Chinese phonemaker OnePlus alerts customers to data breach

Chinese smartphone manufacturer OnePlus has confirmed it experienced a data breach involving some users’ names, contact numbers as well as their email and shipping addresses. In a post Friday on OnePlus’ community forum, a company representative said the security team determined “an unauthorized party” accessed data “within certain orders.” OnePlus did not disclose the number of customers affected, when the incident occurred, nor how the outsiders infiltrated its systems. Payment data, passwords and accounts are unaffected by the breach, the company said. Word of the OnePlus breach came one day after T-Mobile announced its own security incident. T-Mobile said information associated with customers’ prepaid service accounts was affected, including phone numbers, account numbers, rate plan and rate features. Payment data and password information were unaffected in that breach, too. Shenzhen-based OnePlus operates in more than two dozen countries, specializing in the production of smartphones and other consumer electronics. The company has […]

The post Chinese phonemaker OnePlus alerts customers to data breach appeared first on CyberScoop.

Continue reading Chinese phonemaker OnePlus alerts customers to data breach

Twitter, tightening security, stops requiring phone numbers for authentication

Twitter says it will allow users to remove their phone numbers from the secure login process, a move that has triggered widespread praise from the security community. Users can now use a one-time code, an app or a physical security key to as a second factor of authentication into their account. Before Thursday, Twitter customers trying to login in a secure way only could enter their username and password, then ask the site to send them an SMS message to verify their identity. The company also forced users who did use a third-party authentication app to use their phone number to sign up. Facebook announced in May 2018 it would stop requiring phone numbers for multi-factor authentication. Now, amid a growing body of evidence hackers can subvert text-based authentication, Twitter is expanding its options. We’re also making it easier to secure your account with Two-Factor Authentication. Starting today, you can […]

The post Twitter, tightening security, stops requiring phone numbers for authentication appeared first on CyberScoop.

Continue reading Twitter, tightening security, stops requiring phone numbers for authentication

Aleksei Burkov, Russian accused of operating ‘elite’ hacking forum, pleads not guilty

The accused Russian scammer at center of a geopolitical standoff pleaded not guilty Friday to allegations that he operated two hacking forums where members bought and sold payment data worth roughly $20 million. Aleksei Burkov appeared in the Eastern District Court of Virginia to refute charges including computer intrusion, identity theft and other fraud-related accusations. The 29-year-old St. Petersburg native arrived in the U.S. on Nov. 12 from Israel after a prolonged extradition battle in which the Russian government tried coercing Israeli officials into sending Burkov to Russia, rather than the U.S. Burkov appeared relaxed to the point of laughing at a joke Judge Thomas Ellis made about his own penchant for eating ice cream in the former Soviet Union. The defendant wore a dark green jumpsuit and had short hair. Defense attorney Gregory Stambaugh said Burkov has been in good spirits, a mood the attorney described as “amazing” under the circumstances. […]

The post Aleksei Burkov, Russian accused of operating ‘elite’ hacking forum, pleads not guilty appeared first on CyberScoop.

Continue reading Aleksei Burkov, Russian accused of operating ‘elite’ hacking forum, pleads not guilty

NeverQuest banking malware administrator sentenced to 4 years

A Russian man who helped create a hacking tool capable of extracting funds from victims’ bank accounts will spend four years behind bars, a punishment that fell short of the five years for which federal prosecutors had asked. A judge in the U.S. Southern District of New York handed down the 48-month prison sentence, including time served, to Stanislav Lisov for his role in deploying the NeverQuest malware. Lisov admitted he profited $885,000 from NeverQuest, while government investigators said the hacking technique had been used to try to steal a total of $4.4 million from international banks. Five years would have been the maximum allowed under the terms of a plea deal Lisov struck with the Department of Justice early this year. “He is happy,” Lisov’s attorney, Arkady Bukh, told CyberScoop, calling the sentence a “great victory.” NeverQuest quickly became a favorite hacking tool for financial scammers after its debut in 2013. Thieves […]

The post NeverQuest banking malware administrator sentenced to 4 years appeared first on CyberScoop.

Continue reading NeverQuest banking malware administrator sentenced to 4 years

Mozilla ups bug bounty rewards to $15,000 on critical sites

Bug bounty researchers probing for vulnerabilities in Mozilla software now will be tempted with more cash after the browser-maker doubled most of its rewards and expanded the list of targets. In a blog post Tuesday, Mozilla said it’s marking the 15-year anniversary of its Firefox browser by dedicating a higher budget to its bounty program. Rewards for critical, core and other Mozilla sites are doubled, while remote code-execution vulnerabilities now are worth up to $15,000 on critical sites. Meanwhile, Mozilla also is asking researchers to try hacking its Autograph cryptography service, its Lando code repository tool, the Phabricator, which reviews code changes in Firefox, and Taskcluster, the framework for continuous integration, among others. “We hope the new sites and increased payments will encourage [researchers] to have another look at our sites and help us keep them safe for everyone who uses the web,” Simon Bennetts, a security automation engineer, said […]

The post Mozilla ups bug bounty rewards to $15,000 on critical sites appeared first on CyberScoop.

Continue reading Mozilla ups bug bounty rewards to $15,000 on critical sites

Consumer watchdog says Equifax settlement ‘flunks’ fairness test

As a court weighs the proposed class action settlement stemming from Equifax’s 2017 data breach, an independent legal watchdog is saying the agreement fails to treat victims equally. The nonprofit Center for Class Action Fairness, which advocates on behalf of consumers involved in class action suits, said in a court filing Tuesday the Equifax settlement — which proponents value at $700 million — “flunks” federal requirements for fairness and adequacy. This is the same agreement that Equifax said would include up to $425 million for customers who were affected by the data breach, which compromised information about 147 million Americans. After suggesting individual customers could be paid up t o $125 under certain conditions or accept free credit monitoring, Equifax introduced new requirements forcing Americans to prove they had credit monitoring in place at the time of the breach, otherwise they would be paid nothing. The terms of the deal could result in […]

The post Consumer watchdog says Equifax settlement ‘flunks’ fairness test appeared first on CyberScoop.

Continue reading Consumer watchdog says Equifax settlement ‘flunks’ fairness test

Google, Samsung patch voice assistant flaws that could have allowed access to device’s camera

Security vulnerabilities in personal voice assistant technology would have made it possible for hackers to take photos and videos of users, or track their location without a victims’ knowledge, according to new findings. Flaws in several Android devices opened holes in the Google Assistant and Samsung’s Bixby, according to research published Tuesday by the Israeli security vendor Checkmarx. The issues in Google’s Pixel brand of phones and Samsung’s Galaxy series could have allowed outsiders to record two-way conversations, silence the shutter on a phone’s camera and collect GPS location based on a device’s metadata. Both Google and Samsung say the patch has been available since July in the Play Store. The vulnerabilities show that as new technologies promise more convenience, they can also create new channels that attackers can leverage to infiltrate unwitting users’ devices, or access their information. Researchers proved earlier this month they could intercept Wi-Fi usernames and passwords […]

The post Google, Samsung patch voice assistant flaws that could have allowed access to device’s camera appeared first on CyberScoop.

Continue reading Google, Samsung patch voice assistant flaws that could have allowed access to device’s camera

Someone is using the ‘Cozy Bear’ moniker to scare DDoS victims into bitcoin payments

It looks like scammers are impersonating one of Russia’s most notorious hacking groups in order to extort victims out of thousands of dollars worth of bitcoin. Multiple companies have reported to the security vendor Akamai that they were hit with a distributed denial-of-service attack, which degrades victims’ web services by overwhelming them with fake traffic. After a brief DDoS hit, victims say they receive an extortion note from a group claiming to be Cozy Bear, a state-sponsored Russian hacking group. The scheme works like this: attackers launch the DDoS attack from a botnet, in which each IP in the botnet sends a fraction of the overall traffic to the target. The victim has a deadline, typically six days, to pay two bitcoin. If they don’t pay by the time the deadline expires, the fee increases by one bitcoin per day, and the DDoS resumes. Cozy Bear is best known for […]

The post Someone is using the ‘Cozy Bear’ moniker to scare DDoS victims into bitcoin payments appeared first on CyberScoop.

Continue reading Someone is using the ‘Cozy Bear’ moniker to scare DDoS victims into bitcoin payments

The Dark Overlord hacking suspect who’s fighting extradition to the U.S. is running out of options

An alleged member of the Dark Overlord hacking crew could be extradited to the U.S. before the end of the year. Nathan Wyatt, a 38-year-old U.K. resident, has been charged with conspiracy, two counts of aggravated identity theft and three counts of threatening damage to a computer in connection with a U.S. investigation into the Dark Overlord, according to British court documents. He’s nearing the end of a yearlong legal battle in which his attorneys have argued he shouldn’t be sent to the U.S. The opportunities to continue the fight, however, are becoming scarce. The Dark Overlord is a well-known gang that specializes in stealing sensitive material, then threatening victims with exposure unless they pay an extortion fee. The group is perhaps best known for leaking unreleased episodes of the Netflix show “Orange Is the New Black,” though it also has forced the closure of U.S. schools by threatening students’ families […]

The post The Dark Overlord hacking suspect who’s fighting extradition to the U.S. is running out of options appeared first on CyberScoop.

Continue reading The Dark Overlord hacking suspect who’s fighting extradition to the U.S. is running out of options

The Dark Overlord hacking suspect who’s fighting extradition to the U.S. is running out of options

An alleged member of the Dark Overlord hacking crew could be extradited to the U.S. before the end of the year. Nathan Wyatt, a 38-year-old U.K. resident, has been charged with conspiracy, two counts of aggravated identity theft and three counts of threatening damage to a computer in connection with a U.S. investigation into the Dark Overlord, according to British court documents. He’s nearing the end of a yearlong legal battle in which his attorneys have argued he shouldn’t be sent to the U.S. The opportunities to continue the fight, however, are becoming scarce. The Dark Overlord is a well-known gang that specializes in stealing sensitive material, then threatening victims with exposure unless they pay an extortion fee. The group is perhaps best known for leaking unreleased episodes of the Netflix show “Orange Is the New Black,” though it also has forced the closure of U.S. schools by threatening students’ families […]

The post The Dark Overlord hacking suspect who’s fighting extradition to the U.S. is running out of options appeared first on CyberScoop.

Continue reading The Dark Overlord hacking suspect who’s fighting extradition to the U.S. is running out of options