Craigslist founder’s organization gifts $1 million for election security

Craigslist founder Craig Newmark’s philanthropic organization will provide more than $1 million to the Global Cyber Alliance with the aim of securing media and election offices before the 2020 presidential election, GCA announced Tuesday. Craig Newmark Philanthropies will give $1.068 million to GCA, which has provided security tools to 7,300 public and private sector organizations, to protect journalists, secure voting-focused nonprofit organizations and enable election boards to invest in “cybersecurity protections to preserve election integrity,” GCA said in an announcement. The guidance will include tips from the Center for Internet Security’s top Critical Controls, which encourage planning, security audits and other best practices. The philanthropic organization has donated tens of millions to media organizations and journalism schools in recent years. It donated $1 million each to ProPublica and the Poynter Institute for Media Studies in 2017, and $20 million last year to the City University of New York’s graduate program […]

The post Craigslist founder’s organization gifts $1 million for election security appeared first on CyberScoop.

Continue reading Craigslist founder’s organization gifts $1 million for election security

Cyberattack at med-tech conglomerate Hoya slowed production at Thai factory by 60 percent

Japanese manufacturer Hoya temporarily shut down production at a factory in Thailand in February following a cyberattack, the company said. Roughly 100 computers were infected with malicious software that stole user credentials, then tried to install a program that would co-opt those machines into mining for cryptocurrency. The company detected the attack before the cryptojacking software took hold, though the initial stage of the attack caused output to drop by 60 percent, Hoya said Saturday. The news first was reported by local outlets including Kyodo News and The Japan Times. Hoya had yet to completely recover from the attack by the end of March, though one executive the attack would have “little” impact on business, according to The Japan Times. Reports have not specified what type of cryptocurrency the attackers were mining. Tokyo-based Hoya produces lenses, imaging devices, medical equipment and other technology. It has a $21.6 billion market capitalization, according to Forbes, […]

The post Cyberattack at med-tech conglomerate Hoya slowed production at Thai factory by 60 percent appeared first on CyberScoop.

Continue reading Cyberattack at med-tech conglomerate Hoya slowed production at Thai factory by 60 percent

Tax scammers impersonating ADP, Paychex with aim to steal financial information

Hackers are trying to steal Americans’ tax information ahead of the April 15 deadline by sending emails that appear to be from trustworthy sources at Paychex, ADP and elsewhere, according to IBM research published Monday. Those messages actually are laced with TrickBot, a malicious software strain that typically infects victims through a malicious Microsoft Excel attachment. TrickBot steals valuable data including banking credentials, allowing thieves to wire themselves money from the victim without immediate detection. It’s delivered in the form of spam emails from Paychex and ADP, exploiting users’ familiarity with those financial companies at the height of tax season. The emails, tracked in early March, landed in inboxes between 11:45 a.m. and 3:45 p.m. Eastern Standard Time, during U.S. working hours. They also were written in English, and used a technique known as typo-squatting, in which a hacker creates a fake website meant to look a legitimate one in […]

The post Tax scammers impersonating ADP, Paychex with aim to steal financial information appeared first on CyberScoop.

Continue reading Tax scammers impersonating ADP, Paychex with aim to steal financial information

Facebook hosted more than 70 cybercrime groups that advertised all types of illicit activity

Cybercriminals used 74 Facebook groups to buy and sell hacking tools, stolen information and rent out spam services, according to research published Friday by Cisco’s Talos threat intelligence group. Roughly 385,000 members speaking a variety of different languages were involved with the groups, which used obvious names such as “Spam Professional,” “Spammer & Hacker Professional” and “Facebook hack (phishing),” Talos reported. Researchers said anyone with a Facebook account could find the groups by searching for keywords such as “spam,” “carding,” or “CVV,” and Facebook’s algorithm then would suggest similar groups. While most groups have been removed, their size and reach again demonstrates how Facebook has struggled to prevent users from using the platform for nefarious purposes. Some of the pages detected by Talos researchers existed for up to eight years. “Talos initially attempted to take down these groups individually through Facebook’s abuse reporting functionality,” the researchers said. “While some groups […]

The post Facebook hosted more than 70 cybercrime groups that advertised all types of illicit activity appeared first on CyberScoop.

Continue reading Facebook hosted more than 70 cybercrime groups that advertised all types of illicit activity

Backdoor vulnerability in open source tool exposes thousands of apps to remote code execution

Roughly 28 million users have downloaded a malicious version of a popular open source framework that masquerades as the real thing, but in fact gives a hackers a back door into applications. A compromised version of the website development tool bootstrap-sass was published to the official RubyGems repository, a hub where programmers can share their application code. The open source security firm Snyk alerted developers to the issue Wednesday, advising users to update their systems away from the infected framework (version 3.2.0.3). “That doesn’t mean there are something like 27 million apps out there using this,” said Chris Wysopal, chief technology officer at app security company Veracode. “[But] when you’re using open source packages to build your applications, you’re inheriting many of the vulnerabilities. … But bootstrap-sass is a popular component used by enterprises and startups so there’s potentially thousands of applications affected by this.” While the vulnerability is serious — hackers […]

The post Backdoor vulnerability in open source tool exposes thousands of apps to remote code execution appeared first on CyberScoop.

Continue reading Backdoor vulnerability in open source tool exposes thousands of apps to remote code execution

German drug giant Bayer blames Chinese hacking group Wicked Panda for breach: report

German drug conglomerate Bayer says it was victimized in a cyberattack that originated with Chinese hackers, German media reported Thursday. The $39 billion pharmaceutical giant said it found malicious software on its computer networks last year and contained the breach, according to the outlets BR and NDR. Investigators examining the breach said attackers used the Winnti malware, which is tied to a Chinese-based hacking group known as Wicked Panda. The group in the past has been blamed for attacks on targets including the online gambling industry and companies with intellectual property that would benefit Beijing. Wicked Panda “makes use of a number of open-source and custom tools to infect and move laterally in victim networks,” according to a CrowdStrike description. “The group’s tools have been traced to “contractors who count multiple Chinese government agencies as clients, including the Ministry of Public Security. Observed targeting by the Wicked Panda adversary has […]

The post German drug giant Bayer blames Chinese hacking group Wicked Panda for breach: report appeared first on CyberScoop.

Continue reading German drug giant Bayer blames Chinese hacking group Wicked Panda for breach: report

Nevada data center used to distribute Dridex, GandCrab malware right under the FBI’s nose

Scammers used data centers located in the United States to launch nasty strains of malware against English-speaking web users, according to Bromium research published Thursday. The hacking campaign lasted from May 2018 to last month, and included five families of banking trojans, two families of ransomware and three forms of malware meant to collect victims’ personal information. The cybercriminal operation relied on U.S. data centers, with 11 web servers hosted at BuyVM, a virtual private server company in Nevada. The malware — identified as Neutrino, IcedID, GandCrab, and Dridex, among others — is estimated to have stolen millions from international banks. The location alone makes this operation unusual, Bromium noted, because hackers typically organize in areas outside the FBI’s reach. “It was interesting to us that the hosting infrastructure is located in the United States and not a jurisdiction that is known to be uncooperative with law enforcement,” the researchers […]

The post Nevada data center used to distribute Dridex, GandCrab malware right under the FBI’s nose appeared first on CyberScoop.

Continue reading Nevada data center used to distribute Dridex, GandCrab malware right under the FBI’s nose

Magecart is the most infamous payment skimmer. But it’s hardly the only one.

There’s been a steady stream of news about malware designed to skim customer payment data during e-commerce transactions, but research by security vendor Group-IB suggests that the problem is broader than the public might realize. JavaScript-sniffers — JS-sniffers for short — were lurking on 2,440 hacked websites that receive roughly 1.5 million unique daily visitors, according to research published Wednesday by the Moscow-based company. The malicious software essentially produces the same results as a credit card skimmer: Cybercriminals inject a few lines of code onto target websites, then sweep up account numbers, names, addresses and other information that’s valuable on dark web markets. And it’s not just Magecart, the best known group of JS-sniffers, Group-IB says. Twelve Magecart groups have been in operation, but Group-IB says its researchers discovered a total of 38 JS-sniffer groups — at least eight of which have not previously been investigated in detail. One JS-sniffer campaign, known as TokenLogin, was detected on sites that […]

The post Magecart is the most infamous payment skimmer. But it’s hardly the only one. appeared first on CyberScoop.

Continue reading Magecart is the most infamous payment skimmer. But it’s hardly the only one.

The ‘permission’ question is much different for iOS and Android apps, researchers say

It’s 2019, and digital scammers are going mobile. Do you know what your permissions allow? An analysis of 30,000 iOS applications released Wednesday by Wandera shows that social networking, weather, and e-commerce apps request access to lots of valuable information about users. Sixty-two percent of the iOS apps examined sought permission to a user’s photo library, while 55 percent requested camera access and 51 percent wanted to know a mobile user’s location. While app developers said they sought user permissions for a number of reasons — typically for functionality or for marketing purposes — Wandera’s research demonstrates the different risks mobile-device users can be up against, depending on what’s in their pocket. While hackers may exploit Androids to steal financial information or mine for cryptocurrency, iOS apps may abuse user trust for reasons that are less clear-cut. The London-based company’s previous research found that most Android apps asked for permission to connect to technical functions, […]

The post The ‘permission’ question is much different for iOS and Android apps, researchers say appeared first on CyberScoop.

Continue reading The ‘permission’ question is much different for iOS and Android apps, researchers say

Microsoft Edge, Internet Explorer zero-days could allow spying on your browsing activity

Two zero-day vulnerabilities in the updated versions of Microsoft Edge and Internet Explorer could enable outsiders to access confidential information shared between websites, according to new security research highlighted by Trend Micro Tuesday. The browser vulnerabilities were first made public March 29 by James Lee, a 20-year-old security researcher who says he first notified Microsoft about the issues 10 months ago. A Trend Micro analysis of the attacks found that if a web user visits a malicious page using either browser, attackers can exploit a process known as Origin Validation Error to gather information about other pages the user visited. Thieves could use this technique to bypass security measures and steal financial or other personal information, researchers said. “The browser is not restricting information about the website redirection properly, and instead allows [hackers] to access information about the client’s activities on other websites,” Trend Micro said in a blog post. “In […]

The post Microsoft Edge, Internet Explorer zero-days could allow spying on your browsing activity appeared first on CyberScoop.

Continue reading Microsoft Edge, Internet Explorer zero-days could allow spying on your browsing activity