Home Blog Page 114

30,000 Macs Affected by “Silver Sparrow” Mystery Malware

silver sparrow malware

Apple is known for its airtight security across its product line. However, a mystery malware dubbed “Silver Sparrow” has broken this myth by infecting nearly 30,000 Macs (29,139 to be precise) in over 153 countries worldwide. Researchers are scratching their heads trying to understand this malware because it is hiding on the infected machines still waiting for a payload to arrive. Usually, post-compromise, a payload is dropped that then carries out malicious activities, however, this is not the case here.

Analyzing the Silver Sparrow Malware

Red Canary’s blog post offers an in-depth analysis of how the malware was discovered, its targets, operations, and how it affects Apple’s latest M1 chip. For those who want facts and figures, the Silver Sparrow malware is currently the second known malware targeting the Apple M1 silicon chip. The first one was incidentally discovered a week ago by security researcher Patrick Wardle from Objective-See.

As per Red Canary, the Silver Sparrow malware has two versions:

  1. Version 1 IOCs

File name: updater.pkg (installer package for v1)

MD5: 30c9bc7d40454e501c358f77449071aa

  1. Version 2 IOCs

File name: update.pkg (installer package for v2)

MD5: fdd6fb2b1dfe07b0e57d4cbfef9c8149

silver sparrow malware
Image Credit: Red Canary

As shown in the above image, one version is a binary in mach-object format compiled for Intel x86_64 processors and the other version is a Mach-O binary for the M1 chip. The researchers believe that these are “bystander binaries” as they only display messages like “Hello World!” and “You did it!” when executed. As precautionary measures, Apple has revoked the licenses of both the binaries effective immediately.

Related News:

TeamTNT Spreads Malware with New Detection Evasion Tool “Libprocesshider”

Silver Sparrow uses Apple’s system.run command for execution and is thus difficult to detect. Researchers found that every hour the malware contacts the command-and-control center (C2) for further actions, however, none have been observed until now keeping the malware in stealth mode. Another interesting mechanism that the Silver Sparrow malware contains is its self-destruct mode. It has a file check that causes removal of all persistence mechanisms and scripts on execution leaving behind no trail of the attack vectors. Researchers say that the presence of such a sophisticated mechanism for this malware is also a “mystery,” because it means that the attackers were getting ready for a stealthy persistent attack rather than a simple intrude, spread, and exfiltrate kind of attack.

Thankfully, there is still no known indication of any damages through this malware, but the fact that Red Canary’s researchers found these strains of malware on Macs in the wild is worrisome. For the complete list of IOCs of the Silver Sparrow malware, click here.

Related News:

Researcher Finds New Android Malware Spreading Via WhatsApp Messages

How HR and IT Teams Can Streamline to Reduce Risk and Data Theft

Data breach

Businesses sink a lot of time and effort into finding the right candidate for a position. One SHRM survey, for instance, found that the average cost-per-hire is more than $4,100 (a conservative number). However, all that time and money become immaterial if the employee has a poor and inefficient onboarding process.

By Jill Pappenheimer and Michael Sellai, BPM LLP

According to one online survey, 93% of employers agree that a good onboarding experience is critical to determining a new hire’s decision to stay. However, Gallup’s 2017 State of the American Workforce report found that just 12% of employees “strongly agree” that their employer does a good job at onboarding. Combine with this the fact that replacing an employee costs businesses an average of 21.4% of the lost employee’s salary and it becomes clear how urgent the need is for businesses to develop effective onboarding processes.

Delegation of Duties

One fundamental source of this problem with onboarding can be attributed to the delegation of duties within a business. While HR professionals are generally in charge of posting positions, conducting screening interviews, extending offers, etc., it has been a separate IT process to collect employee information for  — setting up enterprise software accounts, assigning employee devices, deploying applications to said employee devices, and everything else associated with getting an employee to work on company IT. And while HR professionals use often-sophisticated human resources management systems, or HRMS, to manage the hiring process, IT organizations are often starting from scratch when onboarding employees, lacking access to all the important information already collected during the hiring process that could save them significant time. This not only drags down IT organizations but also causes critical delays for new employees to get acclimated to their new organization, acquire needed equipment, and do their jobs effectively.

This less-than-ideal situation usually is not the result of HR and IT jousting for responsibilities. Ask any IT person how they feel about onboarding and they will tell you they would prefer to focus on other priorities, like performing system maintenance and keeping company data secure. Moreover, most HR and IT professionals will agree that as much as possible of the onboarding process ought to be left in HR’s capable hands.

The Automation Solution

How can HR and IT teams that have each been in charge of gathering this essential component of onboarding abdicate these key day-to-day responsibilities solely to HR professionals? The solution lies with automation. By leveraging integrations, typically through APIs, between the company’s HRMS and its identity management systems, IT can enable new employees to automatically be set up in the majority of the company’s enterprise systems, using the data collected from employees from new-hire (online) paperwork to automatically populate most of the necessary fields. Where that data is insufficient, the identity management system can be set up to automatically prompt new employees for information, allowing the HRMS to become the single source of truth.

Similarly, for the management of employee devices and other hardware, IT can use mobile device management, or MDM, the solution to automatically customize the set up of devices using data provided by employees to the HRMS. And should any relevant HR data be changed, such as the employee’s job title or department, or even if the employee leaves, that information can automatically be replicated from the HRMS and the appropriate changes can be made.

This is what we call “zero-touch onboarding,” and the best part is once it is set up, IT and HR both have very little to do with day-to-day onboarding tasks with regard to IT. The essence — and the strength — of this approach is that it makes the HRMS, rather than strictly IT management systems, the source of all data related to employee attributes, including but not limited to pay, benefits, paid time off (PTO), and job title and function. More precisely, the zero-touch approach makes the electronic employee file or record the single source of truth for IT and HR data in cases where those two systems interact. Having a single source of truth drives data integrity, which in turn drives consistency and accuracy.

Before going to IT to ask them to enable zero-touch onboarding, HR professionals will want to ensure a few conditions are met first. The first is to ensure that you are capturing the right kind of HR data. For instance, your HRMS might contain fields that are technically optional, but essential from the perspective of setting employees up with IT. Once you have identified where the gaps in the data are, you will need to not only update data that is currently missing, but also update your processes and procedures so that this information is automatically captured and updated in the future. Another useful step is to ensure your current organizational chart and your HRMS’s representation of it are consistent. Having the organizational taxonomy be accurately reflected in the HRMS makes it easier for IT to customize applications so that they automatically assign people the right kind and level of credentials, which helps them maintain a secure IT environment.

Managing Risk

A smooth onboarding process is not only about enabling the employee and immersing them in company culture and practices — although that is an important aspect, to be sure. But from a risk management perspective, onboarding is more than anything a critical vector for data loss or theft. According to a study by McAfee, the computer software security provider, internal actors are responsible for 43% of enterprise data loss — about half of which is accidental. In a business environment subject to ever-increasing cyberattacks, corporate espionage, and other nefarious threats, applying rigor to employee data and systems access is essential. And new employees in particular, who lack familiarity with systems or processes, represent a particular security risk. Again, collaborating with HR to ensure that there are well-defined groups that drive consistency with regard to application access ought to be the starting point for managing risks associated with security. Note that this will likely involve some negotiation: HR and management want to ensure people have enough authority that they can complete their jobs effectively, while IT typically wants to minimize risk arising from what they see as excessive access. Ultimately, the balance arising out of this dialogue is beneficial to the business.

Onboarding is only one source of risk associated with employee transitions, unfortunately. End of employment, or “offboarding,” whether it comes about as the result of lay-off, dismissal, or resignation, also represents an important source of risk for businesses. It is unhappy to think about, but an employee that leaves through no choice of their own can be a threat to their former employer. The direct monetary risk of a disgruntled former employee — i.e., lawsuits or shakedowns — seems to be generally well understood. But the unique IT risk of former employees is often overlooked. When an employee leaves an employer, everything from cloud ERP credentials to email and slack accounts to employee badges needs to be dealt with. Businesses, then, should have clear, established processes for how to handle the accounts and credentials of former employees. Moreover, the offboarding process should begin immediately, with any access the employee held to company systems fully revoked upon their final shift. This last requirement is predicated upon the assumption that IT and HR stay in communication with each other. Here again, an automated solution that alerts the InfoSec team upon any changes to employment status made to the HRMS is invaluable, and establishing this connection should be a priority of HR and IT teams.

An Easy Alliance

To sum up, in today’s technology-driven business environment, onboarding with company IT is with few exceptions the precondition for an employee to start demonstrating their value in their new role. Yet onboarding at many organizations remains haphazard, in large part due to disconnects between HR and IT. With today’s HRMS technologies and APIs, however, HR and IT departments can collaborate to create a single source of truth in the HRMS, and zero-touch onboarding process that not only saves both organizations time and money but is also more efficient and empowering for employees.


About the Authors

Jill Pappenheimer is a partner in the HR Consulting practice at BPM, a West Coast-based accounting and consulting firm that ranks among the 50 largest in the U.S.

 

 

Michael Sellai is a partner at BPM and leads the firm’s Managed IT Support group.

 

 

Disclaimer

The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. 

A Note of Caution on the Digital Document Revolution

Digital Fraud

A revolution is underway in the secured document field. Society is migrating from using physical secured documents, such as banknotes and identity cards, to the use of smartphones and electronic payment cards for financial transactions and as carriers of our identity credentials.

By Ian Lancaster, CEO and Consultant, Lancaster Consulting

The COVID-19 crisis has thrown this trend more sharply into focus in relation to payments. In just one week, cash usage halved in the UK and a similar story is playing out around the world as more people turn to contactless payments to minimize the spread of the virus. Whether this is a temporary measure while the virus is active or another nail in the coffin of cash, remains to be seen.

In the minds of many people, this transition from physical to digital is inevitable, unstoppable, and irrevocable, even though cash is still used for most retail purchases globally (COVID-19 influence aside).

On the other hand, certain physical documents like passports are still required to enter a territory. Nonetheless, this transition is inevitable, so there is a need to consider the impact and implications of this change.

These considerations are the driving force behind Reconnaissance International’s new White Paper, “Physical to Digital: A Revolution in Document Security,” which looks at the implications of the current digital revolution in the areas of financial transactions and ID document security. The publication contrasts more than 1,000 years of experience in printing and examining security documents with the 30 years of digital experience, and the use of smartphones in what has previously been the domain of secured printed documents.

In simple terms, is it a revolution that leaves us and our data safe? We are moving from a world in which people can examine and inspect a document to check its legitimacy (in order to be confident it can be trusted), to one in which we have to trust that a device, such as our smartphone, is doing what we think it’s doing, that the data it’s using is accurate and secure, and the decision it makes – or leads us to make – is correct and appropriate.

Are we right to invest this much trust in these new methods of making payments and showing our identity? Or should we pay heed to the view that, in failing to question the algorithms that are doing this work for us, we open the door to cybercriminals?

In examining the transition in security documents from the physical to the digital, our White Paper considers:

  • How far has it gone and what is its future?
  • What are its implications and – crucially – how safe is the data held and used in the digital world?
  • Are we merely users of these systems, or is there a role for us in ensuring that they and the data they use are secure? What might that role be?
  • Is anything needed to enhance the safety and security of these digital methods and if so, what?

The Current Landscape

The use of digital technologies has some way to go before replacing cash – most people in most countries continue to rely on cash for retail transactions. Similarly, when it comes to ID documents (like passports), digital technologies, while attractive, remain for the time being some way short of being ubiquitous. It’s clear that physical banknotes and ID credentials remain the norm – but why?

Physical documents are tangible, familiar, and with security and authentication features built-in. Moreover, a key driver for specifiers and designers – honed over these 1,000 years of experience – in security and document protection. In this physical world, professional document examiners develop a sixth sense, a feeling for the document which comes with familiarity and practice.

The result is reflected in the low counterfeiting levels for banknotes and passports; for example, 0.003% of euro banknotes in circulation and 2% of passports worldwide. This compares to, say, the World Health Organization’s estimate that 10% of medicines worldwide are fake.

As digital methods become more common, we need to question whether they match the security and detection built into the physical document world. If not, how can they be improved? Should we abandon the use of human inspection and, if not, how do we combine the best of both worlds?

These questions become more pertinent when we consider the significant number of data breaches, hacks, and outages that occur in the digital world. There are numerous examples of online identity and financial theft, often serious enough that they are reported in the mass media, not just the specialist media. In addition, there have been many cases of systems crashing, making it impossible for people dependent on their credit cards or smartphones to conduct any financial transactions.


This story first appeared in the July 2020 issue of CISO MAG. To read the full story: Subscribe now!

About the Author

Ian Lancaster has many years of experience in security and authentication. He is the CEO of Lancaster Consulting and Founder and former MD of Reconnaissance International, a specialist analyst of and consultant in holography and anticounterfeiting, he served as the general secretary to the International Hologram Manufacturers Association (IHMA) from its foundation in 1993 to 2015; the organization celebrated its twenty-fifth anniversary in 2018. He was a member of the BSI Societal Security committee and the ISO Security and Resilience Committee. Ian holds an honors degree and a postgraduate business studies diploma. Prior to founding Reconnaissance in 1990, he was founder/ director of the hologram manufacturer Third Dimension and later served as executive director of the Museum of Holography, New York.

Disclaimer

The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. 

After the Breach and Beyond

biggest data breaches in India,data breach, Aptoide Android App Admits Data Breach, Suspends Sign-Up Option Temporarily, Panasonic

There is a popular saying that goes, “A Prophet is without honor in his own country.” I can attest to the veracity of this statement as a Security Evangelist. Rodney Dangerfield stated it in another way: “I don’t get no respect!”. This sentiment is felt by many professionals within the cybersecurity profession seeking senior management buy-in and support for establishing robust information security programs within their enterprises. Consequently, leadership often dismisses the recommendations made by their CISOs for hardening their networks in order to make them more secure due to financial considerations.

.

By Zachery S. Mitcham, MSA, CCISO, CSIH, VP and Chief Information Security Officer, SURGE Professional Services-Group

The CISO serves as a trusted steward of the enterprise, charged with the responsibility to safeguard the confidentiality, integrity, and availability of all data that is processed, stored, or transmitted over the company’s technological network, whether it is in transit or at rest. Therefore, management must view the role that they play as a guardian of the network rather than just a consultant. Senior leaders have not kept pace with the need to equip the CISO with the tools necessary to be successful in properly securing their networks by allocating appropriate budgets to security programs. Those that try to keep up sometimes fall short of fully understanding the threat landscape and security issues they are facing.

Senior corporate management tends to use security industry terms interchangeably without knowing that they have subtle differences. It is important to use precise terms especially when it relates to identifying various breaches that occur within our organizations. I submit to you that no matter how secure an organization considers itself to be, a security breach occurs within their environment almost every day. If there is a virus or other malware found within one of the endpoints operating on the network, then a security breach has taken place. The rationale being, if the user did not place the variant on the system then how did it get there? On the other hand, data breaches don’t happen nearly as often. A data breach or compromise is specifically that: definitive proof or evidence that data has been exfiltrated, modified, damaged, pilfered, or the like. This article focuses on the latter.

Leadership, no matter what the industry, tends to be tone-deaf when it comes to the matter of allowing the CISO to implement the information security controls necessary to keep their data secure – until, that is, they find themselves engulfed in a catastrophic circumstance like a data breach. Afterward, they tend to be all ears and willing to provide the money and resources necessary to remedy the problem. However, this is not until after the initial panic and media attention that sends heads rolling.

All too often information security officers are viewed as “Chicken Little” screaming that the sky is falling or Peter, as in “Peter and the Wolf,” that always cried wolf when in actuality, there was no one. For this reason, as information security officers, we should never abuse our ability to influence organization leadership and decision-makers by requesting unnecessary security controls for the systems that we oversee. Conversely, the aforementioned stereotypes shouldn’t absolve senior leadership from acting on valid recommendations rendered to them by their CISO with respect to information security requirements necessary to secure their data.

The NIST 800-61 special publication (SP), Computer Security Incident Handling Guide outlines a detailed, pragmatic approach to actions organizations should conduct before, during, and after security incidents. It is incumbent upon every organization to develop their own Computer Security Incident Response Plan tailor-fitted for their needs after the data breach. Additionally, beyond the data breach, the organization must focus its attention on developing a culture of security that is pervasive throughout the enterprise concentrating its efforts on the following areas:

1. Institutional Reputation Repair and Restoration – Consumer confidence in an enterprise’s ability to safeguard its data is of paramount importance. Retention of the customer base is imperative and necessary for the continued existence of any company. The repair and restoration of a company’s reputation can be a very costly endeavor depending on the size and type of organization it is. It may be necessary for an organization to retain the services of a public relations firm to assist with this effort.

2. IT Enterprise Risk Management Program – This element of the institution’s strategic plan allows the enterprise to effectively manage IT risks utilizing a standard framework like ISO 27005 and NIST 800-30. The risk analysis process must be integrated into every facet of the organization’s operations in order to reduce the possibility of unexpected losses as a result of administrative oversight.

3. Information Security Awareness and Training – There are six basic components that make up an information system. You have people, data, hardware, software, policies, and network communications. The majority of security threats that exist on the network are a direct result of insider threats caused by humans, no matter if they are unintentional or deliberate. The most effective way an organization can mitigate the damage caused by insider threats is to develop effective security awareness and training program that is ongoing and mandatory.

4. Governance and Information Security Strategic Planning – A serious information security program is instituted from a top-down perspective. It must have the support and buy-in of every subordinate unit within the organization. The governance of the program must include representation of senior leadership from all the mission-essential areas of the company in order to embed the mission of data security throughout the strategic planning process.

It is always a good idea to have a fresh set of eyes on security consulting engagements and assessments, however not at the expense of disregarding the input provided to you by the individual that you hired to safeguard that network. Listen and support your own internal enterprise information security subject matter expert. They are your information security evangelist, before the breach.


This story first appeared in the June 2020 issue of CISO MAG.  Subscribe now!

About the Author

Zachery S. MitchamZachery S. Mitcham, MSA, CCISO, CSIH is the VP and Chief Information Security Officer at SURGE Professional Services-Group. He is a 20-year veteran of the United States Army where he retired as a Major. He earned his BBA in Business Administration from Mercer UniversityEugene W. Stetson School of Business and Economics. He also earned an MSA in Administration from Central Michigan University. Zachery graduated from the United States Army School of Information Technology where he earned a diploma with a concentration in systems automation. He completed a graduate studies professional development program earning a Strategic Management Graduate Certificate at Harvard University extension school. Mr. Mitcham holds several computer security certificates from various institutions of higher education to include Stanford, Villanova, Carnegie-Mellon Universities, and the University of Central Florida. He is certified as a Chief Information Security Officer by the EC-Council and a Certified Computer Security Incident Handler from the Software Engineering Institute at Carnegie Mellon University. Zachery received his Information Systems Security Management credentials as an Information Systems Security Officer from the Department of Defense Intelligence Information Systems Accreditations Course in Kaiserslautern, Germany.

Disclaimer

CISO MAG does not endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. Views expressed in this article are personal.

Attackers Reinvent Masslogger Trojan to Target Popular Brands

Malware and Vulnerability Trends Report, Mobile malware threats

A new version of the Masslogger Trojan has been targeting Windows users in a new phishing campaign. Cybersecurity experts from Cisco Talos stated that they’ve found an improved version of the Masslogger Trojan, designed to pilfer login credentials from popular applications like Microsoft Outlook, Google Chrome, and other messenger accounts. The new Masslogger phishing campaign, which was uncovered in mid-January 2021, targeted users across Italy, Latvia, and Turkey.

What is Masslogger?

Masslogger is a spyware written in .NET to steal user credentials from browsers, popular messaging applications, and email clients.

Improved Masslogger Trojan

First identified in April 2020, the malware authors are selling the updated versions of the Trojan to other malicious actors on underground dark web forums.

Researchers found that Masslogger operators can evade detection by disguising their malicious RAR files as Compiled HTML files. The discovery of the new variant of the Trojan indicates how malware developers are constantly updating their hacking methods.

“Although operations of the Masslogger Trojan have been previously documented, we found the new campaign notable for using the compiled HTML file format to start the infection chain. This file format is typically used for Windows Help files, but it can also contain active script components, in this case JavaScript, which launches the malware’s processes,” researchers said.

How Masslogger Trojan Attacks

The infection starts with an email with a malicious RAR attachment and a legitimate-looking subject line claiming to be from a business. The filename creates files with the RAR extensions named .rar, .r00, and .chm to bypass any programs that would block the email attachment based on its file extension. The payloads are hosted on compromised legitimate hosts with a filename containing one letter and one number concatenated with the filename extension .jpg.

The Masslogger Trojan payload is designed to retrieve and exfiltrate user credentials from a variety of sources. According to Cisco Talos, the new version of Masslogger has the capabilities to target and retrieve credentials from the various other applications like:

  • Pidgin messenger client
  • FileZilla FTP client
  • Discord
  • NordVPN
  • Outlook
  • FoxMail
  • Thunderbird
  • Firefox
  • QQ Browser
  • Chromium-based browsers (Chrome, Chromium, Edge, Opera, Brave)

“While most of the public attention seems to be focused on ransomware attacks, big game hunting, and APTs, it is important to keep in mind that crimeware actors are still active and can inflict significant damage to organizations by stealing users’ credentials. The credentials themselves have value on the dark web and actors sell them for money or use them in other attacks. Based on the IOCs we retrieved, we have moderate confidence that this actor has previously used other payloads such as AgentTesla, Formbook , and AsyncRAT in campaigns starting as early as April 2020,” researchers added.

Telephony Denial-of-Service Attacks on Rise, FBI Suggest Recommendations

Cybersecurity is standard business practice for most large companies: Survey

The FBI has warned about potential security risks with Telephony Denial-of-Service (TDoS) attacks. In an official Private Industry Notification (PIN), the agency revealed how TDoS attacks affect the availability of emergency service call centers like police, ambulance, or firefighting services.

“TDoS attacks pose a genuine threat to public safety, especially if used in conjunction with a physical attack, by preventing callers from being able to request service. The public can protect themselves if 911 is unavailable by identifying in advance non-emergency phone numbers and alternate ways to request emergency services in their area,” the FBI said.

What is TDoS Attack

In TDoS attacks, attackers make an emergency telephone system unavailable to the users by blocking incoming and outgoing calls. The primary motive of bad actors in these attacks is to delay or block users’ calls to Public Safety Answering Points (PSAPs).  PSAPs represent key infrastructure that enables emergency responders to identify and respond to critical events affecting the public.

How Cybercriminals Launch TDoS Attacks

Threat actors are evolved to launch TDoS attacks both manually and automatically. In manual TDoS attacks, attackers use social networks to trick individuals into flooding a particular number with unwanted calls. While an automated TDoS attack leverages software-applications to make hundreds of calls in rapid succession, including Voice over Internet Protocol (VoIP) and Session Initiation Protocol (SIP).

Using Emergency Services in TDoS Attack

The FBI stated that malicious actors launch TDoS attacks in hacktivism, to harass call centers and distract operators, exploit computer networks for political and financial gains. The agency recommended certain steps to overcome an emergency in the event of a TDoS attack. These include:

  • Before there is an emergency, contact your local emergency services authorities for information on how to request service in the event of a 911 outage. Find out if text-to-911 is available in your area.
  • Have non-emergency contact numbers for fire, rescue, and law enforcement readily available in the event of a 911 outage.
  • Sign up for automated notifications from your locality if available to be informed of emergencies in your area via text, phone call, or email.
  • Identify websites and follow social media for emergency responders in your area for awareness of emergencies.

Singtel Data Breach: 129,000 Customers including Former Employees Affected

Singtel data breach

The Accellion hack might have gotten overshadowed by the amount of disruption caused by the SolarWinds hack, but it surely is not lagging by any means when it comes to the outreach of the attack. Critical organizations in the U.S., Australia, and New Zealand have already reported of being indirectly affected by the Accellion hack and now joining this list is Singapore telco giant – Singtel. The company on February 11, issued a statement where it informed all its customers of a security incident through a third-party product, FTA, from Accellion. At the time, the investigation was ongoing, and the extent of the attack was unknown. But now in the latest statement, the telco giant has confirmed that 129,000 of its customers’ data has indeed been breached.

Timeline of the Singtel Data Breach

Accellion which first found out about the zero-day vulnerability in mid-December (tentatively December 13, 2020) initiated a patch almost immediately and started rolling it out to all its customers using the legacy FTA file transfer system. However, Singtel was first contacted for a patch only on December 23, 2020.

Related News:

Ripples of the Accellion Hack Reach Australia; QIMR Berghofer Confirms ‘Likely’ Data Breach

Following the trail, we have formulated the entire timeline as follows:

  • December 23, 2020: Accellion first informed Singtel of the vulnerability.
  • December 24, 2020: Singtel was provided the first patch which its engineers applied instantaneously.
  • December 27, 2020: Singtel applied the second patch.
  • January 23, 2021: Accellion issued another advisory citing that the discovery of a new vulnerability against which the December 27 patch was ineffective. Singtel took down the FTA system instantly.
  • January 30, 2021: Accellion provided another patch to fix the second vulnerability, but an anomaly alert got triggered while Singtel engineers tried to apply it. On checking this alert and running an internal investigation, Accellion informed Singtel that there could have been a possible data breach to their system on January 20.
  • February 9, 2021: The joint investigation found that a certain amount of data was indeed exfiltrated from Singtel’s system.

Who was Affected?

As Singtel is the largest telecom company in Singapore, not just Singaporeans but many foreign nationals who frequent Singapore on a work-basis were skeptical whether they were impacted by this data breach. Based on the investigations and analysis until now, Singtel issued a statement saying that the following data was exfiltrated:

  • Personally Identifiable Information (PII) of approximately 129,000 customers containing National Registration Identity Card (NRIC) and certain combinations of the following information: name, date of birth, mobile number, address.
  • Bank account details of 28 former Singtel employees.
  • Credit card details of 45 corporate customer staff who have Singtel mobile lines.
  • Certain Discrete information of 23 enterprises which includes suppliers, partners, and corporate customers.

Singtel is still carrying out a detailed forensic and criminal investigation with the help of cybersecurity experts, the Cyber Security Agency of Singapore (CSA), and the Police. As due diligence, Singtel will be personally informing all affected customers and providing them a free identity monitoring service that will help them counter suspicious activities on the open internet and darknet, using their leaked identities. Additionally, Singtel has already suspended operations of the legacy FTA system whose end of life was announced by Accellion effective from April 30, 2021.

Singtel Fined for Data Breach Previously

Incidentally, while the investigation was going on, the Personal Data Protection Commission (PDPC) of Singapore found Singtel accountable for violating the Personal Data Protection Act for a data breach involving its “My Singtel” mobile app in 2018. The commission has imposed a S$9,000 (US$6479) fine on them. Read the complete story here.

Related News:

Bug in Accellion’s Software Exposes Data of 1.4 Mn Washington State Residents

California DMV Halts Operations After Vendor Suffers Ransomware Attack

California DMV data breach

A ransomware attack on a third-party vendor for the California Department of Motor Vehicles (DMV) may have affected users’ sensitive information. DMV stated that Automatic Funds Transfer Services (AFTS), which verifies vehicle registration addresses for local DMV customers, was hit by a cyberattack earlier this month, which may have affected California vehicle registration records of the last 20 months.

The exposed records contain names, addresses, license plate numbers, and vehicle identification numbers (VIN). However, DMV clarified that AFTS does not have access to the customers’ social security numbers, birthdates, voter registration, immigration status, and driver’s license information.

The DMV temporarily halted all data transfers to AFTS and notified the FBI and law enforcement authorities for further investigation on the incident. While there is no evidence whether any cybercriminal group misused the exposed data after the cyberattack, the DMV urged customers to report any suspicious incident.

“Data privacy is a top priority for the DMV. We are investigating this recent data breach of a DMV vendor to quickly provide clarity on how it may impact Californians. We are looking at additional measures to implement to bolster security to protect information held by the DMV and companies that we contract with,” said DMV Director Steve Gordon said.

Not the First Time!

Earlier, information of thousands of drivers was exposed in a data breach after the DMV was hit by a cyberattack that had gone unnoticed for four years. It was found that the social security information of 3,200 driver’s license holders was improperly accessed by federal agencies, including the Department of Homeland Security, Internal Revenue Service, Small Business Administration, and district attorneys in San Diego and Santa Clara counties.

“Having a universal standard for privacy may not be practically possible”

Anshuman Sharma is a seasoned professional with over 15 years of experience in the field of cybersecurity, leading the Hong Kong & India market for the Investigative Response (VTRAC) practice. He brings unique and vast experience in leading digital forensics and incident response, threat hunting, threat & vulnerability, advisory & security assurance, and PCI DSS compliance. Currently, he is the Principal Consultant, APAC, VTRAC (Verizon Threat Research Advisory Center).

In an exclusive interaction with Augustin Kurian, Senior Feature Writer at CISO MAG, Sharma talks about his journey, the impact of COVID-19 on cybersecurity, the adoption of AI and ML, and the global compliance norms.

Edited excerpts of the interview follow:

AK: You have over 15 years of experience across a wide spectrum of areas spanning information security, cybersecurity, cyber forensics, cyber warfare, risk management, expertise in the SOC and CERT, cloud computing, Big Data, Internet of Things (IoT), MEC, ML, and AI. How has your journey been so far? How has the cybersecurity space evolved in the last 20 years, and how did COVID-19 change the cybersecurity dynamics?

Sharma: My journey in the past 15 years has been fascinating. I need to be on my toes, keeping myself abreast with the latest know-how within the security domain. The security landscape has undergone exponential growth in the past 20 years. For example, two decades ago, organizations were taken by storm with the advent of firewalls. Then came the era of Intrusion Detection and Intrusion Prevention Systems (IDS/IPS).

Moving to the more recent past, with the advent of the Internet of Things (IoT), Artificial intelligence, and Machine Learning (AI & ML), cybersecurity has taken another quantum jump. The threat landscape changed with the advent of the cloud, and the complexity of the threats increased parallelly.

Digital transformation has played a key role in how cybersecurity has changed over the years. We moved from packet-filtering firewalls to next-gen firewalls, which provided other functionalities such as gateway AV controls, web content filtering, and email content filtering.

In the current context, AI and ML is being used for the next generation preventive and detective solutions such as Endpoint Detection and Response (EDR) at the endpoints; Network Detection and Response (NDR) at the network level, and User Entity Behavior Analytics (UEBA) — all utilizing the power of AI and ML to identify anomalies by first understanding what is normal. The contribution that threat intelligence brings to the table cannot be ignored. Threat intelligence (from Clearnet and Darknet) is providing the necessary ingredients for a threat hunting program in an organization, and it matures with the help of EDR and NDR technologies. Couple that with other recently matured and evolving technologies such as Security Incident and Event Management (SIEM), Deception Technologies, and Security Orchestration, Automation and Response (SOAR). This provides the necessary tools to a cybersecurity professional to thwart most of the cyberattacks and/or helps them in detecting many within a timely fashion. Also, matured organizations have great response plans in place as they know, “it is no more a question of if, but when.” The COVID-19 pandemic has changed, possibly forever, the way we work. It has caused many organizations to adapt and/or hasten their roadmap towards digital transformation and has resulted in many organizations such as banks, which traditionally have never moved aggressively towards the cloud or even toward providing remote access to the work environment.

When there is change, there exists a potential for confusion, omissions, and mistakes. Cybercriminals are aware of this and will do their best to capitalize on any opportunities that are afforded by them. I do not mean to imply that the cloud and remote technologies mentioned above are inherently less secure. Rather, the concern arises from the fact that due to the conditions the pandemic has created, most organizations are hurriedly adopting them, and they are often forced to do so while relying on fewer resources in terms of both personnel and revenue. When one adds to that dangerous concoction of digital transformation, the additional ingredient of large-scale remote work enablement, it can easily spell disaster. The likely factors contributing to the incident and breaches in the COVID-19 situation include:

  • Increase in error – These error types are typically due to carelessness and/or hurry on the part of a system administrator or regular end-user, which includes misconfiguration, misdelivery, and publishing errors.
  • Stolen credential-related hacking – Our recent research shows that over 80% of breaches within the hacking category are caused by stolen or brute-forced credentials. The majority of the time, these occur via web apps and/or the cloud. Since businesses are forced to lean on Software-as-a-Service (SaaS) platforms more heavily now, we expect this increased reliance to substantially widen the attack surface for bad actors looking for stolen and brute-forced credentials.
  • Asset management and patching – Most of us will agree that making sure that, all corporate-owned assets are promptly and consistently patched, may be more difficult in the current environment than it has been in the past. However, given the current circumstances in which a large number of employees are being encouraged (or mandated) to work from home, maintaining those newly external workstations for remote access suddenly becomes a much bigger deal.
  • Ransomware likely to rise – Several incidents where the ransomware group was also confirmed to have taken a copy of the data before triggering encryption and posting the data (either partially or entirely) publicly on their website of choice.
  • Impact on the phishing landscape – The surge in remote working due to the pandemic may increase the reliance on mobile phones and tablets. Research from last year’s DBIR report indicates that many users are more likely to click on a malicious link when using a mobile device than a desktop or laptop.
  • The Mind Games – Clearly, COVID-19-related terms are showing up in threat indicators. However, how susceptible people are to them is still an open question. To try to provide an answer, Verizon examined some simulated phishing data provided by a report contributor. Verizon compared emails that contained COVID-19-related terms (such as COVID, Corona, pandemic, Wuhan, SARS, etc.) to those emails that did not contain such references. Based on the data, phishing emails that were related to COVID-19 had a somewhat higher success rate and showed more organizations having far higher click rates, even above 50% in some cases.

AK: CEO frauds are a concern these days. Do you believe the new work from home format has heightened cybersecurity risks on CEOs and those with privileged access?

Sharma: In one of the recent reports, it was mentioned that senior executives are 12x more likely to be the target of social incidents, and 9x more likely to be the target of social breaches than in previous years. One of the factors behind targeting the senior executives is that they have access to the most critical information, and often, they have unrestricted access to such information.

With the new work from home scenario, we expect to see a rise in phishing emails. With the number of executives making use of personal devices for work-related tasks increasing, the risk for compromise becomes greater. So, we may see the number of business email compromise attacks increasing.

AK: When it comes to data security, many times, industries do not know what their critical data is. So, how do you think they can combat it?

Sharma: One of the most important aspects of securing data is being able to answer what sensitive data an organization has (PII, PHI, Payment Data, etc.), where it is stored, processed, and transmitted, who has the access, and what privileges they have, and what it will cost the organization if such data gets leaked. It means that a data classification exercise needs to be carried out.

Organizations are creating massive amounts of data that is both structured and unstructured. The key is to have a sound understanding of business processes and having business process flows to identify the data life cycle — creation, storage, usage, sharing, archiving, and destruction. Having a data classification policy is another important aspect as it identifies any legal and regulatory requirement and setting up of various classification levels. Using an Identity and Access Management Solution (IAM) and Privilege Identity Management (PIM) solution with assigned roles and responsibilities can help in better managing users’ access to data.


Augustin Kurian

About the Interviewer

Augustin Kurian is the Senior Feature Writer and part of the editorial team at CISO MAG and writes interviews and features.

 

This interview first appeared in the December 2020 issue of CISO MAG. Get all your copies now! Subscribe

This New Security Feature in iOS 14.5 will Enhance User Privacy

Apple Notarization, operational technology

Apple has yet again announced a cool new security feature for iPhone users. And it’s said to be the much-awaited one! The upcoming iOS 14.5 security update will have a new feature that will re-route all Safari’s Safe Browsing traffic via Apple-monitored proxy servers to prevent Google from discovering the IP addresses of iOS users. However, the new feature will only work when users activate the “Fraudulent Website Warning” option on the device.

What is Fraudulent Website Warning?

Some websites use third-party content providers to track users across websites to advertise their products and services. The Fraudulent Website Warning option removes and blocks the data that websites use to track users in Safari. When Fraudulent Website Warning is enabled, Safari will display a warning alert if the website you are visiting is a malicious or phishing site. Safari also sends the suspicious website details to Google Safe Browsing to check the website’s legitimacy.

How to Activate Fraudulent Website Warning

You can enable Fraudulent Website Warnings in Safari by going to Settings >> Safari >> sliding the Fraudulent Website Warning switch to On.

Browsing with Google v/s Apple

Google identifies malicious websites by scanning portions of Google’s web index and adds them to its online database if they prove to be suspicious. Apple sends a hashed prefix of the suspected website’s URL to Google Safe Browsing to check if it has been listed in its database. With the latest iOS 14.5 update, Apple users will experience enhanced web security while browsing on Safari.

Recently, Samuel Grob, a security researcher at Google Project Zero, uncovered a new security feature that Apple added in its iOS 14 version without any revelation. Dubbed “BlastDoor,” the improved sandbox system feature was introduced due to the zero-click exploits that leveraged the Apple iMessage flaw in iOS 13.5.1. Reportedly, the iPhones of 36 Al Jazeera journalists were infected with malware, leaving their devices open to cyber espionage.