential advertising revenue. In response, the engineer, one of the first forty or so employees of the company, took his prototype to Google's co-founders, who approved it after watching him demonstrate only two search terms: "Google" and "Larry Page," the name of one of the co-founders.

Learning what other people thought about us used to take either a great deal of luck, like Tom Sawyer being mistaken for dead and then getting to eavesdrop on his own funeral, or a great deal of effort, like Harun al-Rashid, a caliph of the Abbasid dynasty, in the "Arabian Nights," disguising himself in order to venture out into the streets and talk with his subjects candidly. But the Internet has made it easy -- made it, in fact, almost unavoidable. The same Google Alert can make sure you know that your long-lost bunkmate from summer camp has mentioned you in an essay, that a friend of your deceased uncle has written a memoir of their time together in the Marines (including the care packages you sent them), and that the local newspaper has digitized its archives, thereby offering up to the Internet your high-school football averages and your arrest for vandalism.

Security

The Dire Predictions About a Russian Cyber Onslaught Haven't Come True in Ukraine. At Least Not Yet. (washingtonpost.com) 66

An anonymous reader shares a report: Ukraine's core cyberdefense has done better than expected because it focused on the issue after Russian hackers briefly knocked out power to swaths of the country in 2015 and 2016, said David Cowan, a veteran cybersecurity venture capitalist and corporate director, and because it has had help from American and European experts. "I would have thought that by now Russia would have disabled a lot more infrastructure around communications, power and water," Cowan said. "If Russia were attacking the U.S., there would be more cyber damage." The absence of major disruptions predicted by cyberwar doctrine has allowed Ukraine's President Volodymyr Zelensky to deliver propaganda coups with little more than a smartphone and a data link.
Security

Russian Cybersecurity Giant Kaspersky Tries To Maintain Neutrality During Ukraine War (vice.com) 161

An anonymous reader quotes a report from Motherboard, written by Joseph Cox: Around the same time Russian forces launched a massive rocket into a square in Kharkiv, Ukraine's second-largest city, killing and wounding an as of yet unknown number of people, Eugene Kaspersky, head of his namesake Russian cybersecurity firm, tweeted that he hoped negotiations between Ukraine and Russia would lead to "a compromise." The statement encapsulates the company's position since Russia invaded Ukraine six days ago -- that of attempted neutrality in a war where silence or fence sitting is implicitly siding with the Russian forces. In another statement to Motherboard sent on Monday, the company said "As a technology and cybersecurity service provider the company is not in a position to comment or speculate on geopolitical developments outside of its area of expertise."

Kaspersky is one of the best-known Russian companies, and for years its antivirus product has been among the most used in the world. The antivirus software also harvests telemetry data for Kaspersky's researchers who can then use that to identify and counter new threats. Its researchers are some of the best in the world, with its Global Research & Analysis Team (GReAT) regularly publishing leading research on various government malware operations. Famously the company first revealed details of a U.S. government hacking group that it dubbed Equation Group. Kaspersky has also researched suspected Russian government linked hackers. Eugene's tweet also brings something else to the surface again: how much is Kaspersky, the company, influenced by the Russian government, even if indirectly? As a Russian firm operating in Moscow under Russian laws, it may feel the need to toe the line on Russian issues.

Kaspersky's company statement on Monday added that "Kaspersky is focused on its mission to build a safer world. For 25 years, the company delivers deep threat intelligence and security expertise that is constantly transforming into innovative security solutions and services to protect businesses, critical infrastructure, governments and consumers around the globe. Kaspersky's business operations remain stable. The company guarantees the fulfillment of its obligations to partners and customers -- including product delivery and support and financial transaction continuity. The global management team is monitoring the situation carefully and is ready to act very quickly if needed." Kaspersky may not currently feel it is in a position to speculate or take a position on the invasion of Ukraine. But with a 40 mile long Russian military convoy making its way to Kyiv, and with the prospect of more cyber attacks playing a role in the invasion, Kaspersky may need to take a side.

IT

Web Hosting Provider Namecheap To Ban Russia-Based Users, Citing Ukraine (pcmag.com) 136

Domain and web hosting provider Namecheap is terminating all service with the company's Russian-based users over the Kremlin's invasion of Ukraine. From a report: "Unfortunately, due to the Russian regime's war crimes and human rights violations in Ukraine, we will no longer be providing services to users registered in Russia," US-based Namecheap told Russian users in an email on Monday. The company is asking Russian users to transfer their domains to another provider by March 6. Otherwise their sites will resolve to a 403 Forbidden page. In addition, Namecheap has begun blocking Russian clients from using the company's web hosting and private email services over Russian internet domains, including .ru and .su. "While we sympathize that this war may not affect your own views or opinion on the matter, the fact is, your authoritarian government is committing human rights abuses and engaging in war crimes so this is a policy decision we have made and will stand by," the company added. The decision has caused some Russian users to complain they've been unfairly targeted. "Whoever came up with this idea is an idiot and should be fired," wrote one user on Twitter, who claims Namecheap is "blanket targeting" civilians, instead of going after Russia's government.
Security

Nvidia Says Employee, Company Information Leaked Online After Cyber Attack (cnn.com) 9

U.S. chipmaker Nvidia said on Tuesday a cyber attacker has leaked employee credentials and some company proprietary information online after their systems were breached. From a report: "We have no evidence of ransomware being deployed on the Nvidia environment or that this is related to the Russia-Ukraine conflict," the company's spokesperson said in a statement. The Santa Clara, California-based company said it became aware of the breach on Feb. 23. Nvidia added it was working to analyze the information that has been leaked and does not anticipate any disruption to the company's business. A ransomware outfit under the name "Lapsus$" has reportedly claimed to be responsible for the leak and seemingly has information about the schematics, drivers and firmware, among other data, about the graphics chips.
Security

Nvidia Allegedly Hacks Hackers Who Stole Company's Data (tomshardware.com) 57

According to Vx-underground on Twitter, Nvidia has reportedly retaliated against the hacker group that stole over 1TB of the company's data by sneaking back into the hacker's system and encrypting the stolen data. Tom's Hardware reports: LAPSU$, an extortion group in South America, had illegally tapped into Nvidia's mailing server and installed malware on the software distribution server. As a result, the hacker group purportedly extracted over 1TB of Nvidia's data. However, it's unknown what kind of data the hackers had stolen, whether Nvidia's or its clients' data. It would seem that Nvidia has identified the attackers. According to the Vx-underground's Twitter post and backed by screenshots, the chipmaker has infected the perpetrators' system with ransomware and encrypted the stolen data in response to the attack. The group claimed that it had a backup of the data, though.
China

New Chinese Hacking Tool Found, Spurring US Warning To Allies (reuters.com) 14

Security researchers with U.S. cybersecurity firm Symantec said they have discovered a "highly sophisticated" Chinese hacking tool that has been able to escape public attention for more than a decade. Reuters reports: The discovery was shared with the U.S. government in recent months, who have shared the information with foreign partners, said a U.S. official. Symantec, a division of chipmaker Broadcom, published its research about the tool, which it calls Daxin, on Monday. "It's something we haven't seen before," said Clayton Romans, associate director with the U.S. Cybersecurity Infrastructure Security Agency (CISA). "This is the exact type of information we're hoping to receive."

CISA highlighted Symantec's membership in a joint public-private cybersecurity information sharing partnership, known as the JCDC, alongside the new research paper. The JCDC, or Joint Cyber Defense Collaborative, is a collective of government defense agencies, including the FBI and National Security Agency, and 22 U.S. technology companies that share intelligence about active cyberattacks with one another. Symantec's attribution to China is based on instances where components of Daxin were combined with other known, Chinese-linked computer hacker infrastructure or cyberattacks, said Vikram Thakur, a technical director with Symantec. [...] "Daxin can be controlled from anywhere in the world once a computer is actually infected," said Thakur. "That's what raises the bar from malware that we see coming out of groups operating from China."

Security

Ukraine Says Its 'IT Army' Has Taken Down Key Russian Sites (bleepingcomputer.com) 60

Key Russian websites and state online portals have been taken offline by attacks claimed by the Ukrainian cyber police force, which now openly engages in cyber-warfare. From a report: As the announcement of the law enforcement agency's site details, specialists from the force have teamed with volunteers to attack the web resources of Russia and Belarus. The three countries are currently involved in an ongoing and large-scale armed forces conflict that includes a cyber frontline, which manifested even before the invasion. The Ukrainian cyber police have announced having targeted the websites of the Investigative Committee of the Russian Federation, the FSB (Federal Security Service), and the Sberbank, Russia's state-owned bank.
Microsoft

Microsoft Detected 'Destructive Cyberattacks' Against Ukraine Hours Before Russian Invasion (geekwire.com) 26

Microsoft says it began detecting "destructive cyberattacks directed against Ukraine's digital infrastructure" several hours before the Russian military began launching missiles or moving tanks into the country last week. From a report: The disclosure Monday, part of a larger blog post about Ukraine by Microsoft President Brad Smith, provides a glimpse of how cyber-warfare is being used as part of the ongoing invasion. The company says it is giving ongoing guidance to the Ukrainian government about cyberthreats as the situation unfolds. Smith also outlined the company's efforts to combat state-sponsored disinformation campaigns, ensuring that its platforms are not displaying or distributing any content or apps from Russia's state-sponsored RT and Sputnik news organizations, in line with a recent European Union decision. He wrote that there's "a well-orchestrated battle ongoing in the information ecosystem where the ammunition is disinformation, undermining truth and sowing seeds of discord and distrust," he wrote.
Security

Toyota Suspends Domestic Factory Operations After Suspected Cyber Attack (reuters.com) 27

Toyota said it will suspend domestic factory operations on Tuesday, losing around 13,000 cars of output, after a supplier of plastic parts and electronic components was hit by a suspected cyber attack. From a report: No information was immediately available about who was behind the possible attack or the motive. The attack comes just after Japan joined Western allies in clamping down on Russia after it invaded Ukraine, although it was not clear if the attack was at all related. Japanese Prime Minister Fumio Kishida said his government would investigate the incident and whether Russia was involved. Kishida on Sunday announced that Japan would join the United States and other countries in blocking some Russian banks from accessing the SWIFT international payment system. He also said Japan would give Ukraine $100 million in emergency aid.
Security

Conti Ransomware Gang Chats Leaked by Pro-Ukraine Member (therecord.media) 27

A member of the Conti ransomware group, believed to be Ukrainian of origin, has leaked the gang's internal chats after the group's leaders posted an aggressive pro-Russian message on their official site, on Friday, in the aftermath of Russia's invasion of Ukraine. From a report: The message appears to have rubbed Conti's Ukrainian members the wrong way, and one of them has hacked the gang's internal Jabber/XMPP server. Internal logs were leaked earlier today via an email sent to multiple journalists and security researchers. Dmitry Smilyanets, a threat intelligence analyst for Recorded Future, who has interacted with the Conti gang in the past, has confirmed the authenticity of the leaked conversations. The leaked data contains 339 JSON files, with each file consisting of a full day's log. Conversations from January 29, 2021, to last February 27, 2022, have been leaked and can be read online here, courtesy of security firm IntelligenceX.
Security

Ukraine Official Urges 'IT Army' of World's Digital Talent To Attack Russian Energy and Financial Firms (venturebeat.com) 149

VentureBeat reports: In Ukraine today, Mykhailo Fedorov, the country's vice prime minister, announced on Twitter, "We are creating an IT army."

"We need digital talents," wrote Fedorov, who also holds the title of minister of digital transformation — sharing a link to a Telegram channel where he said operational tasks will be distributed. "We continue to fight on the cyber front." On the Telegram channel, the IT army reportedly posted its list of Russian targets — which were also translated into English "for all IT specialists from other countries...."

On Friday, Christian Sorensen, a former U.S. Cyber Command official, told VentureBeat that "hacktivists around the world [will be] working against Russia, because they are the aggressor.... I think things will ramp up against western targets, but Russia and Belarus will be targeted by these groups even more" said Sorensen, formerly the operational planning team lead for the U.S. Cyber Command....

[O]n Friday, a Bloomberg report said that a hacker group that was now forming to bring counterattacks against Russia had amassed 500 members. And today, we have the announcement of Ukraine's IT army — potentially including assistance from hackers around the globe. "Whether sanctioned or not, official or not, if people have or can get the right information, know-how, and desire — they can make an impact," Sorensen said on Friday, prior to the announcement of Ukraine's IT army. "We'll have to wait and see what they are able to do."

The next day Reuters reported that the official website of the Kremlin, "the office of Russian President Vladimir Putin....was down on Saturday, following reports of denial of service (DDoS) attacks on various other Russian government and state media websites.

"The outages came as Ukraine's vice prime minister said it had launched an 'IT army' to combat Russia in cyberspace."

But the Independent reports that the cyberattacks may have been even more extensive: Ukraine's state telecommunications agency announced on Saturday that six Russian government websites, including the Kremlin's, were down, according to The Kyiv Independent.

The agency also stated that the Russian media regulator's website had gone down, and that hackers had got Russian TV channels to play the Ukrainian music.


Note from Slashdot: the blue/purple bar means the story was posted automatically from the firehose without a Slashdot editor selecting it. This happens when a story gets a huge amount of upvotes in the firehose.
Bitcoin

How a US Tech Firm Struggled to Get Its Employees Out of Kyiv (washingtonpost.com) 167

On Friday the Washington Post's live updates on the Russia-Ukraine situation included the story of a tech firm trying to get its employees out of Kyiv: John Sung Kim, chief executive of the software outsourcing company JetBridge, has been communicating with his 24 employees in Kyiv, all software developers, through Slack. Half of them are trying to leave Ukraine, but Kim says he is struggling to help them and has been unable to get them train tickets, a rental car or gasoline.

"The other half of my team wants to stay and fight," said Kim. "I got on an all-hands with them this morning and told them it's not their responsibility to be soldiers and there's other ways they can contribute since they're software engineers, but there's nothing I can say to dissuade them." Kim said JetBridge's clients are almost exclusively Silicon Valley tech companies that are publicly traded or have raised venture capital financing. "The universal issue other than transportation logistics seems to be grandparents. 'My babushka' is the common theme of why they're torn from actually leaving," he said. The fallout from Russia's invasion has also impacted JetBridge's employees in Belarus. "The males in Belarus are scared that there's going to be military conscription, and unlike the Ukrainians, my Belarusian engineers have zero desire to pick up a rifle. Zero," he said.

In anticipation of European Union sanctions on Belarus, Kim said JetBridge has started paying employees in bitcoin.

EU

NATO Secretary-General Warns Cyberattacks Could Trigger Article 5 (nbcnews.com) 73

NATO Secretary-General Jens Stoltenberg said Friday that cyberattacks could trigger Article 5 of the organization's charter, the so-called "commitment clause" that considers an attack on any NATO ally an attack on all. NBC News reports: Stoltenberg's comment comes as national security professionals and cybersecurity industry professionals remain on high alert for any major attacks. While conflict on the ground in Ukraine continues to escalate, little has been seen thus far in terms of major cyberwar activities. Still, some hacker and activist groups have sprung into action. One ransomware group announced Friday that it supported the Russian government and would respond to cyberattacks on Russia by going after "critical infrastructures of an enemy." As for attacks on Ukraine, the country's computer emergency response team said Friday that it had seen a large email phishing campaign from Belarus targeted at military personnel. The statement comes amid a major cyberattack on Nvidia that was initiated at the same time as the Russian cyber warfare division started their offensive against Ukraine. Security researchers are concerned that somebody could put something malicious in one of the software updates that are then sent out to Nvidia's clients.
Security

NVIDIA Hit By Major Cyberattack That May Have 'Completely Compromised' Parts of Its Business (wccftech.com) 48

An anonymous reader quotes a report from Wccftech: NVIDIA has seemingly been hit by a major cyberattack that may have completely compromised parts of its business, reports The Telegraph. In their exclusive report, The Telegraph reports that the cyberattack was initiated at the same time as the Russian cyber warfare division started their offensive against Ukraine. All Nato allies have announced major sanctions on Russia and this could potentially be why Russia has decided to target major companies such as NVIDIA.

The report further states that the cyberattack on NVIDIA has completely compromised parts of their business and there are already reports from several users coming in regarding services disruption. The scale of this attack is currently unknown but it clearly seems to be a major one as NVIDIA had to take several systems offline to pacify the intrusion before it could spread further: "'The ultimate concern is that somebody may have put something in one of the software updates,' Dr Woodward said, pointing to the devastating SolarWinds hack that exploited American software companies to gain access to US government computer systems. 'They'll be going through trying to make sure to see if there's any indication that anything has been changed in their software that they then shipped to their clients.'" NVIDIA's mail servers were also partially operational during this time so it's entirely likely that there might have been a breach in confidential documents. But it is not confirmed yet if any data was stolen.
In a brief statement, an Nvidia spokesperson confirmed the report, saying: "We are investigating an incident. We don't have any additional information to share at this time."
Security

Ukraine Says Belarusian Hackers Are Targeting Its Defense Forces (techcrunch.com) 29

Ukrainian cybersecurity officials have warned that Belarusian state-sponsored hackers are targeting the private email addresses of Ukrainian military personnel. From a report: Announcing the activity in a Facebook post, Ukraine's Computer Emergency Response Team (CERT-UA) said that a mass phishing campaign is targeting the private i.ua and meta.ua accounts belonging to Ukrainian military personnel. "After the account is compromised, the attackers, by the IMAP protocol, get access to all the messages," it added. "Later, the attackers use contact details from the victim's address book to send the phishing emails." CERT-UA has attributed the ongoing campaign to the UNC1151 threat group, which Mandiant formally linked to the Belarusian government in November 2021. Mandiant also linked the state-backed cyber-espionage group to the Ghostwriter disinformation campaign, which has been involved in spreading anti-NATO rhetoric and hack-and-leak operations throughout Europe. "The Minsk-based group 'UNC1151' is behind these activities. Its members are officers of the Ministry of Defence of the Republic of Belarus," CERT-UA wrote.
Security

Ukraine Calls on Hacker Underground To Defend Against Russia (reuters.com) 44

The government of Ukraine is asking for volunteers from the country's hacker underground to help protect critical infrastructure and conduct cyber spying missions against Russian troops, according two people involved in the project. From a report: As Russian forces attacked cities across Ukraine, requests for volunteers began to appear on hacker forums on Thursday morning, as many residents fled the capital Kyiv. "Ukrainian cybercommunity! It's time to get involved in the cyber defense of our country," the post read, asking hackers and cybersecurity experts to submit an application via Google docs, listing their specialties, such as malware development, and professional references. Yegor Aushev, co-founder of a cybersecurity company in Kyiv, told Reuters he wrote the post at the request of a senior Defense Ministry official who contacted him on Thursday. Aushev's firm Cyber Unit Technologies is known for working with Ukraine's government on the defense of critical infrastructure. Another person directly involved in the effort confirmed that the request came from the Defense Ministry on Thursday morning. Further reading: Washington steels for Russian cyberattacks.

Slashdot Top Deals