Medicine

Genetically Modified Viruses Help Save a Patient With a 'Superbug' Infection (npr.org) 64

reporter shares a report from NPR: For the first time, scientists have used genetically modified viruses to treat a patient fighting an antibiotic-resistant infection. Isabelle Carnell-Holdaway, 17, began the experimental treatment after doctors lost all hope. She was struggling with a life-threatening infection after a lung transplant. With the new treatment, she has not been completely cured. But the Faversham, England, teenager has recovered so much that she has resumed a near-normal life. The treatment involves a cocktail of three viruses known as "bacteriophages" that specifically attack the dangerous bacterium causing her infection. "These viruses have one specialty: they naturally infect bacteria," reports Live Science. "Once they do so, the viruses replicate inside the bacterial cell, and, through this replicative process, kill the bacterium." The downside with phages is that they're so specific to the bacteria they infect that a phage that works for one patient with a particular infection may not work for another patient infected with the same species of bacteria.

The findings have been published in the journal Nature Medicine.
Security

New Intel Firmware Boot Verification Bypass Enables Low-Level Backdoors (csoonline.com) 43

itwbennett writes: At the Hack in the Box conference in Amsterdam this week, researchers Peter Bosch and Trammell Hudson presented a new attack against the Boot Guard feature of Intel's reference UEFI implementation, known as Tianocore. The attack, which can give an attacker full, persistent access, involves replacing a PC's SPI flash chip with one that contains rogue code, reports Lucian Constantin for CSO. "Even though such physical attacks require a targeted approach and will never be a widespread threat, they can pose a serious risk to businesses and users who have access to valuable information," writes Constantin. Intel has patches available for Tianocore, but as we all remember from the Meltdown and Spectre vulnerabilities, distributing UEFI patches isn't an easy process.
Security

'Unhackable' Encrypted Flash Drive eyeDisk Is, As It Happens, Hackable (techcrunch.com) 49

According to the findings of Pen Test Partners, a U.K.-based cybersecurity firm, the "unhackable" eyeDisk, an allegedly secure USB flash drive that uses iris recognition to unlock and decrypt the device, is hackable. From a report: In its Kickstarter campaign last year, eyeDisk raised more than $21,000; it began shipping devices in March. There's just one problem: it's anything but "unhackable." Pen Test Partners researcher David Lodge found the device's backup password -- to access data in the event of device failure or a sudden eye-gouging accident -- could be easily obtained using a software tool able to sniff USB device traffic.
Government

Researchers Are Liberating Thousands of Pages of Forgotten Hacking History From the Government (vice.com) 35

An anonymous reader writes: In 1989, just a few months after the web became a reality, a computer worm infected thousands of computers across the world, including those of NASA. Late last month -- 30 years after the "WANK worm" struck NASA -- the agency released an internal report that the agency wrote at the time, thanks to a journalist and a security researcher who have embarked on a project to use the Freedom of Information Act to get documents on historical hacking incidents. The project is called "Hacking History," and the people behind it are freelance journalists Emma Best, and security researcher (and former NSA hacker) Emily Crose. The two are crowdfunding to raise money to cover the costs of the FOIA requests via the document requesting platform MuckRock.

In the last few years, hackers and the cybersecurity industry have gone mainstream, earning headlines in major newspapers, becoming key plotlines in Hollywood movies, and even getting a hit TV show. But it hasn't always been this way. For decades, infosec and hacking was a niche industry that got very little news coverage and very little public attention. As a result, the ancient and not so ancient history of hacking has a lot of holes. Now, the two women are trying to fill in those gaps in hacker history, like missing pieces of a puzzle, sending FOIA requests to several US government agencies, including the FBI.

Microsoft

Microsoft SharePoint Servers Are Under Attack (zdnet.com) 37

Hacker groups are attacking Microsoft SharePoint servers to exploit a recently patched vulnerability and gain access to corporate and government networks, according to recent security advisories sent out by Canadian and Saudi Arabian cyber-security agencies. From a report: The security flaw exploited in these attacks is tracked as CVE-2019-0604, which Microsoft patched through security updates released in February, March, and April this year. "An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application pool and the SharePoint server farm account," Microsoft said at the time.
Firefox

Mozilla To Track Infrastructure Time-Bombs in Wake of Recent Firefox Armagadd-on (zdnet.com) 123

In the wake of the mass disablement of Mozilla Firefox's add-on ecosystem last weekend, Mozilla has committed to improving its asset tracking and developing a mechanism that can quickly push updates to users when needed. From a report: Due to an intermediate certificate expiring on May 4 at 1AM UTC, users found their browser add-ons were switched off and could not be re-enabled. Thanks to timezones and the rotation of the planet, users on the western side of the Pacific were the first hit. Writing in a blog post, Firefox CTO Eric Rescorla detailed some initial thoughts and announced a formal post-mortem would be published next week. "First, we should have a much better way of tracking the status of everything in Firefox that is a potential time bomb and making sure that we don't find ourselves in a situation where one goes off unexpectedly. We're still working out the details here, but at minimum we need to inventory everything of this nature," Rescorla wrote. "Second, we need a mechanism to be able to quickly push updates to our users even when -- especially when -- everything else is down.
China

US Charges Chinese Hacker For 2015 Anthem Breach (zdnet.com) 25

The US Department of Justice charged this week a Chinese national for his role as a member of an elite Chinese hacking group that breached at least four US companies, including Indianapolis-based health insurer Anthem Inc. in 2015. From a report: The DOJ indictment, unsealed today, names Fujie Wang, 32, as one of the group's members. According to court documents, Wang and the other hackers typically operated using spear-phishing to trick employees into installing malware on their computers. Once the group infected an employee, they used the malware to escalate access to other systems inside a victim company's network until they found and stole data of interest -- such as personally identifiable information (PII) and confidential business information. US investigators said the group operated between February 2014 and January 2015. The DOJ only named Anthem in the court documents and did not disclose the names the three other companies hacked by Wang and his co-conspirators during this span.
Privacy

The Rise of Fear-Based Social Media Like Nextdoor, Citizen, and Now Amazon's Neighbors (vox.com) 291

An anonymous reader quotes a report from Vox: Violent crime in the U.S. is at its lowest rate in decades. But you wouldn't know that from a crop of increasingly popular social media apps that are forming around crime. Apps like Nextdoor, Citizen, and Amazon Ring's Neighbors -- all of which allow users to view local crime in real time and discuss it with people nearby -- are some of the most downloaded social and news apps in the U.S., according to rankings from the App Store and Google Play.

Nextdoor was the ninth most-downloaded lifestyle app in the U.S. on iPhones at the end of April, according to App Annie, a mobile data and analytics provider; that's up from No. 27 a year ago in the social networking category. (Nextdoor changed its app category from social to lifestyle on April 30; on April 29 it was ranked 14th in social, according to App Annie.) Amazon Ring's Neighbors is the 36th most-downloaded social app. When it launched last year, it was 115th. Citizen, which considers itself a news app, was the seventh most-downloaded news app on iOS at the end of April, up from ninth last year and 29th in 2017. These apps have become popular because of -- and have aggravated -- the false sense that danger is on the rise. Americans seem to think crime is getting worse, according to data from both Gallup and Pew Research Center. In fact, crime has fallen steeply in the last 25 years according to both the FBI and the Bureau of Justice Statistics.
David Ewoldsen, professor of media and information at Michigan State University, says these apps foment fear around crime, which feeds into existing biases and racism and largely reinforces stereotypes around skin color. As Steven Renderos, senior campaigns director at the Center for Media Justice, put it, "These apps are not the definitive guides to crime in a neighborhood -- it is merely a reflection of people's own bias, which criminalizes people of color, the unhoused, and other marginalized communities."

A recent Motherboard article found that the majority of people posted as "suspicious" on Neighbors in a gentrified Brooklyn neighborhood were people of color.
Microsoft

Microsoft Recommends Using a Separate Device For Administrative Tasks (zdnet.com) 177

In a rare article detailing insights about its staff's efforts in securing its own internal infrastructure, Microsoft has shared some very insightful advice on how companies could reduce the risk of having a security breach. From a report: The central piece of this article is Microsoft's recommendation in regards to how companies should deal with administrator accounts. Per Microsoft's Security Team, employees with administrative access should be using a separate device, dedicated only for administrative operations. This device should always be kept up to date with all the most recent software and operating system patches, Microsoft said. "Provide zero rights by default to administration accounts," the Microsoft Security Team also recommended. "Require that they request just-in-time (JIT) privileges that gives them access for a finite amount of time and logs it in a system." Furthermore, the OS vendor also recommends that administrator accounts should be created on a separate user namespace/forest that cannot access the internet, and should be different from the employee's normal work identity.
Security

Hackers Breached 3 US Antivirus Companies, Researchers Reveal (arstechnica.com) 79

In a report published Thursday, researchers at the threat-research company Advanced Intelligence (AdvIntel) revealed that a collective of Russian and English-speaking hackers are actively marketing the spoils of data breaches at three US-based antivirus software vendors. From a report: The collective, calling itself "Fxmsp," is selling both source code and network access to the companies for $300,000 and is providing samples that show strong evidence of the validity of its claims. Yelisey Boguslavskiy, director of research at AdvIntel, told Ars that his company notified "the potential victim entities" of the breach through partner organizations; it also provided the details to US law enforcement. In March, Fxmsp offered the data "through a private conversation," Boguslavskiy said. "However, they claimed that their proxy sellers will announce the sale on forums."
Bug

Reporter Recounts a Quirk in Google's Search Algorithm That Resulted in His Phone Number Getting Listed as Facebook's Customer Support (vice.com) 49

Lorenzo Franceschi-Bicchierai, writing for Vice's Motherboard: I'm waiting for the subway when the phone rings. On the other end of the line an angry woman is shouting at me about her Facebook account. I hang up. A few hours later, I'm walking to get some lunch when someone calls. "I forgot my Facebook password," the man says. I sigh, and -- once again -- explain that I can't help. [...] This keeps happening. In the last three days, I've gotten more than 80 phone calls. Just today, in the span of eight minutes, I got three phone calls from people looking to talk to Facebook. I didn't answer all of them, and some left voicemails.

Initially, I thought this was some coordinated trolling campaign. As it turns out, if you Googled "Facebook phone number" on your phone earlier this week, you would see my cellphone as the fourth result, and Google has created a "card" that pulled my number out of the article and displayed it directly on the search page in a box. The effect is that it seemed like my phone number was Facebook's phone number, because that is how Google has trained people to think. Considering that on average, according to Google's own data, people search for "Facebook phone numberâ tens of thousands of times every month, I got a lot of calls.

Google

All Chromebooks Will Also Be Linux Laptops Going Forward (zdnet.com) 135

At Google I/O in Mountain View, Google said "all devices [Chromebook] launched this year will be Linux-ready right out of the box." From a report: In case you've missed it, last year, Google started making it possible to run desktop Linux on Chrome OS. Since then, more Chromebook devices are able to run Linux. Going forward, all of them will be able to do so, too. Yes. All of them. ARM and Intel-based.
Google

Google Is Bringing Electronic IDs To Android (venturebeat.com) 84

Krystalo writes: The last day of Google's developer conference tends not to have any news, but this year was a little overloaded. Google announced today that it's working on bringing Electronic IDs to Android. Separately, the company also confirmed that all new Android Q devices will be required to encrypt user data. Replacing ID cards, such as driver's licenses and club memberships, has been the last major piece of the digital wallet puzzle. We're not talking about securely logging into web pages -- this is for identifying yourself in "physical world transactions." Wallet apps can replace plane tickets, loyalty cards, and credit cards, but they still can't pass for valid ID. Google is looking to add Electronic ID support so developers can build mobile apps that can be securely used as an ID.
Businesses

Amazon Hit By Extensive Fraud With Hackers Siphoning Merchant Funds (mercurynews.com) 32

Amazon.com was hit by an "extensive" fraud, revealing that unidentified hackers were able to siphon funds from merchant accounts over six months last year. schwit1 shares a report: Amazon believes it was the victim of a "serious" online attack by hackers who broke into about 100 seller accounts and funneled cash from loans or sales into their own bank accounts, according to a U.K. legal document. The hack took place between May and October 2018, Amazon's lawyers said in a redacted filing from November that can now be made public. Amazon said it was still investigating the compromised accounts and believed that hackers managed to change details of accounts on the Seller Central platform to their own at Barclays and Prepay Technologies, which is partly owned by Mastercard, according to the filing. The case highlights how the world's biggest online retail platform -- designed to be automated with minimal human input -- can be misused and how difficult it is for Amazon to find perpetrators. Lawyers for Amazon asked a London judge to approve searches of account statements at Barclays and Prepay, which "have become innocently mixed up in the wrongdoing," it said.
Bug

How a Half-Inch Beetle Finds Fires 80 Miles Away (scientificamerican.com) 62

How does a half-inch beetle find fires 80 miles away? Why, it's called "stochastic resonance" of course! Slashdot reader bodog shares an excerpt from a report via Scientific American: The fire chaser beetle, as its name implies, spends its life trying to find a forest fire (because freshly burnt trees are fire chaser beetle baby food). [T]hey can sense fires from distances over which car stereos are hard pressed to pick up FM radio. In fact, because the infrared emission of a burning oil tank of known volume (in this case, 750,000 barrels) can be calculated with reasonable certainty, scientists that studied the Coalinga oil tank explosion have inferred the beetles can detect infrared radiation intensities so low that they are buried in the thermal noise around them. But ... how?

The heat eyes on the sides of fire chaser beetles are filled with about 70 infrared sensilla. Inside each sensillum is a hair-like sensor (called a dendritic tip in the diagram above) that physically deforms when the sensillum expands in response to heat, triggering a neural response. [...] A signal picked up by more than one of them can be summed up and amplified by the neurons that wire the [70-90] array. As a result, the heat eye can detect softer signals than a single sensor could.

Finally, it is also possible the beetles are better able to detect a signal buried in noise due to a spooky (to me) phenomenon called "stochastic resonance." In this scenario, added thermal noise counterintuitively helps a sensor pick up a signal. A signal below the threshold for triggering a sensor -- but still close to it -- will resonate by chance with a portion of thermal noise that is the same frequency. When there is more noise, there is more signal at that resonant frequency. Together, noise plus signal adds up to an impulse sufficient enough to trip the sensor when signal alone or signal with less noise would not. Incredibly, the measurement gets more precise in the presence of noise than without.

Privacy

Samsung Spilled SmartThings App Source Code, Secret Keys (techcrunch.com) 28

Mossab Hussein, a security researcher at SpiderSilk, has discovered that a development lab used by Samsung engineers was leaking highly sensitive source code, credentials and secret keys for several internal projects -- including its SmartThings platform. TechCrunch reports: The electronics giant left dozens of internal coding projects on a GitLab instance hosted on a Samsung-owned domain, Vandev Lab. The instance, used by staff to share and contribute code to various Samsung apps, services and projects, was spilling data because the projects were set to "public" and not properly protected with a password, allowing anyone to look inside at each project, access and download the source code. Hussein said one project contained credentials that allowed access to the entire AWS account that was being used, including more than 100 S3 storage buckets that contained logs and analytics data.

Many of the folders, he said, contained logs and analytics data for Samsung's SmartThings and Bixby services, but also several employees' exposed private GitLab tokens stored in plaintext, which allowed him to gain additional access from 42 public projects to 135 projects, including many private projects. Samsung told him some of the files were for testing but Hussein challenged the claim, saying source code found in the GitLab repository contained the same code as the Android app, published in Google Play on April 10. The app, which has since been updated, has more than 100 million installs to date.

Chrome

Google Chrome To Support Same-Site Cookies, Get Anti-Fingerprinting Protection (zdnet.com) 57

Google plans to add support for two new privacy and security features in Chrome, namely same-site cookies and anti-fingerprinting protection. From a report: The biggest change that Google plans to roll out is in regards to how it treats cookie files. These new controls will be based on a new IETF standard that Chrome and Mozilla developers have been working on for more than three years. This new IETF specification describes a new attribute that can be set inside HTTP headers. Called "SameSite," the attribute must be set by the website owner and should describe the situations in which a site's cookies can be loaded.

[...] Google engineers also announced a second major new privacy feature for Chrome. According to Google, the company plans to add support for blocking certain types of "user fingerprinting" techniques that are being abused by online advertisers. Google didn't go into details of what types of user fingerprinting techniques it was planning to block. It is worth mentioning that there are many, which range from scanning locally installed system fonts to abusing the HTML5 canvas element, and from measuring a user's device screen size to reading locally installed extensions.

Bitcoin

Binance Says More Than $40 Million in Bitcoin Stolen in 'Large Scale' Hack (techcrunch.com) 138

Hackers have stolen over $40 million worth of bitcoin from Binance, world's largest cryptocurrency exchanges, the company said on Tuesday. From a report: In a statement, the company said hackers stole API keys, two-factor codes and other information in the attack. Binance traced the cryptocurrency theft -- more than 7,000 bitcoins at the time of writing -- to a single wallet after the hackers stole the contents of the company's bitcoin hot wallet. Binance, the world's largest cryptocurrency exchange by volume, said the theft impacted about 2 percent of its total bitcoin holdings.
Businesses

Successful IT Startup Actively Hires People On the Autism Spectrum (fastcompany.com) 174

Suren Enfiajyan shares a report from Fast Company: Ultra Testing, a New York-based software testing and quality assurance startup, employs over 60 workers remotely across 20 states, 75% of whom are on the autism spectrum. Not only was the company open to hiring neurodiverse employees, but it actively sought them out. Though small, the company punches well above its weight class, growing an average of 50% year-over-year since its founding in 2013, with 60% of revenues coming from Fortune 500 clients and the remainder from hypergrowth startups. Its innovative employment and talent management strategies have also received accolades and praise, including an honorable mention in Fast Company's World Changing Ideas awards.

CEO Rajesh Anandan founded Ultra Testing alongside his former M.I.T. roommate Art Shectman after discovering research on the overlooked strengths common among autistic individuals. Anandan's wife, who worked with autistic children at a community mental health clinic in Oakland, had also pointed out how much energy is spent trying to improve the skills that are lacking rather than nurturing the children's often remarkable natural talents. "Individuals on the autism spectrum are more likely to have strengths around pattern recognition, logical reasoning ability, enhanced focus, and so on," says Anandan. "That's not to say that everyone on the spectrum has those abilities, but based on peer-reviewed studies published in scientific journals, there is evidence that there is an over indexing of those abilities -- and those very abilities are exactly what you would look for in quite a few roles, especially around quality engineering or quality assurance."
The report goes on to say that the company utilizes Slack for all of its communications, which makes it much easier for their staff to communicate because many people on the autism spectrum struggle with their communication skills.

"Furthermore, after one teammate quipped how great it would be if humans came with a user manual, Anandan developed the 'BioDex' and attached it to each employee's Slack profile," reports Fast Company. "The 28-point BioDex includes instructions on how each team member prefers to receive critical feedback, their preferred communication medium, their typical response time, and more. [...] The company also polls every team member daily at 5 p.m. with a single question related to inclusion and well-being via Slack and shares responses anonymously with the rest of the team."
Microsoft

Microsoft's Edge Browser for Mac Leaks, Available Now From Microsoft's Official Download Servers 80

Microsoft teased its Edge browser for macOS yesterday, but now, download links have appeared online a little early. From a report: Twitter user WalkingCat discovered official Microsoft download links to both the daily Chromium-powered Canary builds of Edge for Mac [warning: direct download link] and the weekly Dev builds [warning: direct download link]. Microsoft has been working to support Mac keyboard shortcuts, and it has been experimenting with button placement so its browser looks and feels like a Mac app. Microsoft is also adding in Touch Bar support, with options for media control sliders and the ability to switch tabs from the Touch Bar. Rounded corners for tabs are also available in the macOS Edge version, and Microsoft is planning to bring this same UI to Windows.

Slashdot Top Deals