Federal CISOs are bracing for further cyber cuts in wake of Trump budget

Despite having a severe workforce shortage, federal CISOs are bracing for further cuts to their cybersecurity personnel under President Donald Trump’s proposed budget. Current and former government CISOs warned of their potential struggles Tuesday at the SINET ITSEF conference in Mountain View, Calif., saying that cuts on top of a hiring freeze compounds already mounting technical staffing challenges. According to Department of Health and Human Services CISO Chris Wlaschin, the agency is preparing for a $15.1 billion budget cut under the proposed budget. Additionally, Wlaschin said HHS currently faces a 30 percent vacancy rate across information technology positions in the department today. If money quickly evaporates from the agency’s budget, that vacancy rate is slated to grow. “We are struggling to compete against private sector and other agencies,” Wlaschin said, pointing to disparities in pay and training that drive potential employees away from HHS. In anticipation of cuts, HHS is working hard to “run […]

The post Federal CISOs are bracing for further cyber cuts in wake of Trump budget appeared first on Cyberscoop.

Continue reading Federal CISOs are bracing for further cyber cuts in wake of Trump budget

Why was North Korea running a phantom cybersecurity startup in Malaysia?

Cut off from the rest of the world, North Korea may be the last country anybody would expect to produce a cybersecurity startup advertising products intended to compete on the global market. North Korea’s leadership, however, often turns expectations upside down. From the heart of the Malaysian capital of Kuala Lumpur as well as the nearby financial center of Singapore, North Korean spies covertly ran a technology business that, until last year, publicly sold a wide array of products including iPhone apps, web development apps and even cybersecurity tools. Virtually nobody knew who really controlled the company until recently. Even today, nobody is entirely sure how it worked. Now, CyberScoop has learned that United Nations officials are currently looking into the business as part of larger inquiries into sanctions violations by North Korea. The now-defunct company, Adnet International, was one among a dynamic network of North Korean fronts in Malaysia, many of which were […]

The post Why was North Korea running a phantom cybersecurity startup in Malaysia? appeared first on Cyberscoop.

Continue reading Why was North Korea running a phantom cybersecurity startup in Malaysia?

FedEx paying customers to re-install Flash

FedEx is running a new promotion offering customers $5 off a purchase if they install Adobe Flash and permanently re-enable it. From FedEx’s angle, Flash is used to deliver cloud printing services. That’s the sign of an ancient web app, especially when you consider Google Chrome officially began blocking Flash content in December 2016 in favor of HTML5. Apple’s Safari did the same thing earlier in the year. Last summer, Mozilla Firefox began blocking Flash content as well. Facebook blocked it before then and, to top it all off, Adobe itself announced the impending death of Flash in 2015. Flash introduces stability, performance and security issues to every browser it touches, hence the movement to have Flash removed from the internet. In 2015, the year before the technology started to be blacklisted in major browsers, Flash accounted for four out of five widely used zero day vulnerabilities. The years-long campaign to exterminate the technology is moving […]

The post FedEx paying customers to re-install Flash appeared first on Cyberscoop.

Continue reading FedEx paying customers to re-install Flash

Economists have studied how criminals can make the most out of ransomware

You’ve infected a computer, locked it down and demanded ransom. Congratulations, you’re a cybercriminal. The bad news is that you’re doing a terrible job of maximizing profits. Ransomware was an estimated one billion dollar per year industry in 2016, but new research from computing and economics academics at the United Kingdom’s University of Kent shows that the “unsophisticated” techniques of ransomware criminals could easily be refined and “could lead to dramatic increases in profits at relatively little costs.” “The profit [the hackers] can make largely depends on the willingness of those attacked to pay the ransom,” researchers Julio Hernandez-Castro, Edward Cartwright and Anna Stepanova explain in the report. “This, in turn, will depend on various components – how much a victim values their files, the extent to which they trust the criminals to honor their word, willingness to give money to criminals, etc.” It’s a novel scenario for economists, but the academics approached their research with the cut-throat […]

The post Economists have studied how criminals can make the most out of ransomware appeared first on Cyberscoop.

Continue reading Economists have studied how criminals can make the most out of ransomware

Monero cryptocurrency doubled in price in March and is being used more widely on dark net markets

Monero, a cryptocurrency designed for anonymity and security, doubled in price over the last month to around $23 while other digital currencies, including bitcoin, saw a mixed month. One reason for Monero’s recent success: Cybercriminals intrigued by the currency’s promises of greater anonymity are using it more often on black markets. Several prominent vendors dealing in malware and other illicit products told CyberScoop they saw a slow but noticeable rise in Monero’s use over the last month. Amid a wave of interest in privacy-focused cryptocurrency technology, Monero was created by a psuedononymous hacker in 2014 as scams swallowed early attempts to develop anonymous coins. By the time it appeared on the scene, bitcoin was already widely used on dark net markets and was being closely watched by law enforcement. The creator faded away quickly while Monero itself has stuck around and, in 2016,  grew 2,760 percent in price. The early 2017 growth builds on that. Here’s […]

The post Monero cryptocurrency doubled in price in March and is being used more widely on dark net markets appeared first on Cyberscoop.

Continue reading Monero cryptocurrency doubled in price in March and is being used more widely on dark net markets

Russian hacker pleads guilty in U.S. for role in Citadel malware

The hacker known as Kolypto plead guilty in an Atlanta court room on Monday to a charge of computer fraud after reaching a deal with federal prosecutors who agreed to seek no more than five years in prison for the crime. Mark Vartanyan, 29, was arrested in Norway in 2014 and extradited to the United States in Dec. 2016. Although he pleaded not guilty last week, Vartanyan took a deal just four days later, the Associated Press reports. Citadel malware was described in its heyday as a “state-of-the-art toolkit to both distribute malware and manage infected computers” by security firm Malwarebytes. The malware’s own tagline boasted it was a “universal spyware system.” Citadel launched in 2011 on Russian invite-only hacker forums and gained widespread popularity, promising to steal financial information from infected computers. It’s estimated to have cost $500 million in losses on 11 million infected machines over a three year period. In […]

The post Russian hacker pleads guilty in U.S. for role in Citadel malware appeared first on Cyberscoop.

Continue reading Russian hacker pleads guilty in U.S. for role in Citadel malware