Home Blog Page 283

Data Breach Occurred due to Series of Missteps: Imperva

Unprotected Server Exposes Facebook Scraped Data of 12 Mn Users in Vietnam

The data breach that recently affected customers of Imperva’s Cloud Web Application Firewall (WAF) occurred due to errors that happened while the company was migrating to a cloud-based database service, Imperva’s Chief Technology Officer, Kunal Anand, recently disclosed.

According to Anand, Imperva started migrating to the AWS Relational Database Service (RDS) in 2017. And a series of mistakes during this process allowed an unauthorized party to steal an administrative API key for one of Imperva’s product Incapsula, the firm’s cloud Web Application Firewall (WAF).

Anand stated that after the investigation with its internal security teams and outside forensics specialists, it identified that unauthorized use of an administrative API key in one of the company’s AWS accounts in October 2018, led to an exposure of a database snapshot containing emails and hashed passwords.

“I’ll start by going back to 2017 when our Cloud WAF, previously known as Incapsula, was under a significant load from onboarding new customers and meeting their critical demands. That year, our product development team began the process of adopting cloud technologies and migrated to AWS Relational Database Service (RDS) to scale our user database,” Anand said in a statement.

In August 2019, Imperva notified its customers about the data breach that affected a subset of its Cloud WAF. “We learned from a third-party of a data exposure that impacts a subset of customers of our Cloud WAF product who had accounts through September 15, 2017,” wrote Heli Erickson, director of analyst relations at Imperva. “We want to be very clear that this data exposure is limited to our Cloud WAF product.”

“While the situation remains under investigation, what we know today is that elements of our Incapsula customer database from 2017, including email addresses and hashed and salted passwords, and, for a subset of the Incapsula customers from 2017, API keys and customer-provided SSL certificates, were exposed,” Erickson added.

Manhattan Federal Court Arrests 18 Hackers for ATM Skimming Attack

Cybercriminals are “Jackpotting” ATMs in Europe to Steal Cash

The U.S. Department of Justice stated that they’ve detained 18 International Cybercriminals who allegedly committed various financial frauds and stole tens of millions of dollars from financial institutions and individuals. The hackers were involved in ATM skimming and money laundering operations and have stolen more than US$ 20 million across the U.S., including 17 different states.

According to Geoffrey S. Berman, the U.S. Attorney from New York, the hackers were indicted for committing a variety of crimes, including bank fraud, device fraud, wire fraud, and identity theft. The 18 defendants imported skimming devices from different countries and deployed in ATMs to record debit card details and personal identification numbers whenever the victims use an ATM. The stolen information was then used to fraudulently withdraw cash from victims’ bank accounts.

“The Skimming Organization unlawfully obtained victim accountholders debit card account information by using advanced technological devices to surreptitiously record the debit card numbers and personal identification numbers at automated teller machines (ATMs), and then manufacturing counterfeit and fraudulent debit cards that bore the victim accountholders’ account information.  The Skimming Organization’s members then used those cards to fraudulently withdraw cash from victims’ bank accounts,” the Department of Justice stated in its report.

“If they are found guilty then each defendant will be charged with one count of conspiracy to commit access device fraud, which carries a maximum sentence of 7.5 years in prison; one count of conspiracy to commit wire and bank fraud, which carries a maximum sentence of 30 years in prison; and one count of aggravated identity theft, which carries a mandatory sentence of two years in prison, consecutive to any other sentence imposed,” the report added.

Recently, security experts discovered a malware that’s intended to exploit ATMs of Indian Banks and steal customers’ sensitive information. The malware, dubbed ATMDtrack, allows the attackers to read and store customers’ card data when they are inserted into the infected ATMs.

According to Konstantin Zykov, a researcher at Kaspersky Labs, the attacker who created the ATMDtrack has been traced to the cyber-hacking outfit Lazarus Group controlled by North Korea’s primary intelligence bureau. The scandalous Lazarus Group is a prime suspect in a series of cyber-muggings, including the cyber- attack on Sony Pictures Entertainment in 2014, and the WannaCry ransomware attack in 2017.

Security Bug Exposes Personal Data of 156 Million JustDial Users

microsoft, flaws in SonicWall SRA SMA

A security flaw in JustDial systems, an Indian-based local search services provider, left data of around 156 million of its users vulnerable. However, the company managed to patch the bug after a security researcher Ehraz Ahmed flagged the issue.

According to the researcher, the flaw could allow an attacker to access accounts without the user’s knowledge. It’s said that the bug affected JustDial’s website, mobile app, and voice platforms.

The researcher explained in a video that how a hacker can use any JustDial user’s phone number as username and gain access to the account by exploiting the bug. Ahmed also revealed the bug allows hackers to change account details for JustDial’s payment option — JD Pay, allowing them to redirect all the money in the account.

“The hackers can also access your Justdial Pay account and receive funds on your behalf by entering their bank account information in the Bank Details Settings, but they cannot transfer the funds as it requires them to have access to your bank account/UPI code,” Ahmed said.

JustDial clarified that no loss of data or money has been reported as of now. “We at JustDial take security seriously. There was a bug in one of our APIs which could potentially be accessed by an expert hacker. This bug has been fixed. We work with various security researchers to strengthen our platform and would like to thank Ehraz Ahmed for bringing this out to us,” JustDial said in a statement.

According to a recent survey from technology giant IBM, the average cost of a data breach in India has grown 7.29 percent to reach Rs 12.8 crore from Rs 11.9 crore last year. According to the survey report dubbed Cost of a Data Breach 2019, the Per capita cost for a stolen record raised to Rs 5,019, which is an increase of 9.76 percent when compared to the last year.

The survey findings, which are based on in-depth interviews with 507 companies around the world, highlighted that the root cause for 51 percent of data breaches was malicious or criminal attacks, 27 percent of breaches due to technical issues, and human error led to 22 percent of breaches in India.

Trend Micro Launches its XDR Data center in India

Trend Micro

Cybersecurity and defense company Trend Micro recently launched its local managed XDR data center service in India to solve data sovereignty issue. The company announced the news at its own security event named CLOUDSEC India 2019, which gathered more than 750 business and technology leaders from the cybersecurity industry. Trend Micro stated that its XDR offers 24/7 service for organizations that want additional detection and response support.

Based out in Japan, Trend Micro is a major player in the information and network security landscape. Founded in 1988, the company holds a variety of cybersecurity merchandise for multiple operating systems, including threat detection, and antivirus products. Hybrid cloud security, network defense, user protection, and small business products are at the core of its product line.

In India, Trend Micro holds around 1,000 large enterprise customers, which provides security across the hybrid cloud, network, and endpoints. The company also has its presence across the government, BFSI, IT/ITeS, manufacturing, pharmaceutical, and telecom sectors.

“Today, data is collected and analyzed in silos, however, what enterprises need is to collect and analyze data as a whole and be able to generate high-priority, actionable intelligence with context. To address this challenge, we recently launched our XDR solution that will be a gamechanger for the industry. Managed XDR is a great service for customers who have detection and response tools, but don’t have the required resources or skillsets to maximize them,” said Nilesh Jain, Vice President, Southeast Asia and India, Trend Micro.

“The engagement around cybersecurity is no longer limited to CISOs and CIOs. At Trend Micro, we have taken the engagement to the next level by speaking to the application team and the operations team. We are also looking at initiatives like community day to deepen our interactions with the DevOps professionals. Our top three priorities for India this year are to – first, focus on hybrid cloud customers who are looking to grow aggressively; second, build on existing customers including those who are sitting on the fence evaluating prospective options; and, finally, to recruit and grow our partner ecosystem,” Jain added.

Recently, Trend Micro launched its new headquarters in Singapore for Asia-Pacific, Middle East and Africa (AMEA) operations. The facility will be a part of Trend Micro’s new managed detection and response (MDR) security operations center across North America, Europe, and Southeast Asia.

Trend Micro stated its new center comprises an executive briefing area to host cybersecurity sessions for customers and government officials in the AMEA region. The company is also offering Certification Programs in IT Security to train the security officials in Singapore.

Survey reveals 1 in 3 Indian Companies Suffered Huge Financial Costs from Hacking

Insider attacker leak data

New research by hardware networking firm Cisco revealed that one in three Indian organizations are facing huge financial losses from security breaches and 24 percent of companies lost around US$ 1 million or more in the past year.

“Hackers are no longer just targeting IT infrastructure but have started to attack operational technology infrastructure, intensifying the challenge for companies,” the report said.

The research, 2019 Asia Pacific CISO Benchmark Study, disclosed that nearly 37 percent of organizations in India suffered downtime of over nine hours after a data breach. Around 46 percent of companies surveyed stated that they’ve received more than 5,000 threat alerts in a day, in which 43 percent of them went unattended.

The survey findings are based on responses from 2,000 security leaders across 11 countries in the Asia Pacific, from public and private organizations. The report gathered data in four areas – Cybersecurity culture; Security alerts and the impact of data breaches; Cybersecurity trends: Cloud and Operational Technology threats; and the Defenders’ approach on managing vendors.

“Organizations in India have made significant improvements to their cybersecurity postures, in the last year. However, high workloads and alert fatigue continue to be a big challenge,” said Vishak Raman, Director, Security Business, Cisco India and SAARC.

“Hence, enterprises in India are looking at increasing the level of automation in their security strategy as well as for opting for an integrated end-to-end solution to secure their infrastructure,” Raman added.

Recently, the Reserve Bank of India (RBI) revealed that it discovered around 50,000 cyber frauds in the country’s Scheduled Commercial Banks (SCB) in 2018-19 fiscal. In reply to an RTI (Right to Information) query, the RBI stated that cybercrimes are related to ATM, debit and credit cards, and internet banking. It notified that over 50,547 banking frauds occurred in the SCBs that resulted in a loss worth of Rs. 145.08 crore in the last fiscal.

According to the RBI, the total number of banking frauds, including cyber, detected in all the SCBs are 59,826 and the loss incurred is around Rs. 67,432.26 crore. More than 4,269 frauds occurred due to insiders in the banks, involving Rs. 1,014.97 crore loss during the period, RBI added.

Ransomware Victim Does a Tit-for-Tat and Hacks the Hacker

cybersecurity

Call it an act of bittersweet revenge. A victim of the Muhstik Ransomware attack who had to pay up the hackers for releasing his data went right back at the hackers by hacking them (him/her) back, and even released 3,000 decryption keys along with a decryptor tool so that other affected victims of the ransomware attack would get their files back.

Towards the latter half of September, attackers targeted publicly exposed QNAP Network Attached Storage (NAS) devices and encrypted files within them. The ransomware was dubbed “Muhstik” as it used the .muhstik extension to encrypt files. After the files were hacked, the attackers would demand 0.09 bitcoins, or approximately $700 USD to decrypt the files. German programmer Tobias Frömel was one of the victims of the attack and had to pay up €670 to gain his files back.

Frömel found the entire incident demeaning and insulting and decided to get back at the hacker and hacked the attacker’s command and control server. While scouting through the command and control server he stumbled upon the web shells which got him access to the PHP script that generates passwords for a new victim.

He then used the same web shell to create a PHP file based on the key generator. Digging deeper he found decryption keys for 2,858 Muhstik victims stored in the database of the attacker. Frömel with the support of Bleeping Computer released the keys and a free decryptor at Bleeping Computer’s Muhstik support and help topic.

Several users have reached out to Bleeping Computer over the key generator and its use.  Bleeping Computer also confirmed that the key generator along with the decryptor was working perfectly.

Even though what Frömel did may earn him accolades on the moral front, it may not be completely legal. He, in his original announcement on the Bleeping Computer forum, urged readers to know he’s “not the bad guy here.”

In a similar incident when attackers got a taste of their own medicine, hours after the terrorist Islamic State (IS) claimed its news site was unhackable, Muslim hacking collective called Di5s3nSi0N hacked into the network and published a list of almost 2,000 subscribers’ email addresses. This came as a blow to the online caliphate. For the hacker collective, it was just another “Challenge accepted” scenario.

Within three hours after the terrorist wing claimed that its news site Amaq had spruced up its security, the subscribers received a mail which read, “We have hacked the full ‘secure’ email list for Amaq”. Adding “Daesh…shall we call you dogs for your crimes or snakes for your cowardice? We are the bugs in your system.”

IBM and McAfee Spearhead Formation of Open Source Cybersecurity Alliance

U.S. and Australia to Jointly Develop Cyber Training Platform

In a bid to provide interoperability and data-sharing across several cybersecurity products and companies, IBM Security and McAfee are spearheading an open-source cybersecurity alliance along with 14 other cybersecurity companies across the globe.

The new Open Cybersecurity Alliance (OCA) will fall under the umbrella of the Organization for the Advancement of Structured Information Standards (OASIS) open standards and open-source group and will include companies like Advanced Cyber Security Corp, Corsa, CrowdStrike, CyberArk, Cybereason, DFLabs, EclecticIQ, Electric Power Research Institute, Fortinet, Indegy, New Context, ReversingLabs, SafeBreach, Syncurity, ThreatQuotient, and Tufin.

IBM Security and McAfee kicked off the open-source initiative which will enable information security companies that are a part of the OCA consortium to freely exchange information, insights and even threat orchestration.

“Today, organizations struggle without a standard language when sharing data between products and tools,” Carol Geyer, chief development officer of OASIS, said in a statement. “We have seen efforts emerge to foster data exchange, but what has been missing is the ability for each tool to transmit and receive these messages in a standardized format, resulting in more expensive and time-consuming integration costs. The aim of the OCA is to accelerate the open sharing concept making it easier for enterprises to manage and operate.”

At present, enterprises use up to 50 different security tools from 10 major cybersecurity vendors. The new consortium will enable companies under the OCA to even develop and promote open source content, codes, etc. The alliance will tackle siloed data gathered by different security products and speed up response time, which would have been time-consuming when the data packets were isolated to particular vendors or products.

“When security teams are constantly spending their time manually integrating tools and maintaining those integrations, it’s not helping anyone other than the attackers,” said Jason Keirstead, chief architect, IBM Security Threat Management, in a statement. “The mission of the OCA is to create a unified security ecosystem, where businesses no longer have to build one-off manual integrations between every product, but instead can build one integration to work across all, based on a commonly accepted set of standards and code.”

Mississippi State Agencies not Complying with Cybersecurity Laws

Technology Governance

Cybersecurity has been at a nascent stage for several states in the United States. With the California Consumer Privacy Act (CCPA) around the corner, you would imagine that other states are sprucing up cybersecurity in their region and are catching up with the compliance norms. But the reality paints a stark different picture.

In a recent cybersecurity audit undertaken by the office of the state auditor of Mississippi, it was found that a sizable number of state’s agencies are regularly failing to comply with the cybersecurity protocols. These protocols which were devised in 2018 is called the Mississippi Enterprise Security program was aimed at building cooperation among agencies on defense and cybersecurity.

According to the survey by Office of State Auditor Shad White, several state agencies, boards, commissions, and universities have failed to comply with cybersecurity laws and regulations in the region leaving the data of citizens of Mississippi vulnerable.

The survey pointed out that over half of all respondents are less than 75 percent compliant with cybersecurity laws and regulations of the state. The report also pointed out that several state entities care a hoot for cybersecurity laws in the region.

The condition of cybersecurity is so dire in the region that out of 125 state agencies, boards, commissions, and universities which Auditor’s office sent a cybersecurity survey to, only 71 cared to reply, even here several agencies did not even complete the survey leaving the state of cybersecurity in nearly 50 state agencies in complete jeopardy.

Even among the ones who responded, nearly 11 percent of agencies do not have an adequately stated procedure to prevent or even recover from a cybersecurity incident. The region has also mandated vulnerability assessment from third parties, which nearly 22 percent of the responder agencies haven’t executed. It was also found that 38 percent of the respondents who deal with sensitive information like healthcare data, tax data, and student data haven’t even initiated the first-level encryption.

“This survey represents some excellent but alarming work by the data services division in the auditor’s office,” said Auditor Shad White. “October is cybersecurity awareness month, and we should start this month by acknowledging the very real weaknesses in our state government system. I personally have seen screenshots of other states’ private data on the dark web, and we do not need Mississippians’ personal information leaking out in the same way. The time to act to prevent hacking is now.”

Razberi Technologies Secures US$ 5.8 Million Investment

Number of IoT Devices Expected to Reach 24.1 Bn in 2030: Report

Razberi Technologies, a provider of simple and secure IoT solutions, recently raised US$ 5.8 million in an investment round led by LiveOak Venture Partners along with the participation from Chartline Capital Partners and other investors.

Doug Dickerson, the CEO of Razberi Technologies, stated the new proceeds will help accelerate business and product expansion. “This financing will give us the opportunity to continue to grow the business rapidly and roll-out fantastic new products in the coming year,” said Dickerson.

Headquartered in Dallas, Razberi helps organizations by providing intelligent appliances for automated cybersecurity, Internet of Things, video surveillance, and health monitoring software. The company claims that its technologies make it simple to manage and secure video surveillance and connected devices.

“Razberi has developed a leadership position in the large and fast-growing IoT / video surveillance and cybersecurity market,” said Krishna Srinivasan, Founding Partner at LiveOak and Board Member at Razberi. “The team has done a great job of building the business, landing prestigious customers and continuing to innovate on strong products at the intersection of video, cybersecurity and remote management. We’re delighted to be working together to continue to create a market leader across these categories.”

“Razberi will apply the funds to building out its market coverage and continuing to deliver industry-leading products. Razberi intends to bring on additional investors over the coming months,” Srinivasan added.

The Next-Gen Attackers (and What Attacks Will Look Like in Future)

By Benjamin Donnelly

Let me be clear.  The types of hackers that we’ve been seeing have rapidly changed in the past five or so years.  There is a clear trend that only a few highly informed individuals have been following.  If you’re not aware, you are going to get left behind.

Cracking into a network used to be an easy and routine task.  The same types of attacks worked almost everywhere.  You could use a few well known “tricks” to gain access to any network of your choosing.  Hackers would collect not just zero-days, but 100-days, or even 1,000-days (vulnerabilities that are well known to the public).  Times have been changing, though.  Companies like Microsoft have done an increasingly great job of building security into their products.  Whereas MS08-067 was still being found on computer networks even five years after its first discovery, nowadays you will be hard-pressed to find MS17-010 even two years later.

And it’s not just vulnerability patching.  It’s getting harder to find new functional exploits.  In the earlier days of the internet, you could easily find a stack-based buffer overflow in nearly any program of your choosing. Modern tools like EMET – as well as increasingly effective secure coding standards, have made this style of research very difficult.  And it’s not just that the internet has seen less per-software-component buffer overflows.  Similar attack styles in various other subdomains have also been steadily cleaned up by the ever-advancing push for better cybersecurity controls.

Do you remember how easy it was to find SQLi (SQL injection) even a few years ago?  Have you noticed how much harder it’s gotten now?  There was a time when many web applications were built on PHP, requiring developers to implement security controls manually. Modern web applications are built from a selection of various web frameworks like Django, Flask, Node.js, Spring, etc.  These frameworks often include baked in protections against various web application vulnerabilities.

For example, where CSRF (Cross-Site-Request-Forgery) used to be an attack style that required mitigating developers to build out a special submission routine for all returned form POSTs — Flask’s WTF Forms handles mitigation automatically.  If a developer writes an application in Flask, using built-in modules, CSRF will be mitigated from the start.  In another example, with PHP it was very common for a developer to “echo” untrusted user input unsanitized back to the page — thereby generating an XSS (cross-site-scripting) vulnerability; Flask’s Jinja2 templating engine automatically escapes such content.

Note: Jinja2 still creates the possibility of XSS in a few rare circumstances, such as when a variable is echoed into an HTML tag’s attribute section, where it may be interpreted as Javascript.  But that’s a huge improvement from what we had before!

Combine all these new technologies and techniques – with increasingly effective workstation and network protections against malware and malicious traffic, and we are looking at an ever increasingly secure world.  At least that is, against traditional threats.

If you haven’t been watching, you might think that things have been slowly getting better for computer network defenders.  It’s far easier today to identify, track, and remove threats from your network than it has ever been before.  But not all vulnerabilities are gone.  Networks are not perfectly secure.  If anything, the partial mitigation of entire vulnerability classes has left many networks and security teams worse off than before.

A true hacker’s story

Let me tell you the story of a web application that I myself personally destroyed as part of a pen test.  This application had no SQLi vulnerabilities that I could find.  It was perfectly protected from XSS.  The security team assured me that it was well built.  And I’m sure that from their perspective it was.  In reality, it was anything but that.  Their overreliance on various web frameworks meant that when the time came to deal with a next-generation threat model, they had nothing to counter what was coming.

Instead of focusing on OWASP top ten style vulnerabilities, I slowly unwrapped their website by pulling hidden token values from a glob of Javascript they presented to the client upon each request.  Over time I was able to find hidden but unsecured endpoints that generated authentication tokens to enable me to delve further into the site.  Finally, I was able to uncover an endpoint which gave me the ability to add my user to the Administrators group on the site – without authentication other than the tokens I had already generated.

From there, it was game over.  I had access to all the personal information owned by the site.  No known attack styles required.  All it took was to slowly unpack the logic of their site – and making it play against itself.

This is what more and more attacks in the future will look like.  Let me warn you – so that you can go back to your organizations and push for a solution.  Because if you don’t, you’ll be left standing when the music stops.

The new attackers are coming!

Here’s the big prediction: Tech isn’t getting more secure. It’s getting more complex. You know it’s true too.  You’ve likely been watching it happen, thinking that it was entirely a good thing.  And in many ways, it is.  But let’s be clear.  Your networks aren’t getting objectively more secure.  The complexity of the products and pipelines that you’re using are raising the bar.  Requiring more and advanced attackers.

It’s no longer enough that an attacker simply has custom malware unknown to anti-virus and basic knowledge of Metasploit.  There is a new class of attacker coming.  I want you to be ready for them.

To be clear, when I say that they’re coming, I only mean that they’re becoming more common.  In reality, members of this class of attacker are already here.  They leverage vast infrastructure, advanced computing, and complex attack styles to tear your security paradigm wide open.

Want a sampling of what these new attackers can do? Take a quick peek at what happened in February of 2017.  If you weren’t paying attention to scholarly research, you probably missed it.  There was no big breach or scary announcement.  In what became known as “SHAttered” a teaming of Google security researchers and the Dutch research institute CWI, announced that they had generated the first known collision of SHA-1 hashes for two different PDF files.

Note: Though a full explanation of this attack is beyond the scope of this article, a quick explanation is that the SHAttered team created two PDF files that might be mistaken for the same PDF file by various software systems.  This means that it would be possible for them to replace a “secure” message with one of their choosing.  Making it look like a person or system had said something they had not.  For instance, modifying the secure message “ATTACK AT DAWN” to “ATTACK AT DUSK”.  For more information check out: https://shattered.io

It had been known for a long time that SHA-1 was out in the open.  But many organizations had thought of such attacks as simply “theoretical” or otherwise impractical.  Against the previous generation of attackers, this assessment was almost certainly right.  But against attackers from the next-generation model – with complex attack styles, advanced computing power, and vast infrastructure, not only would such an attack be possible, it might even be trivial.

SQLi, XSS, CSRF, and generic RCE attacks slowly wane. But you’ll observe that increasingly insidious supply chain and custom logic attacks grow over time – remember the following: tech isn’t getting more secure; it’s getting more complex.

So, what can you do about it?

Be prepared

As a leader in an organization, here is the best advice I can give you.  If you want to increase your security against previous-generation threats, keep doing what you’ve been doing.  Hire security analysts, invest in network security devices, build strong patching policies and processes.

If you want to be one of the few organizations prepared to handle the next wave, you have one solution.  You need to hire engineers.  Not front-end developers; not “programmers”; not “tech wizards”.  Your infrastructure is getting more complex.  Your software is getting more complex.  Without people who can actively operate in that environment you are literally blind.  Hoping that some attacker will not come along who is able to see — and open a door you forgot to lock.

Benjamin (Ben) Donnelly is an omni-domain engineer, and the founder of Promethean Information Security LLC.  Ben has worked as part of teams hacking such things as prisons, powerplants, multi-nationals, and even entire states.  He is well-known for his research projects, including his work on the DARPA funded Active Defense Harbinger Distribution.  Ben has produced a number of field-leading advancements, including the Ball and Chain cryptosystem.  He has spoken at Derbycon and BSides Boise; and has contributed content to multiple SANS courses.  Outside of cybersecurity, he can often be found skydiving, producing underground electronic music, or starring in indie films. 

The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. All views stated in the article are personal.