Bitcoin

Cryptomining Botnet Alters CPU Settings To Boost Mining Performance (tomshardware.com) 21

Uptycs Threat Research Team has discovered malware that not only hijacks vulnerable *nix-based servers and uses them to mine cryptocurrency but actually modifies their CPU configurations in a bid to increase mining performance at the cost of performance in other applications. Tom's Hardware reports: Perpetrators use a Golang-based worm to exploit known vulnerabilities like CVE-2020-14882 (Oracle WebLogic) and CVE-2017-11610 (Supervisord) to gain access to Linux systems, reports The Record. Once they hijack a machine, they use model-specific registers (MSR) to disable the hardware prefetcher, a unit that fetches data and instructions from the memory into the L2 cache before they are needed.

Prefetching has been used for years and can boost performance in various tasks. However, disabling it can increase mining performance in XMRig, the mining software the perpetrators use, by 15%. But disabling the hardware prefetcher lowers performance in legitimate applications. In turn, server operators either have to buy additional machines to meet their performance requirements or increase power limits for existing hardware. In either case, they increase power consumption and spend additional money. The botnet has been reportedly used since at least December 2020 and targeted vulnerabilities in MySQL, Tomcat, Oracle WebLogic, and Jenkins.

Businesses

These People Who Work From Home Have a Secret: They Have Two Jobs (wsj.com) 168

When the pandemic freed employees from having to report to the office, some saw an opportunity to double their salary on the sly. From a report: They were bored. Or worried about layoffs. Or tired of working hard for a meager raise every year. They got another job offer. Now they have a secret. A small, dedicated group of white-collar workers, in industries from tech to banking to insurance, say they have found a way to double their pay: Work two full-time remote jobs, don't tell anyone and, for the most part, don't do too much work, either. Alone in their home offices, they toggle between two laptops. They play "Tetris" with their calendars, trying to dodge endless meetings. Sometimes they log on to two meetings at once. They use paid time off -- in some cases, unlimited -- to juggle the occasional big project or ramp up at a new gig. Many say they don't work more than 40 hours a week for both jobs combined. They don't apologize for taking advantage of a system they feel has taken advantage of them.

[...] Gig work and outsourcing have been on the rise for years. Inflation is now ticking up, chipping away at spending power. Some employees in white-collar fields wonder why they should bother spending time building a career. "The harder that you work, it seems like the less you get," one of the workers with two jobs says. "People depend on you more. My paycheck is the same." Overemployed says it has a solution. "There's no implied lifetime employment anymore, not even at IBM," writes one of the website's co-founders, a 38-year-old who works for two tech companies in the San Francisco Bay Area. The site serves up tips on setting low expectations with bosses, staying visible at meetings and keeping LinkedIn profiles free of red flags. (A "social-media cleanse" is a solid excuse for an outdated LinkedIn profile, it says.) In a chat on the messaging platform Discord, people from around the world swap advice about employment checks and downtime at various brand-name companies.

Google

Activist Raided By London Police After Downloading Docs Found On Google Search (theregister.com) 139

A man who viewed documents online for a controversial London property development and shared them on social media was raided by police after developers claimed there had been a break-in to their systems. The Register reports: The raid by four Metropolitan Police constables took place after Southwark campaigner Robert Hutchinson was reportedly accused of illegally entering a password-protected area of a website. "I was searching in Google and found links to board meeting minutes," he told The Register. "Board reports, none of which were marked confidential. So I have no question that it was in the public domain." The Southwark News reported that Hutchinson was arrested at 8.20am on 10 June this year at home following allegations made by Leathermarket Community Benefit Society (CBS). The society is a property development firm that wants to build flats over a children's caged ball court in the south London borough, something Hutchinson "vocally opposes," according to the local paper.

"There's a directory, which you need to enter a password and a username to get into. But documents from that area were being published on Google," explained Hutchinson. "I didn't see a page saying 'this is the directors' area' or anything like that, the documents were just available. They were just linked directly." Police said in a statement that Hutchinson was arrested on suspicion of breaking section 1 of Britain's Computer Misuse Act 1990 "between the 17th and 24th February 2021 and had published documents from the website on social media." They added: "He was taken into custody and later released under investigation. Following a review of all available evidence, it was determined no offences had been committed and no further action was taken."

Hutchinson said his identification by Leathermarket and subsequent arrest raised questions in his mind, saying police confirmed to him that the company had handed over an access log containing IP addresses: "Now, how that ended up with me being in the frame, I don't know. There's part of this that doesn't add up..." While the property business did not respond to The Register's request for comment at the time of publication, in a statement given to the Southwark News it said: "When it came to the CBS's attention that confidential information had been accessed and subsequently shared via Twitter, the CBS made a general report of the data breach to the police â" who requested a full log of visitor access to the website before deciding whether or not to progress. The police carried out their own independent investigation into who accessed the documents and how, and have now concluded their investigation." The prepared police statement did not explain whether investigators tested Leathermarket CBS's version of events before arresting the campaigner.

Encryption

Apple's Child Protection Features Spark Concern Within Its Own Ranks (reuters.com) 99

According to an exclusive report from Reuters, Apple's move to scan U.S. customer phones and computers for child sex abuse images has resulted in employees speaking out internally, "a notable turn in a company famed for its secretive culture." From the report: Apple employees have flooded an Apple internal Slack channel with more than 800 messages on the plan announced a week ago, workers who asked not to be identified told Reuters. Many expressed worries that the feature could be exploited by repressive governments looking to find other material for censorship or arrests, according to workers who saw the days-long thread. Past security changes at Apple have also prompted concern among employees, but the volume and duration of the new debate is surprising, the workers said. Some posters worried that Apple is damaging its leading reputation for protecting privacy.

In the Slack thread devoted to the photo-scanning feature, some employees have pushed back against criticism, while others said Slack wasn't the proper forum for such discussions. Core security employees did not appear to be major complainants in the posts, and some of them said that they thought Apple's solution was a reasonable response to pressure to crack down on illegal material. Other employees said they hoped that the scanning is a step toward fully encrypting iCloud for customers who want it, which would reverse Apple's direction on the issue a second time.
Apple has said it will refuse requests from governments to use the system to check phones for anything other than illegal child sexual abuse material.
Security

Accenture Downplays Ransomware Attack as LockBit Gang Leaks Corporate Data (therecord.media) 15

Fortune 500 company Accenture has fell victim to a ransomware attack but said today the incident did not impact its operations and has already restored affected systems from backups. From a report: News of the attack became public earlier this morning when the company's name was listed on the dark web blog of the LockBit ransomware cartel. The LockBit gang claimed it gained access to the company's network and was preparing to leak files stolen from Accenture's servers at 17:30:00 GMT. In an emailed statement, Accenture not only confirmed the attack but also greatly played down its impact. But while Accenture said the incident was quickly contained, this didn't stop the hackers from threatening to leak files they stole from the company's internal network.
Windows

Windows 11 is Getting Updated Snipping Tool, Calculator, and Mail Apps (theverge.com) 51

Microsoft is improving some of the built-in apps available in Windows 11. From a report: Windows Insiders in the Dev Channel can now test new updates to the Snipping Tool, Calculator, Mail, and Calendar apps. Some of the updates are minor, but all are designed to match the new visual style in Windows 11. Microsoft is replacing the classic Snipping Tool and Snip & Sketch apps in Windows 11 with a new Snipping Tool app that combines the best features of both apps. The Win + Shift + S keyboard shortcut will be the main way to take a screenshot in Windows 11, and it will activate the snipping menu with various options for selecting what content to screenshot.
Privacy

Amazon To Monitor Customer Service Workers' Keyboard and Mouse Strokes (vice.com) 57

Amazon plans to monitor the keyboard strokes and mouse movements of customer service employees in an attempt to stop rogue workers, imposters, or hackers accessing customers' data, according to a confidential Amazon document obtained by Motherboard. The document also includes several concrete instances where people managed to steal Amazon customer data. From the report: Although the document says Amazon has considered deploying a solution that captures all of a worker's keystrokes, the tool the company has seemingly leaned towards buying is not designed to record exactly what workers type or monitor their communications. Instead, the system generates a profile based on the employee's natural keyboard and mouse movements, and then continuously verifies whether it seems the same person is in control of the worker's account to catch hackers or imposters who may then steal data. The move highlights the sorts of tools companies may increasingly deploy as working from home or remotely continues during the ongoing pandemic, and the issues Amazon is already facing with the theft of customer data.
Businesses

NortonLifeLock and Avast PLC To Merge In $8.4 Billion Transaction (zdnet.com) 19

Antivirus vendor NortonLifeLock this afternoon said it will merge with Britain's Avast PLC in a transaction combining cash and stock in two different options, totaling between $8.1 billion and $8.6 billion in stock. ZDNet reports: That value is roughly equivalent to the value in U.S. dollars of Avast's enterprise value, which takes into account its cash and debt, of 6.5 billion pounds, based on the closing price of Avast stock Tuesday of 5.68 pounds on the London Stock Exchange. The two companies said in the joint press release that their respective boards of directors see an opportunity to "create a new, industry-leading consumer Cyber Safety business, leveraging the established brands, technology and innovation of both groups to deliver substantial benefits to consumers, shareholders, and other stakeholders."

The two companies said the deal will bring together product lines that are broadly complementary, while giving the combined company a user base of over half a billion customers. The deal will broaden the geographic market coverage of the combined company. In addition, the two expect to realize "$280 million of annual gross cost synergies." Under terms of the deal, "Avast shareholders will be entitled to receive a combination of cash consideration and newly issued shares in NortonLifeLock with alternative consideration elections available."

IT

Passwords Aren't Just a Problem For Adults (cnet.com) 76

Though you might assume children are the most tech-savvy generation out there, it turns out there's an area where they're just as behind as adults: passwords. From a report: National Institute of Standards and Technology released research on Wednesday showing that even though kids are taught best practices for creating passwords, they're not following them. NIST surveyed more than 1,500 children, ages 8 to 18, and found that, for example, 87% of high schoolers use the same password for everything. Depending on age group (45% of high schoolers versus 23% of elementary school kids), many share passwords with friends. Researchers suggested that those surveyed don't see password sharing as risky behavior, but rather a matter of building friendships and trust. "The end goal of this research is to better support children and provide recommendations that can be used to provide guidance to them, parents and educators," NIST researcher Yee-Yin Choong said in a statement.
Bitcoin

Hackers Return Nearly Half of the $600 Million they Stole in One of the Biggest Crypto Heists (cnbc.com) 58

Hackers have returned nearly half of the $600 million they stole in what's likely to be one of the biggest cryptocurrency thefts ever. From a report: The cybercriminals exploited a vulnerability in Poly Network, a platform that looks to connect different blockchains so that they can work together. Poly Network disclosed the attack Tuesday and asked to establish communication with the hackers, urging them to "return the hacked assets."

A blockchain is a ledger of activities upon which various cryptocurrencies are based. Each digital coin has its own blockchain and they're different from each other. Poly Network claims to be able to make these various blockchains work with each other. Poly Network is a decentralized finance platform. DeFi is a broad term encompassing financial applications based on blockchain technology that looks to cut out intermediaries -- such as brokerages and exchanges. Hence, it's dubbed decentralized. Proponents say this can make financial applications such as lending or borrowing more efficient and cheaper. "The amount of money you hacked is the biggest in defi history," Poly Network said in a tweet. In a strange turn of events Wednesday, the hackers began returning some of the funds they stole. They sent a message to Poly Network embedded in a cryptocurrency transaction saying they were "ready to return" the funds. The DeFi platform responded requesting the money be sent to three crypto addresses. As of 7 a.m. London time, more than $4.8 million had been returned to the Poly Network addresses. By 11 a.m. ET, about $258 million had been sent back.

Facebook

Facebook Engineers Develop New Open Source Time Keeping Appliance (techcrunch.com) 99

Ron Miller, writing for TechCrunch: Most people probably don't realize just how much our devices are time driven, whether it's your phone, your laptop or a network server. For the most part, time keeping has been an esoteric chore, taken care of by a limited number of hardware manufacturers. While these devices served their purpose, a couple of Facebook engineers decided there had to be a better way. So they built a new more accurate time keeping device that fits on a PCI Express (PCIe) card, and contributed it to the Open Compute Project as an open source project. At a basic level, says Olag Obleukhov, a production engineer at Facebook, it's simply pinging this time-keeping server to make sure each device is reporting the same time.

"Almost every single electronic device today uses NTP -- Network Time Synchronization Protocol -- which you have on your phone, on your watch, on your laptop, everywhere, and they all connect to these NTP servers where they just go and say, 'what time is it's and the NTP server provides the time," he explained. Before Facebook developed a new way of doing this, there were basically two ways to check the time. If you were a developer, you probably used something like Facebook.com as a time checking mechanism, but a company like Facebook, working at massive scale, needed something that worked even when there wasn't an internet connection.

Companies running data centers have a hardware device called Stratum One, which is a big box that sits in the data center, and has no other job than acting as the time keeper. Because these time-keeping boxes were built by a handful of companies over years, they were solid and worked, but it was hard to get new features. What's more, companies like Facebook couldn't control the boxes because of their proprietary nature. Obleukhov and his colleague research scientist, Ahmad Byagowi began to attack the problem by looking for a way to create these devices by building a PCIe card with off-the-shelf parts that you could stick into any PC with an open slot.

AI

Researchers Create 'Master Faces' To Bypass Facial Recognition (vice.com) 38

An anonymous reader quotes a report from Motherboard: Researchers have demonstrated a method to create "master faces," computer generated faces that act like master keys for facial recognition systems, and can impersonate several identities with what the researchers claim is a high probability of success. In their paper (PDF), researchers at the Blavatnik School of Computer Science and the School of Electrical Engineering in Tel Aviv detail how they successfully created nine "master key" faces that are able to impersonate almost half the faces in a dataset of three leading face recognition systems. The researchers say their results show these master faces can successfully impersonate over 40 percent of the population in these systems without any additional information or data of the person they are identifying.

The researchers tested their methods against three deep face recognition systems -- Dlib, FaceNet, and SphereFace. Lead author Ron Shmelkin told Motherboard that they used these systems because they are capable of recognizing "high-level semantic features" of the faces that are more sophisticated than just skin color or lighting effects. The researchers used a StyleGAN to generate the faces and then used an evolutionary algorithm and neural network to optimize and predict their success. The evolutionary strategy then creates iterations, or generations, of candidates of varying success rates. The researchers then used the algorithm to train a neural network, to classify the best candidates as the most promising ones. This is what teaches it to predict candidates' success and, in turn, direct the algorithm to generate better candidates with a higher probability of passing. The researchers even predict that their master faces could be animated using deepfake technology to bypass liveness detection, which is used to determine whether a biometric sample is real or fake.

Microsoft

Microsoft To Require Admin Rights Before Using Windows Point and Print Feature (therecord.media) 53

Microsoft has released today a security update that will change the default behavior of the "Point and Print" feature to mitigate a severe security issue disclosed last month. From a report: First added in Windows 2000, the Point and Print feature works by connecting to a print server to download and install necessary print drivers every time a user creates a connection to a remote printer without providing installation media. Earlier this year, Jacob Baines, a reverse engineer for Dark Wolf Solutions, found that threat actors inside a company's network could abuse the Point and Print feature to run a malicious print server and force Windows systems to download and install malicious drivers.

Since Point and Print ran with SYSTEM privileges, the feature effectively provided threat actors with an easy way to gain admin rights inside any large corporate or government network. Microsoft initially tried to patch the issue -- tracked as CVE-2021-34481 -- last month, but the patches were deemed incomplete. Today, the company took another approach. Since the vulnerability is exploiting a design flaw, Microsoft chose today to change the default behavior of the Point and Print feature.

Security

Cross-Chain DeFi Site Poly Network Hacked; Hundreds of Millions Potentially Lost (coindesk.com) 85

Cross-chain decentralized finance (DeFi) platform Poly Network was attacked on Tuesday, with the alleged hacker draining roughly $600 million in crypto. From a report: Poly Network, a protocol launched by the founder of Chinese blockchain project Neo, operates on the Binance Smart Chain, Ethereum and Polygon blockchains. Tuesday's attack struck each chain consecutively, with the Poly team identifying three addresses where stolen assets were transferred. At the time that Poly tweeted news of the attack, the three addresses collectively held more than $600 million in different cryptocurrencies, including USDC, wrapped bitcoin (WBTC), wrapped ether (WETH) and shiba inu (SHIB), blockchain scanning platforms show.

"We call on miners of affected blockchain and crypto exchanges to blacklist tokens coming from the above addresses," the Poly team tweeted. The $600 million figure would place the Poly Network hack among the largest in crypto history. Tether froze approximately $33 million in relation to the hack, Tether CTO Paul Adroino tweeted. About one hour after Poly announced the hack on Twitter, the hacker tried to move assets including USDT through the Ethereum address into liquidity pool Curve.fi, records show. The transaction was rejected.

Firefox

Firefox 91 Pushes Privacy With Stronger New Cookie-clearing Option (cnet.com) 35

WIth the release of Firefox 91 on Tuesday, Mozilla has introduced a bigger hammer for smashing the cookies that websites, advertisers and tracking companies can use to record your online behavior. From a report: The new feature, called enhanced cookie clearing, is designed to block tracking not just from a website, but also from third parties whose code appears on the site. The technology is designed to let you clear cookies for a particular website but also the more aggressive "supercookies" designed to evade lesser privacy protections. The feature is an option if you enable Firefox's strict mode for cookie handling, which partitions website data into separate storage containers. "You can easily recognize and remove all data a website has stored on your computer, without having to worry about leftover data from third parties embedded in that website," Mozilla said in a blog post.
Security

DEF CON: Security Holes In Deere, Case IH Shine Spotlight On Agriculture Cyber Risk (securityledger.com) 48

chicksdaddy shares a report from The Security Ledger: A lot has changed in the agriculture sector in the last decade. And farm country's cybersecurity bill has come due in a big way. A (virtual) presentation at the annual DEF CON hacking conference in Las Vegas on Sunday described a host of serious, remotely exploitable holes in software and services by U.S. agricultural equipment giants John Deere and Case IH, The Security Ledger reports. Together, the security flaws and misconfigurations could have given nation-state hackers access to Deere's global product infrastructure, sensitive customer and third-party data and, potentially, the ability to remotely access critical farm equipment like planters and harvesters that are the lynchpin of the U.S. food chain.

The talk is the most detailed presentation, to date, of a range of flaws in Deere software and services that were first identified and disclosed to the company in April. The disclosure of two of those flaws in the company's public-facing web applications set off a scramble by Deere and other agricultural equipment makers to patch the flaws, unveil a bug bounty program and to hire cyber security and embedded device security talent.

In addition to a slew of common web flaws like Cross Site Scripting- and account enumeration bugs linked to Deere's web site and public APIs, the researchers discovered a vulnerability (CVE-2021-27653) in third-party software by Pega Systems, a maker of customer relationship management (CRM) software that Deere uses. A misconfiguration of that software gave the researchers administrative access to the remote, back end Pegasystems server. With wide ranging, administrative access to the production backend Pega server, the researchers were able to obtain other administrative Pegasystems credentials including passwords, security audit logs, as well as John Deere's OKTA signing certificate for the Pegasystems server, according to the presentation. In an email statement to The Security Ledger, a John Deere spokesperson said that "none of the claims -- including those identified at DEF CON -- have enabled access to customer accounts, agronomic data, dealer accounts, or sensitive personal information," though data included in the presentation as well as prior public disclosures make clear that sensitive data on Deere employees, equipment, customers and suppliers was exposed.

IT

Why CAPTCHA Pictures Are So Unbearably Depressing (medium.com) 115

Clive Thompson: I hate doing Google's CAPTCHAs. Part of it is the sheer hassle of repeatedly identifying objects -- traffic lights, staircases, palm trees and buses -- just so I can finish a web search. I also don't like being forced to donate free labor to AI companies to help train their visual-recognition systems. But a while ago, while numbly clicking on grainy images of fire hydrants, I was struck by another reason: The images are deeply, overwhelmingly depressing.

CAPTCHA images are never joyful vistas of human activity, full of Whitmanesque vigor. No, they're blurry, anonymous landscapes that possess a positively Soviet anomie. I think I've figured it out, and so now I present -- The Six Reasons CAPTCHA Pictures Make You Feel Like Crap:

1. They're devoid of humans.
2. The angles are all wrong.
3. They're voyeuristic.
4. They look like crime-scene footage.
5. The grids on the photos are an alien's-eye view of the world.
6. There's very little nature.

Security

Google Drops Bluetooth Titan Security Keys In Favor of NFC Versions (bleepingcomputer.com) 19

Google is discontinuing the Bluetooth Titan Security Key to focus on security keys with Near Field Communication (NFC) functionality. As part of this move, Google has also announced a new Titan Security Key with USB-C and NFC to go along with the previously available USB-A + NFC security key. Bleeping Computer reports: Google's Titan Security Keys were introduced in 2018 and are designed to help users prevent Google account takeover attempts using credentials stolen in data breaches or following phishing attacks. They work with the most popular devices, browsers, and an increasing number of apps that come with FIDO standard support.

"Since NFC functionality is now supported by a wide range of Android phones and iPhones, we are discontinuing the Bluetooth Titan Security Key and focusing on the easier and more widely available NFC capability," said Christiaan Brand, Google Cloud Product Manager. "However, for existing users with our Bluetooth Titan Security Keys, these will continue to work with Bluetooth and will continue to work as an NFC key on most modern mobile devices." The company will also continue to service existing Bluetooth Titan Security Keys until they are out of warranty.

IT

When Amazon Customers Leave Negative Reviews, Some Sellers Hunt Them Down (wsj.com) 130

Ever wonder how cheap, no-name products on Amazon can amass hundreds, sometimes thousands, of nearly perfect star ratings, with just a handful of negative reviews? From a report: Here's one way: Some sellers are reaching out to unhappy buyers to revise or delete their negative reviews, in exchange for refunds or gift cards. With fewer disgruntled shoppers, the overall average star rating rises. Sellers who ship products via Amazon aren't supposed to reach out to customers outside of Amazon's official channel -- in fact, it's a violation of the terms they agree to on the retail platform. In March, New Yorker Katherine Scott picked out an oil spray bottle for cooking, based on nearly 1,000 glowing Amazon reviews of the product, which had a 4.5-star rating average. When the $10 sprayer arrived, she found the item didn't work as advertised: Instead of a mist, it produced a stream of oil, she said. She left a negative review.

A week later, Ms. Scott received an email from someone claiming to be from the customer-service team of the oil sprayer's brand, Auxtun -- correspondence which I have reviewed. "We are willing to refund in full," the representative wrote. "We hope you can reconsider deleting comments at your convenience okay?" The message concluded, "When we do not receive a response, we will assume that you did not see it, and will continue to send emails." The seller shouldn't have had her email address. Sellers who fulfill orders themselves do receive customer names and mailing addresses. But for orders that Amazon itself fulfills, customer data is supposed to be shielded from sellers and brands.

Sellers are permitted to communicate with buyers through Amazon's built-in messaging platform, which hides the customer's email address. Amazon's terms of service also prohibit sellers from requesting that a customer remove a negative review or post a positive one. "We do not share customer email addresses with third-party sellers," an Amazon spokesman told me. Meanwhile, brands, which can be distinct from sellers, may reach out to unsatisfied customers through Amazon's messaging service, but they also aren't allowed to ask customers to remove negative reviews.

Ms. Scott asked for a refund but didn't want to delete her review. Another representative reached out the next day and declined to issue her refund. "A bad review is a fatal blow to us," read the email. "Could you help me delete the review? If you can, I want to refund $20 to you to express my gratitude." (This was twice what Ms. Scott paid.) A few hours later, she received another plea from the same email address. "It was so creepy. They emailed me directly about it over and over," Ms. Scott said. Ms. Scott contacted Amazon twice about the matter. I reviewed Amazon's chat transcripts and emails.

Security

Routers and Modems Running Arcadyan Firmware Are Under Attack (therecord.media) 24

Routers and modems running a version of the Arcadyan firmware, including devices from ASUS, Orange, Vodafone, and Verizon, are currently under attack from a threat actor attempting to ensnare the devices into their DDoS botnet. From a report: First spotted by security firm Bad Packets earlier this week and confirmed by Juniper Labs on Friday, the attacks are exploiting a vulnerability tracked as CVE-2021-20090.

Discovered by Tenable security researcher Evan Grant earlier this year, the vulnerability resides in the firmware code produced by Taiwanese tech firm Arcadyan. Grant says the vulnerability has existed in the code for at least ten years and has made its way into the firmware of at least 20 router and modem models sold by 17 different vendors, which based their products on a white-label version of old Arcadyan devices. The list of affected devices includes some of today's biggest router vendors and internet service providers, such as ASUS, Orange, Vodafone, Telstra, Verizon, Deutsche Telekom, British Telecom, and many others.

Slashdot Top Deals