Home Blog Page 276

Insider Sold 68K Customer Records to Scammers: Trend Micro

Insider attacker leak data

Cybersecurity and defense company Trend Micro revealed that one of its employees illegally accessed and sold personal information of around 68,000 of its customers.

The company stated that customers’ data like names, email addresses, ticket support numbers, and phone numbers were copied from its internal database by the employee and sold off to scammers. However, Trend Micro stated that payment card details or enterprise customer accounts have not been accessed.

Trend Micro became aware of the incident in August 2019, after some of its customers complained that they’re receiving scam calls by criminals impersonating Trend Micro staff.

“Our open investigation has confirmed that this was not an external hack, but rather the work of a malicious internal source that engaged in a premeditated infiltration scheme to bypass our sophisticated controls,” Trend Micro said in a statement.

“Our investigation revealed that this employee sold the stolen information to a currently unknown third-party malicious actor. We took swift action to contain the situation, including immediately disabling the unauthorized account access and terminating the employee in question, and we are continuing to work with law enforcement on an ongoing investigation,” the statement added.

With its HQ in Japan, Trend Micro is a major player in the information and network security landscape. Founded in 1988, the company holds a variety of cybersecurity merchandise for multiple operating systems, including threat detection, and antivirus products.

In its Mid-Year Cybersecurity report, Trend Micro revealed that out of 1.8 billion ransomware threats, from January 2016 to June 2019, the highest number of ransomware threats (42.98 percent) are suffered by businesses in Asia. And the companies in India reported around 23.88 percent of ransomware attacks in the first half of 2019, the report stated.

The company recently revealed a 265 percent increase in Fileless Attacks in the first half of 2019 when compared with the same period in 2018. A Fileless Attack, also known as a zero-footprint attack or non-malware attack, will not install any malicious software on a user’s computer, as it exploits applications that are already installed in the device.

U.K. Launches “Call for Evidence” to Improve Cybersecurity

Call for Evidence

As part of its present review on cybersecurity incentives and regulations, the Government of the United Kingdom recently announced the launch of “Call for Evidence” on improving cybersecurity across the U.K. economy.

The Call for Evidence is an evaluation on Cybersecurity Incentives & Regulation and is seeking information on the barriers acting on cybersecurity.

“This Government is committed to making the U.K. the best place to start and grow a digital business. We’re providing the public and businesses with faster broadband, improved digital skills, and stronger data protection laws. We’re also tackling online harms and facing the challenges of the digital revolution in an effective and responsible way,” an official statement read.

According to Matt Warman, the Minister for Digital and Broadband, the Call for Evidence supports the Government’s Review of Cyber Security Incentives and Regulation, which is intended at how the Government can help organizations better protect themselves online.

The Call for Evidence review is aimed to help understand the barriers which prevent organizations from improving their cybersecurity capabilities and understand the effectiveness of existing interventions, including regulations like GDPR and the NIS Directive.

“Good cybersecurity is an absolute necessity, but recent research shows less than a fifth of company Boards understand the impact associated with the cyber threat. I hope this review will encourage the industry to think about what the government could do to help and what incentives might encourage firms and businesses to manage their cyber risk,” Matt Warman said. “By driving cybersecurity improvements across the whole economy, we can help make the U.K. the safest place to live and do business online.”

The government stated that it’s expecting inputs from all types of organizations in all sectors, including membership bodies, consultancies, auditors, insurers, investors, corporate and risk governance bodies, regulators, and professional associations.

A recent survey from data security firm Clearswift revealed that more than half of the companies in the United Kingdom experienced a security incident over the past 12 months. The survey also highlighted that around 70 percent of financial firms in the U.K. reported security incidents last year, in which half of the incidents occurred due to internal errors.

The research, which surveyed 100 senior business decision-makers from financial organizations in the U.K., highlighted that most of the attacks have originated due to employees who failed to follow proper data protection policies.

App Defense Alliance – Google’s Fab Four for Mobile App Security

Google Play

Google in its latest, and probably the most important announcement for Google Play Store security, has informed about the creation of the App Defense Alliance. This Alliance brings the industry’s leading mobile security providers onboard with Google Play Protect. The App Defense Alliance is a collaboration between Google, ESET, Lookout, and Zimperium. The App Defense Alliance was created to ensure the safety of the Google Play Store. Google and its partners aim to quickly find Potentially Harmful Applications (PHAs)
and take the appropriate action to protect users.

Google Play Store which was first introduced as Android Market, is designed on the lines of Apple’s App Store. The Play Store has a wide range of offerings – games, apps, books, music, TV shows, movies and much more at your fingertips. But this is only the icing on the cake; Google Play Protect is the cherry on top.

Google Play Protect is Google’s built-in malware protection which scans and verifies billions of downloaded apps every day. It helps keep your Android device(s) secure by running safety checks on Google Play Store apps before you download them, and raises an alert if any PHA is found. This ensures that PHAs are stopped even before they make it to the Google Play Store.

This alliance is going to be a give and take relationship. The App Defense Alliance partners can send a request to the Google Play Protect scanner service for analyzing it. The scanner service then sends back the scan results directly to the partner. But as we mentioned it’s two-way traffic. Google Play Protect scanners can also send requests to partner’s scanner services and receive results from their scan engines. This helps in creating an advanced app security and risk mitigation. Based on the combined scan results it can further be decided whether a certain app can be published on Google Play Store or not.

In Google’s Security Blog, Dave Kleidermacher, VP, Android Security & Privacy said, “Our number one goal as partners is to ensure the safety of the Google Play Store, quickly finding potentially harmful applications and stopping them from being published.

As part of this Alliance, we are integrating our Google Play Protect detection systems with each partner’s scanning engines. This will generate new app risk intelligence as apps are being queued to publish. Partners will analyze that dataset and act as another, vital set of eyes prior to an app going live on the Play Store.”

Speaking about the partners involved in the App Defense Alliance, he further adds, “All of our partners work in the world of endpoint protection and offer specific products to protect mobile devices and the mobile ecosystem. Like Google Play Protect, our partners’ technologies use a combination of machine learning and static/dynamic analysis to detect abusive behavior. Multiple heuristic engines working in concert will increase our efficiency in identifying potentially harmful apps.

We hand-picked these partners based on their successes in finding potential threats and their dedication to improving the ecosystem. These partners are regularly recognized in analyst reports for their work.

Knowledge sharing and industry collaboration are important aspects in securing the world from attacks. We believe working together is the ultimate way we will get ahead of bad actors. We’re excited to work with these partners to arm the Google Play Store against bad apps.”

Data Breach at California DMV Affects 3,200 Drivers’ Information

California DMV data breach

Information of thousands of drivers has been exposed in a data breach at the California Department of Motor Vehicles (DMV) that went unnoticed for four years.

According to the DMV, Social Security information of 3,200 driver’s license holders was improperly accessed by federal agencies, including the Department of Homeland Security, Internal Revenue Service, Small Business Administration, and district attorneys in San Diego and Santa Clara counties, the Los Angeles Times reported.

DMV restricted access to the data after discovering the breach on August 2, 2019. However, Anita Gore, DMV’s spokesperson, clarified that no information was accessed or shared with private individuals during the breach.

As per the official statement, a total of seven agencies have accessed the data, including district attorneys in San Diego and Santa Clara counties, the Small Business Administration, and the Internal Revenue Service. It also stated that data was accessed as part of investigations into criminal activity or compliance with tax laws.

“Protection of personal information is important to DMV, and we have taken additional steps to correct this error, protect this information and reaffirm our serious commitment to protecting the privacy rights of all license holders,” Anita Gore said. “That’s why DMV immediately began correcting the access error following a legal compliance review, ensured that no additional confidential information was disclosed to these entities, and has implemented several additional layers of review.”

The affected people were informed of the breach via letters. In which, the Chief Privacy Officer at the DMV, Albert C. Hwang said, “We sent this letter and the attached notice to you based on having, in the past, shared your Social Security information in error.”

In February 2019, the officials of California’s government had announced that they were going to support cybersecurity education and committed to providing programs and events that help train the next generation of cybersecurity professionals.

The officials stated that they’ve initiated a program, the California Mayors Cyber Cup (CMCC), that utilizes cyber competitions to spread awareness about cybersecurity and the many career opportunities that exist within that field. CMCC brings students, parents, teachers, government officials, business leaders, and other stakeholders together to create awareness of cybersecurity issues and reinforce the connection between the community and the educational institutions to highlight the many career and business support resources available in each community.

Researchers Found New Laser-Based “Light Commands” Attack

Light Commands Attacks

Security researchers from the University of Electro-Communications & Michigan discovered a new kind of injection attack that allows an attacker to infuse arbitrary audio signals into voice assistants using light.

The new attack dubbed “Light Commands” is a vulnerability that exists in MEMS (micro-electro-mechanical systems) microphones, allowing attackers to inject inaudible and invisible commands into voice assistants via Photoacoustic effect.

“We propose a new class of signal injection attacks on microphones based on the photoacoustic effect: converting light to sound using a microphone,” researchers stated.

To launch the Light Commands attack, an attacker needs to transmit a light modulated audio signal that converts into the original audio signal within a microphone. Researchers revealed that hackers can remotely send invisible and inaudible signals to smart home devices like Alexa, Portal, Google Assistant, and Siri. It’s said that the Voice Controller systems in MEMS microphones lack authentication mechanisms.

Once the attackers hijack the device, they can control smart home switches, operate smart doors, make online purchases, and unlock smart locks by stealthily brute-forcing the user’s PIN.

Researchers stated that attackers require no physical access or user interaction to exploit the vulnerability; all they need is sight access to the target device and its microphone ports. It’s confirmed that Light Commands attack works within a distance of  110 meters.

With technology advancing day-by-day, cyber-attackers are finding innovative ways to get into our devices.  Recently, academic researchers from England and Sweden have discovered that hackers can use the microphone on the smartphone to steal the phone password and gain access to the device’s data.

Researchers found malware that can exploit the smartphone’s microphone to steal the device’s passwords and codes. In their report, s, the researchers claimed that they’ve found the first Acoustic side-channel attack that presents what users type on their touch-screen devices.

Recently, a cybersecurity researcher, Matt Wixey, revealed that attackers can hack modern audio gadgets to make deafening sounds. He discovered that attackers can build a custom-made malware to induce it on connected speakers to produce deafening sounds at high intensity, turning them into offensive cyber-weapons.

These developments are reminiscent of the early days of phone hacking in the 1980s when phone hackers (or “phreaks”) hacked into telecommunication systems. They used devices (or used their own whistling) that made sounds to emulate phone signals going across to switchboards and modems. The concept was called “phreaking”. It was done just to make free phone calls and have some innocent fun.

Don’t Reboot Your Systems after Ransomware Attack: Experts

Ransomware attacks, ransomware, Sinclair Broadcast group

Security pros stated rebooting a computer after a ransomware attack could lead to restarting a crashed file-encryption process and cause potential loss of encryption keys stored in memory. Instead, the victims should hibernate the computer or disconnect it from the network, experts recommended.

According to a research report, powering down the computer is also a good idea, but hibernating is better as it saves a copy of the memory of ransomware strains. The report revealed that in 1,180 U.S. users, who fell victim to ransomware, almost 30 percent of them chose to reboot their computers to deal with the attack.

The report stated that there are two stages of a ransomware recovery process. The first is finding the ransomware’s items like processes and boot persistence mechanisms and removing them from the infected host. And, the second is restoring the data if a backup mechanism is available.

“The classical paradigm to defend against malware attacks has traditionally been victim-agnostic and reactive, with defenses focusing on identifying the attacks like phishing emails, malicious websites, and files,” the report stated.

Ransomware has received considerable news coverage in recent years, in part due to several attacks against high-profile corporate targets. Multiple governments have fallen victim to ransomware attacks in recent times. In July this year, Louisiana declared a state of emergency after a wave of ransomware attacks hit school districts. The incident affected school systems in Sabine, Morehouse, and Ouachita parishes in North Louisiana. The attack infected the school’s computer and network systems with ransomware. The Emergency Declaration allows Louisiana’s cybersecurity experts to assist local governments in securing their network systems.

Recently, the Texas Department of Information Resources (DIR) revealed that around 23 Local Government Organizations in Texas have been hit with a ransomware attack. “On the morning of August 16, 2019, more than 20 entities in Texas reported a ransomware attack.  The majority of these entities were smaller local governments,” the DIR said in a statement. “The State of Texas systems and networks have not been impacted. It appears all entities that were actually or potentially impacted have been identified and notified.”

Libarchive Vulnerability Allows Code Execution on Linux and BSD Distros

Linux

Libarchive is a default compression library that is optimized for reading and writing compressed archive files in a single go. It means that Libarchive can process large archive files that cannot be stored on a disk and instead process them on-the-go as they read from or write to a network or a tape drive.

Google recently disclosed a Libarchive vulnerability which was discovered by its security researchers (having identifier CVE-2019-18408) using ClusterFuzz and OSSFuzz automated testing tools. It allowed hackers to execute arbitrary code if it received a specially crafted archive file. This library is included by default in Debian, Ubuntu, Gentoo, Arch Linux, FreeBSD (Berkeley Software Distribution), and NetBSD distros. The announcement of this vulnerability was made public as several Linux and FreeBSD distros released updated patches to fix the Libarchive vulnerability.

Debian Security Advisory authored by Moritz Muehlenhoff said, “A use-after-free was found in libarchive, a multi-format archive and compression library, which could result in denial of service (DDOS attack) and potentially, the execution of arbitrary code if a malformed archive is processed.” IBM in its security bulletin also mentioned that multiple Libarchive vulnerabilities have affected its Watson Explorer, a cognitive and content analysis platform.

Libarchive is also included as a default library in Microsoft Windows 10 (insider build 17063) since 2017.  Similarly, MacOS has integrated the usage of Libarchives since 2009, with bsdtar and bsdcpio being the default system tar and cpio command-line utilities. The bsdtar and bsdcpio command-line utilities are feature and performance enhanced as compared to other tar and cpio implementations and hence very popular across various operating environments. Its features include:

  • Reads a variety of formats, including tar, pax, cpio, zip, xar, lha, ar, cab, mtree, rar, and ISO images.
  • Writes tar, pax, cpio, zip, xar, ar, ISO, mtree, and shar archives.
  • Automatically handles archives compressed with gzip, bzip2, lzip, xz, lzma, or compress.
  • Unique format conversion feature.

Although this could have affected a wider audience, the Libarchive vulnerability being ineffective on Apple and Microsoft operating systems helped in its timely containment and rapid fix.

Australia Spends AU$ 8.5m to Build National Freight Data Hub

Remote Access Scams

The Australian government recently announced that it’s going to spend AU$8.5 million to create a national freight data hub. The government stated the new data hub helps businesses and governments make better operational decisions.

“A well-designed hub will improve access to and sharing of valuable freight location and performance data,” said Michael McCormack, the Deputy Prime Minister of Australia.

The funding will be divided into two parts, in which AU$5.2 million will be allocated for designing the national freight data hub, including arrangements for data protection, data collection, confidentiality, dissemination, and hosting. And the remaining AU$3.3 million will be used to establish a freight data exchange pilot.

The government also released a discussion paper to seek views on the design of the hub, including what datasets should be collected and how the data should be shared. Cybersecurity and the protection of commercial in confidence material are considered as high priorities to the government.

“The protection and confidentiality of data is a key concern of stakeholders that could inhibit participation in the Hub, therefore lessening the potential network-wide benefits. Sharing of freight data is also hampered by inconsistent and disparate approaches, such as data that cannot be compared across supply chains or states,” the announcement stated.

Earlier, the government of Australia launched several Joint Cyber Security Centers (JCSC) to promote cybersecurity across the government, business, and academia. The facilities are a part of the government’s $47 million JCSC program that bridges the security gap between several public and private companies in sectors such as defense, finance, transport, energy, health, mining, and education.

In July this year, Australia established a new cybersecurity node in a bid to drive innovation and harness cybersecurity talent in the region. The New South Wales government and AustCyber have jointly launched the NSW Cyber Security Innovation Node at the harbor city’s Joint Cyber Security Centre. Announced in 2018, the new information security hub will form a part of a series of nodes backed across Victoria, the ACT, Western Australia, South Australia and Tasmania, and will be coordinated by the NSW Cyber Security Network, which is backed by the NSW Government and universities, and aligned with AustCyber’s national agenda of sector growth.

Canadian Territory Nunavut Suffers Ransomware Attack

Ransomware attack on Nunavut, Emotet Cobalt Strike

The Government of Nunavut is the latest victim of a sophisticated ransomware attack. In an official statement, the Premier of Nunavut, Joe Savikataaq, stated he noticed a new and advanced type of ransomware that affected their network systems across the territory on November 2, 2019.

The attack encrypted individual files on various servers and workstations impacting all government online services. “All government services requiring access to electronic information stored on the Government of Nunavut (GN) network are impacted, except Qulliq Energy Corporation,” said Savikataaq.

“I want to assure Nunavummiut (citizens of Nunavut) that we are working non-stop to resolve this issue. Essential services will not be impacted and the GN will continue to operate while we work through this issue. There will likely be some delays as we get back online, and I thank everyone for their patience and understanding,” Savikataaq added.

The officials from the government stated that there is no information as of now about the loss of personal information or data breach. The state departments are implementing emergency plans to restore electronic data services related to health, family services, education, justice, and finance.

Multiple governments have fallen victim to ransomware attacks in recent times. In July this year, Louisiana declared a state of emergency after a wave of ransomware attacks hit school districts. The incident affected school systems in Sabine, Morehouse, and Ouachita parishes in North Louisiana. The attack infected the school’s computer and network systems with ransomware. The Emergency Declaration allows Louisiana’s cybersecurity experts to assist local governments in securing their network systems.

Recently, the Texas Department of Information Resources (DIR) revealed that around 23 Local Government Organizations in Texas have been hit with a ransomware attack. “On the morning of August 16, 2019, more than 20 entities in Texas reported a ransomware attack.  The majority of these entities were smaller local governments,” the DIR said in a statement. “The State of Texas systems and networks have not been impacted. It appears all entities that were actually or potentially impacted have been identified and notified.”

Data Breach Reports Increase in Canada after Privacy Law

Canada Revenue Agency Shut Down Services after Cyberattacks

The number of reported data breaches in Canada increased by six times after the country implemented a new breach-reporting regulation.

The new regulation, the Personal Information Protection and Electronic Documents Act (PIPEDA), went into effect on November 01, 2018. As per the regulation, Canadian companies are required to report all the details of data breaches that occurred within the organization. They also need to notify affected individuals and keep records of all data breaches.

According to the Office of the Privacy Commissioner of Canada’s report, around 680 security breach reports, which is six times the volume received during the same period one year earlier, were received since November 01, 2018. It’s said that the number of Canadians affected by a data breach is more than 28 million, in which 58 percent of reported breaches involved unauthorized access.

“Since reporting became mandatory, we’ve seen the number of data breach reports skyrocket. Some of those reports have involved well-known corporate names, but we have also seen significant volumes coming from small- and medium-sized businesses,” the report stated. “We have seen a significant rise in reports of breaches affecting a small number of individuals – often just one and sometimes through a targeted, personalized attack.  This is the correct approach to reporting: there can be a risk of significant harm even when only one person is affected by an incident.”

Cybersecurity experts have opined the Canadian government isn’t doing enough to protect businesses and consumers from data breaches.

A recent survey from Keyfactor, a provider of secure digital identity management solutions, revealed that 87 percent of surveyed cybersecurity pros think that more privacy and security legislation is required to better protect Canada’s businesses and consumers.

According to the survey, 58 percent of respondents think regulators and the Canadian officials are not trying to regulate the security guidance on measures like data encryption. The survey also highlighted that 50 percent of respondents stated that manual and complex processes as their greatest challenge in managing Public Key Infrastructure (PKI) while 43 percent of respondents were concerned about their ability to securely adopt DevOps, cloud, and IoT.