More stories

  • in

    Is T-Mobile secretly recording your phone’s screen? How to check and turn it off

    Elyse Betters Picaro / ZDNETT-Mobile may be spying on your phone, but it’s not as bad as it sounds.Earlier this week, T-Mobile users started noticing an ominously titled feature called “screen recording tool” appear in their T-Life app on both Android and Apple devices. On by defaultThe company hadn’t announced anything, and the feature was on by default. Naturally, some customers freaked out about this apparent invasion of privacy (perhaps rightfully so, given the company’s data breach history) and wondered what the app was watching. Also: How to screen record on your iPhone – it’s easyThe first instinct for many people was that this was some sort of customer service feature that lets a company representative see a customer’s screen, but the feature’s description dispelled that notion: “We use a tool to record how customers use the app to analyze and improve your experience” it read. “Only T-Mobile will review and analyze your info.” More

  • in

    Your Asus router may be compromised – here’s how to tell and what to do

    Elyse Betters Picaro / ZDNETDo you own an Asus router? If so, your device may have been one of thousands compromised in a large campaign waged by cybercriminals looking to exploit it. In a blog post published Wednesday, security firm GreyNoise revealed that the attack was staged by what it suggests is “a well-resourced and highly capable adversary.”Also: Massive data breach exposes 184 million passwords for Google, Microsoft, Facebook, and moreTo gain initial access, the attackers used brute-force login techniques and two different methods to bypass the built-in authentication. They’ve also been able to exploit certain vulnerabilities not yet assigned official CVE numbers. Once they’d accessed the router, they were able to run arbitrary system commands by exploiting a known security flaw identified as CVE-2023-39780.Though no malware was actually installed, the attackers certainly left their mark. More than 9,000 Asus routers affectedBy using built-in Asus settings, they were able to set up SSH access, a secure way to connect to and control a remote device. They also installed a backdoor to return easily to the router’s firmware without worrying about authentication. The backdoor was stored in non-volatile memory (NVRAM), which meant it couldn’t be removed by rebooting the router or updating its firmware. To avoid being caught, the criminals even disabled logging, which would otherwise record their access. Also: Why no small business is too small for hackers – and 8 security best practices for SMBsBased on data from internet scanner Censys, more than 9,000 Asus routers are affected, and that number is growing. However, GreyNoise said that over the past three months, it witnessed only 30 related requests to access the affected routers. That seems to be a sign that the campaign is moving along slowly and quietly. If no malware is installed, what’s the goal behind the attack? “This appears to be part of a stealth operation to assemble a distributed network of backdoor devices — potentially laying the groundwork for a future botnet,” GreyNoise said in its post.And who’s behind it?”The tactics used in this campaign — stealthy initial access, use of built-in system features for persistence, and careful avoidance of detection — are consistent with those seen in advanced, long-term operations, including activity associated with advanced persistent threat (APT) actors and operational relay box (ORB) networks. While GreyNoise has made no attribution, the level of tradecraft suggests a well-resourced and highly capable adversary.” Also: Your old router could be a security threat – here’s why and what to doThe language used by GreyNoise, particularly the reference to APTs, suggests a nation-state or attackers working on behalf of a hostile government. Though GreyNoise didn’t cite any particular adversary, such attacks have been attributed to different countries, including China, Russia, North Korea, and Iran.Using its AI-powered payload analysis tool Sift and its observation grid, GreyNoise discovered the attack on March 18. But the firm said it waited until now to disclose it publicly so it could have time to consult with its government and industry partners. More