For foreign hackers, 2018 was all about subtlety, CrowdStrike says

Nation-state hackers from China, Russia and elsewhere spent last year updating their tradecraft and tightening their focus on espionage targets, according to a new CrowdStrike report examining the evolution of cyber-espionage in 2018. The year didn’t see a suspected state-sponsored cyberattack on the scale of 2017’s NotPetya or WannaCry ransomware campaigns, which researchers have suggested were the work of Russian and North Korean hackers, respectively. But in the absence of another headline-grabbing crime spree, international hackers sought to advance their boss’ interests in more subtle ways: by more carefully determining who to hack and moving more quickly once inside, CrowdStrike said. Chinese actors re-ignited their attacks against American targets amid a trade war with the U.S. Russia continued their reconnaissance efforts, while North Korea used digital techniques to generate cryptocurrency that would help Pyongyang avoid sanctions. Meanwhile, in Iran, state-sponsored hackers focused on domestic targets and rivals in the Middle […]

The post For foreign hackers, 2018 was all about subtlety, CrowdStrike says appeared first on CyberScoop.

Continue reading For foreign hackers, 2018 was all about subtlety, CrowdStrike says

That battery-saving app may have used your device to mine Monero, Symantec says

Eight applications designed to hijack users’ computing power to generate cryptocurrency slipped past security guards and into the Microsoft store, security giant Symantec announced Friday, in what was only the latest example of hackers using online markets to spread illicit wares. The apps masqueraded as Windows 10 tools to help users optimize their batteries, aid their internet searches and help stream or download video. In fact, each app was used to generate the cryptocurrency Monero. They were distributed by the developers DigiDream, 1clean and Findoo, though Symantec determined each app likely was developed by the same person or group. The apps were called Fast-search Lite, Battey Optimizer (Tutorials), VPN Browser+, Downloader for YouTube Videos, Clean Master + (Tutorials), FastTube, Findoo Browser 2019 and Findoo Mobile and Desktop Search. “Although we can’t get exact download or installation counts, we can see that there were almost 1,900 ratings posted for these apps,” […]

The post That battery-saving app may have used your device to mine Monero, Symantec says appeared first on CyberScoop.

Continue reading That battery-saving app may have used your device to mine Monero, Symantec says

Here’s the latest evidence that security burnout is very real

As businesses scramble to avoid data breaches and reconsider where the chief information security officer fits into the corporate structure, the uncertainty is having a measurable effect on the mental health of the people who protect the networks. The pressure is real, according to a survey published Thursday by Osterman Research and the domain name vendor Nominet. Thirty-two percent of security practitioners say they believe they would either lose their job or receive an official warning in the event of a data breach. Ninety-one percent reported moderate or high stress, with a quarter saying the job has affected their mental or physical health. Burnout is so common among security professionals that some executives are considering ways to ease the pressure on their teams. Chris Betz, the chief security officer at telecommunications company CenturyLink, told CyberScoop this week he tries to avoid contacting staffers after they’ve left the office. If Betz notices a task that […]

The post Here’s the latest evidence that security burnout is very real appeared first on CyberScoop.

Continue reading Here’s the latest evidence that security burnout is very real

Facebook scrubs accounts spreading disinformation in Moldova ahead of heated election

Facebook has removed nearly 200 accounts and pages for spreading fake news about Moldova ahead of an election that could deepen the divide between the country’s pro-Russian and pro-Western lawmakers. The social media company announced Wednesday it took 168 Facebook accounts, 28 pages and eight Instagram accounts offline for misleading users in Moldova about who they were. The pages posted frequently about political issues such as required Russian language education and  Moldova’s supposed reunification with Romania posed as a fact-checking organization or spread doctored photos, Facebook said. “Although the people behind this activity attempted to conceal their identities, our manual review found that some of this activity was linked to employees of the Moldovan government,” Facebook said. Roughly 54,000 accounts followed at least one of the pages Facebook has removed, and some 1,300 accounts followed one of the Instagram pages. Moldova, one of the poorest countries in Europe, is scheduled to […]

The post Facebook scrubs accounts spreading disinformation in Moldova ahead of heated election appeared first on CyberScoop.

Continue reading Facebook scrubs accounts spreading disinformation in Moldova ahead of heated election

Hard drives in accused CIA leaker’s case were ‘misplaced’ after jailhouse search, prosecutors say

Months after the government accused a former CIA computer engineer of leaking government secrets from behind bars, prosecutors said hard drives containing discovery materials in the case somehow has been “misplaced.” The announcement is the latest complication in a case that only has become more convoluted since it entered the public consciousness. The government said it intends to provide the defendant, Joshua Schulte, with a reproduction of the unclassified material. Prosecutors have accused Schulte, a former software engineer, of providing WikiLeaks with an archive of stolen documents — known as the Vault 7 files — detailing the agency’s surveillance and hacking capabilities. In a Feb. 12 court filing, U.S. Attorney Geoffrey Berman told Judge Paul Crotty “the government has consulted with the [New York City’s Metropolitan Correctional Center, where Schulte is being held] and understand that the hard drives containing the defendant’s discovery were misplaced.” The government, as a result, said it plans to provide Schulte […]

The post Hard drives in accused CIA leaker’s case were ‘misplaced’ after jailhouse search, prosecutors say appeared first on CyberScoop.

Continue reading Hard drives in accused CIA leaker’s case were ‘misplaced’ after jailhouse search, prosecutors say

Atlantic Council holding worldwide events to combat the rise of disinformation

You don’t need to look far to find an example of where disinformation had a profound effect on international politics. Consider Ireland’s abortion referendum, where foreign anti-abortion organizations targeted Irish social media users with specific ads. Or, last month, when Facebook announced it detected Russian propagandists masquerading as a Georgian fashion site. Or, of course, the 2016 U.S. presidential election. Incidents like this are why the Atlantic Council is organizing a series of events and listening sessions next month in Brussels, Madrid and Athens where security experts can advise international lawmakers on how to stifle influence efforts. The goal is to help world leaders recognize and act more quickly to stop campaigns to magnify false narratives like ones used in debates over the Catalonia policy, Brexit, Ireland’s abortion referendum and the 2016 election. “Western Europe and European Union countries once thought this is just a problem affecting the U.S. and Balkan […]

The post Atlantic Council holding worldwide events to combat the rise of disinformation appeared first on CyberScoop.

Continue reading Atlantic Council holding worldwide events to combat the rise of disinformation

WordPress plugin patches flaw that gave hackers potential access to 40,000 websites

A new vulnerability in a popular WordPress plugin could allow outsiders who exploit the flaw to take control of a website, according to new research. Luka Šikić, who works as a security developer at WebARX, published a report Monday revealing the bug in the Simple Social Buttons plugin, which more than 40,000 websites use to distribute their content on Facebook, Twitter and others. The problem would allow hackers to modify a WordPress site’s settings in a way plugin developers did not intend. WPBrigade, the firm that developed Simple Social Buttons, patched the flaw in the 2.0.22 software update, which was released Friday. Šikić said he informed WPBrigade about the vulnerability on Feb. 7, and that the company fixed the issue within a day. “If your website uses the WordPress plugin ‘Simple Social Buttons,’ you should update it to the latest version as soon as possible,” WebARX said in a blog […]

The post WordPress plugin patches flaw that gave hackers potential access to 40,000 websites appeared first on CyberScoop.

Continue reading WordPress plugin patches flaw that gave hackers potential access to 40,000 websites

Instagram data from 14 million profiles found in insecure database, researcher says

Information about more than 14 million Instagram accounts is being kept in an insecure database that could render users vulnerable to hackers, a security researcher told CyberScoop Friday. Data including users’ profile names, stored links to profile pictures and their Instagram ID is available in the database, which researcher Oliver Hough found on the Shodan web scanning service. The database, physically located in the U.K., includes 14,526,602 entries, according to a screenshot Hough tweeted Friday. Entries also have empty fields for home addresses and telephone numbers, he said. It’s not clear who is logging the information. But Hough suggested a third party could be scraping Instagram and storing public data for analysis later, either for targeted marketing or another purpose. He suggested the information could be combined with unrelated databases of stolen passwords, which hackers could correlate with the usernames leaked here to try to infiltrate victims’ accounts. “On the black hat side […]

The post Instagram data from 14 million profiles found in insecure database, researcher says appeared first on CyberScoop.

Continue reading Instagram data from 14 million profiles found in insecure database, researcher says

Apple patches FaceTime flaw, and two exploited zero-days in new security update

An Apple security update released Thursday includes fixes for three vulnerabilities hackers already have exploited, leaving customers who fail to download the new software unprotected from known threats. The security patch, iOS 12.1.4, squashes the widely-publicized FaceTime bug that allowed attackers to spy on others via audio and video. It also fixes two zero-day vulnerabilities that Ben Hawkes, a researcher on Google’s Project Zero security team, said had been exploited before the update was issued. The bugs, dubbed CVE-2019-7286 and CVE-2019-7287, would have allowed attackers to gain elevated privileges, and execute arbitrary code with kernel privileges, respectively. Few details were immediately available about how and when those bugs were exploited, though prominent experts are encouraging users to update their phone as soon as possible. Users should visit the “Settings” page on their iPhone, then follow “General” to “Software Update.” Click “Download and Install.” iOS user? Update to 12.1.4 now. It […]

The post Apple patches FaceTime flaw, and two exploited zero-days in new security update appeared first on CyberScoop.

Continue reading Apple patches FaceTime flaw, and two exploited zero-days in new security update

There’s business in the basics as corporate America embraces opsec apps

New evidence suggests corporate America is embracing some of the basic cybersecurity functions that the experts have advocated for years. In a survey of more than 5,600 customers, identity management Okta found that three cybersecurity services ranked at the top of the list of the fastest-growing apps in corporate America. The security training platform KnowBe4, the password manager LastPass and the email security service Proofpoint landed in the top three spots, respectively, ahead of the video-conferencing service Zoom and software from Adobe. Security incidents are expensive, after all, and it’s often much more cost-effective to train workers about opsec, safeguard their passwords and protect their emails. An unrelated Ponemon Institute report found that the average cost of a stolen record is $148, and a typical enterprise shells out $3.86 million to recover from a data breach. And the Okta report, published Thursday, provides the latest evidence corporate executives are scrambling to build cybersecurity into their applications in an […]

The post There’s business in the basics as corporate America embraces opsec apps appeared first on CyberScoop.

Continue reading There’s business in the basics as corporate America embraces opsec apps