Inspector general finds deficiencies in how FBI tells companies they’ve been breached

The FBI needs to shore up its internal processes for notifying the victims of cyberattacks, according to a U.S. Justice Department inspector general’s report published Monday. There are issues with the quality and completeness of the data stored in the FBI’s Cyber Guardian system — a tool for disseminating notifications after security breaches — reports Inspector General Michael E. Horowitz. Many FBI agents tasked with responding to cybercrimes improperly handle the work associated with indexing the victims in the bureau’s system, a problem that could make it more difficult for hacked organizations to recover, according to the report. “During this audit, we visited six FBI field offices and discussed the victim notification process with cyber squad Special Agents and supervisory Special Agents,” the report said. “In our discussions, we found that 29 of 31 field agents we interviewed do not use the ‘Victim Notification’ lead type when setting leads for victim notification. Five of […]

The post Inspector general finds deficiencies in how FBI tells companies they’ve been breached appeared first on CyberScoop.

Continue reading Inspector general finds deficiencies in how FBI tells companies they’ve been breached

‘Small stickers’ were enough to trick a Tesla’s autopilot to drive into the wrong lane

A security vulnerability in Tesla firmware made it possible for outsiders to take remote control over a vehicle’s steering and push it into an opposite lane, according to recent research from Tencent’s Keen Security Lab. The computer experts discovered that, by painting “small stickers” on a roadway, they could fool the autopilot on a Tesla Model S 75 into following a path the driver did not intend. The technique exploited the car’s autopilot protocol, which quickly collects data about a vehicle’s surroundings based on radar signals, cameras and other sensors. By placing stickers over road markings, the Keen team caused the Tesla to move to the wrong side of the road. Researchers also proved it was possible to activate the windshield wipers by using a camera to trick the Tesla’s artificial intelligence into believing there was moisture on the surface. Tesla fixed the “primary” flaw with a series of security […]

The post ‘Small stickers’ were enough to trick a Tesla’s autopilot to drive into the wrong lane appeared first on CyberScoop.

Continue reading ‘Small stickers’ were enough to trick a Tesla’s autopilot to drive into the wrong lane

Gustuff malware can steal from banking apps, then spread via contact lists

A new strain of malicious software affecting Android devices is capable of phishing credentials and automating bank transactions for more than 100 banks and 32 virtual currency apps, according to new research from security firm Group-IB. The malware, dubbed Gustuff, is aimed at top international banks including Bank of America, Wells Fargo, Chase, Capital One, and others, researchers found. It also is designed to steal from cryptocurrency apps like Bitcoin Wallet and Coinbase, and can phish usernames and passwords from PayPal, Western Union, Walmart, eBay and WhatsApp, according to researchers at Group-IB. The hacking tool infects victims with a text message, tricking them to provide access to the Android Accessibility function. That service enables Android phones to take action by default, such as increasing the size of an icon or reading text out loud. Once inside, Gustuff is then able to siphon funds from payment software called Automatic Transfer Service. Gustuff has been available on […]

The post Gustuff malware can steal from banking apps, then spread via contact lists appeared first on CyberScoop.

Continue reading Gustuff malware can steal from banking apps, then spread via contact lists

Facebook links Duterte campaign volunteer to 200 bogus accounts

Facebook says it has removed another 200 pages for misleading users about who was behind the content and for misrepresenting what the pages were supposed to achieve. This time the pages, groups and accounts were located in the Philippines. Facebook has tied the activity to a network organized by Nic Gabunada, a businessman who said he managed social media for Philippine President Rodrigo Duterte during his 2016 campaign. A bulletin published Thursday is the latest such update from the company, which in recent weeks has removed accounts from Iran, Russia, Moldova and elsewhere for “coordinated inauthentic behavior.” Facebook’s moves have been closely watched by political organizations, intelligence agencies, law enforcement and other entities with an interest in election security or information operations. The identification of Gabunada, former chief executive of Omnicom Media Group Philippines, marks a departure for Facebook, which says it removes accounts based on their behavior, but that it doesn’t have the capability […]

The post Facebook links Duterte campaign volunteer to 200 bogus accounts appeared first on CyberScoop.

Continue reading Facebook links Duterte campaign volunteer to 200 bogus accounts

Chinese-speaking phone scammers stole $40 million, mostly from Chinese targets in the U.S., FBI says

The FBI has received a rash of complaints from scammers who claimed to be calling from the Chinese embassy, then threatened legal action if call recipients didn’t pay them, the bureau said. In a public service announcement released Thursday, the FBI’s Internet Crime Complaint Center reports that victims have reported receiving phone calls and text messages from people speaking in a Chinese-dialect claiming to be from the Chinese embassy, consulate or a shipping company. The scammers often tell victims they have a package waiting for them at the embassy, and that they are under investigation by Chinese law enforcement. From there, the victim is transferred to an “investigator,” who tells the victim they need to send money to China or Hong Kong to resolve the situation. Other versions of the scam involves callers posing as representatives from Chinese credit card companies and demanding payment on an outstanding balance, otherwise they […]

The post Chinese-speaking phone scammers stole $40 million, mostly from Chinese targets in the U.S., FBI says appeared first on CyberScoop.

Continue reading Chinese-speaking phone scammers stole $40 million, mostly from Chinese targets in the U.S., FBI says

Office Depot to pay $25 million to settle tech support scam charges

Office Depot and a tech support service have agreed to pay the Federal Trade Commission a total of $35 million to settle charges they lied to customers by convincing them their products had been hacked, the FTC announced Wednesday. Office Depot and Support.com will pay $25 million and $10 million, respectively, for their role in a years-long scheme to use a software program, known as PC Health Check, as a tool to convince customers to buy tech support from Office Depot, the FTC said. A complaint alleges that both companies configured PC Health Check to report it had found malware based on whether customers agreed with statements such as “My PC recently became much slower or is too slow to use,” rather than true malware scans. Both companies knew about the problem as early as 2012 yet they continued marketing and using PC Health Check until late 2016, the FTC […]

The post Office Depot to pay $25 million to settle tech support scam charges appeared first on CyberScoop.

Continue reading Office Depot to pay $25 million to settle tech support scam charges

Dark web marketplace Dream Market to close after U.S. police nab suspected vendors

One of the most popular dark web marketplaces says it will cease operations next month, an announcement that came on the same day international authorities said they’d spent eight months investigating digital drug dens. Dream Market, founded in 2013 and only accessible with anonymity software, has been among the busiest drug sites in operation today, specializing in sales of narcotics as well as stolen data. But administrators announced Tuesday the site is going down on April 30, and moving its files to a “partner service,” according to a screenshot provided by the dark web intelligence company IntSights. With the announcement, Dream Market joins AlphaBay, Hansa and other once-busy drug sites to close up shop. The announcement coincides with announcements from the FBI and Europol that they have arrested 61 people and shut down 50 dark web accounts as part of an international police operation. While it’s not clear if the Dream […]

The post Dark web marketplace Dream Market to close after U.S. police nab suspected vendors appeared first on CyberScoop.

Continue reading Dark web marketplace Dream Market to close after U.S. police nab suspected vendors

Facebook removes accounts for masquerading as news outlets in the Middle East

Facebook has removed 2,632 pages, groups and accounts for engaging in “coordinated inauthentic behavior” including misrepresenting their origin and using fake accounts, the company said Tuesday. The information operations were connected to Iran, Russia, Macedonia and Kosovo, Facebook said. Researchers said the activity engaged in many of the same behaviors, typically magnifying state media propaganda, but cautioned they did not find any links between the operations. In recent months, Facebook has announced similar takedowns of accounts targeting users in Moldova and for spreading disinformation in the Middle East. “While we are making progress rooting out this abuse, as we’ve said before, it’s an ongoing challenge because the people responsible are determined and well-funded,” Nathaniel Gleicher, Facebook’s head of cybersecurity policy, said in a blog post. Facebook typically does not directly attribute such activity to governments or other specific groups, saying it does not have the capability to determine exactly who […]

The post Facebook removes accounts for masquerading as news outlets in the Middle East appeared first on CyberScoop.

Continue reading Facebook removes accounts for masquerading as news outlets in the Middle East

LinkedIn is becoming China’s go-to platform for recruiting foreign spies

Buried in the 41-page felony complaint charging a former U.S. intelligence operative of spying for the Chinese, FBI investigators declare that the suspect, Ron Rockwell Hansen, had been printing information from his colleagues’ LinkedIn pages. Hansen, a former Defense Intelligence Agency case officer who pleaded guilty on March 15 to attempted espionage against the U.S., took information from the professional networking site related to several former and current DIA case officers before a 2015 trip to China. The complaint does not state how that information were used, if at all, but it’s enough to raise the notion Hansen may have been passing LinkedIn data, along with other secret DIA materials files to Chinese handlers. “I solicited from an intelligence case officer working for the Defense Intelligence Agency national defense information that I knew Chinese Intelligence services would find valuable, and I agreed to act as a conduit to sell that […]

The post LinkedIn is becoming China’s go-to platform for recruiting foreign spies appeared first on CyberScoop.

Continue reading LinkedIn is becoming China’s go-to platform for recruiting foreign spies

Second flaw found in Swiss election system could change ‘valid votes into nonsense,’ researchers say

Researchers have uncovered a second security flaw in the electronic voting system employed by the Swiss government. The vulnerability involves a problem with the implementation of a cryptographic protocol used to generate decryption proofs, a weakness that could be leveraged “to change valid votes into nonsense that could not be counted,” researchers Sarah Jamie Lewis, Olivier Pereira and Vanessa Teague wrote in a paper published Monday. This disclosure comes weeks after the same team of researchers announced they had uncovered a flaw in the e-voting system that could allow hackers to replace legitimate votes with fraudulent ones. Swiss Post, the country’s national postal service, which developed the system along with Spanish technology maker Scytl, said earlier this month that first vulnerability had been resolved. Researchers said at the time that the vulnerability demonstrated what can go wrong when governments shift to electronic voting with no alternative plan. The security and integrity of electronic voting […]

The post Second flaw found in Swiss election system could change ‘valid votes into nonsense,’ researchers say appeared first on CyberScoop.

Continue reading Second flaw found in Swiss election system could change ‘valid votes into nonsense,’ researchers say