Security

Iranian Spies Accidentally Leaked Videos of Themselves Hacking (wired.com) 41

An anonymous reader quotes a report from Wired: Researchers at IBM's X-Force security team revealed today that they've obtained roughly five hours of video footage that appears to have been recorded directly from the screens of hackers working for a group IBM calls ITG18, and which other security firms refer to as APT35 or Charming Kitten. It's one of the most active state-sponsored espionage teams linked to the government of Iran. The leaked videos were found among 40 gigabytes of data that the hackers had apparently stolen from victim accounts, including U.S. and Greek military personnel. Other clues in the data suggest that the hackers targeted U.S. State Department staff and an unnamed Iranian-American philanthropist.

The IBM researchers say they found the videos exposed due to a misconfiguration of security settings on a virtual private cloud server they'd observed in previous APT35 activity. The files were all uploaded to the exposed server over a few days in May, just as IBM was monitoring the machine. The videos appear to be training demonstrations the Iran-backed hackers made to show junior team members how to handle hacked accounts. They show the hackers accessing compromised Gmail and Yahoo Mail accounts to download their contents, as well as exfiltrating other Google-hosted data from victims. This sort of data exfiltration and management of hacked accounts is hardly sophisticated hacking. It's more the kind of labor-intensive but relatively simple work that's necessary in a large-scale phishing operation. But the videos nonetheless represent a rare artifact, showing a first-hand view of state-sponsored cyberspying that's almost never seen outside of an intelligence agency.

Security

Who's Behind Wednesday's Epic Twitter Hack? (krebsonsecurity.com) 75

Brian Krebs has written a blog post with clues about who may have been behind yesterday's Twitter hack, which had some of the world's most recognizable public figures tweeting out links to bitcoin scams. An anonymous reader shares an excerpt from the report (though we strongly recommend you read the full analysis here): There are strong indications that this attack was perpetrated by individuals who've traditionally specialized in hijacking social media accounts via "SIM swapping," an increasingly rampant form of crime that involves bribing, hacking or coercing employees at mobile phone and social media companies into providing access to a target's account. In the days leading up to Wednesday's attack on Twitter, there were signs that some actors in the SIM swapping community were selling the ability to change an email address tied to any Twitter account. In a post on OGusers -- a forum dedicated to account hijacking -- a user named "Chaewon" advertised they could change email address tied to any Twitter account for $250, and provide direct access to accounts for between $2,000 and $3,000 apiece. "This is NOT a method, you will be given a full refund if for any reason you aren't given the email/@, however if it is revered/suspended I will not be held accountable," Chaewon wrote in their sales thread, which was titled "Pulling email for any Twitter/Taking Requests."

Hours before any of the Twitter accounts for cryptocurrency platforms or public figures began blasting out bitcoin scams on Wednesday, the attackers appear to have focused their attention on hijacking a handful of OG accounts, including "@6." That Twitter account was formerly owned by Adrian Lamo -- the now-deceased "homeless hacker" perhaps best known for breaking into the New York Times's network and for reporting Chelsea Manning's theft of classified documents. @6 is now controlled by Lamo's longtime friend, a security researcher and phone phreaker who asked to be identified in this story only by his Twitter nickname, "Lucky225."[...] But around the same time @6 was hijacked, another OG account -- @B -- was swiped. Someone then began tweeting out pictures of Twitter's internal tools panel showing the @B account. Another Twitter account -- @shinji -- also was tweeting out screenshots of Twitter's internal tools. Minutes before Twitter terminated the @shinji account, it was seen publishing a tweet saying "follow @6," referring to the account hijacked from Lucky225.

Cached copies of @Shinji's tweets prior to Wednesday's attack on Twitter are available here and here from the Internet Archive. Those caches show Shinji claims ownership of two OG accounts on Instagram -- "j0e" and "dead." KrebsOnSecurity heard from a source who works in security at one of the largest U.S.-based mobile carriers, who said the "j0e" and "dead" Instagram accounts are tied to a notorious SIM swapper who goes by the nickname "PlugWalkJoe." Investigators have been tracking PlugWalkJoe because he is thought to have been involved in multiple SIM swapping attacks over the years that preceded high-dollar bitcoin heists. Now look at the profile image in the other Archive.org index of the @shinji Twitter account (pictured below). It is the same image as the one included in the @Shinji screenshot above from Wednesday in which Joseph/@Shinji was tweeting out pictures of Twitter's internal tools.

This individual, the source said, was a key participant in a group of SIM swappers that adopted the nickname "ChucklingSquad," and was thought to be behind the hijacking of Twitter CEO Jack Dorsey's Twitter account last year. The mobile industry security source told KrebsOnSecurity that PlugWalkJoe in real life is a 21-year-old from Liverpool, U.K. named Joseph James Connor. The source said PlugWalkJoe is in Spain where he was attending a university until earlier this year. He added that PlugWalkJoe has been unable to return home on account of travel restrictions due to the COVID-19 pandemic. [...] If PlugWalkJoe was in fact pivotal to this Twitter compromise, it's perhaps fitting that he was identified in part via social engineering.

IBM

IBM Job Ad Calls For a Minimum 12 Years' Experience With Kubernetes -- Which is Six Years Old (theregister.com) 42

IBM's Global Technology Services has posted a job ad calling for candidates with a "minimum 12+ years' experience in Kubernetes administration and management." From a report: Which is a little odd because the first GitHub commit for the project was made on June 7, 2014. And the feature freeze for version 1.0 was announced on May 22, 2015. Sharp-minded Reg readers will have recognised that -- absent time travel -- it is therefore not possible for anyone to have 12 years' experience with Kubernetes. The ad is sadly silent on just how IBM expects candidates will have found the time to accumulate a dozen years' experience in a six-year-old project.
Security

Microsoft Warns of a 17-Year-Old 'Wormable' Bug (wired.com) 9

Since WannaCry and NotPetya struck the internet just over three years ago, the security industry has scrutinized every new Windows bug that could be used to create a similar world-shaking worm. Now one potentially "wormable" vulnerability -- meaning an attack can spread from one machine to another with no human interaction -- has appeared in Microsoft's implementation of the domain name system protocol, one of the fundamental building blocks of the internet. From a report: As part of its Patch Tuesday batch of software updates, Microsoft today released a fix for a bug discovered by Israeli security firm Check Point, which the company's researchers have named SigRed. The SigRed bug exploits Windows DNS, one of the most popular kinds of DNS software that translates domain names into IP addresses. Windows DNS runs on the DNS servers of practically every small and medium-sized organization around the world. The bug, Check Point says, has existed in that software for a remarkable 17 years. Check Point and Microsoft warn that the flaw is critical, a 10 out of 10 on the common vulnerability scoring system, an industry standard severity rating. Not only is the bug wormable, Windows DNS software often runs on the powerful servers known as domain controllers that set the rules for networks. Many of those machines are particularly sensitive; a foothold in one would allow further penetration into other devices inside an organization.

On top of all of that, says Check Point's head of vulnerability research Omri Herscovici, the Windows DNS bug can in some cases be exploited with no action on the part of the target user, creating a seamless and powerful attack. "It requires no interaction. And not only that, once you're inside the domain controller that runs the Windows DNS server, expanding your control to the rest of the network is really easy," says Omri Herscovici. "It's basically game over." Check Point found the SigRed vulnerability in the part of Windows DNS that handles a certain piece of data that's part of the key exchange used in the more secure version of DNS known as DNSSEC. That one piece of data can be maliciously crafted such that Windows DNS allows a hacker to overwrite chunks of memory they're not meant to have access to, ultimately gaining full remote code execution on the target server. (Check Point says Microsoft asked the company not to publicize too many details of other elements of the technique, including how it bypasses certain security features on Windows servers.)

Security

Israeli Court Rules NSO Group Can Continue Exporting Spyware (vice.com) 39

The infamous spyware company NSO Group scored a major win in what critics are calling a "disgraceful ruling" in an Israeli court this week. From a report: The court ruled that NSO can keep exporting its hacking and surveillance tools, arguing that the human rights organization Amnesty International, which had sued the company in an attempt to block its exports, failed to prove that an NSO customer used its technology to spy on Amnesty staff. In 2018, as Motherboard reported at the time, Amnesty claimed to have found hackers spying on one of the organization's researchers using NSO spyware. After the incident, the organization sued NSO in Israel in an attempt to block the export of its surveillance technology. A Tel Aviv District Court judge dismissed the suit alleging Amnesty did not present enough evidence, and said Israel's Defence Ministry, which is tasked with overseeing the export of surveillance technologies, has the right safeguards in place to protect human rights.
Microsoft

Microsoft Adds Support For Custom '+' Email Addresses in Office 365 (zdnet.com) 74

Microsoft is adding support for custom email addressing to Office 365 email services, a feature it hopes to complete in Q3 2020. From a report: Custom email addresses are an optional feature that some email providers can support. The feature is described in the RFC 5233 internet standard. Officially known as subaddressing, this standard allows users to extend their email address using "tags" or the plus (+) character, hence its two alternative names of tagged addressing or plus addressing. For example, a user with the email address of username@domain.com can use the plus addressing feature to extend their email address to username+tag@domain.com. If the user's email address supports subaddressing, all emails sent to the username+tag@domain.com email will land in the user's username@domain.com inbox.
Encryption

Enigma Code-Breaking Machine Rebuilt At Cambridge (techxplore.com) 34

Cambridge Engineering alumnus Hal Evans has built a fully-functioning replica of a 1930s Polish cyclometer -- an electromechanical cryptologic device that was designed to assist in the decryption of German Enigma ciphertext. The replica currently resides in King's College, Cambridge. TechXplore reports: Work on the hardware-based replica began in 2018, as part of Hal's fourth year Master's project under the supervision of King's College Fellow and Senior Tutor Dr. Tim Flack. The aim was to investigate further into cryptologist Marian Rejewski's cyclometer -- an early forerunner to Cambridge University mathematician Alan Turing's machine, known as the Bombe, which was used to crack the German Enigma code during the Second World War. Hal said he chose to work on the cyclometer as it was the very first machine used to assist the decryption effort. To his knowledge, the replica is the first fully-functioning hardware-based electromechanical cyclometer to exist since the years preceding the Second World War. The original machines would have been destroyed in 1939 to prevent them from falling into the hands of German invaders.

Rejewski's cyclometer exploited the German's procedure at the time of double encipherment of the Enigma message key, and semi-automated the process for calculating what were known as 'characteristics' for every possible Enigma rotor starting position. There were more than 100,000 of these rotor starting positions, and they each needed their characteristic to be calculated and catalogued in a card index system. The cyclometer therefore eliminated the arduous task of calculating these characteristics by hand. The machine consisted of, in effect, two interlinked Enigma systems side-by-side -- one offset by three positions relative to the other -- and 26 lamps and switches to cover the alphabet. On operation, a certain number of bulbs illuminated, indicating the lengths of the characteristics. These were recorded for every single possible rotor starting position to create an immense look-up catalogue. Once this was completed, obtaining the daily Enigma rotor starting settings to decode messages was a simple matter of intercepting enough messages and referencing the catalogue, taking only a matter of minutes.

Security

US Threatens To Restrict WeChat Following TikTok Backlash (techcrunch.com) 36

Amid intense scrutiny over TikTok as a potential national security risk in the U.S., WeChat, the essential tool for Chinese people's day-to-day life, is also taking heat from Washington. TechCrunch reports: White House trade advisor Peter Navarro told Fox Business on Sunday that "[TikTok] and WeChat are the biggest forms of censorship on the Chinese mainland, and so expect strong action on that." Navarro alleged that "all of the data that goes into those mobile apps that kids have so much fun with and seem so convenient, it goes right to servers in China, right to the Chinese military, the Chinese communist party, and the agencies which want to steal our intellectual property."

It's unclear how the U.S. restriction will play out, if it will at all, though some WeChat users are already speculating workarounds to stay in touch with their family and friends back home. In the case that the Tencent-owned messenger is removed by Apple App Store or Google Play, U.S.-based users could switch to another regional store to download the app. If it were an IP address ban, they could potentially access the app through virtual private networks (VPNs), tools that are familiar to many in China to access online services blocked by Beijing's Great Firewall.

Google

Microsoft Worked With Google To Bring Progressive Web Apps To the Play Store (thurrott.com) 42

Microsoft has been collaborating with Google to ensure that their tools interoperate and can help developers get their Progressive Web Apps (PWAs) into the Play Store. From a report: "We're glad to announce a new collaboration between Microsoft and Google for the benefit of the web developer community," Microsoft's Judah Gabriel Himango announced. "Microsoft's PWABuilder and Google's Bubblewrap are now working together to help developers publish PWAs in the Google Play Store." As Himango explains, PWABuilder is a Microsoft tool that helps developers build PWAs from existing websites and publish them in app stores, while Bubblewrap is a Google tool and library used to generate and sign Google Play Store packages from PWAs. After months of collaboration, the two firms have made some interesting progress towards integrating the tools. Now, PWABuilder utilizes Bubblewrap "under the hood," as Himango puts it, allowing developers to package PWAs for the Play Store with PWABuilder that support the new web shortcuts standard. (On Windows 10, web shortcuts appear as jump lists.)
Security

US Secret Service Creates New Cyber Fraud Task Force (bleepingcomputer.com) 28

The U.S. Secret Service announced the creation of the Cyber Fraud Task Force (CFTF) after the merger of its Financial Crimes Task Forces (FCTFs) and Electronic Crimes Task Forces (ECTFs) into a single unified network. Bleeping Computer reports: CFTF's main goal is to investigate and defend American individuals and businesses from a wide range of cyber-enabled financial crimes, from business email compromise (BEC) scams and ransomware attacks to data breaches and the illegal sale of stolen personal information and credit cards on the Internet and the dark web. Consolidating the two task forces into CFTF will allow the Secret Service to boost its agents' ability to prevent, detect, and mitigate financially-motivated cybercrime by improving coordination, sharing of resources and expertise, and best practices dissemination.

"The creation of the new Cyber Fraud Task Force (CFTF), will offer a specialized cadre of agents and analysts, trained in the latest analytical techniques and equipped with the most cutting-edge technologies," said Michael D'Ambrosio, U.S. Secret Service Assistant Director. At the moment, the Secret Service has already operationalized CFTFs in 42 domestic offices and in 2 international locations (London and Rome). The Department of Homeland Security federal law enforcement agency also plans to increase the number of CFTF locations through its network of more than 160 offices across the U.S. and around the globe.

Encryption

Signal's New PIN Feature Worries Cybersecurity Experts (vice.com) 45

Lorenzo Franceschi-Bicchierai, writing for Vice: Ever since NSA leaker Edward Snowden said "use Signal, use Tor," the end-to-end encrypted chat app has been a favorite of people who care about privacy and need a chat and calling app that is hard to spy on. One of the reasons security experts recommended Signal is because the app's developers collected -- and thus retained -- almost no information about its users. This means that, if subpoenaed by law enforcement, Signal would have essentially nothing to turn over. Signal demonstrated this in 2016, when it was subpoenaed by a court in Virginia. But a newly added feature that allows users to recover certain data, such as contacts, profile information, settings, and blocked users, has led some high-profile security experts to criticize the app's developers and threaten to stop using it.

Signal will store that data on servers the company owns, protected by a PIN that the app has initially been asking users to add, and then forced them to. The purpose of using a PIN is, in the near future, to allow Signal users to be identified by a username, as opposed to their phone number, as Signal founder Moxie Marlinspike explained on Twitter (as we've written before, this is a laudable goal; tying Signal to a phone number has its own privacy and security implications). But this also means that unlike in the past, Signal now retains certain user data, something that many cybersecurity and cryptography experts see as too dangerous. Matthew Green, a cryptographer and computer science professor at Johns Hopkins University, said that this was "the wrong decision," and that forcing users to create a PIN and use this feature would force him to stop using the app.

Portables (Apple)

Apple Advises Against MacBook Camera Covers Due To Display Cracking (appleinsider.com) 126

Apple, in a new support document, is warning users against closing their MacBook lids with a cover over the camera. From a report: Placing a cover, sticker or tape over a laptop camera is a practice adopted by some privacy- and security-conscious individuals to protect against webcam hijacking. Now, however, Apple is explicitly advising against the tactic. In a support document published earlier in July, Apple urges users not to close their MacBook Pro or MacBook Air lids if there's a camera cover installed on it. "If you close your Mac notebook with a camera cover installed, you might damage your display because the clearance between the display and keyboard is designed to very tight tolerances," Apple notes. The support document also outlines some of the privacy and security functions of the camera, including the green indicator light that lets users know when the camera is active and the camera permission settings introduced in macOS Mojave.
Businesses

Amazon Makes Employees Delete TikTok From Phones, Citing Security Risk [Update] (nytimes.com) 64

Amazon has asked its employees to delete the Chinese-owned video app TikTok from their cellphones, citing "security risks," according to a company email sent on Friday. From a report: In the email, which was obtained by The New York Times, Amazon officials said that employees must delete the app from any devices that "access Amazon email." Employees had to remove the app by Friday to remain able to obtain mobile access to their Amazon email, the note said. Amazon workers are still allowed to view TikTok from their laptop browser, the company added. Amazon and TikTok did not immediately respond to requests for comment. TikTok, which has been popular with young audiences in the United States, is owned by the Chinese tech company ByteDance. It has been under scrutiny in Washington for security reasons because of its ownership. Mike Pompeo, the Secretary of State, said on Monday that the Trump administration was considering blocking some Chinese apps, which he has called a threat to national security. Updated at 21:01GMT: In a statement, Amazon said the email was sent by accident. "This morning's email to some of our employees was sent in error. There is no change to our policies right now with regard to TikTok."
Security

More Pre-Installed Malware Has Been Found In Budget US Smartphones (zdnet.com) 34

Pre-installed malware has been discovered on another budget handset connected to Assurance Wireless by Virgin Mobile. ZDNet reports: Back in January, cybersecurity researchers from Malwarebytes discovered unremovable malware bundled with the Android operating systems on the Unimax (UMX) U686CL, a low-end handset sold by Assurance Wireless as part of the Lifeline Assistance program, a 1985 U.S. initiative which subsidizes telephone services for low-income families. There was no way to remove a pair of apps on the handsets which would install other software on the devices without the user's knowledge.

Now, Malwarebytes has uncovered another budget handset with similar security issues. The smartphone in question is the ANS (American Network Solutions) UL40, running Android OS 7.1.1. [...] In the same way as the UMX U686CL, two apps -- a settings app and wireless update app -- are compromised. However, these apps are not infected with the same malware variants; instead, Collier says the "infections are similar but have their own unique infection characteristics." The Settings app is detected as Downloader Wotby, a Trojan that is able to download apps externally. The researchers did not find any evidence of malicious apps in a third-party store linked to the software but noted this doesn't mean that malicious apps could not be added or find their way into the store at a later date. The WirelessUpdate app is considered a Potentially Unwanted Program (PUP) that is also able to automatically install apps without user permission or knowledge. While the app does function as an over-the-air updater for security fixes and as an updater to the operating system itself, the software also installs four variants of HiddenAds, a Trojan family found on Android handsets.
Thankfully, Malwarebytes has instructions on how to stop HiddenAds infections.
Bug

AI Researchers Create Testing Tool To Find Bugs in NLP From Amazon, Google, and Microsoft (venturebeat.com) 10

AI researchers have created a language-model testing tool that discovers major bugs in commercially available cloud AI offerings from Amazon, Google, and Microsoft. Yesterday, a paper detailing the CheckList tool received the Best Paper award from organizers of the Association for Computational Linguistics (ACL) conference. From a report: NLP models today are often evaluated based on how they perform on a series of individual tasks, such as answering questions using benchmark data sets with leaderboards like GLUE. CheckList instead takes a task-agnostic approach, allowing people to create tests that fill in cells in a spreadsheet-like matrix with capabilities (in rows) and test types (in columns), along with visualizations and other resources. Analysis with CheckList found that about one in four sentiment analysis predictions by Amazon's Comprehend change when a random shortened URL or Twitter handle is placed in text, and Google Cloud's Natural Language and Amazon's Comprehend makes mistakes when the names of people or locations are changed in text. "The [sentiment analysis] failure rate is near 100% for all commercial models when the negation comes at the end of the sentence (e.g. 'I thought the plane would be awful, but it wasn't'), or with neutral content between the negation and the sentiment-laden word," the paper reads.
Chrome

Chrome and Firefox Are Getting Support For the New AVIF Image Format (zdnet.com) 50

The new lightweight and royalty-free AVIF image format is coming to web browsers. Work is almost complete on adding AVIF support to Google Chrome and Mozilla Firefox. From a report: The new image format is considered one of the lightest and most optimized image compression formats, and has already gained praise from companies such as Netflix, which considers it superior to existing image formats such as JPEG, PNG, and even the newer WebP. The acronym of AVIF stands for AV1 Image File Format. As its name hints, AVIF is based on AV1, which is a video codec that was developed in 2015, following a collaboration between Google, Cisco, and Xiph.org (who also worked with Mozilla). At the time, the three decided to pool their respective in-house video codecs (VPX, Thor, and Daala) to create a new one (AV1) that they planned to offer as an open-source and royalty-free alternative to all the commercial video codecs that had fragmented and clogged the video streaming market in the late 2000s and early 2010s.
Microsoft

Microsoft's New KDP Tech Blocks Malware By Making Parts of the Windows Kernel Read-Only (zdnet.com) 43

Microsoft today published technical details about a new security feature that will soon be part of Windows 10. From a report: Named Kernel Data Protection (KDP), Microsoft says this feature will block malware or malicious threat actors from modifying (corrupting) the operating system's memory. According to Microsoft, KDP works by giving developers access to programmatic APIs that will allow them to designate parts of the Windows kernel as read-only sections. "For example, we've seen attackers use signed but vulnerable drivers to attack policy data structures and install a malicious, unsigned driver," Microsoft's Base Kernel Team said today. "KDP mitigates such attacks by ensuring that policy data structures cannot be tampered with." Microsoft says this new technology was developed with security in mind but that it also has other applications, such as anti-cheat and digital rights management (DRM) software.
Security

Smartwatch Hack Could Trick Patients To 'Take Pills' With Spoofed Alerts (techcrunch.com) 21

Security researchers say a smartwatch, popular with the elderly and dementia patients, could have been tricked into letting an attacker easily take control of the device. From a report: These watches are designed to help patients to easily call their carers and for carers to track the location of their patients. They come with their own cellular connection, so that they work anywhere. But researchers at U.K.-based security firm Pen Test Partners found that they could trick the smartwatch into sending fake "take pills" reminders to patients as often as they want, they said. "A dementia sufferer is unlikely to remember that they had already taken their medication," wrote Vangelis Stykas in a blog post. "An overdose could easily result." The vulnerabilities were found in the back-end cloud system, known as SETracker, which powers the smartwatch.
Security

Over 100 Wi-Fi Routers Fail Major Security Test -- Protect Yourself Now (tomsguide.com) 102

schwit1 shares a report from Tom's Guide: Using its own analytical software, the [Fraunhofer Institute] tested the most recently available firmware for 117 home Wi-Fi models currently sold in Europe, including routers from ASUS, D-Link, Linksys, Netgear, TP-Link, Zyxel and the small German brand AVM. The models themselves were not physically tested. A full list of the tested models and firmware is on GitHub. The institute was not able to examine the firmware of 10 more models, mostly from Linksys. The report notes (PDF) that many firmware updates are issued without fixing known flaws.

So what can you do? You can make sure that the next router you buy automatically installs firmware updates. You can check to see whether your current router does so, or makes it fairly easy to install firmware updates manually. You should also make sure that the administrative password for your router has been changed from the factory default password. (Check the list of default passwords at https://www.routerpasswords.com.) You should also check its administrative interface to make sure that UPnP and remote access are disabled. And if your router was first released more than 5 years ago, consider buying a newer model unless it meets all of the above criteria. Alternatively, you could try to "flash" your older router to run more secure open-source router firmware such as OpenWrt, DD-WRT or Tomato.
"The worst case regarding high severity CVEs [widely known flaws] is the Linksys WRT54GL powered by the oldest kernel found in our study," the report said, noting that this model uses the 2.4.20 kernel from 2002. "There are 579 high severity CVEs affecting this product."

"That particular model last had its firmware updated in January 2016, one of the oldest firmwares in the study," adds Tom's Guide. "The Linksys WRT54GL was first released in 2005 and is still sold today, even though it handles Wi-Fi protocols only up to 802.11g. However, the WRT54G series is possibly the best-selling family of Wi-Fi routers ever..."
Firefox

Mozilla Suspends Firefox Send Service While It Addresses Malware Abuse (zdnet.com) 19

An anonymous reader writes: Mozilla has temporarily suspended the Firefox Send file-sharing service as the organization investigates reports of abuse from malware operators and while it adds a "Report abuse" button. The browser maker took down the service today after ZDNet reached out to inquire about Firefox Send's increasing prevalence in current malware operations. Since last year, several malware operations have hosted payloads on the service. This includes ransomware gangs like REvil/Sodinokibi, financial crime crews like FIN7, the Zloader and Ursnif banking trojans operations, and government surveillance groups targeting human rights defenders. Reasons include the fact that Firefox Send doesn't have an Report Abuse mechanism, all file uploads are encrypted (useful to dodge malware scanners), and the Firefox URL is whitelisted in most orgs (useful for bypassing email filters).

Slashdot Top Deals