Foxconn says it will build plant in Wisconsin after talk with Trump

Foxconn Technology < said Friday it will build a factory in Wisconsin after the company's chairman spoke to U.S. President Donald Trump.


from Reuters: Technology News https://reut.rs/2RzlJ0o

Shell open to carmaker partners in EV charging expansion

Shell is open to partnerships with carmakers to expand electric vehicle (EV) charging beyond its petrol stations, one of the oil major's executives said on Friday.


from Reuters: Technology News https://reut.rs/2Wx0KPE

NSA Releases Updated Guidance on Side-Channel Vulnerabilities

Original release date: February 01, 2019

The National Security Agency (NSA) has released updated information on a set of side-channel vulnerabilities affecting modern computer processors. An attacker can exploit these vulnerabilities to obtain sensitive information.

The National Cybersecurity and Communications Integration Center (NCCIC), part of the Cybersecurity and Infrastructure Security Agency (CISA), encourages users and administrators to review the NSA Cybersecurity Advisory on Updated Guidance for Vulnerabilities Affecting Modern Processors and Hardware and Firmware Security Guidance GitHub website for more information and updated mitigations.


This product is provided subject to this Notification and this Privacy & Use policy.




from US-CERT: The United States Computer Emergency Readiness Team http://bit.ly/2TytsO0

New York Fed to assist Bangladesh in cyber-heist law suit

The Federal Reserve Bank of New York said on Friday it will provide "technical assistance" to Bangladesh Bank as it sues a Philippine bank to recoup losses, after unidentified hackers stole $81 million from its account at the U.S. central bank three years ago.


from Reuters: Technology News https://reut.rs/2D2lfKZ

U.S. appeals court hears challenge to FCC net neutrality repeal

A federal appeals court was hearing arguments on Friday over whether the Trump administration acted legally when it repealed landmark net neutrality rules governing internet providers in December 2017.


from Reuters: Technology News https://reut.rs/2Sjn3ck

Collaborating with Law Enforcement to Tackle the Scourge of ATM Attacks

At Trend Micro, we’ve always been keen to collaborate with law enforcement. While we do our best to protect our customers from the latest threats, it’s only with concerted cross-border police action against the perpetrators of these crimes that we can hope to swing the pendulum back in our favor. One common target of attack over the years has been ATMs: offering hackers a direct route to skim card details and get ahold of free cash.

 

That’s why we were pleased to have contributed to a new Europol report for law enforcement detailing guidelines on logical ATM attacks. By sharing our expertise in this way, we support the ongoing efforts by both law enforcement and the financial industry to stop ATM abuse.

In the firing line 

The report in question, Guidance and recommendations regarding logical attacks on ATMs, is an update to a landmark 2015 document, coordinated by the European Association for Secure Transactions Expert Group on All Terminal Fraud (EAST EGAF). It represents fantastic vendor-neutral guidance on typical attack methods, how to improve cyber protection of ATM systems, and enhancing incident detection and response.

Steven Wilson, Head of Business at Europol’s European Cybercrime Centre (EC3) said, “This updated and refocused edition of the report draws upon the expertise of an expanded panel of experts from both law enforcement and the private sector. In addition to the key role played by EAST, I would like to extend my thanks to Diebold Nixdorf, GMV, ING, INTERPOL, NCR, TMD Security and Trend Micro for their invaluable work and contributions, without which this report would not be possible.  I continue to look forward to Europol’s engagement and cooperation with all of our partners within private industry and law enforcement in such endeavors, and our continuing fight against threats affecting the payment industry.”

ATMs are a classic example of the dangers of expanding digital infrastructure without engineering cybersecurity in from the start. In many cases, there’s just enough IT and connectivity to expose machines to attackers, but not enough to protect them.

Attacks have been ongoing for over a decade now, although they’ve changed significantly during that time. Back in the day, criminals had to gain physical access to the ATM itself, gluing card skimmers onto the outside, and overlaying fake keypads to harvest PINs. In some cases, they introduced malware via USBs or CDs and/or attached external keyboards to send commands to dispense cash. These so-called “jackpotting” attacks were for many years confined to Asia and Europe, although they’ve recently started appearing in the US.

However, attackers have also adapted their methods to reduce their chances of getting caught. By attacking bank IT networks remotely there’s no danger of leaving fingerprints at the scene of the crime, or of the alarm being raised by passers-by. Instead, attacker use tried-and-true methods: sending malware-laden phishing emails to bank employees that, when downloaded, provide remote access to networks. From there they can pivot to ATM controllers, and then choose which machines to jackpot, while waiting mules collect the cash.

One of the first attacks of this kind used the Ripper ATM malware to steal an estimated 12 million baht ($350,000) from NCR machines in Thailand in July and August 2016.

“ATM attacks can only be effectively eradicated when the financial sector, cybersecurity companies and law enforcement all work in tandem,” said Martin Bally, chief information security officer for Diebold Nixdorf. “Trend Micro is a strong positive force among these collaborations. Their continued work with both the financial industry and law enforcement brings us all closer to protecting the industry from cybercrime.”

Joining forces

At Trend Micro, we’ve been covering ATM threats for years now and in 2017 released a detailed report into new attack types in collaboration with Europol’s European Cybercrime Centre (EC3). We’re proud to continue this relationship, by sharing our knowledge with the authors of the latest EAST EGAF report for law enforcement.

Private cybersecurity companies have a wealth of resources at their disposal that many law enforcement organizations may be unable to match. At Trend Micro our 1200+ team of TrendLabs researchers work round the clock and around the globe to find emerging threats, while our Smart Protection Network identifies over six billion unique new threats each year.

By sharing this insight when requested, we can get some great results. Just consider the recent conviction of two ringleaders of notorious Scan4You CAV service, which came about after our close cooperation with the FBI. Or how about the conviction of a UK man responsible for selling crypting and CAV services, secured after a landmark partnership with the National Crime Agency?

We’re looking forward to many more successes like these in the future as we continue to partner with global law enforcement entities.

The post Collaborating with Law Enforcement to Tackle the Scourge of ATM Attacks appeared first on .



from Trend Micro Simply Security http://bit.ly/2HNj97t

This Week in Security News: Hacker Strategies and Spyware Attacks

Welcome to our weekly roundup, where we share what you need to know about the cybersecurity news and events that happened over the past few days. This week, learn about how hackers are improving their breach strategies. Also, learn about new spyware attacks via URLs, websites, and mobile apps.

Read on: 

Informing Your Security Posture: How Cybercriminals Blend into the Background

Maintaining protection over an enterprise’s critical data, systems and assets is a continual uphill battle. Hackers are bolstering their capabilities to silently breach platforms and staying under the radar.

Trend Micro: Cybersecurity Staff Feel Unsupported By Businesses

In a global survey of 1,125 IT executives, Trend Micro discovered that enterprise cybersecurity staff feels unsupported by their enterprises, with 33 percent feeling isolated in their positions.

What Enterprise Leaders Should know about Persistent Threats in 2019

As hackers continually shift and improve upon their attack and breach strategies, IT and security stakeholders must do their best to keep up and remain informed of these trends. 

Facebook Pays Teens to Install VPN That Spies on Them

Facebook has been secretly paying people to install a “Facebook Research” VPN that lets the company suck in all of a user’s phone and web activity.

ThinkPHP Vulnerability Abused by Botnets Hakai and Yowai

Cybercriminals use websites created using the PHP framework to breach web servers via dictionary attacks on default credentials and gain control of these routers for distributed denial of service attacks.  

Major iPhone FaceTime Bug Lets You Hear the Audio of the Person You Are Calling … Before They Pick Up

A bug has been discovered that lets you call anyone with FaceTime and immediately hear the audio coming from their phone — before the person on the other end has accepted or rejected the incoming call.

Various Google Play “Beauty Camera” Apps Sends Users Pornographic Content, Redirects Them to Phishing Websites and Collects Their Pictures

Trend Micro discovered several beauty camera apps on Google Play that are capable of accessing remote ad configuration servers that can be used for malicious purposes. 

Microsoft Exchange Vulnerability Enables Attackers to Gain Domain Admin Privileges

Microsoft Exchange 2013 and newer versions are vulnerable to a privilege escalation attack that gives anyone with a mailbox a way to gain domain administrator rights at potentially 90% of organizations running Active Directory and Exchange.

Zero-Day Vulnerability in Total Donations Plugin Could Expose WordPress Websites to Compromise

Owners and administrators of WordPress websites that use the “Total Donations” plugin are advised to remove the plugin after a zero-day vulnerability and design flaws were seen actively exploited. 

U.S. Judge Rejects Yahoo Data Breach Settlement

A U.S. judge rejected Yahoo’s proposed settlement with millions of people whose email addresses and other personal information were stolen in the largest data breach in history, faulting the Internet services provider for a lack of transparency.

Modified TeamViewer Tool Drops Trojan Spyware on Victims

On January 20, a security researcher going by FewAtoms spotted a malicious URL in the wild. The URL is an open directory that leads would-be victims to a malicious self-extracting archive. 

Which spyware attack were you most surprised to hear about? Share your thoughts in the comments below or follow me on Twitter to continue the conversation: @JonLClay.

The post This Week in Security News: Hacker Strategies and Spyware Attacks appeared first on .



from Trend Micro Simply Security http://bit.ly/2WxjbUh

Apple fixes FaceTime privacy bug, will issue update next week

Apple Inc has fixed a bug that let iPhone users see and hear others before they accept FaceTime calls and will roll out a software update next week to re-enable Group FaceTime, it said on Friday.


from Reuters: Technology News https://reut.rs/2SlZ6RF

Hacker who reported flaw in Hungarian Telekom faces up to 8-years in prison

Many of you might have this question in your mind: "Is it illegal to test a website for vulnerability without permission from the owner?" Or… "Is it illegal to disclose a vulnerability publicly?" Well, the answer is YES, it’s illegal most of the times and doing so could backfire even when you have good intentions. Last year, Hungarian police arrested a 20-year-old ethical hacker accused of


from The Hacker News http://bit.ly/2Si7EJk

Tesla begins sales of cheaper Model 3 car variant in China

U.S. electric vehicle maker Tesla Inc said it will start taking orders in China on Friday for a lower-priced version of its Model 3 car, as it seeks to accelerate China sales hit by trade friction between Washington and Beijing.


from Reuters: Technology News https://reut.rs/2D1U0jV

New Mac Malware Targets Cookies to Steal From Cryptocurrency Wallets

Mac users need to beware of a newly discovered piece of malware that steals their web browser cookies and credentials in an attempt to withdraw funds from their cryptocurrency exchange accounts. Dubbed CookieMiner due to its capability of stealing cookies-related to cryptocurrency exchanges, the malware has specifically been designed to target Mac users and is believed to be based on


from The Hacker News http://bit.ly/2RvCeuz

Go-Jek raises $1 billion in round led by Google, Tencent, JD

Indonesian ride-hailing firm Go-Jek has raised around $1 billion in a funding round, led by Alphabet Inc's Google, JD.com Inc and Tencent Holdings, sources familiar with the matter said on Friday.


from Reuters: Technology News https://reut.rs/2t3DYkJ

Sony's profit disappoints as weaker games biz overshadows record result

Japan's Sony Corp reported lower-than-expected profit on Friday as its previously thriving gaming business sagged, though a one-off gain related to its acquisition of EMI nevertheless pushed the quarterly result to a record high.


from Reuters: Technology News https://reut.rs/2Ggw13O

New e-commerce rules jolt Amazon.com in India as products vanish

India's revised e-commerce rules caused widespread disruption on Amazon's India website when they kicked in on Friday, forcing the company to take down its key grocery service and remove a wide range of products such as sunglasses and floor cleaners.


from Reuters: Technology News https://reut.rs/2DOO3Zk

Tesla begins sales of cheaper Model 3 car in China

U.S. electric vehicle maker Tesla Inc said it will start taking orders in China on Friday for a lower-priced version of its Model 3 car, as it seeks to accelerate China sales hit by trade friction between Washington and Beijing.


from Reuters: Technology News https://reut.rs/2HJuPbw

Tesla starts selling cheaper Model 3 car in China

U.S. electric carmaker Tesla Inc said it will start taking orders in China on Friday for a lower-priced version of its Model 3 vehicle, whose price will start at 433,000 yuan ($64,300.56).


from Reuters: Technology News https://reut.rs/2Wzawkr

Hackers Use LinkedIn Messages to Spread RAT Malware Through DLL Sideloading

Cybersecurity researchers have uncovered a new phishing campaign that exploits social media private messages to propagate malicious payloads...