Researchers uncover malicious sites targeting China’s Uyghur population

Eleven websites related to China’s Uyghur population and the East Turkestan region where they reside were compromised and exploited as part of a surveillance operation that may be connected to an iOS hacking campaign revealed last week, according to new security research. Volexity, an incident response and digital forensics firm, on Monday said at least 11 websites had been “strategically compromised and leveraged as part of a series of attack campaigns” aimed at the Uyghur people. By using the affected websites — which range from the Uighur Times, the Turkistan Press, Turkistan TV, and the Uyghur Academy — hackers could infect visitors’ Android devices and collect information including the unique identification number, the phone number, location, CPU data, username and other sensitive details. Volexity did not directly attribute the attack to Beijing, saying only that two advanced persistent threat (APT) groups with ties to Chinese were behind it. The Chinese […]

The post Researchers uncover malicious sites targeting China’s Uyghur population appeared first on CyberScoop.

Continue reading Researchers uncover malicious sites targeting China’s Uyghur population

Zerodium offers $2.5 million for Android zero-days, in keeping with market rates

For the first time, exploit sellers who provide Zerodium with fresh break-in techniques for Android devices can now earn more money from those tools than they would for similar hacks of iOS devices, the company announced Tuesday. The Washington, D.C., firm just updated its price list, promising to pay $2.5 million to hackers who demonstrate a zero-click exploit chain, a powerful tool that requires no user interaction, for Android devices. Compare that to the $1 million reward available for a one-click iOS full chain exploit against iOS, knocked down today from $1.5 million. Zerodium, founded in 2015, is dedicated to purchasing unpatched security vulnerabilities then re-selling those zero-days to corporate and government clients. It didn’t offer any specific explanations for the latest price changes. A security researcher who pays attention to the market said this round of updates might be pointing to some shifts in how Zerodium’s customers view iOS devices. “The change in exploit prices is […]

The post Zerodium offers $2.5 million for Android zero-days, in keeping with market rates appeared first on CyberScoop.

Continue reading Zerodium offers $2.5 million for Android zero-days, in keeping with market rates

Huawei accuses U.S. of hacking networks, menacing employees

Chinese telecommunication giant Huawei has accused U.S. authorities of using cyberattacks to interrupt its business and deploying police to harass employees, allegations that coincide with a growing investigation into the company’s international conduct. Huawei leveled the charges in a press release Tuesday, offering little evidence to substantiate its claims but denying it stole trade secrets from Rui Oliveira, a Portuguese inventor who accused Huawei of stealing his smartphone camera technology. U.S. prosecutors are probing Huawei for multiple instances of alleged intellectual property theft, according to the Wall Street Journal, while the firm also has become a focal point in the ongoing trade war between the U.S. and China. “For the past several months, the U.S. government has been leveraging its political and diplomatic influence to lobby other government to ban Huawei equipment,” the company said Tuesday. “Furthermore, it has been using every tool at its disposal — including both judicial and […]

The post Huawei accuses U.S. of hacking networks, menacing employees appeared first on CyberScoop.

Continue reading Huawei accuses U.S. of hacking networks, menacing employees

Google’s Project Zero details ‘indiscriminate’ hacking campaign against thousands of iPhones

Researchers from Google on Thursday announced the discovery of a hacking campaign in which attackers spent two years using breached websites to try to siphon information off thousands of iPhones, a blockbuster announcement that upends traditional narratives around Apple device security. Google’s Project Zero detailed the malicious activity with five so-called exploit chains, which demonstrate how hackers linked together Apple vulnerabilities to infiltrate Apple’s protections. By directing iPhone connections to specific web pages, hackers proved capable of accessing a device’s kernel and other key functionality, access they could abuse to secretly install malicious apps, monitor a user’s location, or take other action, Google said. The vulnerabilities affect iOS versions 10 through iOS 12.4. The vulnerabilities were patched in the latest update, iOS 12.4.1. Google’s research team discovered a total of 14 vulnerabilities, including seven for the Safari browser, five for the kernel and another two sandbox escapes (exploits that enable […]

The post Google’s Project Zero details ‘indiscriminate’ hacking campaign against thousands of iPhones appeared first on CyberScoop.

Continue reading Google’s Project Zero details ‘indiscriminate’ hacking campaign against thousands of iPhones

Russia’s state-funded news outlet RT keeps hyping fringe stories on Clinton, collusion long after 2016

Russian state media’s approach to the next U.S. presidential election will look a lot like the plan for the last one, if a new analysis of articles from the network RT is any indication. RT is a Kremlin-funded television network with a strong digital presence that broadcasts in English, Russian and a range of other languages. The outlet’s biases have been well documented, with English-language TV broadcasts, YouTube videos and articles on the RT website covering news through an anti-establishment and anti-government lens. Researchers from threat intelligence company Recorded Future analyzed content from RT’s website from Jan. 2017 through July 2019 to find that the Russian news agency continues to revisit the same topics in an apparent attempt to divide public opinion in the United States. The analysis was shared exclusively with CyberScoop prior to its publication Thursday. Phrases including “Hillary Rodham Clinton,” “Russian Hackers,” and “COLLUSION” (in all capital […]

The post Russia’s state-funded news outlet RT keeps hyping fringe stories on Clinton, collusion long after 2016 appeared first on CyberScoop.

Continue reading Russia’s state-funded news outlet RT keeps hyping fringe stories on Clinton, collusion long after 2016

Indictment of Capital One suspect alleges breaches of 30 companies, cryptojacking

A federal grand jury indicted Paige Thompson, the accused Capital One hacker, in connection with allegations that she accessed data on more than 30 companies and used that illicit access to generate cryptocurrency, the Department of Justice said Wednesday. Thompson was arrested on July 29 on suspicion of hacking into the bank’s systems and accessing data on roughly 106 million people. The indictment this week reiterates many of the allegations laid out in last month’s FBI complaint against Thompson, adding accusations that she obtained sensitive data from companies outside Capital One, including an unnamed university and a telecommunications firm. Federal attorneys from the Western District of Washington also say Thompson, upon breaching victim organizations, leveraged their computing power to mine for cryptocurrency, an activity known as cryptojacking. Thompson, 33, is a Seattle-based software engineer who formerly worked for Amazon Web Services, the cloud computing giant on which Capital One relies to […]

The post Indictment of Capital One suspect alleges breaches of 30 companies, cryptojacking appeared first on CyberScoop.

Continue reading Indictment of Capital One suspect alleges breaches of 30 companies, cryptojacking

Alleged CIA leaker’s attorneys now might have to become witnesses

The bizarre legal wrangling in the case of an accused CIA leaker took another turn this week when lawyers for Joshua Schulte asked the court to appoint new representation in the event the existing attorneys need to testify at trial. Defense attorneys, in an Aug. 26 letter, ask Judge Paul Crotty of the Southern District of New York to divide the case and appoint new counsel over “an ethical issue” in the matter. Schulte was charged last year with allegedly leaking U.S. government secrets to WikiLeaks, eventually resulting in the so-called Vault7 files. Later he was charged with conspiring to leak information from jail. The current moves are associated with those accusations. The attorneys now say Sabrina Schroff, who represents Schulte now, and Matthew Larsen, who previously consulted with Schulte, can testify to the defendant’s mental state before the alleged transmission of classified information from within Manhattan’s Metropolitan Correctional Center. Understanding Schulte’s […]

The post Alleged CIA leaker’s attorneys now might have to become witnesses appeared first on CyberScoop.

Continue reading Alleged CIA leaker’s attorneys now might have to become witnesses

A hacker accessed a Hostinger database containing information on 14 million customers

Internet domain registrar Hostinger International says it has reset customer passwords following a data breach in which an outsider accessed a database containing information about 14 million users. Founded in 2004, Hostinger is a web hosting service that markets itself as a digital backbone for small and medium websites. The site on Sunday disclosed a security incident, saying in a blog post that “an unauthorized third party has gained access to our internal system API, one of which had access to hashed passwords and other non-financial data about our customers.” The breached API database includes client usernames, emails, hashed passwords, first names and IP addresses about 14 million Hostinger users. The exact number of affected users of the 14 million in that database was not immediately clear. The hosting provider said it uses a cryptographic hash function to encrypt all client password by using a one-way mathematical process to convert […]

The post A hacker accessed a Hostinger database containing information on 14 million customers appeared first on CyberScoop.

Continue reading A hacker accessed a Hostinger database containing information on 14 million customers

The company behind ‘Time A.I.’ is suing the company behind Black Hat

Makers of a security product that was roundly mocked earlier this month at the Black Hat USA conference are out for revenge against the researchers who scrutinized their technology. Well, if not exactly those researchers, then…someone. Crown Sterling, which describes itself as an “emerging digital cryptography” vendor, filed a lawsuit Thursday accusing UBM, which organizes the Black Hat conference, for alleged breach of contract in connection with a controversy over a sponsored talk delivered during the recent conference. On Aug. 8, Crown Sterling CEO Robert Grant described “Time A.I.,” a technology he claimed would upend the world of encryption with its use of “quasi prime numbers” and “infinite wave conjugations.” Dan Guido, CEO of the consultancy Trail Of Bits, stood up toward the end of the presentation to say Grant “should be ashamed” of himself for hawking technology that others have described as bunk, and predicted Black Hat would remove […]

The post The company behind ‘Time A.I.’ is suing the company behind Black Hat appeared first on CyberScoop.

Continue reading The company behind ‘Time A.I.’ is suing the company behind Black Hat

YouTube disables 210 channels spreading disinformation about Hong Kong

YouTube has disabled 210 channels working as part of a “coordinated” influence operation against pro-democracy protesters in Hong Kong, who the Chinese government has sought to portray as terrorists or paid demonstrators. The Google-owned video streaming company on Thursday provided no details about the number of subscribers each channel had, the content of the videos they disseminated, the number of views each video had, nor other information about targeting. In a blog post, Shane Huntley, a member of Google’s threat analysis team, said only that this activity “was consistent with recent observations and actions related to China announced by Facebook and Twitter.” Both social media companies on Monday announced they had removed accounts spreading disinformation on Beijing’s behalf. Twitter cited “reliable evidence” tying the nefarious use of its platform to a state-sponsored effort. Chinese officials have sought to disrupt international media coverage showing that protests in the semi-autonomous territory are mostly peaceful. An estimated […]

The post YouTube disables 210 channels spreading disinformation about Hong Kong appeared first on CyberScoop.

Continue reading YouTube disables 210 channels spreading disinformation about Hong Kong