Home Blog Page 253

Hacker Leaks More Than 500,000 Telnet Credentials

common password of 2021,Password Protection, password spray attacks, Microsoft accounts passwords

As reported by ZDNet, a hacker who seems to be a DDoS-for-hire (DDoS booter) service operator, has published a massive list of 515,000 Telnet credentials consisting passwords of servers, home routers, and IoT (Internet of Things) devices. The published list also includes IP address of each device along with a username and password of its Telnet service. Telnet is a remote access protocol that can be used to control devices over the internet.

The hacker compiled the leaked list by scanning the internet for devices exposing their Telnet port. He reportedly used two methods for finding the device credentials and generating the list:

  1. Factory-default usernames and passwords
  2. Custom, yet easy-to-guess password combinations

This list, which is also known as a bot list, is prepared after scanning the internet and is further used to connect to vulnerable devices and install various malware.

The hacker also told ZDNet that he upgraded his DDoS service that previously worked only on IoT botnets to a new model that relies on renting high-output servers from cloud service providers. All the credentials leaked are dated between October and November 2019.

Experts suggest that some of these devices might now have a different IP address, or its login credentials might be changed. A threat actor can use the IP addresses found in the leaked list, determine the name of the service provider, and then re-scan the ISP network to update the latest IP addresses list.

Server and router password security has long been a cybersecurity issue. Earlier, TP-Link’s Archer Router series, which is capable of handling high-speed online traffic, had a vulnerability that if exploited, could allow hackers to bypass the admin passwords and remotely take control of the devices. This vulnerability, tracked as CVE-2019-7405, was first discovered in TP-Link Archer C5 (v4) routers.

Grzegorz Wypych, a Senior Security Consultant at IBM X-Force Red said, “This was a zero-day flaw that was not previously reported and could affect both home and business environments. If exploited, this router vulnerability allowed a remote attacker to take control of the router’s configuration via Telnet on the local area network (LAN) and connect to a File Transfer Protocol (FTP) server through the LAN or wide area network (WAN).”

The vulnerability could be exploited by simply sending a character string longer than the allowed number of bytes through an HTTP request. This is also known as Password Overflow. The built-in validation checks the referrer’s HTTP headers; this tricked the TP-Link routers into believing that it is a valid HTTP request, making the password void and replacing it with an empty value.

Almost 7 in 10 Security Cameras Running on Outdated Firmware: Genetec’s Research

Almost 7 in 10 Security Cameras Running on Outdated Firmware: Genetec’s Research

Security cameras running with outdated firmware might compromise security systems of enterprises in the Middle East region, claims a research from technology firm Genetec.

According to the research, seven out of 10 (68.4 percent) security cameras have out of date camera firmware. The research was based on a survey conducted on a sample of 44,763 security cameras, which revealed that more than half of the cameras (53.9 percent) contain known vulnerabilities and nearly four out of 10 cameras are vulnerable to attacks. The research also highlighted that one in four organizations (23 percent)  that use the same passwords for all the security cameras are falling prey to intruders, as they can easily attack all cameras if they crack a password for one camera.

Describing the scenario, Mathieu Chevalier, Lead Security Architect at Genetec, said, “Unfortunately, our research shows that the  ‘set it and forget it’  mentality remains prevalent putting an entire organization’s security and people’s privacy at risk. All it takes is one camera with obsolete firmware or a default password to create a foothold for an attacker to compromise the whole network. It is critical that organizations should be as proactive in the update of their physical security systems as they are in updating their IT networks.”

The Middle East cybersecurity market is expected to grow at a compound annual growth rate (CAGR) of 22.5 percent between 2018 and 2024. Recently, technology conglomerate, Honeywell stated that it is imperative for cities in the region that are ready to jump on the smart bandwagon to address the needs and security of smart building systems.

Honeywell also released its predictions on emerging trends that will shape cybersecurity for buildings. The company pointed out that Building Internet of Things (BIoT) will likely see a spur in cyberthreats as they become more connected. The surge of smart buildings will also put data and reputation of companies at potentially greater risk. Among the reasons for the trend were less-guarded entry points for buildings and lack of focus on cybersecurity when managing OT (Operational Technology). Another prediction was around cybersecurity for OT in buildings. The technology giant suggested that with buildings becoming smarter, they tend to produce more connected data, thereby attracting more potential threats.

National Healthcare Group Fined SG$6,000 for Data Breach

The National Healthcare Group (NHG), a group of public hospitals and polyclinics, was fined SG$6,000 (approximately US$4,452) for exposing sensitive data of 129 general practitioners. The issue came to light after one of the practitioners found a bug and then notified the organization. The incident occurred on February 7, 2018, and NHG fixed the cause of the incident immediately. The exposed information included full names, photographs, contact details, NRIC numbers, mailing addresses, email addresses, and clinic addresses.

According to the Personal Data Protection Commission (PDPC), Singapore government’s privacy authorization body, personal information of general practitioners, partner doctors of NHG, and five members of the general public was exposed online, the CNA reported.

PDPC claimed that NHG failed to make reasonable security arrangements for data security and thus violated the Personal Data Protection Act. It also stressed that NHG neglected to fix known vulnerabilities in its network systems that allowed unauthorized access to sensitive information.

Last year, PDPC fined its computer vendor Option Gift US$4,000 for disclosing personal information of 426 NSmen (National Servicemen). The commission stated that it discovered Option Gift’s violation of section 24 of the Personal Data Protection Act, which exposed sensitive information.

The compromised data included information like log-in identifications, e-mail addresses, delivery addresses, and mobile phone numbers of the NSmen from the Singapore Armed Forces (SAF) and Home Team. The issue occurred due to a technical flaw in UniqueRewards, an online portal maintained by Option Gift, which allows NSmen to redeem credits for service-linked rewards from the Ministry of Defence (MINDEF) and the Ministry of Home Affairs (MHA). The PDPC stated that Option Gift had failed to conduct enough testing before deploying the program script.

NSDC Acknowledges Data Leak in Ukrainian Government Job Portal

recruitment sites data leak

Reuters from Kiev reported that the government job portal https://career.gov.ua/ published PII (Personally Identifiable Information) of Ukrainian Nationals, which included passport scans, and diploma and graduation certificates among other documents. These documents were submitted by citizens who registered on the portal for job searches in the government sector. However, the National Security and Defence Council (NSDC) is yet to confirm whether it was a targeted cyberattack or a human error.

On January 16, 2020, Office of the Ombudsman of Ukraine published a Facebook wall post that said, “A possible leak of personal data of citizens who registered on the site https://career.gov.ua/ with the aim of passing a competition for government service was identified. A copy of the passport and other scanned documents that users uploaded to the Unified Vacancy Portal for public service are in free access.” The Ombudsman’s Office first received a complaint about the data leak by an activist of the Ukrainian Cyber Alliance, a non-profit Ukrainian cyber community.

The NSDC of Ukraine held an emergency meeting of the working members to discuss the cause, effect, and measures to be taken by the state resources in connection with the leak of data from the Unified Vacancy Portal. Later, NSDC stated that its cybersecurity experts had identified the vulnerability and secured the portal.

Some Ukrainians said that they won’t be surprised if a loan is accidentally taken in their name while others questioned the government’s stand and preparedness on cybersecurity and digitalization.

Ukraine and its institutions have been victims of multiple cyberattacks in the recent past. As per a study by the tech firm Comparitech, Ukraine ranks 10th least cyber-secure out of 60 countries researched.  The Ukraine Cyber Police Department has been working overtime to curb and nab the miscreants. Just before the new year, the Ukraine Cyber Police department arrested a cybercriminal hacker group (including three Ukrainians and one foreign national) from the Kharkiv region that was responsible for hacking more than 20,000 servers of private organizations around the globe.

The hacker group, which had been active since 2014, targeted organizations mainly from Ukraine, Europe, and U.S. regions. From the hardware and other physical and virtual property confiscated during the raid, the officials learned that hackers sold the hacked server credentials and access points to various customers around the world. These servers were also used to create botnets for mining, DDoS attacks, installing software command centers with viruses, and turning them into weapons for brute-force attacks.

Play Store Records 600 Million Fleeceware Installs

Google Play

Researchers at Sophos, a U.K. based cybersecurity company, discovered a set of 25 fleeceware apps on Play Store having more than 600 million installs. Some of these apps have close to 100 million installs, which can rival even the legitimate apps on the Google Play Store.

What is Fleeceware?

Fleeceware is a term introduced by researchers at Sophos Labs in September 2019. It has been named fleeceware due to its defining characteristic of overcharging users for functionality that’s widely available in free or low-cost apps.

All users signing up for an Android app’s trial period are required to cancel the trial version manually to avoid service continuation charges. However, most users just uninstall an app when they don’t like it. The majority of app developers interpret the action of uninstallation as a trial period cancelation and thus don’t charge the user for service continuation.

However, researchers discovered that some Android app developers intentionally didn’t cancel an app’s trial period when a user uninstalled the app. An obscene amount of service continuation charges (between US$100 and US$240 per year) were debited from the users’ saved cards for the most basic and simplistic of apps, such as QR/barcode readers and calculators.

Jagadeesh Chandraiah, Sophos mobile malware analyst, said that he suspects the apps bought fake five-star reviews to boost their ranking on the Play Store and also used pay-per-install services to boost install counts to attract a large number of users.

Earlier, in December 2019, Tatyana Shishkova, an Android Malware Analyst from Kaspersky, discovered a few malicious Adware apps on Google’s Play Store. Adware is a type of malware (malicious software) that displays unwanted advertisements on the user’s device. These ads are generally in the form of a pop-up and at times without a Close Popup option. This form of malware is less serious than others but has a ton of nuisance value to it. Adware implementers can sell users’ browsing history and behavior to interested clients, which in turn could be used to target them with more customized ads as per their likes and dislikes.

Tatyana also found three hidden Ad apps on the Play Store, which had close to 12,000 installs. Digital adverts are no longer just used to pursue the user to only buy products, however, this set of information is also used to earn profit by selling it to interested third-party clients.

McAfee Appoints Peter Leav as New Chief Executive Officer

Peter Leav

The device-to-cloud cybersecurity firm, McAfee, appointed Peter Leav as the new Chief Executive Officer, effective from February 3, 2020.

Leav had previously served as President and CEO of BMC Software. He holds more than 20 years of executive leadership experience in large-scale technology companies like NCR Corporation, Symbol Technologies, Cisco Systems, Proofpoint, and Motorola.

Commenting on his new role Leav said, “I am delighted to be joining McAfee at this exciting time for the company and am looking forward to working with the team to pursue the significant growth opportunities ahead. McAfee is one of the largest, most important cybersecurity brands in the world, with a commitment to innovation and excellence. By maintaining the forward-thinking, customer-centric approach that has come to define McAfee, I am confident that we will continue to play a very meaningful role in protecting individuals, businesses and communities from the rapidly changing cyber threat landscape.”

Apart from addition to leadership roles, McAfee also forged multiple partnerships. The company recently acquired NanoSec, a container security startup, to improve its compliance and to mitigate the risk of its container deployments. NanoSec is a multi-cloud and zero-trust application security platform that’s focused on the container approach to application security. The acquisition will allow McAfee to boost its MVISION Cloud and MVISION Server Protection products.

Also, McAfee and IBM Security jointly directed an open-source cybersecurity alliance along with 14 other cybersecurity companies across the globe. The new Open Cybersecurity Alliance (OCA) will fall under the umbrella of the Organization for the Advancement of Structured Information Standards (OASIS) open standards and open-source group and will include companies like Advanced Cyber Security Corp, Corsa, CrowdStrike, CyberArk, Cybereason, DFLabs, EclecticIQ, Electric Power Research Institute, Fortinet, Indegy, New Context, ReversingLabs, SafeBreach, Syncurity, ThreatQuotient, and Tufin.

Equifax to Pay US$380.5 Million to Settle Class-Action Lawsuit

Atlanta-based consumer credit reporting agency Equifax has agreed to pay US$380.5 million to settle a class-action lawsuit, brought forward by the U.S. Federal Trade Commission (FTC), relating to a 2017 data breach that leaked a massive amount of information of more than 147 million people in the U.S. alone.

As per the settlement, Equifax will pay US$380.5 million as a penalty from where the class action members can withdraw up to US$20,000 as compensation. Additionally, the company may also require spending US$125 million for out-of-pocket claims. Class action members will also receive 10 years of free credit monitoring services from Equifax.

The Northern District Court of Georgia granted the settlement after consulting with the U.S. FTC, State Attorneys, and members of the class-action suit.

Overview of the Data Breach

In September 2017, Equifax disclosed that its databases were hacked between May and June 2017, and attackers gained access to the company’s data that compromised sensitive information for 147 million American consumers, including Social Security numbers, credit card numbers, and driver’s license numbers.

Equifax discovered the breach on July 29, 2017, but waited until after the close of trading nearly six weeks later to disclose the breach to its consumers and investors, after hackers exfiltrated data for 76 days.

Earlier, in September 2018, Equifax was charged with a fine of £500,000 (US$660,000) by the Information Commissioner Office (ICO) for failing to protect the personal and financial data of customers. The ICO, which carried out the investigation, stated that Equifax was warned about vulnerabilities in its systems by the U.S. Department of Homeland Security in March 2017. However, Equifax failed to take proper steps to fix the vulnerabilities.

FBI Seizes WeLeakInfo.com for Selling Breached Data Online

99% of Websites Are Prone to Cyberattacks Via JavaScript Plug-Ins: Report

The authorities of the FBI and the U.S. Department of Justice seized the domain “weleakinfo.com” for selling sensitive information that was hacked from other sources for the past three years.

According to the official notice, published by the U.S. Attorney Jessie K. Liu of the District of Columbia and Special Agent in Charge Timothy M. Dunham of the FBI’s Washington Field Office, WeLeakInfo sold access data of more than 12 billion user records that included: names, usernames email addresses, phone numbers, and passwords for online accounts.

The notice also claimed that WeLeakInfo provided its users with a search engine to access the data that was illicitly obtained from over 10,000 data breaches. The U.S. Department of Justice urged the general public for help in finding the website’s owners.

The website was taken down after a joint operation by the FBI and authorities from Northern Ireland, including the U.K.’s National Crime Agency, the Netherlands’ National Police Corps, the Federal Criminal Police Office of Germany, and the Police Service of Northern Ireland.

Earlier in the year, the FBI came up with a new surveillance proposal to monitor social media platforms for potential threats. As per the proposal, the FBI was asking third-party vendors to provide monitoring services, which might bring up possible conflicts with Facebook and other social media companies over privacy policies.

As per the new proposal, the FBI is asking third-party vendors to provide monitoring services, which might bring up possible conflicts with Facebook and other social media companies over privacy policies. It’s said that the new surveillance proposal by FBI would clash with Facebook’s privacy policies settlement, worth US$5 billion, with the U.S. government.

Security experts had opined that the FBI’s proposal would violate the companies’ ban against using their data for monitoring purposes.

Cyber Kiosks: The Digital Age Weapon of Police Scotland

Cyber weapons, cyber threats

Police Scotland has geared up for the first phase roll-out of Digital Triage Devices, known as Cyber Kiosks, on January 20, 2020. These Cyber Kiosks are desktop computers configured with a special software, and are approved by Police Scotland’s Strategic Leadership Board. In the first phase, 41 police stations across local policing divisions will receive these Cyber Kiosks. This new device empowers Police Scotland to detect and mitigate cybercrimes at a granular level.

How do Cyber Kiosks Work?

Cyber Kiosks allow its operator to carry-out a specific search on a mobile or tablet device for criteria such as:

  • Date
  • Time
  • Telephone number

Cyber Kiosks also enable a filtered search of text messages or photographs on the scanned device. On identification of critical/criminal information on a device, it is submitted to a Digital Forensics Hub for further examination and evidence for court. This quickens the progress of investigations and leads to quicker return of irrelevant devices. Identification of evidence at early stages largely enhances the ability of threat detection and inversely helps in bringing down the crime rate.

The technology has been under trial since 2016. Edinburgh and Stirling were the first two places where phones and SIM cards legally seized by frontline officers were first tested using these kiosks. However, Police Scotland acknowledged that the previous trials fell below the standard expected from the service. Ever since, a lot of research and collaborative efforts have been made by the Cybercrime and Technical Surveillance Programme Team (CTSP) to improve on the earlier shortcomings.

Mobile devices and tablets hold a host of personal data that falls under Personally Identifiable Information (PII) category. And U.K.’s Data Protection Act 2018 safeguards the PII of every individual alike. Thus, complying to this act and yet fulfilling the objective of using a Cyber Kiosk has been a difficult challenge to overcome for Police Scotland. They have worked closely with various groups, partners and stakeholders for considering the legal framework and designed procedures that support digital forensic examination and the use of Cyber Kiosks. They also include an enhancement to the process and procedures that support the capture of informed consent from victims and witnesses for the purpose of digital device examination.

Deputy Chief Constable of Police Scotland, Malcolm Graham, said, “We are committed to providing the best possible service to victims and witnesses of crime. This means we must keep pace with society. People of all ages now lead a significant part of their lives online and this is reflected in how we investigate crime and the evidence we present to courts. Many online offences disproportionately affect the most vulnerable people in our society, such as children at risk of sexual abuse, and our priority is to protect those people.

Increases in the involvement of digital devices in investigations and the ever-expanding capabilities of these devices mean that demand on digital forensic examinations is higher than ever. Current limitations however, mean the devices of victims, witnesses and suspects can be taken for months at a time, even if it later transpires that there is no worthwhile evidence on them.”

Silence Hacking Group Targets Banks in Sub-Saharan Africa

New Programming Language

Security researchers from Kaspersky discovered thousands of attack notifications on popular banks in the sub-Saharan Africa (SSA) region. Researchers opined that Russian speaking hacking group Silence is likely behind these attacks. It’s said that the hacker group appears to have deployed a malicious code on the bank’s network to run malicious commands on hosts and allegedly used the access to orchestrate fund withdrawals from the bank’s ATMs.

The researchers discovered the attacks in early January 2020 and revealed that the Silence hacking group is one of the most active Advanced Persistent Threat (APT) actors, which previously attacked banks in Bangladesh, India, Sri Lanka, Kyrgyzstan, Russia, former Soviet states, and Eastern Europe.

Sergey Golovanov, a security researcher at Kaspersky said, “We urge all banks to stay vigilant, as apart from the large sums Silence group also steal sensitive information while monitoring the Banks activity as they video record screen activity. This is a serious privacy abuse that might cost more than money can buy.”

Kaspersky also advised financial organizations to follow the necessary security measures, which include:

  • Introduce basic security awareness training for all employees so that they can better distinguish phishing attempts.
  • Monitor activity in enterprise information systems information security operations center.
  • Use security solutions with dedicated functionality aimed at detecting and blocking phishing attempts.
  • Provide security teams with access to up to date threat intelligence data, to keep pace with the latest tactics and tools used by cybercriminals.
  • Prepare an incident response plan to be ready for potential incidents in the network environment.