Advarer mot skreddersydd svindel etter datalekkasje – NRK

https://www.nrk.no/norge/advarer-mot-skreddersydd-svindel-etter-datalekkasje-1.15963551

Personopplysningene som er på avveie etter det store datainnbruddet mot Norkart, kan åpne for mer utspekulerte former for svindel, tror ekspert.

[…]

De neste månedene anbefaler han å være ekstra varsom for spesielle brev, e-poster og telefoner.

– Bruk god dømmekraft, og være skeptisk – hver eneste gang du får en henvendelse, hvor du ikke enkelt kan identifisere hvem som står bak, påpeker Jøsang.

Dataangrep mot Norkart: 3,3 millioner kan være berørt – NRK

https://www.nrk.no/norge/dataangrep-mot-norkart_-3_3-millioner-kan-vaere-berort-1.15962268

Selskapet Norkart, som leverer IT-systemer for kart- og eiendomsinformasjon, er utsatt for et dataangrep. Persondata for opp mot 3,3 millioner innbyggere er på avveier.

Selskapet varslet om dataangrepet tirsdag. Alle som eier eiendom i Norge kan være berørt.

[…]

– Det vi ønsker nå er at alle som er eiere eller festere er ekstra årvåkne når det gjelder forsøk på svindel. Et godt råd er å sperre seg for sjekk av kredittopplysninger og følge med på hva som skjer i postkassen din.

Facebook removes ‘deepfake’ of Ukrainian President Zelenskyy - The Verge

https://www.theverge.com/2022/3/16/22981806/facebook-removes-deepfake-ukraine-zelenskyy-meta-instagram

In the fake video, Zelenskyy surrenders to Russian invasion

The deepfake appears to have been first broadcasted on a Ukrainian news website for TV24 after an alleged hack

Researcher uses Dirty Pipe exploit to fully root a Pixel 6 Pro and Samsung S22 - Ars Technica

https://arstechnica.com/information-technology/2022/03/researcher-uses-dirty-pipe-exploit-to-fully-root-a-pixel-6-pro-and-samsung-s22/

It was bound to happen. Worst Linux vulnerability in 6 years fells two popular handsets.

Attackers can force Amazon Echos to hack themselves with self-issued commands - Ars Technica

https://arstechnica.com/information-technology/2022/03/attackers-can-force-amazon-echos-to-hack-themselves-with-self-issued-commands/

Popular “smart” device follows commands issued by its own speaker. What could go wrong?

2FA app with 10,000 Google Play downloads loaded well-known banking trojan | Ars Technica

https://arstechnica.com/information-technology/2022/01/2fa-app-with-10000-google-play-downloads-loaded-well-known-banking-trojan/

A fake two-factor-authentication app that has been downloaded some 10,000 times from Google Play surreptitiously installed a known banking-fraud trojan that scoured infected phones for financial data and other personal information, security firm Pradeo said.

Israeli police used spyware to hack its own citizens, a report says : NPR

https://www.npr.org/2022/01/18/1073828708/israel-spyware-citizens-nso-group

Israeli police have used spyware from controversial Israeli company NSO Group to hack the cell phones of Israeli citizens without judicial oversight, including activists protesting former Prime Minister Benjamin Netanyahu, an Israeli newspaper reported Tuesday.

The Israeli spyware company faces mounting global scrutiny and recent U.S. sanctions for equipping regimes with powerful surveillance tools used to target human rights activists, journalists and politicians. Recently, Palestinian activists said their phones were infected with NSO spyware.

U.S. State Department phones hacked with Israeli company spyware - sources - Reuters

https://www.reuters.com/technology/exclusive-us-state-department-phones-hacked-with-israeli-company-spyware-sources-2021-12-03/

iPhones of at least nine U.S. State Department employees were hacked by an unknown assailant using sophisticated spyware developed by the Israel-based NSO Group

Google Caught Hackers Using a Mac Zero-Day Against Hong Kong Users

https://www.vice.com/en/article/93bw8y/google-caught-hackers-using-a-mac-zero-day-against-hong-kong-users

The hackers had set up a watering hole attack, meaning they hid malware within the legitimate websites of “a media outlet and a prominent pro-democracy labor and political group” in Hong Kong. Users who visited those websites would get hacked with an unknown vulnerability—in other words, a zero-day—and another exploit that took advantage of a previously patched vulnerability for MacOS that was used to install a backdoor on their computers, according to Hernandez. 

Apple patched the zero-day used in the campaign in an update pushed out on September 23, according to the report.

Østre Toten kommune får fire millioner i bot etter dataangrepet mot kommunen – NRK

https://www.nrk.no/innlandet/ostre-toten-kommune-far-fire-millioner-i-bot-etter-dataangrepet-mot-kommunen-1.15695776

kommunen har hatt store mangler på grunnleggende sikkerhet.

– Vi ser at det har vært mangler i logging, av tofaktorautorisering, innen sikkerhetskultur og i rutiner for backup.

Tilsynet skriver i vedtaket at de ser særlig alvorlig på at personopplysninger og opplysninger om barn er rammet av angrepet. Begge har krav på et særskilt vern. Dataene er tapt for kommunen og delt i ukjent omfang på det mørke nettet.

The NSA and CIA Use Ad Blockers Because Online Advertising Is So Dangerous

https://www.vice.com/en/article/93ypke/the-nsa-and-cia-use-ad-blockers-because-online-advertising-is-so-dangerous

The news highlights the continued risk from the online advertising ecosystem. Some hackers leverage how adverts are delivered to send target devices malware. Data brokers and potentially intelligence agencies can leverage the ecosystem to gather information on devices and by extension people, sometimes including their physical location. The IC taking steps to protect itself from the dangers of the advertising ecosystem shows just how malicious it can be.

Forensic Methodology Report: How to catch NSO Group’s Pegasus - Amnesty International

https://www.amnesty.org/en/latest/research/2021/07/forensic-methodology-report-how-to-catch-nso-groups-pegasus/

Amnesty International’s Security Lab has performed in-depth forensic analysis of numerous mobile devices from human rights defenders (HRDs) and journalists around the world. This research has uncovered widespread, persistent and ongoing unlawful surveillance and human rights abuses perpetrated using NSO Group’s Pegasus spyware.

Most recently, a successful “zero-click” attack has been observed exploiting multiple zero-days to attack a fully patched iPhone 12 running iOS 14.6 in July 2021.

How does Apple technology hold up against NSO spyware? - The Guardian

https://www.theguardian.com/news/2021/jul/19/how-does-apple-technology-hold-up-against-nso-spyware

The iPhone maker says it is keeping pace with malware, but the Pegasus project paints a worrying picture

Revealed: leak uncovers global abuse of cyber-surveillance weapon - Surveillance - The Guardian

https://www.theguardian.com/world/2021/jul/18/revealed-leak-uncovers-global-abuse-of-cyber-surveillance-weapon-nso-group-pegasus

Human rights activists, journalists and lawyers across the world have been targeted by authoritarian governments using hacking software sold by the Israeli surveillance company NSO Group, according to an investigation into a massive data leak.

The investigation by the Guardian and 16 other media organisations suggests widespread and continuing abuse of NSO’s hacking spyware, Pegasus, which the company insists is only intended for use against criminals and terrorists.

Pegasus is a malware that infects iPhones and Android devices to enable operators of the tool to extract messages, photos and emails, record calls and secretly activate microphones.

U.S. and key allies accuse China of Microsoft Exchange cyberattacks - Axios

https://www.axios.com/china-cyberattacks-nato-181e71d2-7414-45f3-9463-c8b1d46392c1.html

The U.S., NATO, European Union, U.K., Australia, Canada, New Zealand and Japan say they can now, “with high confidence,” attribute the March attack using the Exchange flaw to cyberattackers affiliated with China’s state security ministry. That attack crippled thousands of computers around the world.

Stort dataangrep mot norsk ingeniørselskap – NRK Norge – Oversikt over nyheter fra ulike deler av landet

https://www.nrk.no/norge/stort-dataangrep-mot-norsk-ingeniorselskap-1.15568171

Hackargruppa hevdar dei har 2000 gigabyte med sensitiv informasjon som dei vil publisere viss selskapet ikkje innfrir kravet

A new ‘digital violence’ platform maps dozens of victims of NSO Group’s spyware - TechCrunch

https://techcrunch.com/2021/07/03/digital-violence-nso-group-spyware/

The research reveals new links between phone hacks and real-world violence

For the first time, researchers have mapped all the known targets, including journalists, activists, and human rights defenders, whose phones were hacked by Pegasus, a spyware developed by NSO Group

Sverige: Hackere krever 600 millioner kroner – NRK

https://www.nrk.no/urix/sverige_-hackere-krever-600-millioner-kroner-1.15564723

Angrepet har rammet hundrevis av selskaper over hele verden. Blant dem er svenske Coop, som har måttet stenge hundrevis av dagligvarebutikker, Apotek Hjärtat og SJ.

Kravet er blitt publisert på bloggen til hackergruppen Revil og virker ifølge eksperter autentisk.

Angrepet ble innledet fredag og var rettet mot det amerikanske programvareselskapet Kaseya, som selger tjenester til kunder over hele verden, deriblant Coop.

It-attack bakom Coops kassahaveri – stänger butikerna i hela Sverige - SVT

https://www.svt.se/nyheter/inrikes/coop-tvingas-stanga-efter-kassahaveri

NFC Flaws Let Researchers Hack ATMs by Waving a Phone - WIRED

https://www.wired.com/story/atm-hack-nfc-bugs-point-of-sale/

FOR YEARS, SECURITY researchers and cybercriminals have hacked ATMs by using all possible avenues to their innards, from opening a front panel and sticking a thumb drive into a USB port to drilling a hole that exposes internal wiring. Now one researcher has found a collection of bugs that allow him to hack ATMs—along with a wide variety of point-of-sale terminals—in a new way: with a wave of his phone over a contactless credit card reader.

Rodriguez has built an Android app that allows his smartphone to mimic those credit card radio communications and exploit flaws in the NFC systems’ firmware.