Privacy

Pegasus Spyware Found On Journalists' Phones, French Intelligence Confirms (theguardian.com) 50

French intelligence investigators have confirmed that Pegasus spyware has been found on the phones of three journalists, including a senior member of staff at the country's international television station France 24. Pegasus is the hacking software -- or spyware -- that is developed, marketed and licensed to governments around the world by NSO Group. The malware has the capability to infect billions of phones running either iOS or Android operating systems. It enables operators of the spyware to extract messages, photos and emails, record calls and secretly activate microphones. The Guardian reports: It is the first time an independent and official authority has corroborated the findings of an international investigation by the Pegasus project -- a consortium of 17 media outlets, including the Guardian. Forbidden Stories, a Paris-based nonprofit media organization, and Amnesty International initially had access to a leaked list of 50,000 numbers that, it is believed, have been identified as those of people of interest by clients of Israeli firm NSO Group since 2016, and shared access with their media partners.

France's national agency for information systems security (Anssi) identified digital traces of NSO Group's hacking spyware on the television journalist's phone and relayed its findings to the Paris public prosecutor's office, which is overseeing the investigation into possible hacking. Anssi also found Pegasus on telephones belonging to Lenaig Bredoux, an investigative journalist at the French investigative website Mediapart, and the site's director, Edwy Plenel. Forbidden Stories believes at least 180 journalists worldwide may have been selected as people of interest in advance of possible surveillance by government clients of NSO.

Le Monde reported that the France 24 journalist, based in Paris, had been selected for "eventually putting under surveillance." Police experts discovered the spyware had been used to target the journalist's phone three times: in May 2019, September 2020 and January 2021, the paper said. Bredoux told the Guardian that investigators had found traces of Pegasus spyware on both her and Plenel's mobile phones. She said the confirmation of long-held suspicions that they had been targeted contradicted the repeated denials of those who were believed to be behind the attempt to spy on them.

Businesses

The Rise of Never-Ending Job Interviews (bbc.com) 205

An anonymous reader quotes a report from the BBC: Every jobseeker welcomes an invitation to a second interview, because it signals a company's interest. A third interview might feel even more positive, or even be the precursor to an offer. But what happens when the process drags on to a fourth, fifth or sixth round -- and it's not even clear how close you are to the 'final' interview? That's a question Mike Conley, 49, grappled with earlier this year. The software engineering manager, based in Indiana, US, had been seeking a new role after losing his job during the pandemic. Five companies told him they had to delay hiring because of Covid-19 -- but only after he'd done the final round of interviews. Another three invited him for several rounds of interviews until it was time to make an offer, at which point they decided to promote internally. Then, he made it through three rounds of interviews for a director-level position at a company he really liked, only to receive an email to co-ordinate six more rounds. "When I responded to the internal HR, I even asked, 'Are these the final rounds?,'" he says. "The answer I got back was: 'We don't know yet.'"

That's when Conley made the tough decision to pull out. He shared his experience in a LinkedIn post that's touched a nerve with fellow job-seekers, who've viewed it 2.6 million times as of this writing. Conley says he's received about 4,000 public comments of support, and "four times that in private comments" from those who feared being tracked by current or prospective employers. [...] In fact, the internet is awash with similar stories jobseekers who've become frustrated with companies -- particularly in the tech, finance and energy sectors -- turning the interview process into a marathon. That poses the question: how many rounds of interviews should it take for an employer to reasonably assess a candidate before the process veers into excess? And how long should candidates stick it out if there's no clear information on exactly how many hoops they'll have to jump through to stay in the running for a role?
Google recently determined that four interviews was enough to make a hiring decision with 86% confidence, noting that there was a diminishing return on interviewer feedback thereafter.

"John Sullivan, a Silicon Valley-based HR thought leader, says companies should nail down a hire-by date from the start of the recruitment process, because the best candidates only transition the job market briefly," reports the BBC. "According to a survey from global staffing firm Robert Half, 62% of US professionals say they lose interest in a job if they don't hear back from the employer within two weeks -- or 10 business days -- after the initial interview. That number jumps to 77% if there is no status update within three weeks. "
Security

Hackers Shut Down System For Booking COVID-19 Shots in Italy's Lazio Region (reuters.com) 33

Hackers have attacked and shut down the IT systems of the company that manages COVID-19 vaccination appointments for the Lazio region surrounding Rome, the regional government said on Sunday. From a report: "A powerful hacker attack on the region's CED (database) is under way," the region said in a Facebook posting. It said all systems had been deactivated, including those of the region's health portal and vaccination network, and warned the inoculation programme could suffer a delay. "It is a very powerful hacker attack, very serious... everything is out. The whole regional CED is under attack," Lazio region's health manager Alessio D'Amato said.


HP

Tale of Fake Hewlett-Packard Gear Spurs Arrest in China, Lawsuit (bloomberg.com) 45

An anonymous reader shares a report: When three Chinese nationals were jailed in Beijing almost a decade ago and accused of selling fake Hewlett-Packard networking gear, it looked like an example of U.S. companies getting what they'd long demanded: aggressive protection of intellectual property in the world's most populous nation. A drawn-out court case heading to trial in Massachusetts paints a much muddier picture. The three, exonerated in China, accuse the former Silicon Valley icon of setting them up. They argue that it was H-P units that conspired to sell counterfeit gear, and then pinned the blame on them. H-P disputes the claims, and is asking a U.S. federal judge to dismiss the lawsuit, saying the story was concocted by Integrated Communications & Technologies Inc., the Massachusetts-based company that employed the three Chinese nationals, to cover up its own criminal behavior. U.S. District Judge Leo T. Sorokin may rule on the dismissal request at any time. If he lets the case continue, a trial is scheduled for February.

Western companies have been calling on China for years to combat counterfeiting and take action against those that steal their intellectual property. One of the triggers for former U.S. President Donald Trump's trade war was the technology industry's lobbying of the American government to help protect their IP. A loss for either side in the lawsuit would tarnish its reputation in the world's largest market for computers by marking them as an organization that fraudulently sold counterfeit goods. The Office of the U.S. Trade Representative identified China as the "primary source" of counterfeit goods in a 2020 report. With Hong Kong, the document details, China accounts for 92% of the value of fake goods seized by U.S. Customs and Border Protection in 2019. In this case, the networking gear was made by an affiliate of H-P's in China, exported to India on lease, then sold back into the Chinese market.

Security

Hackers Leak Full EA Data After Failed Extortion Attempt (therecord.media) 56

The hackers who breached Electronic Arts last month have released the entire cache of stolen data after failing to extort the company and later sell the stolen files to a third-party buyer. From a report: The data, dumped on an underground cybercrime forum on Monday, July 26, is now being widely distributed on torrent sites. According to a copy of the dump obtained by The Record, the leaked files contain the source code of the FIFA 21 soccer game, including tools to support the company's server-side services. The existence of this leak was initially disclosed on June 10, when the hackers posted a thread on an underground hacking forum claiming to be in possession of EA data, which they were willing to sell for $28 million.
IT

New Startup 'Sentral' Pushes High-End Rental/Homesharing Apartments (seattlepi.com) 56

A new $500 million startup is now offering high-end apartments for short- and long-term rentals in America's "most vibrant, walkable neighborhoods". (And long-term renters can also avail themselves of its "turn-key homesharing program" to offset some of their rent.)

The Seattle Post-Intelligencer says it's "aimed mainly at tech workers, nomadic independent contractors and other folks whose work is no longer tied to a specific location." [A]menities might include workspaces offering private and collaborative office space. Inside the units themselves, residents might find work-from-home perks like adjustable height desks and ergonomic chairs. And let's not forget that work-life balance: Sentral buildings offer rooftop pools, outdoor kitchens and fire pits, gyms, photo booths, theaters, and more — as well as offering a plethora of curated events to its residents...

The folks behind the idea are savvy: CEO Jon Slavet is formerly of WeWork and Rodan + Fields. Michael Curtis, formerly VP of Engineering at Airbnb is now a strategy advisor at Sentral...

The price to lease at Sentral, given the amenities, isn't much higher than regular rent prices in the major cities it serves. The LIVE program offers designer-furnished homes for stays over 30 days starting at $2,500 a month. For comparison purposes, a studio in downtown Seattle listed on Craigslist (with none of the bling offered at Sentral) is asking $1,890 a month.

Sentral operates now in seven cities: LA, Austin, Chicago, Seattle, Denver, Chicago, Miami. An Atlanta location is next up, with more growth planned.

Sentral's press release calls them seven "vibrant gateway cities... a launchpad to explore the country's most exciting neighborhoods" (assisted by "a world-class onsite team that fosters a true sense of community"). Sentral enables residents to live or visit stylish buildings in the nation's most coveted cities for any period of time, whether a night, a month, or multiple years. Qualifying residents can also monetize their homes through Sentral's managed homeshare program... From the city registration process to logistical details such as housekeeping, insurance, photography, contactless check-in, and around-the-clock service, Sentral's turn-key platform makes homesharing seamless for hosts, enhancing their financial freedom and fueling their ability to travel and explore.
A recent tweet calls it "the future of living," while the company's new web site promises it offers "The comforts you crave + the freedom to travel."

"There has been a massive shift to a 'work-from-anywhere' culture that is blurring the lines among home, work, and travel," argues CEO Jon Slavet in Sentral's press release. And the lavish press release ends by saying that the company "is creating a global community of modern adventurers with the freedom to monetize their homes, explore their passion for travel, and live life on their own terms."
Security

Remote Work Without VPN Patches? Govt Security Agencies Reveal Most Exploited Vulnerabilities (esecurityplanet.com) 17

Slashdot reader storagedude quotes eSecurityPlanet : The FBI and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) joined counterparts in the UK and Australia Wednesday to announce the top 30 vulnerabilities exploited since the start of the pandemic.

The list, a joint effort with the Australian Cyber Security Centre (ACSC) and the UK's National Cyber Security Centre (NCSC), details vulnerabilities — primarily Common Vulnerabilities and Exposures (CVEs) — "routinely exploited by malicious cyber actors in 2020 and those being widely exploited thus far in 2021."

Many of the vulnerabilities are known ones for which patches exist, so they can typically be easily fixed. The agencies also recommended a centralized patch management system to prevent such oversights going forward.

Most of the vulnerabilities targeted in 2020 were disclosed during the last two years. "Cyber actor exploitation of more recently disclosed software flaws in 2020 probably stems, in part, from the expansion of remote work options amid the COVID-19 pandemic," said a CISA statement. "The rapid shift and increased use of remote work options, such as virtual private networks (VPNs) and cloud-based environments, likely placed additional burden on cyber defenders struggling to maintain and keep pace with routine software patching."

The vulnerabilities include a number of well publicized ones from major vendors like Citrix, Microsoft, Fortinet, VMware and others, so a good portion of the blame can be placed on those who just aren't being vigilant with patching.

IT

Is Remote Work Forcing Smaller Cities to Compete With Big Tech Salaries? (indiatimes.com) 100

Remote working seems like a boon to smaller cities, Reuters reports: About 30 per cent of remote workers plan on moving, according to two recent surveys: an April poll of 1,000 tech workers by nonprofit One America Works and a June survey of 1,006 national remote workers for MakeMyMove, focused on intentions for the next 18 months... [T]he numbers mean a lot for some towns and cities that have seen "brain drains" to larger metropolitan areas, said Prithwiraj Choudhury, associate professor at the Harvard Business School.
But smaller cities are now also competing with big-tech recruiters, reports the Wall Street Journal: Some of the biggest names in tech aren't just allowing existing workers to relocate out of the Bay Area, they are also starting to hire in places they hadn't often recruited from before. The result is the most geographically distributed tech labor market to date. That's leading to above-market rates for workers in smaller hubs, forcing local companies to raise wages to keep up with the cost of living and fend off deeper-pocketed rivals from California.
IT

It's the Hottest Job Market in 20 Years for Tech Workers (bostonherald.com) 56

Tribune News Services says we're now experiencing the "hottest job market for tech workers since dot-com era" There's an air of desperation among tech employers this summer. Software talent, it seems, is in such high demand that companies are morphing how they hire. And workers are the ones with the power. Good and experienced tech workers are being treated like local celebrities — hounded by recruiters, courted by managers and bestowed a bevy of options before choosing their next boss...

The demand has been attributed to all sorts of things. During the pandemic, businesses that had been slow to adopt enterprise software began rapidly catching up. A tidal wave of productivity software, conferencing and collaboration tools, and e-commerce tech flooded the world. The same was true for consumer tech, with video game development, entertainment tech and social platforms booming. Many of these jobs are going unfilled, as competition for new hires ramps up. Simultaneously, remote work became the status quo in the tech industry. Suddenly, software talent could pick and choose from a massive pool of job opportunities...

To win a bid on a quality engineer, companies are offering things like flexible hours, sign-on bonuses and permanent remote work, the last of which has become a requirement for much of the workforce. Dice, a website and staffing firm that focuses on tech talent, published a report in June that found only 17% of technologists wanted to work in an office full time, while 59% wanted remote and hybrid approaches.

Communications

Chinese Hackers Used Mesh of Home Routers To Disguise Attacks (therecord.media) 25

An anonymous reader quotes The Record: A Chinese cyber-espionage group known as APT31 (or Zirconium) has been seen hijacking home routers to form a proxy mesh around its server infrastructure in order to relay and disguise the origins of their attacks.

In a security alert, the French National Cybersecurity Agency, also known as ANSSI (Agence Nationale de la Sécurité des Systèmes d'Information), published a list of 161 IP addresses that have been hijacked by APT31 in recent attacks against French organizations. French officials said that APT31's proxy botnet was used to perform both reconnaissance operations against their targets, but also to carry out the attacks themselves. The attacks started at the beginning of 2021 and are still ongoing...

The Record understands that APT31 used proxy meshes made of home routers as a way to scan the internet and then launch and disguise its attacks against Exchange email servers earlier this year; however, the technique was also used for other operations as well.

Government

US Justice Department Says Russians Hacked Its Federal Prosecutors (apnews.com) 45

In January America's federal Justice Department said there was no evidence that Russian hackers behind the massive SolarWinds breach had accessed classified systems, remembers the Associated Press. But today? The department said 80% of Microsoft email accounts used by employees in the four U.S. attorney offices in New York were breached. All told, the Justice Department said 27 U.S. Attorney offices had at least one employee's email account compromised during the hacking campaign.

The Justice Department said in a statement that it believes the accounts were compromised from May 7 to Dec. 27, 2020. Such a timeframe is notable because the SolarWinds campaign, which infiltrated dozens of private-sector companies and think tanks as well as at least nine U.S. government agencies, was first discovered and publicized in mid-December... Jennifer Rodgers, a lecturer at Columbia Law School, said office emails frequently contained all sorts of sensitive information, including case strategy discussions and names of confidential informants, when she was a federal prosecutor in New York. "I don't remember ever having someone bring me a document instead of emailing it to me because of security concerns," she said, noting exceptions for classified materials...

The Associated Press previously reported that SolarWinds hackers had gained access to email accounts belonging to the then-acting Homeland Security Secretary Chad Wolf and members of the department's cybersecurity staff...

United States

Tech Companies Praised for 'Pandemic Leadership', Vaccine Mandates (indiatimes.com) 178

"America reported 122,000 new COVID-19 cases on Friday, the highest single-day spike since February," reports Business Insider. But when it comes to anti-Covid measures like vaccine mandates, America's technology companies have been "decisive trend setters," according to the New York Times' On Tech newsletter. (Alternate URL) Last year, some high-profile tech companies were relatively early to close their corporate offices as coronavirus outbreaks started in the United States, and they continued to pay many hourly workers who couldn't do their jobs remotely. Those actions from companies including Microsoft, Salesforce, Facebook, Google, Apple and Twitter probably helped save lives in the Bay Area and perhaps beyond. Now many of the same tech companies — along with schools and universities, health care institutions and some government employers in the United States — have started to announce vaccine mandates for staff, the resumption of requirements to wear masks, delayed reopenings of offices or on-site workplace vaccinations to help slow the latest wave of infections.

America's tech companies, which deserve criticism for misusing their power, also should get credit for using their power to take decisive action in response to virus risks. Those steps helped make it palatable for other organizations to follow. And in some cases, tech companies have acted more quickly in response to health threats and communicated about them more effectively than federal or local government leaders.

Disney, the world's largest entertainment company, is also requiring all salaried and nonunion hourly employees in the U.S. to be fully vaccinated, according to the Washington Post. Walmart, the nation's largest private employer at almost 1.6 million employees, announced all of its corporate staff members and regional managers would need to be fully vaccinated by Oct. 4. Though the mandate does not apply to store and warehouse staffers, which make up the bulk of the company's workforce, Walmart is offering a $150 bonus as incentive for those unvaccinated employees to get inoculated... While companies are pushing for vaccinations, they must contend with employees who are seeking exceptions for medical or religious reasons. Walmart said in a statement that while a "small percentage" of employees are unable to be vaccinated due to such reasons, those workers "must follow all social distancing standards, wear a mask while working, and receive weekly Covid-19 testing provided by Walmart...."

The news comes after corporate giants Google, Facebook and Uber announced their own vaccine mandates for employees this week. Companies such as Apple, Twitter, Lyft and the New York Times said they are delaying their return to the office due to the rising cases.

More examples from CNN:
  • BlackRock the world's largest asset manager, is currently allowing only vaccinated employees to return to the office
  • Morgan Stanley's New York office is banning all unvaccinated staff and clients from entering its headquarters.
  • Luxury department store chain Saks Fifth Avenue is requiring that all employees be vaccinated.
  • All new hires and current employees of the Washington Post will be required to demonstrate proof of full Covid-19 vaccinations.
  • As of August 2, all employees working in Lyft's offices are required to be vaccinated
  • If Uber employees want to come back to the office, they must be fully vaccinated

Android

New Android Malware Uses VNC To Spy and Steal Passwords From Victims (thehackernews.com) 15

A previously undocumented Android-based remote access trojan (RAT) has been found to use screen recording features to steal sensitive information on the device, including banking credentials, and open the door for on-device fraud. The Hacker News reports: Dubbed "Vultur" due to its use of Virtual Network Computing (VNC)'s remote screen-sharing technology to gain full visibility on targeted users, the mobile malware was distributed via the official Google Play Store and masqueraded as an app named "Protection Guard," attracting over 5,000 installations. Banking and crypto-wallet apps from entities located in Italy, Australia, and Spain were the primary targets. "For the first time we are seeing an Android banking trojan that has screen recording and keylogging as the main strategy to harvest login credentials in an automated and scalable way," researchers from ThreatFabric said in a write-up shared with The Hacker News. "The actors chose to steer away from the common HTML overlay development we usually see in other Android banking Trojans: this approach usually requires a larger time and effort investment from the actors to create multiple overlays capable of tricking the user. Instead, they chose to simply record what is shown on the screen, effectively obtaining the same end result."

Vultur [...] takes advantage of accessibility permissions to capture keystrokes and leverages VNC's screen recording feature to stealthily log all activities on the phone, thus obviating the need to register a new device and making it difficult for banks to detect fraud. What's more, the malware employs ngrok, a cross-platform utility used to expose local servers behind NATs and firewalls to the public internet over secure tunnels, to provide remote access to the VNC server running locally on the phone. Additionally, it also establishes connections with a command-and-control (C2) server to receive commands over Firebase Cloud Messaging (FCM), the results of which, including extracted data and screen captures, are then transmitted back to the server.

ThreatFabric's investigation also connected Vultur with another well-known piece of malicious software named Brunhilda, a dropper that utilizes the Play Store to distribute different kinds of malware in what's called a "dropper-as-a-service" (DaaS) operation, citing overlaps in the source code and C2 infrastructure used to facilitate attacks. These ties, the Amsterdam-based cybersecurity services company said, indicate Brunhilda to be a privately operating threat actor that has its own dropper and proprietary RAT Vultur.

Security

Software Downloaded 30,000 Times From PyPI Ransacked Developers' Machines (arstechnica.com) 26

Open source packages downloaded an estimated 30,000 times from the PyPI open source repository contained malicious code that surreptitiously stole credit card data and login credentials and injected malicious code on infected machines, researchers said on Thursday. Ars Technica reports: In a post, researchers Andrey Polkovnichenko, Omer Kaspi, and Shachar Menashe of devops software vendor JFrog said they recently found eight packages in PyPI that carried out a range of malicious activity. Based on searches on https://pepy.tech, a site that provides download stats for Python packages, the researchers estimate the malicious packages were downloaded about 30,000 times. [...] Different packages from Thursday's haul carried out different kinds of nefarious activities. Six of them had three payloads, one for harvesting authentication cookies for Discord accounts, a second for extracting any passwords or payment card data stored by browsers, and the third for gathering information about the infected PC, such as IP addresses, computer name, and user name. The remaining two packages had malware that tries to connect to an attacker-designated IP address on TCP port 9009, and to then execute whatever Python code is available from the socket. It's not now known what the IP address was or if there was malware hosted on it.

Like most novice Python malware, the packages used only a simple obfuscation such as from Base64 encoders. Karas told me that the first six packages had the ability to infect the developer computer but couldn't taint the code developers wrote with malware. "For both the pytagora and pytagora2 packages, which allows code execution on the machine they were installed, this would be possible." he said in a direct message. "After infecting the development machine, they would allow code execution and then a payload could be downloaded by the attacker that would modify the software projects under development. However, we don't have evidence that this was actually done."

Security

Russian Hackers Continue With Attacks Despite Biden Warning (bloomberg.com) 104

Security researchers say they have uncovered an ongoing hacking campaign carried out by suspected Russian spies who are continuing to stage attacks amid U.S. pressure on the Kremlin to curtail its alleged cyber-intrusions. From a report: The California-based cybersecurity firm RiskIQ Inc. said in a report released on Friday that it had uncovered more than 30 command and control servers -- used by cybercriminals to send orders to compromised networks or receive stolen data -- associated with the state-sponsored hacking group, which is known as APT29 or Cozy Bear. The group is using the servers to deploy malicious software named WellMess, according to RiskIQ. APT stands for "advanced persistent threat," and is a term often used to describe state-sponsored hacking groups.

In July last year, government agencies from the U.S., U.K., and Canada, said that APT29 was "almost certainly" part of the Russian intelligence services and accused it of hacking organizations involved in the development of the Covid-19 vaccine and stealing intellectual property. The same group was also allegedly involved in the 2016 hack on the Democratic National Committee and the breach of SolarWinds, which was disclosed last year, according to U.S. officials. The Russian embassy in Washington referred to an earlier statement, in which it urged journalists to stop "sweeping accusations" and said it was confident that discussions with the U.S. related to cyberspace would "improve the security of the information infrastructure of our countries."

Privacy

Estonia Says a Hacker Downloaded 286,000 ID Photos From Government Database (therecord.media) 11

Estonian officials said they arrested last week a local suspect who used a vulnerability to gain access to a government database and downloaded government ID photos for 286,438 Estonians. From a report: The attack took place earlier this month, and the suspect was arrested last week on July 23, Estonian police said in a press conference yesterday, July 28. The identity of the attacker was not disclosed, and he was only identified as a Tallinn-based male. Officials said the suspect discovered a vulnerability in a database managed by the Information System Authority (RIA), the Estonian government agency which manages the country's IT systems.
Microsoft

Windows 11 Now Has Its First Beta Release (theverge.com) 49

Microsoft has released the first beta of Windows 11, available to those enrolled in its Windows Insider Program. From a report: Until today, getting access to Windows 11 meant installing the Dev preview, which Microsoft says is for "highly technical users" as it has "rough edges." According to Microsoft, the beta release is less volatile, with builds being validated by Microsoft (though it's still probably something you'll want to install on a test machine or second partition). Of course, to install the beta you'll need a compatible computer. Figuring out if your hardware will work with the next version of Windows has been notoriously tricky to pin down, but Microsoft's article about preparing for Insider builds directs people to its system requirements page. The company has said that it will be paying close attention to how well 7th Gen Intel and AMD Zen 1 CPUs work during the testing period, so it's possible those systems could be allowed to run the beta but not the final release.
Android

New Android Malware Records Smartphones via VNC To Steal Passwords (therecord.media) 15

Security researchers have discovered a novel piece of Android malware that uses the VNC technology to record and broadcast a victim's smartphone activity, allowing threat actors to collect keyboard presses and app passwords. From a report: First spotted in March 2021 by Dutch security firm ThreatFabric, this new piece of malware, named Vultur, is a departure from other Android malware strains that usually rely on fake login screens floating on top of legitimate apps to collect a victim's credentials. Instead, Vultur opens a VNC server on the infected phone, and broadcasts screen captures to an attacker command and control server, where the Vultur operator extracts passwords for desired apps.
Links

What That Google Drive 'Security Update' Message Means (arstechnica.com) 9

An anonymous reader quotes a report from Ars Technica: A security update will be applied to Drive," Google's weird new email reads. If you visit drive.google.com, you'll also see a message saying, "On September 13, 2021, a security update will be applied to some of your files." You can even see a list of the affected files, which have all gotten an unspecified "security update." So what is this all about? Google is changing the way content sharing works on Drive. Drive files have two sharing options: a single-person allow list (where you share a Google Doc with specific Google accounts) and a "get link" option (where anyone with the link can access the file). The "get link" option works the same way as unlisted YouTube videos -- it's not really private but, theoretically, not quite public, either, since the link needs to be publicized somewhere. The secret sharing links are really just security through obscurity, and it turns out the links are actually guessable.

Google knew about the problem of guessable secret links for a while and changed the way link generation works back in 2017 (presumably for Drive, too?). Of course, that doesn't affect links you've shared in the past, and soon Google is going to require your old links to change, which can break them. Google's new link scheme adds a "resourcekey" to the end of any shared Drive links, making them harder to guess. So a link that used to look like "https://drive.google.com/file/d/0BxI1YpjkbX0OZ0prTHYyQ1U2djQ/" will now look like "https://drive.google.com/file/d/0BxI1YpjkbX0OZ0prTHYyQ1U2djQ/view?resourcekey=0-OsOHHiQFk1QEw6vIyh8v_w." The resource key makes it harder to guess. If you head to drive.google.com/drive/update-drives in a browser, you should be able to see a list of your impacted files, and if you mouse over them you'll see a button on the right to remove or apply the security update. "Applied" means the resourcekey will be required after September 13, 2021, and will (mostly) break the old link, while "removed" means the resourcekey isn't required and any links out there should keep working.
YouTube is also making similar changes. "In 2017, we rolled out an update to the system that generates new YouTube Unlisted links, which included security enhancements that make the links for your Unlisted videos even harder for someone to discover if you haven't shared the link with them," says YouTube in a support page.

YouTube creators can decide to opt out of this change. They also have the option of making Unlisted pre-2017 videos public or re-uploading as a new Unlisted video at the expense of stats.
Security

Israel Begins Investigation Into NSO Group Spyware Abuse (technologyreview.com) 21

Israeli government officials visited the offices of the hacking company NSO Group on Wednesday to investigate allegations that the firm's spyware has been used to target activists, politicians, business executives, and journalists, the country's Ministry of Defense said in a statement today. From a report: An investigation published last week by 17 global media organizations, claims that phone numbers belonging to notable figures have been targeted by Pegasus, the notorious spyware that is NSO's best-selling product. The Israeli Ministry of Defense did not specify which government agencies were involved in the investigation, but Israeli media previously reported that the Foreign Ministry, Justice Ministry, Mossad, and Military Intelligence were also looking into the company following the publication of the Pegasus Project. NSO Group CEO Shalev Hulio confirmed to MIT Technology Review that the visit had taken place, but continued the company's denials that the list published by reporters was linked to Pegasus.

"That's true," he said. "I believe it's very good that they are checking, since we know the truth and we know that the list never existed and is not related to NSO." The reports focused largely on the successful hacking of 37 smartphones of business leaders, journalists, and human rights activists. But they also pointed to a leaked list of over 50,000 more phone numbers of interest in countries that are reportedly clients of NSO Group. The company has repeatedly denied the reporting. At this point, both the source of and meaning of the list remain unclear, but numerous phones on the list were hacked according to technical analysis by Amnesty International's Security Lab. When asked if the government's investigation process will continue, Hulio said he hopes it will be ongoing. "We want them to check everything and make sure that the allegations are wrong," he added.

Slashdot Top Deals