Russians Pose as Americans to Steal Data on Social Media

The Americans were targeted on social media by Russian agents on a mission to harvest personal information, The Wall Street Journal reported Wednesday.

The agents pretended to work for organizations promoting African-American businesses as a ruse to obtain personal information from black business owners during the 2016 presidential election campaign, according to the report.

Using names like "BlackMattersUS" and "Black4Black," the agents set up hundreds of accounts on Facebook and Instagram, the WSJ said.

As part of its efforts to address the abuse of its platform during the election, Facebook introduced a tool that would enable its members to determine if they had contact with Russian propaganda during that period. The tool doesn't address the problem of Kremlin agents masquerading as Americans, however.

Facebook did not respond to our request to comment for this story.

Defeating America Without Bullets

The Journal story came on the heels of President Donald Trump's Tuesday announcement that his administration was doing a "very, very deep" study of election meddling and would make "very strong" recommendations about the 2018 elections.

However, Adm. Michael Rogers, chief of the U.S. Cyber Command and head of the National Security Agency, last week told the Senate Armed Services Committee that the White House had not directed him to take any actions to counter potential Russian meddling in the 2018 elections.

"The impact of social media is very real," said Ajay K. Gupta, program chair for computer networks and cybersecurity at the University of Maryland.

"The lack of real attribution for social media content means that elections are being impacted by people who we don't know who they are," he told TechNewsWorld.

"Russians have said since the beginning of the Cold War they would be able to defeat America without firing a single bullet," Gupta added. "They couldn't do that as the U.S.S.R., but social media has given them another opportunity to try that."

Target of Opportunity

The latest revelation about Russian activity on social media during the elections lends credence to the idea that the Kremlin's goal is not to swing elections one way or another, but to weaken America's form of government.

One in four voters were considering staying away from the polls due to cybersecurity fears, according to a survey Carbon Black conducted last year, for example. If accurate, that could put the number who would not vote for that reason in the neighborhood of 55 million.

"This blended campaign of human intelligence and signals intelligence is dangerous for democracy," said Tom Kellermann, chief cybersecurity officer at Carbon Black.

Russia is into the long game, noted Tellagraff CEO Mark Graff.

"Hillary Clinton was a target of opportunity for the Russians in the 2016 election," he told TechNewsWorld.

"Their strategic goal was not to elect Donald Trump. The strategic goal was to disrupt American society, undermine our feelings of unity, undermine our faith in democracy," Graff maintained. "They've been trying to do that for over 50 years -- and now what they can do, using social media, is do it from the comfort of government buildings inside Russia."

What's a Social Network to Do?

Both Twitter and Facebook have made efforts to counter nation-state backed exploitation of their platforms, but the consensus is that more can be done.

"They must dynamically verify the identities of their users and filter illicit and inflammatory content," Carbon Black's Kellermann told TechNewsWorld.

"Facebook and Twitter are seemingly just learning how to combat this, and they both appear to be very late to the game," observed Brian Martin, director of vulnerability intelligence at Risk Based Security.

The social networks could deploy a number of measures, he told TechNewsWorld, ranging from monitoring the IP addresses of suspect accounts to refining their analyses of the language in posts, looking for key indicators of actors who don't speak English as their first language.

Users should have the option to flag suspected bots, so the social media companies could investigate and weed out bad actors, said Sherban Naum, senior vice president for corporate strategy and technology at Bromium.

Better Authentication

Credible news outlets should be given some kind of distinctive authentication, Naum also recommended.

Social media companies have certain "verified" users, but that appears to be inadequate. "Lots of bad guys are verified," he told TechNewsWorld.

"Twitter and Facebook could also publish trending information about bots and bad information so users can see what's trending that is legit and what's trending that is junk," Naum suggested.

What can consumers do to protect themselves?

Users should "approach social media with the same skepticism that they should be approaching email and scams," Risk Based Security's Martin advised.

"Someone offering you 100 million dollars is suspect, of course," he said.

"Someone that seems to have a 'magic bullet' showing a political figure is the next devil? Think about it more critically than you might otherwise," Martin cautioned. "Does the post have any evidence to back it up? Or is it just a compelling picture, that may have been doctored, and a catchy one-liner that invokes emotional responses?"

Source:  TECHNEWSWORLD 


Microsoft June 2018 Patch Tuesday Pushes 11 Critical Security Updates

It's time to gear up for the latest June 2018 Microsoft security patch updates.

Microsoft today released security patch updates for more than 50 vulnerabilities, affecting Windows, Internet Explorer, Edge, MS Office, MS Office Exchange Server, ChakraCore, and Adobe Flash Player—11 of which are rated critical and 39 as important in severity.

Only one of these vulnerabilities, a remote code execution flaw (CVE-2018-8267) in the scripting engine, is listed as being publicly known at the time of release. However, none of the flaws are listed as under active attack.

Discovered by security researcher Dmitri Kaslov, the publicly known vulnerability is a remote memory-corruption issue affecting Microsoft Internet Explorer.

The flaw exists within the IE rendering engine and triggers when it fails to properly handle the error objects, allowing an attacker to execute arbitrary code in the context of the currently logged-in user.

The most critical bug Microsoft patched this month is a remote code execution vulnerability (CVE-2018-8225) exists in Windows Domain Name System (DNS) DNSAPI.dll, affecting all versions of Windows starting from 7 to 10, as well as Windows Server editions.

The vulnerability resides in the way Windows parses DNS responses, which could be exploited by sending corrupted DNS responses to a targeted system from an attacker-controlled malicious DNS server.

Successful exploitation of this vulnerability could allow an attacker to run arbitrary code in the context of the Local System Account.

Another critical bug is a remote code execution flaw (CVE-2018-8231) in the HTTP protocol stack (HTTP.sys) of Windows 10 and Windows Server 2016, which could allow remote attackers to execute arbitrary code and take control of the affected systems.

This vulnerability originates when HTTP.sys improperly handles objects in memory, allowing attackers to send a specially crafted packet to an affected Windows system to trigger arbitrary code execution.

Next critical remote code execution vulnerability (CVE-2018-8213) affecting Windows 10 and Windows Server exists in the way the operating system handles objects in memory. Successful exploitation could allow an attacker to take control of an affected Windows PC.

"To exploit the vulnerabilities, an attacker would first have to log on to the target system and then run a specially crafted application," Microsoft explains in its advisory.

Microsoft has also addressed seven critical memory corruption bugs—one in Chakra scripting engine, three in Edge browser, one in the ChakraCore scripting engine, and one in Windows Media Foundation—all lead to remote code execution.

Rest CVE-listed flaws have been addressed in Windows, Microsoft Office, Internet Explorer, Microsoft Edge, ChakraCore, along with a zero-day bug in Flash Player that Adobe patched last week.
Users are strongly advised to apply security patches as soon as possible to keep hackers and cybercriminals away from taking control of their computers.

For installing security updates, simply head on to Settings → Update & security → Windows Update → Check for updates, or you can install the updates manually.


Source:  TheHackerNews 


FBI Arrest 74 Email Fraudsters Involved in Nigerian BEC Scams

The United States Department of Justice announced  Monday the arrest of 74 email fraudsters across three continents in a global crackdown on a large-scale business email compromise (BEC) scheme.

The arrest was the result of a six-month-long operation dubbed "Operation Wire Wire" that involved the US Department of Justice, the US Department of Homeland Security, the US Treasury, and the US Postal Inspection Service.

The international law enforcement authorities led by the FBI arrested 42 of the total 74 individuals involved in BEC scheme in the United States, 29 in Nigeria and 3 each in Canada, Mauritius, and Poland.

"Foreign citizens perpetrate many BEC scams. Those individuals are often members of transnational criminal organizations, which originated in Nigeria but have spread throughout the world," the DoJ says.

Moreover, the authorities seized nearly $2.4 million and recovered about $14 million in fraudulent transfers, according to the FBI, which estimates that businesses worldwide have lost up to $5.3 billion to BEC fraudsters since 2013.

Like most BEC scheme, the cybercriminals targeted both businesses and individuals, including many senior citizens and real estate purchasers, to steal millions using socially-engineered emails to convince them to make wire transfers to bank accounts controlled by the criminals.

In one case, the US Department of Justice alleged that two Nigerians living in Dallas, Texas, posed as a property seller and requested a $246,000 wire transfer from a real estate attorney, who lost $130,000 after the bank was notified of the fraud while $116,000 were frozen.

The US Department of Justice said such scams are "prevalent" and pledged to pursue and prosecute the perpetrators "regardless of where they are located."

"This operation demonstrates the FBI's commitment to disrupt and dismantle criminal enterprises that target American citizens and their businesses," said FBI Director Christopher A. Wray.

According to the DoJ, the fraudsters also targets individuals with romance, employment opportunities, fraudulent online vehicle sales, rental, and lottery scams. Sometimes they ask for valuable data like employee tax records instead of, or in addition to, money.
Since such email fraud attacks are on the rise, the law enforcement recommended people to educate themselves and organizations to educate their employees on BEC schemes to protect their businesses.

Are you already a victim of the BEC scheme? Please file a complaint with the IC3. You can also take a look at this IC3 public service announcement on BEC schemes.



Source:  TheHackerNews 


Thousands of Android Devices Running Insecure Remote ADB Service

Despite warnings about the threat of leaving insecure remote services enabled on Android devices, manufacturers continue to ship devices with open ADB debug port setups that leave Android-based devices exposed to hackers.

Android Debug Bridge (ADB) is a command-line feature that generally uses for diagnostic and debugging purposes by helping app developers communicate with Android devices remotely to execute commands and, if necessary, completely control a device.
Usually, developers connect to ADB service installed on Android devices using a USB cable, but it is also possible to use ADB wirelessly by enabling a daemon server at TCP port 5555 on the device.

If left enabled, unauthorized remote attackers can scan the Internet to find a list of insecure Android devices running ADB debug interface over port 5555, remotely access them with highest "root" privileges, and then silently install malware without any authentication.

Therefore, vendors are recommended to make sure that the ADB interface for their Android devices is disabled before shipping. However, many vendors are failing to do so.
In a Medium blog post published Monday, security researcher Kevin Beaumont said there are still countless Android-based devices, including smartphones, DVRs, Android smart TVs, and even tankers, that are still exposed online.

"This is highly problematic as it allows anybody — without any password — to remotely access these devices as ‘root’* — the administrator mode — and then silently install software and execute malicious functions," Beaumont said.

The threat is not theoretical, as researchers from Chinese security firm Qihoo 360's NetLab discovered a worm, dubbed ADB.Miner, earlier this year, that was exploiting the ADB interface to infect insecure Android devices with a Monero (XMR) mining malware.


Smartphones, smart TVs, and TV set-top boxes were believed to be targeted by the ADB.Miner worm, which managed to infect more than 5,000 devices in just 24 hours.

Now, Beaumont once again raised the community concerns over this issue. Another researcher also confirmed that the ADB.Miner worm spotted by Netlab in February is still alive with millions of scans detected in the past month itself.

  "@GossiTheDog inspired me to take a look back at the ADB.Miner worm, which I've been fingerprinting in February. It seems that it lives and it feels pretty well. I've checked out two days (4th, 5th of June) - about 40 000 unique IP addresses. I'll provide some deep analysis soon," Piotr Bazydło, IT Security researcher at NASK, tweeted.

Although it is difficult to know the exact number of devices due to Network Address Translation and dynamic IP reservations, Beaumont says "it is safe to say 'a lot.'"
In response to Beaumont's blog post, the Internet of Things (IoT) search engine Shodan also added the capability to look for port 5555. Based on the scanning IP addresses, the majority of exposed devices are found in Asia, including China and South Korea.

Kevin advises vendors to stop shipping products with Android Debug Bridge enabled over a network, as it creates a Root Bridge—a situation anybody can misuse the devices.
Since ADB debug connection is neither encrypted nor requires any password or key exchange, Android device owners are advised to disable it immediately.

Source:  The HackerNews 


Train Your Employees to Think for Themselves in Data Security

Employers have learned (the hard way) that one of the biggest security threats in the organization is their own staff.

A report published by Ipswitch looks at data breach causes to find out how rogue employees rank. An interesting find is that up to 75% of data breaches result from insider threats, while a separate report by Veriato  suggests that 90% of cybersecurity experts feel that their company is vulnerable to insider attacks. In fact, about 50% of the 472 professionals surveyed said they had suffered these attacks in the previous 12 months.

Deliberate or not, these threats are very real and as heavily as companies might invest in data security software, they are always going to be vulnerable because they continually ignore a large component of realizing fewer cybersecurity threats.

Since employees (insiders) have access to company information, they are technically a bigger danger to data security than the third party cyber-criminals who use all manner of innovative ways to gain access to personal data.

A curious business owner wants to know: Why must I involve employees in implementing data security when they have been shown to be a weak point in the same strategy?

1. Social engineering transcends security tools
Human error is often the weakest link in an otherwise ideal chain. From technology to literature, social engineering is the big boss you have to beat after meeting all the other mini-bosses.

By definition, social engineering involves the use of psychological tricks to manipulate people into revealing sensitive information about themselves. For an organization, once the hacker has your employee at this point, they can gain access to all the areas the employee can typically access. Through social engineering security awareness you can help your employees avoid the three commonest security scams thereby protecting your company as well: identity theft; vishing; and baiting.

Without adequate education on social engineering and covering that loophole, security tools are almost useless.

2. It’s part of their responsibility
Apart from preventing the catastrophic aftermath of social engineering, data security is the responsibility of every employee in the organization in this sense: if consumers expect organizations to protect their data, isn’t it the responsibility of employees to make sure the data doesn’t land in the wrong hands?

Dropbox's 2012 incident, during which hackers reportedly stole data belonging to over 60 million of Dropbox's  clients at the time, was attributed to employee negligence.

As reported, the hackers who used the password of the employee were able to access the company portal by reusing a password from the LinkedIn breach of the same year that exposed the emails and passwords of 117 million LinkedIn users.

Such an example shows that as a company, you can still unwillingly betray your customers. While Dropbox wasn’t entirely to blame, one of their employees reusing passwords was a great insight into the company’s internal security standards and more importantly, a good example for all employees on password don’ts.

3. It is now a common regulatory requirement
Through internet security awareness training, organizations are required to equip their staff with knowledge about data security. Some of the laws, regulations and industry codes include HIPAA, FTC Red Flags Rule and PCI DSS among others. While many SMEs don’t do any training to remain compliant, many conduct the training to avoid cyber-attacks.

These tips will help you implement a great training program:

1. Diversify your training methods. Have a mix of training techniques at your disposal including classrooms, videos, team discussions, newsletters, posters, etc.

2. Educate often. Conduct regular training in monthly, quarterly, or annual cycles.

3. There’s no one size that fits all. Different members at different levels will start learning at equally different points.
Don’t ignore industry regulations.

Don’t be like the owner who delegates the role of data security to themselves because it’s “too important.” If you really want to be stress-free, train your employees well and promote a culture of information security.

Source:  Infosecurity 


Facebook's Special-Access, Data-Sharing Deals

In the months that have followed Mark Zuckerberg's testimony before Congress, Facebook has repeatedly found itself in the headlines. Once again, it has come to light that the social media giant has been less than transparent, with the Wall Street Journal reporting that certain companies deemed to provide particular value to Facebook were placed on what was internally dubbed as "whitelists," granting them access to customer data.

Two companies identified as making the whitelist include the Royal Bank of Canada and Nissan Motor Co., a source familiar with the matter reportedly told the Journal. In addition to phone numbers, the information the companies were able to access included a "friend link" metric, which provided data on the degrees of separation among users and their friends.

While no additional names of whitelisted companies have been disclosed, Facebook has justified the deals, reportedly claiming that the access was granted with the intention of both improving the user experience and allowing third parties and partners the time needed to conclude their previously existing data-sharing projects.

Facebook acknowledged the "small group" had been granted extended access beyond 2015 May as part of what Ime Archibong, vice president of product partnerships, Facebook, called the company's consistent and principled approach to working with developers.

“As we were winding down over the year, there was a small number of companies that asked for short-term extensions, and that, we worked through with them,” Archibong reportedly said. “But other than that, things were shut down.”

This newest whitelist revelation is separate from the data-sharing partnerships with device makers that was reported last week. A Facebook spokeswoman is reported to have confirmed that the company has been sharing users’ data with at least 60 different device producers, including Apple, Microsoft and Samsung, since 2007.

Despite its claim to have stopped third-party access to information on users's friends back in 2015, NordVPN wrote that "Facebook does not internally consider device makers to be third parties, so it did not disclose the fact that it was sharing the same exact data with those companies."

Source:  Infosecurity 


RIP Yahoo Messenger, 1998-2018

First they came for AOL Instant Messenger, and killed it off on December 15 of last year. Now they're aiming for Yahoo Messenger, one of the original chat services. It is scheduled to die on July 17 this year. If you want to, you can download your chat history for the next six months by accessing this link.

Oath, the Verizon-owned company that currently runs Yahoo Messenger, hasn't announced any plans to replace it with something that could become an actual competitor to the likes of WhatsApp or Facebook Messenger.

It's funny how, many years ago when someone said "messenger" you naturally assumed they meant Yahoo's, and today your brain automatically thinks of Facebook's. Times, they definitely are a changin'.

Yahoo Messenger launched on March 9, 1998 as Yahoo Pager, and then got its iconic rebranding on June 21, 1999. Thus, on July 17, 2018, when it's scheduled to be put down, it will be exactly 20 years, 4 months, and 8 days old. Too young to go? You'll be the judge of that.

Oath took this opportunity to remind everyone about Yahoo Squirrel, which is an invite-only group messaging app, currently in beta. You need to request access to the beta in order to use it, because hey, that worked for Gmail in 2004 so it has to still be a valid launch strategy, right?

Don't be surprised if Squirrel will be euthanized at some point in the near future as well. You may not hear about that, though - while some have fond memories of Yahoo Messenger, we're betting that there aren't a lot of people who've ever heard of Squirrel.

Source:  gsmarena 


Intel Tiger Lake CPUs to come with Anti-Malware Protection

Intel’s Tiger Lake CPUs will come with Control-flow Enforcement Technology (CET), aimed at battling common control-flow hijacking attacks. I...