Intel

Intel Unveils the Thunderbolt 4 Spec, Debuting in PCs in the Fall (pcworld.com) 95

Intel unveiled Thunderbolt 4 on Wednesday, the next iteration of the I/O specification that provides a high-speed peripheral bus to docks, displays, external storage and eGPUs for PCs. Rather than increase the available bandwidth, however, Thunderbolt 4 provides more clarity and helps create new categories of products. From a report: Thunderbolt 4 will debut later this year as part of Intel's "Tiger Lake" CPU platform, as Intel originally announced during CES in January. We now know it will support 40Gbps throughput, but with tighter minimum specs. Thunderbolt 4 will guarantee that a pair of 4K displays will work with a Thunderbolt dock, and require Thunderbolt 4-equipped PCs to charge on at least one Thunderbolt port. Thunderbolt PCs will be able to connect to either "compact" or "full" docks with up to four Thunderbolt ports. Longer Thunderbolt cables will be possible, too. One thing that doesn't seem to be changing is Thunderbolt's exclusivity. Intel developed Thunderbolt, and perhaps not coincidentally, OEM systems based on rival AMD's CPUs have never had this technology. While AMD has officially dismissed the need for Thunderbolt, with generation 4 Intel appears to have made it even harder for AMD to get it, even if it wanted to. Intel's still pitching Thunderbolt as a single standard to rule them all, but the reality up to now has been complicated. You still have to squint hard at that USB-C-shaped port to determine which of the multitude of USB specifications it meets, including whether it's a USB4 connection that happens to support Thunderbolt. To muddy things further, Thunderbolt also encompasses PCIe, DisplayPort, and USB Power Delivery standards.
Privacy

Security Cameras Can Tell Burglars When You're Not Home, Study Shows (cnn.com) 119

schwit1 shares a report from CNN: Some popular home security cameras could allow would-be burglars to work out when you've left the building, according to a study published Monday. Researchers found they could tell if someone was in, and even what they were doing in the home, just by looking at data uploaded by the camera and without monitoring the video footage itself. The international study was carried out by researchers from Queen Mary University of London (QMUL) and the Chinese Academy of Science, using data provided by a large Chinese manufacturer of Internet Protocol (IP) security cameras. Cameras like these allow users to monitor their homes remotely via a video feed on the internet, but the researchers say the traffic generated by the devices can reveal privacy-compromising information.

Study author Gareth Tyson from QMUL told CNN that data uploads of the unencrypted data increase when a camera is recording something moving, so an attacker could tell if the camera was uploading footage of someone in motion, and even different types of motion like running or sitting. The risk is that "someone who is specifically targeting an individual household rocks up outside with a device to try and start passively monitoring traffic," he said. Tyson told CNN that an attacker would require a decent level of technical knowledge to monitor the data themselves, but there is a chance that someone could develop a program that does so and sell it online. Noting that he hasn't seen any direct evidence of this kind of attack taking place, he said one potential use would be if someone wanted to burgle your house.
Tyson says companies could randomly inject data into their systems to make it harder for attackers to spot a pattern.

The study has been published at the IEEE International Conference on Computer Communications.
Security

Cops Seize Server That Hosted BlueLeaks, DDoSecrets Says (vice.com) 15

An anonymous reader quotes a report from Motherboard: Authorities in Germany have seized a server used by the organization that published a trove of US police internal documents commonly known as BlueLeaks, according to the organization's founder. On Tuesday, Emma Best, the founder of Distributed Denial of Secrets or DDoSecrets, a WikiLeaks-like website that has published the police data, said that prosecutors in the German town of Zwickau seized the organization's "primary public download server."

"We are working to obtain additional information, but presume it is [regarding] #BlueLeaks," Best added on Twitter. "The server was used ONLY to distribute data to the public. It had no contact with sources and was involved in nothing more than enlightening the public through journalistic publishing." Best shared a screenshot of the email they received from DDoSecrets' hosting provider informing of the server seizure. "Your server has been confiscated," the email reads. "Until now we were not allowed to inform you accordingly." The email then notes that the seizing authority was the Department of Public Prosecution Zwickau.
"We're gonna get set up with a new data host and move up our plans to evolve some of our infrastructure," Best told Motherboard. "It's the perfect time for it to fall apart because we were rebuilding it anyway. It's a huge headache and a violates the ideal of press freedom, but we'll survive, even if we have to close Hunter for a time. The equivalent system they mention is blank and unconfigured, and obviously we can't rely on it."
Microsoft

Microsoft Will Axe Control Panel From Windows 10 (gizmodo.com) 208

Microsoft seems to be getting a kick out seeing users struggle to find Windows 10 features these days. After moving the Fresh Start feature in the latest version, 2004, and reducing the number of days Windows 10 Pro, Enterprise, and Education users can manually delay updates, the company is now experimenting with moving key Control Panel features, including System information, to Settings, Windows Latest blog spotted. From a report: It's a change that some long-time Windows users might not take to easily. If you're like me and have been using the Control Panel for decades, getting accustomed to this feature will be as arduous as unlearning a bad habit. To be fair, it's a bit redundant to have information on your system's specs located in three different places, not to mention all three don't show the exact same information. Currently, Windows 10 users can access hardware information about their PC in several places, but the main ways are: Control Panel > System and Security > System, and Settings > System > About, or by typing 'system information' into the search bar.

System and About show nearly the same info, what processor you have and how much RAM you have installed, for instance, except About will show you what version of Windows you have. System Information shows more detailed information about your PC, including your motherboard, GPU, and other hardware. Microsoft is trying to centralize this information, and moving forward, it seems likely that Control Panel will be killed off entirely.

Microsoft

Microsoft Seizes Six Domains Used in COVID-19 Phishing Operations (zdnet.com) 26

Microsoft has obtained a court order this month allowing the company to seize control of six domains that were used in phishing operations against Office 365 customers, including in campaigns that leveraged COVID-19 lures. From a report: According to court documents obtained by ZDNet, Microsoft has targeted a two-person phishing operation that has been targeting the company's customers since December 2019. The duo operated by sending emails to companies that hosted email servers and enterprise infrastructure on Microsoft's Office 365 cloud service. The emails were spoofed to look like they came from fellow employees or a trusted business partner. This particular phishing operation was unique because attackers didn't redirect users to phishing sites that mimicked the Office 365 login page. Instead, hackers touted an Office document. When users tried to open the file, they were redirected to install a malicious third-party Office 365 app created by the hackers.
Businesses

Hackers Are Exploiting a 5-Alarm Bug In Networking Equipment (wired.com) 32

Andy Greenberg writes via Wired: Late last week, government agencies, including the United States Computer Emergency Readiness Team and Cyber Command, sounded the alarm about a particularly nasty vulnerability in a line of BIG-IP products sold by F5. The agencies recommended security professionals immediately implement a patch to protect the devices from hacking techniques that could fully take control of the networking equipment, offering access to all the traffic they touch and a foothold for deeper exploitation of any corporate network that uses them. Now some security companies say they're already seeing the F5 vulnerability being exploited in the wildâ"and they caution that any organization that didn't patch its F5 equipment over the weekend is already too late.

The F5 vulnerability, first discovered and disclosed to F5 by cybersecurity firm Positive Technologies, affects a series of so-called BIG-IP devices that act as load balancers within large enterprise networks, distributing traffic to different servers that host applications or websites. Positive Technologies found a so-called directory traversal bug in the web-based management interface for those BIG-IP devices, allowing anyone who can connect to them to access information they're not intended to. That vulnerability was exacerbated by another bug that allows an attacker to run a "shell" on the devices that essentially lets a hacker run any code on them that they choose. The result is that anyone who can find an internet-exposed, unpatched BIG-IP device can intercept and mess with any of the traffic it touches. Hackers could, for instance, intercept and redirect transactions made through a bank's website, or steal users' credentials. They could also use the hacked device as a hop point to try to compromise other devices on the network. Since BIG-IP devices have the ability to decrypt traffic bound for web servers, an attacker could even use the bug to steal the encryption keys that guarantee the security of an organization's HTTPS traffic with users, warns Kevin Gennuso, a cybersecurity practitioner for a major American retailer.
While only a small minority of F5 BIG-IP devices are directly exploitable, Positive Technologies says that still includes 8,000 devices worldwide. "About 40 percent of those are in the U.S., along with 16 percent in China and single-digit percentages in other countries around the globe," reports Wired.

"Owners of those devices have had since June 30, when F5 first revealed the bug along with its patch, to update," adds Wired. "But many may not have immediately realized the seriousness of the vulnerability. Others may have been hesitant to take their load balancing equipment offline to implement an untested patch, points out Gennuso, for fear that critical services might go down, which would further delay a fix."
Businesses

Fujitsu Announces Permanent Work-From-Home Plan (bbc.com) 47

Technology firm Fujitsu announced a new "Work Life Shift" program that will offer unprecedented flexibility to its 80,000 workers in Japan. "Staff will be able to work flexible hours, and working from home will be standard wherever possible," reports the BBC. From the report: In a statement sent to the BBC, Fujitsu said it "will introduce a new way of working that promises a more empowering, productive, and creative experience for employees that will boost innovation and deliver new value to its customers and society." Under the plan employees will "begin to primarily work on a remote basis to achieve a working style that allows them to flexibly use their time according to the contents of their work, business roles, and lifestyle." The company also said the program would allow staff to choose where they worked, whether that was from home, a major corporate hub or a satellite office. Fujitsu believes that that the increased autonomy offered to its workers will help to improve the performance of teams and increase productivity.
Security

US Secret Service Reports an Increase in Hacked Managed Service Providers (zdnet.com) 29

The US Secret Service sent out a security alert last month to the US private sector and government organizations warning about an increase in hacks of managed service providers (MSPs). From a report: MSPs provide remote management software for companies. MSPs can be simple services like file-sharing systems to complete solutions that manage a customer's entire computer fleet. Most MSP services are built around a server-client software architecture. The server part can be remotely hosted with the MSP inside a clout infrastructure, or installed on-premise with the client. Usually, getting access to the server component of an MSP grants an attacker full control of all software clients. In a security alert sent out on June 12, Secret Service officials said their investigations team (GIOC -- Global Investigations Operations Center) has been seeing an increase in incidents where hackers breach MSP solutions and use them as a springboard into the internal networks of the MSP's customers. Secret Service officials said they've been seeing threat actors use hacked MSPs to carry out attacks against point-of-sale systems, to perform business email compromise (BEC) scams, and to deploy ransomware.
Security

Ask Slashdot: Could We Not Use DNS For a Certificate Revocation Mechanism? 97

Long-time Slashdot reader dhammabum writes: As reported in the recent slashdot story, starting in September we system admins will be forced into annually updating TLS certificates because of a decision by Apple, abetted by Google and Mozilla. Supposedly this measure somewhat rectifies the current ineffective certificate revocation list system by limiting the use of compromised certificates to one year... But in an attempt to prevent this pathetic measure, could we instead use DNS to replace the current certificate revocation list system?

Why not create a new type of TXT record, call it CRR (Certificate Revocation Record), that would consist of the Serial Number (or Subject Key ID or thumbprint) of the certificate. On TLS connection to a website, the browser does a DNS query for a CRR for the Common Name of the certificate. If the number/key/thumbprint matches, reject the connection. This way the onus is on the domain owner to directly control their fate. The only problem I can see with this is if there are numerous certificate Alternate Names — there would need to be a CRR for each name. A pain, but one only borne by the hapless domain owner.

Alternatively, if Apple is so determined to save us from ourselves, why don't they fund and host a functional CRL system? They have enough money. End users could create a CRL request via their certificate authority who would then create the signed record and forward it to this grand scheme.

Otherwise, are there any other ideas?
Security

Body Cam with Military Police Footage Sold on Ebay (azmirror.com) 17

"A security researcher was able to access files on a Axon body-worn camera he purchased from eBay that had video files of Fort Huachuca Military Police officers conducting investigations and filling out paperwork," reports the Arizona Mirror: The files were able to be extracted after the researcher, who goes by KF on Twitter, was able to remove a microSD card from the body-worn camera. KF was then able to extract the un-encrypted files, which were not protected by a password, using a tool called Foremost. KF shared screenshots of the footage he was able to pull from the cards that appeared to show members of the Fort Huachuca Military Police entering a person's home and filling out paperwork.

"We are aware of this issue and have launched an investigation looking into the matter," a statement from Scottsdale-based Axon said to Arizona Mirror. "We are also reevaluating our processes to better emphasize proper disposal procedures for our customers."

The camera that was purchased by KF was an Axon Body 1, one of the company's earliest generation models that launched in 2013. The company said it stopped the model in 2015. "Our latest generation camera, Axon Body 3, offers enhanced security measures such as storage encryption to protect video from being retrieved from lost or improperly disposed cameras," the statement said.

Friday the original security researcher posted an update on Twitter, saying he'd offered to send the body cam's SD card back to the military police -- an offer that was eventually accepted by Axon itself -- and "I only listened to a few seconds of audio merely to verify its presence. I've since removed all extracted data in full."

In an earlier tweet he'd added, "Those of you asking... NO, I won't dump the card for you. Procure your own BWC (Body Worn Cam), and dump it yourself " But it looks like they already are. Earlier on Twitter, one Security Operations Center analyst posted, "I just ordered two myself.

"I'd actually really like to get a fund going to buy literally all of them and dump them to an open cloud storage bucket... Freedom of Information Act through the secondhand market."
Bug

Microsoft Released an Emergency Security Update to Fix Two Bugs in Windows Codecs (zdnet.com) 62

Tuesday Microsoft published two out-of-band security updates to patch two vulnerabilities in the Microsoft Windows Codecs Library, reports ZDNet: Tracked as CVE-2020-1425 & CVE-2020-1457, the two bugs only impact Windows 10 and Windows Server 2019 distributions... Microsoft said the two security flaws can be exploited with the help of a specially crafted image file. If the malformed images are opened inside apps that utilize the built-in Windows Codecs Library to handle multimedia content, then attackers would be allowed to run malicious code on a Windows computer and potentially take over the device. The two bugs -- described as two remote code execution vulnerabilities -- received patches Wednesday.

"Customers do not need to take any action to receive the update," Microsoft said.

Yahoo!

Former Yahoo Engineer Who Infiltrated 6,000 Accounts Avoids Jail (siliconvalley.com) 35

This week finally saw the federal sentencing of a former Yahoo software engineer who "admitted to using his access through his work at the company to hack into about 6,000 Yahoo accounts" back in 2018, according to America's Department of Justice: Ruiz admitted to targeting accounts belonging to younger women, including his personal friends and work colleagues. He made copies of images and videos that he found in the personal accounts without permission, and stored the data at his home. Once he had access to the Yahoo accounts, Ruiz admitted to compromising the iCloud, Facebook, Gmail, DropBox, and other online accounts of the Yahoo users in search of more private images and videos. After his employer observed the suspicious account activity, Ruiz admitted to destroying the computer and hard drive on which he stored the images.
He stopped working at Yahoo in July of 2018. The next month the FBI visited his home. He was indicted in April of 2019 and pleaded guilty in September — facing up to five years in prison and a $250,000 fine.

But it was not until this week that a federal court finally handed down its sentence for the "former Yahoo! engineer who hacked 6,000 accounts on a hunt for private sexual videos and pictures," according to one Bay Area newspaper.

The sentence? Five years of probation, with a home confinement condition: Reyes Daniel Ruiz, 35, of Tracy, is allowed to leave his home for "verified employment, medical needs and religious services," according to the sentencing terms. He has also been ordered to pay nearly $125,000 in fines and restitution, court records show...

He also accessed financial information, but his main goal was to steal pornographic files, prosecutors said. Assistant U.S. Attorney Daniel Kaleba asked for Ruiz to be sentenced to "a period of incarceration," arguing he'd violated not only the trust of his employee but the privacy of thousands of people. "By his estimation, he downloaded approximately two terabytes of data, and possessed between 1,000 and 4,000 private images and videos," Kaleba wrote in a sentencing memo.

The defense argued that Ruiz, who has no criminal history, deserved leniency because he accepted responsibility quickly. He admitted to destroying the hard drive where he stored the ill-gotten files when the FBI visited his home in August 2018. Ruiz told federal investigators that he acquired the pictures and videos for his own personal "self-gratification" and that he didn't share them online, a pre-sentence report says.

In October Gizmodo reported that Ruiz was now working for a Silicon Valley company specializing in SSO (single sign-on) solutions.
Chrome

Chrome for Android is Finally Going 64-bit, Giving it a Speed Boost in Benchmarks (androidpolice.com) 46

An anonymous reader shares a report: The first Android version to support 64-bit architecture was Android 5.0 Lollipop, introduced back in November 2014. Since then, more and more 64-bit processors shipped, and today, virtually all Android devices are capable of running 64-bit software (excluding one or two or more oddballs). However, Google Chrome has never made the jump and is only available in a 32-bit flavor, potentially leading to some unnecessary security and performance degradations. That's finally changing: Starting with Chrome 85, phones running Android 10 and higher will automatically receive a 64-bit version. A look at chrome://version confirms as much: The current stable and beta builds, version 83 and 84, note that they're still 32-bit applications. Chrome Dev and Chrome Canary (release 85 and 86) are proper 64-bit apps. Google confirms as much on its Chromium Bugs tracker.

When compared in a number of Octane 2.0 benchmarks, the 64-bit version got consistently better results than the 32-bit version. It's possible that there have been other optimizations that make Chrome 85 faster than 83 -- the architecture is not necessarily all there is to it. Still, the benchmark results suggest that there are some enhancements, even if these tests aren't easy to translate to real-world usage.

Security

New Apple macOS Big Sur Feature To Hamper Adware Operations (zdnet.com) 16

With macOS 11, also known as Big Sur, Apple has removed the ability to install macOS profile configurations from the command-line. ZDNet reports: This ability was previously a core feature of macOS' enterprise package, which allows system administrators to deploy new configurations company-wide via automated scripts. However, the ability to deploy a new profile config via the command-line has also been abused by malware gangs or adware strains, who used it because it was silent and didn't require any type of user interaction. Hackers or malware authors who gained access to Mac Deployment servers or who infected just one Mac, abused the command-line to deploy their own malicious configurations to hijack proxy settings, change default apps, and more.
Encryption

Inside the Plot To Kill the Open Technology Fund (vice.com) 80

An anonymous reader quotes a report from VICE News: [The Open Technology Fund is a U.S. government-funded nonprofit, which is part of the umbrella group called the U.S. Agency for Global Media (USAGM), which also controls Radio Free Asia and Voice of America.] OTF's goal is to help oppressed communities across the globe by building the digital tools they need and offering training and support to use those tools. Its work has saved countless lives, and every single day millions of people use OTF-assisted tools to communicate and speak out without fear of arrest, retribution, or even death. The fund has helped dissidents raise their voices beyond China's advanced censorship network, known as the Great Firewall; helped citizens in Cuba to access news from sources other than the state-sanctioned media; and supported independent journalists in Russia so they could work without fear of a backlash from the Kremlin. Closer to home, the tools that OTF has funded, including the encrypted messaging app Signal, have allowed Black Lives Matter protesters to organize demonstrations across the country more securely.

But now all of that is under threat, after Michael Pack, a Trump appointee and close ally of Steve Bannon, took control of USAGM in June. Pack has ousted the OTF's leadership, removed its bipartisan board, and replaced it with Trump loyalists, including Bethany Kozma, an anti-transgender activist. One reason the OTF managed to gain the trust of technologists and activists around the world is because, as its name suggests, it invested largely in open-source technology. By definition, open-source software's source code is publicly available, meaning it can be studied, vetted, and in many cases contributed to by anyone in the world. This transparency makes it possible for experts to study code to see if it has, for example, backdoors or vulnerabilities that would allow for governments to compromise the software's security, potentially putting users at risk of being surveilled or identified. Now, groups linked to Pack and Bannon have been pressing for the funding of closed-source technology, which is antithetical to the OTF's work over the last eight years.
Pack is being pressed to fund Freegate and Ultrasurf, "two little-known apps that allow users to circumvent internet censorship in repressive regimes but currently have very small user bases inside China," reports Vice. "These apps are not widely trusted by internet freedom experts and activists, according to six experts who spoke to VICE News. That the OTF would pivot its funding from trusted, open-source tech to more obscure, closed-source tech has alarmed activists around the world and has resulted in open revolt among OTF's former leadership."

More than half a dozen experts who spoke to VICE News "said the apps' code is out of date, dangerously vulnerable to compromise, and lacks the user base to allow it to effectively scale even if they secured government funding."
Microsoft

Microsoft is Force-Feeding Edge To Windows Users With a Spyware-like Install (theverge.com) 155

Sean Hollister, writing for The Verge: If I told you that my entire computer screen just got taken over by a new app that I'd never installed or asked for -- it just magically appeared on my desktop, my taskbar, and preempted my next website launch -- you'd probably tell me to run a virus scanner and stay away from shady websites, no? But the insanely intrusive app I'm talking about isn't a piece of ransomware. It's Microsoft's new Chromium Edge browser, which the company is now force-feeding users via an automatic update to Windows. Seriously, when I restarted my Windows 10 desktop this week, an app I'd never asked for:

1. Immediately launched itself
2. Tried to convince me to migrate away from Chrome, giving me no discernible way to click away or say no
3. Pinned itself to my desktop and taskbar
4. Ignored my previous browser preference by asking me -- the next time I launched a website -- whether I was sure I wanted to use Chrome instead of Microsoft's oh-so-humble recommendation.
5. Did I mention that, as of this update, you can't uninstall Edge anymore?

Facebook

Facebook Says 5,000 App Developers Got User Data After Cutoff Date (zdnet.com) 3

Social media giant Facebook disclosed on Wednesday a new user privacy incident. The company said that it continued sharing user data with approximately 5,000 developers even after their application's access expired. From a report: The incident is related to a security control that Facebook added to its systems following the Cambridge Analytica scandal of early 2018. Responding to criticism that it allowed app developers too much access to user information, Facebook added at the time a new mechanism to its API that prevented apps from accessing a user's data if the user did not use the app for more than 90 days. However, Facebook said that it recently discovered that in some instances, this safety mechanism failed to activate and allowed some apps to continue accessing user information even past the 90-day cutoff date. Konstantinos Papamiltiadis, VP of Platform Partnerships at Facebook, said engineers fixed the issue on the same day they found it.
Security

One Out of Every 142 Passwords is '123456' (zdnet.com) 71

In one of the biggest password re-use studies of its kind, an analysis of more than one billion leaked credentials has discovered that one out of every 142 passwords is the classic "123456" string. From a report: The study, carried out last month by computer engineering student Ata Hakcil, analyzed username and password combinations that leaked online after data breaches at various companies. These "data dumps" have been around for more than half a decade, and have been piling up as new companies are getting hacked. The data dumps are easily available online, on sites like GitHub or GitLab, or freely distributed via hacking forums and file-sharing portals. Over the years, tech companies have been collecting these data dumps. For example, Google, Microsoft, and Apple, have collected leaked credentials to create in-house alert systems that warn users when they're utilizing a "weak" or "common" password.
Crime

How Police Secretly Took Over a Global Phone Network for Organized Crime (vice.com) 87

Police monitored a hundred million encrypted messages sent through Encrochat, a network used by career criminals to discuss drug deals, murders, and extortion plots. From a report: Something wasn't right. Starting earlier this year, police kept arresting associates of Mark, a UK-based alleged drug dealer. Mark took the security of his operation seriously, with the gang using code names to discuss business on custom, encrypted phones made by a company called Encrochat. For legal reasons, Motherboard is referring to Mark using a pseudonym. Because the messages were encrypted on the devices themselves, police couldn't tap the group's phones or intercept messages as authorities normally would. On Encrochat, criminals spoke openly and negotiated their deals in granular detail, with price lists, names of customers, and explicit references to the large quantities of drugs they sold, according to documents obtained by Motherboard from sources in and around the criminal world.

Maybe it was a coincidence, but in the same time frame, police across the UK and Europe busted a wide range of criminals. In mid-June, authorities picked up an alleged member of another drug gang. A few days later, law enforcement seized millions of dollars worth of illegal drugs in Amsterdam. It was as if the police were detaining people from completely unrelated gangs simultaneously. "[The police] all over it aren't they," the dealer wrote in one of the messages obtained by Motherboard. "My heads still baffled how they got on all my guys." Unbeknownst to Mark, or the tens of thousands of other alleged Encrochat users, their messages weren't really secure. French authorities had penetrated the Encrochat network, leveraged that access to install a technical tool in what appears to be a mass hacking operation, and had been quietly reading the users' communications for months. Investigators then shared those messages with agencies around Europe.

Only now is the astonishing scale of the operation coming into focus: It represents one of the largest law enforcement infiltrations of a communications network predominantly used by criminals ever, with Encrochat users spreading beyond Europe to the Middle East and elsewhere. French, Dutch, and other European agencies monitored and investigated "more than a hundred million encrypted messages" sent between Encrochat users in real time, leading to arrests in the UK, Norway, Sweden, France, and the Netherlands, a team of international law enforcement agencies announced Thursday. As dealers planned trades, money launderers washed their proceeds, and even criminals discussed their next murder, officers read their messages and started taking suspects off the street.

Security

New Mac Ransomware Is Even More Sinister Than It Appears (wired.com) 49

An anonymous reader quotes a report from Wired: The threat of ransomware may seem ubiquitous, but there haven't been too many strains tailored specifically to infect Apple's Mac computers since the first full-fledged Mac ransomware surfaced only four years ago. So when Dinesh Devadoss, a malware researcher at the firm K7 Lab, published findings on Tuesday about a new example of Mac ransomware, that fact alone was significant. It turns out, though, that the malware, which researchers are now calling ThiefQuest, gets more interesting from there. In addition to ransomware, ThiefQuest has a whole other set of spyware capabilities that allow it to exfiltrate files from an infected computer, search the system for passwords and cryptocurrency wallet data, and run a robust keylogger to grab passwords, credit card numbers, or other financial information as a user types it in. The spyware component also lurks persistently as a backdoor on infected devices, meaning it sticks around even after a computer reboots, and could be used as a launchpad for additional, or "second stage," attacks. Given that ransomware is so rare on Macs to begin with, this one-two punch is especially noteworthy.

Though ThiefQuest is packed with menacing features, it's unlikely to infect your Mac anytime soon unless you download pirated, unvetted software. Thomas Reed, director of Mac and mobile platforms at the security firm Malwarebytes, found that ThiefQuest is being distributed on torrent sites bundled with name-brand software, like the security application Little Snitch, DJ software Mixed In Key, and music production platform Ableton. K7's Devadoss notes that the malware itself is designed to look like a "Google Software Update program." So far, though, the researchers say that it doesn't seem to have a significant number of downloads, and no one has paid a ransom to the Bitcoin address the attackers provide. [...] Given that the malware is being distributed through torrents, seems to focus on stealing money, and still has some kinks, the researchers say it was likely created by criminal hackers rather than nation state spies looking to conduct espionage.

Slashdot Top Deals