Home Blog Page 104

Adversaries Misuse Text-messaging Management Services to Access Users’ SMSes

Bait attacks, Email Attacks

Researchers discovered threat actors misusing text messaging services to snoop on victims’ message inboxes. According to a report from security firm Motherboard, certain text-messaging management services have been misused to secretly redirect text messages from victims’ devices to cybercriminals, including 2FA codes and login links that are sent through SMS.

Companies are the Culprits!

The investigation revealed that threat actors are misusing text-messaging service providers to illicitly redirect users’ SMSes to hackers for just $16, exposing them to privacy and security risks. With this, hackers not only access victims’ incoming text messages, but they can reply as well.

Sometimes, the text-messaging service providers fail to notify the users about SMS redirection.

“The invisible cyberattacks on companies providing SMS redirection services are reportedly being carried out in connivance with workers at telecom companies,” the report said.

In general, SMS redirection is a process of diverting your incoming messages to any local Dialog number, email address, or other contact number. Users mostly use this service when their mobile’s battery is dying, or their network is out of coverage.

 SIM Swapping vs. SIM Redirection

Threat actors use several hacking methods, like SIM swapping attacks, to exploit users’ SMS services. In a SIM swapping attack, the hacker calls the service provider and tricks them into changing a victim’s phone number to an attacker-controlled SIM card. It is one of the simplest ways for cybercriminals to bypass users’ 2FA protection. This allows the attacker to reset passwords and gain access to the victim’s sensitive data.

However, it’s easy to discover a SIM swap attack, as the user’s device will be disconnected from the network. While in SMS redirection, the user can’t notice the damage until hackers compromise the device and personal-financial data.

“The method of attack, which has not been previously reported or demonstrated in detail, has implications for cybercrime, where criminals often take over target’s phone numbers to harass them, drain their bank account, or otherwise tear through their digital lives. It is better to use an app like Google Authenticator or Authy. Some password managers even have support for 2FA built-in, like 1Password or many of the other free managers we recommend,” the report added.

“In STEM fields broadly, the industry suffers from a lack of women, particularly women of color”

As the world celebrated womanhood and women’s contribution to society on International Women’s Day, we at CISO MAG decided to devote the month of March to all the women in cybersecurity. The purpose of this article is to highlight the role of women in the industry and address several issues they face. This was in the light of the revelation that women’s representation in cybersecurity has been less than a quarter and has remained that way for almost a decade, if not more. Most of the problems faced by women can be traced back to the earliest days of their education, where stereotypes begin.

Here’s what Jacquie Young, Sr. Director of Channels, APAC, Tenable, has to say about gender disparity, representation, and diversity in cybersecurity:

The representation of women in cybersecurity is just 24%. What are the reasons for these? 

Not only in cybersecurity but in STEM fields broadly, the industry suffers from a lack of women, particularly women of color. This is because young girls are often discouraged from pursuing STEM fields at an early age for a variety of reasons – low expectations from teachers and parents, cultural perception of what’s considered a successful career, limited mentors, lack of exposure, and longstanding stereotypes that underestimate young women’s and minorities’ capabilities.

This leads to an unhealthy lack of self-belief when it comes to filling a role that’s traditionally male-dominated. We need to break through these stereotypes and encourage women to take on roles that excite them regardless and encourage young girls to pursue an education that will lead them to this path.

Do you think there is a dearth of women role models in technology and cybersecurity?

If you look at the Fortune 500 list, there are 37 women-led companies – that’s just 7.4% of the largest corporations. Twenty years ago there were only two women-led companies. While the numbers are heading in the right direction, companies today are nowhere near where they should be to experience the true benefits of diverse workforces and leadership teams.

It’s important for women to have role models in technology, and companies should do everything possible to encourage this because diversity breeds diversity. When women see other women in the industry it sends a powerful message that “you can do it, too.”

Do you think for areas like cybersecurity which often require certifications, scholarships for women are important?

While formal certifications in cybersecurity are useful, organizations also need to think about different career pathways into the security field. Employers should be looking to upskill their new and current workforce and provide them with accessible tools to acquire cybersecurity skill sets.

How can men support women in terms of climbing the corporate ladder?

Be an advocate for women. If you hear a woman being spoken over, call it out. If you see that a woman may need encouragement to put themselves forward for a new or promoted role, help her. It takes everyone paying attention to create cultural change to make an organization more diverse and inclusive. In order to achieve progress in gender parity, mentorship programs, sponsorship opportunities, and the development of a positive office culture has to take place from across all levels of the organization.


Jacquie YoungJacquie Young is the Senior Director of Channels for the Asia-Pacific region at Tenable with over 20 years of experience specializing in Consumer Electronics, Networking, Channel Development, and Sales Strategy. She oversees channel strategy, market analysis, and target partner selection across APAC ensuring a robust collaboration between Tenable’s sales teams and its partners across countries.

She was previously at Cisco for seven years, including leading strategic planning with partners across APAC. In 2011, she established MBT Consultancy, a management consulting firm specializing in strategy & planning in the IT industry after obtaining her Masters in Business and Technology from the University of New South Wales in 2011. Prior to joining Tenable, Jacquie also led APAC Channels at Nokia.

Disclaimer

Views expressed in this article are personal.

CISO MAG’s March issue on Women in Cybersecurity is out. Preview hereSubscribe now!

1 in 15 Government Employees Exposed to Phishing Attacks

phishing, Telegram bots and Google Forms used for phishing

Android users who are running older versions of the operating system are prone to various mobile takeover attacks.  A recent analysis from mobile security firm Lookout found that 99.2% of Android users in the U.S. government agencies are running on outdated operating systems, exposing their devices to vulnerabilities and cyberattacks. The findings raised severe security concerns since the federal agencies host critical sensitive information.

Key Findings

  • Nearly, 99% of U.S. government Android users are exposed to hundreds of vulnerabilities due to out-of-date operating systems.
  • App threats surged nearly 20 times across all levels of government as the cybersecurity community recategorized the risks surrounding embedded adware.
  • 1 in 15 government employees was exposed to phishing threats. With over two million federal government employees alone.
  • Over 70% of phishing attacks against government organizations sought to steal login credentials, which is a 67% increase from 2019.
  • Nearly one-quarter of state and local government employees use personal unmanaged devices, outpacing the nearly 9% in the federal government.

Remote Work – An Added Fuel to Rising Threats

With remote working conditions globally, most of the employees in government organizations are using their personal devices to access sensitive government data. These multiple endpoints along with cloud applications are encouraging cybercriminals to discover vulnerable entry points to break into the victims’ devices.

The analysis found that 22.8% of the U.S. government workers still use the Android 8 operating system, which has over 636 known vulnerabilities. And 28.2% of federal, state, and local government employees use the Android 9 operating system, which has over 173 publicly known vulnerabilities.

Risks with a vulnerable operating system

  • Attackers can exploit vulnerabilities to actively target and take over a device or surpass its built-in security measures.
  • Compliance violations due to data handling practices.
  • If an employee is running an old version, they present a risk to the organization that could be easily eliminated with an operating system update.
  • Access to the camera and microphone to spy on the user.
  • Access to the device’s file system.
  • Connections to servers in foreign countries. 

How to Maximize Mobile Security

Lookout also made certain recommendations to boost mobile security, these include:

  • Keep mobile systems up to date. This may mean accelerating the testing of proprietary apps, but it’s a necessary change of priority.
  • Make sure mobile vulnerability and patch management capabilities are part of your operation.
  • Require users to install updates on mobile devices whenever they’re available.
  • Implement an approved device list for BYOD devices.
  • Train employees to recognize phishing attacks, but don’t stop at desktop attacks: Be sure to include recognizing phishing on mobile devices as well.

“Malicious actors have embraced mobile phishing because they can use any one of the hundreds of apps on the average person’s mobile device. Attackers can socially engineer targets on a personal level through social media apps, messaging platforms, games, and even dating apps. An attacker will target particular individuals, including department heads, law enforcement officials, city superintendents, revenue officers, or other government officials to gain privileged access to the data they want to steal,” Lookout said.

COVID-19 Vaccine-related Fraudulent Website Registrations are Up 2100%

COVID-19 Cyberthreats

A recent report from Barracuda alerted how threat actors were capitalizing on the vaccine distribution campaigns through phishing attacks. However, a new study from an online threat hunting company, BrandShield found alarming evidence that over 5,000 suspicious and fraudulent COVID-19 vaccine websites have already been registered in the first two months of 2021. This is a steep rise of up to 2100% as compared to October-November 2020.

fraudulent covid-19 vaccine websites
Image Credit: BrandShield

The Analysis

BrandShield took up this study as a part of its collaboration with the Pharmaceutical Security Institute (PSI), a trade association of pharmaceutical manufacturers focused on patient safety. The analysis revealed that notable instances of fraud on these suspicious websites include organizations claiming to offer vials of brand name vaccines approved by the FDA.

fraudulent covid-19 vaccine websites
Image Credit: BrandShield

 What experts say… 
Yoav Keren, Co-founder and CEO of BrandShield said,

Fraud preys on the vulnerable, and there’s never been a more universal global threat than COVID-19. This environment is especially dangerous for our aging population. They were already the most at risk of suffering from the pandemic and online fraud; but now, cybercriminals have combined the two, creating a potentially deadly situation. It’s a double-whammy and one that I hope to help avoid.

 What we say… 

This means threat actors are targeting the lesser-known and newly approved brands. As people have limited knowledge about these brands’ online identity and acronyms, it is easier to create and imitate a fraudulent website. Also, since there’s an observed surge in COVID-19 cases around the globe – an indication of a mighty second wave  – people are rushing to get vaccinated from any brand available at the earliest. Threat actors are leveraging this very fear and anxiety among the masses.

fraudulent covid-19 vaccine websites
Image Credit: BrandShield

Social Media: The Latest Threat Surface

Since December 2020, BrandShield has analyzed over 20,000 potentially fraudulent social media posts, users, and handles. The data shows that the popular photo-sharing social media app, Instagram, accounts for most of the threats detected. Twitter, and surprisingly Telegram, are tied for the second most popular platforms of choice for fraudsters, followed by Facebook in the third place.

fraudulent covid-19 vaccine websites
Fraudulent Vaccine Selling Scam on Instagram. Image Credit: BrandShield

Scammers have often used social media platforms to market themselves. They impersonate legitimate pharmaceutical companies or lie about being able to sell vaccines. Social media platforms are also being used to sell fraudulent vaccines or drive people to phishing sites that can either steal their money or credentials. Fraudsters also dupe their victims on social media by promising them the sale of a potentially banned product or move the scam offline through private messaging.

 What we say… 

This trend is even more serious. This means phishing is no longer limited to just emails and SMSes, but it has now been widely targeted at popular social media platforms too. Emails and SMSes are used generally by an older population. Whereas social media has largely been used by the tech-savvy and Generation Z. Threat actors are now interested in targeting the younger masses who seem to be more susceptible and easier targets as they tend to spend more than saving.

Time to keep a closer eye on Generation Z!

Note of Caution

In the U.S. and EU, the vaccines are available through state-approved vaccination locations. Any offer online, over the phone, or in-person to supply vaccines or to charge you any associated cost is a scam. If you spot an online scam, please immediately report the crime to the Federal Bureau of Investigation’s Internet Crime Complaint Center, which can be found here.

Related News:

Beware! COVID-19 Vaccine-related Phishing Scams on Rise

Beware of Fake COVID-19 Vaccines Circulating on Dark Web

Operation Diànxùn: Chinese Cyber Espionage Campaign Targeting 5G Operators

Chinese actors target telecom

Cybersecurity experts discovered a cyber espionage campaign targeting telecom operators globally to steal sensitive information. According to McAfee’s Advanced Threat Research (ATR) team, the campaign is aimed at pilfering trade secrets and other technical details related to 5G technology. Dubbed “Operation Diànxùn,” the campaign tricks employees in the telecom sector with a fake Huawei career page asking them to provide personal data.

Links to Chinese Hackers

McAfee researchers suspect that Chinese state-sponsored hackers are behind Operation Diànxùn because the tactics, techniques, and procedures (TTPs) used in the campaigns are similar to the ones used by Chinese threat actor groups RedDelta and Mustang Panda.

“Most probably this threat is targeting people working in the telecommunications industry and has been used for espionage purposes to access sensitive data and to spy on companies related to 5G technology,” McAfee said. 

Three Phases of Attack Vectors

The research team found that Operation Diànxùn operators initiate their attacks in three phases:

  • The attackers send phishing emails to the targets as the initial phase of the infection. In this phase, the victims are directed to a domain, masquerading as the Huawei company career page, controlled by the threat actor group.
  • The second phase of exploitation involves malware execution on the victim’s endpoint of Flash-based artifacts malware and Dotnet payload. The fake Flash installer acts as a payload downloader to further compromise the targeted machine.
  • The last phase of the attack involves creating a backdoor for remote control of the victim via a Command-and-Control Server and Cobalt Strike Beacon.

“To defeat targeted threat campaigns like Operation Dianxun, defenders must build an adaptive and integrated security architecture which will make it harder for threat actors to succeed and increase resilience in the business,” McAfee added.

Multiple Indian Banks Encounter Phishing Attacks

Acronis Cyber Readiness Report, cyberattacks in India, cybercrime in India, India’s Private Sector

Sensitive financial information is always a lucrative target for cybercriminals. Threat actors often use advanced techniques in their phishing campaigns to harvest victims’ banking data. A recent investigation from Cyber Peace Foundation, an Indian-based think tank of cybersecurity and policy experts, revealed that threat actors are targeting users with a malicious URL “http://204.44.124[.]160/ITR,” asking them to apply for the disbursement of an income tax refund. They are distributing a malicious link that redirects the users, when clicked, to a fake income tax e-filing web page that tricks the users into entering personal information.

Attackers duplicated the layout and features of the official income tax website on their phishing page to trick unwitting users.

Multiple Banks on Target

According to Cyber Peace, the targeted banks in this phishing campaign include the State Bank of India, HDFC, ICICI, Axis Bank, and Punjab National Bank. “The campaign is collecting personal as well as banking information from the user and getting into this type of trap could cause a massive financial loss for the users,” Cyber Peace said.

Hackers Operating from Abroad

It was found that the fraudulent links originated from the U.S. and France. The shared SMS with the malicious link has no domain name and is not linked with the Indian government.

“All IP addresses associated with the campaign belong to some third-party dedicated cloud hosting providers. The whole campaign uses a plain HTTP protocol instead of secure HTTPS. This means anyone on the network or internet can intercept the traffic and get the confidential information in plain text to misuse against the victim,” Cyber Peace added.

How are users phished?

  • If a user clicks on the fake link it redirects to a landing page that is mostly like the government income tax e-filing website.
  • Upon clicking the Proceed to the verification steps option, users are asked to submit personal details like full name, PAN, Aadhar number, contact details, address, pin code, date of birth, email address, gender, marital status along with bank details like account number, IFSC code, card number, expiry date, CVV/CVC, and card PIN.
  • Once the user submits the required data, the page then asks to confirm the entered data.
  • On clicking the confirm option, the user is redirected to a fake banking login page mimicking the legitimate one, which asks for the username and password for online banking.
  • Once submitted, a mobile verification section with instructions provided to download an Android application (.apk file) appears, to complete the ITR verification.
  • Users are asked to grant all device permissions to this .apk application.
  • The application apk starts downloading upon clicking the download link, which later exfiltrates sensitive data for the victim’s device.

Since this phishing campaign uses “HTTP” web protocol, the requests and responses are sent in plain text or clear text that can be read by anyone on the internet.

Enterprise Information Security and Risk Management Spending in India to Grow 9.5% in 2021: Gartner

spending

After a dip in spending last year, organizations are once again investing in information security. Enterprise information security and risk management end-user spending in India is on pace to total $2.08 billion in 2021, an increase of 9.5% from 2020, according to the latest forecast from Gartner, Inc. Compare this with global average spending growth of 10.5%. Spending in matured APAC markets will grow by 8.6% in 2021 and 10.7% in emerging APAC markets, estimates Gartner. This spending is being driven by increased digitalization and the need to secure digital infrastructure on the cloud.

“The overnight move to remote-working in reaction to the pandemic exposed organizations’ vulnerabilities,” said Prateek Bhajanka, Senior Principal Research Analyst at Gartner. “While security leaders had to cut down on their security spending in 2020 because of IT budget-cuts, in 2021, this trend is reversing. A secure digital environment is now foundational to organizations’ growth and in preparation to another crisis that may arise. Security leaders are ready to reinvest in cybersecurity with a renewed and refreshed rigor.”

Gartner analysts shared how security and risk management leaders (CISOs) can advance their IT cybersecurity and risk strategy at the Gartner Security & Risk Management Summit India taking place virtually through Thursday (March 18).

In 2021, organizations are expected to increase their spending across all segments of security and risk management. Continuing the trend from last year, cloud security and integrated risk management will experience the highest growth in 2021, up 251% and 27.8%, respectively (see Table below).

Source: Gartner (March 2021)

Shift to cloud drives triple-digit spending on cloud security

“India is at an early stage of cloud adoption and the pandemic only accelerated this shift as organizations moved to the cloud to achieve cost efficiency and business continuity,” said Bhajanka. “In 2020, hyperscalers, such as Amazon Web Services, Microsoft Azure, and Google Cloud, increased their investment in data centers in India, further catalyzing Indian organizations’ move to cloud during the pandemic.”

CISOs and security leaders are aware of the risks and vulnerabilities that their organizations can be exposed to while migrating to the cloud from legacy systems. To manage these risks, organizations are increasing their spending on cloud security tools, driving the market up 251.1% in 2021. Cloud access security brokers (CASB) and cloud workload protection platforms (CWPP) will be some of the major technologies that CISOs in India will increase their spending on within the cloud security segment in 2021.

In addition, Indian CISOs and security leaders will focus on establishing and deploying threat detection and response programs and capabilities, such as endpoint detection and response (EDR), and move to cloud-delivered security capabilities to have consistent security coverage whether working from the office, home, or off-site.

Gartner clients can read more in the report “Forecast: Information Security and Risk Management, Worldwide, 2018-2024, 4Q20 Update.” 

Cybersecurity and the Board

Gartner also said that by 2025, 40% of Boards of directors will have a dedicated cybersecurity committee overseen by a qualified board member, up from less than 10% today.  “This shows increased commitment to cybersecurity coming from top management. And it will increase the success of projects undertaken by the execution teams,” said Bhajanka.

“In the past, security was seen as an inhibitor and a cost center. But that perception changed during the pandemic when cybersecurity and ransomware became a major concern for businesses across the world. Today, cybersecurity is being addressed at a higher level and is now a concern of the Board.”

Bhajanka says the investments and commitments towards cybersecurity were slow to pick up and the challenge is the way cybersecurity is communicated to the board.

“Cybersecurity is an enabler for (digital) business, but the security team has not been able to communicate that effectively to the Board of directors. That’s because the security teams communicate in technical terms and have not been successful in communicating and translating cybersecurity language to the business language that the board of directors understands. If they understand it, they would be able to internalize it, and take action on it,” added Bhajanka.

And that reinforces our belief that communication will be a key skill for CISOs in 2021.

Smart City Project in India Receives a Ransomware Jolt

paying ransom, Conti Ransomware Attacks

Based on an IBM security report, India had recently gained an unwanted second spot in the list of most cyberattacked countries in APAC for 2020. Out of the total attack share, ransomware accounted for the highest at 40%. It seems that the ghosts of the past are well and truly haunting India. A Smart City project carried out by Indian tech giant, Tech Mahindra, has reportedly fallen prey to a ransomware attack that infected nearly 25 of its project servers. As per the FIR registered by the project in charge at a local police station, Tech Mahindra has suffered losses amounting to INR 5 crore (approximately $690,000) due to the attack.

Ransomware Attack on Tech Mahindra

The Government of India (GoI) launched the Smart Cities Mission in June 2015. The objective of this initiative was to promote sustainable and inclusive cities that provide core infrastructure and give a clean and sustainable environment to their citizens by integrating ‘Smart Solutions.’ Under this program, the Pimpri-Chinchwad town (adjacent to Pune) was also ordained to become a “Smart City”. Tech Mahindra, which has handled such projects before, won INR 500 crore bid (approximately $ 6,88,45,600) for this project in December 2019 from the Pimpri-Chinchwad Municipal Corporation (PCMC).

Related News:

India Becomes the Second Most Cyberattacked Country in APAC in 2020

However, just after a year into the project, Tech Mahindra set up nearly 300 servers, moving at full throttle towards completion. But the company hit a major bump on February 26, 2021, when 25 of its PCMC smart city project servers were targeted by a ransomware attack. The project manager of Tech Mahindra’s PCMC project immediately lodged a criminal offense complaint at the Nigdi Police Station in which he mentioned that the attackers had demanded a ransom to be paid in Bitcoins in exchange for the decryption key.

Talking about the complaint, Municipal Commissioner Rajesh Patil was quoted saying, “The civic body will not pay for the loss”. Adding to this, PCMC’s IT Officer also said,

We are surprised by the police complaint lodged by Tech Mahindra. We believe they can restore the system. There is no justification for any loss. The PCMC will not pay anything to the firm. We have told them so.

However, Tech Mahindra has clarified that it only went by the procedure and they are not expecting any compensations from the PCMC for the damages or the ransom demand.

Tech Mahindra’s Response

Clearing the air, Sujit Baksi, president of corporate affairs, Tech Mahindra, said,

On February 26, we were informed about the ransomware attack on the PCMC servers. The team briefed the whole situation to the cybersecurity officials and filed an FIR with the police. After a detailed analysis of the situation in the past 10 days, we have concluded that 25 servers are impacted, which need to be rebuilt along with the implementation of a robust security system. Our team is monitoring the situation on a regular basis and has also continued the work on rebuilding the environment without touching the infected servers.

On the other hand, Tech Mahindra also confirmed that servers impacted by the ransomware attack are recoverable and that no other commercial impact has been observed.

This incident however exposes the inadequacy of cybersecurity policy-making and lack of skilled manpower in the government sector. The attack is the latest in a long line of security incidents aimed at the government and public sector. In a report titled “China-linked Group RedEcho Targets the Indian Power Sector Amid Heightened Border Tensions,” Recorded Future, a cybersecurity company, cites geopolitical reasons and heightened border clashes between India and China since last May, as the reasons for the escalation in cyberattacks. Read the full story here.

Related News:

RedEcho Attacked 10 Indian Power Sector Companies and 2 Seaports: Recorded Future

PYSA Ransomware Targets Education Institutions: FBI

Ransomware attacks, ransomware, Sinclair Broadcast group

Educational institutions are concerned about security after the increase in cyberattacks. These institutions became more vulnerable to ransomware operators after the transition to remote education, globally. Recently, the FBI’s Cyber Division issued an alert warning about an uptick in cyberattacks against higher education institutions and K-12 schools, delivering the PYSA ransomware.

Also known as Mespinoza, the PYSA ransomware is malware that exfiltrates users’ data and encrypts critical files on their systems. It was found that the operators behind the PYSA targeted educational institutions in 12 U.S. states and the U.K. The attackers compromised sensitive information before encrypting the victims’ systems to blackmail them for ransom.

How PYSA Attacks

Active since March 2020, the PYSA ransomware operators launched attacks on the U.S. and foreign government entities, educational institutions, private organizations, and the healthcare sector. The attackers leverage Remote Desktop Protocol (RDP) credentials or phishing techniques to gain unauthorized access to victims’ networks.

The FBI found that the PYSA actors use Advanced Port Scanner and Advanced IP Scanner1 to conduct network reconnaissance and install open-source tools like PowerShell Empire2, Koadic3, and Mimikatz4. The attackers then execute commands to deactivate antivirus protection on the victim’s network before deploying the ransomware. “The cyber actors then exfiltrate files from the victim’s network, sometimes using the free opensource tool WinSCP5, and proceed to encrypt all connected Windows and/or Linux devices and data, rendering critical files, databases, virtual machines, backups, and applications inaccessible to users,” the FBI said.

Upon deploying the malware, a message is displayed on the victim’s login page, demanding ransom. The attackers warn the victims that encrypted data will be uploaded and traded on the darknet forums if the ransom is not paid.

The FBI stated that paying the ransom to cybercriminals does not guarantee file recovery. It may encourage adversaries to target other organizations using the same strategy in distributing ransomware.

Mitigations

The FBI also recommended certain security measures to overcome threats against ransomware operators. These include:

  • Regularly back up data, air gap, and password-protect backup copies offline. Ensure copies of critical data are not accessible for modification or deletion from the system where the data resides.
  • Implement a recovery plan to maintain and retain multiple copies of sensitive or proprietary data and servers in a physically separate, segmented, secure location (i.e., hard drive, storage device, the cloud).
  • Install updates/patch operating systems, software, and firmware as soon as they are released.
  • Regularly, change passwords to network systems and accounts, and avoid reusing passwords for different accounts. Implement the shortest acceptable timeframe for password changes.
  • Provide users with training on information security principles and techniques as well as overall emerging cybersecurity risks and vulnerabilities.

DuckDuckGo Quacks Again About uXSS Vulnerability in Multiple Browsers

Positioned as a private search engine that doesn’t track users, DuckDuckGo claims that it does not store users’ IP addresses or search details. Many users use DuckDuckGo for its privacy features. But recent vulnerability disclosures have made users question their data privacy.

Security experts recently uncovered a Universal Cross-site Scripting (uXSS) vulnerability in multiple browser extensions, including Chrome, Microsoft Edge, and Firefox. The vulnerability exists in DuckDuckGo’s Privacy Essentials feature, which blocks hidden trackers and offers private browsing features to users.

What is Cross-site Scripting (XSS)

Cross-site scripting (XSS) is a type of flaw found in web applications. It allows attackers to inject client-side scripts into web pages viewed by other users and bypass access controls.

Cyber Snooping

Discovered by security researcher Wladimir Palant, the uXSS vulnerability can be exploited by an attacker to execute arbitrary code on any domain. The flaw could enable threat actors to spy on users’ online activities, leaving their sensitive information at risk. However, Palant stated that an attacker must gain access to the DuckDuckGo server to exploit the vulnerability.

“The vulnerability gave a DuckDuckGo server way more privileges than intended: a Cross-site Scripting (XSS) vulnerability in the extension allowed this server to execute arbitrary JavaScript code on any domain. The attackers can spy on anything the users do in their browser, they can manipulate displayed information, take over accounts, impersonate the user. As a trivial consequence, online banking or shopping sessions can no longer be considered secure – the attackers can reroute transfers or shipments,” Palant said.

Patch on the Way!

While the vulnerability has been patched in Chrome and Mozilla Firefox, a security update for other browsers like Microsoft Edge is expected to be released shortly. “These vulnerabilities are very typical; I’ve seen similar mistakes in other extensions many times. This isn’t merely extension developers being clueless. The extension platform introduced by Google Chrome simply doesn’t provide secure and convenient alternatives. So, most extension developers are bound to get it wrong on the first try,” Palant added.

DuckDuckGo Slams Google for Spying

Google recently updated its iOS applications with the App Store privacy labels to give users clarity about what type of data the app collects from users. DuckDuckGo leveraged this situation promptly to show how much data both Google and Google Chrome collect from their users comparing what they collect, which is null. In a Twitter post, DuckDuckGo slammed the search engine giant for spying on users’ search details by using App Store privacy labels as proof.