23andMe confirms hackers stole ancestry data on 6.9 million users | TechCrunch

https://techcrunch.com/2023/12/04/23andme-confirms-hackers-stole-ancestry-data-on-6-9-million-users/

On Friday, genetic testing company 23andMe announced that hackers accessed the personal data of 0.1% of customers, or about 14,000 individuals. The company also said that by accessing those accounts, hackers were also able to access “a significant number of files containing profile information about other users’ ancestry.” But 23andMe would not say how many “other users” were impacted by the breach that the company initially disclosed in early October.

As it turns out, there were a lot of “other users” who were victims of this data breach: 6.9 million affected individuals in total.

In an email sent to TechCrunch late on Saturday, 23andMe spokesperson Katie Watson confirmed that hackers accessed the personal information of about 5.5 million people who opted-in to 23andMe’s DNA Relatives feature, which allows customers to automatically share some of their data with others. The stolen data included the person’s name, birth year, relationship labels, the percentage of DNA shared with relatives, ancestry reports and self-reported location.

Sellafield nuclear site hacked by groups linked to Russia and China |The Guardian

https://www.theguardian.com/business/2023/dec/04/sellafield-nuclear-site-hacked-groups-russia-china

It is still not known if the malware has been eradicated. It may mean some of Sellafield’s most sensitive activities, such as moving radioactive waste, monitoring for leaks of dangerous material and checking for fires, have been compromised.

Sources suggest it is likely foreign hackers have accessed the highest echelons of confidential material at the site, which sprawls across 6 sq km (2 sq miles) on the Cumbrian coast and is one of the most hazardous in the world.

Sellafield covers 6 sq km on the Cumbrian coast and is one of the most hazardous nuclear sites in the world. Photograph: David Levene/The Guardian
The full extent of any data loss and any ongoing risks to systems was made harder to quantify by Sellafield’s failure to alert nuclear regulators for several years, sources said.

Israel warns citizens of security camera hack risk | Risky Biz News

In the face of an escalating military conflict with Hamas and Hezbollah forces, the Israeli government has asked citizens to secure home security cameras or shut them down completely, fearing the devices could be hacked and used for espionage and intelligence collection.

In a memo on Friday, Israel’s National Cyber Directorate has asked camera owners to change their passwords, enable two-factor authentication if present, and enable automatic security updates.

If camera owners can’t change any of their settings, officials have urged owners to either cover camera lenses or shut down devices completely.Israeli officials aren’t taking any chances and have most likely learned a vital lesson from the recent Russo-Ukrainian conflict, where security cameras across Ukraine have been hacked by Russian hackers to track military aid convoys and adjust missile targeting in real-time.

In addition, there is also a propaganda aspect to take into consideration. Since the initial Hamas attack on October 7, footage taken from hacked security cameras showing Hamas rockets hitting Israeli homes has also been widely shared online.

Risky Biz News: Israel warns citizens of security camera hack risk

Security Vulnerability of Switzerland’s E-Voting System – Schneier on Security

https://www.schneier.com/blog/archives/2023/10/security-vulnerability-of-switzerlands-e-voting-system.html

Online voting is insecure, period. This doesn’t stop organizations and governments from using it. (And for low-stakes elections, it’s probably fine.) Switzerland—not low stakes—uses online voting for national elections.

Inside the deadly instant loan app scam that blackmails with nudes – BBC News

https://www.bbc.com/news/world-asia-india-66964510

The business model is brutal but simple.
There are many apps that promise hassle-free loans in minutes. Not all of them are predatory. But many – once downloaded – harvest your contacts, photos and ID cards, and use that information later to extort you.
When customers don’t repay on time – and sometimes even when they do – they share this information with a call centre where young agents of the gig economy, armed with laptops and phones are trained to harass and humiliate people into repayment.

Genetics firm 23andMe says user data stolen in credential stuffing attack – BleepingComputer

https://www.bleepingcomputer.com/news/security/genetics-firm-23andme-says-user-data-stolen-in-credential-stuffing-attack/

The initial data leak was limited, with the threat actor releasing 1 million lines of data for Ashkenazi people. However, on October 4, the threat actor offered to sell data profiles in bulk for $1-$10 per 23andMe account, depending on how many were purchased.

A 23andMe spokesperson confirmed the data is legitimate and told BleepingComputer that the threat actors used exposed credentials from other breaches to access 23andMe accounts and steal the sensitive data.

https://arstechnica.com/security/2023/10/private-23andme-user-data-is-up-for-sale-after-online-scraping-spree/

The information that has been exposed from this incident includes full names, usernames, profile photos, sex, date of birth, genetic ancestry results, and geographical location.

While there are benefits to storing genetic information online so people can trace their heritage and track down relatives, there are clear privacy threats. Even if a user chooses a strong password and uses two-factor authentication as 23andMe has long urged, their data can still be swept up in scraping incidents like the one recently confirmed. The only sure way to protect it from online theft is to not store it there in the first place.

Rules of engagement issued to hacktivists after chaos

The International Committee of the Red Cross (ICRC) has, for the first time, published rules of engagement for civilian hackers involved in conflicts.The organisation warns unprecedented numbers of people are joining patriotic cyber-gangs since the Ukraine invasion.The eight rules include bans on attacks on hospitals, hacking tools that spread uncontrollably and threats that engender terror among civilians.

https://www.bbc.com/news/technology-66998064

Malicious ad served inside Bing’s AI chatbot

https://www.malwarebytes.com/blog/threat-intelligence/2023/09/malicious-ad-served-inside-bing-ai-chatbot

Considering that tech giants make most of their revenue from advertising, it wasn’t surprising to see Microsoft introduce ads into Bing Chat shortly after its release. However, online ads have an inherent risk attached to them. In this blog, we show how users searching for software downloads can be tricked into visiting malicious sites and installing malware directly from a Bing Chat conversation.

Hacking Gas Pumps via Bluetooth – Schneier on Security

Turns out pumps at gas stations are controlled via Bluetooth, and that the connections are insecure. No details in the article, but it seems that it’s easy to take control of the pump and have it dispense gas without requiring payment.
https://www.schneier.com/blog/archives/2023/10/hacking-gas-pumps-via-bluetooth.html

Norway to fine Meta $98,500 a day over user privacy breach | The Guardian

https://www.theguardian.com/technology/2023/aug/07/norway-meta-fine-user-privacy-breach-targeted-ads

Country’s data protection regulator said firm cannot harvest user information such as physical locations for showing targeted ads

The Need for Trustworthy AI - Schneier on Security

https://www.schneier.com/blog/archives/2023/08/the-need-for-trustworthy-ai.html

If you ask Alexa, Amazon’s voice assistant AI system, whether Amazon is a monopoly, it responds by saying it doesn’t know. It doesn’t take much to make it lambaste the other tech giants, but it’s silent about its own corporate parent’s misdeeds.

When Alexa responds in this way, it’s obvious that it is putting its developer’s interests ahead of yours. Usually, though, it’s not so obvious whom an AI system is serving. To avoid being exploited by these systems, people will need to learn to approach AI skeptically.

Norway investigates cyberattack affecting 12 government ministries

https://therecord.media/norway-investigates-cyberattack-affecting-government-ministries

The Norwegian police are investigating a cyberattack uncovered earlier this month that affected the IT systems used by a dozen government ministries.

Norway’s Office of the Prime Minister, as well as its foreign, defense, and justice ministries, were not affected by the hack because they use a different IT platform, said Erik Hope, head of the government agency in charge of providing security and services to the ministries, during a press briefing on Monday.

According to Hope, the hackers exploited a now-patched vulnerability in the platform of one of the government’s suppliers. The government’s security specialists identified the attack following “unusual” traffic on the supplier’s platform. Hope declined to provide more details until the investigation is over.

The attack didn’t disrupt the government’s operation. As a result of the hack, employees of several Norwegian ministries couldn’t access some shared services on their mobile phones, including email, but they could still use work devices without issue, Norwegian cybersecurity officials said.

Chinese communist party ‘accessed Hong Kong protesters’ TikTok data’ | The Guardian

https://www.theguardian.com/technology/2023/jun/07/communist-party-accessed-hong-kong-protesters-tiktok-data-former-executive-says

A former executive at TikTok’s parent company, ByteDance, has alleged that the Chinese Communist party accessed user data from the social video app belonging to Hong Kong protesters and civil rights activists.

Yintao Yu, a former head of engineering at ByteDance’s US operation, claimed in a legal filing that a committee of Communist party members accessed TikTok data that included the users’ network information, Sim card identifications and IP addresses in a bid to identify the individuals and their locations.

The claims, in a wrongful dismissal lawsuit brought by Yu in a California court and reported by the Wall Street Journal, also allege the party accessed TikTok users’ communications, monitored Hong Kong users who uploaded protest-related content and that Beijing-based ByteDance maintained a “backdoor channel” for the party to access US user data.

Yu alleges in the filing that members of a Communist party committee inside ByteDance had access to a “superuser” credential which was also called a “God credential” and allowed them to view all data collected by ByteDance.

Android phones are vulnerable to fingerprint brute-force attacks

https://www.bleepingcomputer.com/news/security/android-phones-are-vulnerable-to-fingerprint-brute-force-attacks/

Researchers at Tencent Labs and Zhejiang University have presented a new attack called ‘BrutePrint,’ which brute-forces fingerprints on modern smartphones to bypass user authentication and take control of the device.

Brute-force attacks rely on many trial-and-error attempts to crack a code, key, or password and gain unauthorized access to accounts, systems, or networks.

The attacker needs physical access to the target device to launch a BrutePrint attack

NHS data breach: trusts shared patient details with Facebook without consent | The Guardian

https://www.theguardian.com/society/2023/may/27/nhs-data-breach-trusts-shared-patient-details-with-facebook-meta-without-consent

Observer investigation reveals Meta Pixel tool passed on private details of web browsing on medical sites

Report: ‘massive’ Tesla leak reveals data breaches, thousands of safety complaints | The Guardian

https://www.theguardian.com/technology/2023/may/26/tesla-data-leak-customers-employees-safety-complaints

Tesla has failed to adequately protect data from customers, employees and business partners and has received thousands of customer complaints regarding the carmaker’s driver assistance system, Germany’s Handelsblatt has reported, citing 100 gigabytes of confidential data leaked by a whistleblower.

The Handelsblatt report said customer data could be found “in abundance” in a data set labelled “Tesla Files”.

CISA, FDA warn of new Illumina DNA device vulnerability

https://therecord.media/illumina-dna-sequencing-devices-vulnerability-fda-cisa

Several U.S. agencies warned this week about a vulnerability affecting software in devices used for DNA research that would allow hackers access to sensitive patient information.

The Food and Drug Administration (FDA) and the company behind the devices — Illumina — said they have not received any reports indicating the vulnerability has been exploited.

Illumina is one of the world’s biggest manufacturers of medical devices that handle bioanalysis and DNA sequencing.

Hyundai and Kia thefts keep rising despite security fix

https://news.yahoo.com/hyundai-kia-thefts-keep-rising-144034139.html

Nearly three months ago, Hyundai and Kia unveiled software that was designed to thwart an epidemic of thefts of their vehicles, caused by a security flaw that was exposed on TikTok and other social media sites.

So far, it hasn’t solved the problem. Across the country, thieves are still driving off with the vehicles at an alarming rate.

The companies’ affected cars, many of them lower-cost models from the 2011 to early 2022 model years, were not equipped with a theft immobilizer. Such a device contains a computer chip in the key that must be recognized by another chip in the steering column before the engines will start.

Though most automakers have had the chips for years, Hyundai and Kia have lagged behind the industry as a whole in installing them on many models, thereby allowing thieves to exploit the security gap.

NSO Group Exploited New Zero-Click Vulnerabilities in iOS

https://gizmodo.com/nso-group-exploited-new-zero-click-vulnerabilities-in-i-1850347936

Citizen Lab identified three new exploits that targeted iOS users worldwide in 2022. Apple’s Lockdown Mode reportedly worked as promised.

Students’ psychological reports, abuse allegations leaked by ransomware hackers

https://www.nbcnews.com/tech/security/students-psychological-reports-abuse-allegations-leaked-ransomware-hac-rcna79414

Hackers who broke into the Minneapolis Public Schools earlier this year have circulated an enormous cache of files that appear to include highly sensitive documents on schoolchildren and teachers, including allegations of teacher abuse and students’ psychological reports.