Wednesday, April 05, 2023

NPR Now Under Same Twitter Label as Russia and China Media Groups

 

NPR Gets ‘State-Affiliated Media’ Tag in Twitter’s Latest Swipe at News Outlets

NPR’s Twitter account.
NPR’s Twitter account.

Bloomberg

Updated on

"Twitter Inc. has labeled the nonprofit media organization NPR as “US state-affiliated media” in the latest escalation of tensions between its billionaire owner Elon Musk and news outlets.

The label now appears on the public broadcaster’s Twitter profile and its tweets and the designation means that NPR’s posts won’t be recommended or amplified on the platform. 

Twitter has defined state-affiliated media as news outlets where the government “exercises control over editorial content through financial resources, direct or indirect political pressures, and/or control over production and distribution.” The designation was reserved for outlets like Russia’s state-backed international broadcaster RT.

Previous versions of Twitter’s policy website made exceptions for the BBC and NPR, which the company called “state-financed media organizations with editorial independence.” But a new version of the the website only makes an exception for the BBC. 

> In a statement, NPR President John Lansing said “we were disturbed” by the designation “and it is unacceptable for Twitter to label us this way. NPR and our member stations are supported by millions of listeners who depend on us for the independent, fact-based journalism we provide,” he said.

> An NPR spokeswoman said the organization has reached out to Twitter to have the label removed.

NPR’s two largest sources of revenue are corporate sponsorships and fees paid by NPR member organizations, according to the company. On average, less than 1% of NPR’s annual operating budget comes in the form of grants from the Corporation for Public Broadcasting and federal agencies and departments.

Musk has used his role as Twitter’s owner to agitate news organizations he doesn’t like. He has banned journalists from the platform. And in recent days, the main account for the New York Times lost its Twitter verified badge after attracting the ire of Musk over its refusal to pay for the privilege.

Twitter has disbanded its press team and doesn’t respond to media requests for comment. But Musk weighed in, responding to a post of Twitter’s rules, saying “seems accurate.”

(Updates with statement from NPR executive in fifth paragraph
READ MORE 
From ArsTechnica:

MUSK-AFFILIATED SOCIAL NETWORK —

Musk expands feud with media by labeling NPR Twitter account “state-affiliated”

Twitter changes policy to exclude NPR but hasn't fully scrubbed the old language.

Screenshot of NPR's Twitter account with the label designating it as
Enlarge / NPR's Twitter account on April 5, 2023.

Twitter has branded NPR with the "state-affiliated media" tag applied to news organizations controlled by governments, contradicting a Twitter policy that cites NPR as an example of a state-financed media organization that retains editorial independence.

The move continues Twitter owner Elon Musk's feud with media organizations. He publicly endorsed the new label for NPR, claiming the outlet falls under policy language that defines state-affiliated media "as outlets where the state exercises control over editorial content."

The NPR Twitter account is now labeled "US state-affiliated media," similar to how RT and Xinhua are labeled "Russia state-affiliated media" and "China state-affiliated media." That move contradicted Twitter's own policy on labeling government or state-affiliated media accounts, which said:

State-financed media organizations with editorial independence, like the BBC in the UK or NPR in the US for example, are not defined as state-affiliated media for the purposes of this policy.

Twitter deleted "or NPR in the US" from that line of the policy, apparently doing so shortly after a Washington Post reporter pointed out last night that "Twitter branding @NPR 'state-affiliated media' literally conflicts with its own policy." Twitter removed NPR from the policy sometime after 2:34 am UTC today, Internet Archive captures show.

Twitter not thorough in scrubbing policy

But Twitter wasn't very thorough in scrubbing NPR from its guidelines. There's another Twitter help page that describes the policy and as of today still contains the same language stating that "the BBC in the UK or NPR in the US for example, are not defined as state-affiliated media." The BBC's Twitter accounts have not been labeled as state-affiliated media.

When contacted by Ars today, NPR said, "This must be a mistake as it contradicts Twitter's own guidelines. We have reached out to Twitter to have the label removed."

But Musk appeared to confirm that the change was deliberate in a response to right-wing media personality Benny Johnson, who was once fired from BuzzFeed for 41 instances of plagiarism. Johnson got a reply from Musk today after posting a screenshot of NPR's state-affiliated media tag and writing, "GET REKT @NPR… Nicely done, @elonmusk 🤣."

Musk replied to Johnson, "Seems accurate," and included a screenshot from a news story quoting this language from Twitter's policy:

State-affiliated media is defined as outlets where the state exercises control over editorial content through financial resources, direct or indirect political pressures, and/or control over production and distribution.

NPR describes itself as "an independent, non-profit media organization," with most of its funding coming from "corporate sponsorships and fees paid by NPR Member organizations." Federal funding indirectly contributes to a large chunk of NPR's revenue because the publicly funded Corporation for Public Broadcasting provides annual grants to public radio stations that pay NPR for programming.

Twitter's "state-affiliated media" tag has an impact on how many people see an account's tweets. "In the case of state-affiliated media entities, Twitter will not recommend or amplify accounts or their Tweets with these labels to people," the company policy says.

Musk’s feud with media

The NPR labeling occurred days after Twitter revoked The New York Times' verification badge over the paper stating publicly that it won't pay Twitter's new $1,000-per-month charge for businesses. The NYT lost verification even though the badge hasn't yet been pulled from other accounts that don't pay due to a grace period that Musk said would last a few weeks "unless they tell [us] they won't pay now." Musk also wrote, "The real tragedy of @NYTimes is that their propaganda isn't even interesting," and "their feed is the Twitter equivalent of diarrhea. It's unreadable."

2 hours ago — Elon Musk's Twitter slapped a new label on the account of American public radio broadcaster NPR that says it is “US state-affiliated media.
56 minutes ago — Elon Musk's Twitter puts NPR under the same category as Russia's RT and China's Xinhau, as the company inconsistently rolls out changes to ...
12 minutes ago — NPR LABELED 'STATE-AFFILIATED MEDIAON TWITTERSAME AS RUSSIA'S RT ... currently states that "[s]tate-financed media organizations with ...

CGTN Report: How much chaos has the U.S. brought to the world in the name of human rights

AS THE WORLD TURNS: Top stories from the Russian press on Tuesday, April 4th

 

Press review: Zelensky, Duda to meet in Warsaw and US aims to drag India into West orbit 




MOSCOW, April 4. /TASS/. The Ukrainian and Polish presidents are seeking to show unity ahead of Kiev’s expected counteroffensive; Washington is attempting to drag New Delhi into the Western camp; and a cafe blast in the Russian city of St. Petersburg has been reclassified as an act of terrorism. These stories topped Tuesday’s newspaper headlines across Russia


Nezavisimaya Gazeta: Ukrainian, Polish presidents in show of unity ahead of Kiev’s counteroffensive

Warsaw has announced a "special" visit by Ukrainian President Vladimir Zelensky, scheduled for Wednesday. Along with economic and humanitarian issues, the parties also plan to discuss further military assistance to Kiev, including delivery of the second batch of MiG-29 fighter jets, Nezavisimaya Gazeta writes.

A clear demonstration of support for Kiev will probably be one of the key goals of the upcoming talks. One of the decisions the parties will make may concern the delivery of the second batch of MiG-29 aircraft. Earlier, Poland and Slovakia agreed to send 29 such planes to Ukraine and the first batches have already been provided to Kiev. However, it is also possible that the Warsaw meeting will address the need for more advanced aircraft, as well as more active assistance to Kiev from other countries.

The German government is often indecisive on such issues and the application of joint pressure by Poland and Ukraine could prod Berlin into joining them, Oleg Barabanov, program director at the Valdai International Discussion Club, points out. Notably, Warsaw has staked out one of the most uncompromising stances both on weapons supplies and any potential peace process..." 

UPDATE INSERT TODAY 



2 hours ago · Ukrainian President Volodymyr Zelenskyy will visit Warsaw on Wednesday, where he will meet his Polish counterpart Andrzej Duda in his second ...
43 minutes ago · Ukrainian President Volodymyr Zelensky has arrived in Poland to meet with one of Ukraine's strongest allies, Polish President Andrzej Duda.
Feb 24, 2023 · They all worked to help Ukraine," Zelensky said. Duda said it was fortunate for Ukraine to have friendly neighbours. "Luckily, Ukraine does not ...

Nezavisimaya Gazeta: Washington seeking to drag New Delhi into Western camp

The air forces of India and the United States plan to hold joint drills; Japan has been invited to take part as an observer. Indian media outlets link the exercise to tensions on the border with China. The drills are seen as a means of warning China that India is not alone. In theory, New Delhi could get assistance from the Quad alliance, which brings together India, the US, Japan and Australia, but, in fact, the member countries did not make any mutual assistance commitments. This is why New Delhi is more inclined to rely on diplomacy to settle its dispute with China, Nezavisimaya Gazeta writes.

The Indian-US drills look like direct support for New Delhi from a powerful nation. All the more so since there is a platform from which assistance could theoretically be provided. However, this is only in theory. First, the Quad is not a military bloc. Second, New Delhi is unwilling to surrender even one iota of its sovereignty and has repeatedly reaffirmed its commitment to an independent foreign policy course. In practice, this means that India will continue to balance between major powers - the US, Russia and China - until its confrontation with China takes the same dramatic turn as in 1962, when then-Indian Prime Minister Jawaharlal Nehru requested military assistance from Washington.

However, such a scenario is hard to imagine...

Media: Law enforcement agencies view St. Petersburg cafe blast as terrorist attack

The criminal case initiated following a blast at a cafe in the Russian city of St. Petersburg has been reclassified from murder by generally dangerous means (Article 105.2 of the Russian Criminal Code) to an act of terrorism (Article 205.3), Vedomosti writes.

According to investigators, an explosion rocked the Patriot cafe in St. Petersburg on April 2. More than 30 people suffered injuries and military blogger Maxim Fomin, who wrote under the pen name Vladlen Tatarsky, was killed. A young woman, Darya Trepova, was detained on suspicion of involvement in the terrorist attack shortly after the blast. Several videos of the incident show her handing a statuette over to Tatarsky, which then exploded. Russia’s Investigative Committee believes that the crime was planned in Ukraine and orchestrated from there. According to a source close to intelligence agencies, the Ukrainian masterminds of the attack failed to achieve any meaningful goals, and only embittered people against its organizers.

Ivan Konovalov, development director at the Foundation for the Promotion of 21st Century Technologies, says that while underground Islamist cells mostly sought to intimidate ordinary citizens, Ukrainian intelligence agencies tend to focus on mounting high-profile attacks on public figures who support Russia’s special military operation.

The murder of military blogger Vladlen Tatarsky is an example of the type of terrorist activities that Ukraine’s government agencies, the Security Service of Ukraine (SBU) and the Defense Ministry’s Main Directorate of Intelligence, are engaged in on an entirely official basis, Center for Political Information Director General Alexey Mukhin told Izvestia.

Each such action is carried out with the consent and under the guidance of Western intelligence agencies,..

Media: Output cut by OPEC+ gives Russian oil price upward lift

The Brent oil price benchmark has renewed its monthly high, pushing past the $85 per barrel mark. The price of Russia’s Urals grade crude grew by more than 12%, rising beyond $60 per barrel. This was facilitated by the OPEC+ countries’ decision to once again cut oil production up until the end of the year, Kommersant notes.

SberCIB Senior Investment Research Analyst Gennady Sukhanov believes that the Brent price will remain near current levels in the second quarter of the year, while it may grow to $85-90 per barrel in the summer due to the seasonal increase in demand and may even surpass the $90 level by the year-end.

Valery Andrianov, associate professor at the Financial University under the Russian Government, told Rossiyskaya Gazeta that by reducing supplies OPEC+ has created the necessary margin of safety to ensure that oil prices will continue to grow steadily up until the end of the year, reaching $100 per barrel and perhaps even a slightly higher level.

The decision made by other OPEC+ members is good news for Russia, National Energy Security Fund Director Konstantin Simonov notes. Not only have we been able to redirect our export flows, but other oil producers are supporting us.

Earlier, European Union and G7 countries decided, under pressure from the United States, that they would not lower the ceiling on Russian oil exports ($60 per barrel) for fear of destabilizing the market and triggering a rise in prices.

In fact, Western countries have no leverage left to put pressure on oil prices. Simonov points out that the market has almost completely won back the price drop caused by the banking crisis and prices once again have started to rise. Now, there is an additional stimulus for price growth.

 

Vedomosti: MOEX to commence futures trading in UAE dirham, Indian rupee

On April 4, the Moscow Exchange will launch trading in futures contracts for cross-currency pairs involving the ruble and the UAE dirham and the Indian rupee. The trading platform’s move comes in response to client demand for a swift reaction to the rapidly changing situation in global markets. In March, the exchange launched futures trading in the Turkish lira and the Hong Kong dollar, Vedomosti notes.

Trade between Russia and the United Arab Emirates soared 68% to $9 bln in 2022. As for India, bilateral trade more than doubled to $50 bln. Meanwhile, the share of the dollar/ruble pair in forex trading dropped to 36%, the lowest level in recent years.

The UAE dirham and the Indian rupee differ in terms of their risk profiles, Finam analyst Andrey Maslov said. The dirham is a more protective and stable asset in "the new reality" that came into being after the launch of Russia’s special military operation, while the rupee is more volatile and risky.

Anton Prokudin, chief macroeconomist at the Ingosstrakh Investment asset management company, views the UAE dirham as a very convenient alternative to the US dollar. According to him, there is a major surplus in the United Arab Emirates’ current transaction account, so there is no prospect that the dirham will get away from the dollar. The only downside of the UAE currency is its lack of liquidity in Russia because Russia rarely receives export payments denominated in dirham, BCS World of Investment expert Valery Yemelyanov notes.

The Indian rupee could be suitable for diversifying more risk-oriented portfolios, Maslov assumes. Its fluctuations against relatively strong currencies are offset by the ruble’s similar volatility, Yemelyanov added. The rupee also has prospects for growth amid a rapprochement between Russia and India, the expert said. It could also become an alternative to the Chinese yuan, which is not so freely traded.

TASS is not responsible for the material quoted in these press reviews

 


Tuesday, April 04, 2023

Stocks: Rally in equities likely to come to a halt, JPMorgan warns

JPMorgan's Jamie Dimon voices recession concerns as bearish sentiment sw...

**NEW RANSOMWARE STRAIN: At the moment the operators of the Rorschach Ransomware remain unknown

 

RORSCHACH – A NEW SOPHISTICATED AND FAST RANSOMWARE

 April 4, 2023

Research by: Jiri  Vinopal, Dennis Yarizadeh and Gil Gekker

Key Findings:

  • Check Point Research (CPR) and Check Point Incident Response Team (CPIRT) encountered a previously unnamed ransomware strain, we dubbed Rorschach, deployed against a US-based company.
  • Rorschach ransomware appears to be unique, sharing no overlaps that could easily attribute it to any known ransomware strain. In addition, it does not bear any kind of branding which is a common practice among ransomware groups.
  • The ransomware is partly autonomous, carrying out tasks that are usually manually performed during enterprise-wide ransomware deployment, such as creating a domain group policy (GPO). In the past, similar functionality was linked to LockBit 2.0.
  • The ransomware is highly customizable and contains technically unique features, such as the use of direct syscalls, rarely observed in ransomware. Moreover, due to different implementation methods, Rorschach is one of the fastest ransomware observed, by the speed of encryption.
  • The ransomware was deployed using DLL side-loading of a Cortex XDR Dump Service Tool, a signed commercial security product, a loading method which is not commonly used to load ransomware. The vulnerability was properly reported to Palo Alto Networks.

Introduction

While responding to a ransomware case against a US-based company, the CPIRT recently came across a unique ransomware strain deployed using a signed component of a commercial security product. Unlike other ransomware cases, the threat actor did not hide behind any alias and appears to have no affiliation to any of the known ransomware groups. Those two facts, rarities in the ransomware ecosystem, piqued CPR interest and prompted us to thoroughly analyze the newly discovered malware.

Throughout its analysis, the new ransomware exhibited unique features. A behavioral analysis of the new ransomware suggests it is partly autonomous, spreading itself automatically when executed on a Domain Controller (DC), while it clears the event logs of the affected machines. In addition, it’s extremely flexible, operating not only based on a built-in configuration but also on numerous optional arguments which allow it to change its behavior according to the operator’s needs. While it seems to have taken inspiration from some of the most infamous ransomware families, it also contains unique functionalities, rarely seen among ransomware, such as the use of direct syscalls.

The ransomware note sent out to the victim was formatted similarly to Yanluowang ransomware notes, although other variants dropped a note that more closely resembled DarkSide ransomware notes (causing some to mistakenly refer to it as DarkSide). Each person who examined the ransomware saw something a little bit different, prompting us to name it after the famous psychological test – Rorschach Ransomware. . ."

READ MORE

New Rorschach ransomware is the fastest encryptor seen so far

 
  • April 4, 2023
  •  
  • 10:13 AM
  •  
  • 0

New Rorschach ransomware is the fastest encryptor seen so far

Following a cyberattack on a U.S.-based company, malware researchers discovered what appears to be a new ransomware strain with "technically unique features," which they named Rorschach.

Among the capabilities observed is the encryption speed, which, according to tests from the researchers, would make Rorschach the fastest ransomware threat today.

The analysts found that the hackers deployed the malware on the victim network after leveraging a weakness in a threat detection and incident response tool.

Rorschach details

Researchers at cybersecurity company Check Point, responding to an incident at a company in the U.S., found that Rorschach was deployed using the DLL side-loading technique via a signed component in Cortex XDR, the extended detection and response product from Palo Alto Networks.

The attacker used the Cortex XDR Dump Service Tool (cy.exe) version 7.3.0.16740 to sideload the Rorschach loader and injector (winutils.dll), which lead to launching the ransomware payload, “config.ini,” into a a Notepad process.

The loader file features UPX-style anti-analysis protection, while the main payload is protected against reverse engineering and detection by virtualizing parts of the code using the VMProtect software.

Check Point reports that Rorschach creates a Group Policy when executed on a Windows Domain Controller to propagate to other hosts on the domain.

After compromising a machine, the malware erases four event logs (Application, Security, System and Windows Powershell) to wipe its trace.

Attack chain
Attack chain (Check Point)

While it comes with hardcoded configuration, Rorschach supports command-line arguments that expand functionality.

Check Point notes that the options are hidden and can't be accessed without reverse engineering the malware. Below are some of the arguments the researchers discovered:

Arguments decoded by Check Point
Arguments decoded by Check Point

Rorschach's encryption process

Rorschach will start encrypting data only if the victim machine is configured with a language outside the Commonwealth of Independent States (CIS). . .To find how fast Rorschach’s encryption is, Check Point set up a test with 220,000 files on a 6-core CPU machine.

It took Rorschach 4.5 minutes to encrypt the data, whereas LockBit v3.0, considered the fastest ransomware strain, finished in 7 minutes.

After locking the system, the malware drops a ransom note similar to the format used by the Yanlowang ransomware.

According to the researchers, a previous version of malware used a ransom note similar to what DarkSide used.

Check Point says that this similarity is likely what caused other researchers to mistake a different version of Rorschach with DarkSide, an operation that rebranded to BlackMatter in 2021, and disappeared the same year.

Latest ransom note dropped by Rorschach
Latest ransom note dropped by Rorschach (Check Point)

BlackMatter's members alter formed the ALPHV/BlackCat ransomware operation that launched in November 2021.

Check Point assesses that Rorschach has implemented the better features from some of the leading ransomware strains leaked online (Babuk, LockBit v2.0, DarkSide).

Along with the self-propagating capabilities, the malware "raises the bar for ransom attacks."

At the moment the operators of the Rorschach ransomware remain unknown and there is no branding, something that is rarely seen on the ransomware scene." 

Top stories

Related Articles:

New Money Message ransomware demands million dollar ransoms

New Dark Power ransomware claims 10 victims in its first month

New ESXiArgs ransomware version prevents VMware ESXi recovery

ALPHV ransomware exploits Veritas Backup Exec bugs for initial access

DISH slapped with multiple lawsuits after ransomware cyber attack

El-Erian on Fed, SVB Collapse, Credit Suisse, Bank Regulation, Inflation

Zelensky Calls for a European Army as He Slams EU Leaders’ Response

      Jan 23, 2026 During the EU Summit yesterday, the EU leaders ...