United Kingdom

UK Plans To Invest 5 Billion Pounds In Retaliatory Cyberattacks (bleepingcomputer.com) 57

The United Kingdom has revealed plans to invest 5 billion pounds ($6.8 billion) in bolstering national cybersecurity that includes creating a "Cyber Force" unit to perform retaliatory attacks. BleepingComputer reports: As the UK's Secretary of State for Defense Ben Wallace points out in an interview with The Telegraph, Britain isn't just looking to strengthen its stance against threats, but also to build up its capacity to launch retaliatory assaults. The UK's goal is to strike back on 'tier one' attacks, targeting crucial sectors of hostile states such as Russia, China, and North Korea. As Wallace points out, Britain will be one of the very few countries in the world that will have the capacity to mount offensive cyber-attacks at such a scale, essentially discouraging any future attempts against them. Typical targets could include electric power stations, telecommunication service providers, and various basic infrastructure entities where any service disruption would result in a large-scale impact and notable adverse economical effects.

As Mr. Wallace revealed, some foreign states are waging cyber warfare on Britain on a daily basis, so responding to this aggressively is within the rights that underpin international laws. One of the examples that the official gave during the interview is dismantling servers that are used for ransomware deployment, spyware, or IoT malware. Creating the National Cyber Force center is meant to help keep things this way, acting as a deterrent for those eyeing Britain as a lucrative target candidate. The new digital warfare center will be based out of Samlesbury, Lancashire and jointly run by the Ministry of Defense and the GCHQ. Wallace states that the new division should be fully operational by 2030, with more details revealed by Boris Johnson, UK's Prime Minister, at the upcoming conference of the Conservative Party in Manchester.

Crime

Ukrainian Cops Cuff Two Over $150 Million Ransomware Gang Allegations, Seize $1.3 Million In Cryptocurrency (theregister.com) 8

Ukrainian police have reportedly arrested two members of a ransomware gang -- and while some have fingered REvil, no firm details have been published by cops from multiple countries. The Register reports: A round of speculation was triggered when inter-EU law enforcement body Europol declared this morning that Ukrainian fuzz had arrested "two prolific ransomware operators known for their extortionate demands," claimed to be up to [$81.3 million]. One of the two suspects arrested on September 28, according to the National Police of Ukraine, was a "hacker." The other allegedly "helped to withdraw money obtained by criminal means." $1.3m in cryptocurrency was said to have been frozen. A multinational police operation with input from France's National Gendarmerie and the US Federal Bureau of Investigation helped lead the Ukraine cops to their targets, with support from Europol and Interpol.

The 25-year-old suspect allegedly deployed "virus software," compromising remote-working software, with one attack vector being "through spam-mailings on corporate e-mail boxes of malicious content." "In total, the hacker attacked more than 100 foreign companies in North America and Europe," said the Ukrainian police, adding that they blamed the 25-year-old arrestee for causing $150m of damage to Western organizations. [...] Numerous people speculated on Twitter that the latest Ukrainian arrests were members of the REvil ransomware gang. This was based solely on Europol's claim that the two main accused had once issued an "extortionate" [$81.3 million] ransom demand, which has not been repeated by cops in Ukraine. REvil once issued a ransom demand for $70 millionagainst managed service provider Kaseya) but that is not the same sum...

Facebook

Facebook, Instagram, WhatsApp, and Oculus Have Been Suffering Global Outage For More Than 3 Hours Now [Update] (arstechnica.com) 252

Facebook -- and all the major services that Facebook owns -- are down today. ArsTechnica: We first noticed the problem at about 11:30 am Eastern time, when some Facebook links stopped working. Investigating a bit further showed major DNS failures at Facebook: "Google anycast DNS returns SERVFAIL for Facebook queries; querying http://a.ns.facebook.com directly times out."

The problem goes deeper than Facebook's obvious DNS failures, though. Facebook-owned Instagram was also down, and its DNS services -- which are hosted on Amazon rather than being internal to Facebook's own network -- were functional. Instagram and WhatsApp were reachable but showed HTTP 503 (no server is available for the request) failures instead, an indication that while DNS worked and the services' load balancers were reachable, the application servers that should be feeding the load balancers were not. A bit later, Cloudflare VP Dane Knecht reported that all BGP routes for Facebook had been pulled. With no BGP routes into Facebook's network, Facebook's own DNS servers would be unreachable -- as would the missing application servers for Facebook-owned Instagram, WhatsApp, and Oculus VR.
UPDATE 10/4/2021 22:15 UTC: Facebook is coming back online after a six-hour outage due to DNS routing problems.

"Inside Facebook, the outage broke internal systems as well, leaving employees unable to get into offices and communicate easily with each other," reports The Verge. "Some told The Verge they were using work-provided Outlook email accounts, allowing Facebook workers to email each other but unable to send or receive emails from external addresses."

Not only was it a rough day for Facebook and their stockholders, but it was especially hard on CEO Mark Zuckerberg. According to Bloomberg, Zuckerberg's personal wealth has fallen by more than $6 billion in just a few hours.
Bug

Researcher Refuses Telegram's Bounty Award, Discloses Auto-Delete Bug (arstechnica.com) 6

An anonymous reader quotes a report from Ars Technica: Telegram patched another image self-destruction bug in its app earlier this year. This flaw was a different issue from the one reported in 2019. But the researcher who reported the bug isn't pleased with Telegram's months-long turnaround time -- and an offered $1,159 bounty award in exchange for his silence. In February 2021, Telegram introduced a set of such auto-deletion features in its 2.6 release: Set messages to auto-delete for everyone 24 hours or 7 days after sending; Control auto-delete settings in any of your chats, as well as in groups and channels where you are an admin; and To enable auto-delete, right-click on the chat in the chat list > Clear History > Enable Auto-Delete. But in a few days, mononymous researcher Dmitrii discovered a concerning flaw in how the Telegram Android app had implemented self-destruction.

Messages that should be auto-deleted from participants in private and private group chats were only 'deleted' visually [in the messaging window], but in reality, picture messages remained on the device [in] the cache," the researcher wrote in a roughly translated blog post published last week. Tracked as CVE-2021-41861, the flaw is rather simple. In the Telegram Android app versions 7.5.0 to 7.8.0, self-destructed images remain on the device in the /Storage/Emulated/0/Telegram/Telegram Image directory after approximately two to four uses of the self-destruct feature. But the UI appears to indicate to the user that the media was properly destroyed.

But for a simple bug like this, it wasn't easy to get Telegram's attention, Dmitrii explained. The researcher contacted Telegram in early March. And after a series of emails and text correspondence between the researcher and Telegram spanning months, the company reached out to Dmitrii in September, finally confirming the existence of the bug and collaborating with the researcher during beta testing. For his efforts, Dmitrii was offered a $1,159 bug bounty reward. Since then, the researcher claims he has been ghosted by Telegram, which has given no response and no reward. "I have not received the promised reward from Telegram in [$1,159] or any other," he wrote.

Communications

Company That Routes Billions of Text Messages Quietly Discloses It Was Hacked (vice.com) 33

A company that is a critical part of the global telecommunications infrastructure used by AT&T, T-Mobile, Verizon and several others around the world such as Vodafone and China Mobile, quietly disclosed that hackers were inside its systems for years, impacting more than 200 of its clients and potentially millions of cellphone users worldwide. From a report: The company, Syniverse, revealed in a filing dated September 27 with the U.S. Security and Exchange Commission that an unknown "individual or organization gained unauthorized access to databases within its network on several occasions, and that login information allowing access to or from its Electronic Data Transfer (EDT) environment was compromised for approximately 235 of its customers." A former Syniverse employee who worked on the EDT systems told Motherboard that those systems have information on all types of call records. [...] The company wrote that it discovered the breach in May 2021, but that the hack began in May of 2016.
Security

Millions Experience Browser Problems After Long-Anticipated Expiration of 'Let's Encrypt' Certificate (zdnet.com) 94

"The expiration of a key digital encryption service on Thursday sent major tech companies nationwide scrambling to deal with internet outages that affected millions of online users," reports the Washington Examiner.

The expiring certificate was issued by Let's Encrypt — though ZDNet notes there's been lots of warnings about its pending expiration: Digital Shadows senior cyber threat analyst Sean Nikkel told ZDNet that Let's Encrypt put everyone on notice back in May about the expiration of the Root CA Thursday and offered alternatives and workarounds to ensure that devices would not be affected during the changeover. They have also kept a running forum thread open on this issue with fairly quick responses, Nikkel added.
Thursday night the Washington Examiner describes what happened when the big day arrived: Tech giants — such as Amazon, Google, Microsoft, and Cisco, as well as many smaller tech companies — were still battling with an endless array of issues by the end of the night... At least 2 million people have seen an error message on their phones, computers, or smart gadgets in the past 24 hours detailing some internet connectivity problems due to the certificate issue, according to Scott Helme, an internet security researcher and well-known cybersecurity expert. "So many people have been affected, even if it's only the inconvenience of not being able to visit certain websites or some of their apps not working," Helme said.

"This issue has been going on for many hours, and some companies are only just getting around to fixing it, even big companies with a lot of resources. It's clearly not going smoothly," he added.

There was an expectation before the certificate expired, Helme said, that the problem would be limited to gadgets and devices bought before 2017 that use the Let's Encrypt digital certificate and haven't updated their software. However, many users faced issues on Thursday despite having the most cutting-edge devices and software on hand. Dozens of major tech products and services have been significantly affected by the certificate expiration, such as cloud computing services for Amazon, Google, and Microsoft; IT and cloud security services for Cisco; sellers unable to log in on Shopify; games on RocketLeague; and workflows on Monday.com.

Security researcher Scott Helme also told ZDNet he'd also confirmed issues at many other companies, including Guardian Firewall, Auth0, QuickBooks, and Heroku — but there might be many more beyond that: "For the affected companies, it's not like everything is down, but they're certainly having service issues and have incidents open with staff working to resolve. In many ways, I've been talking about this for over a year since it last happened, but it's a difficult problem to identify. it's like looking for something that could cause a fire: it's really obvious when you can see the smoke...!"

Digital certificates expert Tim Callan added that the popularity of DevOps-friendly architectures like containerization, virtualization and cloud has greatly increased the number of certificates the enterprise needs while radically decreasing their average lifespan. "That means many more expiration events, much more administration time required, and greatly increased risk of a failed renewal," he said.

Security

Neiman Marcus Discloses a 2020 Data Breach That Impacted 4.6 Million Customers (arstechnica.com) 11

"American luxury retailer Neiman Marcus Group has just disclosed a major data breach impacting approximately 4.6 million customers," reports Ars Technica.

"The breach occurred sometime in May 2020 after 'an unauthorized party' obtained the personal information of some Neiman Marcus customers from their online accounts." Neiman Marcus is working with law enforcement agencies and has selected cybersecurity company Mandiant to assist with the investigation. Thursday, Neiman Marcus disclosed that its 2020 data breach impacted about 4.6 million customers with Neiman Marcus online accounts. The personal information of these customers was potentially compromised during the incident. The bits of information include:

- Names, addresses, contact information

- Usernames and passwords of Neiman Marcus online accounts

- Payment card numbers and expiration dates (although no CVV numbers)

- Neiman Marcus virtual gift card numbers (without PINs)

- Security questions of Neiman Marcus online accounts

"Although the data breach occurred over a year ago, Neiman Marcus states it became aware of the incident this September."
Security

Hackers Bypass Coinbase 2FA To Steal Customer Funds (therecord.media) 13

An anonymous reader quotes a report from The Record: More than 6,000 Coinbase users had funds stolen from their accounts after hackers used a vulnerability in Coinbase's SMS-based two-factor authentication system to breach accounts. The intrusions took place earlier this year, between March and May, the exchange said in a data breach notification letter it has filed with US state attorney general offices. Coinbase said the attacks could exploit this bug only if they knew the victim's username and password. "While we are not able to determine conclusively how these third parties gained access to this information, this type of campaign typically involves phishing attacks or other social engineering techniques to trick a victim into unknowingly disclosing login credentials to a bad actor. "We have not found any evidence that these third parties obtained this information from Coinbase itself," the company said. Coinbase said it would reimburse all users who lost funds in these intrusions.
Microsoft

Microsoft Announces Office 2021 Features and Pricing (theverge.com) 102

Microsoft is launching Office 2021 on October 5th, and the company is finally detailing the features and pricing today. From a report: Office 2021 will be the next standalone version of Microsoft's Office suite, designed for businesses and consumers who want to avoid the subscription version of Office. Office Home and Student 2021 will be priced at $149.99 and include Word, Excel, PowerPoint, OneNote, and Microsoft Teams for PC and Mac. Office Home and Business 2021 is priced at $249.99 and will include everything in the Home version and Outlook for PC and Mac, alongside the rights to use all of the Office apps for business purposes. Office 2021 will include the collaboration features found in Microsoft 365 versions of Office, with real-time co-authoring, OneDrive support, and even Microsoft Teams integration. Office 2021 will also include the new Office design that has a refreshed ribbon interface, rounded corners, and a neutral color palette that all matches the UI changes in Windows 11.
Privacy

Former OnlyFans Employees Could Access Users' and Models' Personal Information (vice.com) 18

samleecole shares a report from Motherboard: Some former OnlyFans support staff employees still had access to users' data -- including sensitive financial and personal information -- even after they stopped working for the company used by sex workers to sell nudes and porn videos. According to a former OnlyFans employee who asked to remain anonymous because they feared retaliation, some ex-employees still had access to Zendesk, a popular customer service software used by many companies including OnlyFans, to track and respond to customer support tickets, long after leaving the company. OnlyFans uses Zendesk to respond to both users who post content and those who just pay to view that content. According to the source and OnlyFans users who spoke to Motherboard, depending on what a user is seeking help with, support tickets may contain their credit card information, drivers' licenses, passports, full names, addresses, bank statements, how much they have earned on OnlyFans or spent, Know Your Customer (KYC) selfies where the creator holds up an ID next to their face for verification, and model release forms. "It's a shame that they have this large company and feel they can play with people's lives like this," the former employee said. "There are already so many things they are in trouble for and privacy should not be one of them. Everyone on that platform, especially sex workers, need to have their information be safe and it isn't."
Security

Apple Pay With Visa Hacked To Make Payments Via Unlocked iPhones (threatpost.com) 48

Researchers have demonstrated that someone could use a stolen, unlocked iPhone to pay for thousands of dollars of goods or services, no authentication needed. Threatpost reports: An attacker who steals a locked iPhone can use a stored Visa card to make contactless payments worth up to thousands of dollars without unlocking the phone, researchers are warning. The problem is due to unpatched vulnerabilities in both the Apple Pay and Visa systems, according to an academic team from the Universities of Birmingham and Surrey, backed by the U.K.'s National Cyber Security Centre (NCSC). But Visa, for its part, said that Apple Pay payments are secure and that any real-world attacks would be difficult to carry out.

The team explained that fraudulent tap-and-go payments at card readers can be made using any iPhone that has a Visa card set up in "Express Transit" mode. Express Transit allows commuters around the world, including those riding the New York City subway, the Chicago El and the London Underground, to tap their phones on a reader to pay their fares without unlocking their devices. "An attacker only needs a stolen, powered-on iPhone," according to a writeup (PDF) published this week. "The transactions could also be relayed from an iPhone inside someone's bag, without their knowledge. The attacker needs no assistance from the merchant."

This attack is made possible by a combination of flaws in both Apple Pay and Visa's systems, the academic team noted. "The details of this vulnerability have been disclosed to Apple (Oct 2020) and to Visa (May 2021)," according to the writeup. "Both parties acknowledge the seriousness of the vulnerability, but have not come to an agreement on which party should implement a fix." "Variations of contactless-fraud schemes have been studied in laboratory settings for more than a decade and have proven to be impractical to execute at scale in the real world," Visa said in a statement to the BBC, adding that its fraud-detection systems would flag any suspicious transactions. Apple meanwhile shifted the responsibility to Visa and told the outlet, "We take any threat to users' security very seriously. This is a concern with a Visa system, but Visa does not believe this kind of fraud is likely to take place in the real world given the multiple layers of security in place. In the unlikely event that an unauthorized payment does occur, Visa has made it clear that their cardholders are protected by Visa's zero-liability policy."
The researchers say users can protect themselves by not using Visa as a transport card in Apple Pay, and if they do, by remotely wiping the device if lost or stolen. The bug does not affect other types of payment cards or payment systems.
Security

Telegram Bots Are Trying To Steal Your One-time Passwords (zdnet.com) 12

Telegram-powered bots are being utilized to steal the one-time passwords required in two-factor authentication (2FA) security. From a report: The ransomware threat is growing: What needs to happen to stop attacks getting worse? On Wednesday, researchers from Intel 471 said that they have seen an "uptick" in the number of these services provided in the web's underground, and over the past few months, it appears the variety of 2FA circumvention solutions is expanding -- with bots becoming a firm favorite. [...] While 2FA can improve upon the use of passwords alone to protect our accounts, threat actors were quick to develop methods to intercept OTP, such as through malware or social engineering. According to Intel 471, since June, a number of 2FA-circumventing services are abusing the Telegram messaging service. Telegram is either being used to create and manage bots or as a 'customer support' channel host for cybercriminals running these types of operations. "In these support channels, users often share their success while using the bot, often walking away with thousands of dollars from victim accounts," the researchers say.
IT

New USB-C Logos Make Picking USB Cables, Chargers Less Confusing (pcworld.com) 87

Choosing the correct USB-C charger and cable for you laptop is about as fun as visiting the dentist, but new logos released today should go a long way toward making easier. PCWorld: The USB Implementers Forum group that oversees the USB standard has released logos that easily indicate whether a cable or charger can hit the new 240 watt rating. Previous USB-C chargers and cables were rated to hit 65 watts or 100 watts but a new version of USB Power Delivery released this May has pushed the limit to an impressive 240 watts. Obviously, that means if you're looking for a 240 watt aftermarket charger for a new gaming laptop that supports it, you want one. With the new USB-C logos, all you have to do is look for a Certified USB Charger 240W logo with a lightning bolt like the one from the chart above. The other component you may need is a 240 watt USB-C cable, so consumers need only look for Certified USB Charger 240W with a cable in its logo. Both logos also can also be paired with USB 40Gbps bits to indicate if the cable is certified to support USB4's 40Gbps speed.

The higher output 240 watt power range is a welcome addition to USB-C as it should allow laptop makers to bringing universal USB-C charging to far more powerful laptops, including gaming laptops with discrete graphics chips -- something that was out of reach of the previous USB-C chargers, cables, and ports. In fact, we found that we probably wouldn't want to use a small USB-C charger in a gaming laptop with today's technology. With 240 watt USB-C charger, we'd probably change our mind. The problem, of course, is that the USB-IF is an organization that certifies cables, chargers, and USB-C brick a brats, but it's not mandatory. This has lead to small brand and no-name manufacturers getting the spec wrong in the past. The good news is the cables from companies that actually obtain certifications correctly should work correctly.

Security

Chinese Espionage Group Deploys New Rootkit Compatible With Windows 10 Systems (therecord.media) 18

At the SAS 2021 security conference today, analysts from security firm Kaspersky Lab published details about a new Chinese cyber-espionage group that has been targeting high-profile entities across South East Asia since at least July 2020. From a report: Named GhostEmperor, Kaspersky said the group uses highly sophisticated tools and is often focused on gaining and keeping long-term access to its victims through the use of a powerful rootkit that can even work on the latest versions of Windows 10 operating systems. "We observed that the underlying actor managed to remain under the radar for months," Kaspersky researchers explained today. The entry point for GhostEmperor's hacks were public-facing servers. Kaspersky believes the group used exploits for Apache, Oracle, and Microsoft Exchange servers to breach a target's perimeter network and then pivoted to more sensitive systems inside the victim's network.
Security

Anonymous: We've Leaked Disk Images Stolen From Web Host Epik (theregister.com) 107

slack_justyb writes: As previously reported the web host Epik was hacked by a group identifying themselves with the group Anonymous. However, in the most recent leaks from this group the scale of data that was stolen is becoming apparent, and signs point to a wholesale theft of data with no stone left unturned.

We're told the dump is a 70GB archive of files and "several bootable disk images of assorted systems" that represent Epik's server infrastructure. Journalist Steve Monacelli, who broke the news of the first data release, said the latest leak expands to 300GB. "This leak appears to be fully bootable disk images of Epik servers, including a wide range of passwords and API tokens," he added.

WhiskeyNeon, a Texas-based hacker and cybersecurity expert who reviewed the file structure of the leak, told the Daily Dot how the disk images represented Epik's entire server infrastructure. "Files are one thing, but a virtual machine disk image allows you to boot up the company's entire server on your own," he said. "We usually see breaches with database dumps, documents, configuration files, etc. In this case, we are talking about the entire server image, with all the programs and files required to host the application it is serving."

Daily Dot brings some word on Epik CEO Rob Monster response to the latest news:

Epik CEO Rob Monster, who did not respond to requests for comment from the Daily Dot, would go on to hold a more than four hour long live video conference online to address the initial hack. The meeting would see Monster break out into prayer numerous times, make attempts to vanquish demons, and warn viewers that their hard drives could burst into flames due to "curses" placed on the hacked data.


IOS

iOS 15 Messages Bug Causes Saved Photos to Be Deleted (macrumors.com) 37

A serious bug in the iOS 15 Messages app can cause some saved photos to be deleted, according to multiple complaints reported by MacRumors readers and Twitter users. From the report: If you save a photo from a Messages thread and then go on to delete that thread, the next time an iCloud Backup is performed, the photo will disappear. Even though the image is saved to your personal iCloud Photo Library, it appears to still be linked to the Messages app in "iOS 15," and saving it does not persist through the deletion of the thread and an "iCloud" backup. This is a concern because most users keep the "iCloud" Backup feature enabled and it's something that happens automatically. If you're someone who regularly deletes message threads, if there's a photo that you want to keep, you won't be able to keep it with "iCloud" Backup turned on.

To replicate this bug, the following steps must be taken:
1. Save a photo from a Messages conversation to your Camera Roll.
2. Check to see that the photo has been saved.
3. Delete the Messages conversation the photo came from. The photo will still be in your "iCloud Photo Library" at this point.
4. Perform an "iCloud" Backup, and the photo disappears.

Android

New GriftHorse Malware Infects More Than 10 Million Android Phones (therecord.media) 30

Security researchers have found a massive malware operation that has infected more than 10 million Android smartphones across more than 70 countries since at least November 2020 and is making millions of dollars for its operators on a monthly basis. The Record reports: Discovered by mobile security firm Zimperium, the new GriftHorse malware has been distributed via benign-looking apps uploaded on the official Google Play Store and on third-party Android app stores. If users install any of these malicious apps, GriftHorse starts peppering users with popups and notifications that offer various prizes and special offers. Users who tap on these notifications are redirected to an online page where they are asked to confirm their phone number in order to access the offer. But, in reality, users are subscribing themselves to premium SMS services that charge over $35 per month, money that are later redirected into the GriftHorse operators' pockets.

Zimperium researchers Aazim Yaswant & Nipun Gupta, who have been tracking the GriftHorse malware for months, described it as "one of the most widespread campaigns the zLabs threat research team has witnessed in 2021." Based on what they've seen until now, the researchers estimated that the GriftHorse gang is currently making between $1.5 million to $4 million per month from their scheme.

Security

Apple AirTag Bug Enables 'Good Samaritan' Attack (krebsonsecurity.com) 29

An anonymous reader quotes a report from Krebs On Security: The new $30 AirTag tracking device from Apple has a feature that allows anyone who finds one of these tiny location beacons to scan it with a mobile phone and discover its owner's phone number if the AirTag has been set to lost mode. But according to new research, this same feature can be abused to redirect the Good Samaritan to an iCloud phishing page -- or to any other malicious website. The AirTag's "Lost Mode" lets users alert Apple when an AirTag is missing. Setting it to Lost Mode generates a unique URL at https://found.apple.com/ and allows the user to enter a personal message and contact phone number. Anyone who finds the AirTag and scans it with an Apple or Android phone will immediately see that unique Apple URL with the owner's message.

When scanned, an AirTag in Lost Mode will present a short message asking the finder to call the owner at at their specified phone number. This information pops up without asking the finder to log in or provide any personal information. But your average Good Samaritan might not know this. That's important because Apple's Lost Mode doesn't currently stop users from injecting arbitrary computer code into its phone number field -- such as code that causes the Good Samaritan's device to visit a phony Apple iCloud login page. The vulnerability was discovered and reported to Apple by Bobby Rauch, a security consultant and penetration tester based in Boston. Rauch told KrebsOnSecurity the AirTag weakness makes the devices cheap and possibly very effective physical trojan horses.

China

German IT Security Watchdog Examines Xiaomi Mobile Phone (reuters.com) 16

Germany's federal cybersecurity watchdog, the BSI, is conducting a technical examination of a mobile phone manufactured by China's Xiaomi, a spokesperson for the interior ministry told Reuters on Wednesday. From the report: The spokesperson did not provide further details on what kind of examination the agency was carrying out. Lithanua's state cybersecurity body said last week that Xiaomi phones had a built-in ability to detect and censor terms such as "Free Tibet," "Long live Taiwan independence" or "democracy movement." Xiaomi said on Monday it was engaging a third-party expert to assess the allegations by Lithuania that its smartphones carry built-in censorship capabilities.
Security

Russian Authorities Arrest Cybersecurity Giant Group-IB's CEO on Treason Charges (techcrunch.com) 30

Russian authorities have arrested and detained Ilya Sachkov, the co-founder and chief executive of Group-IB -- one of the biggest cybersecurity companies in the country -- on charges of treason. From a report: Details about Sachkov's detention remain unclear but it was reported by Russian media as authorities searched the company's offices, reports Reuters. State news agency Tass said Sachkov, who was arrested on Tuesday, was charged with allegedly transferring classified information to an unnamed foreign government, claims that Sachkov denied, according to the report. Group-IB confirmed the arrest of its CEO, but a spokesperson for Group-IB did not comment beyond a statement on the company's website, which said the company is examining the Moscow court's decision and that it is "confident" in Sachkov's innocence. Sachkov, 35, founded Group-IB in 2003. The company, now headquartered in Singapore, helps companies and governments investigate cyberattacks and online fraud, and has customers ranging from Interpol to Russian banks and defense companies.

Slashdot Top Deals