Databases

Hackers Are Selling More Than 85,000 MySQL Databases On a Dark Web Portal (zdnet.com) 24

An anonymous Slashdot reader writes: For the past year, hackers have been breaking into MySQL databases, downloading tables, deleting the originals, and leaving ransom notes behind, telling server owners to contact the attackers to get their data back. If database owners don't respond and ransom their data back in nine days, the databases are then put up on auction on a dark web portal.
"More than 85,000 MySQL databases are currently on sale on a dark web portal for a price of only $550/database," reports ZDNet: This suggests that both the DB intrusions and the ransom/auction web pages are automated and that attackers don't analyze the hacked databases for data that could contain a higher concentration of personal or financial information. Signs of these ransom attacks have been piling up over the course of 2020, with the number of complaints from server owners finding the ransom note inside their databases popping up on Reddit, the MySQL forums, tech support forums, Medium posts, and private blogs.
Facebook

Facebook Says Hackers Backed By Vietnam's Government Are Linked To IT Firm (arstechnica.com) 11

An anonymous reader quotes a report from Ars Technica: Facebook said it has linked an advanced hacking group widely believed to be sponsored by the government of Vietnam to what's purported to be a legitimate IT company in that country. The so-called advanced persistent threat group goes under the monikers APT32 and OceanLotus. It has been operating since at least 2014 and targets private sector companies in a range of industries along with foreign governments, dissidents, and journalists in South Asia and elsewhere. It uses a variety of tactics, including phishing, to infect targets with fully featured desktop and mobile malware that's developed from scratch. To win targets' confidence, the group goes to great lengths to create websites and online personas that masquerade as legitimate people and organizations.

Earlier this year, researchers uncovered at least eight unusually sophisticated Android apps hosted in Google Play that were linked to the hacking group. Many of them had been there since at least 2018. OceanLotus repeatedly bypassed Google's app-vetting process, in part by submitting benign versions of the apps and later updating them to add backdoors and other malicious functionality. FireEye published this detailed report on OceanLotus in 2017, and BlackBerry has more recent information here. On Thursday, Facebook identified Vietnamese IT firm CyberOne Group as being linked to OceanLotus. The group lists an address in Ho Chi Minh city.

Email sent to the company seeking comment returned an error message that said the email server was misconfigured. A report from Reuters on Friday, however, quoted a person operating the company's now-suspended Facebook page as saying: "We are NOT Ocean Lotus. It's a mistake." At the time this post went live, the company's website was also unreachable. An archive of it from earlier on Friday is here.

Security

CISA and FBI Warn of Rise in Ransomware Attacks Targeting K-12 Schools (zdnet.com) 13

In a joint security alert published this week, the US Cybersecurity Infrastructure and Security Agency, along with the Federal Bureau of Investigation, warned about increased cyber-attacks targeting the US K-12 educational sector, often leading to ransomware attacks, the theft of data, and the disruption of distance learning services. From a report: "As of December 2020, the FBI, CISA, and MS-ISAC continue to receive reports from K-12 educational institutions about the disruption of distance learning efforts by cyber actors," the alert reads. "Cyber actors likely view schools as targets of opportunity, and these types of attacks are expected to continue through the 2020/2021 academic year," it added.

But of all the attacks plaguing the K-12 sector (kindergarten through twelfth-grade schools), ransomware has been a particularly aggressive threat this year, CISA and the FBI said. "According to MS-ISAC data, the percentage of reported ransomware incidents against K-12 schools increased at the beginning of the 2020 school year," the two agencies said. "In August and September, 57% of ransomware incidents reported to the MS-ISAC involved K-12 schools, compared to 28% of all reported ransomware incidents from January through July," they said.

Security

Spotify Resets Passwords After a Security Bug Exposed Users' Private Account Information (techcrunch.com) 19

Jerry Rivers shares a report from TechCrunch, adding: "...and it took the music service seven months to notice." From the report: In a data breach notification filed with the California attorney general's office, the music streaming giant said the data exposed "may have included email address, your preferred display name, password, gender, and date of birth only to certain business partners of Spotify." The company did not name the business partners, but added that Spotify "did not make this information publicly accessible." The company says the vulnerability existed as far back as April 9 but wasn't discovered until November 12. It didn't say what the vulnerability was or how user account data became exposed.

"We have conducted an internal investigation and have contacted all of our business partners that may have had access to your account information to ensure that any personal information that may have been inadvertently disclosed to them has been deleted," the letter read.
Hardware

'This Is a Bad Time to Build a High-End Gaming PC' (extremetech.com) 177

Joel Hruska, writing at ExtremeTech: It's not just a question of whether top-end hardware is available, but whether midrange and last-gen hardware is selling at reasonable prices. If you want to go AMD, be aware that Ryzen 5000 CPUs are hard to find and the 6800 and 6800 XT are vanishingly rare. The upper-range Ryzen 3000 CPUs available on Amazon and Newegg are also selling for well above their prices six months ago. If you want to build an Intel system, the situation is a little different. A number of the 9th and 10th-gen chips are actually priced at MSRP and not too hard to find. The Core i7-9700K has fallen to $269, for example, and it's still one of Intel's fastest gaming CPUs. At that price, paired with a Z370 motherboard, you could build a gaming-focused system, so long as you don't actually need a new high-end GPU. The Core i7-10700K is $359, which isn't quite as competitive, but it squares off reasonably well against chips like the 3700X at $325. Amazon and Newegg both report the 3600X selling for more, at $400 and $345, respectively.

But even if these prices are appealing, the current GPU market makes building a gaming system much above lower-midrange to midrange a non-starter. Radeon 6000 GPUs and RTX 3000 GPUs are both almost impossible to find, and the older, slower, and less feature-rich cards that you can buy are almost all selling for more today than they were six months ago. Not every GPU has been kicked into the stratosphere, but between the cards you can't buy and the cards you shouldn't buy, there's a limited number of deals currently on the market. Your best bet is to set up price alerts on specific SKUs you are watching with the vendor in question. There is some limited good news, though: DRAM and SSDs are both still reasonably priced. DRAM and SSD prices are both expected to decline 10-15 percent through Q4 2020 compared with the previous quarter, and there are good deals to be had on both. [...] Power supply prices look reasonable, too, and motherboard availability looks solid. If you don't need to buy a GPU right now and you're willing to or prefer to use Intel, there's a more reasonable case to be made for building a system. But if you need a high-end GPU and/or want a high-end Ryzen chip to go with it, you may be better off shopping prebuilt systems or waiting a few more months.

Microsoft

Microsoft Exposes Adrozek, Malware That Hijacks Chrome, Edge, and Firefox (zdnet.com) 17

Microsoft has raised the alarm today about a new malware strain that infects users' devices and then proceeds to modify browsers and their settings in order to inject ads into search results pages. From a report: Named Adrozek, the malware has been active since at least May 2020 and reached its absolute peak in August this year when it controlled more than 30,000 browsers each day. But in a report today, the Microsoft 365 Defender Research Team believes the number of infected users is much, much higher. Microsoft researchers said that between May and September 2020, they observed "hundreds of thousands" of Adrozek detections all over the globe. Based on internal telemetry, the highest concentration of victims appears to be located in Europe, followed by South and Southeast Asia. Microsoft says that, currently, the malware is distributed via classic drive-by download schemes. Users are typically redirected from legitimate sites to shady domains where they are tricked into installing malicious software. The boobytrapped software installs the Androzek malware, which then proceeds to obtain reboot persistence with the help of a registry key.
IT

Weather Service Faces Internet Bandwidth Shortage, Proposes Limiting Key Data (washingtonpost.com) 67

For the past decade, the National Weather Service has been plagued by failures in disseminating critical forecast and warning information that is aimed at protecting lives and saving property. In some cases, its websites have gone down during severe weather events, unable to handle the demand. From a report: Other agency systems, including information and data streams that deliver vital weather modeling data to broadcast meteorologists and commercial users, have also suffered periodic outages. Now, during a year that featured record California wildfires and the busiest Atlantic hurricane season on record, the Weather Service says it has an Internet bandwidth problem and is seeking to throttle back the amount of data its most demanding users can access. The Weather Service, which is part of the National Oceanic and Atmospheric Administration (NOAA), announced the proposed limits in a memo dated Nov. 18. "As demand for data continues to grow across NCEP websites, we are proposing to put new limits into place to safeguard our web services," the memo stated, referring to the Weather Service's National Centers for Environmental Prediction. "The frequency of how often these websites are accessed by the public has created limitations and infrastructure constraints."
Bug

Cyberpunk 2077 Bugs Hit CD Projekt (bloomberg.com) 148

An anonymous reader shares a report: Numerous glitches reported by players as the long-awaited Cyberpunk 2077 game went live robbed creator CD Projekt of a stock surge on the back of encouraging advance-order sales figures. Poland's biggest computer-games studio sold more than eight million copies of the futuristic title prior to its official release, mainly using higher-margin digital distribution. Excitement around Wednesday's launch saw player numbers peak at more than one million, the most ever for a premier night on the Steam platform, and an industry record for a single-player production. Less positively, in excess of 17,000 Steam users gave Cyberpunk a rating of just 71%, with their complaints of bugs in the game pushing CD Projekt's shares as much as 7.5% lower.

Before the release, Cyberpunk's average rating was 91% on Metacritic, a website that aggregated journalists reviews. That less-than-perfect verdict also weighed on the stock earlier this week, paring its gains of almost 60% in 2020 as of last Friday. The stakes are high for CD Projekt as, after eight years of developing Cyberpunk, the game is the studio's only new franchise. The company said Thursday it's already working on fixes and is confident they will be resolved and that it wants to publish initial sales data before Christmas.

Medicine

EU Agency in Charge of COVID-19 Vaccine Approval Says it Was Hacked (zdnet.com) 40

The European Medicines Agency (EMA), the EU regulatory body in charge of approving COVID-19 vaccines, said today it was the victim of a cyber-attack. From a report: In a short two-paragraph statement posted on its website today, the agency discloses the security breach but said it couldn't disclose any details about the intrusion due to an ongoing investigation. EMA is currently in the process of reviewing applications for two COVID-19 vaccines, one from US pharma giant Moderna, and a second developed in a collaboration between BioNTech and Pfizer. An EMA spokesperson did not return a request for comment seeking information if the attack targeted its vaccine approval process or if it was a financially-motivated attack like ransomware. Nonetheless, in a follow-up statement released on its own website, BioNTech said that "some documents relating to the regulatory submission for Pfizer and BioNTech's COVID-19 vaccine candidate, BNT162b2, which has been stored on an EMA server, had been unlawfully accessed" during the attack, confirming that COVID-19 research was most likely the target of the attack.
EU

Germany, France, 11 Other EU Countries Team Up For Semiconductor Push (reuters.com) 45

An anonymous reader quotes a report from Reuters: Germany, France, Spain and ten other EU countries have joined forces to invest in processors and semiconductor technologies, key to internet-connected devices and data processing, in a push to catch up with the United States and Asia. Europe's share of the 440-billion-euro ($533 billion) global semiconductor market is around 10%, with the EU currently relying on chips made abroad. The 13 countries said they would work together to bolster Europe's electronics and embedded systems value chain. The group will reach out to companies to form industrial alliances for research and investment into designing and making processors and look into funding for such projects. It will also come up with a European-wide scheme known as an Important Project of Common European Interest which allows for funding under looser EU state aid rules. The group will seek to set up common standards and certification for electronics. The signatories include Belgium, Croatia, Estonia, Finland, Greece, Italy, Malta, the Netherlands, Portugal and Slovenia.
Security

FireEye, a Top Cybersecurity Firm, Says It Was Hacked By a Nation-State (nytimes.com) 51

An anonymous reader quotes a report from The New York Times : For years, the cybersecurity firm FireEye has been the first call for government agencies and companies around the world who have been hacked by the most sophisticated attackers, or fear they might be. Now it looks like the hackers -- in this case, evidence points to Russia's intelligence agencies -- may be exacting their revenge. FireEye revealed on Tuesday that its own systems were pierced by what it called "a nation with top-tier offensive capabilities." The company said hackers used "novel techniques" to make off with its own tool kit, which could be useful in mounting new attacks around the world.

It was a stunning theft, akin to bank robbers who, having cleaned out local vaults, then turned around and stole the F.B.I.'s investigative tools. In fact, FireEye said on Tuesday, moments after the stock market closed, that it had called in the F.B.I. The $3.5 billion company, which partly makes a living by identifying the culprits in some of the world's boldest breaches -- its clients have included Sony and Equifax -- declined to say explicitly who was responsible. But its description, and the fact that the F.B.I. has turned the case over to its Russia specialists, left little doubt who the lead suspects were and that they were after what the company calls "Red Team tools." These are essentially digital tools that replicate the most sophisticated hacking tools in the world. FireEye uses the tools — with the permission of a client company or government agency -- to look for vulnerabilities in their systems. Most of the tools are based in a digital vault that FireEye closely guards.

The hack raises the possibility that Russian intelligence agencies saw an advantage in mounting the attack while American attention -- including FireEye's -- was focused on securing the presidential election system. At a moment that the nation's public and private intelligence systems were seeking out breaches of voter registration systems or voting machines, it may have a been a good time for those Russian agencies, which were involved in the 2016 election breaches, to turn their sights on other targets. The hack was the biggest known theft of cybersecurity tools since those of the National Security Agency were purloined in 2016 by a still-unidentified group that calls itself theShadowBrokers. [...] The N.S.A.'s tools were most likely more useful than FireEye's since the U.S. government builds purpose-made digital weapons. FireEye's Red Team tools are essentially built from malware that the company has seen used in a wide range of attacks. Still, the advantage of using stolen weapons is that nation-states can hide their own tracks when they launch attacks.

Security

GE Puts Default Password In Radiology Devices, Leaving Healthcare Networks Exposed 40

An anonymous reader quotes a report from Ars Technica: Dozens of radiology products from GE Healthcare contain a critical vulnerability that threatens the networks of hospitals and other health providers that use the devices, officials from the US government and a private security firm said on Tuesday. The devices -- used for CT scans, MRIs, X-Rays, mammograms, ultrasounds, and positron emission tomography -- use a default password to receive regular maintenance. The passwords are available to anyone who knows where on the Internet to look. A lack of proper access restrictions allows the devices to connect to malicious servers rather than only those designated by GE Healthcare. Attackers can exploit these shortcomings by abusing the maintenance protocols to access the devices. From there, the attackers can execute malicious code or view or modify patient data stored on the device or the hospital or healthcare provider servers.

Aggravating matters, customers can't fix the vulnerability themselves. Instead, they must request that the GE Healthcare support team change the credentials. Customers who don't make such a request will continue to rely on the default password. Eventually, the device manufacturer will provide patches and additional information. The flaw has a CVSS severity rating of 9.8 out of 10 because of the impact of the vulnerability combined with the ease of exploiting it. Security firm CyberMDX discovered the vulnerability and privately reported it to the manufacturer in May. The US Cyber Security and Infrastructure Security Agency is advising affected healthcare providers to take mitigation steps as soon as possible.
In a statement, GE Healthcare officials wrote: "We are not aware of any unauthorized access to data or incident where this potential vulnerability has been exploited in a clinical situation. We have conducted a full risk assessment and concluded that there is no patient safety concern. Maintaining the safety, quality, and security of our devices is our highest priority. We are providing on-site assistance to ensure credentials are changed properly and confirm proper configuration of the product firewall. Additionally, we are advising the facilities where these devices are located to follow network management and security best practices."
Spam

Spam Calls Grew 18% This Year Despite the Global Pandemic (techcrunch.com) 89

Despite several efforts from carriers, telecom regulators, mobile operating system developers, smartphone makers, and a global pandemic, spam calls continued to pester and scam people around the globe this year -- and they only got worse. From a report: Users worldwide received 31.3 billion spam calls between January and October this year, up from 26 billion during the same period last year, and 17.7 billion the year prior, according to Stockholm-headquartered firm Truecaller. The firm, best known for its caller ID app, estimated that an average American received 28.4 spam calls a month this year, up from 18.2 last year. As a result, And with 49.9 spam calls per user a month, up from an already alarming 45.6 figure last year, Brazil remained the worst impacted nation to spam calls, the firm said in its yearly report on the subject. The coronavirus pandemic, however, lowered the volume of spam calls users had to field in several markets, including India, which topped Truecaller's chart for the worst nation affected three years ago. The nation, the biggest market of Truecaller, dropped to the 9th position on the chart this year with 16.8 monthly spam calls per user, down from 25.6 last year.
The Internet

Cloudflare and Apple Design a New Privacy-Friendly Internet Protocol (techcrunch.com) 90

Engineers at Cloudflare and Apple say they've developed a new internet protocol that will shore up one of the biggest holes in internet privacy that many don't know even exists. Dubbed Oblivious DNS-over-HTTPS, or ODoH for short, the new protocol makes it far more difficult for internet providers to know which websites you visit. From a report: [...] Recent developments like DNS-over-HTTPS (or DoH) have added encryption to DNS queries, making it harder for attackers to hijack DNS queries and point victims to malicious websites instead of the real website you wanted to visit. But that still doesn't stop the DNS resolvers from seeing which website you're trying to visit. Enter ODoH, which decouples DNS queries from the internet user, preventing the DNS resolver from knowing which sites you visit. Here's how it works: ODoH wraps a layer of encryption around the DNS query and passes it through a proxy server, which acts as a go-between the internet user and the website they want to visit. Because the DNS query is encrypted, the proxy can't see what's inside, but acts as a shield to prevent the DNS resolver from seeing who sent the query to begin with. "What ODoH is meant to do is separate the information about who is making the query and what the query is," said Nick Sullivan, Cloudflare's head of research.
Security

Did COVID Data Whistleblower Hack Florida's Emergency Alert System? Police Raid Home (miamiherald.com) 210

FriendlySolipsist writes: Independent journalist Rebekah Jones, a scientist fired by the Florida state government because, she said, of her refusal to manipulate official COVID-19 data releases to coincide with political considerations and who now operates website floridacovidaction.com, had her home raided by the FL state police who seized computers and cellphones, the Miami Herald reported. The FDLE affidavit in support of the raid was published by the Miami Herald and asserts that an unauthorized internal message was sent to the "ReadyOps" system within the state Department of Health from an IPv6 address associated with the Comcast account at Jones residence. "The Florida Department of Law Enforcement on Monday raided the home of a former Department of Health data analyst who has been running an alternative web site to the state's COVID dashboard, alleging that she may have broken into a state email system and sent an unauthorized message to employees," reports the Miami Herald. "But Rebekah Jones, who was was fired from her job in May as the geographic information system manager for DOH's Division of Disease Control and Health Protection and who has since filed a whistleblower complaint against the state, denied having any role in the alleged intrusion into the state web site and instead said she believes Monday's action was intended to silence her."

Slashdot reader mtrachtenberg shares a thread on Twitter of Jones describing what happened.
Security

Hacker Opens 2,732 PickPoint Package Lockers Across Moscow (zdnet.com) 31

A mysterious hacker sed a cyber-attack to force-open the doors of 2,732 package delivery lockers across Moscow. ZDNet reports: The attack, which took place on Friday afternoon, December 4, targeted the network of PickPoint, a local delivery service that maintains a network of more than 8,000 package lockers across Moscow and Saint Petersburg. Russians can order products online and choose to have any of their orders delivered to a PickPoint locker instead of their home address. Once the package arrives, users receive an email or mobile notification, and they can show up and pick up their orders using the PickPoint app. However, the same system that allows users to open lockers and retrieve their packages was attacked on Friday.

Using a yet-to-be-identified exploit, a mysterious hacker forced open the doors for a third of PickPoint's lockers, leaving thousands of packages exposed to theft across Moscow. The reason for the attack has yet to be discovered, but in press releases over the weekend, PickPoint said it notified authorities. The Russian company said it is currently working to restore its network, which has been damaged during the attack. It also remains unclear if packages were stolen from lockers. As the company highlighted in a press release on Saturday, this appears to be "the world's first targeted cyberattack against a post-gateway network."

Businesses

Will Businesses Make 2021 The Year of the Linux Desktop? (techrepublic.com) 214

Writing for TechRepublic, open source advocate Jack Wallen predicts 2021 will be a year where open source technology dominates the world of big data even more than 2021 (with a big role predicted for SUSE). But he also sees businesses cutting costs by switching to open source solutions — including a big move to Linux on enterprise desktops, thanks to enterprise-ready options now available from System76, Lenovo, and Dell: This will have the added benefit of even more companies jumping into the mix and offering more and more desktops and laptops, all powered by Linux and open source technology.

One added bonus for this movement is that System76 will finally gain the recognition they've deserved for so many years. Linux on the desktop would not be where it is today, had it not been for their stalwart support for open source technology. Year after year, System76 has proved that high-quality, business-class systems, powered by Linux, can be produced at a level befitting the enterprise.

That success within the realm of business will start trickling down to consumers. As more and more people start using Linux at their place of business, they'll begin seeing the benefits of the open source operating system and desire to adopt it for their home computers. I suspect that by the end of 2021, we'll see Linux desktop market share to finally break the 10% bubble. It may not sound like much, but given how Linux has hovered around 2% and maxed out at 5%, that 10% figure is like a dream come true.

That's only the tip of the iceberg. Although Linux will max out at around 10% by the end of the year, it will lead to continued growth over the coming years.

Government

Kazakhstan's Government Begins Intercepting HTTPS Traffic In Its Capital (zdnet.com) 126

ZDNet reports: Under the guise of a "cybersecurity exercise," the Kazakhstan government is forcing citizens in its capital of Nur-Sultan (formerly Astana) to install a digital certificate on their devices if they want to access foreign internet services. Once installed, the certificate would allow the government to intercept all HTTPS traffic made from users' devices via a technique called MitM (Man-in-the-Middle).

Starting today, December 6, 2020, Kazakh internet service providers (ISPs) such as Beeline, Tele2, and Kcell are redirecting Nur-Sultan-based users to web pages showing instructions on how to install the government's certificate. Earlier this morning, Nur-Sultan residents also received SMS messages informing them of the new rules.

Kazakhstan users have told ZDNet today that they are not able to access sites like Google, Twitter, YouTube, Facebook, Instagram, and Netflix without installing the government's root certificate.

This is the Kazakh government's third attempt at forcing citizens to install root certificates on their devices after a first attempt in December 2015 and a second attempt in July 2019. Both previous attempts failed after browser makers blacklisted the government's certificates.

Google

Chrome's New 'Cache Partitioning' System Impacts Google Fonts Performance (zdnet.com) 27

A change made in the Google Chrome browser in October has impacted the performance of the Google Fonts service for millions of websites. From a report: The change is an update to Chrome's internal cache system. A browser's cache system works by serving as a temporary storage system for images, CSS, and JavaScript files used by websites. Files stored in the cache are typically reused across multiple sites instead of having the browser re-download each file for every page/tab load. But with the release of Chrome 86 in early October 2020, Google has overhauled how Chrome's entire caching system works. Instead of using one big cache for all websites, Google has "partitioned" the Chrome cache, which will now be storing resources on a per-website and per-resource basis. While this is a big win for user security, preventing some forms of web attacks, this change has affected web services designed around the old cache system.
Windows

Microsoft is Testing a Cortana 'File Skill' To Find Files Faster in Windows 10 (pcworld.com) 45

Cortana may not be the personal assistant she once was, but a new update as part of the Windows Insider Dev Channel means that her capabilities to find files have improved. From a report: The new "File Skill" in the Cortana app appears in the new Windows 10 Insider Preview Build 20270, part of the Dev Channel. (Dev Channel releases publish test code that may or may not end up in a future release.) In this experimental app, Cortana's skills have been honed to the point where she can find files in the cloud, with a better understanding of what you're looking for. If your PC is enrolled in the Windows 10 May 2020 Update or later, some of these capabilities will already be available. As long as you have speech recognition enabled on your PC, you can ask Cortana "find my recent files," and it should unearth the last two or three files you've used on your PC. What Microsoft is trying with Cortana in this beta is the ability to search corporate SharePoint and OneDrive files stored in the cloud on a work account. (You'll need to be signed into a work account, too.)

Slashdot Top Deals