Home Blog Page 187

Promo.com Data Breach Exposes Gaps in Third-Party Risk Management, Yet Again!

data breach

Promo.com, which is popularly known for its social media ads creation platform, went on record to disclose a data breach incident that compromised nearly 22 million of its user records. As per the initial internal investigation, the source of the data breach is linked to an existing vulnerability in Promo’s unnamed third-party service provider.

Your attack surface is a lot bigger than you think. The Promo breach serves as a reminder of the importance of vetting your third-party partners.

– Justin Heard, Director of Security Intelligence at Nuspire

Things We Know So Far… 

  • Promo.com team became aware of the data breach on July 21, 2020
  • The data breach affected 22.1 million users of both Promo and Slidely
  • A data security vulnerability in a third-party service provider caused the data breach
  • No reports of financial data loss, including credit cards and billing information, were observed as Promo does not store any of this information on its servers
  • The leaked data includes first and last name, email address, IP address, approximate user location based on the IP address, gender, as well as encrypted, hashed, and salted user passwords of Promo and/or Slidely accounts. Promo also informed that some hashed passwords may have been decoded into plain text
  • User login via social media account was not affected
  • Promo has now terminated and removed the third-party service under question
  • They hired an external cybersecurity firm to further reinforce and upgrade their security measures
  • As a precautionary measure, Promo requested all its users to change their passwords at the earliest

Experts Speak 

Although Promo.com, in its FAQ related to the data breach, has stated that it is safe to use the platform post a password reset,  this incident has yet again highlighted the gap and need of paying utmost attention towards third-party risk management.

Talking about the side angle of this attack with Justin Heard, Director of the Security Intelligence and Analytics Team at Nuspire, he pointed out that we often overlook the vulnerabilities in the expanded threat surface, i.e. the third-party services.

Heard said, “Your attack surface is a lot bigger than you think. The Promo breach serves as a reminder of the importance of vetting your third-party partners. If your third-party partners do not have equal or greater security standards, they are a security risk. As your organization grows and scales, so does your list of third-party vendors, and thus, it is in every organization’s best interest to always vet the security of their vendors.”

I recommend employing a layered approach to security. This requires advanced antivirus detection over legacy tools and educating your most important stakeholder in such a business environment – your staff.

– Justin Heard, Director of Security Intelligence at Nuspire

The added, “The overarching issue with third-party security is accountability. If your organization collects customer data or has privileged access, it is your responsibility to keep that data protected and fines should be issued if an organization fails to do so. I recommend employing a layered approach to security. This requires advanced antivirus detection over legacy tools and educating your most important stakeholder in such a business environment – your staff. Train them on what they can do to prevent such security incidents.”

54% of Universities in the U.K. Suffered a Data Breach Last Year

54% of Universities in the U.K. Suffered a Data Breach Last Year, Herff Jones payments card breach

A survey on the state of cybersecurity in the higher education sector, conducted by managed threat detection provider Redscan, revealed that nearly 54% of universities in the U.K. reported a data breach to the Information Commissioner’s Office (ICO) last year.

The survey report titled “The State of Cybersecurity across U.K. Universities”  stated that around 46% of all university staff received no security training and 24% did not commission a penetration test from a third-party. Security training is key to building a safe cyber space however, there is a lack of staff and student awareness about the current threats, such as COVID-19 scams.

Endless Phishing Attacks

Defending against the constant stream of phishing scams remains a challenge for all universities. Several universities receive millions of spam and phishing emails each year, with one institution reporting a high of 130 million. Phishing scams are becoming endless and the volume of attempts has increased by 50% since 2019.

Image Source: Redscan

Other Key Findings include:

  • Universities spend an average of £7,529 (US$ 9,729) per year on security training, with expenditure ranging from £0 to £49,000 (US$ 63,319)
  • Universities employ, on average, three qualified cybersecurity professionals
  • 51% of universities are proactive in providing security training and information to students
  • 12% of universities do not offer any kind of security guidance, support, or training at all to students
  • 66 out of 134 universities have Cyber Essentials or Cyber Essential Plus certification
  • 65% of students say that they would be less likely to apply to a university with a reputation for poor cybersecurity

“Universities are targeted by criminals seeking financial gain, as well as by nation state attackers looking to steal intellectual property. The Redscan report raises concerns that many may not be doing enough to defend against the latest threats, particularly at a time when institutions are embracing remote teaching en masse and conducting world-changing research in relation to COVID-19. The impact of failing to address key security vulnerabilities could be disastrous. State-sponsored espionage has the potential to inflict long-term damage on U.K. universities by deterring funding for research and damaging public perception,” the U.K.’s National Cyber Security Centre (NCSC) said in a statement.

Redscan CTO, Mark Nicholls, said, “The fact that such a large number of universities don’t deliver cybersecurity training to staff and students, nor commission independent penetration testing, is concerning. These are foundational elements of every security program and key to helping prevent data breaches. Even at this time of intense budgetary pressure, institutions need to ensure that their cybersecurity teams receive the support they need to defend against sophisticated adversaries. Breaches have the potential to seriously impact organizations’ reputation and funding. The threat posed to universities by nation state attackers makes the need for improvements even more critical. The cost of failing to protect scientific research is immeasurable.”

 

How Threat Actors Exploited Google Cloud to Launch Phishing Attacks

google cloud

The world today is increasingly digital. And with rapid digital transformation and technology adoption, hackers are misusing the situation with more targeted attacks. A report from cyberthreat intelligence provider Check Point Research stated that threat actors exploited Google Cloud to host malicious payloads and launch phishing attacks.

By Pooja Tikekar, Feature Writer at CISO MAG

The Google Cloud Phishing Journey

  • A PDF was uploaded to Google Drive.
  • The PDF was disguised to resemble a Microsoft SharePoint notice, which contained a link to an MS Access Document.
  • Once clicked, it redirected the user to a phishing page, which was hosted on googleapis.com/asharepoint-unwearied-439052791/index.html.
  • The user was then prompted with a popup to login with their Microsoft Office 365 credentials or organizational e-mail ID and password.
  • Once the login credentials were entered, the user was led to a real PDF report published by renowned global consulting firm. The final PDF left little or no suspicion in the mind of the user because he was tricked into viewing useful information.

Security professionals find it difficult to identify or detect such phishing campaigns as they are hosted on public cloud services.

During all these stages, the user never gets suspicious since the phishing page is hosted on Google Cloud Storage. However, viewing the phishing page’s source code has revealed that most of the resources are loaded from a website that belongs to the attackers, prvtsmtp[.]com:, the report stated.

Image source: Check Point

Investigating prvtsmtp[.]com showed that it resolved to a Ukrainian IP address (31.28.168[.]4). Many other domains related to this phishing attack resolved to the same IP address, or to different ones on the same netblock, the report added.

Google has a zero-day tolerance policy; hence it suspended the phishing URL and all the URLs associated with it. In the past, the hackers used Dropbox and Microsoft Azure to host phishing pages.

Precautionary Measures

To stay protected against phishing attacks, Check Point suggested the following practical precautions:

  • Beware of lookalike domains and double-check spelling errors in emails and websites.
  • Be cautious with files received via email from unknown senders, especially if they prompt for a certain action you would not usually do.
  • Do not click on promotional links or emails. Order goods from authentic sources.
  • Beware of “special” offers. “An exclusive cure for coronavirus for $150” is usually not a reliable or trustworthy purchase opportunity.
  • Do not reuse passwords between different applications and accounts.

About the Author

Pooja Tikekar is a Feature Writer, and part of the editorial team at CISO MAG. She writes news and feature stories on cybersecurity trends.

More from the author.

 

Blur or Focus? Malicious Photo Editing Apps Target Android Devices

Mobile Apps Security, mobile apps

The threat intelligence and research team from cybersecurity firm White Ops found a new campaign of malicious photo editing apps on the Google Play Store targeting Android devices with random out-of-context ads. The researchers discovered 29 malicious Android apps in the Play Store with more than  3.5 million downloads.

ChartreuseBlur Analysis

The researchers named their investigation as “ChartreuseBlur,” since a majority of the apps used the word “blur” in their package name. The malicious apps have known to obfuscate the code and escape security detection by making its icon disappear from the device’s home screen shortly after download.

The apps have a three-stage payload evolution. In the first two stages, the app appears normal, but it reveals its malicious activities in the third phase. Once the app is downloaded, it begins attacking the device with unwanted ads.

The researchers stated that they conducted an analysis on one of the apps called Square Photo Blur and found that its features were like that of all apps. The team published a list of malicious applications and recommended users to remove them immediately, if anyone is using them.

How to Identify Malicious Apps

Researchers stated that users should reverse engineer every mobile app before installing it. Here are some questions a user can ask to help identify malicious apps:

  • Do the reviews talk about ads popping up all the time?
  • Do the reviews talk about the app disappearing or being unable to uninstall itself?
  • Do the reviews have a lot of complaints that the app does not work as advertised?
  • Are there a lot of 5-star reviews, but the recent reviews are mostly 1-star?
  • Does the app publisher have a lot of downloads in a very short amount of time?

If the answer is yes to any of the above, then it might be a bogus or malicious app.

Cyberthreats associated with Malicious Apps

Researchers from cybersecurity firm Trend Micro revealed that they have discovered three malicious apps on Google Play, which are designed to compromise victim’s devices and steal information. The three malicious apps, Camero, FileCryptManager, and CallCam, were masked as photography and file manager tools. It’s also observed that the Camero app exploits use-after-free vulnerability CVE-2019-2215 that exists in Binder, an inter-process communication system in Android. By exploiting the CVE-2019-2215 vulnerability, attackers can inject malicious codes and steal information without user knowledge.

 

CISA and NCSC Warn QNAP Users to Upgrade Firmware to Avoid QSnatch Malware Infection

WhisperGate malware campaign, Flagpro malware, MosaicLoader Malware, drinik

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the U.K.’s National Cyber Security Centre (NCSC) are investigating a data-stealing malware dubbed “QSnatch,” which is targeting Network Attached Storage (NAS) devices manufactured by QNAP (Quality Network Appliance Provider). In a joint security advisory, the agencies stated that the number of QNAP NAS devices infected with the QSnatch malware has reached 62,000 across the globe, of which 7,600 were in the U.S. and 3,900 in the U.K.

Once a device is infected with QSnatch malware, it enables hackers to prevent administrators from installing firmware updates by modifying the system’s host file, redirecting core domain names used by the NAS to local out-of-date versions. According to the advisory, all QNAP NAS devices are potentially vulnerable to QSnatch malware if not updated with the latest security updates. While it is unclear how the malware breaks into vulnerable devices, the agencies urged QNAP device users to upgrade to the latest firmware to prevent malware infection.

Locations of QNAP NAS devices infected by QSnatch are:

Image Source: CISA

“The infection vector has not been identified, but QSnatch appears to be injected into the device firmware during the infection stage, with the malicious code subsequently run within the device, compromising it. The attacker then uses a domain generation algorithm (DGA)—to establish a command and control (C2) channel that periodically generates multiple domain names for use in C2 communications,” the advisory said.

QSnatch Malware Properties

The agencies stated that QSnatch malware contains multiple properties like:

  • CGI password logger – This installs a fake version of the device admin login page, logging successful authentications and passing them to the legitimate login page
  • Credential scraper
  • SSH backdoor – This allows the attacker to execute arbitrary code on a device
  • Exfiltration
  • Webshell functionality for remote access

QSnatch Discovery

CISA and NCSC stated that they first spotted QSnatch malware in two campaigns — one in early 2014 which continued until mid-2017, and in late 2018 that was active till  late 2019. “The two campaigns are distinguished by the initial payload used as well as some differences in capabilities. This alert focuses on the second campaign as it is the most recent threat.  It is important to note that infrastructure used by the malicious cyber actors in both campaigns is not currently active, but the threat remains to unpatched devices,” the advisory added.

Malware Mitigation

CISA and NCSC recommended organizations to follow certain security measures to protect their devices against malware attacks. These include:

  • Organizations need to ensure their devices have not been previously compromised. Organizations that are still running a vulnerable version must run a full factory reset on the device prior to completing the firmware upgrade to ensure the device is not left vulnerable.
  • Verify that you purchased QNAP devices from reputable sources.
  • If sources are in question, run a full factory reset on the device prior to completing the firmware upgrade.
  • Block external connections when the device is intended to be used strictly for internal storage.

 

Good News for SecOps Teams! Mapping Cloud Threats to MITRE ATT&CK Gets Easier

cloud, cloud security

The sudden and accelerated implementation of cloud technology due to the COVID-19 pandemic can be termed as a high-risk proposition. The hurried shift towards new technologies often makes the businesses overlook the security implications and compliances associated with them. Poor configurations also create security gaps. However, cybercriminals are taking advantage of these loopholes and targeting cloud environments with customized malware, ransomware, and other types of cyberattacks.  According to  McAfee’s research, most enterprises face an average of 20 attack attempts per month on their cloud services.

Many SecOps teams leverage repeatable processes and frameworks such as ATT&CK to mitigate risk and respond to threats to their endpoints and networks, but so far cloud threats and vulnerabilities have presented an unfamiliar paradigm.

– Rajiv Gupta, Senior VP and GM, Cloud Security – McAfee

Thus, it is more essential than ever for businesses to arm their SecOps teams with a solution that enables them to manage the ‘n-number’ of security risks impacting their cloud environment. One such solution that helps the SecOps teams in mapping the cloud threats to MITRE ATT&CK, a curated knowledge base and model for noted cyber adversary behavior, is now being provided by McAfee’s MVISION Cloud.

Mapping Cloud Threats to MITRE ATT&CK

McAfee’s MVISION Cloud, a device-to-cloud cybersecurity provider has announced the integration of MITRE ATT&CK into the company’s flagship service. McAfee MVISION Cloud, also known as Cloud Access Security Broker (CASB), claims to deliver an accurate methodology to hunt, detect, and stop cyberattacks on cloud services. Being the first of its kind, this new offering from McAfee gives SecOps teams much-needed direct visibility of the source of cloud vulnerabilities and threats mapped to the tactics and techniques of ATT&CK.

Rajiv Gupta, Senior Vice President and General Manager of Cloud Security, McAfee, said, “Many SecOps teams leverage repeatable processes and frameworks such as ATT&CK to mitigate risk and respond to threats to their endpoints and networks, but so far cloud threats and vulnerabilities have presented an unfamiliar paradigm. By translating cloud threats and vulnerabilities into the common language of ATT&CK, MVISION Cloud allows security teams to extend their processes and run books to the cloud, understand and preemptively respond to cloud vulnerabilities, and improve enterprise security.”

How This Helps SecOps Teams

The ATT&CK integration with McAfee MVISION Cloud has rendered new capabilities to the SecOps teams for mitigating cloud attack risks and vulnerabilities, which include:

  • Moving from a Reactive to Proactive Approach: It allows SecOps teams to visualize not only executed threats in the ATT&CK framework, but also potential attacks that they can stop across multiple Software-as-a-Service (SaaS), Platform-as-a-Service (PaaS) and Infrastructure-as-a-Service (IaaS) environments.
  • Break Silos: SecOps teams can now bring pre-filtered cloud security incidents into their Security Information Event Management/Security Orchestration, Automation, and Response platforms via API, mapped to the same ATT&CK framework they use for device and network threat investigation.
  • Take Direct Action: Helps in fortifying Cloud Security Posture Management (CSPM) by providing security managers with cloud service configuration recommendations for SaaS, PaaS, and IaaS environments, which address specific ATT&CK adversary techniques.

With the introduction of ATT&CK into McAfee MVISION Cloud, SecOps teams will no longer be required to manually sort and map incidents to a separate framework for cloud threats and vulnerabilities, which can be cumbersome and time-consuming. It provides the security teams with a meaningful tool that enables them to automatically map all their threat incidents to a single framework and maintain a log of the cloud attacks that have been fully executed, and also the ones that are in progress. It also has the ability to combine incidents, anomalies, threats, and vulnerabilities into one holistic, familiar view.

Phishing is the Top Digital Fraud Globally: Report

Phishing Campaign on FINRA

A new research from consumer credit reporting agency TransUnion revealed that phishing is the top digital fraud across the globe related to the COVID-19 pandemic. In its research report “Consumer Financial Hardship Studies” TransUnion stated that 27% of consumers reported that they were hit with COVID-19-themed phishing scams. Nearly, 32% of respondents said they had been targeted by digital fraud related to COVID-19.

“From the impacts of phishing and other well documented COVID-19 scams like unemployment fraud, it’s clear that fraudsters have the data and increasing opportunities to create synthetic identities and utilize stolen identities. Identity fraud is a primary way fraudsters leverage stolen consumer data from phishing and other social engineering schemes. It can have long-term impacts for consumers such as the compromise of multiple online accounts and bringing down credit scores, which we anticipate will increase during pandemic reconstruction,” said Shai Cohen, Senior Vice President of Global Fraud & Identity Solutions at TransUnion.

The Top Global Online COVID-19 Scams Targeting Consumers 

Rankings

Percentage Hit by Scheme

Phishing

27%

Third-party seller scams on legitimate online retail websites

21%

Charity and fundraising scam

19%

Unemployment scam

18%

Fraudulent COVID-19 vaccines, cures, tests, and PPE

15%

Fake insurance

15%

Shipping fraud

14%

Identity theft

14%

Stolen credit card or fraudulent charges

13%

Stimulus check scam

12%

Someone changing your personal or account information via a call center

12%

Account taken over

11%

 

Online COVID-19 Scams Targeting Consumers by Country 

Country Top Fraud Type Percent Targeted by All Digital COVID-19 Fraud

Canada

Phishing

30%

Colombia

Third-party seller scams on legitimate online retail websites

25%

Hong Kong

Phishing

37%

South Africa

Unemployment scam

38%

The U.K.

Phishing

30%

The U.S.

Phishing

31%

 

The findings are based on the responses from 7,384 consumers surveyed in Canada, Colombia, Hong Kong, South Africa, the U.K., and the U.S. between June 30 and July 6, 2020.

Bala Kumar, vice president of product management, Global Fraud & Identity Solutions at TransUnion, said, “With successful phishing attacks that have increased during the pandemic, data breaches and social media sharing, consumers should assume their data is on the dark web. Despite these threats, consumers expect that organizations will protect their identities, and enable secure but still convenient digital experiences. TransUnion’s Document Verification solution provides comprehensive consumer-friendly identity verification by triangulating the validity of the document, danger of the device used to capture the document and risk associated with the identity on the document.”

 

Cybercrimes Continue to be a Growing Problem for Older Adults

Senior citizens data

Every year, cybercriminals steal approximately $40 billion from older adults (senior citizens aged 60 and over) in the U.S. Cybercrime can be defined as “any criminal activity in which a computer (or networked device) is targeted and/or used.” Cybercriminals with access to an older adult person’s information via a computer, smartphone, or other networked device, can easily exploit it for nefarious intent, defined as “an act of forcing, compelling, or exerting undue influence over a vulnerable adult causing the vulnerable adult to act in a way that is inconsistent with relevant past behavior or causing the vulnerable adult to perform services for the benefit of another.”

By Yotam Gutman, Director of Marketing, SentinelOne

The scope of bad actors targeting senior citizens can be explained by the lack of experience and skills in using computers/technology among the elderly, against the growing popularity of computer systems held by people of the same age, and the fact that most of them have credit cards.

In the past, people in their 70s and 80s hardly ever used computers. Nowadays, people of the same age have social media accounts, surf the Internet, and of course use smartphones.

Unlike their younger counterparts, seniors are less aware of cyberthreats and, in many cases, lack the tools and experience to identify attacks and fraudulent attempts. Even elderly people with no access to computers or smartphones can fall victim to cyber crimes such as in the case where their personal details have been leaked from a database and sold to criminals who can then exploit. Seniors also give bad actors the highest hit rates from phone phishing scams with frequent attempts being compromise of personal information and news of harm/captivity of the elderly’s children.

Most of the crimes against the adult population use a similar pattern as fraud against the elderly with no connection to computers (such as telemarketing of unnecessary services by highly aggressive sales reps).

The criminals will reach out to those people in a non-suspicious manner – sending a legitimate-looking email, offering to connect on Facebook or by using a legitimate website that offers them some vacation or other prize. The criminals will then try to obtain the details of those people. They will seek credit card and identification details that allow them to use these cards. Another tactic is impersonating a person in need and requesting a transfer of funds.

Recently, the FBI arrested a network of criminals impersonating other people (Captain Garcia of the U.S. military stationed in Syria, for example) who then persuaded their victims – many of whom were elderly – to transfer money to various causes, all of which were fictitious.

Another favorite method of criminals is impersonating “official” entities – government officials, municipalities and various authorities, while exploiting the trust (or innocence) of those veteran citizens and fraudulently obtaining their details.

In addition, this population is exposed to “normal” cybercrime – phishing, infection by malware and theft of personal information. The only difference is that the likelihood of this population recognizing such an attack is extremely slim, as the ability of people in this age group to understand that they have been compromised and to seek assistance is minimal. It should be noted that such attacks can also be carried out against people through their smartphones, which are very popular with this age group. These devices are usually not installed with protection software that could alert the user to malicious websites or warn them of attempts to exfiltrate personal details from the device.

What can be done?

It all starts and ends with education, but this time it is the younger generation which needs to educate their parents. We should remember the warnings they repeatedly told us when we were younger, and echo similar messages back to them, though in a slightly different way:

  • Know your friends and enemies: Research shows that the elderly are oblivious to cyber risks, so it’s worthwhile explaining to them some basic concepts and providing them with some examples of criminal or fraudulent online activities for them to learn from and avoid.
  • Do not open the door to strangers, and do not receive anything from strangers: Any communication from a party that they do not know personally should be treated with caution. It’s wise to assume all profiles on social networks are fake until proven otherwise.
  • Don’t tell anyone any personal information: Even if you are convinced that you are in contact with an official, or a real person – do not provide credit card details, residential address or social security number – certainly not by email or messenger.
  • If there is any suspicion, call “a responsible adult”: if requests are made to provide contact information, it is advisable to consult a person who is well-versed in security to see that the site is genuine. Yes, that person could be your 13-year-old grandson!
  • If something looks too good to be true, it’s probably not true: This old adage is just as true in the online world as it is in the physical world. Resist those tempting offers that pop up while browsing for weird apps that install themselves on the mobile device, and avoid those people who offer big, congested “if only” details or who to send you money.

Conclusion

Unfortunately, today’s elderly will continue to be the victims of cybercrime. This phenomenon will likely become worse before getting better as more elderly dable in technology their generation adopts digital means of payment and banking through smartphones. It will probably take years until the generation who “grew up using computers” come of age, and are immune to such scams with their decades of built-in experience and suspicion of every poor girl from Nigeria who needs a hundred dollars a month to buy dresses for school. Until then, watch out for your parents, and help guard them against those they cannot guard against themselves.

Aspen initiative for protecting older users online-
https://www.aspentechpolicyhub.org/project/protecting-older-users-online/

 

About the Author

Yotam_Gutman_Yotam Gutman is the Director of Marketing at SentinelOne. He has filled several operational, technical, and business positions at defense, HLS, Intelligence, and cybersecurity companies, and provided consulting services for numerous others. Gutman joined SentinelOne 6 months ago to oversee local marketing activities in Israel and contribute to the global content marketing team. He founded and managed the Cybersecurity Marketing Professionals Community, which includes over 300 marketing professionals from more than 170 cyber companies.

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article.

Patch Now! Hackers Exploiting Cisco’s ASA/FTD Software to Steal Data

Hackers Exploiting Cisco’s ASA/FTD Software to Steal Data

Networking and hardware company Cisco stated that it has become aware of the availability of public exploit code and active exploitation of a high-severity vulnerability in its web services interface,  Adaptive Security Appliance (ASA) and the Firepower Threat Defense (FTD) software. In a security advisory, Cisco stated that the security vulnerability dubbed as “CVE-2020-3452” could allow an unauthenticated, remote attacker to perform directory traversal attacks and steal sensitive data.

“An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device,” Cisco said.

It is found that the vulnerability affects Cisco products if they are running a vulnerable release of Cisco ASA Software or Cisco FTD Software with a vulnerable AnyConnect or WebVPN configuration. The company also confirmed that this vulnerability does not affect Cisco Firepower Management Center (FMC) Software and cannot be used to obtain access to ASA or FTD system files or underlying operating system files. The company has released software updates to fix the vulnerability.

“The attacker can view files within the web services file system only. The web services file system is enabled for the WebVPN and AnyConnect features outlined in the Vulnerable Products section of this advisory; therefore, this vulnerability does not apply to the ASA and FTD system files or underlying operating system (OS) files. The web services files that the attacker can view may have information such as WebVPN configuration, bookmarks, web cookies, partial web content, and HTTP URLs,” the advisory said.

Counterfeit Cisco Switches

Recently, an investigation report from F-Secure revealed a pair of counterfeit network switches  impersonating the  Cisco network switches.   The counterfeit devices, versions of the Cisco Catalyst 2960-X series switches, were designed to bypass authentication processes to system components. According to the investigation, the counterfeit devices did not have any backdoor functionalities, but had the ability to bypass security controls.  The counterfeits were physically and operationally similar to an authentic Cisco switch. Threat actors either invested heavily in imitating Cisco’s original design or had access to proprietary engineering documentation to create fake copy, the report said.

 

Dave’s User Database Available for Free Download on Hacking Forums

data breach

Dave, a digital banking and overdraft protection service provider, confirmed that a data breach incident compromised 7,516,625 of its user details. The leaked data includes personally identifiable information (PII) like names, email IDs, birth dates, physical addresses, and phone numbers. The investigation will be carried out in accordance with FBI’s directives.

Key Highlights of Dave Data Breach

  • The data breach took place through Waydev – a former third-party service provider for Dave.
  • 7,516,625 Dave users were affected due to the data breach.
  • The leaked information included user(s) names, email IDs, birth dates, physical addresses, and phone numbers, and passwords stored in hashed form using bcrypt.
  • No bank account or credit card numbers, records of financial transactions, or unencrypted Social Security numbers (SSN) of its users were compromised.
  • The leaked records were put on the underground forum by a threat actor popularly known as “ShinyHunters”.
  • Dave reported the incident to appropriate law enforcement authorities and is now working with the FBI for further investigations.
  • Dave also onboarded CrowdStrike, to assist in the further investigation as a cybersecurity consultant.
  • All its users will be asked to do a mandatory password reset for their accounts as a precautionary measure.

The First Traces

The leaked information first surfaced when a cybercriminal put a sale advert on an underground forum called RAID. The sale of the entire database was offered for $16,000 (i.e. approximately $470 per record). The ad was later removed, probably due to the successful sale of the leaked database. However, the same database later appeared on other forums but this time as a free download by a notorious threat actor named “ShinyHunters”. This is the same threat actor who is responsible for various other mega hacks and publishing of user records like Tokopedia, Unacademy, Wishbone, and many more.

In a blogpost, Dave informed that it had no evidence of any unauthorized actions taken with any of its user accounts or that any user had experienced any financial loss because of this incident. Dave’s security team quickly secured its systems and has been working around the clock to keep the user accounts safe.

However, this entire incident yet again highlights the limitations and dangers of not having a fully equipped third-party management system, since such data thefts can eventually lead to the downfall of any organization’s cybersecurity posture.

Check this story to know more about The Role of Third-Party Management in Cybersecurity