Security

Dell Announces New Solutions For Its Supply Chain's Security (zdnet.com) 22

PC maker powerhouse Dell announced today a flurry of new enterprise security solutions for the company's line of enterprise products. From a report: The new services can be grouped into two categories, with (1) new solutions meant to protect the supply chain of Dell products while in transit to their customers and (2) new features meant to improve the security of Dell products while in use. While Dell has previously invested in securing its customers' supply chains, the company has announced today three new services. The first is named SafeSupply Chain Tamper Evident Services and, as its name implies, involves Dell adding anti-tampering seals to its devices, transport boxes, and even entire pallets before they leave Dell factories. The anti-tampering seals will allow buyers of Dell equipment to determine if any intermediary agents or transporters have opened boxes or devices to alter physical components. The second supply chain security offering, named the Dell SafeSupply Chain Data Sanitization Services, is meant for tampering made at the storage level.
Privacy

Data of 243 Million Brazilians Exposed Online via Website Source Code (zdnet.com) 34

The personal information of more than 243 million Brazilians, including alive and deceased, has been exposed online after web developers left the password for a crucial government database inside the source code of an official Brazilian Ministry of Health's website for at least six months. From a report: The security snafu was discovered by reporters from Brazilian newspaper Estadao, the same newspaper that last week discovered that a Sao Paolo hospital leaked personal and health information for more than 16 million Brazilian COVID-19 patients after an employee uploaded a spreadsheet with usernames, passwords, and access keys to sensitive government systems on GitHub. Estadao reporters said they were inspired by a report filed in June by Brazilian NGO Open Knowledge Brasil (OKBR), which, at the time, reported that a similar government website also left exposed login information for another government database in the site's source code. Since a website's source code can be accessed and reviewed by anyone pressing F12 inside their browser, Estadao reporters searched for similar issues in other government sites.
Security

Mysterious Phishing Campaign Targets Organizations in COVID-19 Vaccine Cold Chain (zdnet.com) 20

IBM's cyber-security division says that hackers are targeting companies associated with the storage and transportation of COVID-19 vaccines using temperature-controlled environments -- also known as the COVID-19 vaccine cold chain. From a report: The attacks consisted of spear-phishing emails seeking to collect credentials for a target's internal email and applications. While IBM X-Force analysts weren't able to link the attacks to a particular threat actor, they said the phishing campaign showed the typical "hallmarks of nation-state tradecraft." Targets of the attacks included a wide variety of companies, sectors, and government organizations alike.
Microsoft

AWS Engineer Puts Windows 10 on Arm on Apple Mac M1 -- and It Thrashes Surface Pro X (zdnet.com) 107

An Amazon Web Services (AWS) virtualization engineer has shown what Windows 10 on Arm could be like if Microsoft licensed its Arm-based OS to the public rather than just to Windows 10 manufacturers. From a report: With Apple's new M1 Arm-based system on chip, Mac users who need to use Windows 10 can't run Microsoft's Arm-based version of Windows using Apple's Bootcamp. The key obstacle is that Microsoft doesn't license Windows 10 on Arm to any entities other than its own Surface group and Windows 10 on Arm OEMs like HP, Asus and Lenovo. Technically, there's nothing stopping owners of the M1 MacBook Air, MacBook Pro 13-inch or Mac mini from running Windows 10 on Arm, as Apple's software engineering chief Craig Federighi recently pointed out. [...]

But Microsoft's reluctance to create a license for Windows 10 on Arm for end users hasn't stopped creative engineers from putting together a working example of what things could be like if it did. AWS principal engineer Alexander Graf did just that, using the open-source QEMU virtualization software for Windows on Arm. QEMU emulates access to hardware such as the CPU and GPU. [...] "Who said Windows wouldn't run well on #AppleSilicon? It's pretty snappy here," Graf wrote in a tweet. Graf previously worked on the Kernel Virtual Machine (KVM) for Linux distribution SUSE for over a decade. Now he's a KVM developer at AWS, which this week announced new Mac instances for AWS Elastic Compute Cloud (EC2) based on Nitro System, an AWS hypervisor for EC2 instances. [...] A developer using the handle @imbushuo on Twitter has posted Geekbench versions 4 and 5 scores that compare Windows 10 on Arm on an M1 computer with the Microsoft-made Surface Pro X. Windows on an M1 got a single-core score of 1,288 and multi-core score of 5,685 whereas the Surface Pro X's scores were roughly 800 and 3,000 in those respective benchmarks.

Security

FBI Warns of Email Forwarding Rules Being Abused in Recent Hacks (zdnet.com) 10

The US Federal Bureau of Investigation says that cyber-criminals are increasingly relying on email forwarding rules in order to disguise their presence inside hacked email accounts. From a report: In a PIN (Private Industry Notification) alert sent last week and made public today, the FBI says the technique has been seen and abused in recent BEC (Business Email Compromise) attacks reported over the summer. The hackers' technique relies on a feature found in some email services called "auto-forwarding email rules." As its name implies, the feature allows the owner of an email address to set up "rules" that forward (redirect) an incoming email to another address if a certain criteria is met. Threat actors absolutely love email auto-forwarding rules as they allow them to receive copies of all incoming emails without having to log into an account each day -- and be at risk of triggering a security warning for a suspicious login.
Security

Malicious npm Packages Caught Installing Remote Access Trojans (zdnet.com) 20

The security team behind the "npm" repository for JavaScript libraries removed two npm packages this Monday for containing malicious code that installed a remote access trojan (RAT) on the computers of developers working on JavaScript projects. From a report: The name of the two packages was jdb.js and db-json.js., and both were created by the same author and described themselves as tools to help developers work with JSON files typically generated by database applications. Both packages were uploaded on the npm package registry last week and were downloaded more than 100 times before their malicious behavior was detected by Sonatype, a company that scans package repositories on a regular basis. According to Sonatype's Ax Sharma, the two packages contained a malicious script that executed after web developers imported and installed any of the two malicious libraries. The post-install script performed basic reconnaissance of the infected host and then attempted to download and run a file named patch.exe that later installed njRAT, also known as Bladabindi, a very popular remote access trojan that has been used in espionage and data theft operations since 2015.
Security

iPhone Zero-Click Wi-Fi Exploit is One of the Most Breathtaking Hacks Ever (arstechnica.com) 114

Dan Goodin, writing for ArsTechnica: Earlier this year, Apple patched one of the most breathtaking iPhone vulnerabilities ever: a memory corruption bug in the iOS kernel that gave attackers remote access to the entire device -- over Wi-Fi, with no user interaction required at all. Oh, and exploits were wormable -- meaning radio-proximity exploits could spread from one nearby device to another, once again, with no user interaction needed. This Wi-Fi packet of death exploit was devised by Ian Beer, a researcher at Project Zero, Google's vulnerability research arm. In a 30,000-word post published on Tuesday afternoon, Beer described the vulnerability and the proof-of-concept exploit he spent six months developing single-handedly. Almost immediately, fellow security researchers took notice.

"This is a fantastic piece of work," Chris Evans, a semi-retired security researcher and executive and the founder of Project Zero, said in an interview. "It really is pretty serious. The fact you don't have to really interact with your phone for this to be set off on you is really quite scary. This attack is just you're walking along, the phone is in your pocket, and over Wi-Fi someone just worms in with some dodgy Wi-Fi packets." Beer's attack worked by exploiting a buffer overflow bug in a driver for AWDL, an Apple-proprietary mesh networking protocol that makes things like Airdrop work. Because drivers reside in the kernel -- one of the most privileged parts of any operating system -- the AWDL flaw had the potential for serious hacks. And because AWDL parses Wi-Fi packets, exploits can be transmitted over the air, with no indication that anything is amiss.

Microsoft

Microsoft's New Windows Feature Experience Packs Are Smaller Updates To Windows 10 (theverge.com) 30

Microsoft has started testing smaller feature updates for Windows 10 in the form of a Windows Feature Experience Pack. The branding appeared inside Windows 10 earlier this year, but Microsoft has only confirmed what the packs will be used for this week. From a report: The Windows Feature Experience Pack will be used to "improve certain features and experiences that are now developed independently of the OS," according to Microsoft. The first feature pack has been released to Windows 10 beta testers this week, and it includes the ability to use the built-in screen snipping app to paste screenshots directly into folders within the File Explorer. The pack also includes a split keyboard mode for 2-in-1 touch devices.
Microsoft

Microsoft Will Remove User Names from 'Productivity Score' Feature After Privacy Backlash (geekwire.com) 37

Microsoft says it will make changes in its new Productivity Score feature, including removing the ability for companies to see data about individual users, to address concerns from privacy experts that the tech giant had effectively rolled out a new tool for snooping on workers. From a report: "Going forward, the communications, meetings, content collaboration, teamwork, and mobility measures in Productivity Score will only aggregate data at the organization level -- providing a clear measure of organization-level adoption of key features," wrote Jared Spataro, Microsoft 365 corporate vice president, in a post this morning. "No one in the organization will be able to use Productivity Score to access data about how an individual user is using apps and services in Microsoft 365." The company rolled out its new "Productivity Score" feature as part of Microsoft 365 in late October. It gives companies data to understand how workers are using and adopting different forms of technology. It made headlines over the past week as reports surfaced that the tool lets managers see individual user data by default. As originally rolled out, Productivity Score turned Microsoft 365 into a "full-fledged workplace surveillance tool," wrote Wolfie Christl of the independent Cracked Labs digital research institute in Vienna, Austria. "Employers/managers can analyze employee activities at the individual level (!), for example, the number of days an employee has been sending emails, using the chat, using 'mentions' in emails etc."
Microsoft

Microsoft Removes 18 Malicious Edge Extensions for Injecting Ads Into Web Pages (zdnet.com) 15

Microsoft has removed 18 Edge browser extensions from the Edge Add-ons portal after the extensions were caught injecting ads into users' web search results pages. From a report: The extensions were removed between November 20 and November 25 after Microsoft received multiple complaints from users via Reddit. A subsequent investigation found multiple abusive extensions that had been uploaded on Microsoft's new fledgling Edge Add-ons portal. According to a list shared by a Microsoft community manager, the 18 extensions can be grouped into two categories. The first one is for extensions that tried to pass as the official versions of various apps, even if those apps didn't have official versions for Edge. This included: NordVPN, Adguard VPN, TunnelBear VPN, Ublock Adblock Plus, Greasemonkey, and Wayback Machine.
Security

Companies Urged To Adjust Hiring Requirements for Cyber Jobs (wsj.com) 164

Companies need millions more cybersecurity professionals to fill roles around the world, but researchers say outlandish job requirements are the problem, rather than a lack of workers. From a report: Around 3.1 million professionals are needed to bridge the cybersecurity talent gap, a trade association for cybersecurity professionals estimated in a November report. The International Information System Security Certification Consortium, known as ISC2, said world-wide employment in the field would need to grow 89% to meet security requirements. However, excessive requirements for years of experience and professional certifications plus inflated expectations for junior roles aren't uncommon, said Chase Cunningham, principal analyst at research firm Forrester. He said that results in the perpetual problem of such positions going unfilled because companies often target overqualified candidates who can command greater salaries than these jobs tend to offer.
United States

Are Tech Workers Fleeing the San Francisco Bay Area? (nbcnews.com) 196

NBC News reports: Many urban centers have seen residents move out in large numbers since the start of stay-at-home orders in March, but the shift has been especially dramatic for San Francisco, a city that was already experiencing rapid change because of the tech industry. Software engineers, CEOs and venture capitalists have chosen to jump from the Bay Area to places such as Denver, Miami and Austin, Texas, citing housing costs, California's relatively high income tax and the Bay Area's general resistance to rapid growth and change.

The scale of the departures is visible in vacant high-end apartments, moth-balled offices and quieter streets in neighborhoods popular with tech workers. And while no one is exactly celebrating, especially as Covid-19 has devastated the incomes of many people, some residents were ready to take a break from the rich.... Rents may have fallen 20 percent or more from a year ago, but they're still high by national standards, and many artists left the city a long time ago.

Although some companies such as Pinterest have canceled leases, Google is expanding its offices in San Francisco, a sign of the tech industry's attachment to the city despite the local hostility and the predictions of a permanent work-from-home culture...

Tracy Rosenberg, executive director of Media Alliance, a San Francisco nonprofit that is often critical of the power of tech companies, said she wonders whether tech workers will want to return to a place where they've received a mixed welcome. "The level of tech blowback in San Francisco and the Bay Area was going up in intensity," she said. "I think there'll be sort of a reluctance to come back and face that, because that was reaching a level that was hard to live with — when you are the cause of all social problems, in the eyes of a significant part of the population, at least."

Government

Report Claims America's CIA Also Controlled a Second Swiss Encryption Firm (courthousenews.com) 100

Long-time Slashdot reader SonicSpike brings this report from AFP: Swiss politicians have voiced outrage and demanded an investigation after revelations that a second Swiss encryption company was allegedly used by the CIA and its German counterpart to spy on governments worldwide. "How can such a thing happen in a country that claims to be neutral like Switzerland?" co-head of Switzerland's Socialist Party, Cedric Wermuth, asked in an interview with Swiss public broadcaster SRF late Thursday. He called for a parliamentary inquiry after an SRF investigation broadcast on Wednesday found that a second Swiss encryption firm had been part of a spectacular espionage scheme orchestrated by U.S. and German intelligence services.

A first investigation had revealed back in February an elaborate, decades-long set-up, in which the CIA and its German counterpart creamed off the top-secret communications of governments through their hidden control of a Swiss encryption company called Crypto.

SRF's report this week found that a second but smaller Swiss encryption firm, Omnisec, had been used in the same way.

That company, which was split off from Swiss cryptographic equipment maker Gretag in 1987, sold voice, fax and data encryption equipment to governments around the world until it halted operations two years ago. SRF's investigative program Rundschau concluded that, like Crypto, Omnisec had sold manipulated equipment to foreign governments and armies. Omnisec meanwhile also sold its faulty OC-500 series devices to several federal agencies in Switzerland, including its own intelligence agencies, as well as to Switzerland's largest bank, UBS, and other private companies in the country, the SRF investigation showed.

The findings unleashed fresh outrage in Switzerland, which is still reeling from the Crypto revelations.

The first compromised cryptography company "served for decades as a Trojan horse to spy on governments worldwide," according to the article, citing news reports from SRF, the Washington Post and German broadcaster ZDF. "The company supplied devices for encoded communications to some 120 countries from after World War II to the beginning of this century, including to Iran, South American governments, India and Pakistan.

"Unknown to those governments, Crypto was secretly acquired in 1970 by the U.S. Central Intelligence Agency together with the then West Germanyâ(TM)s BND Federal Intelligence Service."
Bug

New Videogame Bug Turns Spider-Man Into a Trash Can (gamespot.com) 52

A new bug in the PlayStation game Spider-Man: Miles Morales "turns Miles into various inanimate objects, including bricks, cardboard boxes, and even a trash can," reports GameSpot: Despite Miles' changed appearance, he can still perform many of his heroic antics, including web-swinging and beating up bad guys. It's an important lesson to all of us in these trying times: You might look like trash, but you can still do your job.
Today Engadget reports that the glitch even turns Spider-Man into a patio heater: If you've ever wanted to keep people toasty warm while fighting crime, now's your chance.

We've asked [the game's creator] Insomniac Games for comment, although it already tweeted that the hiccup was "equally embarrassing as it is heart-warming." Into the Spider-Verse's Phil Lord joked that the heater would find its way into the sequel if the team had "any self respect at all."

Transportation

Raspberry Pi Used To Hack Tesla Model X SUV Key Fob (tomshardware.com) 43

Pig Hogger (Slashdot reader #10,379) writes: According to this Tom's Hardware story, a Belgian PhD student managed to wrest full control of a Tesla Model X SUV, by way of hijacking the Bluetooth keyfob and reprogramming it, using a Raspberry Pi.

Tesla has since issued a software update to protect against that kind of attack

Since the attack is done via Bluetooth, control could be gained wirelessly from 5 meters away.

According to the article this is the third time the same student "has managed to exploit the key fob and gain access to the car. Previously he was able to clone the fob..."

Computer Weekly also got an interesting quote from a senior security consultant at the electronic design automation company Synopsys, who argues that the research "demonstrates the impacts of security requirements and security features not having proper validation."
Privacy

A Hacker is Selling Access To the Email Accounts of Hundreds of C-Level Executives (zdnet.com) 40

A threat actor is currently selling passwords for the email accounts of hundreds of C-level executives at companies across the world. From a report: The data is being sold on a closed-access underground forum for Russian-speaking hackers named Exploit.in, ZDNet has learned this week. The threat actor is selling email and password combinations for Office 365 and Microsoft accounts, which he claims are owned by high-level executives occupying functions such as: CEO, COO, CFO, CMO, CTO, President, VP, Exec Assistant, Finance Manager, Accountant, and Director. Access to any of these accounts is sold for prices ranging from $100 to $1,500, depending on the company size and user's role.
Windows

Microsoft's 'Project Latte' Aims To Bring Android Apps To Windows 10 (windowscentral.com) 65

Windows Central reports: Microsoft is working on a software solution that would allow app developers to bring their Android apps to Windows 10 with little to no code changes by packaging them as an MSIX and allowing developers to submit them to the Microsoft Store. According to sources familiar with the matter, the project is codenamed 'Latte' and I'm told it could show up as soon as next year. The company has toyed with the idea of bringing Android apps to Windows 10 before via a project codenamed Astoria that never saw the light of day. Project Latte aims to deliver a similar product, and is likely powered by the Windows Subsystem for Linux (WSL.) Microsoft will need to provide its own Android subsystem for Android apps to actually run, however.

Microsoft has announced that WSL will soon get support for GUI Linux applications, as well as GPU acceleration which should aid the performance of apps running through WSL. It's unlikely that Project Latte will include support for Play Services, as Google doesn't allow Play Services to be installed on anything other than native Android devices and Chrome OS. This means that apps which require Play Services APIs will need to be updated to remove those dependencies before they can be submitted on Windows 10.

Security

Patients of a Vermont Hospital Are Left 'in the Dark' After a Cyberattack (nytimes.com) 112

A wave of damaging attacks on hospitals upended the lives of patients with cancer and other ailments. From a report: At lunchtime on Oct. 28, Colleen Cargill was in the cancer center at the University of Vermont Medical Center, preparing patients for their chemotherapy infusions. A new patient will sometimes be teary and frightened, but the nurses try to make it welcoming, offering trail mix and a warm blanket, a seat with a view of a garden. Then they work with extreme precision: checking platelet and white blood cell counts, measuring each dosage to a milligram per square foot of body area, before settling the person into a port and hooking them up to an IV. That day, though, Ms. Cargill did a double-take: When she tried to log in to her work station, it booted her out. Then it happened again. She turned to the system of pneumatic tubes used to transport lab work. What she saw there was a red caution symbol, a circle with a cross. She walked to the backup computer. It was down, too.

"I wasn't panicky," she said, "and then I noticed my cordless phone didn't work." That was, she said, the beginning of the worst 10 days of her career. Cyberattacks on America's health systems have become their own kind of pandemic over the past year as Russian cybercriminals have shut down clinical trials and treatment studies for the coronavirus vaccine and cut off hospitals' access to patient records, demanding multimillion-dollar ransoms for their return. Complicating the response, President Trump last week fired Christopher Krebs, the director of CISA, the cybersecurity agency responsible for defending critical systems, including hospitals and elections, against cyberattacks, after Mr. Krebs disputed Mr. Trump's baseless claims of voter fraud. The attacks have largely unfolded in private, as hospitals scramble to restore their systems -- or to quietly pay the ransom -- without releasing information that could compromise an F.B.I. investigation. [...] The latest wave of attacks, which hit about a dozen hospitals in the United States, was believed to have been conducted by a particularly powerful group of Russian-speaking hackers that deployed ransomware via TrickBot, a vast network of infected computers used for cyberattacks, according to security researchers who are tracking the attacks.

Microsoft

Microsoft Productivity Score Feature Criticised as Workplace Surveillance (theguardian.com) 60

Microsoft has been criticised for enabling "workplace surveillance" after privacy campaigners warned that the company's "productivity score" feature allows managers to use Microsoft 365 to track their employees' activity at an individual level. From a report: The tools, first released in 2019, are designed to "provide you visibility into how your organisation works," according to a Microsoft blogpost, and aggregate information about everything from email use to network connectivity into a headline percentage for office productivity. But by default, reports also let managers drill down into data on individual employees, to find those who participate less in group chat conversations, send fewer emails, or fail to collaborate in shared documents. "This is so problematic at many levels," tweeted the Austrian researcher Wolfie Christl, who raised alarm about the feature. "Employers are increasingly exploiting metadata logged by software and devices for performance analytics and algorithmic control," Christl added. "MS is providing the tools for it. Practices we know from software development (and factories and call centres) are expanded to all white-collar work."
Security

US Fertility Says Patient Data Was Stolen in a Ransomware Attack (techcrunch.com) 15

U.S. Fertility, one of the largest networks of fertility clinics in the United States, has confirmed it was hit by a ransomware attack and that data was taken. From a report: The company was formed in May as a partnership between Shady Grove Fertility, a fertility clinic with dozens of locations across the U.S. east coast, and Amulet Capital Partners, a private equity firm that invests largely in the healthcare space. As a joint venture, U.S. Fertility now claims 55 locations across the U.S., including California. In a statement, U.S. Fertility said that the hackers "acquired a limited number of files" during the month that they were in its systems, until the ransomware was triggered on September 14. That's a common technique of data-stealing ransomware, which steals data before encrypting the victim's network for ransom. Some ransomware groups publish the stolen files on their websites if their ransom demand isn't paid. U.S. Fertility said some personal information, like names and addresses, were taken in the attack. Some patients also had their Social Security numbers taken. But the company warned that the attack may have involved protected health information.

Slashdot Top Deals