Government

US Defense Agency That Secures Trump's Communications Confirms Data Breach (forbes.com) 66

An anonymous reader quotes a report from Forbes: The Department of Defense agency responsible for securing the communications of President Trump has suffered a data breach. Here's what is known so far. The U.S. Defense Information Systems Agency (DISA) describes itself as a combat support agency of the Department of Defense (DoD) and is tasked with the responsibility for supporting secure White House communications, including those of President Trump. As well as overseeing Trump's secure calls technology, DISA also establishes and supports communications networks in combat zones and takes care of military cyber-security issues. It has also confirmed a data breach of its network, which exposed data affecting as many as 200,000 users.

First picked up by Reuters, disclosure letters dated February 11 have been sent out to those whose personal data may have been compromised. Although it is not clear which specific servers have been breached, nor the nature of the users to whom the letters have been sent, that an agency with a vision to "connect and protect the war-fighter in cyberspace" should suffer such an incident is concerning, to say the least. While many of the details surrounding this breach are likely to remain, understandably, confidential, given the nature of the DISA work, the letter itself has already been published on Twitter by one recipient. Signed by Roger S. Greenwell, the chief information officer at DISA, the letter revealed the breach took place between May and July last year, and information including social security numbers may have been compromised as a result. It also stated that there is no evidence that any personally identifiable information (PII) has been misused as a result. The letter does, however, confirm that DISA will be offering free credit monitoring services to those who want it.

Security

Slickwraps Data Breach Exposing Financial and Customer Info (droid-life.com) 5

Slickwraps, a mobile device case retailer, has suffered a major data breach exposing employee resumes, personal customer information, API credentials, and more. Bleeping Computer reports: In a post to Medium, a security researcher named Lynx states that in January 2020 he was able to gain full access to the Slickwraps web site using a path traversal vulnerability in an upload script used for case customizations. Using this access, Lynx stated that they were allegedly able to gain access to the resumes of employees, 9GB of personal customer photos, ZenDesk ticketing system, API credentials, and personal customer information such as hashed passwords, addresses, email addresses, phone numbers, and transactions.

After trying to report these breaches to Slickwraps, Lynx stated they were blocked multiple times even when stating they did not want a bounty, but rather for Slickwraps to disclose the data breach. "They had no interest in accepting security advice from me. They simply blocked and ignored me," Lynx stated in the Medium post. This post has since been taken down by Medium, but is still available via archive.org. Since posting his Medium post, Lynx told BleepingComputer that another unauthorized user sent an email to 377,428 customers using Slickwraps' ZenDesk help desk system. These emails begin with "If you're reading this it's too late, we have your data" and then link to the Lynx's Medium post. [...] In a statement posted to their Twitter account, Slickwraps CEO Jonathan Endicott has apologized for the data breach and promises to do better in the future. In the statement, though, Endicott says they first learned about this today, February 21st, while Lynx stated and showed screenshots of attempts to contact both Endicott via email and Slickwraps on Twitter prior to today.

IT

FBI Recommends Passphrases Over Password Complexity (zdnet.com) 93

An anonymous reader shares a report: For more than a decade now, security experts have had discussions about what's the best way of choosing passwords for online accounts. There's one camp that argues for password complexity by adding numbers, uppercase letters, and special characters, and then there's the other camp, arguing for password length by making passwords longer. This week, in its weekly tech advice column known as Tech Tuesday, the FBI Portland office leaned on the side of longer passwords. "Instead of using a short, complex password that is hard to remember, consider using a longer passphrase," the FBI said. "This involves combining multiple words into a long string of at least 15 characters," it added. "The extra length of a passphrase makes it harder to crack while also making it easier for you to remember."
Android

Google To Put a Muzzle on Android Apps Accessing Location Data in the Background (zdnet.com) 41

Google has announced this week plans to crack down on Android apps that abuse the OS permissions system and request access to user geo-location data when the app is not in use. From a report: Starting with May, the OS maker plans to show warnings in the Play Store backend to all Android app developers about the need to update their apps. Going forward, Android apps will have to request access to location data based on the way they need this information. Google plans to review each app on a case-by-case basis and remove apps from the Play Store if they request access to location data and that's not immediately used inside the app. Google plans to review its own apps as well, the company said in a blog post this week. The goal of this major rule change is to crack down on apps that may be secretly harvesting location data while they are not in use. This type of data is called "background location data" and most app makers often sell it to analytics firms and online advertisers.
Chrome

Chrome Deploys Deep-Linking Tech in Latest Browser Build Despite Privacy Concerns (theregister.co.uk) 40

Google has implemented a browser capability in Chrome called ScrollToTextFragment that enables deep links to web documents, but it has done so despite unresolved privacy concerns and lack of support from other browser makers. From a report: Via Twitter on Tuesday, Peter Snyder, privacy researcher at privacy-focused browser maker Brave Software, observed that ScrollToTextFragment shipped earlier this month in Chrome 80 unflagged, meaning it's active, despite privacy issues that have been raised. "Imposing privacy and security leaks to existing sites (many of which will never be updated) REALLY should be a 'don't break the web,' never-cross redline," he wrote. "This spec does that." The debate over the feature percolated last year on mailing lists and in GitHub issues posts and picked up in October when the team working on Chrome's Blink engine declared their intent to implement the specification. The feature rollout serves to illustrate that the consensus-based web standards process doesn't do much to constrain the technology Google deploys.
Businesses

A Group of Ex-NSA and Amazon Engineers Are Building a 'GitHub For Data' (techcrunch.com) 21

A group of engineers and developers with backgrounds from the National Security Agency, Google, and Amazon Web Services are working on Gretel, an early-stage startup that aims to help developers safely share and collaborate with sensitive data in real time. TechCrunch reports: It's not as niche of a problem as you might think, said Alex Watson, one of the co-founders. Developers can face this problem at any company, he said. Often, developers don't need full access to a bank of user data -- they just need a portion or a sample to work with. In many cases, developers could suffice with data that looks like real user data. "It starts with making data safe to share," Watson said. "There's all these really cool use cases that people have been able to do with data." He said companies like GitHub, a widely used source code sharing platform, helped to make source code accessible and collaboration easy. "But there's no GitHub equivalent for data," he said.

And that's how Watson and his co-founders, John Myers, Ali Golshan and Laszlo Bock came up with Gretel. "We're building right now software that enables developers to automatically check out an anonymized version of the data set," said Watson. This so-called "synthetic data" is essentially artificial data that looks and works just like regular sensitive user data. Gretel uses machine learning to categorize the data -- like names, addresses and other customer identifiers -- and classify as many labels to the data as possible. Once that data is labeled, it can be applied access policies. Then, the platform applies differential privacy -- a technique used to anonymize vast amounts of data -- so that it's no longer tied to customer information. "It's an entirely fake data set that was generated by machine learning," said Watson.
The startup has already raised $3.5 million in seed funding. "Gretel said it will charge customers based on consumption -- a similar structure to how Amazon prices access to its cloud computing services," adds TechCrunch.
Security

Microsoft To Bring Its Defender Antivirus Software To iOS and Android (cnet.com) 35

Microsoft said today it plans to bring its antivirus software, Defender Advanced Threat Protection, to phones and other devices running Apple's iOS and Google's Android. From a report: The software, also called Defender ATP, is already available on Windows and MacOS. It offers features like preventive protection, post-breach detection and automated investigation and response, according to Microsoft. When it comes to mobile devices, Microsoft's Rob Lefferts said that the Defender software could help companies protect employees from things like malware and phishing attacks. Apple's and Google's app stores are "pretty safe," Lefferts said, but "malware does happen on those platforms."
Microsoft

Microsoft Has a Subdomain Hijacking Problem (zdnet.com) 24

A security researcher has pointed out that Microsoft has a problem in managing its thousands of subdomains, many of which can be hijacked and used for attacks against users, its employees, or for showing spammy content. From a report: The issue has been brought up this week by Michel Gaschet, a security researcher and a developer for NIC.gp. In an interview with ZDNet, Gaschet said that during the past three years, he's been reporting subdomains with misconfigured DNS records to Microsoft, but the company has either ignored those reports or silently secured some subdomains, but not all. Gaschet says he reported 21 msn.com subdomains that were vulnerable to hijacks to Microsoft in 2017, and then another 142 misconfigured microsoft.com subdomains in 2019. Further, the researcher also privately shared with ZDNet another list of 117 microsoft.com subdomains that he also reported to Microsoft last year.
Firefox

Mozilla's Standalone Firefox VPN is Now Available in Beta (cnet.com) 19

Mozilla has a new virtual private network service and if you have a Chromebook, a Windows 10 computer or an Android device in the US, you can start using a beta version now. From a report: Called Firefox Private Network, the new service is designed to function as a full-device VPN and give better protection when surfing the web or when using public Wi-Fi networks. The company offers two options: a free browser-extension version, which it launched in beta last year, that provides 12 one-hour VPN passes when using the Firefox browser and a Firefox account; and a second, $4.99-a-month option that provides a more complete VPN service across your whole device. The new paid option, which runs off of servers provided by Swedish open-source VPN company Mullvad, can protect up to five devices with one account. It allows for faster browsing and streaming, and gives you the ability to tap into servers located in "30-plus countries" for masking your location data.
Microsoft

Microsoft's Office App That Replaces Word, Excel, and PowerPoint Hits General Availability (venturebeat.com) 41

Microsoft today launched Office for Android and iOS in general availability. The unified app means you no longer need to download, install, and switch between the individual Word, Excel, and PowerPoint apps. From a report: The company today also announced new features coming to the app this spring: Word Dictation, Excel Cards View, and Outline to PowerPoint. You can use Office for free, and if you sign in with a Microsoft Account or connect a third-party storage service you can access and store documents in the cloud. Microsoft has over 200 million monthly active Office 365 business users and over 37 million Office 365 consumer subscribers. When the company launched the new Office mobile app as a public preview in November, "tens of thousands of people" rushed to try it. Microsoft has found that most users and businesses want to use the Office app as a hub or starting point for all their document work.
Medicine

Almost Half of Connected Medical Devices Are Vulnerable To Hackers Exploiting BlueKeep (zdnet.com) 67

An anonymous reader quotes a report from ZDNet: Connected medical devices are twice as likely to be vulnerable to the BlueKeep exploit than other devices on hospital networks, putting patients and staff at additional risk from cyber attacks. This is especially concerning when healthcare is already such a popular target for hacking campaigns. BlueKeep is a vulnerability in Microsoft's Remote Desktop Protocol (RDP) service which was discovered last year, and impacts Windows 7, Windows Server 2008 R2 and Windows Server 2008.

According to figures in a new report from researchers at healthcare cybersecurity company CyberMDX, 22% of all Windows devices in a typical hospital are exposed to BlueKeep because they haven't received the relevant patches. And when it comes to connected medical devices running on Windows, the figure rises to 45% -- meaning almost half are vulnerable. Connected devices on hospital networks can include radiology equipment, monitors, x-ray and ultrasound devices, anesthesia machines and more. If these devices aren't patched, it's possible that destructive cyber attacks searching for machines vulnerable to BlueKeep could put hospital networks -- and patients -- at risk.
"One of the key problems for hospitals is that many devices are classed as obsolete: Windows 7, for example, is vulnerable to BlueKeep and no longer supported by Microsoft, but remains common across hospital networks," adds ZDNet. "Any further vulnerabilities uncovered in Windows 7 -- and other out-of-support operating systems -- aren't guaranteed security patches, leaving networks potentially at further risk going forward."
Businesses

Dell Sells RSA To Symphony Technology Group Consortium For $2.075 Billion (zdnet.com) 17

Dell said it will sell RSA to a consortium led by Symphony Technology Group for $2.075 billion in a move to simplify its portfolio of businesses. From a report: RSA provides security technologies for threat detection and response, identity and access management as well as fraud prevention. RSA has more than 12,500 customers. According to Dell, the all-cash deal includes RSA Archer, RSA NetWitness Platform, RSA SecureID, RSA Fraud and Risk Intelligence and the RSA Conference. The Symphony Technology Group consortium includes the Ontario Teachers' Pension Plan Board (Ontario Teachers') and AlpInvest Partners (AlpInvest). Dell's deal to sell RSA comes as Broadcom acquired Symantec Enterprise Security business for $10.7 billion and Symantec's consumer unit became NortonLifelock. McAfee, formerly part of Intel, is now independent with a new CEO.
Security

Five Years After the Equation Group HDD Hacks, Firmware Security Still Sucks (zdnet.com) 49

In a report published today, Eclypsium, a cyber-security firm specialized in firmware security, says that the issue of unsigned firmware is still a widespread problem among device and peripheral manufactures. From a report: According to researchers, many device makers still don't sign the firmware they ship for their components. Furthermore, even if they sign a device's firmware, they don't enforce checks for the firmware signature every time the driver/firmware is loaded, but only during installation. Researchers say this leaves the door open for malicious actors to tamper with local firmware after it's been installed in order to plant persistent and nearly invisible malware on user devices. To prove their point, in their report, the Eclypsium team disclosed vulnerabilities in four types of peripheral firmware -- for touchpads/trackpads, cameras, WiFi adapters, and USB hubs. "Apple performs signature verification on all files in a driver package, including firmware, each time before they are loaded into the device, to mitigate this type of attack," the Eclypsium team said. "In contrast, Windows and Linux only perform this type of verification when the package is initially installed." But while some might be quick to blame the operating systems for not enforcing a stricter firmware signing practice, the Eclypsium team is not on this boat.
Security

Israeli Soldiers Tricked Into Installing Malware By Hamas Agents Posing As Women (zdnet.com) 24

An anonymous reader quotes a report from ZDNet: Members of the Hamas Palestinian militant group have posed as young teenage girls to lure Israeli soldiers into installing malware-infected apps on their phones, a spokesperson for the Israeli Defence Force (IDF) said today. Some soldiers fell for the scam, but IDF said they detected the infections, tracked down the malware, and then took down Hamas' hacking infrastructure. IDF said Hamas operatives created Facebook, Instagram, and Telegram accounts and then approached IDF soldiers. According to IDF spokesperson Brigadier General Hild Silberman, Hamas agents posed as new Israeli immigrants in order to excuse their lacking knowledge of the Hebrew language.

Gen. Silberman said the apps would give the impression they can't run on soldiers' phones by showing a crash message. The apps would then delete their icons from the soldier's smartphone, tricking the user into thinking the app uninstalled itself. However, the app would keep running in the background. The malicious apps would then exfiltrate photos, SMS messages, contacts, and more. The apps could also install other malware on the device, track the phone's geo-location in real-time, and even take screenshots via the phone's camera.
Israeli cyber-security firm Check Point says the malware belongs to a group it's been tracking under the codename of APT-C-23, active since the summer of 2018.
Security

New Email-Based Extortion Scheme Targets Website Owners Serving Ads Via Google AdSense (krebsonsecurity.com) 16

Brian Krebs sheds light upon a new email-based extortion scheme targeting website owners serving banner ads through Google's AdSense program. "In this scam, the fraudsters demand bitcoin in exchange for a promise not to flood the publisher's ads with so much bot and junk traffic that Google's automated anti-fraud systems suspend the user's AdSense account for suspicious traffic," writes Krebs. From his report: Earlier this month, KrebsOnSecurity heard from a reader who maintains several sites that receive a fair amount of traffic. The message this reader shared began by quoting from an automated email Google's systems might send if they detect your site is seeking to benefit from automated clicks. The message goes on to warn that while the targeted site's ad revenue will be briefly increased, "AdSense traffic assessment algorithms will detect very fast such a web traffic pattern as fraudulent."

The message demands $5,000 worth of bitcoin to forestall the attack. In this scam, the extortionists are likely betting that some publishers may see paying up as a cheaper alternative to having their main source of advertising revenue evaporate. The reader who shared this email said while he considered the message likely to be a baseless threat, a review of his recent AdSense traffic statistics showed that detections in his "AdSense invalid traffic report" from the past month had increased substantially.
"We hear a lot about the potential for sabotage, it's extremely rare in practice, and we have built some safeguards in place to prevent sabotage from succeeding," Google said in a statement. "For example, we have detection mechanisms in place to proactively detect potential sabotage and take it into account in our enforcement systems."

"We have a help center on our website with tips for AdSense publishers on sabotage," the statement continues. "There's also a form we provide for publishers to contact us if they believe they are the victims of sabotage. We encourage publishers to disengage from any communication or further action with parties that signal that they will drive invalid traffic to their web properties. If there are concerns about invalid traffic, they should communicate that to us, and our Ad Traffic Quality team will monitor and evaluate their accounts as needed."
Bug

Bug In WordPress Plugin Can Let Hackers Wipe Up To 200,000 Sites (zdnet.com) 6

An anonymous reader quotes a report from ZDNet: WordPress site owners who use commercial themes provided by ThemeGrill are advised to update one of the plugins that come installed with these themes in order to patch a critical bug that can let attackers wipe their sites. The vulnerability resides in ThemeGrill Demo Importer, a plugin that ships with themes sold by ThemeGrill, a web development company that sells commercial WordPress themes. The plugin, which is installed on more than 200,000 sites, allows site owners to import demo content inside their ThemeGrill themes so they'll have examples and a starting point on which they can build their own sites.

However, in a report published yesterday, WordPress security firm WebARX says that older versions of the ThemeGrill Demo Importer are vulnerable to remote attacks from unauthenticated attackers. Remote hackers can send a specially crafted payload to vulnerable sites and trigger a function inside the plugin. The vulnerable function resets the site's content to zero, effectively wiping the content of all WordPress sites where a ThemeGrill theme is active, and the vulnerable plugin is installed. Furthermore, if the site's database contains a user named "admin," then the attacker is granted access to that user with full administrator rights over the site.

Security

Israeli Soldiers Tricked Into Installing Malware by Hamas Agents Posing as Women (zdnet.com) 75

Members of the Hamas Palestinian militant group have posed as young teenage girls to lure Israeli soldiers into installing malware-infected apps on their phones, a spokesperson for the Israeli Defence Force (IDF) said today. From a report: Some soldiers fell for the scam, but IDF said they detected the infections, tracked down the malware, and then took down Hamas' hacking infrastructure. IDF said Hamas operatives created Facebook, Instagram, and Telegram accounts and then approached IDF soldiers. According to IDF spokesperson Brigadier General Hild Silberman, Hamas agents posed as new Israeli immigrants in order to excuse their lacking knowledge of the Hebrew language. IDF investigators said they tracked accounts for six characters used in the recent social engineering campaign. The accounts were named Sarah Orlova, Maria Jacobova, Eden Ben Ezra, Noa Danon, Yael Azoulay, and Rebecca Aboxis, respectively. Soldiers who engaged in conversations were eventually lured towards installing one of three chat apps, named Catch & See, Grixy, and Zatu, where the agents promised to share more photos.
Programming

Many Businesses Still Love COBOL (techradar.com) 195

TechRadar shares some surprising results from a new survey of enterprises using COBOL and mainframe technologies: According to a survey by Micro Focus, which follows data gathered in previous 2017 survey, 70 percent favor modernization as an approach for implementing strategic change. This is opposed to replacing or retiring their key COBOL applications as they continue to provide a low-risk and effective means of transforming IT to support digital business initiatives...

This is further supported by the results of the survey with an increase in the size of the average application code base which grew from 8.4m in 2017 to 9.9m this year, showing continued investment, re-use and expansion in core business systems.

"92 percent of respondents felt as though their organization's COBOL applications are strategic in comparison to 84 percent of respondents in 2017," according to the official survey results. The survey spanned 40 different countries, and involved COBOL-connected architects, developers, development managers and IT executives.

"COBOL's credentials as a strong digital technology appear to be set for another decade," according to Micro Focus' senior vice president of application modernization and connectivity. "With 60 years of experience supporting mission-critical applications and business systems, COBOL continues to evolve as a flexible and resilient computer language that will remain relevant and important for businesses around the world."
The Almighty Buck

IOTA Cryptocurrency Shut Down Its Entire Network After a Wallet Breach (zdnet.com) 20

The nonprofit organization behind the IOTA cryptocurrency shut down its entire network this week after someone exploited a vulnerability in their wallet app to steal funds.

ZDNet reports: The attack happened this week, Wednesday, on February 12, 2020, according to a message the foundation posted on its official Twitter account. According to a status page detailing the incident, within 25 minutes of receiving reports that hackers were stealing funds from user wallets, the IOTA Foundation shut down "Coordinator," a node in the IOTA network that puts the final seal of approval on any IOTA currency transactions.

The never-before-seen move was meant to prevent hackers from executing new thefts, but also had the side-effect of effectively shut down the entire IOTA cryptocurrency...

IOTA members said hackers used an exploit in "a third-party integration" of Trinity, a mobile and desktop wallet app developed by the IOTA Foundation. Based on current evidence, confirmed by the IOTA team, it is believed that hackers targeted at least 10 high-value IOTA accounts and used the Trinity exploit to steal funds.

Sunday the team released "a safe version" of their Trinity Desktop "to allow users to check their balance and transactions. This version (1.4.0) removes the vulnerability announced on 12th February 2020..."

Their status page advised users to contact a member of the IOTA Foundation if their balance looks incorrect. "Please be aware that there are unfortunately active imposters posing as IOTA Foundation personnel on our Discord. Therefore it is important that you directly initiate contact with the IF or mod team yourself..."

"The Coordinator remains down for now as we finalise our remediation plan. You will not be able to send value transactions."
Security

Iran Has Been Targeting VPN Servers to Plant Backdoors (zdnet.com) 49

"A new report published today reveals that Iran's government-backed hacking units have made a top priority last year to exploit VPN bugs as soon as they became public in order to infiltrate and plant backdoors in companies all over the world," writes ZDNet: According to a report from Israeli cyber-security firm ClearSky, Iranian hackers have targeted companies "from the IT, Telecommunication, Oil and Gas, Aviation, Government, and Security sectors." The report comes to dispel the notion that Iranian hackers are not sophisticated, and less talented than their Russian, Chinese, or North Korean counterparts. ClearSky says that "Iranian APT groups have developed good technical offensive capabilities and are able to exploit 1-day vulnerabilities in relatively short periods of time." [ATP stands for "advanced persistent threat" and is often used to describe nation-state backed cyberattackers.]

In some instances, ClearSky says it observed Iranian groups exploiting VPN flaws within hours after the bugs have been publicly disclosed...

According to the ClearSky report, the purpose of these attacks is to breach enterprise networks, move laterally throughout their internal systems, and plant backdoors to exploit at a later date.

Slashdot Top Deals