Home Blog Page 205

Safeguarding Your Networks and Applications from the Risks of Remote Work with VPNs and RDP

remote desktop protocol (rdp)

With so many employees sheltering in place due to Coronavirus, enterprises with Windows are depending on VPNs and Microsoft’s Remote Desktop Protocol (RDP). However, while this allows employees to access company apps and files, using VPN and RDP surfaces creates other, longer-lasting problems.

By Gil Azrielant, CTO and Co-founder, Axis Security

VPNs are notoriously problematic to begin with, especially when paired with RDP’s security flaws. RDP has numerous known vulnerabilities (CVEs) registered against it. And even with patches, new vulnerabilities continue to emerge.

For an organization to thrive in this environment, they will need to adopt security measures when deploying Microsoft RDP-enabled access widely — ideally without having to constantly upgrade their servers. This is difficult when they have to provide remote access quickly, without the privilege of upgrading software.

How vulnerable is your RDP environment?

For remote workers to do their jobs, they often need to connect to remote workstations, servers or applications within the company. That’s why so many organizations with Windows computers rely on both VPNs to get on the network and Microsoft’s Remote Desktop Protocol (RDP) via the Remote Desktop Connection application to get to a particular machine.

VPN enablement can be painful for both IT and end users. In fact, VPNs can aggravate RDP’s security flaws. While many have patches available, some may not be able to receive upgrades, resulting in untold numbers of vulnerable legacy servers, which may or may not be able to receive upgrades. And even with those patches, RDP vulnerabilities continue to emerge.

Common vulnerabilities and exposures (CVEs) of RDP include BlueKeep, which allows cybercriminals to remotely take over a connected PC. We have listed relevant CVEs at the end of this post. Further, hackers continually use brute force attacks to try to obtain user credentials that have remote desktop access.

We recommend that, when using Microsoft’s RDP, organizations adopt additional security measures. Some are simply procedural. But whatever form they take, they are necessary to keep enterprise data safe.

How to alleviate RDP’s vulnerabilities?

Providing large scale urgent access while keeping users safe is not easy. But new access and security technologies make it possible without fiddling with VPNs or directly upgrading servers. A modern solution that is equipped to handle RDP’s vulnerabilities will provide a layer of security over all managed RDP servers. These solutions will analyze all user requests before they are securely forwarded to the RDP server. This protects the RDP host and its data by acting something like an RDP request broker.

This process of preventing the remote users from touching the applications effectively mitigates all those RDP-related CVE’s below, reducing the application attack surface and minimizing risk.

The most important thing to remember regarding RDP is to never put your RDP servers on the public Internet. Within minutes of public-facing RDP servers going out, they will be scanned, and then every hour numerous connection requests and exploitation attempts will take place. It is impractical that such legacy protocols can be secure on the Internet.

Other important steps that can be taken to protect against RDP vulnerabilities include:

  • Enable network level authentication (NLA)
  • Eliminate network access to the machine
  • Enforce MFA for every login
  • Focus on system patching, with virtual patching being the ideal technique for this
  • Choose and enforce a strict policy

No VPN required, Giving your access and security a boost

The risks of enabling remote access are legitimate concerns for any enterprise. Traditional mitigation techniques, such as upgrading the server operating system, can take time and have cascading consequences. But new technologies are stepping up to improve access security and minimize complexity when it comes to VPNs and server software upgrades.

Here’s a partial list of CVEs related to RDP, which can be mitigated with the right steps taken and the support of the right technologies:

CVE-2019-0708 (BlueKeep) – The exploitation requires the client to bind to a specific channel. Axis security has a whitelist of allowed channels, and the MS_T120 channel is blacklisted.

CVE-2020-0660 – Is caused by insufficient validation of requests, that allow a crafted-malformed request to be sent and crash the system. Malformed packets will never be sent from the Application Access Cloud to your servers, as it validates and disarms every request and response before sending it over.

RDP as implemented in versions of Windows, including Server 2008/12 R2, 7, 8.1, 10, are known vulnerable to exploits described:

CVE-2020-0609 – This vulnerability lies in Windows RD Gateway. We isolate your RD gateway from the internet, so no one can send malicious requests to it. Malformed packets will never be sent from the Application Access Cloud to your servers, as it validates and disarms every request and response before sending it over.

CVE-2020-0610 – This is very similar to the last one. This vulnerability lies in Windows RD Gateway. We isolate your RD gateway from the internet, so no one can send malicious requests to it. Malformed packets will never be sent from the Application Access Cloud to your servers, as it validates and disarms every request and response before sending it over.

CVE-2019-1181 – This vulnerability affects unpatched versions of Windows Server 2008-2019, and Windows 7-10. Our RDP service is not vulnerable to this vulnerability.

CVE-2019-1182 – This vulnerability affects unpatched versions of Windows Server 2008-2019, and Windows 7-10. Our RDP service is not vulnerable to this vulnerability.

CVE-2019-1222 – This vulnerability affects unpatched versions of Windows Server 2016-2019, and Windows 10. Our RDP service is not vulnerable to this vulnerability.

CVE-2019-1226 – This vulnerability affects unpatched versions of Windows Server 2016-2019, and Windows 10. Our RDP service is not vulnerable to this vulnerability.

About the Author

Gil AzrielantGil Azrielant is the Co-founder and CTO of Axis Security. He is responsible for technology strategy and the development of the company’s cloud-based zero-trust application access platform. Gil’s cybersecurity career began in the elite Unit 8200 of the Israeli Army Intelligence Corps, where he worked on advanced cybersecurity and code decryption. He served five years inside this elite unit, working as a researcher and team leader.

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article.

Open Source Software Flaws Rise by 130% in 2019: RiskSense

microsoft, flaws in SonicWall SRA SMA

A recent study by vulnerability management firm RiskSense revealed that the number of open source software (OSS) vulnerabilities increased in 2019 compared to 2018.

The study titled “The Dark Reality of Open Source” also stated that the total common vulnerabilities and exposures vulnerabilities (CVEs) reached 968 in 2019, up from 421 in 2018, a rise of 130%. It also found that it takes an average of 54 days for OSS vulnerabilities to be added to the National Vulnerability Database (NVD) after public disclosure, thereby leaving organizations exposed to critical application security risks for a long time.

Vulnerabilities in Open Source Projects

According to the study, the OSS projects that had the most number of CVEs were the Jenkins automation server (646) and MySQL (624), each of which had 15 weaponized vulnerabilities. While HashiCorp’s Vagrant only had nine CVEs. Other OSS projects that had vulnerabilities that were trending or popular in real-world attacks included Apache Tomcat, Magento, Kubernetes, Elasticsearch, and JBoss.

RiskSense also stated that cross-site scripting weaknesses are the second most common form of vulnerabilities and the most weaponized ones. In addition, the study revealed that some weaknesses like deserialization issues (28) and code injections (16) were far less common but remained popular in active attack campaigns.

Srinivas Mukkamala, CEO of RiskSense, said, “While open source code is often considered more secure than commercial software since it undergoes crowdsourced reviews to find problems, this study illustrates that OSS vulnerabilities are on the rise and may be a blindspot for many organizations. Since open source is used and reused everywhere today, when vulnerabilities are found, they can have incredibly far-reaching consequences.”

70% Of Mobile and Desktop Apps Contain Open Source Security Flaws

According to Veracode’s annual report, 70% of mobile and desktop applications that are being used today have at least one security flaw which stems from the use of open-source library. The report, “State of Software Security,” revealed that lack of awareness about where and how open-source libraries are being used are major factors in contributing toward security issues. Open-source library is free to use centralized code repositories that provide ready-made applications for developers. These libraries are not only ubiquitous but also risky, the research stressed. The research examined 351,000 external libraries in 85,000 applications and found that these libraries have several security bugs. Even a single bug can affect hundreds of applications.

 

Is There a “SNAKE” Under Honda’s Hood?

Honda, Honda Snake Ransomware attack

Although metamorphically, however, many cybersecurity experts believe that “there is a Snake under Honda’s hood”. Yes, you read it right! Operations of the Japanese automobile giant, Honda, were reportedly disrupted in parts across Europe, Japan, and the U.S. due to Snake ransomware (also known as EKANS).

A report from NBC News stated that the ransomware attack was first discovered in the late hours of Sunday night. Owing to the security crisis, the operations on certain production units of Honda in Europe was put on hold.

Honda Confirms Disruption

Honda’s spokesperson confirmed the security incident but did not exactly mention the type and motive behind the cyberattack. He said, “On Sunday, June 7, Honda experienced a disruption in its computer network that has caused a loss of connectivity. We have canceled some production today (Monday, June 8) and are currently assessing the situation. At this point, there is no effect on either Japanese production or dealer activities, and no customer impact. In Europe, we are investigating to understand the nature of any impact. We can confirm some impact in Europe and are currently investigating the exact nature.”

However, the cybersecurity company Virus Total claimed that it had certain evidence which clearly points out that Honda’s internal server has been encrypted with Snake ransomware and the cybercriminals have demanded a ransom in exchange of the encryption key. At this point, it is unclear as to how many systems were exactly being affected, but Snake ransomware operators are notoriously known to copy critical data before encrypting it for leveraging negotiations with the victim.

Earlier this year, a threat intelligence report from security firm Dragos had uncovered the Snake ransomware targeting industrial control systems (ICS). Researchers said Snake was the first of its kind file-encrypting malware customized to infect the network systems that control operations in manufacturing environments.

While investigating, researchers found a list of command processes linked to ICS operations. This disrupted the ICS processes on victims’ devices and allowed cybercriminals to deploy the ransomware and compromise the targeted devices asking them for a ransom.

Cyberattacks on Automated Vehicles Rise by 99%: Report

Cyberattacks on Automated Vehicles Rise by 99%: Report

A recent study from Uswitch, a UK-based price comparison service and switching website, stated that threat actors are constantly enhancing their attack vectors and targeting linked devices for data theft. Smart vehicles saw a 99% increase in cyberattacks  in 2019, which is seven times higher from 2018 alone. Uswitch revealed that over 67% of new cars registered in the U.K. are smart cars,  which is estimated to rise to 100% by 2026 and a market worth up to £52 billion (US$ 65.71 billion) by 2035.

According to the study, connected cars produce up to 25 GB of personal data every hour, including data about the driver, the vehicle, and passengers. It is said that a Boeing 787 jet has about 6.5 million lines of code, while a standard connected car has about 100 million lines of code.

Vulnerabilities in Connected Cars

Uswitch also found certain key vulnerabilities in connected cars that attackers can abuse to take control of the car, these include:

  • Bluetooth
  • Remote Key
  • On-Board Diagnostics (OBD)
  • Tire Pressure Monitoring System (TPMS)
  • Remote Link Type App
  • Steering and Braking ECU
  • Lighting System ECU
Image Courtesy: USWITCH

Risks of Data Theft

The study stated that connected cars collect information like location and movement information. It may also store personal data like messages, phone numbers, calls made, and financial information provided by car owners. This occurs when users sync their phones with the car’s entertainment system. This allows hackers to find vulnerabilities in the car system and steal users’ data via remote access.

Keyless Car Theft

The study also revealed that “Keyless Theft” attacks are increasing significantly. Hackers scan for the signal your key passively sends out to the car, and remotely access the car. “This approach is sometimes known as “relay theft”. Essentially, a thief can receive signals coming from your car key fob, even through windows and walls. The hardware they use tricks the car into thinking the key is nearby and unlocks the doors. The process can take as little as 10 seconds,” the report said.

Image Courtesy: USWITCH

Preventive Measures

Uswitch listed certain guidelines to protect connected cars:

  • Limit the number of devices connected to your vehicle
  • Use steering or wheel locks that can discourage car thieves
  • Keep your car’s software up to date
  • Be mindful of what apps you download – it is best to install only trustworthy applications from Google Play or the App Store
  • Wipe any personal data from your vehicle before selling it

With the number of connected cars increasing significantly, industry regulators should ensure that connected car data is both encrypted end-to-end to reduce cyber risks from third parties and monitor what data it should store.

 

“SFERS” Suffers Data Breach

credential phishing campaigns

San Francisco Employees’ Retirement System (SFERS) admitted it become a victim of a data breach that exposed information of around 74,000 beneficiaries, including names, addresses, birth dates, banking and IRS data, and other details. However, SFERS clarified that no social security numbers or bank account details were exposed in the breach. In case any member had registered at the site, it is also possible that their login name and security questions and answers may have been compromised.

According to the official statement, On February 24, 2020, an unauthorized third-party accessed its database that an SFERS vendor, 10up Inc., was using in a test environment. 10up discovered the intrusion later on March 21 and reported SFERS about the security incident on March 26, 2020.

“On March 21, 2020, 10up Inc. learned that this server had been accessed by an outside party on February 24, 2020.  The vendor promptly shut down the server and began an investigation.  The vendor found no evidence that the information of SFERS members was removed from its server, but at this time, it cannot confirm that the information was not viewed or copied by an unauthorized party.  On March 26, 2020, the vendor notified SFERS of the server breach and both SFERS and the vendor continue to investigate the potential exposure of data,” the breach notification said.

SFERS stated that it is going to offer all the affected members a complimentary one-year membership of Experian’s credit monitoring service. The organization also urged the members to monitor their credit history and bank accounts for any authorized transactions, as the exposed information can be used in phishing attacks.

Risks with Exposed Data

Cybercriminals make use of the stolen data in credential stuffing attacks. In credential stuffing attack, a hacker tries to log into various user accounts with known email and password combinations. Attackers take advantage of the fact that most people reuse email ids and passwords for multiple accounts. Once hackers gain access to an account, they try hacking other accounts by changing password combinations. The compromised accounts are used for a variety of purposes including spam, phishing, fraud, identity theft attacks, and selling on darknet forums.

 

Remote Workforce in APAC Region Not Fully Secure: Report

Data Breach at CDSL

The COVID-19 outbreak forced organizations globally to work remotely, while cybersecurity risks increased exponentially as threat actors prey on fear and disinformation to launch cyberattacks.

According to CrowdStrike’s “2020 Work Security Index” survey, around 54% of employees working at home believe their organizations are likely to suffer a cyberattack during the COVID-19 pandemic. The study surveyed 4,048 senior decision-makers globally including 1,780 from four Asia-Pacific markets– 252 from Singapore, 526 in India, 502 from Japan, and 500 in Australia.

The survey found a 100x increase in COVID-19 themed malicious attacks from February to March 2020 alone. Around 30% of SMBs surveyed believe that cyberattacks are more likely to occur during the COVID- 19 situation than before; 30% of them stated they are less likely to use company-provided devices to work from home compared to large companies (68%).  Nearly 73% of senior business decision-makers surveyed admit that they are using personal devices to work from home.

In India, 9 out of 10 security leaders surveyed believe that the devices they use at home are secure from advanced cybersecurity threats. Nearly 61% of Indian business leaders surveyed think their business is more likely to suffer a cyberattack during the current crisis, while 45% of them opposed it. According to the survey, 72% of respondents are using personal devices like laptops and mobile devices, to do their jobs in India, while 93% use a mix of company-issued and personal devices. 62% of organizations in India stated that they provided additional security training for their employees to avoid threats while working from home.

CrowdStrike also recommended certain guidelines to improve remote workers cybersecurity, which include:

  • Update your current cybersecurity policy to include remote working
  • Implement a secure access plan for BYOD on corporate networks
  • Prepare for sensitive data being accessed via unsecured networks
  • Maintain cybersecurity hygiene and comprehensive visibility into endpoints
  • Continue cybersecurity training as coronavirus-themed scams escalate
  • Prepare crisis management and incident response plans to be executable by a remote workforce

Remote Working Threatens Business Operations

A similar study from HiveIO revealed the impact of COVID-19 on corporate data security. It highlighted the effect of the new virtual economy on security professionals and organizations across a wide variety of industry verticals. Nearly 85% of organizations anticipate a larger remote workforce will threaten operations because of new risks. The study stated that several organizations are unable to introduce new security solutions designed to improve the efficiency of work-from-home employees. Around 70% of respondents admitted that they have suffered increased costs due to the ongoing pandemic. Nearly 25% of respondents reported shrinking staff support and another 18% fear additional staff reductions.

 

Coinsquare Data Theft Flags Insider Threat Issue

Insider Threats

Coinsquare, a Canadian crypto exchange that enables its users to trade Bitcoin, Ethereum, and other cryptocurrencies, confirmed that its customer information was stolen by an ex-employee last year. Cybercriminals laid their hands on this data and are now reportedly going to carry out SIM swapping attacks.

According to Stacey Hoisak, Coinsquare’s general counsel, the data theft took place a year ago by a now ex-employee of the company from the Customer Service system. They had notified the law enforcement and data protection authorities concerned, as well as all known impacted users at the time as soon as the data theft was detected.

As per Vice Media’s interview with an anonymous hacker, the cybercriminals want to “embarrass the company (Coinsquare) for claiming they were the most secure Canadian exchange on their website.” Initially, they thought of selling or auctioning this data which includes CoinSquare clients’ email addresses, phone numbers, and physical addresses. However, they later thought of using it in SIM swapping attacks as it would bring them additional monetary benefits.

Since the data theft, Coinsquare has streamlined and introduced sophisticated internal controls to avoid insider threats. They have also re-written their older data management policies and changed their customer management systems for an increased level of protection.

Insider Threat: A Rising Concern

A recent survey report “2020 Cost of Insider Threats: Global Report” from the Ponemon Institute revealed that insider threats increased by 47% from 3,200 in 2018 to 4,716 in 2020. It also revealed that the cost of insider threat incidents surged by 31% from $8.76 million in 2018 to $11.45 million in 2020.

According to the survey, negligent employees are responsible for around 62% of security incidents, costing organizations an average of $307,111 per incident. The fastest-growing industries for insider threats are the retail sector (38.2% two-year increase) and the financial services sector (20.3% two-year increase). It takes 77 days for a company to contain each insider threat incident, and only 13% of the analyzed security incidents were contained in less than 30 days, the report stated.

8 in 10 Australian Companies Say Cybersecurity Investments Fail

Cryptocurrency scams in Australia

A new research from Accenture revealed that 80% of companies in Australia believe that their cybersecurity investments are failing. The research also reported a 50% increase in security incidents in Australia from 2018 to 2019.

According to the survey, nearly 91% of respondents admitted that their organizations are spending more than 20% of the cybersecurity budgets on advanced security technologies to bolster their cyber resilience.

Around 70% of organizations stated that staying ahead of attackers is a constant battle. The survey also revealed that the security costs incurred to strengthen cyber resilience are skyrocketing, with 43% of organizations reported their expenditure increased within their cybersecurity space in the last 24 months, and 11% recorded costs rising more than 25% in the same period. Only 43% of respondents stated that they are actively protected by their security programs, while 90% of all breaches in Australia lasted more than 24 hours.

Other Key Findings Include:

  • More than half (58%) of breaches in Australian companies are identified by the security team
  • 38% of security breaches at Australian organizations are indirect attacks that target weak links in the supply chain
  • 38% of breaches have no impact on organizations
  • Almost three-quarters (71%) of breaches were fixed in less than 15 days

The research findings are based on the responses of 373 security leaders in various Australian companies.

Joseph Failla, Security Lead, Accenture Australia and New Zealand, said, “Now, more than ever, cybersecurity is an increasing challenge for Australian organizations, as the prevalence of sophisticated and insidious cyberattacks continues to grow. Organizations are grappling with the new and sudden reality of COVID-19 which is putting even greater strain on their already under-pressure security systems.”

“Using threat intelligence and more strategic approaches to cybersecurity can help Australian organizations stay protected and better equipped to respond effectively when the enemy strikes. By becoming more resilient and agile, businesses will be able to grow confidently through this turbulent time,” Failla added.

Australia Ranked World’s 15th Secure Country

A study on global comparison of cybersecurity defenses ranked Australia as the world’s 15th secure country. According to the security research firm Comparitech, Australia climbed 12 positions in its latest cybersecurity ranking report. The study evaluated 76 countries’ exposure to security vulnerabilities to find which countries are well prepared for cyberattacks. Comparitech stated that it found improvement in Australia’s cybersecurity readiness with an overall score of 13.95 when compared to the previous year’s 16.34 (lower scores represent better ranking). The scores are based on the indicators of compromise like the percentage of mobiles infected with malware, the frequency of financial malware attacks, and the number of computers infected with viruses in a country.

 

Beware of these “fleeceware” VPN apps on Apple App Store

Beware of these “fleeceware” VPN apps on Apple App Store, SonicWall hacked

Avast, a maker of digital security and privacy products, has discovered and reported three fleeceware apps to Apple’s App Store, which overcharge users, do not provide the services they promote and appear to be “fleeceware”. The apps are available on the Apple App Store as Beetle VPN, Buckler VPN, and Hat VPN Pro, and according to data from Sensor Tower, a mobile apps marketing intelligence and insights company, the apps have been downloaded over 420K, 271K, and 96K times, respectively, between April 2019 and May 2020.

How to identify Fleeceware

Fleeceware” has a characteristic of overcharging users for functionality that is widely available in free or low-cost apps.

Fleeceware apps can come in any category. The reviews for fleeceware apps tend to look fake, with multiple users leaving a review like “Exciting” or “My love”, and real reviews reveal the app does not actually work, or unknowingly charge users large sums of money. Fleeceware apps typically offer a free, three to seven day trial, but can require users to enter their payment information before the trial begins, and automatically charge users unreasonable sums of money after the trial ends.

Users should carefully note what happens after an app’s trial period ends and how much an app will charge after a free trial period, to check if the charge will be automatically deducted from their card on an ongoing basis unless they cancel the subscription.

What Avast researchers observed

The apps claim to be VPN apps, charging $9.99 (USD) a week for a weekly subscription once their free three-day trial expires. The apps all have high ratings, ranging from 4.6 to 4.8, and include enthusiastic reviews, all similarly written, which Avast thinks could potentially be fake. In between the rave reviews, there are a few reviews warning of the scams. The apps’ privacy policies also have very similar language and structure.

Avast researchers installed the three apps and successfully purchased subscriptions to each app; however, when they tried to use the VPNs, the apps only provided subscription options again. After attempting to purchase the subscriptions again, Avast researchers were notified they already have a subscription and thus were unable to establish a VPN connection using any of the apps.

“Fleeceware apps fall into a gray area, because they are not malicious per se, they simply charge users absurd amounts of money for weekly, monthly or yearly subscriptions for features that should be offered at much lower costs. In this case, the VPNs are being sold for $9.99 (USD) a week, when trustworthy VPNs cost ten times less,” said Nikolaos Chrysaidos, Head of Mobile Threats & Security at Avast. “These apps are not behaving maliciously so they circumvent screening processes to be added to the official app stores’ that users trust. With many people turning to VPN apps to protect their data while working remotely, this illustrates how important it is for users to research VPN apps before installing them, including who is behind the product, their track record with other products and user reviews, and experience in offering security and privacy apps.”

You can read the privacy policies of these apps here:

Buckler VPN: https://bucklervpn.com/policy.html

Hat VPN: https://hatvpnpro.com/data-policy.html

Beetle VPN: https://beetlevpn.com/data-policy.html