×
Privacy

Hackers Claim They Breached T-Mobile More Than 100 Times In 2022 (krebsonsecurity.com) 14

An anonymous reader quotes a report from KrebsOnSecurity: Three different cybercriminal groups claimed access to internal networks at communications giant T-Mobile in more than 100 separate incidents throughout 2022, new data suggests. In each case, the goal of the attackers was the same: Phish T-Mobile employees for access to internal company tools, and then convert that access into a cybercrime service that could be hired to divert any T-Mobile user's text messages and phone calls to another device. The conclusions above are based on an extensive analysis of Telegram chat logs from three distinct cybercrime groups or actors that have been identified by security researchers as particularly active in and effective at "SIM-swapping," which involves temporarily seizing control over a target's mobile phone number.

Countless websites and online services use SMS text messages for both password resets and multi-factor authentication. This means that stealing someone's phone number often can let cybercriminals hijack the target's entire digital life in short order -- including access to any financial, email and social media accounts tied to that phone number. All three SIM-swapping entities that were tracked for this story remain active in 2023, and they all conduct business in open channels on the instant messaging platform Telegram. KrebsOnSecurity is not naming those channels or groups here because they will simply migrate to more private servers if exposed publicly, and for now those servers remain a useful source of intelligence about their activities.

Each advertises their claimed access to T-Mobile systems in a similar way. At a minimum, every SIM-swapping opportunity is announced with a brief "Tmobile up!" or "Tmo up!" message to channel participants. Other information in the announcements includes the price for a single SIM-swap request, and the handle of the person who takes the payment and information about the targeted subscriber. The information required from the customer of the SIM-swapping service includes the target's phone number, and the serial number tied to the new SIM card that will be used to receive text messages and phone calls from the hijacked phone number. Initially, the goal of this project was to count how many times each entity claimed access to T-Mobile throughout 2022, by cataloging the various "Tmo up!" posts from each day and working backwards from Dec. 31, 2022. But by the time we got to claims made in the middle of May 2022, completing the rest of the year's timeline seemed unnecessary. The tally shows that in the last seven-and-a-half months of 2022, these groups collectively made SIM-swapping claims against T-Mobile on 104 separate days -- often with multiple groups claiming access on the same days.
In a written statement to KrebsOnSecurity, T-Mobile said this type of activity affects the entire wireless industry.

"And we are constantly working to fight against it," the statement reads. "We have continued to drive enhancements that further protect against unauthorized access, including enhancing multi-factor authentication controls, hardening environments, limiting access to data, apps or services, and more. We are also focused on gathering threat intelligence data, like what you have shared, to help further strengthen these ongoing efforts."
Communications

SpaceX Unveils 'V2 Mini' Starlink Satellites With Quadruple the Capacity (arstechnica.com) 89

An anonymous reader quotes a report from Ars Technica: With Starlink speeds slowing due to a growing capacity crunch, SpaceX said a launch happening as soon as today will deploy the first "V2 Mini" satellites that provide four times more per-satellite capacity than earlier versions. Starlink's second-generation satellites include the V2 Minis and the larger V2. The larger V2s are designed for the SpaceX Starship, which isn't quite ready to launch yet, but the V2 Minis are slimmed-down versions that can be deployed from the Falcon 9 rocket. "The V2 Minis are smaller than the V2 satellites (hence the name) but don't let the name fool you," SpaceX said in a statement provided to Ars yesterday. "The V2 Minis include more advanced phased array antennas and the use of E-band for backhaul, which will enable Starlink to provide ~4x more capacity per satellite than earlier iterations."

SpaceX didn't specify the amount of data that each V2 Mini satellite can provide, but its first-generation satellites were designed for an aggregate downlink capacity of 17 to 23Gbps per satellite. The Federal Communications Commission recently gave SpaceX approval to launch 7,500 of the 30,000 planned second-generation satellites. A SpaceX Falcon 9 launch tentatively scheduled for today would put 21 V2 Minis into orbit. The larger V2 satellites that can't launch until Starship is ready will be able to send signals directly to cell phones, a capability that'll be used by SpaceX and T-Mobile in a partnership announced in August 2022.
"Each Starlink V2 Mini satellite weighs about 1,760 pounds (800 kilograms) at launch, nearly three times heavier than the older Starlink satellites," notes Spaceflight Now. "They are also bigger in size, with a spacecraft body more than 13 feet (4.1 meters) wide, filling more of the Falcon 9 rocket's payload fairing during launch."

UPDATE: SpaceX successfully launched the first batch of "V2 Mini" Starlink satellites. "A Falcon 9 rocket hauled the 21 Starlink satellites into a 230-mile-high (370-kilometer) orbit after lifting off from pad 40 at Cape Canaveral Space Force Station at 6:13:50 p.m. EST (2313:50 GMT) Monday," reports Spaceflight Now. "SpaceX delayed the launch from earlier Monday afternoon to wait for radiation levels to abate following a solar storm that sparked dramatic auroral displays visible across Northern Europe and Canada." You can watch the launch here. Elon Musk also shared video of the first V2 satellites to reach orbit.
Businesses

Dish Network's Internal Systems Are So Broken Some Employees Haven't Worked In Over a Day 46

An anonymous reader quotes a report from The Verge: Since Thursday morning, Dish Network has been experiencing a major outage that's taken down the company's main websites, apps, and customer support systems, and employees tell The Verge it's not clear what's going on inside the company. The company's Dish.com website is completely blank save for a notice apologizing for "any disruptions you may be having" while promising that "teams are working hard to restore systems as soon as possible." The Boost Mobile and Boost Infinite sites display a similar message. When we called each brand's customer support lines, there were no humans on the other end -- each call automatically hung up after delivering a recorded message about the outage.

In an ironic twist, the outage started around the time that Dish was set to release its earnings for Q4 and fiscal year 2022. CEO Erik Carlson addressed it during the company's earnings call, saying the company was experiencing an "internal outage that's continuing to affect our internal servers and IT telephony." While Carlson claimed that Dish, Sling, and the company's wireless networks were operating normally, he admitted that "internal communications, customer care functions, Internet sites" were knocked out. Internally, frontline employees have been kept in the dark about what's going on. Two sources tell The Verge that they are being told to stand by for information from their leadership teams, which haven't yet been forthcoming. They say it hasn't even been made clear whether they'll be paid. Employees have also been told that they won't be able to connect to their VPN, keeping remote workers from logging in to work.

Despite Carlson's comments that Dish's services should be working normally, Downdetector shows an increase in reports of issues using Dish Network's services, which include satellite TV and Boost Mobile's wireless network. Customers are reporting on social media that they're unable to activate new equipment or SIM cards received from the company, and alleged technicians say they can't complete installs and upgrades for customers. Customers have also said that the outage is preventing them from paying their bills. Some of the company's sites, like dishwireless.com and launch.5gmobilegenesis.com, are currently completely down and don't even display an error message.
The good news is that the outage doesn't appear to be the result of a cyberattack, according to The Desk, though Dish likely hasn't concluded its investigation yet.
Microsoft

Microsoft Has Been Secretly Testing Its Bing Chatbot 'Sydney' For Years (theverge.com) 25

According to The Verge, Microsoft has been secretly testing its Sydney chatbot for several years after making a big bet on bots in 2016. From the report: Sydney is a codename for a chatbot that has been responding to some Bing users since late 2020. The user experience was very similar to what launched publicly earlier this month, with a blue Cortana-like orb appearing in a chatbot interface on Bing. "Sydney is an old codename for a chat feature based on earlier models that we began testing in India in late 2020," says Caitlin Roulston, director of communications at Microsoft, in a statement to The Verge. "The insights we gathered as part of that have helped to inform our work with the new Bing preview. We continue to tune our techniques and are working on more advanced models to incorporate the learnings and feedback so that we can deliver the best user experience possible."

"This is an experimental AI-powered Chat on Bing.com," read a disclaimer inside the 2021 interface that was added before an early version of Sydney would start replying to users. Some Bing users in India and China spotted the Sydney bot in the first half of 2021 before others noticed it would identify itself as Sydney in late 2021. All of this was years after Microsoft started testing basic chatbots in Bing in 2017. The initial Bing bots used AI techniques that Microsoft had been using in Office and Bing for years and machine reading comprehension that isn't as powerful as what exists in OpenAI's GPT models today. These bots were created in 2017 in a broad Microsoft effort to move its Bing search engine to a more conversational model.

Microsoft made several improvements to its Bing bots between 2017 and 2021, including moving away from individual bots for websites and toward the idea of a single AI-powered bot, Sydney, that would answer general queries on Bing. Sources familiar with Microsoft's early Bing chatbot work tell The Verge that the initial iterations of Sydney had far less personality until late last year. OpenAI shared its next-generation GPT model with Microsoft last summer, described by Jordi Ribas, Microsoft's head of search and AI, as "game-changing." While Microsoft had been working toward its dream of conversational search for more than six years, sources say this new large language model was the breakthrough the company needed to bring all of its its Sydney learnings to the masses. [...] Microsoft hasn't yet detailed the full history of Sydney, but Ribas did acknowledge its new Bing AI is "the culmination of many years of work by the Bing team" that involves "other innovations" that the Bing team will detail in future blog posts.

Earth

What's Inside the Earth's Core? (nytimes.com) 30

The inner core of the Earth appears to hold an innermost secret. From a report: Geology textbooks almost inevitably include a cutaway diagram of the Earth showing four neatly delineated layers: a thin outer shell of rock that we live on known as the crust; the mantle, where rocks flow like an extremely viscous liquid, driving the movement of continents and the lifting of mountains; a liquid outer core of iron and nickel that generates the planet's magnetic field; and a solid inner core. Analyzing the crisscrossing of seismic waves from large earthquakes, two Australian scientists say there is a distinctly different layer at the very center of the Earth. "We have now confirmed the existence of the innermost inner core," said one of the scientists, Hrvoje Tkalcic, a professor of geophysics at the Australian National University in Canberra.

Dr. Tkalcic and Thanh-Son Pham, a postdoctoral researcher, estimate that the innermost inner core is about 800 miles wide; the entire inner core is about 1,500 miles wide. Their findings were published on Tuesday in the journal Nature Communications. While the cutaway diagram appears to depict clear-cut divisions, knowledge about the deep interior of Earth is unavoidably fuzzy. It is nearly 4,000 miles to the center of Earth, and it is impossible to drill more than a few miles into the crust. Most of what is known about what lies beneath comes from seismic waves -- the vibrations of earthquakes traveling through and around the planet. Think of them as a giant sonogram of Earth.

Two Harvard seismologists, Miaki Ishii and Adam Dziewonski, first proposed the idea of the innermost inner core in 2002 based on peculiarities in the speed of seismic waves passing through the inner core. Scientists already knew that the speed of seismic waves traveling through this part of the Earth varied depending on the direction. The waves traveled fastest when going from pole to pole along the Earth's axis and slowest when traveling perpendicular to the axis. The difference in speeds -- a few percent faster along polar paths -- arises from the alignment of iron crystals in the inner core, geophysicists believe. But in a small region at the center, the slowest waves were those traveling at a 45-degree angle to the axis instead of 90 degrees, the Harvard seismologists said. The data available then were too sparse to convince everyone.

Google

DOJ Alleges Google Destroyed Chat Messages It Was Required To Save During Antitrust Investigation (cnbc.com) 79

Google "systematically destroyed" instant message chats every 24 hours, violating federal rules to preserve potentially relevant communications for litigation, the Department of Justice alleged in a filing that became public on Thursday. From a report: As a result of Google's default to preserve chats for only 24 hours unless an employee opts to turn on history for the conversation, "for nearly four years, Google systematically destroyed an entire category of written communications every 24 hours," the department wrote in the filing.

According to the DOJ, Google should have adjusted its defaults in mid-2019 "when the company reasonably anticipated this litigation." Instead, it relied on individual employees to decide when chats were potentially relevant to future litigation, the department said. "Few, if any," did, according to DOJ. Meanwhile, investigators alleged, Google "falsely" told the government it had "'put a legal hold in place' that 'suspends auto-deletion.'" The government added that "at every turn, Google reaffirmed that it was preserving and searching all potentially relevant written communications." The data deletion continued up until as recently as this month when the government indicated it would file a motion for sanctions and an evidentiary hearing, investigators allege. At that point, the DOJ said, Google committed to "permanently set to history on."

Google

Google Parent Alphabet Shuts Down Yet Another Robot Project (theverge.com) 19

Alphabet is shutting down its Everyday Robots project -- another casualty of job cuts at Google's parent company and the latest in a long list of failed hardware ventures. From a report: According to a report from Wired, Everyday Robots will no longer exist as a discrete team at the tech giant. "Everyday Robots will no longer be a separate project within Alphabet," Denise Gamboa, director of marketing and communications for Everyday Robots, told the publication. "Some of the technology and part of the team will be consolidated into existing robotics efforts within Google Research." Everyday Robots launched in 2019, with an aim of designing armed robots that could help out in domestic and office settings; taking on light custodial work like sorting trash and cleaning tables. The project's prototype, single-armed, wheeled robots were tested in Google's offices from 2021, and in 2022 received an upgrade courtesy of Google's AI language research, letting them process natural language commands.
Businesses

EU Eyes Big Tech as it Seeks Feedback on Who Should Pay Network Costs (reuters.com) 56

The European Commission on Thursday launched a consultation on the future of Europe's telecoms sector, starting a process that could lead to requiring Alphabet's Google, Apple, Meta and Netflix to pay some network costs. From a report: For more than two decades Deutsche Telekom, Orange, Telefonica, Telecom Italia and other operators have lobbied for leading technology companies to contribute to 5G and broadband roll-out. They argue companies including Amazon and Microsoft account for more than half of data internet traffic. The tech firms in response call it an internet tax that will undermine EU network neutrality rules to treat all users equally. The 12-week consultation will end on May 19. EU industry chief Thierry Breton cited the heavy investments required to roll out 5G and broadband, saying he was not targeting any company.
Communications

Samsung Readying Its Own Smartphone-to-Satellite Communication Platform (engadget.com) 30

An anonymous reader shares a report: There was speculation that Samsung could use smartphone-to-satellite technology in its Galaxy S23 much like Apple has for the iPhone 14, but that didn't happen in the end. Now, the company has unveiled a new standardized 5G NTN (non-terrestrial network) modem that will enable two-way communication between smartphones and satellites. The technology will allow users to send and receive calls, text messages and data without the need for a cellular network, and will be integrated into Samsung's future Exynos chips.

The aim is to allow people in mountains, deserts or other remote areas to communication with others in critical situations. 5G NTN conforms to 3rd Generation Partnership Project (3GPP Release 17) standards, meaning it works with traditional communication services from chip manufacturers, smartphone makers and telecoms. However, Samsung indicated that the tech could eventually be used to transmit high-definition photos and even video, on top of texts and calls.

Google

Google Warns Internet Will Be 'A Horror Show' If It Loses Landmark Supreme Court Case 324

The U.S. Supreme Court, hearing a case that could reshape the internet, considered on Tuesday whether Google bears liability for user-generated content when its algorithms recommend videos to users. From a news writeup: In the case, Gonzalez vs, Google, the family of a terrorist attack victim contends that YouTube violated the federal Anti-Terrorism Act because its algorithm recommended ISIS videos to users, helping to spread their message. Nohemi Gonzalez was an American student killed in a 2015 ISIS attack in Paris, and his family's lawsuit challenges the broad legal immunity that tech platforms enjoy for third party content posted on their sites. Section 230 of the Communications Decency Act, passed in 1996, protects platforms from legal action over user-generated content, and it also protects them if they choose to remove content. Section 230 has withstood court challenges for the past three decades even as the internet exploded.

The attorney for Gonzalez's family claimed that YouTube's recommendations fall outside the scope of Section 230, as it is the algorithms, not the third party, that actively pick and choose where and how to present content. In this case, the attorney said, it enhanced the ISIS message. "Third parties that post on YouTube don't direct their videos to specific users," said the Gonzalez's attorney Eric Schnapper. Instead, he said, those are choices made by the platform. Justice Neil Gorsuch said he was '"not sure any algorithm is neutral. Most these days are designed to maximize profit." [...] Internet firms swear that removing or limiting 230 protections would destroy the medium. Would it? Chief Justice John Roberts asked Google's attorney Lisa Blatt. "Would Google collapse and the internet be destroyed if Google was prevented from posting what it knows is defamatory?" She said, "Not Google," but other, smaller websites, yes. She said if the plaintiffs were victorious, the internet would become a zone of extremes -- either The Truman Show, where things are moderated into nothing, or like "a horror show," where nothing is.
Space

Texas Is Planning To Make a Huge Public Investment In Space (arstechnica.com) 103

An anonymous reader quotes a report from Ars Technica: As part of the state's biennial budget process, Texas Governor Greg Abbott has called on the state legislature to provide $350 million to create and fund a Texas Space Commission for the next two years. "With companies seeking to expand space travel in coming years, continued development of the space industry in the state will ensure Texas remains at the forefront not only in the United States, but the entire world," Abbott stated in his budget document for the 88th Legislature. "Further investment will cement Texas as the preeminent location for innovation and development in this rapidly growing industry. Due to increased competition from other states and internationally, further planning and coordination is needed to keep Texas at the cutting edge." Texas has a historic budget surplus this year due to oil prices, inflation, and other factors driving economic growth. The state is projected to have $188.2 billion available in general revenue for funding the business of the state over the 2024-2025 period, a surplus of $32.7 billion over spending during the previous two years.

In their initial drafts, both the House and the Senate budget bills for this legislative session include the full $350 million in funding for a space commission. The initiative is being led by the chair of the House Appropriations Committee, Texas Rep. Greg Bonnen, whose district just south of Houston is adjacent to NASA's Johnson Space Center. A source said the bill "has all of the support it needs to pass" from leaders in both the House and Senate. Bonnen's office did not specify what the Texas Space Commission will address, including how the money would be spent. A second source in the Texas Legislature told Ars that details about the commission's funding priorities were expected to be worked out later in the legislative session, which ends on May 29.

However, the framework for the proposed space commission appears to have been prepared by a Houston-based workforce-development organization called TexSpace, which published an annual report in December calling for the creation of such a commission. According to this document, the commission would "focus on policy and arranging statewide strategy by monitoring local, state, and federal policies and opportunities and establishing an economic ecosystem for Texas' space enterprises." It would include 15 members, including those appointed by political officials, as well as an appointee each from SpaceX and Blue Origin. [...] The commission will likely seek to ensure that SpaceX and Blue Origin continue to grow their presence in the state and to nurture other, smaller startups.
"Compared to the Texas proposal, Space Florida has a modest annual budget of $12.5 million," notes Ars.

"Florida leaders made the brilliant decision to invest in the commercial space industry years ago, and that investment has paid off," Anna Alexopoulos Farrar, a vice president of communications for Space Florida, told Ars. "Space Florida alone had a $5.9 billion economic impact on the state over the past 15 years, and we project a $1.1 billion impact every year starting this year. It's not surprising that other states want to emulate our proven model, and we welcome the challenge from our friends in Texas -- competition yields the best outcomes for both businesses and taxpayers."
United States

FDA's Own Reputation Could Be Restraining Its Misinfo Fight (apnews.com) 223

The government agency responsible for tracking down contaminated peanut butter and defective pacemakers is taking on a new health hazard: online misinformation. From a report: It's an unlikely role for the Food and Drug Administration, a sprawling, century-old bureaucracy that for decades directed most its communications toward doctors and corporations. But FDA Commissioner Dr. Robert Califf has spent the last year warning that growing "distortions and half-truths" surrounding vaccines and other medical products are now "a leading cause of death in America."

"Almost no one should be dying of COVID in the U.S. today," Califf told The Associated Press, noting the government's distribution of free vaccines and antiviral medications. "People who are denying themselves that opportunity are dying because they're misinformed." Califf, who first led the agency under President Barack Obama, said the FDA could once rely on a few communication channels to reach Americans. "We're now in a 24/7 sea of information without a user guide for people out there in society," Califf said. "So this requires us to change the way we communicate."

Cellphones

FCC Proposals Require Phone Companies To Help Domestic Violence Survivors (engadget.com) 43

An anonymous reader quotes a report from Engadget: Now that the Safe Connections Act (SCA) has become law, the Federal Communications Commission is taking steps to help domestic violence survivors leave their partners' phone plans. The agency has proposed rules that would require carriers separate the line for a survivor within two business days of a request. Another proposal would also have carriers hide contact with abuse hotlines from consumer-facing call and text logs.

The FCC also hopes to use the Lifeline or Affordable Connectivity Program to support survivors enduring financial hardships for up to six months. Separately, providers are teaming with the National Domestic Violence Hotline to ensure survivors leaving a family plan will get in touch with someone who can offer support from experts on abuse. The proposals are entering a public comment phase and may be modified when they take effect as required by the SCA.

Medicine

Male Birth Control Stopped Sperm In Mice, Study Found (wsj.com) 84

An anonymous reader quotes a report from the Wall Street Journal: A drug aimed at treating eyes immobilized sperm and prevented pregnancy in mice, encouraging researchers that it might work as a contraceptive for men. Injected into male mice, the drug was 100% effective in preventing pregnancy for 2 1/2 hours and about 91% effective for up to 3 1/2 hours, according to a study published Tuesday in the journal Nature Communications. The male mice were fertile after a day, the study found. The new approach is appealing for how quickly the contraceptive acts. The researchers said they would test the drug in other animals and aim for human trials in the coming years.

The drug presented in Tuesday's study acts by deactivating an enzyme in mice and men that make sperm swim. "It's like your on-switch on your TV," said Jochen Buck, a pharmacologist at Weill Cornell Medicine, an author of the study. When the researchers added the drug to human and mice sperm in a dish, the cells stopped moving temporarily. Lower doses of the drug resulted in progressively more mobile sperm cells, Dr. Buck said. The drug took about 15 minutes to take effect. Male mice injected with the drug didn't alter their mating behavior. Allowed to mate in the 2.5 hours after injection, none of 52 pairs of mice produced offspring. A third of mice partners in a control group of 50 had pregnancies. Mice given the drug were later able to father healthy pups, the study said.

Communications

Biden FCC Nominee Slams Critics, Says ISPs Shouldn't Get To Choose Regulators (arstechnica.com) 64

President Biden's long-stalled nominee to the Federal Communications Commission fired back at her critics today, saying that the telecom industry shouldn't be allowed to choose its own regulators. From a report: "I believe deeply that regulated entities should not choose their regulator," Sohn said in prepared testimony for a Senate Commerce Committee nomination hearing today. "Unfortunately, that is the exact intent of the past 15 months of false and misleading attacks on my record and my character. My industry opponents have hidden behind dark money groups and surrogates because they fear a pragmatic, pro-competition, pro-consumer policymaker who will support policies that will bring more, faster, and lower-priced broadband and new voices to your constituents."

Biden first nominated Sohn, a longtime consumer advocate and former FCC official, on October 26, 2021. The full Senate never voted on whether to confirm Sohn as an FCC commissioner, and Biden renominated her last month. With the FCC deadlocked at two Democrats and two Republicans, Chairwoman Jessica Rosenworcel hasn't been able to pursue any major regulation of an industry that was deregulated during the Trump era. "The FCC has been without a majority for the entirety of the Biden administration -- over two years -- at a time when closing the digital divide is front and center," Sohn's testimony said. "There are too many important issues in front of the commission to lack a full complement of members, including improving the broadband maps, fixing the Universal Service Fund, closing the homework gap, ensuring fair access to broadband, and protecting consumers' privacy. Americans deserve a full FCC where I could play a critical role in addressing every one of these, but time is of the essence."

Security

NameCheap's Email Hacked To Send Metamask, DHL Phishing Emails (bleepingcomputer.com) 11

An anonymous reader quotes a report from BleepingComputer: Domain registrar Namecheap had their email account breached Sunday night, causing a flood of MetaMask and DHL phishing emails that attempted to steal recipients' personal information and cryptocurrency wallets. The phishing campaigns started around 4:30 PM ET and originated from SendGrid, an email platform used historically by Namecheap to send renewal notices and marketing emails. After recipients began complaining on Twitter, Namecheap CEO Richard Kirkendall confirmed that the account was compromised and that they disabled email through SendGrid while they investigated the issue.

Namecheap published a statement Sunday night stating that their systems were not breached but rather it was an issue at an upstream system that they use for email. "We have evidence that the upstream system we use for sending emails (third-party) is involved in the mailing of unsolicited emails to our clients. As a result, some unauthorized emails might have been received by you," reads a statement issued by Namecheap. "We would like to assure you that Namecheap's own systems were not breached, and your products, accounts, and personal information remain secure." After the phishing incident, Namecheap says they stopped all emails, including two-factor authentication code delivery, trusted devices' verification, and password reset emails, and began investigating the attack with their upstream provider. Services were restored later that night at 7:08 PM EST.

While Namecheap did not state the name of this upstream system, the CEO of Namecheap previously tweeted that they were using SendGrid, which is also confirmed in the phishing emails' mail headers. However, Twilio SendGrid told BleepingComputer that Namecheap's incident was not the result of a hack or compromise of the email service provider's systems, adding more confusion as to what happened: "Twilio SendGrid takes fraud and abuse very seriously and invests heavily in technology and people focused on combating fraudulent and illegal communications. We are aware of the situation regarding the use of our platform to launch phishing email and our fraud, compliance and cyber security teams are engaged in the matter. This situation is not the result of a hack or compromise of Twilio's network. We encourage all end users and entities to take a multi-pronged approach to combat phishing attacks, deploying security precautions such as two factor authentication, IP access management, and using domain-based messaging. We are still investigating the situation and have no additional information to provide at this time."

United States

The FBI's Most Controversial Surveillance Tool is Under Threat (arstechnica.com) 39

An existential fight over the US government's ability to spy on its own citizens is brewing in Congress. And as this fight unfolds, the Federal Bureau of Investigation's biggest foes on Capitol Hill are no longer reformers merely interested in reining in its authority. Many lawmakers, elevated to new heights of power by the recent election, are working to dramatically curtail the methods by which the FBI investigates crime. From a report: New details about the FBI's failures to comply with restrictions on the use of foreign intelligence for domestic crimes have emerged at a perilous time for the US intelligence community. Section 702 of the Foreign Intelligence Surveillance Act (FISA), the so-called crown jewel of US intelligence, grants the government the ability to intercept the electronic communications of overseas targets who are unprotected by the Fourth Amendment. That authority is set to expire at the end of the year. But errors in the FBI's secondary use of the data -- the investigation of crimes on US soil -- are likely to inflame an already fierce debate over whether law enforcement agents can be trusted with such an invasive tool.

Central to this tension has been a routine audit by the Department of Justice's (DOJ) national security division and the office of the director of national intelligence (ODNI) -- America's "top spy" -- which unearthed new examples of the FBI failing to comply with rules limiting access to intelligence ostensibly gathered to protect US national security. Such "errors," they said, have occurred on a "large number" of occasions. A report on the audit, only recently declassified, found that in the first half of 2020, FBI personnel unlawfully searched raw FISA data on numerous occasions. In one incident, agents reportedly sought evidence of foreign influence linked to a US lawmaker. In another, an inappropriate search pertained to a local political party. In both cases, these "errors" were attributed to a "misunderstanding" of the law, the report says. At some point between December 2019 and May 2020, FBI personnel conducted searches of FISA data using "only the name of a US congressman," the report says, a query that investigators later found was "noncompliant" with legal procedures.
Further reading: NSA Director Urges Congress To Renew Controversial Intelligence Authority.
Businesses

Twilio To Lay Off About 1,500 Employees, or 17% of Its Workforce (cnbc.com) 20

Twilio on Monday announced plans to cut around 17% of its workforce, or roughly 1,500 jobs based on the 8,992 employees reported as of Sept. 30, 2022, in a company filing with the Securities and Exchange Commission. Twilio announced the layoffs in a blog post shared on the company's website. From a report: The announcement came after the cloud communications software maker already laid off around 11% of its workforce as part of a restructuring plan in September. In an email to employees, CEO Jeff Lawson said the additional cuts were driven by the need to reorganize Twilio in order to succeed. "These changes hurt," Lawson wrote. "The weeks ahead will be about processing all this change and working together to acclimate to our new structure." Lawson said Twilio is forming two business units to help the company spend less and become more efficient. One unit, Twilio Data & Applications, will be led by Elena Donio, and the second unit, Twilio Communications, will be led by Khozema Shipchandler. Lawson said that when executives were looking at these two business units, it was clear the company had gotten "too big," particularly in communications.
AI

Opera is Building ChatGPT Into Its Browser's Sidebar (theverge.com) 27

"Opera's adding a ChatGPT-powered tool to its sidebar that generates brief summaries of webpages and articles," reports the Verge: "The feature, called 'shorten,' is part of the company's broader plans to integrate AI tools into its browser, similar to what Microsoft's doing with Edge."

The "shorten" feature isn't available to everyone just yet, though. Jan Standel, the vice president of marketing and communications at Opera, tells The Verge that it's going to "launch in browsers very soon." Opera's also working on other AI-powered features that "augment" the browsing experience and plans on adding "popular AI-generated content services to the sidebar," although it's not yet clear what this could entail.

In the blog post Opera's EVP for PC Browsers and Gaming shared their belief that "with AI solutions springing up both for text, image, and audio generation and in countless other forms, we are at the brink of a new era of creativity on the Web."

The post says the forthcoming AI integration follows their "track record of giving users direct access to the internet's most in-demand platforms, such as TikTok, Telegram, and WhatsApp." And Opera's co-CEO added that "Whether inventing browser tabs or providing our users with built-in access to generative AI tools, we always push the limits of what's possible on the web."
China

US Sanctions Six Chinese Tech Companies For Supporting Spy Balloon Programs (cnbc.com) 37

According to CNBC, the United States is placing sanctions on six Chinese tech companies for supporting spy balloon programs that have spanned more than 40 countries. The development comes less than a week after the U.S. military used fighter jets to shoot down a suspected Chinese spy balloon along the South Carolina coast. From the report: "The Commerce Department will not hesitate to use the Entity List and our other regulatory and enforcement tools to protect U.S. national security and sovereignty," said Deputy Secretary of Commerce Don Graves. "The Entity List is a powerful tool for identifying and cutting off actors that seek to use their access to global markets to do harm and threaten American national security. We will not hesitate to use the Entity List and our other regulatory and enforcement tools to protect U.S. national security." Earlier today, a U.S. military F-22 shot down a second "high altitude object" in American airspace over Alaska.

"We're calling this an object because that's the best description we have right now," said White House spokesman John Kirby. He also said U.S. officials did not yet know which nation or group was responsible for it.

Slashdot Top Deals