UK won’t ban Huawei in British 5G technology, defying U.S. warnings

U.K. officials won’t prohibit Chinese telecommunication giant Huawei from providing equipment when the country constructs its 5G wireless network, a decision that comes after the Trump administration spent more than a year urging Britain to ban the company  over security concerns. The U.K.’s National Cyber Security Centre said Tuesday it will keep Huawei away from providing “sensitive functions” to “core” areas of the network. The government also will prevent organizations that oversee equipment networks from purchasing more than 35% of their networking infrastructure from a “high risk vendor” like Huawei, a move that the National Cyber Security Centre that will prevent Britain’s new, high-speed internet from becoming “nationally dependent” on technology that could be problematic. Allowing Huawei into Britain’s upcoming internet infrastructure with stipulations effectively is a compromise between the Chinese company and Western intelligence agencies that have warned Huawei beholden to China’s government, and thus presents a national security […]

The post UK won’t ban Huawei in British 5G technology, defying U.S. warnings appeared first on CyberScoop.

Continue reading UK won’t ban Huawei in British 5G technology, defying U.S. warnings

Security tools still among the fastest-growing apps in corporate America

More of the tools used throughout the private sector are ones that help company staffers better manage or prevent security incidents. In an analysis based on the log-in activity of more than 7,4000 customers, identity management firm Okta found that of the 10 fastest-growing apps in the enterprise, five are known at least in part for their security offerings. Adoption of the incident management tool Opsgenie, which alerts developers to possible problems, grew by 194%, while Google Cloud implementation climbed by 108%, Splunk by 102%, KnowBe4 by 89% and Jamf Pro enjoyed an 82% increase. The cloud data app Snowflake experienced the greatest uptick in adoption among Okta clients, at 273%, while Looker, visitor management software Envoy, FreshService and Zoom also saw gains over 2019. Last year, the security training platform KnowBe4 experienced the largest growth of all apps among Okta users, followed by the password manager LastPass and the […]

The post Security tools still among the fastest-growing apps in corporate America appeared first on CyberScoop.

Continue reading Security tools still among the fastest-growing apps in corporate America

Indonesian police arrest 3 men for alleged Magecart-style attacks

Police in Indonesia have arrested three men accused of inserting malicious code into e-commerce websites to steal shoppers’ payment data, an emerging hacking technique that scammers have used to pilfer victims’ information while avoiding detection. Interpol announced Monday it coordinated a law enforcement operation that identified hundreds of websites that had been infected with malicious software used to collect customers’ financial data and personal details. Three men, identified only by their initials, were arrested on Dec. 20 in Jakarta and Yogyakarta, for allegedly using the stolen data to purchase electronics and other luxury items, then reselling that merchandise for a profit. By relying a malicious tool that attacked the JavaScript programming language, this group used a technique known as a Magecart-style attack to carry out the digital equivalent of a smash-and-grab robbery. At least a dozen so-called Magecart groups use similar techniques to steal data from victims that have included […]

The post Indonesian police arrest 3 men for alleged Magecart-style attacks appeared first on CyberScoop.

Continue reading Indonesian police arrest 3 men for alleged Magecart-style attacks

Tampa Bay Times struck by ransomware, joining a growing club of hacked media outlets

The Tampa Bay Times became the latest major U.S. news organization to be infected with ransomware Thursday when the virus known as Ryuk forced the newspaper to activate incident response plans. The company reported on Jan. 23 that the ransomware had infiltrated its systems, though exactly how the attack occurred remains unclear. Hackers did not compromise any data, such as payment or customer information, the Times reported, and the paper expected to recover by restoring its system from backup files. One company executive told the outlet’s reporters it had no intention of paying a digital extortion fee. It seems like the Times was largely unaffected by the attack. The paper’s website appeared to be publishing at a normal rate by Friday. The Ryuk ransomware strain in particular, has hit companies like Tribune Publishing in 2018, creating a ripple effect that led to problems at the Los Angeles Times, San Diego Tribune and the […]

The post Tampa Bay Times struck by ransomware, joining a growing club of hacked media outlets appeared first on CyberScoop.

Continue reading Tampa Bay Times struck by ransomware, joining a growing club of hacked media outlets

Judge forces insurer to help small business to clean up after a crippling ransomware attack

At least one insurance company will cover the costs from a cyberattack against one of its clients. A Maryland federal judge on Thursday ruled that an Ohio insurer must cover the costs following a ransomware attack that forced a client to replace much of its technology. State Auto Property & Casualty Insurance is on the hook for losses incurred by National Ink & Stitch, a Maryland screen printing business, after a 2016 hack resulted in “direct physical loss or damage” of National Ink & Stitch’s property. No dollar figure has been set yet. The embroidery company had sought $310,000 in damages from State Auto, which has a $1.3 billion market cap. The summary judgment decision from Judge Stephanie A. Gallagher, of the U.S. District Court of Maryland, comes amid ongoing skepticism with the way insurance companies have waded into data security incidents, which are difficult to predict. As a number […]

The post Judge forces insurer to help small business to clean up after a crippling ransomware attack appeared first on CyberScoop.

Continue reading Judge forces insurer to help small business to clean up after a crippling ransomware attack

DHS pushes alert on vulnerable patient monitors sold by GE Healthcare

The U.S. Department of Homeland Security’s cybersecurity outfit on Thursday issued an alert about six flaws in popular health care devices that could affect device functionality, expose patients’ health information or create other vulnerabilities. DHS’ Cybersecurity and Infrastructure Security Agency detailed the six vulnerabilities, known collectively at “MDhex,” lurking in medical technology manufactured by GE Healthcare. The issues exist in GE’s line of CARESCAPE patient monitors, including some versions of the Central Information Center product, the Apex Telemetry Server/Tower, the Central Station, a Telemetry Server and three monitor products (the B450, B650 and B850) that display vital patient information to hospital professionals. No known public exploits specifically target these vulnerabilities, CISA said in its alert. Five of the vulnerabilities were assigned a severity score of 10 on a scale of 1-10, while the sixth was rated an 8.5 on the National Infrastructure Advisory Council’s system. GE Healthcare is “developing software […]

The post DHS pushes alert on vulnerable patient monitors sold by GE Healthcare appeared first on CyberScoop.

Continue reading DHS pushes alert on vulnerable patient monitors sold by GE Healthcare

Another Methbot suspect, Sergey Denisoff, arrested more than a year after initial charges

U.S. police have arrested another suspect in connection with an advertising fraud conspiracy that relied on run-of-the-mill hacking techniques to scam American companies out of roughly $30 million, according to new court documents. Police in New York City this month arrested Sergey Denisoff on charges that he allegedly helped members of the Methbot ad fraud crew by setting up dummy web pages where other conspirators could direct illegitimate traffic. Members then charged U.S. advertising companies for access to visitors who didn’t actually exist. Denisoff supplied fake domains, helped Methbot members circumvent cybersecurity software meant to stop this kind of fraud and was in regular communication with alleged ringleader Aleksandr Zhukov, an NYPD detective said in an affidavit first noticed by Seamus Hughes, the deputy director of the Program on Extremism at George Washington University. Subsequent documents filed Jan. 19 in the Eastern District of New York indicate Denisoff was released on $100,000 bond. His […]

The post Another Methbot suspect, Sergey Denisoff, arrested more than a year after initial charges appeared first on CyberScoop.

Continue reading Another Methbot suspect, Sergey Denisoff, arrested more than a year after initial charges

U.S. says accused Vault 7 leaker tried orchestrating PR campaign from jail cell

With less than two weeks before a former Central Intelligence Agency contractor is scheduled to strand trial for allegedly leaking classified information to WikiLeaks, U.S. prosecutors on Tuesday asked a judge to admit evidence detailing the defendant’s behavior behind bars, including alleged communications with reporters. The defendant, Joshua Schulte, has been charged with stealing national defense information, then providing it to WikiLeaks, which then published a trove of CIA hacking tools known as the Vault7 files. Schulte was arrested in August 2017 and has been awaiting his trial in Manhattan’s Metropolitan Correctional Center. While detained, Schulte sought to “drum up media attention for his case and to paint himself as an innocent man,” prosecutors wrote in a Jan. 21 court filing. This public relations campaign involved writing a series of articles that he sought to distribute to the media, urging family members to post his missives on a public Facebook […]

The post U.S. says accused Vault 7 leaker tried orchestrating PR campaign from jail cell appeared first on CyberScoop.

Continue reading U.S. says accused Vault 7 leaker tried orchestrating PR campaign from jail cell

Accused scammer Burkov to plead guilty to ‘some’ charges after extradition dispute

A Russian man who has spent months at the center of an international political dispute is slated to plead guilty to hacking-related charges this week in Virginia. Aleksei Burkov faces criminal counts including access device fraud and conspiracy to commit identity theft in connection with allegedly operating two cybercriminal forums where visitors bought and sold stolen information worth $20 million. The 29-year-old initially pleaded not guilty during his first appearance in the Eastern District Court of Virginia, though a change-of-plea hearing now is scheduled for Jan. 23. “He will be pleading [guilty] to some, but not all of the original charges,” said Gregory Stambuagh, Burkov’s defense attorney. He declined further comment. Burkov was arrested in Israel in 2015, then extradited to the U.S. in November 2019 after exhausting his appeals. The  St. Petersburg native operated two hacking forums, Cardplanet.cc and Direct Connection, according to court documents filed last week. Through Cardplanet, Burkov […]

The post Accused scammer Burkov to plead guilty to ‘some’ charges after extradition dispute appeared first on CyberScoop.

Continue reading Accused scammer Burkov to plead guilty to ‘some’ charges after extradition dispute

WeLeakInfo, a search engine for breached personal data, shut down

U.S. authorities have shuttered a website claiming users could scour more than 12 billion records compiled from some 10,000 data breaches to purchase usernames, passwords and other personal data meant to facilitate identity theft. The U.S. Department of Justice on Thursday announced its seized weleakinfo.com, which has existed since 2017. The site sold different subscription levels, making it possible for scammers to access and search through the database. Two 22-year-old men, one in the Netherlands and the other in Northern Ireland, were arrested in connection with running the site, according to the Dutch news outlet Nu.nl. Law enforcement from the U.K. and Germany also assisted in the shutdown. The site also promised to alert members if their own information was stolen and uploaded to the database, with a feature called “Asset Monitoring.” “Get notified when your information is detected in a data breach,” the sales pitch said, according to an […]

The post WeLeakInfo, a search engine for breached personal data, shut down appeared first on CyberScoop.

Continue reading WeLeakInfo, a search engine for breached personal data, shut down