Lawyers Could Net $30m in Yahoo Data Breach Settlement

Lawyers Could Net $30m in Yahoo Data Breach Settlement

Lawyers who secured a $117.5m deal to resolve litigation tied to multiple data breaches at Yahoo could get paid $30m for their efforts.

Class counsel who secured the breach settlement are currently waiting for US District Judge Lucy Koh to give her final stamp of approval and to award them the fees, according to new documents filed in California federal court.

The sizeable settlement, approved by a federal judge in California last summer, relates to a host of massive historic data breaches that occurred at Yahoo between 2012 and 2016. Data exposed included names, email addresses, telephone numbers, birth dates, passwords, security questions and answers, as well as potentially the contents of emails, calendars, and contacts.

The deal will allow only 194 million Yahoo users in the US and Israeli who were affected by the breaches to claim compensation. Globally, the breaches impacted some 3 billion Yahoo users.

Consumers or small business affected by the breach could potentially get up to $25,000 in reimbursement if they had out-of-pocket expenses tied to the breach, such as losses or fees incurred as a result of handling identity fraud or setting up credit monitoring.

Individuals who didn’t suffer any direct harm from the breach will be given the option to claim for free credit monitoring. Users who demonstrate they have a minimum of 12 months of credit monitoring can claim a cash payout of up to $100. 

The amount of the cash payment that actually gets paid depends on how many people file for the benefit. If funds remain after all the claims are paid, then claimants could get up to $358.80 each. However, due to the 194 million potential claimants involved, the real payout could be as little as 60 cents per user. 

If even a third of the potential class members lodge a claim, then the payout will be $1.84 per person. 

Commenting on the settlement to CNBC, cybersecurity expert Joseph Steinberg predicted that the actual amount of compensation Yahoo users will receive is likely to be far lower.

“Everybody probably has free credit monitoring at this point,” said Steinberg. “If you’re expecting to get $100, you’re probably going to be significantly disappointed.”

Settlement class members have until July 20 to sign up for credit monitoring or alternative compensation.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Gorgon Group Grows More Sophisticated

Gorgon Group Grows More Sophisticated

New research has revealed that the threat group behind the cryptocurrency-stealing MasterMana botnet has grown increasingly sophisticated and is now trapping victims through spoofed login portals.

Gorgon Group has been observed targeting the European Union as well as Dubai’s main electrical/water utility DEWA with fake login pages that are highly convincing.

The illicit activity was detected by researchers at cyber-intelligence firm Prevailion, who published a report yesterday on the growing threat posed by Gorgon Group. 

In another newly detected campaign, researchers observed Gorgon Group using a clever social engineering scheme targeting Spanish/Portuguese speakers with typo-squatted hotel websites and spoofed reservation confirmations.

Historically, the group has relied on cheap malware obtained via the dark web to orchestrate their dastardly scams, but researchers say that Gorgon Group is now developing and customizing these tools to become even more dangerous. 

“I am surprised at the level of sophistication that this group has shown over the past year,” Prevailion’s director of intelligence analysis, Danny Adamitis, told Infosecurity Magazine. “During this time, they have taken a number of steps in order to increase their operational security both against network and host-based detection. 

“One example is their use of the new ‘office.dll’ that would elevate the actor’s privilege level and then disable Windows Defender. Another example is the actor going back and modifying an old Pastebin post in order to make tracking their activity more difficult.”

Along with the new “office.dll,” Gorgon Group has rocked out a variant of the NJrat trojan and a new, trojanized PowerPoint file, as well as a downloader that references the lyrics of rapper Drake.

Adamitis, whose favorite Drake track is “God’s Plan,” said it was difficult to predict how the threat group would evolve.

He said: “Unfortunately we don’t have enough data at this time to make any sound conclusions about their intent.”

It is not currently known from where Gorgon Group operates, though Adamitis speculates that the group is operating out of Pakistan.  

Adamitis said: “We have observed some Gorgon Group activity occurring from Pakistani-based IP addresses; however, IP addresses can be spoofed. We do not have enough evidence at this time to make any definitive comments on attribution.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

White Hats Shine a Light on Philips Hue Hack

White Hats Shine a Light on Philips Hue Hack

Security researchers have discovered a new exploit which could allow hackers to compromise home and corporate IT networks via smart light bulbs.

The CVE-2020-6007 flaw exists in the Zigbee wireless protocol used to communicate with IoT devices. Check Point white hats found a way to exploit the bug in popular Philips Hue smart bulbs to take control of the bulbs’ control bridge and then attack the network.

However, to achieve the above, a hacker would first need to implant malicious firmware on the bulb itself. By doing so, they can tamper with the settings remotely to trick the user into thinking there is a fault.

As the bulb appears “unreachable” in the user’s control app, they will try to reset it, by deleting it from the app and then instructing the control bridge to re-discover it.

Once the user has added the compromised bulb back onto the network, it can use the Zigbee vulnerability to trigger a heap-based buffer overflow on the control bridge by inundating it with data.

“This data also enables the hacker to install malware on the bridge – which is in turn connected to the target business or home network,” Check Point explained. “The malware connects back to the hacker and using a known exploit (such as EternalBlue), they can infiltrate the target IP network from the bridge to spread ransomware or spyware.”

Check Point disclosed the research to Philips and Hue brand owner Signify in November 2019 and waited until now to publish so the manufacturer had time to release a firmware update, which it has.

However, as the main problem lies with the Zigbee protocol itself, there could be a range of other IoT devices vulnerable to exploitation in a similar way.

This isn’t the first time critical flaws have been found in the popular low-power comms protocol. Back in 2015, Black Hat researchers outlined a range of threats to the smart home through its unsecure use of encryption keys.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

UK Government Under Fire Over NSO Group Links

UK Government Under Fire Over NSO Group Links

The British government is under fire after it emerged that controversial espionage software provider NSO Group has been invited to a secretive security trade fair next month.

According to the Guardian, the government will host the Israeli firm as an exhibitor at the closed-door Security and Policing Home Office event in early March.

The Farnborough-based event is marketed by the Home Office as “the official government global security event, offering a world-class opportunity to meet, network and discuss the latest advances in delivering national security and resilience with UK suppliers, colleagues and government officials.”

The NSO Group is currently being sued by WhatsApp in the US over allegations it helped to develop and deploy malware used to spy on over 1000 users of the messaging app.

Attacks using the firm’s Pegasus spyware have been detected by rights activists, journalists, political dissidents and others, and are thought to be used by repressive regimes to monitor those who oppose them.

However, NSO Group has always claimed it offers its tools for only legitimate law enforcement and intelligence purposes.

It was recently forced to deny involvement in the hacking of Amazon boss Jeff Bezos’s iPhone by Saudi Arabian crown prince, Mohammed bin Salman.

According to a report by UN special rapporteurs Agnes Callamard and David Kaye, Bezos received an MP4 file loaded with malware via WhatsApp which then proceeded to exfiltrate data on a massive scale.

“The forensic analysis assessed that the intrusion likely was undertaken through the use of a prominent spyware product identified in other Saudi surveillance cases, such as the NSO Group’s Pegasus-3 malware, a product widely reported to have been purchased and deployed by Saudi officials,” the UN analysis claimed.

“This would be consistent with other information. For instance, the use of WhatsApp as a platform to enable installation of Pegasus onto devices has been well-documented and is the subject of a lawsuit by Facebook/WhatsApp against NSO Group.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Facebook Encryption Plans Slammed by Children’s Charities

Facebook Encryption Plans Slammed by Children’s Charities

Facebook is coming under increasing pressure over its encryption plans after the NSPCC and 100 other organizations signed an open letter warning that more secure messaging could undermine child safety.

The social media giant is set to roll out end-to-end encryption for users of its Messenger and Instagram Direct services as part of efforts to improve user privacy and data protection.

However, encryption is often portrayed by governments and law enforcement as the bad guy, in protecting not only hundreds of millions of law-abiding users but also the small number who use it to hide criminal acts.

Child charities like the NSPCC agree, hence the open letter, which was also signed by Barnardo’s, 5Rights, the International Centre For Missing and Exploited Children and Child USA. It argues that encryption provides a safe space for pedophiles to operate online.

“We urge you to recognize and accept that an increased risk of child abuse being facilitated on or by Facebook is not a reasonable trade-off to make,” the letter reportedly said.

“Children should not be put in harm’s way either as a result of commercial decisions or design choices.”

The NSPCC claims that, according to FOI data obtained from UK police forces, Facebook, Instagram and WhatsApp were used in child abuse image and online child sexual offences on average 11 times per day over a 12-month period to March 2019.

Despite the pressure from the UK government and children’s charities, it’s unlikely that Facebook will change its plans, given its renewed commitment to data protection and user privacy.

Jake Moore, cybersecurity expert at ESET, agreed with the social network’s decision to press ahead.

“Encryption is the backbone of the internet; without it, you lose all security. If you create a backdoor to encryption, you undermine the encryption entirely,” he argued.

“I think Facebook are right to secure their applications, which in fact protects users. Taking away encryption allows cyber-criminals to view sensitive data, which creates more problems in the long run. You could also argue that if Facebook was to allow access to its messaging platforms, many users could simply move to other more privacy-focused applications.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk