Meet ‘Simjacker,’ a nasty mobile vulnerability researchers say puts 1 billion phones at risk

A vulnerability in smartphone technology has made it possible for outsiders to conduct targeted surveillance against victims for the past two years, according to new security findings. Researchers from AdaptiveMobile Security said Thursday they found an SMS-based hacking technique that actively is being exploited by a spyware vendor to track individual phone users. The company did not disclose who is behind the surveillance or the identities of the victims. Researchers warned that the attack, dubbed “Simjacker,” has ramifications for more than 1 billion mobile phones worldwide. By relying on malicious text messages, hackers infect target phones to retrieve location information and other data. The attack leverages SIM cards, a circuit that stores customers’ international mobile subscriber information in a way that isn’t restricted to a single phone platform. “This is potentially the most sophisticated attack ever seen over core mobile networks,” Cathal Mc Daid, AdaptiveMobile Security’s chief technology officer, said in a […]

The post Meet ‘Simjacker,’ a nasty mobile vulnerability researchers say puts 1 billion phones at risk appeared first on CyberScoop.

Continue reading Meet ‘Simjacker,’ a nasty mobile vulnerability researchers say puts 1 billion phones at risk

Radio broadcaster Entercom hit with ransomware attack, reports say

A ransomware attack launched last week against Philadelphia-based radio conglomerate Entercom Communications resulted in the disruption of email service and crashed computers, according to media reports. Digital extortionists demanded payment of $500,000 to unlock the affected systems at the company, which owns 235 radio stations throughout the U.S. A memo obtained by the industry publication RadioInk warned employees not to connect their laptop to Entercom’s wired network, and to “not expect any resolutions to the above-listed problems for at least three to four days.” Employees are not permitted to discuss the matter with anyone outside the company, the note says in large bold font. Entercom said it was “experiencing a disruption of some IT systems” in a statement to RadioInk, and apologized for any inconvenience. The attack originated with a hacked machine in programming that spread through other systems, bringing down email, billing and shared network drives. Entercom reportedly will […]

The post Radio broadcaster Entercom hit with ransomware attack, reports say appeared first on CyberScoop.

Continue reading Radio broadcaster Entercom hit with ransomware attack, reports say

FIN7’s IT admin pleads guilty for role in billion-dollar cybercrime crew

An accused operator of the FIN7 hacking collective pleaded guilty on Wednesday to charges in connection with working as the administrator of the group that researchers have suggested stole more than $1 billion from victims worldwide. Fedir Hladyr, 34, appeared in a courtroom in the Western District of Washington to plead guilty to wire fraud and conspiracy to commit computer hacking as part of a deal with prosecutors that will result in a prison sentence of no more than 25 years, according to his defense attorney. Hladyr was arrested in Dresden, Germany in January 2018 and accused of working as an administrator for the FIN7 group who maintained servers and delegated responsibilities throughout the international hacking crew, among other duties. He is the first member of the group to be found guilty of hacking-related crimes in U.S. court. The case marks a significant win for the Department of Justice, which […]

The post FIN7’s IT admin pleads guilty for role in billion-dollar cybercrime crew appeared first on CyberScoop.

Continue reading FIN7’s IT admin pleads guilty for role in billion-dollar cybercrime crew

Cloudflare may have provided service to terrorists, drug traffickers in violation of U.S. sanctions

Internet services and cybersecurity provider Cloudflare has acknowledged it may have violated U.S. sanctions by doing business with terrorist groups and international drug traffickers, an admission that comes as the San Francisco company prepares to go public as soon as this week. Cloudflare voluntarily disclosed the possible economic and trade sanction violations to the U.S. Department of Treasury in its S-1 filing, amended to stipulate that Cloudflare technology was “used by, or for the benefit of, certain individuals or entities” named on the Office of Foreign Assets Control’s list of Specially Designated Nationals, as the Wall Street Journal first reported. The filing does not name specific parties, saying only that the group includes “entities identified in OFAC’s counter-terrorism and counter-narcotics trafficking sanctions programs, or affiliated with governments currently subject to comprehensive U.S. sanctions.” A small number of those entities also made payments to Cloudflare. The updated regulatory filing also notes […]

The post Cloudflare may have provided service to terrorists, drug traffickers in violation of U.S. sanctions appeared first on CyberScoop.

Continue reading Cloudflare may have provided service to terrorists, drug traffickers in violation of U.S. sanctions

U.S. arrests 281 people worldwide accused of involvement in BEC scams

The U.S. Department of Justice has announced the arrests of 281 people and the seizure of nearly $3.7 million in connection with a four-month investigation into business email compromise scams. Prosecutors on Tuesday detailed the results of an elaborate interagency probe into BEC scams, which occur when thieves impersonate a trusted co-worker, lover or other associate in order to convince a victim to send them money or personal information. Among the accused are a group of alleged scammers who defrauded a community college out of $5 million from Illinois, two men in Texas who prosecutors say used 12 fictitious identities to steal and launder more than $3 million, and a Florida crime ring that relied on 18 money mules to launder $950,000. Seventy-four people were taken into custody in the U.S, while there were also 167 arrests in Nigeria, 18 in Turkey, 15 in Ghana, and more in France, Italy, the […]

The post U.S. arrests 281 people worldwide accused of involvement in BEC scams appeared first on CyberScoop.

Continue reading U.S. arrests 281 people worldwide accused of involvement in BEC scams

Scraping public website data does not violate CFAA, judge rules

Scraping public data from a website without the website’s authorization is not a violation of the Computer Fraud and Abuse Act, a U.S. federal court ruled Monday, limiting a U.S. anti-hacking law that academics have criticized for allowing broad legal action against innocuous activity. The U.S. Court of Appeals for the Ninth Circuit on Monday refused to overturn a preliminary injunction that required professional networking site LinkedIn to allow talent management startup hiQ Labs to gather data from users’ public profiles. Microsoft-owned LinkedIn had installed technical safeguards to stop hiQ from sweeping up data on members until a court in 2017 ordered LinkedIn to stop blocking that automated collection. LinkedIn appealed, alleging hiQ had broken CFAA, among other things, by using LinkedIn data in a way LinkedIn did not intend. “LinkedIn has no protected property interest in the data contributed by its users, as the users retain ownership over their […]

The post Scraping public website data does not violate CFAA, judge rules appeared first on CyberScoop.

Continue reading Scraping public website data does not violate CFAA, judge rules

Student faces two years behind bars for trying to hack into Trump’s tax records

A Philadelphia man has pleaded guilty in connection with a scheme to trick a U.S. government website into serving up the president’s tax returns. Andrew Harris, a student who attended Haverford College, admitted in court last week that he used a school computer and the Free Application for Student Aid website to try to access Donald Trump’s financial records. By opening a FAFSA account in the name of a Trump family member and using Trump’s Social Security number, Harris and another student apparently thought the FAFSA page would populate with Trump’s tax data. The attempt failed when the pair found a username and password for Trump already existed. Harris, 24, pleaded guilty on Sept. 5 to two misdemeanor counts of computer fraud. He faces two years in federal prison and a $200,000 fine. Another man, 22-year-old Justin Hiemstra of Minnesota, pleaded guilty last month. FAFSA is run by the Department of Education, […]

The post Student faces two years behind bars for trying to hack into Trump’s tax records appeared first on CyberScoop.

Continue reading Student faces two years behind bars for trying to hack into Trump’s tax records

‘Indiscriminate’ iOS hacking was relatively limited, Apple says. Try telling that to the Uighur population.

Apple doesn’t like what Google has been saying about Apple. The iPhone-maker released a surprise statement on Friday refuting assertions from Google’s Project Zero researchers, who last week revealed how hackers had exploited five chains of iOS vulnerabilities to spy on “thousands” of users. The high-profile report by Google did not identify the victims, but claimed those targeted were vulnerable for years if they simply visited an infected website. In its response, Apple described the attack as “narrowly focused,” rather than the kind of “en masse” targeting described by the Project Zero researchers. Apple confirmed that the hacking activity was aimed at the Uighur community, a Muslim population under mass surveillance by the Chinese government, and said the campaign involved fewer than a dozen websites. Apple said the attacks were “only operational” for two months, rather than two years. The statement takes issue with the scope and volume of Google’s findings, but does […]

The post ‘Indiscriminate’ iOS hacking was relatively limited, Apple says. Try telling that to the Uighur population. appeared first on CyberScoop.

Continue reading ‘Indiscriminate’ iOS hacking was relatively limited, Apple says. Try telling that to the Uighur population.

Accused Capital One hacker pleads not guilty to all charges

Paige Thompson has pleaded not guilty to all charges in connection with a data breach at Capital One that resulted in the compromise of information about roughly 106 million people. Thompson appeared in Western District of Washington federal court on Thursday for the first time after she was arrested on July 29 on charges related to the Capital One hack. A federal grand jury previously had indicted Thompson on two criminal counts, wire fraud and computer fraud and abuse, for which she could be sentenced to up to 25 years in prison if convicted. Upon being advised of her charges and pleading not guilty Thursday, Thompson was taken back into custody. A jury trial is scheduled to begin Nov. 4. Thompson, a software engineer, formerly worked for AWS, the cloud computing giant on which Capital One relies to store sensitive data. She allegedly built a customer scanning software that searched […]

The post Accused Capital One hacker pleads not guilty to all charges appeared first on CyberScoop.

Continue reading Accused Capital One hacker pleads not guilty to all charges

Apple’s $1 million bug bounty makes a lot more sense after that iOS hacking spree

Say what you will about Apple, but the company certainly knows how to get the security community fired up. Ivan Kristic, Apple’s head of security engineering, announced Aug. 8 at the Black Hat security conference that the company would offer up to $1 million, or $1.5 million under specific conditions, to hackers who disclosed new ways of infiltrating the iPhone’s operating system. That million-dollar promise instantly earned praise as the highest bug bounty offer from a technology company, and seemed to indicate the notoriously inaccessible company was becoming more transparent. The weeks since, though, have demonstrated that the stakes are higher for Apple than initially understood. The company’s stellar security reputation took a hit when Google’s Project Zero announced that hackers had spent two years targeting thousands of iPhones by combining 14 vulnerabilities into five exploit chains that allowed them to spy victims with few limitations. Now, researchers and bug bounty participants […]

The post Apple’s $1 million bug bounty makes a lot more sense after that iOS hacking spree appeared first on CyberScoop.

Continue reading Apple’s $1 million bug bounty makes a lot more sense after that iOS hacking spree