Posts

Showing posts with the label Cybersecurity

Massive SMS stealer campaign infects Android devices in 113 countries

Image
By Bill Toulas,  Bleeping Computer A malicious campaign targeting Android devices worldwide utilizes thousands of Telegram bots to infect devices with SMS-stealing malware and steal one-time 2FA passwords (OTPs) for over 600 services. Zimperium researchers discovered the operation and have been tracking it since February 2022. They report finding at least 107,000 distinct malware samples associated with the campaign. The cybercriminals are motivated by financial gain, most likely using infected devices as authentication and anonymization relays. Telegram entrapment The SMS stealer is distributed either through malvertising or Telegram bots that automate communications with the victim. In the first case, victims are led to pages mimicking Google Play, reporting inflated download counts to add legitimacy and create a false sense of trust. On Telegram, the bots promise to give the user a pirated application for the Android platform, asking for their phone number before they share the ...

HealthEquity says data breach impacts 4.3 million people

Image
By Bill Toulas,  Bleeping Computer HSA provider HealthEquity has determined that a cybersecurity incident disclosed earlier this month has compromised the information of 4,300,000 people. HealthEquity, one of the largest HSA custodians in the U.S., specializes in providing health savings accounts (HSAs), flexible spending accounts (FSAs), health reimbursement arrangements (HRAs), and 401(k) retirement plans. In a Form 8-K filing submitted on July 2, 2024, the company disclosed that threat actors stole members' sensitive health data using a partner's compromised credentials. An investigation determined that the breach occurred on March 9, 2024, but was only verified by the firm on June 26, following an internal investigation. "We discovered some unauthorized access to and potential disclosure of protected health information and/or personally identifiable information stored in an unstructured data repository outside our core systems," reads the data breach notice to be...

Crooks Steal Phone, SMS Records for Nearly All AT&T Customers

Image
By  KrebsOnSecurity AT&T Corp . disclosed today that a new data breach has exposed phone call and text message records for roughly 110 million people — nearly all of its customers. AT&T said it delayed disclosing the incident in response to “national security and public safety concerns,” noting that some of the records included data that could be used to determine where a call was made or text message sent. AT&T also acknowledged the customer records were exposed in a cloud database that was protected only by a username and password (no multi-factor authentication needed). In a regulatory filing with the U.S. Securities and Exchange Commission today, AT&T said cyber intruders accessed an AT&T workspace on a third-party cloud platform in April, downloading files containing customer call and text interactions between May 1 and October 31, 2022, as well as on January 2, 2023. The company said the stolen data includes records of calls and texts for mobile providers...

British Columbia investigating cyberattacks on government networks

Image
By Sergiu Gatlan, Bleeping Computer The Government of British Columbia is investigating multiple "cybersecurity incidents" that have impacted the Canadian province's government networks. Premier David Eby said in a Wednesday statement that there is no evidence that the attackers had accessed or stolen sensitive information from the compromised networks. However, an ongoing investigation is assessing the incidents' impact and looking into what data, if any, may have been accessed. "Recently, the Government of B.C. has identified sophisticated cybersecurity incidents involving government networks," Eby said. "The government is working closely with the Canadian Centre for Cyber Security (Cyber Centre) and other agencies to determine the extent of the incidents and implement additional measures to safeguard data and information systems." The Government of B.C. has yet to disclose the number of cybersecurity incidents that impacted its networks and when...

Why Your VPN May Not Be As Secure As It Claims

Image
By Krebs On Security Virtual private networking (VPN) companies market their services as a way to prevent anyone from snooping on your Internet usage. But new research suggests this is a dangerous assumption when connecting to a VPN via an untrusted network, because attackers on the same network could force a target’s traffic off of the protection provided by their VPN without triggering any alerts to the user. When a device initially tries to connect to a network, it broadcasts a message to the entire local network stating that it is requesting an Internet address. Normally, the only system on the network that notices this request and replies is the router responsible for managing the network to which the user is trying to connect. The machine on a network responsible for fielding these requests is called a Dynamic Host Configuration Protocol (DHCP) server, which will issue time-based leases for IP addresses. The DHCP server also takes care of setting a specific local address — known ...

Cybersecurity consultant arrested after allegedly extorting IT firm

By Bill Toulas, Bleeping Computer A former cybersecurity consultant was arrested for allegedly attempting to extort a publicly traded IT company by threatening to disclose confidential and proprietary data unless they paid him $1,500,000. A staffing company assigned Vincent Cannady, 57, to assess and remediate potential vulnerabilities in a New York-based multinational information technology infrastructure services provider. After the termination of his employment for performance reasons, on June 23, 2023, Cannady allegedly used a company-issued laptop to download proprietary and confidential information, including architectural maps, trade secrets, and lists of potential vulnerabilities, from the victim company's network, to which he still had access. The Department of Justice says Cannady threatened to publicly disclose this sensitive information unless the company agreed to pay him up to $1.5 million as a settlement for what he claimed was employment discrimination. When confron...

Bogus npm Packages Used to Trick Software Developers into Installing Malware

Image
An ongoing social engineering campaign is targeting software developers with bogus npm packages under the guise of a job interview to trick them into downloading a Python backdoor. NPM is a package manager for the JavaScript programming language maintained by Microsoft's npm, Inc. npm is the default package manager for the JavaScript runtime environment Node.js and is included as a recommended feature in the Node.js installer. Wikipedia Cybersecurity firm Securonix is tracking the activity under the name DEV#POPPER, linking it to North Korean threat actors. "During these fraudulent interviews, the developers are often asked to perform tasks that involve downloading and running software from sources that appear legitimate, such as GitHub," security researchers Den Iuzvyk, Tim Peck, and Oleg Kolesnikov said . "The software contained a malicious Node JS payload that, once executed, compromised the developer's system." Details of the campaign first emerged in l...

United Nations agency investigates ransomware attack, data theft

Image
By Sergiu Gatlan,  Bleeping Computer ​The United Nations Development Programme (UNDP) is investigating a cyberattack after threat actors breached its IT systems to steal human resources data. UNDP, the UN's global development network, works in over 170 countries and territories and relies on donations from UN member states and private sector/multilateral organizations to help eradicate poverty and fight inequality and exclusion. In a statement published Tuesday, the organization revealed that the attackers hacked into local IT infrastructure in UN City, Copenhagen, in late March. "On March 27, UNDP received a threat intelligence notification that a data-extortion actor had stolen data which included certain human resources and procurement information," the UN agency disclosed. "Actions were immediately taken to identify a potential source and contain the affected server as well as to determine the specifics of the exposed data and who was impacted." UNDP is now ...

The Biggest Takeaways from Recent Malware Attacks

Image
Among the never-ending list of malicious software that threat actors use in cyber attacks are viruses, worms, trojans, ransomware, spyware, and adware. Today's malware is not just about causing immediate damage; some programs get embedded within systems to siphon off data over time, disrupt operations strategically, or lay the groundwork for massive, coordinated attacks.  A prime example is a recently found malicious backdoor in a popular compression tool, known as xz Utils. Thankfully the malicious code was identified early “due to bad actor sloppiness”, but the consequences could’ve been massive. Read on to get the lowdown on recent high-profile malware attacks along with strategies to help limit malware risks at your organization.  Recent High-Profile Malware Attacks Here's a detailed overview of recent malware attacks, highlighting key incidents and offering valuable insights and lessons learned from each event. StripedFly A prolific and advanced cross-platform malware fra...

UnitedHealth brings some Change Healthcare pharmacy services back online

Image
By Bill Toulas, Bleeping Computer Optum's Change Healthcare has started to bring systems back online after suffering a crippling BlackCat ransomware attack last month that led to widespread disruption to the US healthcare system. United Health Group (UHG) is the largest American health insurance company, and its subsidiary, Optum Solutions, operates the Change Healthcare platform. Change Healthcare operates the largest payment exchange platform between doctors, pharmacies, healthcare providers, and patients in the US. On February 21, 2024, Optum Solutions suffered a ransomware attack by ALPHV/BlackCat, causing extensive outages after servers were allegedly encrypted and the company shut down its IT systems. These outages led to wide disruption at pharmacies and doctor offices, which could not send claims, causing some patients to pay full price for their medications. Today, UHG released a statement that finally delivered some good news, announcing the electronic prescription syst...

FBI: U.S. lost record $12.5 billion to online crime in 2023

Image
By Bill Toulas, Bleeping Computer FBI's Internet Crime Complaint Center (IC3) has released its 2023 Internet Crime Report, which recorded a 22% increase in reported losses compared to 2022, amounting to a record of $12.5 billion. The number of relevant complaints submitted to the FBI in 2023 reached 880,000, 10% higher than the previous year, with the age group topping the report being people over 60, which shows how vulnerable older adults are to cybercrime. Both figures continue a worrying trend seen by the agency since 2019, where complaints and losses rise yearly. For 2023, the types of crimes that increased were tech support scams and extortion, whereas phishing, personal data breach, and non-payment/non-delivery scams slightly waned.

An Entire Canadian Town Is Being Extorted By Ransomware Cyber Criminals

Image
by Lane Babuder,  Hot Hardware Ransomware attacks have been on the rise. This time around, the small Ontario, Canada town of St. Marys has been targeted. The ransomware organization behind the attack seems to be LockBit. So far though, no ransom has been paid. The town itself claims that most city functions are still operational and staff are still working and getting paid. Upon visiting the official web site of the town visitors are greeted with a large red box containing the following quote. "The Town of St. Marys is currently investigating a cyber security incident that locked our internal server and encrypted our data. We are working closely with cyber security experts to investigate the source of the incident, restore our back up data, and assess impacts on our information, if any." "We have a skilled and knowledgeable team of Town staff, cyber security experts and legal counsel working around the clock to resolve any issues related to this incident. I have full con...

Senators take aim at future quantum-enabled hacking with new bill

By Patrick Tucker,  American Military News Experts believe quantum computing may render some of the core cybersecurity algorithms at the heart of many modern-day digital experiences—from accessing money via an ATM to sending secure messages—obsolete. A new bipartisan bill pushes the U.S. government to prepare more quickly for that eventuality. The problem is a complex one, literally. The public key encryption standards for everything from bank transactions to secure communications are based on the mathematical principle of factorization. A classical computer would take around 300 trillion years to crack them. But a quantum computer, able to process bits composed of values far more diverse than “1” or “0,” could crack the same encryption standard in seconds. While no quantum computer yet exists that can perform such a trick, the rapidly growing field suggests it’s possible within the decade. And that won’t stop adversaries from attempting to steal encrypted data now for later decodi...

China fines Didi more than $1 billion for breaking data security laws

By Evelyn Cheng,  CNBC China’s cybersecurity authority fined ride-hailing giant Didi Global on Thursday in apparent closure of a yearlong probe that prevented the company from adding new users. The Cyberspace Administration of China said it fined Didi 8.026 billion yuan ($1.19 billion) after deciding the company violated China’s network security law, data security law and personal information protection law. The administration also fined two Didi executives 1 million yuan each. Didi said in an online statement it accepted the cybersecurity regulators decision. Didi did not immediately respond to a CNBC request for comment. The cybersecurity authority’s announcement did not say whether the fine meant that Didi would soon be able to add new users or restore its presence on app stores in China. The investigation was first announced last year, just days after Didi’s initial public offering on the New York Stock Exchange. Didi had come under fire after it reportedly pushed ahead wi...

Thwarting attacks from the charging socket: Team explores protecting mobile device touchscreens from 'ghost touch'

By Silke Paradowski,  TechXplore Touch screens on mobile devices can be attacked and manipulated via charging cables and power supply units. This is what researchers at the System Security Lab at TU Darmstadt have discovered together with a Chinese research team. Several smartphones and standalone touchscreen panels could be compromised in practical tests by simulated touches, the "ghost touches." The results were presented at this year's IEEE Symposium on Security and Privacy. The researchers from TU Darmstadt and Zhejiang University in Hangzhou carried out attacks on capacitive touchscreens via charging cables and power adapters, revealing a new way to attack mobile devices. Similar to their previous research project, "GhostTouch," the researchers were able to create false touches, called "Ghost Touches," on multiple touchscreens and manipulate the device via them. The international research team had to overcome two main challenges. The first was to ...

MIT bets on deep learning to fight cybercrime

By Jurgita LapienytÄ—,  Cyber News Despite best efforts and innovation, cybercrime is on the rise. MIT scientists and leading network defenders urge to explore deep learning to secure systems. In the first quarter of 2022 alone, there were 404 publicly reported data breaches in the US. Ransomware breaches increased by 13% in a single year. “No wonder an increasing number of organizations are beginning to explore how deep learning, and its ability to mimic the human brain, can outsmart and outpace the world’s fastest and most dangerous cyber threats,” MIT Technology Review said in its research paper produced together with cybersecurity company Deep Instinct. MIT is looking at deep learning-driven malware prevention, hoping it could boost organizations in an innovation race against ransomware groups, enhancing their evasive capabilities, using sandbox detection or even adversarial artificial intelligence (AI.) Deep learning is the most advanced form of AI technology that uses neural n...

Hackers steal 50,000 credit cards from 300 U.S. restaurants

By Bill Toulas,  Bleeping Computer Payment card details from customers of more than 300 restaurants have been stolen in two web-skimming campaigns targeting three online ordering platforms. Web-skimmers, or Magecart malware, are typically JavaScript code that collects credit card data when online shoppers type it on the checkout page. Recently, Recorded Future’s threat detection tools identified two Magecart campaigns injecting malicious code into the online ordering portals of MenuDrive, Harbortouch, and InTouchPOS. As a result, 50,000 payment cards were stolen and have already been offered for sale on various marketplaces on the dark web.

EU warns of Russian cyberattack spillover, escalation risks

By Sergiu Gatlan,  Bleeping Computer The Council of the European Union (EU) said today that Russian hackers and hacker groups increasingly attacking "essential" organizations worldwide could lead to spillover risks and potential escalation. "This increase in malicious cyber activities, in the context of the war against Ukraine, creates unacceptable risks of spillover effects, misinterpretation and possible escalation," the High Representative on behalf of the EU said Tuesday. "The latest distributed denial-of-service (DDoS) attacks against several EU Member States and partners claimed by pro-Russian hacker groups are yet another example of the heightened and tense cyber threat landscape that EU and its Member States have observed." In this context, the EU reminded Russia that all United Nations member states must adhere to the UN's Framework of responsible state behavior in cyberspace to ensure international security and peace. The EU urged all states ...

Mass malware infection detected on Digium phones

By Damien Black,  Cyber News More than half a million instances of malware have been observed on software used by the popular landline brand Digium in the first three months of the year. Unit 42, the cyber-detective wing of infosecurity firm Palo Alto, said it had “witnessed more than 500,000 unique malware samples” over a three-month period to the end of March targeting the Elastix and Asterisk operating systems that Digium phones depend upon. Though ostensibly conventional wired handsets, the phones benefit from special features including voicemail, call logging and queuing, and phone status display, which require them to be connected to the internet of things. Unfortunately for businesses like call centers that rely on such features, they appear to have put the phones on the radar of cybercriminals. “The attacker implants a web shell to exfiltrate data by downloading and executing additional payloads inside the target's Digium phone software,” said Unit 42. “The malware installs...

‘Hackers Love It' When You Make These 6 Biggest Password Mistakes, Says Security Expert

By John Shier, CNBC Increased cyberattacks in 2022 have created a high-risk internet landscape. But for many people, hitting "refresh" on their password habits still isn't a priority. As a cybersecurity advisor, I consistently hear stories about people getting their personal information stolen because they made a simple mistake like using the same password for multiple website logins. After 20 years of studying online criminal behaviors, tactics, techniques and procedures, I've found that hackers love it when people make these six password mistakes: 1. Reusing the same password. More than two-thirds of Americans do this, but it only allows data breaches to remain dangerous for years after they happen. To avoid creating a brand new password for every account, people also tend to reuse passwords with slight variations, like an extra number or symbol. But these are also easy for hackers to guess, and they're no match for software designed to quickly test iterations o...