Ad industry launches cybersecurity intelligence-sharing organization

Digital advertisers’ Trustworthy Accountability Group said it will take on a new cybersecurity role as the first information-sharing and analysis organization in the industry. “Despite the widespread vulnerabilities facing digital advertising — including ad-distributed malware, malicious pirate sites, and security holes exploited by fraud — there has not been an official ISAO to help coordinate the digital ad industry’s response to those threats to this point,” Andrew Weinstein, a spokesperson for the group, said. TAG’s announcement comes the same day of the discovery of Judy malware, auto-clicking adware that reached over 4.5 million downloads in the Google Play store across 41 apps. The infecting apps were recently removed by Google after several years on the store. Malware cuts into the advertising industry’s bottom line.  In addition to slowing connections and distracting users, malvertising can pose serious cybersecurity risks and deliver downright dangerous payloads. Making ads more secure raises the possibility that users won’t […]

The post Ad industry launches cybersecurity intelligence-sharing organization appeared first on Cyberscoop.

Continue reading Ad industry launches cybersecurity intelligence-sharing organization

Tanium raises $100 million investment, raises value to $3.75 billion

Private cybersecurity company Tanium announced Thursday it raised $100 million in funding, led by the private equity firm TPG, raising the company’s valuation to $3.75 billion. The company, which sells endpoint protection and management to government and military agencies as well as most of the top banks and retailers in the United States, had $300 million in cash and investments plus over 100 percent revenue growth before the latest injection of money. Earlier this week, Tanium hired Chris Bream, a director of product security at Facebook, as their new Chief Technology Officer. The raise comes despite the latest controversy for the California-based company: Tanium was found to be using real-time data from a hospital network in sales demos. Company CEO Orion Hindawi admitted mistakes were made, but the data was from the customer’s demo environment. Additionally, nine senior executives have the left the company over the last eight months, according to an […]

The post Tanium raises $100 million investment, raises value to $3.75 billion appeared first on Cyberscoop.

Continue reading Tanium raises $100 million investment, raises value to $3.75 billion

‘Cloak & Dagger’ attack hits all the typical Android security weaknesses

Hackers can use a malicious app to secretly take over and spy on an Android device with a new series of attacks dubbed Cloak & Dagger, according to award-winning new research published recently at the IEEE Symposium on Security and Privacy. “The possible attacks include advanced clickjacking, unconstrained keystroke recording, stealthy phishing, the silent installation of a God-mode app (with all permissions enabled), and silent phone unlocking and arbitrary actions (while keeping the screen off),” the researchers explained. A study of 20 users showed the attacks are practical and virtually undetectable. They were disclosed to Google beginning in August 2016 and remain partially actionable today because, according to the account given by the researchers, the Android security team repeatedly deemed the attacks less severe than the researchers did. We’ve reached out to Android’s security team for comment and will update the story when we hear back. “A quick experiment shows that it […]

The post ‘Cloak & Dagger’ attack hits all the typical Android security weaknesses appeared first on Cyberscoop.

Continue reading ‘Cloak & Dagger’ attack hits all the typical Android security weaknesses

Keybase browser extension brings encrypted messaging to social networks

Public encryption key database Keybase announced a Chrome extension Tuesday lends the service’s encryption tools to many of the most popular social networks including Twitter, which does not encrypt private messages, and Facebook, which requires users to opt-in to encryption. Created by two of the founders of SparkNotes and OkCupid, the service has built some of the most interesting encryption tools on the Internet. The browser extension comes in the wake of apps for PC, Mac, iPhone and Android, as well as an encrypted file sharing system. The first half of 2017 has been extremely active for the team who say they will now focus on improving what’s already been launched. Keybase has just over 146,000 users, co-founder Chris Coyne told CyberScoop. At a time when PGP (Pretty Good Privacy) encryption has been heavily criticized as far too cumbersome, Keybase offers an set of tools that make secure messaging, file sharing and verification easier than other PGP offerings. […]

The post Keybase browser extension brings encrypted messaging to social networks appeared first on Cyberscoop.

Continue reading Keybase browser extension brings encrypted messaging to social networks

DNI: Chinese hacking against U.S. companies is ‘ongoing’ but ‘significantly reduced’

Chinese hacking against U.S. targets is ongoing but “at volumes significantly lower” than before the landmark agreement reached in 2015 between Beijing and Washington D.C., according to the Director of National Intelligence Dan Coats. Former President Barack Obama and Chinese President Xi Jinping signed a deal in 2015 after cyberattacks that included widespread intellectual property theft for commercial gain, along with soft attribution that prompted threats of sanctions and other retaliation. Coats’ comments came in front of the Senate Armed Services Committee Tuesday during a hearing on worldwide military threats faced by the United States. Almost two years after the agreement was signed, Coats’ assessment notes significant progress on the cybersecurity front between the world’s two biggest economies. “We assess that Beijing will continue actively targeting the U.S. government, its allies, and U.S. companies for cyber espionage,” Coats said in his written testimony. “Private-sector security experts continue to identify ongoing cyber […]

The post DNI: Chinese hacking against U.S. companies is ‘ongoing’ but ‘significantly reduced’ appeared first on Cyberscoop.

Continue reading DNI: Chinese hacking against U.S. companies is ‘ongoing’ but ‘significantly reduced’

Tor’s ex-director: ‘The criminal use of Tor has become overwhelming’

Nearly two years to the day since Andrew Lewman quit his job as executive director of Tor, the anonymity software meant to shield users from government intervention, he found himself rushing between meetings with European law enforcement. Boosted by endorsements from internet activists like Julian Assange and Edward Snowden, Lewman had been at the helm of Tor as it became synonymous with internet user privacy. Now, as the newly minted vice president of dark web intel firm OWL Cybersecurity, his meetings with governments have gone from educating officials on how people use Tor to helping law enforcement investigate criminal activity occurring on Tor. As Lewman spoke to CyberScoop last month in between two of those meetings, it became clear that his perspective on the software has shifted. “What’s changed most about Tor is the drug markets have taken over,” Lewman said. “We had all these hopeful things in the beginning but ever since Silk Road has proven you […]

The post Tor’s ex-director: ‘The criminal use of Tor has become overwhelming’ appeared first on Cyberscoop.

Continue reading Tor’s ex-director: ‘The criminal use of Tor has become overwhelming’

As investigation against Assange is dropped, WikiLeaks releases new CIA malware

It’s Friday, which means that WikiLeaks is releasing another installment from Vault 7, the cache of CIA documents on cyberwarfare. This time it’s a tool that targets Microsoft Windows and a common version of Linux. This release comes the same day that Sweden announced it would drop its rape investigation into WikiLeaks founder Julian Assange. British authorities still have a warrant out for Assange’s arrest for failure to appear in court. The U.S. government has not said whether it will charge Assange in the releases of classified information. The newest WikiLeaks release is focused on classified CIA malware called Athena that targets all Windows operating systems including the latest offering, Windows 10. The dates of the leaked documents show that the CIA was able to hack Windows 10 only months after it was released. The malware also targets Ubuntu v. 14.04, the most popular version of Linux. The weapon was developed […]

The post As investigation against Assange is dropped, WikiLeaks releases new CIA malware appeared first on Cyberscoop.

Continue reading As investigation against Assange is dropped, WikiLeaks releases new CIA malware

Facebook Messenger upgrades encrypted chat feature

Chatting on Facebook is quietly getting more secure. The social media company’s Messenger, used by more than 900 million people around the world, just launched a significant usability upgrade to its “Secret Conversations” feature that enables encrypted communications between two people on multiple devices. Previously, encrypted communications were available to one device per person, severely limiting their attractiveness in a world where people rapidly switch between mobile, tablets and desktop devices. NEW! Facebook #Messenger “Secret Conversations” End-to-End Encryption is rolling out multi-device E2E chats! pic.twitter.com/awy4URXYcH — Alec Muffett (@AlecMuffett) May 18, 2017 Messenger’s adoption of strong encryption and this latest feature upgrade has won plaudits in the privacy community. The change, however, was practically whispered in a small update to a year-old blog post that had first announced the encryption features — and Facebook only added the information after users actually noticed the existence of the new feature.  For a company with the ability to […]

The post Facebook Messenger upgrades encrypted chat feature appeared first on Cyberscoop.

Continue reading Facebook Messenger upgrades encrypted chat feature

Researchers build WannaCry decryption tools for Windows XP

Less than a week after the WannaCry ransomware rapidly spread across the world, a French security researcher released a tool on Thursday that gives Windows XP users a chance to decrypt and save their files from oblivion. Adrien Guinet created WannaKey that generates an RSA private key which can be used in combination with WanaFork to decrypt the files. It requires a bit of luck — that the memory hasn’t been reallocated and erased — but can be a potential file saver for those who meet the requirements. Make sure to read the program’s instructions and warnings closely before usage. #wannacry in-memory private RSA key recovery for Windows XP : https://t.co/nMqVKgfv58 — Adrien Guinet (@adriengnt) May 18, 2017 I got to finish the full decryption process, but I confirm that, in this case, the private key can recovered on an XP system #wannacry!! pic.twitter.com/QiB3Q1NYpS — Adrien Guinet (@adriengnt) May 18, 2017 Windows XP, […]

The post Researchers build WannaCry decryption tools for Windows XP appeared first on Cyberscoop.

Continue reading Researchers build WannaCry decryption tools for Windows XP

Researchers: WannaCry ransomware shares code with North Korean malware

The ransomware known as WannaCry that spread rapidly to 300,000 machines in 150 countries over the past few days shares code with malware written by a group of North Korean hackers known as the Lazarus Group. While the shared code is important, experts warned that it’s far from proof about who created and launched the ransomware attacks. Neel Mehta, a security researcher at Google, first pointed out the shared code on Monday on Twitter. The link was quickly echoed by numerous other experts. Shared code between an early, Feb 2017 Wannacry cryptor and a Lazarus group backdoor from 2015 found by @neelmehta from Google. pic.twitter.com/hmRhCSusbR — Costin Raiu (@craiu) May 15, 2017 Similitude between #WannaCry and Contopee from Lazarus Group ! thx @neelmehta – Is DPRK behind #WannaCry ? pic.twitter.com/uJ7TVeATC5 — Matthieu Suiche (@msuiche) May 15, 2017 “From a technical point of view those two functions and their references are identical,” said […]

The post Researchers: WannaCry ransomware shares code with North Korean malware appeared first on Cyberscoop.

Continue reading Researchers: WannaCry ransomware shares code with North Korean malware