Security

Michigan State University Network Breached In Ransomware Attack (bleepingcomputer.com) 8

Netwalker ransomware-as-a-service (RaaS) operators have reportedly breached Michigan State University's network, threatening to leak private files to the public if they don't pay a ransom in time. BleepingComputer reports: A countdown timer on the attacker's website shows that the university has about six days to comply or "secret data" will become public. The site set up by the Netwalker ransomware gang gives no details about the attack but they posted images with directories, a passport scan, and two financial documents allegedly stolen from the university's network. Information about how and when the attack happened, its impact on MSU, and the ransom demand remain unknown at this time.
Chrome

Google To Enable the Chrome Anti-Notification Spam System in July 2020 (zdnet.com) 17

Google announced this week plans to enable its new anti-notification spam system in Chrome over the summer, with the release of Chrome 84, on July 12, 2020. From a report: Known internally as the "quieter notification permission UI," this Chrome component works by blocking sites from showing notification requests, which are hidden under an icon in the Chrome URL bar (on desktop) or under a toolbar (on mobile). Google first announced the "quieter notification permission UI" in January, and shipped it in February, in Chrome 80, in a limited, user opt-in fashion. But in a blog post, Google said the new UI and its ability to detect spammy notification popups has been improved and will roll out enabled by default for all users in July, with the release of Chrome 84.
Bug

Software Bug In Bombardier Airliner Made Planes Turn the Wrong Way (theregister.co.uk) 34

An anonymous reader quotes a report from The Register: A very specific software bug made airliners turn the wrong way if their pilots adjusted a pre-set altitude limit. The bug, discovered on Bombardier CRJ-200 aircraft fitted with Rockwell Collins Aerospace-made flight management systems (FMSes), led to airliners trying to follow certain missed approaches turning right instead of left -- or vice versa.

First discovered in 2017, the flaw was only apparent when pilots manually edited a pre-set "climb to" altitude programmed into a "missed approach" procedure following an Instrument Landing System approach. It also arose if pilots used the FMS's temperature compensation function in extremely cold weather. In theory the bug could have led to airliners crashing into the ground, though the presence of two trained and alert humans in the cockpit monitoring what the aircraft was doing made this a remote possibility.
"The bug was first uncovered when a CRJ-200 crew flying into Canada's Fort St John airport used the FMS's temperature correction function," the report adds. "They discovered that the software turned their aeroplane in the wrong direction while it was following the published missed approach, something that generally does not happen. The fault was swiftly reported to the authorities and the relevant manufacturers."

Full details, including the maths, are available here. The U.S. Federal Aviation Authorities also published a Powerpoint presentation (PDF) about the bug.
Security

NSA Warns of New Sandworm Attacks on Email Servers (zdnet.com) 21

The US National Security Agency (NSA) has published a security alert warning of a new wave of cyberattacks against email servers, attacks conducted by one of Russia's most advanced cyber-espionage units. From a report: The NSA says that members of Unit 74455 of the GRU Main Center for Special Technologies (GTsST), a division of the Russian military intelligence service, have been attacking email servers running the Exim mail transfer agent (MTA). Also known as "Sandworm," this group has been hacking Exim servers since August 2019 by exploiting a critical vulnerability tracked as CVE-2019-10149, the NSA said in a security alert shared today with ZDNet. "When Sandworm exploited CVE-2019-10149, the victim machine would subsequently download and execute a shell script from a Sandworm-controlled domain," the NSA says.
Businesses

Miss Your Office? Some Companies Are Building Virtual Replicas (wsj.com) 48

An anonymous reader quotes a report from The Wall Street Journal: Stay-home orders and the shuttering of workplaces have given corporate employees some respite from getting dragged into time-wasting water-cooler conversations. But some companies and their employees don't want to leave everything about the office behind, it turns out, and are replicating their offices in "SimCity"-like simulations online. File-transfer service WeTransfer BV opened its virtual space on May 1, almost seven weeks after closing its physical offices in New York, Los Angeles and Amsterdam as part of the global effort to slow the spread of the new coronavirus.

Graphics reminiscent of early "Tomb Raider" videogames depict a version of the company's Dutch headquarters, adapted to include pool tables, techno music and in-jokes such as a "memorial" library named for the very- much-alive chief creative officer. Staff roam around in the form of avatars such as robots and panda bears. Gordon Willoughby, the chief executive of WeTransfer, said the platform helps provide the social experience of office life in the way that Zoom calls and Slack have replaced business meetings and desk-side chats. That is particularly valuable for recent hires, he said. [...] Although clients can use Breakroom to create their office utopia, the platform also enables real-world elements such additional privileges for senior staff. In Sine Wave's own virtual world, senior members can lock the boardroom, which is located on top of a hill overlooking the rest of the office.

Government

NSA Warns of Ongoing Russian Hacking Campaign Against US Systems (reuters.com) 25

The U.S. National Security Agency on Thursday warned government partners and private companies about a Russian hacking operation that uses a special intrusion technique to target operating systems often used by industrial firms to manage computer infrastructure. Reuters reports: "This is a vulnerability that is being actively exploited, that's why we're bringing this notification out," said Doug Cress, chief of the cybersecurity collaboration center and directorate at NSA. "We really want... the broader cybersecurity community to take this seriously." Cress declined to discuss which business sectors had been most affected, how many organizations were compromised using the Russian technique, or whether the cyber espionage operation targeted a specific geographic region.

The NSA said the hacking activity was tied directly to a specific unit within Russia's Main Intelligence Directorate, also known as the GRU, named the Main Center for Special Technologies. The cybersecurity research community refers to this same hacking group as "Sandworm," and has previously connected it to disruptive cyberattacks against Ukrainian electric production facilities. A security alert published by the NSA on Thursday explains how hackers with GRU, Russia's military intelligence, are leveraging a software vulnerability in Exim, a mail transfer agent common on Unix-based operating systems, such as Linux. The vulnerability was patched last year, but some users have not updated their systems to close the security gap.

Security

$100 Million in Bounties Paid by HackerOne To Ethical Hackers (bleepingcomputer.com) 8

Bug bounty platform HackerOne announced today that it has paid out $100,000,000 in rewards to white-hat hackers around the world as of May 26, 2020. From a report: Since it started delivering vulnerability reports to its customers, HackerOne bug bounty hunters have found roughly 170,000 security vulnerabilities according to the company's CEO Marten Mickos. Over 700,000 ethical hackers are no using the bug bounty platform to get paid for security bugs in the products of more than 1,900 HackerOne customers. "It is impossible to know exactly how many cyber breaches have thereby been averted but we can estimate that it is thousands or perhaps over ten thousand," Mickos said.
Programming

Developers Reveal Programming Languages They Love and Loathe, and What Pays Best (zdnet.com) 139

Stack Overflow has released the results of its 2020 survey of nearly 65,000 developers, revealing their favorite and most dreaded programming languages, tools and frameworks. From a news writeup: The survey shows that TypeScript, Microsoft's superset of the widely-used JavaScript programming language, has overtaken Python as the second most beloved programming language behind Rust. This year 86% of respondents say they are keen to use Rust, while 67.1% want to use TypeScript, and 66.7% want to use Python. Stack Overflow attributes TypeScript's rising popularity to Microsoft's embrace of open source software as well as the existence of larger and more complex JavaScript and Node.js codebases.

Rust has been the most loved programming language for five years running, despite few developers having experience with it. This year, just 5.1% developers report having used Rust, compared with the 68% who use JavaScript, which is the most commonly used language. [...] Meanwhile, the top 10 most dreaded programming languages are VBA, Objective-C, Perl, Assembly, C, PHP, Ruby, C++, Java and R.

The report also looks at average salaries of each developer role. In the US, engineering managers attract the highest salary at $152,000 per year, followed by site reliability engineers who earn $140,000 per year. Salaries across the globe for these roles are lower, at $92,000 for an engineering manager and $80,000 for a site reliability engineer. Other high-paying roles with an average salary of at least $115,000 in the US include data scientist and machine learning specialist, DevOps specialist, engineer, back-end developer, embedded application developers, mobile developers, scientist, desktop application developer, and educator.

Google

Google Highlights Indian 'Hack-for-Hire' Companies in New TAG Report (zdnet.com) 4

The Google Threat Analysis Group (TAG), a division inside Google's security department that tracks nation-state and high-end cybercrime groups, has published its inaugural TAG quarterly report. In the Q1 2020 TAG Bulletin, Google analysts chose to highlight two rising trends the company saw in the first three months of 2020. The first is the rising scene of hack-for-fire companies currently operating out of India, a country where such services have not been prominent until now. From a news story: The second trend was the rising number of political influence operations carried out by governments across the world. This also marks the first time when Google publishes official disclosures of coordinated influence operations that abused the company's platforms. According to Google, attacks that leveraged the coronavirus (COVID-19) theme were one of the most common trends the company saw among nation-state and high-end cybercrime operators in Q1 2020. While the company saw efforts from Chinese and Iranian hacking groups, there was also a novel set of threat actors exploiting the coronavirus pandemic to launch cyber-attacks.
Security

Turla Hacker Group Steals Antivirus Logs To See If Its Malware Was Detected (zdnet.com) 8

An anonymous reader quotes a report from ZDNet: Security researchers from ESET have discovered new attacks carried out by Turla, one of Russia's most advanced state-sponsored hacking groups. The new attacks have taken place in January 2020. ESET researchers say the attacks targeted three high-profile entities, such as a national parliament in the Caucasus and two Ministries of Foreign Affairs in Eastern Europe. Targets could not be identified by name due to national security reasons. [...] The ComRAT malware, also known as Agent.BTZ, is one of Turla's oldest weapons, and the one they used to siphon data from the Pentagon's network in 2008. The tool has seen several updates across the years, with new versions discovered in 2014 and 2017, respectively.

The latest version, known as ComRAT v4, was first seen in 2017, however, in a report published today, ESET says they've spotted a variation of ComRAT v4 that includes two new features, such as the ability to exfiltrate antivirus logs and the ability to control the malware using a Gmail inbox. The first of these features is the malware's ability to collect antivirus logs from an infected host and upload it to one of its command and control servers. The exact motives of a hacker group will always remain unclear, but Matthieu Faou, the ESET researcher who analyzed the malware, told ZDNet that Turla operators might be collecting antivirus logs to "allow them to better understand if and which one of their malware sample was detected." The belief is that if Turla operators see a detection, they can then tweak their malware and avoid future detections on other systems, where they can then operate undetected.

Bug

New Fuzzing Tool Finds 26 USB Bugs in Linux, Windows, macOS, and FreeBSD (zdnet.com) 37

Academics say they have discovered 26 new vulnerabilities in the USB driver stack employed by operating systems such as Linux, macOs, Windows, and FreeBSD. From a report: The research team, made up by Hui Peng from Purdue University and Mathias Payer from the Swiss Federal Institute of Technology Lausanne, said all the bugs were discovered with a new tool they created, named USBFuzz. The tool is what security experts call a fuzzer. Fuzzers are applications that let security researchers send large quantities of invalid, unexpected, or random data as inputs to other programs. Security researchers then analyze how the tested software behaves to discover new bugs, some of which may be exploited in a malicious way.
Security

OpenSSH To Deprecate SHA-1 Logins Due To Security Risk (zdnet.com) 39

OpenSSH, the most popular utility for connecting to and managing remote servers, has announced today plans to drop support for its SHA-1 authentication scheme. From a report: The OpenSSH team cited security concerns with the SHA-1 hashing algorithm, currently considered insecure. The algorithm was broken in a practical, real-world attack in February 2017, when Google cryptographers disclosed SHAttered, a technique that could make two different files appear as they had the same SHA-1 file signature. At the time, creating an SHA-1 collision was considered computationally expensive, and Google experts thought SHA-1 could still be used in practice for at least half a decade until the cost would go down. However, subsequent research released in May 2019 and in January 2020, detailed an updated methodology to cut down the cost of an SHA-1 chosen-prefix collision attack to under $110,000 and under $50,000, respectively.
Windows

Microsoft Releases Windows 10 Update with Linux and Notepad Enhancements 82

Microsoft is starting to release the latest twice-annual update to Windows 10, featuring enhancements to the longstanding Notepad app and a way to find your cursor in a sea of text. Some of the other features include: Faster and easier connections: We're making it easier and faster to pair your Bluetooth devices to your compatible Windows 10 PC. Now you can take care of everything in notifications (instead of Settings) with fewer steps.
Go passwordless: Did you know -- for improved security and a simple sign-in experience, you can sign in with your face, fingerprint, or PIN? It's easier than ever to enable passwordless sign-in for your Microsoft accounts: just go to Settings > Accounts > Sign-in options on your Windows 10 PC and select 'On' under 'Make your device passwordless.' Note that this is hardware dependent.
Name your desktops: Now instead of "Desktop 1" or "Desktop 2" you can give your Virtual Desktops more descriptive, clever, or amusing names. Using Virtual Desktop in Windows 10 allows you to expand your desktop beyond the physical limitations of the space, organize groups of related tasks, and easily switch between them. Tackling what you want to -- when you want to -- just got a whole lot easier. Visit this post to learn more on how to access Virtual Desktop in Windows 10.
See gaming in a whole new light: New DirectX 12 Ultimate features provide smoother graphics with increased detail -- all without sacrificing framerate.
Customization and utility at your fingertips: Xbox Game Bar now supports third-party widgets, helping you customize the overlay experience to fit with the way you game.
The Internet

Chrome and Firefox Block Torrent Site YTS Over 'Phishing' (torrentfreak.com) 34

Chrome and Firefox are blocking direct access to the movie download pages of popular torrent site YTS. According to Google's safe browsing report, YTS.mx is a "deceptive site" that may trick visitors into doing dangerous things. The warning is likely the result of malicious advertisements. TorrentFreak reports: While the site's homepage can be visited just fine, navigating to a torrent detail page throws up the following warning in Chrome. "Deceptive site ahead. Attackers on yts.mx may trick you into doing something dangerous like installing software or revealing your personal information (for example, passwords, phone numbers, or credit cards)." Firefox shows a similar alert and also prevents people from going directly to the download pages. In both browsers, people can, however, accept the risk and visit the page they were looking for.

It's not clear what the exact problem is but the Chrome warning mentions that YTS was caught phishing. This is also reflected in Google's Safe Browsing report, which states the torrent site recently tried to trick visitors into sharing personal info or downloading software. Whether any of this is intentional remains a question. It seems more likely that the warning was triggered by some type of malicious advertisement.

Security

New Android Vulnerability Strandhogg 2.0 Exploits User Trust (arstechnica.com) 10

An anonymous reader quotes a report from Ars Technica: A Norwegian infosec firm discovered a new Android vulnerability, which they've dubbed Strandhogg 2.0. Security firm Promon says "Strandhogg" is an old Norse strategy for coastline raids and abductions, and today's vulnerability is the "evil twin" of a similar one discovered in 2019. The original Strandhogg used an Android feature called taskAffinity to hijack applications -- by setting the taskAffinity of one of its activities to match the packageName of any other app, then setting allowTaskReparenting="true" in its own manifest, the Strandhogg app would be launched in place of the target app. Strandhogg's 1.0 major weakness was the need to declare taskAffinity in the Android Manifest. The Manifest is a plain XML file and must be included in the package hosted at the Play Store itself -- it can't simply be downloaded later, after the app is installed. This made it relatively simple to scan the Play store for apps with sketchy-looking taskAffinity declarations. Strandhogg 2.0 doesn't require any special settings in a package's Android Manifest -- meaning the attacking code doesn't need to be present on the Play Store to be scanned at all. Instead, the attacker can download the attack code later, once the trojan app or game is already installed on a user's device.

In addition to the obvious credential-stealing attacks, Strandhogg can be used to trick users into escalating its privileges based on the trust they have for the apps it hijacks. For example, a user tapping Camera is asked if they want to grant it permission to access the camera and microphone -- if the user taps Yes, they've actually given those privileges to the malware app, not the Camera app it covered up on the screen. Strandhogg 2.0 affects all versions of Android prior to 10 -- which translates to roughly 90 percent of the Android userbase. Google rolled out a patch to close the Strandhogg 2.0 vulnerability, CVE-2020-0096, in May's Android Security Update. This is good news for Pixel users -- but as always, carriers and OEMs may delay those upgrades significantly.

Security

Thousands of Enterprise Systems Infected by New Blue Mockingbird Malware Gang (zdnet.com) 44

Thousands of enterprise systems are believed to have been infected with a cryptocurrency-mining malware operated by a group tracked under the codename of Blue Mockingbird. From a report: Discovered earlier this month by malware analysts from cloud security firm Red Canary, the Blue Mockingbird group is believed to have been active since December 2019. Researchers say Blue Mockingbird attacks public-facing servers running ASP.NET apps that use the Telerik framework for their user interface (UI) component. Hackers exploit the CVE-2019-18935 vulnerability to plant a web shell on the attacked server. They then use a version of the Juicy Potato technique to gain admin-level access and modify server settings to obtain (re)boot persistence. Once they gain full access to a system, they download and install a version of XMRRig, a popular cryptocurrency mining app for the Monero (XMR) cryptocurrency.
Bug

Chrome: 70% of All Security Bugs Are Memory Safety Issues (zdnet.com) 52

Roughly 70% of all serious security bugs in the Chrome codebase are memory management and safety bugs, Google engineers said. From a report: Half of the 70% are use-after-free vulnerabilities, a type of security issue that arises from incorrect management of memory pointers (addresses), leaving doors open for attackers to attack Chrome's inner components. The percentage was compiled after Google engineers analyzed 912 security bugs fixed in the Chrome stable branch since 2015, bugs that had a "high" or "critical" severity rating. The number is identical to stats shared by Microsoft. Speaking at a security conference in February 2019, Microsoft engineers said that for the past 12 years, around 70% of all security updates for Microsoft products addressed memory safety vulnerabilities.
Google

Google Removes QAnon Apps From Play Store for Violating Terms (cnet.com) 207

Google last week removed three apps related to the QAnon conspiracy theory from its Play Store digital marketplace. From a report: The apps -- called QMAP, Q Alerts! and Q Alerts LITE -- were taken down for violating Google's policies against "harmful information," the company said. The removal was earlier reported by Media Matters for America, a progressive not-for-profit. The QAnon conspiracy theory has become popular among a group of supporters of President Donald Trump. One claim is that celebrities are involved in child sex trafficking and pedophilia. Another tenet is that Trump is working to take down the so-called "Deep State," a secret network that manipulates and controls government policy. The theory revolves around "Q," an anonymous user who began writing about the conspiracies on imageboard site 4chan.
Privacy

A Massive Database of 8 Billion Thai Internet Records Leaks (techcrunch.com) 13

Thailand's largest cell network AIS has pulled a database offline that was spilling billions of real-time internet records on millions of Thai internet users. From a report: Security researcher Justin Paine said in a blog post that he found the database, containing DNS queries and Netflow data, on the internet without a password. With access to this database, Paine said that anyone could "quickly paint a picture" about what an internet user (or their household) does in real-time. Paine alerted AIS to the open database on May 13. But after not hearing back for a week, Paine reported the apparent security lapse to Thailand's national computer emergency response team, known as ThaiCERT, which contacted AIS about the open database. The database was inaccessible a short time later. AIS spokesperson Sudaporn Watcharanisakorn confirmed AIS owned the data, and apologized for the security lapse.
Privacy

eBay Port Scans Visitors' Computers For Remote Access Programs (bleepingcomputer.com) 100

AmiMoJo shares a report: When visiting the eBay.com site, a script will run that performs a local port scan of your computer to detect remote support and remote access applications. Many of these ports are related to remote access/remote support tools such as the Windows Remote Desktop, VNC, TeamViewer, Ammy Admin, and more. After learning about this, BleepingComputer conducted a test and can confirm that eBay.com is indeed performing a local port scan of 14 different ports when visiting the site.

Slashdot Top Deals