Security News

US bans Chinese telecoms imports – won't even consider authorizing them
2022-11-27 22:32

The United States' Federal Communications Commission has barred itself from authorizing the import or sale of Chinese telecoms and video surveillance products from Huawei, ZTE, Hytera Communications, Hikvision, and Dahua, on national security grounds. As it is not legal to offer such products in the US without FCC approval, the move is effectively a ban on the five vendors' products.

Meta links US military to fake social media influence campaigns
2022-11-24 12:15

In its latest quarterly threat report, Meta said it had detected and disrupted influence operations originating in the US, and it calls out those it believes are responsible: the American military. Meta said it picked up on three major covert influence operations on its platforms in the third quarter of the year, the first of which originated in the United States.

Multimillion dollar CryptoRom scam sites seized, suspects arrested in US
2022-11-23 19:58

Over the past year, we've had the unfortunate need to warn our readers not once, but twice, about a scam we've dubbed CryptoRom, a portmanteau word formed from the terms "Cryptocurrency" and "Romance scam". The "Romance" in a CryptoRom scam isn't tugging at your heart strings, but at your wallet strings.

The US Has a Shortage of Bomb-Sniffing Dogs
2022-11-23 16:23

Last month, the US Government Accountability Office released a nearly 100-page report about working dogs and the need for federal agencies to better safeguard their health and wellness. The GOA says that as of February the US federal government had approximately 5,100 working dogs, including detection dogs, across three federal agencies.

#US
US offshore oil and gas installation at 'increasing' risk of cyberattack
2022-11-21 16:02

The US Government Accountability Office has warned that the time to act on securing the US's offshore oil and natural gas installations is now because they are under "Increasing" and "Significant risk" of cyberattack. A report to Congress looked at a network of "More than 1,600 offshore oil and gas facilities," which the federal watchdog pointed out produce a "Significant" amount of America's domestic oil and gas - and the operational technology tech that looks after and controls the physical equipment.

US charges BEC suspects with targeting federal health care programs
2022-11-18 17:26

The U.S. Department of Justice has charged ten defendants for their alleged involvement in business email compromise schemes targeting numerous victims across the country, including U.S. federal funding programs like Medicare and Medicaid. "Unwittingly, five state Medicaid programs, two Medicare Administrative Contractors, and two private health insurers allegedly were deceived into making payments to the defendants and their co-conspirators instead of depositing the reimbursement payments into bank accounts belonging to the hospitals," DOJ said in a press release on Friday.

#US
Phishing kit impersonates well-known brands to target US shoppers
2022-11-17 23:44

A sophisticated phishing kit has been targeting North Americans since mid-September, using lures focused on holidays like Labor Day and Halloween. The kit uses multiple evasion detection techniques and incorporates several mechanisms to keep non-victims away from its phishing pages.

Iranian cyberspies exploited Log4j to break into a US govt network
2022-11-16 23:30

Iranian state-sponsored cyber criminals used an unpatched Log4j flaw to break into a US government network, illegally mine for cryptocurrency, steal credentials and change passwords, and then snoop around undetected for several months, according to CISA. In an alert posted Wednesday, the US cybersecurity agency said it detected the advanced persistent threat activity on an unnamed federal civilian executive branch organization's network in April. "CISA and the Federal Bureau of Investigation assess that the FCEB network was compromised by Iranian government-sponsored APT actors," according to the alert.

US govt: Iranian hackers breached federal agency using Log4Shell exploit
2022-11-16 16:34

The attackers compromised the federal network after hacking into an unpatched VMware Horizon server using an exploit targeting the Log4Shell remote code execution vulnerability. After deploying the cryptocurrency miner, the Iranian threat actors also set up reverse proxies on compromised servers to maintain persistence within the FCEB agency's network.

Russia-based Pushwoosh tricks US Army and others into running its code – for a while
2022-11-15 01:30

US government agencies including the Army and Centers for Disease Control and Prevention pulled apps running Pushwoosh code after learning the software company - which presents itself as American - is actually Russian, according to Reuters. Pushwoosh is a software company that provides code and data analysis for developers so they can automate custom push notifications based on smartphone users' online activity.