Dark web intelligence competition escalates as Terbium raises $2 million from Omidyar Network

The Omidyar Network, an investment firm created by eBay and First Look Media founder Pierre Omidyar, has invested $2 million in Terbium Labs, the dark web intelligence company announced Monday. Terbium has raised $19 million from sources including Glasswing Ventures, which invested $6 million in 2017, and .406 Ventures, the company said in a statement Monday. The $2 million investment from the Omidyar Network comes as competition among dark web vendors has intensified, with competitors like Recorded Future, Digital Shadows and Flashpoint also scouring hidden sections of the internet for client information. Terbium utilizes artificial intelligence algorithms to model the dark web, locate new sites and predict where stolen information is most likely to go up for sale next, the company said. More than 10,000 users including Mastercard and Thomson Reuters use Matchlight, Terbium’s dark web search system, according to  Terbium. The company also relies on a fuzzy hashing protocol that […]

The post Dark web intelligence competition escalates as Terbium raises $2 million from Omidyar Network appeared first on CyberScoop.

Continue reading Dark web intelligence competition escalates as Terbium raises $2 million from Omidyar Network

Security flaw in Medtronic heart defibrillators is serious, DHS says, but don’t panic

The Department of Homeland Security has issued an advisory warning that a vulnerability in Medtronic heart defibrillators could allow hackers to change the settings in a medical device from within radio range. The flaw, designated CVE-2019-6538, has been assigned a 9.3 severity out of a possible 10, according to the Cybersecurity and Infrastructure Security Agency advisory issued Thursday. The Food and Drug Administration in its own safety communication said it has “confirmed that these vulnerabilities, if exploited, could allow an unauthorized individual (for example, someone other than the patient’s physician) to access and potentially manipulate an implantable home device, home monitor, or clinic programmer.” The issue involves Conexus, Medtronic’s radio-frequency protocol that’s used for communication between medical technology such as defibrillators, home monitoring devices and other clinician programming tools. Conexus connections fail to implement any kind of authentication or authorization, according to DHS. That means that, in situations where a product’s radio […]

The post Security flaw in Medtronic heart defibrillators is serious, DHS says, but don’t panic appeared first on CyberScoop.

Continue reading Security flaw in Medtronic heart defibrillators is serious, DHS says, but don’t panic

Facebook: hundreds of millions of passwords were stored in plaintext on internal networks

Facebook plans to notify hundreds of millions of users their passwords were in an insecure format that could have allowed company employees to access and view login credentials. An internal investigation has found that between 200 million and 600 million Facebook users may have had their passwords stored in plain text and searchable by more than 20,000 employees, according to KrebsOnSecurity, which first reported the news. There is no evidence anyone outside Facebook viewed the passwords, the company said in a statement Thursday, adding there’s also nothing to indicate company employees improperly accessed the information. The company estimated it will notify “hundreds of millions” of Facebook Lite users, tens of millions of other Facebook users and tens of thousands of Instagram users. “As part of a routine security review in January, we found that some user passwords were being stored in a readable format within our internal data storage systems,” Facebook said. “This caught […]

The post Facebook: hundreds of millions of passwords were stored in plaintext on internal networks appeared first on CyberScoop.

Continue reading Facebook: hundreds of millions of passwords were stored in plaintext on internal networks

Astronomical costs, geopolitical headaches: Telecom fraud is too big to ignore, report says

International telecommunications fraud — a broad category that includes everything from consumer scams to corporate ripoffs — costs over €29 billion (roughly $33 billion) per year, according to a report published Thursday by Europol and Trend Micro. The fraud isn’t just costly, it’s also endlessly frustrating for the companies and for law enforcement, the report’s authors say. The illicit activities range from tricking individuals into divulging their personal information to perpetrating international revenue share fraud — a complex scheme inspired in part by traditional money laundering techniques. “Geopolitically, most telecom crime tends to be addressed by the telecom companies themselves,” the report states. “The costs are absorbed as the cost of doing business. This creates a kind of isolation, however. Without thorough cross-border intelligence sharing and intelligence fusion with law enforcement, the source, investigative method, and evidence cannot be connected in a way that results in a meaningful number of arrests […]

The post Astronomical costs, geopolitical headaches: Telecom fraud is too big to ignore, report says appeared first on CyberScoop.

Continue reading Astronomical costs, geopolitical headaches: Telecom fraud is too big to ignore, report says

New FIN7 hacking tools uncovered months after three suspects were arrested

More than six months after U.S. prosecutors announced the arrests of three accused hackers affiliated with a sophisticated criminal hacking group, researchers say they have new evidence the billion-dollar crime ring is still active. The Department of Justice last year said police apprehended three Ukrainian men involved in the FIN7 hacking group. The financially-motivated group may have stolen as much as one billion dollars, according to one estimate, as well as 15 million credit card numbers from U.S. businesses. Now, there is some evidence to suggest the group’s infrastructure is starting to reappear after months, according to research published Wednesday by Flashpoint. Researchers uncovered a new strain of malicious software called SQLRat, which is spread via phishing emails. The strain is especially difficult for investigators to detect because it doesn’t leave behind much evidence. “The use of SQL scripts is ingenious in that [attackers] don’t leave artifacts behind the way traditional […]

The post New FIN7 hacking tools uncovered months after three suspects were arrested appeared first on CyberScoop.

Continue reading New FIN7 hacking tools uncovered months after three suspects were arrested

Kaspersky alleges Apple violated Russian antitrust law by abusing App Store influence

Kaspersky Lab on Tuesday filed an antitrust lawsuit against Apple in Russia, claiming the company used its control over the App Store to force Kaspersky to remove certain apps. Apple abuses its “position as platform owner and supervisor” of the App Store to prevent other companies from competing with Apple, Kaspersky claimed in a blog post Tuesday. The Moscow-based security vendor said Apple forced developers to remove two features from Kaspersky’s Safe Kids iOS app: app control and Safari browser blocking. The demand came shortly after Apple announced its own Screen Time feature would include similar parental controls, Kaspersky said. The company filed its complaint with Russia’s Federal Antimonopoly Service of Russia. Apple did not immediately respond to a request for comment. “The problem is that Apple does not allow the use of any software marketplaces for iOS, so it effectively controls the only channel for delivering apps from developers […]

The post Kaspersky alleges Apple violated Russian antitrust law by abusing App Store influence appeared first on CyberScoop.

Continue reading Kaspersky alleges Apple violated Russian antitrust law by abusing App Store influence

What actually happens when a company examines third-party risk

For a moment, look past Russian cybercriminals, North Korean cryptocurrency scams and the idea that election infrastructure used by democracies around the world lacks meaningful digital safeguards. While those issues are significant, people in charge of information security at large U.S. companies spend the majority of their time assessing whether their firm is likely to experience a data breach that begins outside of their own proprietary network. That assessment goes beyond the deluge of obfuscated code, technical jargon or marketing pitches. It’s rooted in crunching numbers in Excel spreadsheets and other measuring strategies that can quantify whether their partners and vendors are prepared to keep hackers out. Security bosses at Fortune 500 companies traditionally have compelled partners to answer monotonous questionnaires about their cyber readiness. Private sector surveys, including some obtained by CyberScoop, typically include hundreds, and sometimes thousands, of arcane questions meant to elicit information about how firms use encryption, require […]

The post What actually happens when a company examines third-party risk appeared first on CyberScoop.

Continue reading What actually happens when a company examines third-party risk

Old devices are filled with personal data, Rapid7 research finds

Wannabe thieves shopping around for personal data don’t need to rely on the dark web. They can simply look at used technology stores for second-hand devices that may come pre-loaded with sensitive data. In research published Tuesday, Rapid7 researcher Josh Frantz described how he spent roughly $650 on 85 computers, flash drives and other devices to find more than 366,000 files on them. Just two of the devices Frantz bought had their information properly removed, and three devices were encrypted. The data Frantz found included Social Security numbers, dates of birth, credit data and phone numbers. “After buying the devices, I took them to my command center (a cool name for my basement) and began the data extraction process,” he wrote. “Whenever I brought a computer back, I booted it up to see whether it was bootable and whether it required a password to log in. I wrote a script […]

The post Old devices are filled with personal data, Rapid7 research finds appeared first on CyberScoop.

Continue reading Old devices are filled with personal data, Rapid7 research finds

Inside the secretive concert where spies mingle with Rock ‘n’ Roll royalty

How much would you pay to watch former U.S. Director of National Intelligence James Clapper do a Blues Brothers routine alongside Dan Aykroyd? The going rate for is roughly $1,000, but the real challenge is securing the ticket that gets you in the door. The show, known as “Spookstock,” is an annual invite-only concert organized by a nonprofit organization that brings together current and former U.S. intelligence agents, corporate executives and special forces soldiers to watch performances by members of the Rock & Roll Hall of Fame. The event’s proceeds are donated to the families of Americans killed in action. The event has built up a mystique around the Washington, D.C.-area thanks to scarce invites that often are given out via word-of-mouth, an A-list lineup, and its underlying cause. The Spookstock Foundation’s founders say it has donated $2.7 million to the CIA Officers Memorial Foundation and the Special Operations Warrior Foundation (SOWF), […]

The post Inside the secretive concert where spies mingle with Rock ‘n’ Roll royalty appeared first on CyberScoop.

Continue reading Inside the secretive concert where spies mingle with Rock ‘n’ Roll royalty

Chinese e-commerce giant Gearbest leaks millions of records, researcher finds

An unsecured database has exposed records about millions of customer transactions from the Chinese e-commerce giant Gearbest, security researcher Noam Rotem has announced. Databases of orders, payments and invoices and customer information were exposed, compromising more than 1.5 million records, according to Rotem’s research published by VPN Mentor. It was not immediately clear how long the records have been exposed, though Rotem reported the databases were found unprotected this month. Payment information, products purchased, shipping addresses, and customer data including names, IP addresses and national identification and passport information was all among the data exposed. “Gearbest’s database isn’t just unsecured,” VPN Mentor noted in a blog post. “It’s also providing potentially malicious agents with a constantly-updated supply of fresh data.” Gearbest is owned by the Shenzen-based e-commerce giant Gobalegrow, a cross-border retailer specializing in the sale of electronics and computer accessories. On its website, Gearbest says it works with more […]

The post Chinese e-commerce giant Gearbest leaks millions of records, researcher finds appeared first on CyberScoop.

Continue reading Chinese e-commerce giant Gearbest leaks millions of records, researcher finds