IOS

Apple Is Going To Make It Harder to Hack iPhones With Zero-Click Attacks 60

Apple is going to make one of the most powerful types of attacks on iPhones much harder to pull off in an upcoming update of iOS. From a report: The company quietly made a new change in the way it secures the code running in its mobile operating system. The change is in the beta version of the next iOS version, 14.5, meaning it is currently slated to be added to the final release. Several security researchers who specialize in finding vulnerabilities in and crafting exploits for iOS believe this new mitigation will make it much harder for hackers to take control of an iPhone with a technique known as a zero-click (or 0-click) exploit, which allows a hacker to take over an iPhone with no interaction from the target. Apple also told Motherboard it believes the changes will impact 0-click attacks.

"It will definitely make 0-clicks harder. Sandbox escapes too. Significantly harder," a source who develops exploits for government customers told Motherboard, referring to "sandboxes" which isolate applications from each other in an attempt to stop code from one program interacting with the wider operating system. Motherboard granted multiple exploit developers anonymity to speak more candidly about sensitive industry issues. Like the name suggests, zero-click attacks allow hackers to break into a target without needing the victim to interact with anything, such as a malicious phishing link. This means that the attack is generally harder for the targeted user to detect. These are generally very sophisticated attacks. These attacks may now become much rarer, according to several security researchers who look for vulnerabilities in iOS.
Security

Experian Challenged Over Massive Data Leak in Brazil (zdnet.com) 26

Experian may be in trouble again — this time in Brazil.

ZDNet reports on "the emergence of a leak that exposed the personal data of more than 220 million citizens and companies, which is being offered for sale in the dark web." After receiving feedback from Experian over a massive data leak in Brazil, São Paulo state consumer rights foundation Procon described the company's explanations as "insufficient" and said it is likely that the incident was initiated in a corporate environment...

Security firm PSafe discovered the incident, which exposed all manner of personal details, including information from Mosaic, a consumer segmentation model used by Serasa, Experian's Brazilian subsidiary. Following the emergence of the leak in January, Procon notified the credit bureau, and asked the company for a confirmation of the incident, and an explanation of the reasons that caused the leak, the steps taken to contain it, how it will repair the damage to consumers impacted and the measures taken to prevent it from happening again...

Contacted by ZDNet, Serasa Experian did not answer to requests for comment on Procon's response to its feedback.

The agency's demands for answers follow calls from the Brazilian Institute for Consumer Protection for urgent measures to investigate and punish those responsible for exposing the population's data, as well as improved citizen information and transparency.

Security

Sophisticated New Malware Found on 30,000 Macs Stumps Security Pros (arstechnica.com) 66

Long-time Slashdot reader b0s0z0ku quotes Ars Technica: A previously undetected piece of malware found on almost 30,000 Macs worldwide is generating intrigue in security circles, which are still trying to understand precisely what it does and what purpose its self-destruct capability serves.

Once an hour, infected Macs check a control server to see if there are any new commands the malware should run or binaries to execute. So far, however, researchers have yet to observe delivery of any payload on any of the infected 30,000 machines, leaving the malware's ultimate goal unknown. The lack of a final payload suggests that the malware may spring into action once an unknown condition is met.

Also curious, the malware comes with a mechanism to completely remove itself, a capability that's typically reserved for high-stealth operations. So far, though, there are no signs the self-destruct feature has been used, raising the question why the mechanism exists. Besides those questions, the malware is notable for a version that runs natively on the M1 chip that Apple introduced in November, making it only the second known piece of macOS malware to do so...

The malware has been found in 153 countries with detections concentrated in the US, UK, Canada, France, and Germany.

Red Canary, the security firm that discovered the malware, has named it "Silver Sparrow." Long-time Slashdot reader Nihilist_CE writes: First detected in August of 2020, the Silver Sparrow malware is interesting in several unsettling ways. It uses the macOS Installer Javascript API to launch a bash process to gain a foothold into the user's system, a hitherto-unobserved method for bypassing malware detection. This bash shell is then used to invoke macOS's built-in PlistBuddy tool to create a LaunchAgent which executes a bash script every hour. This is the command and control process, which downloads a JSON file containing (potentially) new instructions.

Besides the novel installation method, Silver Sparrow is also mysterious in its payload: a single, tiny binary that does nothing but open a window reading "Hello, World!" (in v1, which targets Intel Macs) or "You did it!" (in v2, which is an M1-compatible fat binary). These "bystander binaries" are never executed and appear to be proofs-of-concept or placeholders for future functionality.

Microsoft

Microsoft Says SolarWinds Hackers Downloaded Some Azure, Exchange, and Intune Source Code (zdnet.com) 36

Microsoft's security team said today it has formally completed its investigation into its SolarWinds-related breach and found no evidence that hackers abused its internal systems or official products to pivot and attack end-users and business customers. From a report: The OS maker began investigating the breach in mid-December after it was discovered that Russian-linked hackers breached software vendor SolarWinds and inserted malware inside the Orion IT monitoring platform, a product that Microsoft had also deployed internally. In a blog post published on December 31, Microsoft said it discovered that hackers used the access they gained through the SolarWinds Orion app to pivot to Microsoft's internal network, where they accessed the source code of several internal projects. "Our analysis shows the first viewing of a file in a source repository was in late November and ended when we secured the affected accounts," the company said today, in its final report into the SolarWinds-related breach.
Microsoft

New Version of Microsoft Office Won't Require You To Pay For a Subscription (cnet.com) 165

In a company blog post Thursday, Microsoft released more details about the new, flat-price version of its Office productivity software coming later this year. The company emphasized that while its main focus remains in its subscription offering, Microsoft 365, it will release the one-time purchase Office 2021 for those who aren't ready to move to the cloud. From a report: Office 2021 will arrive in two versions: one for commercial users, called Office LTSC (which stands for Long Term Servicing Channel), and one for personal use. Office LTSC will include enhanced accessibility features, performance improvements across Word, Excel and PowerPoint, and visual improvements, like dark mode support across apps. It's meant for specialty situations, as opposed to for an entire organization, such as process control devices on the manufacturing floor that are not connected to the internet. More details about pricing and new features for the commercial version and the personal version will be announced when Office 2021 is closer to general availability. Both will have both Windows and Mac versions, and will ship with the OneNote app. They will also ship both 32- and 64-bit versions, according to the post. Microsoft will support the software for five years, and said it does not plan to change the price at the time of release.
Microsoft

Microsoft Starts Removing Flash From Windows Devices 73

Microsoft has begun deploying this week KB4577586, a Windows update that permanently removes the Adobe Flash Player software from Windows devices. From a report: The update was formally announced last year at the end of October when Microsoft and other browser makers were preparing for the impending Flash end-of-life, scheduled for the end of 2020. According to a support document published at the time, the update was initially supposed to be optional. System administrators who wanted to remove Flash before the EOL date could access the Microsoft Update Catalog, download the KB4577586 packages, and remove Flash to avoid any security-related issues. But this week, multiple Windows 10 users reported that Microsoft is now forcibly installing KB4577586 on their devices and removing Flash support from the OS. While users might think this would cause issues for some enterprises, it actually does not. Last year, Adobe introduced a time bomb in the Flash Player code that prevents the Flash Player app from playing content after January 12.
Security

Suspected Russian Hackers Used US Networks, Official Says (bloomberg.com) 27

A sprawling cyber-attack that compromised popular software created by Texas-based SolarWinds was executed from within the U.S., a top White House official said, though the government believes Russia was responsible. From a report: The federal investigation of the hack will take several months, Deputy National Security Advisor Anne Neuberger said in a briefing for reporters on Wednesday. "As of today, nine federal agencies and about 100 private-sector companies were compromised," Neuberger said. She didn't identify them and said the government hasn't ruled out the possibility of further victims. She said the government believes it's still at the "beginning stages" of understanding the scope and scale of the attack, which was publicly disclosed in December but was likely executed months earlier. "The hackers launched the hack from inside the United States which further made it difficult for the U.S. government to observe their activity," she said. Neuberger is leading the U.S. response to the SolarWinds attack. The Texas-based company's software is used by several government agencies and Fortune 500 companies.
IT

Microsoft Edge Won't Show You Notification Requests Other People Don't Like (theverge.com) 76

Microsoft is trying a new solution for the persistent "would you like to allow notifications from this website" requests that you see across the internet: crowdsourcing data on which ones people block and which ones they allow. From a report: According to a blog post today, Microsoft is calling this feature adaptive notification requests, and the company is rolling it out in Edge 88 after it received positive feedback from testers. For an example of how this works, say there's a website that commonly asks for notifications, and nobody wants them. They'll either ignore the request or click the block button to make sure they never see it again. Microsoft then collects that data and will stop showing new users the notification request in the future.
IT

Fake Amazon Reviews 'Being Sold in Bulk' Online (bbc.com) 91

Fake reviews for products sold on Amazon's Marketplace are being sold online "in bulk", according to Which? The consumer group found 10 websites selling fake reviews from $7 each and incentivising positive reviews in exchange for payment or free products. From a report: It suggested the firm was facing an "uphill struggle" against a "widespread fake reviews industry". An Amazon spokesman said: "We remove fake reviews and take action against anyone involved in abuse." The retail giant's Marketplace allows other retailers to sell their goods via the Amazon website. Which? identified websites offering review services for goods for sale on Amazon Marketplace that violated the firm's terms and conditions. These included "packages" of fake reviews available for sellers to buy for about $21 individually, as well as bulk packages starting at $862 for 50 reviews and going up to $11,130 for 1,000. The group also suggested that five of the businesses it looked at had more than 702,000 "product reviewers" on their books. Product reviewers are offered small payments ranging from a few pounds up to more than $14, alongside free or discounted products. They can even take part in "loyalty schemes" and earn themselves premium goods, from children's toys to exercise equipment.
IT

LastPass' Free Tier Will Become a Lot Less Useful Next Month (theverge.com) 189

LastPass is adding new restrictions to its free subscription tier starting March 16th that'll only allow users to view and manage passwords on one category of devices: mobile or computer. From a report: Mobile users will be limited to iOS and Android phones, iPads, Android tablets, and smartwatches. Computer subscribers will be able to use their passwords from Windows, macOS, and Linux desktops and laptops, the LastPass browser extension, and Windows tablets. Users on LastPass' free tier will be asked to pick between the two options the first time they log in after March 16th, and the company says they'll be able to switch between categories up to three times after they've picked. Although customers are restricted to a single category of devices on the free tier, they'll still be able view and manage passwords from an unlimited number of devices within either the mobile or computer category. LastPass says no users will be locked out of their accounts or lose access to their passwords as a result of the changes. As well as restricting its device types, LastPass is also changing the kinds of customer support free tier users will be able to access. From May 17th, free users will lose access to email support, the company announced.
Security

France Says Russian State Hackers Targeted IT Monitoring Firm Centreon's Servers in Years-Long Campaign (zdnet.com) 24

France's cyber-security agency said that a group of Russian military hackers, known as the Sandworm group, have been behind a three-years-long operation during which they breached the internal networks of several French entities running the Centreon IT monitoring software. From a report: The attacks were detailed in a technical report released today by Agence Nationale de la Securite des Systemes d'Information, also known as ANSSI, the country's main cyber-security agency. "This campaign mostly affected information technology providers, especially web hosting providers," ANSSI officials said today. "The first victim seems to have been compromised from late 2017. The campaign lasted until 2020." The point of entry into victim networks was linked to Centreon, an IT resource monitoring platform developed by French company CENTREON, and a product similar in functionality to SolarWinds' Orion platform. ANSSI said the attackers targeted Centreon systems that were left connected to the internet. The French agency couldn't say at the time of writing if the attacks exploited a vulnerability in the Centreon software or if the attackers guessed passwords for admin accounts. However, in the case of a successful intrusion, the attackers installed a version of the P.A.S. web shell and the Exaramel backdoor trojan, two malware strains that when used together allowed hackers full control over the compromised system and its adjacent network.
Security

270 Addresses Are Responsible for 55% of All Cryptocurrency Money Laundering (zdnet.com) 88

Criminals who keep their funds in cryptocurrency tend to launder funds through a small cluster of online services, blockchain investigations firm Chainalysis said in a report last week. From a report: This includes services like high-risk (low-reputation) crypto-exchange portals, online gambling platforms, cryptocurrency mixing services, and financial services that support cryptocurrency operations headquartered in high-risk jurisdictions. Criminal activity studied in this report included cryptocurrency addresses linked to online scams, ransomware attacks, terrorist funding, hacks, transactions linked to child abuse materials, and funds linked to payments made to dark web marketplaces offering illegal services like drugs, weapons, and stolen data. But while you'd expect that the money laundering resulting from such a broad spectrum of illegal activity to have taken place across a large number of services, Chainalysis reports that just a small group of 270 blockchain addresses have laundered around 55% of cryptocurrency associated with criminal activity.
Security

SolarWinds Hack Was 'Largest and Most Sophisticated Attack' Ever, Microsoft President Says (reuters.com) 66

A hacking campaign that used a U.S. tech company as a springboard to compromise a raft of U.S. government agencies is "the largest and most sophisticated attack the world has ever seen," Microsoft Corp President Brad Smith said. From a report: The operation, which was identified in December and that the U.S. government has said was likely orchestrated by Russia, breached software made by SolarWinds Corp, giving hackers access to thousands of companies and government offices that used its products. The hackers got access to emails at the U.S. Treasury, Justice and Commerce departments and other agencies. Cybersecurity experts have said it could take months to identify the compromised systems and expel the hackers. "I think from a software engineering perspective, it's probably fair to say that this is the largest and most sophisticated attack the world has ever seen," Smith said during an interview that aired on Sunday on the CBS program "60 Minutes." The breach could have compromised up to 18,000 SolarWinds customers that used the company's Orion network monitoring software, and likely relied on hundreds of engineers.
Open Source

Should You Block Connections to Your Network From Foreign Countries? (linuxsecurity.com) 134

Slashdot reader b-dayyy quotes the Linux Security blog: What if you could block connections to your network in real-time from countries around the world such as Russia, China and Brazil where the majority of cyberattacks originate? What if you could redirect connections to a single network based on their origin? As you can imagine, being able to control these things would reduce the number of attack vectors on your network, improving its security. You may be surprised that this is not only possible, but straightforward and easy, by implementing GeoIP filtering on your nftables firewall with GeoIP for nftables.

GeoIp for nftables is a simple and flexible Bash script released in December of 2020 designed to perform automated real-time filtering using nftables firewalls based on the IP addresses for a particular region. In a recent interview with LinuxSecurity researchers, the project's lead developer Mike Baxter explained the mission of GeoIP for nftables, "I hope this project is beneficial to those who may not have the IT budget or resources to implement a commercial solution. The code runs well on servers, workstations and low-power systems like Raspberry Pi. The script has the built-in ability to flush and refill GeoIP sets after a database update without restarting the firewall, allowing servers to run uninterrupted without dropping established connections."

This article will examine the concept of GeoIP filtering and how it could add a valuable layer of security to your firewall, and will then explore how the GeoIP for nftables project is leveraging Open Source to provide intuitive, customizable GeoIP filtering on Linux.

AI

AI Is Being Used to Screen Job Applicants (bbc.com) 147

The BBC reports on "the computers rejecting your job application," noting that applicants are now being screened with AI-scored tests that involve counting dots in boxes and matching emotions to facial expressions: The questions, and your answers to them, are designed to evaluate several aspects of a jobseeker's personality and intelligence, such as your risk tolerance and how quickly you respond to situations. Or as Pymetrics puts it, "to fairly and accurately measure cognitive and emotional attributes in only 25 minutes".

Its AI software is now used in the initial recruitment processes of a number of multinational companies, such as McDonald's, bank JP Morgan, accountancy firm PWC, and food group Kraft Heinz. An interview with a human recruiter then follows if you pass. "It's about helping firms process a much wider pool [of applicants], and getting signals that someone will be successful in a job," says Pymetrics founder Frida Polli...

Another provider of AI recruitment software is Utah-based HireVue. Its AI system records videos of job applicants answering interview questions via their laptop's webcam and microphone. The audio of this is then converted into text, and an AI algorithm analyses it for key words, such as the use of "I" instead of "we" in response to questions about teamwork. The recruiting company can then choose to let HireVue's system reject candidates without having a human double-check, or have the candidate moved on for a video interview with an actual recruiter.

HireVue says that by September 2019 it had conducted a total of 12 million interviews, of which 20% were via the AI software. The remaining 80% were with a human interviewer on the other end of a video screen. The overall figure has now risen to 19 million, with the same percentage split. HireVue first started offering the AI interviews in 2016. Its users include travel services firm Sabre.

Meanwhile, a report from 2019 said that such is the growth in the use of AI that it will replace 16% of recruitment sector jobs before 2029.

Security

The Long Hack: How China Exploited a U.S. Tech Supplier (bloomberg.com) 104

Supermicro chips and software were tampered with by Chinese operatives in the past decade, Bloomberg reported Friday, doubling down on its 2018 report that was widely disputed by several tech giants and government agencies. Today's report says that U.S. security and defense officials knew of the hack but kept it secret in an effort to learn more about China's hacking capabilities. From the report: Bloomberg Businessweek first reported on China's meddling with Supermicro products in October 2018, in an article that focused on accounts of added malicious chips found on server motherboards in 2015. That story said Apple and Amazon.com had discovered the chips on equipment they'd purchased. Supermicro, Apple and Amazon publicly called for a retraction. U.S. government officials also disputed the article.

With additional reporting, it's now clear that the Businessweek report captured only part of a larger chain of events in which U.S. officials first suspected, then investigated, monitored and tried to manage China's repeated manipulation of Supermicro's products. Throughout, government officials kept their findings from the general public. Supermicro itself wasn't told about the FBI's counterintelligence investigation, according to three former U.S. officials. The secrecy lifted occasionally, as the bureau and other government agencies warned a select group of companies and sought help from outside experts.
Some stories from 2018 that capture the reaction of the industry to Bloomberg's earlier piece:

Amazon Has Pulled Ads From Bloomberg Over Controversial 'Big Hack' Chinese Spy Story; Apple Has Not Invited Outlet's Reporters To a Product Event;
In an Unprecedented Move, Apple CEO Tim Cook Calls For Bloomberg To Retract Its Chinese Spy Chip Story;
Bloomberg is Still Reporting on Challenged Story Regarding China Hardware Hack.
Security

CD Projekt Red Hackers Reportedly Sold the 'Cyberpunk 2077' Source Code (engadget.com) 54

The hackers behind this week's ransomware attack on Cyberpunk 2077 studio CD Projekt Red appear to have found a buyer for the stolen data. Engadget reports: They ran an auction on a hacking forum but, as The Verge notes, they shut it down after reportedly accepting an offer from elsewhere. The starting price for the auction was said to be $1 million and there was the option for an interested party with a spare $7 million to buy the data outright. It's not clear who has acquired the data, how much they paid for it or what they're planning to do with the information.
Facebook

Proofpoint Sues Facebook To Get Permission To Use Lookalike Domains For Phishing Tests (zdnet.com) 32

Cyber-security powerhouse Proofpoint has filed a lawsuit this week against Facebook in relation to the social network's attempt to confiscate domain names the security firm was using for phishing awareness training. From a report: The case is a countersuit to a Facebook filing from November 30, 2020, when the social network used a UDRP (Uniform Domain-Name Dispute-Resolution) request to force domain name registrar Namecheap to hand over several domain names that were mimicking Facebook and Instagram brands. Among the listed domain names were the likes of facbook-login.com, facbook-login.net, instagrarn.ai, instagrarn.net, and instagrarn.org.

In court documents filed on Tuesday, Proofpoint said the UDRP should not apply to these domains, which it should be allowed to keep and continue using. Proofpoint argues that UDRP requests should only be used for domains registered in bad faith. The security firm instead says its use of the Facebook and Instagram lookalike domains "has been in good faith and for a legitimate purpose." Proofpoint claims its phishing awareness tests are crucial for the security of its customers, but also for the security of Facebook itself, as the phishing awareness tests teach users to recognize Facebook and Instagram lookalike domains and phishing attacks -- something that Facebook also benefits from, although indirectly.

Iphone

Apple Privacy Chief: North Dakota Bill 'Threatens To Destroy the iPhone As You Know It' (macrumors.com) 321

The North Dakota Senate recently introduced a new bill that would prevent Apple and Google from requiring developers to use their respective app stores and payment methods, paving the way for alternative app store options.

In response, Apple Chief Privacy Engineer Erik Neuenschwander said that it "threatens to destroy the iPhone as you know it" by requiring changes that would "undermine the privacy, security, safety, and performance" of the iPhone. Neuenschwander said that Apple "works hard" to keep bad apps from the App Store, and North Dakota's bill would "require us to let them in." MacRumors reports: According to Senator Kyle Davison, who introduced Senate Bill 2333 yesterday, the legislation is designed to "level the playing field" for app developers in North Dakota and shield customers from "devastating, monopolistic fees imposed by big tech companies," which refers to the cut that Apple and Google take from developers. Specifically, the bill would prevent Apple from requiring a developer to use a digital application distribution platform as the exclusive mode of distributing a digital product, and it would keep the company from requiring developers to use in-app purchases as the exclusive mode of accepting payment from a user. There's also wording preventing Apple from retaliating against developers who choose alternate distribution and payment methods.

Apple does not allow apps to be installed on iOS devices outside of the "App Store" and there are no alternate app store options that are available. Apple reviews every app that is made available for its customers to download, something that would not happen with a third-party app store option. Apple also does not let app developers accept payments through methods other than in-app purchase except in select situations, a policy that has led to Apple's legal fight with Epic Games.

No federal legislation has been introduced as of yet, and the North Dakota Senate committee did not take action on the bill. Senator Jerry Klein said that there's "still some mulling to be done" in reference to the bill.

Security

Breached Water Plant Employees Used the Same TeamViewer Password and No Firewall (arstechnica.com) 80

An anonymous reader quotes a report from Ars Technica: The Florida water treatment facility whose computer system experienced a potentially hazardous computer breach last week used an unsupported version of Windows with no firewall and shared the same TeamViewer password among its employees, government officials have reported. The computer intrusion happened last Friday in Oldsmar, a Florida city of about 15,000 that's roughly 15 miles northwest of Tampa. After gaining remote access to a computer that controlled equipment inside the Oldsmar water treatment plant, the unknown intruder increased the amount of sodium hydroxide -- a caustic chemical better known as lye -- by a factor of 100. The tampering could have caused severe sickness or death had it not been for safeguards the city has in place.

According to an advisory from the state of Massachusetts, employees with the Oldsmar facility used a computer running Windows 7 to remotely access plant controls known as a SCADA -- short for "supervisory control and data acquisition" -- system. What's more, the computer had no firewall installed and used a password that was shared among employees for remotely logging into city systems with the TeamViewer application. [...] The revelations illustrate the lack of security rigor found inside many critical infrastructure environments. In January, Microsoft ended support for Windows 7, a move that ended security updates for the operating system. Windows 7 also provides fewer security protections than Windows 10. The lack of a firewall and a password that was the same for each employee are also signs that the department's security regimen wasn't as tight as it could have been.

Slashdot Top Deals