Security

WordPress Finally Gets the Security Features a Third of the Internet Deserves (zdnet.com) 47

The WordPress content management system (CMS) is set to receive an assortment of new security features today that will finally add the protection level that many of its users have desired for years. From a report: These features are expected to land with the official release of WordPress 5.2, expected for later today. Included are support for cryptographically-signed updates, support for a modern cryptography library, a Site Health section in the admin panel backend, and a feature that will act as a White-Screen-of-Death (WSOD) protection -- letting site admins access their backend in the case of catastrophic PHP errors. With WordPress being installed on around 33.8 percent of all internet sites, these features are set to put some fears at ease in regards to some attack vectors. Probably the biggest and the most important of today's new security features is WordPress' offline digital signatures system. Starting with WordPress 5.2, the WordPress team will digitally sign its update packages with the Ed25519 public-key signature system so that a local installation will be able to verify the update package's authenticity before applying it to a local site.
Microsoft

Microsoft Unveils a New Terminal for Windows 10 and Windows Subsystem for Linux 2 (techcrunch.com) 198

Windows 10 is getting a new terminal for command-line users, Microsoft announced at its Build developer conference today. The new so-called "Windows Terminal" will launch in mid-June and promises to be a major update of the existing Windows Command Prompt and PowerShell experience. From a report: Indeed, it seems like the Terminal will essentially become the default environment for PowerShell, Command Prompt and Windows Subsystem for Linux users going forward. The new terminal will feature faster GPU-accelerated text rending and "emoji-rich" fonts, because everything these days needs to support emojis, and those will sure help lighten up the command-line user experience. More importantly, though, the Windows Terminal will also support shortcuts, tabs, tear-away windows and theming, as well as extensions. It also will natively support Unicode and East Asian fonts. Microsoft also unveiled a new update to WSL, a compatibility layer for running Linux binary executables natively on Windows. From a report: WSL 2 is based on a Linux 4.19 kernel coming soon to Windows. This kernel uses technology built for Azure. In both cases, it helps to reduce Linux boot time and streamline memory use. In fact, Microsoft is promising developers "twice as much speed for file-system heavy operations, such as Node Package Manager install." WSL 2 will also support running Linux Docker containers natively, so that VMs are no longer required. WSL 2, like Windows Terminal, is coming in mid-June.
Microsoft

Microsoft is Bringing Visual Studio To the Browser, Unveils .NET 5 (venturebeat.com) 30

Krystalo writes: At its developer conference Build today, Microsoft previewed new Visual Studio features for remote work, the .NET roadmap, and launched ML.NET 1.0. In April, Microsoft launched Visual Studio 2019 for Windows and Mac. Two notable features were Visual Studio Live Share, a real-time collaboration tool included with Visual Studio 2019, and Visual Studio IntelliCode, an extension offering AI-assisted code completion. At Build 2019, Microsoft shared that IntelliCode's capabilities are now generally available for C# and XAML in Visual Studio 2019 and for Java, JavaScript, TypeScript, and Python in Visual Studio Code. And IntelliCode is now included by default in Visual Studio 2019, starting in version 16.1 Preview 2. The company also previewed an algorithm that can locally track your edits -- repeated edit detection -- and suggest other places where you need that same change. But that's just the tip of the iceberg. Microsoft is experimenting with features that let developers work from anywhere, on any device. The company today announced a private preview for three such new capabilities: Remote-powered developer tools, cloud-hosted developer environments, and a browser-based web companion tool. If the future of work is remote, Microsoft wants to be ready.

[...] Microsoft also announced that it is skipping .NET 4 to avoid confusion with the .NET Framework, which has been on version 4 for years. Going forward, developers will be able to use .NET to target Windows, Linux, macOS, iOS, Android, tvOS, watchOS, WebAssembly, and more. .NET Core 3 will be succeeded by .NET 5, featuring new .NET APIs, runtime capabilities, and language features. Calling it .NET 5 makes it the highest version Microsoft has ever shipped and indicates that the company hopes it is the future for the .NET platform. .NET Core 3 closes much of the remaining capability gap with .NET Framework 4.8, enabling Windows Forms, WPF, and Entity Framework 6. .NET 5 will build on this work, Microsoft says, combining .NET Core, .NET Framework, Xamarin, and Mono (the original cross-platform implementation of .NET) into a single platform. .NET 5 will provide both Just-in-Time (JIT) and Ahead-of-Time (AOT) compilation models. JIT has better performance for desktop/server workloads and development environments. AOT has a faster startup and a small footprint, which is required for mobile and IoT devices. .NET 5 will offer one unified toolchain supported by new SDK project types and a flexible deployment model (side-by-side and self-contained EXEs).

Security

In a First, Israel Responds To Hamas Hackers With an Air Strike (zdnet.com) 568

For the first time, Israel has used brute military force to respond to a Hamas cyberattack, three years after NATO proclaimed "cyber" an official battlefield in modern warfare. From a report: The "bomb-back" response took place on Saturday when Israel Defense Forces (IDF) launched an air strike against a building in the Gaza Strip. They claimed it housed Hamas cyber operatives, which had been engaging in a cyberattack against Israel's "cyberspace." "We were ahead of them all the time," said Brigadier General D., the head of the IDF's cyber defense division. "The moment they tried to do something, they failed." Israeli officials did not disclose any details about the Hamas cyberattack; however, they said they first stopped the attack online, and only then responded with an air strike. "After dealing with the cyber dimension, the Air Force dealt with it in the physical dimension," said IDF spokesperson, Brig. Gen. Ronen Manlis. "At this point in time, Hamas has no cyber operational capabilities."
IT

Is Slack Ruining Work? (vox.com) 102

Though Slack's web site promises that "Slack is where work happens," Vox argues instead that "an increasing emphasis on new technology to moderate our workdays isn't necessarily making our work better or making us more productive. If wielded poorly, it can even make it worse. Slack is one of numerous types of workplace software that companies are using to facilitate collaboration and communication in an increasingly digital world. Teams comes as part of Microsoft's pervasive Office offerings like Word and Excel. Google's G Suite includes Gmail, Hangouts Chat and Meet, and Calendar as well as its cloud-based document-sharing programs. And Facebook has entered the game, too, with Workplace, an attempt to get its 2.7 billion users to employ its products in more productive ways than sharing conspiracy theories...

Much like the ubiquitous open-floor plan, this type of software is meant to get different parts of a company working together, to break down hierarchies, to spark chance interactions and innovations. In practice it can be hell. The addition of yet another communications tool can result in a surfeit of information....

Keeping up with these conversations can seem like a full-time job. After a while, the software goes from helping you work to making it impossible to get work done. Also, workplace software doesn't seem to have supplanted the very thing it was supposed to fix: email. Most people use both... People now have the problem of too many emails, too many meetings, and too many messages. For them, workplace chat software has become just one more demand on their time.

One productivity analytics company even reports that at ten companies (with 500+ employees) they found more Slack channels than there were employees.
Privacy

Security Lapse Exposed a Chinese Smart City Surveillance System (techcrunch.com) 44

An anonymous reader shares a report: Smart cities are designed to make life easier for their residents: better traffic management by clearing routes, making sure the public transport is running on time and having cameras keeping a watchful eye from above. But what happens when that data leaks? One such database was open for weeks for anyone to look inside. Security researcher John Wethington found a smart city database accessible from a web browser without a password. He passed details of the database to TechCrunch in an effort to get the data secured.

The database was an Elasticsearch database, storing gigabytes of data -- including facial recognition scans on hundreds of people over several months. The data was hosted by Chinese tech giant Alibaba. The customer, which Alibaba did not name, tapped into the tech giant's artificial intelligence-powered cloud platform, known as City Brain. "This is a database project created by a customer and hosted on the Alibaba Cloud platform," said an Alibaba spokesperson. "Customers are always advised to protect their data by setting a secure password." "We have already informed the customer about this incident so they can immediately address the issue. As a public cloud provider, we do not have the right to access the content in the customer database," the spokesperson added. The database was pulled offline shortly after TechCrunch reached out to Alibaba. But while Alibaba may not have visibility into the system, we did.

Security

Law Enforcement Seizes Dark Web Market After Moderator Leaks Backend Credentials (zdnet.com) 67

German police, together with Europol and law enforcement agencies from the US, the Netherlands, and France, have seized the servers of a dark web marketplace known as the Wall Street Market, on which users sold illegal products such as drugs, weapons, user credentials, and hacking tools, ZDNet reported Thursday. From the report: The site's seizure comes after a tumultuous two weeks for the Wall Street Market (WSM) and its users, during which the site's administrators have exit-scammed -- ran away with over $14.2 million worth of cryptocurrency from users and vendors' accounts. In this midst of all of this, one of the site's moderators -- named Med3l1n -- began blackmailing WSM vendors and buyers, asking for 0.05 Bitcoin (~$280), and threatening to disclose to law enforcement the details of WSM vendors and buyers who made the mistake of sharing various details in support requests in an unencrypted form. It is unclear if these extortion attempts succeeded, but days later, Med3l1n published the IP address (located in the Netherlands) and login credentials for the WSM backend on Dread, a Reddit-like community for dark web users. The IP address is in the same network range of another IP address that leaked from the Wall Street Market backend two years ago. Further reading: Feds Bust Up Dark Web Hub Wall Street Market.
Firefox

A Glitch Is Breaking All Firefox Extensions (techcrunch.com) 311

Did you just open Firefox only to find all of your extensions disabled and/or otherwise not working? You're not alone, and it's nothing you did. From a report: Reports are pouring in of a glitch that has spontaneously disabled effectively all Firefox extensions. Each extension is now being listed as a "legacy" extension, alongside a warning that it "could not be verified for use in Firefox and has been disabled." A ticket submitted to Mozilla's Bugzilla bug tracker first hit at around 5:40 PM Pacific, and suggests the sudden failure is due to a code signing certificate built into the browser that expired just after 5 PM (or midnight on May 4th in UTC time). Because the glitch stems from an underlying certificate, re-installing extensions won't work -- if you try, you'll likely just be met with a different error message. Getting extensions back for everyone is going to require Mozilla to issue a patch.
UPDATE (5/5/2019): On Sunday Firefox released the second of two weekend updates to address the problem, tweeting that "There are some issues we're still working on, but we wanted to get this release out and get your add-ons back up & running before Monday."
Security

A Hacker is Wiping Git Repositories and Asking For a Ransom (zdnet.com) 213

An anonymous reader writes: Hundreds of developers have had had Git source code repositories wiped and replaced with a ransom demand. The hacker removes all source code and recent commits from vitcims' Git repositories, and leaves a ransom note behind that asks for a payment of 0.1 Bitcoin (~$570). The hacker claims all source code has been downloaded and stored on one of their servers, and gives the victim ten days to pay the ransom; otherwise, they'll make the code public.

Hundreds of users have had code repositories wiped and replaced with ransom notes. The coordinated attack has hit Git repositories stored across multiple platforms, such as GitHub, GitLab,and Bitbucket. Some users who fell victim to this hacker have admitted to using weak passwords for their GitHub, GitLab, and Bitbucket accounts, and forgetting to remove access tokens for old apps they haven't used for months --both of which are very common ways in which online accounts usually get compromised. Several users also tried to pin the issue on the hacker using an exploit in SourceTree, a Git GUI app for Mac and Windows made by Atlassian; however, there is no evidence to support this theory, for the time being.

Communications

Western Allies Agree 5G Security Guidelines, Warn of Outside Influence (reuters.com) 87

Global security officials agreed a set of proposals on Friday for future 5G networks, highlighting concerns about equipment supplied by vendors that might be subject to state influence. From a report: No suppliers were named, but the United States has been pressing allies to limit the role of Chinese telecom equipment makers such as Huawei over concerns their gear could be used by Beijing for spying. Huawei denies this. "The overall risk of influence on a supplier by a third country should be taken into account," participants at the conference in the Czech capital said in a non-binding statement released on the last day of the two-day gathering. Representatives from 30 European Union, NATO and countries such as the United States, Germany, Japan and Australia attended the meeting to hash out an outline of practices that could form a coordinated approach to shared security and policy measures.
Security

Dell Laptops and PCs Vulnerable To Remote Hijacks (zdnet.com) 70

A vulnerability in the Dell SupportAssist utility exposes Dell laptops and personal computers to a remote attack that can allow hackers to execute code with admin privileges on devices using an older version of this tool and take over users' systems. From a report: Dell has released a patch for this security flaw on April 23; however, many users are likely to remain vulnerable unless they've already updated the tool -- which is used for debugging, diagnostics, and Dell drivers auto-updates. The number of impacted users is believed to be very high, as the SupportAssist tool is one of the apps that Dell will pre-install on all Dell laptops and computers the company ships with a running Windows OS (systems sold without an OS are not impacted). According to Bill Demirkapi, a 17-year-old security researcher from the US, the Dell SupportAssist app is vulnerable to a "remote code execution" vulnerability that under certain circumstances can allow attackers an easy way to hijack Dell systems.
Firefox

Mozilla Says It Will Ban Firefox Add-ons With Obfuscated Code (betanews.com) 148

DarkRookie2 writes: As Mozilla continues to try to make it safer than ever to use Firefox, the organization has updated its Add-on Policy so that any updates that include obfuscated code are explicitly banned. Mozilla has also set out in plain terms its blocking process for add-ons and extensions. While there is nothing surprising here, the clarification should mean that there are fewer causes for disputes when an add-on is blocklisted. The updated Add-on policy comes into force on June 10, so add-on developers have a little more than a month to take note of the changes and comply. Mozilla says that the move is designed to help it better deal with malicious extensions. Mozilla also plans to be more aggressive towards taking down extensions that break its policies, with a heavy focus on security issues. ZDNet adds: [...] Starting with June 10, Mozilla's team will also be more aggressive in blocking and disabling Firefox add-ons in users' browsers that are found to be violating one of the company's policies."We will continue to block extensions for intentionally violating our policies, critical security vulnerabilities, and will also act on extensions compromising user privacy or circumventing user consent or control," Nieman said.
IT

Windows Server Hosting Provider Still Down a Week After Ransomware Attack (zdnet.com) 129

An anonymous reader shares a report: A ransomware infection has crippled the operations of a US-based web hosting provider for almost eight days now, several of the company's disgruntled customers have told ZDNet today. Impacted are all Windows-based servers owned by A2 Hosting, a provider of virtual private servers (VPS) and WordPress hosting services. The infection, which took place last week on April 23, has led to a week-long downtime that A2 staff has struggled to fix, leading to an unending stream of complaints and desperate pleas for help from customers bleeding money with each passing day of downtime.
Windows

Mysterious Hacker Has Been Selling Windows 0-Days To APT Groups For Three Years (zdnet.com) 71

For the past three years, a mysterious hacker has been selling Windows zero-days to at least three cyber-espionage groups, as well as cyber-crime gangs, researchers from Kaspersky Lab have told ZDNet. From a report: The hacker's activity reinforces recent assessments that some government-backed cyber-espionage groups -- also known as APTs (advanced persistent threats) -- will regularly buy zero-day exploits from third-party entities, besides developing their own in-house tools. APT groups believed to be operating out of Russia and the Middle East have often been spotted using zero-days developed by real-world companies that act as sellers of surveillance software and exploit brokers for government agencies. However, Kaspersky's recent revelations show that APT groups won't shy away from dipping their toes in the underground hacking scene to acquire exploits initially developed by lone hackers for cyber-crime groups, if ever necessary.
Security

NSA Says Warrantless Searches of Americans' Data Rose in 2018 (techcrunch.com) 97

The intelligence community's annual transparency report revealed a spike in the number of warrantless searches of Americans' data in 2018. From a report: The data, published Tuesday by the Office of the Director of National Intelligence (ODNI), revealed a 28 percent rise in the number of targeted search terms used to query massive databases of collected Americans' communications. Some 9,637 warrantless search queries of the contents of Americans' calls, text messages, emails and other communications were conducted by the NSA during 2018, up from 7,512 searches on the year prior, the report said. The figures also don't take into account queries made by the FBI or the Drug Enforcement Administration, which also has access to the database, nor do they say exactly how many Americans had their information collected.
Security

'Cyber Event' Disrupted US Grid Networks (eenews.net) 55

A "cyber event" interrupted grid operations in parts of the western United States last month, according to a cryptic report posted by the Department of Energy. From a report: The March 5 incident lasted from 9 a.m. until nearly 7 p.m. but didn't lead to a power outage, based on a brief summary of the electric disturbance report filed by the victim utility. If remote hackers interfered with grid networks in California, Utah and Wyoming, as the DOE filing suggests, the event would be unprecedented. A cyberattack is not known to have ever disrupted the flow of electricity anywhere in the United States, though Russian hackers briefly cut off power to parts of Ukraine in 2015 and again in 2016. DOE uses a broad definition of "cyber event," describing it as any disruption to an electrical system or grid communication network "caused by unauthorized access" to hardware, software or data. That leaves open the possibility that a utility employee or trespasser, rather than a remote hacker, triggered the March 5 event.
Youtube

Jimmy Fallon Played a Video Game on Air, Meaning That Streaming Your Own Game Gets You Taken Down as a Pirate (boingboing.net) 168

AmiMoJo shares a report: NBC (and the other broadcasters) provides copies of its shows to YouTube's Content ID filter, which is supposed to protect copyright by blocking uploads of videos that match ones in its database of claimed videos. That means that if you own the copyright to something that is aired on NBC, any subsequent attempts by you or your fans to upload your work will be blocked as copyright infringements, and could cost you your YouTube account. The latest casualty of this is the video game Beat Saber. Jimmy Fallon played part of one of Beat Saber's levels, and so no one else cold upload their own gameplay of that level to YouTube without being accused of copyright infringement and blocked. After a lot of fast work by Beat Saber, they managed to get the ban lifted.
Security

Hackers Steal and Ransom Financial Data Related To Some of the World's Largest Companies (vice.com) 46

Hackers have broken into an internet infrastructure firm that provides services to dozens of the world's largest and most valuable companies, including Oracle, Volkswagen, Airbus, and many more as part of an extortion attempt, Motherboard reported Tuesday. From the report: The attackers have also threatened to release data from all of those companies, according to a website seemingly set up by the hackers to distribute the stolen material. Citycomp, the impacted Germany-based firm, provides servers, storage, and other computer equipment to large companies, according to the company's website. Michael Bartsch, executive director of Deutor Cyber Security Solutions, a firm Citycomp said was authorized to speak about the case, confirmed the breach to Motherboard in an email Tuesday. "Citycomp has been hacked and blackmailed and the attack is ongoing," Bartsch wrote. "We have to be careful as the whole case is under police investigation and the attacker is trying all tricks."
United States

US Will Rethink Cooperation With Allies Who Use Huawei (reuters.com) 230

Washington does not see any distinction between core and non-core parts of 5G networks and will reassess sharing information with any allies which use equipment made by China's Huawei, a U.S. cybersecurity official said on Monday. From a report: "It is the United States' position that putting Huawei or any other untrustworthy vendor in any part of the 5G telecommunications network is a risk," said Robert Strayer, deputy assistant secretary for cyber, international communications and information policy at the State Department. "If other countries insert and allow untrusted vendors to build out and become the vendors for their 5G networks we will have to reassess the ability for us to share information and be connected with them in the ways that we are today," he said. Further reading: UK To Let Huawei Firm Help Build 5G Network.
Security

Microsoft Outlook Email Breach Targeted Cryptocurrency Users (vice.com) 29

Earlier this month, we learned that Microsoft's email services were compromised. Multiple victims now say that hackers stole their cryptocurrency. From a report: Now, multiple victims have come forward to flag what they believe may be one of the motivating reasons behind the breach: emptying peoples' cryptocurrency accounts. "The hackers also had access to my inbox allowing them to password reset my Kraken [dot] com account and withdrawal [sic] my Bitcoin," Jevon Ritmeester, a Microsoft user that the company alerted to the data breach, told Motherboard in an email, referring to popular cryptocurrency exchange Kraken. For verification purposes, Ritmeester provided Motherboard with the breach notification emails he received from Microsoft, as well as a screenshot showing what he said was an email forwarding rule the hackers set up: anytime an email mentioned the term "Kraken," his account would automatically forward it to a Gmail address presumably controlled by the hackers. [...] It appears Ritmeester isn't the only person who hackers stole cryptocurrency from due to the Microsoft breach.

Slashdot Top Deals