Citrix security boss warns that cryptojackers are exploiting cloud ignorance

Don’t count on cloud security providers to keep hackers away. As more companies have shifted their data to the cloud, some firms too strapped to spend on security have begun to rely more heavily on companies like Amazon Web Services and Microsoft Azure to assume more network protection and monitoring responsibilities. But Stan Black, chief security and information officer at the software company Citrix, says that hackers are adapting to this transition, hijacking companies’ cloud infrastructure. The issue demonstrates ways in which hackers are keeping pace with corporate defenders, and it presents an urgent challenge for companies that stand to lose millions of dollars, Black said. “This is about someone stealing assets that I pay for,” he said, comparing cryptojacking to a more nefarious version of peer-to-peer music piracy. “The upside is that it’s not destroying the business, or encrypting data. But they are consuming assets that make us think we need […]

The post Citrix security boss warns that cryptojackers are exploiting cloud ignorance appeared first on Cyberscoop.

Continue reading Citrix security boss warns that cryptojackers are exploiting cloud ignorance

Passport numbers stolen from Marriott provide scammers with another ID theft tool

Hackers who spent four years lurking inside the Starwood hotel chain’s guest database now have a valuable piece of the puzzle for stealing victims’ identities: passport numbers. Marriott announced Friday that the stolen information on 327 million people “includes some combination” of passports and other personal information, such as phone numbers, email addresses, or payment card data. A passport number alone may not be especially valuable, but fraudsters can incorporate that information into an identity theft scheme, making those attacks more likely to be successful. Sen. Chuck Schumer, D-N.Y., on Sunday called on Marriott to pay the fees to replace each U.S. customers’ passports stolen in the breach, which amounts to $110 per passport holder. Marriott did not immediately respond to a request for comment Monday about why Starwood collected guests’ passport information. The breach also provides scammers with other detailed information they can combine to gather a detailed view […]

The post Passport numbers stolen from Marriott provide scammers with another ID theft tool appeared first on Cyberscoop.

Continue reading Passport numbers stolen from Marriott provide scammers with another ID theft tool

EULA out, equity in: Why startups are now a part of larger companies’ security budgets

Cybersecurity sales teams often spread the idea that companies with the most sophisticated data protection strategies got that way by spending the most money on the latest and greatest security products. Truthfully, that’s usually not the case. U.S. companies have begun in recent years to enter strategic partnerships with cybersecurity startups, which often offer products at lower rates and more flexible terms than established market leaders. The technique allows companies like insurance giant Aetna health and New Jersey-based telecommunications firm IDT Corp. to more aggressively experiment with the services security startups offer, sometimes even stitching together technology from multiple distinct organizations. “I tend to choose innovators that are developing capabilities that have the potential to be game-changing, whereas leading enterprise security companies have a commitment to serve the broadest needs of the overall market,” said Jim Routh, chief security officer at Aetna. “Those needs don’t look a whole lot like our needs.” […]

The post EULA out, equity in: Why startups are now a part of larger companies’ security budgets appeared first on Cyberscoop.

Continue reading EULA out, equity in: Why startups are now a part of larger companies’ security budgets

Marriott announces data breach impacting 500 million hotel guests

The Marriott Hotel chain announced Friday that information contained in a Starwood Hotels database was compromised, potentially affecting up to 500 million guests. The company has determined that hackers had unauthorized access on Starwood’s guest database dating back to 2014. Hackers copied and encrypted guest information, then “took steps towards removing it,” the company said. Marriott on Sept. 8 received an alert from a security tool indicating an outsider was trying to access Starwood’s guest reservation database. That alert was enough for the company to consult outside security experts, who ultimately determined that thieves had been inside the database for roughly four years. For roughly 327 million of the 500 million guests affected, hackers stole information including their name, mailing address, phone number, email address, passport number, Starwood account information, date of birth, gender, arrival and departure information, reservation date and communication preferences, the company said. Payment information also was compromised […]

The post Marriott announces data breach impacting 500 million hotel guests appeared first on Cyberscoop.

Continue reading Marriott announces data breach impacting 500 million hotel guests

Rosenstein warns encryption can be ‘significant detriment’ to public safety

U.S. Deputy Attorney General Rod Rosenstein warned technology companies that Americans will not accept a culture in which encryption makes it impossible for law enforcement to investigate crimes, the latest comments in a long effort by the Department of Justice to find a way around end-to-end encryption. In a speech Thursday, Rosenstein urged tech firms to develop technology that keeps users’ data and communication as secure as possible, while also maintaining the ability to provide that information to law enforcement if it’s tied to an investigation. Firms including Apple, WhatsApp and others have introduced end-to-end encryption, a security measure that renders messages unreadable except to the sender and recipient. That type of technology is having “a dramatic impact on our cases, to the significant detriment of public safety,” Rosenstein said. Rosenstein’s remarks at Georgetown University Law Center’s Cybercrime Conference come amid the years-long “Going Dark” debate in which the public […]

The post Rosenstein warns encryption can be ‘significant detriment’ to public safety appeared first on Cyberscoop.

Continue reading Rosenstein warns encryption can be ‘significant detriment’ to public safety

Dunkin’ Donuts struck in latest credential stuffing attack

Dunkin’ Donuts has alerted customers to a data breach that may impact those who signed up to DD Perks, the company’s loyalty program. The fast-casual restaurant chain learned Oct. 31 that thieves obtained username and password information belonging to Dunkin’ customers via a credential stuffing incident. Those attacks occur when cybercriminals take credential information leaked in other data breaches then plug that data into other sites, targeting users who re-use the same password on multiple sites. “Our security vendor was successful in stopping most of these attempts, but it is possible that these third-parties may have succeeded in logging in to your DD Perks account if you used your DD Perks username and password for accounts unrelated to Dunkin’,” the company said in a statement. Compromised information included customers’ first and last names, email addresses, their 16-digit DD Perks account number and the DD Perks QR code. Dunkin’ did not disclose […]

The post Dunkin’ Donuts struck in latest credential stuffing attack appeared first on Cyberscoop.

Continue reading Dunkin’ Donuts struck in latest credential stuffing attack

‘Critical’ flaw in apps for Sennheiser headphones allows certificate access

Two applications developed by German electronics company Sennheiser contain vulnerabilities that could make it possible for hackers to forge digital certificates and impersonate legitimate websites. Sennheiser’s two apps, HeadSetup and HeadSetup Pro, installed certificates on users’ computers then failed to secure the key, according to a vulnerability report published Wednesday by the German security consulting firm Secorvo. The mistake means that hackers could decrypt the key and use the certificate, a means of digital authentication, to monitor victims’ traffic and launch main-in-the-middle attacks. “We found — caused by a critical implementation flaw — the secret signing key of one of the clandestine planted root certificates can be easily obtained by an attacker,” the Secorvo report states. “This allows him or her to sign up and issue technically trustworthy certificates. Users affected by this implementation bug can become victim of such a certificate forgery, allowing an attacker to send e.g. trustworthy signed […]

The post ‘Critical’ flaw in apps for Sennheiser headphones allows certificate access appeared first on Cyberscoop.

Continue reading ‘Critical’ flaw in apps for Sennheiser headphones allows certificate access

U.S. files charges in complex ad-fraud scheme that cost businesses tens of millions

U.S. prosecutors in the Eastern District of New York filed a 13-count cybercrime indictment Tuesday against the suspected orchestrators of a scheme to defraud internet advertisers out of tens of millions of dollars. The indictment accuses the eight defendants, who hail from Russia, Ukraine and Kazakhstan, with criminal violations including wire fraud, computer intrusion, aggravated identity theft and money laundering. The list includes Aleksander Zhukov, one of the Department of Justice’s recent high-profile cybercrime arrests. The group between September 2014 and December 2016 ran a purported advertising network, called “Ad Network #1,” that used 1,900 computer servers to load ads on more than 5,000 fabricated websites, prosecutors said. Defendants also leased some 650,000 IP addresses to falsify billions of visits to those fake websites, charging real companies for ads that real humans never viewed, the indictment alleges. “As alleged in court filings, the defendants in this case used sophisticated computer programming and infrastructure […]

The post U.S. files charges in complex ad-fraud scheme that cost businesses tens of millions appeared first on Cyberscoop.

Continue reading U.S. files charges in complex ad-fraud scheme that cost businesses tens of millions

NSO Group spyware used against two Mexican journalists following assassination

One day in May 2017 after the investigative journalist Javier Cárdenas was assassinated in Mexico, two of his colleagues at the Ríodoce newspaper began receiving text messages claiming to have information about the killer. The texts sent to Andrés Villarreal and Ismael Bojórquez, Ríodoce’s director, included links promising evidence that would prove a Mexican drug cartel was behind Cárdenas’ death. But the messages in fact were a surreptitious attempt by a Mexican government-linked organization to hack the journalists’ phones with Pegasus, a hacking tool that would have allowed operators to monitor their text messages, pictures, location and covertly activate the phones’ microphone and camera. Neither man clicked the links, suspicious that public officials were somehow behind the ruse. Researchers later confirmed their hunch, according to the New York Times. “I believe they wanted to search our conversations and messages for clues to the murder of Javier, but we are absolutely against […]

The post NSO Group spyware used against two Mexican journalists following assassination appeared first on Cyberscoop.

Continue reading NSO Group spyware used against two Mexican journalists following assassination

Alleged LinkedIn hacker to undergo psychiatric evaluation, trial pushed to February

The U.S. trial of the Russian hacker accused of stealing data from LinkedIn and Dropbox has been postponed until the defendant undergoes a court-mandated psychiatric evaluation. Yevgeniy Nikulin is scheduled to be transferred from the San Francisco Bay area this week to a psychiatric facility, where a doctor will determine whether he is fit to stand trial, according to Nikulin’s New York-based attorney Arkady Bukh. The delay complicates a high-profile federal case that is one of several involving extradited hackers tied to well-known large data breaches. Nikulin was arrested in October 2016 on charges related to hacking into LinkedIn and Dropbox in 2012, when he allegedly accessed a database containing some 117 million account passwords. The trial was originally scheduled to begin on Jan. 28, 2019. A court hearing to determine Nikulin’s competency now is scheduled for Feb. 12. Judge William Alsup of the U.S. Northern District of California in […]

The post Alleged LinkedIn hacker to undergo psychiatric evaluation, trial pushed to February appeared first on Cyberscoop.

Continue reading Alleged LinkedIn hacker to undergo psychiatric evaluation, trial pushed to February