There’s a lot more to patching security vulnerabilities than you might think

Just because a technology company published a security update doesn’t mean the flaw it’s trying to fix is completely resolved. A security patch release is often the beginning of what could be a months-long process for companies of all sizes that need to weigh better security with possible unintended consequences, like knocking different areas of their business offline or interrupting client connections. While all companies wrestle with the risk surrounding patching — Look at Equifax, which analysts say will spend hundreds of millions of dollars related its 2017 breach, which could have been avoided had they patched a known vulnerability — the issue is particularly fraught for small companies. Forty-seven percent of small businesses polled by the insurer Hiscox last year said they were breached within the prior 12 months, and only 52 percent had a clearly defined security strategy. Meanwhile, nearly 60 percent of the companies polled by the […]

The post There’s a lot more to patching security vulnerabilities than you might think appeared first on CyberScoop.

Continue reading There’s a lot more to patching security vulnerabilities than you might think

CrowdStrike stock skyrockets on first day of NASDAQ trading

You can bet CrowdStrike executives hope the company has more days like Wednesday. The security vendor’s market value exceeded $12 billion on its first day of trading on the NASDAQ under the ticker symbol “CRWD.” That’s almost four times the company’s valuation in June 2018 when it raised $200 million in its last private round, good enough for a $3 billion valuation. The California-based company traded at $63 per share, nearly double its IPO price of $34. The big money was enough to attract attention from industry experts like Kelly Shortridge, vice president of product strategy at the vendor Capsule8 and an information security behavioral economist, who spent the day watching the ticker. Remember, huge pops on day 1 of the IPO aren’t proportionally beneficial. Doubling of the stock price, in this case, means they left a *lot* of $$$ on the table. In real dollar terms, $CRWD could‘be raised $1.4 billion […]

The post CrowdStrike stock skyrockets on first day of NASDAQ trading appeared first on CyberScoop.

Continue reading CrowdStrike stock skyrockets on first day of NASDAQ trading

Not quite fake news: Twitter accounts amplify old stories to sow discord

Researchers are tracking a new kind of social media influence operation apparently meant to inflame Twitter users by re-packaging old news and amplifying divisive content. More than 215 social media accounts have re-posted news about terrorism, racism and other contentious topics from legitimate media outlets, apparently in an attempt to amplify U.S. schisms, according to research published Wednesday by the threat intelligence firm Recorded Future. The news was real but often outdated by years, and links to the international news organizations were cloaked under URL shorteners to make the headlines appear current. The activity dates back to May 2018. The campaign, which Recorded Future calls “Fishwrap,” marks a subtle evolution in information operations because, by posting news about actual events, the accounts are clearly violating any terms of service and therefore have been able to avoid a general suspension, the company said. Researchers did not attribute the activity to a specific country or […]

The post Not quite fake news: Twitter accounts amplify old stories to sow discord appeared first on CyberScoop.

Continue reading Not quite fake news: Twitter accounts amplify old stories to sow discord

Evernote patches flaw potentially affecting 4.6 million users of Google Chrome extension

Evernote last month fixed a security flaw in a Google Chrome extension that could have allowed hackers to access information about roughly 4.6 million users, according to new research. Security vendor Guardio announced Wednesday it had discovered a vulnerability in Evernote’s Web Clipper extension for Chrome that could have allowed attackers to bypass the browser’s “same origin policy,” a security protocol meant to limit malicious scripts from spreading. Exploiting the flaw would have allowed attackers to gain privileges outside Evernote’s domain in Chrome — including access to a user’s other web content and services, researchers said. Evernote resolved the flaw within days, Guardio said, and there is no evidence the bug was exploited. Evernote did not respond to a request for comment from CyberScoop. The California company designs note-taking software that syncs and archives user files like lists, file attachments and websites between multiple devices. “Evernote was at the top of the list […]

The post Evernote patches flaw potentially affecting 4.6 million users of Google Chrome extension appeared first on CyberScoop.

Continue reading Evernote patches flaw potentially affecting 4.6 million users of Google Chrome extension

Have I Been Pwned enlists KPMG to find a buyer

As the mergers and acquisitions activity in the cybersecurity industry continues at a feverish pace, one of its more consumer-friendly brands — the breach-notification database Have I Been Pwned — is hoping for a new home. Have I Been Pwned, a website where visitors can check if their email address has been compromised, is exploring a sale, founder Troy Hunt revealed in a blog post Tuesday. Since its debut in 2013 the site has won praise as a uniquely free and user-friendly way for individuals to get information about incidents. Nearly 3 million people have subscribed to its breach notifications, and 120,000 individuals use it to monitor web domains. Now, Hunt says he will be working with the mergers and acquisitions team at the professional service firm KPMG to search for a potential buyer. He’s calling the process Project Svalbard — an allusion to a massive bank of plant seeds in Norway. “[I]’m already […]

The post Have I Been Pwned enlists KPMG to find a buyer appeared first on CyberScoop.

Continue reading Have I Been Pwned enlists KPMG to find a buyer

That push notification on your phone might be a phishing attempt

Maybe we should have seen this one coming. Scammers are trying to dupe smartphone owners into turning over their personal information by clicking on push notifications that look like legitimate messages from well-known companies. The messages actually direct recipients to phishing pages, where they’ll be asked to enter their credentials, according to a new scam technique the mobile security company Lookout has detected in recent months. Researchers are still examining the phishing technique, says David Richardson, senior director of product management at Lookout, but he says it’s clear hackers are taking advantage of people’s willingness to trust their mobile devices. Lookout detected one phishing campaign in which attackers created what appeared to be a Chrome notification alerting them to a missed call. They also pointed to an example of how hackers could illicitly use logos from trustworthy companies like Slack to make a push notification look legitimate. Still have to […]

The post That push notification on your phone might be a phishing attempt appeared first on CyberScoop.

Continue reading That push notification on your phone might be a phishing attempt

More than 1 million accounts from retro gaming site Emuparadise compromised

A security incident at Emuparadise, a website where users can play classic video games, has exposed information belonging to 1.1 million accounts, according to breach-tracking site Have I Been Pwned. An April 2018 breach on the vBulletin forum section of Emuparadise resulted in the compromising of 1.1 million email addresses, IP addresses, and username and passwords as salted MD5 hashes, according to a Have I Been Pwned announcement. The data was provided to Have I Been Pwned by DeHashed.com, which tracks when user credentials are exposed in large data breaches. The 19-year-old Emuparadise has called itself “the biggest retro gaming website on Earth” by offering nostalgia-laced titles that debuted on old consoles like the Nintendo 64, Super Nintendo, Sega Genesis and others. Few details about the incident immediately were available, though Bleeping Computer reports that the data was for sale on the dark web dating back to January 2019, when it was […]

The post More than 1 million accounts from retro gaming site Emuparadise compromised appeared first on CyberScoop.

Continue reading More than 1 million accounts from retro gaming site Emuparadise compromised

Google’s Triada backdoor demonstrates vulnerabilities in the mobile supply chain

Hackers in 2017 surreptitiously installed malicious software on Android phones by inserting code in apps and programs built by third party vendors, Google said in a blog post Thursday. The novel hacking technique was designed to load a customers’ phone with spam and unauthorized advertisements all before it even arrived in customers’ hands. When phone manufacturers wanted to include features not approved by the Android Open Source Project, like a face unlock program, Google said, those companies may hire unauthorized third party companies to build the features for them. In this case, a malware group, known as Triada, devised a way to exploit those third parties to pre-install backdoors onto the Android devices. “By working with the OEMs and supplying them with instructions for removing the threat from devices, we reduced the spread of preinstalled Triada variants and removed infections from the devices through the [over-the-air] updates,” Google said. “The […]

The post Google’s Triada backdoor demonstrates vulnerabilities in the mobile supply chain appeared first on CyberScoop.

Continue reading Google’s Triada backdoor demonstrates vulnerabilities in the mobile supply chain

Magecart’s ‘shotgun approach’ to payment card theft is wreaking havoc on e-commerce sites

It’s a good time to be in the credit card-stealing business. Hacking associations like Magecart — a loose collection of at least 12 groups that specialize in skimming payment data from digital checkout pages — are carrying out more efficient attacks to walk off with online shoppers’ data. By injecting malicious code into vulnerable e-commerce systems in anywhere from the payment system Magento to advertisements and analytics pages, thieves are able to exfiltrate payment information without detection. Before scammers hit Amazon’s CloudFront content delivery network last week and Forbes magazine in May, Magecart was best known for shaking down popular sites like Ticketmaster and British Airways. Each group relies on different techniques, ranging from exploiting server vulnerabilities to using unique skimming code and, in the case of Group 5, which was blamed for the Ticketmaster breach, hacking third party suppliers. “It’s like a shotgun approach to mass compromise,” said Yonathan […]

The post Magecart’s ‘shotgun approach’ to payment card theft is wreaking havoc on e-commerce sites appeared first on CyberScoop.

Continue reading Magecart’s ‘shotgun approach’ to payment card theft is wreaking havoc on e-commerce sites

Corporations beware: Dark web markets are selling tools targeting your accounts

If a cybercriminal wants to cause trouble for a major corporation, tools for the job are widely available on dark web markets, according to researchers who spent three months analyzing their activity and interacting with sellers. The wares — including malware and leaked credentials — are specifically promoted for breaching companies on the Fortune 500 and the Financial Times Stock Exchange 100 Index, according to Mike McGuire, a senior lecturer in criminology at the University of Surrey, and the security vendor Bromium. Their research includes data collected from Empire Market, The Hub, and the now-shuttered Dream and Wall Street markets, among others. The findings come amid a period of heightened law enforcement activity on the dark web, with international police recently seizing a number of sites that primarily sold drugs. Forums where members buy and sell hacking tools and access to breached email accounts have survived the dragnet. The financial sector was the target of most of the […]

The post Corporations beware: Dark web markets are selling tools targeting your accounts appeared first on CyberScoop.

Continue reading Corporations beware: Dark web markets are selling tools targeting your accounts