Security News

Feds offer $5m reward for info on North Korean cyber crooks
2022-04-15 23:24

The US government offered a reward up to $5 million for information that helps disrupt North Korea's cryptocurrency theft, cyber-espionage, and other illicit state-backed activities. The cash will be awarded "For information that leads to the disruption of financial mechanisms of persons engaged in certain activities that support North Korea, including money laundering, exportation of luxury goods to North Korea, specified cyber-activity and actions that support WMD proliferation," according to the Feds.

Feds: APTs Have Tools That Can Take Over Critical Infrastructure
2022-04-14 15:57

Threat actors have built and are ready to deploy tools that can take over a number of widely used industrial control system devices, which spells trouble for critical infrastructure providers-particularly those in the energy sector, federal agencies have warned. In a joint advisory, the Department of Energy, the Cybersecurity and Infrastructure Security Agency, the National Security Agency and the FBI caution that "Certain advanced persistent threat actors" have already demonstrated the capability "To gain full system access to multiple industrial control system/supervisory control and data acquisition devices," according to the alert.

Feds Shut Down RaidForums Hacking Marketplace
2022-04-13 15:01

The Department of Justice unveiled Tuesday that it has seized three domains to affectively shut down the RaidForums website, a major English-language online marketplace for cybercriminals to buy and sell databases stolen from organizations in ransomware and other cyber-attacks. The seizure of RaidForum's domains means that members can no longer use the site to traffic stolen data, according to the feds.

Feds take down Kremlin-backed Cyclops Blink botnet
2022-04-06 19:24

The US Justice Department today revealed details of a court-authorized take-down of command-and-control systems the Sandworm cyber-crime ring used to direct network devices infected by its Cyclops Blink malware. The move follows a joint security alert in February from US and UK law enforcement that warned of WatchGuard firewalls and ASUS routers being compromised to run Cyclops Blink.

Feds slay dark-web souk Hydra: Servers and $25m in crypto-coins seized
2022-04-05 23:12

First, German federal police in coordination with US law enforcement seized Hydra servers and cryptocurrency wallets containing $25 million in Bitcoin, thus shutting down the online souk. Later on Tuesday, the US Justice Department announced criminal charges against one of the alleged Hydra operators and system administrators, 30-year-old Dmitry Olegovich Pavlov of Russia.

Consumers fed up with passwords and KBAs, looking to voice enabled technology as the future
2022-03-09 05:00

Pindrop released the findings of a survey that explores how 2000+ US-based consumers feel about the future of voice enabled technology and how it will impact their everyday lives. The report uncovered that consumers are so fed up with passwords and KBAs to access accounts or verify identity that many would be less annoyed by having their flight delayed or having to shovel snow.

EoL Systems Stonewalling Log4j Fixes for Fed Agencies
2022-01-07 22:16

Besides the difficulty of tracking down all instances of the ubiquitous Apache logging library, the job of patching the flaws has been further complicated for many agencies by end-of-life and end-of-support systems connected to the network. Due to network-connected EoL and EoS systems: an issue that's further complicated by pandemic-wrought supply chain delays and remote-work issues.

Oz Feds reveal distribution model behind backdoored 'An0m' chat app spread by crims
2021-12-09 03:43

Australia's Federal Police force has revealed more about how it distributed a backdoored chat app to criminals. The app, named An0m, was revealed in June 2021 when Australia's Feds, the FBI and European authorities revealed they'd combined to convince crims the software allowed secure communications.

Cuba ransomware gang scores almost $44m in ransom payments across 49 orgs, say Feds
2021-12-06 13:02

The US Federal Bureau of Investigation says 49 organisations, including some in government, were hit by Cuba ransomware as of early November this year. The ransomware gang's loader of choice, Hancitor, was the culprit, distributed via phishing emails, or via exploit of Microsoft Exchange vulnerabilities, compromised credentials, or Remote Desktop Protocol tools.

Feds charge two men with claiming ownership of others' songs to steal YouTube royalty payments
2021-12-03 21:54

The US Attorney's Office of Arizona on Wednesday announced the indictment of two men on charges that they defrauded musicians and associated companies by claiming more than $20m in royalty payments for songs played on YouTube. "In short, Batista and Teran, as individuals and through various entities that they operate and control, fraudulently claimed to have the legal rights to monetize a music library of more than 50,000 songs," the indictment [PDF] alleges.