In the weekly edition of Cyber News, we compile the top cyber news from the previous week. We provide an easy breakdown so you can get the news you need and skip the fluff you don’t.
Telegram Founder Arrested in France
Telegram founder and CEO Pavel Durov was arrested Saturday on a warrant shortly after departing his private jet in France.
Telegram, a popular social media app, has more than 900 million active monthly users. Durov has come under criticism for not taking moderation action for the criminal uses of Telegram.
What You Need to Know:
To be more specific, Durov and Telegram are accused of failure to cooperate with law enforcement regarding crimes such as child sexual abuse, drug trafficking, and fraud, the BBC said.
The warrant originated from the French agency, Ofmin, which was incorporated last year to combat violence against children.
Paris prosecutor Laure Beccuau said the investigation concerned crimes related to illicit transactions, child sexual abuse, fraud, and the refusal to communicate information to authorities.
“At the heart of this case is the lack of moderation and cooperation of the platform (which has almost 1 billion users), in particular in the fight against crimes against children,” said Jean-Michel Bernigaud, the secretary general of Ofmin.
Implications:
This is a political quagmire. On one side, Russia is decrying the arrest, touting it as proof of a Western double standard when it comes to free speech. This is also echoed by other First Amendment proponents like Elon Musk.
On the other side, Durov is a Russian native who left Russia after refusing to kowtow to Kremlin demands to crack down on communications from groups opposed to the regime.
At the heart of the issue is the question – how liable are social media platforms for the content and transactions that take place through their platforms? Newspapers are held liable for libel, and celebrities are held liable for slander and defamation. So it becomes a question of the burden of free speech and press versus criminal code, which holds that a party can be charged as an accessory to a crime if that person or platform is aware of a crime being, will be, or has been committed, and who may help or encourage the criminal. It’s being argued that if Durov failed to moderate these transactions, he may be accessory to the sale of child pornography and other crimes.
Future of AI? Department of Justice Nails RealPage with Antitrust Lawsuit
So maybe those soaring rent prices aren’t all evidence of a housing crisis – they may be evidence of price fixing. The Department of Justice slapped RealPage with an antitrust lawsuit last week, accusing the company of creating and using artificial intelligence algorithms allowing landlords to price fix and drive up apartment and rental prices. With 109 million Americans renting and rental prices rising by 35% since 2020, potential price fixing would have massive fallouts.
What You Need to Know:
Yes, it is that bad. According to the DoJ’s case, RealPage software is used in approximately 80% of the market share of multi-family dwellings, harming millions of Americans. The software in question, called LRO, uses AI-powered algorithms to help landlords maximize the prices of apartment rentals within the same market. It collects sensitive market information about properties owned by competing landlords. That information – such as current apartment rental rates and other lease terms – is then used to train RealPage’s pricing algorithm, which generates pricing recommendations for the landlords. This maximizes profits for the landlords – at the expense of American renters. This in turn violates Sections 1 and 2 of the Sherman Antitrust Act, which bans contracts or agreements harming competition or which monopolized more than 70% of a market share.
Implications:
So far, eight states have joined the lawsuit, which was originally filed in North Carolina, including California, Colorado, Connecticut, Minnesota, Oregon, Tennessee, and Washington. This is the first case of its kind pursued against algorithmic collusion and will be pivotal in setting a precedent for how AI is used to make business decisions.
Meta Exposes Iranian Threat Actor
Interestingly, these two stories centered on moderation both popped in the same week – Meta exposed an Iranian state threat actor who they say has been using WhatsApp to target the election. Meta stated that the activity “appeared to have focused on political and diplomatic officials, and other public figures, including some associated with administrations of President Biden and former President Trump.”
The social media giant attributed it to a nation-state actor tracked as APT42, known to be made up of individual actors known as Charming Kitten, Damselfly, Mint Sandstorm (formerly Phosphorus), TA453, and Yellow Garuda, and associated with Iran’s Islamic Revolutionary Guard Corps (IRGC).
What You Need to Know:
The collective is well known for its social engineering and email spear phishing techniques. Proofpoint is tracking an intelligence-gathering attack targeting a prominent Jewish figure.
Implications:
According to Meta, the WhatsApp accounts positioned themselves as technical support for AOL, Google, Yahoo, and Microsoft. At this time, their efforts appear to be unsuccessful. The accounts have since been blocked by the platform. Please remember to always use best practices and follow your gut feeling when being contacted by an outside agency wanting to “help you.”
Microsoft to Host CrowdStrike “Lessons Learned” Security Summit
Microsoft is hosting a security summit to go over lessons learned from the historically botched CrowdStrike update at its home base in Redmond, Washington.
The “Windows Endpoint Security Ecosystem Summit” will be held on September 10th.
“Microsoft, CrowdStrike, and key partners who deliver endpoint security technologies will come together for discussions about improving resiliency and protecting mutual customers’ critical infrastructure,” the company said in the Friday blog post.
What You Need to Know:
During the summit, industry leaders will sit down alongside government representatives to review the series of events leading up to the massive outage to create actionable steps Microsoft and its joint customers can take to improve overall security and resiliency.
Implications:
I love that Microsoft is taking this approach. They’re using what could be a) swept under the rug and pray everyone forgets about it b) quietly publish their findings and bury it in a journal or Congressional hearing or c) do what they’re doing- make it a public learning moment.
By doing it this way, they’re not only functioning as a leader in the cybersecurity space, but they’re also setting a standard for future “oopsies.”