Magecart strikes more than 2 million websites as more groups get involved

Digital scammers have included malicious Magecart code on more than 2 million websites, according to new research that demonstrates how hackers exploit seemingly trivial website vulnerabilities to easily steal customer payment information. “Magecart” is an umbrella term that applies to hacks in which outsiders inject specific, malicious JavaScript code onto e-commerce websites to collect shoppers’ payment information. It’s a subtle fraud technique that RiskIQ has detected on 2,086,529 sites, the security company said in a report published Friday. Notable victims have included British Airways and Ticketmaster, though the number of organizations affected continues to grow because hackers now are leveraging cloud servers and other hard-to-detect methods to steal data. The average Magecart infection lasts for 22 days, RiskIQ said. The company did not disclose which sites were included in the 2 million hit, saying only that the list included sites in Alexa’s ranking of the top 2,000 pages online. Meanwhile, […]

The post Magecart strikes more than 2 million websites as more groups get involved appeared first on CyberScoop.

Continue reading Magecart strikes more than 2 million websites as more groups get involved

Zendesk announces data breach impacting years-old accounts

Up to 10,000 Zendesk support and chat accounts may be impacted by a 2016 data breach, the San Francisco-based company announced Wednesday. Zendesk is a customer service software provider that promises to help clients ranging from Spotify to Vimeo via customer chats and data analysis. A third-party alerted the firm to a security incident impacting roughly 10,000 Zendesk support and chat accounts, including expired trial accounts and accounts that are no longer active. Zendesk determined on Sept. 24 an incident had occurred, the company said, and an initial investigation has confirmed agent names and contact information was compromised, along with user names and hashed and salted passwords. Zendesk “customers” are not individual users, but some 145,000 companies like Airbnb, Squarespace and Uber, according to the Zendesk website. Agents are employees of those client companies and “end users” refers to the customers of the Zendesk client, according to the company’s definitions. Only […]

The post Zendesk announces data breach impacting years-old accounts appeared first on CyberScoop.

Continue reading Zendesk announces data breach impacting years-old accounts

California’s new labor law is going to impact bug bounty companies. By how much is unknown.

While much of the attention around California’s recently passed Assembly Bill 5 (AB5) has focused on the future for Uber and Lyft drivers, bug bounty contractors working in California could also argue they’re covered under the law when it goes into effect next year. California Gov. Gavin Newsom on Sept. 18 signed AB5, which changes how employers can classify independent contractors and employees. Bug bounty firms rely on freelance hackers to use their platforms and identify or help mitigate software vulnerabilities. Many government agencies and Fortune 500 companies use the platforms — and the cheap labor that comes with it — as a way to close a portion of their cybersecurity gaps. The extent to which the law, which goes into effect Jan. 1, is applicable to bug bounty freelancers will hinge on an individual’s specific professional situation, employment attorneys told CyberScoop.  Yet, the grey area in which these freelance […]

The post California’s new labor law is going to impact bug bounty companies. By how much is unknown. appeared first on CyberScoop.

Continue reading California’s new labor law is going to impact bug bounty companies. By how much is unknown.

A cyber-espionage effort against Tibetan leaders leveraged known Android, iOS vulnerabilities

Hackers aimed to infect mobile phones belonging to senior members of Tibetan groups, including people who worked directly for the Dalai Lama, as well as lawmakers in Tibet’s parliament, according to new findings from a team of researchers at the University of Toronto. The digital rights group Citizen Lab on Tuesday detailed an apparent cyber-espionage effort which involved attackers posing as journalists, Amnesty International researchers, nongovernmental organization workers and other faked identities to send malicious links in a WhatsApp conversation. Researchers observed the campaign, dubbed Poison Carp, between November 2018 and May 2019. Hackers relied on eight Android browser vulnerabilities, Android spyware, a single iOS exploit chain (a combination of malicious actions allowing hackers to achieve a goal) and iOS spyware. None of the attacks utilized zero-day exploits, the name given to hacking tools that take advantage of never-disclosed vulnerabilities. None of the intrusion attempts detected here were successful, but at […]

The post A cyber-espionage effort against Tibetan leaders leveraged known Android, iOS vulnerabilities appeared first on CyberScoop.

Continue reading A cyber-espionage effort against Tibetan leaders leveraged known Android, iOS vulnerabilities

Shareholders allege FedEx covered up damages caused by NotPetya attack

FedEx shareholders are accusing the company’s executives of failing to disclose the full extent of the NotPetya ransomware attack while also selling tens of millions of dollars worth of their own stock in the company, according to a lawsuit filed last week. Stock owners filed a lawsuit on Sept. 17 alleging that FedEx brass provided “materially false and misleading statements” about the ransomware attack that locked up systems at company subsidiary TNT Express more than two years ago. NotPetya wreaked havoc on corporate giants including Maersk, the British advertising firm WPP and the pharmaceutical conglomerate Merck. The White House blamed Russia for the attack, which caused more than $10 billion in damages and spurred a number of high profile lawsuits in the private sector. In this case, the suit alleges FedEx failed to inform its shareholders that TNT Express customers were abandoning the company in favor of other logistics providers […]

The post Shareholders allege FedEx covered up damages caused by NotPetya attack appeared first on CyberScoop.

Continue reading Shareholders allege FedEx covered up damages caused by NotPetya attack

Two Methbot suspects set to plead guilty as alleged ringleader maintains his innocence

Two men accused of participating in the multimillion-dollar Methbot digital-advertising fraud scheme are scheduled to plead guilty in the coming days, according to court filings from the Eastern District of New York. Sergey Ovysannikov and Yevgeniy Timchenko, both originally from Kazakhstan, are scheduled to appear in a federal courtroom in Brooklyn on Sept. 24 and Sept. 25, respectively, to enter plea agreements before Judge Steven M. Gold. Both men initially pleaded not guilty after they were extradited to the U.S. earlier this year. A third man, Methbot’s alleged ringleader, Aleksandr Zhukov, has promised to fight the charges against him. Prosecutors say the operation relied on cybercriminal techniques to defraud companies out of roughly $29 million. Few details of the plea agreements were immediately available. Arkady Bukh, defense counsel for Ovysannikov, declined to say to which counts his client intends to plead guilty. Attorneys for Timchenko did not respond Friday to phone […]

The post Two Methbot suspects set to plead guilty as alleged ringleader maintains his innocence appeared first on CyberScoop.

Continue reading Two Methbot suspects set to plead guilty as alleged ringleader maintains his innocence

How much of the cybersecurity talent shortage is self-inflicted?

Money matters when it comes to recruiting cybersecurity staffers. But, beyond salary, a combination of factors have contributed to the widespread skills shortage, and some issues are worsened by the industry itself. Various studies suggest the shortage of qualified cybersecurity candidates is set to hit 3.4 million unfilled positions by 2021, up from the current level of 2.93 million, with 500,000 of those empty seats located in the U.S. It’s the kind of existential problem that makes other headaches worse, resulting in possible data breaches not being investigated and the rise of untested security vendors hawking artificial intelligence tools that promise to help corporate security teams run with fewer humans. And yet, while enterprise executives and recruiters agree there is a significant dearth of skilled security professionals, there is a surge of momentum behind the argument that the industry’s staffing shortage is self-inflicted. The lack of qualified job candidates isn’t […]

The post How much of the cybersecurity talent shortage is self-inflicted? appeared first on CyberScoop.

Continue reading How much of the cybersecurity talent shortage is self-inflicted?

Russian hacker to plead guilty in connection with 2014 breach at JPMorgan Chase

A Russian man accused of hacking into U.S. financial networks has agreed to plead guilty in a case that resulted in the theft of information about more than 80 million people. Andrei Tyurin is scheduled to appear in a courtroom in the Southern District of New York on Monday, according to a Sept. 13 court filing from the U.S. Department of Justice. Tyurin is set to please guilty in connection with a 2014 breach at JPMorgan Chase in which hackers made off with data about some 83 million people. Tyruin was charged in the same indictment as Gery Shalon, an Israeli man who allegedly masterminded the Chase hack and other breaches, though that prosecution remains unresolved. Tyurin, now 36, also was accused of participating in a Shalon-led scheme to infiltrate other financial institutions, including E*Trade, and carrying out a securities fraud scheme in which the scammers artificially inflated the price […]

The post Russian hacker to plead guilty in connection with 2014 breach at JPMorgan Chase appeared first on CyberScoop.

Continue reading Russian hacker to plead guilty in connection with 2014 breach at JPMorgan Chase

Latest Facebook shutdown involves hundreds of accounts misleading users in Ukraine, Iraq

Facebook announced on Monday its taken hundreds of accounts, pages and groups offline upon determining they were engaged in separate information operations with roots in Iraq and Ukraine. The company caught 244 accounts, 269 pages, 80 groups and seven Instagram pages that were used to mislead legitimate Facebook users about their behavior, Nathaniel Gleicher, Facebook’s head of cybersecurity policy, said in a blog post. Facebook has for months publicized its account removals, in which the social media giant scrubs pages deemed to be violating Facebook policy, typically by lying about their true location or account owner. The company’s general term for the offenses is “coordinated inauthentic behavior.” Gleicher repeatedly has stressed that Facebook takes these actions based on apparent user behavior, not the content posted. In this case, Facebook removed 168 accounts, 149 pages and 79 groups for activity focused on Ukraine. People involved in this operation used fake identities […]

The post Latest Facebook shutdown involves hundreds of accounts misleading users in Ukraine, Iraq appeared first on CyberScoop.

Continue reading Latest Facebook shutdown involves hundreds of accounts misleading users in Ukraine, Iraq

Employees from Israeli spyware vendor Ability arrested in probe of ‘significant’ issues

Israeli authorities have arrested multiple employees of the spyware vendor Ability in connection with an investigation into allegations of fraud, smuggling and money laundering at the company, the firm’s chief financial officer said Monday in a U.S. regulatory filing. Avi Levin, CFO of Ability Inc., confirmed to the U.S. Securities and Exchange Commission Monday that employees from subsidiaries Ability Security Systems Ltd. and Ability Computer & Software Industries Ltd. were taken into custody on suspicion of breaking the law on a “significant scale” as part of their business activities. The SEC update followed prior reports from Israeli media outlets indicating the Israeli Defense Ministry has been investigating the firm for allegedly violating international law which regulates Israeli security export controls. Tel Aviv-based Ability was co-founded by CEO Anatoly Hurgin and CTO Alexander Aurovsky. It is best known for marketing hacking tools, like ULIN, which stands for “Ultimate Interception,” to international governments. […]

The post Employees from Israeli spyware vendor Ability arrested in probe of ‘significant’ issues appeared first on CyberScoop.

Continue reading Employees from Israeli spyware vendor Ability arrested in probe of ‘significant’ issues