Home Blog Page 184

Patch It! Google Releases Fixes For 50 Vulnerabilities in Android Operating System

Vulnerabilties

Google released patches for over 50 vulnerabilities in the Android operating system with its August 2020 security updates. “Source code patches for these issues will be released to the Android Open Source Project (AOSP) repository in the next 48 hours. We will revise this bulletin with the AOSP links when they are available,” Google said in a security bulletin.

The tech giant stated that the most severe security flaw fixed this month is a high-severity vulnerability in the Framework component that could have been exploited by a hacker remotely to execute arbitrary code using a malicious file. “The severity assessment is based on the effect that exploiting the vulnerability would possibly have on an affected device, assuming the platform and service mitigations are turned off for development purposes or if successfully bypassed,” Google added.

Security Patch Level Vulnerability

The security bulletin mentioned two security patch levels to help Android users fix a subset of vulnerabilities that are similar across all Android devices more quickly. The 2020-08-01 security patch level fixes 14 high-severity vulnerabilities in the Framework, Media Framework, and System components. And the 2020-08-05 security patch level resolves 40 vulnerabilities in the MediaTek, AMLogic, Kernel, and Qualcomm components of Android.

According to the Android Security Bulletin, “The most severe vulnerability in this section could enable a remote attacker using a specially crafted file to execute arbitrary code within the context of an unprivileged process.”

Mitigation Measures

The Android security platform and Google Play Protect recommended certain protective measures to help defend against cybercriminals who are trying to exploit vulnerabilities in Android devices:

  • Exploitation for many issues on Android is made more difficult by enhancements in newer versions of the Android platform. We encourage all users to update to the latest version of Android where possible.
  • The Android security team actively monitors for abuse through Google Play Protect and warns users about Potentially Harmful Applications. Google Play Protect is enabled by default on devices with Google Mobile Services and is especially important for users who install apps from outside of Google Play.

Critical Vulnerability Fixed

Recently, Google fixed a critical MediaTek Rootkit vulnerability affecting millions of Android devices using MediaTek chips (now tracked as CVE-2020-0069). The issue was first reported on the XDA forum, one of the largest forums for Android software modifications, back in April 2019.

 

COVID-19 Pandemic is a Silver Lining for Cybersecurity

COVID-19 cybersecurity lessons

The digital and medical worlds are very different from each other. One talks about code and machine language, the other talks anatomical and physiological; one talks system and network security, the other talks about human immunity. There is nothing in common, except one small thing.

By Mihir Bagwe, Tech Writer, CISO MAG

This small thing is dreaded and has similar effects in both worlds. Puzzled? This common terminology of the two worlds is called virus. The nature of viruses such as emergence, the spread, damages caused, and the after-effects felt are the same in both worlds. The ongoing COVID-19 pandemic is no different. The world is reeling from the aftermath caused by a microscopic virus that some thought was “just another flu.” However, every crisis teaches us life lessons and this one has also taught a few lessons that can be related and taken note off in both the worlds – medical and digital.

cybersecurity lessons from covid-19

 Basic Hygiene Matters 

cybersecurity lesson - basic hygiene mattersWe were taught in school that washing hands, using a handkerchief while sneezing, taking a bath, or at least washing your hands and feet thoroughly after coming home from outside, etc. was all necessary in maintaining personal hygiene. We religiously followed these back then to impress our parents and teachers, but in transition of life we just lost touch. However, these very basic hygiene practices are what the WHO says will matter the most in the days ahead as this is now our first and best line of defense.

It is pretty much the same in digital world. Knowing your network architecture, the devices connected on it physically and virtually, their configuration, its security controls, and even the simplest of things like maintaining a log of browsed history – all contribute to maintaining hygiene. Hygiene failure should not be tolerated. As seen with the Coronavirus, a failure in hygiene can risk not just yours but others’ lives too. Similarly, hygiene failure in the digital vertical can lead to an organization’s downfall.

The digital shift in the post-pandemic world is going to have a significant impact on the cybersecurity front. World business leaders and CISOs would need to understand these technologies, their limitations and their associated security and compliance intricacies in the “digital normal”. COVID-19 has become the catalyst to trigger change in the ways of managing and operating technology. Thus, we need a solution that can cater to all these demands.

 Contact Tracing 

cybersecurity lesson - contact tracingWith the trends and patterns being analyzed extensively over the past 5-6 months, it is now seemingly clear that the difference between countries who are doing well or worse against the Coronavirus comes down to who tests more. Governments used this model of contact tracing to bring down the possible exposure of potential virus carriers. It is the same in digital world. Unless we know the root of the infection, response teams often play only a catch-up with something that has already begun to spread. When you test, you can analyze the patterns and design an action plan for it.

However, contact tracing is a difficult scenario in the digital world, as computer networks are interconnected, complex, unidirectional, and widespread across the globe. It is very difficult to quickly analyze and point-out the source of the infection in larger networks. Thus,  the responsibility of the security teams has increased twofold to maintain a map of its entire network architecture, understand all the access points, and the manner in which data is transmitted among all endpoints and nodes of your business.

 Restrict Lateral Movement 

cybersecurity lesson - lateral movementMan is a social animal. We are widely connected with each other and the proof of concept (PoC) for this is the current Coronavirus pandemic. The virus originated in a populous province of Wuhan in China, but soon spread laterally in all directions from one country to another. This shows that we are interconnected just like the networks in the digital world.

A biological virus infects a person with weaker immunity and then spreads from person to person forming a chain. In a similar way, threat actors while attacking any larger and complex network target its weaker links first and then spread laterally towards the main target as was the case in the Twitter Hack.

The main problem of the spread is the supply chain. We cannot protect our entire supply chain as they have their own networks and endpoints which are beyond our security perimeter. Therefore, an attacker finds these weaker links in the supply chain, exploits them, and moves laterally, from one network to another until he finally penetrates its targeted location.

However, the countries that successfully flattened the curve, for example, Singapore, restricted this lateral movement of coronavirus by applying a “Circuit Breaker.” This “Circuit Breaker” needs to be applied in the digital world as well. IT architectures need to implement containerization / segmentation and zoning concepts to include not just systems, but also people, roles, and the level of sensitive data they possess. Containerization, thus, will be extended beyond enterprise networks to include endpoints such as remote worker machines and mobiles devices.

This will facilitate cybersecurity teams to apply varied access controls and demarcate data storage to minimize risk of cyber intrusion and data breach. They need to break up patterns of lateral movement through segmentation that walls off data into distinct areas and prevents infections from moving into new segments.

 Slow the Spread 

cybersecurity lesson - control the spreadLockdowns were enforced across the globe to slow the spread of the pandemic. Similarly, slowing down a cyberattack has its own benefits. It’s practically impossible to detect and stop every attack on your organization but slowing them down buys enough time for your IT incident response teams to detect the source and block or quarantine them to avoid further spread and subsequent damages.

 Proactive Approach 

cybersecurity lessons - proactive approachIn countries like India, where population density has contributed to the emergence of community hotspots of COVID-19, local governing bodies changed their approach from preventive to proactive. They decided to “chase the virus” by deploying rigorous contact tracing and testing measures. This is exactly the need of the hour in the digital world.

We can no longer be subdued and complacent about our approach towards strengthening security measures. We may have the best firewalls and security products in place, but the reality is that “security is a myth.” Hackers go by the principle that anything and everything can be penetrated, and this is what businesses need to understand. Thus, instead of only relying on your incident response, implement proactive strategies like Cyber Threat Intelligence (CTI). These would give you insights of the underlying threats in the digital world, which will help you to not only protect but also prepare better for the worst.

About the Author

CISO MAG Writer - Mihir Bagwe
Mihir Bagwe is a Tech Writer and part of the editorial team at CISO MAG. He writes news features, technical blogs, and conducts interviews on latest cybersecurity technologies and trends.

 


Other Posts from the Author:

Australia to Spend $1.19 Bn to Boost Cybersecurity

Australia to Spend $1.19 Bn to Boost Cybersecurity

With the surge in cybercrime the country, the Prime Minister of Australia, Scott Morrison, has announced that the country is going to spend A$1.66 billion (US$ 1.19 billion) over the next decade to bolster the cybersecurity defenses for enterprises. According to a media report cyberattacks on private businesses and households incurred a cost of A$29 billion (US$ 20.83 billion) or 1.5% of Australia’s gross domestic product (GDP) to the country.

The increased security investment is aimed to fortify critical infrastructure, boost police efforts to disrupt malicious activities on the dark web and strengthen community awareness on security. The latest cybersecurity spending announcement comes after the Australian Capital Territory, Canberra, commited to spend A$1.35 billion (US$ 0.97 billion) over the next 10 years to strengthen the capabilities of its chief cyber intelligence agency.

Morrison stated that malicious activities are swelling against small and medium businesses and universities in the country. He also stressed that a sophisticated state-sponsored actor targeted all levels of the government, political bodies, essential service providers, and operators of critical infrastructure in June 2020. “We will protect our vital infrastructure and services from cyberattacks. We will support businesses to protect themselves so they can succeed in the digital economy,” Morrison added.

Cyberattacks on Australia

Recently, Scott Morrison briefed about sustained cyberattacks carried out by a sophisticated state-sponsored actor. These cyberattacks are not only targeted toward government organizations but also toward known corporate entities in the country. After a detailed briefing received from the Australian Cyber Security Center (ACSC), Morrison told the media, “Australian organizations are currently being targeted by a sophisticated state-based cyber actor. Organizations across a range of sectors, including all levels of government, industry, political organizations, education, health, central service providers, and operators of other critical infrastructure, are all being targeted.”

Australia – The World’s 15th Secure Country

study on global comparison of cybersecurity defenses ranked Australia as the world’s 15th secure country. According to the security research firm Comparitech, Australia climbed 12 positions in its latest cybersecurity ranking report. The study evaluated 76 countries’ exposure to security vulnerabilities to find which countries are well prepared for cyberattacks. Comparitech stated that it found improvement in Australia’s cybersecurity readiness with an overall score of 13.95 when compared to the previous year’s 16.34 (lower scores represent better ranking). The scores are based on the indicators of compromise like the percentage of mobiles infected with malware, the frequency of financial malware attacks, and the number of computers infected with viruses in a country.

 

Still Using a Windows 7 Device? Watchout! You Can Get Hacked

Still Using a Windows 7 Device? Watchout! You Can Get Hacked

The FBI warned organizations in the U.S. about security concerns associated with the use of the Windows 7 operating system after it reached its official end-of-life (EOL) earlier this year. In a Private Industry Notification (PIN), the FBI stated that enterprises running Windows 7 systems are vulnerable to getting hacked due to lack of security updates. The notification is intended to help security professionals and system administrators defend against the persistent malicious activities of cybercriminals.

Windows 7 End-of-Life Status

Microsoft ended the security updates and technical support for their Windows 7 OS on January 14, 2020. However, the company is providing Extended Security Update (ESU) services as an additional purchase per-device, which is available for Windows 7 Professional and Enterprise versions. Microsoft will only offer the ESU plan until January 2023.

The FBI stated that continuing to use Windows 7 may attract risks from cybercriminals exploiting the outdated systems and known/newly discovered vulnerabilities.

Microsoft and other industry professionals strongly recommend upgrading computer systems to an actively supported operating system. Migrating to a new operating system can pose its own unique challenges, such as cost for new hardware and software and updating existing custom software. However, these challenges do not outweigh the loss of intellectual property and threats to an organization

— the FBI said in the notification

Threats Associated with Windows 7 OS

The FBI also mentioned several Windows 7 vulnerabilities that have been exploited over the past few years, these include:

  • As of May 2019, 71% of Windows devices used in health care organizations ran an operating system that became unsupported in January 2020. Increased compromises have been observed in the health care industry when an operating system has achieved end of life status. After the Windows XP end of life on 28 April 2014, the health care industry saw a large increase of exposed records the following year.
  • Cybercriminals continue to find entry points into legacy Windows OS and leverage Remote Desktop Protocol (RDP) exploits. Microsoft released an emergency patch for its older operating systems, including Windows 7, after an information security researcher discovered the RDP vulnerability called BlueKeep in May 2019.
  • Since the end of July 2019, malicious RDP activity has increased with the development of a working commercial exploit for the BlueKeep vulnerability. Cybercriminals often use misconfigured or improperly secured RDP access controls to conduct cyberattacks.
  • In 2017, nearly 98% of systems infected with WannaCry employed Windows 7 based operating systems. After Microsoft released a patch in March 2017 for the computer exploit used by the WannaCry ransomware, many Windows 7 systems remained unpatched when the WannaCry attacks began in May 2017. With fewer customers able to maintain a patched Windows 7 system after its end of life, cybercriminals will continue to view Windows 7 as a soft target.

Protective Measures

The FBI also recommended organizations to follow a multilayered approach to defend against cybercriminals, which include:

  • Upgrading operating systems to the latest supported version.
  • Ensuring anti-virus, spam filters, and firewalls are up to date, properly configured, and secure.
  • Auditing network configurations and isolate computer systems that cannot be updated.
  • Auditing your network for systems using RDP, closing unused RDP ports, applying two-factor authentication wherever possible, and logging RDP login attempts.

 

UberEATS Suffers Data Breach; Personal Records of Users Leaked on Dark Web

UberEATS Suffers Data Breach; Personal Records of Users Leaked on Dark Web

The U.S.-based online food ordering and delivery platform UberEATS is the latest victim of a data breach. Security researchers from cybersecurity firm Cyble came across unknown hackers leaking personal records of UberEATS customers and employees on darknet forums.

“During our research process, the Cyble Research Team got hold of some informative details related to this leak,” Cyble said in a release.

What Information Was Exposed

  • 9 TXT files leaked, which contained details of UberEATS delivery drivers, delivery partners, and customers.
  • Around 579 UberEATS customers’ files and login credentials were exposed on the dark web.
  • Leak of over 100 delivery drivers’ personal data including, full name, contact details, trip details, bank card details, and account creation date.

Exposed Data on Dark Web

Image Source: Cyble

How to Mitigate Data Breach Risks

Data breaches can pose serious security issues to individuals and organizations when the stolen data falls in the wrong hands. Cyble recommended certain security tips to protect personal data against attackers:

  • Never share personal information, including financial information over the phone, email, or SMS.
  • Use strong passwords and enforce multi-factor authentication or two-factor authentication (2FA) where possible.
  • Regularly monitor your financial transaction, if you notice any suspicious transaction, contact your bank immediately.
  • Turn-on automatic software update feature on your computer, mobile and other connected devices where possible and pragmatic.
  • Use a reputed anti-virus and internet security software package on your connected devices including PC, laptop, mobile. 

Attacks on Food Delivery Platforms

Multiple security incidents have been reported on food delivery services as cybercriminals are taking advantage of the ongoing pandemic  to target businesses and users online. In a recent incident, threat actors launched a distributed denial-of-service (DDoS) attack on Germany-based food delivery firm Takeaway.com (Liefrando.de). Attackers demanded two Bitcoins (around US$11,000) in ransom to stop the attack. Earlier, DoorDash, a San Francisco-based food-delivery service provider, faced a massive data breach that affected data of around 4.9 million people (its customers, delivery workers, and merchants), who were using its service platform. The company said that an unauthorized third-party accessed its user data on May 4, 2019. DoorDash clarified that users who joined its services platform on or before April 5, 2018, were affected in the incident.

 

97% Indian Organizations Experienced at Least One Business-Impacting Cyberattack in the Past 12 Months: Forrester Study

CEO, cybersecurity, CISO, Future of the CISO

The attacks on Indian organizations have increased in the past two years, yet only four in 10 security leaders in India have a clear picture about how much at risk, or how secure their organizations are. Most Indian organizations (97%) have experienced a business-impacting cyberattack in the past 12 months, according to both business and security executives. And 76% of respondents in India have witnessed a dramatic increase in the number of business-impacting cyberattacks over the past two years. The data is drawn from “The Rise of the Business-Aligned Security Executive,” a commissioned study of more than 800 global business and cybersecurity leaders, including 54 local respondents, conducted by Forrester Consulting on behalf of Tenable, a Cyber Exposure company.

“Business-impacting” relates to a cyberattack or compromise that results in a loss of customer, employee, or other confidential data; interruption of day-to-day operations; ransomware payout; financial loss or theft; and/or theft of intellectual property.

Unfortunately, these business-impacting cyberattacks had damaging effects, with organizations reporting identity theft (44%), financial loss or theft (38%), and ransomware payout (33%). 67% of security leaders in India say these attacks also involved operational technology (OT).

Business leaders want a clear picture of how much at risk they are and how that risk is changing as they plan and execute business strategies. But only four out of 10 of local security leaders say they can answer the fundamental question, “How secure, or at risk, are we?” with a high level of confidence, despite the prevalence of business-impacting cyberattacks.


Adam Palmer, Chief Cybersecurity Strategist, Tenable, business-impacting cyberattacks
Adam Palmer, Chief Cybersecurity Strategist, Tenable

Speaking to CISO MAG Adam Palmer, Chief Cybersecurity Strategist, Tenable said, “Many security leaders use the heat matrices, the red, amber, green (RAG) scores to try to describe risk to the business leaders. This is really IT talk. Every organization I worked at did this. RAG scores do not say anything to really quantify the risk or help people understand the reduction in risk. How can a business leader make a decision, based on a color in RAG scores? There is a gap in communication between how IT people speak (technical or ambiguous) and the expectations of business leaders–quantitative understanding of risk.”


RELATED STORY

Optimizing Security for Your Business


Global findings for business-impacting cyberattacks

Looking at global respondents, fewer than 50% of security leaders said they are framing cybersecurity threats within the context of a specific business risk. For example, though 96% of respondents had developed response strategies to the COVID-19 pandemic, 75% of business and security leaders admitted their response strategies were only “somewhat” aligned.

“The heart of it is really the lack of partnership between the security and the business leaders. There’s not enough alignment of metrics and objectives with business strategic priorities. I see that organizations report risk in a very qualitative language. This is not the language of business leaders. They have to consider industry benchmarking frameworks and accurately report it to the business. In times like today, with the pandemic, it is more important than ever for business leaders to understand their level of risks,” added Palmer.

Organizations with security and business leaders who are aligned in measuring and managing cybersecurity as a strategic business risk deliver demonstrable results. Compared to their siloed peers, business-aligned security leaders are:

  • Eight times more likely to be highly confident in their ability to report on their organizations’ level of security or risk.
    • 90% are very or completely confident in their ability to demonstrate that cybersecurity investments are positively impacting business performance compared with 55% of their siloed counterparts.
    • 85% have metrics to track cybersecurity ROI and impact on business performance versus just 25% of their siloed peers.
  • Organizations with business-aligned cybersecurity leaders are also:
    • Three times more likely to ensure cybersecurity objectives are in lock step with business priorities.
    • Three times more likely to have a holistic understanding of their organization’s entire attack surface.
    • Three times more likely to use a combination of asset criticality and vulnerability data when prioritizing remediation efforts.

Business-impacting cyberattack, Renaud Deraison, Chief Technology Officer and co-founder, Tenable
Renaud Deraison, Chief Technology Officer and co-founder, Tenable

“In the future, there will be two kinds of CISO — those who align themselves directly with the business and everyone else. The only way to thrive in this era of digital acceleration is to bring cyber into every business question, decision, and investment,” said Renaud Deraison, Chief Technology Officer and co-founder, Tenable. “We believe this study shows that forward-leaning organizations view cybersecurity strategy as essential to innovation and that when security and the business work hand-in-glove, the results can be transformational.”


Forrester Consulting conducted the online survey of 416 security and 425 business executives, as well as telephonic interviews with five business and security executives, to examine cybersecurity strategies and practices at midsize to large enterprises in Australia, Brazil, France, Germany, India, Japan, Mexico, Saudi Arabia, the U.K., and the U.S. The study was fielded in April 2020.

To read the full study, visit https://www.tenable.com/analyst-research/forrester-cyber-risk-report-2020

U.S. Issues a Code Red for a New Strain of “Taidoor” Virus from China

U.S. and China

The U.S. law enforcement agencies like the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Department of Defense (DoD), have jointly issued a malware alert against a new strain of “Taidoor” malware. The FBI was very confident in stating that the new variant was introduced by Chinese state actors that are planning to attack various industries in the U.S. as a retaliation to the current geopolitical tension between the two nations.

 Key Highlights 

  • The Malware Analysis Report (MAR) has been jointly prepared by the CISA, FBI and DoD.
  • The FBI is confident that Chinese state sponsored actors are behind this new variant of Taidoor malware.
  • Four Taidoor samples have already been uploaded by the U.S. Cyber Command on Google’s VirusTotal repository.
  • Threat actors are using this malware variant along with proxy servers to maintain access to the victims’ networks and carry further exploitation.

Taidoor’s Evolution

Taidoor was first sighted in 2008 and continues to be active to date. It has been largely used in cyber espionage campaigns across the globe, notably in countries like Taiwan, Japan, and the U.S. According to a FireEye report published in 2013, Taidoor malware is traditionally delivered as a spear-phishing email attachment. If opened, the Taidoor malware is dropped onto the target’s system, which then starts communicating with a command and control (C2) server. Taidoor connects to its C2 server using HTTP, and the “GET” request. This has been consistent since 2008.

However, the same study also stated that Taidoor is a constantly evolving and persistent malware threat. A tactical change was observed by the researchers in the years 2011-2012, when the malicious email attachments started dropping a “downloader,” which then installed the traditional Taidoor malware from over the Internet.

This however has further evolved, according to the Malware Analysis Report (MAR) shared by CISA. “Taidoor is now installed on a target’s system as a service dynamic link library (DLL) and is comprised of two files. The first file is a loader, which is started as a service. The loader decrypts the second file, and executes it in memory, which is the main Remote Access Trojan (RAT).”

Threat Summary
Name Taidoor
Threat type Malware, Remote Access Trojan (RAT)
File Type 32-bit Windows DLL file
Number of .dll files used while installing the malware Two (“ml.dll” is a Taidoor loader which decrypts and loads “svchost.dll” that is identified as Taidoor malware)
Files used for spreading Malware
  • 0d0ccfe7cd476e2e2498b854cef2e6f959df817e52924b3a8bcdae7a8faaa686 (svchost.dll)
  • 363ea096a3f6d06d56dc97ff1618607d462f366139df70c88310bbf77b9f9f90 (svchost.dll)
  • 4a0688baf9661d3737ee82f8992a0a665732c91704f28688f643115648c107d4 (ml.dll)
  • 6e6d3a831c03b09d9e4a54859329fbfd428083f8f5bc5f27abbfdd9c47ec0e57 (rasautoex.dll)

Mitigation Measures Suggested by CISA

CISA and FBI have already informed the affected victims, but they are still uncertain about the exact number of users affected by Taidoor. It recommends the following mitigation measures:

  • Conduct a regular review to determine if there is a security concern or compromise.
  • Implement detection tools for detecting malicious activities.
  • Additionally, customers and users of any IT service provider must:
    • Review and verify all connections between their systems, service provider systems, and other client enclaves.
    • Restrict access to service provider accounts in their environment only for appropriate purposes and disable them when not actively used.
  • Check and maintain all system log file that could serve as a proof for investigation in case of an intrusion.

Your Mobile Location Data Could Pose Security Threats: NSA

Your Mobile Location Data Could Pose Security Threats: NSA

The U.S. National Security Agency (NSA) warned about the security risks associated with location data tracked via mobile phones and other connected devices. The NSA released a detailed guidance report primarily intended for the Department of Defense (DoD) and Federal agencies personnel, and also noted that it could be useful to a wide range of users.

NSA stated that location data is valuable and must be protected against adversaries. The exploitation of  location data can reveal details about the number of users in a location, user movements, and can expose unknown associations between users and locations.

“Mitigations reduce, but do not eliminate, location tracking risks in mobile devices. Most users rely on features disabled by such mitigations, making such safeguards impractical. Users should be aware of these risks and act based on their specific situation and risk tolerance. When location exposure could be detrimental to a mission, users should prioritize mission risk and apply location tracking mitigations to the greatest extent possible. While the guidance in this document may be useful to a wide range of users, it is intended primarily for NSS/DoD system users,” NSA said in a statement.

Not Just Limited to Mobile Phones

According to the NSA report, any device that sends and receives wireless signals is vulnerable to location data risks. Connected devices like fitness trackers, smart watches, smart medical devices, or built-in vehicle communication devices often store users’ geolocation information, which is automatically synced to cloud accounts. This could also pose a risk of location data exposure if the accounts or the servers linked to the accounts are compromised.

“Personal and household smart devices (e.g., light bulbs, cookware, thermostats, home security, etc.) often contain wireless capabilities of which the user is unaware. Such IoT devices can be difficult to secure, most have no way to turn off wireless features, and little, if any, security built in. These security and privacy issues could result in these devices collecting and exposing sensitive location information about all devices that have come into range of the IoT devices,” the statement added.

Location Risks with Apps and Social Networks

Most of the mobile apps request permission for location and other resources that are not required. They even collect, aggregate, and transmit information that exposes a user’s location. Users must be vigilant while sharing information or location data on applications and social media networks.

“If errors occur in the privacy settings on social media sites, information may be exposed to a wider audience than intended. Pictures posted on social media may have location data stored in hidden metadata. Even without explicit location data, pictures may reveal location information through picture content,” the NSA explained.

Risk Mitigation

The NSA also recommended security measures to mitigate location data risks:

  • Disable radios when they are not actively in use: disable Bluetooth (BT) and turn off Wi-Fi if these capabilities are not needed. Use Airplane Mode when the device is not in use. Ensure BT and Wi-Fi are disabled when Airplane Mode is engaged.
  • Disable location services settings on the device.
  • Set privacy settings to ensure apps are not using or sharing location data.
  • Avoid using apps related to location if possible, since these apps inherently expose user location data. If used, location privacy/permission settings for such apps should be set to either not allow location data usage or, at most, allow location data usage only while using the app. Examples of apps that relate to location are maps, compasses, traffic apps, fitness apps, apps for finding local restaurants, and shopping apps.
  • Set privacy settings to limit ad tracking, noting that these restrictions are at the vendor’s discretion.
  • Reset the advertising ID for the device on a regular basis. At a minimum, this should be on a weekly basis.
  • Turn off settings (typically known as Find My Device settings) that allow a lost, stolen, or misplaced device to be tracked.
  • Minimize web-browsing on the device as much as possible and set browser privacy/permission location settings to not allow location data usage.
  • Use an anonymizing Virtual Private Network (VPN) to help obscure location.
  • Minimize the amount of data with location information that is stored in the cloud, if possible.

 

Misconfigured Cloud Storage Services Led to Over 200 Breaches in Past Two Years

Misconfigured Cloud Storage Services Led to Over 200 Breaches in Past Two Years

Cloud security professionals across the globe are concerned about the security of their cloud environments as several organizations are working remotely since the pandemic hit. The prevention of cloud misconfigurations remains a challenge for organizations that are swiftly adopting new access policies, networks, and devices used for managing cloud infrastructure remotely.

A survey “State of DevSecOps,” from Accurics revealed that misconfigured cloud storage services in 93% of cloud deployments led to over 200 breaches in the past two years, exposing more than 30 billion records.  It also stressed that cloud data breaches are expected to increase in both velocity and scale. Around 91% of the cloud deployments evaluated had at least one major data breach and one in two (50%) deployments had unprotected credentials stored in container configuration files.

Other Key Findings include:

  • Misconfigured cloud storage services are commonplace in a stunning 93% of the cloud deployments analyzed, and most also have at least one network exposure where a security group is left wide open.
  • One emerging problem area is that despite the broad availability of tools, hardcoded private keys turned up in 72% of the deployments analyzed. Specifically, unprotected credentials stored in container configuration files were found in half of these deployments, which is an issue given that 84% of organizations use containers.
  • Around 41% of the organizations had high privileges associated with the hardcoded keys and were used to provision compute resources; any breach involving these would expose all associated resources. Hardcoded keys have contributed to a number of cloud breaches.
  • Network exposures resulting from misconfigured routing rules posed the greatest risk to all organizations. In 100% of deployments, an altered routing rule exposed a private subnet containing sensitive resources like databases, to the internet.
  • Automated detection of risks paired with a manual approach to resolution is creating alert fatigue, and only 6% of issues are being addressed. An emerging practice known as Remediation as Code, in which the code to resolve the issue is automatically generated, is enabling organizations to address 80% of risks.

Accurics advised organizations to implement certain security practices like encrypting databases, rotating access keys, and implementing multi-factor authentication for enhanced cloud security.

The adoption of cloud native infrastructure such as containers, serverless, and service mesh is fueling innovation, misconfigurations are becoming commonplace and creating serious risk exposure for organizations. As cloud infrastructure becomes increasingly programmable, we believe that the most effective defense is to codify security into development pipelines and enforce it throughout the lifecycle of the infrastructure. The receptiveness of the developer community toward assuming more security responsibility has been encouraging and a step in the right direction

 

           – Om Moolchandani, Accurics Co-founder & CTO

Misconfigurations Increase the Risks

A similar survey, “The State of Cloud Security 2020,” revealed that inadvertent database exposure continues to be a major risk for organizations, with misconfigurations exploited in 66% of reported attacks. Besides, 33% of organizations reported that attackers gained access through stolen cloud provider account credentials.  A quarter of organizations stated that managing access to cloud accounts is a primary concern to them. Nearly 96% of respondents admitted that they face issues with their current level of cloud security, while 44% of respondents reported data breaches are the top security concern. Only one in four respondents stated lack of staff expertise as a top concern.

 

Hackers Favored Google and Amazon for Brand Phishing Attacks in Q2 2020

Hackers Favored Google and Amazon for Brand Phishing Attacks in Q2 2020

Google and Amazon were the top used brands in phishing attacks (13%) during Q2 2020, according to Check Point’s Brand Phishing Report. The report highlighted various other brands that were frequently impersonated by hackers in their cyber activities to steal victims’ sensitive information. Check Point stated that technology, banking, and social networking are the most targeted sectors in brand phishing attacks.

Brand Phishing Attack: An Overview

  • In brand phishing attacks, attackers impersonate the official website of a popular brand by creating a similar domain name or URL of the original site.
  • The links to the fraudulent website are then sent to targeted individuals via email or SMS.
  • Once the user clicks on the link, it redirects them to a fake website which often contains a form intended to steal user credentials, payment details, or sensitive information.

Top Phishing Brands

According to the report, WhatsApp and Facebook stood at third and fourth positions with 9% brand phishing attacks. Similarly, Microsoft and its brand Outlook, which stood at fifth and sixth spots, were imitated in 7% and 3% of attacks, respectively. Apple (the leading phishing brand in Q1 2020) fell to seventh place in the current rankings with 2% of attacks, followed by Netflix, Huawei, and PayPal at eighth, ninth and tenth spots (2% attacks).

Image Source: Check Point

Top Phishing Brands Per Vector

Email phishing exploits were the second most common type after web-based exploits.  “The reason for this change may be the easing of global Covid-19 related restrictions, which have seen businesses re-opening and employees returning to work,” the report said.

Top 3 Attacked Vectors

table

How to Stay Safe

Check Point recommended certain security measures to avoid falling victim to phishing scams, these include:

  • Verify you are using or ordering from an authentic website. One way to do this is NOT to click on promotional links in emails, and instead Google your desired retailer and click the link from the Google results page.
  • Beware of special offers. An 80% discount on a new iPhone is usually not a reliable or trustworthy purchase opportunity.
  • Beware of lookalike domains, spelling errors in emails or websites, and unfamiliar email senders.