Home Blog Page 256

Citrix Servers on Hackers’ Radar

Citrix server vulnerabilities, reported in December 2019 in  CVE-2019-19781, were being scanned by hackers to find entry points into the Citrix systems.

Citrix ADC (Application Device Controller) and Citrix Gateway (formerly known as NetScaler) consists of critical vulnerabilities, which, if exploited successfully, facilitate unauthorized threat actors to carry out an arbitrary remote code execution (RCE) attack. This is a highly critical flaw and its severity can be understood from its CVSS score, which is 9.8. Citrix acknowledged these vulnerabilities in a release on their official forum but has not yet patched them.

The vulnerability affects all supported product versions and platforms mentioned below:

  • Citrix ADC and Citrix Gateway version 13.0 all supported builds
  • Citrix ADC and NetScaler Gateway version 12.1 all supported builds
  • Citrix ADC and NetScaler Gateway version 12.0 all supported builds
  • Citrix ADC and NetScaler Gateway version 11.1 all supported builds
  • Citrix NetScaler ADC and NetScaler Gateway version 10.5 all supported builds

There are at least 80,000 organizations spread across 158 countries using Citrix ADC. These organizations are at an immediate risk of a cyberthreat. Of the 80,000 organizations, a majority are based in the U.S., U.K., Germany, Netherlands and Australia.

Although these Citrix server vulnerabilities do not yet have a permanent fix, in the interim, Citrix has issued mitigation steps for CVE-2019-19781.

Earlier in December 2019, Citrix Systems collaborated with Google Cloud to boost Google’s Cloud security offering. This partnership made Citrix’s Workspace available for Google’s customers. The partnership integrated Citrix’s remote access tool with G Suite to provide a single sign-in experience, multi-factor authentication, and enhanced security policies for G Suite users.

Insight Partners Acquires Armis to Enhance Endpoint Security

In a US$1.1 billion cash deal, technology and venture capital firm Insight Partners acquired enterprise IoT security firm Armis, with an aim of strengthening its endpoint security services. As per the terms of the acquisition deal, Armis will continue to operate independently by leveraging Insight’s business strategy and ScaleUp division. According to Armis CTO Nadir Izrael, the new proceeds will be used to expand its business globally.

Founded in 1995, Insight Partners is a global venture capital and private equity firm that invests in high-growth technology and software organizations.

Armis provides an enterprise-class security platform to address the new threat landscape of unmanaged and IoT devices. The California-based company analyzes endpoint behavior to identify risks and attacks, and protects critical data by identifying suspicious or malicious devices. In the past, Armis received investment from Sequoia Capital, Tenaya Capital, Bain Capital, and Red Dot Capital Partners.

Armis, in a report, claimed that by 2021, nearly 90 percent of devices in enterprise environments will be unsecured and can’t be manageable through traditional IT security tools.

Izrael said, “One of the biggest challenges keeping CIOs and CISOs up at night is how to secure the unmanaged devices proliferating through their businesses, from manufacturing floors to hospital rooms, from airports to boardrooms. These devices, capturing and creating business-critical information, working on production lines, or administering patient care, have no protection and they need a security solution. With the backing of Insight, we will continue to expand our technology to help identify devices, track their behavior and respond to the threats that target them.”

Commenting on the acquisition deal, Yevgeny Dibrov, co-founder and CEO at Armis, said, “We considered growth rounds and strategic offers, but by partnering with Insight we have the best of both worlds–operational support and independence, both of which were important in our decision to take on a scaleup partner this early in our company journey.”

“Applications that are not visible in a different environment cannot be protected”

Edgar Diaz

Edgar Dias is the Managing Director at F5 Networks for India. In his current role, he is responsible for driving business growth and expanding F5’s India operations. Edgar has over 22 years of experience across networking, cloud and SaaS, bringing with him an excellent understanding of the industry to accelerate revenue and profit growth opportunities.

Prior to joining F5 Networks, Dias was Managing Director at ServiceNow India & SAARC. He was also Managing Director at Brocade Communications India & SAARC and has held various senior roles at Juniper Networks, Nortel Networks, Alteon Websystems, and Wipro Infotech Ltd.

In an exclusive interaction with CISO MAG’s Rudra Srinivas, Edgar Dias narrates his journey, the vision of the company, and the challenges he confronts.

As a security leader, what are the challenges you face while executing new security strategies?

Today the world wide web is much wider, but perhaps not secure. Digital transformation has increased the application footprint (consider different and expanding form factors like web, mobile, APIs, micro services, bots, and more). Modern app architectures are diverse and extend across hybrid and multi-cloud environments, with each app service carrying a potential for compromise and increased exposure. Hence the need to protect app service has become increasingly vital as the attacks are more at the app layer.

The biggest challenge is to defend against sophisticated attacks as the existing standard security tools generally fall short to do, as some attacks need to be detected automatically.

With a wider sprawl of applications deployed across different environments, visibility is the key. Applications that are not visible in a different environment cannot be protected. Hence, data collection from multiple endpoints and correlating the same to make sense of the threats, are both facing a challenge and an opportunity.

Secondly, security should be dynamic and proactive. The system should be capable enough of analyzing potential threat scenarios and act with minimal human intervention, which requires skills above and beyond security alone.

What are the challenges a company encounters during cloud adoption/migration? Why are companies hesitant to move toward a cloud setup? Is (inadequate) cloud security still a hindrance to cloud migration/adoption?

The first challenge is one that may not be identified until it happens: multi-cloud sprawl, where existing applications have been lifted and shifted and born-in-the-cloud applications have been deployed in an unplanned and unmanaged manner. Different IT and DevOps teams, siloed by organizational structure or function, independently design and deploy their applications and select the cloud provider infrastructure services and technologies that best meet their individual needs. It should come as no surprise that siloed teams with varying needs result in architectures that are also siloed and varying.

Several enterprises value both deployment agility and native cloud services to meet their short-term needs. Using native cloud services certainly seem like a simpler, faster, and more cost-efficient approach for small teams or narrowly focused projects. However, this lack of a disciplined methodology leads to the second challenge: the use of disparate cloud platforms, different architectures, varying application services, and multiple toolsets. This results in architectural complexity across the enterprises and makes shifting applications from one environment to another much more difficult, not to mention more expensive.

The result of application sprawl and architectural complexity is limited resiliency against architectural changes and inherited technical debt.

Today more organizations are moving their businesses to cloud, and with new multi-cloud strategies, organizations can work efficiently resulting in better outcomes. However, the top challenge that our customers face when they move on to the cloud is to ensure consistent security across all applications.  There are a rising security concern and a huge disparity between public cloud app and on-premises services deployments.

Second, and perhaps less obvious, is that consistency goes beyond the application service. There are many web application firewalls used but their capabilities are not necessarily equal.

To achieve consistent security across all applications in a multi-cloud world requires consistency:

  • Functional Consistency: Deploying application services from different providers can be problematic for users and difficult to manage operations. The key, however, lies in the uniformity of functionality that can create a seamless system for businesses.
  • Operational Consistency: The second, and less mentioned, the source of inconsistency is at the platform layer. That’s the application delivery controller (ADC) for a significant number of enterprise organizations. When moving to the public cloud, many organizations opt (intentionally or accidentally) to employ cloud-native options for application services. That immediately introduces operational inconsistency at the platform layer. The way that you provision, onboard, and operate those application services is operational, and introduces operational debt the moment you hook into the first API.
  • Consistency Needs Standardization: With IT under pressure to deliver value to the business, increasing operational staff in order to maintain multiple platforms and a menagerie of application services seems orthogonal to the goal of achieving multi-cloud consistency. Standardization, especially at the operational layer, is a key component to innovation because it alleviates the burden on staff to focus on operating platforms and encourages collaboration on policy and architecture. By ensuring both operational and functional consistency across properties, organizations can achieve the consistency of policy they desire without breaking their budgets.

Could you brief us about F5’s recent acquisition of NGINX? What additional value did it bring to F5’s multi-cloud application services and portfolio?

The F5-NGINX combination enables multi-cloud application services across all environments, providing the ease-of-use and flexibility developers require, while also delivering the scale, security, reliability, and enterprise readiness network operations team demand. Secondly, it is extremely lightweight and ideal for Kubernetes, considering how applications today are moving towards a containerized environment.

Also, when you want to scale out and scale in applications in real-time, the load balancer sitting in front of the application must be equally lightweight and flexible. NGINX can provide next-generation architectures that application developers are looking for.

Every single company today is interconnected using APIs. You need to have a gateway that can control the API communication. API security has now become the next aspect for security concern and as you expose your applications to a third-party application, vulnerability increases. So, it is crucial that API traffic is inspected thoroughly to ensure that the communication is legitimate. Together with NGINX, we can provide end-to-end application delivery solutions.

With Cloud Security being an increasingly preferred choice for the new security architecture, how can enterprises deploy, manage, and protect themselves from evolving threats?

Organizations are beginning to realize that the cloud does not lend itself to static security controls. Like all other elements within cloud architecture, security must be integrated into a centralized, dynamic control plane. In the cloud, security solutions must have the capability to intercept all data traffic, interpret its context, and then make appropriate decisions about that traffic, including instructing other cloud elements on how to handle it.

These concerns include authentication, authorization, accounting (AAA) services; encryption; storage; and security breaches. Adding to this array of concerns is the potential loss of control over your data.

According to F5 Labs researchers, 86 percent of successful data breaches begin with compromises of the application layer services or user identities placing responsibility for app security squarely in the hands of the app owners, developers, and enterprises deploying them.

With applications residing on various Clouds, CISOs face the challenge of formulating and administering a consistent policy that can be deployed in real-time. What are your suggestions/solutions to enterprise CISOs on this?

We spoke about the need for CISOs to be aware that the move to a multi-cloud is a conscious decision, driven primarily by the type of application being deployed. Organizations must resist migrating to the cloud just to get around the inefficiencies of legacy IT infrastructure and processes.

We also discussed the need for consistency. Application services aren’t always moving with the applications they protect. The disparity between on-premises and cloud app services deployments lead to security concerns. This means that organizations are deploying apps in the cloud, but they are not matching application services deployments at the same rate.

MSSPs are being targeted these days and that ups the risk factor for enterprises. What should enterprises and MSSPs do to mitigate these risks?

Securing a company’s IT infrastructure and systems requires 24/7 monitoring and expertise as cyberattacks have grown in both volume and sophistication. To protect themselves, mid-market businesses and enterprises often turn to manage security service providers (MSSPs), which are designed to deal with complex and targeted assaults. However, beyond a 24/7 response to threats, a good MSSP should have experienced security engineers well-versed in a range of security threats. They will also be supported by the right security technologies and follow industry-standard incident response methodologies for rapid escalation.

Rudra Srinivas is part of the editorial team at CISO MAG and writes News, Features, and Interviews.

5 Threat Predictions for 2020: Are You Prepared?

Cybercriminals Abuse AI and ML for Launching Sophisticated Cyberattacks

With 2019’s headlines of ransomware, malware, and RDP attacks almost behind us, we shift our focus to the cybercrime threats ahead in 2020. Cybercriminals are increasing the complexity and volume of their attacks and campaigns, always looking for ways to stay one step ahead of cybersecurity practices – and using the world’s evolving technology against us.

By Raj Samani, Chief Scientist and McAfee Fellow, Advanced Threat Research

Continuing advancements in artificial intelligence and machine learning have led to invaluable technological gains, but threat actors are also learning to leverage AI and ML in increasingly sinister ways. AI technology has extended the capabilities of producing convincing deepfake video to a less-skilled class of threat actors attempting to manipulate individual and public opinion. Deepfake content is so realistic that it is difficult for humans to discern real from fake. Deepfakes are used for the spread of misinformation and employ Generative Adversarial Networks (GANs), a recent analytic technology, that can create fake but incredibly realistic images, text, and videos. Enhanced computers can rapidly process the biometrics of a face, and mathematically build or classify human features, among many other applications. While the technical benefits are impressive, the underlying flaws inherent in all types of models represent a rapidly growing threat, which cybercriminals will look to exploit.

Other trends our researchers noted in 2019 include:

  • With more enterprises adopting cloud services to accelerate their business and promote collaboration, the need for cloud security is greater than ever. As a result, the number of organizations prioritizing the adoption of container technologies will likely continue to increase in 2020.
  • Our researchers also foresee more threat actors targeting corporate networks to exfiltrate corporate information in two-stage ransomware campaigns.
  • The increased adoption of automation and the growing importance of securing system accounts used for automation raises security concerns about to Application Programming Interfaces (APIs) and the personal data they can contain.

The threat landscape (threatscape) of 2020 and beyond promises to be interesting for the cybersecurity community. With these trends in mind, here are five predictions that are most likely to shape the threatscape in 2020:

1. Broader Deepfake Capabilities for Less-skilled Threat Actors

Deepfake video or text can be weaponized to enhance information warfare. Freely available videos of public comments can be used to train a machine-learning model that can develop a deepfake video that depicts a person doing or saying something that they never did or said. Attackers can now create automated, targeted content to increase the probability that an individual or a group of people fall for a campaign. In this way, AI and machine learning can be combined to create massive chaos.

In general, adversaries are going to use the best technology to accomplish their goals, so if the goal of nation-state actors is to manipulate an election, using deepfake video to manipulate voters is an excellent strategy. With deepfake technology, a cybercriminal can have a CEO make what appears to be a compelling statement that a company missed its earnings targets, or that there’s a fatal flaw in a product that’s going to require a massive recall. Such a video can be distributed to manipulate a stock price or to enable other financial crimes.

As deepfakes technology improves, the expertise required to use it will continue to fall, leading to an increase in the quantity of misinformation.

2. Adversaries to Generate Deepfakes to Bypass Facial Recognition

As technologies are adopted over the coming years, a very viable threat vector will emerge, and we predict adversaries will begin to generate deepfakes to bypass facial recognition. It will be critical for businesses to understand the security risks presented by facial recognition and other biometric systems and invest in educating themselves of the risks as well as hardening critical systems.

3. Ransomware Attacks to Morph into Two-Stage Extortion Campaigns

Based on what McAfee Advanced Threat Research (ATR) is seeing in the underground, we expect criminals to exploit their extortion victims via targeted ransomware. This means there will be an increased demand for compromised corporate networks that will be met by criminals who specialize in penetrating networks and then selling complete network access.

For 2020, we predict the targeted penetration of corporate networks will continue to grow and ultimately give way to two-stage extortion attacks. In the first stage, cybercriminals will deliver a crippling ransomware attack, extorting victims to get their files back. In the second stage, criminals will target the recovering ransomware victims again with another extortion attack, this time threatening to disclose the sensitive data stolen before the ransomware attack.

4. DevSecOps Will Rise to Prominence as Growth in Containerized Workloads Causes Security Controls to “Shift Left”

Container-based cloud deployments are growing in popularity due to the ease with which DevOps teams can continuously roll out micro-services and interact, reusing components as applications. As a result, the number of organizations prioritizing the adoption of container technologies will continue to increase in 2020.

Threats to containerized applications can be introduced by IaC (Infrastructure as Code) misconfigurations or application vulnerabilities. But they can also be introduced through abused network privileges, which allow lateral movement in an attack.

Organizations are increasingly turning to cloud-native security tools explicitly developed for container environments to address these threats. Cloud Access Security Brokers (CASB) are used to conduct configuration and vulnerability scanning, while Cloud Workload Protection Platforms (CWPP) work as traffic enforcers for network micro-segmentation based on the identity of the application, regardless of its IP. This approach to application identity-based enforcement will push organizations away from the five-tuple approach to network security, which is increasingly irrelevant in the context of ephemeral container deployments.

5. Application Programming Interfaces (API) Will Be Exposed as The Weakest Link Leading to Cloud-Native Threats

Threat actors are will continue to target API-enabled apps because APIs continue to be an easy and vulnerable way to access sensitive data. Despite the fallout of large-scale breaches and ongoing threats, APIs often reside outside of the application security infrastructure and are ignored by security processes and teams. Vulnerabilities will continue to include broken authorization and authentication functions, excessive data exposure, and a failure to focus on rate limiting and resource limiting attacks. Insecure consumption-based APIs without strict rate limits are among the most vulnerable.

Headlines reporting API-based breaches will continue into 2020, affecting high-profile apps in social media, peer-to-peer messaging, financial processes, and others, adding to the hundreds of millions of transactions and user profiles that have been stolen in the past two years. The increasing in API adoption for applications in 2020 will expose API security as the weakest link, putting user privacy and data at risk until security strategies mature.

About the Author

Raj Samani, Chief Scientist and McAfee Fellow, Advanced Threat ResearchRaj Samani is a computer security expert working as the Chief Scientist, and McAfee Fellow for cybersecurity firm McAfee. Raj has assisted multiple law enforcement agencies in cybercrime cases, and is special advisor to the European Cybercrime Centre (EC3) in The Hague.

He has been recognized for his contribution to the computer security industry through numerous awards, including the Infosecurity Europe hall of Fame, Peter Szor award, Intel Achievement Award, among others. Raj is also the co-author of the book ‘Applied Cyber Security and the Smart Grid’, CSA Guide to Cloud computing, as well as technical editor for numerous other publications.

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. 

Dixons Carphone Hit with £500,000 Penalty Over Data Breach

The Information Commissioner’s Office (ICO) in the U.K. recently fined DSG Retail Limited (DSG), a U.K.-based electrical and telecommunications retailer, £500,000 (around US$ 653,841) after its POS system was compromised, affecting nearly 14 million customers.

According to ICO’s investigation, attackers installed a malware on 5,390 POS systems at DSG’s Currys PC World and Dixons Carphone stores between July 2017 and April 2018. The investigation revealed that hackers illegally accessed 5.6 million payment card details and personal information of approximately 14 million people, compromising their full names, postcodes, email addresses, and failed credit checks from internal servers. “DSG breached the Data Protection Act 1998 by having poor security arrangements and failing to take adequate steps to protect personal data. This included vulnerabilities such as inadequate software patching, absence of a local firewall, and lack of network segregation and routine security testing,” ICO said in a statement.

The proposed fine was imposed based on previous legislation as the incident occurred before GDPR came into effect (May 2018). ICO stated that the fine would have been higher if the cyberattack had happened under GDPR.

Steve Eckersley, ICO’s Director of Investigations, said, “The contraventions, in this case, were so serious that we imposed the maximum penalty under the previous legislation, but the fine would inevitably have been much higher under the GDPR.”

Eckersley also highlighted, “Our investigation found systemic failures in the way DSG Retail Limited safeguarded personal data. It is very concerning that these failures related to basic, commonplace security measures, showing a complete disregard for the customers whose personal information was stolen. Such careless loss of data is likely to have caused distress to many people since the data breach left them exposed to increased risk of fraud.”

Google Agrees to Pay US$ 7.5M Over Google+ Data Breaches

Facebook

In a recent data leak incident, which exposed the private data of around 500,000 former Google+ users to outside developers, Google has agreed to pay US$7.5 million in a settlement to resolve a class-action lawsuit against the firm.

The proposed settlement, which was filed with the U.S. District Court Judge Edward Davila in San Jose, allows the affected Google+ users to receive a compensation between US$5 and US$12. However, the settlement only allows users with Google+ accounts between January 2015 and April 2, 2019, to submit their claims.

What Happened?

After an internal audit, Google,  in October 2018, announced that it would shut down its social media network Google+ in August 2019, stating that a bug in Google+ exposed the personal data of 500,000 users to third-party developers since 2015.

The tech giant admitted that the flaw in its APIs exposed users’ data, including usernames, email addresses, occupation, date of birth, profile photos, and gender-related information. The bug allowed around 438 third-party developers to access the data, but Google assured its users that there is no evidence of data misuse by any of the developers.

Again, in December 2018, Google announced that Google+ encountered another data breach that exposed the personal information of 52.5 million users. The company admitted that the incident occurred due to an existing bug in its software update that was introduced in November 2018.

Earlier, in January 2019, Google was fined 50 million euros (around US$57 million) by the French data regulator CNIL (National Data Protection Commission) for violating the GDPR law. The fine was levied for Google’s limited information, lack of transparency, and valid consent from its users regarding ads personalization.

Data Wiping Malware “Dustman” Hits BAPCO

data breaches, Verizon Data Breach Investigation Report

Security analysts from the National Cyber Security Center (NCSC), a part of Saudi Arabia’s National Cyber Security Authority (NCSA), have discovered a new data wiping malware “Dustman” that hit BAPCO, Bahrain’s national oil company, on December 29, 2019. Dustman is designed to delete data from infected computers. The malware was named after the filename and string embedded in the malware.

The malware attack, aimed notoriously at BAPCO, was partially successful as it affected only a certain module of its extensive network. The company was able to detect and contain this malware attack immediately and thus continued normal services after the attack.

Dustman: An evolved version of ZeroCleare

Iran has recently launched a string of data deleting malwares like “Shamoon” and “ZeroCleare”. Dustman belongs to the same family as identified from the traces found in its malicious code and could be an evolved version of ZeroCleare malware.

Both Dustman and ZeroCleare use the exact same skeleton, Turla Driver Loader (TDL), published on March 2019 on GitHub. What’s different in Dustman though is that it has been optimized to deliver all drivers and payloads in a single executable file, as opposed to the two executable files required in ZeroCleare. Analysts also noted that ZeroCleare wipes the data by overwriting it with garbage data (0x55), while Dustman only overwrites the data. The names of Indicators of Compromise (IOC) have been issued as dustman.exe, elrawdsk.exe, assistant.sys and agent.exe.

Earlier, in its research report, IBM stated that the ZeroCleare malware was a creation of two hacking groups xHunt and APT34. It said that the malware was developed by Iranian state-sponsored hackers and was also used in cyberattacks against energy companies in the Middle East region. It further added that the hackers launch brute-force attacks to gain access to weakly secured network systems. Once attackers infect the target device, they spread the malware across the company’s network as the last step of infection.

The Domino Effect: British Banks Running Dry After Travelex Cyberattack

Travelex

As reported earlier, a cyberattack that hit Travelex, the foreign currency exchange provider, on the New Year’s Eve is now confirmed to be a Sodinokibi ransomware attack with a hacker group known as REvil demanding a ransom of US$6 million in exchange of five gigabytes of its customer data. This attack has rendered large British banks such as Barclays, Lloyds Bank, Tesco Bank, HSBC, Westpac Banking, and Royal Bank of Scotland unable to take or process foreign currency orders from customers in branches that rely on Travelex.

Initially, Travelex reported that a cyberattack in the form of a software virus had affected its systems and as part of a containment plan, they had taken down all their online services. The Travelex U.K. website informed its visitors that the site was down due to planned maintenance. But as reported by Bleeping Computers, the Sodinokibi attackers have claimed to have inflicted the cyberattack and are in possess five gigabytes of sensitive Travelex user data including, but not limited to names, sex, date of birth, email addresses, SSN and phone numbers.

Attackers initially demanded US$3 million in exchange but later revised it to US$6 million seeing Travelex’s latency to their demands. They have also warned Travelex of providing proof by leaking some data online. However, the Travelex website still says there is no source of evidence that customer data has been compromised.

The Domino effect

The banks, though, are facing the domino effect of this hack. Travelex is a third-party vendor and a foreign currency provider to several top British banks. It’s been more than a week since Travelex suspended its online operations, which has left the banks running low on their foreign currency reserves.

An RBS representative told BBC, “We are currently unable to accept any travel money orders either online, in branch or by telephone due to issues with our travel-money supplier, Travelex. We apologize for any inconvenience caused.” Others soon followed the suit and issued similar statements across various forums.

Earlier, Complete Technology Solutions (CTS), a Colorado-based IT services provider to oral-care practices, had reportedly been affected by the Sodinokibi ransomware attack. According to security researcher Brian Krebs, attackers installed Sodinokibi on computers at more than 100 dentistry businesses that rely on CTS for IT services, including network security, data backup, and voice-over-IP phone service. He further stated, the attack occurred on November 25, 2019, via a compromised remote administration tool. Many of CTS’ clients struggled to recover their data and business operations, as CTS declined to pay the US$700,000 ransomware demand.

10 IoT Security Incidents That Make You Feel Less Secure

Number of IoT Devices Expected to Reach 24.1 Bn in 2030: Report

Internet of Things (IoT) has become a primary target for cybercriminals. The repeated security incidents on IoT devices represent a rising trend for IoT attacks.

By Rudra Srinivas, Feature Writer, CISO MAG

The proliferation of connected devices in consumer, enterprise, and healthcare organizations, and their internal vulnerabilities, have created a security blind spot where cybercriminals can launch a Zero-day attack to compromise devices like webcams, smart TV, routers, printers, and even a smart home.

Here’s a list of 10 severe threats created by connected devices:

1. Smart Security Cameras

It seems cybersecurity issues with smart security cameras alarmed customers after Xiaomi Mijia’s vulnerabilities were exposed. The incident came to light after Dio-V, who owns a Google Nest Hub and several other Xiaomi Mijia cameras around his home, claimed that he received images from other people’s homes, randomly, when he streamed content from his camera to a Google Nest Hub.

“When I load the Xiaomi camera in my Google Home hub, I get stills from other people’s homes,” Dio-V said.

This isn’t the first incident where smart security cameras posed an issue.

Ring, a home security products provider owned by Amazon, was hit by a class-action lawsuit in the U.S. for reports of multiple hacking incidents on its security cameras that left victims traumatized.

Security researchers from cybersecurity firm Bitdefender discovered and reported a flaw in Amazon’s Ring Video Doorbell Pro, which could have given hackers unauthorized access to the user’s Wi-Fi network and potentially to other connected devices on it. At present, all the Ring Doorbell cameras have received a security patch from Amazon to mitigate the issue.

Also, researchers from vulnerability detection firm Tenable discovered seven critical vulnerabilities in Amazon-owned Blink XT2 security camera systems. If exploited, the vulnerabilities could allow hackers to remotely view the camera footage, listen to audio output, and use the infected device to launch distributed denial of service (DDoS) attacks.

In response, Amazon rolled out patches for the vulnerabilities and urged its users to update their devices to firmware version 2.13.11 or later.

2. Hackers can “Faxploit” Connected Fax Machines

Yaniv Balmas and Eyal Itkin, security researchers from Check Point, discovered that fax machines have security vulnerabilities that could possibly allow a hacker to steal data through a company’s network using just a phone line and a fax number. The researchers also demonstrated how they were able to exploit security flaws in a Hewlett Packard all-in-one printer at DEFCON 26 conference.

Describing the potential threat, the researchers said the attackers can send specially created malware coded image files via fax to the targeted networks. The vulnerabilities in the fax machine enable the malware to decode the files and upload these to its memory, which can breach sensitive information or cause disruption across connected networks.

3. Smart TVs

According to the FBI, smart TVs have several overlooked and neglected security issues. It stated that security is an afterthought for several smart TV manufacturers, which makes them vulnerable to different kinds of threats. Hackers can not only control your unsecured TV for changing channels or volume controls, but also stalk your everyday movements and conversations using the integrated camera and microphone.

4. Smart Bulbs can be Hacked

Multiple reports disclosed security vulnerabilities in smart bulbs. According to Murtuza Jadliwala, a research expert at the University of Texas at San Antonio (UTSA),  hackers can compromise infrared-enabled smart bulbs by sending commands via an infrared invisible light emitted from the bulbs to exploit other connected IoT devices existing on the home network.

5. Smart Home is Vulnerable

A Milwaukee-based couple suffered a horrifying incident after their Smart Home setup was hacked by unknown intruders, Fox 6 News reported.

The couple Samantha and Lamont Westmoreland stated that hackers took over their smart home by compromising the connected devices. The attacker played disturbing music from the video system at high-volume while talking to them via a camera in the kitchen, and also changed the room temperature to 90 degrees Fahrenheit by exploiting the thermostat.

Initially, the couple thought it was a technical glitch and changed their passwords, but the issue continued. The duo later changed their network ID, after realizing that someone hacked their Wi-Fi or Nest system.

6. Smartphone’s Microphone Can be Used to Launch Acoustic Side-Channel Attack

Academic researchers from England and Sweden designed a malware that can exploit a smartphone’s microphone to steal the device’s passwords and codes. In their report, “Hearing Your Touch: A New Acoustic Side-Channel on Smartphones,” the researchers claimed that they’ve found the first acoustic side-channel attack that presents what users type on their touch-screen devices.

7. Hackers can Steal Your Identity and Bank Details from a Coffee Machine

Smart coffee machines that are connected to the internet using special apps could be targeted by hackers to steal their owner’s bank or card details.

Vince Steckler, chief executive of security giant Avast, said, smart coffee machines allow owners to control them remotely using their phones. Users can even give the machines vocal commands if they are connected to virtual assistant software such as Amazon’s Alexa.

“Coffee machines are not designed for security.  They are additional vectors to get into your network. And you can’t protect them,” Steckler said in a media statement.

8. Connected Printers

According to security research firm Quocirca, printers that are connected to an organization’s network are the potential vector for cyberattacks. In its report, “Global Print Security Landscape, 2019,” Quocirca addressed the potential security vulnerabilities posed by connected printers.

The report highlighted that 60 percent of businesses in the U.K., U.S., France, and Germany suffered a print-related data breach in 2019, which resulted in a data loss that cost companies an average of more than US$ 400,000.

 9. Smart Speakers Can be Hacked

Wu HuiYu and Qian Wenxiang, security researchers from Tencent Blade, exposed vulnerabilities around smart speakers in a live demonstration at the DEFCON security conference on how to hack a smart speaker. The team used Amazon Echo smart speakers to present their attack program.

The researchers hacked the speaker by adding a malicious device embedded with an attack program.  They also notified their findings to Amazon before the presentation, and Amazon pushed a security patch to fix the issues.

10. Even Internet-Connected Gas Stations are Vulnerable

Researchers at Trend Micro discovered that hackers are targeting internet-connected gas stations to launch IoT-based cyberattacks.

In its report, “The Internet of Things in the Cybercrime Underground, Trend Micro described how Russian hackers have benefited from the Russian government’s new directive, which mandates to replace all electricity meters in the country with smart meters. Trend Micro stated that hackers in Russian dark web forums requested information on how to exploit smart meters.  Some hackers are even selling altered smart meters in the underground market forums. Researchers also revealed that they’ve seen tutorials on gas pump hacking, including step-by-step procedures on how to hack connected meters.

About the Author

 

Rudra Srinivas is a Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.

TikTok Security Vulnerabilities Could Expose User Data

TikTok Security Vulnerabilities Could Expose User Data, tiktok, tiktok child data mishandling

Researchers at Check Point discovered multiple security vulnerabilities in popular short video streaming app TikTok. According to the researchers, the vulnerabilities could have allowed attackers to access user accounts and expose private data including names, email addresses, and dates of birth details.

SMS Link Spoofing Vulnerability

The first vulnerability in TikTok’s SMS functionality was dubbed as SMS Link Spoofing. The TikTok website allows users to send a text message to themselves with a link to download its app on their devices. This could lead to user data exploitation for malicious purposes.

“Attackers using the SMS Link Spoofing vulnerability can send a custom link that contains the schemas mentioned above. Since the custom link will contain the URL parameter, the mobile application will open a browser window and go to the webpage written in the parameter from the mobile application,” Check Point explained.

However, this attack requires the hacker to know the phone number of the victim, which could be obtained via social engineering, phishing, or from a stolen list of numbers.

Cross-Site Scripting (XSS) Vulnerability

The researchers also found that Tiktok’s subdomain, https://ads.tiktok.com, is vulnerable to XSS attacks, where malicious scripts are injected into trusted websites. It was found that hackers could send a malicious link to a victim that will result in redirecting the victim to a malicious website.

The vulnerabilities allowed hackers to:

  • Get hold of TikTok accounts and manipulate their content
  • Delete videos
  • Upload unauthorized videos
  • Make private “hidden” videos public
  • Reveal personal information saved on the account such as private email addresses

However, it’s unclear if the security flaws have been exploited by attackers. Check Point stated that it notified TikTok’s parent company ByteDance to fix the vulnerabilities and TikTok fixed the issues.

Luke Deshotels, security team member at TikTok, said, “TikTok is committed to protecting user data. Like many organizations, we encourage responsible security researchers to privately disclose zero-day vulnerabilities to us. Before public disclosure, Check Point agreed that all reported issues were patched in the latest version of our app. We hope that this successful resolution will encourage future collaboration with security researchers.”

In the last few months, there has been evidence of the potential risks with TikTok. The U.S. Navy recently banned TikTok, citing cybersecurity concerns. The authorities sent out a statement stating that serving members of both the U.S. Navy and Army, who were using government-issued mobile devices and had the app installed on them, would be blocked from the Navy-Marine Corps Intranet.

Earlier, TikTok was also hit with a class-action lawsuit in the U.S. claiming that the company surreptitiously transferred users’ data to Chinese servers, without users’ consent. The proposed class-action lawsuit was filed in California federal court by Misty Hong, a student from Palo Alto.