Security

Hackers Breached Colonial Pipeline Using Compromised Password (bloomberg.com) 112

An anonymous reader quotes a report from Bloomberg: The hack that took down the largest fuel pipeline in the U.S. and led to shortages across the East Coast was the result of a single compromised password, according to a cybersecurity consultant who responded to the attack. Hackers gained entry into the networks ofColonial Pipeline Co.on April 29 through a virtual private network account, which allowed employees to remotely access the company's computer network, said Charles Carmakal, senior vice president at cybersecurity firm Mandiant, part of FireEye Inc., in an interview. The account was no longer in use at the time of the attack but could still be used to access Colonial's network, he said.

The account's password has since been discovered inside a batch of leaked passwords on the dark web. That means a Colonial employee may have used the same password on another account that was previously hacked, he said. However, Carmakal said he isn't certain that's how hackers obtained the password, and he said investigators may never know for certain how the credential was obtained. The VPN account, which has since been deactivated, didn't use multifactor authentication, a basic cybersecurity tool, allowing the hackers to breach Colonial's network using just a compromised username and password. It's not known how the hackers obtained the correct username or if they were able to determine it on their own. "We did a pretty exhaustive search of the environment to try and determine how they actually got those credentials," Carmakal said. "We don't see any evidence of phishing for the employee whose credentials were used. We have not seen any other evidence of attacker activity before April 29."

A little more than one week later, on May 7, an employee in Colonial's control room saw a ransom note demanding cryptocurrency appear on a computer just before 5 a.m. The employee notified an operations supervisor who immediately began to start the process of shutting down the pipeline, Colonial Chief Executive Officer Joseph Blount said in an interview. By 6:10 a.m., the entire pipeline had been shut down, Blount said. It was the first time Colonial had shut down the entirety of its gasoline pipeline system in its 57-year history, Blount said. "We had no choice at that point," he said. "It was absolutely the right thing to do. At that time, we had no idea who was attacking us or what their motives were."

Security

FreakOut Malware Worms Its Way Into Vulnerable VMware Services (bleepingcomputer.com) 16

A multi-platform Python-based malware targeting Windows and Linux devices has now been upgraded to worm its way into Internet-exposed VMware vCenter servers unpatched against a remote code execution vulnerability. BleepingComputer reports: The malware, dubbed FreakOut by CheckPoint researchers in January (aka Necro and N3Cr0m0rPh), is an obfuscated Python script designed to evade detection using a polymorphic engine and a user-mode rootkit that hides malicious files dropped on compromised systems. FreakOut spreads itself by exploiting a wide range of OS and apps vulnerabilities and brute-forcing passwords over SSH, adding the infected devices to an IRC botnet controlled by its masters. The malware's core functionality enables operators to launch DDoS attacks, backdoor infected systems, sniff and exfiltrate network traffic, and deploy XMRig miners to mine for Monero cryptocurrency.

As Cisco Talos researchers shared in a report published today, FreakOut's developers have been hard at work improving the malware's spreading capabilities since early May, when the botnet's activity has suddenly increased. "Although the bot was originally discovered earlier this year, the latest activity shows numerous changes to the bot, ranging from different command and control (C2) communications and the addition of new exploits for spreading, most notably vulnerabilities in VMWare vSphere, SCO OpenServer, Vesta Control Panel and SMB-based exploits that were not present in the earlier iterations of the code," Cisco Talos security researcher Vanja Svajcer said. FreakOut bots scan for new systems to target either by randomly generating network ranges or on its masters' commands sent over IRC via the command-and-control server. For each IP address in the scan list, the bot will try to use one of the built-in exploits or log in using a hardcoded list of SSH credentials.

Privacy

Startup Stealth Data Working To Uncover the Identities of Website Users (bizjournals.com) 111

An anonymous reader writes: Data mining startup Stealth Data is working to help websites uncover the "individual names, phone numbers, emails and physical addresses" of the users who visit websites. This information "can include a website visitor's job title, employer, annual income, age, and personal and professional social media profiles" so that businesses can use this data for marketing purposes.

Stealth Data's third co-founder Chad Sneed experienced marketing frustrations firsthand through his family's dealership, Dennis Sneed Ford in Gower, Missouri. Sneed, who's a vice president and partner, said the dealership spends a significant amount on marketing, from search engines to third-party advertising. A bulk of the dealership's website visitors were anonymous, however, which meant it couldn't follow-up with visitors to try and close a sale. Sneed wanted to unlock that information and started talking to the dealership's outside marketing firm, Phame Influence, to see if it was possible. Puckett, who co-founded Phame with Paris, also is a trial lawyer.

"My lawyer hat instantly says no," Puckett said.

But after digging further, he discovered it's legal and that using the information for cold calling and emailing is fair game.

Co-founder Chad Sneed noted that he doesn't see any privacy issues.


Chrome

Google To Warn of Chrome Extensions From New or Untrusted Developers (therecord.media) 13

Google says it will scan the extensions users install in their Chrome browsers and warn users if they are adding an extension from a new or untrusted developer. From a report: The new extension scanning feature will be part of a Google security feature called Enhanced Safe Browsing, which Google added to Chrome in May last year. Google says trusted developers are those who adhere to the Chrome Web Store Developer Program Policies. "For new developers, it will take at least a few months of respecting these conditions to become trusted," the browser maker said in a blog post today. Currently, Google said that almost 75% of all extensions hosted on the Chrome Web Store were developed by "trusted developers." For the rest, the browser will show an alert like the one below if users had enabled Enhanced Safe Browsing in their Chrome settings page.
Security

Live Streams Go Down Across Cox Radio and TV Stations in Apparent Ransomware Attack (therecord.media) 33

Catalin Cimpanu, reporting at Record: Live streams for radio and TV stations owned by the Cox Media Group, one of the largest media conglomerates in the US, have gone down earlier today in what multiple sources have described as a ransomware attack. The incident took place earlier this morning and impacted live streaming capabilities for the Cox radio and TV stations. Official websites, telephone lines, and other IT systems remained running. While live streams for most of the impacted TV stations have now returned online, most of the Cox radio streams are still offline at the time of writing.
Security

Fujifilm Becomes the Latest Victim of a Network-Crippling Ransomware Attack (techcrunch.com) 39

Japanese multinational conglomerate Fujifilm has been forced to shut down parts of its global network after falling victim to a suspected ransomware attack. From a report: The company, which is best known for its digital imaging products but also produces high-tech medical kit, including devices for rapid processing of COVID-19 tests, confirmed that its Tokyo headquarters was hit by a cyberattack on Tuesday evening. "Fujifilm Corporation is currently carrying out an investigation into possible unauthorized access to its server from outside of the company. As part of this investigation, the network is partially shut down and disconnected from external correspondence," the company said in a statement posted to its website. "We want to state what we understand as of now and the measures that the company has taken. In the late evening of June 1, 2021, we became aware of the possibility of a ransomware attack. As a result, we have taken measures to suspend all affected systems in coordination with our various global entities," it said.
United States

Supreme Court Narrows Scope of CFAA Computer Hacking Law (therecord.media) 79

The United States Supreme Court has ruled today in a 6-3 vote to overturn a hacking-related conviction for a Georgia police officer, and by doing so, it also narrowed down the scope of the US' primary hacking law, the Computer Fraud and Abuse Act. From a report: The ruling, No. 19-783, comes in the Van Buren v. United States case of Nathan Van Buren, a former police sergeant in Cumming, Georgia, who was sentenced to 18 months in prison in May 2018 for taking a bribe of $5,000 to look up a license plate for a woman one of his informants met at a local strip club. Prosecutors charged Van Buren under the CFAA and argued that even if the police officer had been authorized to access the police database as part of his work duties, he "exceeded authorized access" when he performed a search against department internal policies. In subsequent appeals, Van Buren argued that the "exceeds authorized access" language in the CFAA was too broad and requested that the US Supreme Court rule on the matter, in a case the court decided to pick up and heard arguments last year.
Security

Russian Cybercriminal Group Was Behind Meat Plant Attack, FBI Says (nytimes.com) 69

An anonymous reader quotes a report from The New York Times: The perpetrators of a ransomware attack that shut down some operations at the world's largest meat processor this week was a Russian-based cybercriminal group known for its attacks on prominent American companies, the F.B.I. said Wednesday. The group, known as REvil, is one of the most prolific of the roughly 40 ransomware organizations that cybersecurity experts track and has been identified as responsible for a coordinated strike against operations in almost two dozen Texas cities in 2019. The group is among dozens of ransomware groups that enjoy safe harbor in Russia, where they are rarely arrested or extradited for their crimes.

REvil, which stands for Ransomware Evil, is known as a "ransomware as a service" organization, meaning it leases its ransomware to other criminals, even the technically inept. One of its previous affiliates was a group called DarkSide, which was responsible for the ransomware attack last month on Colonial Pipeline, a conduit for nearly half the gas and jet fuel to the East Coast. DarkSide is believed to have split off from REvil last year. REvil is considered one of the most sophisticated ransomware groups and has demanded as much as $50 million to recover data belonging to companies as prominent as Apple. Its attack on JBS, a Brazilian company that accounts for roughly a fifth of cattle and hog slaughter in the United States, temporarily shut down some operations at a time when prices were already surging for beef, poultry and pork.
Jen Psaki, the White House press secretary, declined to say whether the U.S. government was planning to retaliate. "We're not taking any options off the table in terms of how we may respond, but of course there is an internal policy review process to consider that," she said. The administration is planning to bring up the issue with President Vladimir Putin of Russia when they meet in two weeks.

"Responsible states do not harbor ransomware criminals," she added.
Google

Google Chrome's Top Web App Advocate Resigns (cnet.com) 52

Google is losing one of its strongest champions of the web. Alex Russell, who has led the Fugu project to make web apps as powerful as those running on Google's Android or Apple's iOS software, is leaving the company on Wednesday. From a report: Russell announced his departure on Twitter. He's not quitting in anger or being pushed out. But after 12 years at Google pushing his vision for a more powerful web, "I need some time off," he said in an interview. Russell has been an outspoken advocate for the web, using Chrome's dominant position to help test and introduce new abilities that let programmers build interactive apps on the web, not just relatively static websites. Project Fugu embodies this effort, as does the broader progressive web app, or PWA, movement that lets you install and launch web apps more like those that run natively on smartphones and PCs.
Security

Ransomware Attack Disrupts Massachusetts Ferries (therecord.media) 35

A ransomware attack has caused delays and disruptions at Steamship Authority, the largest ferry service in Massachusetts, and has disrupted ferry transports between mainland US and the Martha's Vineyard and Nantucket islands. From a report: The attack took place earlier today, according to a series of tweets posted on the company's official Twitter account. Steamship Authority said the incident impacted its land-based IT systems and that ships are not impacted. "There is no impact to the safety of vessel operations, as the issue does not affect radar or GPS functionality," a Steamship Authority spokesperson said.

"Scheduled trips to both islands continue to operate, although customers may experience some delays during the ticketing process. Customers are currently unable to book or change vehicle reservations online or by phone. Existing vehicle reservations will be honored at Authority terminals, and rescheduling and cancellation fees will be waived," it added. The company has asked travelers to come prepared with cash on hand as "availability of credit card systems to process vehicle and passenger tickets, as well as parking lot fees, is limited."

Security

Poisoned Installers Found In SolarWinds Hackers Toolkit (securityweek.com) 16

wiredmikey shares a report from SecurityWeek: The ongoing multi-vendor investigations into the SolarWinds mega-hack took another twist this week with the discovery of new malware artifacts that could be used in future supply chain attacks. According to a new report, the latest wave of attacks being attributed to APT29/Nobelium threat actor includes a custom downloader that is part of a "poisoned update installer" for electronic keys used by the Ukrainian government. SentinelOne principal threat researcher Juan Andres Guerrero-Saade documented the latest finding in a blog post that advances previous investigations from Microsoft and Volexity. "At this time, the means of distribution [for the poisoned update installer] are unknown. It's possible that these update archives are being used as part of a regionally-specific supply chain attack," Guerrero-Saade said.
Security

Top Meat Supplier is the Latest Victim of a Cyberattack (axios.com) 45

Major meat supplier JBS USA was the latest victim of an organized cybersecurity attack, with servers in North American and Australian affected, the company said Sunday. From a report: Why it matters: JBS USA is the largest producer of beef in the country, The Hill notes, and also is a major supplier of poultry and pork. The disclosure of the attack comes as cyber threats have picked up over the last year. Last month, Colonial Pipeline was taken offline by its operator because of a cyberattack.

In March, a cyber-espionage unit backed by the Chinese government resulted in 30,000 U.S. victims, including many small businesses and local governments. Earlier this year, the U.S. intelligence community assessed that Russia was responsible for the major SolarWinds attack. Nine federal agencies and more than 100 private sector groups were compromised in the attack, per the Hill.

IT

Xiaomi Shows Off Phone That Can Charge To 100% In 8 Minutes (mashable.com) 124

Xiaomi's at it again: The company's new fast charging technology can get a smartphone from 0 to 100 percent battery in less than 8 minutes. From a report: The 200W wired charging tech, used on a modified Xiaomi MI 11 Pro with a 4,000mAh battery, gets the phone from 0-10% in just 44 seconds. The phone gets to 50% in 3 minutes, and it's fully charged in 7:57 minutes. In a YouTube video, Xiaomi also showcased its 120W wireless charging tech, which gets a smartphone with a 4,000mAh battery from 0 to 100 percent battery in 15 minutes.
Privacy

NSA Spied on European Politicians Through Danish Telecommunications Hub (therecord.media) 40

Denmark's foreign secret service allowed the US National Security Agency to tap into a crucial internet and telecommunications hub in Denmark and spy on the communications of European politicians, a joint investigation by some of Europe's biggest news agencies revealed on Sunday. From a report: The covert spying operation, called Operation Dunhammer, took place between 2012 and 2014, based on a secret partnership signed by the two agencies. The secret pact, signed between the NSA and the Danish Defense Intelligence Service (Danish: Forsvarets Efterretningstjeneste, FE) allowed US spies to deploy a data interception system named XKeyscore on the network of Sandagergardan, an important internet and communications hub in the city of Dragor, near Copenhagen, where several key submarine cables connected Denmark (and continental Europe) to the Scandinavian peninsula.

The NSA allegedly used XKeyscore to mass-sniff internet and mobile traffic and intercept communications such as emails, phone calls, SMS texts, and chat messages sent to the phone numbers and email addresses of European politicians. The covert operation abruptly stopped in 2014 after Danish government officials learned of the NSA-FE collaboration following the Snowden leaks. Danish officials put a stop to the operation after they learned that the NSA had also spied on Danish government members.

Google

Quic Gives the Internet's Data Transmission Foundation a Needed Speedup (cnet.com) 80

One of the internet's foundations just got an upgrade. From a report: Quic, a protocol for transmitting data between computers, improves speed and security on the internet and can replace Transmission Control Protocol, or TCP, a standard that dates back to Ye Olde Internet of 1974. Last week, the Internet Engineering Task Force, which sets many standards for the global network, published Quic as a standard. Web browsers and online services have been testing the technology for years, but the IETF's imprimatur is a sign the standard is mature enough to embrace fully.

It's extremely hard to improve the internet at the fundamental level of data transmission. Countless devices, programs and services are built to use the earlier infrastructure, which has lasted decades. Quic has been in public development for nearly eight years since Google first announced Quic in 2013 as an experimental addition to its Chrome browser. But upgrades to the internet's foundations are crucial to keep the world-spanning communication and commerce backbone humming. That's why engineers spend so much effort on titanic transitions like Quic, HTTPS for secure website communications, post-quantum cryptography to protect data from future quantum computers, and IPv6 for accommodating vastly more devices on the internet.

Government

Will America Confront the Kremlin Over SolarWinds' Latest Massive Phishing Attack? (apnews.com) 64

In the latest SolarWinds mass-phishing attack, "The highest percentage of emails went to the United States, but [incident response firm] Volexity also saw a significant number of victims in Europe..." according to Security Week.

In an article shared by Slashdot reader wiredmikey, they note that the attackers apparently compromised the Constant Contact account of USAID, an independent agency of the United States federal government that is primarily responsible for administering civilian foreign aid and development assistance — and then impersonated it in emails "to roughly 3,000 accounts across over 150 organizations in 24 countries."

So what happens next?

The Associated Press reports: The White House says it believes U.S. government agencies largely fended off the latest cyberespionage onslaught blamed on Russian intelligence operatives, saying the spear-phishing campaign should not further damage relations with Moscow ahead of next month's planned presidential summit. Officials downplayed the cyber assault as "basic phishing" in which hackers used malware-laden emails to target the computer systems of U.S. and foreign government agencies, think tanks and humanitarian groups.

Microsoft, which disclosed the effort late Thursday, said it believed most of the emails were blocked by automated systems that marked them as spam. As of Friday afternoon, the company said it was "not seeing evidence of any significant number of compromised organizations at this time."

Even so, the revelation of a new spy campaign so close to the June 16 summit between President Joe Biden and Russian counterpart Vladimir Putin adds to the urgency of White House efforts to confront the Kremlin over aggressive cyber activity that criminal indictments and diplomatic sanctions have done little to deter. "I don't think it'll create a new point of tension because the point of tension is already so big," said James Lewis, a senior vice president at the Center for Strategic and International Studies. "This clearly has to be on the summit agenda. The president has to lay down some markers" to make clear "that the days when you people could do whatever you want are over."

There's a famous story about Vladimir Putin meeting Joe Biden back in 2011. A decade earlier former U.S. president George W. Bush had said when he'd looked Putin in the eye, "I was able to get a sense of his soul." But as Biden tells it, when he'd met Putin (who was then Russia Prime Minister), "I said, 'Mr. Prime Minister, I'm looking into your eyes, and I don't think you have a soul.'"

"He looked back at me, and he smiled, and he said, 'We understand one another.'"
Government

With 'Massive' Cybersecurity Labor Shortage, Will Corporations Compete with Local Governments? (cnn.com) 83

it's high time for companies to start adding cybersecurity professionals to their teams, reports CNN. "The only hitch: There's a massive, longstanding labor shortage in the cybersecurity industry." "It's a talent war," said Bryan Orme, principal at GuidePoint Security. "There's a shortage of supply and increased demand."

Experts have been tracking the cybersecurity labor shortage for at least a decade — and now, a new surge in companies looking to hire following recent attacks could exacerbate the problem. The stakes are only growing, as technology evolves and bad actors become more advanced. In the United States, there are around 879,000 cybersecurity professionals in the workforce and an unfilled need for another 359,000 workers, according to a 2020 survey by (ISC)2, an international nonprofit that offers cybersecurity training and certification programs. Globally, the gap is even larger at nearly 3.12 million unfilled positions, the group says... The U.S. Bureau of Labor Statistics projects "information security analyst" will be the 10th fastest growing occupation over the next decade, with an employment growth rate of 31% compared to the 4% average growth rate for all occupations.

If demand for cybersecurity professionals in the private sector increases dramatically, some experts say talented workers could leave the government for more lucrative corporate jobs — a risk that is especially acute for smaller, local government agencies that manage critical infrastructure in their communities but have limited budgets. "Think of the criticality of what your local government does: water purification, waste treatment, traffic management, communications for law enforcement, public safety, emergency management," said Mike Hamilton, chief information security officer at Critical Insight. "But Amazon is out there waving around bags of cash to protect their retail operation." Hamilton — who was the former chief information security officer for Seattle, Washington, from 2006 to 2013 — added that local governments "cannot attract and retain these people when the competition for them is so high, which is why we've got to make lots of them."

The article notes educational training/up-skilling programs working to address the shortage, including GuidePoint, which helps train veterans leaving the military for cybersecurity careers. CNN also notes U.S. President Joe Biden's $2 trillion American Jobs Plan included $20 billion for state, local and tribal governments to update and improve cybersecurity controls for their energy systems.

"Still, experts say more needs to be done, suggesting a broad rethinking of education systems from elementary school through higher education to include more cybersecurity training."
IT

Twitch Warns Streamers Another Wave of Copyright Strikes is Coming (theverge.com) 63

Twitch has received a "batch" of new takedown notices from music publishers over copyrighted songs in recorded streams (known as VODs), the company said in an email to streamers today. From a report: The notice may be worrying for some streamers who were affected by the waves of takedowns that hit last year, because if a user gets three copyright strikes on their channel, they will be permanently banned from the platform, according to Twitch's policies. With this advance warning, it seems Twitch is trying to get ahead of a sudden flurry of takedowns and give streamers some time to remove potentially offending VODs.

"We recently received a batch of DMCA takedown notifications with about 1,000 individual claims from music publishers," Twitch said in an email Friday, which was sent to a Verge staffer. "All of the claims are for VODs, and the vast majority target streamers listening to background music while playing video games or IRL streaming." [...] In Friday's email, Twitch noted that the only way to avoid DMCA (or Digital Millennium Copyright Act) strikes is to not stream copyrighted material in the first place, and said that if a streamer does have unauthorized content in their VODs or clips, "we strongly recommend that you permanently delete anything that contains that material."

China

Days Before a Report, Chinese Hackers Removed Malware From Infected Networks 28

An anonymous reader shares a report: Last month, security firm FireEye detected a Chinese hacking campaign that exploited a zero-day vulnerability in Pulse Secure VPN appliances to breach defense contractors and government organizations in the US and across Europe. The hacking campaign allowed the threat actors -- two groups which FireEye tracks as UNC2630 and UNC2717 -- to install web shells on Pulse Secure devices, which the attackers used to pivot to internal networks from where they stole internal network credentials, email communications, and sensitive documents.

But in a follow-up report published today, FireEye said it found something strange -- namely that at least one of the groups involved in the attacks began removing its malware from infected networks three days before its researchers exposed the attacks. "Between April 17th and 20th, 2021, Mandiant incident responders observed UNC2630 access dozens of compromised devices and remove webshells like ATRIUM and SLIGHTPULSE," researchers said on Thursday. The threat actor's actions are highly suspicious and raise questions if they knew of FireEye's probing.
Microsoft

Microsoft Says SolarWinds Hackers Have Struck Again at the US and Other Countries (cnn.com) 24

The hackers behind one of the worst data breaches ever to hit the US government have launched a new global cyberattack on more than 150 government agencies, think tanks and other organizations, according to Microsoft. ytene shares a report: The group, which Microsoft calls "Nobelium," targeted 3,000 email accounts at various organizations this week -- most of which were in the United States, the company said in a blog post Thursday. It believes the hackers are part of the same Russian group behind last year's devastating attack on SolarWinds -- a software vendor -- that targeted at least nine US federal agencies and 100 companies.

Cybersecurity has been a major focus for the US government following the revelations that hackers had put malicious code into a tool published by SolarWinds. A ransomware attack that shut down one of America's most important pieces of energy infrastructure -- the Colonial Pipeline -- earlier this month has only heightened the sense of alarm. That attack was carried out by a criminal group originating in Russia, according to the FBI. Microsoft said that at least a quarter of the targets of this week's attacks were involved in international development, humanitarian, and human rights work, across at least 24 countries. It said Nobelium launched the attack by gaining access to a Constant Contact email marketing account used by the US Agency for International Development.

Slashdot Top Deals