Security

Using VMs To Hide Ransomware Attacks is Becoming More Popular 41

An anonymous reader shares a report: In early 2020, security researchers were baffled to discover that a ransomware gang had come up with an innovative trick that allowed it to run its payload inside virtual machines on infected hosts as a technical solution that bypassed security software. One year later, that technique has spread among the cybercrime underground and is now used by multiple ransomware operators. Initially seen with the Ragnar Locker gang in May 2020, the technique was also adopted by a Maze ransomware subgroup later in the year and has been recently spotted in attacks where the Conti and MountLocker ransomware strains were deployed. In hindsight, it should be no surprise that this technique is becoming more popular, as it has tangible benefits for any threat actor. The general idea behind such an attack is that a ransomware gang that has a small foothold on an infected host can download and install VM software. The ransomware gang will then start a VM instance, share the host computer's storage space with the VM, and then proceed to encrypt the victim's files from within the VM, where the host's antivirus software cannot reach and detect the ransomware during execution.
Open Source

Linux 5.13 Kernel Released, Includes Apple M1 Support, Clang CFI, and Landlock's Linux Security Module (phoronix.com) 33

"Linus Torvalds has just released the Linux 5.13 kernel as stable," reports Phoronix: Linux 5.13 brings initial but still early support for the Apple M1 with basic support but not yet accelerated graphics and a lot more to iron out moving ahead. There are also new Linux 5.13 security features like the Landlock security module, Clang control flow integrity support, and optionally randomizing the kernel stack offset at each system call. There is also AMD fun this cycle around FreeSync HDMI support, initial Aldebaran bring-up, and more. Intel has more work on Alder Lake, a new cooling driver, and more discrete graphics bring-up. There are also other changes for Linux 5.13 around faster IO_uring, a generic USB display driver, and other new hardware enablement.
"5.13 overall is actually fairly large," Linus Torvalds posted on the Linux Kernel Mailing List, calling it "one of the bigger 5.x releases, with over 16,000 commits (over 17k if you count merges), from over 2,000 developers. But it's a "big all over" kind of thing, not something particular that stands out as particularly unusual..."
IT

'No Evidence' Chance Meetings at the Office Boost Innovation (nytimes.com) 171

The New York Times reports: When Yahoo banned working from home in 2013, the reason was one often cited in corporate America: Being in the office is essential for spontaneous collaboration and innovation. "It is critical that we are all present in our offices," wrote Jacqueline Reses, then a Yahoo executive, in a staff memo. "Some of the best decisions and insights come from hallway and cafeteria discussions, meeting new people and impromptu team meetings." Today, Ms. Reses, now chief executive of Post House Capital, an investment firm, has a different view. "Would I write that memo differently now?" she said. "Oh yeah." She still believes that collaboration can benefit from being together in person, but over the last year, people found new, better ways to work.

As the pandemic winds down in the United States, however, many bosses are sounding a note similar to Ms. Reses' in 2013. "Innovation isn't always a planned activity," said Tim Cook, chief executive of Apple, about post-pandemic work. "It's bumping into each other over the course of the day and advancing an idea you just had." Jamie Dimon, chief executive of JPMorgan Chase, said working from home "doesn't work for spontaneous idea generation, it doesn't work for culture." Yet people who study the issue say there is no evidence that working in person is essential for creativity and collaboration. It may even hurt innovation, they say, because the demand for doing office work at a prescribed time and place is a big reason the American workplace has been inhospitable for many people...

"There's credibility behind the argument that if you put people in spaces where they are likely to collide with one another, they are likely to have a conversation," said Ethan S. Bernstein, who teaches at Harvard Business School and studies the topic. "But is that conversation likely to be helpful for innovation, creativity, useful at all for what an organization hopes people would talk about? There, there is almost no data whatsoever. All of this suggests to me that the idea of random serendipity being productive is more fairy tale than reality," he said....

Professor Bernstein found that contemporary open offices led to 70 percent fewer face-to-face interactions. People didn't find it helpful to have so many spontaneous conversations, so they wore headphones and avoided one another.

The chief people officer at real estate marketplace Zillow believes this always-in-the-office culture is what's ultimately lead to problems like long hours, the lack of representation, and burnout, according to the New York Times, which notes Zillow, Salesforce, and Ford are now reconfiguring their offices with fewer rows of desks and more places for informal gatherings.

"Some experts have suggested a new idea for the office: not as a headquarters people go to daily or weekly, but as a place people go sometimes, for group hangouts."
Government

On the Deaths of Two Unvaccinated Florida IT Workers (msn.com) 339

I sometimes talk about "the family of geeks" — how our shared experiences can bring us together.

But if that's true, there's been a death in the family.... Manatee County Administrator Scott Hopes, who is also an epidemiologist, said six unvaccinated employees, including five in the IT department, tested positive for the virus within a two-week period.

The two IT employees who died last week were identified in local media and obituaries as Mary Knight, 58, and Alphonso Cox, 53.

Hopes said that the one IT employee, 23, exposed to the virus who was vaccinated did not get infected. "This particular outbreak demonstrates the effectiveness, I believe, with the vaccine," he said to reporters Monday. "All of the cases were non-vaccinated. They were unvaccinated." He added in a news release, "Individual employees in the IT Department who were known to be fully vaccinated and who were in close proximity of those who were infected did not contract COVID-19."

But even with the outbreak, masks will remain optional for staffers returning this week, with unvaccinated workers being "encouraged but not required, to follow covid-19 prevention measures...." Manatee County, located in southwest Florida, has fully vaccinated 43 percent of its eligible population. The Manatee Board of County Commissioners repealed coronavirus safety requirements last month and strongly recommended that people visiting the County Administration Building "use their best judgment" to protect themselves from a potential spread of the virus...

When the second employee died Thursday, the decision was made to shut down the building the next day so it could be disinfected. "When you have that many cases, and you have a 40 percent fatality rate, you have to worry," Hopes said to Florida Politics. "I would prefer not to have any more employee funerals." Yet the county announced over the weekend that "face masks will be optional for the public and employees inside the facility...."

Funerals and celebration-of-life events for Knight and Cox are scheduled to take place later this week.

Thanks to Slashdot reader luis_a_espinal (a Florida-based software engineer) for sharing the story. Country administrator Hopes is concerned, reports the Sarasota Herald-Tribune, because "Of the first five cases, all were sick enough to be hospitalized or died. That's not the normal COVID variant that we saw last year." And yet... As officials work to control the outbreak, questions have been raised about how far the county can go to keep employees safe — including whether it can inquire about employees' vaccination status, since the recent victims so far have not been fully vaccinated... "We are allowed to ask," Hopes said. "But they don't have to tell us, and whatever their response is, we are not to ask any further." Manatee County School District General Counsel Mitch Teitelbaum said the school district had the same understanding of privacy laws...

[The county-owned seaport] Port Manatee had reported three new cases of COVID-19 on Monday, spurring fears that the virus was continuing to spread among the county's workforce. On Tuesday, port spokeswoman Virginia Zimmerman said the three cases had been an "aberration" and that there are not any additional cases to report. Zimmerman said the port does not inquire about employees' vaccination status, and that the port "encourages, but does not require, staff to be vaccinated."

While the county scrambles to mitigate the spread of the virus, Hopes said many county employees are grieving the loss of their coworkers.

"These weren't just colleagues," Hopes said. "These people have basically lived at work together for 20 years, and this happened quickly."

PlayStation (Games)

Is a Sony PS3 Leak Now Leading To Banned Consoles? (threatpost.com) 26

"Every Sony PlayStation 3 ID out there was compromised, provoking bans of legit players on the network," Threatpost is reporting, calling it "just the latest in a shocking spike in attacks on unsuspecting gamers."

tlhIngan (Slashdot user #30,335) shares Threatpost's report: Sony reportedly left a folder with every PS3 console ID online unsecured, and it was discovered and reported by a Spanish YouTuber with the handle "The WizWiki" in mid-April... Now, several weeks later, players on PlayStation Network message boards are complaining that they can't sign on and are receiving the error message 8071006. After enabling two-factor authentication (2FA), one player was able to sign back in without issue, according to posts on the PS3 subreddit, which includes a link to instructions on how to opt into 2FA on the PS3.

It appears threat actors have started using the stolen PS3 console IDs for malicious purposes, causing the legitimate players to get banned... Sony has not responded to Threatpost's request for comment or confirmed a connection between the PS3 ID breach and player reports of being locked out of the platform...

Sony is hardly the only gaming company leaking data like a sieve. A report from January found a half a million credentials stolen from the Top 25 gaming companies on caches of breached data for sale in criminal marketplaces. In June, the "Battle of the Galaxy" mobile game leaked 6 million gamer profiles, and attackers are working out how to use gaming platforms like Steam to host or deliver malware.

Crime

French Engineer Claims He's Solved the Zodiac Killer's Final Code (msn.com) 57

The New York Times tells the story of Fayçal Ziraoui, a 38-year-old French-Moroccan business consultant who "caused an online uproar" after saying he'd cracked the last two unsolved ciphers of the four attributed to the Zodiac killer in California "and identified him, potentially ending a 50-year-old quest." Maybe because he said he cracked them in just two weeks. Many Zodiac enthusiasts consider the remaining ciphers — Z32 and Z13 — unsolvable because they are too short to determine the encryption key. An untold number of solutions could work, they say, rendering verification nearly impossible.

But Mr. Ziraoui said he had a sudden thought. The code-crackers who had solved the [earlier] 340-character cipher in December had been able to do so by identifying the encryption key, which they had put into the public domain when announcing their breakthrough. What if the killer used that same encryption key for the two remaining ciphers? So he said he applied it to the 32-character cipher, which the killer had included in a letter as the key to the location of a bomb set to go off at a school in the fall of 1970. (It never did, even though police failed to crack the code.) That produced a sequence of random letters from the alphabet. Mr. Ziraoui said he then worked through a half-dozen steps including letter-to-number substitutions, identifying coordinates in numbers and using a code-breaking program he created to crunch jumbles of letters into coherent words...

After two weeks of intense code-cracking, he deciphered the sentence, "LABOR DAY FIND 45.069 NORT 58.719 WEST." The message referred to coordinates based on the earth's magnetic field, not the more familiar geographic coordinates. The sequence zeroed in on a location near a school in South Lake Tahoe, a city in California referred to in another postcard believed to have been sent by the Zodiac killer in 1971.

An excited Mr. Ziraoui said he immediately turned to Z13, which supposedly revealed the killer's name, using the same encryption key and various cipher-cracking techniques. [The mostly un-coded letter includes a sentence which says "My name is _____," followed by a 13-character cipher.] After about an hour, Mr. Ziraoui said he came up with "KAYR," which he realized resembled the last name of Lawrence Kaye, a salesman and career criminal living in South Lake Tahoe who had been a suspect in the case. Mr. Kaye, who also used the pseudonym Kane, died in 2010.

The typo was similar to ones found in previous ciphers, he noticed, likely errors made by the killer when encoding the message. The result that was so close to Mr. Kaye's name and the South Lake Tahoe location were too much to be a coincidence, he thought. Mr. Kaye had been the subject of a report by Harvey Hines, a now-deceased police detective, who was convinced he was the Zodiac killer but was unable to convince his superiors. Around 2 a.m. on Jan. 3, an exhausted but elated Mr. Ziraoui posted a message entitled "Z13 — My Name is KAYE" on a 50,000-member Reddit forum dedicated to the Zodiac Killer.

The message was deleted within 30 minutes.

"Sorry, I've removed this one as part of a sort of general policy against Z13 solution posts," the forum's moderator wrote, arguing that the cipher was too short to be solvable.

Microsoft

Microsoft Admits to Mistakenly Signing a Malicious Malware Rootkit (gdatasoftware.com) 43

Bleeping Computer reports: Microsoft has now confirmed signing a malicious driver being distributed within gaming environments. This driver, called "Netfilter," is in fact a rootkit that was observed communicating with Chinese command-and-control IPs.

G Data malware analyst Karsten Hahn first took notice of this event last week and was joined by the wider infosec community in tracing and analyzing the malicious drivers bearing the seal of Microsoft... This incident has once again exposed threats to software supply-chain security, except this time it stemmed from a weakness in Microsoft's code-signing process.

G Data writes: We forwarded our findings to Microsoft who promptly added malware signatures to Windows Defender and are now conducting an internal investigation. At the time of writing it is still unknown how the driver could pass the signing process.
In a Friday blog post, Microsoft said it was contacting other antivirus software vendors "so they can proactively deploy detections," but also emphasized the attack's limited scope: The actor's activity is limited to the gaming sector specifically in China and does not appear to target enterprise environments. We are not attributing this to a nation-state actor at this time. The actor's goal is to use the driver to spoof their geo-location to cheat the system and play from anywhere. The malware enables them to gain an advantage in games and possibly exploit other players by compromising their accounts through common tools like keyloggers.

It's important to understand that the techniques used in this attack occur post exploitation, meaning an attacker must either have already gained administrative privileges in order to be able to run the installer to update the registry and install the malicious driver the next time the system boots or convince the user to do it on their behalf.

We will be sharing an update on how we are refining our partner access policies, validation and the signing process to further enhance our protections. There are no actions customers should take other than follow security best practices and deploy Antivirus software such as Windows Defender for Endpoint.

Security

Microsoft Says New Breach Discovered In Probe of Suspected SolarWinds Hackers (reuters.com) 23

An anonymous reader quotes a report from Reuters: Microsoft said on Friday an attacker had won access to one of its customer-service agents and then used information from that to launch hacking attempts against customers. The company said it had found the compromise during its response to hacks by a team it identifies as responsible for earlier major breaches at SolarWinds and Microsoft. Microsoft said it had warned the affected customers. "A sophisticated Nation-State associated actor that Microsoft identifies as NOBELLIUM accessed Microsoft customer support tools to review information regarding your Microsoft Services subscriptions," the warning reads in part. The U.S. government has publicly attributed the earlier attacks to the Russian government, which denies involvement.

After commenting on a broader phishing campaign that it said had compromised a small number of entities, Microsoft said it had also found the breach of its own agent, who it said had limited powers. The agent could see billing contact information and what services the customers pay for, among other things. "The actor used this information in some cases to launch highly-targeted attacks as part of their broader campaign," Microsoft said. Microsoft warned affected customers to be careful about communications to their billing contacts and consider changing those usernames and email addresses, as well as barring old usernames from logging in. Microsoft said it was aware of three entities that had been compromised in the phishing campaign. It did not immediately clarify whether any had been among those whose data was viewed through the support agent, or if the agent had been tricked by the broader campaign. Microsoft did not say whether the agent was at a contractor or a direct employee.

Security

NFC Flaws Let Researchers Hack an ATM By Waving a Phone (arstechnica.com) 19

An anonymous reader quotes a report from Ars Technica: For years, security researchers and cybercriminals have hacked ATMs by using all possible avenues to their innards, from opening a front panel and sticking a thumb drive into a USB port to drilling a hole that exposes internal wiring. Now, one researcher has found a collection of bugs that allow him to hack ATMs -- along with a wide variety of point-of-sale terminals -- in a new way: with a wave of his phone over a contactless credit card reader. Josep Rodriguez, a researcher and consultant at security firm IOActive, has spent the last year digging up and reporting vulnerabilities in the so-called near-field communications reader chips used in millions of ATMs and point-of-sale systems worldwide. NFC systems are what let you wave a credit card over a reader -- rather than swipe or insert it -- to make a payment or extract money from a cash machine. You can find them on countless retail store and restaurant counters, vending machines, taxis, and parking meters around the globe.

Now Rodriguez has built an Android app that allows his smartphone to mimic those credit card radio communications and exploit flaws in the NFC systems' firmware. With a wave of his phone, he can exploit a variety of bugs to crash point-of-sale devices, hack them to collect and transmit credit card data, invisibly change the value of transactions, and even lock the devices while displaying a ransomware message. Rodriguez says he can even force at least one brand of ATMs to dispense cash -- though that "jackpotting" hack only works in combination with additional bugs he says he has found in the ATMs' software. He declined to specify or disclose those flaws publicly due to nondisclosure agreements with the ATM vendors. "You can modify the firmware and change the price to one dollar, for instance, even when the screen shows that you're paying 50 dollars. You can make the device useless, or install a kind of ransomware. There are a lot of possibilities here," says Rodriguez of the point-of-sale attacks he discovered. "If you chain the attack and also send a special payload to an ATM's computer, you can jackpot the ATM -- like cash out, just by tapping your phone."

Rodriguez says he alerted the affected vendors -- which include ID Tech, Ingenico, Verifone, Crane Payment Innovations, BBPOS, Nexgo, and the unnamed ATM vendor -- to his findings between seven months and a year ago. Even so, he warns that the sheer number of affected systems and the fact that many point-of-sale terminals and ATMs don't regularly receive software updates -- and in many cases require physical access to update -- mean that many of those devices likely remain vulnerable. "Patching so many hundreds of thousands of ATMs physically, it's something that would require a lot of time," Rodriguez says.

Bug

Dell SupportAssist Bugs Put Over 30 Million PCs At Risk (bleepingcomputer.com) 27

AmiMoJo writes: Security researchers have found four major security vulnerabilities in the BIOSConnect feature of Dell SupportAssist, allowing attackers to remotely execute code within the BIOS of impacted devices. According to Dell's website, the SupportAssist software is 'preinstalled on most Dell devices running Windows operating system,' while BIOSConnect provides remote firmware update and OS recovery features. The chain of flaws discovered by Eclypsium researchers comes with a CVSS base score of 8.3/10 and enables privileged remote attackers to impersonate Dell.com and take control of the target device's boot process to break OS-level security controls. "Such an attack would enable adversaries to control the device's boot process and subvert the operating system and higher-layer security controls," Eclypsium researchers explain in a report shared in advance with BleepingComputer. "The issue affects 129 Dell models of consumer and business laptops, desktops, and tablets, including devices protected by Secure Boot and Dell Secured-core PCs," with roughly 30 million individual devices exposed to attacks.
Security

An Internal Code Repo Used By New York State's IT Office Was Exposed Online (techcrunch.com) 15

A code repository used by the New York state government's IT department was left exposed on the internet, allowing anyone to access the projects inside, some of which contained secret keys and passwords associated with state government systems. From a report: The exposed GitLab server was discovered on Saturday by Dubai-based SpiderSilk, a cybersecurity company credited with discovering data spills at Samsung, Clearview AI and MoviePass. Organizations use GitLab to collaboratively develop and store their source code -- as well as the secret keys, tokens and passwords needed for the projects to work -- on servers that they control. But the exposed server was accessible from the internet and configured so that anyone from outside the organization could create a user account and log in unimpeded, SpiderSilk's chief security officer Mossab Hussin told TechCrunch. When TechCrunch visited the GitLab server, the login page showed it was accepting new user accounts. It's not known exactly how long the GitLab server was accessible in this way, but historic records from Shodan, a search engine for exposed devices and databases, shows the GitLab was first detected on the internet on March 18.
NASA

NASA Can't Figure Out What's Causing Computer Issues On The Telescope (npr.org) 84

The storied space telescope that brought you stunning photos of the solar system and enriched our understanding of the cosmos over the past three decades is experiencing a technical glitch. From a report: Scientists at NASA say the Hubble Space Telescope's payload computer, which operates the spacecraft's scientific instruments, went down suddenly on June 13. Without it, the instruments on board meant to snap pictures and collect data are not currently working. Scientists have run a series of tests on the malfunctioning computer system but have yet to figure out what went wrong. "It's just the inefficiency of trying to fix something which is orbiting 400 miles over your head instead of in your laboratory," Paul Hertz, the director of astrophysics for NASA, told NPR. "If this computer were in the lab, we'd be hooking up monitors and testing the inputs and outputs all over the place, and would be really quick to diagnose it," he said. "All we can do is send a command from our limited set of commands and then see what data comes out of the computer and then send that data down and try to analyze it."

At first NASA scientists wondered if a "degrading memory module" on Hubble was to blame. Then on Tuesday the agency said it was investigating whether the computer's Central Processing Module (CPM) or its Standard Interface (STINT) hardware, which helps the CPM communicate with other components, caused the problem. Hertz said the current assumption, though unverified, was that the technical issue was a "random parts failure" somewhere on the computer system, which was built in the 1980s and launched into space in 1990. "They're very primitive computers compared to what's in your cell phone," he said, "but the problem is we can't touch it or see it." Most of Hubble's components have redundant back-ups, so once scientists figure out the specific component that's causing the computer problem, they can remotely switch over to its back-up part.

Google

A Bunch of Google Drive Links Are About To Be Broken (xda-developers.com) 31

In a blog post today, Google announced a series of new security enhancements that will make many publicly accessible Google Drive links no longer accessible. The enhancements are being brought to Google Drive on September 23rd, 2021. XDA Developers reports: Once this change goes live, Google says that users will need a "resource key" to access a publicly shared link. However, users won't need an updated link with said resource key appended if they've already accessed that file before in the past. As a result of this change, we can imagine that lots of Google Drive links shared online on forums and other sites will no longer work as their owners neglect to update them, leaving them only accessible to the people that have already clicked the links before.

According to the post made on the Google Workspace blog, this won't affect all files. Users who have shared a file that is affected by this change will get an email from Google informing them of this change and how to opt out of needing those files from being updated. These emails will be sent out to users starting on July 26th. Google shared a copy of a sample email to show end-users what the message they'll get will look like. The company doesn't recommend opting out all files and says that only the files that you want publicly accessible should be opted out. Users have until September 13th to decide if they want the update applied, so if you have no files that are publicly accessible, then you won't need to do anything.
YouTube is also making similar changes. "Starting on July 23, Unlisted videos uploaded before the January 1, 2017, system change will be automatically made private," reports 9to5Google. "That said, YouTube creators can decide to opt out of this change. Filling out this form will let you 'keep your Unlisted videos uploaded before 2017 in their current Unlisted state.' Other options include making Unlisted pre-2017 videos public or re-uploading as a new Unlisted video at the expense of stats."
IOS

Apple Says Third-Party App Stores Would Open iPhones To Scammers (bloomberg.com) 154

Apple is raising fears about letting users install applications outside the company's App Store, an issue being targeted by lawmakers and regulators that also played a prominent role in its recent trial against Epic Games. From a report: The company said Wednesday on its website that requiring apps to be downloaded from the App Store protects consumers against scams, keeps their privacy secure and provides developers payment for their work. All those benefits could disappear if apps can be downloaded from third-party app stores with lesser protections or users get an app from a website or PC and "sideload" it onto the phone. The timing of Apple's push back isn't coincidental.

The U.S. House Judiciary Committee Wednesday is scheduled to discuss six proposed antitrust bills, including one sponsored by Rhode Island Democrat Representative David Cicilline, a Democrat from Rhode Island and chairman of the antitrust subcommittee that, if passed into law, could call for Apple to open up to third-party app stores and provide all of its iPhone technologies to third-party software makers. "It shall be unlawful for a person operating a covered platform, in or affecting commerce, to restrict or impede the capacity of a business user to access or interoperate with the same platform, operating system, hardware and software features that are available to the covered platform operator's own products, services, or lines of business," according to an early copy of the bill.

"Allowing sideloading would degrade the security of the iOS platform and expose users to serious security risks not only on third-party app stores, but also on the App Store," the Cupertino, California-based technology giant said on its website. "Because of the large size of the iPhone user base and the sensitive data stored on their phones -- photos, location data, health and financial information -- allowing sideloading would spur a flood of new investment into attacks on the platform."

The Courts

French Spyware Bosses Indicted For Their Role In the Torture of Dissidents (technologyreview.com) 29

Senior executives at a French spyware firm have been indicted for the company's sale of surveillance software to authoritarian regimes in Libya and Egypt that resulted in the torture and disappearance of dissidents. MIT Technology Review reports: While high-tech surveillance is a multibillion-dollar industry worldwide, it is rare for companies or individuals to face legal consequences for selling such technologies -- even to notorious dictatorships or other dangerous regimes. But charges in the Paris Judicial Court against leaders at Amesys, a surveillance company that later changed its name to Nexa Technology, claim that the sales to Libya and Egypt over the last decade led to the crushing of opposition, torture of dissidents, and other human rights abuses. The former head of Amesys, Philippe Vannier, and three current and former executives at Nexa technologies were indicted for "complicity in acts of torture" for selling spy technology to the Libyan regime. French media report that Nexa president Olivier Bohbot, managing director Renaud Roques, and former president Stephane Salies face the same charges for surveillance sales to Egypt.

The charges were brought by brought by the Crimes Against Humanity and War Crimes unit of the court, but the case began 10 years ago when Amesys sold its system for listening in on internet traffic to the Libyan dictator Muammar Gaddafi. Six victims of the spying testified in France about being arrested and tortured by the regime, an experience that they say is a direct result of these spying tools. In 2014, the company sold surveillance software to Egyptian president Abdel al-Sisi shortly after he took control of the country in a military coup. The complaints, filed by the International Federation for Human Rights, or FIDH, and the French League for Human Rights, allege that the company did not have government permission to sell its technologies to Libya or Egypt because oversight was weak and at times nonexistent. The claims led to an independent judicial investigation against Amesys/Nexa, which is still ongoing. Next, the judges will decide whether to send the case to criminal court or dismiss it if there is not sufficient evidence -- but the indictment is a major step forward and points toward the prospect that the judges will view the evidence as potentially strong enough to support a criminal trial.

Security

A CCTV Company Is Paying Remote Workers In India To Yell At Armed Robbers (vice.com) 72

An anonymous reader quotes a report from Motherboard: In a short CCTV video, a clerk at a small convenience store can be seen taking a bottle of coffee from a cooler and drinking it. When he returns to the cash register, an unseen person's voice emits from a speaker on the ceiling and interrogates him about whether he scanned and paid for the item. In another video, a cashier is standing behind the counter talking to someone just out of frame. There's a 'ding' sound, and the voice from above questions the cashier about who the other man is -- he's there to give the cashier a ride at the end of his shift -- then orders the man to stand on the other side of the counter.

The videos are just a few examples that Washington-based Live Eye Surveillance uses to demonstrate its flagship product: a surveillance camera system that keeps constant watch over shops and lets a remote human operator intervene whenever they see something they deem suspicious. For enough money -- $399 per month according to one sales email Motherboard viewed -- a person in Karnal, India will watch the video feed from your business 24/7. The monitors "act as a virtual supervisor for the sites, in terms of assuring the safety of the employees located overseas and requesting them to complete assigned tasks," according to a job posting on the company's website. [...] On its website, the company claims several major corporations as customers, including 7-Eleven, Shell, Dairy Queen, and Holiday Inn. Many of those businesses are franchised, and it isn't clear from Live Eye's materials whether the corporations have purchased the surveillance systems or if they've been bought by individual franchise owners.

Security

ADATA Suffers 700 GB Data Leak In Ragnar Locker Ransomware Attack (bleepingcomputer.com) 21

An anonymous reader quotes a report from BleepingComputing: The Ragnar Locker ransomware gang have published download links for more than 700GB of archived data stolen from Taiwanese memory and storage chip maker ADATA. A set of 13 archives, allegedly containing sensitive ADATA files, have been publicly available at a cloud-based storage service, at least for some time. [...] Two of the leaked archives are quite large, weighing over 100GB, but several of them that could have been easily downloaded are less than 1.1GB large. Per the file metadata published by the threat actor, the largest archive is close to 300GB and its name gives no clue about what it might contain. Another large one is 117GB in size and its name is just as nondescript as in the case of the first one (Archive#2). Judging by the names of the archives, Ragnar Locker likely stole from ADATA documents containing financial information, non-disclosure agreements, among other type of details.

The ransomware attack on ADATA happened on May 23rd, 2021, forcing them to take systems offline, the company told BleepingComputer. As the Ragnar Locker leak clearly shows, ADATA did not pay the ransom and restored the affected systems on its own. The ransomware actor claims stealing 1.5TB of sensitive files before deploying the encryption routine, saying that they took their time in the process because of the poor network defenses. The recently leaked batch of archives is the second one that Ragnar Locker ransomware publishes for ADATA. The previous one was posted earlier this month and includes four small 7-zip archives (less than 250MB together) that can still be downloaded.

Microsoft

Microsoft Fights Back Against Windows 11 Leak 96

Mark Wilson writes: Just a few days ago -- before it has even been officially announced -- Windows 11 leaked online and remains available to download from numerous sites. The Windows 11 ISO torrent spread like wildfire, and now Microsoft is fighting back. The company has issued a slew of DMCA takedown notices to various sites it says are distributing "a leaked copy of the unreleased Windows 11." Unsurprisingly, an article entitled "How to Download and Install Windows 11 Right Now" caught the eyes of Microsoft lawyers. The company has issued a slew of DMCA takedown notices to various sites it says are distributing "a leaked copy of the unreleased Windows 11." Unsurprisingly, an article entitled "How to Download and Install Windows 11 Right Now" caught the eyes of Microsoft lawyers.
Crime

How Cybercriminals Almost Stole $1 Billion From Bangladesh's National Bank (bbc.com) 49

"In 2016 North Korean hackers planned a $1bn raid on Bangladesh's national bank," reports the BBC, "and came within an inch of success — it was only by a fluke that all but $81m of the transfers were halted, report Geoff White and Jean H Lee...

"It all started with a malfunctioning printer..." It was located inside a highly secure room on the 10th floor of the bank's main office in Dhaka, the capital. Its job was to print out records of the multi-million-dollar transfers flowing in and out of the bank. When staff found it wasn't working, at 08:45 on Friday 5 February 2016, "we assumed it was a common problem just like any other day," duty manager Zubair Bin Huda later told police. "Such glitches had happened before." In fact, this was the first indication that Bangladesh Bank was in a lot of trouble. Hackers had broken into its computer networks, and at that very moment were carrying out the most audacious cyber-attack ever attempted. Their goal: to steal a billion dollars.

To spirit the money away, the gang behind the heist would use fake bank accounts, charities, casinos and a wide network of accomplices.... When the bank's staff rebooted the printer, they got some very worrying news. Spilling out of it were urgent messages from the Federal Reserve Bank in New York — the "Fed" — where Bangladesh keeps a US-dollar account. The Fed had received instructions, apparently from Bangladesh Bank, to drain the entire account — close to a billion dollars. The Bangladeshis tried to contact the Fed for clarification, but thanks to the hackers' very careful timing, they couldn't get through... The bank's HQ in Dhaka was beginning two days off. And when the Bangladeshis began to uncover the theft on Saturday, it was already the weekend in New York... And the hackers had another trick up their sleeve to buy even more time. Once they had transferred the money out of the Fed, they needed to send it somewhere. So they wired it to accounts they'd set up in Manila, the capital of the Philippines. And in 2016, Monday 8 February was the first day of the Lunar New Year, a national holiday across Asia...

They had had plenty of time to plan all of this, because it turns out the Lazarus Group had been lurking inside Bangladesh Bank's computer systems for a year... Once inside the bank's systems, Lazarus Group began stealthily hopping from computer to computer, working their way towards the digital vaults and the billions of dollars they contained... But they still had one final hurdle to clear — the printer on the 10th floor. Bangladesh Bank had created a paper back-up system to record all transfers made from its accounts. This record of transactions risked exposing the hackers' work instantly. And so they hacked into the software controlling it and took it out of action.

With their tracks covered, at 20:36 on Thursday 4 February 2016, the hackers began making their transfers — 35 in all, totalling $951m, almost the entire contents of Bangladesh Bank's New York Fed account.

There's more to the story — it's a whole episode on a 10-episode BBC World Service podcast which they're calling an example of "the new front line in a global battleground: a murky nexus of crime, espionage and nation-state power-mongering. And it's growing fast."

The story has a surprise ending — but alongo the way, the BBC's article points out that the consequences for the bank's governor were almost instant. "He was asked to resign," says U.S.-based cyber-security expert Rakesh Asthana. "I never saw him again."
United States

Report: Hackers Breached More US Water Treatment Plants (nbcnews.com) 66

"On January 15, a hacker tried to poison a water treatment plant that served parts of the San Francisco Bay Area," reports NBC News: It didn't seem hard. The hacker had the username and password for a former employee's TeamViewer account, a popular program that lets users remotely control their computers, according to a private report compiled by the Northern California Regional Intelligence Center in February and seen by NBC News. After logging in, the hacker, whose name and motive are unknown and who hasn't been identified by law enforcement, deleted programs that the water plant used to treat drinking water.

The hack wasn't discovered until the following day, and the facility changed its passwords and reinstalled the programs. "No failures were reported as a result of this incident, and no individuals in the city reported illness from water-related failures," the report, which did not specify which water treatment plant had been breached, noted.

The incident, which has not been previously reported, is one of a growing number of cyberattacks on U.S. water infrastructure that have recently come to light. The Bay Area attack was followed by a similar one in Oldsmar, Florida, a few weeks later. In that one, which made headlines around the world, a hacker also gained access to a TeamViewer account and raised the levels of lye in the drinking water to poisonous levels. An employee quickly caught the computer's mouse moving on its own, and undid the hacker's changes... The usernames and passwords for at least 11 Oldsmar employees have been traded on the dark web, said Kent Backman, a researcher at the cybersecurity company Dragos...

[A] number of facilities have been hacked in the past year, though most draw little attention. In Pennsylvania, a state water warning system has reportedly alerted its members to two recent hacks at water plants in the state. In another previously unreported hack, the Camrosa Water District in Southern California was infected with ransomware last summer. Whether hacks on water plants have recently become more common or just more visible is impossible to tell, because there is no comprehensive federal or industry accounting of water treatment plants' security... Unlike the electric grid, which is largely run by a smaller number of for-profit corporations, most of the more than 50,000 drinking water facilities in the U.S. are nonprofit entities.

Some that serve large populations are larger operations with dedicated cybersecurity staff. But rural areas in particular often get their water from small plants, often run by only a handful of employees who aren't dedicated cybersecurity experts, said Bryson Bort, a consultant on industrial cybersecurity systems. "They're even more fragmented at lower levels than anything we're used to talking about, like the electric grid," he said. "If you could imagine a community center run by two old guys who are plumbers, that's your average water plant."

NBC News also a spokesperson for America's Cybersecurity and Infrastructure Security Agency, who shared an internal survey conducted earlier this year. As many as 1 in 10 water and wastewater plants reported they'd recently found a critical cybersecurity vulnerability — and more than 80% of their major vulnerabilities were software flaws discovered before 2017.

Slashdot Top Deals