Google

Chronicle, the Google Moonshot Cybersecurity Startup That Was Supposed To Completely Change the Industry, is Imploding (vice.com) 41

Lorenzo Franceschi-Bicchierai and Joseph Cox, reporting for Motherboard: In early 2018, Google's parent conglomerate Alphabet announced the birth of a new "independent" startup that was supposed to revolutionize cybersecurity. Chronicle was meant to be a new type of startup. One of its products was designed to structure, organize, and help companies understand their security related data -- a "Google Photos for businesses' network security," as Forbes put it when the company announced its first product this year. The promise was radical: Chronicle would leverage machine learning and Alphabet's near-endless well of security telemetry data about known malware and internet infrastructure and use it to help security teams at companies detect intrusions that could threaten a company's network. Crucially, Chronicle would also remain independent from Google, according to Stephen Gillett, the startup's CEO.

"We want to 10x the speed and impact of security teams' work by making it much easier, faster and more cost-effective for them to capture and analyze security signals that have previously been too difficult and expensive to find," Gillett wrote in a blog post announcing Chronicle. "We know this mission is going to take years, but we're committed to seeing it through." At the time it was unclear what Chronicle was going to be. But industry observers were excited for what they thought was going to be a significant disruptor in an industry that is full of relatively old technologies such as antivirus and firewalls, is rife with products that offer solutions in search of a problem and outright snake oil. "Chronicle is dead," a current employee told Motherboard. "Stephen [Gillett] and Google killed it." Employees have left because of a combination of Chronicle losing its original vision, a distant CEO, a lack of clarity about Chronicle's future, and disappointment that the startup has been swallowed into Google, according to interviews with five current and former employees who were present across different stages of Chronicle's growth.

Security

Trend Micro Security Incident Involving Selling Customer Data Was an Inside Job (betanews.com) 16

Mark Wilson shares a report from BetaNews: Security firm Trend Micro has revealed details of an inside scam which led to personal details of its customers being exposed. The security incident dates back to August this year, and the company says that it was made aware of customers being contacted by fake Trend Micro support staff. Following an investigation lasting until the end of October, it was determined that it was a member of staff that had fraudulently gained access to a customer database and sold personal data to a third party.

Trend Micro says that the employee was able to access names, email addresses, support ticket numbers and telephone numbers, stressing that it was an inside job and not an external hack. The finger of blame points squarely at "a Trend Micro employee who improperly accessed the data with a clear criminal intent", and law enforcement is now involved. While the company says that the incident affects less that 1 percent of its 12 million consumer customers, this still means that the details of over 100,000 people could have been exposed.

Security

Google Asks Three Mobile Security Firms To Help Scan Play Store Apps (zdnet.com) 13

Google announced today that it partnered with three private cyber-security firms -- ESET, Lookout, and Zimperium -- to start a new project called the App Defense Alliance. From a report: The purpose of this new project, Google said, was to unify malware and threat detection engines and improve the security scans that Android apps go through before being published on the Play Store. Currently, when an app developer creates and submits an Android to be listed on the official Play Store, the app is scanned by Google employees with a system called Bouncer and another called Google Play Protect. In the past, Google said that both systems have been able to detect thousands of malicious Android apps submitted to the Play Store. However, while this system has been efficient, it hasn't been perfect, and many malicious apps slipped through across the years, from banking trojans to ransomware strains. Over the past few years, Android malware authors have also adopted to counteract and negate Bouncer and Play Protect scans.
Security

This Website Has Solved Cybersecurity (vice.com) 47

A new parody website generates random excuses to explain why companies got hacked and apologizes to their users. From a report: Big companies that hold our personal data get hacked almost every day, but most don't really know how to deal with getting hacked, especially when it comes to telling users what happened. If you've read some data breach disclosures or notices, you know the classic "we take your privacy and security seriously" -- truly the "thoughts and prayers" of cybersecurity. No matter how bad the hack is, companies always have an excuse. Luckily, there's now a website that automatically generates more original, and entertaining, apologies you can use if your company gets hacked. It's called "Why the fuck was I breached?" and its excuse generating algorithm spills out truly hilarious excuses.

Here are a few examples:
"The fucking hacking people used Heartbleed to hack the coffee maker. But we have since worked with industry leading specialists, so it will never happen again."
"The fucking Fancy Bears used a vulnerability in Windows XP SP1 to hack the coffee maker. But we have since worked with industry leading specialists, so it will never happen again."
"The fucking Iranians used the open door in our basement to transfer 7 petabytes of data. But we have since upskilled our cafeteria staff, so it will never happen again."
"The fucking teenage hacking prodigies used nefarious techniques to partially disrupt our services. But we have since watched a YouTube video on cyber security, so it will never happen again."
"The fucking cyber terrorists used IoT malware to extract some private keys. But we have since worked with law enforcement, so it will never happen again."

Android

The Original Google Pixel Will Get One Final Update In December (theverge.com) 47

Google has confirmed to The Verge that it will release "one final software update" next month for the original Google Pixel and Pixel XL. From the report: As of yesterday, it looked like the original Pixel was done getting updates, as Google released its November security update for most Pixel phones, but nothing for the Pixel or Pixel XL. Google tells The Verge that the Pixels won't get that November update, but it says December's "encapsulates a variety of updates" from the November and December updates that were issued for other Pixels.

It wasn't too surprising to see that Google's original Pixels didn't get yesterday's update. When Google announced the phones in 2016, the company said they would get two years of guaranteed Android version updates and three years of security updates, which is also reflected on Google's support page. That said, Google surprised Pixel owners earlier this year by letting them run Android 10, which is one more year of Android than Google originally promised, and now, they have one final update to look forward to as well.

The Almighty Buck

A Glitch in Robinhood App is Allowing Users To Trade Stocks With Excess Borrowed Funds, Giving Them Access To What Amounts To Free Money (bloomberg.com) 68

Dubbed the "infinite money cheat code" by users of Reddit's WallStreetBets forum, the bug is being exploited, according to users on the forum. One trader bragged about a $1 million position funded by a $4,000 deposit. From a report: Robinhood is "aware of the isolated situations and communicating directly with customers," spokesperson Lavinia Chirico said in an email response to questions. The Menlo Park, California-based money-management software designer touts trading "free from commission fees." Robinhood Gold customers are invited to "supercharge" their investing by paying $5 a month to trade on margin, or money borrowed from the company. Here's how the trade works. Users of Robinhood Gold are selling covered calls using money borrowed from Robinhood. Nothing wrong with that. The problem arises when Robinhood incorrectly adds the value of those calls to the user's own capital. And that means that the more money a user borrows, the more money Robinhood will lend them for future trading. One trader managed to turn his $2,000 deposit into $50,000 worth of purchasing power, which he used to buy Apple puts.
Security

Don't Reboot Your Computer After You've Been Infected With Ransomware, Experts Say (zdnet.com) 56

Security experts don't recommend that users reboot their computers after suffering a ransomware infection, as this could help the malware in certain circumstances. From a report: Instead, experts recommend that victims power down the computer, disconnect it from their network, and reach out to a professional IT support firm. Experts are recommending against PC reboots because a recent survey of 1,180 US adults who fell victim to ransomware in the past years has shown that almost 30% of victims chose to reboot their computers as a way to deal with the infection. But while rebooting in safe mode is a good way of removing older screenlocker types of ransomware, it is not recommended when dealing with modern ransomware versions that encrypt files.

"Generally, the [ransomware] executable that actually encrypts your data is designed to crawl through attached, mapped and mounted drives to a given machine. Sometimes it trips, or is blocked by a permission issue and will stop encrypting," Bill Siegel, CEO & Co-Founder of Coveware, a company that provides ransomware data recovery services told ZDNet in an email this week. "If you reboot the machine, it will start back up and try to finish the job," Siegel said.

Businesses

GitLab Considers Ban On New Hires In China and Russia Due To Espionage Fears (zdnet.com) 41

GitLab is considering blocking new hires from countries such as China and Russia over espionage fears. "There is a general train of thought that both Russian and Chinese intelligence agencies might use the same blueprint and plant agents or coerce GitLab staff into handing over data belonging to western companies," reports ZDNet. An anonymous reader shares an excerpt from the report: Eric Johnson, VP of Engineering at GitLab, said discussions on banning new hires from the two countries began after enterprise customers expressed concerns about the geopolitical climate of the two countries. If approved, the hiring ban will apply to two positions; namely Site Reliability Engineer and Support Engineer, the two positions that handle providing tech support to GitLab's enterprise customers. Johnson said these two support staff positions have full access to customers' data, something that companies had an issue with, especially if tech support staff was to be located in countries like China and Russia, where they could be compromised or coerced by local intelligence services. Johnson said GitLab does not have "a technical way" to support data access permission systems for employees based on their country of origin. "Doing so would also force us to confront the possibility of creating a 'second class of citizens' on certain teams who cannot take part in 100% of their responsibilities," Johnson said.

The new "hiring ban" is not yet final. Open conversations on the topic started last month, and are scheduled to end November 6.
Security

Android Bug Lets Hackers Plant Malware Via NFC Beaming (zdnet.com) 14

An anonymous reader quotes a report from ZDNet: Google patched last month an Android bug that can let hackers spread malware to a nearby phone via a little-known Android OS feature called NFC beaming. NFC beaming works via an internal Android OS service known as Android Beam. This service allows an Android device to send data such as images, files, videos, or even apps, to another nearby device using NFC (Near-Field Communication) radio waves, as an alternative to WiFi or Bluetooth. Typically, apps (APK files) sent via NFC beaming are stored on disk and a notification is shown on screen. The notification asks the device owner if he wants to allow the NFC service to install an app from an unknown source. But, in January this year, a security researcher named Y. Shafranovich discovered that apps sent via NFC beaming on Android 8 (Oreo) or later versions would not show this prompt. Instead, the notification would allow the user to install the app with one tap, without any security warning.

The CVE-2019-2114 bug resided in the fact that the Android Beam app was also whitelisted, receiving the same level of trust as the official Play Store app. Google said this wasn't meant to happen, as the Android Beam service was never meant as a way to install applications, but merely as a way to transfer data from device to device. The October 2019 Android patches removed the Android Beam service from the OS whitelist of trusted sources. However, many millions of users remain at risk. If users have the NFC service and the Android Beam service enabled, a nearby attacker could plant malware (malicious apps) on their phones.
Since most newly-sold devices have the NFC feature enabled by default, you'll have to disable Android Beam and NFC or update your phone to receive the October 2019 security updates if you want to protect yourself from this bug.
Security

With a Laser, Researchers Say They Can Hack Alexa, Google Home or Siri (nytimes.com) 65

Researchers in Japan and at the University of Michigan said Monday that they have found a way to take over Google Home, Amazon's Alexa or Apple's Siri devices from hundreds of feet away by shining laser pointers, and even flashlights, at the devices' microphones. The New York Times reports: In one case, they said, they opened a garage door by shining a laser beam at a voice assistant that was connected to it. They also climbed 140 feet to the top of a bell tower at the University of Michigan and successfully controlled a Google Home device on the fourth floor of an office building 230 feet away. And by focusing their lasers using a telephoto lens, they said, they were able to hijack a voice assistant more than 350 feet away. Opening the garage door was easy, the researchers said. With the light commands, the researchers could have hijacked any digital smart systems attached to the voice-controlled assistants.

They said they could have easily switched light switches on and off, made online purchases or opened a front door protected by a smart lock. They even could have remotely unlocked or started a car that was connected to the device. The researchers, who studied the light flaw for seven months, said they had discovered that the microphones in the devices would respond to light as if it were sound. Inside each microphone is a small plate called a diaphragm that moves when sound hits it. That movement can be replicated by focusing a laser or a flashlight at the diaphragm, which converts it into electric signals, they said. The rest of the system then responds the way it would to sound.
While the researchers said they had notified several companies to the light vulnerability, most microphones would need to be redesigned to remedy the problem. And simply covering the microphone with a piece of tape wouldn't solve it.

The findings of the vulnerability can be found here.
Firefox

ISPs Lied To Congress To Spread Confusion About Encrypted DNS, Mozilla Says (arstechnica.com) 70

An anonymous reader quotes a report from Ars Technica: Mozilla is urging Congress to reject the broadband industry's lobbying campaign against encrypted DNS in Firefox and Chrome. The Internet providers' fight against this privacy feature raises questions about how they use broadband customers' Web-browsing data, Mozilla wrote in a letter sent today to the chairs and ranking members of three House of Representatives committees. Mozilla also said that Internet providers have been giving inaccurate information to lawmakers and urged Congress to "publicly probe current ISP data collection and use policies." DNS over HTTPS helps keep eavesdroppers from seeing what DNS lookups your browser is making. This can make it more difficult for ISPs or other third parties to monitor what websites you visit.

"Unsurprisingly, our work on DoH [DNS over HTTPS] has prompted a campaign to forestall these privacy and security protections, as demonstrated by the recent letter to Congress from major telecommunications associations. That letter contained a number of factual inaccuracies," Mozilla Senior Director of Trust and Security Marshall Erwin wrote. This part of Erwin's letter referred to an Ars article in which we examined the ISPs' claims, which center largely around Google's plans for Chrome. The broadband industry claimed that Google plans to automatically switch Chrome users to its own DNS service, but that's not what Google says it is doing. Google's publicly announced plan is to "check if the user's current DNS provider is among a list of DoH-compatible providers, and upgrade to the equivalent DoH service from the same provider." If the user-selected DNS service is not on that list, Chrome would make no changes for that user.

Microsoft

Microsoft Launches Public Previews of Visual Studio Online and Power Virtual Agents (venturebeat.com) 43

An anonymous reader writes: At Ignite 2019 today, Microsoft launched Visual Studio Online public preview. Visual Studio Online meshes Visual Studio, cloud-hosted developer environments, and a web-based editor. AI, big data, and cloud computing are shifting development beyond the "standard issue development laptop," and Visual Studio Online is clearly a reflection of this trend. "Visual Studio Online philosophically (and technically) extends Visual Studio Code Remote Development to provide managed development environments that can be created on-demand and accessed from anywhere," Microsoft explained today. "These environments can be used for long-term projects, to quickly prototype a new feature, or for short-term tasks, like reviewing pull requests." The company also announced the public preview of its Power Virtual Agents tool, a new no-code tool for building chatbots that's part of the company's Power Platform, which also includes Microsoft Flow automation tool, which is being renamed to Power Automate today, and Power BI. From a report: Built on top of Azure's existing AI smarts and tools for building bots, Power Virtual Agents promises to make building a chatbot almost as easy as writing a Word document. With this, anybody within an organization could build a bot that walks a new employee through the onboarding experience for example. "Power virtual agent is the newest addition to the Power Platform family," said Microsoft's Charles Lamanna. "Power Virtual Agent is very much focused on the same type of low code, accessible to anybody, no matter whether they're a business user or business analyst or professional developer, to go build a conversational agent that's AI-driven and can actually solve problems for your employees, for your customers, for your partners, in a very natural way." Further reading: Microsoft rebrands Flow as Power Automate, adds RPA features and virtual agents; and Visual Studio IntelliCode gets whole-line code completions, dynamic refactoring detection.
Data Storage

Microsoft and Warner Bros. Archived the Original 'Superman' Movie on a Futuristic Glass Disc (variety.com) 93

Microsoft has teamed up with Warner Bros. to text. The collaboration, which was unveiled at Microsoft's Ignite 2019 conference in Orlando, Florida Monday, is a first test case for a new storage technology that could eventually help safeguard Hollywood's movies and TV shows, as well as many other forms of data, for centuries to come. From a report: "Glass has a very, very long lifetime," said Microsoft Research principal researcher Ant Rowstron in a recent conversation with Variety. "Thousands of years." The piece of silica glass storing the 1978 "Superman" movie, measures 7.5 cm x 7.5 cm x 2 mm. The glass contains 75.6 GB of data plus error redundancy codes. Microsoft began to investigate glass as a storage medium in 2016 in partnership with the University of Southampton Optoelectonics Research Centre. The goal of these efforts, dubbed "Project Silica," is to find a new storage medium optimized for what industry insiders like to call cold data -- the type of data you likely won't need to access for months, years, or even decades. It's data that doesn't need to sit on a server, ready to be used 24/7, but that is kept in a vault, away from anything that could corrupt it.

Turns out that Warner Bros. has quite a bit of this kind of cold data. Founded in the 1920s, the studio has been safekeeping original celluloid film reels, audio from 1940s radio shows and much more, for decades. Think classics like "Casablanca," "The Wizard of Oz" or "Looney Tunes" cartoons. "Our mission is to preserve those original assets in perpetuity," said Brad Collar, who is leading these efforts at Warner Bros. as the studio's senior vice president of global archives and media engineering. And while the studio is deeply invested in these classics, it also keeps adding an ever-increasing number of modern assets to its archives, ranging from digitally-shot films and television episodes to newer forms of entertainment, including video games. To date, the Warner Bros. archive contains some 20 million assets, with tens of thousands of new items being added every year. Each of them is being stored in multiple locations, explained Collar. "We want to have more than one copy."

Microsoft

What Happened When Microsoft Tried A Four-Day Work Week (mspoweruser.com) 253

MS Power User reports on the results of a 2,300-employee experiment by Microsoft with a four-day work week: In August this year, Microsoft Japan ran an experiment where for one month they had a 3 day weekend, taking Friday off. This was paid leave and did not impact the worker's usual vacation allocation.

Some results were predictable. Workers were happier and took 25.4 percent fewer days off during the month. There were also savings from spending less time at work. 23.1 percent less electricity was used and 58.7 percent fewer pages were printed. More importantly from a bottom-line standpoint, however, productivity went up 39.9%, as fewer and shorter meetings were held, often virtually rather than in person.

Windows

A Widespread BlueKeep 'Exploit' Is Targetting Unpatched Windows 7/XP Computers (forbes.com) 38

An anonymous reader quotes Forbes: When Microsoft issued the first patch in years for Windows XP in May 2019, you knew that something big was brewing. That something was a wormable Windows vulnerability that security experts warned could have a similar impact as the WannaCry worm from 2017. The BlueKeep vulnerability exists in unpatched versions of Windows Server 2003, Windows XP, Windows Vista, Windows 7, Windows Server 2008 and Windows Server 2008 R2: and it's now been confirmed that a BlueKeep exploit attack is currently ongoing...

Security researchers, including Kevin Beaumont who originally named the vulnerability and Marcus Hutchins (also known as MalwareTech) who was responsible for hitting the kill switch that stopped the WannaCry, have confirmed that a widespread BlueKeep exploit attack is now currently underway. Hutchins told Wired that "BlueKeep has been out there for a while now. But this is the first instance where I've seen it being used on a mass scale." It would appear that rather than a wormable threat, where the BlueKeep exploit could spread itself from one machine to another, the attackers are searching for vulnerable unpatched Windows systems that have Remote Desktop Services (RDP) 3389 ports exposed to the internet. This dampens the panic that there could be another WannaCry about to happen, although the potential for such a scenario, albeit on a much smaller scale, certainly remains. For now though, this looks like being an attack campaign with a cryptocurrency miner payload.

While there is always the possibility that the threat actors behind this attack could drop more malicious payloads than a crypto-miner, for now, this acts as yet another warning for users of the 700,000 or so still vulnerable Windows systems to get patching... Seriously folks, if you are using one of the vulnerable versions of Windows, then what more is it going to take to get you to apply the update that fixes the BlueKeep vulnerability?

Security

Study Estimates 50% of WebAssembly Sites Are Using It For Malicious Purposes (infoq.com) 89

InfoQ reports on surprising results from research sponsored by the Institutes for Application Security and System Security at Germany's Technische UniversitÃt Braunschweig: A study published in June 2019 reveals that in the Alexa Top 1 million websites, one out of 600 sites executes WebAssembly (Wasm) code. The study moreover finds that over 50% of those sites using WebAssembly apply it for malicious deeds, such as cryptocurrency mining and malware code obfuscation....
BR> The team examined the websites in the Alexa sample over a time span of four days, and successfully studied 947,704 websites, eventually visiting 3,465,320 web pages... 1,950 Wasm modules were found on 1,639 sites... The research team manually categorized the Wasm modules in 6 categories, reflecting the purpose behind the use of WebAssembly: Custom, Game, Library, Mining, Obfuscation, and Test. Of these six categories, two (Mining -- 55.6% of website sample, and Obfuscation -- 0.2% of websites sample) represent malicious usage of WebAssembly. The study details, "The largest observed category implements a cryptocurrency miner in WebAssembly, for which we found 48 unique samples on 913 sites in the Alexa Top 1 Million....

"[The study] suggests that we are currently only seeing the tip of the iceberg of a new generation of malware.... In consequence, incorporating the analysis of WebAssembly code hence is going to be of essence for effective future defense mechanisms."

The Internet

Data Breaches Reported at NetworkSolutions, Register.com, and Web.com (krebsonsecurity.com) 17

"Top domain name registrars NetworkSolutions.com, Register.com and Web.com are asking customers to reset their passwords after discovering an intrusion in August 2019 in which customer account information was accessed," reports security researcher Brian Krebs: "On October 16, 2019, Web.com determined that a third-party gained unauthorized access to a limited number of its computer systems in late August 2019, and as a result, account information may have been accessed," Web.com said in a written statement. "No credit card data was compromised as a result of this incident." The Jacksonville, Fla.-based Web.com said the information exposed includes "contact details such as name, address, phone numbers, email address and information about the services that we offer to a given account holder...."

Both Network Solutions and Register.com are owned by Web.com. Network Solutions is now the world's fifth-largest domain name registrar, with almost seven million domains in its stable, according to domainstate.com; Register.com listed at #17 with 1.7 million domains.... Web.com said it has reported the incident to law enforcement and hired an outside security firm to investigate further, and is in the process of notifying affected customers through email and via its website....

Web.com wasn't clear how long the intrusion lasted, but if the breach wasn't detected until mid-October that means the intruders potentially had about six weeks inside unnoticed. That's a long time for an adversary to wander about one's network, and plenty of time to steal a great deal more information than just names, addresses and phone numbers.

Privacy

DNA Databases Are a National Security Leak Waiting To Happen (technologyreview.com) 35

schwit1 writes: A private DNA ancestry database that's been used by police to catch criminals is a security risk from which a nation-state could steal DNA data on a million Americans, according to security researchers. Security flaws in the service, called GEDmatch, not only risk exposing people's genetic health information but could let an adversary such as China or Russia create a powerful biometric database useful for identifying nearly any American from a DNA sample. GEDMatch, which crowdsources DNA profiles, was created by genealogy enthusiasts to let people search for relatives and is run entirely by volunteers. It shows how a trend toward sharing DNA data online can create privacy risks affecting everyone, even people who don't choose to share their own information.

"You can replace your credit card number, but you can't replace your genome," says Peter Ney, a postdoctoral researcher in computer science at the University of Washington. Ney, along with professors and DNA security researchers Luis Ceze and Tadayoshi Kohno, described in a report posted online how they developed and tested a novel attack employing DNA data they uploaded to GEDmatch. Using specially designed DNA profiles, they say, they were able to run searches that let them guess more than 90% of the DNA data of other users. The founder of GEDmatch, Curtis Rogers, confirmed that the researchers alerted him to the threat during the summer.
"The same attack wouldn't work on other genealogy sites, like 23andMe, because they don't permit data uploads," the report notes. "Others, like MyHeritage, do allow uploads but don't give users as much information about their matches."

"The problem with GEDmatch is the browser is too good, and searches too deeply," says Erlich. "If I were them, I would remove it, fix it, then put it back."
Security

NordVPN Users' Passwords Exposed In Mass Credential-Stuffing Attacks (arstechnica.com) 13

Last week, NordVPN disclosed a server hack that leaked crypto keys. While the scope of the breach is still being determined, Ars Technica's Dan Goodin reports that NordVPN users' passwords were exposed and at least one site still features user credentials, which include email addresses, plain-text passwords, and expiration dates associated with the accounts. An anonymous Slashdot reader shares an excerpt from his report: I received a list of 753 credentials on Thursday and polled a small sample of users. The passwords listed for all but one were still in use. The one user who had changed their password did so after receiving an unrequested password reset email. It would appear someone who gained unauthorized access was trying to take over the account. Several other people said their accounts had been accessed by unauthorized people. Over the past week, breach notification service Have I Been Pwned has reported at least 10 lists of NordVPN credentials similar to the one I obtained. While it's likely that some accounts are listed in multiple lists, the number of user accounts easily tops 2,000. What's more, a large number of the email addresses in the list I received weren't indexed at all by Have I Been Pwned, indicating that some compromised credentials are still leaking into public view. Most of the Web pages that host these credentials have been taken down, but at the time this post was going live, at least one remained available on Pastebin, despite the fact Ars brought it to NordVPN's attention more than 17 hours earlier.

Without exception, all of the plain-text passwords are weak. In some cases, they're the string of characters to the left of the @ sign in the email address. In other cases, they're words found in most dictionaries. Others appear to be surnames, sometimes with two or three numbers tacked onto the end. These common traits mean that the most likely way these passwords became public is through credential stuffing. That's the term for attacks that take credentials divulged in one leak to break into other accounts that use the same username and password. Attackers typically use automated scripts to carry out these attacks.

Microsoft

Microsoft is Replacing MSDN and TechNet Forums With Microsoft Q&A (zdnet.com) 31

Microsoft has been slowly dismantling its MSDN and TechNet blogging platforms for the past year-plus. This week, Microsoft introduced something meant to replace the MSDN and TechNet forums: A preview of Microsoft Q&A. From a report: Microsoft officials said they are making the switch because its MSDN and TechNet forums are outdated, according to a Frequently Asked Questions page about the new Q&A site. The new Q&A experience is part of the larger docs.microsoft.com platform. It is designed to offer "relevant and timely answers to your technical problems from a community of experts and Microsoft engineers." The new service will allow users to follow posts, tags or people to get information; provide suggested answers as users type their questions; and the ability to bookmark content for future reference. Q&A uses the same user authentication as Microsoft Docs and Learn. Experts will earn Reputation Points for answers they provide.

Slashdot Top Deals