Zcash, Chase’s cryptocurrency partner, fixes bug that could have allowed ‘unlimited’ counterfeits

Developers behind the privacy-focused cryptocurrency Zcash have patched a security flaw that could have allowed hackers to create an unlimited amount of counterfeit coins. Roughly one year ago cryptographer Ariel Gabizon discovered what appeared to be a “subtle” bug in zk-SNARKS, a tool to hide user identities and currency balances. The bug could have allowed attackers to overwhelm Zcash’s financial ecosystem with falsified currency, perhaps enough to undermine trust in the cryptocurrency altogether. The problem also could have put in peril the partnership between Zerocoin Electric Coin Company, the organization behind Zcash, and JPMorgan Chase. “Prior to its remediation, an attacker could have created fake Zcash without being detected,” members of the Zcash team said in a blog post Tuesday. “The counterfeiting vulnerability has been fully remediated in Zcash and no action is required by Zcash users.” Gabizon, a ZECC employee, discovered the issue in March 2018. Only four members […]

The post Zcash, Chase’s cryptocurrency partner, fixes bug that could have allowed ‘unlimited’ counterfeits appeared first on CyberScoop.

Continue reading Zcash, Chase’s cryptocurrency partner, fixes bug that could have allowed ‘unlimited’ counterfeits

E-ticketing system exposes airline passengers’ personal information via email

At least eight airlines, including Southwest, use e-ticketing systems that could allow hackers to access sensitive information about travelers merely by intercepting emails, according to research published Wednesday by the mobile security company Wandera. The systems fail to secure customers’ personally identifiable information, including names, boarding passes, passport numbers and flight numbers, Wandera said. The email vulnerabilities still exist, Wandera found, even though researchers notified affected companies weeks ago, and despite growing corporate awareness about the risks associated with sacrificing security for convenience. The weakness is a check-in link that is emailed to customers, Wandera researchers found. Customer information is embedded in the links, allowing travelers to travel from their email to a website where they check in for a flight without needing to enter their username and password. However the links are unencrypted and re-usable, presenting a tempting target for hackers, according to Michael Covington, vice president of product at Wandera. […]

The post E-ticketing system exposes airline passengers’ personal information via email appeared first on CyberScoop.

Continue reading E-ticketing system exposes airline passengers’ personal information via email

Google wants Chrome users to avoid ‘boring’ security problems with new extension

Google on Tuesday introduced a new browser extension that will alert users when they’re relying on a compromised username and password combination. The plug-in, called Password Checkup, warns Google Chrome users when they enter credentials that previously have been exposed by hacks into non-Google websites. The tool compares the user’s anonymized credentials with a database of names and passwords stolen in prior data breaches, then warns them that re-using the same information on multiple sites makes them especially vulnerable to hackers. The plan resembles ongoing security awareness tools like Have I Been Pwned, the free website where visitors can check if their email address was caught in a breach. Mozilla has added a feature to its Firefox web browser that uses Have I Been Pwned’s information to warn users when they visit a website that recently experienced a data breach. Password Checkup is the latest effort from Google to help unwitting users […]

The post Google wants Chrome users to avoid ‘boring’ security problems with new extension appeared first on CyberScoop.

Continue reading Google wants Chrome users to avoid ‘boring’ security problems with new extension

WhatsApp adds biometric feature to help protect messages

WhatsApp is adding new privacy features for many of its users, as the security community keeps a close eye on how its parent company, Facebook, plans to merge the globally popular messaging app with other products. In a software update, WhatsApp allows iOS users to lock their messages with biometric authentication tools. The update, version 2.19.20, allows iPhone owners to unlock WhatsApp using Face ID or Touch ID. This layer of security applies to the entire app — rather than on a chat-by-chat basis — and can be enabled through iPhone’s settings page. An Android version of the update is in a testing phase, according to the Verge. By adding biometric authentication, WhatsApp is building on its already respected end-to-end encryption protocol. The methodology was developed by Open Whisper Systems, the software organization behind the widely-praised messaging app Signal. But even end-to-end encryption can’t protect users’ messages if someone has physical […]

The post WhatsApp adds biometric feature to help protect messages appeared first on CyberScoop.

Continue reading WhatsApp adds biometric feature to help protect messages

‘Chafer’ group advances espionage tactics by hacking Windows machines in Middle East

A hacking group has used a specific malware variant for the last three years to spy on “foreign diplomatic entities” operating inside Iran, advancing its reputation as an espionage group that previously targeted telecoms throughout the Middle East. The Chafer cyber espionage group deployed malware known as Remexi to steal user credentials, record keystrokes, browser history and take covert screenshots on targeted machines through late 2018, according to Kaspersky research published Wednesday. Few specifics are known about the operation, including concrete details on how the malware spreads. However Kaspersky’s new research builds on previous Symantec findings which determined that Chafer attacked telecommunication companies, an airline in the Middle East and at least one business in the U.S. The group now appears to be targeting Windows machines located inside Iran, Kaspersky said this week. “The vast new majority of the users targeted by this new variant of Remexi appear to have […]

The post ‘Chafer’ group advances espionage tactics by hacking Windows machines in Middle East appeared first on CyberScoop.

Continue reading ‘Chafer’ group advances espionage tactics by hacking Windows machines in Middle East

Pay the ransom? Corporate lawyers say meeting some hackers’ demands may be worth it

Conventional wisdom says ransomware victims shouldn’t pay their attackers, but a panel of legal experts suggested Thursday that standing firm might not always be the smartest play in the real world. FBI officials, corporate bigwigs and public sector security bosses in recent years all have advised their colleagues to keep their wallets closed when ransomeware hits. There’s no honor among thieves, the logic goes, and even if you pay hackers to buzz off, who’s to say they will follow through on promises to unlock encrypted data? But there are scenarios in which small and medium-sized businesses should carefully consider their decision, Mark Knepshield and Matthew Todd said during a panel discussion at the Legalweek conference in New York. “I would say, if it’s small amount, pay it,” said Knepshield, a senior vice president at insurer McGriff, Seibels and Williams. “It’s likely just be the easiest way out of your situation.” In a poll surveying […]

The post Pay the ransom? Corporate lawyers say meeting some hackers’ demands may be worth it appeared first on CyberScoop.

Continue reading Pay the ransom? Corporate lawyers say meeting some hackers’ demands may be worth it

Facebook removes nearly 800 pages for magnifying state media throughout the Middle East

Facebook removed 783 pages, groups and accounts tied to Iran that engaged in “coordinated inauthentic behavior” dating back to 2010, the company said Thursday. Many of the nearly 800 pages magnified content that originated with Iranian state media, such as news stories about relations between Israel and Palestine, the Syrian conflict and the impact of U.S. involvement in international conflicts, Nathaniel Gleicher, Facebook’s head of cybersecurity policy, said in a conference call Thursday. Roughly 2 million accounts followed at least one of these pages, and nearly $30,0000 in advertising spending was tied to the pages in question, Facebook said. Multiple sets of activity specifically targeted users in countries in the Middle East, European Union and Southeast Asia. The company did not directly tie any of the activities in question to the Iranian government. “In this case we can prove this is emanating from actors in Iran,” Gleicher said. “We’re not in a […]

The post Facebook removes nearly 800 pages for magnifying state media throughout the Middle East appeared first on CyberScoop.

Continue reading Facebook removes nearly 800 pages for magnifying state media throughout the Middle East

Facebook beefs up privacy, security staff amid ongoing scrutiny over data collection practices

Although Facebook seems unable to stop infuriating tech watchdogs, the company’s efforts to regain the public’s trust have made quantifiable progress in at least one category: hiring more humans to work on safety and security. Colin Stretch, a vice president and general counsel, told Congress in 2017 Facebook would double staff in those areas to more than 20,000 employees by the end of 2018 in response to outrage following the Cambridge Analytica scandal. The company now has roughly 30,000 employees assigned to safety and security, Nathaniel Gleicher, head of the cybersecurity policy, said Tuesday at a panel at the State of the Net Conference in Washington. Recent additions to the privacy team include Nate Cardozo, an established Facebook critic from the Electronic Frontier Foundation, and Robyn Greene, who is leaving her role at the Open Technology Institute to focus on law enforcement access and data protection issues at the social media company. Both hires […]

The post Facebook beefs up privacy, security staff amid ongoing scrutiny over data collection practices appeared first on CyberScoop.

Continue reading Facebook beefs up privacy, security staff amid ongoing scrutiny over data collection practices

Feds shutter xDedic, a black market used to commit $68 million in fraud

An online marketplace that facilitated more than $68 million in fraud and cybercrime has been shut down following an international law enforcement operation, the U.S. Department of Justice announced Monday. Hackers and thieves used the website, known as xDedic, to sell access to compromised computers located around the world and personal information belonging to U.S. residents, prosecutors said. Buyers could search the site by price, operating system or by the geographic region from where it was stolen, prosecutors said. The method of access was usually through credentials for Remote Desktop Protocol (RDP) servers. The DOJ didn’t name any victims, but said they included major metropolitan transit organizations, emergency services, government agencies, pension funds, universities and others. The site was shut down in 2016, only to re-emerge soon after on the dark web with the new stipulation that members pay $50 to enter. “The xDedic marketplace operated across a widely distributed network and […]

The post Feds shutter xDedic, a black market used to commit $68 million in fraud appeared first on CyberScoop.

Continue reading Feds shutter xDedic, a black market used to commit $68 million in fraud

Tech startups are making security moves sooner. They don’t have much of a choice.

For David Cowan, the tipping point was a cyberattack from Anonymous. Cowan, a venture capitalist at Bessemer Venture Partners, had spent years asking startup founders what they planned to do if hackers targeted their business. Often, the founders on the other side of the boardroom would shrug and say, “We don’t hold any personal information, so they don’t need to come after us.” That changed, he said, after the email marketing company SendGrid was hit in 2013 with a denial-of-service attack that ultimately caused about 20 percent of the young company’s clients to walk away, not too long after Bessemer had led a $21 million funding round for the company The attack occurred after an employee, Adria Richards, publicly complained that a developer from the gaming company Playhaven made sexual remarks in the audience at the 2013 PyCon tech conference. Playhaven fired the employee, infuriating an online mob that sent Richards death threats. Anonymous got involved too, […]

The post Tech startups are making security moves sooner. They don’t have much of a choice. appeared first on CyberScoop.

Continue reading Tech startups are making security moves sooner. They don’t have much of a choice.