Security

Booby-trapped Sites Delivered Potent New Backdoor Trojan To macOS Users (arstechnica.com) 34

Researchers have uncovered advanced, never-before-seen macOS malware that was installed using exploits that were almost impossible for most users to detect or stop once the users landed on a malicious website. From a report: The malware was a full-featured backdoor that was written from scratch, an indication that the developers behind it have significant resources and expertise. DazzleSpy, as researchers from security firm Eset have named it, provides an array of advanced capabilities that give the attackers the ability to fully monitor and control infected Macs. Features include: victim device fingerprinting, screen capture, file download/upload, execute terminal commands, audio recording, and keylogging. Mac malware has become more common over the years, but the universe of advanced macOS backdoors remains considerably smaller than that of advanced backdoors for Windows. The sophistication of DazzleSpy -- as well as the exploit chain used to install it -- is impressive. It also doesn't appear to have any corresponding counterpart for Windows. This has led Eset to say that the people who developed DazzleSpy are unusual. "First, they seem to be targeting Macs only," Eset researcher Marc-Etienne M.Leveille wrote in an email. "We haven't seen payloads for Windows nor clues that it would exist. Secondly, they have the resources to develop complex exploits and their own spying malware, which is quite significant."
Verizon

Verizon's TracFone Customers Complain of Attackers Stealing Their Phone Numbers (wsj.com) 6

Attackers have commandeered thousands of TracFone customers' phone numbers in recent weeks, forcing new owner Verizon Communications to improve safeguards less than two months after it took over the prepaid wireless provider. From a report: TracFone offers prepaid wireless service under several brands, including Straight Talk, Total Wireless and its namesake brand. Some customers of Straight Talk said they found their phone lines suddenly disconnected around the December holidays. "We were recently made aware of bad actors gaining access to a limited number of customer accounts and, in some cases, fraudulently transferring, or porting out, mobile telephone numbers to other carriers," TracFone said in a notice posted on its website this month. In some cases, customers said they discovered their lines had been moved without their permission to Metro, a unit of T-Mobile US. A T-Mobile spokeswoman said the company investigated and found "no fraud or data breach of any sort" on its side. The company added that such unauthorized transfers "are unfortunately an industrywide issue."

Verizon, which acquired TracFone in late November in a $6.25 billion deal, said it had added security protections to the recently acquired services to prevent such fraudulent transfers. For instance, the prepaid operators will now send customers a text message notification when a transfer request is made. A Verizon spokeswoman said the attack appeared to affect about 6,000 TracFone customers, a fraction of Verizon's roughly 24 million prepaid lines. "We have no reason to think that this was caused by anybody on the inside," the spokeswoman said. "You've got the bad actors out there constantly trying to find points of weakness," Matt Ellis, Verizon's finance chief, said Tuesday in an interview. "We've addressed that weakness."

Security

New DeadBolt Ransomware Targets QNAP Devices, Asks 50 BTC For Master Key (bleepingcomputer.com) 68

ryanw shares a report from BleepingComputer: A new DeadBolt ransomware group is encrypting QNAP NAS devices worldwide using what they claim is a zero-day vulnerability in the device's software. The attacks started today, January 25th, with QNAP devices suddenly finding their files encrypted and file names appended with a .deadbolt file extension. Instead of creating ransom notes in each folder on the device, the QNAP device's login page is hijacked to display a screen stating, "WARNING: Your files have been locked by DeadBolt." This screen informs the victim that they should pay 0.03 bitcoins (approximately $1,100) to an enclosed Bitcoin address unique to each victim.

After payment is made, the threat actors claim they will make a follow-up transaction to the same address that includes the decryption key. This decryption key can then be entered into the screen to decrypt the device's files. At this time, there is no confirmation that paying a ransom will result in receiving a decryption key or that users will be able to decrypt files. The DeadBolt ransomware gang is offering the full details of the alleged zero-day vulnerability if QNAP pays them 5 Bitcoins worth $184,000. They are also willing to sell QNAP the master decryption key that can decrypt the files for all affected victims and the zero-day info for 50 bitcoins, or approximately $1.85 million.

Security

Major Linux PolicyKit Security Vulnerability Uncovered: Pwnkit (zdnet.com) 179

An anonymous reader quotes a report from ZDNet: [S]ecurity company Qualys has uncovered a truly dangerous memory corruption vulnerability in polkit's pkexec, CVE-2021-4034. Polkit, formerly known as PolicyKit, is a systemd SUID-root program. It's installed by default in every major Linux distribution. This vulnerability is easy to exploit. And, with it, any ordinary user can gain full root privileges on a vulnerable computer by exploiting this vulnerability in its default configuration. As Qualsys wrote in its brief description of the problem: "This vulnerability is an attacker's dream come true." Why is it so bad? Let us count the ways:

- Pkexec is installed by default on all major Linux distributions.
- Qualsys has exploited Ubuntu, Debian, Fedora, and CentOS in their tests, and they're sure other distributions are also exploitable.
- Pkexec has been vulnerable since its creation in May 2009 (commit c8c3d83, "Add a pkexec(1) command").
- An unprivileged local user can exploit this vulnerability to get full root privileges.
- Although this vulnerability is technically a memory corruption, it is exploitable instantly and reliably in an architecture-independent way.
- And, last but not least, it's exploitable even if the polkit daemon itself is not running.

Red Hat rates the PwnKit as having a Common Vulnerability Scoring System (CVSS) score of 7.8. This is high. [...] This vulnerability, which has been hiding in plain sight for 12+ years, is a problem with how pkexec reads environmental variables. The short version, according to Qualsys, is: "If our PATH is "PATH=name=.", and if the directory "name=." exists and contains an executable file named "value", then a pointer to the string "name=./value" is written out-of-bounds to envp[0]." While Qualsys won't be releasing a demonstration exploit, the company is sure it won't take long for exploits to be available. Frankly, it's not that hard to create a PwnKit attack.
It's recommended that you obtain and apply a patch ASAP to protect yourself from this vulnerability.

"If no patches are available for your operating system, you can remove the SUID-bit from pkexec as a temporary mitigation," adds ZDNet. "For example, this root-powered shell command will stop attacks: # chmod 0755 /usr/bin/pkexec."
United Kingdom

UK Government Plans To Release Nmap Scripts for Finding Vulnerabilities (therecord.media) 18

The UK government's cyber-security agency plans to release Nmap scripts in order to help system administrators in scanning their networks for unpatched or vulnerable devices. From a report: The new project, titled Scanning Made Easy (SME), will be managed by the UK National Cyber Security Centre (NCSC) and is a joint effort with Industry 100 (i100), a collaboration between the NCSC and the UK private sector. "When a software vulnerability is disclosed, it is often easier to find proof-of-concept code to exploit it, than it is to find tools that will help defend your network," the NCSC said yesterday. "To make matters worse, even when there is a scanning script available, it can be difficult to know if it is safe to run, let alone whether it returns valid scan results."

The NCSC said that the SME project was created to solve this problem by having some of the UK's leading security experts, from both the government and public sector, either create or review scripts that can be used to scan internal networks. Approved scripts will be made available via the NCSC's SME GitHub project page, and the agency said it's also taking submissions from the security community as well. Only scripts for the Nmap network scanning app will be made available through this project, the NCSC said on Monday.

IT

New Logitech Mechanical Keyboards are Conservative in Looks and Price (arstechnica.com) 60

Logitech has introduced two mechanical keyboards to its lineup. Shipping in February, the boards are part of the company's PC gaming brand, but with their $70 starting price and classic, toned-down look, they're also interesting candidates for someone seeking a productivity keyboard with mechanical switches. From a report: The Logitech G G413 SE and G413 TKL SE are $80 and $70, respectively, offering a reasonable entry point for people who might think mechanical keyboards are too expensive. Logitech, specifically its G gaming brand, isn't afraid to overload its keyboards with RGB lighting, but the backlight on these boards comes in white only. The standard G413 is available with an all-white or all-red backlight. A subdued appearance continues with a top case made of aluminum-magnesium alloy with a brushed black finish that matches the black PBT keycaps. The plastic should be an upgrade from the non-SE G413's ABS plastic keyboards, as PBT is generally more resistant to degradation over time. Underneath those keycaps are what Logitech calls "tactile mechanical switches." That phrase suggests something like Cherry MX Browns, but Logitech didn't specify the exact switch used. According to the full-size SE keyboard's product page, the switches actuate at 1.9 mm with 50 g of force and bottom out at 4 mm.
Security

Cracking a $2 Million Crypto Wallet (theverge.com) 66

First, he forgot his PIN -- then he started looking for hackers. From a report: In early 2018, Dan Reich and a friend decided to spend $50,000 in Bitcoin on a batch of Theta tokens, a new cryptocurrency then worth just 21 cents apiece. At first, they held the tokens with an exchange based in China, but within weeks, a broad crackdown on cryptocurrency by the Chinese government meant they would soon lose access to the exchange, so they had to transfer everything to a hardware wallet. Reich and his friend chose a Trezor One hardware wallet, set up a PIN, and then got busy with life and forgot about it. By the end of that year, the token had sunk to less than a quarter of its value, come back up, and then crashed again. Reich decided he wanted to cash out, but his friend had lost the paper where he'd written the PIN and couldn't remember the digits. They tried guessing what they thought was a four-digit PIN (it was actually five), but after each failed attempt, the wallet doubled the wait time before they could guess again. After 16 guesses, the data on the wallet would automatically erase. When they reached a dozen tries, they stopped, afraid to go further. Reich gave up and wrote off the money in his mind. He was willing to take the loss -- until the price started to rise again. From a low of around $12,000, the value of their tokens started to skyrocket. By the end of 2020, it would be worth more than $400,000, rising briefly to over $3 million. It would be hard to get into the wallet without the PIN -- but it wasn't impossible.

And with potentially millions on the line, Reich and his friend vowed to find a way inside. The only way to own cryptocurrency on the blockchain is to have sole possession of a private key associated with a block of currency -- but managing those keys has been a, sometimes high-stakes, challenge from the beginning. [...] The cryptocurrency data firm Chainalysis estimates that more than 3.7 million Bitcoins worth $66.5 billion are likely lost to owners. Currency can be lost for many reasons: the computer or phone storing a software wallet is stolen or crashes and the wallet is unrecoverable; the owner inadvertently throws their hardware wallet away; or the owner forgets their PIN or dies without passing it to family members. As the value of their inaccessible tokens rapidly rose in 2020, Reich and his friend were desperate to crack their wallet. They searched online until they found a 2018 conference talk from three hardware experts who discovered a way to access the key in a Trezor wallet without knowing the PIN. The engineers declined to help them, but it gave Reich hope. "We at least knew that it was possible and had some directional idea of how it could be done," Reich says. Then they found a financier in Switzerland who claimed he had associates in France who could crack the wallet in a lab. But there was a catch: Reich couldn't know their names or go to the lab. He'd have to hand off his wallet to the financier in Switzerland, who would take it to his French associates. It was a crazy idea with a lot of risks, but Reich and his friend were desperate.
Gripping story.
Businesses

eBay Will Now Authenticate Trading Cards Worth $750 or More (techcrunch.com) 16

Online marketplace eBay is once again expanding its authentication service, this time to include support for authenticating valuable trading cards. From a report: The service will now be able to authenticate cards worth at least $750 from collectible card games, as well as sports and other non-sports cards, the company said. By the middle of this year, this service will grow to include graded, autograph and patch cards sold for $250 and higher, as well. These additions broaden eBay's ability to assure its customers of the authenticity of high-value items, including the sneakers, watches and handbags the company is already able to authenticate. Like other verticals where authentication is available, eBay saw the value in adding support for trading cards due to the volume of activity in the category on its site. The company said the trading cards category is growing "significantly faster" than its total marketplace, and the category saw $2 billion in transactions in the first half of 2021. That's equal to all of the trading card transactions that took place in 2020, for comparison.
Security

DHS Warns of Russian Cyberattack On US If It Responds To Ukraine Invasion (go.com) 129

As tensions rise in the standoff over Ukraine, the Department of Homeland Security has warned that the U.S. response to a possible Russian invasion could result in a cyberattack launched against the U.S. by the Russian government or its proxies. ABC News reports: "We assess that Russia would consider initiating a cyber attack against the Homeland if it perceived a US or NATO response to a possible Russian invasion of Ukraine threatened its long-term national security," a DHS Intelligence and Analysis bulletin sent to law enforcement agencies around the country and obtained by ABC News said. The bulletin was dated Jan. 23, 2022.

Russia, DHS said, has a "range of offensive cyber tools that it could employ against US networks," and the attacks could range from a low level denial of service attack, to "destructive" attacks targeting critical infrastructure. "We assess that Russia's threshold for conducting disruptive or destructive cyber attacks in the Homeland probably remains very high and we have not observed Moscow directly employ these types of cyber attacks against US critical infrastructure -- notwithstanding cyber espionage and potential prepositioning operations in the past," the bulletin said.
Last year, Russian cybercriminals launched a ransomware attack on Colonial Pipeline, shutting down operations and causing widespread outages across the country. Meat supplier JBS also had its operations shutdown due to Russian based hackers.
Security

Hacktivists Say They Hacked Belarus Rail System To Stop Russian Military Buildup (arstechnica.com) 71

Hacktivists in Belarus said on Monday they had infected the network of the country's state-run railroad system with ransomware and would provide the decryption key only if Belarus President Alexander Lukashenko stopped aiding Russian troops ahead of a possible invasion of Ukraine. Ars Technica reports: Referring to the Belarus Railway, a group calling itself Cyber Partisans wrote on Telegram: "BelZhD, at the command of the terrorist Lukashenko, these days allows the occupying troops to enter our land. As part of the 'Peklo' cyber campaign, we encrypted the bulk of the servers, databases and workstations of the BelZhD in order to slow down and disrupt the operation of the road. The backups have been destroyed [...]." The group also announced the attack on Twitter.

A representative from the group said in a direct message that the Peklo cyber campaign targets specific entities and government-run companies with the goal of pressuring the Belarus government to release political prisoners and stop Russian troops from entering Belarus to use its ground for the attacks on Ukraine. "The government continues to suppress the free will of Belarusians, imprison innocent people, they continue to unlawfully keep... thousands of political prisoners," the representative wrote. "The major goal is to overthrow Lukashenko's regime, keep the sovereignty and build a democratic state with the rule of law, independent institutions and protection of human rights."

At the time this post went live, several services on the railway's website were unavailable. Online ticket purchases, for instance, weren't working [...]. The representative said that besides ticketing and scheduling being disrupted, the cyberattack also affected freight trains. According to reports, Russia has been sending military equipment and personnel by rail into Belarus, which shares a border with Ukraine. @belzhd_live, a group of Belarus Railway workers that tracks activity on the 5,512-km railway, said on Friday that in a week's time, more than 33 Russian military trains loaded with equipment and troops had arrived in Belarus for joint strategic exercises there. The worker group said at the time that it expected a total of 200 so-called echelons to arrive in the coming days.

Security

New MoonBounce UEFI Bootkit Can't Be Removed by Replacing the Hard Drive (therecord.media) 105

Security researchers from Kaspersky said they have discovered a novel bootkit that can infect a computer's UEFI firmware. From a report: What makes MoonBounce -- the name they gave the bootkit -- special is the fact that the malware doesn't burrow and hide inside a section of the hard drive named ESP (EFI System Partition), where some UEFI code typically resides, but instead it infects the SPI flaws memory that is found on the motherboard. This means that, unlike similar bootkits, defenders can't reinstall the operating system and replace the hard drive, as the bootkit will continue to remain on the infected device until the SPI memory is re-flashed (a very complex process) or the motherboard is replaced. According to Kaspersky, MoonBounce marks the third UEFI bootkit they have seen so far that can infect and live inside the SPI memory, following previous cases such as LoJax and MosaicRegressor. Furthermore, MoonBounce's discovery also comes after researchers have also found additional UEFI bootkits in recent months, such as ESPectre, FinSpy's UEFI bootkit, and others, which has led the Kaspersky team to conclude that what was once considered unachievable following the rollout of the UEFI standard has gradually become the norm.
Security

An OpenSea Bug Let Attackers Snatch NFTs from Owners at Six-figure Discounts (theverge.com) 54

A bug in OpenSea, the popular NFT marketplace, has let hackers buy rare NFTs for well below market value, in some cases leading to hundreds of thousands of dollars in losses for the original owners -- and hundreds of thousands of dollars in profits for the apparent thieves. From a report: The bug appears to have been present for weeks and seems to be referenced in at least one tweet from January 1st, 2022. But exploitation of the bug has picked up significantly in the past day: blockchain analytics company Elliptic reported that in a 12-hour stretch before the morning of January 24th, it was exploited at least eight times to "steal" NFTs with a market value of over $1 million. One of the NFTs, Bored Ape Yacht Club #9991, was purchased using the exploit technique for 0.77 ETH ($1,760) and quickly resold for 84.2 ETH ($192,400), netting the attacker a profit of more than $190,000. An Ethereum address linked to the reseller had received more than 400 ETH ($904,000) in payouts from OpenSea in the same 12-hour period.

"It's a subjective thing whether you consider this to be a loophole or a bug, but the fact is that people are being forced into sales at a price they wouldn't otherwise have accepted right now," said Tom Robinson, chief scientist and co-founder of Elliptic. According to a Twitter thread by software developer Rotem Yakir, the bug is caused by a mismatch between the information available in NFT smart contracts and the information presented by OpenSea's user interface. Essentially, the attackers are taking advantage of old contracts that persist on the blockchain but are no longer present in the view provided by the OpenSea application.

IT

Is the Five-Day Work Week Dying? (msn.com) 137

"The traditional idea of going to the office five days a week or working 9 to 5 may be dying," reports the Washington Post: Zoom, which many workplaces and workers relied on during the pandemic, is starting to allow its more than 6,000 workers to choose whether to work in the office, work remotely, or go hybrid, as in working remotely a certain number of days per week or month at their choosing. Bolt, a San Francisco-based e-commerce start-up boldly introduced a permanent four-day workweek for its nearly 600 employees. Workplace communications platform Slack is reimagining its office primarily as a gathering place for meetings and projects. And tech giants Amazon and Salesforce are allowing their employees to decide as a team when and where they should work, based on the projects at hand.

These approaches come as companies rethink workplace policies amid the fast spread of the omicron variant and the "Great Resignation," during which employers are finding it more difficult to retain talent. U.S. office occupancy dipped to about 28 percent during the third week of January, compared to 40 percent in November before the massive spread of the omicron variant, according to building security company Kastle Systems. Still, some employers see this as an opportunity to rethink the way employees have traditionally worked, opting for even more flexible and creative arrangements that are more likely to lure and retain workers....

Jennifer Christie [Bolt's chief people officer] said after piloting the policy last year, 91 percent of managers and 94 percent of employees wanted to continue. They also reported increased productivity and better work-life balance. Meanwhile, the start-up has been inundated with resumes and emails from people interested in working for the company, Christie said. "People want to be empowered and have autonomy to do work in a way that fits them," Christie said. "That's going to be where talent is attracted...."

The one thing the Kickstarter union workers agree on is the desire for the four-day workweek. "I'd be lying if I said I hadn't listened to some recruiters from places that already implemented a four-day workweek," said Dannel Jurado [a member of Kickstarter United, which is part of the Office and Professional Employees International Union].

Government

In High-Tech San Francisco, a Pilot Program Tries Guaranteed Incomes for Artists (sfgate.com) 116

In 2015 the San Francisco Arts Commission surveyed nearly 600 local artists. "More than 70% of them had either already left San Francisco or were about to be displaced from their work, home or both," reports SFGate.com, adding "The pandemic has only intensified these problems. A report by Americans for the Arts found that 53% of artists have no savings whatsoever as a result of the pandemic."

Would it help to give over 100 artists their own Universal Basic Income? In an effort to mitigate what appears to be an existential threat to the arts, in March 2021, the city of San Francisco partnered with the Yerba Buena Center for the Arts [YBCA] to launch a guaranteed income pilot, called the SF Guaranteed Income Pilot for Artists, or SF-GIPA, that gives 130 local low-income artists who have been severely impacted by the COVID-19 pandemic $1,000 a month, no strings attached, for 18 months.... At the time, YBCA was planning to launch its own guaranteed income project for artists, and this allowed it to combine forces and take both projects further. The first six months of funding for the SF-GIPA project came from the Arts Impact Endowment, which is funded by San Francisco's hotel tax and designated for underserved communities. YBCA extended the project by an additional 12 months with private funding from the Start Small Foundation, a philanthropic initiative by former Twitter CEO Jack Dorsey....

Though the additional income from SF-GIPA is a welcome relief, as the project moves past its halfway point, the question remains: Will 18 months be enough time to truly make a difference in these artists' lives? YBCA is currently scrambling to find a way to continue supporting guaranteed income recipients after the project's scheduled end in October 2023.... "It's just so sad; people come to San Francisco because of the art and culture, but the art and culture makers can't afford to live here," says Stephanie Imah, who is leading YBCA's pilot. "This is very much a rental problem. It's really hard for artists living in San Francisco unless they work in tech. It's clear we need long-term solutions." For YBCA, that means advocating for big policy changes down the line.

"Our eyes are on the federal government," YBCA CEO Deborah Cullinan explains in an interview with Berkeley's Aurora Theatre. "We'd like to see guaranteed income programs across the country for all people." For now, the organization is focused on collecting "university standard research" in order to make an irrefutable case for universal basic income as a viable long-term solution to poverty.

Microsoft

Microsoft Released an Out-of-Band Update to Rollback January Patch's VPN Issues (bleepingcomputer.com) 18

"Microsoft's first Patch Tuesday for 2022 was a rocky start to the year, giving admins and users numerous headaches to deal with..." reports ZDNet. "The Windows Update on January 11 was intended to address 96 security flaws but also brought a load of pain for users and admins."

"One of the major issues that came up during the week for IT admins included finding that Windows Server 2012 became stuck in a boot loop," adds the Verge, "while other versions suffered broken Windows VPN clients, and some hard drives appeared as RAW format (and unusable). Many IT Admins were forced to roll back the updates — leaving many servers vulnerable with none of last week's security patches."

And now for some versions of Windows, this week Microsoft "released emergency out-of-band updates to address multiple issues..." reports BleepingComputer: "This update addresses issues related to VPN connectivity, Windows Server Domain Controllers restarting, Virtual Machines start failure," the company said.... According to admin reports, Windows domain controllers were being plagued by spontaneous reboots, Hyper-V was no longer starting on Windows servers, and Windows Resilient File System (ReFS) volumes were no longer accessible after deploying the January 2022 updates. Windows 10 users and administrators also reported problems with L2TP VPN connections after installing the recent Windows 10 and Windows 11 cumulative updates and seeing "Can't connect to VPN." errors....

[S]ince Microsoft also bundles all the security updates with these Windows cumulative updates, removing them will also remove all fixes for vulnerabilities patched during the January 2022 Patch Tuesday.

While all the updates are available for download on the Microsoft Update Catalog, some of them can also be installed directly through Windows Update, notes Bleeping Computer. But "You will have to manually check for updates if you want to install the emergency fixes through Windows Update because they are optional updates and will not install automatically."

ZDNet adds: As Ask Woody's influential IT admin blogger Susan Bradley recently argued in 2020, Microsoft's decision to roll up patches in a big bundle on the second Tuesday of every month requires admins to place a great deal of trust in the company. That trust is eroded if applying the updates results in a lag on productivity from buggy patches.
Thanks to long-time Slashdot reader waspleg for sharing the story.
Privacy

Supply Chain Attack Used Legitimate WordPress Add-Ons To Backdoor Sites (arstechnica.com) 16

An anonymous reader quotes a report from Ars Technica: Dozens of legitimate WordPress add-ons downloaded from their original sources have been found backdoored through a supply chain attack, researchers said. The backdoor has been found on "quite a few" sites running the open source content management system. The backdoor gave the attackers full administrative control of websites that used at least 93 WordPress plugins and themes downloaded from AccessPress Themes. The backdoor was discovered by security researchers from JetPack, the maker of security software owned by Automatic, provider of the WordPress.com hosting service and a major contributor to the development of WordPress. In all, Jetpack found that 40 AccessPress themes and 53 plugins were affected.

In a post published Thursday, Jetpack researcher Harald Eilertsen said timestamps and other evidence suggested the backdoors were introduced intentionally in a coordinated action after the themes and plugins were released. The affected software was available by download directly from the AccessPress Themes site. The same themes and plugins mirrored on WordPress.org, the official developer site for the WordPress project, remained clean. "Users who used software obtained directly from the AccessPress website unknowingly provided attackers with backdoor access, resulting in an unknown number of compromised websites," Ben Martin, a researcher with Web security firm Sucuri, wrote in a separate analysis of the backdoor.

The Jetpack post said evidence indicates that the supply chain attack on AccessPress Themes was performed in September. Martin, however, said evidence suggests the backdoor itself is much older than that. Some of the infected websites had spam payloads dating back nearly three years. He said his best guess is that the people behind the backdoor were selling access to infected sites to people pushing web spam and malware. He wrote, "[...] it seems that the malware that we've found associated with this backdoor is more of the same: spam, and redirects to malware and scam sites." The Jetpack post provides full names and versions of the infected AccessPress software. Anyone running a WordPress site with this company's offerings should carefully inspect their systems to ensure they're not running a backdoored instance. Site owners may also want to consider installing a website firewall, many of which would have prevented the backdoor from working.

Twitter

Twitter Shakes Up Its Security Team (nytimes.com) 10

Twitter shook up the top ranks of its security team this week with the termination of the head of security and the exit of the chief information security officer, the company told employees on Wednesday, as its new chief executive reorganizes the social media service. From a report: Peiter Zatko, the head of security who is better known within the security community as "Mudge," is no longer at the company, Twitter confirmed. Rinki Sethi, the chief information security officer, will depart in the coming weeks. The changes follow "an assessment of how the organization was being led and the impact on top priority work," according to a memo from Parag Agrawal, Twitter's chief executive, that was sent to employees on Wednesday and obtained by The New York Times. Mr. Agrawal said the "nature of this situation" limited what he was allowed to share with employees.

Mr. Agrawal, who was appointed Twitter's chief executive in November, has shuffled the company's executives since taking over from Jack Dorsey, a founder. In December, Mr. Agrawal reorganized the leadership team and dismissed Dantley Davis, the chief design officer, and Michael Montano, the head of engineering. Mr. Zatko and Ms. Sethi joined Twitter in late 2020. He is a well-known hacker and has had a long career in government and private industry. Before taking on his role at Twitter, he held roles at DARPA, Google and Stripe. He began his cybersecurity career in the 1990s, when he was a member of the hacking group Cult of the Dead Cow. He was recruited to Twitter after teenagers compromised the company's systems in July 2020 and took over the accounts of prominent users.

Privacy

Locations and Contact Data on 515,000 Vulnerable People Stolen in Red Cross Data Breach (techcrunch.com) 23

A cyberattack targeting a contractor working for the International Committee of the Red Cross has spilled confidential data on more than 515,000 "highly vulnerable" people, many of whom have been separated from their families due to conflict, migration and disaster. From a report: The Red Cross did not name the contractor, based in Switzerland, which it uses to store data nor say what led to the security incident, but said that the data comes from at least 60 Red Cross and Red Crescent national societies. In a statement, the international organization pleaded with the attackers not to publicly share or leak the information given the sensitivity of the data.
Security

Red Cross Begs Hackers Not To Leak Data of 'Highly Vulnerable People' (therecord.media) 71

The Red Cross has disclosed that it was the victim of a cyber attack and has asked the hackers who broke into the IT network of one of its contractors not to leak the personal information of more than 515,000 of "highly vulnerable people." The Record reports: The data was stolen from a Red Cross program called Restoring Family Links, which aims to reunite family members separated by conflict, disaster, or migration. "While we don't know who is responsible for this attack, or why they carried it out, we do have this appeal to make to them," said Robert Mardini, director-general for the International Committee of the Red Cross. "Your actions could potentially cause yet more harm and pain to those who have already endured untold suffering. The real people, the real families behind the information you now have are among the world's least powerful. Please do the right thing. Do not share, sell, leak or otherwise use this data," Mardini said.

"The people affected include missing people and their families, unaccompanied or separated children, detainees and other people receiving services from the Red Cross and Red Crescent Movement as a result of armed conflict, natural disasters or migration," the organization said in an email.

Bitcoin

Crypto.com CEO Confirms Hundreds of Accounts Were Hacked (theverge.com) 29

An anonymous reader quotes a report from The Verge: The CEO of cryptocurrency exchange Crypto.com, Kris Marszalek, has finally confirmed that hundreds of user accounts were indeed compromised by hackers and had funds stolen as a result, though details of the exact method of breach remain unclear. Marszalek acknowledged the hack in an online interview with Bloomberg Wednesday, stating that around 400 customer accounts had been compromised. He also told Bloomberg that he had not received any outreach from regulators since the attack was first disclosed but would share information if official inquiries were made.

Previous statements from Marszalek and other communications from Crypto.com have been criticized for being vague and unclear. Official messaging from the company referred to a security "incident," and an early Twitter post mentioned only that a small number of users were "reporting suspicious activity on their accounts." Marszalek followed up by tweeting that "no customer funds were lost" -- a statement some commentators interpreted as meaning that the exchange would take the financial hit rather than passing it on to customers. Shortly afterward, security company PeckShield posted a tweet claiming that, in reality, Crypto.com's losses amounted to around $15 million in ETH and were being sent to Tornado Cash to be "washed."

Slashdot Top Deals