Home Blog Page 267

Your Fridge and Your Laptop Should Not be on the Same Network: FBI

IoT attacks

Internet of Things has helped to enhance the connected lifestyle, but it also created new attack vectors for hackers. Many security pros cautioned earlier that IoT devices have become a primary target for cybercriminals.

In its tech advice, the FBI recommended IoT users to isolate their primary connected devices like laptops or smartphones on a separate WiFi or LAN network.

“Your fridge and your laptop should not be on the same network,” FBI said in a post.

FBI advised to use two internet gateways. One for the devices that store sensitive data and another for digital assistants like home security devices, smartwatches, gaming systems, fitness trackers, thermostats, and smart light bulbs, etc., It also recommended to change factory-set default passwords.

What’s the Risk?

According to the FBI, the potential vulnerabilities in IoT devices allow hackers a path into a router network, giving access to other connected devices on a home network. Keeping separate network systems will prevent attacker intrusions to all the devices at a targeted location.

Use Micro-Segmentation

One can use two routers to place primary devices and IoT devices on separate networks. But, using “Micro-Segmentation” would be a good idea.

Micro-Segmentation is a feature available in the firmware of most WiFi routers that allows router admins to create virtual networks (VLANs), which behave as different networks even though they run on the same router. 

FBI Recommendations:

 FBI suggested the following guidelines to Build Digital Defense:

  • Change the device’s factory settings from the default password.
  • Passwords should be as long as possible and unique for IoT devices.
  • Many connected devices are supported by mobile apps on your phone. These apps could be running in the background and using default permissions that you never realized you approved. Know what kind of personal information those apps are collecting and say “no” to privilege requests that don’t make sense.
  • Make sure all your devices are updated regularly.

FBI also gave similar advice on dealing with smart TVs recently. Hackers can stalk users’ everyday movements and conversations using the integrated camera and microphone by exploiting the unsecured smart TVs, FBI said. 

Microsoft says 44 Million Users Reused Passwords in Q1 of 2019

common password of 2021,Password Protection, password spray attacks, Microsoft accounts passwords

Using a common password for various accounts might seem convenient, but it could be a potential threat for other accounts if an attacker breaks into one. With unprotected databases and online services getting breached often, leaked/stolen passwords from data breaches can pose a severe threat if users continue reusing their passwords.

It seems that most of the Microsoft services users also doing the same.

A recent investigation by the Microsoft threat research team revealed that 44 million users were reusing their usernames and passwords. The tech-giant stated it scanned all the company’s user accounts between January 2019, and March 2019.

The scanning was performed on a database of around 3 billion leaked credentials, which was obtained from multiple sources like public databases and law enforcement, Microsoft said.

Risks of Password Reuse

According to Microsoft, 30 percent of reused or modified passwords can be cracked within just 10 guesses. This puts users at risk of a breach replay attack. If attackers get hold of leaked credentials, they can try to execute a breach replay attack by trying the same credentials on different service accounts to break into.

Microsoft urged users to enhance their password hygiene with certain password security mechanisms like Multi-Factor Authentication (MFA). It’s said that around 99.9 percent of breach replay attacks have been prevented by using MFA, according to Microsoft.

Recently, a massive data breach exposed around 773 million email addresses and more than 21 million passwords unprotected online. According to security researcher Troy Hunt, the person behind the breach notification service website Have I Been Pwned, a huge database that includes records from more than 2,000 hacked databases were exposed online.

The breached data, which Troy Hunt dubbed as Collection #1, included almost 773 million (772,904,991) unique email addresses, and 21 million (21,222,975) unique passwords. Sized around 87 GB, the breached records also included 1,160,253,228 unique combinations of breached email addresses and passwords. Hunt stated the data breach is made up of various individual data breaches from thousands of other sources.

TrueDialog Database Exposes Tens of Millions of SMS Data

Bait attacks, Email Attacks

Around ten million text messages were exposed by an unprotected database run by an American-based communications company, TrueDialog.

Security experts Noam Rotem and Ran Locar from VPNMentor discovered that a leaky database exposed millions of users’ data, including text messages, names, addresses, and other private information.

TrueDialog provides bulk SMS services to U.S.-based companies, colleges, and Universities. The company took down the unprotected database after the researchers notified the incident.

The researchers observed the database which hosted 604 GB of data and contained around one billion entries of TrueDialog’s customers. Apart from private text messages, millions of account usernames and passwords, years of information on TrueDialog’s business model, conversations with its customers, and account details were exposed in the incident.

“It’s difficult to put the size of this data leak into context. Tens of millions of people were potentially exposed in several ways. It’s rare for one database to contain such a huge volume of information that’s also incredibly varied. The database contained entries that were related to many aspects of TrueDialog’s business model,” the report stated.

The report also added, “The company itself was exposed, along with its client base, and the customers of those clients. The information contained in this database could have been used in myriad ways against the people whose information was exposed.”

In a similar security incident, Security researchers discovered an open Elasticsearch server that contains unique data records of around 1.2 billion users. According to the security analysts Bob Diachenko and Vinny Troia, the server holds more than 4 terabytes of data, without password protection or authentication.

The exposed data included names, email addresses, phone numbers, LinkedIn, and Facebook profile information. It’s believed that the exposed data appear to have originated from two different data enrichment companies namely People Data Labs (PDL) and OxyData.Io (OXY).

Iranian Hackers Deploy New Data-Wiping Malware: IBM

BotenaGo, malware over encrypted connections

Security analysts from IBM recently discovered a data-wiping malware dubbed as ZeroCleare.

IBM claims that the malware was developed by Iranian state-sponsored hackers and used in cyber-attacks against energy companies in the Middle East region. However, the company didn’t mention the companies’ names that have been targeted by ZeroCleare malware.

In its research report, IBM stated the malware is the creation of two hacking groups namely xHunt and APT34.

Describing the ZeroCleare attack, IBM stated that ZeroCleare is a Wiper malware designed to delete information from an infected host. The attackers can use this Wiper malware to hide their intrusions by deleting crucial forensic evidence.

 ZeroCleare’s Infection Flow

Researchers said that the hackers launch brute-force attacks to gain access to weakly secured network systems. Once attackers infect the target device, they spread the malware across the company’s network as the last step of infection.

“The ZeroCleare wiper is part of the final stage of the overall attack. It is designed to deploy two different ways, adapted to 32-bit and 64-bit systems. The general flow of events on 64-bit machines includes using a vulnerable, signed driver and then exploiting it on the target device to allow ZeroCleare to bypass the Windows hardware abstraction layer and avoid some operating system safeguards that prevent unsigned drivers from running on 64-bit machines,” reads IBM’s report.

In January this year, a report from FireEye claimed that an undetected hacker group from Iran allegedly stole travel and mobile data of individuals in the Middle East region.

According to FireEye, the Iranian group dubbed APT39 has targeted several people in the Middle East, especially in the Gulf region. It’s believed that the espionage group is allegedly providing information to the Iranian government. FireEye stated that they had been tracking APT39 activities since 2014 to protect organizations from cyber incidents.

FireEye also observed that the group uses Persian language words in encrypting data. APT39’s activities are reportedly focused on the telecommunications sector, the travel, and the IT industry, and allegedly represent Iran’s potential global operational reach and how it collects key data.

Attackers Using Facebook’s Ads Manager as Cyberespionage Tool

Facebook copyright complaint

A newly discovered Trojan, dubbed Socelars, allows bad actors to access Facebook advertisements, the Bleeping Computer reported.

The issue came to light after a security researcher Vitali Kremez found that Socelars Trojan was distributed through a fake PDF editing app “PDFreader”. It’s said that attackers are using this Trojan to dig information from Facebook ads.

What’s the Risk?

According to MalwareHunterTeam, the Socelars Trojan tries to steal Facebook session cookies from Chrome and Firefox and then use them to connect to other Facebook URLs.

The stolen data includes advertising email address, session cookies, access tokens, account ids, associated pages, credit card details, PayPal email, ad balances, and spending limits. The data then transferred to the attacker’s Command & Control server.

Primary Target on Facebook Ads Manager

Vitali Kremez stated that attackers using stolen information to extract the user’s account_ID and access token, which were later used in a Facebook Graph API call to steal data from the user’s Ads Manager settings.

If malicious actors access the information of the ads, they can create their own campaign ads, not only regular advertisements but the political posts, which could bring severe implications during elections.

Besides targeting on Facebook ads, the Trojan is also attempting to steal session cookies for Amazon.com and Amazon.co.uk, the researcher said.

With the U.S. elections approaching and bad actors abusing campaigns/ads in the past, it’s a heads-up for anyone running political campaigns.

Recently, Facebook stated that it is tightening its security for the 2020 U.S. elections after fresh signs of Russia meddling. The social media giant stated that it’s taking down accounts involved in illicit activities and stepping up searching state-controlled media trying to manipulate American voters.

Facebook pledged to use a variety of security measures, including artificial intelligence, to counter Russian attackers or other online intruders who use misleading strategies and false information to meddle in the 2020 U.S. elections.

The new steps announced by Facebook include, Fighting Foreign Interference, Preventing inauthentic behavior, Increasing transparency, Labeling state-controlled media on their Page and in the Ad Library, Preventing the spread of misinformation, and monitoring candidates accounts, elected officials through Facebook Protect.

TikTok Stealthily Transferring Users’ Data to China: Lawsuit

TikTok, TikTok data privacy, TikTok children's privacy

Popular video-sharing app TikTok recently hit with a class-action lawsuit in the U.S. claiming that the company has been surreptitiously transferring users’ data to Chinese servers, without the user’s consent.

The proposed class-action lawsuit was filed in California federal court by Misty Hong, a student from Palo Alto.

In her lawsuit, Misty Hong alleges that TikTok and its Beijing-based parent company ByteDance has failed to properly handle users’ data and knowingly violated the Right to Privacy act. The company is also accused of taking users’ draft videos and presenting uncertain privacy policies.

According to the lawsuit, Hong installed the TikTok app in April 2019 but never created an account. But she discovered that TikTok created an account for her, without her consent. Though Hong never saved or published her videos, TikTok secretly transferred her data to Chinese servers.

It’s said that TikTok collecting a set of users’ data, including phone and social network contacts, email addresses, IP addresses, and location.

Claimed to have around half a billion active users worldwide, TikTok previously said it does not store user’s data on Chinese servers. The incident raised severe concerns that data culled by TikTok could be used to identify, profile, and track users.

“TikTok clandestinely has vacuumed up and transferred to servers in China vast quantities of private and personally identifiable user data that can be employed to identify, profile and track the location and activities of users in the United States now and in the future. TikTok also has surreptitiously taken user content, such as draft videos never intended for publication, without user knowledge or consent. In short, TikTok’s lighthearted fun comes at a heavy cost,” the Lawsuit stated.

The proposed lawsuit also stated, “TikTok unjustly profits from its secret harvesting of private and personally identifiable user data by, among other things, using such data to derive vast targeted-advertising revenues and profits. Its conduct violates statutory, Constitutional, and common law privacy, data, and consumer protections.”

Japan Joins NATO’s Cooperative Cyber Defense Centre of Excellence

Japan restricts foreign equipment and tech, Japan Embraces AI Tools to Fight Cyberattacks with US$237 mn Investment

Shinzo Abe, the Prime Minister of Japan, recently announced the decision of Japan joining the North Atlantic Treaty Organization’s (NATO) accredited cyber defense hub in Tallinn, Estonia.

With this decision, Japan becomes a full-fledged participant in NATO’s Cooperative Cyber Defense Centre of Excellence (CCDCOE) program that focuses on cybersecurity research, training, and exercises. The country also upgrades its role from observer status, a position that Japan held between 2015 and 2018.

This move will further strengthen the knowledge base of the currently 20-nation-strong CCDCOE program. NATO’s Cyber Coalition exercises present different scenarios including cyberattacks during the cross-border conflict and compromised state computer systems.

“We welcome the decision of Japan to join CCDCOE as a Contributing Participant, membership status available to non-NATO nations. Japan is one of NATO’s key partners beyond the Euro-Atlantic area and a globally recognized technology and cybersecurity power. Joining the Centre will be a concrete step forward signaling the commitment in cyber defense cooperation between like-minded nations,” said Merle Maigre, Director of the NATO Cooperative Cyber Defence Centre of Excellence.

Earlier, the Japanese government was criticized for hacking the IoT devices of its citizens. The initiative was part of a unique survey the government undertook with the intention of securing IoT devices of its citizens. The survey will be carried by the National Institute of Information and Communications Technology (NICT) with an active involvement of the Ministry of Internal Affairs and Communications.

As part of the survey, employees of NICT will try to hack IoT devices of citizens using default passwords and password dictionaries. After this, they will prepare a list of insecure devices that uses default passwords or easy-to-guess passwords and will submit the list to relevant authorities, as well as internet service providers who will then alert the citizens and ask them to change passwords as well as secure their devices.

The Remote of Your Smart TV Could be in Hackers’ Hand!

Smart TV

Often dubbed as an idiot box, the television is no longer just a dumb gadget. It’s become smart, and is growing smarter, in-line to become one of the smartest household gadgets. From kids to adults, everyone loves to have the smart TV as a center piece in their living room. What you don’t know though, is that having it in your house might just give a free pass to the hackers inside your home, says FBI.

Smart TVs with internet connectivity allow users to browse the web and watch shows from their favorite streaming platforms. They also come with a range of customizable features in lieu of a remote control, including voice commands to flip through channels or to turn up the volume. A few new ones also come with integrated cameras and microphones to provide facial recognition and can be used instead of tablets or laptops for video calling.

Unlike other smart gadgets on offer, smart TVs have one of the most overlooked and neglected issues – security. For several smart TV manufacturers, security of these IoT devices are an afterthought. The result is inevitable, a smart device that is vulnerable to different kinds of threats.

Hackers can not only control your unsecured TV for changing channels or volume controls but also stalk your everyday movements and conversations using the integrated camera and microphone. FBI has asked smart TV users to take following precautionary measures:

  • Know exactly what features your TV has and how to control those features. Do a basic Internet search with your model number and the words “microphone,” “camera,” and “privacy.”
  • Don’t depend on the default security settings. Change passwords if you can – and know how to turn off the microphones, cameras, and collection of personal information if possible. If you can’t turn them off, consider whether you are willing to take the risk of buying that model or using that service.
  • If you can’t turn off a camera but want to, a simple piece of black tape over the camera eye is a back-to-basics option.
  • Check the manufacturer’s ability to update your device with security patches. Can they do this? Have they done it in the past?
  • Check the privacy policy for the TV manufacturer and the streaming services you use. Confirm what data they collect, how they store that data, and what they do with it.

A similar warning was given earlier by Vince Steckler, Chief Executive at security firm Avast. In a media statement he said, “The Internet-connected devices used in the home, like laptops, mobile phones, and other smart gadgets, aren’t secure as they allow hackers to use them to get hold of bank details and other personal information.” He further added, “Coffee machines are not designed for security. TVs are not designed for security. What they are is additional vectors to get into your network. And you can’t protect them.”

New Malware “PyXie” Uses Trojanized Tetris Game

Researchers have discovered a malware operation that uses a trojanized version of Tetris game to target healthcare and educational institutions for credential stealing.

Security pros at Blackberry Cylance stated that threat actors are trying to distribute ransomware with a malware named “PyXie”. It’s said that PyXie, which is written in Python programming language, has been in the wild since 2018.

According to a report from Blackberry Cylance, the Python-based trojan malware gives attackers the control of Windows systems to monitor actions and steal sensitive data.

PyXie is highly customizable and can be used to launch a variety of attacks like credential harvesting, man-in-the-middle, web-injection, keylogging, and video harvesting, suggested Ryan Tracey, a senior threat researcher at BlackBerry Cylance.

Spreading via Trojanized Tetris Game

The analysts observed that an unknown hacking group used a genuine software Cobalt Strike and a trojanized Tetris game to spread the malware.

Once the victim downloads the game, the trojanized Tetris app executes Cobalt Strike binaries, which escalates the privilege in the victim’s Windows OS. After the trojan injected, a malware downloader Cobalt Mode will also get installed in the system to help attackers perform tasks like communicating with the command-and-control server, downloading and decrypting the payload.

It’s still unclear on who’s behind the PyXie campaign.

“PyXie has been deployed in an ongoing campaign that targets a wide range of industries. It has been seen in conjunction with Cobalt Strike beacons as well as a downloader that has similarities to the Shifu banking Trojan. Analysts have observed evidence of the threat actors attempting to deliver ransomware to the healthcare and education industries with PyXie,” stated the report.

Regardless of the advanced capabilities of PyXie, the researchers stated that it can be prevented by application patching, endpoint-protection technology, auditing, logging, and monitoring of endpoint and network activity.