Facebook

Facebook Bug Has Camera Activated While People Are Using the App (cnet.com) 92

When you're scrolling through Facebook's app, the social network could be watching you back, in more ways than just your data, concerned users have found. Multiple people have found and reported that their iPhone cameras were turned on in the background while looking at their feed. From a report: The issue came to light with several posts on Twitter, showing that their cameras were activated behind Facebook's app as they were watching videos or looking at photos on the social network. After clicking on the video to full screen, returning it back to normal would create a bug where Facebook's mobile layout was slightly shifted to the right. With the open space on the left, you could now see the phone's camera activated in the background. This was documented in multiple cases, with the earliest incident on November 2.
Bitcoin

IRS Identifies 'Dozens' of New Crypto, Cybercriminals (bloomberg.com) 57

The IRS's criminal division identified "dozens" of potential cryptocurrency tax evaders or cybercriminals after a meeting this week with tax authorities from four other countries. Bloomberg reports: Officials from the U.S., U.K., Australia, Canada and the Netherlands -- known as the Joint Chiefs of Global Tax Enforcement -- shared data, tools and tax enforcement strategies to find new leads in a quest to mitigate cross-border money-laundering, tax evasion and cybercrime. The IRS's cybercrime unit has developed expertise in "who is moving the money and where it's going," Ryan Korner, a senior special agent in the IRS's Criminal Investigations office in Los Angeles, said in a call with reporters Friday. "We have tools in place that we didn't have six months or a year ago."

The effort is part of the Internal Revenue Service's renewed focus on fighting tax evasion tied to cryptocurrency as digital currency has become more popular and gained in value. The agency has struggled in recent years to enforce tax laws and keep up with criminals as technology has advanced. "Tax fraud is not a new crime, but the sophistication with which criminals commit tax fraud has significantly increased through cyber-related activities in recent years," the joint chiefs said in a statement. "Data breaches, intrusions, takeovers and compromises are the new tools that criminals use to commit tax crimes." The IRS is preparing for a new wave of cryptocurrency audits. The agency sent letters to more than 10,000 people earlier this year, warning that they might be subject to penalties for skirting taxes on their virtual investments. The IRS and its partners are using data from previous enforcement activities to find new criminals, Korner said. Using the data from the five countries gives them a broader view of how accounts, money and people are connected.

Businesses

Canada's OpenText To Buy Cloud Security Firm Carbonite For $1.42 Billion (venturebeat.com) 15

An anonymous reader quotes a report from VentureBeat: Enterprise information management (EIM) company OpenText is acquiring cloud data backup and protection service Carbonite in a deal worth $1.42 billion. Carbonite, which offers a number of data backup and protection services for consumers and businesses, had become the subject of significant takeover rumors over the past few months after its revenue dropped. CEO Mohamad Ali stepped down in July and was replaced on an interim basis by board chair Steve Munford.

Carbonite's announcement was timed to coincide with its Q3 2019 financials, which revealed a net loss of $14 million, compared to a small net income of $600,000 during the same period last year. Founded in 1991, OpenText is among Canada's biggest software companies, specializing in helping enterprises manage all their content and unstructured data in the cloud or on-premises. The company has made a number of other notable acquisitions in the recent past, including Dell EMC's enterprise content division, which it bought for $1.6 billion in 2017, and file-sharing service Hightail, formerly YouSendIt, which it bought for an undisclosed amount last year. OpenText hasn't offered any specifics around how it will leverage Carbonite's technology post-acquisition. But the latter's focus on backing up and protecting data stored in the cloud makes it easy to imagine the two platforms complementing each other as a growing number of businesses migrate to the cloud.
"Following expressions of interest from multiple parties, the Carbonite board conducted a thorough and comprehensive process, which included contact with a number of strategic and financial parties, to identify the best way to maximize shareholder value," Munford said in a press release. "The board strongly believes that a transaction with OpenText delivers compelling, immediate, and substantial cash value to shareholders."
Businesses

WeWork In Talks To Hire T-Mobile CEO John Legere (pymnts.com) 12

According to The Wall Street Journal, WeWork is in discussions with T-Mobile CEO John Legere to take over leadership of the troubled office-sharing startup (Warning: source paywalled; alternative source). From the report: WeWork's parent, formally known as We Co., is searching for a CEO who can stabilize the company following the erratic tenure of its co-founder Adam Neumann. After WeWork's failed attempt at an initial public offering, SoftBank Group Corp. bought a majority stake in the company last month in a bailout, severing most ties with Mr. Neumann. The startup is looking for a new leader who could join as soon as January, some of the people said. There is no guarantee that Mr. Legere, who stands to receive a windfall if T-Mobile completes its proposed takeover of Sprint Corp. next year, would accept the position or that another candidate won't emerge.

Like Mr. Neumann, Mr. Legere is known as an unconventional executive. The 61-year-old has spent the past six years running T-Mobile with a pugnacious style, trashing his rivals on Twitter as "Dumb and Dumber," using foul language and dressing in the company's signature magenta. He has turned around T-Mobile's operations, luring millions of cellphone customers from larger players and initiating the pending takeover of Sprint. Two WeWork executives, Artie Minson and Sebastian Gunningham, have served as co-CEOs since September when Mr. Neumann resigned under pressure as chief executive. SoftBank executives are seeking to replace the duo with a high-profile candidate who they hope can turn the company around with an eye toward potentially taking it public in the future, the people said.

Android

Google Asks Three Outside Antivirus Firms To Start Scanning Submissions To Android's Play Store (arstechnica.com) 14

"Android has a bit of a malware problem," argues Wired, noting that " malware-ridden apps sneak into the official Play Store with disappointing frequency..."

"After grappling with the issue for a decade, Google is calling in some reinforcements." This week, Google announced a partnership with three antivirus firms -- ESET, Lookout, and Zimperium -- to create an App Defense Alliance. All three companies have done extensive Android malware research over the years, and have existing relationships with Google to report problems they find. But now they'll use their scanning and threat detection tools to evaluate new Google Play submissions before the apps go live -- with the goal of catching more malware before it hits the Play Store in the first place.

"On the malware side we haven't really had a way to scale as much as we've wanted to scale," says Dave Kleidermacher, Google's vice president of Android security and privacy. "What the App Defense Alliance enables us to do is take the open ecosystem approach to the next level. We can share information not just ad hoc, but really integrate engines together at a digital level, so that we can have real-time response, expand the review of these apps, and apply that to making users more protected."

Security

Security Researchers Exploit Amazon Echo's Chromium Bug, Win $60,000 Bounty (techcrunch.com) 6

An anonymous reader quotes TechCrunch: Two security researchers have been crowned the top hackers in this year's Pwn2Own hacking contest after developing and testing several high profile exploits, including an attack against an Amazon Echo. Amat Cama and Richard Zhu, who make up Team Fluoroacetate, scored $60,000 in bug bounties for their integer overflow exploit against the latest Amazon Echo Show 5, an Alexa-powered smart display.

The researchers found that the device uses an older version of Chromium, Google's open-source browser projects, which had been forked some time during its development. The bug allowed them to take "full control" of the device if connected to a malicious Wi-Fi hotspot, said Brian Gorenc, director of Trend Micro's Zero Day Initiative, which put on the Pwn2Own contest...

When reached, Amazon said it was "investigating this research and will be taking appropriate steps to protect our devices based on our investigation," but did not say what measures it would take to fix the vulnerabilities -- or when.

The same researchers also compromised Sony and Samsung smart TVs, and the Xiaomi Mi9 smartphone, according to ZDNet, which also reports that "Nobody wanted a piece of the Facebook Portal, and nor did they want to hack Google's Home assistant.

"Security researchers chose to go after the easier targets, like routers and smart TVs, known for running weaker firmware than what you'd usually find on a smart speaker or home automation hub."
Microsoft

'Microsoft Defender ATP' Antivirus is Coming to Linux (zdnet.com) 100

Microsoft is planning to bring its Defender antivirus to Linux systems next year, reports ZDNet: Microsoft announced the brand change from Windows Defender to Microsoft Defender in March after giving security analysts the tools to inspect enterprise Mac computers for malware via the Microsoft Defender console.

Rob Lefferts, corporate vice president for Microsoft's M365 Security, told ZDNet that Microsoft Defender for Linux systems will be available for customers in 2020.

In October TechSpot reported that Defender placed in the top 10 among all major antivirus programs, narrowly beating established software like Bitdefender, Kaspersky, and Mcafee with an online protection rate of 99.96%, according to testing by independent lab AV-Comparative.
Security

6 In 10 Websites May Be Impacted by jQuery XSS Vulnerabilities (i-programmer.info) 25

"Although the JavaScript library jQuery is no longer as popular as it was, it is still widely used. As a result at least six in ten websites are impacted by jQuery XSS vulnerabilities," reports I Programmer: Even more security issues are introduced by the jQuery libraries used to extend jQuery's capabilities. These findings come from open source security platform, Snyk and are included in "The state of JavaScript frameworks security report 2019". While this report is mainly devoted to a security review of the two leading JavaScript frameworks, Angular and React, it takes a "sneak peek" into the security vulnerabilities in three other frontend JavaScript ecosystem projects - Vue.js, Bootstrap and jQuery.

jQuery was downloaded more than 120 million times in the last 12 months, which is equivalent to the number of downloads for Vue.js (40 million) and Bootstrap (79 million) combined. Snyk reports that four vulnerabilities had been found for Vue.js, all of which have been fixed. Bootstrap contained seven cross-site scripting (XSS) vulnerabilities. Three of these were disclosed in 2019 and there are no security fixes or upgrade paths to avoid them. In the case of jQuery, Snyk tracked six security vulnerabilities affecting jQuery across all of its releases to date. Four are medium severity Cross-Site Scripting vulnerabilities, one is a medium severity Prototype Pollution vulnerability, and the final one is a low severity Denial of Service vulnerability.

The report concludes that unless you are using jQuery 3.4.0 and above then you are using vulnerable jQuery versions.

Security

Boeing's Poor Information Security Threatens Passenger Safety, National Security, Says Researcher (csoonline.com) 21

itwbennett writes: Security researcher Chris Kubecka has identified (and reported to Boeing and the Department of Homeland Security back in August) a number of security vulnerabilities in Boeing's networks, email system, and website. "[T]he company's failure to remedy the security failures she reported demonstrate either an unwillingness or inability to take responsibility for their information security," writes JM Porup for CSO online.

The vulnerabilities include a publicly exposed test developer network, a lack of encryption on the boeing.com website, failure to use DMARC for email security, and, perhaps most notably, an email server infected with malware.

For its part, Boeing says that the vulnerabilities Kubecka reported are "common IT vulnerabilities — the type of cyber-hygiene issues thousands of companies confront every day" and that the company has "no indication of a compromise in any aviation system or product that Boeing produces." What Porup's reporting and Kubecka's research clearly shows, however, is how poor information security practices can become aviation security risks.

Firefox

Scammers Are Actively Exploiting A Firefox Bug (arstechnica.com) 26

Long-time Slashdot reader slack_justyb shares this story from Ars Technica: Scammers are actively exploiting a bug in Firefox that causes the browser to lock up after displaying a message warning the computer is running a pirated version of Windows that has been hacked... The message then advises the person to call a toll-free number in the next five minutes or face having the computer disabled...

Jérôme Segura, head of threat intelligence at security provider Malwarebytes, said the Firefox bug is being exploited by several sites... On Monday, Segura reported the bug to the Bugzilla forum. He said he has since received word Mozilla is actively working on a fix. In a statement sent seven hours after this post went live, a Mozilla representative wrote: "We are working on a fix to the authentication prompt bug that we expect to land in the next couple of releases (either in Firefox 71 or 72)."

Businesses

WeWork Says It Will Divest All 'Non-Core' Businesses (cnbc.com) 42

WeWork released Friday a "90-day game plan" that details sweeping changes to its businesses, including a divestiture of all "non-core businesses" and a reduction in headcount. CNBC reports: The changes are detailed in a nearly 50-page presentation, which was first put together in October as part of a pitch to investors, but was made public on Friday. WeWork said it plans to divest several of its side ventures, including content marketing platform Conductor, women-focused co-working start-up The Wing, office management platform Managed by Q, Meetup, real estate-focused start-up SpaceIQ, workplace software company Teem and Wave Garden, a maker of wave pools.

The company expects job cuts to occur across its ventures, G&A and growth-related functions, but said the community teams, which oversee WeWork's physical locations, will not be impacted as a result of the move. WeWork plans to focus on the core office-sharing desk business, in an effort to turn around the struggling company, as well as "re-energize employees" and "realign performance incentives." Specifically, the company plans to turn its focus toward enterprise customers, rather than the small and mid-sized businesses, such as start-ups, that it offered leases to in the past.
The company also said that it would be led by "proven executives in membership-focused, subscription-based businesses" moving forward, instead of being primarily "founder-led."
Security

'Platinum' Hacking Group Strikes Again With Complex Titanium Backdoor To Windows (securelist.com) 14

Freshly Exhumed shares a report from Securelist: Platinum is one of the most technologically advanced APT actors with a traditional focus on the APAC region. During recent analysis we discovered Platinum using a new backdoor that we call Titanium (named after a password to one of the self-executable archives). Titanium is the final result of a sequence of dropping, downloading and installing stages. The malware hides at every step by mimicking common software (protection related, sound drivers software, DVD video creation tools).

The Titanium APT has a very complicated infiltration scheme. It involves numerous steps and requires good coordination between all of them. In addition, none of the files in the file system can be detected as malicious due to the use of encryption and fileless technologies. One other feature that makes detection harder is the mimicking of well-known software.
One of the methods Titanium uses to infect its targets and spread is via a local intranet that has already been compromised with malware. Another is via an SFX archive containing a Windows task installation script. A third is shellcode that gets injected into the winlogon.exe process (it's still unknown how this happens).
Firefox

Firefox Turns 15 (fastcompany.com) 50

harrymcc writes: On November 9 2004, a new version of Mozilla's browser called Firefox shipped. It was taking on one of the most daunting monopolies in tech: Microsoft's Internet Explorer, which had more than 90 percent market share. But Firefox was really good, and it became an instant hit, ending Microsoft's dominance of the web. Over at Fast Company, Sean Captain took a look at the browser's original rise, the challenges it faced after Google's Chrome arrived on the scene, and the moves it's currently making to put user privacy first.
Security

DNS-over-HTTPS Will Eventually Roll Out in All Major Browsers, Despite ISP Opposition (zdnet.com) 119

All major browsers -- including Chrome, Firefox, Safari, Opera, Microsoft Edge, Vivaldi, Brave -- have plans to support DNS-over-HTTPS (or DoH), a protocol that encrypts DNS traffic and helps improve a user's privacy on the web. From a report: The DoH protocol has been one of the year's hot topics. It's a protocol that, when deployed inside a browser, it allows the browser to hide DNS requests and responses inside regular-looking HTTPS traffic. Doing this makes a user's DNS traffic invisible to third-party network observers, such as ISPs. But while users love DoH and have deemed it a privacy boon, ISPs, networking operators, and cyber-security vendors hate it. A UK ISP called Mozilla an "internet villain" for its plans to roll out DoH, and a Comcast-backed lobby group has been caught preparing a misleading document about DoH that they were planning to present to US lawmakers in the hopes of preventing DoH's broader rollout. However, this may be a little too late. ZDNet has spent the week reaching out to major web browser providers to gauge their future plans regarding DoH, and all vendors plan to ship it, in one form or another.
Businesses

Netflix, HBO and Cable Giants Are Exploring New Ways Such as Authentication Using Fingerprints To Crack Down on Password Sharing (bloomberg.com) 116

A coalition that includes Netflix, HBO and cable-industry titans is stepping up efforts to crack down on password sharing, discussing new measures to close a loophole that could be costing companies billions of dollars in lost revenue each year, Bloomberg reported Friday. From the report: Programmers and cable-TV distributors are considering an array of tactics to cut off people who borrow credentials from friends and relatives to access programming without paying for it. The possible measures include requiring customers to change their passwords periodically or texting codes to subscribers' phones that they would need to enter to keep watching, according to people familiar with the matter. Some TV executives want to create rules governing which devices can be used to access a cable-TV subscription outside the home. While someone logging in from a phone or tablet would be fine, someone using a Roku device at a second location could be considered a likely freeloader, one person said. If none of those tactics work, pay-TV subscribers could someday be required to sign into their accounts using their thumbprints.
Security

Ransomware, Data Breaches At Hospitals Tied To Uptick In Fatal Heart Attacks (krebsonsecurity.com) 35

New submitter byteme01 writes: Hospitals that have been hit by a data breach or ransomware attack can expect to see an increase in the death rate among heart patients in the following months or years because of cybersecurity remediation efforts, a new study posits. Health industry experts say the findings should prompt a larger review of how security -- or the lack thereof -- may be impacting patient outcomes. Researchers at Vanderbilt University's Owen Graduate School of Management took the Department of Health and Human Services (HHS) list of healthcare data breaches and used it to drill down on data about patient mortality rates at more than 3,000 Medicare-certified hospitals, about 10 percent of which had experienced a data breach. As PBS noted in its coverage of the Vanderbilt study, after data breaches as many as 36 additional deaths per 10,000 heart attacks occurred annually at the hundreds of hospitals examined. The researchers found that for care centers that experienced a breach, it took an additional 2.7 minutes for suspected heart attack patients to receive an electrocardiogram.
Programming

Microsoft's Rust Experiments Are Going Well, But Some Features Are Missing (zdnet.com) 33

Microsoft gave a status update today on its experiments on using the Rust programming language instead of C and C++ to write Windows components. From a report: Microsoft began experimenting with Rust over the summer. The Redmond-based software giant said it was interested in Rust because, over the past decade, more than 70% of the security patches it shipped out fixed memory-related bugs, an issue that Rust was created to address.

[...] Today, almost four months later, we got the first feedback. "I've been tasked with an experimental rewrite of a low-level system component of the Windows codebase (sorry, we can't say which one yet)," said Adam Burch, Software Engineer at the Microsoft Hyper-V team, in a blog post today. "Though the project is not yet finished, I can say that my experience with Rust has been generally positive," Burch added. "In general, new components or existing components with clean interfaces will be the easiest to port to Rust," the Microsoft engineer said. However, not all things went smoothly. It would have been unrealistic if we expected they would. Burch cited the lack of safe transmutation, safe support for C style unions, fallible allocation, and a lack of support for at-scale unit testing, needed for Microsoft's sprawling code-testing infrastructure.

Privacy

DHS Will Soon Have Biometric Data On Nearly 260 Million People (qz.com) 40

The U.S. Department of Homeland Security (DHS) expects to have face, fingerprint, and iris scans of at least 259 million people in its biometrics database by 2022, according to a recent presentation from the agency's Office of Procurement Operations reviewed by Quartz. From the report: That's about 40 million more than the agency's 2017 projections, which estimated 220 million unique identities by 2022, according to previous figures cited by the Electronic Frontier Foundation (EFF), a San Francisco-based privacy rights nonprofit.

A slide deck, shared with attendees at an Oct. 30 DHS industry day, includes a breakdown of what its systems currently contain, as well as an estimate of what the next few years will bring. The agency is transitioning from a legacy system called IDENT to a cloud-based system (hosted by Amazon Web Services) known as Homeland Advanced Recognition Technology, or HART. The biometrics collection maintained by DHS is the world's second-largest, behind only India's countrywide biometric ID network in size. The traveler data kept by DHS is shared with other U.S. agencies, state and local law enforcement, as well as foreign governments.

Wireless Networking

Amazon Ring Doorbells Exposed Home Wi-Fi Passwords To Hackers (techcrunch.com) 25

An anonymous reader quotes a report from TechCrunch: Security researchers have discovered a vulnerability in Ring doorbells that exposed the passwords for the Wi-Fi networks to which they were connected. Bitdefender said the Amazon-owned doorbell was sending owners' Wi-Fi passwords in cleartext as the doorbell joins the local network, allowing nearby hackers to intercept the Wi-Fi password and gain access to the network to launch larger attacks or conduct surveillance.

"When first configuring the device, the smartphone app must send the wireless network credentials. This takes place in an unsecure manner, through an unprotected access point," said Bitdefender. "Once this network is up, the app connects to it automatically, queries the device, then sends the credentials to the local network." But all of this is carried out over an unencrypted connection, exposing the Wi-Fi password that is sent over the air. Amazon fixed the vulnerability in all Ring devices in September, but the vulnerability was only disclosed today.

Communications

A Ton of People Received Text Messages Overnight That Were Originally Sent on Valentine's Day (theverge.com) 82

Something strange is happening with text messages in the US right now. Overnight, a multitude of people received text messages that appear to have originally been sent on or around Valentine's Day 2019. From a report: These people never received the text messages in the first place; the people who sent the messages had no idea that they had never been received, and they did nothing to attempt to resend them overnight. Delayed messages were sent from and received by both iPhones and Android phones, and the messages seem to have been sent and received across all major carriers in the US. Many of the complaints involve T-Mobile or Sprint, although AT&T and Verizon have been mentioned as well. People using regional US carriers, carriers in Canada, and even Google Voice also seem to have experienced delays. At fault seems to be a system that multiple cell carriers use for messaging. A Sprint spokesperson said a "maintenance update" last night caused the error.

Slashdot Top Deals