Mobile spyware fan Saudi Crown Prince accused by US intel of Khashoggi death
- Reference: 1614580809
- News link: https://www.theregister.co.uk/2021/03/01/in_brief_security/
- Source link:
Khashoggi, a critic of the ruling Saudi Arabian royal family, was ambushed and [1]assassinated in 2018 when he visited the Saudi embassy in Istanbul thinking he was collecting paperwork for his upcoming wedding.
[2]
Last week, Uncle Sam's Office of the Director of National Intelligence (ODNI) [3]released a statement fingering Crown Prince Mohammed bin Salman for orchestrating the killing, which [4]a lawsuit claims was aided by tracking technology provided by spyware biz [5]NSO Group . Saudi-born Khashoggi was a legal US resident on an O-type visa reserved for foreigners of exceptional ability and achievements.
The Crown Prince, according to the UN, also had Washington Post owner and Amazon supremo Jeff Beozs's iPhone [6]hacked to dig up dirt on the American billionaire.
[7]
Warning: Cisco app services insecure due to critical flaw
If you're running Cisco Application Services Engine release 1.1(3d) and earlier, it's time to get patching: anyone who can reach a vulnerable installation can hijack it.
"Multiple vulnerabilities in Cisco Application Services Engine could allow an unauthenticated, remote attacker to gain privileged access to host-level operations or to learn device-specific information, create diagnostic files, and make limited configuration changes," Switchzilla warned in a Wednesday [8]advisory .
The remote-control flaw was assigned CVE-2021-1393, and is rated 9.8 out of 10 in severity on the CVSS scale. Another bug, CVE-2021-1396, rated 6.5, can be exploited to grant an "unauthenticated, remote attacker access to a specific API on an affected device."
Stormy weather for boat-builder Beneteau
Some boat building staff at top-tier French shipwrights Beneteau have had the week off after production facilities were shut down in response to a cyber-attack. Last week, the group [9]warned it has suffered "a malware intrusion affecting some of its servers," and was having to shut down a number of departments to stop the software nasty from spreading further.
"Accompanied by experts and the relevant authorities, the group’s teams are fully mobilized to address the consequences of this attack," it said. "Firstly, the deployment of a backup application and systems will enable activities to start up again securely, but in degraded mode. Alongside this, investigations will continue moving forward with a view to fully restoring all of the Group’s systems."
That doesn't seem to have been easy. By Thursday, the boating biz [10]posted an update saying work is still ongoing, and it might reopen some plants on Friday. Its manufacturing facilities in France have been particularly hard hit, it said.
Keybase patches image bug
A quartet of security boffins going under the name Sakura Samurai [11]found the desktop app of Zoom-owned encrypted comms biz [12]Keybase stores images in plaintext in temporary files. This shortcoming is present in the Windows, macOS and Linux builds of the code. The upshot is that if you encrypt and send a sensitive picture to someone via Keybase, delete your copy of the file, and then someone breaks into your computer somehow, they could view the pictures in plain-text in a cache.
"A user, believing that they are sending photos that can be cleared later, may not realize that sent photos are not cleared from the cache and may send photos of PII or other sensitive data to friends or colleagues," the team noted.
"In addition, there are legal ramifications to such storage of information. For example, Keybase is presenting itself as a secure end-to-end encryption solution. A vulnerability in such a sense could lead to private data being used in court cases against individuals, destroying Keybase’s reputation as a secure and private communication platform."
Users will need to update to Keybase 5.6.0 or later for Windows and macOS, or Keybase 5.6.1 or later for Linux. Updating is usually automatic for Windows and macOS users.
NSA advocates zero trust
The American government's top hackers have issued a [13]memorandum , advising organizations' infosec teams to trust no one, and that zero trust in security is the way to go.
Always question inputs and outputs, verify sources before trusting, and lock down networks so that the participants always have to verify who they are, the NSA stated. The agency has, incidentally, long held an internal network security posture of always assume you're compromised in some way and compartmentalize and defend from there, so this advice isn't too surprising.
"To be fully effective to minimize risk and enable robust and timely responses, Zero Trust principles and concepts must permeate most aspects of the network and its operations ecosystem," it said. "Organizations, from chief executive to engineer and operator, must understand and commit to the Zero Trust mindset before embarking on a Zero Trust path."
This applies particularly in the case of supply chains, the agency warned. As we've seen in the [14]SolarWinds fiasco , and most recently with stolen military designs thanks to [15]Accellion's failings , admins need to be a lot more suspicious of applications and users.
Gab patches database hole amid hack claim
Gab, a digital haven for far-right internet outcasts, has patched a hole in its backend systems that was seemingly used to siphon people's public and private user data.
In a blog post on Friday, Gab CEO Andrew Torba [16]said it was claimed "an archive of Gab public posts, private posts, user profiles, hashed passwords for users, DMs, and plaintext passwords for groups have been leaked via a SQL injection attack. We were aware of a vulnerability in this area and patched it last week. We are also proceeding to undertake a full security audit."
An activist group called Distributed Denial of Secrets said 70GB and 40 million posts were harvested from Gab by a netizen. Photos and videos weren't taken. Gab, like [17]Parler , is home to conspiracy theorists and insurrectionists linked to the January 6 storming of the US Congress building by supporters of now-ex-President Donald Trump. "It's another gold mine of research for people looking at militias, neo-Nazis, the far right, QAnon and everything surrounding January 6," DDoS's Emma Best [18]told Wired of the stolen data.
[19]
Torba first said he had no evidence a security breach had occurred, and then on Sunday complained his and Trump's hashed account passwords had been accessed. ®
Get our [20]Tech Resources
[1] https://en.wikipedia.org/wiki/Assassination_of_Jamal_Khashoggi
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YDzJTA@rmiREqzJJCHagxwAAAFU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://www.odni.gov/index.php/newsroom/reports-publications/reports-publications-2021/item/2186-assessing-the-saudi-government-s-role-in-the-killing-of-jamal-khashoggi
[4] https://www.theguardian.com/world/2020/jan/16/israeli-spyware-firm-nso-hacking-case
[5] https://www.theregister.com/2020/11/17/israeli_hacking_group_goes_hollywood/
[6] https://www.theregister.com/2020/01/22/saudi_bezos_phone_hack/
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YDzJTA@rmiREqzJJCHagxwAAAFU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[8] https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-case-mvuln-dYrDPC6w
[9] https://press.beneteau-group.com/news/information-regarding-a-cyberattack-83cc-49529.html
[10] https://press.beneteau-group.com/news/production-activities-gradually-starting-up-again-95e7-49529.html
[11] https://johnjhacking.com/blog/cve-2021-23827/
[12] https://www.theregister.com/2020/05/07/zoom_buys_keybase/
[13] https://www.nsa.gov/News-Features/Feature-Stories/Article-View/Article/2515176/nsa-issues-guidance-on-zero-trust-security-model/
[14] https://www.theregister.com/2021/02/15/solarwinds_microsoft_fireeye_analysis/
[15] https://www.theregister.com/2021/02/24/seaspray_radar_ransomware/
[16] https://news.gab.com/2021/02/26/alleged-data-breach-26-february-2021/
[17] https://www.theregister.com/2021/01/21/parler_aws_injunction/
[18] https://www.wired.com/story/gab-hack-data-breach-ddosecrets/
[19] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YDzJTA@rmiREqzJJCHagxwAAAFU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[20] https://whitepapers.theregister.com/
Re: Saudi Arabia.
In exchange for some of that apocalyptic strategic resource, aka, go go juice, soon to be replaced with BRAWNDO The Thirst Mutilator, in the near future
The world is run by a bunch of old cunts
How do you feel about this shit show?
I can't help thinking that there is probably a bit more to the Khashoggi story than is being publicly discussed. The bit about collecting paperwork for his wedding doesn't sound quite true. I wonder if he was really expecting to collect some classified information from a source within the embassy. Or if he was on a mission for some intelligence agency.
So basically you're looking to slander the murdered by claiming they're a double agent or some such.
I think there's quite enough corruption to go around without delving into outright fantasy
I can't help thinking you're here to spread misinformation and bullshit.
Tell me, tell me, tell me
Oh, who wrote the Book Of Love?
I've got to know the answer
Was it someone from above?
"I can't help thinking ..."
You stopped before the "you'll be amazed at what happened next" bit.
... And ?
ordered by the head of the Saudi Arabian government, US intelligence has publicly asserted
Well, [1]this is about as good as it gets.
Nothing to see here. Move right along.
Disgusting.
[1] https://www.youtube.com/watch?v=plZRe1kPWZw
Saudi Arabia.
You murdered this man!
By the way, do you want to buy some more weapons?