Instagram is working on bringing long-length videos & 4K contents

It was reported yesterday that Instagram is working on bringing long-length videos and now according to close sources to Techcrunch, the company will offer a dedicated space featuring scripted shows, music videos and more in vertically oriented, full-screen, high-def 4K resolution.

It is also reported that Instagram is meeting with popular social media stars and content publishers to learn more about how their video channels would work elsewhere. Surprisingly, Instagram is also lining up partners to announce the long-form video effort tentatively scheduled for June 20th. Users can expect a kind of videos you see from YouTube creators which often range from 5 to 15 minutes.

Furthermore, Instagram will also eventually creators and publishers monetize longer videos, though it hasn’t finalized how accompanying ads like pre-rolls and mid-breaks or revenue splits would work. The longer videos will have swipe-up to open a link which will give creators an advantage to drive traffic to their websites, e-commerce stores or event ticketing.

As for Instagram long-term videos, the section will spotlight a collection of popular videos, and provide a “continue watching.” Users will also see the long-form clips featured on authors’ profiles near the Stories Highlights bubbles. However, Instagram will not allow to shoot and post long-form videos, as the section will only allow pre-made video uploads. There is no time frame as to when this feature would roll out or what it would be named.

Source: Techrunch 


VPNFILTER MALWARE IMPACT LARGER THAN PREVIOUSLY THOUGHT

Researchers say the impact of the VPNFilter malware discovered last month is larger than originally reported.

On Wednesday, Cisco Talos researchers said they now believe the malware has infected twice the number of router brands than previously stated. They added that Vpnfilter also delivers a more potent punch than they originally thought, and have identified a previously unidentified malicious malware module.

On May 23, Talos researchers first reported that Russian-speaking threat actors, with links to the BlackEnergy APT group, were behind the VPNFilter malware that infected 500,000 router brands (ranging from Linksys, MikroTik, NETGEAR and TP-Link as well as small office network attached storage (NAS) devices).

At the time, known malicious capabilities of VPNFilter included bricking the host device, executing shell commands for further manipulation, creating a ToR configuration for anonymous access to the device, or maliciously configuring the router’s proxy port and proxy URL to manipulate browsing sessions.

In updated research, Cisco Talos said the range of targeted routers now includes those made by manufacturers ASUS, D-Link, Huawei, Ubiquiti, UPVEL and ZTE, bringing the total number of router models targeted by VPNFilter adversaries to 75.

“These new discoveries have shown us that the threat from VPNFilter continues to grow,” Talos wrote in a technical breakdown of the malware on Wednesday.

A closer examination of VPNFilter also demonstrates that the malware has the capability to infect more than the targeted routers and NAS devices — and can traverse into the networks that those devices support.

“If successful, the actor would be able to deploy any desired additional capability into the environment to support their goals, including rootkits, exfiltration capability and destructive malware,” researchers wrote.

To boot, Talos said that it has found a new stage-three module capable of injecting malicious content into web traffic as it passes through targeted network devices. Researchers identified the module as “ssler,” or an “endpoint exploitation module — JavaScript injection.”

“At the time of our initial posting, we did not have all of the information regarding the suspected stage-three modules. The new module allows the actor to deliver exploits to endpoints via a man-in-the-middle capability (e.g. they can intercept network traffic and inject malicious code into it without the user’s knowledge),” researchers wrote.

An additional “dstr” (device destruction module) component to the malware was also identified, which is “used to render an infected device inoperable by deleting files necessary for normal operation,” researchers wrote. “It deletes all files and folders related to its own operation first before deleting the rest of the files on the system, possibly in an attempt to hide its presence during a forensic analysis.”

Lastly, researchers discussed new insights into a stage-three packet-sniffer module that they said was targeting industrial control system traffic. The sniffer specifically singled out the SafeStream Gigabit Broadband VPN router TP-LINK R600VPN.

“VPNFilter is still in full force, in the wild, infecting a broader set of devices than known previously, which makes it quite concerning still,” wrote Derek Manky, global security strategist with Fortinet FortiGuard Labs, in an email. “This is a good example of how even exposed campaigns can continue to move with velocity.”

Source:  Threatpost 


DNA TESTING SERVICE MYHERITAGE LEAKS USER DATA OF 92 MILLION CUSTOMERS

Account data tied to 92 million users of the genealogy and DNA testing service MyHeritage were found on a third-party “private” server in a breach that exposed usernames and passwords of customers.

The breach is the largest since last year’s Equifax leak of 147.9 million pieces of private data ranging from Social Security numbers, birth dates, addresses and some driver’s license numbers.

Users who signed up for the service before October 26, 2017 are impacted, according to a MyHeritage statement released on Monday regarding the incident.

“Today, June 4, 2018 at approximately 1 p.m. EST, MyHeritage’s chief information security officer received a message from a security researcher that he had found a file named myheritage containing email addresses and hashed passwords, on a private server outside of MyHeritage,” the statement reads.

The company did not elaborate on the ownership or origin of the server. It did however confirm that the data originated from MyHeritage and included email addresses and hashed passwords of 92,283,889 users. No other data, such as user financial information, DNA and genealogy specifics, was found on the server hosting the data.

“We have no reason to believe that any other MyHeritage systems were compromised… Other types of sensitive data such as family trees and DNA data are stored by MyHeritage on segregated systems, separate from those that store the email addresses, and they include added layers of security. We have no reason to believe those systems have been compromised,” the firm said.

The Israeli-based MyHeritage said the hash key differs for each customer password, suggesting they were salted and hashed, making it harder for cybercriminals to decode the 92 million individual coded passwords.

The company noted it was complying with recently enacted General Data Protection Regulation (GDPR) rules form the European Union, given its multinational customer base. “We are taking steps to inform relevant authorities including as per GDPR,” the company said. Under GDPR rules, passed May 25, companies with customers inside the EU have 72 hours to report a breach after becoming aware of the incident.

The genealogy and DNA testing service company said it would be implementing two-factor authentication features for user accounts as well.

DNA databases have come under closer scrutiny as more online companies commoditize the service, offering genetic sequencing at low prices and warehouse the data. Privacy activist warn while DNA databases can be a boon when it comes to tracking down and arresting people such as Joseph James DeAngelo, the alleged “Golden State Killer,” DNA samples can also be leaked and abused by criminals or by over-reaching law enforcement officials.

Source:  Threatpost 


Machine Learning Doesn't Mean AI or End of Humans

The introduction of AI and machine learning should not mean a decision of man or machine, but one of man and machine bringing combined skills together.

Speaking at Infosecurity Europe 2018, Christopher Morales, head of security analytics at Vectra Networks, looked at 'Building Security That Works, Machine Learning Fundamentals for Cybersecurity Professionals' admitted that there is confusion around what AI, machine learning and deep learning are.

“AI is the output of what you’re trying to do, and do things that is a repetitive task,” he said. “Machine learning is the method and the means to AI, but it is not AI itself.”

Morales went on to say that deep learning is part of machine learning, and there are two types: supervised or unsupervised. Supervised means it is task driven, “you give it input and have X data and you get Y output.” With unsupervised, he explained that you “have the X but no Y, a set of data and no outputs.”

Explaining unsupervised machine learning, Morales said that as conference delegates “we’ve been clustered by a vendor."

He went to address algorithms, saying that if you have a single algorithm and you’re using it to do a job, that is not really AI, that is about using the right tool for the job. “Look at the task and who administrates the system, and if you want to find a remote access trojan, that is a good use of supervised learning as you are being specific on what you are looking for and how to apply it,” he said.

Moving on to how this can help with security, Morales said that pattern matching has been done for years, and users have focused on understanding what malware is, and with machine learning you can focus on what it does rather than what it is – and match it to that decision.

“Focus on behavior and how it relates to an attack, and focus on what to do and what it is doing to you now.”

He went on to encourage users to train systems on a subset of tools and what it looks like when an attacker wants to get on your network, and apply it to the network so it looks for any tool doing the same behavior.

“Unsupervised learning is good at learning local context and what people do, and in this case security research on what an attacker actually does,” he said.

He concluded by saying that the real value of AI is in replicating human tasks, but what you get out is to reduce the workload of the human. “We need to realize that machines are not going to replace humans, and in most instances they increase the human‘s work,” he said.

“But in security machines and humans are inherently different: machines are good at memorizing data and repetitive tasks and do it fast in multiple tasks, and humans are good at being creative and looking at context. It is not man or machine, but a combination of machines doing tedious work so humans can focus on creative work.”

Source: Dan Raywood  infosecurity 


How to Design Security Awareness Programs & Drive Smart Security Behavior






At Infosecurity Europe 2018, Dr Jessica Barker, co-founder of Redacted Firm, discussed practical ways to build security awareness programs that can drive better user behaviors.

The first step is assessing “what your organization looks like on paper, and knowing about your organization in terms of the sector, the size, the geography – what are the most important information assets, which are the biggest threats and what would be the most damaging thing that could happen to the organization.”

Once you have that understanding of the baseline characteristics of the organization on paper, you can move onto “understanding them in real life,” Dr Barker said, and the key thing that must be done here is speaking to people within the organization “to find out what is actually happening, because as we know, what is happening day-to-day among the employees of an organization will be a very different picture to what you see on paper.”

Dr Barker added that a good level of security awareness does not always equate to good security understanding and changes in behavior, “so when we talk about awareness we need to think about what the outcome is that we want – we don’t want people to be aware just for the sake of it, we want to see changed behaviors.”

Her advice for doing that is to “work backwards” to create a culture in which people are engaged through experiences of what good security behavior is, and making “cybersecurity personal is one of the best ways to get through to people.

“If you really want to change behaviors,” she concluded, “you need to think about intrinsic motivation and what you can do that is really going to tap into their [users’] internal rewards system.”

Source:  infosecurity 


Malware Targets Users of Online Banking Service

After noticing a browser extension communicating with a suspicious domain, researchers analyzed the Google Chrome extension named Desbloquear Conteudo (unblock content) and found that it was a rare banker malware.

The extension, identified as HEUR:Trojan-Banker.Script.Generic has been removed from Chrome Web Store. According to Vyacheslav Bogdanov, researcher, Kaspersky Lab the man-in-the-middle (MitM) extension for Chrome was targeting users of Brazilian online banking services with the goal of collecting user logins and passwords in order to pilfer their savings.

MitM attacks redirect the victim’s web traffic to a spoof website. While the target is under the impression they are connected to a legitimate site, the flow of traffic to and from the real bank site is actually being redirected through an attacker's site so that the criminal can harvest the personal data they are after.

What's interesting about this particular extension is that the developers made no effort to obfuscate its source code. Instead, they opted for a MitM attack using "the WebSocket protocol for data communication, making it possible to exchange messages with the C&C [command-and-control] server in real time. This means the C&C starts acting as a proxy server to which the extension redirects traffic when the victim visits the site of a Brazilian bank."

This particular extension used the Proxy Auto Configuration technology, which enabled additional functions beyond the one written in JavaScript for most modern browsers. The FindProxyForUrl function was replaced with a new task that redirected traffic from the Brazilian bank to the malicious server. Attackers added malicious code to the webpage using cef.js script in order to intercept the user’s one-time password.

Because the malware was targeting Brazilian users, Bogdanov suggested that the browser extension had the additional function of adding cryptocurrency mining scripts to the banking sites users visited.

“Browser extensions aimed at stealing logins and passwords are quite rare in comparison to adware extensions, but given the possible damage that they can cause, it is worth taking them seriously. We recommend choosing proven extensions that have a large number of installations and reviews in the Chrome Web Store or other official services. After all, despite the protection measures taken by the owners of such services, malicious extensions can still penetrate them,” Bogdanov said.

Source:  Infosecurity 


Windows Server 2019 embraces SDN

Software-defined networking in Windows Server 2019 includes, virtual network peering and encryption, auditing and IPv6 support.

When Windows Server 2019 is released this fall, the updates will include features that enterprises can use to leverage software-defined networking (SDN).

SDN for Windows Server 2019 has a number of components that have attracted the attention of early adopters including security and compliance, disaster recovery and cusiness continuity, and multi-cloud and hybrid-cloud

Virtual-network peering

The new virtual networking peering functionality in Windows Server 2019 allows enterprises to peer their own virtual networks in the same cloud region through the backbone network.  This provides the ability for virtual networks to appear as a single network.

Fundamental stretched networks have been around for years and have provided organizations the ability to put server, application and database nodes in different sites. However, the challenge has always been the IP addressing of the nodes in opposing sites.  When there are only two static sites in a traditional wide area network, the IP scheme was relatively static.  You knew the subnet and addressing of Site A and Site B.

However, in the public cloud and multi-cloud world – where your target devices may actually shift between racks, cages, datacenters, regions or even hosting providers – having addresses that may change based on failover, maintenance, elasticity changes, or network changes creates a problem.  Network administrators have already  spent and will drastically increase the amount of time they spend addressing, readdressing, updating device tables, etc to keep up with the dynamic movement of systems.

With Vnet Peering, while the external location and fabric that the host and applications systems are running in may drastically change, the virtual network remains consistent.  No need to change source and target addresses within the application, no need for Web and Database pairs to change settings.

Virtual-network encryption

Another significant improvement in Windows Server 2019 is the ability for virtual-network traffic to be encrypted between virtual machines.  Traffic encryption is not new to the industry, however having the encryption built in to the operating system as the basis of hypervisor communications, server communications and application communications provides both flexibility and that in the past was frequently done at the application layer.

Now with Vnet encryption, entire subnet communications between host servers can be protected, and all network traffic within that network is automatically encrypted.  For organizations looking to ensure communications between a Web server and a database server is encrypted, Vnet encryption in Windows Server 2019 can be enabled. Since the communications is at the network/subnet level, if additional Web frontends and backend databases needed to be added, all those servers join the same encrypted communication stream, offloading the secured communications away from the application itself, improving performance and efficiency.



Source:  NETWORK WORLD 


Intel Tiger Lake CPUs to come with Anti-Malware Protection

Intel’s Tiger Lake CPUs will come with Control-flow Enforcement Technology (CET), aimed at battling common control-flow hijacking attacks. I...