Security

Iran's Rail Network Hit by Possible Cyber Attack, State TV Says (bloomberg.com) 31

A potential cyber attack on Iran's state railway company created "unprecedented chaos" at stations across the country and led to cancellations and delays on hundreds of lines, state TV reported. From a report: Departure notice boards showed blanket cancellations and carried the message "long delay following cyber attack," the national broadcaster said, adding that the disruption to Islamic Republic of Iran Railways' computer systems also affected station entrances and exits as well as ticket booths. The national rail company's website, www.rai.ir, wasn't loading as of 7.50 p.m. in Tehran. Iranian state TV didn't say where it got the information.
Microsoft

Microsoft Awarded $13.6 Million To Security Researchers in the Past 12 Months (therecord.media) 9

Microsoft awarded $13.6 million to security researchers in the past 12 months, From a report: Microsoft said it awarded more than $13.6 million as monetary rewards to security researchers through its public bug bounty programs over the past 12 months. According to Microsoft:
The funds were awarded for 1,261 bugs reported by 341 security researchers across 17 bug bounty platforms between July 1, 2020 and June 30, 2021.

The highest awarded bounty was $200,000 for a vulnerability reported in Hyper-V, Microsoft's OS virtualization technology.
The average bounty was more than $10,000 per valid bug report across all programs.
Most bug reports came from researchers residing in China, the US, and Israel.
The company said it plans to announce the 2021 Most Valuable Security Researcher next month.
The sum awarded this year is identical to what Microsoft reported one year ago when the company said it awarded $13.7 million to 327 security researchers for 1,226 vulnerability reports across 15 bug bounty programs in the previous 12 months (July 1, 2019 to June 30, 2020).

Security

Kaspersky Password Manager Fixes Flaw That Generated Easily Bruteforced Passwords (zdnet.com) 31

An anonymous reader quotes a report from ZDNet: Suppose you are in the business of generating passwords, it would probably be a good idea to use an additional source of entropy other than the current time, but for a long time, that's all Kaspersky Password Manager (KPM) used. In a blog post to cap off an almost two year saga, Ledger Donjon head of security research Jean-Baptiste Bedrune showed KPM was doing just that. "Kaspersky Password Manager used a complex method to generate its passwords. This method aimed to create passwords hard to break for standard password crackers. However, such method lowers the strength of the generated passwords against dedicated tools," Bedrune wrote.

One of the techniques used by KPM was to make letters that are not often used appear more frequently, which Bedrune said was probably an attempt to trick password cracking tools. "Their password cracking method relies on the fact that there are probably 'e' and 'a' in a password created by a human than 'x' or 'j', or that the bigrams 'th' and 'he' will appear much more often than 'qx' or 'zr'," he said. "Passwords generated by KPM will be, on average, far in the list of candidate passwords tested by these tools. If an attacker tries to crack a list of passwords generated by KPM, he will probably wait quite a long time until the first one is found. This is quite clever." The flip side was that if an attacker could deduce that KPM was used, then the bias in the password generator started to work against it.

"If an attacker knows a person uses KPM, he will be able to break his password much more easily than a fully random password. Our recommendation is, however, to generate random passwords long enough to be too strong to be broken by a tool." The big mistake made by KPM though was using the current system time in seconds as the seed into a Mersenne Twister pseudorandom number generator. "It means every instance of Kaspersky Password Manager in the world will generate the exact same password at a given second," Bedrune said. Because the program has an animation that takes longer than a second when a password is created, Bedrune said it could be why this issue was not discovered. "The consequences are obviously bad: every password could be bruteforced," he said. Bedrune added due to sites often showing account creation time, that would leave KPM users vulnerable to a bruteforce attack of around 100 possible passwords.
"Kaspersky was informed of the vulnerability in June 2019, and released the fix version in October that same year," adds ZDNet. "In October 2020, users were notified that some passwords would need to be generated, with Kaspersky publishing its security advisory on 27 April 2021."

"All public versions of Kaspersky Password Manager liable to this issue now have a new logic of password generation and a passwords update alert for cases when a generated password is probably not strong enough," the security company said.
Firefox

Firefox Extends Privacy and Security of Canadian Internet Users With By-default DNS-over-HTTPS Rollout in Canada (mozilla.org) 108

In a few weeks, Firefox will start the by-default rollout of DNS over HTTPS (or DoH for short) to its Canadian users in partnership with local DoH provider CIRA, the Canadian Internet Registration Authority. From a report: DoH will first become a default for 1% of Canadian Firefox users on July 20 and will gradually reach 100% of Canadian Firefox users in late September 2021 -- thereby further increasing their security and privacy online. This follows the by-default rollout of DoH to US users in February 2020. As part of the rollout, CIRA joins Mozilla's Trusted Recursive Resolver (TRR) Program and becomes the first internet registration authority and the first Canadian organization to provide Canadian Firefox users with private and secure encrypted Domain Name System (DNS) services.
Security

Code In Huge Ransomware Attack Written To Avoid Computers That Use Russian, Says New Report (nbcnews.com) 123

The computer code behind the massive ransomware attack by the Russian-speaking hacking ring REvil was written so that the malware avoids systems that primarily use Russian or related languages, according to a new report by a cybersecurity firm. NBC News reports: It's long been known that some malicious software includes this feature, but the report by Trustwave SpiderLabs, obtained exclusively by NBC News, appears to be the first to publicly identify it as an element of the latest attack, which is believed to be the largest ransomware campaign ever. "They don't want to annoy the local authorities, and they know they will be able to run their business much longer if they do it this way," said Ziv Mador, Trustwave SpiderLabs' vice president of security research.

Trustwave said the ransomware "avoids systems that have default languages from what was the USSR region. This includes Russian, Ukrainian, Belarusian, Tajik, Armenian, Azerbaijani, Georgian, Kazakh, Kyrgyz, Turkmen, Uzbek, Tatar, Romanian, Russian Moldova, Syriac, and Syriac Arabic." In May, cybersecurity expert Brian Krebs noted that ransomware by DarkSide, the Russia-based group that attacked Colonial Pipeline in May, "has a hard-coded do-not-install list of countries," including Russia and former Soviet satellites that mostly have favorable relations with the Kremlin. In general, criminal ransomware groups are allowed to operate with impunity inside Russia and other former Soviet states as long as they focus their attacks on the United States and the West, experts say. Krebs noted that in some cases, the mere installation of a Russian language virtual keyboard on a computer running Microsoft Windows will cause malware to bypass that machine.

Security

SideCopy Cyber-Espionage Group Targets Indian Government, Military (therecord.media) 3

A cyber-espionage group has been observed targeting Indian targets with government and military-related lures in a broad campaign to infect victims with malware. From a report: Tracked under the name of SideCopy, this cyber-espionage group has been active since 2019, according to Seqrite, Quick Heal's threat intelligence team, which first documented its spear-phishing campaigns last September. But in a report published today, Cisco Talos, one of the networking giant's cybersecurity divisions, said the group did not retreat or stop its operations after having its attacks and tooling exposed last year.
Republicans

Hackers Scrape 90,000 GETTR User Emails, Surprising No One (vice.com) 75

Just days after its launch, hackers have already found a way to take advantage of GETTR's buggy API to get the username, email address, and location of thousands of users. Motherboard reports: Hackers were able to scrape the email addresses and other data of more than 90,000 GETTR users. On Tuesday, a user of a notorious hacking forum posted a database that they claimed was a scrape of all users of GETTR, the new social media platform launched last week by Trump's former spokesman Jason Miller, who pitched it as an alternative to "cancel culture." The data seen by Motherboard includes email addresses, usernames, status, and location. One of the people whose email is in the database confirmed to Motherboard that they are indeed registered to GETTR. Motherboard also verified the database by attempting to create an account with three email addresses that appear in the database. When doing that, the site displayed the message: "The email is taken," suggesting it's already registered. It's unclear if the database contains the usernames and email addresses of all users on the site. Alon Gal, the co-founder and CTO of cybersecurity firm Hudson Rock, found the forum post with the database. "When threat actors are able to extract sensitive information due to neglectful API implementations, the consequence is equivalent to a data breach and should be handled accordingly by the firm and to be examined by regulators," he told Motherboard in an online chat.
Security

Russian State Hackers Breached Republican National Committee (bloomberg.com) 80

Russian government hackers breached the computer systems of the Republican National Committee last week, around the time a Russia-linked criminal group unleashed a massive ransomware attack, Bloomberg News reported Tuesday, citing two people familiar with the matter. From the report: The government hackers were part of a group known as APT 29 or Cozy Bear, according to the people. That group has been tied to Russia's foreign intelligence service and has previously been accused of breaching the Democratic National Committee in 2016, and of carrying out a supply-chain cyberattack involving SolarWinds Corp., which infiltrated nine U.S. government agencies and was disclosed in December. It's not known what data the hackers viewed or stole, if anything. An RNC spokesman on Tuesday denied its systems were breached and referred to an earlier statement.

"Microsoft informed us that one of our vendors, Synnex, systems may have been exposed," Mike Reed, a spokesman for the RNC, said on Saturday. "There is no indication the RNC was hacked or any RNC information was stolen. We are investigating the matter and have informed DHS and the FBI." The attack on the RNC, coupled with the recent ransomware attack, is a major provocation to President Joe Biden, who warned Russian President Vladimir Putin about cyberattacks at a June 16 summit. It's not clear if the attack on the RNC is connected in any way to the ransomware attacks, which exploited multiple previously unknown vulnerabilities in software from Miami-based Kaseya Ltd.

China

Chinese Regulators Suggested Didi Delay Its US IPO (wsj.com) 14

Weeks before Didi went public in the U.S., China's cybersecurity watchdog suggested the Chinese ride-hailing giant delay its initial public offering and urged it to conduct a thorough self-examination of its network security, WSJ reported Monday, citing people with knowledge of the matter. From a report: But for Didi, waiting would be problematic. In the absence of an outright order to halt the IPO, it went ahead. The company, facing investor pressure to list after raising billions of dollars from prominent venture capitalists, wrapped up its pre-offering "roadshow" in a matter of days in June -- much shorter than typical investor pitches made by Chinese firms. The listing on the New York Stock Exchange raised about $4.4 billion, making it the biggest stock sale for a Chinese company since Alibaba's IPO in 2014.

Back in Beijing, officials, especially those at the Cyberspace Administration of China, remained wary of the ride-hailing company's troves of data potentially falling into foreign hands as a result of greater public disclosure associated with a U.S. listing, the people said. Didi's American depositary shares began trading in New York on Wednesday, just a day before the ruling Communist Party celebrated its centenary.

Security

World's Single-Biggest Ransomware Attack Hit 'Thousands' in 17 Countries (apnews.com) 142

It's now being called "the single biggest global ransomware attack on record," with thousands of victims in at least 17 different countries breached with ransomware Friday, reports the Associated Press, citing new details provided by cybersecurity researchers.

An affiliate of the Russia-linked gang REvil deployed the ransomware "largely through firms that remotely manage IT infrastructure for multiple customers." A broad array of businesses and public agencies were hit by the latest attack, apparently on all continents, including in financial services, travel and leisure and the public sector — though few large companies, the cybersecurity firm Sophos reported... The Swedish grocery chain Coop said most of its 800 stores would be closed for a second day Sunday because their cash register software supplier was crippled. A Swedish pharmacy chain, gas station chain, the state railway and public broadcaster SVT were also hit. In Germany, an unnamed IT services company told authorities several thousand of its customers were compromised, the news agency dpa reported...

CEO Fred Voccola of the breached software company, Kaseya, estimated the victim number in the low thousands, mostly small businesses like "dental practices, architecture firms, plastic surgery centers, libraries, things like that." Voccola said in an interview that only between 50-60 of the company's 37,000 customers were compromised. But 70% were managed service providers who use the company's hacked VSA software to manage multiple customers. It automates the installation of software and security updates and manages backups and other vital tasks...

Dutch researchers said they alerted Miami-based Kaseya to the breach and said the criminals used a "zero day," the industry term for a previously unknown security hole in software. Voccola would not confirm that or offer details of the breach — except to say that it was not phishing. "The level of sophistication here was extraordinary," he said. When the cybersecurity firm Mandiant finishes its investigation, Voccola said he is confident it will show that the criminals didn't just violate Kaseya code in breaking into his network but also exploited vulnerabilities in third-party software...

Kaseya, which called on customers Friday to shut down their VSA servers immediately, said Sunday it hoped to have a patch in the next few days.

The attacks may have been timed to exploit America's three-day weekend celebrating the nation's founding, according to experts interviewed by the Associated Press. America's National Security advisor is now urging all who believed they were compromised to alert the FBI.

"The attack comes less than a month after Biden pressed Russian President Vladimir Putin to stop providing safe haven to REvil and other ransomware gangs whose unrelenting extortionary attacks the U.S. deems a national security threat."

UPDATE: Bleeping Computer notes the exploited vulnerability "had been previously disclosed to Kaseya by security researchers from the Dutch Institute for Vulnerability Disclosure (DIVD), and Kaseya was validating the patch before they rolled it out to customers."

In a statement today, DIVD posted that "During the last 48 hours, the number of Kaseya VSA instances that are reachable from the internet has dropped from over 2,200 to less than 140 in our last scan today... A good demonstration of how a cooperative network of security-minded organizations can be very effective during a nasty crisis."
IT

Apple is 'Decentralizing Out of Silicon Valley' (9to5mac.com) 90

9to5Mac writes: Amid pushback regarding Apple's plans to return to in-person work this fall, Mark Gurman at Bloomberg reports that Apple is "ramping up efforts to decentralize out of Silicon Valley." In the latest edition of his Power On newsletter, Gurman reports that Apple has faced a variety of problems recruiting and retaining talent because of its emphasis on Silicon Valley.

Gurman writes that Apple has been "losing talent" because of the high-cost of living in the San Francisco Bay Area. "Many engineers lamented that they couldn't balance living expenses with other pursuits like college tuition for their children and long-term savings," Gurman says.

Furthermore, Apple has struggled to diversify its workforce because of its focus on Silicon Valley. It also competes with a variety of companies for talent, including Amazon, Google, and Netflix. The cost of operations is also high, and Gurman writes that "Apple could get the same work out of employees demanding far lower salaries in less pricey regions." For these reasons, Apple is reportedly looking to decentralize out of Silicon Valley.

From Bloomberg's report: Decentralization across the company is entering full swing, and Apple has engaged in a costly expansion from the sunny coasts of LA and San Diego to the Pacific Northwest of Oregon and Washington, the Rocky Mountains of Colorado, Iowa's Midwest, the Eastern Seaboard of Massachusetts, Miami and New York. Notably, it's also spending $2 billion on building new campuses in Austin, Texas, and North Carolina. That's in addition to hiring engineers in Canada, Germany, New Zealand, Spain and the U.K. Altogether, the moves will add tens of thousands of jobs outside of Silicon Valley.

As it keeps moving beyond Silicon Valley, Apple will pilot a hybrid office and remote work arrangement globally when it forces nearly all staff back to its offices in September.

Security

REvil Ransomware Hits 200 Companies In MSP Supply-Chain Attack (bleepingcomputer.com) 39

A massive REvil ransomware attack affects multiple managed service providers and their clients through a reported Kaseya supply-chain attack. Bleeping Computer reports: Starting this afternoon, the REvil ransomware gang targeted approximately eight large MSPs, with thousands of customers, through what appears to be a Kaseya VSA supply-chain attack. Kaseya VSA is a cloud-based MSP platform that allows providers to perform patch management and client monitoring for their customers. Huntress Labs' John Hammond has told BleepingComputer that all of the affected MSPs are using Kaseya VSA and that they have proof that their customers are being encrypted as well. "We have 3 Huntress partners that are impacted with roughly 200 businesses encrypted," Hammond told BleepingComputer. Kasey issued an security advisory on their help desk site warniong all VSA customers to immediately shut down their VSA server to prevent the attack's spread while they investigate. In a statement to BleepingComputer, Kaseya stated that they have shut down their SaaS servers and are working with other securty firms to investigate the incident.

A sample of the REvil ransomware used in one of these attacks has been shared with BleepingComputer. However, it is unknown if this is the sample used for every victim or if each MSP received its own ransom demand. The ransomware gang is demanding a $5,000,000 ransom to receive a decryptor from one of the samples. While REvil is known to steal data before deploying the ransomware and encrypting devices, it is unknown if the attackers exfiltrated any files.

Security

DHS Adds Hundreds of New Cyber Professionals To Its Ranks (therecord.media) 46

The US Department of Homeland Security on Thursday announced that it is onboarding nearly 300 cybersecurity professionals and has extended job offers to 500 others in what it refers to as "the most successful cybersecurity hiring initiative in DHS history." From a report: The hiring spree is part of the department's 60-day cybersecurity workforce sprint that aimed to add 200 new cybersecurity personnel by July 1. As The Record reported in May, DHS Secretary Alejandro Mayorkas told attendees of a US Chamber of Commerce event that one of the department's most significant priorities was building out its cybersecurity expertise with an emphasis on diversity.
The Internet

The Tim Berners-Lee NFT that sold for $5.4M might have an HTML error (arstechnica.com) 41

An anonymous reader shares a report: Two weeks ago, World Wide Web creator Tim Berners-Lee sent an NFT of the web's original source code to the auction block with a starting bid of just $1,000. Yesterday, Sotheby's announced that the crypto asset sold for $5.4 million. The sum makes Berners-Lee's work one of the priciest NFTs of all time. The digital package included not just the source code but also a letter from Berners-Lee reflecting on the creation of the web, some original HTML documents, an SVG "poster" of thousands of lines of code, and a 30-minute visualization of the code being typed on a screen.

But there's a twist. An eagle-eyed researcher pointed out on Twitter that the animation initially posted on the Sotheby's site had errors in the code, possibly introduced when the person making the video fed the Objective-C code through an app or web service to produce the typing effect in the animation. Instead of angle brackets that are present in the code (), the HTML codes for the symbols ( & lt; and & gt;) appeared instead. On the poster, which was made by a Python script created by Berners-Lee, the brackets appear correct. Presumably, they are also correct in the code itself. The code was corrected in later animations, raising questions about this particular NFT and NFTs as a whole.

Data Storage

Another Exploit Hits WD My Book Live Owners (tomshardware.com) 50

While it will come as no comfort to those who had their Western Digital My Book Live NAS drives wiped last week, it seems they were attacked by a combination of two exploits, and possibly caught in the fallout of a rivalry between two different teams of hackers. Tom's Hardware reports: Initially, after the news broke on Friday, it was thought a known exploit from 2018 was to blame, allowing attackers to gain root access to the devices. However, it now seems that a previously unknown exploit was also triggered, allowing hackers to remotely perform a factory reset without a password and to install a malicious binary file. A statement from Western Digital, updated today, reads: "My Book Live and My Book Live Duo devices are under attack by exploitation of multiple vulnerabilities present in the device ... The My Book Live firmware is vulnerable to a remotely exploitable command injection vulnerability when the device has remote access enabled. This vulnerability may be exploited to run arbitrary commands with root privileges. Additionally, the My Book Live is vulnerable to an unauthenticated factory reset operation which allows an attacker to factory reset the device without authentication. The unauthenticated factory reset vulnerability [has] been assigned CVE-2021-35941."

Analysis of WD's firmware suggests code meant to prevent the issue had been commented out, preventing it from running, by WD itself, and an authentication type was not added to component_config.php which results in the drives not asking for authentication before performing the factory reset. The question then arises of why one hacker would use two different exploits, particularly an undocumented authentication bypass when they already had root access through the command injection vulnerability, with venerable tech site Ars Technica speculating that more than one group could be at work here, with one bunch of bad guys trying to take over, or sabotage, another's botnet.
Western Digital advises users to disconnect their device(s) from the internet. They are offering data recovery services beginning in July, and a trade-in program to switch the obsolete My Book Live drives for more modern My Cloud devices.
Chrome

Google Is Working On an HTTPS-Only Mode For Chrome (therecord.media) 65

An anonymous reader writes: Following in the footsteps of browsers like Mozilla Firefox and Microsoft Edge, Google Chrome is also in line to receive an HTTPS-Only Mode that will upgrade all unencrypted HTTP connections to encrypted HTTPS alternatives, where possible.

Currently, the new Chrome HTTPS-Only Mode is still under development in Chrome Canary distributions. Work is being done to add specific settings in the browser's interface, and no actual HTTP-to-HTTPS functionality is currently present. The feature is expected to be ready for Chrome 93, set to be released later this fall.

Security

New Charges Filed Against Capital One Hacker, Trial Postponed To 2022 (therecord.media) 18

The US government has filed a superseding indictment against Paige A. Thompson, a former Amazon engineer accused of hacking Capital One and stealing the personal data of more than 100 million Americans. From a report: According to court documents filed earlier this month and obtained by The Record, the US Department of Justice has added seven new charges on top of the original two it filed in August 2019. The new charges -- six counts of computer fraud and abuse, and one count of access device fraud -- come as investigators have made headway in analyzing data seized from Thompson's computers and servers.
Security

Germany Thwarts Cyberattack, Denies Impact on Banking System (bloomberg.com) 5

German authorities thwarted a cyberattack on a data service provider used by federal agencies and pushed back on a report that a broad assault targeted critical infrastructure and banks. From a report: The attempt was quickly dealt with and impact on service was "very marginal," Interior Ministry spokesman Steve Alter told reporters on Wednesday, adding that it was likely criminally motivated. He was queried about a report by Bild newspaper, which cited unidentified intelligence sources saying that a hacker group linked to the Kremlin had carried out an attack on German infrastructure and the country's banking system. Bild identified the group as "Fancy Lazarus" after earlier referencing "Fancy Bear," a group controlled by Russia's GRU military intelligence agency that was behind the hacking of Hillary Clinton's staff before the 2016 election, according to a 2018 U.S. Department of Justice indictment. Authorities haven't detected an increase in cyber activities in recent days, Alter said.
Security

LinkedIn Breach Reportedly Exposes Data of 92% of Users, Including Inferred Salaries (9to5mac.com) 47

A second massive LinkedIn breach reportedly exposes the data of 700M users, which is more than 92% of the total 756M users. The database is for sale on the dark web, with records including phone numbers, physical addresses, geolocation data, and inferred salaries. 9to5Mac reports: RestorePrivacy reports that the hacker appears to have misused the official LinkedIn API to download the data, the same method used in a similar breach back in April: "On June 22nd, a user of a popular hacker advertised data from 700 Million LinkedIn users for sale. The user of the forum posted up a sample of the data that includes 1 million LinkedIn users. We examined the sample and found it to contain the following information: Email Addresses; Full names; Phone numbers; Physical addresses; Geolocation records; LinkedIn username and profile URL; Personal and professional experience/background; Genders; and Other social media accounts and usernames."

With the previous breach, LinkedIn did confirm that the 500M records included data obtained from its servers, but claimed that more than one source was used. PrivacyShark notes that the company has issued a similar statement this time: "While we're still investigating this issue, our initial analysis indicates that the dataset includes information scraped from LinkedIn as well as information obtained from other sources. This was not a LinkedIn data breach and our investigation has determined that no private LinkedIn member data was exposed. Scraping data from LinkedIn is a violation of our Terms of Service and we are constantly working to ensure our members' privacy is protected."

Microsoft

Microsoft Rolls Out Visually Updated Office Preview, Plus Native 64-bit Office for Arm (zdnet.com) 38

Microsoft has released a visually "refreshed" version of its Office desktop apps for both Windows 10 and 11. Microsoft officials said this new Office refresh will "shine" on Windows 11 but still work on Windows 10. Microsoft also is releasing its first publicly available test build of 64-bit Office for Windows on Arm today. From a report: The updated Office uses Fluent design across Word, Excel, PowerPoint, OneNote, Outlook, Access, Project, Publisher, and Visio. The updated apps are meant to look similar to the Windows 11 OS, design-wise. Via the updated Office interface, Office is set to match users' Windows themes, including black (Dark Mode), white, colorful, or dark gray. The Quick Access toolbar is hidden by default in the name of simplifying the interface. The refreshed Office is available to Office Insider testers running Beta Channel builds. Those who don't want it can turn off the "Coming Soon" feature at the top right hand corner of the menu. Testers can toggle between the new and existing interface to move between the current and newly updated Office apps.

Slashdot Top Deals