Spam

A Massive Spam Attack Is Ruining Public 'Among Us' Games (engadget.com) 60

Just days after US Representative Alexandria Ocasio-Cortez played Among Us to an audience of more than 435,000 viewers, InnerSloth, the developer of the popular multiplayer title, is struggling to contain a spam attack that is affecting most of the game's community. Engadget reports: The hack started to spread through the game's userbase on Thursday evening. It causes players to spam their match's text chat with messages that direct people to the YouTube and Discord channels of a person who goes by the pseudonym "Eris Loris," threatening them if they don't subscribe. For good measure, some of the messages also promote President Donald Trump's 2020 campaign.

InnerSloth said it's "super duper aware of the current hacking issue" and that it had planned to roll out an emergency server-side update to address the spam. Forest Willard, one of three developers who make up the InnerSloth team, said they had begun rolling out the update at some point in the middle of the night, but it doesn't seem to have addressed the issue; new reports of spam-filled matches continue to flood Twitter. The studio is advising people to play private games with friends while it works to solve the problem.

As for the hacker, it appears their primary motive in all of this was to troll people. "I was curious to see what would happen, and personally I found it funny," they told Kotaku. "The anger and hatred is the part that makes it funny. If you care about a game and are willing to go and spam dislike some random dude on the internet because you cant [sic] play it for three minutes, it's stupid."

United States

National Guard Called In To Thwart Cyberattack in Louisiana Weeks Before Election (reuters.com) 31

The Louisiana National Guard was called in to stop a series of cyberattacks aimed at small government offices across the state in recent weeks, Reuters reported Friday, citing two people with knowledge of the events, highlighting the cyber threat facing local governments in the run up to the 2020 U.S. presidential election. From the report: The situation in Louisiana follows a similar case in Washington state, according to a cybersecurity consultant familiar with the matter, where hackers infected some government offices with a type of malware known for deploying ransomware, which locks up systems and demands payment to regain access. Senior U.S. security officials have warned here since at least 2019 that ransomware poses a risk to the U.S. election, namely that an attack against certain state government offices around the election could disrupt systems needed to administer aspects of the vote. It is unclear if the hackers sought to target systems tied to the election in Louisiana or were simply hoping for a payday. Yet the attacks raised alarms because of the potential harm it could have led to and due to evidence suggesting a sophisticated hacking group was involved. Experts investigating the Louisiana incidents found a tool used by the hackers that was previously linked to a group associated with the North Korean government, according to a person familiar with the investigation.
Privacy

Bot Generated Fake Nudes of Over 100,000 Women Without Their Knowledge, Says Report (forbes.com) 57

An anonymous reader quotes a report from Forbes: Around 104,852 women had their photos uploaded to a bot, on the WhatsApp-like text messaging app Telegram, which were then used to generate computer-generated fake nudes of them without their knowledge or consent, researchers revealed on Tuesday. These so-called "deepfake" images were created by an ecosystem of bots on the messaging app Telegram that could generate fake nudes on request, according to a report released by Sensity, an intelligence firm that specializes in deepfakes.

The report found that users interacting with these bots were mainly creating fake nudes of women they know from images taken from social media, which is then shared and traded on other Telegram channels. The Telegram channels the researchers examined were made up of 101,080 members worldwide, with 70% coming from Russia and other eastern European countries. A small number of individuals targeted by the bot appear to be underage. According to the report, the bots received significant advertising on the Russian social media website VK. However, the Russian social platform's press team told Forbes that these communities or links were not promoted using VK's advertising tools, adding "VK doesn't tolerate such content or links... and blocks communities that distribute them."

Twitter

Dutch Hacker Says He Logged Into President Trump's Twitter Account (volkskrant.nl) 99

An anonymous reader shares a report: The researcher, Victor Gevers, had access to Trump's personal messages, could post tweets in his name and change his profile. Gevers took screenshots when he had access to Trump's account. These screenshots were shared with de Volkskrant by the monthly opinion magazine Vrij Nederland. Dutch security experts find Gevers' claim credible. The Dutchman alerted Trump and American government services to the security leak. After a few days, he was contacted by the American Secret Service in the Netherlands. This agency is also responsible for the security of the American President and took the report seriously, as evidenced by correspondence seen by de Volkskrant. Meanwhile Trump's account has been made more secure. This is not the first time that Dutch hackers succeeded in taking over Donald Trump's Twitter account. The first time was four years ago, just before the 2016 elections, when three hackers jointly managed to retrieve Trump's password and access his account. That someone has now succeeded again, is remarkable. During the previous presidential elections Russian hackers attempted to influence the elections on a large scale. Subsequently, social media have taken various steps to prevent manipulation. The password was "maga2020!"
Botnet

Microsoft Says It Took Down 94% of TrickBot's Command and Control Servers (zdnet.com) 24

TrickBot survived an initial takedown attempt, but Microsoft and its partners are countering TrickBot operators after every move, taking down any new infrastructure the group is attempting to bring up online. From a report: Last week, a coalition of cyber-security firms led by Microsoft orchestrated a global takedown against TrickBot, one of today's largest malware botnets and cybercrime operations. Even if Microsoft brought down TrickBot infrastructure in the first few days, the botnet survived, and TrickBot operators brought new command and control (C&C) servers online in the hopes of continuing their cybercrime spree. But as several sources in the cyber-security industry told ZDNet last week, everyone expected TrickBot to fight back, and Microsoft promised to continue cracking down against the group in the weeks to come. In an update posted today on its takedown efforts, Microsoft confirmed a second wave of takedown actions against TrickBot. The OS maker said it has slowly chipped away at TrickBot infrastructure over the past week and has taken down 94% of the botnet's C&C servers, including the original servers and new ones brought online after the first takedown.
Encryption

The Police Can Probably Break Into Your Phone (nytimes.com) 96

At least 2,000 law enforcement agencies have tools to get into encrypted smartphones, according to new research, and they are using them far more than previously known. From a report: In a new Apple ad, a man on a city bus announces he has just shopped for divorce lawyers. Then a woman recites her credit card number through a megaphone in a park. "Some things shouldn't be shared," the ad says, "iPhone helps keep it that way." Apple has built complex encryption into iPhones and made the devices' security central to its marketing pitch. That, in turn, has angered law enforcement. Officials from the F.B.I. director to rural sheriffs have argued that encrypted phones stifle their work to catch and convict dangerous criminals. They have tried to force Apple and Google to unlock suspects' phones, but the companies say they can't. In response, the authorities have put their own marketing spin on the problem. Law enforcement, they say, is "going dark." Yet new data reveals a twist to the encryption debate that undercuts both sides: Law enforcement officials across the nation regularly break into encrypted smartphones.

That is because at least 2,000 law enforcement agencies in all 50 states now have tools to get into locked, encrypted phones and extract their data, according to years of public records collected in a report by Upturn, a Washington nonprofit that investigates how the police use technology. At least 49 of the 50 largest U.S. police departments have the tools, according to the records, as do the police and sheriffs in small towns and counties across the country, including Buckeye, Ariz.; Shaker Heights, Ohio; and Walla Walla, Wash. And local law enforcement agencies that don't have such tools can often send a locked phone to a state or federal crime lab that does. With more tools in their arsenal, the authorities have used them in an increasing range of cases, from homicides and rapes to drugs and shoplifting, according to the records, which were reviewed by The New York Times. Upturn researchers said the records suggested that U.S. authorities had searched hundreds of thousands of phones over the past five years. While the existence of such tools has been known for some time, the records show that the authorities break into phones far more than previously understood -- and that smartphones, with their vast troves of personal data, are not as impenetrable as Apple and Google have advertised. While many in law enforcement have argued that smartphones are often a roadblock to investigations, the findings indicate that they are instead one of the most important tools for prosecutions.

Businesses

Employers Warn of Rising Political Tensions At Work (techtarget.com) 579

dcblogs writes: A significant number of employees are avoiding co-workers because of political views, says one research group. "Not only are employees avoiding one another, but they're also having a tougher time staying focused," said Brent Cassell, a Gartner analyst. The firm, which has surveyed workers, say the office tensions over politics are at their highest level. Firms are also on guard against the possibility of workplace disruptions and arguments. In Florida, a battleground state, there's a lot of concern about rising office tensions. "I think we're going to see an interesting atmosphere over the next couple of weeks," said Heather Deyrieux, president of the HR Florida State Council.
Businesses

Offices Resort To Sensors In Futile Attempts To Keep Workers Apart (bloomberg.com) 96

An anonymous reader quotes a report from Bloomberg: Millions of workers in recent months have returned to offices outfitted with new pandemic protocols meant to keep them healthy and safe. But temperature checks and plexiglass barriers between desks can't prevent one of the most dangerous workplace behaviors for the spread of Covid-19 -- the irresistible desire to mingle. "If you have people coming into the office, it's very rare for them consistently to be six feet apart," said Kanav Dhir, the head of product at VergeSense, a company that has 30,000 object-recognition sensors deployed in office buildings around the world tracking worker whereabouts.

Since the worldwide coronavirus outbreak, the company has found that 60% of interactions among North American workers violate the U.S. Centers for Disease Control and Prevention's six-foot distancing guidelines, as do an even higher share in Asia, where offices usually are smaller. [...] For those employers pushing ahead with a return to the office, sensors that measure room occupancy are proving to be a necessity, said Doug Stewart, co-head of digital buildings at the technology unit Cushman & Wakefield, which manages about 785-million-square feet of commercial space in North and South America. Most offices are already fitted with sensors of some kind, even if it's just a badging system or security cameras. Those lagging on such capabilities are now scrambling to add more, he said. The systems were used before the pandemic to jam as many people together in the most cost-effective way, not limit workplace crowding or keep employees away from each other, Stewart said. With that in mind, companies can analyze the data all they want, but changing human behavior -- we're social creatures, after all -- is harder, he said.

Understanding worker habits is more useful if you have a way to nudge them into new patterns. Since the pandemic began, Radiant RFID LLC has sold 10,000 wristbands that vibrate when co-workers are too close to each other. The technology was originally designed to warn workers away from dangerous machinery, not other people. So far, the wristbands are responsible for reducing unsafe contacts by about 65%, said Kenneth Ratton, chief executive of the company, which makes radio-communication devices. At this point, the data on more than 3 billion encounters shows the average worker has had about 300 interactions closer than six feet lasting 10 minutes or more. Nadia Diwas is using another kind of technology: a wireless key fob she carries in her pocket made by her employer, Semtech Corp., which tracks her movements and interactions -- making it useful for contact tracing if someone gets sick, which is as important as warning people they are too close. The technology originally was developed by Semtech to help devices such as thermostats communicate on the so-called internet of things.

Advertising

Adblockers Installed 300,000 Times Are Malicious and Should Be Removed Now (arstechnica.com) 33

An anonymous reader quotes a report from Ars Technica: Adblocking extensions with more than 300,000 active users have been surreptitiously uploading user browsing data and tampering with users' social media accounts thanks to malware its new owner introduced a few weeks ago, according to technical analyses and posts on Github. Hugo Xu, developer of the Nano Adblocker and Nano Defender extensions, said 17 days ago that he no longer had the time to maintain the project and had sold the rights to the versions available in Google's Chrome Web Store. Xu told me that Nano Adblocker and Nano Defender, which often are installed together, have about 300,000 installations total.

Four days ago, Raymond Hill, maker of the uBlock Origin extension upon which Nano Adblocker is based, revealed that the new developers had rolled out updates that added malicious code. The first thing Hill noticed the new extension doing was checking if the user had opened the developer console. If it was opened, the extension sent a file titled "report" to a server at https://def.dev-nano.com/. "In simple words, the extension remotely checks whether you are using the extension dev tools -- which is what you would do if you wanted to find out what the extension is doing," he wrote. The most obvious change end users noticed was that infected browsers were automatically issuing likes for large numbers of Instagram posts, with no input from users. Cyril Gorlla, an artificial intelligence and machine learning researcher at the University of California in San Diego, told me that his browser liked more than 200 images from an Instagram account that didn't follow anyone. The screenshot to the right shows some of the photos involved.

Data Storage

Backblaze Hard Drive Stats Q3 2020 (backblaze.com) 37

Backblaze's Q3 2020 hard drive stats: As of September 30, 2020, Backblaze had 153,727 spinning hard drives in our cloud storage ecosystem spread across four data centers. Of that number, there were 2,780 boot drives and 150,947 data drives. This review looks at the Q3 2020 and lifetime hard drive failure rates of the data drive models currently in operation in our data centers and provides a handful of insights and observations along the way. [...] There are several models with zero drive failures in the quarter. That's great, but when we dig in a little we get different stories for each of the drives.

The 18TB Seagate model (ST18000NM000J) has 300 drive days and they've been in service for about 12 days. There were no out of the box failures which is a good start, but that's all you can say.
The 16TB Seagate model (ST16000NM001G) has 5,428 drive days which is low, but they've been around for nearly 10 months on average. Still, I wouldn't try to draw any conclusions yet, but a quarter or two more like this and we might have something to say.
The 4TB Toshiba model (MD04ABA400V) has only 9,108 drive days, but they have been putting up zeros for seven quarters straight. That has to count for something.
The 14TB Seagate model (ST14000NM001G) has 21,120 drive days with 2,400 drives, but they have only been operational for less than one month. Next quarter will give us a better picture.
The 4TB HGST (model: HMS5C4040ALE640) has 274,923 drive days with no failures this quarter.

Security

Mysterious Hackers Donating Stolen Money (bbc.com) 49

A hacking group is donating stolen money to charity in what is seen as a mysterious first for cyber-crime that's puzzling experts. smooth wombat writes: Darkside hackers claim to have extorted millions of dollars from companies, but say they now want to "make the world a better place." In a post on the dark web, the gang posted receipts for $10,000 in Bitcoin donations to two charities. One of them, Children International, says it will not be keeping the money. The move is being seen as a strange and troubling development, both morally and legally. In the blog post on 13 October, the hackers claim they only target large profitable companies with their ransomware attacks. The attacks hold organisations' IT systems hostage until a ransom is paid. They wrote: "We think that it's fair that some of the money the companies have paid will go to charity. No matter how bad you think our work is, we are pleased to know that we helped changed someone's life. Today we sended (sic) the first donations." The cyber-criminals posted the donation along with tax receipts they received in exchange for the 0.88 Bitcoin they had sent to two charities, The Water Project and Children International.
IT

Seven Mobile Browsers Vulnerable To Address Bar Spoofing Attacks (zdnet.com) 13

In a report published today by cyber-security firm Rapid7, the company said it worked with Pakistani security researcher Rafay Baloch to disclose ten new address bar spoofing vulnerabilities across seven mobile browser apps. From a report: Impacted browsers include big names like Apple Safari, Opera Touch, and Opera Mini, but also niche apps like Bolt, RITS, UC Browser, and Yandex Browser. The issues were discovered earlier this year and reported to browser makers in August. The big vendors patched the issues right away, while the smaller vendors didn't even bother replying to the researchers, leaving their browsers vulnerable to attacks. "Exploitation all comes down to 'JavaScript shenanigans'," said Rapid7's Research Director, Tod Beardsley. The Rapid7 exec says that by messing with the timing between when the page loads and when the browser gets a chance to refresh the address bar URL, a malicious site could force the browser to show the wrong address.
Google

Google Photos Revives Its Prints Subscription Service (techcrunch.com) 15

Google Photos is reviving its photo printing subscription service and introducing same-day prints. The company earlier this year had briefly tested a new program that used A.I. to suggest the month's 10 best photos, which were then shipped to your home automatically. But Google ended the test on June 30. From a report: During the trial, Google had offered users a $7.99 per month subscription that would automatically select 10 photos from one of three themes, including people and pets, landscapes, or "a little bit of everything" mix. The 4x6 photos were printed on matte, white cardstock with a 1/8-inch border. The new subscription, launching soon, leverages feedback from the early tests to now give users more control over which prints they receive and how they look. It also drops the price to $6.99 per month, including shipping and before tax. With the new Premium Print Series, as the subscription is called, Google Photos will use machine learning techniques to pick 10 of your recent photos to print. But users can edit the photo selection and they can choose either a matte or glossy finish or add a border before the photos ship.
Microsoft

Microsoft Teams With SpaceX To Push Cloud Battle With Amazon Into Orbit (zdnet.com) 31

Microsoft is teaming with Elon Musk's SpaceX and others as the software giant opens a new front in its cloud-computing battle with Amazon.com targeting space customers. From a report: Microsoft would help connect and deploy new services using swarms of low-orbit spacecraft being proposed by SpaceX [Editor's note: the link may be paywalled; alternative source], and more traditional fleets of satellites circling the earth at higher altitudes. Microsoft's initiative targeting commercial and government space businesses, formally launched Tuesday, comes about three months after Amazon Web Services, the e-retailer's cloud unit, disclosed its space-focused effort. Some analysts have projected that overall revenue from space-related cloud services could total about $15 billion by the end of the decade, at least several times higher than current levels. Competition in the cloud between Amazon, the market leader, and No. 2 Microsoft has been heating up in recent years. The pandemic has intensified the fight as companies accelerate their shift to the cloud and make vendor choices that could last for years. [...] SpaceX, which is in the process of deploying its Starlink project consisting of thousands of high-speed internet satellites intended to provide connectivity around the globe, makes a natural partner for Microsoft. A major reason is that Amazon founder Jeff Bezos is pursuing his own low-orbit satellite constellation. Mr. Bezos also owns Blue Origin, a rocket company competing with SpaceX.
The Internet

QAnon/8Chan Sites Back Online After Being Ousted By DDoS-Protection Vendor (arstechnica.com) 211

An anonymous reader quotes a report from Ars Technica: A few dozen QAnon and 8chan-related sites were knocked offline temporarily yesterday when a DDoS-protection vendor disabled their access, according to an article by security reporter Brian Krebs. The websites [...] are connected to the Internet via the US-based ISP VanwaTech, which in turn "had a single point of failure on its end," Krebs wrote. "The swath of Internet addresses serving the various 8kun/QAnon sites were being protected from otherwise crippling and incessant distributed-denial-of-service (DDoS) attacks by Hillsboro, Ore. based CNServers LLC."

That changed yesterday when security researcher Ron Guilmette called CNServers, which apparently didn't realize it was providing security protection to the websites. "Within minutes of that call, CNServers told its customer -- Spartan Host Ltd., which is registered in Belfast, Northern Ireland -- that it would no longer be providing DDoS protection for the set of 254 Internet addresses that Spartan Host was routing on behalf of VanwaTech," Krebs wrote. Those 254 addresses included the few dozen related to QAnon and 8chan, which is now known as 8kun. The websites didn't remain offline for long because Spartan Host quickly "changed its settings so that VanwaTech's Internet addresses were protected from attacks by ddos-guard[.]net, a company based in St. Petersburg, Russia," Krebs wrote.
"VanwaTech CEO Nick Lim in November 2019 defended his company's role in keeping 8kun websites online, writing on Twitter, 'I do what I do because I truly believe in free speech and I believe in protecting people from cyber security attacks,'" adds Ars Technica.

Spartan Host founder Ryan McCully told Krebs yesterday that he intends to keep VanwaTech as a customer. "We follow the 'law of the land' when deciding what we allow to be hosted with us, with some exceptions to things that may cause resource issues etc.," McCully told Krebs. "Just because we host something, it doesn't say anything about [what] we do and don't support; our opinions don't come into hosted content decisions."

Further reading: Is QAnon an 8Chan Game Gone Wrong?
Businesses

IKEA To Buy Back Used Furniture In Recycling Push (bbc.com) 42

Last week, the BBC reported that IKEA, the world's biggest furniture business, is planning to launch a scheme to buy back your unwanted furniture you no longer need or want. From the report: Under the plan, it will offer vouchers worth up to 50% of the original price, to be spent at its stores. The "Buy Back" initiative will launch to coincide with Black Friday. "By making sustainable living more simple and accessible, Ikea hopes that the initiative will help its customers take a stand against excessive consumption this Black Friday and in the years to come," it said in reference to November 27, when lots of retailers offer discounts on their products.

The international scheme will see customers given vouchers to spend at Ikea stores, the value of which will depend on the condition of the items they are returning. Customers must log the item they wish to return and will then be given an estimate of its value. "As new" items, with no scratches, will get 50% of the original price, "very good" items, with minor scratches, will get 40% and "well used," with several scratches, will get 30%. They should then return them -- fully assembled -- to the returns desk where they will be checked and the final value agreed. The offer, which will run in 27 countries, applies to furniture typically without upholstery, such as the famous Billy bookcases, chairs, stools, desks and dining tables. Ikea said that anything that cannot be resold will be recycled. Ikea plans to have dedicated areas in every store where people can sell back their old furniture and find repaired or refurbished furniture.

Security

Google Confirms the Nest Secure Has Been Discontinued (androidpolice.com) 26

Google's Nest Secure alarm system, which was discussed on Slashdot for featuring an unlisted, disabled microphone, has been discontinued by Google, though it will continue functioning. Android Police reports: Google released the Nest Guard in 2017 as a simple security system with motion sensors and a keypad, but it never received an upgrade, even as other Nest devices were updated again and again. The product page for the Nest Guard on the Google Store was updated last week with a 'No longer available' message, possibly indicating it had been discontinued. Google later confirmed to Android Police that the Nest Guard will no longer be sold, but it will continue to work for people who have already bought it.
The Internet

Microsoft Adds Option To Disable JScript In Internet Explorer (zdnet.com) 21

As part of the October 2020 Patch Tuesday security updates, Microsoft has added a new option to Windows to let system administrators disable the JScript component inside Internet Explorer. ZDNet reports: The JScript scripting engine is an old component that was initially included with Internet Explorer 3.0 in 1996 and was Microsoft's own dialect of the ECMAScript standard (the JavaScript language). Development on the JScript engine ended, and the component was deprecated with the release of Internet Explorer 8.0 in 2009, but the engine remained in all Windows OS versions as a legacy component inside IE. Across the years, threat actors realized they could attack the JScript engine, as Microsoft wasn't actively developing it and only rarely shipped security updates, usually only when attacked by threat actors. [...]

Now, 11 years after deprecating the component, Microsoft is finally giving system administrators a way to disable JScript execution by default. According to Microsoft, the October 2020 Patch Tuesday introduces new registry keys that system administrators can apply and block the jscript.dll file from executing code. Details on how this can be done are available below, as taken from Microsoft's documentation.

Security

US Charges Russian Hackers Behind NotPetya, KillDisk, OlympicDestroyer Attacks (zdnet.com) 33

The US Department of Justice has unsealed charges today against six Russian nationals believed to be part of one of Russia's most elite and secretive hacking groups, universally known as Sandworm. From a report: US officials said all six nationals are officers in Unit 74455 of the Russian Main Intelligence Directorate (GRU), a military intelligence agency of the Russian Army, DOJ officials said today. Under orders from the Russian government, US officials said the six (believed to be part of a much larger group) conducted cyber-attacks on behalf of the Russian government with the intent to destabilize other countries, interfere in their internal politics, and cause havoc and monetary losses. Their attacks span the last decade and include some of the biggest cyber-attacks known to date: Ukrainian Government & Critical Infrastructure (between December 2015 to December 2016), French Elections (April and May 2017), Worldwide Businesses and Critical Infrastructure (aka NotPetya; June 2017), PyeongChang Winter Olympics Hosts, Participants, Partners, and Attendees (December 2017 through February 2018), PyeongChang Winter Olympics IT Systems (aka Olympic Destroyer; 2017 through February 2018), Novichok Poisoning Investigations (April 2018), and Georgian Companies and Government Entities (a 2018 spearphishing campaign targeting a major media company, 2019 efforts to compromise the network of Parliament, and a wide-ranging website defacement campaign in 2019.)
Security

Three npm Packages Opened Remote-Access Shells on Linux and Windows Systems (zdnet.com) 65

"Three JavaScript packages have been removed from the npm portal on Thursday for containing malicious code," reports ZDNet.

"According to advisories from the npm security team, the three JavaScript libraries opened shells on the computers of developers who imported the packages into their projects." The shells, a technical term used by cyber-security researchers, allowed threat actors to connect remotely to the infected computer and execute malicious operations. The npm security team said the shells could work on both Windows and *nix operating systems, such as Linux, FreeBSD, OpenBSD, and others.

All three packages were uploaded on the npm portal in May (first) and September 2018 (last two). Each package had hundreds of downloads since being uploaded on the npm portal. The packages names were:

plutov-slack-client
nodetest199
nodetest1010

"Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer," the npm security team said.

Slashdot Top Deals