Microsoft

Microsoft Word Now Flags Double Spaces as Errors, Ending the Great Space Debate (theverge.com) 344

Microsoft has settled the great space debate, and sided with everyone who believes one space after a period is correct, not two. From a report: The software giant has started to update Microsoft Word to highlight two spaces after a period (a full stop for you Brits) as an error, and to offer a correction to one space. Microsoft recently started testing this change with the desktop version of Word, offering suggestions through the Editor capabilities of the app. If you're still (strangely) on the two-spacer side, you will be able to ignore the suggestion. The Editor feature in Word allows users to ignore the suggestion once, make the change to one space, or turn off the writing-style suggestion. We understand Microsoft has been testing the feature change recently and it will roll out to everyone using the desktop version of Word soon. Feedback to the change has been overwhelmingly positive. "As the crux of the great spacing debate, we know this is a stylistic choice that may not be the preference for all writers, which is why we continue to test with users and enable these suggestions to be easily accepted, ignored, or flat out dismissed in Editor," says Kirk Gregersen, partner director of program management at Microsoft, in a statement to The Verge.
Security

When in Doubt: Hang Up, Look Up, and Call Back (krebsonsecurity.com) 85

Many security-conscious people probably think they'd never fall for a phone-based phishing scam. But if your response to such a scam involves anything other than hanging up and calling back the entity that claims to be calling, you may be in for a rude awakening. Brian Krebs: Here's how one security and tech-savvy reader got taken for more than $10,000 in an elaborate, weeks-long ruse. Today's lesson in how not to get scammed comes from "Mitch," the pseudonym I picked for a reader in California who shared his harrowing tale on condition of anonymity. Mitch is a veteran of the tech industry -- having worked in security for several years at a fairly major cloud-based service -- so he's understandably embarrassed that he got taken in by this confidence scheme. On Friday, April 17, Mitch received a call from what he thought was his financial institution, warning him that fraud had been detected on his account. Mitch said the caller ID for that incoming call displayed the same phone number that was printed on the back of his debit card. But Mitch knew enough of scams to understand that fraudsters can and often do spoof phone numbers. So while still on the phone with the caller, he quickly logged into his account and saw that there were indeed multiple unauthorized transactions going back several weeks. Most were relatively small charges -- under $100 apiece -- but there were also two very recent $800 ATM withdrawals from cash machines in Florida.

If the caller had been a fraudster, he reasoned at the time, they would have asked for personal information. But the nice lady on the phone didn't ask Mitch for any personal details. Instead, she calmly assured him the bank would reverse the fraudulent charges and said they'd be sending him a new debit card via express mail. After making sure the representative knew which transactions were not his, Mitch thanked the woman for notifying him, and hung up. The following day, Mitch received another call about suspected fraud on his bank account. Something about that conversation didn't seem right, and so Mitch decided to use another phone to place a call to his bank's customer service department -- while keeping the first caller on hold. "When the representative finally answered my call, I asked them to confirm that I was on the phone with them on the other line in the call they initiated toward me, and so the rep somehow checked and saw that there was another active call with Mitch," he said. "But as it turned out, that other call was the attackers also talking to my bank pretending to be me."

The Internet

NordVPN Unveils First Mainstream WireGuard Virtual Private Network (zdnet.com) 51

One of the largest VPN companies, NordVPN, is rolling out NordLynx -- it's first mainstream WireGuard virtual private network for its Windows, Mac, Android and iOS client-software applications. ZDNet reports: NordVPN's own tests have shown NordLynx easily outperforms the other protocols, IKEv2/IPsec and OpenVPN. How much faster? According to NordVPN's 256,886 speed tests, "When a user connects to a nearby VPN server and downloads content that's served from a content delivery network (CDN) within a few thousand miles/kilometers, they can expect up to twice higher download and upload speed." While speed is what customers will notice, security experts like WireGuard for its code's simplicity. With only about 4,000 lines of code, WireGuard's code can be comprehensively reviewed by a single individual.

Besides WireGuard, NordVPN adds in its double Network Address Translation (NAT) system to protect users' privacy. This enables users to establish a secure VPN connection while storing no identifiable user data on a server. You're assigned a dynamic local IP address that remains assigned only while the session is active. User authentication is done with the help of a secure external database. To switch to NordLynx, users need to update their NordVPN app to the latest version. The NordLynx protocol can be chosen manually from the Settings menu.

Privacy

Team Fortress 2 Source Code Leak Raises Security Fears (techradar.com) 12

"The source code for Team Fortress 2 has apparently been leaked, leading to hackers reportedly able to deliver malware through Remote Code Execution to other players," reports TechRadar. However, Valve assures users that playing on official servers is perfectly safe. From the report: This leak was initially reported by @SteamDB on Twitter, with the source code in question dating back to 2017 and 2018, affecting Counter-Strike: Source and Team Fortress 2. According to a report on the issue from PCGamesN, several Team Fortress 2 server communities have advised players to avoid the game until further notice.

Valve has reached out with a comment, saying "We have reviewed the leaked code and believe it to be a reposting of a limited CS:GO engine code depot released to partners in late 2017, and originally leaked in 2018. From this review, we have not found any reason for players to be alarmed or avoid the current builds (as always, playing on the official servers is recommended for greatest security)." Valve goes on to clarify that it's investigating the problem and anyone who has any information can report it on Valve's security page, which will explain how to fix the issue.

Businesses

People Are Making Bots To Snatch Whole Foods Delivery Order Time Slots (vice.com) 109

Social distancing and stay-home orders have led to booming demand for grocery delivery services. In some big cities, people report not being able to find an open delivery time slot for days or weeks at a time. And now Motherboard has found a series of bots that automatically give some people an upper hand when limited delivery time slots are available on Amazon Fresh or Wholefoods. From a report: A slew of developers have made bots and other tools that, in some cases, automatically hunt for a free delivery slot, grab it, and then complete the user's food order, making sure they have a much better chance of buying food before other people snatch up the slot. While some of the developers told Motherboard they designed their bots to help those in need, such as senior citizens who may need to stay inside as exposure to the coronavirus could be more serious for them, others are dealing with the ethical issue of releasing a tool that can clearly be abused, by allowing those who can figure out how to use a technical tool to buy food while others go without.

"Yes, it's an unfair advantage over others who aren't tech-savvy but may still need to purchase items urgently. However, I try my best to reduce the abused [sic] problem," Manfong, the developer behind a Chrome extension that notifies users when a delivery slot is available, told Motherboard in an email. Checkout bots, often reserved for buying things like limited edition sneakers or concert tickets, are in particularly high demand at the moment for other items. Last week Motherboard reported how one developer had created a bot dedicated to buying the Nintendo Switch, with resellers grabbing as many as they can to sell for a profit during the crisis. Now, that idea of getting a technical one-up over others has expanded to buying essential items such as food.

Iphone

Researchers Say They Caught an iPhone Zero-Day Hack in the Wild (vice.com) 31

In the summer of 2016, researchers at a digital rights organization and a cybersecurity firm announced they had caught one of the rarest fish in the cybersecurity ocean -- an in the wild attack against an iPhone, using unknown vulnerabilities inside Apple's vaunted operating system. Since then, only a handful of similar attacks have been caught and publicly disclosed. Now, a small startup said it has caught another one. From a report: ZecOps, a company based in San Francisco, announced on Wednesday that a few of its customers were targeted with two zero-day exploits for iOS last year. Apple will patch the vulnerability underlying these attacks on an upcoming release of iOS 13. "We concluded with high confidence that it was exploited in the wild," Zuk Avraham, the founder of ZecOps, told Motherboard. "One of [the vulnerabilities] we clearly showed that it can be triggered remotely, the other one requires an additional vulnerability to trigger it remotely."

"These vulnerabilities," ZecOps researchers wrote in a report they published Wednesday, "are widely exploited in the wild in targeted attacks by an advanced threat operator(s) to target VIPs, executive management across multiple industries, individuals from Fortune 2000 companies, as well as smaller organizations such as MSSPs." One of the two vulnerabilities, according to Avraham, is what's known as a remote zero-click. This kind of attack is dangerous because it can be used by an attacker against anyone on the internet, and the target gets infected without any interaction -- hence the zero-click definition. Vulnerabilities or exploits called zero-days are bugs in software or hardware that are unknown to their manufacturers and can be used to hack targets. They can be particularly effective attacks because they use flaws that are not patched yet, meaning there's no code deployed to specifically defend against them.

Nintendo

Nintendo Accounts Are Getting Hacked and Used To Buy Fortnite Currency (zdnet.com) 23

Over the course of the last month, Nintendo users have been increasingly reporting that their accounts have been getting hacked and accessed from remote locations around the globe, with some users losing money as a result of the unauthorized intrusion. From a report: The account hijackings appear to have started mid-March and have reached a peak over the weekend when more and more users started receiving email alerts that unknown IP addresses have been seen accessing their Nintendo profiles. The way accounts are getting hacked is currently unknown. It is unclear if hackers are using passwords leaked in data breaches at other sites to also gain access to Nintendo accounts. Some users reported using complex passwords generated through a password manager, passwords that were unique to their accounts, and not used anywhere else. This suggests hackers might be using more than the classic credential stuffing, password spraying, or brute-force attacks. Nintendo has yet to release a formal statement about the attacks; however, the company has advised users earlier month on Twitter and Reddit to enable two-step verification (2SV) for their accounts, suggesting that this might prevent intrusions.
Security

You Can Now Check If Your ISP Uses Basic Security Measures (wired.com) 28

"Is BGP Safe Yet" is a new site that names and shames internet service providers that don't tend to their routing. From a report: For more than an hour at the beginning of April, major sites like Google and Facebook sputtered for large swaths of people. The culprit wasn't a hack or a bug. It was problems with the internet data routing standard known as the Border Gateway Protocol, which had allowed significant amounts of web traffic to take an unexpected detour through a Russian telecom. For Cloudflare CEO Matthew Prince, it was the last straw. BGP disruptions happen frequently, generally by accident. But BGP can also be hijacked for large-scale spying, data interception, or as a sort of denial of service attack.

[...] On Friday, the company launched Is BGP Safe Yetâ, a site that makes it easier for anyone to check whether their internet service provider has added the security protections and filters that can make BGP more stable. Those improvements are most effective with wide adoption from ISPs, content delivery networks like Cloudflare, and other cloud providers. Cloudflare estimates that so far about half of the internet is more protected thanks to heavy hitters like AT&T, the Swedish telecom Telia, and the Japanese telecom NTT adopting BGP improvements. And while Cloudflare says it doesn't seem like the Rostelecom incident was intentional or malicious, Russian telecoms do have a history of suspicious BGP meddling, and similar problems will keep cropping up until the whole industry is on board.

Security

Cognizant Confirms Maze Ransomware Attack, Says Customers Face Disruption (techcrunch.com) 9

Cognizant, one of the largest tech and consulting companies in the Fortune 500, has confirmed it was hit by a ransomware attack. From a report: Details remain slim besides a brief statement on its site, confirming the incident. "Cognizant can confirm that a security incident involving our internal systems, and causing service disruptions for some of our clients, is the result of a Maze ransomware attack," the statement read. "Our internal security teams, supplemented by leading cyber defense firms, are actively taking steps to contain this incident." The New Jersey-headquartered IT giant said it was engaging with the law enforcement.

The company, which offers a range of services including IT consultation to clients in more than 80 countries, posted $16.8 billion in revenue last year. The decades-old firm also maintains a business agreement with Facebook to help the social giant moderate content on its platform. Cognizant employs about 290,000 people, most of whom live in India. Maze is not like typical data-encrypting ransomware. Maze not only spreads across a network, infecting and encrypting every computer in its path, it also exfiltrates the data to the attackers' servers where it is held for ransom.

Security

Zoom's Security Woes Were No Secret to Business Partners Like Dropbox (nytimes.com) 33

Dropbox privately paid top hackers to find bugs in software by the videoconferencing company Zoom, then pressed it to fix them. From a report: One year ago, two Australian hackers found themselves on an eight-hour flight to Singapore to attend a live hacking competition sponsored by Dropbox. At 30,000 feet, with nothing but a slow internet connection, they decided to get a head start by hacking Zoom, a videoconferencing service that they knew was used by many Dropbox employees. The hackers soon uncovered a major security vulnerability in Zoom's software that could have allowed attackers to covertly control certain users' Mac computers. It was precisely the type of bug that security engineers at Dropbox had come to dread from Zoom, according to three former Dropbox engineers.

Now Zoom's videoconferencing service has become the preferred communications platform for hundreds of millions of people sheltering at home, and reports of its privacy and security troubles have proliferated. Zoom's defenders, including big-name Silicon Valley venture capitalists, say the onslaught of criticism is unfair. They argue that Zoom, originally designed for businesses, could not have anticipated a pandemic that would send legions of consumers flocking to its service in the span of a few weeks and using it for purposes -- like elementary school classes and family celebrations -- for which it was never intended.

[...] The former Dropbox engineers, however, say Zoom's current woes can be traced back two years or more, and they argue that the company's failure to overhaul its security practices back then put its business clients at risk. Dropbox grew so concerned that vulnerabilities in the videoconferencing system might compromise its own corporate security that the file-hosting giant took on the unusual step of policing Zoom's security practices itself, according to the former engineers, who spoke on the condition of anonymity because they were not authorized to publicly discuss their work. As part of a novel security assessment program for its vendors and partners, Dropbox in 2018 began privately offering rewards to top hackers to find holes in Zoom's software code and that of a few other companies. The former Dropbox engineers said they were stunned by the volume and severity of the security flaws that hackers discovered in Zoom's code -- and troubled by Zoom's slowness in fixing them.

Security

After 8 Years of Remote-Access Trojans Attacks, Can We Still Say Linux is Secure? (linuxsecurity.com) 139

Remember when BlackBerry reported Advanced Persistent Threat groups have been infiltrating critical Linux servers for at least eight years? What's the lesson to be learned?

LinuxSecurity Founder Dave Wreski argues "Although it may be easy to blame the rise in attacks targeting Linux in recent years on security vulnerabilities in the operating system as a whole, this is simply not the truth. The majority of exploits on Linux systems can be attributed to misconfigured servers and poor administration."

Writing for Linux Security, Slashdot reader b-dayyy gathered some additional responses: Some experts argue that it is the popularity of Linux that makes it a target. Joe McManus, Director of Security at Canonical, explains: "Linux and, particularly Ubuntu, are incredibly secure systems but, that being said, it is their popularity that makes them a target." Ian Thornton-Trump, a threat intelligence expert and the CISO at Cyjax, adds: "From an economic and mission perspective, it makes sense for a threat actor to invest in open-source skills for flexibility and the ability to target the systems where the good stuff is happening."

Despite the increasing number of threats targeting Linux systems, there is still a sound argument for the inherent security of Linux, which can be attributed to the core fundamentals of Open Source. Due to the transparency of open-source code and the constant scrutiny that this code undergoes by a vibrant global community, vulnerabilities are identified and remedied quicker than flaws that exist in the opaque source code of proprietary software and operating systems. Threat actors recognize this, and are still directing the majority of their attacks at proprietary operating systems.

These attacks do; however, serve as a much-needed wakeup call for the security community that more needs to be done to protect Linux servers. BlackBerry's report reveals that security solutions and defensive coverage available within Linux environments is "immature at best". Endpoint protection, detection and response products are inadequately utilized by too many Linux users, and endpoint solutions available for Linux systems are often insufficient in combating advanced exploits. Eric Cornelius, Chief Product Officer at BlackBerry, evaluates: "Security products and services that support Linux, offerings that might detect and give us insight into a threat like this, are relatively lacking compared to other operating systems, and security research about APT use of Linux malware is also relatively sparse."

Netscape

Silicon Valley Legends Launch 'Beyond Identity' To Eliminate All Passwords (securityweek.com) 143

SecurityWeek editor wiredmikey shares new that Jim Clark and Tom Jermoluk (past founders of Netscape, Silicon Graphics and @Home Network) "have launched a phone-resident personal certificate-based authentication and authorization solution that eliminates all passwords."

Security Week reports: The technology used is not new, being based on X.509 certificates and SSL (invented by Netscape some 25 years ago and still the bedrock of secure internet communications). It is the opportunity provided by the modern smartphone with biometric user access, enough memory and power, and a secure enclave to store the private keys of a self-certificate that never leaves the device that is new. The biometric access ties the phone to its user, and the Beyond Identity certificate authenticates the device/user to the service provider, whether that's a bank or a corporate network...

"When this technology was created at Netscape during the beginning of the World Wide Web, it was conceived as a mechanism for websites to securely communicate, but the tools didn't yet exist to extend the chain all the way to the end user," commented Jermoluk. "Beyond Identity includes the user in the same chain of certificates bound together with the secure encrypted transport (TLS) used by millions of websites in secure communications today...."

With no passwords, the primary cause of data breaches (either to steal passwords or by using stolen passwords) is gone. It removes all friction from the access process, takes the password reset load off the help desk, and can form the basis of a zero-trust model where identity is the perimeter.

Though they're first focusing on the corporate market, their solution should be available to consumers by the end of 2020, the article reports, which speculates that the possibility of pre-also installing the solution on devices "is not out of the question."
Piracy

The Pirate Bay Blocked By MalwareBytes But Normal Service Will Be Resumed (torrentfreak.com) 16

The Pirate Bay returned to the clear web this week after a month-long hiatus. However, the structure of the infamous torrent index presented an access problem to users of the popular anti-malware software MalwareBytes, which persistently blocked an essential element of the platform due to the presence of "a few" cryptocurrency miners on a secondary domain. TorrentFreak reports: The problem lay in The Pirate Bay's setup. Aside from cosmetic changes to some pages, the site sends requests to another domain (apibay.org) in order to present torrents to the user on thepiratebay.org. However, those accessing the main domain with Malwarebytes installed were greeted with blank torrent pages after the security software blocked apibay.org. Any warning of this type, especially concerning trojans, should be of concern to users of any site. However, dumping trojans on users hasn't been the modus operandi of The Pirate Bay thus far, so TorrentFreak contacted Malwarebytes to find out what was causing the alert.

Manager of WebProtection Labs at MalwareBytes Andres Ortiz informs TorrentFreak that the issue was caused by the presence of "a few" cryptocurrency miners, not on thepiratebay.org, but on a sub-directory of apibay.org, the domain from where TPB appears to present its torrent results. The analysis for just one example miner is shown [here]. After examining the apibay.org domain once again, MalwareBytes has now confirmed that the miners have been removed so in response, they will push an update to their users to stop TPB's indexes from being blocked moving forward. However, if any party reintroduces the miners, it's certainly possible that the site will be rendered inaccessible once again.

Security

DHS CISA: Companies Are Getting Hacked Even After Patching Pulse Secure VPNs (zdnet.com) 9

According to the DHS's Cybersecurity and Infrastructure Security Agency (CISA), companies that run Pulse Secure VPN servers are still at risk of getting hacked, despite patching vulnerable systems. ZDNet reports: Pulse Secure VPN servers are enterprise-grade VPN gateways that companies use to let workers connect to internal company networks from across the internet. Last year, a major vulnerability was disclosed in these products. The vulnerability, tracked as CVE-2019-11510, allowed hackers to run malicious code on vulnerable servers. [...] According to the [DHS CISA and Japan's Computer Emergency Response Team (JPCERT)], hackers have also been using access to the Pulse Secure VPN server to extract plaintext Active Directory (AD) credentials.

Now, JPCERT and CISA say they're seeing attacks where hackers are leveraging these stolen credentials to access internal networks even after companies patched Pulse Secure VPN gateways. In an alert published yesterday, CISA said it was aware of "incidents where compromised Active Directory credentials were used months after the victim organization patched their VPN appliance." The U.S. agency has released a tool on GitHub for companies that run Pulse Secure VPNs. The tool can be used to sift through their Pulse Secure logs and spot signs of a potential compromise. The tool scans for IP addresses and user-agents known to be associated with groups that have exploited Pulse Secure VPN servers.

Ruby

Clipboard Hijacking Malware Found in 725 Ruby Libraries (zdnet.com) 22

Security researchers from ReversingLabs say they've discovered 725 Ruby libraries uploaded on the official RubyGems repository that contained malware meant to hijack users' clipboards. From a report: The malicious packages were uploaded on RubyGems between February 16 and 25 by two accounts -- JimCarrey and PeterGibbons. The 725 libraries, which are listed here in full, have been removed two days later, on February 27, after the ReversingLabs team notified the RubyGems security team. All the Ruby libraries were copies of legitimate libraries, used lookalike names, worked as intended, but also contained additional malicious files. The extra file inserted into each package was named aaa.png. However, ReversingLabs say this file wasn't a PNG image, but instead was a Windows PE executable.
Android

The Secret Behind 'Unkillable' Android Backdoor Called xHelper Has Been Revealed (arstechnica.com) 40

An anonymous reader quotes a report from Ars Technica: In February, a researcher detailed a widely circulating Android backdoor that's so pernicious that it survives factory resets, a trait that makes the malware impossible to remove without taking unusual measures. The analysis found that the unusual persistence was the result of rogue folders containing a trojan installer, neither of which was removed by a reset. The trojan dropper would then reinstall the backdoor in the event of a reset. Despite those insights, the researcher still didn't know precisely how that happened. Now, a different researcher has filled in the missing pieces.

Last week, Kaspersky Lab researcher Igor Golovin published a post that filled in some of the gaps. The reinfections, he said, were the result of files that were downloaded and installed by a notorious trojan known as Triada, which ran once the xHelper app was installed. Triada roots the devices and then uses its powerful system rights to install a series of malicious files directly into the system partition. It does this by remounting the system partition in write mode. To make the files even more persistent, Triada gives them an immutable attribute, which prevents deleting, even by superusers. (Interestingly, the attribute can be deleted using the chattr command.) A file named install-recovery.sh makes calls to files added to the /system/xbin folder. That allows the malware to run each time the device is rebooted. The result is what Golovin described as an "unkillable" infection that has extraordinary control over a device.

Privacy

India Says Zoom 'Not a Safe Platform' For Video Conferencing (reuters.com) 49

India is the latest country to denounce videoconferencing software Zoom, calling it "not a safe platform." Reuters reports: "Zoom is a not a safe platform," the Cyber Coordination Centre (CyCord) of India's ministry of home affairs said in a 16-page advisory. The government body also provided guidelines on how to avoid unauthorized users from carrying out malicious acts while using the tool. Zoom's mobile app saw a sharp surge in downloads in India as the country enforced a nationwide lockdown late last month to curb the spread of the coronavirus. Even some Indian government officials have held discussions with industry executives to discuss coronavirus relief measures via Zoom. One media report this week said the Indian government was advising its ministers not to use third-party software for sensitive meetings.
IT

Pastebin Made It Harder To Scrape Its Site And Researchers Are Pissed Off (vice.com) 27

The most famous paste site, used by hackers of all stripes to host lists of stolen passwords, announcements of data breaches, and malware has made it harder for security researchers to scrape it looking for that kind of information. From a report: And security researchers are pissed off. Pastebin is one of the most famous websites that allows anyone, even without being registered, to "paste" any kind of text and make it public. Over the years, it became a repository for all kinds of unsavory data, such as the personal details of people who got doxed by hackers, leaked passwords, hacker manifestos, and even malware payloads. Naturally, this meant it was a treasure trove for security researchers investigating data breaches or hunting hackers. On Tuesday, several security researchers complained on Twitter that they were unable to search Pastebin or scrape it using a special API, which they paid to get access to. (The lifetime subscription, which was required to scrape the site, cost $50.)
AI

AI Spots Critical Microsoft Security Bugs 97% of the Time (venturebeat.com) 41

Microsoft claims to have developed a system that correctly distinguishes between security and non-security software bugs 99% of the time, and that accurately identifies the critical, high-priority security bugs on average 97% of the time. From a report: In the coming months, it plans to open-source the methodology on GitHub, along with example models and other resources. Their work suggests that such a system, which was trained on a data set of 13 million work items and bugs from 47,000 developers at Microsoft stored across AzureDevOps and GitHub repositories, could be used to support human experts. It's estimated that developers create 70 bugs per 1,000 lines of code and that fixing a bug takes 30 times longer than writing a line of code, and that in the U.S., $113 billion is spent annually on identifying and fixing product defects. In the course of architecting the model, Microsoft says that security experts approved the training data and that statistical sampling was used to provide those experts a manageable amount of data to review. The data was then encoded into representations called feature vectors and Microsoft researchers designed the system using a two-step process, in which the model first learned to classify security and non-security bugs and then to apply severity labels -- critical, important, low-impact -- to the security bugs.
Security

Linksys Asks Users To Reset Passwords After Hackers Hijacked Home Routers Last Month (zdnet.com) 28

Router vendor Linksys has locked user accounts on its Smart WiFi cloud service and is asking them to reset passwords after hackers have been observed hijacking accounts and changing router settings to redirect users to malware sites. From a report: Linksys' decision only impacts Smart WiFi accounts. Linksys Smart WiFi is a cloud-based account system that lets device owners connect to Linksys routers (and other equipment) over the internet to manage router settings. Smart WiFi is widely deployed across Linksys' router fleet, making it an ideal target for hackers who may want to hijack routers en-masse. According to a Bitdefender report published last month, this is exactly what's been recently happening. The cyber-security firm said it detected an organized campaign to break into D-Link and Linksys routers and change DNS settings.

Slashdot Top Deals