Axios Codebook

April 18, 2023
Happy Tuesday! Welcome back to Codebook.
- Less than a week until so, so many of us gather in San Francisco for RSA, but who's counting?
- π¬ Have thoughts, feedback or scoops to share? [email protected].
Today's newsletter is 1,249 words, a 5-minute read.
1 big thing: Researchers start playing spyware whack-a-mole
Illustration: Brendan Lynch/Axios
Now that the Biden administration has taken a stronger stance against some commercial spyware vendors, the real race begins: detecting and squashing them.
The big picture: Spyware vendors are known to operate in the shadows and obfuscate their business structure to confuse potential buyers. Dark market dealings, generic intermediaries and swiftly shifting practices can make identifying dubious vendors feel like playing whack-a-mole to researchers.
- The most egregious form of spyware allows a user to target someone else's phone without them knowing, giving unfettered access to phone calls, text messages and real-time location.
- And many vendors, such as well-known Israeli company NSO Group, in recent years have been spotted selling their tools to both authoritarian and democratic governments that abuse the tech to target dissidents, human rights activists, politicians and journalists.
Driving the news: Researchers at the University of Toronto's Citizen Lab uncovered new details last week about how Israeli spyware vendor QuaDream's products were used around the world to target journalists, political opposition figures and an NGO worker.
- Exposure from the Citizen Lab report was the nail in the coffin for QuaDream, as it was forced to shut down over the weekend following dwindling sales.
Between the lines: Experts tell Axios research like Citizen Lab's will play an outsize role in containing the commercial spyware ecosystem as the Biden administration enforces it through a new executive order.
- The order bans U.S. government use of commercial spyware that either "poses significant counterintelligence or security risks" or has "significant risks of improper use by a foreign government or foreign person."
- Proving this will require insights into not only which vendors come with those risks, but also which of their subsidiaries.
Assessing spyware vendors can be difficult. Like criminal hacking gangs, many prefer to operate outside of the public eye or to sell products through third-party vendors and secret subsidiaries, Natalia Krapiva, tech legal counsel at Access Now, told Axios.
- For example: Shortly after President Joe Biden signed the executive order last month, the New York Times reported that a U.S. government office had purchased an NSO product through a little-known subsidiary. (The U.S. placed NSO on a trade blacklist in 2021.)
The intrigue: As agencies determine what spyware they can use, the federal government will need to dedicate more resources to in-house teams and civil society researchers investigating vendors, Krapiva said.
- "We actually have been winning," she added. "But at the same time, we need help, we need help from the governments, we need help regulating and imposing more transparency around this."
Meanwhile, the game of whack-a-mole isn't likely to last forever, Jon Callas, director of public interest technology at the Electronic Frontier Foundation, told Axios.
- The executive order will likely discourage most agencies from even trying to procure spyware to begin with β and U.S. tech vendors from trying to enter the spyware market too.
- "Having potential entrants into spyware-making know that this is not considered to be a good thing and might even be illegal will chase them away," Callas said.
Yes, but: Government demand for spyware remains high.
- India is reportedly looking for a new spyware tool to replace the high-profile NSO Group's Pegasus, according to the Financial Times.
- Biden's executive order bars only commercial spyware, not government-created tools. Law enforcement interest in spyware in their investigations still exists too.
- "It is good, but it is only a start, and we need the administration to go from here and do even more to protect people's privacy," Callas said.
2. Scanning the cloud for hackable security bugs
Illustration: Natalie Peeples/Axios
The majority of cloud accounts are riddled with improper security controls, exposed sensitive databases and high-risk vulnerabilities, according to new research from Palo Alto Networks.
Driving the news: Palo Alto Networks' Unit 42 threat intelligence team analyzed 210,000 cloud accounts across 1,300 organizations in its annual cloud threat report released today.
- 76% of organizations that store data in the cloud don't enforce multifactor authentication (MFA) for their users, per the report, while 58% of organizations also don't require MFA for network administrators either.
- Researchers also found sensitive data in 66% of cloud storage buckets associated with these accounts.
- 60% of organizations took longer than four days to resolve security alerts tied to their cloud systems.
The big picture: Malicious hackers have only been getting better at breaking into companies' cloud infrastructure, despite perceptions that cloud data storage would be ironclad against cyberattacks.
- A CrowdStrike report earlier this year found that attacks exploiting cloud systems nearly doubled in 2022, while the number of hacking groups targeting the cloud tripled.
Details: Nearly two-thirds of source code found in cloud networks had unpatched vulnerabilities considered either high risk or critically severe.
- "In a cloud environment, a single vulnerability in the source code can be replicated to multiple workloads, posing risks to the entire cloud infrastructure," the report notes.
Be smart: The report suggests organizations enable MFA for all network users, turn on audit logs to monitor potentially suspicious activity, and set up automated backups for critical cloud systems in case they go offline.
3. Hikvision's conflicting contract narratives
Illustration: Gabriella Turrisi/Axios
Chinese surveillance giant Hikvision has repeatedly denied reports that the company is complicit in human rights abuses targeting Uyghurs in China's northwestern region of Xinjiang.
But an internal review of the company's contracts with police agencies in the region reveals the company has known since at least 2020 that some of its Xinjiang contracts were a "problem," Axios' Bethany Allen-Ebrahimian and Ina Fried report.
- The contracts included language about targeting Uyghurs as a group, according to a recording of a recent private company meeting obtained by technology trade publication IPVM and shared exclusively with Axios.
Why it matters: The Chinese government is perpetrating an ongoing campaign of genocide and mass detention of Uyghurs and other ethnic minorities in Xinjiang.
- Procurement documents reportedly show that Hikvision cameras have been installed in public spaces across Xinjiang and in mass detention facilities, and Hikvision cameras have captured footage that has led to the detention of Uyghurs.
- Hikvision has also advertised that it offers biometric surveillance technology that can track ethnic minorities, including Uyghurs, though in 2020 the company stated its products no longer offer that capability.
- Human rights groups and the U.S. and other governments have accused Hikvision of participating in human rights abuses in Xinjiang β allegations the surveillance giant has rejected.
4. Catch up quick
@ D.C.
π The U.S. eavesdropped on the United Nations secretary-general's conversations with other UN officials, according to recently leaked Pentagon documents. (Washington Post)
β Montana lawmakers approved a state ban on TikTok. (Associated Press)
π¨π³ Government officials are increasingly worrying about how China-backed cyberattacks will factor into a possible invasion of Taiwan. (Politico)
@ Industry
π Venture capital funding to cyber companies dropped 58% in the first quarter compared to the same time last year. (Cybersecurity Dive)
π² NSO Group found three new "zero-click" ways to hack iPhones last year, researchers say. (Washington Post)
@ Hackers and hacks
π³ Payment processing giant NCR is recovering from a ransomware attack that caused outages across point-of-sale platforms. (BleepingComputer)
π The Vice Society ransomware gang published stolen data from U.S. network infrastructure giant CommScope, including employees' Social Security numbers. (TechCrunch)
πΊπ¦ Ukraine's top cyber agency warned that the intensity of Russian cyberattacks targeting energy and media organizations remains high. (SSSCIP)
5. 1 fun thing
Screenshot: @vxunderground/Twitter
Extortion notes from ransomware gangs are spiraling out of control, as evidenced by the latest one from the ALPHV gang.
- "Even the largest companies would want to know every detail they can about what was taken, but Western Digital didn't even bother to contact us," the note reads π βοΈ.
βοΈ See y'all on Friday!
Thanks to Peter Allen Clark for editing and Khalid Adad for copy editing this newsletter.
If you like Axios Codebook, spread the word.



