Trump’s national security adviser warns Canadians against Huawei 5G tech

A top White House official warned Canadians this weekend against allowing China-based Huawei to help in building out Canada’s next generation 5G telecommunications networks. “The technology allows China to put together profiles of the most intimate details, intimate personal details, of every single man, woman and child in China,” President Donald Trump’s national security adviser, Robert O’Brien, said at the Halifax International Security Forum, according to CBC News. “When they get Huawei into Canada or other Western countries, they’re going to know every health record, every banking record, every social media post; they’re going to know everything about every single Canadian,” O’Brien said. Given that China has a law that would require Chinese companies to yield to Chinese intelligence agencies’ requests, the Trump administration and lawmakers are concerned that Beijing could use Huawei and other Chinese-based companies for spying. O’Brien threatened that Canadian-U.S. intelligence-sharing could be affected if Canada goes through […]

The post Trump’s national security adviser warns Canadians against Huawei 5G tech appeared first on CyberScoop.

Continue reading Trump’s national security adviser warns Canadians against Huawei 5G tech

Mozilla ups bug bounty rewards to $15,000 on critical sites

Bug bounty researchers probing for vulnerabilities in Mozilla software now will be tempted with more cash after the browser-maker doubled most of its rewards and expanded the list of targets. In a blog post Tuesday, Mozilla said it’s marking the 15-year anniversary of its Firefox browser by dedicating a higher budget to its bounty program. Rewards for critical, core and other Mozilla sites are doubled, while remote code-execution vulnerabilities now are worth up to $15,000 on critical sites. Meanwhile, Mozilla also is asking researchers to try hacking its Autograph cryptography service, its Lando code repository tool, the Phabricator, which reviews code changes in Firefox, and Taskcluster, the framework for continuous integration, among others. “We hope the new sites and increased payments will encourage [researchers] to have another look at our sites and help us keep them safe for everyone who uses the web,” Simon Bennetts, a security automation engineer, said […]

The post Mozilla ups bug bounty rewards to $15,000 on critical sites appeared first on CyberScoop.

Continue reading Mozilla ups bug bounty rewards to $15,000 on critical sites

Citing security concerns, senators call on White House to appoint coordinator for 5G issues

A bipartisan group of senators wants the Trump administration to appoint a top official to coordinate policy for issues related to 5G communications, saying the current marketplace for the technology poses an “unprecedented security challenge” to the U.S. and its allies. “China’s leadership [in 5G], combined with the United States’ increased reliance on high-speed, reliable telecommunications services to facilitate both commerce and defense, poses a strategic risk for the country,” the senators wrote Tuesday to White House national security adviser Robert O’Brien, advising him to tap a senior official to coordinate 5G policy across federal agencies. The chairman and ranking member of Senate committees dealing with intelligence, foreign relations, defense and homeland security all signed the letter. U.S. officials have long fretted that Chinese telecommunications companies like Huawei are in prime position to shape 5G deployments around the world. Those networks, which promise must faster connectivity, would be ripe for Chinese […]

The post Citing security concerns, senators call on White House to appoint coordinator for 5G issues appeared first on CyberScoop.

Continue reading Citing security concerns, senators call on White House to appoint coordinator for 5G issues

Aventura Charged With Selling Chinese-Made Security Equipment

Aventura Technologies and seven of its executives have been charged with illegally importing Chinese-made security and surveillance equipment and claiming it to be made in the United States. The company, based in Commack, New York, claimed its securit… Continue reading Aventura Charged With Selling Chinese-Made Security Equipment

New York company charged with selling vulnerable Chinese-made equipment to U.S. military

U.S. prosecutors on Thursday announced charges against a New York company and seven of its current and former employees for allegedly selling Chinese-made surveillance equipment with known cybersecurity flaws while falsely claiming the technology was made in the U.S. Aventura Technologies, which makes security equipment like metal detectors and surveillance cameras, is accused of lying to customers, including the U.S. military, for over a decade by claiming to make their equipment in Long Island while surreptitiously importing it from China. In doing so, Aventura exposed its customers to “serious, known cybersecurity risks, and created a channel by which hostile foreign governments could have accessed some of the government’s most sensitive facilities,” the Justice Department said in a press release. The U.S. Air Force, Navy, and the Department of Energy were among Aventura’s clients. Jack Cabasso, the company’s de facto owner, his wife, Frances, and other senior company executives were charged with […]

The post New York company charged with selling vulnerable Chinese-made equipment to U.S. military appeared first on CyberScoop.

Continue reading New York company charged with selling vulnerable Chinese-made equipment to U.S. military

FCC chair pitches rules to block Huawei, ZTE

Federal Communications Commission Chairman Ajit Pai revealed a proposal Monday that would bar U.S. communications companies from using federal subsidies to buy Huawei and ZTE equipment and services. It’s the latest push from the Trump administration to block Chinese-owned telecommunications equipment and services from being used in the U.S. due to national security concerns. Pai’s proposal would prevent communications companies from using the FCC’s $8.5 billion service fund, known as the Universal Service Fund, from buying equipment that poses a “national security threat” to the U.S. Pai specifically cites Huawei and ZTE. “We need to make sure our networks won’t harm our national security, threaten our economic security, or undermine our values. The Chinese government has shown repeatedly that it is willing to go to extraordinary lengths to do just that,” Pai said in a statement. “As the United States upgrades its networks to the next generation of wireless technologies — […]

The post FCC chair pitches rules to block Huawei, ZTE appeared first on CyberScoop.

Continue reading FCC chair pitches rules to block Huawei, ZTE

Researcher releases PoC rooting app that exploits recent Android zero-day

Late last month Google Project Zero researcher Maddie Stone detailed a zero-day Android privilege escalation vulnerability (CVE-2019-2215) and revealed that it is actively being exploited in attacks in the wild. She also provided PoC code that could he… Continue reading Researcher releases PoC rooting app that exploits recent Android zero-day