Slashdot is powered by your submissions, so send in your scoop

 



Forgot your password?
typodupeerror

Submission + - Could Data Destruction + Exfiltration Replace Ransomware? (esecurityplanet.com)

storagedude writes: Ransomware groups have been busy improving their data exfiltration tools, and with good reason: As ransomware decryption fails to work most of the time, victims are more likely to pay a ransom to keep their stolen data from being publicly leaked.

But some security researchers think the trend suggests that ransomware groups may change their tactics entirely and abandon ransomware in favor of a combined approach of data destruction and exfiltration, stealing the data before destroying it and any backups, thus leaving the stolen copy of the data as the only hope for victims to recover their data. After all, if ransomware just destroys data anyway, why waste resources developing it?

“With data exfiltration now the norm among threat actors, developing stable, secure, and fast ransomware to encrypt files is a redundant and costly endeavor compared to corrupting files and using the exfiltrated copies as the means of data recovery,” Cyderes researchers wrote after analyzing an attack last month.

“Eliminating the step of encrypting the data makes the process faster and eliminates the risk of not getting the full payout, or that the victim will find other ways to decrypt the data," they added. “Data destruction is rumored to be where ransomware is going to go, but we haven’t actually seen it in the wild. During a recent incident response, however, Cyderes and Stairwell discovered signs that threat actors are actively in the process of staging and developing this capability.”

That incident – involving BlackCat/ALPHV ransomware – turned up an exfiltration tool with hardcoded sftp credentials that was analyzed by Stairwell’s Threat Research Team, which found partially-implemented data destruction functionality.

"The use of data destruction by affiliate-level actors in lieu of RaaS deployment would mark a large shift in the data extortion landscape and would signal the balkanization of financially-motivated intrusion actors currently working under the banners of RaaS affiliate programs,” the Stairwell researchers wrote.

Submission + - Why is My Cat Using Baidu? And Other IoT DNS Oddities (sans.edu)

UnderAttack writes: IoT devices are often stitched together from various odd libraries and features. The SANS Internet Storm Center has a story about a cat feeder that not only appears to reach out to Baidu.com every five minutes but also uses a vulnerabile DNS library that uses repeating query ids allowing for simple spoofing not seen since the early dark years of DNS

Submission + - Australia's Medibank Says Data of All 4 Million Customers Accessed By Hacker (reuters.com)

An anonymous reader writes: Australia's biggest health insurer, said on Wednesday a cyber hack had compromised the data of all of its of its nearly 4 million customers, as it warned of a $16 million to $22.3 million hit to first-half earnings. It said on Wednesday that all personal and significant amounts of health claims data of all its customers were compromised in the breach reported this month, a day after it warned the number of customers affected would grow.

Medibank, which covers one-sixth of Australians, said the estimated cost did not include further potential remediation or regulatory expenses. The company reiterated that its IT systems had not been encrypted by ransomware to date and that it would continue to monitor for any further suspicious activity. "Everywhere we have identified a breach, it is now closed," John Goodall, Medibank's top technology executive, told an analyst call on Wednesday.

Submission + - New Zealand Uber Drivers Win Landmark Case Declaring Them Employees (theguardian.com)

An anonymous reader writes: A group of New Zealand Uber drivers have won a landmark case against the global ridesharing company, forcing it to treat them as employees, not contractors, and entitling them to a suite of worker rights and protections. New Zealand’s employment court ruled on Tuesday that the drivers were employees, not independent contractors. While the ruling applies specifically to the case of four drivers, the court noted that it may have wider implications for drivers across the country. The court “does not have jurisdiction to make broader declarations of employment status” so all Uber drivers “do not, as a result of this judgment, instantly become employees," chief judge Christina Inglis wrote. She continued, however: “It may well have broader impact, particularly where, as here, there is apparent uniformity in the way in which the companies operate, and the framework under which drivers are engaged.”

Employment status is the bedrock on which most of New Zealand’s minimum employment rights rest. It is “the gate through which a worker must pass” before they can access legal minimum entitlements including the minimum wage, six minimum hours of work, rest and meal breaks, holidays, parental leave, domestic violence leave, bereavement leave, ability to pursue a personal grievance, and access to union membership and collective bargaining.

Submission + - Disappointment: Dwarf star's rocky planet lacks a detectable atmosphere (cnn.com)

Tablizer writes: CNN: The hunt for planets that could harbor life may have just narrowed dramatically.

Scientists had long hoped and theorized that the most common type of star in our universe — called an M dwarf — could host nearby planets with atmospheres, potentially rich with carbon and perfect for the creation of life. But in a new study of a world orbiting an M dwarf 66 light-years from Earth, researchers found no indication such a planet could hold onto an atmosphere at all.

Without a carbon-rich atmosphere, it’s unlikely a planet would be hospitable to living things. Carbon molecules are, after all, considered the building blocks of life. And the findings don’t bode well for other types of planets orbiting M dwarfs, said study coauthor Michelle Hill, a planetary scientist and a doctoral candidate at the University of California, Riverside.

“The pressure from the star’s radiation is immense, enough to blow a planet’s atmosphere away,” Hill said in a post on the university’s website...

They pored over the data produced by Spitzer, searching for emission signatures, or signs that a gaseous bubble could encase the planet. The telescope captured the planet as it passed behind its home star, allowing researchers to “look at the starlight as it’s passing through the atmosphere of the planet,” giving a “spectral signature of the atmosphere” — or lack thereof, Hill said.

Hill added that she wasn’t shocked to find no signs of an atmosphere, but she was disappointed. She’s looking for moons and planets in “habitable zones,” and the results made looking at worlds circling the ubiquitous M dwarf stars slightly less interesting.

Submission + - Intel Launches 8th Generation Core CPUs (anandtech.com)

joshtops writes: Today Intel is launching its new 8th Generation family of processors, starting with four CPUs for the 15W mobile family. There are two elements that make the launch of these 8th Gen processors different. First is that the 8th Gen is at a high enough level, running basically the same microarchitecture as the 7th Gen. But the key element is that, at the same price and power where a user would get a dual core i5-U or i7-U in their laptop, Intel will now be bumping those product lines up to quad-cores with hyperthreading. This gives a 100% gain in cores and 100% gain in threads. Obviously nothing is for free, so despite Intel stating that they've made minor tweaks to the microarchitecture and manufacturing to get better performing silicon, the base frequencies are down slightly. Turbo modes are still high, ensuring a similar user experience in most computing tasks. Memory support is similar — DDR4 and LPDDR3 are supported, but not LPDDR4 — although DDR4 moves up to DDR4-2400 from DDR4-2133. Another change from 7th Gen to 8th Gen will be in the graphics. Intel is upgrading the nomenclature of the integrated graphics from HD 620 to UHD 620, indicating that the silicon is suited for 4K playback and processing.

Submission + - US Customs Wants To Know Travelers' Social Media Account Names (helpnetsecurity.com)

Orome1 writes: The US Customs and Border Protection agency has submitted a request to the Office of Management and Budget, asking for permission to collect travelers social media account names as they enter the country. The CBP, which is part of the US Department of Homeland Security, proposes that the request “Please enter information associated with your online presence — Provider/Platform — Social media identifier” be added to the Electronic System for Travel Authorization (ESTA) and to the CBP Form I-94W (Nonimmigrant Visa Waiver Arrival/Departure).

Slashdot Top Deals

Machines take me by surprise with great frequency. - Alan Turing

Working...