Home Blog Page 236

NULLCON Stresses Need for International Cooperation to Mitigate New Threat Vectors

NULLCON 2020

The first day of the NULLCON International Security Conference 2020 here in Goa, India (5 – 6 March), saw many young security enthusiasts, consultants, solution providers, speakers, and business leaders. Welcoming the delegates, Antriksh Shah, co-founder of NULLCON said they received 2,500 registrations for the event, but there were many cancellations due to the Coronavirus pandemic. But as they say, the show must go on. “The content of the conference will not be diluted,” said Shah. There were many international speakers and security researchers who attended, notwithstanding the travel advisories issued by their respective countries. The organizers took adequate measures to ensure the safety of the delegates, handing out face masks, hand sanitizers and providing medical facilities. The conference, now in its eleventh year, has become one of the biggest cybersecurity conferences in Asia. It is a big draw for students who aspire to make a career in cybersecurity.

By Brian Pereira, Principal Editor, CISO MAG

Satish Chandra Jha, Chairman of India’s NTRO
Satish Chandra Jha, Chairman of India’s NTRO

The chief guest was Satish Chandra Jha, Chairman of India’s NTRO (National Technical Research Organization). In his opening speech, Jha said, “India has a large IT footprint in the Internet domain. India has about 500 mn Internet users and over 1.5 bn IoT devices. All this fuels economic growth and creates new commercial opportunities. It also presents a challenge of securing cyberspace. Cybersecurity and some of the recent attacks like Stuxnet are serious. Cyberthreat vectors are becoming sophisticated and targeting infrastructure that supports essential services like Power & Energy, Banking & Finance, Transport, Information, and Telecommunications. And if these systems are impacted it will paralyze the nation. These sophisticated attacks outpaces our response.”

Jha said there is little coordination among nations to contain these sophisticated attacks. He cited industry data points to quantify the impact of the attacks and the opportunities for startups and cybersecurity professionals.

“Organizations are spending US$120 billion annually on cyber initiatives. Of this, India is expected to spend US$25 bn. This presents a great opportunity for young cybersecurity professionals, startups, and micro, small and medium enterprises to showcase their expertise,” said Jha.

Global estimates indicate the loss due to cyber incidents is around US$5 – 6 trillion, annually. This does not include loss due to disruption of business impact on the reputation of the company.

“We have a collective responsibility to ensure that the attacks do not impact Digital India initiatives or impede our efforts to be a US$5 trillion economy by 2025,” said Jha.

Conference tracks

NULLCON 2020
Lots of students and youngsters could be seen participating in CTFs at NULLCON

The conference had two days of research talks, workshops, panel discussions, dedicated tracks (StartVille, macOS/iOS), hacker talks, CTFs (Capture The Flag), and specially designated sessions like Resume Clinic, Red Team Village, and Soldering Village. In addition, there was an exhibition area (titled AMMO) showcasing the latest security tools.

Lots of students and youngsters could be seen participating in CTFs like SCADA CTF (a live demo of attacks against PLCs (programmable logic controllers) and RTUs (remote telemetry units). These are hacking competitions with team participation.

NULLCON 2020
IMAGE CREDIT: Brian Pereira

CISO MAG asked Siddhartha Malladi, a second-year undergraduate student why he was participating in the Hardware CTF and what brings him to NULLCON every year.

“This is the second time I am attending NULLCON. I am amazed at all the talks especially those given by the international speakers. This year I am playing in the Hardware CTF since I have a background in electronics and communications engineering. We are team of six students and have come here to meet like-minded people and build our network. Right now, our team is in the seventh position in this competition. We are keen to attend the StartVille (startup track) but we have to be here to participate in the competition,” said an elated Malladi.

The CXO track had some engaging panel discussions with the participation of CXOs from organizations like Bharti Airtel, Adani Group, OLAM International, PayPal, E&Y, NTRO and others.

Speaking to CISO MAG on the sidelines of the event, Venkatesh Subramaniam, Global CISO, OLAM Information Services Pvt. Ltd, said, “I am here in the capacity of a speaker. But I come to NULLCON to network with my peers. It’s also for the technical learning. Events like NULLCON give me an opportunity to understand what my peers are doing and what is happening in their organizations. The platform enables a good informal exchange of information. We discuss each other’s pain points. And we also get an update on where the industry is heading.”

In conclusion, we must mention that NULLCON is an event not to be missed if you are a cybersecurity professional or want to make a career in cybersecurity. There are also recruitment and internship opportunities as the participating startup companies use this event to source talent. There are exciting hacking competitions and bug bounty programs to pursue as well.

It was well worth the three days we spent here, with plenty of networking opportunities and a lot of learning.

Brian Pereira was hosted by NULLCON in Goa for this conference.

Google Fixes MediaTek Rootkit Vulnerability

Google Cybersecurity Action Team Google, EU warns Google

After almost a year since its discovery, a critical vulnerability affecting millions of Android devices using MediaTek chips (now tracked as CVE-2020-0069) has been finally fixed by Google. The issue was first reported on the XDA forum, one of the largest forums for Android software modifications, back in April 2019.

The MediaTek Vulnerability

The Amazon Fire tablets are heavily guarded, and the tablet manufacturer does not provide an official method to unlock the bootloader of Fire tablets. The only way to root the Fire tablet without hardware modifications is to find a loophole in the software itself that bypasses Android’s security model. An active member of the forum did just that and hit the bull’s eye only to discover that the exploit had a greater outreach and not just limited to the Amazon Fire Tablet.

The exploit was successfully tested on all MediaTek 64-bit chipsets used in several devices including   Motorola, OPPO, Sony, Alcatel, Amazon, ASUS, Blackview, Realme, Xiaomi, and more. On gaining root shell access and privileges, an attacker can install a malicious application on the device and have unrestricted access to all the files including private data directories.

This was a grave concern and thus reported to MediaTek immediately. However, XDA states that although MediaTek released a security patch to fix the issue in a month’s time, it was continued to be exploited in the wild by many hacking groups until recently.

Google’s Helping Hand

Failing to fix the issue and considering the high severity of it, in February 2020, MediaTek turned to Google for a helping hand. Google’s engineers obliged as it also affected its flagship Android mobile device brand – Pixel. On March 3, 2020, Google released an Android Security Bulletin for March 2020 in which it announced the fixture of over 70 various issues affecting its Android devices including CVE-2020-0069.

Earlier in 2019, Google’s security researchers discovered that an iPhone could be turned into a surveillance tool exposing a victim’s sensitive information including contacts, Live Location, chat history, emails, photos, and passwords. A total of fourteen vulnerabilities spread across five exploit chains: seven for the iPhone’s web browser, five for the kernel and two separate sandbox escapes were discovered and later fixed.

Virgin Media Data Breach Affects 900,000 Customers’ Data

Data breach in 100 U.S. cities

Virgin Media, a provider of telephone, television, and internet services in the U.K., revealed that it discovered an unsecured database that exposed the personal information of around 900,000 customers, which is 15% of the company’s entire customer base. The leaked database was taken down immediately and is now password protected.

According to the Virgin Media release, the exposed information includes names, home addresses, emails, phone numbers, and product information. The incident response team at Virgin Media stated that the database was used for marketing activities and did not contain sensitive information like passwords, credit/debit card numbers, and other financial details.

The company stated it already notified the Information Commissioner’s Office, the U.K.’s data protection watchdog, for further investigation on the security incident. It also warned the affected customers to be vary of phishing attacks.

Lutz Schuler, CEO of Virgin Media, said, “Protecting our customers’ data is a top priority and we sincerely apologize. The database did not include any passwords or financial details, such as credit card information or bank account numbers, but did contain limited contact information such as names, home and email addresses and phone numbers. Based upon our investigation, Virgin Media does believe that the database was accessed on at least one occasion but we do not know the extent of the access or if any information was actually used.”

“We are now contacting those affected to inform them of what happened. We urge people to remain cautious before clicking on an unknown link or giving any details to an unverified or unknown party,” Schuler added.

Private Information of British Citizens Exposed Online

In a similar database leak incident, an unprotected AWS (Amazon Webservices) S3 database that contained personal information of British citizens was discovered by security researchers Noam Rotem and Ran Locar of the security firm vpnMentor. It included passport scans, tax documents job applications, background checks, expense forms, scanned contracts complete with signatures, salary information, emails and more.

Researchers found no security protection on this AWS database, also known as bucket, and thus were able to see all the files stored in it. The files contained a wide range of Personally Identifiable Information (PII), including names, addresses, phone numbers, dates of birth, gender, national insurance number–in short, everything that a threat actor requires to complete identity theft, fraud, or any cyberattack targeted towards the user or against him.

More Than Half Global Healthcare Organizations Suffered a Cyberattack Last Year

Healthcare Data Breaches, Premier Diagnostics data exposed

Cybersecurity firm Keeper Security revealed that nearly two-thirds of global healthcare organizations suffered a cyberattack in their lifetime, while 53% were attacked within the last 12 months. Keeper, in its report “2019 Global State of Cybersecurity in Small and Medium-Sized Businesses”, revealed that data breaches in healthcare resulted in an average of 7,202 patient and employee records lost or stolen. The most commonly reported types of attacks were phishing (68%), malware (41%) and web-based attacks (40%), according to the report.

Keeper Security provides cybersecurity platform for enterprises to prevent password-related data breaches and cyberthreats. The findings are based on the responses from 2,391 IT security practitioners in the U.S., U.K., and regions like DACH, Benelux and Scandinavia. The respondents also indicated they lack security resources to defend themselves from cyberattacks. Only one-third of healthcare organizations believe they have sufficient budget to support strong IT security and 87% said they don’t have the personnel needed to achieve a more effective cybersecurity posture.

Other highlights from the report include:

  • 66% of healthcare providers agree that passwords are an important part of cybersecurity prevention, yet over half don’t have visibility into their employees’ password practices
  • Less than half of those surveyed have a plan for responding to an attack
  • 90% of healthcare organizations dedicate less than 20% of their IT budget to cybersecurity, with an average allocation of 13%

Darren Guccione, CEO and Co-Founder of Keeper Security, said, “Electronic health records are some of the most lucrative documents on the dark web, so it’s not surprising that the healthcare industry is highly-targeted by cybercriminals. While the majority of healthcare organizations have already experienced a cyberattack, this research shows the industry still doesn’t have the necessary resources and budget allocated to preventing and responding to major data breaches. Patients depend on providers to protect their sensitive health information and moreover, their lives via connected medical devices. Therefore, it’s critical that cybersecurity become a top priority in healthcare.”

Mellanox Acquires Titan IC to Boost its Security and Data Analytics Platform

U.S. and Australia to Jointly Develop Cyber Training Platform

Israel-based chipmaker and connectivity firm Mellanox Technologies acquired Belfast-based network intelligence and security technology firm Titan IC to strengthen its capabilities in security and data analytics platform. As per the acquisition, the two companies will work on cyber intelligence, intrusion detection and protection, and advanced data analytics.

Mellanox Technologies is a supplier of end-to-end smart security solutions for data center servers and storage systems. The latest acquisition will improve Mellanox’s network intelligence capabilities delivered through the company’s advanced ConnectX and BlueField families of SmartNIC and I/O Processing Unit (IPU) solutions. Titan IC provides real-time internet traffic inspection for advanced cybersecurity and data analytics applications. With the acquisition, Titan IC will become the Mellanox center for advanced network intelligence research and development.

Speaking on the latest acquisition deal, Eyal Waldman, President and CEO, Mellanox Technologies, said, “Network Intelligence is an important technology when combined with our industry-leading networking portfolio of switches, SmartNICs, and IPUs. Our customers will benefit from the deep analytics and enhanced security that will be delivered by the integration of our best-in-class Ethernet and InfiniBand products and world-leading deep packet inspection and analytics technologies from Titan IC. With this acquisition, our M&A investments total more than 1.2 billion dollars to date and more than 53 million dollars invested in startups to further our intelligent networking strategy.”

“We have worked with Mellanox for many years to integrate our RXP regular expression processor into their advanced line of BlueField I/O Processing Units (IPUs). Now as part of Mellanox, we will be able to achieve new capabilities for cyber intelligence, intrusion detection and protection, and advanced data analytics applications,” said Noel McKenna, CEO, Titan IC.

McAfee Report Predicts 2020 to be Year of Mobile Sneak Attacks

Malware and Vulnerability Trends Report, Mobile malware threats

McAfee released its Mobile Threat Report 2020, which found that hackers are using hidden mobile apps, third-party login and counterfeit gaming videos to target consumers. Last year, hackers targeted consumers with a wide variety of methods, from backdoors to mining cryptocurrencies. Based on new research, McAfee has uncovered that hackers have expanded the ways of hiding their attacks, making them increasingly difficult to identify and remove, which makes it seem like 2020 will be the year of mobile sneak attacks.

The highlights of the report are:
  • Hidden mobile apps result in approximately 50% of all malicious threats in 2019
  • Hidden apps are the most active mobile threat category, generating almost half of all malicious telemetry, a 30% increase from 2018
  • New mobile malware uses third-party sign-on to cheat app ranking
  • A unique approach to steal sensitive data through legitimate transit app
  • Hackers use gaming popularity to spoof consumers
  • LeifAccess tricks victims into enabling risky settings using fake security warnings to perform unwanted automated actions

McAfee found that hidden apps are the most active mobile threat facing consumers, generating nearly 50% of all malicious activities in 2019–a 30% increase from 2018. Hackers continue to target consumers through channels that they spend the most time on–their devices, as the average person globally is expected to own 15 connected devices by 2030. Hidden apps take advantage of unsuspecting consumers in multiple ways, including taking advantage of consumers using third-party login services or serving unwanted ads.

“Mobile devices hold the key to our lives–both corporate and personal. Unfortunately, they are also amongst the easiest attack vectors for cybercriminals because, consumer awareness levels towards the security of their devices and apps are low. Hidden apps have emerged as the most active mobile threat category and it’s highly advisable consumers stay vigilant with regards to where they download applications from, what they click on and also ensure they use the right security software on their devices–to enable detection and protection of their digital lives,” said Venkat Krishnapur, Vice-President of Engineering and Managing Director, McAfee India.

The McAfee Mobile Threat Report 2020 highlights the following mobile trends:
  • Hackers use gaming popularity to spoof consumers – Hackers are taking advantage of the popularity of gaming by distributing their malicious apps via links in popular gamer chat apps and cheat videos, by creating their own content containing links to fake apps. These apps masquerade as genuine ones with icons that closely mimic those of the real apps but serve unwanted ads and collect user data. McAfee researchers uncovered that popular apps like FaceApp, Spotify, and Call of Duty all have fake versions trying to prey on unsuspecting consumers, especially younger users.
  • New mobile malware uses third-party sign-on to cheat app ranking systems – McAfee researchers have uncovered new information on mobile malware dubbed LeifAccess, also known as Shopper. This malware takes advantage of the accessibility features in Android to create accounts, download apps, and post reviews using names and emails configured on the victim’s device. McAfee researchers observed apps based on LeifAccess being distributed via social media, gaming platforms, malvertising, and gamer chat apps. Fake warnings are used to get the user to activate accessibility services, enabling the full range of the malware’s capabilities.
  • A unique approach to steal sensitive data through a legitimate transit app. McAfee researchers found that a series of South Korean transit apps, were compromised with a fake library and plugin that could exfiltrate confidential files, called MalBus. The attack was hidden in a legitimate South Korean transit app by hacking the original developer’s Google Play account. The series provides a range of information for each region of South Korea, such as bus stop locations, route maps, and schedule times for more than 5 years. MalBus represents a different attack method as hackers went after the account of a legitimate developer of a popular app with a solid reputation.

“There exists a growing trend for many apps to remain hidden, stealing precious resources and important data from the device that acts as the remote control to consumers digital world,” said Raj Samani, McAfee Fellow and Chief Scientist. “Now, more than ever, it is critical consumers make themselves aware of modern threats and the steps they can take to defend themselves against them, such as staying on legitimate app stores and reading reviews carefully.”

BAE Systems Obtain Five-Year Contract for U.S. Navy’s AEGIS Combat System

Cyber war

BAE Systems, a British multinational defense, security, and aerospace company, awarded a five-year US$188.2 million contracts to provide the U.S. Navy’s AEGIS Technical Representative (AEGIS TECHREP) organization with critical large-scale system engineering, cybersecurity solutions, and testing expertise for the AEGIS Weapons and Combat Systems. The company also offers security solutions, testing, evaluation personnel to provide fleet experience and operational insight, logistics, production, acquisition, and waterfront support required for upgrading and maintaining the development of AEGIS Combat System capabilities.

Mark Keeler, vice president and general manager of BAE Systems’ Integrated Defense Solutions business, said, “BAE Systems personnel have worked side-by-side with Navy sailors and civilians for nearly 40 years to strengthen and modernize the fleet of AEGIS-equipped surface ships. Our team brings a wealth of AEGIS combat system expertise with the agility, innovation, and technical acumen to ensure the U.S. Navy has the safe and effective combat capability it needs to meet mission objectives.”

U.K. Invests in Revolutionary Artificial Intelligence Warships

With an aim to help warship crews make quick decisions and process data efficiently, the U.K.’s Ministry of Defense recently announced contracts to use AI-based technology in warships. According to a source, Defense and Security Accelerator (DASA) will be funding £1 million (around US$1.3 million) for AI contracts as part of its “Intelligent Ship – The Next Generation” competition, which is aimed at using innovative approaches for Human-AI and AI-AI teaming for various defense platforms like warships, aircraft, and land vehicles.

DASA’s warship competition, in alliance with the Defense Science and Technology Laboratory (Dstl), is intended to enhance the designs of future defense platforms by using advances in automation, autonomy, machine learning, and AI.

James Heappey, U.K.’s Defense Minister, said, “The astonishing pace at which global threats are evolving requires new approaches and fresh thinking to the way we develop our ideas and technology. The funding will research pioneering projects into how AI and automation can support our armed forces in their essential day-to-day work.”

McAfee Acquires Browser Isolation Firm Light Point Security

McAfee Acquires Browser Isolation Firm Light Point Security

Device-to-cloud cybersecurity company McAfee recently entered into a definitive agreement to acquire browser isolation company Light Point Security. As per the acquisition deal, employees of Light Point Security will join McAfee.

Founded by former NSA employees, Light Point Security protects users from zero-day and other emerging malware like ransomware and credential phishing attacks by isolating browser sessions in a remote virtual environment outside of the corporate network. The acquisition integrates Light Point Security’s browser isolation technology with McAfee Secure Web Gateway for inbound and outbound protection for all web and cloud traffic. Additionally, McAfee stated that it’s going to integrate browser isolation into its newly released MVISION UCE solution, which includes McAfee Secure Web Gateway, McAfee Data Loss Prevention, and MVISION Cloud (CASB) to enable a complete implementation of the SASE Architecture.

Ash Kulkarni, EVP and Chief Product Officer at McAfee, said, “Web browsing is one of the most common threat vectors for endpoints to get infected. Adding Light Point Security’s capabilities into our products will create solutions that enable our customers to mitigate web-based threats without impacting user experience. We are constantly working to find ways to help our customers safely adopt the cloud so they enjoy increased productivity without experiencing heightened concerns about cyber-attacks. Light Point Security’s browser isolation capabilities will bolster the McAfee Unified Cloud Edge offering to make it a preferred solution for security-focused businesses without compromising on productivity.”

Commenting on the acquisition, Zuly Gonzalez, co-founder and CEO of Light Point Security, said, “Light Point Security’s technology enables users to browse any website safely, securely and without limitations, without having to keep up with website changes. This stops attacks launched against a web browser before they can even enter the network without hampering user experience. We’ve been recognized for revolutionizing the way that organizations think about security; now we will be joining a leading standalone cybersecurity player to be part of the next revolution.”

McAfee Appoints New Chief Executive Officer

McAfee, appointed Peter Leav as the new Chief Executive Officer, effective from February 3, 2020. Leav had previously served as President and CEO of BMC Software. He holds more than 20 years of executive leadership experience in large-scale technology companies like NCR Corporation, Symbol Technologies, Cisco Systems, Proofpoint, and Motorola.

Apart from addition to leadership roles, McAfee also forged multiple partnerships. The company acquired NanoSec, a container security startup, to improve its compliance and to mitigate the risk of its container deployments. NanoSec is a multi-cloud and zero-trust application security platform that’s focused on the container approach to application security. The acquisition will allow McAfee to boost its MVISION Cloud and MVISION Server Protection products.

UK ICO Fines Cathay Pacific with £500,000 for 2018 Data Breach

Cathay Pacific

UK’s Information Commissioner’s Office (ICO) has found Hong Kong-based air carrier Cathay Pacific guilty on various counts of data breach reported by the latter in 2018. Owing to this, Cathay Pacific has been asked to pay a data breach fine of £500,000 (approx. US$640,000) by March 13, 2020.

Cathay Pacific Data Breach

Cathay Pacific collects and stores flyers’ data including their names, passport numbers, contact details, date of birth and nationalities for official use. Additionally, they also store information of its frequent flyer loyalty program that includes membership numbers, previous travel and customer support interaction information.

Cathay Pacific discovered the data breach in March 2018 when one of its database was targeted with a brute force attack. It immediately assigned a cybersecurity firm to investigate into the cyberattack. While investigating the root cause and the threat actors involved in the brute force attack, the cyber forensic experts subsequently unearthed a much greater data breach.

According to the ICO’s report, between October 15, 2014 and May 11, 2018, Cathay Pacific’s computer systems didn’t have adequate security measures. This led to the compromise of approximately 9.4 million worldwide customers’ personal details of which 111,578 were from the U.K.

The air carrier officially reported the data breach episode to the IOC only on October 25, 2018, after analyzing the compromised data and the extent of the breach. Meanwhile, it also set up customer care services and precise and accurate notifications for every individual telling them of exactly what data was leaked.

IOC’s Verdict

IOC said that the breach affected Cathay Pacific’s four databases: customer database, membership details database, web applications’ back-end database and transient database used by Asia Miles members for award points redemption. After analyzing all these breaches and their corresponding causes, the commissioner found Cathay Pacific violating the Data Protection Principle (DPP7) on multiple counts. These include unencrypted database backups, security patches were not applied to known server vulnerabilities, unrestricted admin-level access through public internet, an unsupported operating system on one of the compromised server/systems, lack of two-factor/multi-factor authentication (2FA/MFA), and inadequate penetration testing, among others.

Although the £500,000 (approximately US$640,000) is huge, the IOC has also suggested a 20% reduction in the total penalty amount which brings it down to £400,000 (approximately US$516,000) if Cathay Pacific pays the data breach fine latest by March 12, 2020.

T-Mobile Reveals Security Breach, Customers’ Data Exposed

T-Mobile data breach

Mobile telecommunication company T-Mobile US, Inc. has revealed a security incident that compromised some of its customers’ personal information. In an official announcement, the company alerted customers about the attack against its email vendor that led to unauthorized access to certain T-Mobile employee email accounts, which contained account information of T-Mobile customers and employees.

The information accessed in the incident included customer names, addresses, phone numbers, billing information, email addresses, account numbers, and rate plans.  According to the company, the people behind the breach have not accessed financial data like credit card numbers, social security numbers, and passwords.

On the bright side, T-Mobile’s incidence response team has informed that they didn’t find any evidence on misuse of the exposed data. However, the company urged its users to review their account information and update account passwords. They further reported the breach incidence to the concerned authorities and are taking appropriate legal actions.

“Our Cybersecurity team recently identified and shut down a malicious attack against our email vendor that led to unauthorized access to certain T-Mobile employee email accounts, some of which contained account information for T-Mobile customers and employees. An investigation was immediately commenced, with assistance from leading cybersecurity forensics experts, to determine what happened and what information was affected. We immediately reported this matter to federal law enforcement and are actively cooperating in their investigation,” T-mobile said in a statement.

This is not the first time that T-Mobile has faced a data breach. In 2018, a data breach had compromised around 2 million users’ personal information of the U.S. telco. T-Mobile, in an announcement, informed its customers about the security breach that was discovered and stopped on August 20, 2018. The compromised data had included names, email addresses, account numbers, and other billing information of its customers. However, financial data like credit card numbers, social security numbers, and passwords were not affected in that incident as well.