Security

Billions of Devices Vulnerable To New 'BLESA' Bluetooth Spoofing Attack (zdnet.com) 27

An anonymous reader writes: "Billions of smartphones, tablets, laptops, and IoT devices are using Bluetooth software stacks that are vulnerable to a new security flaw disclosed over the summer," reports ZDNet. Named BLESA (Bluetooth Low Energy Spoofing Attack), the vulnerability impacts devices running the Bluetooth Low Energy (BLE) protocol, and affects the reconnection process that occurs when a device moves back into range after losing or dropping its pairing. A successful BLESA attack allows bad actors to connect with a device (by getting around reconnection authentication requirements) and send spoofed data to it. In the case of IoT devices, those malicious packets can convince machines to carry out different or new behavior. For humans, attackers could feed a device deceptive information. BLESA impacts billions of devices that run vulnerable BLE software stacks. Vulnerable are BLE software libraries like BlueZ (Linux-based IoT devices), Fluoride (Android), and the iOS BLE stack. Windows' BLE stack is not impacted.
IT

USB-C Was Supposed To Simplify Our Lives. Instead, It's a Total Mess. (medium.com) 155

USB-C is near-ubiquitous: Almost every modern laptop and smartphone has at least one USB-C port, with the exception of the iPhone, which still uses Apple's proprietary Lightning port. For all its improvements, USB-C has become a mess of tangled standards -- a nightmare for consumers to navigate despite the initial promise of simplicity. From a report: Anyone going all-in on USB-C will run into problems with an optional standard called Power Delivery. The standard allows devices to charge at a much higher wattage relative to older connectors, therefore allowing them to charge faster. But it requires the right combination of charger, cables, and device to actually achieve this. If you buy a USB-C charger that doesn't support Power Delivery and try to use it with a Microsoft Surface, for example, the laptop will complain that it's "not charging" despite receiving some power. Fixing this requires figuring out whether or not it's the cable or wall charger that doesn't support Power Delivery, and replacing it with something that does support it. There would be no way for a layperson to hold two USB-C chargers and know the difference between one that supports Power Delivery and one that doesn't.

Furthering the confusion, some devices actually can't be charged with chargers supporting Power Delivery, despite sporting a USB-C port -- because they weren't designed to negotiate the higher wattage being delivered by the Power Delivery standard. A pair of cheap Anker headphones I own, for example, refuse to charge when plugged into a MacBook charger. Other devices, like the Nintendo Switch, only partially support the standard, and some unsupported chargers have bricked devices, reportedly due to the Switch's maximum voltage being exceeded. Then there's DisplayPort and Thunderbolt, another set of standards supported by some USB-C devices. DisplayPort allows the use of an external display, such as a 4K monitor, but only supports one at a time at full resolution. Thunderbolt, yet another optional standard, is a much faster layer on top of USB-C that allows additional possibilities, like the use of multiple displays daisy-chained from a single port, or the use of an external graphics card. It uses the exact same connector, but can be identified with an additional "lightning" symbol when supported.

Security

Zerologon Attack Lets Hackers Take Over Enterprise Networks Within 3 Seconds (zdnet.com) 59

An anonymous reader writes: Researchers have developed and published a proof-of-concept exploit for a recently patched Windows vulnerability that can allow access to an organization's crown jewels -- the Active Directory domain controllers that act as an all-powerful gatekeeper for all machines connected to a network.

CVE-2020-1472, as the vulnerability is tracked, carries a critical severity rating from Microsoft as well as a maximum of 10 under the Common Vulnerability Scoring System. Exploits require that an attacker already have a foothold inside a targeted network, either as an unprivileged insider or through the compromise of a connected device. However, when this condition is met, it's literally game over for the attacked company, as an attacker can hijack its entire network within three seconds by leveraging a bug in the Netlogon authentication protocol cryptography by adding zero characters in certain Netlogon authentication parameters, bypassing authentication procedures and then changing the password for the DC server itself.
The technical report from Secura B.V., a Dutch security firm, is available here.
Security

Personal Information of Roughly 46,000 Veterans Exposed In VA Hack (cnn.com) 19

An anonymous reader quotes a report from CNN: The Department of Veterans Affairs said Monday that roughly 46,000 veterans had their personal information, including Social Security numbers, exposed in a data breach in which "unauthorized users" gained access to an online application used for making health care payments. A preliminary review of the incident indicated that the hackers accessed the application "to change financial information and divert payments from VA by using social engineering techniques and exploiting authentication protocols," according to the department's announcement.

"The Financial Services Center (FSC) determined one of its online applications was accessed by unauthorized users to divert payments to community health care providers for the- medical treatment of Veterans. The FSC took the application offline and reported the breach to VA's Privacy Office," the statement said. "To prevent any future improper access to and modification of information, system access will not be reenabled until a comprehensive security review is completed by the VA Office of Information Technology," it added.
The department is taking steps to alert veterans whose information was compromised. "To protect these Veterans, the FSC is alerting the affected individuals, including the next-of-kin of those who are deceased, of the potential risk to their personal information. The department is also offering access to credit monitoring services, at no cost, to those whose social security numbers may have been compromised," Monday's statement said.

"Veterans whose information was involved are advised to follow the instructions in the letter to protect their data. There is no action needed from Veterans if they did not receive an alert by mail, as their personal information was not involved in the incident," it adds.
Security

A Bug In Joe Biden's Campaign App Gave Anyone Access To Millions of Voter Files (techcrunch.com) 83

schwit1 shares a report from TechCrunch: A privacy bug in Democratic presidential candidate Joe Biden's official campaign app allowed anyone to look up sensitive voter information on millions of Americans, a security researcher has found. The campaign app, Vote Joe, allows Biden supporters to encourage friends and family members to vote in the upcoming U.S. presidential election by uploading their phone's contact lists to see if their friends and family members are registered to vote. The app uploads and matches the user's contacts with voter data supplied from TargetSmart, a political marketing firm that claims to have files on more than 191 million Americans.

When a match is found, the app displays the voter's name, age and birthday, and which recent election they voted in. This, the app says, helps users find people you know and encourage them to get involved." While much of this data can already be public, the bug made it easy for anyone to access any voter's information by using the app. The App Analyst, a mobile expert who detailed his findings on his eponymous blog, found that he could trick the app into pulling in anyone's information by creating a contact on his phone with the voter's name.
The Biden campaign fixed the bug and pushed out an app update on Friday.

"We were made aware about how our third-party app developer was providing additional fields of information from commercially available data that was not needed," Matt Hill, a spokesperson for the Biden campaign, told TechCrunch. "We worked with our vendor quickly to fix the issue and remove the information. We are committed to protecting the privacy of our staff, volunteers and supporters will always work with our vendors to do so."
Security

FBI Says Credential Stuffing Attacks Are Behind Some Recent Bank Hacks (zdnet.com) 30

The FBI has sent a private security alert to the US financial sector last week warning organizations about the increasing number of credential stuffing attacks that have targeted their networks and have led to breaches and considerable financial losses. From a report: Credential stuffing is a relatively new term in the cyber-security industry. [...] According to an FBI security advisory obtained by ZDNet today, credential stuffing attacks have increased in recent years and have now become a major problem for financial organizations. "Since 2017, the FBI has received numerous reports on credential stuffing attacks against US financial institutions, collectively detailing nearly 50,000 account compromises," the FBI said. "The victims included banks, financial services providers, insurance companies, and investment firms."
Businesses

At JPMorgan, Productivity Falls For Younger Employees At Home (bloomberg.com) 102

An anonymous reader quotes a report from Bloomberg: A troubling pattern emerged as most of JPMorgan Chase & Co.'s employees worked from home to stem the spread of Covid-19: productivity slipped. Work output by younger employees was particularly affected on Mondays and Fridays, according to findings discussed by Chief Executive Office Jamie Dimon in a private meeting with Keefe, Bruyette & Woods analysts. That, along with worries that remote work is no substitute for organic interaction, are part of why the biggest U.S. bank is urging more workers to return to offices over the coming weeks. "The WFH lifestyle seems to have impacted younger employees, and overall productivity and 'creative combustion' has taken a hit," KBW's Brian Kleinhanzl wrote in a Sept. 13 note to clients, citing an earlier meeting with Dimon. "Overall, Jamie thinks a shift back to the office will be good for the young employees and to foster creative ideas," Kleinhanzl wrote.
Security

CISA: Chinese State Hackers Are Exploiting F5, Citrix, Pulse Secure, and Exchange Bugs (zdnet.com) 26

The Cybersecurity and Infrastructure Security Agency (CISA) has published a security advisory today warning of a wave of attacks carried out by hacking groups affiliated with China's Ministry of State Security (MSS). From a report: CISA says that over the past year, Chinese hackers have scanned US government networks for the presence of popular networking devices and then used exploits for recently disclosed vulnerabilities to gain a foothold on sensitive networks. The list of targeted devices includes F5 Big-IP load balancers, Citrix and Pulse Secure VPN appliances, and Microsoft Exchange email servers. For each of these devices, major vulnerabilities have been publicly disclosed over the past 12 months, such as CVE-2020-5902, CVE-2019-19781, CVE-2019-11510, and CVE-2020-0688, respectively. According to a table summarizing Chinese activity targeting these devices published by CISA today, some attacks have been successful and enabled Chinese hackers to gain a foothold on federal networks.
Cloud

Microsoft Wants To Take on Amazon in Connecting Satellites To the Cloud (cnbc.com) 8

Microsoft is looking to challenge Amazon in offering a service that connects satellites directly to the company's cloud computing network, according to documents the company filed with the Federal Communications Commission last month. From a report: The effort shows how the two largest providers of cloud infrastructure -- data centers in far-flung places that can host websites and run applications with a smorgasbord of computing and storage services -- regularly seek to one-up each other. That way, the companies can appear ready and willing to meet many of the needs of prospective customers. Microsoft plans to connect a Spanish imaging satellite to two ground stations -- both located in Microsoft's home state of Washington -- to show that it can directly download satellite "data to the Azure Cloud for immediate processing," the FCC documents said.

A ground station, sometimes called an earth station, is the vital link for transmitting data to and from satellites in orbit. Microsoft notably proposed to construct one of the two ground stations itself at its data center in Quincy, Wash. The FCC on Sept. 2 authorized Microsoft to perform proof-of-concept demonstrations of the service. The authorization gives Microsoft a six month license that allows for communications and imagery data downloads. The Spanish satellite, called Deimos-2, was launched into orbit in June 2014. The satellite is operated by a subsidiary of Canadian satellite imagery company UrtheCast and, for the tests, the Deimos-2 satellite will only be in range of Microsoft's antennas for "just a few minutes."

Security

Security Researchers Detail New 'BlindSide' Speculative Execution Attack (phoronix.com) 33

"Security researchers from Amsterdam have publicly detailed 'BlindSide' as a new speculative execution attack vector for both Intel and AMD processors," reports Phoronix: BlindSide is self-described as being able to "mount BROP-style attacks in the speculative execution domain to repeatedly probe and derandomize the kernel address space, craft arbitrary memory read gadgets, and enable reliable exploitation. This works even in face of strong randomization schemes, e.g., the recent FGKASLR or fine-grained schemes based on execute-only memory, and state-of-the-art mitigations against Spectre and other transient execution attacks."

From a single buffer overflow in the kernel, researchers claim three BlindSide exploits in being able to break KASLR (Kernel Address Space Layout Randomization), break arbitrary randomization schemes, and even break fine-grained randomization.

There's more information on the researcher's web site, and they've also created an informational video.

And here's a crucial excerpt from their paper shared by Slashdot reader Hmmmmmm: In addition to the Intel Whiskey Lake CPU in our evaluation, we confirmed similar results on Intel Xeon E3-1505M v5, XeonE3-1270 v6 and Core i9-9900K CPUs, based on the Skylake, KabyLake and Coffee Lake microarchitectures, respectively, as well as on AMD Ryzen 7 2700X and Ryzen 7 3700X CPUs, which are based on the Zen+ and Zen2 microarchitectures.

Overall, our results confirm speculative probing is effective on a modern Linux system on different microarchitectures, hardened with the latest mitigations.

Microsoft

Microsoft Surface Duo Review: Two Screens, Too Many Problems (wsj.com) 41

Joanna Stern, reviewing the Surface Duo for the Wall Street Journal: It isn't always clear when something is ready. Take my grilling. Sometimes I remove steak well before or after I should've. You might say it's a "tough" call. But there's nothing tough about stating this: The new two-screen Surface Duo is undercooked. Microsoft's new $1,400 book-like phone-tablet thingy is not ready for me and not ready for you. Unless, of course, you want an Android device that repeatedly ignores your taps on its screens, randomly slows down, struggles to figure out its own up, down and sideways positioning, and abruptly rearranges parts of its own interface. If that is your dream, well, then it is ready. Somehow, Microsoft disagrees. "We had been testing for some time. We wanted to get it out. We thought this was the right time for us," said Matt Barlow, Microsoft's corporate vice president of modern life, search and devices.

With OneNote, I've loved brainstorming and taking notes with the $100 Surface Pen (sold separately). I'd love it even more if the pen could keep up with my writing. Another performance issue. Unfortunately, key Microsoft apps like Excel and Skype haven't been optimized for two screens. Microsoft and Google are also working with third-party app developers. The Kindle app, for instance, places a page on each screen to make this one adorable little e-reader. (Or at least it should. It glitched midway through testing, but began working again later, after I complained to Microsoft.) You can also launch one app on each screen -- Edge browser on left, Word on right, for instance. One of my favorite features is App Groups, which lets you pair two apps together to simultaneously launch. I have Twitter and TikTok in one with the label, "Bad for My Brain." One screen is still better suited to many of our current needs, and that makes this wide device feel awkward more often than not.

Businesses

The Surprising Traits of Good Remote Leaders (bbc.com) 37

New data shows that "the confidence, intelligence and extroversion that have long propelled ambitious workers into the executive suite are not enough online because they simply don't translate into virtual leadership," writes Arianna Cohen via the BBC. "Instead, workers who are organized, dependable and productive take the reins of virtual teams." From the report: The study, published in the Journal of Business and Psychology, tracked 220 US-based teams to see which team members emerged as leaders across in-person, virtual and hybrid groups. The researchers conducted a series of in-lab experiments with 86 four-person teams, and also traced the communications and experiences of 134 teams doing a semester-long project in a university class (students are commonly used as proxy for workers in leadership research). The study was carried out pre-pandemic, focusing on emergent leaders: those perceived as leaders, and whose influence is willingly accepted.

As expected, the face-to-face teams chose leaders with the same confident, magnetic, smart-seeming extroverted traits that we often see in organizational leaders. But those chosen as remote leaders were doers, who tended towards planning, connecting teammates with help and resources, keeping an eye on upcoming tasks and, most importantly, getting things done. These leaders were goal-focused, productive, dependable and helpful. In other words, virtually, the emphasis shifts from saying to doing. This discovery is timely, as most of our workplace in-person teams are now all or partially digital operations in the wake of the pandemic.

Security

Biden Campaign Firm Hit By Suspected Kremlin Hacking Attack (thedailybeast.com) 177

Joe Biden's presidential campaign was hit by an attack that was caught by Microsoft, which reportedly gathered information identifying hackers linked to the Kremlin as the most likely suspects. The Daily Beast reports: Reuters reported Thursday morning that suspected Russian state-backed hackers have attempted to breach the systems at Washington-based SKDKnickerbocker, a strategy and communications firm working hand-in-glove with Joe Biden's campaign. The attacks, which took place over the past two months, were unsuccessful. The failed hacking attempt was brought to SKDK's attention by Microsoft, which reportedly gathered information identifying hackers linked to the Kremlin as the most likely suspects. The attacks are said to have mainly focussed on phishing -- a common hacking method which lures users into disclosing sensitive passwords. That was the method used by Russian hackers to access DNC emails, which were subsequently leaked online, ahead of the 2016 presidential election.

A person familiar with SKDK's repelling to the hacking attempts said the agents didn't get very far, telling Reuters: "They are well-defended, so there has been no breach." Another source said it was impossible to confirm if Biden's campaign was the target, or whether the Russians were trying to gather intel on the long list of other SKDK clients.

Security

Ransomware Accounted For 41% of All Cyber Insurance Claims in H1 2020 (zdnet.com) 13

Ransomware incidents accounted for 41% of cyber insurance claims filed in the first half of 2020, according to a report published today by Coalition, one of the largest providers of cyber insurance services in North America. From a report: The high number of claims comes to confirm previous reports from multiple cyber-security firms that ransomware is one of today's most prevalent and destructive threats. "Ransomware doesn't discriminate by industry. We've seen an increase in ransom attacks across almost every industry we serve," Coalition added. "In the first half of 2020 alone, we observed a 260% increase in the frequency of ransomware attacks amongst our policyholders, with the average ransom demand increasing 47%," the company added. Among the most aggressive gangs, the cyber insurer listed Maze and DoppelPaymer, which have recently begun exfiltrating data from hacked networks, and threatening to release data on specialized leak sites, as part of double extortion schemes. Based on cyber insurance claims filed by customers who faced a ransomware attack in the first half of 2020, Coalition said the Maze ransomware gang was the most greedy, with the group requesting ransom demands six times larger than the overall average.
Bug

Academics Find Crypto Bugs in 306 Popular Android Apps, None Get Patched (zdnet.com) 32

A team of academics from Columbia University has developed a custom tool to dynamically analyze Android applications and see if they're using cryptographic code in an unsafe way. From a report: Named CRYLOGGER, the tool was used to test 1,780 Android applications, representing the most popular apps across 33 different Play Store categories, in September and October 2019. Researchers say the tool, which checked for 26 basic cryptography rules (mentioned in the source story), found bugs in 306 Android applications. Some apps broke one rule, while others broke multiple.
Transportation

Tesla Can Detect Aftermarket Hacks Designed To Defeat EV Performance Paywalls (thedrive.com) 209

As recently highlighted by a Tesla Model 3 owner on Reddit, your connected car knows when you've hacked it, and it might be logging that data to use against you in a future warranty claim. The Drive reports: The image you see above is a warning message popped up on the man's Model 3 infotainment screen after he installed the latest over-the-air OS update from Tesla a couple weeks ago. Prior to the update, he had also added an aftermarket module from an outfit called Ingenext that allows the dual-motor Model 3 to achieve its quickest 0-60 mph time without Tesla's requisite $2,000 "Acceleration Boost" option. Its presence didn't trigger a warning prior to the software update, and though the car still drove normally, the owner couldn't get the display to clear. Ingenext is a Canadian company focused on activating the latent performance and comfort features baked-in to Tesla vehicles. One particular modification developed by the company is called "Boost 50," a $1,458 upgrade which claims to shave up to a half-second off the zero-to-60 MPH time when installed in a Model 3 equipped with dual motors but not the performance option.
[...]
Ingenext's founder Guillaume Andre told The Drive that he feared Tesla could use the detection of aftermarket parts to justify blocking vehicles from using the Supercharger network and make customers "a prisoner of the Tesla system". The owner of the Model 3 that began getting the pop-ups told us that he planned to visit a Tesla Supercharger to ensure normal functionality, but has not yet reported the results of his findings. [...] Ingenext got to working on finding just how Tesla detected its "undetectable" mod. After some prodding, it was determined that the vehicle had used a separate communications network to detect the presence of the module and ultimately determined that a second small hardware module could be installed to combat the detection. Ingenext dubbed its fix the "Nice Try Module" and has already begun shipping it to customers.

The Tesla community is torn on this matter. Some argue that owners who purchased the module knew the risk of not going through the official channels, akin to using a cheat code to unlock a DLC upgrade in a video game. Others bring up the very valid point of right to repair -- but does that also include right to modify? After all, you do own the vehicles you spent upwards of $40,000 on. Nearly every enthusiast-focused vehicle has an off-the-shelf tune of some sort that can be purchased. Ingenext says that this is only the beginning of a fight that it anticipates will be an uphill battle, if not for it, than for all aftermarket companies who develop performance mods for Teslas.

Security

Windows 10 Themes Can Be Abused To Steal Windows Passwords (bleepingcomputer.com) 37

AmiMoJo writes: Specially crafted Windows 10 themes and theme packs can be used in 'Pass-the-Hash' attacks to steal Windows account credentials from unsuspecting users. Windows allows users to create custom themes that contain customized colors, sounds, mouse cursors, and the wallpaper that the operating system will use. Windows users can then switch between different themes as desired to change the appearance of the operating system. A theme's settings are saved under the %AppData%\Microsoft\Windows\Themes folder as a file with a .theme extension, such as 'Custom Dark.theme.' Windows themes can then be shared with other users by right-clicking on an active theme and selecting 'Save theme for sharing,' which will package the theme into a '.deskthemepack' file. These desktop theme packs can then be shared via email or as downloads on websites, and installed by double-clicking them.

This weekend security researcher Jimmy Bayne (@bohops) revealed that specially crafted Windows themes could be used to perform Pass-the-Hash attacks. Pass-the-Hash attacks are used to steal Windows login names and password hashes by tricking a user into accessing a remote SMB share that requires authentication. When trying to access the remote resource, Windows will automatically try to login to the remote system by sending the Windows user's login name and an NTLM hash of their password. In a Pass-the-Hash attack, the sent credentials are harvested by the attackers, who then attempt to dehash the password to access the visitors' login name and password.

Education

City of Hartford Postpones First Day of School After Ransomware Attack (zdnet.com) 7

Officials from the city of Hartford, Connecticut, were forced to postpone the first day of the new school calendar year after a ransomware infection impacted the city's IT network. From a report: According to a statement published by Hartford Public Schools, the school district serving the city of Hartford, the ransomware attack impacted several of the school's internal IT systems, causing a prolonged outage. IT staff have been working to restore services, but these were not completed in time for the first day of the new school year, scheduled for today, Sept. 8. Following the COVID-19 pandemic, in-person schooling has been suspended since the spring. In the city of Hartford, today marked not only the first day of the new 2020 school year but also the first day of in-person attendance in months. According to the district's school re-opening plan, today, PreK-Grade 2, Grade 6, and Grade 9 students were supposed to have the first school classes in months.
Security

Chilean Bank Shuts Down All Branches Following Ransomware Attack (zdnet.com) 18

BancoEstado, one of Chile's three biggest banks, was forced to shut down all branches on Monday following a ransomware attack that took place over the weekend. From a report: "Our branches will not be operational and will remain closed today," the bank said in a statement published on its Twitter account on Monday. Details about the attack have not been made public, but a source close to the investigation told ZDNet that the bank's internal network was infected with the REvil (Sodinokibi) ransomware. The incident is currently being investigated as having originated from a malicious Office document received and opened by an employee. The malicious Office file is believed to have installed a backdoor on the bank's network.

Slashdot Top Deals