Security

Google Discloses Chrome Zero-Day Exploited in the Wild (zdnet.com) 17

Yesterday, on late Halloween night, Google engineers delivered the best scare of the evening and released an urgent update for the Chrome browser to patch an actively exploited zero-day. From a report: "Google is aware of reports that an exploit for CVE-2019-13720 exists in the wild," Google engineers said in a blog post announcing the new v78.0.3904.87 release. The actively-exploited zero-day was described as a use-aster-free bug in Chrome's audio component. Use-after-free vulnerabilities are memory corruption bugs that occur when an application tries to reference memory that was previously assigned to it but has been freed or deleted in the meantime. This usually causes a program to crash, but can also sometimes lead to other, unintended consequences, such as code execution scenarios. Google credited Anton Ivanov and Alexey Kulaev, two malware researchers from Kaspersky, with reporting the issue. According to a blog post published after this article's publication, Kaspersky said the zero-day was being used to install malware on user devices. It was being deployed on user devices via a Korean-language news portal.
Facebook

Facebook, Mozilla, and Cloudflare Announce New TLS Delegated Credentials Standard (zdnet.com) 25

Facebook, Mozilla, and Cloudflare announced today a new technical specification called TLS Delegated Credentials, currently undergoing standardization at the Internet Engineering Task Force (IETF). From a report: The new standard will work as an extension to TLS, a cryptographic protocol that underpins the more widely-known HTTPS protocol, used for loading websites inside browsers via an encrypted connection. The TLS Delegate Credentials extension was specifically developed for large website setups, such as Facebook, or for website using content delivery networks (CDNs), such as Cloudflare. For example, a big website like Facebook has thousands of servers spread all over the world. In order to support HTTPS traffic on all, Facebook has to place a copy of its TLS certificate private key on each one. This is a dangerous setup. If an attacker hacks one server and steals the TLS private key, the attacker can impersonate Facebook servers and intercept user traffic until the stolen certificate expires. The same thing is also valid with CDN services like Cloudflare. Anyone hosting an HTTPS website on Cloudflare's infrastructure must upload their TLS private key to Cloudflare's service, which then distributes it to thousands of servers across the world. The TLS Delegate Credentials extension allows site owners to create short-lived TLS private keys (called delegated credentials) that they can deploy to these multi-server setups, instead of the real TLS private key.
Security

Uber Allegedly Paid $100K Ransom and Had Hackers Sign NDAs After Data Breach (cbsnews.com) 20

An anonymous reader quotes a report from CBS News: New details about how Uber responded to a massive hack attack in 2016 raise questions about the way it handled sensitive customer information. Instead of reporting the hackers to police, the company allegedly paid $100,000 in exchange for a promise to delete 57 million user files the men stole off a third party server, prosecutors said. Within weeks of paying the ransom, Uber employees showed up at Brandon Glover's Winter Park, Florida, home and found Vasile Mereacre at a hotel restaurant in Toronto, Canada, the Justice Department said. The pair admitted their crimes, but Uber didn't turn them over to the cops. Instead, they had the hackers sign non-disclosure agreements, promising to keep quiet. The two hackers pleaded guilty on Wednesday.

But there was a third person involved who was unknown to Uber, U.S. attorney for Northern California Dave Anderson told CBS News correspondent Kris Van Cleave in an exclusive interview. Anderson, who investigated the hack, said there's "no way to know definitively" what actually happened to the stolen data. [...] The hackers also targeted a company owned by LinkedIn in December of 2016, but prosecutors say LinkedIn did not pay and promptly reported the hack to police. Uber eventually did as well -- a year after the hack, when new CEO, Dara Khosrowshahi, publicly disclosed the attack. The two known hackers were eventually arrested and pleaded guilty on Wednesday to conspiracy to commit extortion charges. They face a maximum of five years in prison. The third person involved remains at large.

Government

US Interior Department To Ground Its Drones Over Chinese Spying Risk (cnet.com) 33

The Interior Department is grounding its entire fleet of aerial drones (Warning: source paywalled; alternative source), one of the largest in the federal government, citing increasing concerns about the national security risk from Chinese manufacturers. The Wall Street Journal reports: The department has more than 800 drones, all of which are either made in China or have Chinese parts, according to a person familiar with the matter. The machines are used to fight forest fires, survey erosion, monitor endangered species and inspect dams. Under an order from Interior Secretary David Bernhardt on Wednesday, the drones will be grounded until the department completes a review of potential security risks of Chinese drones, said department spokesman Nick Goodwin. Exceptions will be made for emergency situations, including natural disasters or when lives are threatened, Mr. Goodwin said.

Officials worry that U.S. reliance on Chinese drones might be putting critical infrastructure at risk. They are concerned the drones may be sending information back to the Chinese government or hackers elsewhere to use for cyberattacks or other offenses. The Interior Department's decision is one of the biggest responses yet and may be the only total fleet shutdown in the federal government. It is not coordinating with the White House or other federal agencies.

Security

At Least 13 Managed Service Providers Were Used To Push Ransomware This Year (zdnet.com) 9

A new report published this week by threat intelligence firm Armor puts the number of managed service providers (MSPs) that got hit with ransomware this year at 13, possibly more. From a report: For those unfamiliar with the term, a managed service provider is a company that manages a customer's IT infrastructure using remote administration tools. MSPs have been around since the 90s, with the dawn of large computer fleets; however, they've been catching on with more and more companies in recent years. [...] Starting this year, ransomware gangs have realized that they could compromise the network of an MSP, and then use their remote access tools to deploy ransomware on the MSP's customer networks, infecting hundreds of companies and thousands of computers, all at once, with the push of a few buttons. In a report published this week, Armor took a deeper look at the entire MSP ecosystem and unearthed several other incidents. In total, the company found 13, but many more could be unreported.
Bug

Complaints Mounting About iOS 13.2 Being 'More Aggressive at Killing Background Apps and Tasks' (macrumors.com) 52

Apple's iOS 13 has had a rocky start since its release last month, with it being among the most buggy Apple software releases in recent memory. Now, iPhone owners are complaining of yet another issue that may be bug-related. From a report: A growing number of iPhone and iPad users have complained about poor RAM management on iOS 13 and iPadOS 13, leading to apps like Safari, YouTube, and Overcast reloading more frequently upon being reopened. We've lightly edited some of the comments to correct things like capitalization.
Privacy

WhatsApp Hacked To Spy on Top Government Officials at US Allies (reuters.com) 42

Senior government officials in multiple U.S.-allied countries were targeted earlier this year with hacking software that used Facebook's WhatsApp to take over users' phones, Reuters reported Thursday, citing people familiar with the messaging company's investigation. From a report: Sources familiar with WhatsApp's internal investigation into the breach said a "significant" portion of the known victims are high-profile government and military officials spread across at least 20 countries on five continents. The hacking of a wider group of top government officials' smartphones than previously reported suggests the WhatsApp cyber intrusion could have broad political and diplomatic consequences. WhatsApp filed a lawsuit on Tuesday against Israeli hacking tool developer NSO Group. The Facebook-owned software giant alleges that NSO Group built and sold a hacking platform that exploited a flaw in WhatsApp-owned servers to help clients hack into the cellphones of at least 1,400 users. While it is not clear who used the software to hack officials' phones, NSO says it sells its spyware exclusively to government customers.
Security

China-Linked Hackers Target Military, Government Texts, FireEye Says (bloomberg.com) 16

A state-linked Chinese hacking group is using malware to steal SMS text messages from high-ranking military and government targets, according to cybersecurity company FireEye. From a report: The hacking technology, known as MESSAGETAP, "allows China to efficiently steal data from multitudes of sources from one location," Steven Stone, FireEye's director of advanced practices, said in a statement. "Espionage-related theft and intrusions have been long occurring, but what is new is the vast scale due to the use of this tool." The company's finding, released in a blog on Thursday, underscores the growing concerns about China's use of technology for espionage and the theft of intellectual property. Telecommunications pose a special concern, as the U.S. seeks to persuade its allies not to build their next-generation networks with tools from Chinese companies such as Huawei. But even in networks that China hasn't built, sophisticated hacking operations might allow access to data. In 2019 alone, FireEye observed eight attempts to target telecommunications entities by groups with suspected links to the Chinese government. Four of these hacking attempts were conducted by the group known as APT41 that is now using MESSAGETAP.
Software

Text Editor Releases 'Free Uyghur' Edition, Gets Swamped With Chinese Spam (theverge.com) 245

An anonymous reader quotes a report from The Verge: This week, the developer of the popular text- and code-editing software Notepad++ released a new version update. Nothing seemed particularly strange about it, except maybe the name: Notepad++ v7.8.1 is the "Free Uyghur" edition. In a blog post announcing the updated version, developer Don Ho writes about the plight of the Uyghur people, an ethnic minority in China that's faced persecution from the country's authoritarian government. China operates internment camps that are used to detain Uyghur people throughout the country's Xinjiang region.

Since the announcement, the software's GitHub "issues" page has been bombarded with spam, much of it in the Chinese language. "Stop sending meaningless political-related issues, it just makes you look like an idiot," reads one comment. Another one simply reads, "Bye ! Uninstall." There's a litany of curses, and one asks, "What do you know about China?" Others have moved in to criticize the Chinese government in response. Ho told The Verge that the software's dedicated site was also under a distributed-denial-of-service attack, but that it has been stopped by an anti-DDoS service provided by the site's host.
Ho writes in the announcement that he anticipated potential pushback, saying "talking about politics is exactly what software and commercial companies generally try to avoid," but decided to take the step anyway. "The problem is," Ho writes in the announcement of the Free Uyghur edition, "if we don't deal with politics, politics will deal with us."
Software

Apple App Store Bug Reportedly Erases Over 20 Million App Ratings In a Week (techcrunch.com) 10

A bug in Apple's App Store removed more than 20 million ratings from apps both big and small. "The issue began on October 23, 2019 and wasn't resolved until yesterday, October 29," reports TechCrunch. "Apple hasn't yet explained how such a sizable and impactful change to app ratings occurred." From the report: This massive ratings drop was spotted by the mobile app insights platform Appfigures. The firm found that more than 300 apps from over 200 developers were affected by the sweep, which wiped out a total of 22 million app reviews from the App Store. On average, apps saw a 50% decrease in ratings in the affected countries, which included the U.S.

The U.S. was hit the hardest, however, as some 10 million ratings disappeared. But the sweep was global in nature, hitting all 155 countries Apple supports. China, the U.K., South Korea, Russia and Australia also felt a noticeable impact. A few apps were hit harder than others. Hulu, for example, lost a whopping 95% of ratings in the U.S., while Dropbox and Chase lost 85%. Several companies affected by the bug declined to comment, but told us that the rating removals weren't done at their request -- they were just as surprised as everyone else. Of the more than 300 apps that got hit, about half (154) saw a drop of more than 100 ratings, Appfigures said.
Some of the impacted companies (and Appfigures) confirmed to TechCrunch the missing ratings were restored as of yesterday.
Facebook

Facebook Permanently Deletes the Accounts of NSO Workers (arstechnica.com) 48

An anonymous reader quotes a report from Ars Technica: A day after Facebook-owned WhatsApp sued NSO Group, the social media platform has permanently deleted the accounts of employees who work at the Israel-based spyware maker, according to message boards and a security researcher who spoke to one worker. "Your account has been deleted for not following our terms," said a message sent to one employee by Facebook-owned Instagram. "You won't be able to log into this account, and no one else will be able to see it. We're unable to restore accounts that are deleted for these types of violations."

A message board popular in Israel indicated that the deletion was widespread. "I had just personally verified it (I have friends working there)," one person wrote. "Ninety-eight percent of the company employees were blocked." Another person who claimed to work at NSO responded to say he or she hadn't been blocked. Another person claiming to be an NSO employee complained bitterly on LinkedIn. An Israel-based security researcher who spoke to an NSO employee said the deletions affected a much smaller percentage of the company's employees and didn't involve WhatsApp accounts.

Security

NHS Pagers Are Leaking Medical Data (techcrunch.com) 29

An anonymous reader quotes a report from TechCrunch: An amateur radio rig exposed to the internet and discovered by a security researcher was collecting real-time medical data and health information broadcast by hospitals and ambulances across U.K. towns and cities. The rig, operated out of a house in North London, was picking up radio waves from over the air and translating them into readable text. The hobbyist's computer display was filling up with messages about real-time medical emergencies from across the region. For some reason, the hobbyist had set up an internet-connected webcam pointed at the display. But because there was no password on the webcam, anyone who knew where to look could also see what was on the rig's computer display.

Daley Borda, a security researcher and bug bounty hunter, stumbled upon the exposed webcam. The live stream was grainy, and the quality of the images so poor that it was just possible to make out the text on the display. "You can see details of calls coming in -- their name, address, and injury," he told TechCrunch. TechCrunch verified his findings. Messages spilling across the screen appeared to direct nearby ambulances where to go following calls to the 999 emergency services. One message said a 98-year-old man had fallen at his home address. A few moments later, another message said a 49-year-old male was complaining of chest pains at a nearby residence. One after the other, messages were flooding in, describing accidents, incidents and medical emergencies, often including their home addresses.
"The hobbyist was picking up and decoding pager communications from a nearby regional National Health Service trust," adds TechCrunch. These devices remain a fixture in UK hospitals and "allow anyone to send messages to one or many pagers at once by calling a dedicated phone number, often manned by an operator, which are then broadcast as radio waves over the pager network."

While the NHS still uses about 130,000 pagers, according to the UK government, it's not clear how many trusts are exposing medical information -- if at all.
Chrome

Google Workers Sidestepping Controversial Chrome Tool Sparks Security Worries (cnet.com) 55

Google is facing a backlash over an internal tool for the company's Chrome browser that some employees worry is intended for spying on workers organizing protests and discussing workplace issues. From a report: To get around using the tool, some employees have turned to third-party browsers. That's prompted at least one security engineer at Google to voice concern over the possible vulnerabilities that using outside software could bring. The tool is a software extension for Google's Chrome browser, which is installed on all employee computers. It's designed to activate when workers create calendar events that include more than 100 people or use more than 10 rooms. Google said the tool is a pop-up reminder that asks people to "be mindful" before setting up large meetings. But some employees have accused Google management of trying to keep tabs on big gatherings. Google has called those claims "categorically false" and said the purpose of the tool is to cut down on calendar spam. To avoid the extension, employees are encouraging each other to use browsers other than Chrome, a Google security engineer wrote in an internal forum, screenshots of which were reviewed by CNET. Those browsers include Chromium, the open-source browser foundation on which Google Chrome is built, the engineer wrote, adding that people shifting to other browsers "has an impact on overall security of this fleet."
Security

Country of Georgia Hit By Massive Cyberattack 22

An anonymous reader quotes a report from the BBC: A huge cyber-attack has knocked out more than 2,000 websites -- as well as the national TV station -- in the country of Georgia. Court websites containing case materials and personal data have also been attacked. In many cases, website home pages were replaced with an image of former President Mikheil Saakashvili, and the caption "I'll be back." The origin of the attack is not yet known. BBC Caucasus correspondent Rayhan Demytrie said people on social media were speculating that Russia might be behind it. She added that she had been told by cyber-security experts that Georgian government websites were "poorly protected and vulnerable to attack." More than 15,000 pages were affected, including the presidential website, non-government organizations and private companies.
Security

Indian Nuke Plant's Network Reportedly Hit By Malware Tied To North Korea 31

North Korea is reportedly behind a cyberattack on India's Kudankulam Nuclear Power Plant. "The malware, identified by researchers as North Korea's Dtrack, was reported by [former analyst for India's National Technical Research Organization (NTRO) Pukhraj Singh] to have gained 'domain controller-level access' at Kudankulam," reports Ars Technica. "The attack has been reported to the government." From the report: The attack likely did not affect reactor controls, but it may have targeted research and technical data. The attack apparently focused on collection of technical information, using a Windows SMB network drive share with credentials hard-coded into the malware to aggregate files to steal. Dtrack was tied to North Korea's Lazarus threat group by researchers based on code shared with DarkSeoul, a malware attack that wiped hard drives at South Korean media companies and banks in 2013.

Singh alluded to the attack in a September 7 tweet, in which he wrote, "I just witnessed a casus belli in the Indian cyberspace and it sucks at every level." He said that he did not discover the intrusion himself but learned of it from "a third party." Singh passed on the information to India's National Cyber Security Coordinator on September 4, and the third party shared the indicators of compromise "over the preceding days." Kaspersky later identified the malware involved as Dtrack, Singh said. Officials at Kudankulam have said that the plant is safe from cyber attack because the control systems network is isolated from the plant's administrative networks, but they have not addressed what data may have been stolen.
Businesses

Ask Slashdot: How Do You Spot Bullies During an Interview? 226

An anonymous reader writes: I have met approximately two bullies in my career so far in which I have had about 15 bosses. One of them I was able to spot during the interview itself but I took the job (I shouldn't have) and left five months later. The other boss only revealed his bully persona to me in secret and only to me in one-on-one meetings. I had to announce I am starting to record all meetings and he promptly fired me the next meeting, after my first month on the job. I got my old no-bully job back last month and I am happy as always, but I wish I could have detected the bully during the interview itself and avoided them.

How do you spot bullies? What commonalities have you noticed? Fun fact: I have noticed bullies start their bullying when they see you doing something they cannot do.
Android

New 'Unremovable' XHelper Malware Has Infected 45,000 Android Devices (zdnet.com) 60

An anonymous reader quotes a report from ZDNet: Over the past six months, a new Android malware strain has made a name for itself after popping up on the radar of several antivirus companies, and annoying users thanks to a self-reinstall mechanism that has made it near impossible to remove. Named xHelper, this malware was first spotted back in March but slowly expanded to infect more than 32,000 devices by August (per Malwarebytes), eventually reaching a total of 45,000 infections this month (per Symantec). The malware is on a clear upward trajectory. Symantec says the xHelper crew is making on average 131 new victims per day and around 2,400 new victims per month. Most of these infections have been spotted in India, the U.S., and Russia.

According to Malwarebytes, the source of these infections is "web redirects" that send users to web pages hosting Android apps. These sites instruct users on how to side-load unofficial Android apps from outside the Play Store. Code hidden in these apps downloads the xHelper trojan. The good news is that the trojan doesn't carry out destructive operations. According to both Malwarebytes and Symantec, for most of its operational lifespan, the trojan has shown intrusive popup ads and notification spam. The ads and notifications redirect users to the Play Store, where victims are asked to install other apps -- a means through which the xHelper gang is making money from pay-per-install commissions.
What's interesting about xHelper is that it gains access to an Android device via an initial app and installs itself as a separate self-standing service. Furthermore, you can't remove the app, as the trojan reinstalls itself every time, even after users perform a factory reset.
Communications

Facebook Sues Israel's NSO Group Over Alleged WhatsApp Hack (reuters.com) 11

Facebook on Tuesday sued Israeli cyber surveillance firm NSO Group, alleging it hacked users of its messaging platform WhatsApp earlier this year. From a report: The hacking spree targeted journalists, diplomats, human rights activists, political dissidents, senior government officials and others, Facebook said in its lawsuit, filed in U.S. District Court in San Francisco. Facebook-owned WhatsApp, which is also a plaintiff in the lawsuit, said in a statement that it believed the attack "targeted at least 100 members of civil society, which is an unmistakable pattern of abuse." Facebook is seeking to have NSO barred from accessing or attempting to access WhatsApp and Facebook's services and is seeking unspecified damages. NSO's alleged use of a flaw in WhatsApp to hijack phones caused international consternation when it was made public in May of this year. NSO at the time said in a statement that it would investigate any "credible allegations of misuse" of its technology. WhatsApp said the attack exploited its video calling system in order to send malware to the mobile devices of a number of users. Further reading: Will Cathcart, head of WhatsApp, elaborates why WhatsApp is pushing back on NSO Group hacking.
Google

Google Search To Stop Indexing Flash Content in Late 2019 (venturebeat.com) 46

Google has announced that it will stop indexing Flash content in Search as the internet prepares to bid a (not so fond) farewell to the multimedia software platform next year. From a report: "In web pages that contain Flash content, Google Search will ignore the Flash content," said Google engineering manager Dong-Hwi Lee in a blog post. "Google Search will stop indexing standalone SWF files." It is no secret that Adobe Flash is well and truly on its way out -- two years ago, a consortium of internet companies (including Adobe itself) committed to killing Flash by 2020. Preceding that, Steve Jobs' famous Thoughts on Flash letter from 2010 helped set the wheels in motion for the proprietary software's eventual demise, with the Apple cofounder citing numerous reasons why his company's hardware would not support Flash, including performance on mobile and poor security.
Security

iPhone Emulation Company Sued by Apple Says It's Making iPhones Safer (vice.com) 35

A startup that makes replicas of the iPhone that help hackers find vulnerabilities is accusing Apple of suing it in an attempt to shut it down. Corellium also fired back at Apple and claimed the company owes it $300,000. From a report: On Monday, Corellium, the startup that was sued by Apple for alleged copyright infringement in August, filed its response to the lawsuit. Apple alleged that Corellium's product is illegal, and helps researchers sell hacking tools based on software bugs found in iOS to government agencies that then use them to hack targets. The cybersecurity world was shocked by Apple's lawsuit, which was seen as an attempt to use copyright as an excuse to control the thriving, and largely legal, market for software vulnerabilities. The lawsuit was filed just a few days after Apple announced it would give researchers special "pre-hacked" devices to allow them to find and report more bugs to the company.

"Through its invitation-only research device program and this lawsuit, Apple is trying to control who is permitted to identify vulnerabilities, if and how Apple will address identified vulnerabilities, and if Apple will disclose identified vulnerabilities to the public at all," Corellium argues in its response, echoing arguments made by the security research community. In its response, Corellium essentially argues that using Apple's code in Corellium is fair use and its product makes the world a better place by helping security researchers inspect the iPhone's operating system, find flaws in it, and help Apple fix them. With Corellium, researchers can more easily find bugs by creating virtual instances of iOS and test them more quickly, as opposed to having to use actual physical devices. Corellium attempts to illustrate this by including "before" and "after" images in its response that demonstrate what it was like to try to hack the iPhone before it released its software.

Slashdot Top Deals