IT

Canada's Major Banks Go Offline in Mysterious Hours-long Outage (bleepingcomputer.com) 310

Five major Canadian banks went offline for hours blocking access to online and mobile banking as well as e-transfers for customers. From a report: The banks reportedly hit by the outage include Royal Bank of Canada (RBC), BMO (Bank of Montreal), Scotiabank, and the Canadian Imperial Bank of Commerce (CIBC). Canada's five major banks went offline yesterday impeding access to e-Transfers, online and mobile banking services for many.
Security

How Roblox 'Beamers' Get Rich Stealing from Children (vice.com) 47

Underneath the gaming platform worth $68 billion and used by over half of all children in America is a ballooning and highly profitable ecosystem of hackers and traders. From a report: Motherboard spoke to 11 people connected to Roblox beaming (Roblox slang for getting hacked and your items stolen), including victims, the people who administer the marketplaces where people then sell Roblox items, and hackers themselves. There's a ballooning and highly profitable ecosystem where hackers stand to steal tens of thousands of dollars worth of items in minutes, with many victims including children. The sketchy, and sometimes illicit, economy sits in the shadow of Roblox's legitimate business, which is worth $68 billion and which half of all children in the U.S. play on in some form. One beamer called Max told Motherboard how he targets many of these victims. "I go to servers with rich idiots, then message every single one of them," he said.

Roblox isn't a single game but a free application players download onto their PC, phone, or Xbox games console. From there, they can access tens of millions of different games, or as Roblox calls them, "experiences," made by members of the wider Roblox community and player base. At the time of this writing, popular Roblox games include Murder Mystery 2, where players try to identify the killer; Pet Simulator X, for players who want to take care of and trade pets; and Hide and Seek Extreme.

Businesses

Akamai To Acquire Linode (linode.com) 19

"Akamai, which announced quarterly earnings today, also announced that they plan to acquire longtime Linux VPS host Linode for $900 million," writes Slashdot reader virtig01. From a press release announcing the acquisition: Akamai Technologies, the world's most trusted solution to power and protect digital experiences, today announced it has entered into a definitive agreement to acquire Linode, one of the easiest-to-use and most trusted infrastructure-as-a-service (IaaS) platform providers. [...] Under terms of the agreement, Akamai has agreed to acquire all of the outstanding equity of Linode Limited Liability Company for approximately $900 million, after customary purchase price adjustments. As a result of structuring the transaction as an asset purchase, Akamai expects to achieve cash income tax savings over the next 15 years that have an estimated net present value of approximately $120 million. The transaction is expected to close in the first quarter of 2022 and is subject to customary closing conditions.

Christopher Aker, founder and chief executive officer, Linode, added, "We started Linode 19 years ago to make the power of the cloud easier and more accessible. Along the way, we built a cloud computing platform trusted by developers and businesses around the world. Today, those customers face new challenges as cloud services become all-encompassing, including compute, storage, security and delivery from core to edge. Solving those challenges requires tremendous integration and scale which Akamai and Linode plan to bring together under one roof. This marks an exciting new chapter for Linode and a major step forward for our current and future customers."

Security

74% of Ransomware Revenue Goes To Russia-Linked Hackers (bbc.com) 51

New analysis suggests that 74% of all money made through ransomware attacks in 2021 went to Russia-linked hackers. The BBC reports: Researchers say more than $400 million worth of crypto-currency payments went to groups "highly likely to be affiliated with Russia." Russia has denied accusations that it is harboring cyber-criminals. Researchers also claim "a huge amount of crypto-currency-based money laundering" goes through Russian crypto-companies. Chainalysis, which carried out the research, said it was able to follow the flow of money to and from the digital wallets of known hacking groups using public blockchain transaction records.

In the Chainalysis report, it's highlighted that 9.9% of all known ransomware revenue is going to Evil Corp - an alleged cyber-crime group which the US has issued sanctions and indictments against, but who are operating in Russia with apparent impunity. A BBC investigation in November found that Igor Turashev, one of the accused leaders of Evil Corp, is operating several businesses out of Moscow City's Federation Tower. The tower is one of Russia's most prestigious addresses, home to prominent businesses and with apartments going for millions of dollars. Chainalysis claims several crypto-currency companies based in the tower were used by hackers to launder illicit funds, turning crypto-currency from digital wallet addresses to mainstream money. "In any given quarter, the illicit and risky addresses account for between 29% and 48% of all funds received by Moscow City crypto-currency businesses," researchers allege.

Security

Ukraine's Military and Banks Hit By Apparent DDoS Cyberattack Campaign (cnet.com) 45

Ukraine's Ministry of Defense website suffered from what appeared to be a distributed denial of service attack Tuesday, according to the government's Facebook account. CNET reports: The military's website remained unavailable as of 12 p.m. PT Tuesday, with the Ukrainian military's Facebook account saying work is currently underway to restore regular functioning to the online portal. The nation's largest commercial bank, PrivatBank, has also been subjected to a "massive DDoS attack" for the past few hours, according to the Ukraine Center for Strategic Communications. There's no threat to customer funds stored at the bank, it said, though the attack is preventing customers from accessing the Privat24 application and viewing their balances. Online banking with Oschadbank is also down, the Center for Strategic Communications said, as reported earlier by Vice. Nobody has yet to be blamed for the attack, but as CNET notes, "it comes after Russia is believed to have mounted multiple cyberattacks on Ukraine as part of efforts that security experts say are designed to destabilize the country's government and economy."

UPDATE (2/16/2022): America's Undersecretary of State said Wednesday that "While we're still investigating and doing forensics along with the Ukrainians, I think what's most important is that these cyberattacks were not very successful," reports CNN, which adds that the official "credited Ukrainian officials for responding quickly and helping the websites recover."
Privacy

Pegasus Spyware Should Be Banned, EU Data Agency Warns (bloomberg.com) 26

NSO Group's controversial Pegasus spyware should be banned in the European Union, the bloc's in-house privacy watchdog warned on Tuesday. From a report: "The ban on the development and the deployment of spyware with the capability of Pegasus in the EU would be the most effective option to protect our fundamental rights and freedoms," the European Data Protection Supervisor said in a statement on Tuesday. The warning comes amid increasing scrutiny of abuses of surveillance technologies meant to help intelligence and law enforcement agencies fight serious crime and terrorism. While the EU regulator doesn't make decisions for member countries, its influence at the top echelons of the bloc's institutions may encourage other authorities to crack down on surveillance software.
Security

Microsoft Defender Will Soon Block Windows Password Theft (bleepingcomputer.com) 33

Microsoft is enabling a Microsoft Defender 'Attack Surface Reduction' security rule by default to block hackers' attempts to steal Windows credentials from the LSASS process. BleepingComputer reports: When threat actors compromise a network, they attempt to spread laterally to other devices by stealing credentials or using exploits. One of the most common methods to steal Windows credentials is to gain admin privileges on a compromised device and then dump the memory of the Local Security Authority Server Service (LSASS) process running in Windows. This memory dump contains NTLM hashes of Windows credentials of users who had logged into the computer that can be brute-forced for clear-text passwords or used in Pass-the-Hash attacks to login into other devices. While Microsoft Defender block programs like Mimikatz, a LSASS memory dump can still be transferred to a remote computer to dump credentials without fear of being blocked.

To prevent threat actors from abusing LSASS memory dumps, Microsoft has introduced security features that prevent access to the LSASS process. One of these security features is Credential Guard, which isolates the LSASS process in a virtualized container that prevents other processes from accessing it. However, this feature can lead to conflicts with drivers or applications, causing some organizations not to enable it. As a way to mitigate Windows credential theft without causing the conflicts introduced by Credential Guard, Microsoft will soon be enabling a Microsoft Defender Attack Surface Reduction (ASR) rule by default. The rule, ' Block credential stealing from the Windows local security authority subsystem,' prevents processes from opening the LSASS process and dumping its memory, even if it has administrative privileges.

While enabling the ASR rule by default will significantly impact the stealing of Windows credentials, it is not a silver bullet by any means. This is because the full Attack Surface Reduction feature is only supported on Windows Enterprise licenses running Microsoft Defender as the primary antivirus. However, BleepingComputer's tests show that the LSASS ASR rule also works on Windows 10 and Windows 11 Pro clients. Unfortunately, once another antivirus solution is installed, ASR is immediately disabled on the device. Furthermore, security researchers have discovered built-in Microsoft Defender exclusion paths allowing threat actors to run their tools from those filenames/directories to bypass the ASR rules and continue to dump the LSASS process. Mimikatz developer Benjamin Delpy told BleepingComputer that Microsoft probably added these built-in exclusions for another rule, but as exclusions affect ALL rules, it bypasses the LSASS restriction.

Music

How Fake Song Lyrics Ended Up On Spotify (pitchfork.com) 26

DevNull127 writes: More bad news for Spotify from Conde Naste via their music site Pitchfork:

Last month, in the tone of a band reluctantly summoned from some deep seabed, My Bloody Valentine issued a prickly public service announcement: "Just noticed that Spotify has put fake lyrics up for our songs without our knowledge," the Irish shoegazers tweeted. "These lyrics are actually completely incorrect and insulting." Cocteau Twins' Simon Raymonde chimed in to report that they, too, had found gibberish transcriptions of their famously elliptical songs on streaming services.

The lyric snafu was not limited to Spotify. Over the past decade, a data platform called Musixmatch has assumed dominion over the world of lyrics, securing sub-licensing deals with the major publishing companies. The lyrics you see on Spotify, Tidal, and Amazon Music usually come through Musixmatch, via a data pipeline that links the platform's enormous transcriber community with a small core of paid quality-control monitors. (Apple Music has a dedicated lyrics team handling most of its transcriptions.)

The affair illustrates tech capitalism's discombobulation when faced with a key element in art, which is the inexplicable. I think the problem, though, is not Musixmatch and its protocol so much as the service's unilateral rollout, with quasi-official imprimatur, on platforms already under fire for flattening artistic identity and repackaging music as scaleable content. Having sub-licensed the rights, Musixmatch is perfectly entitled to crowd-source transcriptions and sell them on. But artists should know whose words are being put in their mouths—and that, should they wish, they have the right to opt out.

Security

Thousands of Npm Accounts Use Email Addresses With Expired Domains (therecord.media) 35

An academic research project found that thousands of JavaScript developers are using an email address with an expired domain for their npm accounts, leaving their projects exposed to easy hijacks. From a report: The study, performed last year by researchers from Microsoft and North Caroline State University, analyzed the metadata of 1,630,101 libraries uploaded on Node Package Manager (npm), the de-facto repository for JavaScript libraries and the largest package repository on the internet. Researchers said they found that 2,818 project maintainers were still using an email address for their accounts that had an expired domain, some of which they found on sale on sites like GoDaddy. The team argued that attackers could buy these domains, re-register the maintainer's address on their own email servers, and then reset the maintainer's account password and take over his npm packages.
Opera

Opera Browser Now Allows Emoji-only Web Addresses (theverge.com) 61

Web browser company Opera said Monday it will enable emoji-only based web addresses "to bring a new level of creativity to the internet." From a report: The integration is part of a partnership with Yat, a company that sells URLs with strings of emoji in them. "It's been almost 30 years since the world wide web launched to the public, and there hasn't been much innovation in the weblink space: people still include .com in their URLs," Jorgen Arnesen, executive vice president of mobile at Opera, said in a press release.
Security

Linux Malware Attacks are Increasing, and Businesses Aren't Ready (zdnet.com) 63

ZDNet reports: Cyber criminals are increasingly targeting Linux servers and cloud infrastructure to launch ransomware campaigns, cryptojacking attacks and other illicit activity — and many organisations are leaving themselves open to attacks because Linux infrastructure is misconfigured or poorly managed. Analysis from cybersecurity researchers at VMware warns that malware targeting Linux-based systems is increasing in volume and complexity, while there's also a lack of focus on managing and detecting threats against them.

This comes after an increase in the use of enterprises relying on cloud-based services because of the rise of hybrid working, with Linux the most common operating system in these environments. That rise has opened new avenues that cyber criminals can exploit to compromise enterprise networks, as detailed by the research paper, including ransomware and cryptojacking attacks tailored to target Linux servers in environments that might not be as strictly monitored as those running Windows. These attacks are designed for maximum impact, as the cyber criminals look to compromise as much as the network as possible before triggering the encryption process and ultimately demanding a ransom for the decryption key.

The report warns that ransomware has evolved to target Linux host images used to spin up workloads in virtualised environments, enabling the attackers to simultaneously encrypt vast swathes of the network and make incident response more difficult. The attacks on cloud environments also result in attackers stealing information from servers, which they threaten to publish if they're not paid a ransom.... Cryptojacking and other malware attacks are also increasingly targeting Linux servers. Cryptojacking malware steals processing power from CPUs and servers in order to mine for cryptocurrency....

Many of the cyberattacks targeting Linux environments are still relatively unsophisticated when compared with equivalent attacks targeting Windows systems — that means that with the correct approach to monitoring and securing Linux-based systems, many of these attacks can be prevented. That includes cybersecurity hygiene procedures such as ensuring default passwords aren't in use and avoiding sharing one account across multiple users.

Security

America's Cybersecurity Agency is Now Urging 'Heightened Posture' Against Russian Cyberattacks (pcmag.com) 29

America's Cybersecurity and Infrastructure Agency (CISA) "says that American companies should be extra wary about potential hacking attempts from Russia as tensions with the country rise," reports PC Magazine: Even if Russia doesn't invade Ukraine, it has often targeted the country with what Wired has characterized as "many of the most costly cyberattacks in history." Those attacks might not always be confined to Ukraine, however, which is where CISA's new Shields Up campaign comes in.... CISA says that it "recommends all organizations — regardless of size — adopt a heightened posture when it comes to cybersecurity and protecting their most critical assets." It also says that it's collaborated with its "critical infrastructure partners" to raise awareness of these risks.

The agency wants everyone to "reduce the likelihood of a damaging cyber intrusion," "take steps to quickly detect a potential intrusion," "ensure that the organization is prepared to respond if an intrusion occurs," and "maximize the organization's resilience to a destructive cyber incident." CISA offers advice related to each of those focus areas on its website.

Earlier this week CISA also added 15 "known exploited" vulnerabilities to its catalog, ZDNet reports, in products from Apache, Apple, Jenkins, and Microsoft: The list includes a Microsoft Windows SAM local privilege escalation vulnerability with a remediation date set for February 24. Vulcan Cyber engineer Mike Parkin said the vulnerability — CVE-2021-36934 — was patched in August 2021 shortly after it was disclosed. "It is a local vulnerability, which reduces the risk of attack and gives more time to deploy the patch. CISA set the due date for Federal organizations who take direction from them, and that date is based on their own risk criteria," Parkin said. "With Microsoft releasing the fix 5 months ago, and given the relative threat, it is reasonable for them to set late February as the deadline."
Security

Hundreds of E-Commerce Sites Booby-Trapped With Payment Card-Skimming Malware (arstechnica.com) 9

An anonymous reader quotes a report from Ars Technica, written by Dan Goodin: About 500 e-commerce websites were recently found to be compromised by hackers who installed a credit card skimmer that surreptitiously stole sensitive data when visitors attempted to make a purchase. A report published on Tuesday is only the latest one involving Magecart, an umbrella term given to competing crime groups that infect e-commerce sites with skimmers. Over the past few years, thousands of sites have been hit by exploits that cause them to run malicious code. When visitors enter payment card details during purchase, the code sends that information to attacker-controlled servers.

Sansec, the security firm that discovered the latest batch of infections, said the compromised sites were all loading malicious scripts hosted at the domain naturalfreshmall[.]com. "The Natural Fresh skimmer shows a fake payment popup, defeating the security of a (PCI compliant) hosted payment form," firm researchers wrote on Twitter. "Payments are sent to https://naturalfreshmall.com/p...." The hackers then modified existing files or planted new files that provided no fewer than 19 backdoors that the hackers could use to retain control over the sites in the event the malicious script was detected and removed and the vulnerable software was updated. The only way to fully disinfect the site is to identify and remove the backdoors before updating the vulnerable CMS that allowed the site to be hacked in the first place.

Sansec worked with the admins of hacked sites to determine the common entry point used by the attackers. The researchers eventually determined that the attackers combined a SQL injection exploit with a PHP object injection attack in a Magento plugin known as Quickview. [...] It's not hard to find sites that remain infected more than a week after Sansec first reported the campaign on Twitter. At the time this post was going live, Bedexpress[.]com continued to contain this HTML attribute, which pulls JavaScript from the rogue naturalfreshmall[.]com domain. The hacked sites were running Magento 1, a version of the e-commerce platform that was retired in June 2020. The safer bet for any site still using this deprecated package is to upgrade to the latest version of Adobe Commerce. Another option is to install open source patches available for Magento 1 using either DIY software from the OpenMage project or with commercial support from Mage-One.

Google

Google Says Default 2FA Cut Account Breaches In Half (engadget.com) 31

Google's decision to enable two-factor authentication by default has resulted in a 50 percent decrease in account breaches among those users where the feature was auto-enabled. Engadget reports: The company didn't say how rapidly it expected 2FA to spread, but promised to continue the rollout through 2022. More than 150 million people have been auto-enrolled so far, including more than 2 million YouTube creators. The company also promised more security upgrades to help mark Safer Internet Day. As of March, Google will let you opt-in to an account-level safe browsing option that keeps you from visiting known harmful sites. Google is also expanding Assistant's privacy-minded Guest Mode to nine new languages in the months ahead, and has promised to ramp up safeguards for politicians ahead of the US midterm elections.
Security

Ukraine Busts Alleged Russian Bot Farm Using Thousands of SIM Cards (vice.com) 28

An anonymous reader quotes a report from Motherboard: Ukraine's Security Service said it has shut down a troll farm in the city of Lviv. "The SSU cyber specialists uncovered and dismantled two bot farms in Lviv with a total capacity of 18,000 fake accounts," an SSU press release said. "According to preliminary information, organizers from Russia supervised the administrators of the bot farms." According to the press release, three people in two different residences were involved. Two gave over their apartments to the operation while a third took care of maintaining the accounts and equipment. "The bot farms worked mostly in social networks: distributed fakes to spread panic," the press release said. "The bots also published false information about bomb threats at various facilities."

The SSU said it seized two sets of GSM gateways, 3,000 SIM cards, laptops, and accounting records. GSM gateways are equipment that allows people to use SIM cards to connect to networks outside the default network they're meant to be connected to. They're popular tools for hackers and other cyber criminals, who can use them to manage several phone numbers, and to connect to Voice Over IP, or VoIP networks. The photos of the bust show dozens of GSM gateways stuffed with blurred SIM cards.

It's funny.  Laugh.

Mysterious Glitch Has Mazda Drivers Stuck on Public Radio (geekwire.com) 139

Drivers of certain vehicles in Seattle and other parts of Western Washington are shouting at their car radios this week. Not because of any particular song or news item that's being broadcast, but because an apparent technical glitch has caused the radios to be stuck on public radio station KUOW. From a report: The impacted drivers appear to all be owners of Mazda vehicles from between 2014 and 2017. In some cases the in-car infotainment systems have stopped working altogether, derailing the ability to listen to the radio at all or use Bluetooth phone connections, GPS, the rear camera and more. According to Mazda drivers who spoke with GeekWire, and others in a Reddit thread discussing the dilemma, everyone who has had an issue was listening to KUOW 94.9 in recent weeks when the car systems went haywire. KUOW sounded unsure of a possible cause; at least one dealership service department blamed 5G; and Mazda told GeekWire in an official statement that it identified the problem and a fix is planned.
Microsoft

Microsoft Considers Pursuing a Deal for Cybersecurity Firm Mandiant (bloomberg.com) 6

Microsoft is in talks to acquire cybersecurity research and incident response company Mandiant, Bloomberg News reported Wednesday, citing people familiar with the discussions, a deal that would bolster efforts to protect customers from hacks and breaches. From the report: The deliberations may not result in an offer, said the people, who asked not to be identified because the talks are private. Mandiant and Microsoft declined to comment. Mandiant shares surged 18% in New York, bringing its market value to almost $4.3 billion. Microsoft stock gained 1.2% to $304.56. Adding Mandiant would build up Microsoft's arsenal of products for protecting clients and responding to cybersecurity threats. The software giant bought two smaller cybersecurity companies last year, and said last month that it had amassed $15 billion in security software sales in 2021, up almost 45% from a year earlier. The company last year named former Amazon.com cloud executive Charlie Bell to oversee its security efforts, and said it had 3,500 employees working to safeguard customers "from the chip to the cloud."
Twitter

Twitter Tells US Senator It's Cutting Ties To Swiss Tech Firm (bloomberg.com) 7

Twitter told a U.S. senator it is cutting ties with a European technology company that helped it send sensitive passcodes to its users via text message. From a report: The social media firm said in a disclosure to U.S. Senator Ron Wyden, a Democrat from Oregon, that it is "transitioning" its service away from working with Mitto AG, according to a Wyden aide. A co-founder of Mitto operated a service that helped governments secretly surveil and track mobile phones, according to former employees and clients, as Bloomberg News and London-based Bureau of Investigative Journalism reported in December. Twitter cited media reports as the motivating factor behind its decision, the Wyden aide said. Several other companies have allegedly already cut ties with Mitto. In recent weeks, messaging companies Kaleyra and MessageBird have both ceased commercial relationships with Mitto, according to three people familiar with the matter.
Bug

ExpressVPN Offering $100,000 To First Person Who Hacks Its Servers (bleepingcomputer.com) 28

ExpressVPN has updated its bug bounty program to make it more inviting to ethical hackers, now offering a one-time $100,000 bug bounty to whoever can compromise its systems. Bleeping Computer reports: Today, ExpressVPN announced that they are now offering a $100,000 bug bounty for critical vulnerabilities in their in-house technology, TrustedServer. "This is the highest single bounty offered on the Bugcrowd platform and 10 times higher than the top reward previously offered by ExpressVPN," the company shared in an email to BleepingComputer. The new $100,000 one-time bounty is offered with the following conditions:

- The first person to submit a valid vulnerability, granting unauthorized access or exposing customer data, will receive the $100,000 bounty. This one-time bonus is valid until the prize has been claimed.
- The one-time $100,000 bounty is only eligible for vulnerabilities in ExpressVPN's VPN Server.
- Activities should remain in scope to the TrustedServer platform. If unsure that your testing is considered in-scope, please reach out to support@bugcrowd.com to confirm first.

ExpressVPN also invites security researchers to uncover possible ways to leak the actual IP address of clients and monitor user traffic. The bug bounty program is run through BugCrowd, which offers a safe harbor for researchers who attempt to breach ExpressVPN's servers as part of the program.

Security

Poland Army Adds New Cyber Component With Offensive Capabilities (therecord.media) 21

The Polish government has announced today the creation of a new cyber component inside its Army Forces that will be tasked with carrying out operations in cyber-space. From a report: Named the Cyberspace Defense Forces (Wojska Obrony Cyberprzestrzeni), the new branch will operate as a command center inside the Polish Army and will have the authority to carry out reconnaissance, defensive, and offensive operations, the Polish Ministry of National Defense said today. Work on establishing this unit began in 2019 and was formalized earlier today in a ceremony at the Club of the Military University of Technology in Warsaw, where Minister of National Defense Mariusz Blaszczak appointed Brig. Gen. Karol Molenda as the unit's inaugural commander. [...] With today's announcement, Poland becomes one of the very few countries in the world to formally create a cyber component for their armed forces after NATO officially declared cyberspace a formal warfare battleground and domain of operations at the 2016 NATO Summit, held in Warsaw, Poland.

Slashdot Top Deals