Researchers suggest Gorgon Group behind hacking spree that abused Bit.ly and Blogspot functionalities

A hacking campaign that targeted victims around the world used Blogspot, Pastebin and the link-shortening service Bit.ly to carry out its attacks, according to research published Wednesday by the security vendor Palo Alto Networks. Palo Alto’s Unit 42 research group in March uncovered what it has called the Aggah campaign, a digital crime spree focused on organizations in the U.S., Middle East, Europe and throughout Asia. The group distributes malicious macro-enabled documents which rely on Blogspot posts and multiple Pastebin posts for a command-and-control infrastructure. Researchers suggested the hacking campaign originated with the Gorgon Group, a collective that’s carried out a string of attacks from Pakistan over the past year, though Unit 42 said it’s too soon to directly attribute the Gorgon Group with any level of certainty. “Unfortunately, our current data set does not afford insight into the attackers’ motivation other than to compromise a large number of victims,” […]

The post Researchers suggest Gorgon Group behind hacking spree that abused Bit.ly and Blogspot functionalities appeared first on CyberScoop.

Continue reading Researchers suggest Gorgon Group behind hacking spree that abused Bit.ly and Blogspot functionalities

Fortinet settles charges of selling intentionally mislabeled Chinese-made tech to U.S. military

Security vendor Fortinet has agreed to pay the equivalent of $545,000 to settle allegations it illegally sold the U.S. military Chinese technology disguised as American-made equipment, the U.S. Department of Justice announced. The Sunnyvale, California-based cybersecurity company agreed to pay the government $400,000 and provide the U.S. Marine Corps with equipment valued at $145,000 to resolve charges it violated the False Claims Act from January 2009 until the fall of 2016, according to a statement. Fortinet acknowledged that an employee responsible for supply chain management altered labels on products to make them appear compliant with the Trade Agreements Act, a law prohibiting federal agencies from acquiring products in specific countries. The unnamed employee directed others at Fortinet to include the phrases “Designed in the United States and Canada” or “Assembled in the United States” before those products were sold to distributors and resellers who resold the technology to the government. “Contractors […]

The post Fortinet settles charges of selling intentionally mislabeled Chinese-made tech to U.S. military appeared first on CyberScoop.

Continue reading Fortinet settles charges of selling intentionally mislabeled Chinese-made tech to U.S. military

Alleged Methbot scammer Zhukov asks judge for new attorney in ad fraud case

Aleksandr Zhukov is not happy. The accused leader of an advertising fraud scheme that U.S. officials say defrauded international companies out of millions of dollars wrote a letter last week to Judge Edward Korman of the Eastern District of New York asking for assistance in finding new legal representation. Zhukov, in the note submitted Friday, asked the judge to appoint Simone Bertollini, a New York-based attorney, as his public defender. He hopes to hire Bertollini because of the attorney’s representation of Fabio Gasperini, an Italian man convicted in 2017 of operating a botnet of 100,000 hacked computers for malicious purposes. Bertollini would replace Igor Litvak, another New York-based attorney who withdrew from the case in March because of Zhukov’s inability to pay his legal fees. Litvak also appeared to be negotiating with prosecutors seeking a plea deal, though it’s clear now Zhukov intends to go to trial. In his letter to Korman, […]

The post Alleged Methbot scammer Zhukov asks judge for new attorney in ad fraud case appeared first on CyberScoop.

Continue reading Alleged Methbot scammer Zhukov asks judge for new attorney in ad fraud case

Shimo VPN service contains six unpatched vulnerabilities, Talos discovers

A series of vulnerabilities in virtual private network service Shimo’s Helper Tool, a popular app used to connect multiple VPNs for Mac operating systems, would make it possible for hackers to obtain root control, according to research published Monday by Cisco’s Talos research team. Researchers detailed six vulnerabilities in the Shimo VPN Helper Tool that relies on to carry out its privileged work, according to a blog post. Details of the vulnerabilities were released after Cisco made “repeated attempts” to communicate with Shimo over 90 days to no avail, Talos said. Shimo did not immediately respond to a request for comment from CyberScoop. One vulnerability, listed as CVE-2018-4004, is a privilege escalation vulnerability that resides in the Shimo VPN helper’s disconnectService function, and would allow a “non-root user to kill privileged processes on the system.” Another, CVE-2018-4007, resides in the deleteConfig functionality and “could allow an attacker to delete any […]

The post Shimo VPN service contains six unpatched vulnerabilities, Talos discovers appeared first on CyberScoop.

Continue reading Shimo VPN service contains six unpatched vulnerabilities, Talos discovers

Microsoft email breach gave hackers access to account information for months

Microsoft has experienced a data breach involving attackers leveraging a customer support account to access customers’ email information, including the content of some email content, according to news reports. The company on Saturday confirmed to TechCrunch that a “limited” number of people who rely on Microsoft-managed email services such as @Outlook.com, @MSN.com and @Hotmail.com experienced account compromises. Microsoft notified users that hackers may have had able to access information about their accounts — including their email address, email subject lines, and frequent contacts — but not the contents of any messages or attachments, according to TechCrunch. Hackers were in fact able to access email content from “a large number” of Outlook, MSN, and Hotmail email accounts, Motherboard reported Sunday. A source told Motherboard reporter Joseph Cox outsiders could exploited a customer support portal to infiltrate any normal customer account, reading contents including the body of an email message. Enterprise accounts […]

The post Microsoft email breach gave hackers access to account information for months appeared first on CyberScoop.

Continue reading Microsoft email breach gave hackers access to account information for months

U.K. fines company that collected data from new moms, then sold it to Equifax

Bounty UK, a pregnancy and parenting club, has been hit with the equivalent of a $524,000 fine for illegally sharing personal information belonging to more than 14 million people with credit reference and marketing agencies, Britain’s data protection authority announced Friday. The U.K. Information Commissioner’s Office fined Bounty UK £400,000 for collecting personal information “directly from new mothers at hospital bedsides,” through merchandise claim cards, its website and mobile app. The company collected information from new mothers, mothers-to-be, as well as the birth dates and genders of young children, according to the ICO. Bounty UK then would supply that data, some 34.4 million records, to 39 third party services including Equifax and other data brokers that in the past have failed to protect customer information. The fine was enforced for violations of the U.K.’s Data Protection Act, which requires firm to be transparent in their data collection practices, and involves […]

The post U.K. fines company that collected data from new moms, then sold it to Equifax appeared first on CyberScoop.

Continue reading U.K. fines company that collected data from new moms, then sold it to Equifax

Why bug bounty firms want to be penetration testing companies

A popular form of crowdsourcing might have a problem with the size of its crowd. Most of the high-value digital security vulnerabilities reported to bug-bounty programs are found by just a fraction of the freelance researchers who participate in those contests, recent reports show, suggesting that there are not enough skilled bounty hunters to handle the available work. The trend has big implications for an industry that has come to expect regular growth over the past half-decade. For the companies, it means their customers — corporations such as Fiat Chrysler, LinkedIn, Starbucks and others — are paying to hear about lots of low-severity bugs while more critical problems potentially remain undiscovered. The latest numbers come from the 2019 Hacker Report by HackerOne, one of the leading bug bounty platforms along with Bugcrowd and Synack. Seventy-two percent of the hackers polled by HackerOne said they preferred to probe for vulnerabilities in websites. Compare that to the 3.5 percent who […]

The post Why bug bounty firms want to be penetration testing companies appeared first on CyberScoop.

Continue reading Why bug bounty firms want to be penetration testing companies

An attempted password crack was enough for a U.S. indictment against Julian Assange

The U.S. government unsealed an indictment Thursday charging Julian Assange with a single count of conspiracy to commit computer intrusion for allegedly agreeing to help crack a password on a protected U.S. government computer. Legal experts who spoke with CyberScoop said Assange didn’t actually have to directly hack anything to violate the Computer Fraud and Abuse Act (CFAA), which was enacted in 1984 to prohibit unauthorized access to a computer system. Assange, the founder of WikiLeaks, in March 2010 was engaged in a conspiracy with former U.S. Army soldier Chelsea Manning (formerly Bradley) to access and publish classified material stolen from U.S. government networks, the indictment says. By actively participating in the collection of data from a protected government network, rather than receiving it from a source after the collection — as journalists typically do — Assange is legally liable, according to prosecutors. After Manning provided Assange with “hundreds of thousands” of government […]

The post An attempted password crack was enough for a U.S. indictment against Julian Assange appeared first on CyberScoop.

Continue reading An attempted password crack was enough for a U.S. indictment against Julian Assange

Corporate giants want to help students, feds and themselves by offering cyber pros $75,000 in loan assistance

It’s just like the old saying: When you can’t hire them, offer to pay their student loan debt. Microsoft, Mastercard and Workday announced this week they’ve teamed with 11 federal government agencies as part of a Cyber Talent Initiative meant to fill hundreds of thousands of open cybersecurity jobs. Graduating college students can apply for a two-year placement in a security role at the FBI, CIA or another agency. At the end of that two years they’ll be eligible for a position at one of those three companies, which will pay up to $75,000 of their student loan debt as part of their deal. The Cyber Talent Initiative appears to be unique in the way it offers student loan assistance, but it’s hardly the only corporate effort meant to enhance an enterprise’s security posture. Mastercard and Microsoft also are involved with the Cyber Readiness Institute, a program in which Fortune […]

The post Corporate giants want to help students, feds and themselves by offering cyber pros $75,000 in loan assistance appeared first on CyberScoop.

Continue reading Corporate giants want to help students, feds and themselves by offering cyber pros $75,000 in loan assistance

New APT group TajMahal operates as a ‘full-blown spying network,’ Kaspersky says

Researchers have uncovered an advanced persistent threat that for at least five years has used an array of hacking tools and covert automatic updates as part of a hacking campaign that bears little technical similarity to any other APT. The “TajMahal” cyber-espionage group uses software backdoors, audio recorders, keyloggers, screen and webcam grabbers, cryptography key stealers and up to 80 malicious modules as part of a “full-blown spying framework,” according to research published Wednesday by Kaspersky Lab. TajMahal relies on an entirely new base of code that has no similarities to other known malware or APT techniques, helping its operators avoid detection between August 2013 and April 2018, researchers found. “Just to highlight its capabilities, TajMahal is able to steal data from a CD burnt by a victim as well as from the printer queue,” Kaspersky said in a blog post. “It also can request to steal a particular file from […]

The post New APT group TajMahal operates as a ‘full-blown spying network,’ Kaspersky says appeared first on CyberScoop.

Continue reading New APT group TajMahal operates as a ‘full-blown spying network,’ Kaspersky says