Marriott says 25 million passport numbers, some unencrypted, involved in massive breach

Marriott International said Friday that 383 million customer records were stolen in a data breach last month, down from the hotel chain’s original estimate of 500 million. Roughly 25.5 million passport numbers also were compromised in the data breach affecting Starwood Hotels reservation system, the company said in a statement. Hackers spent roughly four years inside Starwood’s networks, the company announced Nov. 30. The breach is the one of the largest ever reported and is under investigation by at least five U.S. states as well as European regulators. Some 5.25 million of the 25.5 million passports numbers were stored in plain text, Marriott said Friday, providing hackers with a valuable means of stealing individuals’ identities. The hotel chain previously said it would compensate customers for passport replacements if they can prove they had been victims of fraud. The company also said it believes that approximately 8.6 million encrypted payment cards […]

The post Marriott says 25 million passport numbers, some unencrypted, involved in massive breach appeared first on CyberScoop.

Continue reading Marriott says 25 million passport numbers, some unencrypted, involved in massive breach

Democrats’ massive House bill to include election security measures

House Democrats will include proposed cybersecurity measures in a massive bill due to be unveiled Friday as Congress begins a new session. The bill, H.R. 1, includes an array of legislation, such as a plan to force all presidential nominees to disclose their tax returns, new campaign finance rules and changes to sexual harassment law. Cybersecurity also is a major component, as reports indicate H.R. 1 will repurpose much of the language from the Elections Security Act, proposed last year by Rep. Bennie Thompson, D-Miss. H.R. 1, known as the “For the People Act,” also would require states to replace paperless voting systems, create grants to help states audit their election results, and force election system vendors to report data breaches, according to the Brennan Center. Last year’s version of the bill designated $1.7 billion for states to secure their voting technology and would have required the White House to […]

The post Democrats’ massive House bill to include election security measures appeared first on CyberScoop.

Continue reading Democrats’ massive House bill to include election security measures

The Dark Overlord hackers release documents allegedly tied to 9/11 civil lawsuits

A group of hackers has released documents stolen from high-profile firms allegedly detailing litigation and real-estate development deals after the September 11, 2001 terrorist attacks. The Dark Overlord, a hacking group known for breaching entertainment companies and harassing U.S. school systems, said Wednesday it released “a small sample of documents” to verify prior claims that the group breached international firms. In a Dec. 31 Pastebin post, the group said it hacked New York-based real estate developer Silverstein Properties along with insurers Hiscox Syndicates and Lloyds of London to find sensitive security information tied to the 9/11 attacks. The group also claims it obtained classified material from U.S. agencies including the FBI, the Department of Justice, the Federal Aviation Administration and others. The files, released Wednesday with access instructions and a decryption key, includes various documents and powerpoint presentations tied to liability cases regarding the World Trade Center attacks. The documents […]

The post The Dark Overlord hackers release documents allegedly tied to 9/11 civil lawsuits appeared first on CyberScoop.

Continue reading The Dark Overlord hackers release documents allegedly tied to 9/11 civil lawsuits

Too soon to attribute cyberattack that disrupted U.S. newspapers, researchers say

It’s too soon to tell whether North Korean hackers were responsible for a cyberattack that prevented multiple major U.S. newspapers from delivering weekend editions on time. The attack last week against the Tribune Company disrupted printing operations at papers including the Los Angeles Times, the San Diego Union-Tribune, the New York Times and the Wall Street Journal. Several sources told the Los Angeles Times the attack appeared to be caused by Ryuk, a type of ransomware with low technical capabilities. Ryuk  has infected hundreds of computers at multiple companies, according to researchers from security vendor Check Point. While Ryuk shares attributes with the Hermes malware, which is often attributed to suspected North Korean hackers known as the Lazarus Group, researchers say that doesn’t mean Pyongyang has launched a digital assault against U.S. press institutions. “The style of this attack fits the pattern of a lot of different groups at this point,” […]

The post Too soon to attribute cyberattack that disrupted U.S. newspapers, researchers say appeared first on CyberScoop.

Continue reading Too soon to attribute cyberattack that disrupted U.S. newspapers, researchers say

Open-source tool aims to curb BGP hijacking amid Chinese espionage concerns

BGP security is going global. International agencies including the U.S. Department of Homeland Security, the National Science Foundation, the European Research Council and others are funding the Automatic and Real-Time dEtection and Mitigation System (ARTEMIS), in an effort to stop hackers from rerouting internet traffic through malicious networks. Border Gateway Protocol hijacking occurs when attackers redirect web traffic away from its intended destination and instead send those connections somewhere else. Perhaps the best known example of BGP hijacking occurred in November when millions of IP addresses aimed at Google were instead sent to a state-controlled telecom in China, apparently by accident. The issue has become more urgent since nation-state hackers and criminal groups started to utilize this technique for their own gain, Rob Joyce, a senior adviser at the U.S. National Security agency, said in December. ARTEMIS is seeking to resolve this problem with the release of an open-source software […]

The post Open-source tool aims to curb BGP hijacking amid Chinese espionage concerns appeared first on CyberScoop.

Continue reading Open-source tool aims to curb BGP hijacking amid Chinese espionage concerns

Flaw in Guardzilla home security devices allows outsiders to view stored video, researchers say

A popular home security device made by Guardzilla contains a security vulnerability that could make it possible for outsiders to access video recordings, according to research published Thursday. Guardzilla’s indoor wireless security system, the GZ501W, contains hardcoded security keys rendered vulnerable by an outdated algorithm that TechCrunch reports is easy to crack. Hackers can use those keys to log on to Guardzilla’s storage servers at Amazon Web Services to access data uploaded by customers, according to the new findings. Researchers from 0DayAllDay released their findings Thursday after notifying Guardzilla to the vulnerabilities in September and receiving no response. [W]e’re publishing this [Thursday], which happens to be right about 60 days after our first disclosure to the vendor of this video camera,” Tod Beardlsey, research director at Rapid7, explained in blog post. Rapid7 was involved in the research. “Unfortunately, despite multiple efforts at coordination with the vendor, we haven’t heard back from […]

The post Flaw in Guardzilla home security devices allows outsiders to view stored video, researchers say appeared first on CyberScoop.

Continue reading Flaw in Guardzilla home security devices allows outsiders to view stored video, researchers say

Justice Department hopes to disrupt ‘dumbest tradition ever’ with latest DDoS seizure

Law enforcement may have just ruined what’s become a holiday tradition for cybercriminals who spend Christmas knocking gaming websites offline. The U.S. Department of Justice announced on Thursday officials had seized 15 internet domains that made it possible for web users to launch distributed denial-of-service attacks, which render software inaccessible by flooding targets with fake traffic. The sites involved in the takedown were known as “booter” and “stresser” websites, which enabled users to easily launch DDoS attacks like the kinds that have hit Sony’s PlayStation and Microsoft’s Xbox services in recent Christmas seasons. Prosecutors also filed charged against two men with conspiring to violate the Computer Fraud and Abuse Act by allegedly operating DDoS-for-hire services known as Downthem and Ampnode. In another case, investigators charged a 23-year-old Pennsylvania man with operating a criminal service that was used to launch more than 50,000 attacks in 2018 alone. “The attack-for-hire websites targeted […]

The post Justice Department hopes to disrupt ‘dumbest tradition ever’ with latest DDoS seizure appeared first on CyberScoop.

Continue reading Justice Department hopes to disrupt ‘dumbest tradition ever’ with latest DDoS seizure

NASA investigating ‘cyber incidents’

NASA says it was hacked earlier this year, according to a memo sent to employees Tuesday. In the memo, NASA said an unauthorized user accessed a server containing Social Security numbers and personally identifiable information on current and former employees. Personnel began investigating the breach on Oct. 23, at which point NASA “took immediate action to secure the servers,” the agency said. An investigation is ongoing, though NASA says it does not believe any agency missions were jeopardized by the “cyber incidents.” NASA Civil Service employees who joined the agency, separated from the agency, and/or were transferred between NASA centers between July 2006 and October 2018 may have been affected, according to the internal memo. “NASA and its federal cybersecurity partners are continuing to examine the servers to determine the scope of the potential data exfiltration and identify potentially affected individuals,” the agency said. “This process will take time. The […]

The post NASA investigating ‘cyber incidents’ appeared first on CyberScoop.

Continue reading NASA investigating ‘cyber incidents’

Microsoft hopes crowdsourced A.I. algorithms will help avoid the next global cyberattack

If you’ve developed an artificial intelligence tool capable of predicting the next ransomware outbreak, Microsoft wants to hear about it. And they’re willing to pay. More than 300 data scientists, security practitioners and academics are involved in an initiative to help Microsoft determine which Windows machines are the most vulnerable to malicious software. The competition challenges participants to assess the probability a device will be hit with malware based on different factors about the machine, ranging from the firewall configuration to the antivirus software and CPU. Microsoft announced the competition on Dec. 13, giving participants three months to develop an algorithm that can predict whether a Windows 10 or Windows XP computer, for example, is likely to be infected with the next major virus, organizers said. The competition offers a glimpse at how cybersecurity will blend with artificial intelligence and machine learning, as major companies invest in experiments that could […]

The post Microsoft hopes crowdsourced A.I. algorithms will help avoid the next global cyberattack appeared first on CyberScoop.

Continue reading Microsoft hopes crowdsourced A.I. algorithms will help avoid the next global cyberattack

Twitter detects possible state-sponsored activity from China, Saudi Arabia

Twitter says there has been suspicious activity on its platform that may have involved state-sponsored hackers from China and Saudi Arabia seeking information about specific users. The social media company says it detected an “issue” on Nov. 15 related to one of its support forums, where users contact Twitter to report any problems with an account. Outsiders potentially could view the country code users associated with their accounts and could assess whether an account was locked for violating Twitter’s rules, the company said in an announcement late Monday. “Specifically, we observed a large number of inquiries coming from individual IP addresses located in China and Saudi Arabia,” Twitter said. “While we cannot confirm intent or attribution for certain, it is possible that some of these IP addresses may have ties to state-sponsored actors.” The issue was fixed within one day and Twitter has notified the affected users, the company said. No personal information […]

The post Twitter detects possible state-sponsored activity from China, Saudi Arabia appeared first on CyberScoop.

Continue reading Twitter detects possible state-sponsored activity from China, Saudi Arabia