Music

MIDI Association Announces MIDI 2.0 Prototyping (hackaday.com) 133

MIDI was introduced at the 1983 NAMM show as a means to connect various electronic instruments together. Since then, our favorite five-pin DIN has been stuffed into Radio Shack keyboards, MPCs, synths, eurorack modules, and DAWs. The standard basically hasn't changed. Now, ahead of the 2019 NAMM show, the MIDI Manufacturers Association (MMA) in conjunction with AMEI, Japan's MIDI Association, are announcing MIDI 2.0. From a report: The new features include, "auto-configuration, new DAW/web integrations, extended resolution, increased expressiveness, and tighter timing." It will retain backwards-compatibility with MIDI 1.0 devices. The new initiative, like the release of the first MIDI spec, is a joint venture between manufacturers of musical instruments. The company lineup on this press release is as follows: Ableton/Cycling '74, Art+Logic, Bome Software, Google, imitone, Native Instruments, Roland, ROLI, Steinberg, TouchKeys, and Yamaha.
Security

Popular WordPress Plugin WPML Hacked By Angry Former Employee (zdnet.com) 37

A very popular WordPress plugin was hacked over the weekend after a hacker defaced its website and sent a mass message to all its customers revealing the existence of supposed unpatched security holes. From a report: In a follow-up mass email, the plugin's developers blamed the hack on a former employee, who also defaced their website. The plugin in question is WPML (or WP MultiLingual), the most popular WordPress plugin for translating and serving WordPress sites in multiple languages. According to its website, WPML has over 600,000 paying customers and is one of the very few WordPress plugins that is so reputable that it doesn't need to advertise itself with a free version on the official WordPress.org plugins repository. But on Saturday, ET timezone, the plugin faced its first major security incident since its launch in 2007. The attacker, which the WPML team claims is a former employee, sent out a mass email to all the plugin's customers.
Security

Firmware Vulnerability In Popular Wi-Fi Chipset Affects Laptops, Smartphones, Routers, Gaming Devices (zdnet.com) 100

Embedi security researcher Denis Selianin has discovered a vulnerability affecting the firmware of a popular Wi-Fi chipset deployed in a wide range of devices, such as laptops, smartphones, gaming rigs, routers, and Internet of Things (IoT) devices. According to Selianin, the vulnerability impacts ThreadX, a real-time operating system that is used as firmware for billions of devices. ZDNet reports: In a report published today, Selianin described how someone could exploit the ThreadX firmware installed on a Marvell Avastar 88W8897 wireless chipset to execute malicious code without any user interaction. The researcher chose this WiFi SoC (system-on-a-chip) because this is one of the most popular WiFi chipsets on the market, being deployed with devices such as Sony PlayStation 4, Xbox One, Microsoft Surface laptops, Samsung Chromebooks, Samsung Galaxy J1 smartphones, and Valve SteamLink cast devices, just to name a few.

"I've managed to identify ~4 total memory corruption issues in some parts of the firmware," said Selianin. "One of the discovered vulnerabilities was a special case of ThreadX block pool overflow. This vulnerability can be triggered without user interaction during the scanning for available networks." The researcher says the firmware function to scan for new WiFi networks launches automatically every five minutes, making exploitation trivial. All an attacker has to do is send malformed WiFi packets to any device with a Marvell Avastar WiFi chipset and wait until the function launches, to execute malicious code and take over the device.
Selianin says he also "identified two methods of exploiting this technique, one that is specific to Marvell's own implementation of the ThreadX firmware, and one that is generic and can be applied to any ThreadX-based firmware, which, according to the ThreatX homepage, could impact as much as 6.2 billion devices," the report says. Patches are reportedly being worked on.
Democrats

Russian Hackers Allegedly Attempted To Breach the DNC After the 2018 Midterms (fortune.com) 127

An anonymous reader quotes a report from Fortune: Russian hackers attempted to breach Democratic National Committee email addresses in a spear-phishing campaign just after the 2018 midterms, according to a DNC court document filed Thursday night. "The content of these emails and their timestamps were consistent with a spear-phishing campaign that leading cybersecurity experts have tied to Russian intelligence," reads the complaint. "Therefore, it is probable that Russian intelligence again attempted to unlawfully infiltrate DNC computers in November 2018." The complaint [...] said there is no evidence that the attempted hack in Nov. 2018 was successful.

Spear-phishing campaigns involve sending emails that appear to be from a trusted source in order to gain confidential information. According to CNN, the emails in question appeared to have been sent from a State Department official and contained a PDF attachment that, if opened, would allow the hacker access to the recipient's computer. The timing and content of these emails were consistent with the practices of the Russian hacking group known as Cozy Bear, one of the two groups that hacked the DNC prior to the 2016 U.S. presidential election. According to the cybersecurity firm FireEye, Cozy Bear attempted to hack over 20 entities in Nov. 2018, including clients in local government, transportation, defense, law enforcement, and military.

Firefox

Firefox To Remove UI Dark Pattern From Screenshot Tool After Months of Complaints (zdnet.com) 127

After months of user complaints, Mozilla will remove a misleading "dark pattern" from its page screenshot utility. From a report: The problematic feature is the "Save" button that appears when Firefox users take a screenshot. The issue is that the Save button doesn't save the screenshot to the PC, as most users would naturally expect, but uploads the image to a Mozilla server. This is both a privacy violation, as some users don't appreciate being tricked into uploading sensitive images saved on remote servers, but also an incovenience as users would still have to download the image locally, but in multiple steps afterward.
Spam

Verizon Will Give Subscribers Free Access To Anti-Robocall Tools (engadget.com) 40

Verizon says it will give all its subscribers free access to its spam alert and call blocking tools, so long as their phones can support the features. From a report: The carrier originally rolled out those tools over a year ago as part of its $3-per-month Call Filter add-on. But starting in March, subscribers with compatible smartphones (including iPhone and Android devices) will be able fend off unwanted robocalls without having to pay extra. Verizon says it will release more info on how to sign up for the free tools near their launch date.
Security

That 773M Password 'Megabreach' is Years Old (krebsonsecurity.com) 29

Security reporter Brian Krebs writes: My inbox and Twitter messages positively lit up today with people forwarding stories from Wired and other publications about a supposedly new trove of nearly 773 million unique email addresses and 21 million unique passwords that were posted to a hacking forum. A story in The Guardian breathlessly dubbed it "the largest collection ever of breached data found." But in an interview with the apparent seller, KrebsOnSecurity learned that it is not even close to the largest gathering of stolen data, and that it is at least two to three years old.

The dump, labeled "Collection #1" and approximately 87GB in size, was first detailed earlier today by Troy Hunt, who operates the HaveIBeenPwned breach notification service. Hunt said the data cache was likely "made up of many different individual data breaches from literally thousands of different sources." KrebsOnSecurity sought perspective on this discovery from Alex Holden, CTO of Hold Security, a company that specializes in trawling underground spaces for intelligence about malicious actors and their stolen data dumps. Holden said the data appears to have first been posted to underground forums in October 2018, and that it is just a subset of a much larger tranche of passwords being peddled by a shadowy seller online.

Android

Google Play Malware Used Phones' Motion Sensors To Conceal Itself (arstechnica.com) 55

An anonymous reader quotes a report from Ars Technica: Malicious apps hosted in the Google Play market are trying a clever trick to avoid detection -- they monitor the motion-sensor input of an infected device before installing a powerful banking trojan to make sure it doesn't load on emulators researchers use to detect attacks. The thinking behind the monitoring is that sensors in real end-user devices will record motion as people use them. By contrast, emulators used by security researchers -- and possibly Google employees screening apps submitted to Play -- are less likely to use sensors. Two Google Play apps recently caught dropping the Anubis banking malware on infected devices would activate the payload only when motion was detected first. Otherwise, the trojan would remain dormant.

Security firm Trend Micro found the motion-activated dropper in two apps -- BatterySaverMobi, which had about 5,000 downloads, and Currency Converter, which had an unknown number of downloads. Google removed them once it learned they were malicious. The motion detection wasn't the only clever feature of the malicious apps. Once one of the apps installed Anubis on a device, the dropper used requests and responses over Twitter and Telegram to locate the required command and control server. Once Anubis was installed, it used a built-in keylogger that can steal users' account credentials. The malware can also obtain credentials by taking screenshots of the infected users' screen.

Bug

Twitter Bug Exposed Some Android Users' Protected Tweets For Years (theverge.com) 13

Twitter disclosed on its Help Center page today that some Android users had their private tweets revealed for years due to a security flaw. "The issue caused the Twitter for Android app to disable the 'Protect your Tweets' setting for some Android users who made changes to their account settings, such as changing the email address associated with their account, between November 3rd, 2014 and January 14th, 2019," reports The Verge. From the report: Though the company says the issue was fixed earlier this week and that iOS or web users weren't affected, it doesn't yet know how many Android accounts were affected. Twitter says it's reached out to affected users and turned the setting back on for them, but it still recommends that users review their privacy settings to make sure it reflects their desired preferences.
Spam

Verizon Blames School Text Provider In Dispute Over 'Spam' Fee (arstechnica.com) 46

Last week, Ars Technica reported that Verizon's new "spam" fee for texts sent from teachers to students might stop working on the network because of a dispute over texting fees that Verizon demanded from Remind, the company that operates the service. Now, it appears that Verizon "has backed down from its original position slightly, and ongoing negotiations could allow the free texting service to continue," reports Ars. From the report: As we reported Monday, the dispute involves Verizon and Remind, which makes a communication service used by teachers and youth sports coaches. Verizon is charging an additional fee, saying the money will be used to fund spam-blocking services. The fee would increase Remind's costs for sending texts to Verizon users from a few hundred thousand dollars to several million dollars per year, Remind said. Remind said it would absorb the cost in order to continue providing the paid version of its service. But most of Remind's 30 million users rely on the free version of the service, and Remind said it could no longer provide free text message notifications over Verizon's network unless the fee is reversed.

Verizon issued an announcement today, titled "App provider Remind threatens to eliminate a free texting service for K-12 education organizations (which will cost it nothing)." The title reflects a new offer Verizon said it made on Tuesday, which would reverse the fee for K-12 users of the free Remind service. "Verizon will not charge Remind fees as long as they don't begin charging K-12 schools, educators, parents and students using its free text message service," Verizon said. "Despite this offer, made Tuesday, Remind has not changed its position that it will stop sending free texts to Verizon customers who use the service regarding school closures, classroom activities and other critical information."
The report goes on to note that simply limiting the offer to K-12 users means the fee "would still be charged for preschools, day-care centers, and youth sports coaches who use the free Remind service."
Government

Oklahoma Government Data Leak Exposes FBI Investigation Records, Millions of Department Files (zdnet.com) 28

An anonymous reader quotes a report from ZDNet: Researchers have disclosed the existence of a server exposed to the public which not only contained terabytes of confidential government data but information relating to FBI investigations. According to UpGuard cybersecurity researchers Greg Pollock and Chris Vickery, the open storage server belonged to the Oklahoma Department of Securities (ODS), a U.S. government department which deals with securities cases and complaints. The database was found through the Shodan search engine which registered the system as publicly accessible on November 30, 2018.

The UpGuard team stumbled across the database on December 7th and notified the department a day later after verifying what they were working with. To ODS' credit, the department removed public access to the server on the same day. In order to examine the security breach, the team was able to download the server's contents. The oldest records dated back to 1986 and the most recent was timestamped in 2016. In total, three terabytes of information representing millions of files. Contents ranged from personal data to system credentials and internal communication records.
ODS said in a statement to ZDNet: "All state IP addresses, and many city and county addresses, are registered to OMES, but the agency has no visibility into the computer systems at the Oklahoma Department of Securities. For the past eight years the state has been working to consolidate all IT infrastructure under OMES and ODS had the option to consolidate its systems voluntarily and they did not."
Android

Some Android GPS Apps Are Just Showing Ads on Top of Google Maps (zdnet.com) 65

A security researcher with antivirus maker ESET has discovered a collection of 19 Android apps that pose as GPS applications but which don't do anything but show ads on top of the legitimate Google Maps service. From a report: "They attract potential users with fake screenshots stolen from legitimate Navigation apps," said Lukas Stefanko, the ESET researcher who found them, who pointed out the 19 apps have been downloaded more than 50 million times. The apps "pretend to be full featured navigation apps, but all they can do is to create useless layer between User and Google Maps app," the researcher said. Stefanko says that the apps don't have any actual "navigation technology" and they only "misuse Google Maps."
Security

North Korean Hackers Infiltrate Chile's ATM Network After Skype Job Interview (zdnet.com) 44

A Skype call and a gullible employee was all it took for North Korean hackers to infiltrate the computer network of Redbanc, the company that interconnects the ATM infrastructure of all Chilean banks. From a report: Prime suspects behind the hack are a hacker group known as Lazarus Group (or Hidden Cobra), known to have associations to the Pyongyang regime, is one of the most active and dangerous hacking groups around, and known to have targeted banks, financial institutions, and cryptocurrency exchanges in the past years. Lazarus' most recent attack took place at the end of December last year but only came to the public's attention after Chilean Senator Felipe Harboe called out Redbanc on Twitter last week for not disclosing its security breach. The company, which has direct lines into the networks of all Chilean banks, formally admitted to the hack a day later in a message posted on its website, but that announcement didn't include any details about the intrusion. However, a day after Redbanc's admission, an investigation conducted by Chilean tech news site trendTIC revealed that the financial firm was the victim of a serious cyber-attack, and not something that could be easily dismissed. According to reporters, the source of the hack was identified as a LinkedIn ad for a developer position at another company to which one of the Redbanc employees applied.
Businesses

US CEOs Are More Worried About Cybersecurity Than a Possible Recession (fortune.com) 88

With markets uncertain, many onlookers might think a recession is on the way, whether that's most CFOs in the world or voters in the United States. But domestic CEOs don't find heavy economic headwinds their biggest external business worry, according to a new survey by the Conference Board. Instead, it's cybersecurity followed by new competitors. Risk of a recession is third. From a report: After high-profile data breaches experienced over the last two years by such companies as Marriott, Equifax, and Uber, that might seem understandable. But U.S. CEOs stand in stark contrast to those of the rest of the world. Cybersecurity was the sixth most pressing issue for chief executives in Europe. It was seventh in Latin America, eighth in Japan, and 10th in China. Regarding concerns over a potential recession, Europe put that in second place, while Japan, China, and Latin America all rated it number one.
Privacy

Collection 1 Data Breach Exposes More Than 772 Million Email Addresses (zdnet.com) 68

A collection of almost 773 million unique email addresses and just under 22 million unique passwords were exposed on cloud service MEGA. Security researcher Troy Hunt said the collection of data, dubbed Collection #1, totaled over 12,000 separate files and more than 87GB of data. ZDNet reports: "What I can say is that my own personal data is in there and it's accurate; right email address and a password I used many years ago," Hunt wrote. "In short, if you're in this breach, one or more passwords you've previously used are floating around for others to see." Some passwords, including his own, have been "dehashed", that is converted back to plain text. Hunt said he gained the information after multiple people reached out to him with concerns over the data on MEGA, with the Collection #1 dump also being discussed on a hacking forum. "The post on the forum referenced 'a collection of 2000+ dehashed databases and Combos stored by topic' and provided a directory listing of 2,890 of the files," Hunt wrote. The collection has since been removed. You can visit Hunt's Have I Been Pwned service to see if you are affected by this breach.
Security

Fortnite Bugs Gave Hackers Access To Millions of Player Accounts, Researchers Say (techcrunch.com) 27

Researchers at cybersecurity firm Check Point say three vulnerabilities chained together could have allowed hackers to take control of any of Fortnite's 200 million players. "The flaws, if exploited, would have stolen the account access token set on the gamer's device once they entered their password," reports TechCrunch. "Once stolen, that token could be used to impersonate the gamer and log in as if they were the account holder, without needing their password." From the report: The researchers say that the flaw lies in how Epic Games, the maker of Fortnite, handles login requests. Researchers said they could send any user a crafted link that appears to come from Epic Games' own domain and steal an access token needed to break into an account.

Here's how it works: The user clicks on a link, which points to an epicgames.com subdomain, which the hacker embeds a link to malicious code on their own server by exploiting a cross-site weakness in the subdomain. Once the malicious script loads, unbeknownst to the Fortnite player, it steals their account token and sends it back to the hacker. "If the victim user is not logged into the game, he or she would have to log in first," a researcher said. "Once that person is logged in, the account can be stolen." Epic Games has since fixed the vulnerability.

Android

Google Play Starts Manually Whitelisting SMS, Phone Apps (arstechnica.com) 37

An anonymous reader quotes a report from Ars Technica: Google is implementing major new Play Store rules for how Android's "SMS" and "Call Log" permissions are used. New Play Store rules will only allow certain types of apps to request phone call logs and SMS permissions, and any apps that don't fit into Google's predetermined use cases will be removed from the Play Store. The policy was first announced in October, and the policy kicks in and the ban hammer starts falling on non-compliant apps this week.

Google says the decision to police these permissions was made to protect user privacy. SMS and phone permissions can give an app access to a user's contacts and everyone they've ever called, in addition to allowing the app to contact premium phone numbers that can charge money directly to the user's cellular bill. Despite the power of these permissions, a surprising number of apps ask for SMS or phone access because they have other, more benign use cases. So to clean up the Play Store, Google's current plan seems to be to (1) build more limited, replacement APIs for these benign use cases that don't offer access to so much user data and (2) kick everyone off the Play Store who is still using the wide-ranging SMS and phone permissions for these more limited use cases.
Google provides a help page that helps explain the new rules and offer workarounds for some use cases.
Mozilla

Mozilla Kills Its Experimental Firefox Test Pilot Program 3 Years After Launch (venturebeat.com) 23

Mozilla has announced that it is closing Firefox Test Pilot, an experimental program it launched three years ago. Firefox Test Pilot allowed users to try out potential new built-in Firefox features and offer feedback to the browser maker. The company says the program was used by an average of 100,000 daily users. A report adds: It's worth noting here that Test Pilot is separate from the various beta versions of Firefox, which are early iterations designed to fine-tune features intended for the prime-time Firefox. Test Pilot, on the other hand, is more about Mozilla dipping its toes in the water to see whether a new feature is worth pursuing at all in the main version of the app, or even as a standalone product. Ultimately, it allows Firefox developers to take bigger risks with their ideas.
Bug

Insect Collapse: 'We Are Destroying Our Life Support Systems' (theguardian.com) 401

An anonymous reader quotes a report from The Guardian: Scientist Brad Lister returned to Puerto Rican rainforest after 35 years to find 98% of ground insects had vanished. His return to the Luquillo rainforest in Puerto Rico after 35 years was to reveal an appalling discovery. The insect population that once provided plentiful food for birds throughout the mountainous national park had collapsed. On the ground, 98% had gone. Up in the leafy canopy, 80% had vanished. The most likely culprit by far is global warming. "It was just astonishing," Lister said. "Before, both the sticky ground plates and canopy plates would be covered with insects. You'd be there for hours picking them off the plates at night. But now the plates would come down after 12 hours in the tropical forest with a couple of lonely insects trapped or none at all."

"We are essentially destroying the very life support systems that allow us to sustain our existence on the planet, along with all the other life on the planet," Lister said. "It is just horrifying to watch us decimate the natural world like this." Lister calls these impacts a "bottom-up trophic cascade", in which the knock-on effects of the insect collapse surge up through the food chain. "I don't think most people have a systems view of the natural world," he said. "But it's all connected and when the invertebrates are declining the entire food web is going to suffer and degrade. It is a system-wide effect." To understand the global scale of an insect collapse that has so far only been glimpsed, Lister says, there is an urgent need for much more research in many more habitats. "More data, that is my mantra," he said.

Security

Pwn2Own Contest Will Pay $900,000 For Hacks That Exploit Tesla's Model 3 (techcrunch.com) 47

The Model 3 will be entered into Pwn2Own this year, the first time a car has been included in the annual high-profile hacking contest. The prize for the winning security researchers: a Model 3. TechCrunch reports: Pwn2Own, which is in its 12th year and run by Trend Micro's Zero Day Initiative, is known as one of the industry's toughest hacking contests. ZDI has awarded more than $4 million over the lifetime of the program. Pwn2Own's spring vulnerability research competition, Pwn2Own Vancouver, will be held March 20 to 22 and will feature five categories, including web browsers, virtualization software, enterprise applications, server-side software and the new automotive category. The targets, chosen by ZDI, include software products from Apple, Google, Microsoft, Mozilla, Oracle and VMware. And, of course, Tesla . Pwn2Own is run in conjunction with the CanSec West conference. There will be "more than $900,000 worth of prizes available for attacks that subvert a variety of [the Model 3's] onboard systems," reports Ars Technica. "The biggest prize will be $250,000 for hacks that execute code on the car's getaway, autopilot, or VCSEC."

"A gateway is the central hub that interconnects the car's powertrain, chassis, and other components and processes the data they send. The autopilot is a driver assistant feature that helps control lane changing, parking, and other driving functions. Short for Vehicle Controller Secondary, VCSEC is responsible for security functions, including the alarm."

Slashdot Top Deals