Government

Microsoft, SolarWinds Face New Criticism Over Russian Breach of US Networks (msn.com) 61

After Russia's massive breach of both government and private networks in the U.S., American intelligence officials "have expressed anger that Microsoft did not detect the attack earlier.

But new criticisms are also falling on SolarWinds: Some of the compromised SolarWinds software was engineered in Eastern Europe, and American investigators are now examining whether the incursion originated there, where Russian intelligence operatives are deeply rooted.... SolarWinds moved much of its engineering to satellite offices in the Czech Republic, Poland and Belarus, where engineers had broad access to the Orion network management software that Russia's agents compromised. The company has said only that the manipulation of its software was the work of human hackers rather than of a computer program. It has not publicly addressed the possibility of an insider being involved in the breach.

None of the SolarWinds customers contacted by The New York Times in recent weeks were aware they were reliant on software that was maintained in Eastern Europe. Many said they did not even know they were using SolarWinds software until recently.

Even with its software installed throughout federal networks, employees said SolarWinds tacked on security only in 2017, under threat of penalty from a new European privacy law. Only then, employees say, did SolarWinds hire its first chief information officer and install a vice president of "security architecture." Ian Thornton-Trump, a former cybersecurity adviser at SolarWinds, said he warned management that year that unless it took a more proactive approach to its internal security, a cybersecurity episode would be "catastrophic." After his basic recommendations were ignored, Mr. Thornton-Trump left the company.

SolarWinds declined to address questions about the adequacy of its security. In a statement, it said it was a "victim of a highly-sophisticated, complex and targeted cyberattack" and was collaborating closely with law enforcement, intelligence agencies and security experts to investigate. But security experts note that it took days after the Russian attack was discovered before SolarWinds' websites stopped offering clients compromised code.

And privately U.S. officials are now also considering the security of the U.S. power grid: Publicly, officials have said they do not believe the hackers from Russia's S.V.R. pierced classified systems containing sensitive communications and plans. But privately, officials say they still do not have a clear picture of what might have been stolen. They said they worried about delicate but unclassified data the hackers might have taken from victims like the Federal Energy Regulatory Commission, including Black Start, the detailed technical blueprints for how the United States plans to restore power in the event of a cataclysmic blackout. The plans would give Russia a hit list of systems to target to keep power from being restored in an attack like the one it pulled off in Ukraine in 2015, shutting off power for six hours in the dead of winter. Moscow long ago implanted malware in the American electric grid, and the United States has done the same to Russia as a deterrent....
Security

Backdoor Account Discovered in More Than 100,000 Zyxel Firewalls, VPN Gateways (zdnet.com) 74

More than 100,000 Zyxel firewalls, VPN gateways, and access point controllers contain a hardcoded admin-level backdoor account that can grant attackers root access to devices via either the SSH interface or the web administration panel. From a report: The backdoor account, discovered by a team of Dutch security researchers from Eye Control, is considered as bad as it gets in terms of vulnerabilities. Device owners are advised to update systems as soon as time permits. Security experts warn that anyone ranging from DDoS botnet operators to state-sponsored hacking groups and ransomware gangs could abuse this backdoor account to access vulnerable devices and pivot to internal networks for additional attacks.
Games

It's Game Over For FarmVille, as Flash Also Buys the Farm (bloomberg.com) 110

The last day of the year was also the last day for FarmVille, one of the original addictive Facebook games. From a report: FarmVille, which allowed players to cultivate colorful cartoonish farms by tending crops and caring for livestock, had 30 million daily players at its peak. But game developer Zynga announced in September it would shut down the game on Dec. 31, a victim of Adobe's decision to stop distributing and updating its Flash Player for web browsers, which in turn led Facebook to announce an end to support for Flash games on its platform.
Security

T-Mobile Data Breach Exposed Phone Numbers, Call Records (bleepingcomputer.com) 14

T-Mobile has announced a data breach exposing customers' proprietary network information (CPNI), including phone numbers and call records. From a report: Starting this week, T-Mobile began texting customers that a "security incident" exposed their account's information. According to T-Mobile, its security team recently discovered "malicious, unauthorized access" to their systems. After bringing in a cybersecurity firm to perform an investigation, T-Mobile found that threat actors gained access to the telecommunications information generated by customers, known as CPNI. The information exposed in this breach includes phone numbers, call records, and the number of lines on an account.
Microsoft

Microsoft Says SolarWinds Hackers Viewed Source Code (cnet.com) 47

The hackers who carried out a sophisticated cyberattack on government agencies in the US and private companies were able to access Microsoft's source code, the company said Thursday. From a report: A Microsoft investigation turned up "unusual activity with a small number of internal accounts" and that "one account had been used to view source code in a number of source code repositories," the company said in a blog post. Microsoft said the account didn't have the ability to modify code and that no company services or customer data was put at risk. "The investigation, which is ongoing, has also found no indications that our systems were used to attack others," the company said.
Security

CISA Updates SolarWinds Guidance, Tells US Govt Agencies To Update Right Away (zdnet.com) 27

The US Cybersecurity and Infrastructure Security Agency has updated its official guidance for dealing with the fallout from the SolarWinds supply chain attack. From a report: In an update posted late last night, CISA said that all US government agencies that still run SolarWinds Orion platforms must update to the latest 2020.2.1HF2 version by the end of the year. Agencies that can't update by that deadline are to take all Orion systems offline, per CISA's original guidance, first issued on December 18. The guidance update comes after security researchers uncovered a new major vulnerability in the SolarWinds Orion app over the Christmas holiday. Tracked as CVE-2020-10148, this vulnerability is an authentication bypass in the Orion API that allows attackers to execute remote code on Orion installations. This vulnerability was being exploited in the wild to install the Supernova malware on servers where the Orion platform was installed, in attacks separate from the SolarWinds supply chain incident.
Windows

Adobe Now Shows Alerts in Windows 10 To Uninstall Flash Player (bleepingcomputer.com) 61

With the Flash Player officially reaching the end of life tomorrow, Adobe has started to display alerts on Windows computers recommending that users uninstall Flash Player. From a report: When Flash Player is installed, it creates a scheduled task named 'Adobe Flash Player PPAPI Notifier' that executes the following command: "C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_465_pepper.exe" -update pepperplugin. When this command is executed, it is now displaying an alert thanking users for using Adobe Flash Player and then recommending that they uninstall the program due to its looming end of life. Further reading: Adobe Flash is about to die, but classic Flash games will live on.
Privacy

NSO Used Real People's Location Data To Pitch Its Contact-Tracing Tech, Researchers Say (techcrunch.com) 19

Spyware maker NSO Group used real phone location data on thousands of unsuspecting people when it demonstrated its new COVID-19 contact-tracing system to governments and journalists, researchers have concluded. From a report: NSO, a private intelligence company best known for developing and selling governments access to its Pegasus spyware, went on the charm offensive earlier this year to pitch its contact-tracing system, dubbed Fleming, aimed at helping governments track the spread of COVID-19. Fleming is designed to allow governments to feed location data from cell phone companies to visualize and track the spread of the virus. NSO gave several news outlets each a demo of Fleming, which NSO says helps governments make public health decisions "without compromising individual privacy." But in May, a security researcher told TechCrunch that he found an exposed database storing thousands of location data points used by NSO to demonstrate how Fleming works -- the same demo seen by reporters weeks earlier. TechCrunch reported the apparent security lapse to NSO, which quickly secured the database, but said that the location data was "not based on real and genuine data." NSO's claim that the location data wasn't real differed from reports in Israeli media, which said NSO had used phone location data obtained from advertising platforms, known as data brokers, to "train" the system. Academic and privacy expert Tehilla Shwartz Altshuler, who was also given a demo of Fleming, said NSO told her that the data was obtained from data brokers, which sell access to vast troves of aggregate location data collected from the apps installed on millions of phones.
Netscape

Brexit Deal Mentions Netscape Browser and Mozilla Mail (bbc.com) 194

References to decades-old computer software are included in the new Brexit agreement, including a description of Netscape Communicator and Mozilla Mail as being "modern" services. From a report: Experts believe officials must have copied and pasted chunks of text from old legislation into the document. The references are on page 921 of the trade deal, in a section on encryption technology. It also recommends using systems that are now vulnerable to cyber-attacks. The text cites "modern e-mail software packages including Outlook, Mozilla Mail as well as Netscape Communicator 4.x." The latter two are now defunct - the last major release of Netscape Communicator was in 1997. The document also recommends using 1024-bit RSA encryption and the SHA-1 hashing algorithm, which are both outdated and vulnerable to cyber-attacks.
Privacy

Finland Says Hackers Accessed MPs' Emails Accounts (zdnet.com) 17

The Finnish Parliament said on Monday that hackers gained entry to its internal IT system and accessed email accounts for some members of Parliament (MPs)fin. From a report: Government officials said the attack took place in the fall of 2020 and was discovered this month by the Parliament's IT staff. The matter is currently being investigated by the Finnish Central Criminal Police (KRP). In an official statement, KRP Commissioner Tero Muurman said the attack did not cause any damage to the Parliament's internal IT system but was not an accidental intrusion either. Muurman said the Parliament security breach is currently being investigated as a "suspected espionage" incident. "At this stage, one alternative is that unknown factors have been able to obtain information through the hacking, either for the benefit of a foreign state or to harm Finland," Muurman said. "The theft has affected more than one person, but unfortunately, we cannot tell the exact number without jeopardizing the ongoing preliminary investigation.
Security

Vietnam Targeted in Complex Supply Chain Attack (zdnet.com) 23

A group of mysterious hackers has carried out a clever supply chain attack against Vietnamese private companies and government agencies by inserting malware inside an official government software toolkit. From a report: The attack, discovered by security firm ESET and detailed in a report named "Operation SignSight," targeted the Vietnam Government Certification Authority (VGCA), the government organization that issues digital certificates that can be used to electronically sign official documents. Any Vietnamese citizen, private company, and even other government agency that wants to submit files to the Vietnamese government must sign their documents with a VGCA-compatible digital certificate. The VGCA doesn't only issue these digital certificates but also provides ready-made and user-friendly "client apps" that citizens, private companies, and government workers can install on their computers and automate the process of signing a document.
EU

What Happened When Finland Tried to Lure the World's Remote Tech Workers? (indiatimes.com) 24

As 2020 came to a close, the city of Helsinki, Finland tried offering "City as a Service" to attract new workers to its growing technology hub.

"We will provide selected applicants with a free 90-day relocation package for the entire family," explained the web site for the program (which is now no longer accepting applications). "We'll arrange your housing, daycare, schooling, everything you need — the real deal, just like a Finn." They'd pick you up at the airport, and then offer orientation services, "relocation consultation," and regular get-togethers, even offering in-person introductions to Helsinki-area technology hubs and business networks. (And of course, they'd arrange all the necessary documentation for a 90-day stay and permanent residency applications.) "Are you a 90 Day Finn...?" asked the site. "This is your call for a 90-day audition in Helsinki, featuring an unseen level of work-life balance!"

So what happened? The program "received 5,300 applications from across the world in just a month," reports the India Times, citing an article in the Guardian: The report adds that about 30 per cent of the applications came from the US and Canada. The remaining applications, 'evenly spread,' included 50 Britons and one application from Vanuatu. Johanna Huurre from Helsinki Business Hub, an agency that came up with the campaign, told The Guardian, "800 were entrepreneurs seeking to launch startups, 60 were investors, and the remainder were job hunting."

"It's been a great campaign to showcase Finland," said Joonas Halla, of Business Finland. "What's good is the practical approach. The tech sector here is really thriving — by one estimate it should create 50,000 new jobs in 2021. We need the talent."

United States

'Unforced Error' in Suspected Russian Data Breach May Have Led to Its Discovery (cnn.com) 50

CNN reports: US officials and private sector experts investigating the massive data breach that has rocked Washington increasingly believe the attackers were ultimately discovered because they took a more aggressive "calculated risk" that led to a possible "unforced error" as they tried to expand their access within the network they had penetrated months earlier without detection, according to a US official and two sources familiar with the situation... FireEye was tipped off to the hackers' presence when they attempt to move laterally within the firm's network, according to the sources, a move that suggested the hackers were targeting sensitive data beyond emails addresses or business records.

Whether that exposure was the result of a mistake by the attackers or because they took a calculated risk remains unclear, the sources said. "At some point, you have to risk some level of exposure when you're going laterally to get after the things that you really want to get. And you're going to take calculated risks as an attacker," one source familiar with the investigation said...

Now, the hackers are attempting to salvage what access they can as the US government and private sector are "burning it all down," sources said, referring to their complete overhaul of networks, which will force the attackers to find new ways of getting the information they seek. Meanwhile, US officials continue to grapple with the fallout and assess just how successful the operation was, the US official said, noting that it is clear the nation-state responsible invested significant time and resources into the effort. While the scope of the hacking campaign remains unclear, government agencies that have disclosed they were impacted have said there is no evidence to date that classified data was compromised. But the way the hackers were discovered suggests the operation was intended to steal sensitive information beyond what was available on unclassified networks and sought to establish long-standing access to various targeted networks, the sources said.

The fact that FireEye — not the federal government — discovered the breach has also raised questions about why the attack went undetected at US government agencies.

The article also notes FireEye's acknowledgement that the breach "occurred when the hackers, who already had an employee's credentials, used those to register their own device to FireEye's multi-factor authentication system so they could receive the employee's unique access codes."
Network

Citrix Devices Are Being Abused as DDoS Attack Vectors (zdnet.com) 17

Threat actors have discovered a way to bounce and amplify junk web traffic against Citrix ADC networking equipment to launch DDoS attacks. From a report: While details about the attackers are still unknown, victims of these Citrix-based DDoS attacks have mostly included online gaming services, such as Steam and Xbox, sources have told ZDNet earlier today. The first of these attacks have been detected last week and documented by German IT systems administrator Marco Hofmann. Hofmann tracked the issue to the DTLS interface on Citrix ADC devices. DTLS, or Datagram Transport Layer Security, is a more version of the TLS protocol implemented on the stream-friendly UDP transfer protocol, rather than the more reliable TCP. Just like all UDP-based protocols, DTLS is spoofable and can be used as a DDoS amplification vector.
Windows

Scott Hanselman's 2021 Ultimate Developer and Power Users Tool List for Windows (hanselman.com) 65

Scott Hanselman: Everyone collects utilities, and most folks have a list of a few that they feel are indispensable. Here's mine. Each has a distinct purpose, and I probably touch each at least a few times a week. For me, "util" means utilitarian and it means don't clutter my tray. If it saves me time, and seamlessly integrates with my life, it's the bomb. Many/most are free some aren't. Those that aren't free are very likely worth your 30-day trial, and very likely worth your money. These are all well loved and oft-used utilities. I wouldn't recommend them if I didn't use them constantly. Things on this list are here because I dig them. No one paid money to be on this list and no money is accepted to be on this list.
Security

Russians Are Believed To Have Used Microsoft Resellers in Cyberattacks (nytimes.com) 50

As the United States comes to grips with a far-reaching Russian cyberattack on federal agencies, private corporations and the nation's infrastructure, new evidence has emerged that the hackers hunted their victims through multiple channels. From a report: The most significant intrusions discovered so far piggybacked on software from SolarWinds, the Austin-based company whose updates the Russians compromised. But new evidence from the security firm CrowdStrike suggests that companies that sell software on Microsoft's behalf were also used to break into customers of Microsoft's Office 365 software. Because resellers are often entrusted to set up and maintain clients' software, they -- like SolarWinds -- have been an ideal front for Russian hackers and a nightmare for Microsoft's cloud customers, who are still assessing just how deep into their systems Russia's hackers have crawled. "They couldn't get into Microsoft 365 directly, so they targeted the weakest point in the supply chain: the resellers," said Glenn Chisholm, a founder of Obsidian, a cybersecurity firm.

CrowdStrike confirmed Wednesday that it was also a target of the attack. In CrowdStrike's case, the Russians did not use SolarWinds but a Microsoft reseller, and the attack was unsuccessful. A CrowdStrike spokeswoman, Ilina Dimitrova, declined to elaborate beyond a company blog post describing the attempted attack. The approach is not unlike the 2013 attack on Target in which hackers got in through the retailer's heating and cooling vendor. The latest Russian attacks, which are thought to have begun last spring, have exposed a substantial blind spot in the software supply chain. Companies can track phishing attacks and malware all they want, but as long as they are blindly trusting vendors and cloud services like Microsoft, Salesforce Google's G-Suite, Zoom, Slack, SolarWinds and others -- and giving them broad access to employee email and corporate networks -- they will never be secure, cybersecurity experts say. "These cloud services create a web of interconnections and opportunity for the attacker," Mr. Chisholm said. "What we are witnessing now is a new wave of modern attacks against these modern cloud platforms, and we need 2021 defenses." Some reports have confused the latest development with a breach of Microsoft itself. But the company said it stood by its statement last week that it was not hacked, nor was it used to attack customers.

Security

GoDaddy Employees Were Told They Were Getting a Holiday Bonus. It Was Actually a Phishing Test. 236

An anonymous reader shares a report (alternative source): "2020 has been a record year for GoDaddy, thanks to you!" the email read. Sent by Happyholiday@Godaddy.com, tucked underneath a glittering banner of a snowflake and stamped with the words "GoDaddy Holiday Party," the Dec. 14 email to hundreds of GoDaddy employees promised some welcome financial relief during an otherwise stressful year. "Though we cannot celebrate together during our annual Holiday Party, we want to show our appreciation and share a $650 one-time Holiday bonus!" the email read.

"To ensure that you receive your one-time bonus in time for the Holidays, please select your location and fill in the details by Friday, December 18th." But, two days later, the company sent another email. "You're getting this email because you failed our recent phishing test," the company's chief security officer Demetrius Comes wrote. "You will need to retake the Security Awareness Social Engineering training." The follow-up email from Comes said that roughly 500 GoDaddy employees clicked on the holiday bonus email and failed the test. Scottsdale-based GoDaddy, the world's largest domain registrar and web-hosting company, did not respond to repeated requests for comment about the emails. The emails were forwarded to The Copper Courier by three GoDaddy employees.
Security

Hackers Threaten To Leak Plastic Surgery Pictures (bbc.com) 33

Hackers have stolen the data of a large cosmetic surgery chain and are threatening to publish patients' before and after photos, among other details. From a report: The Hospital Group, which has a long list of celebrity endorsements, has confirmed the ransomware attack. It said it had informed the Information Commissioner of the breach. On its darknet webpage, the hacker group known as REvil said the "intimate photos of customers" were "not a completely pleasant sight." It claimed to have obtained more than 900 gigabytes of patient photographs. The Hospital Group, which is also known as the Transform Hospital Group, claims to be the UK's leading specialist weight loss and cosmetic surgery group. It has 11 clinics specialising in bariatric weight loss surgery, breast enlargements, nipple corrections and nose adjustments. The company has previously promoted itself via celebrity endorsements, although it has not done so for several years. Former Big Brother contestant Aisleyne Horgan-Wallace told Zoo magazine about her breast enhancement surgery with The Hospital Group in 2009. Atomic Kitten singer Kerry Katona, Shameless actress Tina Malone and reality TV star Joey Essex from The Only Way is Essex are also previous patients who have endorsed the clinic.
United States

US Cyber Agency Says SolarWinds Hackers Are 'Impacting' State, Local Governments (reuters.com) 35

The U.S. cybersecurity agency says that a sprawling cyber espionage campaign made public earlier this month is affecting state and local governments, although it released few additional details. From a report: The hacking campaign, which used U.S. tech company SolarWinds as a springboard to penetrate federal government networks, was "impacting enterprise networks across federal, state, and local governments, as well as critical infrastructure entities and other private sector organizations," the Cybersecurity and Infrastructure Security Agency (CISA) said in a statement posted to its website. The CISA said last week that U.S. government agencies, critical infrastructure entities, and private groups were among those affected, but did not specifically mention state or local bodies. So far only a handful of federal government agencies have officially confirmed having been affected, including the U.S. Treasury Department, the Commerce Department, and the Department of Energy.
Encryption

Signal Says Cellebrite Cannot Break Its Encryption 14

Signal, in a blog post: Yesterday, the BBC ran a story with the factually untrue headline, "Cellebrite claimed to have cracked chat app's encryption." This is false. Not only can Cellebrite not break Signal encryption, but Cellebrite never even claimed to be able to. Since we weren't actually given the opportunity to comment in that story, we're posting this to help to clarify things for anyone who may have seen the headline. Last week, Cellebrite posted a pretty embarrassing (for them) technical article to their blog documenting the "advanced techniques" they use to parse Signal on an Android device they physically have with the screen unlocked. This is a situation where someone is holding an unlocked phone in their hands and could simply open the app to look at the messages in it. Their post was about doing the same thing programmatically (which is equally simple), but they wrote an entire article about the "challenges" they overcame, and concluded that "...it required extensive research on many different fronts to create new capabilities from scratch."

[...] What really happened: If you have your device, Cellebrite is not your concern. It is important to understand that any story about Cellebrite Physical Analyzer starts with someone other than you physically holding your device, with the screen unlocked, in their hands. Cellebrite does not even try to intercept messages, voice/video, or live communication, much less "break the encryption" of that communication. They don't do live surveillance of any kind.

Cellebrite is not magic. Imagine that someone is physically holding your device, with the screen unlocked, in their hands. If they wanted to create a record of what's on your device right then, they could simply open each app on your device and take screenshots of what's there. This is what Cellebrite Physical Analyser does. It automates the process of creating that record. However, because it's automated, it has to know how each app is structured, so it's actually less reliable than if someone were to simply open the apps and manually take the screenshots. It is not magic, it is mediocre enterprise software. Cellebrite did not "accidentally reveal" their secrets. This article, and others, were written based on a poor interpretation of a Cellebrite blog post about adding Signal support to Cellebrite Physical Analyzer. Cellebrite posted something with a lot of detail, then quickly took it down and replaced it with something that has no detail. This is not because they "revealed" anything about some super advanced technique they have developed (remember, this is a situation where someone could just open the app and look at the messages). They took it down for the exact opposite reason: it made them look bad.

Slashdot Top Deals