IEEE Cipher --- Items from security-related news (E193)
Prior news summaries from Cipher
Summary:
When a US citizen, known for protesting Atlanta's "cop city", returned
home to Atlanta after vacationing in Europe, he was detained at the
airport before being granted entry. US agents told him that he had to
present his phone for examination as part of an investigation into
child sexual abuse. After refusing several demands, he gave the agents a
"duress" passcode that caused the operating on his Google Pixel phone
to delete all his data. Agents in turn charged him with destroying
evidence. This case centers on details of federal law regarding the
rights of citizens who are seeking to enter the country. The US
citizen felt that the detention and search were a fishing expedition
about his political activities, not a legitimate inquiry based on
evidence. The outcome may help to clarify some little-noticed aspects
of US law.
Summary:
On Sunday, dozens of municipal water systems in Minnesota were
subjected to a cyberattack. The report by the state's IT service department
did not indicate that any cities experienced outages or harm,
but the scope of the attack was concerning. They worked with Federal
agencies to investigate the incident, and the general consensus was
that entities in Iran or posing as Iranian entities were responsible
for the incident. No ransom demands were made, and the investigation
is ongoing.
Summary:
Summary:
The Utah Legislative Auditor General issues a report at the beginning of this year center on "drinking water cybersecurity". That report noted the importance of increasing cybersecurity across all of the state's drinking water systems, and it raises possibility of regulation of these entities.
Summary:
When the UK's AI Security Institute (AISI) conducted tests of two AI
systems (OpenAI and Anthropic's Mythos), they noticed "unusual"
activity. Upon investigation they found that the systems were trying
to upload malicious code into GitHub by pretending to be humans
seeking help. OpenAI and Anthropic said that the testers were at
fault for not isolating the tests from the Internet more carefully,
but what concerned AISI was the level of deception that the
systems pursued. Mythos furthered the deception by taking steps
to remove evidence of the fake accounts through which it sent
messages asking for assistance accessing GitHub.
This is not the first time that AI agents have been deceptive and have removed the evidence. One might view the activity as a way of "cleaning up" by removing information that was clearly not wanted by the human user.
Summary:
After months of investigation, the FBI disabled a longstanding overlay
network that was run by Chinese threat actors for the purpose of
evading network traffic controls while finding vulnerable IoT devices
and corrupting them. The overlay network also served as a botnet for
targeting US institutions, including the Department of Justice (DOJ).
There was no information about the victims or damage caused by the
botnet, which may have been operating since 2018.. The Chinese group
is known as "QTFY" and seems closely associated with the Chinese
government.
Summary:
This article is also about dismantling the QTFY network.
Assistant Attorney General for National Security John
A. Eisenberg. "These court-authorized seizures deny PRC-linked
hackers access to tools they use to mount online attacks against our
Nation's critical infrastructure." The press release mentioned other
similar operations carried out by the FBI over the past several years.
Summary:
This article has more information about the QTFY network and its takedown
by the FBI. One interesting note concerns the effect of sending QTFY traffic
over VPNs used by people within China who are evading the "Great Firewall"
censorship. Those networks carry so much traffic that the FBI had trouble
finding the QTFY traffic in the deluge.
Summary:
The FBI apparently left a door ajar on its "jobs portal", the
ShinyHunters group made off with a few terabytes of sensitive
personnel data from applicants, some of whom are presently FBI agents.
The records also included data about former FBI agents. The full
extent of the breach is not known. The ShinyHunters group has made no
financial demand, but it wants the FBI to retract a statement they
previously made about the group using violent threats for extortion.
They want the FBI to "set the record straight."
Summary:
The ShinyHunters breach of FBI personnel information included a good
deal of medical information. This is no ordinary data breach. The FBI
has acknowledged that its FBIJobs systems were compromised, but
ShinyHunters says that they accessed the systems with medical information
and background check reports on employees. The hacker group says that
it has information about 60K current and former FBI staff.
The medical information is particularly concerning because unlike like and email address or password, it cannot be changed and can have lasting effects on how a person is perceived and treated.