Connect with us

Published

on

Over the years, travelers have repeatedly been warned to avoid public Wi-Fi in places like airports and coffee shops. Airport Wi-Fi, in particular, is known to be a hacker honeypot, due to what is typically relatively lax security. But even though many people know they should stay away from free Wi-Fi, it proves as irresistible to travelers as it is to hackers, who are now updating an old cybercrime tactic to take advantage.

An arrest in Australia over the summer set off alarm bells in the United States that cybercriminals are finding new ways to profit from what are called “evil twin” attacks. Also classified within a type of cybercrime called “Man in the Middle” attacks, evil twinning occurs when a hacker or hacking group sets up a fake Wi-Fi network, most often in public settings where many users can be expected to connect.

In this instance, an Australian man was charged with conducting a Wi-Fi attack on domestic flights and airports in Perth, Melbourne, and Adelaide. He allegedly set up a fake Wi-Fi network to steal email or social media credentials.

“As the general population becomes more accustomed to free Wi-Fi everywhere, you can expect evil twinning attacks to become more common,” said Matt Radolec, vice president of incident response and cloud operations at data security firm Varonis, adding that no one reads the terms and conditions or checks the URLs on free Wi-Fi.

“It’s almost a game to see how fast you can click “accept” and then ‘sign in’ or ‘connect.’ This is the ploy, especially when visiting a new location; a user might not even know what a legitimate site should look like when presented with a fake site,” Radolec said.

Today’s ‘evil twins’ can more easily hide

One of the dangers of today’s twinning attacks is that the technology is much easier to disguise. An evil twin can be a tiny device and can be tucked behind a display in a coffee shop, and the small device can have a significant impact.

“A device like this can serve up a compelling copy of a valid login page, which could invite unwary device users to enter their username and password, which would then be collected for future exploitation,” said Cincinnati-based IT consultant Brian Alcorn. 

The site doesn’t even have to actually log you in. “Once you’ve entered your information, the deed is done,” Alcorn said, adding that a harried, weary traveler probably would just think the airport Wi-Fi is having issues and not give it another thought.  

People who are not careful with passwords, such as use of pet’s names or favorite sports teams as their password for everything, are even more vulnerable to an evil twin attack. Alcorn says for individuals who reuse username and password combinations online, once the credentials are obtained they can be fed into AI, where its power can quickly give cybercriminals the key.

“You are susceptible to exploitation by someone with less than $500 in equipment and less skill than you might imagine,” Alcorn said. “The attacker just has to be motivated with basic IT skills.”

How to avoid becoming a victim of this cybercrime

When in public places, experts say it’s best to use alternatives to public WiFi networks.

“My favorite way to avoid evil twin attacks is to use your phone’s mobile hotspot if possible,” said Brian Callahan, Director of the Rensselaer Cybersecurity Collaboratory at Rensselaer Polytechnic Institute.

Users would be able to spot an attack if through a phone relying on its mobile data and sharing it via a mobile hotspot.

“You will know the name of that network since you made it, and you can put a strong password that only you know on it to connect,” Callahan said.

If a hotspot isn’t an option, a VPN can also provide some protection, Callahan said, as traffic should be encrypted to and from the VPN.

“So even if someone else can see the data, they can’t do anything about it,” he said.

Airport, airline internet security issues

At many airports, the responsibility for WiFi is outsourced and the airport itself has little if any involvement in safeguarding it. At Dallas Fort Worth International Airport, for example, Boingo is the Wi-Fi provider.

“The airport’s IT team does not have access to their systems, nor can we see usage and dashboards,” For said an airport spokesman. “The network is isolated from DAL’s systems as it is a separate standalone system with no direct connection to any of the City of Dallas’ networks or systems internally.” 

A spokeswoman for Boingo, which provides service to approximately 60 airports in North America, said it can identify rogue Wi-Fi access points through its network management. “The best way passengers can be protected is by using Passpoint, which uses encryption to automatically connect users to authenticated Wi-Fi for a safe online experience,” she said, adding that Boingo has offered Passpoint since 2012 to enhance Wi-Fi security and eliminate the risk of connecting to malicious hotspots.

Alcorn says evil twin attacks are “definitely” occurring with regularity in the United States, it’s just rare for someone to get caught because they are such stealth attacks.  And sometimes hackers use these attacks as a learning model. “Many evil twin attacks may be experimental by individuals with novice-to-intermediate skills just to see if they can do it and get away with it, even if they don’t use the collected information right away,” he said.

The surprise in Australia wasn’t the evil twinning attack itself, but the arrest.

“This incident isn’t unique, but it is unusual that the suspect was arrested,” said Aaron Walton, threat analyst at Expel, a managed services security company. “Generally, airlines are not equipped and prepared to handle or mediate hacking accusations. The typical lack of arrests and punitive action should motivate travelers to exercise caution with their own data, knowing what a tempting and usually unguarded -target it is — especially at the airport.”

In the Australian case, according to Australian Federal Police, dozens of people had their credentials stolen.

According to a press release from the AFP, “When people tried to connect their devices to the free WiFi networks, they were taken to a fake webpage requiring them to sign in using their email or social media logins. Those details were then allegedly saved to the man’s devices.”  

Once those credentials were harvested, they could be used to extract more information from the victims, including bank account information.

For hackers to be successful, they don’t have to dupe everyone. If they can persuade only a handful of people – statistically easy to do when thousands of harried and hurried people are milling around an airport – they will succeed.

“We expect WI-Fi to be everywhere. When you go to a hotel, or an airport, or a coffee shop, or even just out and about, we expect there to be Wi-Fi and often freely available WI-FI,” Callahan said. “After all, what’s yet another network name in the long list when you’re at an airport? An attacker doesn’t need everyone to connect to their evil twin, only some people who go on to put credentials into websites that can be stolen.”

The next time you’re at the airport, the only way to be 100% sure you’re safe is to bring your own Wi-Fi.

Continue Reading

Technology

SoftBank to acquire chip designer Ampere in $6.5 billion deal

Published

on

By

SoftBank to acquire chip designer Ampere in .5 billion deal

The logo of Japanese company SoftBank Group is seen outside the company’s headquarters in Tokyo on January 22, 2025. 

Kazuhiro Nogi | Afp | Getty Images

SoftBank Group said Wednesday that it will acquire Ampere Computing, a startup that designed an Arm-based server chip, for $6.5 billion. The company expects the deal to close in the second half of 2025, according to a statement.

Carlyle Group and Oracle both have committed to selling their stakes in Ampere, SoftBank said.

Ampere will operate as an independent subsidiary and will keep its headquarters in Santa Clara, California, the statement said.

“Ampere’s expertise in semiconductors and high-performance computing will help accelerate this vision, and deepens our commitment to AI innovation in the United States,” SoftBank Group Chairman and CEO Masayoshi Son was quoted as saying in the statement.

The startup has 1,000 semiconductor engineers, SoftBank said in a separate statement.

Chips that use Arm’s instruction set represent an alternative to chips based on the x86 architecture, which Intel and AMD sell. Arm-based chips often consume less energy. Ampere’s founder and CEO, Renee James, established the startup in 2017 after 28 years at Intel, where she rose to the position of president.

Leading cloud infrastructure provider Amazon Web Services offers Graviton Arm chip for rent that have become popular among large customers. In October, Microsoft started selling access to its own Cobalt 100 Arm-based cloud computing instances.

This is breaking news. Please refresh for updates.

Continue Reading

Technology

Nvidia’s Huang says faster chips are the best way to reduce AI costs

Published

on

By

Nvidia's Huang says faster chips are the best way to reduce AI costs

Nvidia CEO Jensen Huang introduces new products as he delivers the keynote address at the GTC AI Conference in San Jose, California, on March 18, 2025.

Josh Edelson | AFP | Getty Images

At the end of Nvidia CEO Jensen Huang’s unscripted two-hour keynote on Tuesday, his message was clear: Get the fastest chips that the company makes.

Speaking at Nvidia’s GTC conference, Huang said that questions clients have about the cost and return on investment the company’s graphics processors, or GPUs, will go away with faster chips that can be digitally sliced and used to serve artificial intelligence to millions of people at the same time.

“Over the next 10 years, because we could see improving performance so dramatically, speed is the best cost-reduction system,” Huang said in a meeting with journalists shortly after his GTC keynote.

The company dedicated 10 minutes during Huang’s speech to explain the economics of faster chips for cloud providers, complete with Huang doing envelope math out loud on each chip’s cost-per-token, a measure of how much it costs to create one unit of AI output.

Huang told reporters that he presented the math because that’s what’s on the mind of hyperscale cloud and AI companies.

The company’s Blackwell Ultra systems, coming out this year, could provide data centers 50 times more revenue than its Hopper systems because it’s so much faster at serving AI to multiple users, Nvidia says. 

Investors worry about whether the four major cloud providers — Microsoft, Google, Amazon and Oracle — could slow down their torrid pace of capital expenditures centered around pricey AI chips. Nvidia doesn’t reveal prices for its AI chips, but analysts say Blackwell can cost $40,000 per GPU.

Already, the four largest cloud providers have bought 3.6 million Blackwell GPUs, under Nvidia’s new convention that counts each Blackwell as 2 GPUs. That’s up from 1.3 million Hopper GPUs, Blackwell’s predecessor, Nvidia said Tuesday. 

The company decided to announce its roadmap for 2027’s Rubin Next and 2028’s Feynman AI chips, Huang said, because cloud customers are already planning expensive data centers and want to know the broad strokes of Nvidia’s plans. 

“We know right now, as we speak, in a couple of years, several hundred billion dollars of AI infrastructure” will be built, Huang said. “You’ve got the budget approved. You got the power approved. You got the land.”

Huang dismissed the notion that custom chips from cloud providers could challenge Nvidia’s GPUs, arguing they’re not flexible enough for fast-moving AI algorithms. He also expressed doubt that many of the recently announced custom AI chips, known within the industry as ASICs, would make it to market.

“A lot of ASICs get canceled,” Huang said. “The ASIC still has to be better than the best.”

Huang said his is focus on making sure those big projects use the latest and greatest Nvidia systems.

“So the question is, what do you want for several $100 billion?” Huang said.

WATCH: CNBC’s full interview with Nvidia CEO Jensen Huang

Watch CNBC's full interview with Nvidia CEO Jensen Huang

Continue Reading

Technology

Microsoft announces new HR executive, company veteran Amy Coleman

Published

on

By

Microsoft announces new HR executive, company veteran Amy Coleman

Microsoft’s Amy Coleman (L) and Kathleen Hogan (R).

Source: Microsoft

Microsoft said Wednesday that company veteran Amy Coleman will become its new executive vice president and chief people officer, succeeding Kathleen Hogan, who has held the position for the past decade.

Hogan will remain an executive vice president but move to a newly established Office of Strategy and Transformation, which is an expansion of the office of the CEO. She will join Microsoft’s group of top executives, reporting directly to CEO Satya Nadella.

Coleman is stepping into a major role, given that Microsoft is among the largest employers in the U.S., with 228,000 total employees as of June 2024. She has worked at the company for more than 25 years over two stints, having first joined as a compensation manager in 1996.

Hogan will remain on the senior leadership team.

“Amy has led HR for our corporate functions across the company for the past six years, following various HR roles partnering across engineering, sales, marketing, and business development spanning 25 years,” Nadella wrote in a memo to employees.

“In that time, she has been a trusted advisor to both Kathleen and to me as she orchestrated many cross-company workstreams as we evolved our culture, improved our employee engagement model, established our employee relations team, and drove enterprise crisis response for our people,” he wrote.

Hogan arrived at Microsoft in 2003 after being a development manager at Oracle and a partner at McKinsey. Under Hogan, some of Microsoft’s human resources practices evolved. She has emphasized the importance of employees having a growth mindset instead of a fixed mindset, drawing on concepts from psychologist Carol Dweck.

“We came up with some big symbolic changes to show that we really were serious about driving culture change, from changing the performance-review system to changing our all-hands company meeting, to our monthly Q&A with the employees,” Hogan said in a 2019 interview with Business Insider.

Hogan pushed for managers to evaluate the inclusivity of employees and oversaw changes in the handling of internal sexual harassment cases.

Coleman had been Microsoft’s corporate vice president for human resources and corporate functions for the past four years. In that role, she was responsible for 200 HR workers and led the development of Microsoft’s hybrid work approach, as well as the HR aspect of the company’s Covid response, according to her LinkedIn profile.

Don’t miss these insights from CNBC PRO

Enterprise exposure better than consumer exposure: D.A. Davidson's Luria on the Microsoft bull case

Continue Reading

Trending