Craig Newmark Philanthropies donated $450k to boost anti-ransomware coalition

The Institute for Security and Technology received a $450,000 donation from Craig Newmark Philanthropies to continue its work combatting ransomware, the organization shared first with CyberScoop. The money will go towards continuing the work started by the Ransomware Task Force, a public-private collaboration launched earlier this year by the Insitute. The task force brought together representatives from more than 60 companies and organizations across government, nonprofits and the private sector. Microsoft, Rapid 7, the Cyber Threat Alliance, FBI and the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency are among the participants. The Ransomware Task Force released a report at the end of April offering four dozen recommendations for policymakers and industry to take on the problem. The task force recommended that governments establish a fund to support ransomware response, and closer regulation of the cryptocurrency. IST will use the funding from Newmark, the founder of Craigslist, and other forthcoming […]

The post Craig Newmark Philanthropies donated $450k to boost anti-ransomware coalition appeared first on CyberScoop.

Continue reading Craig Newmark Philanthropies donated $450k to boost anti-ransomware coalition

USB-based malware is a growing concern for industrial firms, new Honeywell findings show

The number of cyber threats designed to use USB sticks and other external media devices as launching pads doubled in 2021, according to new research from Honeywell, the industrial automation giant.  Of those threats, 79% could be used to disrupt operational technology systems, researchers found. The report was based on cybersecurity threat data collected from hundreds of industrial facilities over a 12-month period. The company did not immediately provide details on the specific type of threat data detected.  “USB-borne malware was a serious and expanding business risk in 2020, with clear indications that removable media has become part of the playbook used by organized and targeted attacks, including ransomware,” Eric Knapp, director of cybersecurity research at Honeywell Connected Enterprise said in a statement.  Since many industrial systems are cut off from the internet, external devices like USB drives can provide hackers with a foothold into sensitive networks. USB drives have […]

The post USB-based malware is a growing concern for industrial firms, new Honeywell findings show appeared first on CyberScoop.

Continue reading USB-based malware is a growing concern for industrial firms, new Honeywell findings show

Spanish-language misinformation about vaccines is evading Facebook’s moderators

Facebook is still struggling to rein in COVID-19 misinformation in Spanish, a recent report from the advocacy group Avaaz indicates. Avaaz, a global human rights group, looked at top-performing posts on the platform promoting a debunked viral claim the coronavirus will make patients’ arms magnetic because it contains metals or possibly a microchip. Of the 30 posts in Spanish, only one had received a fact-checking label as of June 14. In comparison, roughly half of the 47 high-performing English posts had a fact-checking label. One post flagged by the group showed a woman placing a magnet on her arm, claiming that it stuck to the site where she received her vaccine injection. The post, which racked up tens of thousands of views, has been removed by Facebook. Facebook employs third-party organizations to fact-check its content. If a post receives a fact-checking label as false, it’s deprioritized in the user’s feed. […]

The post Spanish-language misinformation about vaccines is evading Facebook’s moderators appeared first on CyberScoop.

Continue reading Spanish-language misinformation about vaccines is evading Facebook’s moderators

CISA doesn’t know how many US federal agencies use firewalls to fend off malicious traffic

The Department of Homeland Security’s top cybersecurity agency doesn’t know how many agencies are segmenting their networks from unwanted outside traffic, a basic security practice, according to a letter recently sent to the office of Sen. Ron Wyden (D-Ore.) by the agency. The agency provided the answers in response to a February inquiry from Wyden’s office following a heated Senate Intelligence Committee hearing about the breach at the federal contractor SolarWinds. The suspected Russian espionage campaign used a vulnerability in SolarWinds and other software to infiltrate the systems of at least nine federal agencies and about 100 private companies. Wyden questioned why agencies did not have properly configured firewalls defending their servers running the SolarWinds software, Orion. Such a measure would have prevented hackers from implementing the second stage of the SolarWinds attack and using the backdoor they had planted, according to an assessment by SolarWinds. The agency concurred that […]

The post CISA doesn’t know how many US federal agencies use firewalls to fend off malicious traffic appeared first on CyberScoop.

Continue reading CISA doesn’t know how many US federal agencies use firewalls to fend off malicious traffic

Chris Inglis confirmed as first US national cyber director after Senate vote

The Senate on Thursday confirmed Chris Inglis as the new White House cyber czar, a role it enacted into law late last year. The new role will play a key part in coordinating the government response to major hacks and other cybersecurity threats. Inglis takes on the position as the U.S. has dealt with an onslaught of cybersecurity incidents, including ransomware attacks on Colonial Pipeline and meat supplier JBS. The national cyber director will also lead the implementation of cyber policy and strategy, including efforts mandated by the Biden administration to improve federal cybersecurity. Inglis will be expected to work closely with Anne Neuberger, deputy national security advisor for cyber and emerging technology on the National Security Council, as well as Jen Easterly, Biden’s nominee to lead the Department of Homeland Security’s cybersecurity agency, should she also be confirmed by Congress. Inglis will also coordinate cooperation between the government and […]

The post Chris Inglis confirmed as first US national cyber director after Senate vote appeared first on CyberScoop.

Continue reading Chris Inglis confirmed as first US national cyber director after Senate vote

As vaccine passports morph into digital IDs, privacy advocates want to know that user data is protected

Tech companies and global organizations have championed health passes, sometimes known as vaccine passports, as a means to securely reopen businesses and borders as COVID-19 cases drop and vaccination rates rise. The technology is meant to serve as a secure way to prove vaccination without someone needing to present a physical vaccine card or other documentation. For instance, instead of checking a customer’s vaccine card, a business or airline could simply scan a QR code that provides verification based on uploaded medical records. The European Union, Israel, Japan and Singapore have all embraced vaccine passports to an extent to help reopen their borders. Several states including New York and soon California have embraced verification technology. A growing number of states, including Arizona, Florida, and Georgia have banned requiring them. Some opponents of the technology have raised concerns that vaccine passports are an unnecessary replacement for paper, and could disadvantage individuals […]

The post As vaccine passports morph into digital IDs, privacy advocates want to know that user data is protected appeared first on CyberScoop.

Continue reading As vaccine passports morph into digital IDs, privacy advocates want to know that user data is protected

Top tech critic Lina Khan named FTC chair

Just hours after the Senate confirmed Columbia law professor Lina Khan as the new Democratic commissioner of the Federal Trade Commission, the Biden administration reportedly picked her to run the agency. Sen. Amy Klobuchar, D-Minn., first noted Khan’s selection as FTC chair in a Senate Judiciary antitrust subcommittee hearing on Tuesday. A White House spokesperson confirmed the pick. The 32-year old Khan has been a staunch critic of Amazon, Facebook and Google, contending that they abuse their market power. She’s also warned of tech firms that could mine consumer data in a way that endangers privacy. The selection is a huge warning shot to big tech companies that the Biden administration will put close scrutiny on how they wield market might to acquire and crush the competition. Khan’s power could also be buoyed by efforts in the House from both parties to limit anti-competitive behavior in Silicon Valley. The FTC […]

The post Top tech critic Lina Khan named FTC chair appeared first on CyberScoop.

Continue reading Top tech critic Lina Khan named FTC chair

Former NSA contractor Reality Winner is released from prison for good behavior

Reality Winner, a former NSA-contractor found guilty of leaking classified government material, has been released early for good behavior, according to her lawyer. Winner accepted a guilty plea agreement in 2018 for leaking classified information about the Russian government’s attempt to interfere with U.S. elections to The Intercept. “Winner is released a bit early for good behavior and will be finished with the reentry process and onto supervised release in November,” her lawyer Alison Grinter said in an email. Winner was originally sentenced to more than five years in prison, the longest term ever imposed by a court for a case involving leaking. Winner and her lawyer have petitioned the Department of Justice to commute the sentence and unsuccessfully requested a pardon from former President Donald Trump. Grinter says that there has been no decision made on the commutation or pardon. “The fight continues and I’ll still be taking meetings […]

The post Former NSA contractor Reality Winner is released from prison for good behavior appeared first on CyberScoop.

Continue reading Former NSA contractor Reality Winner is released from prison for good behavior

Hackers reportedly used EA Games’ Slack to breach network, access source code

Hackers who reportedly stole valuable source code from games company Electronic Arts did so by first infiltrating the company’s Slack, a representative for a group claiming credit for the attack told Motherboard. For just $10, the hackers purchased a cookie that allowed them to infiltrate the $5 billion company’s Slack. They then posed as an employee to convince at IT administrator to grant them authentification to get into the company’s corporate network. The EA hack, first reported by Motherboard, included some game source code and related tools. No player data was accessed in the breach and the company does not expect the hack to impact its games, EA said in a statement. EA did not immediately respond to an email asking for verification of the hackers’ claims that they leveraged Slack to carry out the operation. The attack highlights the vulnerabilities created by workplace communication technologies, which have skyrocketed in […]

The post Hackers reportedly used EA Games’ Slack to breach network, access source code appeared first on CyberScoop.

Continue reading Hackers reportedly used EA Games’ Slack to breach network, access source code

Justice Department, international law enforcement disrupt major marketplace for cybercriminals

The Justice Department partnered with international law enforcement to take down an online marketplace offering stolen login credentials for various accounts including bank and online payment, DOJ said on Thursday. It’s unclear how much cybercriminals scored financially using the stolen logins, but the newly unsealed affidavit for a warrant notes victim reports topping $200 million in losses in the U.S. alone. The marketplace, Slilpp, reportedly sold login credentials for over 1,400 account providers at the time that law enforcement disrupted the marketplace’s servers and domains. “With today’s coordinated disruption of the Slilpp marketplace, the FBI and our international partners sent a clear message to those who, as alleged, would steal and traffic in stolen identities: we will not allow cyber threats to go unchecked,” acting U.S. Attorney Channing Phillips of the District of Columbia said in a statement. “We applaud the efforts of the FBI and our international partners who […]

The post Justice Department, international law enforcement disrupt major marketplace for cybercriminals appeared first on CyberScoop.

Continue reading Justice Department, international law enforcement disrupt major marketplace for cybercriminals