IT

India's Yes Bank Breakdown Disrupts Walmart's PhonePe Among Dozen Other Services (techcrunch.com) 18

Tens of millions of merchants and users in India are struggling to make online transactions and use several popular services after the nation's central bank seized control of Yes Bank, the fourth largest lender in the country. From a report: The emergency takeover of the private sector bank has taken off several financial startups that rely on it for facilitating services such as processing QR codes, point-of-sale terminals as well as transactions of UPI-based payments. Leading payments app PhonePe, owned by e-commerce giant Walmart, has been inaccessible to tens of millions of its users since Thursday evening (local time). The startup said in a statement that it was working to restore its services, and has solved some of the issues for its merchant partners. [...]

New Delhi took over Yes Bank midnight on Thursday, after the Reserve Bank of India said it had no alternative but to implement measures to replace the private sector firm's board and temporarily restrict withdrawals and suspend all other transactions for 30 days. Yes Bank has struggled for months to raise capital to improve its financials. According to NPCI, Yes Bank is the technology banking partner for ticketing platforms Cleartrip, MakeMyTrip, and RedBus, telecom operator Airtel, food-delivery startup Swiggy, movie ticketing business BookMyShow and PVR, Microsoft's chat service Kaizala, as well as several other Flipkart properties including the marquee service, fashion platforms Jabong, and Myntra.

Facebook

Facebook Sues Namecheap For Letting Scammers Register Lookalike Domains (zdnet.com) 87

Facebook filed a lawsuit this week against Namecheap, claiming the domain name registrar has refused to cooperate in an investigation into a series of malicious domains that have been registered through its service and which impersonated the Facebook brand. ZDNet reports: Christen Dubois, Director and Associate General Counsel at Facebook, said today that Facebook engineers tracked down 45 suspicious Facebook lookalike domains registered through Namecheap, which had the owners' details hidden through the company's WhoisGuard side-service. Some of the sample domains included the likes of instagrambusinesshelp.com, facebo0k-login.com, and whatsappdownload.site. Dubois said lookalike domains like these -- which abuse the Facebook brand -- are often used for phishing, fraud, and scams.

"We sent notices to Whoisguard between October 2018 and February 2020, and despite their obligation to provide information about these infringing domain names, they declined to cooperate," Dubois said. "We don't want people to be deceived by these web addresses, so we've taken legal action," the Facebook exec said.

Microsoft

Microsoft Releases PowerShell 7 for Windows, macOS and Linux (betanews.com) 88

Microsoft has announced that its cross-platform automation tool and configuration framework PowerShell 7 is now generally available. From a report: Available for Windows, macOS and Linux, PowerShell 7 sees Microsoft moving from .NET Core 2.x to 3.1 which enables greater backwards compatibility with existing Windows PowerShell modules thanks to the resurrection of numerous .NET Framework APIs. The cross-platform nature of PowerShell 7 means that Ubuntu, openSUSE, Fedora, Debian and other Linux distro are embraced. Joey Aiello, product manager of PowerShell, says: "If you weren't able to use PowerShell Core 6.x in the past because of module compatibility issues, this might be the first time you get to take advantage of some of the awesome features we already delivered since we started the Core project!"
Security

Defense Contractor CPI Knocked Offline by Ransomware Attack (techcrunch.com) 27

A major electronics manufacturer for defense and communications markets was knocked offline after a ransomware attack, TechCrunch reported Thursday. From the report: A source with knowledge of the incident told TechCrunch that the defense contractor paid a ransom of about $500,000 shortly after the incident in mid-January, but that the company was not yet fully operational. California-based Communications & Power Industries (CPI) makes components for military devices and equipment, like radar, missile seekers and electronic warfare technology. The company counts the U.S. Department of Defense and its advanced research unit DARPA as customers. The company confirmed the ransomware attack. "We are working with a third-party forensic investigation firm to investigate the incident. The investigation is ongoing," said CPI spokesperson Amanda Mogin. "We have worked with counsel to notify law enforcement and governmental authorities, as well as customers, in a timely manner."
Privacy

Live Facial Recognition Is Coming To US Police Body Cameras (medium.com) 50

Wolfcom, a company that makes technology for police, is pitching body cameras with live facial recognition to law enforcement groups across the United States, OneZero reported Thursday. From a report: It's a move that pushes against industry norms: Axon, the largest manufacturer of body cameras in the United States, declared last year that it would not put the invasive technology in its hardware, citing "serious ethical concerns." NEC, which sells live facial recognition elsewhere in the world, has also not sold it to U.S. law enforcement. Wolfcom claims to have sold body cameras to at least 1,500 police departments, universities, and federal organizations across the country. It has been developing live facial recognition for the Halo, Wolfcom's newest body camera model, according to documents and a video obtained by OneZero through public records requests. This new initiative makes Wolfcom the first major body camera provider in the United States to pursue live facial recognition, a controversial stance given a nationwide push from privacy advocates to ban the technology.
Intel

Intel CSME Bug Worse Than Previously Thought (zdnet.com) 68

Security researchers say that a bug in one of Intel's CPU technologies that was patched last year is actually much worse than previously thought. From a report: "Most Intel chipsets released in the last five years contain the vulnerability in question," said Positive Technologies in a report published today. Attacks are impossible to detect, and a firmware patch only partially fixes the problem. To protect devices that handle sensitive operations, researchers recommend replacing CPUs with versions that are not impacted by this bug. Only the latest Intel 10th generation chips are not vulnerable, researchers said. The actual vulnerability is tracked as CVE-2019-0090, and it impacts the Intel Converged Security and Management Engine (CSME), formerly called the Intel Management Engine BIOS Extension (Intel MEBx).
Android

Almost Half of Mobile Malware Are Hidden Apps (techrepublic.com) 27

Certain apps are hiding themselves and stealing resources and data from mobile devices, according to a new report by security firm McAfee. From a report: This is a growing threat comprising almost half of all malicious mobile malware, and a 30% increase from 2018, said Raj Samani, chief scientist and McAfee fellow, who authored the Q1 2020 McAfee Mobile Threat Report. "This shows where the focus from criminals [is] on the mobile platform, which is in stark contrast to non-mobile malware,'' Samani said. A new malware family called LeifAccess or Shopper is taking advantage of the accessibility features in Android to create accounts, download apps, and post reviews, according to the report. LeifAccess, "is a broad campaign [and] is using alternate methods to achieve installation but thereafter trying to achieve legitimacy to the user with fake warnings," Samani said. For example, LeifAccess does not create an icon or shortcut, "so it's not immediately obvious that the app is installed ... but for some of the hidden apps within the report, malicious mobile attacks will even masquerade as a legitimate app," he said.
IOS

Apple Now Lets Apps Send Ads in Push Notifications (theverge.com) 68

Apple will now allow push notifications to be used for advertising, so long as users agree to receive the ads first. From a report: Apple updated its App Store guidelines today with a change to its traditionally strict restrictions around push notifications. Apple has long banned apps from using notifications for "advertising, promotions, or direct marketing purposes," but that changes today. Apps can now send marketing notifications when "customers have explicitly opted in to receive them." Users must also be able to opt out of receiving the ads.
Security

Let's Encrypt Discovers CAA Bug, Must Revoke Customer Certificates (arstechnica.com) 66

rufey writes: The free SSL certificate provider Let's Encrypt is going to revoke 2.6% of the SSL certs issued by them that are currently active, due to a bug in boulder, the Certificate Authority Authorization (CAA) software Let's Encrypt uses. Ars Technica reports: "Let's Encrypt uses Certificate Authority software called Boulder. Typically, a Web server that services many separate domain names and uses Let's Encrypt to secure them receives a single LE certificate that covers all domain names used by the server rather than a separate cert for each individual domain. The bug LE discovered is that, rather than checking each domain name separately for valid CAA records authorizing that domain to be renewed by that server, Boulder would check a single one of the domains on that server n times (where n is the number of LE-serviced domains on that server). Let's Encrypt typically considers domain validation results good for 30 days from the time of validation -- but CAA records specifically must be checked no more than eight hours prior to certificate issuance. The upshot is that a 30-day window is presented in which certificates might be issued to a particular Web server by Let's Encrypt despite the presence of CAA records in DNS that would prohibit that issuance.

Since Let's Encrypt finds itself in the unenviable position of possibly having issued certificates that it should not have, it is revoking all current certificates that might not have had proper CAA record checking on Wednesday, March 4. Users whose certificates are scheduled to be revoked will need to manually force-renewal before then. If an admin does not perform this manual renewal step, browsers reaching their websites will show TLS security warnings due to the revoked certificates. Let's Encrypt certificates are issued for 90-day intervals, and Certbot automatically renews them only when 30 days or less are left on the cert -- so this could mean roughly two months of browser errors if the manual forced renewal isn't performed."

The CAB Forum, which oversees the public CAA space, has a ticket for this specific issue.
According to a community post on Let's Encrypt's website, 3,048,289 of the ~116 million overall active Let's Encrypt certificates are affected.
Businesses

Cisco: Avoid Coronavirus, Stay Home, Use Webex (arstechnica.com) 58

An anonymous reader quotes a report from Ars Technica: Networking giant Cisco is getting into the coronavirus monitoring and mitigation game with its Webex remote meeting property. The company notes that in the wake of mandates issued to employees to halt travel plans and/or work from home, traffic across its Webex backbone has increased significantly. Webex meeting traffic connecting Chinese users to global workplaces has increased by a factor of 22 since the outbreak began; traffic in other Asian countries is up by 400 percent or more, and free signup rates in impacted countries have increased 700 percent or more. In response, Cisco is offering temporarily unlimited usage (with no time restrictions) in all countries where the service is available (full list here), not just the ones worst hit by coronavirus. The company is also offering free 90-day licenses to businesses that are not currently Webex customers and offering free upgrades to customers whose current plan is insufficient to accommodate increased traffic due to the outbreak.

In the worst affected countries, telepresence and remote work software like Webex is currently the only alternative to a complete shutdown of activities. In its press release, Cisco highlights the Nesbitt Center, an organization working with disabled young adults in Hong Kong. All Hong Kong schools, including the Nesbitt Center, have been required to suspend day programs during the outbreak. Webex videoconferencing has allowed the Nesbitt Center to continue delivering educational sessions despite the lockdown.
Ars Technica also recommends Jitsi, a "free and open source software, offering video call and screen sharing capabilities." There's also Jitsi Meet for people "who just need to get something done on-the-fly with no setup at all."

Do you have a favorite remote work software?
China

Chinese Security Firm Says CIA Hacked Chinese Targets For the Past 11 Years (zdnet.com) 49

China's largest cyber-security vendor has published today a report accusing the CIA of hacking Chinese companies and government agencies for more than 11 years. From a report: The report, authored by Qihoo 360, claims the CIA hacked targets in China's aviation industry, scientific research institutions, petroleum industry, Internet companies, and government agencies. CIA hacking operations took place between September 2008 and June 2019, and most of the targets were located in Beijing, Guangdong, and Zhejiang, Qihoo researchers said. Qihoo claims that a large part of the CIA's hacking efforts focused on the civil aviation industry, both in China and in other countries. The Chinese security firm claims the purpose of this campaign was "long-term and targeted intelligence-gathering" for the purpose of tracking "real-time global flight status, passenger information, trade freight and other related information."
Businesses

Trading App Robinhood Experiencing 'Major Outage' For a Second Day Amid Heavy Volume Market Action (cnbc.com) 20

Robinhood on Tuesday reported technical issues for a second day following an outage that kept clients from trading on a historic market rally. From a report: As U.S. stocks traded actively again in wake of a surprise Fed rate cut, Robinhood reported a "major outage" for trading across its platform. Earlier updates on the site said that all trading was "operational," but Twitter users posted screenshots of error messages as U.S. markets opened Tuesday. "We are experiencing a system-wide outage," a message on Robinhood's website read. Technical issues began Monday morning and lasted throughout the trading day, leaving users with their hands tied as the Dow Jones Industrial Average's biggest one-day point gain in history. In a volatile session Tuesday, stocks surged off their lows after the Federal Reserve cut interest rates in an effort to stem slower economic growth from the coronavirus outbreak.
The Almighty Buck

Robinhood Glitch Steals From the Poor, Gives To the Rich (yahoo.com) 71

theodp writes: On its Careers page, zero-commission online broker Robinhood explains its founders "decided it was more important to build products that would provide everyone with access to the financial markets, not just the wealthy. Two years after heading to New York, they moved back to California and built Robinhood -- a company that leverages technology to encourage everyone to participate in our financial system." But on Monday, at least, the advantage went to the wealthy. Bloomberg reports that Robinhood suffered an outage that lasted the entire U.S. trading day and prevented customers from making trades as stocks surged after last week's rout (status). Just another reminder that we're all just one technology fail away from chaos.
Security

'Have I Been Pwned' Is No Longer For Sale 11

Troy Hunt, the owner and founder of the well-known and respected data breach notification website "Have I Been Pwned," announced in a blog post today that his website is no longer being sold and will continue running independently. The news comes several months after Hunt announced he was actively looking for a buyer.

Last June, Hunt wrote: "To date, every line of code, every configuration and every breached record has been handled by me alone. There is no 'HIBP team,' there's one guy keeping the whole thing afloat. It's time for HIBP to grow up. It's time to go from that one guy doing what he can in his available time to a better-resourced and better-funded structure that's able to do way more than what I ever could on my own."

Now, according to Hunt, "unexpected changes" with the business model of the party believed to be the purchaser of the service "made the deal infeasible." "It wasn't something I could have seen coming nor was it anything to do with HIBP itself, but it introduced a range of new and insurmountable barriers," writes Hunt in today's blog post. Hunt goes on to explain what's been happening since April 2019 and how the service will operate in the future.
Security

Microsoft To Retire MCSA, MCSD and MCSE Certifications (ghacks.net) 67

Microsoft will retire MCSA, MCSD and MCSE certifications on June 30, 2020, according to a new post by Alex Payne, GM, Global Technical Learning at Microsoft Worldwide Learning, on the Microsoft Learning Blog. twocows shares a report: Microsoft shifted its focus to role-based training and certifications in September 2018 and has added 34 different certifications since then to its portfolio "across Azure, Modern Workplace, and Business Applications". Since Microsoft is now focusing on role-based training and certifications, it will retire all remaining Microsoft Certified Solutions Associate (MCSA), Microsoft Certified Solutions Developer (MCSD) and Microsoft Certified Solutions Expert (MCSE) certifications on June 30, 2020.
Desktops (Apple)

Stealing Advanced Nations' Mac Malware Isn't Hard. Here's How One Hacker Did It (arstechnica.com) 19

Malware developers are always trying to outdo each other with creations that are stealthier and more advanced than their competitors'. At the RSA Security conference last week, a former hacker for the National Security Agency demonstrated an approach that's often more effective: stealing and then repurposing a rival's code. From a report: Patrick Wardle, who is now a security researcher at the macOS and iOS enterprise management firm Jamf, showed how reusing old Mac malware can be a smarter and less resource-intensive approach for deploying ransomware, remote access spy tools, and other types of malicious code. Where the approach really pays dividends, he said, is with the repurposing of advanced code written by government-sponsored hackers. "There are incredibly well-funded, well-resourced, very motivated hacker groups in three-letter agencies that are creating amazing malware that's fully featured and also fully tested," Wardle said during a talk titled "Repurposed Malware: A Dark Side of Recycling." "The idea is: why not let these groups in these agencies create malware and if you're a hacker just repurpose it for your own mission?" he said.

To prove the point, Wardle described how he altered four pieces of Mac malware that have been used in in-the-wild attacks over the past several years. The repurposing caused the malware to report to command servers belonging to Wardle rather than the servers designated by the developers. From there, Wardle had full control over the recycled malware. The feat allowed him to use well-developed and fully featured applications to install his own malicious payloads, obtain screenshots and other sensitive data from compromised Macs, and carry out other nefarious actions written into the malware.

Security

'How a Hacker's Mom Broke Into Prison -- and the Warden's Computer' (arstechnica.com) 25

An anonymous reader quotes Ars Technica: John Strand breaks into things for a living. As a penetration tester, he gets hired by organizations to attack their defenses, helping reveal weaknesses before actual bad guys find them. Normally, Strand embarks on these missions himself or deploys one of his experienced colleagues at Black Hills Information Security. But in July 2014, prepping for a pen test of a South Dakota correctional facility, he took a decidedly different tack. He sent his mom.

In fairness, it was Rita Strand's idea. Then 58, she had signed on as chief financial officer of Black Hills the previous year after three decades in the food service industry. She was confident, given that professional experience, that she could pose as a state health inspector to gain access to the prison. All it would take was a fake badge and the right patter. "She approached me one day and said 'You know, I want to break in somewhere," says Strand, who is sharing the experience this week at the RSA cybersecurity conference in San Francisco. "And it's my mom, so what am I supposed to say...?"

To help get her in the door, Black Hills made Rita a fake badge, a business card, and a "manager's" card with John's contact info on it. Assuming she got inside, she would then take photos of the facility's access points and physical security features. Rather than have her try to hack any computers herself, John equipped Rita with so-called Rubber Duckies, malicious USB sticks that she would plug into every device she could. The thumb drives would beacon back to her Black Hills colleagues and give them access to the prison's systems. Then they could work on the digital side of the pen test remotely while Rita continued her rampage.

It's a fascinating story, though Strand also points out that "Prison cybersecurity is crucial for obvious reasons.

"If someone could break into the prison and take over computer systems, it becomes really easy to take someone out of the prison."
Programming

Will The Next Job Impacted By Automation Be App Development? (forbes.com) 149

Leading CIOs, CTOs and technology executives on the "Forbes Technology Council" just made some predictions for the future: Now that the business world has seen the power of automation, the question has become, "What's next?" The members of Forbes Technology Council are constantly looking out for new tech trends, and they believe the next jobs to be impacted by automation might not be the ones people expect...

#1. Reminders, Notifications And Reporting
Christy Johnson, AchieveIt: I think as workflow technology expands, any kind of oversight-related job will be delegated to the bots. No human will be taking the time to manually build reports, see who they're missing data from and send those employees a reminder email/plea for a status update. The tech is already around, but I think it still has a long way to go to reach human-level logic and function....

#3. App Development

Katherine Kostereva, Creatio (formerly bpm'online): In the next five years, everyone will become a developer thanks to low-code/no-code technology. It allows users to build apps and processes in a visual integrated development environment with drag and drop features. Hand-coding isn't likely to become obsolete in five years, but we are moving towards a far future where little to no coding is involved in development.

United States

What Happened When Tulsa Paid People to Work Remotely (citylab.com) 70

Remember when Tulsa, Oklahoma offered $10,000 to remote workers who'd relocate to their city?

It was an immensely popular program. "You have better odds of getting into Harvard or Yale than you do of getting into the Tulsa Remote program," the city's mayor told CityLab: All of the Remoters get a free one-year membership to the coworking space, though others prefer to work at home, perhaps because for some of them, home is a luxury apartment building downtown where they receive subsidized rent — another part of their welcome package...

A year after Tulsa Remote launched, the first participants — a mix of expats from expensive coastal cities, wanderlusty young adults, and those with roots in the region — say they've found many of the things they were looking for: a more comfortable and affordable quality of life, new neighbors they like, enough of an economic cushion to ease the stress of buying new furniture, and a fresh start. Many say they'll stick around past the end of the one-year program. More than that: Some of them tell stories of positive personal transformation that are so dramatic, they might appear too perfect, almost canned. But after checking in with participants over the course of eight months, I found that many of them remained just as effusive. Maybe it's something about Tulsa. Or maybe it's something about Tulsa Remote...

One "Remoter," as they're called in the Tulsa program, is a Harlem Globetrotter. Another runs an online finance site, helping people maximize their credit points. Others work in education, and online marketing, and consulting, and media. Of the 100 participants who were originally selected, 70 accepted [program director] Bolzle's offer, and two left within a few months of arriving to the city...

At least 25 participants from the first Tulsa Remote cohort have purchased property in the city, Bolzle says. One bought a $700,000 house... The endgame of Tulsa Remote is that these residents will help build a flourishing new economic ecosystem in town; they'll start families and launch start-ups and tell their friends to come join them. There's a "multiplier effect" expected of a project like this, even if the workers aren't employed by Tulsa-based companies, said Pamela Loprest, a senior fellow and labor economist in the Income and Benefits Policy Center at the Urban Institute. "They'll create other jobs and [draw] other people into that area..."

Even a few participants who had initially told me they wanted to leave when the program ended have now changed their minds.

Other states are trying variations on the idea, including Vermont, northwest Alabama, and Topeka, Kansas. "It used to be that talent went where the jobs were," the program's executive director tells them, but "That's shifting." The article notes that new development downtown -- including a $465 million riverfront park -- "seems engineered to look like a Millennial playground. The problem, says Tulsa Mayor G.T. Bynum, is there just aren't enough people to play in it..."

"Now, the program's executive director says, it's the responsibility of cities to create a community that someone would want to call home, and make sure people know to move there..."
Security

Ghostcat Bug Impacts All Apache Tomcat Versions Released in the Last 13 Years (zdnet.com) 45

Apache Tomcat servers released in the last 13 years are vulnerable to a bug named Ghostcat that can allow hackers to take over unpatched systems. From a report: Discovered by Chinese cybersecurity firm Chaitin Tech, Ghostcat is a flaw in the Tomcat AJP protocol. AJP stands for Apache JServ Protocol and is a performance-optimized version of the HTTP protocol in binary format. Tomcat uses AJP to exchange data with nearby Apache HTTPD web servers or other Tomcat instances. Tomcat's AJP connector is enabled by default on all Tomcat servers and listens on the server's port 8009. Chaitin researchers say they discovered a bug in AJP that can be exploited to either read or write files to a Tomcat server.

Slashdot Top Deals