U.S. Army bans TikTok amid ongoing scrutiny of Chinese-made video app

The U.S. Army is barring its soldiers from using TikTok, a video-sharing app owned by a company with ties to the Chinese government. Lt. Col. Robin Ochoa, an Army spokeswoman, told Military.com on Dec. 30 the military branch considers TikTok a “cyberthreat” and that personnel may not use the app on government phones. Some 1.3 billion people globally use TikTok to create short videos. The new Army policy follows a December advisory from the U.S. Department of Defense stating that TikTok includes “potential security risks associated with its use” and that using the program could result in the exposure of personal information. Much of the U.S. government’s anxiety over TikTok is connected to ByteDance, a Chinese technology giant with government ties that has owned the app since 2017. ByteDance shares a series of partnerships with Chinese state organizations, Reuters reported, and must abide by Chinese law. In September, the Washington Post reported that TikTok appeared to be censoring […]

The post U.S. Army bans TikTok amid ongoing scrutiny of Chinese-made video app appeared first on CyberScoop.

Continue reading U.S. Army bans TikTok amid ongoing scrutiny of Chinese-made video app

Microsoft seizes 50 websites used by North Korean hackers to gather intelligence

Microsoft has taken hold of 50 websites used by suspected North Korean hackers to bolster attempted hacks against government employees, universities and nuclear organizations, among other targets. The company announced Monday it won a court order allowing it to take over 50 websites that a hacking group Microsoft refers to as Thallium (also known as APT37, or Reaper) has used as part of a campaign to steal sensitive data. Thallium would send phishing emails which directed would-be victims to malicious websites, where they would be prompted to enter their username and password. A successful effort would provide Thallium access to victimized account data including messages, contact lists and appointments. This effort marks the fourth time Microsoft has used U.S. courts to sink nation-state hacking infrastructure. In March, Microsoft said it took over domains used by Phosphorous, an Iranian group also known as Charming Kitten, and in August 2018 said it […]

The post Microsoft seizes 50 websites used by North Korean hackers to gather intelligence appeared first on CyberScoop.

Continue reading Microsoft seizes 50 websites used by North Korean hackers to gather intelligence

Coast Guard says Ryuk ransomware hit systems that monitor cargo transfers at maritime facility

Hackers used Ryuk ransomware to infiltrate computer networks at a marine transportation facility, causing an outage of roughly 30 hours, the U.S. Coast Guard said in a recent security advisory. The incident resulted in the disruption of “the entire corporate IT network,” and difficulties for camera and physical access controls, among other tasks, according to the advisory. The facility shut down its primary operations for 30 hours while incident responders reacted to the situation. “Once the embedded malicious link in the email was clicked by an employee, the ransomware allowed for a threat actor to access significant enterprise Information Technology (IT) network files, and encrypt them, preventing the facility’s access to critical files,” the bulletin stated. “The virus burrowed into the industrial control systems that monitor and control cargo transfer and encrypted files critical to process operations.” This bulletin came five months after the Coast Guard encouraged mariners to focus […]

The post Coast Guard says Ryuk ransomware hit systems that monitor cargo transfers at maritime facility appeared first on CyberScoop.

Continue reading Coast Guard says Ryuk ransomware hit systems that monitor cargo transfers at maritime facility

Arkansas telemarketing firm blames ransomware for sudden holiday closure

The CEO of an Arkansas telemarketing firm is blaming a ransomware attack for her decision to temporarily shut the company’s doors and leave workers unsure of their employment status just days before Christmas. Sandra Franecke, in a letter to employees of The Heritage Company, said the business, which solicits money on behalf of nonprofit clients, was infected with malicious software about two months ago. Hackers “basically ‘held us hostage for ransom’ and we were forced to pay the crooks to get the ‘key’ just to get our systems back up and running,” Franecke said in a letter obtained by KATV, the local ABC affiliate. Company IT staffers have been working in the time since to restore normal operations “but they still have a long way to go,” Franecke noted, without detailing the reason for the two-month notification delay or providing any information about the attack or the strain of malware. […]

The post Arkansas telemarketing firm blames ransomware for sudden holiday closure appeared first on CyberScoop.

Continue reading Arkansas telemarketing firm blames ransomware for sudden holiday closure

Mastercard jumps into the risk-assessment race with RiskRecon acquisition

Mastercard is getting into the security assessment business. The credit giant announced Monday it has agreed to acquire RiskRecon, a Salt Lake City-based startup that grades companies based on their ability to withstand cyberattacks and protect personally identifiable information. The companies did not disclose the terms of the deal. RiskRecon is one of several firms that collect publicly available data — such as what kind of web servers companies use and whether their protected information turns up on the dark web — to make cybersecurity assessments. Mastercard has an obvious financial interest in understanding which companies are more likely to be breached. CEO Ajay Banga has pushed for awareness that most data breaches start at small and medium-sized businesses (SMBs) and then spread to larger ones. Banga is a member of the Cyber Readiness Institute, a Washington nonprofit that distributes cybersecurity advice to SMBs. “Mastercard has been one of the brands that has stood out as a true innovator, focusing on the real problems of real business,” RiskRecon co-founder Kelly […]

The post Mastercard jumps into the risk-assessment race with RiskRecon acquisition appeared first on CyberScoop.

Continue reading Mastercard jumps into the risk-assessment race with RiskRecon acquisition

Twitter removes nearly 6,000 accounts spreading Saudi-backed propaganda

Twitter on Friday announced the removal of 5,929 accounts that researchers say has ties to a man accused of recruiting Twitter employees to gather information on Saudi dissidents. In a blog post, Twitter’s Site Integrity team revealed that the accounts removed this week operated as part of a “significant state-backed information operation” originating within the kingdom of Saudi Arabia. The accounts represent the “core” of a larger network of 88,000 accounts, and primarily were dedicated to liking, retweeting and replying to tweets that were favorable to the Saudi government on issues such as officials’ appearances in Western media and Iranian sanctions. Twitter attributed the activity to Smaat, a Saudi marketing firm that managed the accounts on behalf of its clients. “We have permanently suspended Smaat’s access to our service as a result, as well as the Twitter accounts of Smaat’s senior executives,” the company said in the blog post. “Smaat […]

The post Twitter removes nearly 6,000 accounts spreading Saudi-backed propaganda appeared first on CyberScoop.

Continue reading Twitter removes nearly 6,000 accounts spreading Saudi-backed propaganda

Lithuanian scammer gets 5 years for defrauding Google, Facebook of $120 million

A Lithuanian man’s scheme to steal more than $120 million from Facebook and Google has earned him 60 months in U.S. federal prison. A federal judge in Manhattan handed down the sentence Thursday to Evaldas Rimasauskas, who pleaded guilty in March to orchestrating a phishing plan that allowed him to pose as a Taiwanese technology manufacturer, then collect money transfers from the U.S. technology giants. Rimasauskas created domains spoofing Quanta — a contractor that actually did build servers and other components for Facebook and Google — then sent fraudulent invoices, directing the companies’ employees to wire the fake Quanta real money. The activity occurred between 2013 and 2015, during which time Rimasauskas, now 51, netted $99 million from Facebook and $23 million from Google. A judge in the U.S. Southern District of New York ordered the Lithuanian man to pay that money back, along with the five years in prison and two years […]

The post Lithuanian scammer gets 5 years for defrauding Google, Facebook of $120 million appeared first on CyberScoop.

Continue reading Lithuanian scammer gets 5 years for defrauding Google, Facebook of $120 million

Scammers are using Play Store apps to serve ads that nobody can escape

A sneaky network of more than 100 Android applications is allowing fraudsters to make money by pushing pervasive advertisements to users’ devices, according to new cybersecurity findings. The device owners aren’t the real victims, even though they’re being exploited.  The constant stream of ads, some miniscule and others loud and inescapable, are leveraging victims’ phones as conduits for scammers to rip off companies’ marketing dollars. More than 100 applications with some 4.6 million downloads from the Google Play Store include malicious code that enables the bogus advertising network, according to research published Thursday by the bot detection firm White Ops. Android subscribers who downloaded these apps, some of which still existed on the Play Store at press time, believed they were installing programs that would predict their fortune, play games, take selfies or remove bugs. But the apps also abused their access to inundate the devices with advertisements that could be tracked but often couldn’t be […]

The post Scammers are using Play Store apps to serve ads that nobody can escape appeared first on CyberScoop.

Continue reading Scammers are using Play Store apps to serve ads that nobody can escape

Private equity firms to acquire LastPass parent for $4.3 billion

LogMeIn, the Boston-based software company that owns password manager LastPass, said it will sell itself to two private equity companies as part of a cash deal valuing LogMeIn at roughly $4.3 billion. LogMeIn announced Tuesday it has agreed to be acquired by affiliates of Francisco Partners and Elliott Management Corp. at a purchase price totaling $86.05 per share. LogMeIn’s best known product likely is GoToMeeting, a video conferencing tool, but the company also purchased LastPass for $110 million in 2015. LastPass, with its 18.6 million stated users, is one of a number of password management tools promising to store and protect subscribers’ usernames and passwords. LastPass competitors include Dashlane, which has raised $210 million in venture capital, and 1Password, which announced in November a $200 million funding round, among others. The plan now is for LogMeIn’s new owners to “accelerate growth and product investment organically and inorganically,” Andrew Kowal, senior […]

The post Private equity firms to acquire LastPass parent for $4.3 billion appeared first on CyberScoop.

Continue reading Private equity firms to acquire LastPass parent for $4.3 billion

Venmo and PNC Bank are fighting over third-party data access

Information security and access to third-party data is at the heart of a dispute between an established financial giant and Venmo, the PayPal-owned payment app that’s challenged big banks. Customers from Pittsburgh-based PNC Bank have complained in recent months that they no longer can transfer funds to their Venmo accounts. The change disrupted customers’ financial transfers, and has resulted in a public back-and-forth between Venmo and the bank. Venmo has told customers to tweet complaints at PNC. In turn, PNC has encouraged frustrated customers to move to Zelle, a Venmo competitor operated by a network of banks. In an Oct. 29 tweet, PNC’s customer service account said the bank has made a “security enhancement” which “may be causing difficulty when you try to link your PNC [account] with Venmo.” As part of its security upgrade, PNC stopped Plaid, a third-party data aggregator, from accessing PNC customers’ account and routing information, […]

The post Venmo and PNC Bank are fighting over third-party data access appeared first on CyberScoop.

Continue reading Venmo and PNC Bank are fighting over third-party data access