Facebook Inc. and Facebook Ireland imposed legal action against two people in Portugal for violating Portugal’s Database Protection Law. The social media giant stated the culprits were scraping users’ personal information from their Facebook pages.
Malicious Extensions
Under the company name “Oinkn and Stuff,” the offenders specially designed browser extensions and made them available on the Chrome store. The malicious Chrome extensions, Web for Instagram plus DM, Blue Messenger, Emoji keyboard, and Green Messenger, contained hidden code that functions like spyware. The extensions were coded to scrape username, user ID, gender, relationship status, age group, and other personal data related to their social media accounts. The developers tricked users into installing the extensions with a privacy policy, claiming they did not collect users’ personal data.
“When people installed these extensions on their browsers, they were installing concealed code designed to scrape their information from the Facebook website, but also information from the users’ browsers unrelated to Facebook — all without their knowledge. The defendants did not compromise Facebook’s security systems. Instead, they used the extensions on the users’ devices to collect information,” Facebook said.
“We are seeking a permanent injunction against defendants and demanding that they delete all Facebook data in their possession. This case is the result of our ongoing international efforts to detect and enforce against those who scrape Facebook users’ data, including those who use browser extensions to compromise people’s browsers,” Facebook added.
What is Data Scraping?
Data scraping is a process of extracting users’ personal data from websites. It is a common practice for third-party vendors, web developers, business intelligence analysts, and authentic businesses to scrape users’ data for market research purposes. Social media companies like Facebook allow users to access third-party websites by using their existing Facebook login information. However, this process can also allow unauthorized users/threat actors to perform malicious activities, including identity theft and financial fraud.
Joe Biden had already upped his cybersecurity game during the race to the White House. The Democratic President had on-boarded former White House cybersecurity official Chris DeRusha as the CISO and Jacky Chang as the Chief Technology Officer for his election campaign. Yet his campaign website “Vote Joe” was defaced by Turkish threat actors. It did not stop here. His election app was also vulnerable to a cyberattack whose proof-of-concept was provided by white hat hackers from Promon. These incidents, along with the devastation and compromise caused by the SolarWinds cyberattack, have probably pushed the newly appointed POTUS to rethink the national cybersecurity posture immediately.
On his first day in office, Biden has already made his intentions clear that he is serious about cybersecurity. He has introduced and sanctioned a host of cybersecurity plans starting with three new appointments to key national cybersecurity positions.
Biden’s C–Suite
From left to Right: Rob Joyce, Anne Neuberger and Michael Sulmeyer
We had earlier reported that Biden had plans of appointing Anne Neuberger to the newly formed National Security Council (NSC). If reports are to be confirmed, the NSA Cybersecurity Director will now prefix a “Former” title to her current designation and move to her new position – Deputy National Security Adviser for Cyber and Emerging Technology. Neuberger has successfully led the NSA Cybersecurity Directorate since its inception in 2019 and played a pivotal role in countering 2020 U.S. election interferences from foreign adversaries.
This appointment meant that the top spot of NSA Cyber command was up for grabs. But, filling up Neuberger’s shoes is a huge task itself. Biden, however, seems to have found a perfect fit in Rob Joyce.
Joyce previously served as NSA’s senior representative to the U.K. at the U.S. embassy in London. He has a proven track record of more than 30 years in federal services and served in critical positions, including special assistant to the president and cybersecurity coordinator at the White House, deputy homeland security adviser and acting homeland security adviser.
Michael Sulmeyer is another name that has come up in Biden’s White House. Sulmeyer has been appointed as the Senior Director for Cyber. He comes with the experience of having served as a senior adviser to National Security Agency director and U.S. Cyber Command commander Gen. Paul Nakasone. The White House, however, is yet to decide what duties Sulmeyer will disperse in his new role.
Apart from these three, the U.S. Senate approved Avril Haines as the Director of National Intelligence.
This morning Avril Haines took the oath of office to serve as Director of National Intelligence. DNI Haines is the first woman to lead the U.S. Intelligence Community. https://t.co/r3Aqn7aaoS
What makes this appointment more noteworthy is that Haines is the seventh director of National Intelligence but the FIRST woman to lead the country’s intelligence community. Women in cybersecurity are breaking ground and, more importantly, the stereotypes.
Biden Reviews SolarWinds Hack
Biden has swiftly moved into the office and took charge. The POTUS has already signed 17 executive orders on his first working day and seems enthusiastic about getting a hold of things at the earliest. His enthusiasm is not just limited to undoing the policies of the previous chair in the White House but also in knowing the impacts of the previous regime and taking immediate remedial measures. It is with this view that Biden has ordered the U.S. intelligence agencies to provide him with an assessment of a suspected Russian espionage operation, popularly known as the SolarWinds cyberattack, which breached multiple U.S. federal agencies and exposed glaring weaknesses in U.S. cyber defenses.
The early days of Biden’s administration will be under the lens of his critics and his supporters, and the tact with which he responds to such a sophisticated spying operation against the nation may just as well define the way forward for his regime. What information would be given to Biden in the intelligence brief is still not clear, but by the looks of it, he sure seems keen enough on learning and seeking answers to the 4W’s and H of the hacking incident.
Biden Proposes $10 Billion Cybersecurity Spending
Biden’s role in making cybersecurity appointments and plans look realistically promising. However, to materialize such large level blueprints, one needs monetary investments. Giving this a deep thought, Biden, in his $1.9 trillion COVID-19 stimulus, also included a $9 billion spending proposal to help the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the General Services Administration (GSA) upgrade their cybersecurity and IT projects.
Additionally, Biden also proposed spending another $1 billion over cybersecurity and IT initiatives, including the hiring of security experts in the Office of the U.S. Chief Information Security Officer as well as the Digital Service unit in the White House; additional IT projects within the GSA; and for CISA’s multiple in-house projects aimed at improving its monitoring and incident response capabilities across all federal agencies.
Security experts are lauding Biden’s efforts and backing him in the fight against evolving cyberthreats. However, there are a few more laws and acts that need urgent attention and upgrade, including the Federal Information Security Act and the 1990 Chief Financial Officers Act, so that smaller federal agencies also benefit from the investments and resources that the new government is bringing to the table.
We hope Biden and his C–Suite are listening to this.
About the Author
Mihir Bagwe is a Tech Writer and part of the editorial team at CISO MAG. He writes news features, technical blogs, and conducts interviews on latest cybersecurity tech and trends.
Ever since the GDPR guidelines were launched (May 25, 2018), the data regulators in European Union (EU) have imposed sizable penalties on various organizations that misused customer information or failed to maintain the required cybersecurity standards. The EU has issued over €272.5 million (approximately $332.4 million) in fines since the GDPR was initiated, according to research from international law firm DLA Piper. Along with the surge in fines, the number of data breach notifications have also increased by 19% compared to last year.
In total, there have been more than 281,000 data breach notifications since the initiation of GDPR, with Germany (77,747), the Netherlands (66,527), and the U.K. (30,536) topping the list. Italy tops the list in aggregate fines with more than €69.3 million (about $84.5 million) in fines imposed since the initiation of GDPR. Germany and France stood second and third with aggregate fines of €69.1 million and €54.4 million, respectively.
Key Findings
Around €158.5 ($192,80) of fines have been imposed since January 28, 2020, a 39% increase on the previous 20-month period since the application of GDPR.
Double-digit growth for breach notifications for the second year running with 121,165 breaches notified since January 28, 2020, compared to 101,403 breaches notified in the previous year, a 19% increase.
Denmark tops the rankings for data breach notifications.
Italy has imposed the highest aggregate fines and France has imposed the highest individual fine to date.
Regulators have not had everything their own way this year with several multi-million-euro fines being successfully appealed or significantly reduced.
The highest GDPR fine to date remains the €50 million (about $61 million) imposed by the French data protection regulator on Google, for alleged infringements of GDPR’s transparency principle and lack of valid consent.
The research findings are based on the latest GDPR fines and data breach reports from the EU, the U.K., Norway, Iceland, and Liechtenstein.
Ross McKean, Chair of DLA Piper’s U.K. Data Protection and Security Group, said, “Fines and breach notifications continue their double-digit annual growth and European regulators have shown their willingness to use their enforcement powers. They have also adopted some extremely strict interpretations of GDPR setting the scene for heated legal battles in the years ahead. However, we have also seen regulators show a degree of leniency this year in response to the ongoing pandemic with several high-profile fines being reduced due to financial hardship.”
OpenWRT, an open-source project that offers free firmware for home routers, is the latest victim of a data breach. OpenWRT’s administrator forum has been reportedly accessed and breached, and the attackers have downloaded a copy of the users’ list that contained email addresses, handles, and other statistical information of the forum users.
Strong Password but no 2FA
While it is unknown how the attackers compromised the account, the forum administrators stated that the account had a strong password but did not have two-factor authentication (2FA). “Although we do not believe the intruder could download the database, from an abundance of caution, we are following the advice of the Discourse community and have reset all passwords on the Forum, and flushed any API keys,” the OpenWRT’s administrators said.
OpenWRT admins warned community users and impacted users to be vigilant of various phishing attacks. Besides, the admins suggested security measures, which include:
Reset your password by manually typing the following link without spaces on https://forum. openwrt.org. Enter your username and follow the “get a new password”
Assume that your email address and handle have been disclosed. That means you may get phishing emails that include your name. Don’t click links, but instead manually type the URL of the forum as above.
If you use the Github login/OAuth key, you should reset/refresh it.
OpenWrt forum credentials are entirely independent of the OpenWrt Wiki (https://openwrt.org). There is no reason to believe there has been any compromise to the Wiki credentials.
Knowledge, Possession, Identity
With the surge in security breaches and digital fraud, data protection has never been more crucial. 2FA is gaining momentum, but it is more common than you think. It plays on three factors:
Knowledge (something you know): A pin, password, or username.
Possession (something you have): An ATM or debit card, phone, token, etc.
Identity (something you are): Facial recognition, voice note, or fingerprint.
Take some time and make it harder for identity thieves!
Pixlr, a free online photo-editing platform, is the latest victim of a data breach after the notorious threat actor group “ShinyHunters” leaked over 1.9 million users’ records online, as reported by SiliconAngle. The exposed information included usernames, hashed passwords, email addresses, country of origin, and other personal data. It’s suspected that the hacking group illicitly obtained access to Pixlr user records by exploiting an unsecured AWS S3 bucket.
The Impact
ShinyHunters distributed the stolen information on various hacking forums for free, allowing other cybercriminals to access the data. The leaked data can be misused to launch a variety of cyberattacks against Pixlr users. Attackers can also compromise users’ accounts by committing spear-phishing or credential-stuffing attacks on users whose data was exposed in the incident.
Link to 123RF.com Data Breach
ShinyHunters operators claimed that they stole Pixlr’s database while they were breaking into 123RF.com user records. 123RF.com is a royalty-free image website. Both Pixlr and 123RF.com are owned by Inmagine company. According to a report, malicious actors leaked 123RF.com users’ data (3GB in size) on a Russian hacker forum. The company stated that the exposed database holds over 8,500,246 user records including users’ full names, email addresses, IP addresses, Facebook IDs, locations, and passwords that have been hashed using the MD5 hashing algorithm.
ShinyHunters Continue to Strike
Recently, the operators of ShinyHunters traded databases of three India-based enterprises – ClickIndia, ChqBook, and WedMeGood – on Darknet forums. The data dump contained over 8 million records of ClickIndia (name, email, mobile and other personal details), 1 million records of ChqBook (name, email, mobile, full address, and other personal details), and 1.3 million from WedMeGood (name, email, hashed password, other sensitive personal information).
Google Chrome has introduced a new password security feature to prevent users from using weak and compromised passwords online. The new feature will be rolled out with the upcoming Chrome version 88. The feature automatically detects and reports weak or easy-to-guess passwords by performing a quick safety check scan. A similar feature was introduced to Chrome Canary in December 2020.
Improved Password Protection
Google Chrome can now create, store, and fill in saved passwords and warn users if their passwords were compromised in any past data breaches. With Chrome 88, users can perform a simple check to identify passwords that are not strong enough and can take quick action by changing them.
How to find weak passwords using Chrome’s password safety check?
How to edit weak and compromised passwords in Chrome settings?
Image Courtesy: Google
Vulnerable Login Credentials!
Earlier, a study from Google revealed that 1.5% of all logins used across the Internet are vulnerable to credential stuffing attacks. Based on the data collected from February 5 to March 4, 2019, Google found that 1.5% of the 21,177,237 monitored logins were identified in data breaches.
“Nearly 670,000 users from around the world installed our extension over a period of February 5–March 4, 2019. During this measurement window, we detected that 1.5% of over 21 million logins were vulnerable due to relying on a breached credential — or one warning for every two users. By alerting users to this breach status, 26% of our warnings resulted in users migrating to a new password. Of these new passwords, 94% were at least as strong as the original,” the study revealed.
When we first reported about the SolarWinds attack in December 2020, we said it was just the tip of the iceberg, and now a month later, organizations around the globe can see what lies beneath. Malwarebytes, a U.S. – based cybersecurity firm, has reportedly been intruded on by the same nation-state actor behind the SolarWinds cyberattack.
In an official release, Marcin Kleczynski, CEO of Malwarebytes, stated that although the same threat actors were involved in this breach, it was not related to the SolarWinds supply chain attack. Instead, Kleczynski said that the intruders abused privileged access to Microsoft Office 365 and Azure environments to breach their network.
The Malwarebytes security team received security notifications from the Microsoft Security Response Center (MSRC) on December 15, 2020, about suspicious activity on one of its dormant Microsoft Office 365 apps. After comparing the vectors, the security team found them consistent with the tactics, techniques, and procedures (TTPs) of the threat actor involved in the SolarWinds attacks. Thus, from that day on, Malwarebytes’ researchers carried out extensive research and found the following:
Attackers breached Malwarebytes’ internal systems by exploiting a dormant email protection product within its Office 365 tenant.
The attackers only gained access to a limited subset of internal company emails.
No evidence of unauthorized access or compromise in any of the internal, on-premises, and production environments of their products has been found.
Our Products are Safe!
The SolarWinds cyberattack is known to have infested networks with additional payloads like the SUNBURST and Raindrop malware that can go undetected for months, if not days. Thus, Kleczynski assured that a thorough internal audit was carried out to investigate the matter at hand. The entire source code of all its products has been scanned, and he reassured stating, “Our software remains safe to use.”
Kleczynski also took the opportunity to thank FireEye, Crowdstrike, and Microsoft, who shared their resources and all the information on the SolarWinds cyberattack with them for quicker mitigation. He has reiterated the same sentiments that many cybersecurity experts have been saying for a long time – unite, associate, and fight the adversaries as one.
Natalie Silvanovich, a security researcher at Google Project Zero, disclosed critical vulnerabilities in multiple messaging and video conferencing mobile apps that allowed malicious actors to snoop into users’ conversations without their permission. The affected applications include Signal, JioChat, Mocha, Google Duo, and Facebook Messenger.
Silvanovich claimed the vulnerability in these platforms is similar to the critical flaw dubbed “Logic bug,” which was discovered in Apple’s FaceTime group chat feature in January 2019. The Logic flaw allowed threat actors to initiate a FaceTime video call and eavesdrop on victims by adding their phone number as a third person in a group chat before the other person accepted the call. Apple removed the FaceTime group chat feature and fixed the issue in a subsequent iOS update.
Silvanovich Tweets…
I found logic bugs that allow audio or video to be transmitted without user consent in five mobile applications including Signal, Duo and Facebook Messenger https://t.co/PlB0PzLzjJ
“The ability to force a target device to transmit audio to an attacker device without gaining code execution was an unusual and possibly unprecedented impact of a vulnerability. Moreover, the vulnerability was a logic bug in the FaceTime calling state machine that could be exercised using only the user interface of the device. While this bug was soon fixed, the fact that such a serious and easy to reach vulnerability had occurred due to a logic bug in a calling state machine — an attack scenario I had never seen considered on any platform — made me wonder whether other state machines had similar vulnerabilities as well,” Silvanovich explained.
Logic Bugs in Multiple Apps
Silvanovich stated that she found Logic vulnerabilities in Signal, Google Duo, Facebook Messenger, JioChat, and Mocha messaging apps, which are now patched. Most of these vulnerabilities allowed calls to be connected without interaction from the person on the other end. The other effects of these flaws include:
Google Duo
The vulnerability, which was fixed in December 2020, would disable the video and set up a connection to trigger the callee to leak video packets from unanswered calls. It is because Google Duo’s signaling methodology supports a feature that allows the callee to preview the caller’s video before answering, which is different from other video chat applications.
Signal
The audio call flaw, which was fixed in September 2019, in Signal’s Android app allowed the caller to hear the callee’s surroundings as the application didn’t check that the device receiving the connect message was the caller device. This caused the audio call to connect, allowing the caller to hear the callee’s surroundings.
Facebook Messenger
The vulnerability in Facebook Messenger, which was fixed in November 2020, allowed an attacker to initiate a call and send a specially crafted message to a victim who was signed in to both the app and the web browser.
JioChat and Mocha
Silvanovich found two similar vulnerabilities in JioChat (fixed in July 2020) and Mocha (fixed in August 2020). The vulnerabilities allowed a caller to force the victim’s device to send audio and video content without the user’s knowledge.
Microsoft has alerted security admins that it is enabling Domain Controller enforcement mode by default to address a critical Remote Code Execution (RCE) vulnerability dubbed “Zerologon” that impacts the Netlogon protocol. The latest mode, which will be rolled out with the upcoming security update on February 9, 2021, will prevent vulnerable connections from non-compliant devices.
“Domain Controller enforcement mode requires that all Windows and non-Windows devices use secure Remote Procedure Call (RPC) with Netlogon secure channel unless customers have explicitly allowed the account to be vulnerable by adding an exception for the non-compliant device,” Microsoft said.
Zerologon – An Unpatched Flaw
The Zerologon (CVE-2020-1472), with a CVSSv3 score of 10.0, is a privilege escalation flaw in the Windows Netlogon Remote Protocol (MS-NRPC) that was patched in the Microsoft August Patch Tuesday. The vulnerability would have allowed attackers to hijack the Windows domain controller. All an attacker requires is local network access, which is also why it cannot be performed directly over the internet.
However, the Cybersecurity and Infrastructure Security Agency (CISA) stated that several proof-of-concept exploits caused widespread concern across the industry, and the bug remained unpatched in many government agencies. In an emergency directive, the agency urged to update all Windows Servers with the domain controller role in any information systems that collects, processes, stores, transmits, disseminates, or maintains agency information.
Microsoft advised security admins and organizations to update their Domain Controllers with August 11, 2020, security update, monitor event logs to find out which devices are making vulnerable connections, and enable Domain Controller enforcement mode to address Zerologon flaw. In addition, the tech giant stated, “Organizations that deploy Microsoft Defender for Identity or Microsoft 365 Defender can detect adversaries as they try to exploit this specific vulnerability against their domain controllers.”
Cybersecurity experts from security firm JSOF uncovered seven critical vulnerabilities in popular open-source Domain Name System (DNS) forwarding software DNSMasq, which is deployed in networking units to cache and forward Domain Identify Method requests. Dubbed as DNSpooq, the vulnerabilities include four Buffer Overflow Flaws (CVE-2020-25687, CVE-2020-25683, CVE-2020-25682, and CVE-2020-25681) and three DNS Cache Poisoning vulnerabilities (CVE-2020-25686, CVE-2020-25684, and CVE-2020-25685).
Various popular brands like Cisco, Android, Aruba, Technicolor, Red-Hat, Siemens, Ubiquiti Networks, and Comcast use DNSMasq in their products and services. JSOF’s researchers stated that the devices that are using DNSMasq could be affected or unaffected based on how they are using the software.
“One of the interesting things about these vulnerabilities is that each one of them, on its own, has limited impact. However, the vulnerabilities could be combined and chained in certain ways to build extremely effective multi-staged attacks. This is because exploiting some of the vulnerabilities makes it easier to exploit others,” JSOF said.
What’s the impact?
The Buffer Overflow vulnerabilities include high severity risks that could potentially lead to remote code execution when configured to DNSMasq. These vulnerabilities could pose critical risks when attackers combine these with the cache-poisoning vulnerabilities to launch more effective cyberattacks.
DNS Cache Poisoning flaws can potentially result in various kinds of frauds. Scammers could exploit these vulnerabilities to route unwitting victims from a legitimate browser to a malicious one. Fraudsters can manipulate the Internet traffic, including regular Internet browsing, emails, SSH, remote desktop, RDP video and voice calls, and software updates.
“For the Buffer Overflows and Remote Code execution, devices that don’t use the DNSSEC feature will be immune. DNSSEC is a security feature meant to prevent cache poisoning attacks and so we would not recommend turning it off, but rather updating to the newest version of DNSMasq,” JSOF added.
Ensuring that you get the best experience is our only purpose for using cookies. If you wish to continue, please accept. You are welcome to provide a controlled consent by visiting the cookie settings. For any further queries or information, please see our privacy policy.
This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
Cookie
Duration
Description
cookielawinfo-checkbox-analytics
11 months
This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional
11 months
The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary
11 months
This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others
11 months
This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance
11 months
This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy
11 months
The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.