A company in transition, FireEye sees surprise boost in revenue

At 13 years old, FireEye has already been through a pretty rough adolescence, including the loss of a CEO last year and a 40 percent drop in the value of its stock at one point. But the prominent cybersecurity company’s current leadership has been aiming for long-term profitability, and its numbers from the first quarter of 2017 brought some good news. FireEye reported a better-than-expected 3.4 percent rise in revenue to $173.7 million for the quarter, thanks to its product subscription and services businesses. New CEO Kevin Mandia projects bigger numbers in the coming quarters and eventual profitability by the end of the year, pinning much of that forecast to the recent release of the company’s Helix platform. High-profile hacks from Target to Sony resulted in headline-making FireEye investigations in recent years, but the company’s stock cratered in 2016. That trend has changed — the share price is up 13 percent in 2017, jumping 15 percent to $13.80 in after-hours trading following […]

The post A company in transition, FireEye sees surprise boost in revenue appeared first on Cyberscoop.

Continue reading A company in transition, FireEye sees surprise boost in revenue

Cyber business continues to solidify at U.S. military contracting giants

While stocks and profits at the biggest U.S. military contractors are driving up across the board under the saber-rattling of President Donald Trump, first-quarter financial results for industry giants like Lockheed Martin, Raytheon and Northrop Grumman show that cybersecurity is a growing if still relatively small part of their businesses. Forcepoint, Raytheon’s cybersecurity division and the company’s smallest segment by far, grew sales by 4 percent to $144 million last quarter. That tops the company’s overall 3.4 percent sales growth on $6 billion of sales but comes in well behind the 8 percent sales increase to $1.55 billion total in Space and Airborne Systems — a number driven largely by new spending on electronic warfare. Forcepoint’s profit margins declined, which Raytheon chief financial officer Anthony O’Brien credited to long-term investments being made in the business’s infrastructure. Forcepoint was acquired by Raytheon in 2015 when it was named Websense. The company has a decades-long history of selling censorship technology — with a customer […]

The post Cyber business continues to solidify at U.S. military contracting giants appeared first on Cyberscoop.

Continue reading Cyber business continues to solidify at U.S. military contracting giants

Iran-linked hackers used Microsoft Word flaw against Israeli targets, security firm says

Hackers allegedly linked to the Iranian government launched a digital espionage operation this month against more than 250 different Israel-based targets by using a recently disclosed and widely exploited Microsoft Word vulnerability, cybersecurity experts tell CyberScoop. The hacking group, dubbed OilRig by security researchers and believed to be tied to Iranian intelligence services, utilized a software flaw in Word officially known as CVE-2017-0199 that allows attackers to execute a remote computer intrusion to take full control of a target device while leaving little or no trace, said Michael Gorelik, vice president of Israeli security firm Morphisec. Over the last month, Morphisec has investigated the incident on behalf of multiple victims. Clients showed forensic evidence on their respective networks that could be linked back to OilRig. After its disclosure in March, CVE-2017-0199 was quickly exploited by nation-states and cybercriminals alike. OilRig has been around since at least 2015, according to numerous security industry experts who have […]

The post Iran-linked hackers used Microsoft Word flaw against Israeli targets, security firm says appeared first on Cyberscoop.

Continue reading Iran-linked hackers used Microsoft Word flaw against Israeli targets, security firm says

U.S. launches ‘Hack the Air Force’ bug bounty program

The U.S. Air Force launched a new bug bounty program dubbed “Hack the Air Force” on Wednesday, continuing a trend within the U.S. military that began last year with Hack the Pentagon and Hack the Army. Before the Pentagon’s bug bounty programs launched, it was illegal to search for vulnerabilities on Defense Department networks. The trend has extended overseas, as well, with the U.K. government’s announcement of its own bug bounty program last month. The Air Force program is directed by HackerOne, the bug bounty platform behind Hack the Pentagon that just raised a $40 million investment in February, and Luta Security, the security consulting firm driving the U.K. program. HackerOne and Luta Security are partnering to deliver up to 20 bug bounty challenges over three years to the Defense Department. “This outside approach — drawing on the talent and expertise of our citizens and partner-nation citizens — in identifying our security vulnerabilities will […]

The post U.S. launches ‘Hack the Air Force’ bug bounty program appeared first on Cyberscoop.

Continue reading U.S. launches ‘Hack the Air Force’ bug bounty program

Ransomware demands now average about $1,000 because so many victims decide to pay up

The average ransomware attack yielded $1,077 last year, new research shows, representing a 266 percent spike from a year earlier. The reason for the landmark year for hackers? Many ransomware victims readily pay the price. The number of attacks, varieties of distinct malware and money lost ballooned as ransomware became one of the top tactics of attackers, according to new research from the security firm Symantec. Some of the most high-profile ransomware incidents of the last year include San Francisco’s Muni getting hit, Washington D.C.’s police department being breached just before inauguration and a Los Angeles college paying a $28,000 ransom. Hoping to turn the tide against the billion-dollar ransomware industry, last year the FBI urged businesses to alert authorities and not pay up. Instead, most keep attacks a secret, paying off hackers 70 percent of the time. That behavior only increases the sweet spot for demands, as criminals seek the highest possible ransom while trying to […]

The post Ransomware demands now average about $1,000 because so many victims decide to pay up appeared first on Cyberscoop.

Continue reading Ransomware demands now average about $1,000 because so many victims decide to pay up

Zero day exploits are rarer and more expensive than ever, Symantec says

It’s basic economics: When supply drops but demand keeps rising, price goes up. It’s no different for pieces of information that give cyberattackers big advantages. The number of zero day exploits revealed in the wild fell for a third straight year in 2016, pushing the prices for them skyward and driving attackers to use alternative tactics, according to new research from Symantec. The total number of zero days exploited — a “zero day” is a software vulnerability that hasn’t been disclosed to the vendor and thus hasn’t been patched — dropped to 3,986 in 2016, Symantec said. That number was as high as 4,985 in 2014. Meanwhile, demand for zero days is as high as it’s ever been. Zero days discovered by security researchers are purchased by a wide variety of parties including militaries, intelligence agencies, law enforcement, software vendors, cybercriminals and military contractors. Their intentions also vary widely: Some buyers want to fix and defend software, others want to mount […]

The post Zero day exploits are rarer and more expensive than ever, Symantec says appeared first on Cyberscoop.

Continue reading Zero day exploits are rarer and more expensive than ever, Symantec says

U.S. Air Force invests millions this month on cyberweapons projects

Three of the United States’ largest military contractors each won multimillion-dollar projects in the last month to boost American offensive power in the cyber domain. Raytheon, Northrop Grunman and Booz Allen Hamilton have all seen their stock prices rise 10 to 20 percent since the November 2016 U.S. election. Investors sprinted to military contractors based on Trump’s promises for higher spending on — among other warfighting capabilities — the cyber domain. Many of the world’s biggest weapons manufacturers are expanding aggressively into offensive and defensive cybersecurity in search of the same level of profitability found in building conventional weapons systems. Raytheon will build the Air Force’s newest Cyber Command and Control Mission System (C3MS) operating location — at San Antonio’s Lackland Air Force Base — after winning an $8.5 million contract this week. Lackland is home to the 24th Air Force, the organization tasked with operating and defending the Air Force’s networks. It’s […]

The post U.S. Air Force invests millions this month on cyberweapons projects appeared first on Cyberscoop.

Continue reading U.S. Air Force invests millions this month on cyberweapons projects

Leaked NSA tools, now infecting over 200,000 machines, will be weaponized for years

More than 200,000 machines have been infected by an NSA backdoor leaked nearly two weeks ago by the Shadow Brokers hacking group, according to the latest scans and estimates. Experts expect to see the exploits, implants and other NSA-built hacking tools in use for as long as a decade into the future. U.S. computers are by far the most frequently hit targets of DOUBLEPULSAR, a backdoor implant allowing attackers to stealthily collect information and run malicious code on a target’s machine, according to the Swiss security firm Binary Edge, which counted 183,107 infected machines as of early Monday morning. More than 67,000 of those machines were American, while China, Russia and the U.K. have suffered several thousand infections each. On Friday, that number was 100,000 globally. An average of 25,000 machines have been infected globally every day over the last week. Experts say the actual number is higher than Monday’s assessment because each count is slow and does always not catch everything […]

The post Leaked NSA tools, now infecting over 200,000 machines, will be weaponized for years appeared first on Cyberscoop.

Continue reading Leaked NSA tools, now infecting over 200,000 machines, will be weaponized for years

Android spyware in the Google Play Store was downloaded over 1 million times over 3 years

A piece of malware pretending to be an Android system update was downloaded over 1 million times since launch 2014. The malware, dubbed SMSVova, spied on a victim’s location and relayed it to the attacker in real time. The app, named “System Update” and sporting official-looking Android art, was spotted by security researchers at Zscaler and then removed by Google soon after disclosure. When a user starts the newly downloaded app, it quits and pops up a message alerting the user that “Unfortunately, Update Service has stopped.” It then goes into hiding but remains active. The malware watches a victim’s location and incoming SMS messages. The attacker sends a message like “get faq” and the infected device responds with a set of commands allowing for constant monitoring or conditional alerts on a victim’s location. “There are many apps on the Google Play Store that act as a spyware; for example, those that spy on […]

The post Android spyware in the Google Play Store was downloaded over 1 million times over 3 years appeared first on Cyberscoop.

Continue reading Android spyware in the Google Play Store was downloaded over 1 million times over 3 years

LastPass vulnerability ‘beats the entire purpose’ of two-factor authentication

LastPass, one of the web’s most popular password managers, had a critical flaw in its implementation of two-factor authentication, according to new research published Thursday. The purpose of 2FA is to secure accounts and systems against attackers who already have your password. LastPass’s problem lies in how they stored the QR code used for setting up 2FA. In this case, the QR code holds the “secret” that will allow a user or an attacker to generate valid codes that serve as the second factor. Unfortunately, according to researcher Martin Vigo, LastPass stored that secret under a URL that can be derived from the password. That means an attacker with the password could then compromise the second factor of authentication. “This literally beats the entire purpose of 2FA, which is a layer of security to prevent attackers already in possession of the password from logging in,” Vigo explained. “To put it in perspective, imagine […]

The post LastPass vulnerability ‘beats the entire purpose’ of two-factor authentication appeared first on Cyberscoop.

Continue reading LastPass vulnerability ‘beats the entire purpose’ of two-factor authentication