Dark web marketplaces aren’t the hacker hotbeds they used to be

Wannabe cybercriminals no longer are relying on dark web marketplaces to buy and sell their hacking tools, it seems. The selection and prices of malicious software offerings on well known dark web markets has remained mostly unchanged since 2017, according to findings published Tuesday by the risk intelligence firm Flashpoint. The mostly stagnant prices on these forums, which are most frequently used to buy and sell narcotics, is the latest proof that, even as cybercriminals continue to harass victims, skilled hackers are moving to more private channels to trade the most valuable techniques, suggested Ian Gray, Flashpoint’s director of analysis and research. The quality of the tools, like commodity malware and distributed denial-of-service rental services, also has remained steady, even as defenses have improved. “There’s a lack of innovation we’re seeing in the kinds of goods and on the marketplaces,” Gray said. “It might be an indication they’re looking at […]

The post Dark web marketplaces aren’t the hacker hotbeds they used to be appeared first on CyberScoop.

Continue reading Dark web marketplaces aren’t the hacker hotbeds they used to be

Scammers are dangling an iOS jailbreak to trick victims into downloading a malicious app

It’s only been a week weeks since a researcher released an iOS exploit that could allow outsiders to jailbreak an iPhone, but scammers already are leveraging the tool to try commandeer victims’ phones. Last month, a researcher known as @axi0mx published checkm8, a series of technical instructions that enable users to remove restrictions imposed on their iPhone by Apple or telecommunication companies. Now, after weeks of publicity around checkm8, attackers have launched a malicious website that masquerades as a legitimate page, only to launch a hacking tool that tries to take over an affected device. Cisco’s Talos threat intelligence crew on Tuesday said they found checkrain[.]com, a site meant to look like an offshoot of checkra1n, a legitimate project that researchers can use to modify their iPhone’s processes and jailbreak their device. Instead of allowing that, though, the malicious checkrain site encourages visitors to download an application that clicks on […]

The post Scammers are dangling an iOS jailbreak to trick victims into downloading a malicious app appeared first on CyberScoop.

Continue reading Scammers are dangling an iOS jailbreak to trick victims into downloading a malicious app

Thoma Bravo spends $3.8 billion on Sophos in private equity’s latest cyber deal

Thoma Bravo will acquire British network security firm Sophos for $3.8 billion in cash, the firms announced Monday, marking another major deal that could reshape a decades-old security vendor. The deal is a win for Sophos investors, who will be paid $7.40 per share, up from the Oct. 11 closing price of $4.86. Chicago-based Thoma Bravo, a private equity firm, has acquired more than 200 technology companies over the past 40 years, and recently targeted security firms. Thoma Bravo had been in talks to acquire Symantec, a Sophos competitor, before that company sold much of its business to Broadcom. This comes amid a period of historic consolidation in the cybersecurity industry. There has been more than 80 mergers or acquisitions by August this year, up from 54 deals over the same period in 2018, as industry leaders seek to incorporate a suit of products into a single portfolio. Offering security clients more […]

The post Thoma Bravo spends $3.8 billion on Sophos in private equity’s latest cyber deal appeared first on CyberScoop.

Continue reading Thoma Bravo spends $3.8 billion on Sophos in private equity’s latest cyber deal

Why are cyber insurers incentivizing clients to invest in specific vendors?

The cyber insurance industry is taking baby steps away from a long and messy infancy. For the hundreds of companies that offer policies, toddlerhood is here, and it means exerting more influence over how clients protect their networks and information. For years, headlines have fixated on how big firms like AIG and Zurich have been locked in legal disputes over specific claims, but insurers are now trying to be more proactive with customers. The smartest approach for everyone, they say, is to prevent breaches from happening in the first place. Key to that, and saving money, is trying to identify the products that are most effective. Marsh, the global insurance broker and risk adviser, last month published its first list of Cyber Catalyst-designated products, a tag given to 17 services that a group of insurance firms say its clients should consider, including offerings like FireEye’s Endpoint tool and CrowdStrike penetration testing service. Insurers for years have assessed security products, […]

The post Why are cyber insurers incentivizing clients to invest in specific vendors? appeared first on CyberScoop.

Continue reading Why are cyber insurers incentivizing clients to invest in specific vendors?

NSO Group’s Pegasus spyware detected in attacks against Moroccan journalist, activist

Hackers potentially working on behalf of a foreign government have targeted Moroccan human rights advocates with malicious software built by NSO Group, a controversial spyware vendor, according to Amnesty International. Since 2017, journalist Maati Monib and Abdessadak El Bouchattaoui, an attorney who has protested the Moroccan government’s security forces, repeatedly have received SMS messages containing malicious links that, if clicked, would install the Pegasus malware, Amnesty found. It’s the latest allegation that NSO Group provided Pegasus to a customer that used it for more than combating terrorism and crime. The software allows attackers to take almost total control of an affected phone. Human Rights Watch has documented a list of government efforts to obstruct reform in Morocco, including prison sentences for people who have “harmed” the monarchy there or insulted Islam. El Bouchattaoui, one of the activists whose experience was detailed by Amnesty, was sentenced to two years in prison for […]

The post NSO Group’s Pegasus spyware detected in attacks against Moroccan journalist, activist appeared first on CyberScoop.

Continue reading NSO Group’s Pegasus spyware detected in attacks against Moroccan journalist, activist

Breach at e-commerce provider gave hackers an entry to Sesame Street

The Sesame Street Live Store, where fans of the children’s show buy merchandise, is one of more than 6,500 websites that security researchers say may be compromised by payment skimmers after an apparent incident at an e-commerce platform. A breach at Volusion, which provides cloud infrastructure for online stores, made it possible for thieves to insert malicious code on to many of the sites partnered with Volusion, Marcel Afrahim, a malware researcher who works at Check Point, wrote in an independent blog post Tuesday. Malicious JavaScript code “which on the surface looks like some code that some developer just grabbed from any open source libraries” is extracting credit card information from affected pages, Afrahim wrote. Volusion told CyberScoop on Wednesday that the issue, which affected what it described as V1 merchants only, has been resolved. “We have taken appropriate measures in order to secure our customer accounts,” a spokesperson said […]

The post Breach at e-commerce provider gave hackers an entry to Sesame Street appeared first on CyberScoop.

Continue reading Breach at e-commerce provider gave hackers an entry to Sesame Street

How Russian operatives also used Google to influence Americans in 2016

While Russian propagandists relied heavily on Facebook and Twitter to spread disinformation before the 2016 U.S. presidential election, a new congressional report elaborates on how they also used Google and YouTube to sway Americans’ public opinion in favor of Donald Trump. The Senate Intelligence Committee on Tuesday released a report detailing expansive, and ongoing, information warfare directed against American internet users. The 85-page explanation confirmed much of what was already known about Russian operations: a Kremlin-directed effort utilized an array of social media networks, with their targeted advertising capabilities, to provoke and confuse likely voters ahead of a contentious presidential election. Facebook, Instagram and Twitter were the most crucial aspects of this effort, though Russia’s Internet Research Agency also leveraged Google and its subsidiaries for its own gain. “Periodically, particularly in the context of fast breaking news, Google’s algorithm can elevate extremist content or disinformation to the top of certain […]

The post How Russian operatives also used Google to influence Americans in 2016 appeared first on CyberScoop.

Continue reading How Russian operatives also used Google to influence Americans in 2016

AIG says its cyber insurance plans don’t cover criminal acts; wants lawsuit tossed

Insurance giant AIG argued to a New York federal court on Monday that it is not responsible to cover nearly $6 million in losses incurred by a client that was victimized by suspected Chinese hackers. The company asked a court in the Southern District of New York to dismiss a lawsuit filed in August by SS&C Technologies, a $6 billion financial technology company, which alleged that AIG violated its contract by failing to cover losses from fraud. Hackers fleeced SS&C out of $5.9 million in 2016 by emailing company employees from spoofed email addresses, and requesting monetary transfers. AIG says its policy stipulates that the insurer will not cover losses stemming from criminal activity. “SS&C admits that it has filed suit seeking indemnity coverage for its settlement of a breach of contract claim concerning criminals using ‘spoof emails’ to trick SS&C into improperly using its authority over its client’s bank […]

The post AIG says its cyber insurance plans don’t cover criminal acts; wants lawsuit tossed appeared first on CyberScoop.

Continue reading AIG says its cyber insurance plans don’t cover criminal acts; wants lawsuit tossed

APT groups are exploiting outdated VPNs to spy on international targets, U.K. and U.S. warn

International hacking groups are exploiting vulnerabilities in virtual private network technologies to steal user credentials and monitor sensitive traffic, the United Kingdom’s National Cyber Security Centre said, amid recent warnings that the Chinese government has used similar tactics to collect intelligence. The NCSC, an offshoot of Britain’s intelligence agency, the GCHQ, said on Oct. 2 hackers are leveraging outdated versions of Palo Alto Networks, Fortinet and Pulse Secure products. The U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Agency published its own advisory on the vulnerabilities, which attackers could use to take over an affected system, on Oct. 4. Neither warning speculates on who may be behind the attack, though the alerts come after Microsoft in August said Manganese, a Chinese hacking collective also known as APT5, was focusing attacks on Pulse Secure and Fortinet products. Pulse Secure, Palo Alto and Fortinet have each released security updates for all of […]

The post APT groups are exploiting outdated VPNs to spy on international targets, U.K. and U.S. warn appeared first on CyberScoop.

Continue reading APT groups are exploiting outdated VPNs to spy on international targets, U.K. and U.S. warn

UAE, Egypt, Nigeria cited as sources of latest information operations blocked by Facebook

Facebook has removed hundreds of pages and accounts spreading propaganda on behalf of marketing agencies in Egypt, Nigeria and the United Arab Emirates, in the latest takedown demonstrating how so-called coordinated inauthentic behavior is not just a tactic of governments. The company scrubbed 211 accounts, 107 pages, 43 groups and 87 accounts for engaging in information operations, according to a blog post Thursday from Nathaniel Gliecher, head of cybersecurity policy. Operators of the network relied on fake accounts to spread content, promote local news and generate engagement meant to increase interest in the UAE. The activity was linked to the marketing firms Charles Communications, in UAE; Nigeria’s MintReach; and a company called Flexell in Egypt, Facebook said. Facebook’s action was the result of an independent BuzzFeed News investigation that found the network after Facebook in August announced it had removed more than 350 pages and accounts operated out of UAE and Egypt. No more […]

The post UAE, Egypt, Nigeria cited as sources of latest information operations blocked by Facebook appeared first on CyberScoop.

Continue reading UAE, Egypt, Nigeria cited as sources of latest information operations blocked by Facebook