All posts by FreeNews

Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes

International law enforcement agencies, working with CrowdStrike and Shadowserver Foundation, have disrupted Sality, a 23-year-old peer-to-peer botnet used to deliver malware to more than 15,000 machines worldwide. The botnet has operated since 2003 and distributed all types of malicious code to victims, spanning credential theft, spam distribution, proxy services, network exploitation, and distributed denial-of-service (DDoS) attacks. For the past eight years, Sality’s primary payload has been EggJagger, a tool that monitors clipboards for cryptocurrency wallet addresses, then silently replaces them with attacker-controlled addresses. When a victim copies a bitcoin or ethereum address to make a payment, the malware redirects funds into the criminals’ wallets. CrowdStrike estimates Sality’s operator stole at least $150,000 in cryptocurrency using EggJagger alone. On Monday, CrowdStrike’s Counter Adversary Operations team, working with international law enforcement agencies and industry partners, disrupted Sality by executing a peer-to-peer sinkhole operation. This operation isolated infected machines, which broke the criminal operator’s ability to communicate with devices on its network. Once isolated, the bots can no longer receive payload download instructions or direct payload transfers, effectively breaking the botnet. “In practice, the operation targeted the data structure at the heart of every bot’s network awareness: its peer list,” CrowdStrike Counter Adversary Operations team said in a technical writeup about the takedown. Each Sality bot maintains a list of known super peers – publicly reachable infected machines that form the backbone of the P2P network. Every 40 minutes, the bots check to see if their peers are still online. Peers that fail to respond are purged from the network. The counterattack took advantage of this by removing legitimate super peers in each bot’s peer list, continually isolating more infected machines in the network, and inserting purpose-built sinkhole entries into peer lists. That approach gave police and cyber operatives visibility into the operation’s progress and helped them notify victims. In addition to the sinkhole operation, the US Justice Department, FBI, and Department of Defense Office of Inspector General’s Defense Criminal Investigative Service seized Sality-linked domains in the US. Meanwhile, international law enforcement in Bulgaria, Hungary, and Romania took action against additional Sality-linked domains hosted in Europe. Meanwhile, the Shadowserver Foundation is working with internet service providers and Computer Security Incident Response Teams (CSIRTs) to identify infections and aid in victim notification and remediation.®

Anthropic promises zero data retention – but customers must check it worked

Anthropic will provide zero data retention to enterprise customers who have been promised the perk, subject to approval, when using the company’s Fable model. With the arrival of new versions of its high-end models, Fable 5.1 and Mythos 5.1, the Claudefather has announced a service called Enterprise Frontier Safeguards (EFS) that combines the privacy of not storing customer data with model abuse detection. Under the new deal, enterprises do not receive zero data retention (ZDR) agreements automatically — they must apply for them. Thirty-day retention of inputs and outputs is the norm for commercial customers using the API unless other arrangements have been made. Earlier this year, Anthropic said it would temporarily keep the inputs (prompts) and outputs of covered models (Fable and Mythos) in order to review the material for safety violations, even when customers have ZDR agreements. The upstart’s concern was that these models are capable of hacking companies – something both Anthropic and rival OpenAI have experienced – and enabling other harmful activities. Having seen “substantial evidence of attempted misuse of AI models” over the past few months, Anthropic says it has been necessary to store data for short periods in order to correlate events over time across accounts. This non-zero amount of data retention, the company says, is not about training on enterprise data, which the biz insists it doesn’t do. Even with that assurance, corporate customers weren’t happy. “The enterprises we worked with generally understood the safety and security value of data retention, but many – especially in regulated industries – found it difficult to use models with data retention,” Anthropic said. OpenAI appears to have considered similar sentiments; last month it unveiled Private Safety Processing, a way to check if customers’ interactions with models represent a risk without violating ZDR commitments. Having been shown that non-zero data retention is a competitive disadvantage with large corporate customers, and perhaps concerned that its safety requirements further disadvantage Fable in a market already reluctant to pay a premium, Anthropic plans to release EFS this fall. “EFS works by storing data in cloud infrastructure controlled by the customer, not Anthropic,” the AI biz explained. It works by shifting safety work to enterprise customers. As Anthropic puts it, “When monitoring detects a pattern that needs attention, those signals are sent directly to customers so they can review what the automated systems detected.” So what may be a compliance win for users of Fable comes with a cost – handling monitoring chores that might otherwise have been carried out by Anthropic personnel. Mythos remains under Anthropic’s earlier policy. Anthropic will offer EFS for Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, Claude Platform on AWS, Google’s Agent Platform, and Microsoft Foundry, by invitation. Consumer plans – Claude Free, Pro, and Max on the web, desktop, and mobile, plus Claude.ai and Claude Code – continue under the company’s previous data retention plan. ®