Beazley: ransomware claims more than doubled in the last year

Ransomware attacks on a prominent insurer’s client base rose by more than 100% last year, driven by new attacks on healthcare, professional services and financial institutions, according to new figures released Monday. Beazley Breach Response services, a unit of the London-based insurance firm, said Monday that its clients reported 775 ransomware attacks in 2019, a 131% increase over the previous year. The spike was motivated by a combination of factors, including the increased accessibility of pernicious strains of malicious software, higher demands and the simple inability of enterprises to fend off phishing emails or protect remote desktop protocol technology. The numbers are the latest addition to a pervasive ransomware problem that has been difficult to quantify. Victims often do not report attacks to law enforcement, while extortion demands range from thousands to millions of dollars. Meanwhile insurers like Beazley are asked to cover ransomware claims, and typically keep their risk […]

The post Beazley: ransomware claims more than doubled in the last year appeared first on CyberScoop.

Continue reading Beazley: ransomware claims more than doubled in the last year

Pwn2Own hackers go remote, then crack macOS and Oracle machines anyway

If any demographic should be set up to work remotely, it’s hackers. The Pwn2Own hacking contest, in which security researchers earn rewards by uncovering flaws in commercial technology, closed its spring 2020 edition Thursday after participants probed systems like the macOS and Oracle VirtualBox. It’s a premier competition that global technology firms now use to recruit bug hunters who might be able to help protect widely used products. Unlike prior contests, which have taken place in Vancouver and Miami, organizers conducted much of this tournament online amid the novel coronavirus pandemic. For participants, it didn’t seem to make much of a difference. The @Synacktiv team of @OnlyTheDuck and @BrunoPujos are setting up for their attempt against #VMware Workstation. #Pwn2Own pic.twitter.com/s3WGTG9plI — Zero Day Initiative (@thezdi) March 19, 2020 The winning team, called Fluoroacetate, made up of researchers Amat Cama and Richard Zhu, demonstrated ways to crack Microsoft Windows and Adobe […]

The post Pwn2Own hackers go remote, then crack macOS and Oracle machines anyway appeared first on CyberScoop.

Continue reading Pwn2Own hackers go remote, then crack macOS and Oracle machines anyway

Venture funding in security startups is falling. Don’t blame the coronavirus.

Investors don’t have an unlimited appetite for cybersecurity firms after all. Venture capital investment in security startups in the first two months of this year is down from years past. The downward trend started gaining steam in 2019 and continued into the beginning of 2020, even before the COVID-19 pandemic sent the economy into a freefall. Forty-three venture capital deals have closed so far this year, compared to 103 deals in the first two months of 2018, and 91 deals over the same period in 2018, according to research from DataTribe, a venture capital firm known for its investments in security businesses like Dragos and Enveil. “Given that the venture investments typically take one or two quarters to close, it’s unlikely that COVID-19 is the driver behind this downdraft in early 2020 deal volume,” DataTribe co-founder Mike Janke wrote in a research paper published Thursday. “However, looking ahead we can […]

The post Venture funding in security startups is falling. Don’t blame the coronavirus. appeared first on CyberScoop.

Continue reading Venture funding in security startups is falling. Don’t blame the coronavirus.

Magecart hackers have spent weeks lurking on NutriBullet’s website

A group of scammers using a pervasive hacking technique have spent weeks lurking on the website where NutriBullet customers entered their payment data, according to new findings from a cybersecurity vendor. RiskIQ published research on Wednesday detailing how a hacking group, known as Magecart Group 8, snuck malicious code onto NutriBullet’s website to collect financial information from customers who purchased blenders and other products from the company. The attack began on Feb. 20 and continues today, despite an interruption between March 1 and March 5, RiskIQ said. NutriBullet did not respond to multiple requests for comment. RiskIQ said its researchers have spent three weeks trying to contact the company without receiving a response. The compromise was ongoing as of this article’s publication, RiskIQ said. “Magecart” is a blanket name for a hacking technique in which attackers insert a small amount of malicious code into the e-commerce payment process. Magecart groups […]

The post Magecart hackers have spent weeks lurking on NutriBullet’s website appeared first on CyberScoop.

Continue reading Magecart hackers have spent weeks lurking on NutriBullet’s website

U.S. drops charges against accused IRA sponsor over concerns Russia would weaponize evidence

U.S. prosecutors said on Monday they would drop criminal charges against two Russian firms accused of funding disinformation efforts ahead to the 2016 election, amid concerns that the companies would weaponize evidence in the trial to boost future operations. The U.S. Department of Justice charged the two companies, Concord Management and Concord Consulting, in 2018 as part of former Special Counsel Robert Mueller’s investigation into Russian meddling in the 2016 presidential election. Both shell firms funded Russian efforts to use social media platforms like Facebook and Twitter to divide public opinion in the U.S., prosecutors said. With a trial set to begin April 6, though, prosecutors filed a motion to dismiss the charges. The abrupt change came after U.S. attorneys complained in prior court filings they would need to provide the defendants with some details about the U.S. government’s sources and methods for its national security investigation. Justice Department officials […]

The post U.S. drops charges against accused IRA sponsor over concerns Russia would weaponize evidence appeared first on CyberScoop.

Continue reading U.S. drops charges against accused IRA sponsor over concerns Russia would weaponize evidence

One private equity firm sells Checkmarx to another for $1 billion

The application security company Checkmarx is changing ownership again. The private equity firm Insight Partners said on Monday it will sell Checkmarx to Hellman & Friedman, another private equity company, at a valuation of $1.15 billion. Intsight has owned Checkmarx since June 2015, when investors injected $84 million into the Israeli company. Intsight will retain a significant minority stake in Checkmarx under the terms of the deal. “As cybersecurity threats continue to intensify, we strongly believe that embedding security early in the software development lifecycle is critical,” Tarim Wasim, a partner at Hellman & Friedman, said in a statement. “We look forward to building on Checkmarx’s tremendous success to date and supporting the company’s rapid growth in the years ahead.” Founded in 2006, Checkmarx says it mitigates enterprise security risk by helping developers find vulnerabilities, then fix them. The company is perhaps best known for discovering a number of bugs […]

The post One private equity firm sells Checkmarx to another for $1 billion appeared first on CyberScoop.

Continue reading One private equity firm sells Checkmarx to another for $1 billion

A coronavirus-tracking app locked users’ phones and demanded $100

You can always count on hackers to exploit a terrible situation to try to make a buck. A new Android app that promises to deliver up-to-date figures on the coronavirus pandemic includes a strain of malicious software that locks up a user’s phone and demands an extortion fee. The ransomware app, called CovidLock, threatens to erase everything on an infected phone if victims don’t pay $100 in bitcoin within 48 hours, according to the security firm DomainTools. The number of users affected remains unclear. The app is not available in the Google Play store, and was accessible on a standalone website. DomainTools has said it intends to release a decryption tool for affected victims, while Reddit users claim to already have deciphered the password to release locked data. The program only represents scammers’ latest attempt to use concerns around the COVID-19 virus to defraud anxious technology users. Scams, misinformation campaigns, attempted hacks […]

The post A coronavirus-tracking app locked users’ phones and demanded $100 appeared first on CyberScoop.

Continue reading A coronavirus-tracking app locked users’ phones and demanded $100

FSB asset introduced LinkedIn hacker, future Group-IB executive in 2012, U.S. alleges

Attorneys are using the trial of a man who allegedly stole more than 100 million usernames and passwords from U.S. social media companies to hint at the murky, long-rumored relationships between Russian cybercriminals and the Kremlin’s intelligence agencies. Yevgeniy Nikulin, a 32-year-old St. Petersburg, Russia native, currently is on trial in San Francisco, accused of hacking into LinkedIn, Formspring and Dropbox in 2012 and obtaining 117 million users credentials. Roughly 30 million of those credentials were taken from Formspring. Prosecutors say he worked with a number of co-conspirators to gather and attempt to sell that data, including Nikita Kislitsin, who allegedly tried selling stolen Formspring data before he became an executive at Group-IB, and Alexsey Belan, a Russian man who made the introduction between Nikulin and Kislitin. In a recent filing, the government reproduced an email conversation in which, prosecutors say, Kislitsin was trying to sell the stolen Formspring data, and wanted Belan […]

The post FSB asset introduced LinkedIn hacker, future Group-IB executive in 2012, U.S. alleges appeared first on CyberScoop.

Continue reading FSB asset introduced LinkedIn hacker, future Group-IB executive in 2012, U.S. alleges

European police nab 26 suspects in SIM swapping dragnet

Police in Europe have arrested 26 people in an effort against two gangs of scammers who would take over victims’ phones, then steal financial and personal data from the devices. Law enforcement in Spain and Romania, in coordination with Europol, arrested 12 and 14 people, respectively, in actions against two distinct groups of SIM swappers, Europol announced Friday. SIM swapping occurs when thieves convince phone companies to give them access to an individual’s phone number, often by impersonating the victim during a call with a customer service representative. This grants attackers access to incoming phone calls, text messages and credentials like one-time codes that various sites send via text as part of the two-factor authentication process. The group in Spain stole more than €3 million ($3.34 million) in a series 100 attacks, Europol said. In each instance, the group walked off with between €6,000 ($6,700) and €137,000 ($153,000) from hacked bank […]

The post European police nab 26 suspects in SIM swapping dragnet appeared first on CyberScoop.

Continue reading European police nab 26 suspects in SIM swapping dragnet

Two Exabeam employees who attended RSA Conference contract coronavirus

Two Exabeam employees who attended the RSA Conference last month have tested positive for the coronavirus, according to a statement released Tuesday. While it remains unclear when the employees began developing symptoms, Exabeam is asking anyone who came into contact with its personnel to “please be vigilant in monitoring yourself for symptoms and follow recommended guidelines to prevent possible infection.” A 45-year-old man working for Exabeam began experiencing symptoms upon his return home to Connecticut, Bloomberg first reported Tuesday. The man, who was predisposed for pneumonia because of a pre-existing heart condition, was hospitalized for respiratory distress on March 6. He is now on a ventilator in a “guarded condition,” according to Bloomberg. RSA attracted some 36,000 participants in 2020, despite some concerns about the infectious nature of the virus. Sponsors including IBM, Verizon and AT&T withdrew from the event in the days before it started on Feb. 25. Still, […]

The post Two Exabeam employees who attended RSA Conference contract coronavirus appeared first on CyberScoop.

Continue reading Two Exabeam employees who attended RSA Conference contract coronavirus