After ‘significant’ malware attack, U.S. Coast Guard issues maritime security advisory

The U.S. Coast Guard has issued a safety alert encouraging mariners to follow basic cybersecurity protocols after a ship bound for the East Coast experienced a “significant cyber incident” in February. The Coast Guard said the deep draft ship was traveling to the Port of New York and New Jersey from international waters earlier this year when it experienced an incident affecting its shipboard network. An interagency team of specialists responded, finding that “malware significantly degraded the functionality of the onboard computer system,” though the boat’s essential controls were not affected, the Coast Guard said Monday. The shipboard network had been used to conduct official business, like updating electronic charts, managing cargo information and communicating with onshore resources. The warning comes as maritime traffic has become a prominent venue for ongoing tensions between Iran and Saudi Arabia and its allies, including the United States. In March, the FBI privately notified industry of cyberthreats to U.S. […]

The post After ‘significant’ malware attack, U.S. Coast Guard issues maritime security advisory appeared first on CyberScoop.

Continue reading After ‘significant’ malware attack, U.S. Coast Guard issues maritime security advisory

British Airways fined $229 million under GDPR for data breach tied to Magecart

Britain’s data protection watchdog says it will fine British Airways £183.39 million ($229.2 million) for security weaknesses that made it possible for hackers to steal information about roughly 500,000 customers. The U.K. Information Commissioner’s Office said Monday it would fine the airline for violating the European Union’s General Data Protection Regulation. By exploiting weaknesses in British Airways’ site last year, a hacking group known as Magecart was able to collect customer payment card numbers, travel booking details and other sensitive data. The fine would be the largest issued yet under GDPR, surpassing the €50 million levied by French regulators on Google. “When an organization fails to protect [personal data] from loss, damage or theft it is more than an inconvenience,” U.K. Information Commissioner Elizabeth Denham said in a statement. “That’s why the law is clear – if you are entrusted with personal data you must look after it. Those that don’t […]

The post British Airways fined $229 million under GDPR for data breach tied to Magecart appeared first on CyberScoop.

Continue reading British Airways fined $229 million under GDPR for data breach tied to Magecart

$3 million hack of Bangladesh ATMs was by Russian group called Silence, researchers say

A small Russian hacking group should be considered the main suspect in a bank heist of $3 million in Bangladesh, according to research published Wednesday. The group, which researchers are calling “Silence,” appears to have softened up access controls on Dutch Bangla Bank ATMs before money mules made a series of cash withdrawals ending on May 31, according to Group-IB, an international security vendor with headquarters in Singapore. Infrastructure used in the past by Silence hackers communicated with external IPs from Dutch Bangla Bank in the months prior to the cash extractions, Group-IB said. By abusing access to the banking system, Silence could have removed withdrawal limits on the ATMs. The money mules were caught on security cameras. Local law enforcement officials previously said the crooks might be connected with Lazarus Group, a cybercrime organization linked to North Korea, according to local news reports. Lazarus is the same hacking team that was blamed for trying to steal nearly $1 […]

The post $3 million hack of Bangladesh ATMs was by Russian group called Silence, researchers say appeared first on CyberScoop.

Continue reading $3 million hack of Bangladesh ATMs was by Russian group called Silence, researchers say

CBP suspends Perceptics from doing government business following data breach

U.S. Customs and Border Protection officials suspended Perceptics, the provider of license-plate scanners and other surveillance technology, from federal contracting following a data breach that exposed travelers’ information, according to federal records first obtained by the Washington Post. CBP last month said one of its subcontractors, later identified as Perceptics, was breached in a “malicious cyberattack” that resulted in images of travelers’ faces, license plates, contracting documents and other data being made publicly available on the internet. Now, the Post reports, CBP has taken the rare step of punishing a federal contractor, citing “evidence of conduct indicating a lack of business honesty or integrity.” As a result, Perceptics is prohibited from doing business with the government, a punishment that could last for years if the company is placed on a government blacklist. CBP said on June 12 that a subcontractor had violated government policy by transferring images of license plates […]

The post CBP suspends Perceptics from doing government business following data breach appeared first on CyberScoop.

Continue reading CBP suspends Perceptics from doing government business following data breach

FTC settles with device maker D-Link, requires ‘comprehensive’ security effort

Device manufacturer D-Link Systems has agreed to implement a “comprehensive software security program” to settle Federal Trade Commission charges that the company exposed customer data to hackers while advertising top-of-the-line security measures. D-Link will not pay any financial penalties as part of the settlement, but its manufacturing process will have to threat modeling; tests for security bugs prior to a product’s release; ongoing device monitoring to address flaws; automatic firmware updates; and the acceptance of vulnerability reports from researchers. The government’s litigation against the Southern California company, which makes wireless routers and smart cameras, began in 2017. Regulators found that D-Link, despite billing its products as having “advanced network security,” actually failed to test them and did not remediate “well known and preventable security flaws.” That same year, researchers found 10 vulnerabilities in a single D-Link router model that could have been exploited to take over a device. Under the settlement, the company also will be subject […]

The post FTC settles with device maker D-Link, requires ‘comprehensive’ security effort appeared first on CyberScoop.

Continue reading FTC settles with device maker D-Link, requires ‘comprehensive’ security effort

Newly reported flaws in cameras, locks add to scrutiny of smart-home security

Homeowners trying to protect their property with surveillance cameras and smart locks may have actually made their households more vulnerable, according to security flaws unveiled by separate teams of researchers Tuesday. The Netgear Arlo system, which the company says streams more than 100 million videos every day, and certain types of Zipato smart hubs, which can lock or unlock doors, are affected by security flaws detailed in unrelated announcements from Tenable and researchers Chase Dardaman and Jason Wheeler, respectively. The discoveries again demonstrate how the same technology that promises to make life more convenient and secure also can put consumers at risk. Patches are available for both vulnerabilities, and hackers would need physical access in both cases to carry out attacks. The weakness in the Arlo devices could allow malicious outsiders to take control of all the cameras connected to a single hub, at which point they could disable the video […]

The post Newly reported flaws in cameras, locks add to scrutiny of smart-home security appeared first on CyberScoop.

Continue reading Newly reported flaws in cameras, locks add to scrutiny of smart-home security

Google Play Store scrubs more than 100 adware-infected camera and gaming apps

Next time you’re thinking about downloading a new app — especially if it’s a freebie from the Google Play Store — and ask yourself: Is this worth getting hacked over? If that sounds overly cautious, look at new findings published Monday by Trend Micro, which provide the latest evidence that the Play Store is littered with programs that aim to leverage unwitting users’ devices for their own purposes. The problem of malicious apps isn’t new, but the urgency to solve the problem is growing as web users increasingly connect to the internet with only their phone, and scammers’ techniques evolve. Researchers from the Japanese security giant found 182 gaming and camera-related apps, which collectively had been downloaded more than 9.3 million times, that came loaded with malicious software that exploited victims’ phones to boost advertising revenue. This discovery come less than a week after Symantec and Wandera unveiled other Android apps meant to […]

The post Google Play Store scrubs more than 100 adware-infected camera and gaming apps appeared first on CyberScoop.

Continue reading Google Play Store scrubs more than 100 adware-infected camera and gaming apps

Dozens of Facebook pages about current events in Libya were linked to malware

Hackers used more than 30 Facebook pages to spread malicious software aimed at social media users following news about Libya, according to new findings. Researchers from the security vendor Check Point on Monday published details about Operation Tripoli, a coordinated campaign in which hackers used a network of seemingly legitimate Facebook pages to dupe users into downloading Windows malware. The pages impersonated people like Khalifa Haftar, the head of the Libyan National Army, militia leaders and a range of political causes urgent in the North African country. Attackers would use the pages to post malicious URLs, disguising the links as news or mobile applications. Facebook removed the pages — which collectively had hundreds of thousands of followers — after notification from researchers, Check Point said. A closer inspection of the attackers’ habits proved that a single account, known as “Dexter Ly,” was behind much of the activity, researchers said. It’s […]

The post Dozens of Facebook pages about current events in Libya were linked to malware appeared first on CyberScoop.

Continue reading Dozens of Facebook pages about current events in Libya were linked to malware

Scammers are spreading fake Jio apps to generate advertising revenue

Ad scammers are impersonating the Indian mobile network operator Jio, which has roughly 314 million subscribers, to trick Android users into downloading apps that are nothing more than malicious software, according to research published this week. Researchers from Symantec discovered 152 Android apps that promise to provide downloaders with free data boosts, but in fact flood device screens with advertisements in order to make a buck, the security vendor said in a blog post Wednesday. The programs appear with names like My Jio 4G and My Jio Offers, or other variations on the legitimate MyJio app. The malicious apps have been downloaded more than 39,000 times since January. The discovery reaffirms how insecure Android apps can leverage users’ phones in ways they never intended. The issue is especially pervasive in developing countries like India, where analysts have predicted that 829 million people will connect to the internet via smartphone by […]

The post Scammers are spreading fake Jio apps to generate advertising revenue appeared first on CyberScoop.

Continue reading Scammers are spreading fake Jio apps to generate advertising revenue

Chronicle, Alphabet’s push into security, will join Google Cloud

Alphabet’s moonshot appears to have flown off course. Google Cloud announced on Thursday it will takeover Chronicle, the cybersecurity company that Alphabet launched last year as part of its “moonshot program.” Chronicle began as an independent Alphabet company led by former Symantec chief operating officer Stephen Gillett. Chronicle launched its first product, the analytics tool Backstory, in March. “Chronicle’s products and engineering team complement what Google cloud offers,” Google Cloud CEO Thomas Kurian wrote in a blog post. “Chronicle’s VirusTotal malware intelligence services will be a powerful addition to the pool of threat data informing Google Cloud offerings, and will continue to support applications running on our platforms.” The companies are scheduled to be completely combined by the fall, Kurian added. This change comes after Google Cloud purchased Looker, a data analytics provider, for $2.6 billion with an eye on accelerating that company’s growth. Google said at the time that […]

The post Chronicle, Alphabet’s push into security, will join Google Cloud appeared first on CyberScoop.

Continue reading Chronicle, Alphabet’s push into security, will join Google Cloud