Home Blog Page 274

“Pipka” JavaScript Skimmer Targets Ecommerce Websites

Skimming-Attack

Visa, in a security alert rung alarm bells for eCommerce websites. Researchers at Visa’s eCommerce Threat Disruption (eTD) program found a new JavaScript skimmer called “Pipka”. It has already affected 16 eCommerce websites.

eTD is a proprietary Visa solution under its Payment Fraud Disruption (PFD) program. It scans the internet to identify malicious code on merchant payment pages and provides threat notification so that affected merchants can quickly take remedial measures. During one such routine scanning procedure carried out in September, researchers stumbled upon Pipka JavaScript skimmer on a North American merchant website. According to Visa, this merchant website was earlier infected with another JavaScript skimmer Inter – and hence was specifically under eTD’s scanner.

What’s New?

After its execution, Pipka JavaScript skimmer can remove itself from the HTML code of the compromised website, thereby decreasing the likelihood of detection. Visa says that it has not seen anything like this before and it’s a proof that cybercriminals are getting more sophisticated in the way they are carrying out attacks by the day.

What does it extract?

Pipka enables configuration of form fields that allows extraction of payment card details such as payment account number, expiration date, CVV, and cardholder name and address, from the checkout pages of the targeted eCommerce website.

How does it extract?

According to PFD, the skimmer checks the payment account number form field and injects Pipka in various locations of the targeted website. Once executed, it collects the data from the configured form fields and perform a base64 encoding on it. This encoded data is further encrypted using ROT13 cipher. The ROT13 cipher is a substitution cipher with a specific key where the letters of the alphabet are offset 13 places.

For example, all ‘A’s are replaced with ‘N’s, all ‘B’s are replaced with ‘O’s, and so on. For more clarification refer the below substitution key:

ABCDEFGHIJKLMNOPQRSTUVWXYZ

↓↓↓↓↓↓↓↓↓↓↓↓↓↓↓↓↓↓↓↓↓↓↓↓↓↓↓↓↓↓↓↓↓↓↓↓↓↓↓

NOPQRSTUVWXYZABCDEFGHIJKLM

It can also be thought of as a Caesar cipher with a shift of 13.

Further, Pipka checks if the data string was previously sent to avoid data duplication. If the data string is unique, then data is fetched and sent to a command and control (C2) server. Pipka’s self-cleaning begins as soon as the initial script loads. This is exactly the reason why it is so difficult to detect its presence on a compromised web page.

What are its effects?

Sam Cleveland, senior analyst at Visa’s PFD team, says Visa presently is unable to provide any information on payment card fraud or theft related to Pipka. “Visa does not have this information to share due to this being an ongoing investigation,” Cleveland says. But as per the payment card information harvested, cybercriminals can carry out financial frauds and identity theft related crimes.

What mitigation measures can be taken?

Visa has listed the following measures and asked eCommerce websites to strictly adhere to it:

  • Implement recurring checks in eCommerce environments for potential communications with the C2 servers
  • Be vigilant about the code integrated into eCommerce environments via service providers.
  • Keep a close eye on the Content Delivery Networks (CDN)
  • Regularly scan and test eCommerce sites for vulnerabilities or malware
  • Ensure third-party services and other integrations are all upgraded and patched
  • Exercise access control to Admin users

Visa also informed its merchants to contact them immediately in case the Pipka JavaScript skimmer does infect their website even after taking preventive measures.

7 Times Ransomware Became a Major Healthcare Hazard

Cyberattack on Ireland's Health care

By Rudra Srinivas

Cyber-attacks on healthcare organizations has become a trend in the last few years. With sensitive information of their patients with them, healthcare providers have become a hot favorite for attackers. According to Beazley Breach Insights Report, healthcare organizations have suffered the highest number of data breaches in 2018 than any sector in the U.S. economy.

In 2019, healthcare firms continued to be primary targets of cyber-attacks with several data breaches and ransomware attacks taking major headlines again. The financial health of the healthcare industry might get even worse with data breaches expected to cost US$ 4 billion by the end of the year.

The recent outbreak of ransomware attacks on hospitals and healthcare providers shows the serious threat these attacks vectors can pose. Here are seven times when ransomware attacks took a toll on the healthcare sector.

DCH Medical Center:

DCH Health System in Alabama paid an undisclosed ransom to hackers to unlock its IT system, after three of its hospitals were attacked in October this year. According to reports, the attack affected the IT systems of the DCH Regional Medical Center, Northport Medical Center, and Fayette Medical Center from West Alabama’s Tuscaloosa, Northport, and Fayette.

The affected hospitals turned away new patients and even canceled several surgeries. The government authorities later stated that they’re working with the affected health services and cybersecurity professionals to investigate the incident.

 Multiple Hospitals in Australia:

Network systems at several hospitals and healthcare services in Gippsland and south-west Victoria were targeted by a ransomware attack. The attack blocked access to several systems including financial management and led to the deletion of several patients’ records, as well as booking and management systems, which may have impacted patient contact and scheduling. However, the Victorian government clarified that there was no sign of patients’ data being stolen.

Premier Family Medical at Utah

Protected Health Information (PHI) of more than 300,000 patients of the physician group named Premier Family Medical at Utah was compromised in a ransomware attack in September. The group confirmed the attack but didn’t disclose the number of patients affected.

According to an official statement, the incident occurred on July 8, 2019, that barred access to patients’ data and other network systems. The physician group stated that it notified law enforcement authorities about the attack and appointed a technical team to investigate the issue and regain access to its systems and patient data.

 NEO Urology

NEO Urology in Boardman, Ohio suffered a ransomware attack after hackers breached its entire IT system and left all its data encrypted. According to an official statement, the hospital authorities paid US$ 75,000 ransom to hackers to unlock their data. An investigation by the company revealed the attack had likely originated from Russia.

Harbor Medical Group

Hackers infected Grays Harbor Community Hospital and Harbor Medical Group with ransomware and demanded a payment of US$ 1 million to unlock patients’ files. Washington-based hospitals also faced downtime issues. According to the reports, the attack had triggered after an employee clicked on a malicious link containing ransomware.

Wood Ranch Medical

Wood Ranch Medical decided to permanently close its services after it failed to recover patients’ records that were encrypted in a ransomware attack on August 10, 2019. The California-based health services provider stated that it would be impossible to rebuild its medical records and will close its practice and cease operations on December 17, 2019.

Health Alliance Plan

Around 120,000 Health Alliance Plan patients were affected in a ransomware attack. The health service provider stated their personal and medical data were breached after a ransomware attack hit its third-party vendor Wolverine Solutions Group. The compromised data included patients’ names, addresses, dates of birth, Social Security numbers, insurance contact details and numbers, medical data, and phone numbers.

Rudra Srinivas is part of the editorial team at CISO MAG and writes on cybersecurity trends and news features. 

Researchers Found 265 Fake Sites Spreading Anti-Pakistan Propaganda

99% of Websites Are Prone to Cyberattacks Via JavaScript Plug-Ins: Report

Researchers discovered a network of around 265 fake websites in 65 countries that is operated by a shadowy Indian company to spread anti-Pakistan propaganda.

The campaign was discovered by EU DisinfoLab, an EU-based NGO focused on researching sophisticated disinformation campaigns.

The NGO stated the fake news sites are traced back to a group of Indian companies, NGOs, and think tanks. It’s said that the campaign is aimed to sway lawmakers in Europe in favor of Indian interests in Kashmir.

Revealing its findings in a blog post, EU DisinfoLab highlighted that all the fake news sites were registered to use a domain that mimicked the name of a popular local news site or used the name of an inactive newspaper. They republish content from news agencies like KCNA, Voice of America, and Interfax covering Indian-related demonstrations and events. The sites also republish anti-Pakistan content from the Indian network, including EP Today, 4NewsAgency, Times of Geneva, and New Delhi Times.

“EU DisinfoLab quickly discovered that EP Today is managed by Indian stakeholders, with ties to a large network of think tanks, NGOs, and companies from the Srivastava Group. We also found that the IP address of the Srivastava Group is also home to the obscure online media “New Delhi Times” and the International Institute for Non-Aligned Studies (IINS), which are all based at the same address in New Delhi, India,” EU DisinfoLab said in a statement.

“Using OSINT (Open-Source Intelligence) techniques, we continued our investigation into this network, and this led us to Geneva, where the UN Refugee Agency has its headquarters. There, we discovered timesofgeneva.com – an online “newspaper” that is “approaching 35 years in business”. Strangely enough, Times of Geneva publishes the same type of content as EP Today and produces videos covering events and demonstrations criticizing Pakistan’s role in the Kashmir conflict,” the statement added.

Facebook Bug Turns On iPhone Camera Inadvertently

Facebook Bug iPhone Camera

This might be shocking news for iPhone lovers, who strongly believe that their Apple devices are safe, and no one can spy on them. A recent discovery revealed that Facebook is accessing the iPhone’s camera without user permission.

The issue came to light after a user going by the name Joshua Maddux reported the unusual behavior. Maddux took to Twitter to display the issue, which occurs in the Facebook app for iOS.

“Found a @facebook #security & #privacy issue. When the app is open it actively uses the camera. I found a bug in the app that lets you see the camera open behind your feed. Note that I had the camera pointed at the carpet,” Joshua Maddux said in a post.

The footage he shared shows the rear camera which is active in the background while he scrolls through his Facebook feed. It’s believed that a bug in the Facebook application inadvertently gained access to the iPhone user’s camera.

Maddux highlighted that he found the same issue on five different iPhones running iOS 13.2.2. It seems like the issue is not limited to only one user as many other people had reported a similar issue online.

However, Facebook has also confirmed the issue, calling it a bug. “We recently discovered our iOS app incorrectly launched in the landscape. In fixing that last week in v246 we inadvertently introduced a bug where the app partially navigates to the camera screen when a photo is tapped,” Facebook VP of Integrity Guy Rosen tweeted. “We have no evidence of photos/videos uploaded due to this.”

Rosen also stated that Facebook is submitting a patch to the App Store to fix the bug.

From the Cambridge Analytica data breach to a hack of more than 50 million accounts in 2018, Facebook users have several privacy concerns about the social media giant.

Recently, Facebook agreed to pay the £500,000 (around US$ 645,000) penalty imposed by the Information Commissioner Office (ICO), the UK’s data protection watchdog, for failing to safeguard the users’ data gathered by political data firm Cambridge Analytica. According to the settlement deal, Facebook agreed to drop its legal appeal against the penalty. The ICO stated that Facebook can retain some documents that ICO disclosed during the appeal process to use for its own investigation into issues around Cambridge Analytica.

Hackers Demand US$ 5 Million in Ransom from Mexico’s Pemex

Bitcoin, Ransomware Attacks

Pemex, a Mexican state-owned petroleum company is the latest victim of a ransomware attack. The attackers demanded around US$5 million ransom in bitcoins to take off the ransomware from their systems, according to a report from the Reuters.

The petroleum company stated that it detected the hack on November 10, 2019, and shut down its computers across Mexico after the attack, that disturbed its systems and halted certain payment operations. The attackers warned Pemex with a 48-hour deadline and listed an email address on the website to contact.

However, Pemex denied the impact of the cyberattack saying, “Let’s avoid rumors and disinformation,” in a statement. The company stated that the attack had affected less than 5 percent of its computers and its storage and distribution facilities were operating fine.

It’s unclear which ransomware was used by hackers to launch the attack. The Pemex officials said that hackers were attacked by “Ryuk” ransomware. But according to Reuters, which saw a ransom note that appeared on Pemex computers, it’s affiliated with the “DoppelPaymer” ransomware.

Multiple organizations and governments have fallen victim to ransomware attacks in recent times. In July this year, Louisiana declared a state of emergency after a wave of ransomware attacks hit school districts. The incident affected school systems in Sabine, Morehouse, and Ouachita parishes in North Louisiana. The attack infected the school’s computer and network systems with ransomware. The Emergency Declaration allows Louisiana’s cybersecurity experts to assist local governments in securing their network systems.

Recently, the Texas Department of Information Resources (DIR) revealed that around 23 Local Government Organizations in Texas have been hit with a ransomware attack. “On the morning of August 16, 2019, more than 20 entities in Texas reported a ransomware attack.  The majority of these entities were smaller local governments,” the DIR said in a statement. “The State of Texas systems and networks have not been impacted. It appears all entities that were actually or potentially impacted have been identified and notified.”

Google Partners with Ascension for “Project Nightingale”

Google’s Project Nightingale

Search engine giant Google recently unveiled an alliance with the U.S.’s popular health-care systems provider Ascension to design an AI-driven software.

Under the alliance, named as “Project Nightingale,” Ascension will be migrating its on-premises data warehouse and analytics infrastructure to a Google cloud environment via Google G-suite tools and support Google’s artificial intelligence and machine learning technologies to bring improvements in clinical quality and patient data security.

According to a report from the Wall Street Journal, Ascension is working with Google to deliver a comprehensive portfolio of digital capabilities that enhance the experience of Ascension consumers, patients, and clinical providers. It’s said that Google is collecting the detailed personal-health information of millions of people across 21 states and permitting nearly 150 Google employees to access the data.

The alliance has sparked concern among cybersecurity experts, consumer advocates, and even certain Ascension employees because neither patients nor physicians were informed previously about the data-sharing arrangement. The project is raising severe privacy concerns, as the partnership involves sharing of millions of patients’ data without their permission.

The information that Ascension is sharing with Google included patient names, diagnoses, lab results, hospitalization records, health histories, and date of birth, according to the Wall Street Journal report.

Ascension is a faith-based healthcare organization committed to transformation through innovation across the continuum of care. The health system holds more than 2,600 care facilities, including 150 hospitals in the country.

Describing the initiative, Tariq Shaukat, president of industry products and solutions at Google Cloud, said: “Today, we’re proud to announce more details on our partnership with Ascension, one of the nation’s leading non-profit health systems, to support them with technology that helps them to deliver better care to patients across the United States. There’s been a good deal of speculation on this partnership, so we want to make sure everyone has the facts.”

“The partnership will modernize Ascension’s infrastructure, enabling them to migrate their on-premise data warehouse and analytics environments to their own private and secure Google Cloud environment. Key elements of this work will focus on network and system connectivity, data integration, privacy and security, and compliance,” Shaukat added.

A recent joint study from Michigan State University and Johns Hopkins University revealed that more than 169 million people lost their health records in healthcare data breaches over the past decade.

The study analyzed around 1461 health care breaches reported to the Federal government between October 21, 2009, and July 1, 2019. The exposed Patient Health Information (PHI) included patient’s diagnosis, lab results, treatment, and prescriptions along with personal data, including patient names, date of birth details, e-mail addresses, phone numbers, social security numbers, and driving license details.

UK’s Labour Party Successfully Defeated a Cyber-Attack

Labour Party

The Labour Party in the United Kingdom stated that it effectively sustained a cyber-attack that targeted its digital platforms. Describing it as a “sophisticated and large-scale cyber-attack,” the party officials stated the attack affected the party’s website and online campaigning tools temporarily, the BBC reported.

The officials of the Labour Party clarified that no data breach had occurred as they’re maintaining a strong security system. It’s believed that the attacks came from computers linked to Russia and Brazil.

“Yesterday afternoon our security systems identified that, in a very short period of time, there were large-scale and sophisticated attacks on Labour Party platforms, which had the intention of taking our systems entirely offline,” said Niall Sookoo, the party’s executive director of elections and campaigns.

“The integrity of all our platforms was maintained and we are confident that no data breach occurred,” Our security procedures have slowed down some of our campaign activities, but these were restored this morning and we are back up to full speed,” Sookoo added.

The party officials stated that they’ve notified the incident to the National Cyber Security Centre for further investigation. The attack comes in front of the General Election campaign, with the UK set to go to the polls on December 12, 2019.

The election campaigns have always been a primary target for cybercriminals. The attackers try to steal sensitive information and even manipulate election advertisements online.

Recently, Facebook stated that it is tightening its security for the 2020 U.S. elections after fresh signs of Russia meddling. The social media giant stated that it’s taking down accounts involved in illicit activities and stepping up searching state-controlled media trying to manipulate American voters.

Facebook pledged to use a variety of security measures, including artificial intelligence, to counter Russian attackers or other online intruders who use misleading strategies and false information to meddle in the 2020 U.S. elections.

Microsoft Rolls Out the Red Carpet for CCPA in U.S.

Brand Phishing Attacks

In an age where data traffic volumes are higher than the road traffic, the lack of a comprehensive privacy law has long been a case of concern for general census. But this seems to be changing soon as the California Consumer Privacy Act (CCPA), comes into effect from January 1, 2020. This is a baby step towards solving the larger problem, but it is a start, nevertheless. Among the first few to support this law are Microsoft. A statement made by Julie Brill, Corporate Vice President for Global Privacy and Regulatory Affairs and Chief Privacy Officer at Microsoft said, “Microsoft honors CCPA compliance and is committed towards handing data privacy rights in their (peoples) own hands.”

“We are strong supporters of California’s new law and the expansion of privacy protections in the United States that it represents. Our approach to privacy starts with the belief that privacy is a fundamental human right and includes our commitment to provide robust protection for every individual. This is why, in 2018, we were the first company to voluntarily extend the core data privacy rights included in the European Union’s General Data Protection Regulation (GDPR) to customers around the world, not just to those in the EU who are covered by the regulation. Similarly, we will extend CCPA’s core rights for people to control their data to all our customers in the U.S.”

This new law will give consumers the right to control their personal data and information. Following are some of the key rights that CCPA will empower consumers with:

Right to Ownership: Protect your right to tell a business not to share or sell your personal information.

Right to Control: Gain control over the personal information that is collected about you.

Right to Security: Hold businesses responsible for safeguarding your personal information.

Julie further says, “We (Microsoft) are optimistic that the California Consumer Privacy Act — and the commitment we are making to extend its core rights more broadly — will help serve as a catalyst for even more comprehensive privacy legislation in the U.S. As important a milestone as CCPA is, more remains to be done to provide the protection and transparency needed to give people confidence that businesses respect the privacy of their personal information and can be trusted to use it appropriately.

In addition to guaranteeing the rights of individuals to control their personal information, we believe privacy laws should be further strengthened by placing more robust accountability requirements on companies. This includes making companies minimize the data they collect about people, specify the purposes for which they are collecting and using people’s data, and making them more responsible for analyzing and improving data systems to ensure that they use personal data appropriately.”

Appdome, VMware Partnership to Help Customers to Deliver Workspace ONE Security, Privacy and Intelligent Analytics Capabilities

Collaboration, partnership, alliance, KnowBe4 and Agari Partner to Prevent Identity-Based Email Attacks

One of the mobile industry’s first no-code mobile solutions platforms Appdome has partnered Vmware. With this partnership, Appdome will be available for VMware Workspace ONE, a new no-code solution that enables every enterprise to deliver Workspace ONE security, privacy and intelligent analytics capabilities in a single solution for any iOS or Android app out of the box.

The new service will enable enterprise customers to quickly and easily deliver the complete Workspace ONE SDK into any mobile app, with full support for all modern frameworks, push notifications and Wkwebview, plus advanced support for data encryption, data & video tunneling, DLP, mobile app security and more.

“VMWare’s Workspace ONE is leading in the UEM market,” said Tom Tovar, CEO of Appdome. “Our goal is to make it super easy for enterprise customers and app developers to adopt Workspace ONE and, without coding a thing, get the full benefit of all the services and capabilities that Workspace ONE has to offer inside Android and iOS apps.”

Appdome for VMware Workspace ONE UEM also comes out of the box with support for VMWare’s secure mobile ecosystem, including optional integrations to VMWare’s secure browser, secure email, and secure document sharing. Just as important, Appdome for VMware Workspace ONE UEM allows enterprise customers to build WS1 Intelligence Analytics SDK and WS1 Privacy SDK into mobile apps, with no code or coding required.

“Customers need to manage a landscape of constantly changing security, privacy and supportability requirements, which is both costly to deal with and difficult to find the right expertise,” said Evan Hurst, Director of Product Management at VMware. “By pairing the capabilities of the Workspace ONE Platform and SDK with Appdome’s no-code integration platform for any mobile app, we can lower the cost and complexity of building enterprise-ready applications for our customers.”

OpenText Venturing into Cloud Security with Carbonite Acquisition

Partnership

Canada based OpenText, is a leading content services provider and has announced the acquisition of Carbonite, a cloud-based data protection and cybersecurity solutions provider. This acquisition is valued at about US$1.42 billion, which includes debt obligations. As reported by Reuters, the deal is expected to close within 90 days with OpenText paying close to US$800 million (i.e. US$23 per share) in cash to Carbonite.

OpenText has already acquired EasyLink, GXS, ANX, Covisint, Recommind, Hightail, Catalyst and Liaison. These are all cloud-focused entities, and now adding Carbonite at the ninth spot consolidates its position in providing cloud security to its offerings in data-loss prevention and digital forensics services. However, the hidden motive of OpenText is to combine its various service offerings and create a single broad cloud platform that solves multiple business problems starting with content management services.

“This acquisition will further strengthen OpenText as a leader in cloud platforms, complete end-point security and protection, and will open a new route to connect with customers, through Carbonite’s marquee SMB/prosumer channel and products,” said Mark J. Barrenechea, CEO and CTO of OpenText, in a statement to Bizjournals. “We are very excited about the opportunities that Carbonite will bring, and I look forward to welcoming our new customers, partners and employees to OpenText.”

Earlier this year, Carbonite itself had announced the acquisition of cybersecurity solutions provider Webroot in a cash deal of US$618.5 million. The alliance combined the cloud-based backup and recovery solutions together with cloud-based cybersecurity, which brought a new approach to endpoint data protection.

OpenText recently reported first-quarter revenue of US$74.4 million, or 27 cents a share, on revenue of US$696.9 million with about US$1 billion in cash. On the other hand, Carbonite reported third-quarter revenue of US$125.6 million and a net loss of US$14 million which probably prompted them for going ahead with the acquisition process.