Privacy

Hackers Are Selling a Critical Zoom Zero-Day Exploit for $500,000 (vice.com) 38

Hackers are selling two critical vulnerabilities for the video conferencing software Zoom that would allow someone to hack users and spy on their calls, Motherboard reported Wednesday. From the report: The two flaws are so-called zero-days, and are currently present in Zoom's Windows and MacOS clients, according to three sources who are knowledgeable about the market for these kinds of hacks. The sources have not seen the actual code for these vulnerabilities, but have been contacted by brokers offering them for sale. Zero-day exploits or just zero-days or 0days are unknown vulnerabilities in software or hardware that hackers can take advantage of to hack targets. Depending on what software they're in, they can be sold for thousands or even millions of dollars.

Last week, Motherboard reported that there was an increased interest in zero-days for Zoom as millions of people, including employees and executives at big companies around the world, moved onto the platform for sensitive or confidential meetings, due to the coronavirus pandemic. "From what I've heard, there are two zero-day exploits in circulation for Zoom. [...] One affects OS X and the other Windows," said Adriel Desautels, the founder of Netragard, a company that used to sell and trade zero-days. "I don't expect that these will have a particularly long shelf-life because when a zero-day gets used it gets discovered."

Security

North Korea Hacking Threatens US and Global Financial System: US Officials (reuters.com) 87

U.S. government officials warned on Wednesday about the threat of North Korean hackers, calling particular attention to banking and other finance. From a report: The reason for the advisory -- which was jointly issued by the U.S. Departments of State, Treasury, and Homeland Security, and the Federal Bureau of Investigation -- was unclear. North Korean hackers have long been accused of targeting financial institutions, and the content of the warning appeared to draw on material already in the public domain. North Korea is alleged to be behind an ambitious, years-long campaign of digital theft, including siphoning tens of millions of dollars in cash from ATMs, carrying out gigantic thefts at major banks, extorting computer users worldwide, and hijacking digital currency exchanges. The global money-grab has been a topic of increasing international concern.
Google

Google Is Lowering Nest Camera Quality 'To Conserve Internet Resources' (techcrunch.com) 59

Google is temporarily lowering the video quality of its Nest security cameras to "conserve internet resources" during the COVID-19 pandemic. "The adjustment is rolling out over the next few days, and Google says anyone who has their quality settings adjusted will get a notification in the Nest app," reports TechCrunch. From the report: While Nest cameras aren't inherently using more bandwidth right now than they otherwise might, each camera already used a good amount of bandwidth day to day. A Nest Cam IQ, for example, uses roughly 400GB of data per month at its highest settings; cutting this down to medium high shaves that down to 300GB. Google confirmed their plans with TechCrunch, with a Google spokesperson adding: "To answer the global call to prioritize internet bandwidth for learning and working, in the next few days we're going to be making a few changes. We believe these changes have the potential to help make it easier for communities to keep up with school, work, and everything in between."

While they're automatically making the change on behalf of the user (a move some owners are complaining is an overstep), Google notes that you're able to bump your cameras back up to their highest settings should you see fit. They're not capping the quality, instead just lowering settings by default -- so if you've got a camera in a setting where every pixel counts, know that you're going to need to adjust accordingly.

The Internet

Over 500,000 Zoom Accounts Sold On Hacker Forums, the Dark Web (bleepingcomputer.com) 23

An anonymous reader quotes a report from Bleeping Computer: Over 500,000 Zoom accounts are being sold on the dark web and hacker forums for less than a penny each, and in some cases, given away for free. These credentials are gathered through credential stuffing attacks where threat actors attempt to login to Zoom using accounts leaked in older data breaches. The successful logins are then compiled into lists that are sold to other hackers. Some of these Zoom accounts are offered for free on hacker forums so that hackers can use them in zoom-bombing pranks and malicious activities. Others are sold for less than a penny each.

Cybersecurity intelligence firm Cyble told BleepingComputer that around April 1st, 2020, they began to see free Zoom accounts being posted on hacker forums to gain an increased reputation in the hacker community. These accounts are shared via text sharing sites where the threat actors are posting lists of email addresses and password combinations. The purchased accounts include a victim's email address, password, personal meeting URL, and their HostKey. Cyble has told BleepingComputer that these accounts include ones for well-known companies such as Chase, Citibank, educational institutions, and more.
You can use Have I Been Pwned and Cyble's AmIBreached to check if your email address has been leaked in a data breach.
Chrome

Google Removes 49 Chrome Extensions Caught Stealing Crypto-Wallet Keys (zdnet.com) 18

Google has removed 49 Chrome extensions from the Web Store that posed as legitimate cryptocurrency wallet apps but contained malicious code that stole crypto-wallet private keys, mnemonic phrases, and other raw secrets. From a report: The 49 extensions were discovered by Harry Denley, Director of Security at the MyCrypto platform, who shared his findings exclusively with ZDNet last week. Denley says the 49 extensions appear to have been put together by the same person/group, believed to be a Russian-based threat actor. "Whilst the extensions all function the same, the branding is different depending on the user they are targeting," Denley said. The MyCrypto security researcher says he has identified malicious extensions posing as known crypto-wallets apps such as Ledger, Trezor, Jaxx, Electrum, MyEtherWallet, MetaMask, Exodus, and KeepKey.
Security

Ransomware Scumbags Leak Boeing, Lockheed Martin, SpaceX Documents After Contractor Refuses To Pay (theregister.co.uk) 152

An anonymous reader quotes a report from The Register: Internal confidential documents belonging to some of the largest aerospace companies in the world have been stolen from an industrial contractor and leaked online. The data was pilfered and dumped on the internet by the criminals behind the DoppelPaymer Windows ransomware, in retaliation for an unpaid extortion demand. The sensitive documents include details of Lockheed-Martin-designed military equipment -- such as the specifications for an antenna in an anti-mortar defense system -- according to a Register source who alerted us to the blueprints. Other documents in the cache include billing and payment forms, supplier information, data analysis reports, and legal paperwork. There are also documents outlining SpaceX's manufacturing partner program.

The files were siphoned from Visser Precision by the DoppelPaymer crew, which infected the contractor's PCs and scrambled its files. When the company failed to pay the ransom by their March deadline, the gang -- which tends to demand hundreds of thousands to millions of dollars to restore encrypted files -- uploaded a selection of the documents to a website that remains online and publicly accessible. Visser is a manufacturing and design contractor in the U.S. whose clients are said to include aerospace, automotive, and industrial manufacturing outfits -- think Lockheed Martin, SpaceX, Tesla, Boeing, Honeywell, Blue Origin, Sikorsky, Joe Gibbs Racing, the University of Colorado, the Cardiff School of Engineering, and others. The leaked files relate to these customers, in particular Tesla, Lockheed Martin, Boeing, and SpaceX.

IT

Thousands of Techies in Locked-Down India Are Braving Coronavirus Daily To Keep the World Running (qz.com) 70

The world's abrupt slowing down in the past few weeks may have introduced millions of Covid-19-wary professionals to the whole new paradigm of work-from-home. Yet, a third of India's four million IT employees are still trudging regularly to the office even if mostly to make life easier for clients abroad. From a report: Every working day, these thousands risk contracting coronavirus, jeopardising even their families' health, by going to work amid India's ongoing 21-day lockdown. Only because their jobs, in cities like Bengaluru, Pune, and Hyderabad, form the backroom spine of some of the world's corporate behemoths. Indian IT majors like Tata Consultancy Services (TCS), Infosys, and Wipro service giants like General Electric, Citibank, Morgan Stanley, Fidelity, HSBC, Lloyds Banking Group, Airbus, Cisco, British Telecom, Vodafone, and Nielsen, among thousands of other companies across the globe.

"We power the financial backbones of several countries, support some of the largest health care and pharmacy companies in the world, run technology for governments and public services organisations," a TCS spokesperson told Quartz when asked about the lockdown. Besides, many global businesses also have essential functions -- accounting, payments, billing, human resources, and payroll -- being carried out in their own back offices in India.

Books

'Abolish Silicon Valley' Author Urges 'Expropriating' Platforms, Making them Open-Source Public Services (siliconvalley.com) 250

The Bay Area Newsgroup just interviewed the author of "Abolish Silicon Valley: How to liberate technology from capitalism". Q: How do you fix this broken system?

A: Overall the goal that I'm thinking about is that you have the private sector so overfunded and glorified that it seems like the only way to do things, but things could be much better serviced by the public sector without the profit motive that the private sector demands. Reclaim the wealth from capital, push back capital and fund public innovation... Right now the way it works is all these tech companies are predicated on a very particular way of regulating work and will hire people short-time and pay them nothing and not provide them with safety nets.

There are also companies that shouldn't necessarily exist. A lot of companies are being funded to do something the public sector could've provided. Instead of good public transit, we have Uber. Instead of a good social mobility system, we get paid scooters. What people want is to streamline a centralized system that is run in a way that is accountable and actually serves the public...

My Utopian view is to put tech companies in full public view. Expropriate platforms and turn them into municipal services, public services and make them open-source.

Social Networks

Turkey To Require Social Media Giants To Appoint Local Representatives (reuters.com) 49

Turkey will require foreign social media companies with high internet traffic to appoint a representative in the country to address concerns raised by authorities over content on their platforms, a draft law seen by Reuters showed. From the report: Companies that do not comply with the new measure could face having their bandwith halved after 30 days by court order, and then slashed by 95% if they hold out another 30 days, it said. The law will apply to social media networks accessed by more than 1 million people daily from Turkey, the draft law said. Ankara strictly polices social media content, especially during periods such as military operations and the current coronavirus pandemic. In the three weeks to April 6, more than 3,500 social media accounts were reviewed, 616 suspects were identified and 229 were detained for "provocative" social media posts, according to the Interior Ministry.
China

China Telecom Should Be Barred in US as Threat, Agencies Say (bloomberg.com) 33

A group of U.S. security agencies is urging the Federal Communications Commission to revoke China Telecom's permission to operate in the United States. From a report: "This recommendation reflects the substantial and unacceptable national security and law enforcement risks" associated with China Telecom's access to the U.S. telecommunications network, the agencies said in a filing at the FCC. The U.S. and China are at odds over a suite of issues such as the spread of the novel coronavirus, trade, and security of telecommunications networks. U.S. officials have moved to bar Chinese gear maker Huawei Technologies as a security threat, a assertion the company denies.

Thursday's recommendation to revoke an authorization held by China Telecom since 2007 is part of a review announced last year by the FCC, as the agency barred China Mobile Ltd. from the U.S. market. The FCC usually follows recommendations from security agencies. "The threat from China Telecom is a reflection of the threat that we see from Chinese telecommunications companies generally," said John Demers, assistant attorney general for national security. "They are beholden to the government of China both by law and in fact to do its bidding."

Encryption

Signal Threatens To Dump US Market If EARN IT Act Passes (pcmag.com) 82

Signal is warning that an anti-encryption bill circulating in Congress could force the private messaging app to pull out of the U.S. market. PC Magazine reports: Since the start of the coronavirus pandemic, the free app, which offers end-to-end encryption, has seen a surge in traffic. But on Wednesday, the nonprofit behind the app published a blog post, raising the alarm around the EARN IT Act. "At a time when more people than ever are benefiting from these (encryption) protections, the EARN IT bill proposed by the Senate Judiciary Committee threatens to put them at risk," Signal developer Joshua Lund wrote in the post. Although the goal of the legislation, which has bipartisan support, is to stamp out online child exploitation, it does so by letting the U..S government regulate how internet companies should combat the problem -- even if it means undermining the end-to-end encryption protecting your messages from snoops.

If the companies fail to do so, they risk losing legal immunity under Section 230 of the Communications Decency Act, which can shield them from lawsuits concerning objectionable or illegal content posted on their websites or apps. "Some large tech behemoths could hypothetically shoulder the enormous financial burden of handling hundreds of new lawsuits if they suddenly became responsible for the random things their users say, but it would not be possible for a small nonprofit like Signal to continue to operate within the United States," Lund wrote in the blog post.

IOS

Fleeceware Apps Discovered on the iOS App Store (zdnet.com) 28

More than 3.5 million iOS users have installed "fleeceware" apps on their devices, UK security firm Sophos warned in a report published earlier this week. From a report: The term fleeceware is a new addition to the cyber-security jargon and describes apps engaging in a new form of online fraud. Coined last year by Sophos researchers, the term refers to mobile apps that abuse legal loopholes in the app trial mechanism on Android -- and now iOS. Both the Google and Apple app stores allow app makers to create trial periods for commercial/paid/subscription apps. Users can install these apps and sign-up for a trial by giving the app permission to incur a charge on the user's Play Store or App Store account. Once the trial period ends, the user is charged automatically on their card and allowed to use the app.
IOS

Apple is Developing 'Clips' Feature For Using Apps Without Requiring Full Downloads (9to5mac.com) 32

Apple is working on a new way to offer specific parts of third-party apps across the system without needing to have them installed, 9to5Mac has learned based on an early build of iOS 14. From a report: The feature would allow users to experience parts of an app's functionality by scanning a QR Code. If you open a link or scan a QR code today from an app that you haven't installed on your iPhone or iPad, it will open that link in Safari. Apps can provide universal links, which open the app instead of Safari when the app is installed. But that could change in the near future with a new API internally referred to as "Clips" found on iOS 14 code. As 9to5Mac has analyzed this new API, we can say that it allows developers to offer interactive and dynamic content from their apps even if you haven't installed them. The Clips API is directly related to the QR Code reader in the build we have access to, so the user can scan a code linked to an app and then interact with it directly from a card that will appear on the screen.
The Internet

Cloudflare Dumps reCAPTCHA as Google Intends To Charge For Its Use (zdnet.com) 81

Internet web infrastructure company Cloudflare announced plans to drop support for Google's reCAPTCHA service and move to a new bot detection provider named hCaptcha. From a report: Cloudflare co-founder and CEO Matthew Prince said the move was motivated by Google's future plans to charge for the use of the reCAPTCHA service, which would have "added millions of dollars in annual costs" for his company, costs that Cloudflare would have undoubtedly had to unload on its customers. "That is entirely within their right," Prince said yesterday. "Cloudflare, given our volume, no doubt imposed significant costs on the reCAPTCHA service, even for Google." "If the value of the image classification training did not exceed those costs, it makes perfect sense for Google to ask for payment for the service they provide," he added.
China

Chinese Cybercriminals Target High-Value Linux Servers With Weak Defenses: BlackBerry (techrepublic.com) 41

Linux malware is real and Advanced Persistent Threat (APT) groups have been infiltrating critical servers with these tools for at least eight years, according to a new report from BlackBerry. From a report: In "Decade of the RATs: Cross-Platform APT Espionage Attacks Targeting Linux, Windows and Android," security researchers found that these groups have attacked companies around the world and across all industries with goals ranging from simple cybercrime to full-blown economic espionage. The RATs report describes how five APT groups are working with the Chinese government and the remote access trojans (RATs) the cybercriminals are using to get and maintain access to Linux servers.

According to the report, the groups appeared to be using WINNTI-style tooling to take aim at Linux servers and remain relatively undetected for almost a decade. These groups are targeting Red Hat Enterprise, CentOS, and Ubuntu Linux environments for espionage and intellectual property theft. The APT groups examined include the original WINNTI GROUP, PASSCV, BRONZE UNION, CASPER (LEAD), and a newly identified group BlackBerry researchers are tracking as WLNXSPLINTER. The BlackBerry researchers think all five groups are working together, given the distinct similarities in their preferred tools, tactics, and procedures.

Bug

Soil Gets Its Smell From Bacteria Trying To Attract Invertebrates (newscientist.com) 11

"Soil gets its characteristic earthy smell from certain chemicals produced primarily by soil-dwelling bacteria called Streptomyces," reports New Scientist. But as for why these bacteria produce these odors, researchers at the Swedish University of Agriculture Science in Alnarp discovered that the smell seems to attract invertebrates that help the bacteria disperse their spores. From the report: Paul Becher at the Swedish University of Agricultural Sciences in Alnarp and his colleagues set up field traps in woodland containing colonies of Streptomyces. They thought that the smell may act as a signal to other organisms that they are poisonous, because some bacteria like Streptomyces can be toxic. Instead, the smell -- which comes from gases released by Streptomyces, including geosmin and 2-methylisoborneol (2-MIB) -- seems to attract invertebrates that help the bacteria disperse their spores. Becher and his team found that springtails -- tiny cousins of insects -- that feed on Streptomyces were drawn to the traps containing the bacterial colonies, but weren't drawn to control traps that didn't contain Streptomyces. By comparison, insects and arachnids weren't attracted to the traps containing Streptomyces. The findings have been reported in the journal Nature Microbiology.
The Courts

Zoom Accused of Misrepresenting Security Measures In New Lawsuit (gizmodo.com) 22

Video conferencing company Zoom is being used by a shareholder over allegations of fraud and overstating the security protocols in place on its service. Gizmodo reports: In the lawsuit filed Tuesday in the U.S. District Court for the Northern District of California, plaintiff Michael Drieu -- on behalf of individuals who purchased Zoom securities after the company went public last year -- accuses the company of making "materially false and misleading statements" about its product and failing to disclose key information about the service. Namely, the suit cites Zoom as claiming that its product supported end-to-end encryption, when in fact it supports a different form of encryption called transport encryption -- as the Intercept reported last month -- that still allows Zoom to access data.

Additionally, the suit alleges that Zoom's security failures put users "eat an increased risk of having their personal information accessed by unauthorized parties, including Facebook," that these facts would necessarily result in a decline in users, and that the company's responses to ongoing reporting on myriad problems on the service were "misleading at all relevant times." The suit states that the fallout from these incidents was exacerbated by the covid-19 crisis, during which time users of the service jumped from just 10 million to 200 million in a matter of months as schools and organizations turned to Zoom amid social distancing measures and shelter-in-place orders. The suit cites documentation related to Zoom's IPO as evidence that the company misrepresented the security protocols in place for protecting users. Specifically, the suit states, Zoom said it offered "robust security capabilities, including end-to-end encryption, secure login, administrative controls and role-based access controls," and -- in what was clearly an embarrassing claim by the company -- that it strives "to live up to the trust our customers place in us by delivering a communications solution that "just works.'"

Security

Attackers Can Bypass Fingerprint Authentication With an 80 Percent Success Rate (arstechnica.com) 47

An anonymous reader quotes a report from Ars Technica: A study published on Wednesday by Cisco's Talos security group makes clear that the alternative isn't suitable for everyone -- namely those who may be targeted by nation-sponsored hackers or other skilled, well-financed, and determined attack groups. The researchers spent about $2,000 over several months testing fingerprint authentication offered by Apple, Microsoft, Samsung, Huawei, and three lock makers. The result: on average, fake fingerprints were able to bypass sensors at least once roughly 80 percent of the time.

The percentages are based on 20 attempts for each device with the best fake fingerprint the researchers were able to create. While Apple Apple products limit users to five attempts before asking for the PIN or password, the researchers subjected the devices to 20 attempts (that is, multiple groups of from one or more attempts). Of the 20 attempts, 17 were successful. Other products tested permitted significantly more or even an unlimited number of unsuccessful tries. Tuesday's report was quick to point out that the results required several months of painstaking work, with more than 50 fingerprint molds created before getting one to work. The study also noted that the demands of the attack -- which involved obtaining a clean image of a target's fingerprint and then getting physical access to the target's device -- meant that only the most determined and capable adversaries would succeed.
The most susceptible devices were the AICase padlock and Huawei's Honor 7x and Samsung's Note 9 Android phones, "all of which were bypassed 100 percent of the time," the report says. "Fingerprint authentication in the iPhone 8, MacBook Pro 2018, and the Samsung S10 came next, where the success rate was more than 90 percent. Five laptop models running Windows 10 and two USB drives -- the Verbatim Fingerprint Secure and the Lexar Jumpdrive F35 -- performed the best, with researchers achieving a 0-percent success rate."
Google

Google Told Its Workers That They Can't Use Zoom On Their Laptops Anymore (buzzfeednews.com) 25

BuzzFeed News has learned that Google has banned the popular videoconferencing software Zoom from its employees' devices. From the report: Zoom, a competitor to Google's own Meet app, has seen an explosion of people using it to work and socialize from home and has become a cultural touchstone during the coronavirus pandemic. Last week, Google sent an email to employees whose work laptops had the Zoom app installed that cited its "security vulnerabilities" and warned that the videoconferencing software on employee laptops would stop working starting this week.

"We have long had a policy of not allowing employees to use unapproved apps for work that are outside of our corporate network," Jose Castaneda, a Google spokesperson, told BuzzFeed News. "Recently, our security team informed employees using Zoom Desktop Client that it will no longer run on corporate computers as it does not meet our security standards for apps used by our employees. Employees who have been using Zoom to stay in touch with family and friends can continue to do so through a web browser or via mobile.â
Earlier this month, Elon Musk's SpaceX also banned employees from Zoom, citing "significant privacy and security concerns." And on Monday, New York City's Department of Education urged schools to abandon Zoom and switch to a service from Microsoft.
Security

Tails, the Security-Focused OS, Adds Support For Secure Boot (zdnet.com) 20

Tail OS, an operating system optimized for privacy and anonymity, has released version 4.5 this week, the first version that supports a crucial security feature named UEFI Secure Boot. From a report: Secure Boot works by using cryptographic signatures to verify that firmware files loaded during a computer's boot-up process are authentic and have not been tampered. If any of the firmware checks fail, Secure Boot has the authority to stop the boot process, preventing the operating system from launching. The feature has been available as part of the UEFI specification for almost two decades but is rarely used. The reason is because not all firmware vendors cryptographically sign their files, leaving the door open to verification errors that -- when Secure Boot is enabled -- block many operation systems from launching.

Slashdot Top Deals