Affordable phishing services help make email fraud the most profitable form of cybercrime

There has never been a better time to invest in email fraud techniques. Cybercriminal forums are bursting with advertisements from scammers who are selling pre-made tools necessary for carrying out phishing attacks. The average cost of a tutorial that includes instructions on how to carry out a scam is under $25, while templates for malicious websites meant to dupe victims out of their usernames and passwords are typically worth $3 apiece. The numbers are included in research published Tuesday by Digital Shadows, a threat intelligence firm which monitors illicit web forums for criminal activity. The sales figures, if not always surprising, help illustrate how business email compromise (BEC) attacks, which sometimes begin with compromised accounts, caused more than $1.7 billion in cybercrime-related losses reported to the FBI last year. “As long as you have the money to buy a template, you don’t need to be a sophisticated threat actor to […]

The post Affordable phishing services help make email fraud the most profitable form of cybercrime appeared first on CyberScoop.

Continue reading Affordable phishing services help make email fraud the most profitable form of cybercrime

Joshua Schulte’s defense asks for a mistrial in the Vault 7 case

A former CIA employee accused of being responsible for the largest leak in agency history thinks his case should be thrown out of court. Defense attorneys for Joshua Schulte, who’s on trial now in the U.S. Southern District of New York for allegedly providing WikiLeaks with a cache of the agency’s hacking tools, filed a motion on Tuesday for a mistrial. The argument undergirding the request remains classified, though the defense says the request is “based on Brady and other violations.” The mention of “Brady” is an apparent reference to the Brady Rule, which requires prosecutors to provide any favorable evidence to a defendant that could negate the guilt of the accused. The request comes after prosecutors and the defense have sparred over the questioning of a witness who testified against Schulte. The witness, known only as “Michael,” was placed on administrative leave during his time at the CIA when he […]

The post Joshua Schulte’s defense asks for a mistrial in the Vault 7 case appeared first on CyberScoop.

Continue reading Joshua Schulte’s defense asks for a mistrial in the Vault 7 case

Dell to sell RSA to private equity group for $2 billion

RSA will soon have a new parent company. Dell Technologies said Tuesday it intends to sell RSA, a security vendor known for its access management, fraud prevention and threat detection offerings, to a consortium led by private equity firm Symphony Technologies Group. The two sides have entered into a “definitive agreement” for an all-cash transaction worth $2.075 billion, Dell said in a statement Tuesday. The deal was first reported Sunday by the Wall Street Journal. The deal includes products and services including RSA Archer, RSA NetWitness Platform RSA SecurID, RSA Fraud and Risk Intelligence and the RSA Conference, a large security conference scheduled to hold its 2020 event starting Feb. 25 in San Francisco. Symphony Technology Group entered the security industry last year, with its acquisition of a majority stake in the risk scoring company RedSeal for a reported $70 million. Other investors in RSA include the Ontario Teachers’ Pension Plan […]

The post Dell to sell RSA to private equity group for $2 billion appeared first on CyberScoop.

Continue reading Dell to sell RSA to private equity group for $2 billion

Joshua Schulte’s attorneys are trying to call Mike Pompeo in the Vault 7 trial

Defense attorneys representing the former CIA developer accused of carrying out the largest leak in agency history are trying to call U.S. Secretary of State Mike Pompeo as a witness. Joshua Schulte, 31, is on trial in the U.S. Southern District of New York for allegedly abusing his access in 2016 as a CIA employee to steal the agency’s hacking tools and eventually like them to WikiLeaks. While the prosecution has argued that Schulte endangered the security of the U.S. by stealing the so-called Vault 7 files, the defense has argued that so many CIA employees had access to the classified documents that it would be impossible for investigators to know who was behind the leak. The defense is argues that Pompeo, who was CIA director when WikiLeaks began posting the stolen material, “took an active role in the investigation and appears to have first-hand, non-hearsay information that is relevant […]

The post Joshua Schulte’s attorneys are trying to call Mike Pompeo in the Vault 7 trial appeared first on CyberScoop.

Continue reading Joshua Schulte’s attorneys are trying to call Mike Pompeo in the Vault 7 trial

How the suspected Equifax hackers covered their tracks

Even for U.S. law enforcement, the Equifax hack was different. Unlike in previous examples of apparent Chinese government-backed cyber-operations, the hackers behind the Equifax breach stymied police for months. After the Office of Personnel Management hack in 2015, and the Marriott breach which was disclosed in 2018, investigators were confident enough that China was involved to tell the Wall Street Journal and New York Times about their suspicions soon afterward. With Equifax, the search for who was responsible was remarkably harder. Data stolen from the credit monitoring firm hadn’t appeared for sale on criminal forums, a possible indication of a nation-state’s involvement. And while the trove of financial information would certainly be useful to foreign intelligence agencies, using forensic data to validate that theory would prove to be a tall order. The charges announced Monday outline a conspiracy to not only steal a massive trove of information on 145 million Americans […]

The post How the suspected Equifax hackers covered their tracks appeared first on CyberScoop.

Continue reading How the suspected Equifax hackers covered their tracks

The latest in Facebook’s dragnet: Propaganda from Russian military intelligence

Facebook on Wednesday announced the removal of three networks of accounts it had determined were operating on behalf of foreign governments, including a number of pages that the company tied to Russian intelligence services. Researchers found a network of 78 accounts, 11 Pages, 29 groups and four Instagram pages that often posted about news such as Russia’s involvement in Syria and the downing of the Malaysian airliner MH17 and also had links to Russian military intelligence services, the company said. Sometimes, the account holders misrepresented themselves as citizen journalists, and contacted policymakers, reporters and other known figures in the region who could help amplify their content, Facebook said in a blog post. The other networks originated in Iran, where operators also impersonated journalists, and Vietnam and Myanmar, where the Burmese telecommunications company MyTel, which is indirectly owned by the Burmese and Vietnamese militaries, engaged in “coordinated inauthentic behavior.” These takedowns are […]

The post The latest in Facebook’s dragnet: Propaganda from Russian military intelligence appeared first on CyberScoop.

Continue reading The latest in Facebook’s dragnet: Propaganda from Russian military intelligence

Known bugs and predictable phishing are behind your average security incident, IBM says

Lessons from the Equifax hack still haven’t spread far enough, it seems. In that case, Chinese military personnel allegedly exploited a known security flaw in Equifax’s systems to steal data on roughly 145 million Americans. The vulnerability, an issue in the software framework called Apache Struts, had been solved with a patch some two months before, though the credit processing company had failed to install the proper fix. Now, an IBM analysis of 70 billion security incidents in 130 countries over the past year has determined that attackers typically used known vulnerabilities or stolen credentials to break into a victims’ networks. By combining purloined usernames and passwords — typically captured via phishing emails, with malicious attachments — hackers are able to break into networks much in the same way they have for a generation, according to the report released Tuesday. So many credentials are available in online data repositories, and malware so widely accessible […]

The post Known bugs and predictable phishing are behind your average security incident, IBM says appeared first on CyberScoop.

Continue reading Known bugs and predictable phishing are behind your average security incident, IBM says

Scammers are trying to exploit coronavirus concerns to breach companies

Hackers are preying upon fears about the new coronavirus from China by sending companies malicious emails cloaked as warnings about the economic repercussions that could occur as the illness spreads. Researchers from the email security firm Proofpoint discovered a series of phishing attempts aimed at businesses in sectors that are particularly vulnerable to a disruption in trade because of the coronavirus, such as manufacturing, transportation and finance. The messages feature subject lines like “Coronavirus – Brief note for the shipping industry,” then direct recipients to download a Microsoft Word document promising more information. That Word file activates a strain of malicious software, AZORult, which allows attackers to make off with sensitive data. “The malware actors doing this appear to be from Russia and Eastern Europe, and while they aren’t part of an [advanced persistent threat] group, they clearly understand the economic concerns surrounding the Coronavirus,” Sherrod DeGrippo, Proofpoint’s senior director for threat research […]

The post Scammers are trying to exploit coronavirus concerns to breach companies appeared first on CyberScoop.

Continue reading Scammers are trying to exploit coronavirus concerns to breach companies

GAO: CISA’s ‘nationwide strategy’ on election security should be enacted as soon as possible

The cybersecurity wing of the Department of Homeland Security must “urgently finalize” its plans to protect the 2020 presidential election, a government watchdog agency said in a new report released Thursday. The Cybersecurity and Infrastructure Security Agency (CISA) provides state and local election officials with federal assistance, education and information sharing about how to safeguard U.S. voting infrastructure from possible interference. Despite three years of work meant to improve security, CISA still is “not well-positioned to execute a nationwide strategy for securing election infrastructure prior to the start of the 2020 election cycle,” according to a Government Accountability Office (GAO) report published Thursday. Most notably, CISA has not created clear plans to respond to a possible Election Day security incident in which state and local response capabilities were exhausted, according to the GAO report. The audit also determined that CISA had failed to address challenges it experienced in 2018, including an […]

The post GAO: CISA’s ‘nationwide strategy’ on election security should be enacted as soon as possible appeared first on CyberScoop.

Continue reading GAO: CISA’s ‘nationwide strategy’ on election security should be enacted as soon as possible

Forescout goes for $1.9 billion in private-equity acquisition

Private equity dollars continued to flow into the cybersecurity industry Thursday when Forescout Technologies announced it reached an agreement to be acquired by the investment firm Advent International. It’s an all-cash deal worth $1.9 billion, meaning Advent International will pay $33 per Forescout share, a rate that’s about 18% above Forescout’s closing price of $27.98 on Thursday. The company first went public in October 2017 at $22 a share. Forescout specializes in “device security,” a concept that allows companies to protect their share of any device connected to their networks. Its shares have fallen by some 12% over the past year, while the overall S&P 500 index has climbed by 22%, Silicon Valley Business Journal reported. The company’s fourth-quarter revenue grew 8% year-over-year to $91.3 million, propelled in part by a 14% jump in subscription revenue to $37.6 million. President and CEO Mike DeCesare will remain in charge, and Forescout’s headquarters […]

The post Forescout goes for $1.9 billion in private-equity acquisition appeared first on CyberScoop.

Continue reading Forescout goes for $1.9 billion in private-equity acquisition