Home Blog Page 222

Social Media Trends Can Lead to Cyber Fraud: FBI

blockchain-based social media, Parental Consent for Minors, Iranian Facebook accounts

With no physical interactions these days, many people are sharing  their updates online through pictures, posts, and other information. Hence, the FBI has issued a warning stating that people involved in such social media trends could be making themselves vulnerable to cyber fraud and scams. In a press release, the FBI’s Charlotte office urged users to be vigilant to the information they share online. It is said that malicious threat actors could exploit the information posted by users to reset account passwords and take control of the data stored within.

“A number of trending social media topics seem like fun games, but can reveal answers to very common password retrieval security questions. Fraudsters can leverage this personal information to reset account passwords and gain access to once-protected data and accounts,” the release stated.

The FBI also cited examples wherein people are sharing  their high school photo, with information such as  the name of their schools, mascots, and graduation years — all of which are answers to common password retrieval security questions.

Other examples include:

  • Posting a picture of your first car
  • Answering questions about your best friend
  • Providing the name of your first pet
  • Identifying your first concert, favorite restaurant or favorite teacher
  • Tagging your mother, which may reveal her maiden name

Enable Multi-Factor Authentication

Apart from  encouraging people to curb the sharing of personal information online, the FBI also urged individuals to enable two-factor or multi-factor authentication when available. “Multi-factor authentication is required by some providers, but is optional for others. If given the choice, take advantage of multi-factor authentication whenever possible, but especially when accessing your most sensitive personal data — to include your primary email account, and your financial and health records,” the FBI added.

The FBI also gave similar advice on dealing with IoT devices earlier. It recommended IoT users to isolate their primary connected devices like laptops or smartphones on a separate WiFi or LAN network. “Your fridge and your laptop should not be on the same network,” the FBI said in a post.

The FBI advised to use two internet gateways. One for the devices that store sensitive data and another for digital assistants like home security devices, smartwatches, gaming systems, fitness trackers, thermostats, and smart light bulbs, etc. It also recommended changing the factory-set default passwords.

Singapore Warns Political Parties of Possible Cyberthreats and Election Interference

Election campaign

Singapore is gearing up for the general elections, which will be held in April 2021. Owing to this, the Ministry of Home Affairs (MHA), the Cyber Security Agency (CSA) of Singapore and the Elections Department (ELD), have published advisories to all the political parties about the possible threat of foreign interference in elections and the cybersecurity risks that it poses.

Foreign Interference Advisory

The advisory said that reports of foreign interferences in the elections of other countries like U.S. Presidential Elections (2016), French Presidential Elections (2017), German Federal Elections (2017), U.S. Mid-Term Elections (2018) and Italian General Elections (2018) have been recorded. Singapore is a digitally connected nation and is not completely immune to such influences by foreign actors. However, the government strongly believes that Singapore politics should be decided by Singaporeans alone. Thus, the said advisory covers information on some of the methods which foreign actors may employ to interfere in the elections, and the steps that political parties need to implement to mitigate these risks.

Political parties play an important role in safeguarding the integrity of our General Elections. They should enhance their understanding of the threat of foreign interference, and their cybersecurity posture.

MHA-CSA-ELD Advisory

Political parties play an important role in safeguarding the integrity of our GE. They should enhance their understanding of the threat of foreign interference, and their cybersecurity posture.

Cyberthreats and Cybersecurity Risks Advisory

Threat actors may launch a cyberattack towards the IT systems used by political parties and candidates during the build-up to the elections or during the elections itself as it has been seen in recent years. The advisory states that it is the responsibility of the political parties and candidates to look after their own cybersecurity posture, which includes their smartphones, computers, online and social media accounts, as well as data storage and management. However, the advisory also provides information on some of the potential cyberthreats like DDoS attack, ransomware attack, phishing, etc.

The joint statement from the three departments MHA, CSA and ELD highlighted the importance of the role these political parties play in safeguarding the integrity of the nation’s general elections. It said, “They should enhance their understanding of the threat of foreign interference, and their cybersecurity posture. They are also advised to stay vigilant by monitoring their platforms for suspicious activity and not re-share posts or tweets of suspicious provenance. Political parties and candidates should make a Police report immediately, if they detect or suspect foreign interference in elections, or if their account(s) or system(s) have been compromised or misused. They should also keep the Elections Department informed.”

Aptoide Android App Admits Data Breach; Suspends Sign-Up Option Temporarily

biggest data breaches in India,data breach, Aptoide Android App Admits Data Breach, Suspends Sign-Up Option Temporarily, Panasonic

Aptoide, a third-party app store for Android applications, recently admitted that one of its databases may have been a victim of a cyberattack and suffered a possible data breach. In an official statement, Aptoide stated that login emails and hashed passwords were leaked in the attack,  however, no personal data was compromised. “Aptoide users were never requested for physical addresses, credit card information, telephone numbers, or other personal data.” Aptoide said in a statement.

Aptoide assured that all its user passwords were encrypted. The company is evaluating the attack and has halted the sign-up option temporarily until a full audit is conducted. Aptoide also urged its users to change their credentials as a security measure.

Leaked Data Published on Hacker Forum

The Have I Been Pwned? website added Aptoide’s data breach entry stating that the app store had suffered a data breach exposing 20 million customer records in a hacker forum. It is said that data breach occurred on April 13, 2020, and published the precise number of compromised accounts as 20,012,235. Have I Been Pwned? is a website that allows internet users to check whether their personal data has been compromised by data breaches.

“In April 2020, the independent Android app store Aptoide suffered a data breach. The incident resulted in the exposure of 20M customer records which were subsequently shared online via a popular hacking forum. Impacted data included email and IP addresses, names, IP addresses and passwords stored as SHA-1 hashes without a salt,” the website said in a post.

CIRA Offers Free Cybersecurity to Health Care, Small Businesses, and NGOs in Canada

Canada Revenue Agency Shut Down Services after Cyberattacks

Essential services like health care facilities, small businesses, and non-profit organizations in Canada will be getting free cybersecurity services, until September 30, 2020, the Canadian Internet Registration Authority (CIRA) recently announced. CIRA is a non-profit organization that manages the .CA domain name registry on behalf of Canada. It also offers a suite of cybersecurity services.

CIRA is offering free access to CIRA DNS Firewall for all hospitals and health care facilities regardless of size; and free access to CIRA DNS Firewall for small businesses with 100 users or fewer. The new initiative will help the critical businesses and services in the country protect against the growing number of cyberthreats in the wake of COVID-19.

In addition, CIRA is providing access to a new free service “CIRA Canadian Shield” for all small businesses to protect their network systems and personal devices from phishing and malware attacks while working remotely. It is also allowing access to a free cybersecurity awareness training course for educational institutions, students, teachers, and remote workers who are learning and working from home.

“As health care workers work tirelessly to protect us, small businesses pivot online and teachers educate our kids from home, the value of a safe internet has never been clearer. To provide some relief to these organizations who are keeping Canada running, we are making our malware and phishing cybersecurity service free to help these impacted communities. We are also delivering some permanent solutions for Canadian households,” CIRA said in a statement.

CIRA’s technologies and services like D-Zone DNS Firewall helps support its goal of building a better online Canada.

Jacques Latour, Chief Technology Officer at CIRA, said, “Canada’s internet is holding strong against this unprecedented situation. Unfortunately, bad actors will always try to exploit a crisis. As such, CIRA is extending access to the infrastructure and tools we use to keep the .CA domain system safe to those who are helping to keep Canada running.”

Canada’s COVID-19 Cyber Defense Force

SecDev Group in Canada recently initiated a volunteer-based program wherein it called upon Canada’s top cybersecurity and IT professionals to join the COVID-19 Cyber Defense Force in order to protect the country’s key services and critical infrastructure from cyberattacks. The Group’s vision and mission are crystal clear:

  • No ransomware attack should close hospital operations
  • No cyberattacks should affect any patients’ treatment; and
  • No form of essential services should be affected by any cyberattack

SecDev Group has also collaborated with Zeropoint to provide VPN strategies and access control to governments and companies and help them adapt to cybersecurity monitoring to accommodate a workforce that is majorly working on distributed remote desktops from home.

How Startups Can Take the Affordable Route to Cybersecurity

Startup

Anyone at the helm of a startup with any presence in the digital sector has to be keenly aware (even if only subconsciously) of the vital importance of cybersecurity. High-profile data leaks and system disruptions steadily brought it into public awareness, the 2018 implantation of GDPR cast further light on how data can be misused, and the current rush to embrace remote working has heaped further pressure on cloud services.

By Stevie Nicks, Digital Editor at Just Another Magazine

Knowing that it’s necessary to protect digital systems is one thing, though: actually protecting them is another. The potential cost of investing in security services can lead entrepreneurs to question whether it’s better to leave their systems unsecured until they’ve bolstered their revenue — but that option is extremely risky.

Whether you’re in charge of arranging security for such a startup or part of a security company and looking to improve your approach to pitching, you can benefit from knowing how a small company can embrace cybersecurity while keeping the expenses down.

Let’s look at how startups can take sensible (and affordable) precautions:

They can broadly migrate to the cloud

Storing files locally can sound better to some because they fear the loss of privacy that presumably comes with online storage. Surely the best way to keep files safe is to physically protect the drives, they reason, plus it has to be cheaper to work with that relative inconvenience. That assessment is very far from the truth, obviously.

As noted, local storage is less convenient. It makes it harder to access files from afar and requires configuration. It’s also more expensive: bulk buying allows cloud storage suppliers to offer cheap rates and can offer almost no risk of drive failure causing disruption. With local storage you need to worry about the physical protection. And there’s wear and tear on the media. On the other hand, cloud storage drives get physical protection that the average company couldn’t hope to rival, and digital protection that’s top-class. The service provider maintains the physical media and bears the cost for storage expansion (buying additional hard drives). The consumer pays a fraction of the media cost for storage. For instance, you could get 1TB of storage on Google Drive/Google One for $9.99 per month. Google One (for paid plans) also offers other plans: 100GB for $1.99 and 200GB for $2.99. Compare that with the cost of a new 1 TB hard drive (approximately $45).

Cloud migration might sound expensive, but on the whole it really isn’t, particularly if you go through a reseller that can package licenses from a cloud solution distributor that has tight-knit relationships with cloud vendors and can negotiate cheaper prices.

They can cut back on systems to improve security

Regardless of whether companies operate in the cloud, locally, or are using a hybrid approach, they can easily get into the bad habit of installing myriad programs and subscribing to countless services, many of which share data through integrations. The more points of access there are, the more vulnerability there is. It’s hard to keep a castle secure when it has a hundred doors.

Due to this, startups should try to be more discerning about the systems they use. If something can be done through an entire suite instead of numerous distinct tools, it’s better for security. Just one of those tools being compromised could lead to the others being affected too. It’s the same reason why it’s ill-advised to use numerous plugins with a CMS.

At the same time, it may well be better for their finances: they might need to pay more for high-powered suites, but all the money saved on individual subscriptions could well leave their accounts better off (or at least keep their costs even).

They can start following best practices

This is the simplest and cheapest way for any company to improve its cybersecurity. No matter how secure the systems you use may be, they’re always vulnerable to human error through general indifference or incompetence. The moment you give someone access to a system, they can abuse that access, or allow someone it to be used by another (deliberately or unknowingly).

Best practices for cybersecurity are all the things people know they should do but generally don’t bother doing. Using secure passwords, changing them often, limiting admin access to those who absolutely need it, using contractual obligations and NDAs where necessary — all of these things are important, and they’re completely free to implement.

Key to this is training. Every last employee needs to be aware of how they need to proceed, and what they can and can’t do. Putting time and money into training courses (See EC-Council’s masterclasses and training programs) will be a short-term drain on resources, of course, but it’s all justified — and any startup that lacks the budget to invest in basic training has much deeper problems than cybersecurity.

Conclusion

By using cloud services where possible, using suites to minimize points of vulnerability, and following best practices, even the smallest startups can afford to make cybersecurity a priority matter. In the long run, though, the concern isn’t whether they can afford to invest in it: it’s whether they can afford not to.

About the Author

Stevie Nicks is Digital Editor at Just Another Magazine – a website that covers the topics you care about. You’ll find articles about lifestyle, travel, fashion, trends and relationships on our site – each of which is written in our unique style. 

Disclaimer 

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article.

Webroot’s Report Highlights the Need for Cyber Resilience and Security Education

Uncertain Data Sharing Practices Keep Educational Organizations at Risk: Research

The fourth annual report from Webroot on consumer security behavior across the U.S. revealed that there is a high need to adopt the best cybersecurity practices at present as more people are working remotely than ever before. The report, “A Look at 2020’s Most (and Least) Cyber-Secure States” also highlighted the continued need for greater security awareness education nationwide. Webroot, an OpenText company, partnered with Wakefield Research to conduct the survey. The survey provides insight into the consumer outlook on cyber hygiene.

The report stated that almost all (89%) Americans say they’re taking appropriate steps to protect against cyber risks, but there is a lack of understanding when it comes to cybersecurity. Almost half (49%) of Americans still use the same password across multiple accounts and only 37% keep their social media accounts private. It is also found that the majority of Americans say they are familiar with malware (78%) and phishing scams (68%), but only about a third feel confident they can explain what malware or phishing is. Around 83% of Americans use antivirus software and regularly back up their data (80%), but only 50% of them know if their backup is encrypted and only 18% back up their data online and offline.

The report recommended some basic guidelines to stay cyber resilient during the pandemic, which includes:

  • Protect devices with antivirus and a VPN
  • Keep antivirus software and other apps up to date
  • Use a secure backup program
  • Create strong, unique passwords (and do not share them) or use a password manager
  • Be extra cautious with links – hover over them to check the full URL or type the website directly into the browser

Webroot’s researchers also provided each states’ online security standards, ranks, know-how and habits and measured people’s ability to prevent attacks. Webroot security analyst Tyler Moffitt, said, “This is the fourth consecutive year we’ve seen the same high levels of consumer misunderstanding and general overconfidence when it comes to cybersecurity practices and safety. In fact, only 11% of Americans scored an ‘A’ grade on our index, and no state scored above a ‘D’. The need for better cyber hygiene and security education is clear, especially as more Americans work from home.”

The findings of the survey are based on the responses from 10,000 U.S. consumers, 200 from each state.

Cryptocurrency Worth $25 Mn Stolen in Lendf.Me and Uniswap Hacking

cryptocurrency-related cyberattacks

Cryptocurrencies have always been a primary target for cybercriminals, leading to cyber heist on cryptocurrency exchanges. Recently, $25 million worth of cryptocurrency was stolen from Uniswap exchange and the Lendf.me lending platform. The hacker took advantage of a known vulnerability that concerns the ERC777 token standard in the Ethereum blockchain technology. Experts believe that the two attacks could have been carried out by the same hacker as a similar exploit termed as a “reentrancy attack” was used in both the cases.

Lendf.Me is a decentralized lending platform that enables instant borrowing and withdrawal capabilities. Lendf.Me faced a major blow with 99.95% of funds or 24.5 million dollars being stolen. Lendf.Me is driven by the dForce Foundation, a provider of an integrated and interoperable platform of open finance protocols that runs on the DeFi stack. The attack involved the theft of imBTC, an ERC-20 token that was designed by the dForce Foundation but is now run by a separate company called Tokenlon.

The ERC-777 token standard has — to our knowledge — no security vulnerabilities. However, the combination of using ERC777 tokens and Uniswap/Lendf.Me contracts enables the reentrancy attacks.

– TokenIon

The second targeted company, Uniswap, is an independent and fully decentralized protocol-based automated liquidity provider of Ethereum cryptocurrency. UniSwap does not use DeFi stack but uses the Lendf.me protocol, which is built using the DeFi stack as well as imBTC. The losses at Uniswap are believed to be between $300,000 and $1.1 million in imBTC tokens.

According to Tokenlon, the first attack was targeted at Uniswap’s ERC777 token to perform a “reentrancy” attack. This attack exploits a function that makes an external call to another untrusted contract before it resolves any effects, allowing an attacker to take over control flow of the smart contract. To evaluate potential security risks, Tokenlon suspended the transfer of imBTC while informing users about it. The transfers resumed in a while but Lendf.me informed TokenIon of a redundant attack on their platform, which suspended the operations completely.

The proof of concept for exploiting an ERC777 token of a Uniswap exchange has been publicly made available on the GitHub platform in June 2019. The exploit details and how the exploit works has  been shared on this forum.

Uniswap and Lendf.me, both platforms operations remained suspended till the time of publish. However, according to ChainNews, the hackers in a bizarre turn of events, have returned $126,014 back to Lendf.Me with a note saying, “Better luck next time”.

Cloud Security Risks Rise During the Coronavirus Pandemic: Survey

Cloud Security Risks Rise During the Coronavirus Pandemic: Survey

As several organizations are forced to shift to work from home to curb the spread of COVID-19, IT and cloud security professionals are concerned about the security of their cloud environments, according to the “State of Cloud Security” survey conducted by Fugue.

The survey revealed that 96% of cloud engineering teams are at present 100% working from home, while  83% of them completed the transition or are still in the process. It also found that 84% (who are making the shift) are concerned about security vulnerabilities created during the swift adoption of new access policies, networks, and devices used for managing cloud infrastructure remotely. Nearly 84% of IT professionals admitted that their organization has already suffered a major cloud breach that they have yet to discover (39.7% highly concerned, 44.3% somewhat concerned). While 28% of them stated that they have already suffered a critical cloud data breach that they are aware of.

In addition, the survey also highlighted that 92% are worried that their organization is vulnerable to a major cloud misconfiguration-related data breach (47.3% highly concerned, 44.3% somewhat concerned). It is estimated that over the next year, 33% believe cloud misconfigurations will increase and 43% believe the rate of misconfiguration will stay the same. Only 24% believe cloud misconfigurations will decrease in their organization.

According to Fugue, the main causes of cloud misconfiguration are:

  • Lack of awareness of cloud security and policies (52%)
  • Lack of adequate controls and oversight (49%)
  • Too many cloud APIs and interfaces to adequately govern (43%)
  • Negligent insider behavior (32%)

Challenges in Managing Cloud Misconfiguration

  • Human error in missing critical misconfigurations (46%)
  • Human error when remediating critical misconfigurations (45%)
  • Difficulties in training team members on misconfigurations (43%)

The survey stressed that preventing cloud misconfiguration remains a challenge for cloud engineering and security teams, with 73% of them citing more than 10 incidents per day, 36% experiencing more than 100 per day, and 10% suffering more than 500 per day. It states that 3% had no idea what their misconfiguration rate is, while  73% of IT professionals rely on manual processes to defend against automated misconfiguration threats.

The survey findings are based on the responses from 300 IT, cloud, and security professionals, including DevOps engineers, cloud architects, security engineers, site reliability engineers (SREs), DevSecOps engineers, and application developers, who have hands-on experience in using Amazon Web Services, Microsoft Azure, and Google Cloud Platform for cloud computing.

65% of COVID-19 Phishing Campaigns Spread Spyware: Research

xss vulnerability in UPS, Phishing Attack, spear phishing, phishing mails

Singapore-based cybersecurity company Group-IB’s Computer Emergency Response Team (CERT-GIB) analyzed hundreds of Coronavirus-related phishing emails between February 13 and April 1, 2020. Researchers found that spyware was the most common malware class (65%) hiding in fraudulent COVID-19 emails, with AgentTesla topping the list of phishers’ favorite strains.

Spyware: The Most likely COVID-19 Phishing Campaign Payload

CERT-GIB’s report is based on the Threat Detection System (TDS) Polygon, which analyzes Coronavirus-related phishing traffic to detect both known and unknown threats in isolated environments. Most COVID-19-related phishing emails had different spyware strains embedded as attachments. However, AgentTesla (45%), NetWire (30%), and LokiBot (8%) were the most actively exploited malware families. With some minor differences, all these malware samples are designed to collect personal and financial data. They are highly efficient in mining user credentials from browsers, exfiltrating mail clients and file transfer protocol (FTP) clients, capturing screenshots, and in secretly tracking user behavior, which is further sent to the operators’ command and control (C&C) server(s).

COVID-19 phishing campaign
Source: CERT-GIB

Other Findings

  • Most of the emails detected were written in the English language. Those behind such COVID-related campaigns target government organizations and private companies.
  • The emails were masked as advisories, purchase orders, face mask offers, and alerts or safety recommendations from world bodies such as the World Health Organization (WHO), UNICEF, and other international companies such as Maersk, Pekos Valves, and CISCO.

Important: Please take note that these world bodies and international organizations are in no way involved in these fraudulent activities and/or scams.

phishing email, covid-19 phishing campaign
Source: CERT-GIB

Fig. 1. Example of a malicious email disguised as “UNICEF COVID-19 TIPS APP” with spyware in the attachment.

covid-19 phishing campaign
Source: CERT-GIB

Fig. 2. Example of a phishing email disguised as an offer of free masks.

  • Following file extensions have been used to deliver malware samples: .gz, .ace, .arj,and .rar, which are mainly archive file formats.

To trick antivirus software installed on the victim’s system, threat actors now include the passwords for accessing the content in the email subject line, in the archive name, or in a subsequent correspondence email sent to the victim. Thus, unless behavioral analytics is employed, such malware are likely to go undetected.

A single employee who opens a malicious file from an undetected phishing email could jeopardize the whole company’s operations.

– Head of CERT-GIB

Aleksandr Kalinin, Head of CERT-GIB says, “People should remain particularly vigilant now that most people are working from home due to the pandemic. We predict an increase in the number of cyberattacks on unprotected home networks used by employees who have switched to remote work. Corporate security teams should reassess their approach to securing corporate digital space by strengthening their perimeter, which now includes employees’ home devices. A single employee who opens a malicious file from an undetected phishing email could jeopardize the whole company’s operations.”

What Needs to be Done?

  • All remote employees’ email accounts and VPNs used to access corporate networks should be protected with two-factor / multi-factor authentication.
  • Implement network protection solutions to analyze incoming and outgoing e-mails traffic.
  • Employ network segmentation and role-based access (RBAC) rights to all employees.
  • Remote user activity should also be covered under the organization’s security perimeter and hence endpoint security tools need to be implemented.

Cognizant Suffers Maze Ransomware Attack; Services Disrupted

Ransomware attacks, ransomware, Sinclair Broadcast group

Information technology services provider Cognizant admitted that it is a recent victim of a ransomware attack. In an official statement, the IT giant stated that it was hit by Maze ransomware that caused service disruptions for some of its clients. It has also notified its clients and users about the attack.

“Cognizant can confirm that a security incident involving our internal systems, and causing service disruptions for some of our clients, is the result of a Maze ransomware attack. Our internal security teams, supplemented by leading cyber defense firms, are actively taking steps to contain this incident. Cognizant has also engaged with the appropriate law enforcement authorities,” Cognizant said in a statement.

Cognizant notified its clients and users about the incident and also engaged with law enforcement authorities to investigate the attack. “We are in ongoing communication with our clients and have provided them with Indicators of Compromise (IOCs) and other technical information of a defensive nature,” Cognizant added.

According to Bleeping Computer, the listed IOCs included file hashes for the kepstl32.dll, IP addresses of servers, memes.tmp, and maze.dll files. It is said that clients can use this information to monitor and secure their network systems.

The Maze ransomware operators made headlines in recent months for holding its victims’ systems and threatening to leak their information if they fail to pay the ransom. The hackers who carried out the Maze ransomware attack in the Pensacola city of Florida released two gigabytes of data files stolen before encrypting the data on the internet. Florida Department of Law Enforcement sent an official letter to the County Commissioner stating that it was a Maze ransomware attack and the hackers demanded a ransom of $1 million in order to restore all the services.

Cybercriminals Vow Not to Attack

Amid the Coronavirus pandemic, cyberattacks on the business sector have become an additional threat level and hurdle to organizations, especially for health care providers. However, on the flipside, several ransomware groups recently came forward to assure that they would hold back from attacking health organizations during the Coronavirus crisis. Lawrence Abrams from Bleeping Computer reached out to the operators of the Maze, DoppelPaymer, Ryuk, Sodinokibi/REvil, PwndLocker, and Ako Ransomware infections to find out if they would cease to target health care organizations during this time of dire crises.

Maze ransomware authors responded stating that, “We also stop all activity versus all kinds of medical organizations until the stabilization of the situation with the virus.” They also stated that if any health care organization is hit by mistake,  they would decrypt it for free.