Senate IT systems are ‘far behind’ on basic cybersecurity, Wyden charges

The U.S. Senate is “far behind when it comes to implementing basic cybersecurity practices,” Sen. Ron Wyden, D-Ore., said in a letter sent Thursday to the Senate Rules Committee. Wyden urges committee chair Sen. Richard Shelby, R-Ala., and ranking member Sen. Amy Klobuchar, D-Minn., to improve information security in all Senate IT systems by requiring two-factor authentication. Two-factor authentication is a basic and effective security measure requiring two types of authentication such as a password, a code from a mobile app or a chip on an ID card. The layers of protection make it more difficult for hackers to successfully attack targeted accounts and networks. Eighty percent of all executive branch agencies use two-factor authentication, Wyden said, while the Senate neither requires nor even offers the additional protection for desktop computers and email accounts except for remote work. “It is critical that the legislative branch is able to secure our systems […]

The post Senate IT systems are ‘far behind’ on basic cybersecurity, Wyden charges appeared first on Cyberscoop.

Continue reading Senate IT systems are ‘far behind’ on basic cybersecurity, Wyden charges

Russia is ‘ready to discuss’ election hacking and cybercrime with U.S.

The Russian government is open to discussions with the United States on a wide range of cybersecurity issues including election hacking and cybercrime, Deputy Foreign Minister Sergey Ryabkov told the daily Russian political newspaper Kommersant. Even the question of election hacking “is not a taboo for us, although it had been made extremely tense by the efforts of the Obama team,” Ryabkov said Wednesday. “We are ready to discuss with the Americans the whole range of these questions.” Attempts at dialogues with the Obama administration were met with silence, he said. Having renewed those attempts now with the Trump administration, Ryabkov “expects the response will be more positive.” “Classical” cybercrime including bank fraud and intellectual property theft is also on the table for discussions and possible cooperation, the foreign minister said. The prospect of greater Russian government cooperation with the West on issues of cybercrime looms large because the Russian-speaking sphere is a widely seen as […]

The post Russia is ‘ready to discuss’ election hacking and cybercrime with U.S. appeared first on Cyberscoop.

Continue reading Russia is ‘ready to discuss’ election hacking and cybercrime with U.S.

High school student allegedly hacks school, charges fellow students to change grades

A tenth-grade student at Memorial High School in Houston, Texas is under arrest after allegedly hacking into his school’s computer systems, changing grades and then charging another student to changes to their own records. The scheme, which started with a password stolen in an unspecified theft, ended on March 31 with an arrest by Spring Branch ISD police, according to local news reports. “At this time, an ongoing investigation has found only one other underclassman paid the student to change their grades,” a spokesperson said. The service, however, was allegedly advertised to others. The student faces felony breach of computer security charges. In Texas, those charges automatically become felonies if the computers in question are government property, as the school’s machines are. Students hacking school systems to change grades is a crime seemingly as old as time. Every year brings new schemes and arrests as a result of grade changing, including the […]

The post High school student allegedly hacks school, charges fellow students to change grades appeared first on Cyberscoop.

Continue reading High school student allegedly hacks school, charges fellow students to change grades

High school student allegedly hacks school, charges fellow students to change grades

A tenth-grade student at Memorial High School in Houston, Texas is under arrest after allegedly hacking into his school’s computer systems, changing grades and then charging another student to changes to their own records. The scheme, which started with a password stolen in an unspecified theft, ended on March 31 with an arrest by Spring Branch ISD police, according to local news reports. “At this time, an ongoing investigation has found only one other underclassman paid the student to change their grades,” a spokesperson said. The service, however, was allegedly advertised to others. The student faces felony breach of computer security charges. In Texas, those charges automatically become felonies if the computers in question are government property, as the school’s machines are. Students hacking school systems to change grades is a crime seemingly as old as time. Every year brings new schemes and arrests as a result of grade changing, including the […]

The post High school student allegedly hacks school, charges fellow students to change grades appeared first on Cyberscoop.

Continue reading High school student allegedly hacks school, charges fellow students to change grades

Hong Kong regulators move to tighten cybersecurity rules after hacks cost stockbrokers over $14M

A string of 20 cyberattacks against Hong Kong stockbrokers led to $14.2 million (HK$110 million) in losses over the last 18 months, according to Hong Kong’s Securities and Futures Commission. In response, the regulator is tightening cybersecurity requirements. The specifics of the new legal framework are still being figured out. In a Wednesday press conference, the regulator launched a “market consultation” on cybersecurity upgrade requirements expected to cost over $125,000 for larger brokers, according to a report in the South China Morning Post. “We have to require all [brokers] to invest more to enhance the cybersecurity of their computer systems after customers lost up to HK$110 million from hacker attacks. The police have been investigating these cases,” a SFC spokesperson said on Wednesday. “The upgrade may cost money but it will ensure investors can trade safely when using their computers or mobile phones.” The new regulatory push follows a review begun last year […]

The post Hong Kong regulators move to tighten cybersecurity rules after hacks cost stockbrokers over $14M appeared first on Cyberscoop.

Continue reading Hong Kong regulators move to tighten cybersecurity rules after hacks cost stockbrokers over $14M

Why Jabber reigns across the Russian cybercrime underground

Much of the Russian cybercrime underworld is an enigma, but one technology serves as a crucial common link across all of it: Jabber. In a space of cutting-edge tech, creativity and crime, the 18-year-old instant messenger is the most popular communication tool among Russian-speaking cybercriminals, according to new research from the security firm Flashpoint. It’s how hackers make deals, share intelligence and offer tech support on their malware products. While it already reigns in Russian communities, Jabber is simultaneously rising in popularity for cybercriminals around the world. It’s a testament not only to the quality of the technology, but also to the influence of hacking trends set in Russia. “In the cybercriminal economy, Jabber is seen as the gold standard for communication,” Leroy Terrelonge III, a senior researcher at the security firm Flashpoint, told CyberScoop. Jabber (also known as XMPP or Extensible Messaging and Presence Protocol) is an open-source, federated instant messenger with thousands of independent servers and […]

The post Why Jabber reigns across the Russian cybercrime underground appeared first on Cyberscoop.

Continue reading Why Jabber reigns across the Russian cybercrime underground

Cheap and effective ransomware-as-a-service introduced in Russian underground

A cheap, effective and easy-to-use ransomware service is currently being sold in the Russian-language hacking underground. At a cost of $175, Karmen allows any buyer to encrypt infected machines using the AES-256 protocol and then trigger a ransom note demanding money, according to the security firm Recorded Future. Unlike most other ransomware, Karmen knows how to defend itself. The malware deletes its own decryptor if analysis software or a sandbox environment is detected. The tool is developed by a team includes two individuals: DevBitox, a Russian-speaking cybercriminal who sells the product, and an unknown developer in Germany, according to Recorded Future. Karmen has been observed since December 2016 when it was developed from the open source ransomware project Hidden Tear. The scope of Karmen’s infections and sales isn’t clear, but Recorded Future researchers observed at least 20 sales by DevBitox. Here’s DevBitox’s commercial for Karmen: The ransomware is interesting and highly professional […]

The post Cheap and effective ransomware-as-a-service introduced in Russian underground appeared first on Cyberscoop.

Continue reading Cheap and effective ransomware-as-a-service introduced in Russian underground

Shadow Brokers latest leak a gold mine for both criminals and researchers

As information security enthusiasts continue to pour over the Shadow Brokers latest dump, the alleged cache of NSA tools is turning out to be a treasure trove for both researchers and criminals. Ransomware known as “AES-NI” has been updated with a so-called “NSA Exploit Edition” that the malware’s developer claims  is now using EsteemAudit and EternalBlue exploits to infect machines, encrypt files and demand ransom for release.  EsteemAudit and EternalBlue were two tools dumped in last week’s leak. A rash of forum posts show several ransomware victims running old, unpatched or unsupported Windows servers that have been infected. There has been no independent confirmation on how the new ransomware works, but the malware’s author claimed to CyberScoop that they are using NSA exploits. “We use SMB [Server Message Block] and RDP [Remote Desktop Protocol] exploits: Esteemaudit, Eternalblue,” the developer said. “They all are in public now.” Liam O’Murchu, the director of Symantec’s security […]

The post Shadow Brokers latest leak a gold mine for both criminals and researchers appeared first on Cyberscoop.

Continue reading Shadow Brokers latest leak a gold mine for both criminals and researchers

Tech workers are routinely pressured to roll out products that aren’t secure, report says

The majority of tech professionals are pressured to roll out projects before they’ve undergone necessary security audits and hardening, according to a new security pressures survey from the security firm Trustwave. 65 percent of full-time IT professionals said management prioritized speed over security, according to the survey of 1,600 tech professionals from around the world. Worldwide, security is actually on a major upswing in this fight compared to 77 percent of IT professionals feeling this pressure in the previous two years. In the United States, however, there has been virtually no change: 71 percent of respondents are pushed to get projects out the door without necessary security checks. Only 35 percent of worldwide respondents said they never faced such pressure. What happens to projects that set aside security in favor of speed? The top two consequences tech professionals fear most from a hacker is personal and corporate reputation damage followed by financial damage to the […]

The post Tech workers are routinely pressured to roll out products that aren’t secure, report says appeared first on Cyberscoop.

Continue reading Tech workers are routinely pressured to roll out products that aren’t secure, report says

Synack raises $21.25 million in Series C round

The company best known for assembling a team that took only four hours to find critical vulnerabilities in U.S. military systems announced Tuesday a $21.25 million Series C funding round led by Microsoft Ventures. Total investment in the Silicon Valley firm, Synack, is now $55.25 million. Its bug bounty and penetration testing platform operates with a more closed and exclusive model than competitors, as the company aims to emphasize actionable intelligence and minimize noise. Founded by two former NSA researchers, Synack vetted a team of white-hat hackers that found 138 vulnerabilities overall as part of the official Hack the Pentagon program, which is set to expand in the coming years. It was conducted in concert with HackerOne, another bug bounty platform that received $40 million in Series C funding in February. Compared with competitors, Synack employs a relatively smaller and more heavily vetted pool of hackers to work with clients. The process to get on Synack’s red ream involves an application, interview, skill […]

The post Synack raises $21.25 million in Series C round appeared first on Cyberscoop.

Continue reading Synack raises $21.25 million in Series C round