from Reuters: Technology News https://reut.rs/2RzlJ0o
Foxconn says it will build plant in Wisconsin after talk with Trump
from Reuters: Technology News https://reut.rs/2RzlJ0o
Shell open to carmaker partners in EV charging expansion
from Reuters: Technology News https://reut.rs/2Wx0KPE
NSA Releases Updated Guidance on Side-Channel Vulnerabilities
The National Security Agency (NSA) has released updated information on a set of side-channel vulnerabilities affecting modern computer processors. An attacker can exploit these vulnerabilities to obtain sensitive information.
The National Cybersecurity and Communications Integration Center (NCCIC), part of the Cybersecurity and Infrastructure Security Agency (CISA), encourages users and administrators to review the NSA Cybersecurity Advisory on Updated Guidance for Vulnerabilities Affecting Modern Processors and Hardware and Firmware Security Guidance GitHub website for more information and updated mitigations.
This product is provided subject to this Notification and this Privacy & Use policy.
from US-CERT: The United States Computer Emergency Readiness Team http://bit.ly/2TytsO0
New York Fed to assist Bangladesh in cyber-heist law suit
from Reuters: Technology News https://reut.rs/2D2lfKZ
U.S. appeals court hears challenge to FCC net neutrality repeal
from Reuters: Technology News https://reut.rs/2Sjn3ck
Collaborating with Law Enforcement to Tackle the Scourge of ATM Attacks
At Trend Micro, we’ve always been keen to collaborate with law enforcement. While we do our best to protect our customers from the latest threats, it’s only with concerted cross-border police action against the perpetrators of these crimes that we can hope to swing the pendulum back in our favor. One common target of attack over the years has been ATMs: offering hackers a direct route to skim card details and get ahold of free cash.
That’s why we were pleased to have contributed to a new Europol report for law enforcement detailing guidelines on logical ATM attacks. By sharing our expertise in this way, we support the ongoing efforts by both law enforcement and the financial industry to stop ATM abuse.
In the firing line
The report in question, Guidance and recommendations regarding logical attacks on ATMs, is an update to a landmark 2015 document, coordinated by the European Association for Secure Transactions Expert Group on All Terminal Fraud (EAST EGAF). It represents fantastic vendor-neutral guidance on typical attack methods, how to improve cyber protection of ATM systems, and enhancing incident detection and response.
Steven Wilson, Head of Business at Europol’s European Cybercrime Centre (EC3) said, “This updated and refocused edition of the report draws upon the expertise of an expanded panel of experts from both law enforcement and the private sector. In addition to the key role played by EAST, I would like to extend my thanks to Diebold Nixdorf, GMV, ING, INTERPOL, NCR, TMD Security and Trend Micro for their invaluable work and contributions, without which this report would not be possible. I continue to look forward to Europol’s engagement and cooperation with all of our partners within private industry and law enforcement in such endeavors, and our continuing fight against threats affecting the payment industry.”
ATMs are a classic example of the dangers of expanding digital infrastructure without engineering cybersecurity in from the start. In many cases, there’s just enough IT and connectivity to expose machines to attackers, but not enough to protect them.
Attacks have been ongoing for over a decade now, although they’ve changed significantly during that time. Back in the day, criminals had to gain physical access to the ATM itself, gluing card skimmers onto the outside, and overlaying fake keypads to harvest PINs. In some cases, they introduced malware via USBs or CDs and/or attached external keyboards to send commands to dispense cash. These so-called “jackpotting” attacks were for many years confined to Asia and Europe, although they’ve recently started appearing in the US.
However, attackers have also adapted their methods to reduce their chances of getting caught. By attacking bank IT networks remotely there’s no danger of leaving fingerprints at the scene of the crime, or of the alarm being raised by passers-by. Instead, attacker use tried-and-true methods: sending malware-laden phishing emails to bank employees that, when downloaded, provide remote access to networks. From there they can pivot to ATM controllers, and then choose which machines to jackpot, while waiting mules collect the cash.
One of the first attacks of this kind used the Ripper ATM malware to steal an estimated 12 million baht ($350,000) from NCR machines in Thailand in July and August 2016.
“ATM attacks can only be effectively eradicated when the financial sector, cybersecurity companies and law enforcement all work in tandem,” said Martin Bally, chief information security officer for Diebold Nixdorf. “Trend Micro is a strong positive force among these collaborations. Their continued work with both the financial industry and law enforcement brings us all closer to protecting the industry from cybercrime.”
Joining forces
At Trend Micro, we’ve been covering ATM threats for years now and in 2017 released a detailed report into new attack types in collaboration with Europol’s European Cybercrime Centre (EC3). We’re proud to continue this relationship, by sharing our knowledge with the authors of the latest EAST EGAF report for law enforcement.
Private cybersecurity companies have a wealth of resources at their disposal that many law enforcement organizations may be unable to match. At Trend Micro our 1200+ team of TrendLabs researchers work round the clock and around the globe to find emerging threats, while our Smart Protection Network identifies over six billion unique new threats each year.
By sharing this insight when requested, we can get some great results. Just consider the recent conviction of two ringleaders of notorious Scan4You CAV service, which came about after our close cooperation with the FBI. Or how about the conviction of a UK man responsible for selling crypting and CAV services, secured after a landmark partnership with the National Crime Agency?
We’re looking forward to many more successes like these in the future as we continue to partner with global law enforcement entities.
The post Collaborating with Law Enforcement to Tackle the Scourge of ATM Attacks appeared first on .
from Trend Micro Simply Security http://bit.ly/2HNj97t
This Week in Security News: Hacker Strategies and Spyware Attacks
Welcome to our weekly roundup, where we share what you need to know about the cybersecurity news and events that happened over the past few days. This week, learn about how hackers are improving their breach strategies. Also, learn about new spyware attacks via URLs, websites, and mobile apps.
Read on:
Informing Your Security Posture: How Cybercriminals Blend into the Background
Maintaining protection over an enterprise’s critical data, systems and assets is a continual uphill battle. Hackers are bolstering their capabilities to silently breach platforms and staying under the radar.
Trend Micro: Cybersecurity Staff Feel Unsupported By Businesses
In a global survey of 1,125 IT executives, Trend Micro discovered that enterprise cybersecurity staff feels unsupported by their enterprises, with 33 percent feeling isolated in their positions.
What Enterprise Leaders Should know about Persistent Threats in 2019
As hackers continually shift and improve upon their attack and breach strategies, IT and security stakeholders must do their best to keep up and remain informed of these trends.
Facebook Pays Teens to Install VPN That Spies on Them
Facebook has been secretly paying people to install a “Facebook Research” VPN that lets the company suck in all of a user’s phone and web activity.
ThinkPHP Vulnerability Abused by Botnets Hakai and Yowai
Cybercriminals use websites created using the PHP framework to breach web servers via dictionary attacks on default credentials and gain control of these routers for distributed denial of service attacks.
A bug has been discovered that lets you call anyone with FaceTime and immediately hear the audio coming from their phone — before the person on the other end has accepted or rejected the incoming call.
Trend Micro discovered several beauty camera apps on Google Play that are capable of accessing remote ad configuration servers that can be used for malicious purposes.
Microsoft Exchange Vulnerability Enables Attackers to Gain Domain Admin Privileges
Microsoft Exchange 2013 and newer versions are vulnerable to a privilege escalation attack that gives anyone with a mailbox a way to gain domain administrator rights at potentially 90% of organizations running Active Directory and Exchange.
Zero-Day Vulnerability in Total Donations Plugin Could Expose WordPress Websites to Compromise
Owners and administrators of WordPress websites that use the “Total Donations” plugin are advised to remove the plugin after a zero-day vulnerability and design flaws were seen actively exploited.
U.S. Judge Rejects Yahoo Data Breach Settlement
A U.S. judge rejected Yahoo’s proposed settlement with millions of people whose email addresses and other personal information were stolen in the largest data breach in history, faulting the Internet services provider for a lack of transparency.
Modified TeamViewer Tool Drops Trojan Spyware on Victims
On January 20, a security researcher going by FewAtoms spotted a malicious URL in the wild. The URL is an open directory that leads would-be victims to a malicious self-extracting archive.
Which spyware attack were you most surprised to hear about? Share your thoughts in the comments below or follow me on Twitter to continue the conversation: @JonLClay.
The post This Week in Security News: Hacker Strategies and Spyware Attacks appeared first on .
from Trend Micro Simply Security http://bit.ly/2WxjbUh
Apple fixes FaceTime privacy bug, will issue update next week
from Reuters: Technology News https://reut.rs/2SlZ6RF
Hacker who reported flaw in Hungarian Telekom faces up to 8-years in prison
from The Hacker News http://bit.ly/2Si7EJk
Tesla begins sales of cheaper Model 3 car variant in China
from Reuters: Technology News https://reut.rs/2D1U0jV
New Mac Malware Targets Cookies to Steal From Cryptocurrency Wallets
from The Hacker News http://bit.ly/2RvCeuz
Go-Jek raises $1 billion in round led by Google, Tencent, JD
from Reuters: Technology News https://reut.rs/2t3DYkJ
Sony's profit disappoints as weaker games biz overshadows record result
from Reuters: Technology News https://reut.rs/2Ggw13O
New e-commerce rules jolt Amazon.com in India as products vanish
from Reuters: Technology News https://reut.rs/2DOO3Zk
Tesla begins sales of cheaper Model 3 car in China
from Reuters: Technology News https://reut.rs/2HJuPbw
Tesla starts selling cheaper Model 3 car in China
from Reuters: Technology News https://reut.rs/2Wzawkr
Hackers Use LinkedIn Messages to Spread RAT Malware Through DLL Sideloading
Cybersecurity researchers have uncovered a new phishing campaign that exploits social media private messages to propagate malicious payloads...
-
Original release date: November 08, 2018 Summary JBoss Verify and EXploitation tool (JexBoss) is an open-source tool used by cybersecurity...
-
Original release date: May 21, 2018 The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recorded b...
-
Original release date: January 29, 2018 The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been record...
-
It's no secret that learning how to code is one of the most important things you can do when it comes to the beginning or furthering pra...
-
Original release date: February 12, 2018 The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recor...
-
Original release date: October 26, 2020 The CISA Weekly Vulnerability Summary Bulletin is created using information from the NIST NVD . In...
-
Original release date: February 26, 2018 The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recor...
-
Os estragos causados pelo ataque com ransomware ao Superior Tribunal de Justiça (STJ) ainda não são totalmente conhecidos. A Polícia Federa...
-
Original release date: March 9, 2020 The CISA Weekly Vulnerability Summary Bulletin is created using information from the NIST NVD . In som...
-
Original release date: January 08, 2018 The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been record...