Businesses

US Committee Is Reviewing Zoom's $14.7 Billion Deal For Five9 On National-Security Grounds (cnbc.com) 11

A U.S. government committee is reviewing Zoom's agreement to acquire cloud contact center software company Five9 for $14.7 billion on national-security grounds. CNBC reports: According to a letter dated Aug. 27, the Federal Communications Commission was asked to refer the case to the Committee for the Assessment of Foreign Participation in the United States Telecommunications Service Sector. Attorney General Merrick Garland is chair of the committee. Zoom announced the deal with Five9 in July, marking the video-chat company's first billion-dollar-plus acquisition. Zoom ballooned in value during the pandemic and, with Five9's technology, is trying to expand into adjacent markets.

Zoom is based in San Jose, California, and founder and CEO Eric Yuan, a native of China, is a U.S. citizen. The company has a significant research and development hub in China, and last year House Speaker Nancy Pelosi of California referred to Zoom as "a Chinese entity" during an MSNBC interview. "USDOJ believes that such risk may be raised by the foreign participation (including the foreign relationships and ownership) associated with the application, and a review by the Committee is necessary to assess and make an appropriate recommendation as to how the Commission should adjudicate this application," David Plotinsky of the Justice Department wrote in the letter to the FCC.
Zoom still expects the acquisition to close in the first half of 2022, a company spokesperson told CNBC in an email. "We have made filings with the various applicable regulatory agencies, and these approval processes are proceeding as expected," the representative said.
Security

FBI Held Back Ransomware Decryption Key From Businesses To Run Operation Targeting Hackers (washingtonpost.com) 45

An anonymous reader quotes a report from The Washington Post: The FBI refrained for almost three weeks from helping to unlock the computers of hundreds of businesses and institutions hobbled by a major ransomware attack this summer, even though the bureau had secretly obtained the digital key needed to do so, according to several current and former U.S. officials. The key was obtained through access to the servers of the Russia-based criminal gang behind the July attack. Deploying it immediately could have helped the victims, including schools and hospitals, avoid what analysts estimate was millions of dollars in recovery costs. But the FBI held on to the key, with the agreement of other agencies, in part because it was planning to carry out an operation to disrupt the hackers, a group known as REvil, and the bureau did not want to tip them off. Also, a government assessment found the harm was not as severe as initially feared. The planned takedown never occurred because in mid-July REvil's platform went offline -- without U.S. government intervention -- and the hackers disappeared before the FBI had a chance to execute its plan, according to the current and former officials. The previously unreported episode highlights the trade-offs law enforcement officials face between trying to damage cyber criminal networks and promptly helping the victims of ransomware -- malware that encrypts data on computers, rendering them unusable.
Security

Crypto Channels Targeted in Biden's Fight Against Ransomware (bloomberg.com) 19

The Biden administration plans a fresh campaign against ransomware attacks through sanctions to cut off criminals' cryptocurrency pipelines, and it urged companies to report extortion attempts and better protect themselves from them. From a report: Deputy Treasury Secretary Wally Adeyemo told reporters that the sanctions would be imposed on Suex, a cryptocurrency transferring service that's registered in the Czech Republic. He said Suex had "facilitated transactions involving illicit proceeds for at least eight ransomware variants. He said "exchanges like Suex are critical to attackers' ability to extract profits," pointing out that this was the first such action by the Office of Foreign Assets Control against a virtual currency exchange. Both Adeyemo and Deputy National Security Adviser Anne Neuberger, who also briefed reporters in a conference call on Monday evening, underscored the importance of ransomware victims coming forward and vulnerable businesses and organizations taking steps to bolster their security. Adeyemo announced new Treasury Department guidance that makes "an express statement that the U.S. government strongly discourages the payment of cyber ransoms or extortion demands."
Iphone

Researcher Discloses iPhone Lock Screen Bypass on iOS 15 Launch Day (therecord.media) 25

On the day Apple released iOS 15, a Spanish security researcher disclosed an iPhone lock screen bypass that can be exploited to grant attackers access to a user's notes. From a report: In an interview with The Record, Jose Rodriguez said he published details about the lock screen bypass after Apple downplayed similar lock screen bypass issues he reported to the company earlier this year. "Apple values reports of issues like this with up to $25,000 but for reporting a more serious issue, I was awarded with $5,000," the researcher wrote on Twitter last week. [...] Because of the unprofessional way Apple handled his bug report, the researcher published today a variation of the same bypass, but this time one that uses the Apple Siri and VoiceOver services to access the Notes app from behind the screen lock. Further reading: Apple Pays Hackers Six Figures To Find Bugs in Its Software. Then It Sits On their Findings.
Microsoft

The Pandemic Made Our Workweeks Longer (axios.com) 48

The average American's workweek has gotten 10% longer during the pandemic, according to a new Microsoft study published in Nature Human Behaviour. From a report: These longer hours are a key part of the pandemic-induced crisis of burnout at U.S. firms -- and workers are quitting in droves. Microsoft calculated the length of the workday based on the time between Teams users' first email, message or work call and their last. So the longer workweeks don't necessarily mean we're working more, the study says. People may be spending more time logged on because they are distracted with other obligations while working from home and so are less productive. This contributes to burnout because the lines between work life and home life are increasingly blurred, experts say. Further reading: Study of 61,000 Microsoft Employees Finds Remote Work Threatened Productivity and Innovation.
Security

BlackMatter Hits Grain Cooperative With Ransomware Attack (bloomberg.com) 25

Iowa-based grain cooperative New Cooperative was struck by ransomware in recent days and has shut down its computer systems as it tries to mitigate the attack. From a report: The attack occurred on or around Friday, according to Allan Liska, senior threat analyst at the cybersecurity firm Recorded Future. The ransomware gang, which goes by the name BlackMatter, is demanding a $5.9 million ransom, Liska said. New Cooperative confirmed that they had been attacked and said they had contacted law enforcement and were working with data security experts to investigate and remediate the situation.

"New Cooperative recently identified a cybersecurity incident that is impacting some of our company's devices and systems," according to a statement from the cooperative. "Out of an abundance of caution, we have proactively taken our systems offline to contain the threat, and we can confirm it has been successfully contained." New Cooperative has communicated with its feed customers and is working to create workarounds to get feed to animals while its systems are down, a person familiar with the matter said.

Security

Alaska Discloses 'Sophisticated' Nation-State Cyberattack on Health Service (therecord.media) 11

A nation-state cyber-espionage group has gained access to the IT network of the Alaska Department of Health and Social Service (DHSS), the agency said last week. From a report: The attack, which is still being investigated, was discovered on May 2, earlier this year, by a security firm, which notified the agency. While the DHSS made the incident public on May 18 and published two updates in June and August, the agency did not reveal any details about the intrusion until last week, when it officially dispelled the rumor that this was a ransomware attack. Instead, the agency described the intruders as a "nation-state sponsored attacker" and "a highly sophisticated group known to conduct complex cyberattacks against organizations that include state governments and health care entities."
Data Storage

What's the Best Ransomware Backup Solution: Disk or Tape? (esecurityplanet.com) 165

Slashdot reader storagedude writes: With the release of LTO-9, just about every tape vendor has pushed its wares as a solution to the ransomware problem. After all, is there any backup technology that's more air-gapped?

Tape IS great for backup — just not so much for recovery. Writing for eSecurity Planet, [CTO of Seagate Government Solutions] Henry Newman notes that not only is disk about 80% cheaper than LTO tape, but even an entry-level RAID card can restore data 6 times faster than tape. "Backup is not about backing up the data, but the time it takes to restore that data to meet your business requirements," writes Newman. "Tape drives are not striped, but disks generally are put into stripe groups," he writes. "With RAID controllers and/or software RAID methods, you can easily get many 10s of GB/sec of bandwidth to restore data from a single set of SAS connections. Doing that with tape is very expensive and requires architectural planning. So the bottom line is you can surely backup to tape and it is cost effective – for backup, that is. If you actually need to restore that data quickly, you have my best wishes."

Tape may have a better bit error rate than disk, but disk can be architected in a way that removes that reliability advantage, he notes. "Tape vendors often state that the BER (bit error rate) of tape is far better than disk, which is 100% true, but you can make up for tape's advantage with RAID methods that check the reliability of your data and ensure that what you wrote is what you read. This has been the case with RAID since the early 1990s, with parity check on read to validate the data. With other ANSI standard techniques – which sadly are not used often enough – such as T10 PI/DIX you can achieve data integrity on a single device equal to or greater than tape. The net-net here is disk is far faster than tape, as there is native striping that has been in use at least since the 1980s with RAID methods, and disk can achieve equal data integrity to tape."

"The most often overlooked part of data backup is the recovery part – the longer it takes to restore your data, the more damage it can do to your business," Newman writes. He concludes: "Yes, tape can be air gapped but so can disk. Does tape provide better protection against ransomware? Likely, but is it so much slower than disk that you can turn off your system and turn on when you need to. Does having slower restoration make tape a better defense against a ransomware attack? As far as I can see, the marketing claims made by tape vendors do not hold up to a rigorous engineering analysis. If you want to use tape, that is your choice and there might be good reasons, but disk-based backups can be air gapped just like tape, for lower cost and with a much faster recovery time. Why tape vendors are making claims such as this, I will leave it to readers to speculate."

But Slashdot reader BAReFO0t takes the "tape" side of the argument. "Being slower does not equal it not working as a solution at all," they argue in a comment on the original submission — adding "Also, it's not even slower, since tape can just as easily be made into a RAID. You can flood ANY bus if you just use enough mirrors, no matter the medium."

And a follow-up comment also defended tapes. "If tape meets the service level agreement and provides a reasonable risk mitigation from ransomware, then it's still a perfectly viable solution regardless of certain performance limitations. LTO development would have likely died long ago otherwise."

But what do other Slashdot readers think? Share your own experiences and opinions in the comments. What offers a better ransomware backup solution: disk or tape?
Earth

Global Computing's Carbon Footprint Is Bigger Than Previously Estimated (upi.com) 41

An anonymous reader quotes a report from UPI: According to a new study, published Friday in the journal Patterns, information and communications technology, or ICT for short, is responsible for a greater share of greenhouse gas emissions than previously estimated.

When researchers at Lancaster University analyzed earlier attempts to calculate ICT's carbon footprint, they determined scientists had failed to account for the entire life-cycle and supply chain of ICT products and infrastructure.

This would include, for example, the emissions produced by makers of ICT components, or the emissions linked with the disposal of ICT products.

Scientists have previously pegged ICT's share of greenhouse gas emissions at between 1.8% and 2.8%. But the latest findings suggest global computing is more likely responsible for between 2.1% and 3.9% of greenhouse gas emissions.

If the latest estimates are accurate, ICT would have a larger carbon footprint than the aviation industry, which is responsible for 2 percent of greenhouse gas emissions.

Security

Web Host Epik Was Warned of a Critical Security Flaw Weeks Before it Was Hacked (techcrunch.com) 31

An anonymous reader shares a report: Hackers associated with the hacktivist collective Anonymous say they have leaked gigabytes of data from Epik, a web host and domain registrar that provides services to far-right sites like Gab, Parler and 8chan, which found refuge in Epik after they were booted from mainstream platforms. In a statement attached to a torrent file of the dumped data this week, the group said the 180 gigabytes amounts to a "decade's worth" of company data, including "all that's needed to trace actual ownership and management" of the company. The group claimed to have customer payment histories, domain purchases and transfers, and passwords, credentials and employee mailboxes. The cache of stolen data also contains files from the company's internal web servers, and databases that contain customer records for domains that are registered with Epik.

The hackers did not say how they obtained the breached data or when the hack took place, but timestamps on the most recent files suggest the hack likely happened in late February. Epik initially told reporters it was unaware of a breach, but an email sent out by founder and chief executive Robert Monster on Wednesday alerted users to an "alleged security incident." TechCrunch has since learned that Epik was warned of a critical security flaw weeks before its breach. Security researcher Corben Leo contacted Epik's chief executive Monster over LinkedIn in January about a security vulnerability on the web host's website. Leo asked if the company had a bug bounty or a way to report the vulnerability. LinkedIn showed Monster had read the message but did not respond.

Security

A US Company Sold iPhone Hacking Tools To UAE Spies (technologyreview.com) 19

An American cybersecurity company was behind a 2016 iPhone hack sold to a group of mercenaries and used by the United Arab Emirates. From a report: When the United Arab Emirates paid over $1.3 million for a powerful and stealthy iPhone hacking tool in 2016, the monarchy's spies -- and the American mercenary hackers they hired -- put it to immediate use. The tool exploited a flaw in Apple's iMessage app to enable hackers to completely take over a victim's iPhone. It was used against hundreds of targets in a vast campaign of surveillance and espionage whose victims included geopolitical rivals, dissidents, and human rights activists.

Documents filed by the US Justice Department on Tuesday detail how the sale was facilitated by a group of American mercenaries working for Abu Dhabi, without legal permission from Washington to do so. But the case documents do not reveal who sold the powerful iPhone exploit to the Emiratis. Two sources with knowledge of the matter have confirmed to MIT Technology Review that the exploit was developed and sold by an American firm named Accuvant. It merged several years ago with another security firm, and what remains is now part of a larger company called Optiv. News of the sale sheds new light on the exploit industry as well as the role played by American companies and mercenaries in the proliferation of powerful hacking capabilities around the world.

Power

Solar Power Could Become a Catalyst For a Major Synthetic Fuel Upgrade (interestingengineering.com) 144

An anonymous reader quotes a report from InterestingEngineering: As global carbon emissions that stem from fossil fuels keep adding to our ever-growing climate change issue, energy companies have turned their focus on renewables to generate fuel. One of those companies is Synhelion from Switzerland. The company harnesses the energy of the heat of the sun and converts the collected carbon dioxide into synthetic fuels, in turn offering a green and sustainable solution. The system is quite genius. Synhelion uses a mirror field filled with heliostats to reflect the radiation of solar power. The radiation is then concentrated in the solar receiver and turned into clean, high-temperature process heat at around 2.732F (1.500C). Next, the produced heat is turned into a CO2 and H2O mixture in a thermochemical reactor. The end product, the syngas, is then turned into gasoline, diesel, or jet fuel with a gas-to-liquid technology process. What makes this sustainable is the fact that the company's thermal energy storage (TES) saves the excess heat after each process which keeps the operation going 24/7.

And how does the solar receiver work? The company says the technology is inspired by nature. To reach ultra-high temperatures, the solar receiver mimics Earth's greenhouse gas effect. The chamber is filled with greenhouse gases that are usually water vapor or water and CO2 mixtures. After solar radiation collected with heliostats enters the chamber, the black surface of the chamber absorbs the heat, thermalizes, and re-radiates it. The greenhouse gas then absorbs the thermal radiation, acting as a heat transfer fluid (HTF), which can, later on, be turned into any type of liquid fuel. And liquid fuels are easy to transport which makes them low-cost compared to their solid counterparts. When there's no sun, the HTF flows through the TES in the opposite direction to recover the previously stored thermal energy. The hot HTF from the storage drives the thermochemical processes in the reactor that keeps the operation working.
"The company states that through this technology, it can provide fuels at a cheaper price with a 50 to 100 percent lower carbon footprint compared to fossil fuels," the report adds. "In addition to Synhelion's aligned motives with the Paris Agreement's CO2 reduction targets, it is supported by larger industries looking to cut their emissions -- and eventually achieve net-zero -- by 2030."
Security

Free REvil Ransomware Master Decrypter Released For Past Victims (bleepingcomputer.com) 7

A free master decryptor for the REvil ransomware operation has been released, allowing all victims encrypted before the gang disappeared to recover their files for free. BleepingComputer reports: The REvil master decryptor was created by cybersecurity firm Bitdefender in collaboration with a trusted law enforcement partner. While Bitdefender could not share details about how they obtained the master decryption key or the law enforcement agency involved, they told BleepingComputer that it works for all REvil victims encrypted before July 13th. "As per our blog post, we received the keys from a trusted law enforcement partner, and unfortunately, this is the only information we are at liberty to disclose right now," Bitdefender's Bogdan Botezatu, Director of Threat Research and Reporting, told BleepingComputer. "Once the investigation progresses and will come to an end, further details will be offered upon approval." REvil ransomware victims can download the master decryptor from Bitdefender (instructions) and decrypt entire computers at once or specify specific folders to decrypt.
Microsoft

New Microsoft Office Arrives Early Next Month, and Won't Require You To Pay For a Subscription (cnet.com) 97

Microsoft's new, flat-price version of its Office productivity software will arrive on Oct. 5 -- the same day Windows 11 begins rolling out, according to a company blog post Thursday. From a report: Microsoft previously emphasized that while its main focus remains in its subscription offering, Microsoft 365, it will release the one-time purchase Office 2021 for those who aren't ready to move to the cloud. Office 2021 arrives in two versions: one for commercial users, called Office LTSC (which stands for Long Term Servicing Channel), and one for personal use. Office LTSC is generally available today, the post said, and includes enhanced accessibility features, performance improvements across Word, Excel and PowerPoint, and visual improvements, like dark mode support across apps. It's meant for specialty situations, as opposed to for an entire organization, such as process control devices on the manufacturing floor that are not connected to the internet. Meanwhile, Office 2021 for personal use will arrive on Oct. 5, though Microsoft has not yet announced pricing information.
Google

Alphabet's Project Taara Laser Tech Beamed 700TB of Data Across Nearly 5km (theverge.com) 34

An anonymous reader shares a report: In January, Google's parent company, Alphabet, shut down Project Loon, an initiative exploring using stratospheric helium balloons to distribute wireless internet (an attempt to use solar-powered drones folded in 2017). However, some technology developed as a part of the Loon project remained in development, specifically the Free Space Optical Communications (FSOC) links that were originally meant to connect the high flying balloons -- and now that technology is actively in use providing a high-speed broadband link for people in Africa.

Sort of like fiber optic cables without the cable, FSOC can create a 20Gbps+ broadband link from two points that have a clear line of sight, and Alphabet's moonshot lab X has built up Project Taara to give it a shot. They started by setting up links in India a few years ago as well as a few pilots in Kenya, and today X revealed what it has achieved by using its wireless optical link to connect service across the Congo River from Brazzaville in the Republic of Congo and Kinshasa in the Democratic Republic of Congo. In 20 days, Project Taara lead Baris Erkmen says the link transmitted nearly 700TB of data, augmenting fiber connections used by local telecom partner Econet and its subsidiaries.

Encryption

Ransomware Encrypts South Africa's Entire Department of Justice Network (bleepingcomputer.com) 59

The justice ministry of the South African government is working on restoring its operations after a recent ransomware attack encrypted all its systems, making all electronic services unavailable both internally and to the public. As a consequence of the attack, the Department of Justice and Constitutional Development said that child maintenance payments are now on hold until systems are back online. BleepingComputer reports: The incident happened on September 6 and the department activated the contingency plan for such events to ensure the continuation of some activity in the country. Last week, [Steve Mahlangu, spokesperson for the Department of Justice and Constitutional Development] said that court sittings continued after a switch into manual mode for recording the hearings. A manual process has also been adopted for issuing various legal documents. However, the ransomware attack impacted monthly child maintenance payments, which have been delayed until the systems are restored.

The department is still in the process of returning to regular operations but it is cannot say when the activity will become normal again. Part of this effort was setting up a new email system, to which some staff has already migrated. Coupled with the long time needed for network restoration, this is a sign that the hackers did not get paid. It is unclear who is behind this attack. Many ransomware gangs also steal data before encrypting it, to force the victim into paying the ransom under the pressure of a public leak. Mahlangu said last week that the Department's IT experts have found "no indication of data compromise." Until now, the attack has not been claimed by any of the gangs with a data leak site.

Open Source

Travis CI Flaw Exposed Secrets of Thousands of Open Source Projects (arstechnica.com) 28

An anonymous reader quotes a report from Ars Technica: Travis CI is a popular software-testing tool due to its seamless integration with GitHub and Bitbucket. As the makers of the tool explain: "When you run a build, Travis CI clones your GitHub repository into a brand-new virtual environment and carries out a series of tasks to build and test your code. If one or more of those tasks fail, the build is considered broken. If none of the tasks fail, the build is considered passed and Travis CI can deploy your code to a web server or application host." But this month, researcher Felix Lange found a security vulnerability that caused Travis CI to include secure environment variables of all public open source repositories that use Travis CI into pull request builds. Environment variables can include sensitive secrets like signing keys, access credentials, and API tokens. If these variables are exposed, attackers can abuse the secrets to obtain lateral movement into the networks of thousands of organizations.

Tracked as CVE-2021-41077, the bug is present in Travis CI's activation process and impacts certain builds created between September 3 and September 10. As a part of this activation process, developers are supposed to add a ".travis.yml" file to their open source project repository. This file tells Travis CI what to do and may contain encrypted secrets. Another place encrypted secrets may be defined is Travis' web UI. But, these secrets are not meant to be exposed. In fact, Travis CI's docs have always stated, "Encrypted environment variables are not available to pull requests from forks due to the security risk of exposing such information to unknown code." Ideally, Travis is expected to run in a manner that prevents public access to any secret environment variables specified. [...] This vulnerability caused these sorts of secrets to be unexpectedly exposed to just about anyone forking a public repository and printing files during a build process. Fortunately, the issue didn't last too long -- around eight days, thanks to Lange and other researchers who notified the company of the bug on September 7. But out of caution, all projects relying on Travis CI are advised to rotate their secrets.

The presence and relatively quick patching of the flaw aside, Travis CI's concise security bulletin and overall handling of the coordinated disclosure process has infuriated the developer community. In a long Twitter thread, Peter Szilagyi details the arduous process that his group endured as it waited for Travis CI to take action and release a brief security bulletin on an obscure webpage. "After 3 days of pressure from multiple projects, [Travis CI] silently patched the issue on the 10th. No analysis, no security report, no post mortem, not warning any of their users that their secrets might have been stolen," tweeted Szilagyi. After Szilagyi and Lange asked GitHub to ban Travis CI over its poor security posture and vulnerability disclosure processes, an advisory showed up. "Finally, after multiple ultimatums from multiple projects, [they] posted this lame-ass post hidden deep where nobody will read it... Not even a single 'thank you.' [No] acknowledgment of responsible disclosure. Not even admitting the gravity of it all," said Szilagyi, while referring to the security bulletin -- and especially its abridged version, which included barely any details. Szilagyi was joined by several members of the community in criticizing the bulletin. Boston-based web developer Jake Jarvis called the disclosure an "insanely embarrassing 'security bulletin.'"
"Travis CI implemented a series of security patches starting on Sept 3rd that resolves this issue," concluded Mendy on behalf of the Travis CI team. "As a reminder, cycling your secrets is something that all users should do on a regular basis. If you are unsure how to do this, please contact Support."
Security

ExpressVPN Knew 'Key Facts' of Executive Who Worked For UAE Spy Unit (vice.com) 11

An anonymous reader quotes a report from Motherboard: ExpressVPN, a popular VPN company, said it was aware of the "key facts" of its chief information officer Daniel Gericke's previous employment before hiring him. On Wednesday, the Department of Justice disclosed in court records that Gericke worked on Project Raven, a surveillance operation for the United Arab Emirates government that involved hacking of Americans, activists, and heads of state. "We've known the key facts relating to Daniel's employment history since before we hired him, as he disclosed them proactively and transparently with us from the start. In fact, it was his history and expertise that made him an invaluable hire for our mission to protect users' privacy and security," ExpressVPN told Motherboard in a statement. "Daniel has a deep understanding of the tools and techniques used by the adversaries we aim to protect users against, and as such is a uniquely qualified expert to advise on defense against such threats. Our product and infrastructure have already benefited from that understanding in better securing user data," the statement continued.

On Tuesday, unsealed court filings described how Gericke as well as Marc Baier and Ryan Adams faced charges for their part in working on Project Raven. The court records say that the three violated the International Traffic in Arms Regulations and conspired to commit access device fraud and computer hacking offenses. The court records say that the three took a zero-click exploit, which allows takeover of a device without any user interaction, and implemented that into Karma, the hacking system used by the UAE's Project Raven. Project Raven involved the hiring of former U.S. intelligence hackers who then worked on behalf of the UAE government, Reuters reported in 2019. The court records also describe other uses and purchases of exploits by the group. The court filings detailed that prosecutors will drop the charges if the three men cooperate with U.S. authorities, pay a financial penalty, and agree to a list of unspecified restrictions on their employment.
Earlier this week, ExpressVPN was sold to Kape Technologies in a deal worth $936 million.
Security

Emergency Software Patches Are on the Rise (nbcnews.com) 43

Emergency software patches, in which users are pushed to immediately update phones and computers because hackers have figured out some novel way to break in, are becoming more common. From a report: Researchers raised the alarm Monday about a big one: The Israeli spyware company NSO Group, which sells programs for governments to remotely take over people's smartphones and computers, had figured out a new way into practically any Apple device by sending a fake GIF through iMessage. The only way to guard against it is to install Apple's emergency software update. Such emergency vulnerabilities are called "zero days" -- a reference to the fact that they're such an urgent vulnerability in a program that software engineers have zero days to write a patch for it. Against a hacker with the right zero day, there is nothing consumers can do other than wait for software updates or ditch devices altogether.

Once considered highly valuable cyberweapons held mostly by elite government hackers, publicly disclosed zero-day exploits are on a sharp rise. Project Zero, a Google team devoted to identifying and cataloging zero days, has tallied 44 this year alone where hackers had likely discovered them before researchers did. That's already a sharp rise from last year, which saw 25. The number has increased every year since 2018. Katie Moussouris, founder and CEO of Luta Security, a company that connects cybersecurity researchers and companies with vulnerabilities, said that the rise in zero days is thanks to the ad hoc way that software is usually programmed, which often treats security as an afterthought. "It was absolutely inevitable," she said. "We've never addressed the root cause of all of these vulnerabilities, which is not building security in from the ground up." But almost paradoxically, the rise in zero days reflects an online world in which certain individuals are more vulnerable, but most are actually safer from hackers.

Microsoft

Amazon Loss of Executive To Microsoft Sets Up Potential Clash (bloomberg.com) 19

Microsoft said it has hired a former Amazon cloud executive to run its cybersecurity operations, potentially setting in motion a legal battle between the two tech giants. From a report: Charlie Bell, who long reported to former Amazon Web Services chief Andy Jassy and oversaw the engineering teams working on AWS's main software services, will become an executive vice president reporting to Microsoft Chief Executive Officer Satya Nadella. "Cybersecurity is one of the most challenging issues of our time -- for every person and organization on the planet -- and it is core to our mission," Nadella wrote in an email to employees obtained by Bloomberg. Securing customers' digital technology platforms, devices, and clouds "is a bold ambition we are going after and is what attracted Charlie to Microsoft."

[...] Bell's departure to a direct rival is a major blow for Amazon, and Microsoft said it's committed to continuing "constructive discussions" with the cloud leader about Bell's role. "We're sensitive to the importance of working through these issues together, as we've done when five recent Microsoft executives moved across town to work for Amazon," Microsoft said in a statement. Amazon, which has a history of seeking to enforce non-compete agreements vigorously, didn't immediately comment on the move. Bell will officially start his role once "a resolution is reached with his former employer," Nadella wrote in the email.

Slashdot Top Deals