Poland calls for NATO, EU action on Huawei technology

Polish government officials have asked the European Union and the North Atlantic Treaty Organization to decide whether both alliances should exclude Huawei’s technology from certain global markets. Poland’s internal affairs minister, Joachim Brudziński, on Saturday told the Polish radio station RMF FM the EU and NATO should work together to form a joint position on whether to allow the continued use of equipment made by the Chinese telecommunication company. Brudziński’s recommendation came after Polish authorities arrested Huawei’s head of sales in Poland, Wang Weijing, and a former Polish intelligence agent on espionage charges. Those arrests came amid ongoing international scrutiny over Huawei, which Western security officials have said acts as a wing of the Chinese government and could represent a threat to national security. The firm provides technology for mobile phones, internet networks and telecommunication infrastructure throughout the world. Huawei has consistently denied any wrongdoing. “There are concerns about Huawei […]

The post Poland calls for NATO, EU action on Huawei technology appeared first on CyberScoop.

Continue reading Poland calls for NATO, EU action on Huawei technology

Poland arrests Huawei executive, former security official for alleged espionage

Poland’s internal security agency has arrested an employee of the Chinese telecommunications giant Huawei and a former agent of Poland’s security services, an official announced Friday. The Huawei employee, identified only as Weijing W., worked as the head of the company’s sales in Poland. The former Polish agent, Piotr D., works for the French telecommunications company Orange, according to the New York Times. Both suspects “carried out espionage activities against Poland,” said Maciej Wasik, deputy head of Poland’s special services. Charges against each man have not been made public, though both suspects have pleaded not guilty and refused to answer questions, according to TYP, Poland’s state media outlet. The arrests came amid ongoing efforts by the U.S. and its allies to limit the use of technology manufactured by firms with ties to Beijing over espionage concerns. Canadian police last month arrested Huawei executive Meng Wanzhou at the behest of U.S. authorities, who allege Meng […]

The post Poland arrests Huawei executive, former security official for alleged espionage appeared first on CyberScoop.

Continue reading Poland arrests Huawei executive, former security official for alleged espionage

Personal data on 202 million Chinese job-seekers left exposed on insecure database

Resume information about more than 200 million Chinese job-seekers was exposed on an insecure database accessed in December by a researcher from Hacken, a cybersecurity company. Bob Diachenko, director of cyber risk research at Hacken.io and the bug bounty platform HackenProof, announced Thursday that he found a 854 gigabyte MongoDB database containing 202,730,434 records about job candidates from China. The files contained candidates’ skills and work experience, as well as their mobile phone number, email address, marriage status, political leanings, height, weight, driver’s license information and salary expectations, among other personal data. Not every field was filled-in for each individual, Diachenko said. The database did not require visitors to enter a username or password to access the information, Diachenko wrote. While the owner of the database remains unclear, Diachenko explained that the information appears to have originated from a tool used to scrape data from the websites of Chinese classifieds. […]

The post Personal data on 202 million Chinese job-seekers left exposed on insecure database appeared first on CyberScoop.

Continue reading Personal data on 202 million Chinese job-seekers left exposed on insecure database

Hal Martin’s defense says prosecutors have yet to provide essential evidence

Attorneys for Harold T. Martin III, the former U.S. National Security Agency contractor accused of perhaps the largest theft of government secrets in American history, said in a court filing that government prosecutors have not allowed access to evidence necessary to mount a sufficient defense. Public defenders, in a document made public Tuesday, renewed their request in a Maryland federal court for an order requiring prosecutors to produce copies of the material confiscated from Martin in 2016. The defense seeks duplicates of the hard drives of the seized devices as well as copies of whatever computers the NSA used to create a database of the information that it seized. The request was made Nov. 13, 2018. The U.S. District Court for the District of Maryland had ordered the defense on Aug. 17, 2018 to have “meaningful access” to the material in question, according to the filing. The defense says in the new filing the […]

The post Hal Martin’s defense says prosecutors have yet to provide essential evidence appeared first on CyberScoop.

Continue reading Hal Martin’s defense says prosecutors have yet to provide essential evidence

The Dark Overlord was recruiting employees and looking for attention before 9/11 data dump

Months before The Dark Overlord claimed it stole a trove of sensitive documents about the 9/11 terrorist attacks, the hacking group was struggling to live up to its own reputation. The hackers were perhaps best known for a two-year cybercrime spree in which they took credit for leaking unaired episodes of the Netflix series “Orange is the New Black,” then for harassing U.S. schools and sending death threats to students in 2017. Both incidents generated international media attention, but it wasn’t long before authorities were on the case, with Serbian police arresting a suspected member in May 2018. While The Dark Overlord denies one of its members was apprehended, the group took steps to staff up in the months that followed. A new report from the threat intelligence provider Digital Shadows, prepared exclusively for CyberScoop, indicates that the hacking group sought new members and methods of gaining publicity. “Do YOU want to get Rich? Come […]

The post The Dark Overlord was recruiting employees and looking for attention before 9/11 data dump appeared first on CyberScoop.

Continue reading The Dark Overlord was recruiting employees and looking for attention before 9/11 data dump

Arrested German hacker confesses to leaking politicians’ information, report says

It looks like Russia turned out to be a red herring, after all. German police have arrested a 20-year-old man in connection with a data breach that resulted in the publication of personal information about hundreds of lawmakers from Germany’s Parliament, the Bundestag. Germany’s federal criminal police, known as the BKA, said they searched the suspect’s home on Sunday, confiscating his computer and other personal materials. The young man has confessed to the crime, a prosecutor told the New York Times. The security incident was widely publicized last week when the @_0rbit Twitter account began distributing phone numbers, home addresses and other data about public figures in Germany, including Chancellor Angela Merkel. Representatives from all parties in the Bundestag were affected, except for the far-right Alternative for Germany. The political nature of the data dump, when considered with suspected Russian hackers’ persistent targeting of Germany’s political establishment, led some researchers and at least […]

The post Arrested German hacker confesses to leaking politicians’ information, report says appeared first on CyberScoop.

Continue reading Arrested German hacker confesses to leaking politicians’ information, report says

German investigators question teenager, search residence, as breach probe continues

Germany’s federal police agency said Monday it has questioned suspects and searched property as part of its investigation into the data breach that led to the publication of hundreds of lawmakers’ personal information. The Federal Criminal Police Office (BKA) said in a Facebook post that officials have been active in the town of Heilbronn, in northern Germany, in the hunt for information about the publication last week of phone numbers, addresses and other data about German officials and journalists. The announcement followed tweets from Jan Schürlein, a German IT developer who announced that authorities had spent four hours on Sunday looking through his home. Da es überall im Fernsehen & den Medien zu sehen ist, ja dass BKA hat gestern in einer mehrstündigen Razzia meine Wohnräume durchsucht. Ich möchte ganz klar darauf hinweisen, dass ich ausschließlich als Zeuge geführt werde. Das BKA bat um öffentliche Zurückhaltung. — Jan Schürlein (@Janomine) […]

The post German investigators question teenager, search residence, as breach probe continues appeared first on CyberScoop.

Continue reading German investigators question teenager, search residence, as breach probe continues

Zerodium offers $2 million for iOS zero-days

A startup company famous for purchasing zero-day exploits is increasing its bounties to anyone who discovers one in Apple operating systems or popular messaging technologies. Zerodium on Monday announced it will pay up to $2 million for remote iOS jailbreaks, $1 million for information that allows remote code execution in WhatsApp, iMessage, or texting apps, and $500,000 for Google Chrome exploits. The bounties are up from $1.5 million, $500,000, and $200,000, respectively. Such price increases are in part a reflection of tighter security in popular technology, Zerodium founder Chaouki Bekrar told CyberScoop in 2017. “The price that Zerodium puts on a product is always an indication of the security of that product; the higher the price, the better is the security of the product,” he said. While many companies offer bug bounties for their own products, Zerodium offers a different service. The Washington-based firm pays for original research that it […]

The post Zerodium offers $2 million for iOS zero-days appeared first on CyberScoop.

Continue reading Zerodium offers $2 million for iOS zero-days

Zerodium offers $2 million for iOS zero-days

A startup company famous for purchasing zero-day exploits is increasing its bounties to anyone who discovers one in Apple operating systems or popular messaging technologies. Zerodium on Monday announced it will pay up to $2 million for remote iOS jailbreaks, $1 million for information that allows remote code execution in WhatsApp, iMessage, or texting apps, and $500,000 for Google Chrome exploits. The bounties are up from $1.5 million, $500,000, and $200,000, respectively. Such price increases are in part a reflection of tighter security in popular technology, Zerodium founder Chaouki Bekrar told CyberScoop in 2017. “The price that Zerodium puts on a product is always an indication of the security of that product; the higher the price, the better is the security of the product,” he said. While many companies offer bug bounties for their own products, Zerodium offers a different service. The Washington-based firm pays for original research that it […]

The post Zerodium offers $2 million for iOS zero-days appeared first on CyberScoop.

Continue reading Zerodium offers $2 million for iOS zero-days

Germany sought NSA help after breach exposed lawmakers’ data

German security officials contacted the National Security Agency following a data breach that resulted in private data about many German politicians, including Chancellor Angela Merkel, being publicly published, according to German media outlets. Germany sought help from the NSA after a Twitter account began distributing phone numbers, addressees, chat histories and vacation photos belonging to politicians, journalists and celebrities, German newspaper Bild reported. Germany asked the NSA to pressure Twitter to shut down accounts that were spreading the hacked information, arguing the NSA had jurisdiction because some U.S. citizens also had their information exposed in the data dump. Outreach to the NSA is not the only example of international cooperation. Hamburg, the German city-state, is working with the Irish Data Protection Commissioner to stop the spread of hacked information, according to the news outlet RTE. When reached by CyberScoop Monday, an NSA spokesman said the agency, if asked, would help an ally […]

The post Germany sought NSA help after breach exposed lawmakers’ data appeared first on CyberScoop.

Continue reading Germany sought NSA help after breach exposed lawmakers’ data