Microsoft

Vladimir Putin 'Still Uses Obsolete Windows XP' Despite Hacking Risk (theguardian.com) 103

Speaking of Russia, whose agents have been accused of worldwide hacking operations, but someone at the Kremlin has apparently forgotten to inform Vladimir Putin of the importance of cyber-security. From a report: Putin, 67, appears to have the obsolete Microsoft Windows XP operating system installed on computers in his office at the Kremlin and at his official Novo-Ogaryovo residence near Moscow, according to images released by his press service. Both computers have the Kremlin towers set as their desktop backgrounds. [...] Moscow is gradually phasing out Microsoft and Google on government computers in favour of Russia's Astra Linux operating system software and domestic browsers such as Yandex. Dmitry Peskov, the Kremlin spokesman, did not comment when asked why Putin continues to use an antiquated Microsoft operating system.
Mozilla

Mozilla To Add Second DNS-over-HTTPS (DoH) Provider in Firefox (zdnet.com) 67

Mozilla has announced that NextDNS would be joining Cloudflare as the second DNS-over-HTTPS (DoH) provider inside Firefox. From a report: The browser maker says NextDNS passed the conditions imposed by its Trusted Recursive Resolver (TRR) program, and can now be added as a second option for DoH inside Firefox. These conditions include (1) limiting the data NextDNS collects from the DoH server used by Firefox users; (2) being transparent about the data they collect; and (3) promising not to censor, filter, or block DNS traffic unless specifically requested by law enforcement.

DNS-over-HTTPS, or DoH, is a new feature that was added to Firefox last year. When enabled, it encrypts DNS traffic coming in and out of the browser. DNS traffic is not only encrypted but also moved from port 53 (for DNS traffic) to port 443 (for HTTPS traffic), effectively hiding DNS queries and replies inside the browser's normal stream of HTTPS content. This encrypted DNS traffic reaches a so-called DoH resolver. Here, the DoH traffic is decrypted and the DoH resolver makes the DNS query on the user's behalf, receives the result, encrypts it, and sends it back to the user's browser -- also disguised inside encrypted HTTPS content.

Microsoft

Microsoft: We Never Encourage a Ransomware Victim To Pay (zdnet.com) 62

An anonymous reader shares a report: Ever since ransomware became a top threat in the mid-2010s, people have been arguing about the proper way of dealing with a ransomware attack and the merits of paying or not paying a ransom demand. A big point of contention has been "the official advice" that various companies or government agencies give out to victims. For example, in late 2015, the FBI found itself in the middle of a controversy when one of its agents publicly admitted that the bureau was, in many cases, recommending that victims pay ransom demands. At the time, many were shocked to find out that the FBI was telling victims to pay ransomware demands, and helping criminal gangs boost their profits.

The Bureau changed its official stance a few months later, in 2016, after US senators sent letters asking why the agency was helping out criminals. Since then, the FBI's official position has been to defer the decision to pay a ransom to the victim, with no formal advice. [...] In a blog post today, Microsoft, for the first time, revealed its stance on the matter. "We never encourage a ransomware victim to pay any form of ransom demand," said Ola Peters, Senior Cybersecurity Consultant for Microsoft Detection and Response Team (DART), the OS maker's official incident response team. "Paying a ransom is often expensive, dangerous, and only refuels the attackers' capacity to continue their operations," Peters added.

The Almighty Buck

Visa Warns That Hackers Are Scraping Card Details From Gas Pumps (engadget.com) 88

Visa has issued a statement warning consumers that cybercriminals are actively exploiting a weakness in gas station point-of-sale (POS) networks to steal credit card data. Engadget reports: The company's fraud disruption teams are investigating several incidents in which a hacking group known as Fin8 defrauded fuel dispenser merchants. In each case, the attackers gained access to the POS networks via malicious emails and other unknown means. They then installed POS scraping software that exploited the lack of security with old-school mag stripe cards that lack a PIN code.

The hack doesn't appear to affect more secure chip-and-pin cards, but not all consumers have those, so service stations often work with mag stripe readers, too. The data is apparently sent in an unencrypted form to the vendor's main network, where the thieves have figured out how to intercept it. The other problem is that the POS systems aren't firewalled off from other, less critical parts of the network, allowing thieves to gain lateral access once the network is breached. There's not much cardholders can do to avoid the attacks, but Visa has advised fuel merchants to encrypt data while it's transferred or use a chip-and-PIN policy.

Security

New Jersey's Largest Hospital System Pays Up In Ransomware Attack 34

New Jersey's largest hospital system said that it has paid hackers a ransom after a ransomware attack disrupted its services earlier this month. Threatpost reports: Hackensack Meridian Health, a $6 billion non-profit health provider system based in Edison, N.J., operates 17 hospitals, nursing homes and outpatient centers, as well as psychiatric facility Carrier Clinic. The hospital system told media outlets on Friday that it was targeted by a cyberattack on Dec. 2, crippling its computer software systems for nearly five days. "Our network's primary clinical systems are operational, and our IT teams continue working diligently to bring all applications back online safely," according to a statement issued to media, Friday. "Based on our investigation to date, we have no indication that any patient or team-member information has been subject to unauthorized access or disclosure."

The attack affected the hospital's computer software systems, from scheduling and billing systems to labs and radiology, according to reports. Consequently, the ransomware attack forced the hospitals that were part of Hackensack Meridian Health system to reschedule around 100 non-emergency appointments and surgeries earlier in December. The hospital system did not clarify how much ransom it paid, or whether its data has since been recovered. It also did not give further indication about how systems were first infected and what data was affected.
Google

Ask Slashdot: Who Is Most Likely To Challenge Microsoft In the Office? 147

Tablizer writes: Microsoft still dominates cubicle-land. Google is making a push into that domain, but it's unclear how far or how fast they can go. Most "serious" applications still run on only Windows and that doesn't seem to be changing much. What's keeping others out? Do we need new desktop-oriented, cross-platform standards? It seems everyone "went web" and forgot about the desktop niche, but it's a big niche still.
Security

Npm Team Warns of New 'Binary Planting' Bug (zdnet.com) 17

The team behind npm, the biggest package manager for JavaScript libraries, issued a security alert yesterday, advising all users to update to the latest version (6.13.4) to prevent "binary planting" attacks. From a report: Npm (Node.js Package Manager) devs say the npm command-line interface (CLI) client is impacted by a security bug -- a combination between a file traversal and an arbitrary file (over)write issue. The bug can be exploited by attackers to plant malicious binaries or overwrite files on a user's computer. The vulnerability can be exploited only during the installation of a boobytrapped npm package via the npm CLI. "However, as we have seen in the past, this is not an insurmountable barrier," said the npm team, referring to past incidents where attackers planed backdoored or boobytrapped packages on the official npm repository. Npm devs say they've been scanning the npm portal for packages that may contain exploit code designed to exploit this bug, but have not seen any suspicious cases. "That does not guarantee that it hasn't been used, but it does mean that it isn't currently being used in published packages on the [official npm] registry," npm devs said.
Security

New Orleans City Government Shuts Off Computers After Cyberattack (nola.com) 30

New submitter tubajock writes: According to NOLA.com, New Orleans City Hall workers were told by a PA system broadcast to immediately unplug all computer systems from the network [following a cyberattack that struck the city government]. The city website is also down and the city has implemented its Emergency Operations Center as well as contacted state and federal authorities for help. Beau Tidwell, a spokesman for Mayor LaToya Cantrell, said the cyberattack started sometime after 11 a.m. In addition to city hall workers, the New Orleans Police Department has also been told to shut down their computers and remove everything from the network.

Thankfully, 9-1-1 and 3-1-1 calls are not impacted by the attack and residents can still access the online 3-1-1 systems through its site, nola311.org.
Security

Mozilla To Force All Add-on Devs To Use 2FA To Prevent Supply-Chain Attacks (zdnet.com) 21

Mozilla announced this week that all developers of Firefox add-ons must enable a two-factor authentication (2FA) solution for their account. From a report: "Starting in early 2020, extension developers will be required to have 2FA enabled on AMO [the Mozilla Add-Ons portal]," said Caitlin Neiman, Add-ons Community Manager at Mozilla. "This is intended to help prevent malicious actors from taking control of legitimate add-ons and their users," Neiman added. When this happens, hackers can use the developers' compromised accounts to ship tainted add-on updates to Firefox users. Since Firefox add-ons have a pretty privileged position inside the browser, an attacker can use a compromised add-on to steal passwords, authentication/session cookies, spy on a user's browsing habits, or redirect users to phishing pages or malware download sites. These types of incidents are usually referred to as supply-chain attacks.
Privacy

Inside the Podcast that Hacks Ring Camera Owners Live on Air (vice.com) 112

In the NulledCast podcast hackers livestream the harassment of Ring camera owners after accessing their devices. Hundreds of people can listen. From a report: A blaring siren suddenly rips through the Ring camera, startling the Florida family inside their own home. "It's your boy Chance on Nulled," a voice says from the Ring camera, which a hacker has taken over. "How you doing? How you doing?" "Welcome to the NulledCast," the voice says. The NulledCast is a podcast livestreamed to Discord. It's a show in which hackers take over people's Ring and Nest smarthome cameras and use their speakers to talk to and harass their unsuspecting owners. In the example above, Chance blared noises and shouted racist comments at the Florida family. "Sit back and relax to over 45 minutes of entertainment," an advertisement for the podcast posted to a hacking forum called Nulled reads. "Join us as we go on completely random tangents such as; Ring & Nest Trolling, telling shelter owners we killed a kitten, Nulled drama, and more ridiculous topics. Be sure to join our Discord to watch the shows live."

Software to hack Ring cameras has recently become popular on the forum. The software churns through previously compromised email addresses and passwords to break into Ring cameras at scale. This has led to a recent spate of hacks that have occurred both during the podcast and at other times, several of which have been covered by local media outlets. In Brookhaven a hacker shouted at a sleeping woman through her hacked Ring camera to wake-up. In Texas, a hacker demanded a couple pay a bitcoin ransom. Hackers targeted a family in DeSoto County, Mississippi, and spoke through the device to one of the young children.

Google

Google Adds Spam Detection and Verified Business SMS To Messages (engadget.com) 14

Businesses often send one-time passwords, account alerts and appointment confirmations via text. But if you've ever received one of those, you know they tend to come from a random number, and bad actors can take advantage of that by disguising phishing scams as one of those messages. To protect users, Google will soon verify SMS messages from registered businesses. From a report: When you receive a message from a verified business, you'll see the company name, logo and a verification badge in the message thread. Businesses must sign up to use Verified SMS, and so far, 1-800-Flowers, Banco Bradesco, Kayak, Payback and SoFi are on-board. Verified SMS is rolling out gradually in the US, Brazil, Canada, France, India, Mexico, Philippines, Spain and the UK. Google is also adding real-time spam detection. When Google suspects a message is phishy or garbage, it will show a spam warning in Messages.
Social Networks

'Link in Bio' is a Slow Knife (anildash.com) 63

Anil Dash: We don't even notice it anymore -- "link in bio." It's a pithy phrase, usually found on Instagram, which directs an audience to be aware that a pertinent web link can be found on that user's profile. Its presence is so subtle, and so pervasive, that we barely even noticed it was an attempt to kill the web. Links on the web are incredibly powerful. There are decades of theory behind the role of hyperlinks in hypertext -- did you know in most early versions, links were originally designed to be two-way? You'd be able to see every page on the web that links to this one. But even in the very simple form that we've ended up with on the World Wide Web for the last 30 years, links are incredibly powerful, opening up valuable connections between unexpected things.

For a closed system, those kinds of open connections are deeply dangerous. If anyone on Instagram can just link to any old store on the web, how can Instagram -- meaning Facebook, Instagram's increasingly-overbearing owner -- tightly control commerce on its platform? If Instagram users could post links willy-nilly, they might even be able to connect directly to their users, getting their email addresses or finding other ways to communicate with them. Links represent a threat to closed systems. Here's the thing, though: people like links. So closed systems have to present a pressure release valve. Hashtags are a great way out. They use the semiotics of links (early versions of hashtags on social platforms were really barely more than automated links to a search for a particular term) but are also constrained by the platforms they live on. A hashtag is easier to gather into a database, to harvest, to monetize. It's much easier, sure, but it also doesn't have all the messiness of a real link. Instagram doesn't have to worry that clicking on its hashtags will accidentally lead people to Twitter, or vice versa.

Security

Iran Banks Burned, Then Customer Accounts Were Exposed Online (nytimes.com) 47

The details of millions of Iranian bank cards were published online after antigovernment protests last month. Experts suspect a state-sponsored cyberattack. From a report: After demonstrators in Iran set fire to hundreds of bank branches last month in antigovernment protests, the authorities dealt with another less visible banking threat that is only now coming to fuller light: a security breach that exposed the information of millions of Iranian customer accounts. As of Tuesday, details of 15 million bank debit cards in Iran had been published on social media in the aftermath of the protests, unnerving customers and forcing the government to acknowledge a problem. The exposure represented the most serious banking security breach in Iran, according to Iranian media and a law firm representing some of the victims.

The breach, which targeted customers of Iran's three largest banks, was likely to further rattle an economy already reeling from the effects of American sanctions and came as Iran's leadership was grappling with deep-seated anger over its deadly crackdown on the protests. The number of affected accounts represents close to a fifth of the country's population. "This is the largest financial scam in Iran's history," reported Aftab News, a conservative media outlet. "Millions of Iranians are worried to find their names among the list of hacked accounts."

Operating Systems

Two of China's Largest Tech Firms Are Uniting To Create a New 'Domestic OS' (zdnet.com) 93

The two biggest OS (operating system) makers in China announced plans last week to unite and jointly build a new "domestic operating system." From a report: The two companies are China Standard Software (CS2C) and Tianjin Kylin Information (TKC), two of China's largest software firms, with known ties to the Beijing government. Both companies are known on the local Chinese OS market. CS2C created "China's Windows XP clone," known as the NeoKylin OS, and TKC is the current steward of Kylin, China's first-ever homegrown operating system. CS2C and TKC plan to set up a new company in which they'll become investors, and through which the new joint OS will be developed. The new company will handle the new operating system's development, technological decisions, marketing, branding, financials, and sales. The current Kylin and NeoKylin operating systems will serve as a base for the new OS, the two said.
Security

Maze Ransomware Was Behind Pensacola 'Cyber Event,' Florida Officials Say (arstechnica.com) 5

An anonymous reader quotes a report from Ars Technica: An email sent by the Florida Department of Law Enforcement to all Florida county commissioners indicated that the ransomware that struck the city of Pensacola on December 7 was the same malware used in an attack against the private security firm Allied Universal, according to a report by the Pensacola News Journal. That malware has been identified elsewhere as Maze, a form of ransomware that has also been distributed via spam email campaigns in Italy.

Bleeping Computer's Lawrence Abrams reported in November that the Maze operators had contacted him after the Allied Universal attack, claiming to have stolen files from the company before encrypting them on the victims' computers. After Allied apparently missed the deadline for payment of the ransom on the files, the ransomware operators published 700 megabytes of files from Allied and demanded 300 Bitcoins (approximately $2.3 million) to decrypt the network. The Maze operators told Abrams that they always steal victims' files to use as further leverage to get them to pay: "It is just a logic. If we disclose it who will believe us? It is not in our interest, it will be silly to disclose as we gain nothing from it. We also delete data because it is not really interesting. We are neither espionage group nor any other type of APT, the data is not interesting for us."
"The use of the data to blackmail the victim, and in Allied's case, the threat to use Allied's certificates and domain name to spam customers with additional ransomware attacks, is something new," writes Sean Gallagher.

"This is the first time this has ever happened, as far as we know," said Brett Callow, a spokesperson for the antivirus software vendor Emisoft. "Ransomware groups usually encrypt, not steal. We expect data exfiltration to become more and more commonplace. Whether Pensacola's data was exfiltrated, I obviously can't say."
Microsoft

Microsoft is About To Start Aggressively Advertising Windows 10 To Windows 7 Stragglers (betanews.com) 266

Mark Wycislik-Wilson, writing for BetaNews: Having already started to notify Windows 7 hangers on that support is due to come to an end, Microsoft is now ready to get a little more aggressive. If you haven't moved on from Windows 7, soon you will see full-screen notifications warning you that "your Windows 7 PC is out of support." The messages are due to be displayed from the day after support ends. So when January 15 rolls around, anyone who has doggedly stuck with Windows 7 will find that they not only have no support and no security updates, but also that they are pestered by an invasive message delivered by a program called EOSnotify.exe.
Encryption

Apple Used the DMCA to Take Down a Tweet Containing an iPhone Encryption Key (vice.com) 66

Security researchers are accusing Apple of abusing the Digital Millennium Copyright Act (DMCA) to take down a viral tweet and several Reddit posts that discuss techniques and tools to hack iPhones. Lorenzo Franceschi-Bicchierai, reporting for Vice: On Sunday, a security researcher who focuses on iOS and goes by the name Siguza posted a tweet containing what appears to be an encryption key that could be used to reverse engineer the Secure Enclave Processor, the part of the iPhone that handles data encryption and stores other sensitive data. Two days later, a law firm that has worked for Apple in the past sent a DMCA Takedown Notice to Twitter, asking for the tweet to be removed. The company complied, and the tweet became unavailable until today, when it reappeared. In a tweet, Siguza said that the DMCA claim was "retracted." Apple confirmed that it sent the original DMCA takedown request, and later asked Twitter to put the Tweet back online.

At the same time, Reddit received several DMCA takedown requests for posts on r/jailbreak, a popular subreddit where iPhone security researchers and hackers discuss techniques to jailbreak Apple devices, according to the subreddit's moderators. "Admins have not reached out to us in regards to these removals. We have no idea who is submitting these copyright claims," one moderator wrote.

The Courts

ACLU is Suing ICE For Details on How It Uses Phone Spying Devices (cnet.com) 14

The American Civil Liberties Union filed a lawsuit Wednesday demanding that two US Homeland Security agencies -- Customs and Border Protection and Immigration and Customs Enforcement -- release details on how they've been using powerful phone surveillance tools. From a report: The ACLU is suing after the two agencies declined to provide it with documents related to International Mobile Subscriber Identity, or IMSI, catchers, more commonly known as Stingrays. These devices pretend to be cell towers and connect with nearby phones, intercepting data that details calls, messages and device location. IMSI catchers can often pull in data from entire neighborhoods, and they're able to obtain sensitive details on people without the people even knowing. Civil liberties and privacy groups have criticized the technology for its invasive surveillance. The two agencies have denied the ACLU's requests for information since 2017, telling the civil rights organization that "no records responsive to your request were found." The assertion comes despite the fact that a House Oversight Committee investigation in 2016 found that ICE spent $10.6 million on 59 IMSI catchers and that CBP had spent $2.5 million on 33 IMSI catchers.
Chrome

Chrome Now Warns You When Your Password Has Been Stolen (theverge.com) 49

Google is rolling out Chrome 79, and it includes a number of password protection improvements. The Verge reports: The biggest addition is that Chrome will now warn you when your password has been stolen as part of a data breach. Google has been warning about reused passwords in a separate browser extension or in its password checkup tool, but the company is now baking this directly into Chrome to provide warnings as you log in to sites on the web.

You can control this new functionality in the sync settings in Chrome, and Google is using strongly hashed and encrypted copies of passwords to match them using multiple layers of encryption. This allows Google to securely match passwords using a technique called private set intersection with blinding. Alongside password warnings, Google is also improving its phishing protection with a real-time option. Google has been using a list of phishing sites that updates every 30 minutes, but the company found that fraudsters have been quickly switching domains or hiding from Google's crawlers. This new real-time protection should generate warnings for 30 percent more cases of phishing.

Security

New Plundervolt Attack Impacts Intel Desktop, Server, and Mobile CPUs (zdnet.com) 74

An anonymous reader quotes a report from ZDNet: Academics from three universities across Europe have disclosed today a new attack that impacts the integrity of data stored inside Intel SGX, a highly-secured area of Intel CPUs. The attack, which researchers have named Plundervolt, exploits the interface through which an operating system can control an Intel processor's voltage and frequency -- the same interface that allows gamers to overclock their CPUs. Academics say they discovered that by tinkering with the amount of voltage and frequency a CPU receives, they can alter bits inside SGX to cause errors that can be exploited at a later point after the data has left the security of the SGX enclave. They say Plundervolt can be used to recover encryption keys or introduce bugs in previously secure software. Intel desktop, server, and mobile CPUs are impacted. A full list of vulnerable CPUs is available here. Intel has also released microcode (CPU firmware) and BIOS updates today that address the Plundervolt attack [by allowing users to disable the energy management interface at the source of the attack, if not needed]. Proof-of-concept code for reproducing attacks will be released on GitHub.

Slashdot Top Deals