Home Blog Page 259

Mozilla Firefox Adopts CCPA for Worldwide Audience

Mozilla, Firefox

New Year’s New Law – California Consumer Privacy Act (CCPA) came into effect from January 1, 2020. Mozilla was one of the first company to acknowledge and back such a law as it has always maintained that consumer data privacy has been the company’s top priority. Supporting its previous claims, Mozilla has adopted the much awaited CCPA in the Firefox 72 stable version which is slated for January 7, 2020 release. The CCPA version of Firefox will not be limited to users in U.S. alone but will be available to all Firefox users worldwide.

Like GDPR, CCPA also gives personal information protection rights to all its consumers. It gives individuals the power to know what personal information has been collected by the service provider and how is it being utilized (whether it is being used for analytical study purposes or being sold to a third party for monetary benefits). CCPA defines a business as a for-profit entity that collects consumer personal data. It is applicable to businesses that:

  • Earn US$25,000,000 or more a year in revenue.
  • Annually buy, receive, sell or share personal information of 50,000 or more consumers, households or devices for commercial purposes.
  • Derive 50 percent or more of its annual revenue from selling consumer personal information.

With its implementation, the users can now request Mozilla to delete Firefox telemetry data stored on its servers. Mozilla doesn’t collect users web history and thus, this data doesn’t include that. However, it does include data such as how many tabs were open and the length of the browser session, etc. “We’ve decided to go the extra mile and expand user deletion rights to include deleting this telemetry data stored in our systems,” said Alan Davidson, VP of global policy, trust and security at Mozilla.

“For Firefox, privacy is not optional. We don’t think people should have to choose between the technology they love and their privacy. We think you should have both. That’s why we are taking these steps to bring additional protection to all our users under CCPA. And why we will continue to press in 2020 – through the products we build and the policies we advocate – for an Internet that gives people the privacy and security they deserve.”

On similar lines, Microsoft had earlier rolled out the red carpet for CCPA to all its users across the U.S. “Microsoft honors CCPA compliance and is committed towards handing data privacy rights in their (peoples) own hands,” said Julie Brill, Corporate Vice President for Global Privacy and Regulatory Affairs and Chief Privacy Officer at Microsoft in a statement. “In 2018, we were the first company to voluntarily extend the core data privacy rights included in the European Union’s General Data Protection Regulation (GDPR) to customers around the world, not just to those in the EU who are covered by the regulation. Similarly, we will extend CCPA’s core rights for people to control their data to all our customers in the U.S.”

VMware Completes Acquisition of Pivotal for US$ 2.7 Billion

VMware, a provider of enterprise software, recently announced that it has completed the acquisition of cloud-native platform provider Pivotal Software in a deal worth US$ 2.7 billion.

The latest acquisition integrates Pivotal’s developer-centric offerings with VMware’s upstream Kubernetes run-time infrastructure tools to deliver a comprehensive enterprise security solutions. The acquisition also offers product building blocks and integrated solutions that are tested and proven with technical expertise that customers need to accelerate software delivery across data center, cloud, and edge environments.

VMware’s cloud, networking, security, and digital workspace offerings provide a dynamic and efficient digital foundation for customers globally. Pivotal’s offerings will be core to the VMware Tanzu portfolio of products and services designed to help customers transform the way they build, run, and manage their most security applications.

“It’s my pleasure to announce Ray O’Farrell as the leader of VMware’s new Modern Applications Platform business unit—uniting the Pivotal and VMware Cloud Native Applications teams,” said Pat Gelsinger, CEO, VMware. “And as Pivotal is now part of VMware, I want to thank the Pivotal leadership team for building a great company. Together, we’re poised to be the leading enabler of Kubernetes with a deep understanding of both operators and developers.”

Commenting on the acquisition deal, Edward Hieatt, senior vice president at Pivotal, said, “Pivotal has fundamentally changed how the world’s biggest brands build and manage software with a focus on developer productivity through platform abstractions and development techniques as well as connecting the business with the developer. The combination of Pivotal and VMware offers the most comprehensive application platform in the industry and is a win for our customers, a win for Pivotal, and a win for VMware. We’re excited to team up with VMware to help more enterprises become like modern software companies by adopting DevOps and Lean techniques developed by internet giants and the startup community.”

London-based Forex Company Suffers Cyber-Attack

Travelex

London-based forex exchange company–Travelex, has been hit by a cyber-attack on New Year’s Eve forcing the exchange to suspend all online services and its official website immediately to limit the damages.

Travelex, a major foreign currency exchange company provides online foreign currency exchange as well as over the counter (OTC) exchange services at various branches across the globe including major airports and tourist destinations. It has operations spread in over 27 countries and has tie-ups with well-known banks such as Tesco Bank.

On its official Twitter handle – @TravelexUK, the company gave an official statement about the malware attack (stated as “virus” in the official statement), “Travelex confirms that a software virus was discovered on New Year’s Eve which has compromised some of its services.” Talking about the online services suspension and whether any customer data was compromised, Travelex said, “As a precautionary measure in order to protect data and prevent the spread of the virus, we immediately took all our services offline. Our investigation to date shows no indication that any personal or customer data has been compromised.”

“We regret having to suspend some of our services in order to contain the virus and protect data,” said Travelex chief executive Tony D’Souza. “We apologize to all our customers for any inconvenience caused as a result and are doing all we can to restore our full services as soon as possible.”

Travelex said it had deployed “teams of IT specialists and external cyber-security experts”, who have been “working continuously since New Year’s Eve to isolate the virus and restore affected systems”. Travelex assured that it will continue to provide manual foreign currency exchange OTC services at all its branches until the problem is fixed.

Travelex also offers certain online services for financial institutions such like the Tesco Bank. The cyber-attack has also affected these services. “Unfortunately, our on-line Travel Money service is currently unavailable due to IT issues at our partner, Travelex. In the meantime, you can still visit one of our in-store bureaux to collect or purchase your currency. Sorry for any inconvenience.”, said a tweet from Tesco Banks official Twitter handle – @tescobankhelp.

Earlier, a survey report from Lloyds Bank pointed out that cybercrimes have jumped to the fourth position from the eighth place since 2018. Cybersecurity has emerged as a primary investment priority for financial firms in the United Kingdom. The banks are increasing their budget allocation to enhance cybersecurity capabilities at their organization, Computer Business Review reported.

The research surveyed several senior business decision-makers from financial organizations in the UK. According to the survey report, in 2018 over 46 percent of respondents stated their top three technology investment agendas were to improve customer satisfaction, enhance cybersecurity, and reduce operating costs. But, in 2019, investment on cybersecurity products and services became the topmost agenda, with 70 percent respondents now focusing on it.

Indian Researcher Finds Starbucks API Key Exposed Online

Security authorities at Starbucks left an API (Application Programming Interface) key online without password protection, that could be used by attackers to access internal systems and manipulate the list of authorized users.

The issue came to light after an Indian security researcher Vinoth Kumar found the open key in a public GitHub repository and reported to Starbucks.

The researcher discovered the flaw in a vulnerability bug bounty platform conducted by HackerOne. “While going through Github search I discovered a public repository which contains Jumbcloud API Key of Starbucks.” Vinod Kumar said.

“Vinothkumar discovered a publicly available Github repository containing a Starbucks JumpCloud API Key which provided access to internal system information,” said HackerOne.

After further analysis, Starbucks rated the flaw as “critical” as the key was left exposed online that allowed attackers to access Starbucks JumpCloud API. JumpCloud is an Active Directory Management platform that provides user management, web app single sign-on (SSO) access control, and Lightweight Directory Access Protocol (LDAP) service.

It’s said that the vulnerability can allow attackers to perform various activities like, execute commands on systems, add/remove users which has access to internal systems, and potentially AWS account takeover.

Starbucks acknowledged Kumar’s proof-of-concept (PoC) of the vulnerability and rewarded him with US$ 4,000 bounty for reporting the flaw.

“Thank you for your patience! We have determined that this report demonstrates “significant information disclosure and is therefore eligible for a bounty,” stated Starbucks. “At this time, we are satisfied with the remediation of the issue and are ready to move to closure. Thank you again for the report! We hope to see more submissions from you in the future.”

In a similar bug bounty program, Laxman Muthiyah, an Indian-based security researcher, discovered a bug in Instagram’s Account Recovery Process that could have allowed attackers to break into users’ accounts. The Facebook-owned Instagram rewarded the researcher with a bounty of US$ 10,000 for reporting the vulnerability.

The researcher said that he found the vulnerability while investigating how the account recovery process of the photo-sharing application allows the user to regain access to the account when the user forgot the password.

According to Muthiyah, the Instagram server used device ID as a unique identifier to validate password reset codes. “When a user requests a passcode using his / her mobile device, a device ID is sent along with the request. The same device ID is used again to verify the passcode,” Muthiyah said in a statement.

Dozens of Hospital Computers Compromised, Former Employee Pleads Guilty

Insider attacker leak data

Richard Liriano, a former IT employee of a New York City-area hospital pled guilty of a computer fraud. He used a “keylogger” on dozens of his coworkers’ computers to obtain usernames and passwords of their personal email and other social media accounts. According to the Department of Justice (DOJ), “Using the victims’ stolen credentials, Richard repeatedly compromised their password-protected online accounts, and accessed their sensitive personal photographs, videos, and other private documents.” The keylogger enabled him record computer user’s keystrokes.

Richard was found guilty by the DOJ for misusing his administrative rights from 2013 to 2018 wherein he logged into employee accounts, and copied other employees’ personal documents, including tax records and personal photographs, onto his own workspace computer for his personal use. Over the course of five years, Richard stole about 70 (or more) email and social media account credentials belonging to hospital employees. This internal breach caused the hospital losses amounting to nearly US$350,000.

Richard was arrested on November 14, 2019 and pled guilty on one count of transmitting a program to a protected computer with an intention of causing damage. The maximum sentence for this offence is ten years in prison. After going through other anomalies, U.S. District Judge Lewis A. Kaplan will deliver the sentencing on April 15, 2020.

Insider threats account for most losses that an organization faces rather than an cyber-attack by external factors. Earlier, cybersecurity firm Trend Micro revealed that one of its employees illegally accessed and sold personal information of around 68,000 of its customers. The company stated that customers’ data like names, email addresses, ticket support numbers, and phone numbers were copied from its internal database by the employee and sold off to scammers. However, officials from Trend Micro stated that payment card details or enterprise customer accounts were not accessed.

“Our investigation revealed that this employee sold the stolen information to a currently unknown third-party malicious actor. We took swift action to contain the situation, including immediately disabling the unauthorized account access and terminating the employee in question, and we are continuing to work with law enforcement on an ongoing investigation,” the statement added.

First the Tokyo Olympics, Now the Special Olympics Faces Phishing Menace

phishing campaign, Smishing attacks

Special Olympics New York, a non-profit organization that helps provide coaching to competitive sportspersons with intellectual disabilities, reportedly faced a breach of its email server. Hackers leveraged the opportunity to launch an email phishing campaign targeting the registered donors list of the non-profit organization.

Founded in 1970, Special Olympics New York has close to 67,000 registered athletes and around 3,000 coaches. They provide coaching and conduct athletic competitions based on Olympics sports for children and adults having an intellectual disability.

Leveraging the Christmas Holidays, hackers gained access to the email server of the organization and used it to launch an email phishing campaign. The two reasons why this campaign was threatening were:

  1. Timing of the Campaign – The campaign was launched during a period when most of the users (donors) are spending their holidays with their family and friends. And during such a period, finding a mail asking for donation towards a noble cause will have maximum number of hits. The hackers took advantage of the human psychology.
  2. Time Frame – In another email sent out by the attackers, they alerted of an impending donation payment of US$194,249 that would be automatically deducted from the donor’s account within two hours. This created panic and a sense of urgency to click on the links that redirected the victims to the phishing page.

“Apologies friends and fans! As you may have guessed, our account was hacked today. Please disregard a message that you may have received about a payment processing. While donating to us is always a good idea, we would never ask in such a grinchy way,” stated an email from Special Olympics New York to its donors. “The hack was to our communication system which only includes your contact information and no financial data. Please be assured that your contact information is protected and has been kept confidential”

Casey Vattimo, the SVP of External Relations for Special Olympics New York said that the issue has been fixed and donors can now continue donating securely without any apprehensions.

Earlier, the authorities of the Tokyo 2020 Summer Olympics issued a warning about an ongoing phishing campaign. The suspicious emails are designed to look like they’re coming from the Tokyo Organizing Committee of the Olympic and Paralympic Games 2020. The authorities stated that the phishing emails will redirect the recipients to fake websites or infect their computer systems with malware if opened.

“We have recently detected emails disguised to look like they are coming from a Tokyo 2020 staff member. Although the email may look official and legitimate, if you have no reason to receive such an email or if the content is questionable, you should not click on the link or open any attached files. It is highly likely that you would be directed to a phishing site or your computer would be exposed to a virus,” the authorities said in an official statement.

Attackers Exploit Vulnerabilities in Ruckus Wireless Routers

Home Routers for botnets

Gal Zror, a security researcher discovered three critical RCE (Remote Code Execution) vulnerabilities in Ruckus Wireless routers that could allow malicious actors to bypass security layers and take control of the devices. Ruckus Networks is a provider of wired and wireless networking equipment and software for enterprises.

According to researcher, the vulnerabilities allow hackers to gain root access to the routers.

The researcher stated that he examined 33 different access points firmware and determined that all of them were vulnerable to RTC vulnerability.

Presenting his findings at the annual Chaos Communication Congress conference, Gal Zror said, “Exploitation used various vulnerabilities such as information leak, authentication bypass, command injection, path traversal, stack overflow, and arbitrary file read/write.”

The demonstration includes:

  • Overviews of Ruckus Wireless Routers equipment and their attack surfaces. Explaining the firmware analysis and emulation prosses using our dockerized QEMU full system framework.
  • Demonstration on the first RCE and its specifics. Describing the webserver logic using the Ghidra decompiler and its scripting environment.
  • Demonstrating the second RCE using stack overflow vulnerability.
  • Determining the third RCE by using a vulnerability chaining technique.

Multiple vulnerabilities were reported on routers in recent times. Cisco, the networking hardware company, disclosed the existence of critical vulnerabilities in its business routers, recently.

According to an official statement, the Cisco Small Business Routers exhibited numerous security issues. Specifically, three major security bugs were discovered in the Cisco RV320 and RV325 Dual Gigabit WAN VPN Routers firmware named as CSCvq34465, CSCvq34469, and CSCvq34472.

The routers affected by these bugs faced issues like, Static certificates and keys, Hardcoded password hashes, and Multiple vulnerabilities in third-party software (TPS) components. If exploited, the vulnerabilities allow anyone to get access to the base operating system to easily gain root access on the target device, according to the statement.

Brazil Fines Facebook for US$ 1.6M Over Cambridge Analytica Scandal

Brazil’s court has fined Facebook for the misuse of personal data belonging to nearly half a million Brazilians during political campaigns. According to reports, a fine of 6.6 million Reais (US$ 1.6 million) was issued by the Ministry of Justice and Public Security of Brazil for the data misuse scandal by Facebook and consultancy firm Cambridge Analytica. It’s said that the social networking giant collected private data of around 87 million Facebook users via a personality quiz app – This Is Your Digital Life.

A statement issued by the Ministry stated that Facebook used Brazilian users’ data for purposes that were “at the very least, questionable” and Facebook is unable to reveal the number of users affected in the data breach.

The imposed fine is larger than the penalty £500,000 (US$ 656,000) issued by the UK government earlier this year, which is also a verdict from the investigation around the Cambridge Analytica scandal.

Also, earlier this year, Facebook was slapped with a massive US$ 5 billion fine by the Federal Trade Commission (FTC) for allegedly violating privacy practices and mishandling user data during the infamous Cambridge Analytica scandal and other privacy breaches.

The FTC ordered Facebook to adopt new policies for protecting users’ data and expand these policies across Instagram and WhatsApp. Facebook was also asked to create a new privacy committee that has independent board members. Moreover, a third-party assessor approved by the FTC will be brought on board to conduct biennial assessments and monitor Facebook’s privacy-related decisions.

“The Order imposes a privacy regime that includes a new corporate governance structure, with corporate and individual accountability and more rigorous compliance monitoring,” the FTC stated. “This approach dramatically increases the likelihood that Facebook will be compliant with the Order; if there are any deviations, they likely will be detected and remedied quickly.”

Responding to the fine, Facebook said “will require a fundamental shift in the way we approach our work and it will place additional responsibility on people building our products at every level of the company. It will mark a sharper turn toward privacy, on a different scale than anything we’ve done in the past.”

Microsoft Takes Control of 50 Domains Operated by North Korean Hackers

Phishing, phishing attacks

Microsoft announced that it has taken control of 50 domains operated by North Korean hacking group called “Thallium”. The tech giant stated that attackers used these domains to launch cyber-attacks on different locations including the United States, Japan, and South Korea.

The news came to light when Microsoft filed a lawsuit against Thallium in the U.S. District Court for the Eastern District of Virginia. The U.S. authorities ordered Microsoft to take control of the 50 domains that Thallium was using to perform their operations, as a result, these sites can no longer be used to execute any attack.

Microsoft said that its Digital Crimes Unit (DCU) and the Microsoft Threat Intelligence Center (MSTIC) have been tracking Thallium for months and have been gathering information on its operations.

Microsoft said these domains were used to send out phishing emails containing a malicious link, a method known as spear-phishing that typically tricks the victims to click and enter their details in a self-hosted page, which are then stored in a hacker database.

The intention of these attacks was to infect victims’ devices with Remote Access Trojans (RATs) such as KimJongRAT and Baby Shark. Once malware was installed it could exploit the information on the victim’s computer by granting remote access to execute commands sent by the hacker.

Tom Burt, Microsoft’s Corporate Vice President, Customer Security & Trust said, “Based on victim information the targets included government employees, think tanks, university staff members, members of organizations focused on world peace and human rights, and individuals that work on nuclear proliferation issues.”

This is not the first time Microsoft took hold of domains belonging to a hacker group. In August 2018, Microsoft filed similar legal actions and took down 84 domains belonging to the Russian group known as Strontium, and it also seized 99 domains that were operated by Phosphorus, an Iran linked cyber-espionage group in May 2019.

Reviewing the Security Predictions for 2019

trend micro's 2020 predictions

By Chris Roberts, Chief Security Strategist, Attivo Networks

Around October or November, we throw the collective fortune darts at the nearest board, wall, or screen to work out how the following year’s going to be in our electronic world.

We’re the digital equivalent of the Farmers’ Almanac.

Yet, how often have we really taken a look back and worked out how accurate we’ve been? How often do we look over our shoulder and assess our success rate and possibly how to improve our accuracy?

So, this year, instead of grabbing the nearest intern, developer, or passing user and practicing the art of extispicy like haruspices on them to work out what we’re going to be looking at in 2020, we’re going to take a look back at some of the 2019 predictions and have a little dig around the Internet to see how well the prognosticators faired.

If one of these predictions is yours or you were the one who copied it, rebranded it, and made it your company’s, then accept the criticism and be a little more careful with how you read this coming years entrails, as there are now consequences. You WILL be held responsible!

So, without further ado, let’s start with some of the cringe worth ones:

Rates of ransomware attacks will fall (Kiuwan)

I’m going to say this hasn’t been the case, and even if it can be found that the actual number of attacks in a country has decreased, then the effects and overall challenges with the attacks has significantly increased, especially in the case of many local, state, and government agencies, let alone the school districts and healthcare facilities. If you look at the statistics being quoted around the “every 14 seconds a business falls victim to a ransomware attack” we’re NOW down to 11 seconds, so this one’s been solidly sunk and we still have to deal with ransomware and all US$11 billion worth of damages.

AI will be a major force in information security (multiple sources for both defense and attack)

Ok, this one’s party true, but unfortunately not in the way we really want to see it. Marketing, sales, and all companies that blink in the night have taken up the cry of “AI will save us!.” As far as the eye can see, it’s a forest of AI marketing, explaining how their solution’s going to solve your problems and cook you breakfast in the morning, and most of it is utter codswallop. At best they’ve created an augmented system of pattern matching rules and assume the recommendations can now be called AI. We won’t even talk about their training models, their update capabilities, or understanding of how to scale and justify an ROI based on cost savings or increased maturity on the security scale. Please do right by all of us, stop throwing good money after bad and really dig into any AI solution to see what actually makes it tick and remember: all that glitters is not gold.

IoT regulations will finally be addressed (Alvarez)

We’ll go with partial credit on this one. Firstly, yes, the regulations are coming and it’s got NIST at the helm. The problem is, various NIST regulations appear to be held up and have been eaten by the “Swamp” or various parties within it. The IoT Cybersecurity Improvement Act (1668) is languishing somewhere in DC, and the Office of Management and Budgets or the Office of Information and Regulatory Affairs has eaten 800-53, which as we all know is one of the backbones of our industry. So, if someone in charge in DC is reading this, can you please finally finish red-lining all the stuff we need? Believe me, you, your friends, families, companies and the entire information security ecosystem will be better off for these things actually getting out of your hands and back to NIST’s and then out to the general population. Until that time, IoT’s a mess, in all likelihood your toaster probably hacked the fridge, which is connected to the Internet and is, therefore, mining cryptocurrency. What a mess.

GDPR will have a significant impact (multiple sources)

If you define a significant impact as making us more aware as to how badly we’re doing in information security then yep, we’ve doubled (or more) the number of breaches being reported. But, the regulation has been absolutely ineffective at levying sanctions, fines, or other legal actions against the companies that still fail to adequately protect our very data. The upside is that a unified front on notification is a good thing; the downside is the sheer volume of notifications simply shows us that we’re not having an impact on stemming the flow of data being stolen, let alone holding the industry or the enterprises accountable for the losses. It will be interesting to see if the U.S. takes note and learns from the colonial cousins across the pond or simply continues to tackle the problem in the patchwork fashion of 50 small independent countries (mostly) united under one flag.


RELATED STORY

CISO MAG Rewind: Biggest Financial Data Breaches of 2019


Honorable mentions:

Defenders will think and operate like the attackers (Our own company) and Companies will focus on their cyber hygiene of their own environments (Illusive Networks)

So, taking both Attivo and one of our competitors to task for these ones. It is something we want, something we aim for, and something we would like to see in the industry. More focus on defense, more focus on giving the blue teams some teeth, more time, effort, and budget spent developing the defensive, detection, deception, and proactive arms of the organizations out there…but, the reality is very different. Many companies are struggling to understand what they have, where it is, and what to do with it, all with limited resources and a plethora of regulatory and compliance directives to adhere to. It’s a real problem, and one that needs focus. The time has to be spent on helping to educate organizations, to work with them, develop roadmaps, run training, tabletops, and effectively act as their advocate in the industry. If we can take the time to do this, and we can bring our own industry into line, then, and only then I think we can make a difference and then the defenders will have the time to “think like the attacker” as opposed to firefighting on a daily basis.

Lastly on the 2019 reflections…

A huge shout out to Ray Potter for nailing his comments. He very eloquently stated: “Same sh**, different year” in an article used to pull some of these cringe worthy data points.

So, what have we learned aside from, don’t trust all that you read on the Internet?

Arm yourself with questions, educate yourself or people you trust around you to know what questions to ask. This is especially relevant when faced with newer technologies that are still establishing themselves in the marketplace.

If someone’s coming at you with data, statistics, metrics, and all sorts of theories as to why their solution is the only one, assume those statistics are tainted unless proven otherwise. Too many companies are buying their way to the top of the latest set of charts; too many organizations spend more on marketing themselves as successful than on development making sure they actually are.

Back to basics, a newly overused phrase that we still haven’t taken notice of. Get the simple things taken care of inside the environment before focusing on the blinky lights that do nothing more than mask the underlying issues. Educate the humans, take care of the defaults, the patching, the authentication, the users, their access, and get eyes on the inside of your world–the boundaries of which keep evolving.

Rules and regulations only go so far. They are impractical to enforce if the volume of inbound data exceeds the ability for the regulatory body to actually process. A disjointed approach to the problem will fail and a united “we” approach stands a chance of success, should all parties agree on a path forward.

We have a long way to go. We should take some time to look at 2019, realize what we’ve done, and then in most cases apologize for it and try to make amends in 2020. Our industry is amazing, innovative, creative, and has so much to give, but we are lost. We are (in the words of seven of nine) erratic, conflicted, and disorganized and that means we are not doing the one single thing that this entire industry was created for: we are not protecting our charges.

Make 2020 different.

Disclaimer: The article has been edited in accordance with the guidelines of CISO MAG. CISO MAG does not endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. Views expressed in this article are personal.