Home security technician pleads guilty to spying on women, couples

A former ADT home security technician pleaded guilty on Thursday to logging into customers’ video feeds to watch naked women and couples having sex. Telesfloro Aviles faces up to five years in prison. Aviles’ Dallas-area snooping stretched over nearly five years and involved him accessing approximately 200 customer accounts more than 9,600 times, he admitted. “This defendant, entrusted with safeguarding customers’ homes, instead intruded on their most intimate moments,” said the acting U.S. Attorney for the Northern District of Texas, Prerak Shah. “We are glad to hold him accountable for this disgusting betrayal of trust.” ADT still faces civil suits over an incident it first disclosed in April, 2020. Aviles would gain improper access by claiming he needed to temporarily add himself to customers’ “ADT Pulse” accounts to conduct system tests. Other times he would add himself without permission, according to federal prosecutors. ADT says it fired Aviles after discovering […]

The post Home security technician pleads guilty to spying on women, couples appeared first on CyberScoop.

Continue reading Home security technician pleads guilty to spying on women, couples

Federal courts are latest apparent victim of SolarWinds hack

The federal judiciary’s electronic case management and filing system suffered “an apparent compromise” as part of the SolarWinds breach, according to the Administrative Office of the U.S. Courts. The office is still assessing the impact, but a representative says the organization has stepped up security precautions in the meantime. “The federal Judiciary’s foremost concern must be the integrity of and public trust in the operation and administration of its courts,” James Duff, secretary of the judiciary’s national policy-making body — the Judicial Conference of the United States — said in a Wednesday communication to the courts. Federal courts are a potential goldmine for hackers, as they harbor sensitive data on millions of people. Government investigators have said Russia is likely behind a cyber-espionage campaign that hit federal agencies and major companies via updates to the SolarWinds Orion software. The Administrative Office of the U.S. Courts said it was working on […]

The post Federal courts are latest apparent victim of SolarWinds hack appeared first on CyberScoop.

Continue reading Federal courts are latest apparent victim of SolarWinds hack

SolarWinds hack spotlights a thorny legal problem: Who to blame for espionage?

Every massive breach comes with a trail of lawsuits and regulatory ramifications that can last for years. Home Depot, for instance, only last month settled with a group of state attorneys general over its 2014 breach. The SolarWinds security incident that U.S. officials have pinned on state-sponsored Russian hackers is unlike anything that came before, legal experts say, meaning the legal liability could take even longer to resolve in court. As Congress, federal government departments and corporations reckon with the vast sweep of the SolarWinds breach, there are still many more questions than answers. Fewer pieces of it are less certain than how it might play out in court, where companies and individuals alike stand to gain or lose. Many millions of dollars, corporate blame and years of finger-pointing are on the line. That’s because the targets — government agencies, and some major companies — aren’t the usual kind of […]

The post SolarWinds hack spotlights a thorny legal problem: Who to blame for espionage? appeared first on CyberScoop.

Continue reading SolarWinds hack spotlights a thorny legal problem: Who to blame for espionage?

Supreme Court considers scope of federal anti-hacking law in biggest cyber case to date

Several U.S. Supreme Court justices, including some of President Donald Trump’s appointees, skeptically questioned a broad interpretation of the main federal anti-hacking law during oral arguments Monday. The hearing represented one of the final steps in the biggest case to come before the nation’s highest court involving the Computer Fraud and Abuse Act (CFAA), written in the 1980s. The case centers on when an individual “exceeds authorized access” to a computer, as defined by that law. The law has long held a contentious place in the cybersecurity world, where it’s viewed as hopelessly vague, outdated and overly punitive. One CFAA prosecution that drew particular criticism was that of Aaron Swartz, an internet activist who took his own life before he was scheduled to stand trial for allegedly downloading articles from an academic database, in a case where he faced decades in prison if convicted. The case now before the Supreme Court involves defendant Nathan […]

The post Supreme Court considers scope of federal anti-hacking law in biggest cyber case to date appeared first on CyberScoop.

Continue reading Supreme Court considers scope of federal anti-hacking law in biggest cyber case to date

Last-minute court rulings on election go against GOP, voting restrictions

A federal judge on Monday rejected a Texas GOP bid to throw out approximately 127,000 ballots in largely Democratic Harris County, saying the Republicans failed to demonstrate that they were harmed by the votes cast at extra drive-through locations. It was one of two major election cases to see action on Monday. In both cases, courts sided against conservative challenges over voting in Democrat-friendly jurisdictions. But it might only foreshadow more legal challenges ahead, after the election. In Texas, GOP activist Steven Hotze brought the case alongside Harris County Republicans state Rep. Steve Toth, congressional candidate Wendell Champion and judicial candidate Sharon Hemphill. They contended the extra 10 drive-through stations violated state election law, in an argument that centered on the definition of curbside voting. The clerk for Harris County, Houston’s home, rebutted the conservatives’ argument on several fronts. but the issue of whether they had standing to sue apparently caught the attention of U.S. District Judge Hanen. […]

The post Last-minute court rulings on election go against GOP, voting restrictions appeared first on CyberScoop.

Continue reading Last-minute court rulings on election go against GOP, voting restrictions

$100 million botnet scheme earns Russian man 8 years in prison

A U.S. judge sentenced a Russian national to eight years in prison over his role in stealing personal and financial information via a botnet conspiracy that aimed to generate an estimated $100 million. Prosecutors announced the sentence Monday for Aleksandr Brovko, who pleaded guilty in February to conspiracy to commit bank and wire fraud. From 2007 to 2019, according to the Department of Justice, Brovko collaborated with other cybercriminals to turn data troves harvested by botnets — networks of infected computers — into cash. Brovko’s role was to write software scripts to go through botnet logs and conduct data searches to extract highly sensitive personal information and online banking credentials, as well as scout out the value of compromised accounts to determine whether they’d be worth using to conduct fraud. In all, prosecutors said, Brovko possessed and trafficked more than 200,000 “unauthorized access devices,” a term for credit cards, mobile identification […]

The post $100 million botnet scheme earns Russian man 8 years in prison appeared first on CyberScoop.

Continue reading $100 million botnet scheme earns Russian man 8 years in prison

TikTok unveils bug bounty program, scraps with US government in court over looming ban

TikTok announced a global bug bounty program Thursday amid an ongoing court battle to continue operating in the U.S. The program, a partnership with HackerOne, is an expansion of a more limited vulnerability disclosure program for the popular video-sharing app. “This partnership will help us to gain insight from the world’s top security researchers, academic scholars and independent experts to better uncover potential threats and make our security defenses even stronger,” TikTok wrote in a blog post. Researchers who uncover vulnerabilities can make between $50 and $14,800, depending on the severity of the flaw. TikTok has previously worked with security research companies to fix flaws they found. A range of high profile companies have relied on bug bounty programs to solicit reports about vulnerabilities for which internal security personnel failed to account. Often, success depends on the firms’ ability to fix those flaws, and reward outside researchers in a way that doesn’t […]

The post TikTok unveils bug bounty program, scraps with US government in court over looming ban appeared first on CyberScoop.

Continue reading TikTok unveils bug bounty program, scraps with US government in court over looming ban

As voters cast their ballots, courts nationwide issue election security edicts

Legal battles with election security implications raged across the country over the holiday weekend, even with early voting well underway at historic levels in many states. In no state did those two things coincide more than in Georgia. Peach State voters amassed in lines marked by reports of 10-hour waits on Tuesday, following two key court rulings. Northern District of Georgia Judge Amy Totenberg on Sunday denied a bid to scuttle touch screen voting machines over cybersecurity vulnerabilities. On Monday, she also denied a request to require a specific number of emergency ballots to be on hand at Georgia polling sites. The ruling Sunday represented a setback for election integrity advocates who contend that Georgia’s machines have not been secure enough, and still aren’t. Totenberg ruled last year that Georgia must phase out its existing paperless voting machines, citing doubts about cybersecurity safeguards for direct-recording election equipment tabulations that couldn’t be audited without a paper record. […]

The post As voters cast their ballots, courts nationwide issue election security edicts appeared first on CyberScoop.

Continue reading As voters cast their ballots, courts nationwide issue election security edicts

SEC settles with trader accused of illegal trades using hacked data

The U.S. Securities and Exchange Commission agreed to settle charges with one of the traders who relied on hacked data from an SEC company filing system to collectively make millions of dollars, the agency said in a federal court filing on Wednesday. The SEC settlement includes both Sungjin Cho, the trader, and Kyungja Cho, his mother. Sungjin Cho made 66 illegal trades under his own name relying on the hacked information, and placed or directed four more under accounts in his mother’s name, according to the original complaint. Last year, the SEC and Justice Department filed charges against alleged hackers and the group of traders whom they said benefited from the scheme dating back to 2016 to steal secrets from EDGAR. EDGAR is a filing system for public companies that sometimes contains information that has not yet been made public. The scheme netted at least $4.1 million for the traders, according to the SEC. Among the […]

The post SEC settles with trader accused of illegal trades using hacked data appeared first on CyberScoop.

Continue reading SEC settles with trader accused of illegal trades using hacked data

John McAfee arrested in Spain, charged with tax evasion

The Justice Department unsealed an indictment Monday against cybersecurity pioneer John McAfee following his arrest in Spain. McAfee stands accused of evading taxes, in part by using cryptocurrency. McAfee founded the antivirus firm that bears his name, but has spent at least a decade in frequent brushes with the law, and not just in the United States. The indictment, dated from June, does not allege that McAfee received any money from, or otherwise had any connection to his former company during the period he allegedly failed to pay taxes, from 2014 to 2018. McAfee left the security firm more than 20 years ago. The indictment states that his millions of dollars in income during the four-year stretch came from promotion of cryptocurrencies, consulting work, speaking engagements and the rights to his story for a documentary. McAfee, the indictment alleges, routed his income into cryptocurrency exchange accounts and bank accounts of others, and sought to conceal assets, including […]

The post John McAfee arrested in Spain, charged with tax evasion appeared first on CyberScoop.

Continue reading John McAfee arrested in Spain, charged with tax evasion