Home Blog Page 124

Facebook Indicts Two Developers for Scraping Users’ Data

Facebook Indicts Two Developers for Scraping Users’ Data, Europol

Facebook Inc. and Facebook Ireland imposed legal action against two people in Portugal for violating Portugal’s Database Protection Law. The social media giant stated the culprits were scraping users’ personal information from their Facebook pages.

Malicious Extensions

Under the company name “Oinkn and Stuff,” the offenders specially designed browser extensions and made them available on the Chrome store.  The malicious Chrome extensions, Web for Instagram plus DM, Blue Messenger, Emoji keyboard, and Green Messenger, contained hidden code that functions like spyware. The extensions were coded to scrape username, user ID, gender, relationship status, age group, and other personal data related to their social media accounts. The developers tricked users into installing the extensions with a privacy policy, claiming they did not collect users’ personal data.

“When people installed these extensions on their browsers, they were installing concealed code designed to scrape their information from the Facebook website, but also information from the users’ browsers unrelated to Facebook — all without their knowledge. The defendants did not compromise Facebook’s security systems. Instead, they used the extensions on the users’ devices to collect information,” Facebook said.

“We are seeking a permanent injunction against defendants and demanding that they delete all Facebook data in their possession. This case is the result of our ongoing international efforts to detect and enforce against those who scrape Facebook users’ data, including those who use browser extensions to compromise people’s browsers,” Facebook added.

What is Data Scraping?

Data scraping is a process of extracting users’ personal data from websites. It is a common practice for third-party vendors, web developers, business intelligence analysts, and authentic businesses to scrape users’ data for market research purposes. Social media companies like Facebook allow users to access third-party websites by using their existing Facebook login information. However, this process can also allow unauthorized users/threat actors to perform malicious activities, including identity theft and financial fraud.

Biden Takes Up Cybersecurity on His First Day in Office

Joe Biden, Biden, POTUS, new POTUS, U.S. President, SolarWinds, Solar Winds hack, SolarWinds cyberattack, cybersecurity, cybersecurity budget, cybersecurity head, national cybersecurity head, Joe Biden cybersecurity budget

Joe Biden had already upped his cybersecurity game during the race to the White House. The Democratic President had on-boarded former White House cybersecurity official Chris DeRusha as the CISO and Jacky Chang as the Chief Technology Officer for his election campaign. Yet his campaign website “Vote Joe” was defaced by Turkish threat actors. It did not stop here.  His election app was also vulnerable to a cyberattack whose proof-of-concept was provided by white hat hackers from Promon. These incidents, along with the devastation and compromise caused by the SolarWinds cyberattack, have probably pushed the newly appointed POTUS to rethink the national cybersecurity posture immediately.

On his first day in office, Biden has already made his intentions clear that he is serious about cybersecurity. He has introduced and sanctioned a host of cybersecurity plans starting with three new appointments to key national cybersecurity positions.

Biden’s C–Suite

Joe Biden, Biden, POTUS, new POTUS, U.S. President, SolarWinds, Solar Winds hack, SolarWinds cyberattack, cybersecurity, cybersecurity budget, cybersecurity head, national cybersecurity head, Joe Biden cybersecurity budget
From left to Right: Rob Joyce, Anne Neuberger and Michael Sulmeyer

We had earlier reported that Biden had plans of appointing Anne Neuberger to the newly formed National Security Council (NSC). If reports are to be confirmed, the NSA Cybersecurity Director will now prefix a “Former” title to her current designation and move to her new position – Deputy National Security Adviser for Cyber and Emerging Technology. Neuberger has successfully led the NSA Cybersecurity Directorate since its inception in 2019 and played a pivotal role in countering 2020 U.S. election interferences from foreign adversaries.

This appointment meant that the top spot of NSA Cyber command was up for grabs. But, filling up Neuberger’s shoes is a huge task itself. Biden, however, seems to have found a perfect fit in Rob Joyce.

Joyce previously served as NSA’s senior representative to the U.K. at the U.S. embassy in London. He has a proven track record of more than 30 years in federal services and served in critical positions, including special assistant to the president and cybersecurity coordinator at the White House, deputy homeland security adviser and acting homeland security adviser.

Michael Sulmeyer is another name that has come up in Biden’s White House. Sulmeyer has been appointed as the Senior Director for Cyber. He comes with the experience of having served as a senior adviser to National Security Agency director and U.S. Cyber Command commander Gen. Paul Nakasone. The White House, however, is yet to decide what duties Sulmeyer will disperse in his new role.

Apart from these three, the U.S. Senate approved Avril Haines as the Director of National Intelligence.

What makes this appointment more noteworthy is that Haines is the seventh director of National Intelligence but the FIRST woman to lead the country’s intelligence community. Women in cybersecurity are breaking ground and, more importantly, the stereotypes.

Biden Reviews SolarWinds Hack

Biden has swiftly moved into the office and took charge. The POTUS has already signed 17 executive orders on his first working day and seems enthusiastic about getting a hold of things at the earliest. His enthusiasm is not just limited to undoing the policies of the previous chair in the White House but also in knowing the impacts of the previous regime and taking immediate remedial measures. It is with this view that Biden has ordered the U.S. intelligence agencies to provide him with an assessment of a suspected Russian espionage operation, popularly known as the SolarWinds cyberattack, which breached multiple U.S. federal agencies and exposed glaring weaknesses in U.S. cyber defenses.

The early days of Biden’s administration will be under the lens of his critics and his supporters, and the tact with which he responds to such a sophisticated spying operation against the nation may just as well define the way forward for his regime. What information would be given to Biden in the intelligence brief is still not clear, but by the looks of it, he sure seems keen enough on learning and seeking answers to the 4W’s and H of the hacking incident.

Biden Proposes $10 Billion Cybersecurity Spending

Biden’s role in making cybersecurity appointments and plans look realistically promising. However, to materialize such large level blueprints, one needs monetary investments. Giving this a deep thought, Biden, in his $1.9 trillion COVID-19 stimulus, also included a $9 billion spending proposal to help the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the General Services Administration (GSA) upgrade their cybersecurity and IT projects.

Additionally, Biden also proposed spending another $1 billion over cybersecurity and IT initiatives, including the hiring of security experts in the Office of the U.S. Chief Information Security Officer as well as the Digital Service unit in the White House; additional IT projects within the GSA; and for CISA’s multiple in-house projects aimed at improving its monitoring and incident response capabilities across all federal agencies.

Security experts are lauding Biden’s efforts and backing him in the fight against evolving cyberthreats. However, there are a few more laws and acts that need urgent attention and upgrade, including the Federal Information Security Act and the 1990 Chief Financial Officers Act, so that smaller federal agencies also benefit from the investments and resources that the new government is bringing to the table.

We hope Biden and his C–Suite are listening to this.


CISO MAG Writer - Mihir Bagwe
 About the Author 
Mihir Bagwe is a Tech Writer and part of the editorial team at CISO MAG. He writes news features, technical blogs, and conducts interviews on latest cybersecurity tech and trends.

 

EU Regulators Imposed over €272.5 Mn in GDPR Fines to Date

GDPR fines in 2020

Ever since the GDPR guidelines were launched (May 25, 2018), the data regulators in European Union (EU) have imposed sizable penalties on various organizations that misused customer information or failed to maintain the required cybersecurity standards. The EU has issued over €272.5 million (approximately $332.4 million) in fines since the GDPR was initiated, according to research from international law firm DLA Piper. Along with the surge in fines, the number of data breach notifications have also increased by 19% compared to last year.

In total, there have been more than 281,000 data breach notifications since the initiation of GDPR, with Germany (77,747), the Netherlands (66,527), and the U.K. (30,536) topping the list. Italy tops the list in aggregate fines with more than €69.3 million (about $84.5 million) in fines imposed since the initiation of GDPR. Germany and France stood second and third with aggregate fines of €69.1 million and €54.4 million, respectively.

Key Findings

  • Around €158.5 ($192,80) of fines have been imposed since January 28, 2020, a 39% increase on the previous 20-month period since the application of GDPR.
  • Double-digit growth for breach notifications for the second year running with 121,165 breaches notified since January 28, 2020, compared to 101,403 breaches notified in the previous year, a 19% increase.
  • Denmark tops the rankings for data breach notifications.
  • Italy has imposed the highest aggregate fines and France has imposed the highest individual fine to date.
  • Regulators have not had everything their own way this year with several multi-million-euro fines being successfully appealed or significantly reduced.
  • The highest GDPR fine to date remains the €50 million (about $61 million) imposed by the French data protection regulator on Google, for alleged infringements of GDPR’s transparency principle and lack of valid consent.

The research findings are based on the latest GDPR fines and data breach reports from the EU, the U.K., Norway, Iceland, and Liechtenstein.

Ross McKean, Chair of DLA Piper’s U.K. Data Protection and Security Group, said, “Fines and breach notifications continue their double-digit annual growth and European regulators have shown their willingness to use their enforcement powers. They have also adopted some extremely strict interpretations of GDPR setting the scene for heated legal battles in the years ahead. However, we have also seen regulators show a degree of leniency this year in response to the ongoing pandemic with several high-profile fines being reduced due to financial hardship.”

Related Story: Four Biggest GDPR Fines of 2020

ShinyHunters Leak 1.9 Mn Pixlr Users’ Records Online

Patchwork BADNEWS, APT31 threat group

Pixlr, a free online photo-editing platform, is the latest victim of a data breach after the notorious threat actor group “ShinyHunters” leaked over 1.9 million users’ records online, as reported by SiliconAngle. The exposed information included usernames, hashed passwords, email addresses, country of origin, and other personal data. It’s suspected that the hacking group illicitly obtained access to Pixlr user records by exploiting an unsecured AWS S3 bucket.

The Impact

ShinyHunters distributed the stolen information on various hacking forums for free, allowing other cybercriminals to access the data. The leaked data can be misused to launch a variety of cyberattacks against Pixlr users. Attackers can also compromise users’ accounts by committing spear-phishing or credential-stuffing attacks on users whose data was exposed in the incident.

Link to 123RF.com Data Breach

ShinyHunters operators claimed that they stole Pixlr’s database while they were breaking into 123RF.com user records. 123RF.com is a royalty-free image website. Both Pixlr and 123RF.com are owned by Inmagine company. According to a report, malicious actors leaked 123RF.com users’ data (3GB in size) on a Russian hacker forum.  The company stated that the exposed database holds over 8,500,246 user records including users’ full names, email addresses, IP addresses, Facebook IDs, locations, and passwords that have been hashed using the MD5 hashing algorithm.

ShinyHunters Continue to Strike

Recently, the operators of ShinyHunters traded databases of three India-based enterprises – ClickIndia, ChqBook, and WedMeGood – on Darknet forums. The data dump contained over 8 million records of ClickIndia (name, email, mobile and other personal details), 1 million records of ChqBook (name, email, mobile, full address, and other personal details), and 1.3 million from WedMeGood (name, email, hashed password, other sensitive personal information).

Google Chrome 88 To Fix Weak Passwords for Better Online Security

reusing passwords

Google Chrome has introduced a new password security feature to prevent users from using weak and compromised passwords online. The new feature will be rolled out with the upcoming Chrome version 88. The feature automatically detects and reports weak or easy-to-guess passwords by performing a quick safety check scan. A similar feature was introduced to Chrome Canary in December 2020.

Improved Password Protection

Google Chrome can now create, store, and fill in saved passwords and warn users if their passwords were compromised in any past data breaches. With Chrome 88, users can perform a simple check to identify passwords that are not strong enough and can take quick action by changing them.

How to find weak passwords using Chrome’s password safety check?

How to edit weak and compromised passwords in Chrome settings?

Image Courtesy: Google

Vulnerable Login Credentials!

Earlier, a study from Google revealed that 1.5% of all logins used across the Internet are vulnerable to credential stuffing attacks. Based on the data collected from February 5 to March 4, 2019, Google found that 1.5% of the 21,177,237 monitored logins were identified in data breaches.

“Nearly 670,000 users from around the world installed our extension over a period of February 5–March 4, 2019. During this measurement window, we detected that 1.5% of over 21 million logins were vulnerable due to relying on a breached credential — or one warning for every two users. By alerting users to this breach status, 26% of our warnings resulted in users migrating to a new password. Of these new passwords, 94% were at least as strong as the original,” the study revealed.

Malwarebytes Reports Being Hacked by SolarWinds Attackers

SolarWinds Microsoft

When we first reported about the SolarWinds attack in December 2020, we said it was just the tip of the iceberg, and now a month later, organizations around the globe can see what lies beneath. Malwarebytes, a U.S. – based cybersecurity firm, has reportedly been intruded on by the same nation-state actor behind the SolarWinds cyberattack.

In an official release, Marcin Kleczynski, CEO of Malwarebytes, stated that although the same threat actors were involved in this breach, it was not related to the SolarWinds supply chain attack. Instead, Kleczynski said that the intruders abused privileged access to Microsoft Office 365 and Azure environments to breach their network.

Related News:

SolarWinds Hack Affected Yet Another Tech Giant – Microsoft

What was Hacked in the Incident?

The Malwarebytes security team received security notifications from the Microsoft Security Response Center (MSRC) on December 15, 2020, about suspicious activity on one of its dormant Microsoft Office 365 apps. After comparing the vectors, the security team found them consistent with the tactics, techniques, and procedures (TTPs) of the threat actor involved in the SolarWinds attacks. Thus, from that day on, Malwarebytes’ researchers carried out extensive research and found the following:

  • Attackers breached Malwarebytes’ internal systems by exploiting a dormant email protection product within its Office 365 tenant.
  • The attackers only gained access to a limited subset of internal company emails.
  • No evidence of unauthorized access or compromise in any of the internal, on-premises, and production environments of their products has been found.

Our Products are Safe!

The SolarWinds cyberattack is known to have infested networks with additional payloads like the SUNBURST and Raindrop malware that can go undetected for months, if not days. Thus, Kleczynski assured that a thorough internal audit was carried out to investigate the matter at hand. The entire source code of all its products has been scanned, and he reassured stating, “Our software remains safe to use.”

Kleczynski also took the opportunity to thank FireEye, Crowdstrike, and Microsoft, who shared their resources and all the information on the SolarWinds cyberattack with them for quicker mitigation. He has reiterated the same sentiments that many cybersecurity experts have been saying for a long time – unite, associate, and fight the adversaries as one.

Related News:

FireEye Releases ‘Azure AD Investigator’ to Know SolarWinds Hacking Techniques

Google’s Project Zero Team Details Patched Bugs in Duo, Signal, JioChat, FB Messenger

Vulnerabilities in Zimbra

Natalie Silvanovich, a security researcher at Google Project Zero, disclosed critical vulnerabilities in multiple messaging and video conferencing mobile apps that allowed malicious actors to snoop into users’ conversations without their permission. The affected applications include Signal, JioChat, Mocha, Google Duo, and Facebook Messenger.

Silvanovich claimed the vulnerability in these platforms is similar to the critical flaw dubbed “Logic bug,” which was discovered in Apple’s FaceTime group chat feature in January 2019. The Logic flaw allowed threat actors to initiate a FaceTime video call and eavesdrop on victims by adding their phone number as a third person in a group chat before the other person accepted the call. Apple removed the FaceTime group chat feature and fixed the issue in a subsequent iOS update.

Silvanovich Tweets…

“The ability to force a target device to transmit audio to an attacker device without gaining code execution was an unusual and possibly unprecedented impact of a vulnerability. Moreover, the vulnerability was a logic bug in the FaceTime calling state machine that could be exercised using only the user interface of the device. While this bug was soon fixed, the fact that such a serious and easy to reach vulnerability had occurred due to a logic bug in a calling state machine — an attack scenario I had never seen considered on any platform — made me wonder whether other state machines had similar vulnerabilities as well,” Silvanovich explained.

Logic Bugs in Multiple Apps

Silvanovich stated that she found Logic vulnerabilities in Signal, Google Duo, Facebook Messenger, JioChat, and Mocha messaging apps, which are now patched. Most of these vulnerabilities allowed calls to be connected without interaction from the person on the other end. The other effects of these flaws include:

Google Duo

The vulnerability, which was fixed in December 2020, would disable the video and set up a connection to trigger the callee to leak video packets from unanswered calls. It is because Google Duo’s signaling methodology supports a feature that allows the callee to preview the caller’s video before answering, which is different from other video chat applications.

Signal

The audio call flaw, which was fixed in September 2019, in Signal’s Android app allowed the caller to hear the callee’s surroundings as the application didn’t check that the device receiving the connect message was the caller device. This caused the audio call to connect, allowing the caller to hear the callee’s surroundings.

Facebook Messenger

The vulnerability in Facebook Messenger, which was fixed in November 2020, allowed an attacker to initiate a call and send a specially crafted message to a victim who was signed in to both the app and the web browser.

JioChat and Mocha

Silvanovich found two similar vulnerabilities in JioChat (fixed in July 2020) and Mocha (fixed in August 2020). The vulnerabilities allowed a caller to force the victim’s device to send audio and video content without the user’s knowledge.

Related Story: WhatsApp vs Signal vs Telegram: Which is More Viable and Secure?

Microsoft to Launch Enforcement Mode to Address Critical “Zerologon” Flaw

Microsoft November 2021 Patch Tuesday, Windows 10, Microsoft PrintNightmare

Microsoft has alerted security admins that it is enabling Domain Controller enforcement mode by default to address a critical Remote Code Execution (RCE) vulnerability dubbed “Zerologon” that impacts the Netlogon protocol. The latest mode, which will be rolled out with the upcoming security update on February 9, 2021, will prevent vulnerable connections from non-compliant devices.

“Domain Controller enforcement mode requires that all Windows and non-Windows devices use secure Remote Procedure Call (RPC) with Netlogon secure channel unless customers have explicitly allowed the account to be vulnerable by adding an exception for the non-compliant device,” Microsoft said.

Zerologon – An Unpatched Flaw

The Zerologon (CVE-2020-1472), with a CVSSv3 score of 10.0, is a privilege escalation flaw in the Windows Netlogon Remote Protocol (MS-NRPC) that was patched in the Microsoft August Patch Tuesday. The vulnerability would have allowed attackers to hijack the Windows domain controller. All an attacker requires is local network access, which is also why it cannot be performed directly over the internet.

However, the Cybersecurity and Infrastructure Security Agency (CISA) stated that several proof-of-concept exploits caused widespread concern across the industry, and the bug remained unpatched in many government agencies.  In an emergency directive, the agency urged to update all Windows Servers with the domain controller role in any information systems that collects, processes, stores, transmits, disseminates, or maintains agency information.

Microsoft advised security admins and organizations to update their Domain Controllers with August 11, 2020, security update, monitor event logs to find out which devices are making vulnerable connections, and enable Domain Controller enforcement mode to address Zerologon flaw. In addition, the tech giant stated, “Organizations that deploy Microsoft Defender for Identity or Microsoft 365 Defender can detect adversaries as they try to exploit this specific vulnerability against their domain controllers.”

DNSMasq Critically Vulnerable to DNS Cache Poisoning Attacks

DNS attacks

Cybersecurity experts from security firm JSOF uncovered seven critical vulnerabilities in popular open-source Domain Name System (DNS) forwarding software DNSMasq, which is deployed in networking units to cache and forward Domain Identify Method requests. Dubbed as DNSpooq, the vulnerabilities include four Buffer Overflow Flaws (CVE-2020-25687, CVE-2020-25683, CVE-2020-25682, and CVE-2020-25681) and three DNS Cache Poisoning vulnerabilities (CVE-2020-25686, CVE-2020-25684, and CVE-2020-25685).

Various popular brands like Cisco, Android, Aruba, Technicolor, Red-Hat, Siemens, Ubiquiti Networks, and Comcast use DNSMasq in their products and services.  JSOF’s researchers stated that the devices that are using DNSMasq could be affected or unaffected based on how they are using the software.

“One of the interesting things about these vulnerabilities is that each one of them, on its own, has limited impact. However, the vulnerabilities could be combined and chained in certain ways to build extremely effective multi-staged attacks. This is because exploiting some of the vulnerabilities makes it easier to exploit others,” JSOF said.

What’s the impact?

The Buffer Overflow vulnerabilities include high severity risks that could potentially lead to remote code execution when configured to DNSMasq. These vulnerabilities could pose critical risks when attackers combine these with the cache-poisoning vulnerabilities to launch more effective cyberattacks.

DNS Cache Poisoning flaws can potentially result in various kinds of frauds. Scammers could exploit these vulnerabilities to route unwitting victims from a legitimate browser to a malicious one. Fraudsters can manipulate the Internet traffic, including regular Internet browsing, emails, SSH, remote desktop, RDP video and voice calls, and software updates.

“For the Buffer Overflows and Remote Code execution, devices that don’t use the DNSSEC feature will be immune. DNSSEC is a security feature meant to prevent cache poisoning attacks and so we would not recommend turning it off, but rather updating to the newest version of DNSMasq,” JSOF added.