<?xml version="1.0"?>
<rss version="2.0"><channel><title><![CDATA[News: Security & Privacy News]]></title><link>https://nsaneforums.com/news/security-privacy-news/page/43/?d=2</link><description><![CDATA[News: Security & Privacy News]]></description><language>en</language><item><title>Google rolls back decision to kill third-party cookies in Chrome</title><link>https://nsaneforums.com/news/security-privacy-news/google-rolls-back-decision-to-kill-third-party-cookies-in-chrome-r24370/</link><description><![CDATA[<p>
	Google has scrapped its plan to kill third-party cookies in Chrome and will instead introduce a new browser experience that allows users to limit how these cookies are used.
</p>

<p>
	 
</p>

<p>
	A third-party cookie is data stored in your web browser by a website other than the website you are currently visiting and is usually dropped by tracking scripts and advertisements. These cookies can then be used to track you on other sites utilizing code from the same third-party domain, allowing advertisers to track your browsing habits and interests.
</p>

<p>
	 
</p>

<p>
	As these cookies are commonly seen as a privacy risk, the European Union's General Data Protection Regulation (GDPR) act, which went live in 2018, required advertisers to gain user's consent before using third-party cookies.
</p>

<p>
	 
</p>

<p>
	In 2019, Mozilla Firefox began <a href="https://blog.mozilla.org/en/products/firefox/todays-firefox-blocks-third-party-tracking-cookies-and-cryptomining-by-default/" rel="external nofollow" target="_blank">blocking third-party cookies by default</a>, followed by <a href="https://www.theverge.com/2020/3/24/21192830/apple-safari-intelligent-tracking-privacy-full-third-party-cookie-blocking" rel="external nofollow" target="_blank">Apple Safari in 2020</a>, striking a massive blow to the advertising industry. Google pledged to do the same in the future.
</p>

<p>
	 
</p>

<p>
	Google started phasing out third-party cookies in Q1 2024, with a gradual phaseout planned to end in Q1 2025. To replace third-party cookies, Google introduced its <a href="https://www.bleepingcomputer.com/news/google/google-rolls-out-privacy-sandbox-to-use-chrome-browsing-history-for-ads/" target="_blank" rel="external nofollow">Privacy Sandbox</a>, which is supposed to be a more anonymous way of tracking a user's interests for advertising purposes.
</p>

<p>
	 
</p>

<p>
	However, advertising platforms and companies have been slow to switch to the new Privacy Sandbox platform, and many are still in beta testing.
</p>

<p>
	 
</p>

<p>
	Google now says that since the transition requires significant work and will impact publishers, advertisers, and any other company involved in online advertising, they are no longer phasing out third-party cookies.
</p>

<p>
	 
</p>

<p>
	Instead, they plan to roll out a new Google Chrome experience that allows users to restrict the use of third-party cookies.
</p>

<p>
	 
</p>

<p>
	"In light of this, we are proposing an updated approach that elevates user choice," Google announced in a <a href="https://privacysandbox.com/intl/en_us/news/privacy-sandbox-update/" rel="external nofollow" target="_blank">blog post</a> today by Anthony Chavez, VP, Privacy Sandbox.
</p>

<p>
	 
</p>

<p>
	"Instead of deprecating third-party cookies, we would introduce a new experience in Chrome that lets people make an informed choice that applies across their web browsing, and they'd be able to adjust that choice at any time."
</p>

<p>
	 
</p>

<p>
	"We're discussing this new path with regulators, and will engage with the industry as we roll this out."
</p>

<p>
	 
</p>

<p>
	It is unclear what this "experience" will be, but it sounds like a global cookie consent system built into Chrome that allows users to opt in and out of third-party cookies.
</p>

<p>
	 
</p>

<p>
	Privacy advocates, such as the EFF, are unhappy with this decision, saying it demonstrates how Google chooses profits over privacy.
</p>

<p>
	 
</p>

<div class="QuoteNewsStyle">
	<p>
		“Google’s announcement underscores their ongoing commitment to profits over user privacy. Safari and Firefox have blocked third-party cookies by default since 2020, when Google pledged to do the same. Third-party cookies are one of the most pervasive tracking technologies, enabling advertising companies and data brokers to collect and sell information about users’ online activities. This can lead to a range of harms, like bad actors buying your sensitive information and predatory ads targeting vulnerable populations.
	</p>

	<p>
		 
	</p>

	<p>
		Google's decision to continue allowing third-party cookies, despite other major browsers blocking them for years, is a direct consequence of their advertising-driven business model. With nearly 80% of Google’s revenue derived from online advertising, it’s clear why Chrome is putting advertisers' interests above users' privacy."
	</p>

	<p>
		 
	</p>
	❖ Electronic Frontier Foundation Staff Technologist Lena Cohen
</div>

<p>
	The EFF recommends users install their <a href="https://privacybadger.org/" rel="external nofollow" target="_blank">Privacy Badger</a> browser extensions, which help block third-party cookies and other online tracking. Users can also use ad blockers like <a href="https://chromewebstore.google.com/detail/ublock-origin/cjpalhdlnbpafiamejdnhcphjbkeiagm?hl=en&amp;pli=1" rel="external nofollow" target="_blank">uBlock Origin</a> to block trackers and advertisements.
</p>

<p>
	 
</p>

<p>
	BleepingComputer contacted Google to learn more about this experience but a reply was not immediately available.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/google-rolls-back-decision-to-kill-third-party-cookies-in-chrome/" rel="external nofollow">Source</a>
</p>

<p>
	 
</p>

<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every single day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>2023: Over 5,800 news posts | 2024 (till end of June): 2,839 news posts</em></span>
</p>
]]></description><guid isPermaLink="false">24370</guid><pubDate>Tue, 23 Jul 2024 03:05:21 +0000</pubDate></item><item><title>Linx emerges from stealth with $33M to lock down the new security perimeter: Identity</title><link>https://nsaneforums.com/news/security-privacy-news/linx-emerges-from-stealth-with-33m-to-lock-down-the-new-security-perimeter-identity-r24353/</link><description><![CDATA[<p>
	Identity management is one of the most common fulcrums around which security breaches have pivoted in the last several years, and one of the main reasons it’s the gift that keeps on giving to malicious hackers is that it’s a nightmare for organizations to track. A security startup founded in Tel Aviv called Linx has been quietly building technology using AI and analytics to address this, and today, on the back of picking up customers in stealth mode, it’s coming out into the open with $33 million in funding to take on the challenge of identity management more aggressively.
</p>

<p>
	 
</p>

<p>
	Linx’s funding is being announced in a single sum, but more specifically it’s coming in two tranches that speak to its momentum while in stealth. The latest is $27 million co-led by Index Ventures and Cyberstarts; prior to that Linx raised $6 million led by Cyberstarts.
</p>

<p>
	 
</p>

<p>
	Other investors in Linx speak to the founders’ reputation in the Israeli security community: they include Mickey Boodaei (Imperva, Trusteer, Transmit), Rakesh Loonkar (Trusteer, Transmit), and Assaf Rappaport and Yinon Costica (Wiz, Adallom). Other investors in the round are Cerca Partners and Knollwood Investment Advisory.
</p>

<p>
	 
</p>

<p>
	Linx Security has been around for just over a year and it has an interesting backstory. The two co-founders, Israel Duanis (CEO) and Niv Goldenberg (CPO), originally met and became friends as so many others do in the world of Israeli tech: they were enlisted together in the army in the 8200 cyber unit. They were not the only ones in that particular cohort: Assaf Rappaport and the other Wiz founders were also in that group.
</p>

<p>
	 
</p>

<p>
	Both Duanis and Goldenberg went on to work for cybersecurity companies, Checkpoint Software in the case of Duanis and Adallom, Microsoft and Transmit for Goldenberg; and Duanis also later ranged away from the space, founding, running and eventually selling (to Via) an automotive fleet management tech company called Fleetonomy. Yet Duanis still felt like there was something in security that he needed to do.
</p>

<p>
	 
</p>

<p>
	“When I looked at past 20 years I felt like ID has always been overlooked,” he said in an interview. At Checkpoint, he recalled, access mgmt and permissions were essentially IT issues, not security, “but so many attacks now are ID-driven.” A quick look at some of the most high-profile breaches of the last several years – Equifax, T-Mobile, Snowflake to name just a few – underscores how identity, specifically ungoverned credentials could be exploited by malicious haciers. “These were all credentials issues,” said Duanis.
</p>

<p>
	 
</p>

<p>
	Their bet was that a platform that could understand and fix this from the perspectives of compliance, security and efficiency “could create a real impact,” he said.
</p>

<p>
	 
</p>

<p>
	“Today identity is the new perimeter, and so you need to address that.”
</p>

<p>
	 
</p>

<p>
	Ultimately, the Rappaport Rapport – heh – was pretty strong. When Duanis told Assaf he was thinking about forming a startup to focus on ID management, Duanis tells me that it was Assaf who introduced him to Gili Raanan at Cyberstarts — kind of a kingmaker in Israeli cyber. The seed deal was done within 24 hours and thus Linx Security was born.
</p>

<p>
	 
</p>

<p>
	With Linx coming out of stealth only today, the company is not disclosing any names of customers, nor a huge amount of detail about how it works, but the basic idea goes a little something like this:
</p>

<p>
	 
</p>

<p>
	Organizations today typically use or have used hundreds, if not thousands, of different apps and software. Each will require user authentication to access, but when an app is no longer used regularly, or when workers come and go, a business might not comprehensively eliminate all of the identity information that comes with the waxing and waning of any particular app or worker.
</p>

<p>
	 
</p>

<p>
	Over time, the organization can start to accrue a massive stockpile of so-called ungoverned identity information, and that soon becomes a big liability: sitting there, ignored, until a malicious actor picks one up and uses it to access the whole system.
</p>

<p>
	 
</p>

<p>
	Linx’s approach is to use analytics and AI to scan and understand the wider landscape of an organization’s system to link (hence the name) all identities up together and to actual, active employees. In the process it also finds IDs that are no longer connected to active users so that they can be removed.
</p>

<p>
	 
</p>

<p>
	The resulting data then becomes a map that can be used to track the system over time, and thus when an ID is picked up and used unexpectedly, you’ll know it’s happening.
</p>

<p>
	 
</p>

<p>
	Although AI has quickly become a hackneyed and likely misused term in tech, Duanis said that Linx’s use of it is very targeted. “AI is overused as a term,” he admitted, “but I think that once you’re able to take the essence of [a network] and to be able to run [algorithms] very quickly on the development side, to use that power to provide suggestions and automations, I think that has created a real impact, and a place for a real change in the way that people manage today.” He said that typically the work that could have taken months to do to weed out ungoverned identities can now be done “in hours.”
</p>

<p>
	 
</p>

<p>
	Raanan at Cyberstarts made the deal to back Linx quickly because of how he could see the market evolving.
</p>

<p>
	 
</p>

<p>
	“Identity is the top threat vector for the modern enterprise,” he said in a statement. “Identity teams under the CISO, are struggling to cope with a growing number of tasks and suffer from antiquated legacy solutions.”
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://techcrunch.com/2024/07/22/linx-emerges-from-stealth-with-33m-to-lock-down-the-new-security-perimeter-identity/" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">24353</guid><pubDate>Mon, 22 Jul 2024 13:55:31 +0000</pubDate></item><item><title>Microsoft's EU agreement means it will be hard to avoid CrowdStrike-like calamities in the future</title><link>https://nsaneforums.com/news/security-privacy-news/microsofts-eu-agreement-means-it-will-be-hard-to-avoid-crowdstrike-like-calamities-in-the-future-r24351/</link><description><![CDATA[<p>
	<span style="font-size:18px;">Microsoft cannot block access to the Windows kernel because of an agreement it has with the EU.</span>
</p>

<p>
	 
</p>

<p>
	CrowdStrike's buggy software update and its kernel-level access to Windows lethally combined to cause the massive outage last week.
</p>

<p>
	 
</p>

<p>
	One of the ways that Microsoft could avoid this type of unfortunate event in the future is to restrict kernel access to third-party developers. However, the company cannot legally do this because of an understanding it struck with the EU in 2009. Thus, this type of outage that affected 8.5 million Windows devices could happen again, especially if it involves widely-used enterprise security software.
</p>

<p>
	 
</p>

<p>
	The Microsoft-EU agreement states that the former must make the Windows Client and Server operating system APIs that its security software, like Microsoft Defender for Endpoint uses, available to other developers. Neowin also said that the company must document the APIs it deploys on the Microsoft Developer Network unless they create security risks.
</p>

<p>
	 
</p>

<p>
	Microsoft made this move after a complaint was filed against it in Europe, and it allowed other vendors to create products that affect Windows at the kernel level. This agreement with the European Commission resulted in a freer market for security products and prevented Microsoft from gaining a monopoly on antivirus and other security suites.  
</p>

<p>
	 
</p>

<p>
	However, it also paved the way for the global CrowdStrike disaster that affected the world last week. Any error at the kernel level could potentially disable any operating system, that’s why Apple locked macOS and stopped giving developers access to its kernels. This move inherently hardens macOS from third-party software-induced crashes, as no one else but Apple can make changes to its kernel. However, it also meant that security providers had to revamp their apps to ensure they would continuously protect their clients, even without access to the kernel level of Macs, MacBooks, and iMacs.
</p>

<p>
	 
</p>

<p>
	Apple and Google still do not have an agreement with the European Commission regarding kernel-level access to their operating systems.
</p>

<p>
	 
</p>

<p>
	Nevertheless, this could change at any moment, especially as Europe has been wary about and making moves against big tech.
</p>

<p>
	 
</p>

<p>
	We cannot directly blame Microsoft or the EU for the CrowdStrike crash, especially as neither was at fault for the event. In the end, the event last week lies solely on the shoulders of CrowdStrike for releasing an unstable update without testing it first. As Microsoft said in its press release, "It's also a reminder of how important it is for all of us across the tech ecosystem to prioritize operating with safe deployment and disaster recovery using the mechanisms that exist."
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.tomshardware.com/software/windows/microsofts-eu-agreement-means-it-will-be-hard-to-avoid-crowdstrike-like-calamities-in-the-future" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">24351</guid><pubDate>Mon, 22 Jul 2024 13:45:26 +0000</pubDate></item><item><title>EU gave CrowdStrike the keys to the Windows kernel, claims Microsoft</title><link>https://nsaneforums.com/news/security-privacy-news/eu-gave-crowdstrike-the-keys-to-the-windows-kernel-claims-microsoft-r24350/</link><description><![CDATA[<p>
	<span style="font-size:18px;">Was a 2009 directive on interoperability to blame?</span>
</p>

<p>
	 
</p>

<p>
	Did the EU force Microsoft to let third parties like CrowdStrike run riot in the Windows kernel as a result of a 2009 undertaking? This is the implication being peddled by the Redmond-based cloud and software titan.
</p>

<p>
	 
</p>

<p>
	As the tech industry deals with the fallout from the CrowdStrike incident, Microsoft is facing questions. Why is software like CrowdStrike permitted to run at such a low level, where a failure could spell disaster for the operating system?
</p>

<p>
	 
</p>

<p>
	To be clear, Microsoft is not to blame for the now-pulled update that continues to cause chaos. However, the underlying architecture that allows third parties to run deeply integrated software merits closer examination.
</p>

<p>
	 
</p>

<p>
	According to a report in the Wall Street Journal, a Microsoft spokesperson pointed to a 2009 undertaking by the company with the European Commission as a reason why the Windows kernel was not as protected as that of the current Apple Mac operating system, for example.
</p>

<p>
	 
</p>

<p>
	The agreement [DOC] is about interoperability and came as Microsoft was subject to European scrutiny. The undertaking seeks a level playing field and includes the following clause:
</p>

<p>
	 
</p>

<p style="margin-left:40px;">
	<strong>Microsoft shall ensure on an ongoing basis and in a Timely Manner that the APIs in the Windows Client PC Operating System and the Windows Server Operating System that are called on by Microsoft Security Software Products are documented and available for use by third-party security software products that run on the Windows Client PC Operating System and/or the Windows Server Operating System.</strong>
</p>

<p>
	 
</p>

<p>
	In other words, third-party security vendors must get the same access as Microsoft's own products. Which, on the face of it, is fair enough.
</p>

<p>
	 
</p>

<p>
	However, nothing in that undertaking would have prevented Microsoft from creating an out-of-kernel API for it and other security vendors to use. Instead, CrowdStrike and its ilk run at a low enough level in the kernel to maximize visibility for anti-malware purposes. The flip side is this can cause mayhem should something go wrong.
</p>

<p>
	 
</p>

<p>
	The Register asked Microsoft if the position reported by the Wall Street Journal was still the company's stance on why a CrowdStrike update for Windows could cause the chaos it did. The company has yet to respond.
</p>

<p>
	 
</p>

<p>
	Windows is far from the only operating system that permits software to run at a level low enough to crash a kernel. However, failures of third-party software running at a low level in Windows can be embarrassingly public, even if Microsoft is not directly to blame. ®
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.theregister.com/2024/07/22/windows_crowdstrike_kernel_eu/" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">24350</guid><pubDate>Mon, 22 Jul 2024 13:42:31 +0000</pubDate></item><item><title>Microsoft blames EU rules for its inability to lock down Windows following CrowdStrike incident</title><link>https://nsaneforums.com/news/security-privacy-news/microsoft-blames-eu-rules-for-its-inability-to-lock-down-windows-following-crowdstrike-incident-r24349/</link><description><![CDATA[<p>
	Microsoft is reportedly analyzing whether restrictions enforced by the European Commission could be partly responsible for amplifying issues with Windows systems during the recent CrowdStrike outage incident.
</p>

<p>
	 
</p>

<p>
	The Wall Street Journal (WSJ) notes that in an intriguing point concerning the security of Windows operating systems, Microsoft’s spokesperson pointed out a 2009 agreement with the Commission prevented the company from enhancing the OS's security more rigorously.
</p>

<p>
	 
</p>

<p>
	The agreement came in response to a complaint, and required Microsoft to offer security software developers the same level of access to Windows as the company itself has.
</p>

<p>
	<br />
	<span style="font-size:22px;"><strong>Microsoft claims European Commission hinders security</strong></span>
</p>

<p>
	 
</p>

<p>
	The decision, intended to encourage competition, inadvertently allowed third-party vendors to disrupt systems.
</p>

<p>
	 
</p>

<p>
	The agreement specifies that Microsoft must share its APIs for Windows Client and Server operating systems with third-party security software developers, but last week’s incident highlighted the risks of such openness.
</p>

<p>
	 
</p>

<p>
	On the flip side, Apple has been restricting developers from kernel-level access to its OSs since 2020. Google is also not bound by similar regulations.
</p>

<p>
	 
</p>

<p>
	Despite the clear security benefits of an OS lock down, the EU is unlikely to grant Microsoft permission to restrict certain developer access given its previous decision. The Commission has also been keeping a close eye on Microsoft in recent months, with two major antitrust cases relating to the bundling of Teams within Microsoft 365 and the company’s cloud market dominance hitting the headlines.
</p>

<p>
	 
</p>

<p>
	Microsoft’s dissatisfaction with the European Commission comes days after a CrowdStrike update accidentally broke 8.5 million Windows PCs globally, which prompted Microsoft to intervene by giving affected users access to an auto-fix tool.
</p>

<p>
	 
</p>

<p>
	<em>TechRadar Pro</em> has offered Microsoft an opportunity to share further context, but the company did not immediately respond.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.techradar.com/pro/security/microsoft-blames-eu-rules-for-its-inability-to-lock-down-windows-following-crowdstrike-incident" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">24349</guid><pubDate>Mon, 22 Jul 2024 13:13:25 +0000</pubDate></item><item><title>What caused the great CrowdStrike-Windows meltdown of 2024? History has the answer</title><link>https://nsaneforums.com/news/security-privacy-news/what-caused-the-great-crowdstrike-windows-meltdown-of-2024-history-has-the-answer-r24345/</link><description><![CDATA[<p>
	<span style="font-size:20px;"><strong>When a trusted software provider delivers an update that causes PCs to immediately stop working across the world, chaos ensues. Last week's incident wasn't the first such event. Here's how to make sure it doesn't happen again. </strong></span>
</p>

<p>
	 
</p>

<p>
	Microsoft Windows powers more than a billion PCs and millions of servers worldwide, many of them playing key roles in facilities that serve customers directly. So, what happens when a trusted software provider delivers an update that causes those PCs to immediately stop working?
</p>

<p>
	 
</p>

<p>
	As of July 19, 2024, we know the answer to that question: Chaos ensues.
</p>

<p>
	 
</p>

<p>
	In this case, the trusted software developer is a firm called CrowdStrike Holdings, whose previous claim to fame was being the security firm that analyzed the 2016 hack of servers owned by the Democratic National Committee. That's just a quaint memory now, as the firm will forever be known as The Company That Caused The Largest IT Outage In History. It grounded airplanes, cut off access to some banking systems, disrupted major healthcare networks, and threw at least one news network off the air.
</p>

<p>
	 
</p>

<p>
	Microsoft estimates that the CrowdStrike update affected 8.5 million Windows devices. That's a tiny percentage of the worldwide installed base, but as David Weston, Microsoft's Vice President for Enterprise and OS Security, notes, "the broad economic and societal impacts reflect the use of CrowdStrike by enterprises that run many critical services." According to a Reuters report, "Over half of Fortune 500 companies and many government bodies such as the top U.S. cybersecurity agency itself, the Cybersecurity and Infrastructure Security Agency, use the company's software."
</p>

<p>
	<br />
	<span style="font-size:24px;"><strong>What happened?</strong></span>
</p>

<p>
	 
</p>

<p>
	CrowdStrike, which sells security software designed to keep systems safe from external attacks, pushed a faulty "sensor configuration update" to the millions and millions of PCs worldwide running its Falcon Sensor software. That update was, according to CrowdStrike, a "Channel File" whose function was to identify newly observed, malicious activity by cyberattackers.
</p>

<p>
	 
</p>

<p>
	Although the update file had a .sys extension, it was not itself a kernel driver. But it communicates with other components in the Falcon sensor that run in the same space as the Windows kernel, the most privileged level on a Windows PC, where they interact directly with memory and hardware. CrowdStrike says a "logic error" in that code caused Windows PCs and servers to crash within seconds after they booted up, displaying a STOP error, more colloquially known as the Blue Screen of Death.
</p>

<p>
	 
</p>

<p>
	Repairing the damage from a flaw like this is a painfully tedious process that requires manually rebooting every affected PC into the Windows Recovery Environment and then deleting the defective file from the PC using the old-school command line interface. And if the PC in question has its system drive protected by Microsoft's BitLocker encryption software, as virtually all business PCs do, the fix requires one extra step: entering a unique 48-character BitLocker recovery key to gain access to the drive and allow removal of the faulty CrowdStrike driver.
</p>

<p>
	 
</p>

<p>
	If you know anyone whose job involves administering Windows PCs in a corporate network that uses the CrowdStrike code, you can be confident they are very busy right now, and will be for days to come.
</p>

<p>
	<br />
	<span style="font-size:24px;"><strong>We've seen this movie before</strong></span>
</p>

<p>
	 
</p>

<p>
	When I first heard about this catastrophe (and I am not misusing that word, I assure you), I thought it sounded familiar. On Reddit's Sysadmin Subreddit, user u/externedguy reminded me why. Maybe you remember this story from 14 years ago:
</p>

<p>
	 
</p>

<p style="margin-left:40px;">
	<strong>"Defective McAfee update causes worldwide meltdown of XP PCs."</strong>
</p>

<p style="margin-left:40px;">
	 
</p>

<p style="margin-left:40px;">
	<strong>Oops, they did it again.</strong>
</p>

<p style="margin-left:40px;">
	 
</p>

<p style="margin-left:40px;">
	<strong>At 6AM today, McAfee released an update to its antivirus definitions for corporate customers that had a slight problem. And by "slight problem," I mean the kind that renders a PC useless until tech support shows up to repair the damage manually. As I commented on Twitter earlier today, I'm not sure any virus writer has ever developed a piece of malware that shut down as many machines as quickly as McAfee did today.</strong>
</p>

<p>
	 
</p>

<p>
	In that case, McAfee had delivered a faulty virus definition (DAT) file to PCs running Windows XP. That file falsely detected a crucial Windows system file, Svchost.exe, as a virus and deleted it. The result, according to a contemporary report, is that "affected systems will enter a reboot loop and [lose] all network access."
</p>

<p>
	 
</p>

<p>
	The parallels between that 2010 incident and this year's CrowdStrike outage are uncanny. At its core was a defective update, pushed to millions of PCs running a powerful software agent, causing the affected devices to stop working. Recovery required manual intervention on every single device. And the flawed code was pushed out by a public company desperately trying to grow in a brutally competitive marketplace.
</p>

<p>
	 
</p>

<p>
	The timing was particularly unfortunate for McAfee. Intel had announced its intention to acquire McAfee, Inc. for $7.68 billion on April 19, 2010. The defective DAT file was released two days later, on April 21.
</p>

<p>
	 
</p>

<p>
	That 2010 McAfee screw-up was a big deal, kneecapping Fortune 500 companies (including Intel!) as well as universities and government/military deployments worldwide. It knocked 10% of the cash registers at Australia's largest grocery chain offline, forcing the closure of 14-18 stores.
</p>

<p>
	 
</p>

<p>
	And in the You Can't Make This Up Department… CrowdStrike's founder and CEO, George Kurtz, was McAfee's Chief Technology Officer during that 2010 incident.
</p>

<p>
	 
</p>

<p>
	What makes the 2024 sequel so much worse is that it also affected Windows-based servers running in the cloud, on Microsoft's Azure and on Amazon's AWS. And just as with the many laptops and desktop PCs that were bricked by this faulty update, the cloud-based servers require time-consuming manual interventions to recover.
</p>

<p>
	<br />
	<span style="font-size:24px;"><strong>CrowdStrike's QA failed</strong></span>
</p>

<p>
	 
</p>

<p>
	Surprisingly, this isn't the first faulty Falcon Sensor update from CrowdStrike this year.
</p>

<p>
	 
</p>

<p>
	Less than a month earlier, according to a report from The Stack, CrowdStrike released a detection logic update for the Falcon sensor that exposed a bug in the sensor's Memory Scanning feature. "The result of the bug," CrowdStrike wrote in a customer advisory, "is a logic error in the CsFalconService that can cause the Falcon sensor for Windows to consume 100% of a single CPU core." The company rolled back the update, and customers were able to resume normal operations by rebooting.
</p>

<p>
	 
</p>

<p>
	At the time, computer security expert Will Thomas noted on X/Twitter, "[T]his just goes to show how important it is to download new updates to 1 machine to test it first before rolling out to the whole fleet!"
</p>

<p>
	 
</p>

<p>
	In that 2010 incident, the root cause turned out to be a complete breakdown of the QA process. It seems self-evident that a similar failure in QA is at work here. Were these two CrowdStrike updates not tested before they were pushed out to millions of devices?
</p>

<p>
	 
</p>

<p>
	Part of the problem might be a company culture that's long on tough talk. In the most recent CrowdStrike earnings call, CEO George Kurtz boasted about the company's ability to "ship game-changing products at rapid pace," taking special aim at Microsoft:
</p>

<p>
	 
</p>

<p style="margin-left:40px;">
	<strong>And more recently, following yet another major Microsoft breach in CIS' Cyber Safety Review Board's findings, we received an outpouring of requests from the market for help. We decided enough is enough, there's a widespread crisis of confidence among security and IT teams within the Microsoft security customer base.</strong>
</p>

<p style="margin-left:40px;">
	 
</p>

<p style="margin-left:40px;">
	<strong>[…]</strong>
</p>

<p style="margin-left:40px;">
	 
</p>

<p style="margin-left:40px;">
	<strong>Feedback has been overwhelmingly positive. CISAs now have the ability to reduce monoculture risk from only using Microsoft products and cloud services. Our innovation continues at breakneck pace multiplying the reasons for the market to consolidate on Falcon. Thousands of organizations are consolidating on the Falcon platform.</strong>
</p>

<p>
	 
</p>

<p>
	Given recent events, some of those customers might be wondering whether that "breakneck pace" is part of the problem.
</p>

<p>
	<br />
	<span style="font-size:24px;"><strong>How much fault should Microsoft shoulder?</strong></span>
</p>

<p>
	 
</p>

<p>
	It's impossible to let Microsoft completely off the hook. After all, the Falcon sensor problems were unique to Windows PCs, as admins in Linux and Mac-focused shops were quick to remind us.
</p>

<p>
	 
</p>

<p>
	Partly, that's an architectural issue. Developers of system-level apps for Windows, including security software, historically implement their features using kernel extensions and drivers. As this example illustrates, faulty code running in the kernel space can cause unrecoverable crashes, whereas code running in user space can't.
</p>

<p>
	 
</p>

<p>
	That used to be the case with MacOS as well, but in 2020, with MacOS 11, Apple changed the architecture of its flagship OS to strongly discourage the use of kernel extensions. Instead, developers are urged to write system extensions that run in user space rather than at the kernel level. On MacOS, CrowdStrike uses Apple's Endpoint Security Framework and says using that design, "Falcon achieves the same levels of visibility, detection, and protection exclusively via a user space sensor."
</p>

<p>
	 
</p>

<p>
	Could Microsoft make the same sort of change for Windows? Perhaps, but doing so would certainly bring down the wrath of antitrust regulators, especially in Europe. The problem is especially acute because Microsoft has a lucrative enterprise security business, and any architectural change that makes life more difficult for competitors like CrowdStrike would be rightly seen as anticompetitive. Indeed, a Microsoft spokesperson told the Wall Street Journal that it can't follow Apple's lead because of antitrust concerns. According to the WSJ report, "In 2009, Microsoft agreed it would give makers of security software the same level of access to Windows that Microsoft gets."
</p>

<p>
	 
</p>

<p>
	That concern might be open for debate, but given Microsoft's history with EU regulators, it's understandable why they haven't wanted to get tangled up in that argument.
</p>

<p>
	 
</p>

<p>
	Microsoft currently offers APIs for Microsoft Defender for Endpoint, but competitors aren't likely to use them. They'd much rather argue that their software is superior, and using the "inferior" offering from Microsoft would be hard to explain to customers.
</p>

<p>
	 
</p>

<p>
	But this incident, which caused many billions of dollars' worth of damage, should be a wake-up call for the entire IT community. At a minimum, CrowdStrike needs to step up its testing game. And customers need to be more cautious about allowing this sort of code to deploy on their networks without testing it themselves.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.zdnet.com/article/what-caused-the-great-crowdstrike-windows-meltdown-of-2024-history-has-the-answer/" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">24345</guid><pubDate>Mon, 22 Jul 2024 12:47:26 +0000</pubDate></item><item><title>Two Russians sanctioned over cyberattacks on US critical infrastructure</title><link>https://nsaneforums.com/news/security-privacy-news/two-russians-sanctioned-over-cyberattacks-on-us-critical-infrastructure-r24344/</link><description><![CDATA[<p>
	<span style="font-size:20px;">Supposed hacktivist efforts previously linked to the Kremlin's GRU</span>
</p>

<p>
	 
</p>

<p>
	Flying under the radar on Clownstrike day last week, two members of the Cyber Army of Russia Reborn (CARR) hacktivist crew are the latest additions to the US sanctions list.
</p>

<p>
	 
</p>

<p>
	Yuliya Vladimirovna Pankratova and Denis Olegovich Degtyarenko, named by the US government as CARR's leader and attacker-in-chief respectively, were designated for their alleged roles in attacks on US critical national infrastructure.
</p>

<p>
	 
</p>

<p>
	Despite much of CARR's work since its inception in 2022 revolving around what the US Department of the Treasury describes as "low-impact, unsophisticated DDoS attacks in Ukraine," the group was blamed for various attacks on US and European water facilities earlier this year.
</p>

<p>
	 
</p>

<p>
	Back in January, CARR claimed responsibility for attacks on human-machine interfaces (HMIs) controlling OT systems in the US and Poland via its Telegram channel. Water supply, hydroelectric, wastewater, and energy facilities were affected by the remote manipulation of controls, which also led to the overflowing of water storage tanks in Abernathy and Muleshoe, Texas. Tens of thousands of gallons of water were lost, officials said.
</p>

<p>
	 
</p>

<p>
	CARR is also said to be responsible for an attack on a US energy company's SCADA system, which handed them control of arms and pumps connected to tanks, the Treasury said.
</p>

<p>
	 
</p>

<p>
	"Despite CARR briefly gaining control of these industrial control systems, instances of major damage to victims have thus far been avoided due to CARR's lack of technical sophistication," the announcement reads.
</p>

<p>
	 
</p>

<p>
	Specifically, this is alleged to be the work of Degtyarenko, a Russian national who also developed training materials for compromising SCADA systems.
</p>

<p>
	 
</p>

<p>
	Mandiant previously attributed these attacks to Sandworm – an offensive cyber unit inside Russia's military intelligence arm, GRU. A report from the infosec giant in April said CARR was just one of the many Telegram accounts Sandworm used to publicize its attacks, but the US hasn't explicitly made these links in announcing Pankratova and Degtyarenko's designation.
</p>

<p>
	 
</p>

<p>
	As is often the case when sanctioning Russian cybercriminals, it becomes illegal to do business with the pair, although arresting the individuals is unlikely as Russia would never give up its assets in cyberspace to an adversary.
</p>

<p>
	 
</p>

<p>
	"CARR and its members' efforts to target our critical infrastructure represent an unacceptable threat to our citizens and our communities, with potentially dangerous consequences," said Brian E Nelson, Under Secretary of the Treasury for Terrorism and Financial Intelligence.
</p>

<p>
	"The United States has and will continue to take action, using our full range of tools, to hold accountable these and other individuals for their malicious cyber activities."
</p>

<p>
	 
</p>

<p>
	Although the US may never get its hands on the CARR pair, they will remain on allied watchlists forever more, which means arrests further down the line can't be ruled out.
</p>

<p>
	 
</p>

<p>
	Even the most prolific and successful cybercriminals in Russia sometimes let their guard down. For example, Mikhail Vasiliev, a 34-year-old former LockBit affiliate dual national of Canada and Russia, was arrested in 2022 after entering Canada on a trip – away from the Kremlin's protection.
</p>

<p>
	 
</p>

<p>
	Earlier this year he was sentenced to four years in prison for ransomware crimes and last week pleaded guilty to further charges brought to him in New Jersey.
</p>

<p>
	 
</p>

<p>
	Alongside Vasiliev was fellow LockBit affiliate Ruslan Magomedovich Astamirov. The 21-year-old admitted to two counts related to computer abuse and wire fraud, and faces a maximum sentence of 25 years. Sentencing dates for both criminals are yet to be set.
</p>

<p>
	 
</p>

<p>
	"Between 2021 and 2023, Vasiliev… deployed LockBit against at least 12 victims, including businesses in New Jersey, Michigan, the United Kingdom, and Switzerland," said the Department of Justice. "He also deployed LockBit against an educational facility in England and a school in Switzerland. Through these attacks, Vasiliev caused at least $500,000 in damage and losses to his victims."
</p>

<p>
	 
</p>

<p>
	"The defendants committed ransomware attacks against victims in the United States and around the world through LockBit, which was one of the most destructive ransomware groups in the world," said principal deputy assistant attorney General Nicole M Argentieri, head of the Justice Department's Criminal Division.
</p>

<p>
	 
</p>

<p>
	"But thanks to the work of the Computer Crime and Intellectual Property Section, along with its domestic and international partners, LockBit no longer claims that title. Today's convictions represent another important milestone in the Criminal Division's ongoing effort to disrupt and dismantle ransomware groups, protect victims, and bring cybercriminals to justice."
</p>

<p>
	 
</p>

<p>
	"Two members of the LockBit affiliate pleading guilty to their crimes in US federal court illustrate we can stop them and bring them to justice," said James E Dennehy, special agent in charge at FBI Newark. "These malicious actors believe they can operate with impunity – and don't fear getting caught because they sit in a country where they feel safe and protected. FBI Newark and our law enforcement partners around the globe have the technology and intelligence to go after these criminals – regardless of where they hide." ®
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.theregister.com/2024/07/22/russians_sanctioned_over_cyberattacks/" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">24344</guid><pubDate>Thu, 01 Jan 1970 00:00:00 +0000</pubDate></item><item><title>Cybercriminals Exploit CrowdStrike Update Mishap to Distribute Remcos RAT Malware</title><link>https://nsaneforums.com/news/security-privacy-news/cybercriminals-exploit-crowdstrike-update-mishap-to-distribute-remcos-rat-malware-r24341/</link><description><![CDATA[<p>
	Cybersecurity firm CrowdStrike, which is facing the heat for causing worldwide IT disruptions by pushing out a flawed update to Windows devices, is now warning that threat actors are exploiting the situation to distribute Remcos RAT to its customers in Latin America under the guise of providing a hotfix.
</p>

<p>
	 
</p>

<p>
	The attack chains involve distributing a ZIP archive file named "crowdstrike-hotfix.zip," which contains a malware loader named Hijack Loader (aka DOILoader or IDAT Loader) that, in turn, launches the Remcos RAT payload.
</p>

<p>
	 
</p>

<p>
	Specifically, the archive file also includes a text file ("instrucciones.txt") with Spanish-language instructions that urges targets to run an executable file ("setup.exe") to recover from the issue.
</p>

<p>
	 
</p>

<p>
	"Notably, Spanish filenames and instructions within the ZIP archive indicate this campaign is likely targeting Latin America-based (LATAM) CrowdStrike customers," the company said, attributing the campaign to a suspected e-crime group.
</p>

<p>
	 
</p>

<p>
	On Friday, CrowdStrike acknowledged that a routine sensor configuration update pushed to its Falcon platform for Windows devices on July 19 at 04:09 UTC inadvertently triggered a logic error that resulted in a Blue Screen of Death (BSoD), rendering numerous systems inoperable and sending businesses into a tailspin.
</p>

<p>
	 
</p>

<p>
	The event impacted customers running Falcon sensor for Windows version 7.11 and above, who were online between 04:09 and 05:27 a.m. UTC.
</p>

<p>
	 
</p>

<p>
	Malicious actors have wasted no time capitalizing on the chaos created by the event to set up typosquatting domains impersonating CrowdStrike and advertise services to companies affected by the issue in return for a cryptocurrency payment.
</p>

<p>
	 
</p>

<p>
	Customers who are impacted are recommended to "ensure they are communicating with CrowdStrike representatives through official channels and adhere to technical guidance the CrowdStrike support teams have provided."
</p>

<p>
	 
</p>

<p>
	Microsoft, which has been engaging with CrowdStrike in remediation efforts, said the digital meltdown crippled 8.5 million Windows devices globally, or less than one percent of all Windows machines.
</p>

<p>
	 
</p>

<p>
	The development – which has once again brought to fore the risks associated with relying on monocultural supply chains – marks the first time the true impact and scale of what's likely to be the most disruptive cyber event in history has been officially made public. Mac and Linux devices were not affected by the outage.
</p>

<p>
	 
</p>

<p>
	"This incident demonstrates the interconnected nature of our broad ecosystem — global cloud providers, software platforms, security vendors and other software vendors, and customers," the tech giant said. "It’s also a reminder of how important it is for all of us across the tech ecosystem to prioritize operating with safe deployment and disaster recovery using the mechanisms that exist."
</p>

<p>
	<br />
	<span style="font-size:20px;"><strong>Update</strong></span>
</p>

<p>
	 
</p>

<p>
	Microsoft has made available a new recovery tool to help IT admins repair Windows machines that were impacted by CrowdStrike's faulty update that crashed 8.5 million Windows devices.
</p>

<p>
	 
</p>

<p>
	CrowdStrike has also published a new Remediation and Guidance Hub that serves as a one-stop shop for all details pertaining to the incident, listing ways to identify impacted hosts and resolve them, including those that have been encrypted with BitLocker.
</p>

<p>
	 
</p>

<p>
	The move comes as reports have since emerged of CrowdStrike updates that caused all Debian Linux servers in an unnamed civic tech lab to crash simultaneously and refuse to boot as well as trigger kernel panics in Red Hat and Rocky Linux distributions.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://thehackernews.com/2024/07/cybercriminals-exploit-crowdstrike.html" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">24341</guid><pubDate>Mon, 22 Jul 2024 12:13:49 +0000</pubDate></item><item><title>New Linux Variant of Play Ransomware Targeting VMware ESXi Systems</title><link>https://nsaneforums.com/news/security-privacy-news/new-linux-variant-of-play-ransomware-targeting-vmware-esxi-systems-r24340/</link><description><![CDATA[<p>
	Cybersecurity researchers have discovered a new Linux variant of a ransomware strain known as Play (aka Balloonfly and PlayCrypt) that's designed to target VMware ESXi environments.
</p>

<p>
	 
</p>

<p>
	"This development suggests that the group could be broadening its attacks across the Linux platform, leading to an expanded victim pool and more successful ransom negotiations," Trend Micro researchers said in a report published Friday.
</p>

<p>
	 
</p>

<p>
	Play, which arrived on the scene in June 2022, is known for its double extortion tactics, encrypting systems after exfiltrating sensitive data and demanding payment in exchange for a decryption key. According to estimates released by Australia and the U.S., as many as 300 organizations have been victimized by the ransomware group as of October 2023.
</p>

<p>
	 
</p>

<p>
	Statistics shared by Trend Micro for the first seven months of 2024 show that the U.S. is the country with the highest number of victims, followed by Canada, Germany, the U.K., and the Netherlands.
</p>

<p>
	 
</p>

<p>
	Manufacturing, professional services, construction, IT, retail, financial services, transportation, media, legal services, and real estate are some of the top industries affected by the Play ransomware during the time period.
</p>

<p>
	 
</p>

<p>
	The cybersecurity firm's analysis of a Linux variant of Play comes from a RAR archive file hosted on an IP address (108.61.142[.]190), which also contains other tools identified as utilized in previous attacks such as PsExec, NetScan, WinSCP, WinRAR, and the Coroxy backdoor.
</p>

<p>
	 
</p>

<p>
	"Though no actual infection has been observed, the command-and-control (C&amp;C) server hosts the common tools that Play ransomware currently uses in its attacks," it said. "This could denote that the Linux variant might employ similar tactics, techniques, and procedures (TTPs)."
</p>

<p>
	 
</p>

<p>
	The ransomware sample, upon execution, ensures that it's running in an ESXi environment before proceeding to encrypt virtual machine (VM) files, including VM disk, configuration, and metadata files, and appending them with the extension ".PLAY." A ransom note is then dropped in the root directory.
</p>

<p>
	 
</p>

<p>
	Further analysis has determined that the Play ransomware group is likely using the services and infrastructure peddled by Prolific Puma, which offers an illicit link-shortening service to other cybercriminals to help them evade detection while distributing malware.
</p>

<p>
	 
</p>

<p style="text-align:center;">
	<img alt="dga.png" class="ipsImage" data-ratio="45.14" height="321" width="720" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj5KK90o_FpqxcfckghxWZVXnlmypHSXdOGiBl4uAXFBcHu7F_Gap9nVr1t5jVZfBdYP7rOg79nVDIMXr5JagIPAc5Jzg5oiWC0ASuyNarir0b6b2GywoH7KEVF0lmGJHr1YBPQ_NVFHjsdBJskJPBzvqV3SuIzDyjx8hWlIdz8krH4IjigzIFhovbYQoOo/s728-rw-e365/dga.png" />
</p>

<p style="text-align:center;">
	 
</p>

<p>
	Specifically, it employs what's called a registered domain generation algorithm (RDGA) to spin up new domain names, a programmatic mechanism that's increasingly being used by several threat actors, including VexTrio Viper and Revolver Rabbit, for phishing, spam, and malware propagation.
</p>

<p>
	 
</p>

<p>
	Revolver Rabbit, for instance, is believed to have registered over 500,000 domains on the ".bond" top-level domain (TLD) at an approximate cost of more than $1 million, leveraging them as active and decoy C2 servers for the XLoader (aka FormBook) stealer malware.
</p>

<p>
	 
</p>

<p>
	"The most common RDGA pattern this actor uses is a series of one or more dictionary words followed by a five-digit number, with each word or number separated by a dash," Infoblox noted in a recent analysis. "Sometimes the actor uses ISO 3166-1 country codes, full country names, or numbers corresponding to years instead of dictionary words."
</p>

<p>
	 
</p>

<p>
	RDGAs are a lot more challenging to detect and defend against than traditional DGAs owing to the fact that they allow threat actors to generate many domain names to register them for use – either all at once or over time – in their criminal infrastructure.
</p>

<p>
	 
</p>

<p>
	"In an RDGA, the algorithm is a secret kept by the threat actor, and they register all the domain names," Infoblox said. "In a traditional DGA, the malware contains an algorithm that can be discovered, and most of the domain names will not be registered. While DGAs are used exclusively for connection to a malware controller, RDGAs are used for a wide range of malicious activity."
</p>

<p>
	 
</p>

<p>
	The latest findings indicate a potential collaboration between two cybercriminal entities, suggesting that the Play ransomware actors are taking steps to bypass security protocols through Prolific Puma's services.
</p>

<p>
	 
</p>

<p>
	"ESXi environments are high-value targets for ransomware attacks due to their critical role in business operations," Trend Micro concluded. "The efficiency of encrypting numerous VMs simultaneously and the valuable data they hold further elevate their lucrativeness for cybercriminals."
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://thehackernews.com/2024/07/new-linux-variant-of-play-ransomware.html" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">24340</guid><pubDate>Mon, 22 Jul 2024 12:09:33 +0000</pubDate></item><item><title>SocGholish Malware Exploits BOINC Project for Covert Cyberattacks</title><link>https://nsaneforums.com/news/security-privacy-news/socgholish-malware-exploits-boinc-project-for-covert-cyberattacks-r24339/</link><description><![CDATA[<p>
	The JavaScript downloader malware known as SocGholish (aka FakeUpdates) is being used to deliver a remote access trojan called AsyncRAT as well as a legitimate open-source project called BOINC.
</p>

<p>
	 
</p>

<p>
	BOINC, short for Berkeley Open Infrastructure Network Computing Client, is an open-source "volunteer computing" platform maintained by the University of California with an aim to carry out "large-scale distributed high-throughput computing" using participating home computers on which the app is installed.
</p>

<p>
	 
</p>

<p>
	"It's similar to a cryptocurrency miner in that way (using computer resources to do work), and it's actually designed to reward users with a specific type of cryptocurrency called Gridcoin, designed for this purpose," Huntress researchers Matt Anderson, Alden Schmidt, and Greg Linares said in a report published last week.
</p>

<p>
	 
</p>

<p>
	These malicious installations are designed to connect to an actor-controlled domain ("rosettahome[.]cn" or "rosettahome[.]top"), essentially acting as a command-and-control (C2) server to collect host data, transmit payloads, and push further commands. As of July 15, 10,032 clients are connected to the two domains.
</p>

<p>
	 
</p>

<p>
	The cybersecurity firm said while it hasn't observed any follow-on activity or tasks being executed by the infected hosts, it hypothesized that the "host connections could be sold off as initial access vectors to be used by other actors and potentially used to execute ransomware."
</p>

<p>
	 
</p>

<p>
	SocGholish attack sequences typically begin when users land on compromised websites, where they are prompted to download a fake browser update that, upon execution, triggers the retrieval of additional payloads to the infiltrated machines.
</p>

<p>
	 
</p>

<p>
	The JavaScript downloader, in this case, activates two disjointed chains, one that leads to the deployment of a fileless variant of AsyncRAT and the other resulting in the BOINC installation.
</p>

<p>
	 
</p>

<p style="text-align:center;">
	<img alt="hacked.png" class="ipsImage" data-ratio="47.50" height="338" width="720" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhdlhFKC9vGAqozrYXHI2WQ-1bPtIHwxcwAez81gyMt-85jkz0_dNjEh7eO8i_Cszem-CHZXfw10odmfOmJscmW7R2aYJDy_gFOa-RhSXjTXHSfXx156IqwVFllzsZdSz8yCLVZbUS_LBhjV9N0wiKndt71uuQwsWuWdF_R6-kttPFCAmEAylfvDdoBu63I/s728-rw-e365/hacked.png" />
</p>

<p>
	 
</p>

<p>
	The BOINC app, which is renamed as "SecurityHealthService.exe" or "trustedinstaller.exe" to evade detection, sets persistence using a scheduled task by means of a PowerShell script.
</p>

<p>
	 
</p>

<p>
	The misuse of BOINC for malicious purposes hasn't gone unnoticed by the project maintainers, who are currently investigating the problem and finding a way to "defeat this malware." Evidence of the abuse dates back to at least June 26, 2024.
</p>

<p>
	 
</p>

<p>
	"The motivation and intent of the threat actor by loading this software onto infected hosts isn't clear at this point," the researchers said.
</p>

<p>
	 
</p>

<p>
	"Infected clients actively connecting to malicious BOINC servers present a fairly high risk, as there's potential for a motivated threat actor to misuse this connection and execute any number of malicious commands or software on the host to further escalate privileges or move laterally through a network and compromise an entire domain."
</p>

<p>
	 
</p>

<p>
	The development comes as Check Point said it's been tracking the use of compiled V8 JavaScript by malware authors to sidestep static detections and conceal remote access trojans, stealers, loaders, cryptocurrency miners, wipers, and ransomware.
</p>

<p>
	 
</p>

<p>
	"In the ongoing battle between security experts and threat actors, malware developers keep coming up with new tricks to hide their attacks," security researcher Moshe Marelus said. "It's not surprising that they've started using V8, as this technology is commonly used to create software as it is very widespread and extremely hard to analyze."
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://thehackernews.com/2024/07/socgholish-malware-exploits-boinc.html" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">24339</guid><pubDate>Mon, 22 Jul 2024 12:07:10 +0000</pubDate></item><item><title>CrowdStrike's Falcon Sensor also linked to Linux kernel panics and crashes</title><link>https://nsaneforums.com/news/security-privacy-news/crowdstrikes-falcon-sensor-also-linked-to-linux-kernel-panics-and-crashes-r24337/</link><description><![CDATA[<p>
	<span style="font-size:20px;">Rapid restore tool being tested as Microsoft estimates 8.5 million machines went down</span>
</p>

<p>
	 
</p>

<p>
	CrowdStrike's now-infamous Falcon Sensor software, which last week led to widespread outages of Windows-powered computers, has also caused crashes of Linux machines.
</p>

<p>
	 
</p>

<p>
	Red Hat in June warned its customers of a problem it described as "Kernel panic observed after booting 5.14.0-427.13.1.el9_4.x86_64 by falcon-sensor process" that impacted some users of Red Hat Enterprise Linux 9.4 after (as the warning suggests) booting on kernel version 5.14.0-427.13.1.el9_4.x86_64.
</p>

<p>
	 
</p>

<p>
	A second issue titled "System crashed at cshook_network_ops_inet6_sockraw_release+0x171a9" advised users "for assistance with troubleshooting potential issues with the falcon_lsm_serviceable kernel module provided from the CrowdStrike Falcon Sensor/Agent security software suite." Red Hat also advised that "disabling the CrowdStrike Falcon Sensor/Agent software suite … will mitigate the crashes and provide temporary stability to the system in question while the issue is investigated." The issue was "Observed but not limited to release 6 and 7."
</p>

<p>
	 
</p>

<p>
	Linux Kernel panics and Windows Blue Screens of Death are broadly comparable. The occurrence of kernel panics mere weeks before CrowdStrike broke many Windows implementations therefore hints at wider issues at the security vendor.
</p>

<p>
	 
</p>

<p>
	The Register has asked CrowdStrike to comment on the issues identified by Red Hat, and will update this story if we receive substantial information.
</p>

<p>
	 
</p>

<p>
	<span style="font-size:18px;"><strong>Rapid restore tool on the way</strong></span>
</p>

<p>
	 
</p>

<p>
	CrowdStrike on Sunday teased a rapid recovery tool for the mess it made.
</p>

<p>
	 
</p>

<p>
	"Together with customers, we tested a new technique to accelerate impacted system remediation," the security vendor stated on LinkedIn, adding "We're in the process of operationalizing an opt-in to this technique. We're making progress by the minute."
</p>

<p>
	 
</p>

<p>
	That progress will likely be of great interest, as Microsoft veep for enterprise and OS security David Weston on Saturday estimated that 8.5 million Windows machines had been laid low by the problem.
</p>

<p>
	 
</p>

<p>
	Microsoft also created a repair tool that runs from a bootable USB storage device and can be found here, along with instructions for use. Those instructions were modified on Sunday to require a full wipe of the USB device "so it doesn't error out when used in the recovery process."
</p>

<p>
	 
</p>

<p>
	CrowdStrike published technical details of the incident. It has also offered guidance on how to recover Windows machines encrypted with BitLocker.
</p>

<p>
	 
</p>

<p>
	<span style="font-size:18px;"><strong>Up in the air</strong></span>
</p>

<p>
	 
</p>

<p>
	The extent of disruption caused by CrowdStrike remains uncertain, but we've read accounts of over 6,800 flights cancelled last Friday alone, and of some airlines only restoring systems on Sunday evening.
</p>

<p>
	 
</p>

<p>
	The British Medical Association has warned that "normal service cannot be resumed immediately" due to the backlog caused by the outage.
</p>

<p>
	 
</p>

<p>
	Australia's home affairs minister Claire O'Neill has warned that remediation could take weeks.
</p>

<p>
	 
</p>

<p>
	This remains a developing story: The Register will update this item, or write others, as further info emerges. ®
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.theregister.com/2024/07/21/crowdstrike_linux_crashes_restoration_tools/" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">24337</guid><pubDate>Mon, 22 Jul 2024 00:09:14 +0000</pubDate></item><item><title>Cybercriminals exploit CrowdStrike chaos to spread Crowdstrike-hotfix.zip malware</title><link>https://nsaneforums.com/news/security-privacy-news/cybercriminals-exploit-crowdstrike-chaos-to-spread-crowdstrike-hotfixzip-malware-r24336/</link><description><![CDATA[<p>
	On Thursday, cybersecurity company CrowdStrike released a problematic update to its Falcon Sensor agent on Windows, causing major disruptions to the day-to-day operations of various organizations, including banks, airlines, and media companies. This problematic update caused nearly 8.5 million Windows PCs to continuously reboot with error code 0x50 or 0x7E Blue Screen of Death (BSOD) errors.
</p>

<p>
	Since then, CrowdStrike and Microsoft have provided guidance to affected customers to recover their PCs. You can check out CrowdStrike's official guide here and Microsoft's official guide here.
</p>

<p>
	 
</p>

<p>
	While the world scrambles to fix the CrowdStrike-affected PCs, cybercriminals are taking advantage of this critical situation. CrowdStrike noticed that cybercriminals are distributing a malicious ZIP archive named crowdstrike-hotfix.zip (SHA256 hash: c44506fe6e1ede5a104008755abf5b6ace51f1a84ad656a2dccc7f2c39c0eca2).
</p>

<p>
	 
</p>

<p>
	The crowdstrike-hotfix.zip archive is malware and contains a HijackLoader payload that loads RemCos. CrowdStrike believes that the Spanish filenames and instructions within the ZIP archive indicate this campaign likely targets Latin America-based (LATAM) CrowdStrike customers.
</p>

<p>
	 
</p>

<p>
	In addition to the malware campaign, cybercriminals are also targeting CrowdStrike customers with phishing campaigns. They are sending phishing emails posing as CrowdStrike support, impersonating CrowdStrike employees in phone calls, posing as independent researchers to offer remediation insights, and even selling scripts to automate recovery from the CrowdStrike update issue.
</p>

<p>
	 
</p>

<p>
	The following malicious domains were recently created for phishing campaigns:
</p>

<p>
	 
</p>

<p>
	crowdstrike.phpartners[.]org crowdstrike0day[.]com crowdstrikebluescreen[.]com
</p>

<p>
	crowdstrike-bsod[.]com crowdstrikeupdate[.]com crowdstrikebsod[.]com
</p>

<p>
	www.crowdstrike0day[.]com www.fix-crowdstrike-bsod[.]com
</p>

<p>
	crowdstrikeoutage[.]info www.microsoftcrowdstrike[.]com crowdstrikeodayl[.]com
</p>

<p>
	crowdstrike[.]buzz www.crowdstriketoken[.]com www.crowdstrikefix[.]com fix-
</p>

<p>
	crowdstrike-apocalypse[.]com microsoftcrowdstrike[.]com crowdstrikedoomsday[.]com crowdstrikedown[.]com whatiscrowdstrike[.]com crowdstrike-helpdesk[.]com crowdstrikefix[.]com fix-crowdstrike-bsod[.]com
</p>

<p>
	crowdstrikedown[.]site crowdstuck[.]org crowdfalcon-immed-update[.]com
</p>

<p>
	crowdstriketoken[.]com crowdstrikeclaim[.]com crowdstrikeblueteam[.]com
</p>

<p>
	crowdstrikefix[.]zip crowdstrikereport[.]com
</p>

<p>
	 
	</p><p>
		CrowdStrike advises its customers to connect with CrowdStrike representatives only through official channels and stick to technical guidance provided by CrowdStrike and Microsoft. Microsoft has also recently updated their guide to offer an automated method involving recovery drives, which you can read about here.
	</p>


<p>
	 
</p>

<p>
	While CrowdStrike and Microsoft have worked to mitigate the immediate damage, the ongoing phishing and malware campaigns underscore the persistence of cybercriminals seeking to capitalize on chaos.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.neowin.net/news/cybercriminals-exploit-crowdstrike-chaos-to-spread-crowdstrike-hotfixzip-malware/" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">24336</guid><pubDate>Sun, 21 Jul 2024 19:18:04 +0000</pubDate></item><item><title>&#x201C;The internet has become a massive web of surveillance:&#x201D; Firefox defends its decision</title><link>https://nsaneforums.com/news/security-privacy-news/%E2%80%9Cthe-internet-has-become-a-massive-web-of-surveillance%E2%80%9D-firefox-defends-its-decision-r24326/</link><description><![CDATA[<p>
	Firefox CTO Bobby Holley has rebutted worries that the privacy-focused browser will be used by advertisers to collect user data. The goal is to create an industry-wide privacy-preserving mechanism that would keep both advertisers and users happy while moving away from predatory data collection practices.
</p>

<p>
	 
</p>

<p>
	Following the backlash regarding the addition of Firefox's new “Privacy-preserving attribution” (PPA) feature, which collects and aggregates anonymized user interaction data for advertisers, Holley admitted that the company should have communicated better about it.
</p>

<p>
	 
</p>

<p>
	In a detailed post on Reddit, Holley explained that Mozilla wants to address the internet's "massive web of surveillance.” Previously, Mozilla approached this problem with anti-tracking features that thwarted the most common surveillance techniques. However, that approach has two inherent limitations.
</p>

<p>
	 
</p>

<p>
	Advertisers have enormous economic incentives to bypass any countermeasures, leading to a perpetual arms race. Also, while blocking helps, Mozilla wants to “improve privacy for everyone,” not only people who use Firefox.
</p>

<p>
	 
</p>

<p>
	“Whatever opinion you may have of advertising as an economic model, it’s a powerful industry that’s not going to pack up and go away,” Holley said.
</p>

<p>
	 
</p>

<p>
	Instead of the current internet, where advertisers gather extensive personal data, Mozilla is working to create a system that could meet the bar of accomplishing advertisers' goals while protecting user privacy.
</p>

<p>
	 
</p>

<p>
	“We’ve been collaborating with Meta on this, because any successful mechanism will need to be actually useful to advertisers, and designing something that Mozilla and Meta are simultaneously happy with is a good indicator we’ve hit the mark,” Holley believes.
</p>

<p>
	 
</p>

<p>
	He assures that the PPA feature, introduced in Firefox version 128, is uncompromising on the privacy front, and only provides bare-bone functionality to advertisers. The experimental prototype has been in the works for several years now and is unrelated to the recent acquisition of AdTech company Anonym. The privacy properties “have been vetted by some of the best cryptographers in the field.”
</p>

<p>
	 
</p>

<p>
	The temporary prototype is also restricted to a handful of test sites and is expected to be extremely low volume.
</p>

<p>
	 
</p>

<p>
	“It’s about measurement (aggregate counts of impressions and conversions) rather than targeting,” the CTO said.
</p>

<p>
	 
</p>

<p>
	Holley also defended enabling the new feature by default, and considered consent dialogs to be a “user-hostile distraction from better defaults.”
</p>

<p>
	 
</p>

<p>
	“Digital advertising is not going away, but the surveillance parts could actually go away if we get it right. A truly private attribution mechanism would make it viable for businesses to stop tracking people, and enable browsers and regulators to clamp down much more aggressively on those that continue to do so,” he concluded.
</p>

<p>
	 
</p>

<p>
	Regardless, some users still expressed concerns about giving any information to advertisers, even if anonymized.
</p>

<p>
	 
</p>

<p>
	“If you give advertisers an inch they take a mile. If this system is in any way breakable, it will be broken. If a person can be bribed to de-anonymize the data, they will and if that can't be they will be replaced,” one Reddit user worried.
</p>

<p>
	 
</p>

<p>
	Holley explained that there’s no tracking in the feature, and nobody outside the local machine gets individualized data, just aggregate counts.
</p>

<p>
	 
</p>

<p>
	Holley also assured users that no money is changing hands between Meta and Firefox, as it is an engineer-to-engineer collaboration.
</p>

<p>
	 
</p>

<p>
	Firefox does not expect any revenues from the PPA. Holley mentioned that if users choose to block ads using various solutions, the API calls will also be blocked.
</p>

<p>
	 
</p>

<p>
	Mozilla posted a detailed explainer on GitHub. The company believes “that a good attribution system will give advertising businesses a real alternative to more objectionable practices, like tracking, which should allow browsers to further restrict those practices.”
</p>

<p>
	 
</p>

<p>
	“A core tenet of the Mozilla Manifesto is that user privacy is fundamental and non-optional. The surveillance practices common in modern digital advertising are deeply problematic in this regard and we want to do something about it.
</p>

<p>
	 
</p>

<p>
	In Firefox 128, we are testing a research prototype of a technology that we hope could one day replace these surveillance practices. The privacy guarantees of this technology are ironclad: unlike other proposed designs, nobody outside the user’s device learns any information whatsoever about their individual activity”, a Mozilla spokesperson said in a comment to Cybernews.
</p>

<p>
	 
</p>

<p>
	The prototype can be disabled directly, and is only enabled if telemetry is otherwise enabled.
</p>

<p>
	 
</p>

<p>
	“Internet advertising is not going away, and many sites rely on advertising to support themselves. To avoid pitting the interests of sites against the interests of users, we want to create a long-term solution that ensures companies can still achieve their goals without collecting personal data. This would be a major step forward for privacy on the Internet,” the spokesperson said.
</p>

<p>
	 
</p>

<p>
	<strong><a href="" rel="">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">24326</guid><pubDate>Sun, 21 Jul 2024 16:09:21 +0000</pubDate></item><item><title>Google Chrome is getting serious about risky desktop downloads with full-screen warnings</title><link>https://nsaneforums.com/news/security-privacy-news/google-chrome-is-getting-serious-about-risky-desktop-downloads-with-full-screen-warnings-r24325/</link><description><![CDATA[<p>
	<br />
	<span style="font-size:18px;"><strong>Summary</strong></span>
</p>

<p>
	   
</p>

<ul>
	<li>
		<span style="font-size:16px;"><strong>Google Chrome's Safe Browsing tool protects against online threats by warning of potentially harmful downloads.</strong></span>
	</li>
</ul>

<p>
	 
</p>

<ul>
	<li>
		<span style="font-size:16px;"><strong>New, more prominent warnings may soon appear in Chrome to alert users of dangerous downloads.</strong></span>
	</li>
</ul>

<p>
	 
</p>

<ul>
	<li>
		<span style="font-size:16px;"><strong>Users may be able to activate the new warning UI by enabling the Download Warning Improvements flag in Chrome settings.</strong></span>
	</li>
</ul>

<p>
	 
</p>

<p>
	Google Chrome is one of the most popular browsers out there. It holds a dominant position within all browsers, with over 65 percent market share, leaving behind browsers like Microsoft's Internet Explorer (Edge), Mozilla's Firefox, and others with the first-mover advantage.
</p>

<p>
	 
</p>

<p>
	Over the years, the browser has gained several handy security-related features, and it consistently releases new security updates and features to protect users from online threats. One such feature is its Safe Browsing tool, which protects users against malware, suspicious extensions, phishing, and intrusive ads, with more privacy-focused features expected to debut soon.
</p>

<p>
	<br />
	The Google Chrome logo against a blue and white background.
</p>

<p>
	 
</p>

<p>
	The browser already warns users about potentially harmful downloads. This shows up as a small dialog box when you attempt to download something that might be harmful. Now, it appears as though Google will soon start showing more prominent warnings, akin to the warning it shows when you attempt to visit a page that might be classified as deceptive or dangerous.
</p>

<p>
	 
</p>

<p>
	The information that Chrome might be working on more prominent download warnings was first shared by Windows Report, indicating that the new warning will cover the entire browser page, and it is being referred to as DangerousDownloadInterstitial.
</p>

<p>
	 
</p>

<p>
	<span style="font-size:22px;"><strong>Red means stop </strong></span>
</p>

<p>
	 
</p>

<p style="text-align:center;">
	<img alt="chrome-full-page-download-warning.jpg?q=" class="ipsImage" data-ratio="73.47" height="377" width="720" src="https://static1.anpoimages.com/wordpress/wp-content/uploads/2024/07/chrome-full-page-download-warning.jpg?q=70&amp;fit=crop&amp;w=1500&amp;dpr=1" />
</p>

<p style="text-align:center;">
	<span style="font-size:12px;"><em>Source: Windows Report</em></span>
</p>

<p style="text-align:center;">
	 
</p>

<p>
	 The full-page warning surfaces with the same text as the current pop-up warning. "This file contains malware or comes from a suspicious site," complete with a link to learn more about why Google blocks certain downloads. The two accompanying buttons still offer the same actions: one to Continue anyway and one to go Back to safety.
</p>

<p>
	 
</p>

<p>
	If you proceed with the download, it also looks like you might have to compulsorily tell Google why you're doing so. Options include I created this file, I trust the site, and I'm willing to accept the risk.
</p>

<p>
	 
</p>

<p>
	Although the UI appeared in a changelog, you might already be able to activate it as an experimental flag. Head to chrome://flags on your Chrome browser or on Chrome Canary and type in Download Warning Improvements. Enable the flag and restart your browser, and the new download warning UI should show up the next time you try to download something risky.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.androidpolice.com/google-chrome-is-getting-a-lot-more-pushy-about-dangerous-downloads/" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">24325</guid><pubDate>Sun, 21 Jul 2024 16:06:20 +0000</pubDate></item><item><title>Don&#x2019;t Fall for CrowdStrike Outage Scams</title><link>https://nsaneforums.com/news/security-privacy-news/don%E2%80%99t-fall-for-crowdstrike-outage-scams-r24311/</link><description><![CDATA[<p>
	<span style="font-size:18px;"><strong>Swindlers are spinning up bogus websites in an attempt to dupe people with “CrowdStrike support” scams following the security firm’s catastrophic software update.</strong></span>
</p>

<p>
	 
</p>

<p>
	The security firm CrowdStrike inadvertently caused mayhem around the world on Friday after deploying a faulty software update to the company's Falcon monitoring platform that bricked Windows computers running the product. Fallout from the incident will take days to resolve, and the company is warning that, as system administrators and IT staff work on remediation, another threat is looming: predatory digital scams attempting to capitalize on the crisis.
</p>

<p>
	 
</p>

<p>
	Researchers on Friday afternoon began warning that attackers are reserving domain names and starting to spin up websites and other infrastructure to run “CrowdStrike Support” scams targeting the company's customers and anyone who might be impacted by the chaos. CrowdStrike's own researchers also warned about the activity on Friday and published a list of domains seemingly registered to impersonate the company.
</p>

<p>
	 
</p>

<p>
	“We know that adversaries and bad actors will try to exploit events like this,” CrowdStrike founder and CEO George Kurtz wrote in a statement. “I encourage everyone to remain vigilant and ensure that you’re engaging with official CrowdStrike representatives. Our blog and technical support will continue to be the official channels for the latest updates."
</p>

<p>
	 
</p>

<p>
	Attackers inevitably take advantage of prominent global events as well as topical issues in specific geographic areas to try to trick people into sending them money, steal target account credentials, or compromise victims with malware.
</p>

<p>
	 
</p>

<p>
	“Threat actors invariably attempt to capitalize on any major event,” says Brett Callow, managing director of cybersecurity and data privacy communications at FTI Consulting. “Whenever an organization experiences an incident, it's something customers and business partners should be prepared for.”
</p>

<p>
	 
</p>

<p>
	While most individuals are not personally responsible for addressing CloudStrike-related computer outages, the incident is ripe for exploitation because some of the IT professionals working on remediation could be desperate for solutions. In most cases, the fix for impacted computers involves individually booting and correcting each one—a potentially time-consuming and logistically difficult process.
</p>

<p>
	 
</p>

<p>
	And for small-business owners who don't have access to extensive IT expertise, the challenge may be particularly daunting.
</p>

<p>
	 
</p>

<p>
	Researchers, including those from CrowdStrike intelligence, have thus far seen attackers sending phishing emails or making phone calls where they pretend to be CrowdStrike support staff and selling software tools that claim to automate the process of recovering from the faulty software update. Some attackers are also pretending to be researchers and claiming to have special information vital to recovery—that the situation is actually the result of a cyberattack, which it's not.
</p>

<p>
	 
</p>

<p>
	CrowdStrike emphasizes that customers should confirm that they are communicating with legitimate company staff members and only trust the company's official corporate communications.
</p>

<p>
	 
</p>

<p>
	“Speedy alerts to employees outlining potential risks will help,” Callow says of how CloudStrike customers should work to defend themselves. "Forewarned is forearmed."
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.wired.com/story/crowdstrike-outage-support-scams/" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">24311</guid><pubDate>Sat, 20 Jul 2024 15:49:12 +0000</pubDate></item><item><title>Scam warning as fake emails and websites target users after outage</title><link>https://nsaneforums.com/news/security-privacy-news/scam-warning-as-fake-emails-and-websites-target-users-after-outage-r24298/</link><description><![CDATA[<p>
	Cyber-security experts and agencies around the world are warning people about a wave of opportunistic hacking attempts linked to the IT outage.
</p>

<p>
	 
</p>

<p>
	Although there is no evidence that the CrowdStrike outage was caused by malicious activity, some bad actors are attempting to take advantage.
</p>

<p>
	 
</p>

<p>
	Cyber agencies in the UK and Australia are warning people to be vigilant to fake emails, calls and websites that pretend to be official.
</p>

<p>
	And CrowdStrike head George Kurtz encouraged users to make sure they were speaking to official representatives from the company before downloading fixes.
</p>

<p>
	 
</p>

<p style="text-align:center;">
	<img alt="8de49880-4688-11ef-ac12-f16ca979d7d8.jpg" class="ipsImage" data-ratio="75.10" height="405" width="720" src="https://ichef.bbci.co.uk/news/1024/cpsprodpb/924c/live/8de49880-4688-11ef-ac12-f16ca979d7d8.jpg.webp" />
</p>

<p style="text-align:center;">
	<span style="font-size:12px;"><em>Thousands of flights were cancelled across the world due to the mass outage</em></span>
</p>

<p style="text-align:center;">
	 
</p>

<p>
	We know that adversaries and bad actors will try to exploit events like this," he said in a blog post.
</p>

<p>
	 
</p>

<p>
	"Our blog and technical support will continue to be the official channels for the latest updates."
</p>

<p>
	 
</p>

<p>
	His words were echoed by cybersecurity expert Troy Hunt, who runs the well-known Have I Been Pwned security website.
</p>

<p>
	 
</p>

<p>
	“An incident like this that has commanded so many headlines and has people worried is a gift to scammers," he said.
</p>

<p>
	 
</p>

<p>
	Mr Hunt was responding to a warning from the Australian Signals Directorate (known as the ASD, the equivalent of the UK's GCHQ or the US's National Security Agency) which issued an alert about hackers sending out bogus software fixes claiming to be from CrowdStrike.
</p>

<p>
	 
</p>

<p>
	"Alert! We understand a number of malicious websites and unofficial code are being released claiming to help entities recover," the notice reads.
</p>

<p>
	 
</p>

<p>
	The agency is urging IT responders to only use CrowdStrike's website to source information and help.
</p>

<p>
	 
</p>

<p>
	The ASD warning follows calls from the UK's National Cyber Security Centre (NCSC) on Friday for people to be hyper vigilante of suspicious emails or calls that pretend to be CrowdStrike or Microsoft help.
</p>

<p>
	 
</p>

<p>
	"An increase in phishing referencing this outage has already been observed, as opportunistic malicious actors seek to take advantage of the situation," the agency said.
</p>

<p>
	<br />
	<span style="font-size:20px;"><strong>Fear and uncertainty</strong></span>
</p>

<p>
	 
</p>

<p>
	Whenever there is a major news event, especially one linked to technology, hackers respond by tweaking their existing methods to take into account the fear and uncertainty.
</p>

<p>
	 
</p>

<p>
	We saw the same with the Covid-19 pandemic when hackers adjusted their phishing email attacks to offer information about the virus and even pretend to have an antidote in order to hack people and organisations.
</p>

<p>
	 
</p>

<p>
	Because the IT outage has been a global news story we are seeing hackers capitalise.
</p>

<p>
	 
</p>

<p>
	According to researchers at Secureworks, there has already been a sharp rise in CrowdStrike-themed domain registrations – hackers registering new websites made to look official and potentially trick IT managers or members of the public into downloading malicious software or handing over private details.
</p>

<p>
	 
</p>

<p>
	The advice is mainly for IT managers who are the ones being affected by this as they try to get their organisations back online.
</p>

<p>
	 
</p>

<p>
	But individuals too might be targeted, so experts are warning to be cautious and only act on information from the official CrowdStrike channels.
</p>

<p>
	 
</p>

<p>
	<strong><a href="https://www.bbc.com/news/articles/cq5xy12pynyo" rel="external nofollow">Source</a></strong>
</p>
]]></description><guid isPermaLink="false">24298</guid><pubDate>Sat, 20 Jul 2024 13:37:33 +0000</pubDate></item><item><title>NordVPN will soon work on Qualcomm Snapdragon X PCs, closing a big part of the Windows on Arm app gap</title><link>https://nsaneforums.com/news/security-privacy-news/nordvpn-will-soon-work-on-qualcomm-snapdragon-x-pcs-closing-a-big-part-of-the-windows-on-arm-app-gap-r24280/</link><description><![CDATA[<h3>
	An Arm-native version of NordVPN is in its final stages of testing.
</h3>

<h2 id="what-you-need-to-know-3">
	What you need to know
</h2>

<ul>
	<li>
		NordVPN will make an Arm-native version of its application in the near future.
	</li>
	<li>
		The company confirmed that the Arm-native version of NordVPN is in its final stages.
	</li>
	<li>
		Being optimized for Arm should make NordVPN perform better and have better efficiency when running on devices powered by the Snapdragon X Elite or other Arm processors.
	</li>
</ul>

<p>
	 
</p>

<hr>
<p>
	 
</p>

<p>
	Windows 11 on Arm PCs are about to get a big boost when it comes to security and privacy. NordVPN, a popular tool for securing devices by hiding your IP address, will have an Arm-native version soon. That's good news for people who already have a NordVPN subscription or that are interested in grabbing one for use on an Arm-powered PC like the <a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/hardware/laptops/surface-pro-11-review" data-component-tracked="1" href="https://www.windowscentral.com/hardware/laptops/surface-pro-11-review" rel="external nofollow">Surface Pro 11</a> or <a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/hardware/laptops/surface-laptop-7-copilot-pc-review" data-component-tracked="1" href="https://www.windowscentral.com/hardware/laptops/surface-laptop-7-copilot-pc-review" rel="external nofollow">Surface Laptop 7</a>.
</p>

<p>
	 
</p>

<p>
	"We are building an Arm-native NordVPN application and the launching process is on the final stages," said NordVPN to <a data-analytics-id="inline-link" data-component-tracked="1" data-hl-processed="none" data-url="https://www.techradar.com/pro/heres-a-list-of-all-the-apps-that-can-run-on-the-qualcomm-snapdragon-x-elite-shame-autocad-and-our-favorite-vpn-provider-is-missing" href="https://www.techradar.com/pro/heres-a-list-of-all-the-apps-that-can-run-on-the-qualcomm-snapdragon-x-elite-shame-autocad-and-our-favorite-vpn-provider-is-missing" referrerpolicy="no-referrer-when-downgrade" rel="external nofollow" target="_blank">TechRadar</a>. "We are now in close cooperation with Microsoft to receive driver signing certificate. We expect to release the application in the near future."
</p>

<p>
	 
</p>

<p>
	NordVPN is one of the most popular VPNs around. It also tops the lists of the <a data-analytics-id="inline-link" data-component-tracked="1" data-hl-processed="none" data-url="https://www.techradar.com/vpn/best-vpn" href="https://www.techradar.com/vpn/best-vpn" referrerpolicy="no-referrer-when-downgrade" rel="external nofollow" target="_blank">best VPNs</a> and <a data-analytics-id="inline-link" data-component-tracked="1" data-hl-processed="none" data-url="https://www.techradar.com/vpn/best-windows-10-vpn" href="https://www.techradar.com/vpn/best-windows-10-vpn" referrerpolicy="no-referrer-when-downgrade" rel="external nofollow" target="_blank">best VPNs PC</a> maintained by our colleagues at TechRadar. NordVPN is easy to set up and use, allowing you to improve your security or unblock international streaming libraries by pretending to be somewhere you are not. What NordVPN is not, at least at the moment, is an option for those using Windows on Arm PCs. In fact, very few VPNs work on PCs with Qualcomm Snapdragon processors due to VPNs relying so heavily on specific drivers.
</p>

<h2 id="vpns-on-copilot-pcs-windows-11-on-arm-3">
	VPNs on Copilot+ PCs / Windows 11 on Arm
</h2>

<p>
	At the moment, you cannot use NordVPN on a <a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/windows-on-arm" data-component-tracked="1" href="https://www.windowscentral.com/windows-on-arm" rel="external nofollow">Windows on Arm PC</a>, even through emulation. While the best experience will come by using native Arm applications, Windows on Arm PCs can run other apps through emulation. Running non-native apps got a boost in the form of <a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/software-apps/what-is-microsoft-prism" data-component-tracked="1" href="https://www.windowscentral.com/software-apps/what-is-microsoft-prism" rel="external nofollow">Microsoft's Prism technology</a>, but there are still some apps that will not work on Arm-powered PCs.
</p>

<p>
	 
</p>

<p>
	The first wave of <a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/software-apps/windows-11/-microsoft-copilot-plus-faq" data-component-tracked="1" href="https://www.windowscentral.com/software-apps/windows-11/-microsoft-copilot-plus-faq" rel="external nofollow">Copilot+ PCs</a>, all of which run on the <a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/hardware/laptops/what-is-snapdragon-x-elite" data-component-tracked="1" href="https://www.windowscentral.com/hardware/laptops/what-is-snapdragon-x-elite" rel="external nofollow">Snapdragon X Elite</a> or <a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/hardware/laptops/what-is-snapdragon-x-plus" data-component-tracked="1" href="https://www.windowscentral.com/hardware/laptops/what-is-snapdragon-x-plus" rel="external nofollow">Snapdragon X Plus</a>, have received positive reviews (in the future there will be <a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/hardware/laptops/hps-new-omnibook-ultra-beats-every-single-copilot-pc-on-the-market-in-tops-and-it-runs-on-an-amd-ryzen-ai-300-processor" data-component-tracked="1" href="https://www.windowscentral.com/hardware/laptops/hps-new-omnibook-ultra-beats-every-single-copilot-pc-on-the-market-in-tops-and-it-runs-on-an-amd-ryzen-ai-300-processor" rel="external nofollow">Copilot+ PCs with non-Arm chips</a>). Generally speaking, the <a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/software-apps/windows-11/essential-windows-on-arm-apps" data-component-tracked="1" href="https://www.windowscentral.com/software-apps/windows-11/essential-windows-on-arm-apps" rel="external nofollow">best native Arm apps</a> perform great on these PCs and non-native apps run fine. 
</p>

<p>
	 
</p>

<p>
	"An important aspect of the Snapdragon X platform is how the emulated apps feel when used. On older generations of Windows on Arm chips, running even basic apps under emulation felt slower than running an Intel or AMD machine," said our Editor-in-Chief Daniel Rubino in our <a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/hardware/laptops/surface-laptop-7-copilot-pc-review" data-component-tracked="1" href="https://www.windowscentral.com/hardware/laptops/surface-laptop-7-copilot-pc-review" rel="external nofollow">Surface Laptop 7 review</a>.
</p>

<p>
	 
</p>

<p>
	"That's no longer the case here on Snapdragon X. Many of the apps I've tried that run under emulation feel fine, with no scrolling lag or frame dropping when navigating through an app."
</p>

<p>
	 
</p>

<div id="slice-container-newsletterForm-articleInbodyContent-xt5ceME2R9XHpZbwMp5QXa">
	<div data-hydrate="true">
		<p>
			While performance of those non-native apps is generally fine, efficiency drops when using apps that are not native to Arm. There are also some apps that perform noticeably slower in emulation. NordVPN and some other apps are not able to run on Windows 11 on Arm at all due to drivers or other limitations.
		</p>

		<p>
			 
		</p>

		<p>
			Certain apps not working with — or working well on — Windows on Arm PCs is a deal breaker for some. It doesn't matter how sleek the designs of the <a data-analytics-id="inline-link" data-before-rewrite-localise="https://www.windowscentral.com/hardware/laptops/samsung-galaxy-book4-edge-announce" data-component-tracked="1" href="https://www.windowscentral.com/hardware/laptops/samsung-galaxy-book4-edge-announce" rel="external nofollow">Galaxy Book4 Edge</a> or other laptops if those PCs can't run the apps you need. The addition of an Arm-native version of NordVPN should close a noticeable gap in the Windows on Arm ecosystem.
		</p>

		<p>
			 
		</p>

		<p>
			<a href="https://www.windowscentral.com/software-apps/nordvpn-will-soon-work-on-qualcomm-snapdragon-x-pcs-closing-a-big-part-of-the-windows-on-arm-app-gap" rel="external nofollow">Source</a>
		</p>

		<p>
			 
		</p>

		<p>
			<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
		</p>

		<p>
			<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every single day for many years.</em></span>
		</p>

		<p>
			<span style="font-size:12px;"><em>2023: Over 5,800 news posts | 2024 (till end of June): 2,839 news posts</em></span>
		</p>
	</div>
</div>
]]></description><guid isPermaLink="false">24280</guid><pubDate>Fri, 19 Jul 2024 18:47:16 +0000</pubDate></item><item><title>Facebook ads for Windows desktop themes push info-stealing malware</title><link>https://nsaneforums.com/news/security-privacy-news/facebook-ads-for-windows-desktop-themes-push-info-stealing-malware-r24209/</link><description><![CDATA[<p>
	Cybercriminals use Facebook business pages and advertisements to promote fake Windows themes that infect unsuspecting users with the SYS01 password-stealing malware.
</p>

<p>
	 
</p>

<p>
	Trustwave researchers who observed the campaigns said the threat actors also promote fake downloads for pirated games and software, Sora AI, 3D image creator, and One Click Active.
</p>

<p>
	 
</p>

<p>
	While using Facebook advertisements to push information-stealing malware is not new, the social media platform's massive reach makes these campaigns a significant threat.
</p>

<h2>
	Facebook advertising
</h2>

<p>
	The threat actors take out advertisements that promote Windows themes, free game downloads, and software activation cracks for popular applications, like Photoshop, Microsoft Office, and Windows.
</p>

<p>
	 
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Facebook advertisements" class="ipsImage" height="720" width="597" src="https://www.bleepstatic.com/images/news/malware/s/SYS01/facebook-malvertising/facebok-ads.jpg">
		<figcaption>
			<em>Facebook advertisements<br>
			Source: Trustwave</em>
		</figcaption>
	</figure>
</div>

<p>
	These advertisements are promoted through newly created Facebook business pages or by hijacking existing ones. When using hijacked Facebook pages, the threat actors rename them to suit the theme of their advertisement and to promote the downloads to the existing page members.
</p>

<p>
	 
</p>

<p>
	"The threat actors assume the business identity by renaming the Facebook pages, this allows them to leverage the existing follower base to amplify the reach of their fraudulent advertisement significantly," reads the Trustwave report.
</p>

<p>
	 
</p>

<p>
	"It's worth highlighting that each of these pages was administered by individuals situated in either Vietnam or the Philippines at various points in time."
</p>

<p>
	 
</p>

<p>
	Trustwave says that the threat actors take out thousands of ads for each campaign, with the top campaigns named blue-softs (8,100 ads), xtaskbar-themes (4,300 ads), newtaskbar-themes (2,200 ads), and awesome-themes-desktop (1,100 ads).
</p>

<p>
	 
</p>

<p>
	When a Facebook user clicks on the ad, they are brought to webpages hosted on Google Sites or True Hosting that pretend to be download pages for the advertisement's promoted content.
</p>

<p>
	 
</p>

<p>
	The True Hosting pages are primarily used to promote a website called Blue-Software, which offers allegedly free software and game downloads.
</p>

<p>
	 
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Download site for fake Windows themes" class="ipsImage" height="334" width="720" src="https://www.bleepstatic.com/images/news/malware/s/SYS01/facebook-malvertising/awesome-themes-website.jpg">
		<figcaption>
			<em>Download site for fake Windows themes<br>
			Source: Trustwave</em>
		</figcaption>
	</figure>
</div>

<p>
	Clicking on the 'Download' buttons will cause the browser to download a ZIP archive named after the particular item. For example, downloading the fake Windows themes would deliver an archive named 'Awesome_Themes_for_Win_10_11.zip', and Photoshop would be 'Adobe_Photoshop_2023.zip.'
</p>

<p>
	 
</p>

<p>
	While downloaders may think they are now getting a free application, game, or Windows theme, the archive actually contains the SYS01 information-stealing malware.
</p>

<p>
	 
</p>

<p>
	This malware was first <a href="https://blog.morphisec.com/sys01stealer-facebook-info-stealer" rel="external nofollow" target="_blank">discovered by Morphisec</a> in 2022 and utilizes a collection of executables, DLLs, PowerShell scripts, and PHP scripts to steal install the malware and steal data from an infected computer.
</p>

<p>
	 
</p>

<p>
	When the archive's main executable is loaded, it uses DLL sideloading to load a malicious DLL that begins setting up the malware's operating environment.
</p>

<p>
	 
</p>

<p>
	This includes running PowerShell scripts to prevent the malware from running in a virtualized environment to evade detection, adding folder exclusions in Windows Defender, and configuring a PHP operating environment to load malicious PHP scripts.
</p>

<p>
	 
</p>

<p>
	The SYS01 information-stealing malware's primary payload consists of PHP scripts that create scheduled tasks for persistence and steal data from the device.
</p>

<p>
	 
</p>

<p>
	The stolen data includes browser cookies, credentials saved in the browser, browser history, and cryptocurrency wallets.
</p>

<p>
	 
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="Stealing web browser cookies" class="ipsImage" height="600" style="height: auto;" width="678" src="https://www.bleepstatic.com/images/news/malware/s/SYS01/facebook-malvertising/stealing-login-cookies.jpg">
		<figcaption>
			<em>Stealing web browser cookies<br>
			Source: Trustwave</em>
		</figcaption>
	</figure>
</div>

<p>
	The malware also includes a task that utilizes Facebook cookies found on the device to steal account information from the social media site:
</p>

<p>
	 
</p>

<ul>
	<li>
		Extracts personal profile information such as name, email, and birthday.
	</li>
	<li>
		Fetches detailed advertising account data, including spending and payment methods.
	</li>
	<li>
		Data including businesses, ad accounts, and business users, highlighting the depth of access to commercial and sensitive financial data.
	</li>
	<li>
		Details regarding Facebook pages managed by the user, including follower counts and roles.
	</li>
</ul>

<p>
	 
</p>

<p>
	The stolen data is temporarily stored in the %Temp% folder before being sent to the attackers.
</p>

<p>
	 
</p>

<div style="">
	<figure class="image" style="display:inline-block">
		<img alt="PHP script to build data store for stolen data" class="ipsImage" height="600" style="height: auto;" width="873" src="https://www.bleepstatic.com/images/news/malware/s/SYS01/facebook-malvertising/stolen-information-store.jpg">
		<figcaption>
			<em>PHP script to build data store for stolen data<br>
			Source: Trustwave</em>
		</figcaption>
	</figure>
</div>

<p>
	The stolen cookies and passwords can later be sold to other threat actors or used to breach further accounts owned by the victim, while the Facebook data is likely used to hijack further accounts for future malvertising campaigns.
</p>

<p>
	 
</p>

<p>
	Trustwave says that this malvertising is not only confined to Facebook, seeing similar profiles set up on LinkedIn and YouTube.
</p>

<p>
	 
</p>

<p>
	"The ongoing SYS01 malvertisement campaign poses a threat to a wider audience and shows the importance of being aware of what users do in social media," concluded Trustwave.
</p>

<p>
	 
</p>

<p>
	"Since it was first observed in 2022, the SYS01 malware has shifted its delivery method by moving away from adult-themed clickbaits and game-related ads to an approach which targets the general audience like Windows themes and AI-based software tools advertisements."
</p>

<p>
	 
</p>

<p>
	Trustwave <a href="https://www.bleepingcomputer.com/news/security/facebook-ads-push-new-ov3r-stealer-password-stealing-malware/" target="_blank" rel="external nofollow">reported in February</a> about a similar Facebook malvertising campaign pushing the Ov3r_Stealer password-stealing malware.
</p>

<p>
	 
</p>

<p>
	More recently, Bitdefender warned that threat actors were hijacking Facebook pages with millions of users to <a href="https://www.bleepingcomputer.com/news/security/fake-facebook-midjourney-ai-page-promoted-malware-to-12-million-people/" target="_blank" rel="external nofollow">impersonate popular AI projects</a>. These pages were then used to push information-stealing malware, like Rilide, Vidar, IceRAT, and Nova.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/facebook-ads-for-windows-themes-push-sys01-info-stealing-malware/" rel="external nofollow">Source</a>
</p>

<p>
	 
</p>

<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every single day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>2023: Over 5,800 news posts | 2024 (till end of June): 2,839 news posts</em></span>
</p>
]]></description><guid isPermaLink="false">24209</guid><pubDate>Mon, 15 Jul 2024 19:47:06 +0000</pubDate></item><item><title>Google reportedly is close to buying cybersecurity company Wiz for $23 billion</title><link>https://nsaneforums.com/news/security-privacy-news/google-reportedly-is-close-to-buying-cybersecurity-company-wiz-for-23-billion-r24203/</link><description><![CDATA[<p>
	Google's parent company Alphabet is reportedly in talks for an acquisition that, if it goes through, will be the company's biggest purchase ever. <a href="https://www.wsj.com/business/deals/google-near-23-billion-deal-for-cybersecurity-startup-wiz-622edf1a?mod=hp_lead_pos1" rel="external nofollow">The Wall Street Journal</a>, citing unnamed sources, claims that Google is in negotiations to purchase the cybersecurity company Wiz for $23 billion. As of this writing, neither Google nor Wiz have commented on the Wall Street Journal's report.
</p>

<p>
	 
</p>

<p>
	Wiz was first launched just a few years ago, in 2020. The company specializes in protecting cloud systems and since its launch it has detected security flaws from many companies, including one of Google's rivals Microsoft. In May 2023, Wiz revealed it had found a flaw in Wiz in Microsoft's search engine Bing that would have allowed hackers to not only get personal information from the engine <a href="https://www.neowin.net/news/researchers-found-security-flaws-in-bing-that-would-have-let-hackers-alter-search-results/" rel="external nofollow">but to actually alter its search results</a>.
</p>

<p>
	 
</p>

<p>
	Since its founding, Wiz has raised a total of $1.9 billion from a variety of investors and companies. <a href="https://www.cnbc.com/2024/07/14/google-wiz-cybersecurity-deal-largest-ever.html" rel="external nofollow">CNBC</a> reports that as recently as May, the company was valued at $12 billion and that it was considering launching its own IPO to make it a publicly traded business.
</p>

<p>
	 
</p>

<p>
	If Google does indeed buy Wiz, it would surpass the <a href="https://www.neowin.net/news/google-closes-acquistion-of-motorola-mobility/" rel="external nofollow">$12.5 billion deal that it made in 2012 to acquire Motorola Mobility</a>. However, that purchase was quickly reversed as Google sold off its interest in Motorola <a href="https://www.neowin.net/news/reports-google-to-sell-off-motorola-mobility-to-lenovo/" rel="external nofollow">to Lenovo for a mere $2.91 billion in 2014.</a>
</p>

<p>
	 
</p>

<p>
	A deal to buy Wiz would almost certainly get at least some attention from antitrust regulators in the US and elsewhere, but it remains to be seen if those agencies would attempt to stop Google from buying the company.
</p>

<p>
	 
</p>

<p>
	In April there were unconfirmed reports that Google <a href="https://www.reuters.com/markets/deals/google-parent-alphabet-weighs-offer-hubspot-sources-say-2024-04-04/" rel="external nofollow">was thinking about acquiring HubSpot</a>, a online marketing company that had a market value of $35 billion. However, it appears those talks, if indeed they did occur, did not conclude in a deal.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/google-reportedly-is-close-to-buying-cybersecurity-company-wiz-for-23-billion/" rel="external nofollow">Source</a>
</p>

<p>
	 
</p>

<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every single day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>2023: Over 5,800 news posts | 2024 (till end of June): 2,839 news posts</em></span>
</p>
]]></description><guid isPermaLink="false">24203</guid><pubDate>Mon, 15 Jul 2024 08:02:45 +0000</pubDate></item><item><title>Google's Gemini may be accessing user documents on Google Cloud even when asked not to do it</title><link>https://nsaneforums.com/news/security-privacy-news/googles-gemini-may-be-accessing-user-documents-on-google-cloud-even-when-asked-not-to-do-it-r24202/</link><description><![CDATA[<p>
	The last couple of years has seen a rise in Artificial Intelligence (AI), from Microsoft's Copilot to Google's Gemini. While, this has opened up many new opportunities, the ever growing use and implementation of AI has also exposed privacy issues associated with generative AI.
</p>

<p>
	 
</p>

<p>
	Now, a claim from Kevin Bankston (via <a href="https://www.tomshardware.com/tech-industry/artificial-intelligence/gemini-ai-caught-scanning-google-drive-hosted-pdf-files-without-permission-user-complains-feature-cant-be-disabled" rel="external nofollow">Tom's Hardware</a>) has raised eyebrows regarding the workings on Google's Gemini AI. Recently, Google <a href="https://www.neowin.net/news/gemini-side-panel-is-now-rolling-out-to-google-docs-drive-slides-and-other-apps/" rel="external nofollow">announced that it is rolling out Gemini sidebar to Google cloud apps, like Google Docs and Drive</a>. The sidebar allows Gemini to see what the user is working on and provide suggestions or analyze files. However, in Kevin's case, Gemini decided to access and read his tax documents without the explicit permission.
</p>

<p>
	 
</p>

<div class="ipsEmbeddedOther" contenteditable="false">
	<iframe allowfullscreen="" data-controller="core.front.core.autosizeiframe" data-embedid="bf8622701e2c6b83494d01a486f419a5" src="https://nsaneforums.com/index.php?app=core&amp;module=system&amp;controller=embed&amp;url=https://twitter.com/KevinBankston/status/1811075836558114968?ref_src=twsrc%255Etfw%257Ctwcamp%255Etweetembed%257Ctwterm%255E1811075836558114968%257Ctwgr%255Ea8e350d71da3193cea8252b21555ae0cfc171339%257Ctwcon%255Es1_%26ref_url=https://www.neowin.net/news/googles-gemini-may-be-accessing-user-documents-on-google-cloud-even-when-asked-not-to-do-it/"></iframe>
</div>

<p>
	Kevin noted that Gemini had summarized his tax PDF without him prompted the AI to do so and when asked how to disable the setting, Gemini guided him to settings that did not even exist. While, Kevin was able to identify the correct setting, he noted that the setting was already disabled so Gemini should not be accessing the documents and summarizing them. Google does have a <a href="https://support.google.com/drive/answer/14356148" rel="external nofollow">support document</a> detailing how to use Gemini in Google Drive, however, the company does not detail how to disable the feature or prevent Gemini from accessing any data stored on Google Drive. Unfortunately, in our case too, Gemini was not able to guide properly to the disable option.
</p>

<p>
	 
</p>

<p>
	In the subsequent tweet, Kevin shared a way to disable Gemini from reading data on Google Drive by turning off Gemini extensions.
</p>

<p>
	 
</p>

<div class="ipsEmbeddedOther" contenteditable="false">
	<iframe allowfullscreen="" data-controller="core.front.core.autosizeiframe" data-embedid="41a24b430d87cde2b2010410ef84ea3d" src="https://nsaneforums.com/index.php?app=core&amp;module=system&amp;controller=embed&amp;url=https://twitter.com/KevinBankston/status/1811182285422817644?ref_src=twsrc%255Etfw%257Ctwcamp%255Etweetembed%257Ctwterm%255E1811182285422817644%257Ctwgr%255Ea8e350d71da3193cea8252b21555ae0cfc171339%257Ctwcon%255Es1_%26ref_url=https://www.neowin.net/news/googles-gemini-may-be-accessing-user-documents-on-google-cloud-even-when-asked-not-to-do-it/"></iframe>
</div>

<p>
	In my case too, the Google Workspace extension was turned off but Gemini was able to read and summarize all the documents on my Drive account. Google does not have any details on this and the company just <a href="https://support.google.com/docs/answer/13447104" rel="external nofollow">suggests opting out of Workspace Labs altogether </a>if you want to prevent Gemini from reading documents/files on Google Drive.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/googles-gemini-may-be-accessing-user-documents-on-google-cloud-even-when-asked-not-to-do-it/" rel="external nofollow">Source</a>
</p>

<p>
	 
</p>

<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every single day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>2023: Over 5,800 news posts | 2024 (till end of June): 2,839 news posts</em></span>
</p>
]]></description><guid isPermaLink="false">24202</guid><pubDate>Mon, 15 Jul 2024 08:01:54 +0000</pubDate></item><item><title>Banks in Singapore to phase out one-time passwords in 3 months</title><link>https://nsaneforums.com/news/security-privacy-news/banks-in-singapore-to-phase-out-one-time-passwords-in-3-months-r24195/</link><description><![CDATA[<p>
	The Monetary Authority of Singapore (MAS) has announced a new requirement impacting all major retail banks in the country to phase out the use of one-time passwords (OTPs) within the next three months.
</p>

<p>
	 
</p>

<p>
	This initiative was agreed upon between the government and the Association of Banks in Singapore (<a href="https://abs.org.sg/docs/library/banks-in-singapore-introduce-new-measures-to-strengthen-resistance-against-phishing-scams.pdf" rel="external nofollow" target="_blank">ABS</a>) to protect consumers against phishing and other scams.
</p>

<p>
	 
</p>

<p>
	"The use of OTP was introduced in the 2000s as a multi-factor authentication option to strengthen online security," <a href="https://www.mas.gov.sg/news/media-releases/2024/banks-in-singapore-to-strengthen-resilience-against-phishing-scams" rel="external nofollow" target="_blank">reads the MAS announcement</a>.
</p>

<p>
	 
</p>

<p>
	"However, technological developments and more sophisticated social engineering tactics have since enabled scammers to more easily phish for customers' OTP, for example through setting up fake bank websites that closely resemble the genuine websites."
</p>

<p>
	 
</p>

<p>
	In addition to phishing sites, OTPs have been the target of Android malware <a href="https://www.bleepingcomputer.com/news/security/android-malware-bypasses-2fa-by-stealing-one-time-passwords/" target="_blank" rel="external nofollow">for many years</a>, helping their operators bypass two-factor authentication protections on target accounts.
</p>

<p>
	 
</p>

<p>
	This has prompted Google to take <a href="https://www.bleepingcomputer.com/news/security/google-tests-blocking-side-loaded-android-apps-with-risky-permissions/" target="_blank" rel="external nofollow">more aggressive action</a> against the abuse of the 'RECEIVE_SMS,' 'READ_SMS,' and 'BIND_Notifications' permissions this year, with Singapore being among the first countries to receive the new protections.
</p>

<p>
	 
</p>

<p>
	Additionally, OTPs can be intercepted by man-in-the-middle attacks, and if they're SMS-based, they can be intercepted by threat actors who conduct SIM-swapping attacks.
</p>

<p>
	 
</p>

<p>
	Singapore bank customers will now use digital tokens instead of OTPs, which they must activate on their mobile devices.
</p>

<p>
	 
</p>

<p>
	According to ABS, digital tokens are <a href="https://www.channelnewsasia.com/singapore/banks-phase-out-otps-login-phishing-scams-digital-tokens-4466786" rel="external nofollow" target="_blank">already activated for 60% to 90%</a> of the customers of the country's three major banks: DBS, OCBC, and UOB.
</p>

<p>
	 
</p>

<p>
	"The digital token will authenticate customers' login without the need for an OTP that scammers can steal, or trick customers into disclosing," explains MAS.
</p>

<p>
	 
</p>

<p>
	Those who have not activated their digital tokens are strongly encouraged to do so soon to benefit from better security against phishing actors and scammers.
</p>

<p>
	 
</p>

<p>
	Customers who don't activate digital tokens will continue to receive OTPs as before, but those are expected to be an increasingly dwindling minority.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/banks-in-singapore-to-phase-out-one-time-passwords-in-3-months/" rel="external nofollow">Source</a>
</p>

<p>
	 
</p>

<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every single day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>2023: Over 5,800 news posts | 2024 (till end of June): 2,839 news posts</em></span>
</p>
]]></description><guid isPermaLink="false">24195</guid><pubDate>Sun, 14 Jul 2024 18:49:34 +0000</pubDate></item><item><title>Proton Pass now lets you securely share passwords with anyone</title><link>https://nsaneforums.com/news/security-privacy-news/proton-pass-now-lets-you-securely-share-passwords-with-anyone-r24168/</link><description><![CDATA[<p>
	Proton Pass, a popular password manager from the company known for its privacy-focused solutions, today is getting a new feature that should make it much easier to share passwords with any user, even if they do not use Proton Pass. Dubbed "Secure Links," the feature will be available on all supported platforms within a few days.
</p>

<p>
	 
</p>

<p>
	Proton Pass already has password-sharing capabilities, but they only work between existing Proton Pass users. The idea behind Proton Pass Secure Links is to give customers the ability to share passwords with anyone.
</p>

<p>
	 
</p>

<p>
	Secure Links in Proton Pass work the following way: The user generates a link to share a stored item and sets an expiration period between 1 hour and 30 days. They can also specify how many times a single item can be viewed. Upon clicking, a Secure Link opens the default browser and provides access to everything stored in the item. That includes notes, security questions, and other additional fields. And if the sender updates the item, its shared Secure Link will get new details automatically—no need to create a new one.
</p>

<p>
	 
</p>

<p>
	Proton stresses that it never "sees" full URLs and thus cannot access shared items. After sharing a link, users can track them in a new section of Proton Pass, revoke them, and perform other actions.
</p>

<p>
	 
</p>

<p>
	In addition to Secure Links, Proton is launching the Extra Password feature, which, as the name implies, is an additional password for Proton Pass.
</p>

<p>
	 
</p>

<p>
	Although Proton Pass is available for free, Secure Links is a premium feature that requires a Pass Plus plan (and above). If you are interested in giving it a try, there is<a href="https://account.proton.me/pass/signup?&amp;coupon=SECURESHARING" rel="external nofollow"> a new promo</a> that lets you get one year of Proton Pass Plus for $12/year. The offer is valid for new subscribers only.
</p>

<p>
	 
</p>

<p>
	You can learn more about Proton Pass Secure Links <a href="http://proton.me/blog/pass-secure-link-sharing" rel="external nofollow">in a post on the official blog</a>.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/proton-pass-now-lets-you-securely-share-passwords-with-anyone/" rel="external nofollow">Source</a>
</p>

<p>
	 
</p>

<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every single day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>2023: Over 5,800 news posts | 2024 (till end of June): 2,839 news posts</em></span>
</p>
]]></description><guid isPermaLink="false">24168</guid><pubDate>Fri, 12 Jul 2024 18:58:53 +0000</pubDate></item><item><title>Netgear warns users to patch auth bypass, XSS router flaws</title><link>https://nsaneforums.com/news/security-privacy-news/netgear-warns-users-to-patch-auth-bypass-xss-router-flaws-r24167/</link><description><![CDATA[<figcaption style="text-align:left; font-size:14px">
	 
</figcaption>

<p>
	Netgear warned customers to update their devices to the latest available firmware, which patches stored cross-site scripting (XSS) and authentication bypass vulnerabilities in several WiFi 6 router models.
</p>

<p>
	 
</p>

<p>
	The stored XSS security flaw (fixed in firmware version 1.0.0.72 and tracked as <a href="https://kb.netgear.com/000066264/Security-Advisory-for-Stored-Cross-Site-Scripting-on-Some-Routers-PSV-2023-0122" rel="external nofollow" target="_blank">PSV-2023-0122</a>) impacts the XR1000 Nighthawk gaming router.
</p>

<p>
	 
</p>

<p>
	While the company didn't disclose any details regarding this bug, successful attacks exploiting such weaknesses can let threat actors hijack user sessions, redirect users to malicious sites or display fake login forms, and steal restricted information.
</p>

<p>
	 
</p>

<p>
	They can also perform actions with the compromised user's permissions, an especially dangerous scenario if the user has administrative privileges on the targeted device.
</p>

<p>
	 
</p>

<p>
	The authentication bypass security bug (fixed in firmware version 2.2.2.2 and tracked as <a href="https://kb.netgear.com/000066265/Security-Advisory-for-Authentication-Bypass-on-Some-Cable-Modem-Routers-PSV-2023-0138" rel="external nofollow" target="_blank">PSV-2023-0138</a>) impacts CAX30 Nighthawk AX6 6-Stream cable modem routers.
</p>

<p>
	 
</p>

<p>
	Even though Netgear hasn't shared any information regarding this vulnerability either, such flaws are usually tagged as maximum severity since they can provide attackers with unauthorized access to the administrative interface and can result in a complete takeover of the targeted devices.
</p>

<p>
	 
</p>

<p>
	A Netgear spokesperson was not immediately available to share more details regarding the two security flaws when BleepingComputer reached out earlier today.
</p>

<h2>
	How to update your router's firmware
</h2>

<p>
	In security advisories published on Wednesday, Netgear said it "strongly recommends that you download the latest firmware as soon as possible."
</p>

<p>
	 
</p>

<p>
	To download and install the latest firmware for your Netgear router, you have to go through the following steps:
</p>

<p>
	 
</p>

<ol>
	<li>
		Visit <a href="https://www.netgear.com/support/" rel="external nofollow" target="_blank">NETGEAR Support</a>.
	</li>
	<li>
		Start by entering your model number in the search box. Then, choose your model from the drop-down menu when it appears.
	</li>
	<li>
		If you do not see a drop-down menu, make sure you have entered your model number correctly or select a product category to browse for your product model.
	</li>
	<li>
		Click <strong>Downloads</strong>.
	</li>
	<li>
		Under <strong>Current Versions</strong>, select the first download whose title begins with <strong>Firmware Version</strong>.
	</li>
	<li>
		Click <strong>Download</strong>.
	</li>
	<li>
		To install the new firmware, follow the instructions in your product's user manual, firmware release notes, or product support page.
	</li>
</ol>

<p>
	 
</p>

<p>
	"NETGEAR is not responsible for any consequences that could have been avoided by following the recommendations in this notification," the company added.
</p>

<p>
	 
</p>

<p>
	Last month, security researchers <a href="https://www.bleepingcomputer.com/news/security/netgear-wnr614-flaws-allow-device-takeover-no-fix-available/" target="_blank" rel="external nofollow">disclosed half a dozen vulnerabilities</a> of varying severity impacting Netgear WNR614 N300, a popular router among home users and small businesses.
</p>

<p>
	 
</p>

<p>
	Since this router model reached end-of-life and is no longer supported by Netgear, the company will not release security patches and advised users to replace the router or apply mitigation measures to block potential attacks.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/netgear-warns-users-to-patch-authentication-bypass-xss-router-flaws/" rel="external nofollow">Source</a>
</p>

<p>
	 
</p>

<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every single day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>2023: Over 5,800 news posts | 2024 (till end of June): 2,839 news posts</em></span>
</p>
]]></description><guid isPermaLink="false">24167</guid><pubDate>Fri, 12 Jul 2024 18:58:18 +0000</pubDate></item><item><title><![CDATA[Massive AT&T data breach exposes call logs of 109 million customers]]></title><link>https://nsaneforums.com/news/security-privacy-news/massive-att-data-breach-exposes-call-logs-of-109-million-customers-r24166/</link><description><![CDATA[<p>
	AT&amp;T is warning of a massive data breach where threat actors stole the call logs for approximately 109 million customers, or nearly all of its mobile customers, from an online database on the company's Snowflake account.
</p>

<p>
	 
</p>

<p>
	The company confirmed to BleepingComputer that the data was stolen from the Snowflake account between April 14 and April 25, 2024.
</p>

<p>
	 
</p>

<p>
	In a Friday morning <a href="https://www.sec.gov/Archives/edgar/data/732717/000073271724000046/t-20240506.htm" rel="external nofollow" target="_blank">Form 8-K filling</a> with the SEC, AT&amp;T says that the stolen data contains the call and text records of nearly all AT&amp;T mobile clients and customers of mobile virtual network operators (MVNOs) made from May 1 to October 31, 2022 and on January 2, 2023.
</p>

<p>
	 
</p>

<p>
	The stolen data includes:
</p>

<p>
	 
</p>

<ul style="list-style-type:square">
	<li>
		Telephone numbers of AT&amp;T wireline customers and customers of other carriers.
	</li>
	<li>
		Telephone numbers with which AT&amp;T or MVNO wireless numbers interacted.
	</li>
	<li>
		Count of interactions (e.g., the number of calls or texts).
	</li>
	<li>
		Aggregate call duration for a day or month.
	</li>
	<li>
		For a subset of records, one or more cell site identification numbers.
	</li>
</ul>

<p>
	 
</p>

<p>
	The exposed records did not contain the content of the calls or texts, customer names, or any other personal information such as Social Security numbers or dates of birth.
</p>

<p>
	 
</p>

<p>
	Although the accessed logs do not contain sensitive information that directly exposes customer identities, the communications metadata can be used to correlate them with publicly available information and easily derive identities in many cases.
</p>

<p>
	 
</p>

<p>
	The company says that after learning of the breach they worked with cybersecurity experts and notified law enforcement. The US Department of Justice gave AT&amp;T permision twice, on May 9, 2024 and June 5, 2024, to delay public notification due to the potential risks to national security and public safety.
</p>

<p>
	 
</p>

<p>
	"Shortly after identifying a potential breach to customer data and before making its materiality decision, AT&amp;T contacted the FBI to report the incident. In assessing the nature of the breach, all parties discussed a potential delay to public reporting under Item 1.05(c) of the SEC Rule, due to potential risks to national security and/or public safety," the FBI told BleepingComputer.
</p>

<p>
	 
</p>

<p>
	"AT&amp;T, FBI, and DOJ worked collaboratively through the first and second delay process, all while sharing key threat intelligence to bolster FBI investigative equities and to assist AT&amp;T’s incident response work."
</p>

<p>
	 
</p>

<p>
	"The FBI prioritizes assistance to victims of cyber-attacks, encourages organizations to establish a relationship with their local FBI field office in advance of a cyber incident, and to contact the FBI early in the event of breach."
</p>

<p>
	 
</p>

<p>
	AT&amp;T is working with law enforcement to arrest those involved and states that they understand at least one person has already been apprehended.
</p>

<p>
	 
</p>

<p>
	AT&amp;T said it has implemented additional cybersecurity measures to block unauthorized access attempts in the future, and it promised to notify current and former customers impacted by this incident soon.
</p>

<p>
	 
</p>

<p>
	Meanwhile, AT&amp;T customers can follow the links provided <a href="https://www.att.com/support/article/my-account/000102979" rel="external nofollow" target="_blank">on this FAQ page</a> to check if their phone number's data was exposed and to download the data associated with their number that was stolen.
</p>

<p>
	 
</p>

<p>
	As of today, AT&amp;T says it has no evidence the accessed data has been made publicly available and says the incident is not related to the 2021 data breach <a href="https://www.bleepingcomputer.com/news/security/att-now-says-data-breach-impacted-51-million-customers/" target="_blank" rel="external nofollow">AT&amp;T confirmed earlier this year</a> impacted 51 million customers.
</p>

<h2>
	The Snowflake data theft attacks
</h2>

<p>
	AT&amp;T has confirmed to BleepingComputer that the data was stolen from its Snowflake account as part of a wave of recent data theft attacks using compromised credentials.
</p>

<p>
	 
</p>

<p>
	Snowflake is a cloud-based database provider that allows customers to perform data warehousing and analytics on large volumes of data.
</p>

<p>
	 
</p>

<p>
	Last month, <a href="https://www.bleepingcomputer.com/news/security/cylance-confirms-data-breach-linked-to-third-party-platform/" target="_blank" rel="external nofollow">Mandiant revealed</a> that a financially motivated threat actor tracked as 'UNC5537' was behind multiple attacks against Snowflake customers, using account credentials stolen via infostealer malware.
</p>

<p>
	 
</p>

<p>
	Snowflake has since <a href="https://www.snowflake.com/blog/snowflake-admins-enforce-mandatory-mfa/" rel="external nofollow" target="_blank">introduced</a> a mandatory multi-factor authentication (MFA) enforcement option for workspace administrators to protect accounts against easy take-overs leading to data breaches impacting millions of people.
</p>

<p>
	 
</p>

<p>
	The list of high-profile victims to which AT&amp;T is being added now includes <a href="https://www.bleepingcomputer.com/news/security/advance-auto-parts-data-breach-impacts-23-million-people/" target="_blank" rel="external nofollow">Advance Auto Parts</a>, <a href="https://www.bleepingcomputer.com/news/security/pure-storage-confirms-data-breach-after-snowflake-account-hack/" target="_blank" rel="external nofollow">Pure Storage</a>, <a href="https://www.bleepingcomputer.com/news/security/los-angeles-unified-confirms-student-data-stolen-in-snowflake-account-hack/" target="_blank" rel="external nofollow">Los Angeles Unified</a>, <a href="https://www.bleepingcomputer.com/news/security/neiman-marcus-confirms-data-breach-after-snowflake-account-hack/" target="_blank" rel="external nofollow">Neiman Marcus</a>, <a href="https://www.bleepingcomputer.com/news/security/ticketmaster-confirms-massive-breach-after-stolen-data-for-sale-online/" target="_blank" rel="external nofollow">Ticketmaster</a>, and <a href="https://www.bleepingcomputer.com/news/security/snowflake-account-hacks-linked-to-santander-ticketmaster-breaches/" target="_blank" rel="external nofollow">Banco Santander</a>.
</p>

<p>
	 
</p>

<p>
	<a href="https://www.bleepingcomputer.com/news/security/massive-atandt-data-breach-exposes-call-logs-of-109-million-customers/" rel="external nofollow">Source</a>
</p>

<p>
	 
</p>

<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every single day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>2023: Over 5,800 news posts | 2024 (till end of June): 2,839 news posts</em></span>
</p>
]]></description><guid isPermaLink="false">24166</guid><pubDate>Fri, 12 Jul 2024 18:56:52 +0000</pubDate></item><item><title>Google will make dark web reports available to all consumer Google Account users for free</title><link>https://nsaneforums.com/news/security-privacy-news/google-will-make-dark-web-reports-available-to-all-consumer-google-account-users-for-free-r24139/</link><description><![CDATA[<p>
	Google's dark web report allows users to set up a profile to monitor the dark web and receive notifications if their information was found in data breaches. Previously, the full dark web report feature was exclusive to Google One members.
</p>

<p>
	 
</p>

<p>
	However, Google recently announced that the dark web report feature will no longer be limited to Google One members and will instead become available to all users with a consumer Google Account. Google Workspace accounts and supervised accounts will not have access to this feature.
</p>

<p>
	 
</p>

<p>
	The dark web report will be integrated with the "Results about you" section, which helps users discover if their personal contact information, such as their home address, phone number, or email address, appears in Google search results.
</p>

<p>
	 
</p>

<blockquote class="QuoteNewsStyle">
	<p>
		Starting in late July 2024, the dark web report will no longer require a Google One membership. All users signed into their Google Accounts will be able to use the feature as it becomes available alongside "Results about you."
	</p>
</blockquote>

<p>
	The dark web report will be available in the following countries:
</p>

<p>
	 
</p>

<p>
	Albania, Algeria, Argentina, Austria, Australia, Bangladesh, Belgium, Bolivia, Brazil, Canada, Chile, Colombia, Denmark, Ecuador, Finland, France, Germany, Greece, Iceland, India, Indonesia, Ireland, Israel, Italy, Japan, Mexico, Morocco, Netherlands, Nicaragua, Norway, Pakistan, Philippines, Senegal, Slovenia, South Korea, Spain, Sri Lanka, Sweden, Switzerland, Taiwan, Türkiye, Ukraine, United Kingdom, United States, Venezuela, and Vietnam.
</p>

<p>
	 
</p>

<p>
	Google One benefits are gradually diminishing, as Google either cancels them or makes them freely available to all users. Recently, Google also discontinued the VPN feature that was previously available for Google One users. As of today, Google One Premium plan users have the following benefits:
</p>

<p>
	 
</p>

<ul>
	<li>
		Additional storage depending on the Premium plan
	</li>
	<li>
		Unlimited saves in Magic Editor with a Google One Premium plan.
	</li>
	<li>
		<p>
			Get up to 10% back on Google Store purchases.
		</p>
	</li>
	<li>
		<p>
			Longer video calling in Google Meet
		</p>
	</li>
	<li>
		<p>
			Enhanced appointment scheduling features in Google Calendar
		</p>

		<p>
			 
		</p>
	</li>
</ul>

<p>
	Via: <a href="https://9to5google.com/2024/07/09/google-one-dark-web-reports-all-google-accounts/" rel="external nofollow">9to5Google</a>
</p>

<p>
	 
</p>

<p>
	<a href="https://www.neowin.net/news/google-will-make-dark-web-reports-available-to-all-consumer-google-account-users-for-free/" rel="external nofollow">Source</a>
</p>

<p>
	 
</p>

<p>
	<span style="font-size:12px;"><em>Hope you enjoyed this news post.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>Thank you for appreciating my time and effort posting news every single day for many years.</em></span>
</p>

<p>
	<span style="font-size:12px;"><em>2023: Over 5,800 news posts | 2024 (till end of June): 2,839 news posts</em></span>
</p>
]]></description><guid isPermaLink="false">24139</guid><pubDate>Wed, 10 Jul 2024 20:00:27 +0000</pubDate></item></channel></rss>
