As iOS vulnerabilities emerge, a new app promises to detect hacked iPhones

A new program in the App Store is promising to help users detect if outsiders are lurking on their device. The consulting firm Trail of Bits on Thursday announced iVerify, a toolkit meant to help users secure their accounts with a series of instructional guides. If the app works as intended, it also will scan iPhones for odd behavior that could prove its been hacked, like if other apps are transferring data in a way they shouldn’t be authorized. It’s available for $4.99 in the App Store, and is one of the first apps ever released in the marketplace meant to catch iPhone hacks, Motherboard reported. “It’s normally almost impossible to tell if your iPhone has been hacked, but our app gives you a heads-up,” the company said in a blog post. “iVerify periodically scans your device for anomalies that might indicate it’s been compromised, gives you a detailed report […]

The post As iOS vulnerabilities emerge, a new app promises to detect hacked iPhones appeared first on CyberScoop.

Continue reading As iOS vulnerabilities emerge, a new app promises to detect hacked iPhones

Nigerian romance scammers swiped thousands of dollars from individuals, U.S. prosecutors say

U.S. prosecutors have charged 10 people with fraud-related crimes as part of a global romance scam in which people assume fake identities on dating websites to ask victims for money. Beginning in 2017, prosecutors say, the defendants worked with other conspirators who posed as U.S. residents working abroad. The scammers would at first would ask for small gifts, like gift cards or cell phones, and then ask for larger payments as the relationships evolved, all while being in Nigeria. The arrests in Oklahoma, New York and California nabbed suspects who moved money between banks accounts and protected the fake identities, prosecutors said. The indictment, unsealed Wednesday, comes as U.S. law enforcement continues to file charges in romance-adjacent scams. Business email compromise, one of the leading causes of cybercrime, occurs when thieves hijack a corporate email address and request monetary transfers, sometimes totaling hundreds of thousands or millions of dollars. Veteran […]

The post Nigerian romance scammers swiped thousands of dollars from individuals, U.S. prosecutors say appeared first on CyberScoop.

Continue reading Nigerian romance scammers swiped thousands of dollars from individuals, U.S. prosecutors say

Russia’s GRU propped up fake media personas, mostly failed at social media promotion after DNC hack

Russian military hackers who stole emails from the Democratic National Committee in 2016 were only acting as one part of a larger, coordinated effort to spread Kremlin-approved messaging before and after the 2016 election, according to new findings from Stanford University. Stanford’s Internet Observatory on Tuesday released a trove of analysis detailing how the GRU, a Russian military intelligence unit, was unable to generate public interest in the data stolen from Hillary Clinton’s campaign for more than a month. Hackers first linked to the stolen emails in a June 14, 2016 set of Facebook posts, pointing to a set of messages supposedly leaked from the campaign. Facebook engagement to the DC Leaks Page, later attributed to Russia, totaled a mere 834 engagements over 22 posts published over four months. International attention only began when WikiLeaks tweeted a link to a database containing thousands of documents revealing internal strife in the […]

The post Russia’s GRU propped up fake media personas, mostly failed at social media promotion after DNC hack appeared first on CyberScoop.

Continue reading Russia’s GRU propped up fake media personas, mostly failed at social media promotion after DNC hack

Alleged Russian scammer appears in U.S. court after extradition battle

A Russian man accused of hacking-related crimes made his first public appearance in federal court Tuesday since being extradited from Israel. Aleksei Burkov, 29, was in the Eastern District Court of Virginia to face allegations including the sale of stolen credit card information, identity theft and money laundering. His presence in court represented a victory for U.S. officials who convinced Israeli judges to send Burkov to the U.S. rather than to Russia. Burkov allegedly operated a website caled “Cardplanet” where scammers could buy and sell information on more than 150,000 credit cards. Damages to American victims totaled roughly $20 million, U.S. officials said in the extradition request. To join Cardplanet, potential members needed three existing members to vouch for their trustworthiness and to provide a cash payment, typically $5,000, the Justice Department said. Burkov faces 80 years in prison if convicted on all counts. “They were heavy, heavy into cybercrime,” […]

The post Alleged Russian scammer appears in U.S. court after extradition battle appeared first on CyberScoop.

Continue reading Alleged Russian scammer appears in U.S. court after extradition battle

Facebook confirms bug that activated iOS cameras

Social media users have complained in recent days that Facebook apparently has been activating iPhone owners’ cameras while they were scrolling through their news feeds. Word of the issue resulted in a handful of news articles suggesting Facebook again was abusing customer trust to collect data in a way it has never made public. And while the company’s failure to protect user data has been well-documented, this case at first glance appeared to be more innocuous. Guy Rosen, vice president of integrity, said in a tweet Tuesday that Facebook is looking into the issue. Thanks for flagging this. This sounds like a bug, we are looking into it. — Guy Rosen (@guyro) November 12, 2019 The bug was born when the company tried fixing an issue with the way Facebook’s iOS app launched. In doing so, a company spokesperson said, the team “inadvertently introduced a bug that caused the app to […]

The post Facebook confirms bug that activated iOS cameras appeared first on CyberScoop.

Continue reading Facebook confirms bug that activated iOS cameras

Canadian tech giant OpenText to acquire Carbonite to boost cloud sales

The billion-dollar deals are still going. OpenText, a Canadian software and technology service company, announced Monday its agreed to spend $1.42 billion to acquire the cloud security vendor Carbonite. The $1.42 billion values Carbonite at a price of $23 per share, a 25% premium to the price at the close of market on Nov. 8. The deal follows Carbonite’s February acquisition of Webroot for $618.5 million in cash, and comes amid tech giants’ ongoing shopping spree for known security vendors. OpenText CEO Mark Barrenechea said in a statement the deal improves his company’s ability to sell to some 300,000 small businesses and 7 million individuals. The Ontario-based company expects “significant expansion of cloud revenues…and cash flows in fiscal 2021.” Carbonite has been the subject of numerous merger and acquisition rumors in recent months since reporting a dip in revenue. Mohamad Ali, the company’s former CEO, stepped down in July and […]

The post Canadian tech giant OpenText to acquire Carbonite to boost cloud sales appeared first on CyberScoop.

Continue reading Canadian tech giant OpenText to acquire Carbonite to boost cloud sales

An issue in Apple Mail means some ‘encrypted’ messages aren’t actually protected

A database in Apple’s MacOS stores encrypted email messages in a plain text format, according to a researcher who says he reported the problem to the company months ago. Bob Gendler, a Mac expert and an IT specialist at the National Institute of Standards and Technology, published a Medium post on Nov. 6 detailing how, if a customer sends encrypted emails via Apple Mail, an outsider could access some of the text. The bug is specific, and likely only affects a fraction of macOS users: Hackers would need to access specific Apple system files from a victim who sent an encrypted message from Apple Mail through a macOS without FileVault encryption. Gendler classified the issue as an “inadvertent information exposure.” The issue involves an Apple system file, snippets.db, that is storing text of emails without encryption (the files are meant to be protected with the S/MIME encryption protocol). Users do […]

The post An issue in Apple Mail means some ‘encrypted’ messages aren’t actually protected appeared first on CyberScoop.

Continue reading An issue in Apple Mail means some ‘encrypted’ messages aren’t actually protected

A flaw in Amazon’s Ring doorbells leaked customers’ Wi-Fi credentials

Internet-connected doorbells sold by Amazon’s Ring service contained a security vulnerability that would have made it possible for hackers to intercept a customer’s Wi-Fi username and password, then launch a larger attack on the network, according to findings made public Thursday. Researchers from the Romanian security firm Bitdefender discovered earlier this year that when a user first configured their Ring doorbell app, it accepted credentials in an unsecure format as it created a new digital access point. Then, when that network went live, the Ring app automatically obtained the Wi-Fi credentials and sent them to the local network. All of those transmissions were sent through an unencrypted HTTP format, meaning anyone with access to that open network could have obtained the Wi-Fi username and password, Bitdefender said. Researchers notified Amazon about the issue, and the company delivered a security patch via an automatic update. (Hackers likely would have needed to be within […]

The post A flaw in Amazon’s Ring doorbells leaked customers’ Wi-Fi credentials appeared first on CyberScoop.

Continue reading A flaw in Amazon’s Ring doorbells leaked customers’ Wi-Fi credentials

Accused Vault7 leaker argues Espionage Act charges are unconstitutional

A former Central Intelligence Agency employee accused of providing U.S. secrets to WikiLeaks is asking a judge to toss some of the key charges against him, asserting they are unconstitutional. A defense attorney for Joshua Schulte filed a motion on Tuesday asking a judge in the U.S. Southern District of New York to dismiss five charges prosecutors brought against Schulte under the Espionage Act and federal larceny law because they “are unconstitutionally overbroad and void for vagueness.” The Department of Justice charged Schulte in June 2018 in connection with leaking a collection of CIA hacking tools used for cyber-espionage to WikiLeaks, which published much of the data under the name “Vault 7.” Schulte also has been accused of possessing child pornography, smuggling cell phones into his Manhattan jail cell, plotting a disinformation campaign to discredit his accusers and other wrongdoing as part of a years-long legal battle that’s only poised […]

The post Accused Vault7 leaker argues Espionage Act charges are unconstitutional appeared first on CyberScoop.

Continue reading Accused Vault7 leaker argues Espionage Act charges are unconstitutional

Shadow Brokers data dump tipped researchers off to a mysterious APT dubbed DarkUniverse

Clues about a hacking group that carried out attacks against targets in countries including Syria, Iran and Russia were included in files leaked by a mysterious group known as the Shadow Brokers, according to new findings. Researchers from the security vendor Kaspersky published a report Tuesday detailing an advanced persistent threat (APT) group the company has dubbed DarkUniverse. Documents published in 2017 by the Shadow Brokers — an elusive group that publicly disseminated NSA hacking tools — included a script that checked for other hacking groups lurking in a compromised system. DarkUniverse was among the groups the script could check for. The DarkUniverse group hit victims in Afghanistan, Tanzania, Ethiopia, Belarus and the United Arab Emirates, along with more common targets like Russia, Iran and Syria. All told, the APT group breached “around” 20 victims ranging from military agencies to private sector organizations like telecommunication firms, and medical institutions. “We believe […]

The post Shadow Brokers data dump tipped researchers off to a mysterious APT dubbed DarkUniverse appeared first on CyberScoop.

Continue reading Shadow Brokers data dump tipped researchers off to a mysterious APT dubbed DarkUniverse