Home Blog Page 286

Cybersecurity startup Kenna Security raises US$ 48 Million

Startup Investment

Risk-based vulnerability cybersecurity startup Kenna Security recently announced that it has raised US$ 48 million in a Series D funding round led by Sorenson Capital and Citi Ventures, along with the participation from the existing investors Bessemer Venture Partners, U.S. Venture Partners, Costanoa Ventures, Hyde Park Angels, and OurCrowd.

As part of the investment deal, Ken Elefant, managing director of Sorenson Capital will be joining in Kenna Security’s board of directors. The startup stated the new funding will help its business expansion and drive product development globally.

Founded in 2010, Kenna Security provides risk intelligence and vulnerability platforms to help security pros prioritize and remediate vulnerabilities even faster.

Kenna Security claims that it uses data science and machine learning platforms to sort vulnerabilities based on the risk factor and reduce the average time required to fix vulnerabilities. The startup stated that it has a strong customer base, including Fannie Mae, TransUnion, Lear Corp., Dow Jones Inc., Hanes Brands, and FICO.

Speaking on the new investment, Karim Toubba, the CEO of Kenna Security said, “Kenna Security has led risk-based vulnerability management and is the first company to bring truly predictive and proactive capabilities to this market,” “We’ve been impressed with their extensive client portfolio and pioneering technology.”

“Kenna Security sees a world where enterprises can efficiently manage current and future cyber risks across the global attack surface. Kenna Security’s revolutionary platform takes the approach proven most effective towards risk mitigation: reduce their risk by prioritizing the vulnerabilities that matter most,” Toubba added.

New Malware ‘Nodersok’ Turns Windows PCs into Zombie Proxies

BotenaGo, malware over encrypted connections

Technology giant Microsoft recently discovered a new malware campaign targeting thousands of computers across the world. The malware, dubbed Nodersok, developed to infect computers will turn them into proxies for launching cyber-attacks.

Security researchers at Microsoft stated the attack begins when a user downloads the HTML application (HTA) file named Player1566444384.hta. Researchers stated the malware has infected thousands of computers across the world targeting various sectors including Healthcare, Finance, Transport, Aerospace, and Education, mainly in the U.S. and Europe.

“The attack begins when a user downloads and runs an HTML application (HTA) file named Player1566444384.hta. The digits in the file name differ in every attack. Analysis of Microsoft Defender ATP telemetry points to compromised advertisements as the most likely infection vector for delivering the HTA files. The mshta.exe tool (which runs when an HTA file runs) was launched with the embedding command-line parameter, which typically indicates that the launch action was initiated by the browser,” Microsoft said in a statement.

According to the researchers, Nodersok campaign delivers two legitimate tools to infect computers. One is Node.exe, a Node.js framework that’s used in applications, and another is WinDivert, a network capture utility. These tools are not vulnerable or malicious but install unusual tools to change the infected machines into zombie proxies.

“This infection chain was consistently observed in several machines attacked by the latest variant of Nodersok. Other campaigns (possibly earlier versions) with variants of this malware (whose main JavaScript payload was named 05sall.js or 04sall.js) were observed installing malicious encoded PowerShell commands in the registry that would end up decoding and running the final binary executable payload,” Microsoft added.

Last month, Microsoft revealed two new security flaws in its Windows Desktop Services package. However, the technology giant clarified that it has fixed both the vulnerabilities. Security officials at Microsoft stated that the two vulnerabilities, dubbed CVE-2019-1181 and CVE-2019-1182, can be exploited by attackers to launch Wormable Attacks that spread across different network systems without a user’s knowledge.

Microsoft also stated the present flaws are similar to the vulnerability known as BlueKeep (CVE-2019-0708), which was patched in May 2019. The infected versions of Windows due to the flaws included, Windows 7 SP1, Windows 8.1, Windows Server 2008 R2 SP1, Windows Server 2012, Windows Server 2012 R2, and other versions of Windows 10. However, Windows Server 2003, Windows XP and Windows Server 2008 are not affected due to the flaws.

Magecart Hackers Group Strikes Again!

New Programming Language

A malicious hacking group named Magecart Group 5 (MG5) is reportedly taking control over the layer 7 (L7) public Wi-Fi routers typically deployed in hotels, airports, casinos, and resorts. According to security experts from IBM X-Force Incident Response and Intelligence Services (IRIS), Magecart Group is specifically targeting Wi-Fi routers that provide commercial Wi-Fi service in public areas.

The researchers said the attackers are injecting malicious code into the authentic Javascript file in the Layer 7 routers. Once the attackers compromise the routers, they can abuse the router features to launch cyber-attacks on Wi-Fi connected devices.

“Our research revealed that MG5 is likely testing malicious code designed for injection into benign JavaScript files loaded by commercial-grade layer 7  routers. These routers are typically used by airports, casinos, hotels, and resorts, to name a few. X-Force IRIS believes MG5 is currently targeting users shopping on the U.S. and Chinese websites,” the researchers said in a statement.

MG5 was involved in multiple cyber intruders, including attacks on British Airways and a ticketing website Ticketmaster. Recently, the attackers used a skimming script, a malicious code, to steal data from 201 online stores that were catering to 176 colleges and universities in the U.S. and 21 in Canada. The security researchers at Trend Micro stated that they detected the Magecart attack against multiple campus online store websites on April 14, 2019, which were injected with a malicious skimming at their payment checkout pages.

The hacker group is also responsible for the recent data breach that impacted several websites by injecting malicious code. According to a report from threat intelligence firm RiskIQ, the hackers used a “spray-and-pray” approach to compromise and plant malicious code on over 17,000 domains since April 2019.

By compromising a few sites, the malicious code spread to thousands of other sites, including Picreel, Alpaca Forms, AppLixir, RYVIU, OmniKick, eGain, and AdMaxim. RiskIQ stated the attackers have been active in web skimming for a long time and started compromising unsecured S3 buckets in early April.

Data Breach Affected 218 Million ‘Words with Friends’ Gamers

Gaming

The popular mobile social game company Zynga Inc. is the latest victim of a cyber-attack that compromised the personal information of more than 218 million gamers.

A Pakistani hacker, with an online name Gnosticplayers, who previously made headlines earlier this year for his various cybercrimes, managed to breach Zynga’s developed word puzzle game Words with Friends and allegedly accessed a database that contained more than 218 million gamers’ data, according to an official statement.

The gaming company stated that it also identified the account login information for certain players of the Draw Something game had been accessed. According to Zynga, the incident affected all Android and iOS game players who installed and signed up for the Words with Friends game on and before September 2, 2019. The exposed information included Names, Email addresses, Login IDs, Hashed passwords, SHA1 with salt, password reset token, phone numbers, Facebook IDs, and Zynga account ID details.

“We recently discovered that certain player account information may have been illegally accessed by outside hackers.  An investigation was immediately commenced, leading third-party forensics firms were retained to assist, and we have contacted law enforcement,” Zynga said in a post.

“While the investigation is ongoing, we do not believe any financial information was accessed.  However, we have identified account login information for certain players of Draw Something and Words with Friends that may have been accessed.  As a precaution, we have taken steps to protect these users’ accounts from invalid logins.  We plan to further notify players as the investigation proceeds,” Zynga added.

Earlier, Gnosticplayers hacked content of nearly 26.42 million from six different companies and kept for sale on the dark web for 1.2431 bitcoin (around $4,940). The hacker compromised the data by hacking dozens of popular websites from various companies.

The hacker stated this would be his last batch of the stolen database that contained nearly 27 million users’ records stolen from 6 different websites- Youthmanual (1.12 million accounts), GameSalad (1.5 million accounts), Bukalapak (13 million accounts), Lifebear (3.86 million accounts), EstanteVirtual (5.45 million accounts), and Coubic (1.5 million accounts).

It’s believed the hacker previously kept three rounds of stolen accounts up for sale on the popular dark-web market called Dream Market. Previously, the hacker exposed the details of around 620 million accounts stolen from 16 websites in the first round, 127 million records from 8 sites in the second, and 92 million from 8 websites in the third.

Hacking Group Targets U.S. Veterans with Phony Job Website

Cyber-attack on U.S. veterans

Security researchers discovered a threat group targeting U.S. military veterans via a fake job portal, promising help for those looking for jobs.

According to research from Cisco Talos, an attacker group, named Tortoiseshell, have been targeting Americans who’re in search of jobs, especially military veterans. The hacker group has been using a phony hxxp://hiremilitaryheroes[.]com, which is similar to the legitimate one https://www.hiringourheroes.org, to trick U.S. military veterans find jobs.

The URL directs the victims to the fake site and prompts to download an app, which was actually a malware downloader that deploys spying and other malicious tools.

“This is just the latest actions by Tortoiseshell. Previous research showed that the actor was behind an attacker on an IT provider in Saudi Arabia. For this campaign Talos tracked, Tortoiseshell used the same backdoor that it has in the past, showing that they are relying on some of the same tactics, techniques, and procedures (TTPs),” Cisco Talos stated in its report.

The report did not share light in the motive behind the campaign. However, the malware and spy tools have been collecting a considerable amount of data. The malware allows attackers to gain access to the information on the system like date, time, drivers, the patch level, the number of processors, the network configuration, the hardware, firmware versions, the domain controller, the name of the admin, and the list of the account, etc.

“This new campaign utilizing the malicious hiring website represents a massive shift for Tortoiseshell. This particular attack vector has the potential to allow a large swath of people to become victims of this attack. Americans are quick to give back and support the veteran population. Therefore, this website has a high chance of gaining traction on social media where users could share the link in the hopes of supporting veterans,” the report added.

Data breach affects 4.9 million customers, workers, and merchants of DoorDash

DoorDash Data Breach

DoorDash, a San Francisco-based food-delivery service provider, revealed a massive data breach that affected around 4.9 million people (its customers, delivery workers, and merchants), who were using its service platform.

In an official statement, the company said that an unauthorized third-party accessed its user data on May 4, 2019. DoorDash clarified that users who joined its services platform on or before April 5, 2018, are affected in the incident and who joined after April 5, 2018, aren’t.

“Earlier this month, we became aware of unusual activity involving a third-party service provider. We immediately launched an investigation and outside security experts were engaged to assess what occurred. We were subsequently able to determine that an unauthorized third party accessed some DoorDash user data on May 4, 2019. We took immediate steps to block further access by the unauthorized third party and to enhance security across our platform. We are reaching out directly to affected users,” DoorDash said in a post.

According to DoorDash, the exposed information included customers’ names, email addresses, delivery addresses, contact details, order history, card details, phone numbers, and hashed passwords.

Hackers took the last four digits of the customers’ payment cards, though complete numbers and CVVs were not taken. In case of delivery workers and merchants, attackers had the last four digits of their bank account numbers stolen along with the card details. Nearly, one lakh delivery workers’ license information was stolen in the incident.

“We have taken a number of additional steps to further secure your data, which include adding additional protective security layers around the data, improving security protocols that govern access to our systems, and bringing in outside expertise to increase our ability to identify and repel threats,” DoorDash added.

The news comes after DoorDash customers reported that their accounts had been hacked. But the company denied at that time claiming that attackers were running credential stuffing attacks.

Mandatory Cybersecurity Training for Government Employees in Texas

Texas Court Systems Affected by Ransomware Attack

In order to protect itself from cyber-attacks, the Texas State Government has introduced new legislation making annual cybersecurity training mandatory for all government employees. The State passed a House bill to introduce the cyber-safety training into law on June 14, 2019.

According to the official statement, the Texas Department of Information Resources (DIR) and the Texas Cybersecurity Council will be operating the cybersecurity training programs as per the new legislation. The cybersecurity awareness training program helps government employees to learn best practices for detecting, reporting, and addressing security threats.

“DIR has worked with state-wide stakeholders and the Texas Cybersecurity Council to develop detailed certification criteria and a systematic process for certifying cybersecurity programs. Once DIR certifies a minimum of five training programs, the list of programs will be published on the DIR website,” DIR said in a statement.

The news comes after the recent ransomware attack on 23 Local Government Organizations in Texas that compromised valuable data.

“On the morning of August 16, 2019, more than 20 entities in Texas reported a ransomware attack.  The majority of these entities were smaller local governments,” the DIR said in a statement. “The State of Texas systems and networks have not been impacted. It appears all entities that were actually or potentially impacted have been identified and notified.”

The DIR activated the State Operations Center (SOC) to investigate the origin of the attack. It also stated that it has discovered and reported all the affected organizations and is working on fixing the affected systems. However, the authorities clarified that Texas network systems were not affected in the incident.

Along with SOC, several other Texas and the U.S. government agencies were involved in the recovery process, including the Texas Division of Emergency Management, the FBI, the DHS, and the Texas Department of Public Safety.

Attackers tried to steal Airbus secrets through its suppliers

Airbus cyber-attack

European aerospace corporation Airbus has suffered a cyber-attack by unknown hackers who targeted its suppliers to steal Airbus’s technical and commercial secrets. The hackers reportedly tried to break into computer systems of Airbus’s contractors. It’s believed that the attack is linked to Chinese-affiliated threat actors known as APT10, the Agence France-Presse (AFP) reported.

Airbus designs, manufactures, and sells thousands of civil and military aerospace products globally. According to AFP, the attackers targeted supplier Expleo, British engine-maker Rolls-Royce, and two other French contractors who are working for Airbus.

The hackers seemed to be interested in stealing technical documents linked to different parts of Airbus aircraft, including avionics and propulsion systems for the Airbus A350 passenger jet. AFP also stated that hackers also took other documents related to the innovative turbo-prop engines used on the Airbus military transport plane A400M.

Airbus encountered multiple security breaches in the last 12 months. In January 2019, hackers attacked Airbus’s commercial aircraft business information systems, which resulted in unauthorized access to its employees’ personal data. The majority of the accessed information was professional contacts and IT identification details related to Airbus employees in Europe. However, Airbus clarified that there was no impact on its commercial operations and also stated the incident was being investigated by its security professionals.

Airbus notified the data regulatory authorities about the data breach in accordance with the GDPR (General Data Protection Regulation). It also suggested its employees take the necessary precautions to prevent further loss.

“This incident is being thoroughly investigated by Airbus’ experts who have taken immediate and appropriate actions to reinforce existing security measures and to mitigate its potential impact, as well as determining its origins. Investigations are ongoing to understand if any specific data was targeted, however, we do know some personal data was accessed. This is mostly professional contact and IT identification details of some Airbus employees in Europe,” Airbus said in a statement.

Why Ethan Hunt, John McClane and James Bond need to be Certified Security Professionals

Cyberwar, cyberterrorist

CISO MAG EDITORIAL

If you’ve been tracking cybersecurity news daily, then you could probably imagine the script for the next  Die Hard, James Bond, Mission Impossible or Lethal Weapon film. The script in these films will continue to include shootouts, car chases, daring leaps from glass towers or craggy cliffs – but there will also be a new kind of duel that won’t involve silencer muzzled Walther PPKs or Magnums. The cat and mouse show became Spy vs. Spy in the cold war, and now becomes hacker vs. hacker. So Ethan Hunt (the character played by Tom Cruise in the Mission Impossible movies) will probably need to be a certified security professional as well – that’s if he intends to stop tech-savvy villains from hacking into the Department of Defense and stealing the launch codes for nuclear weapons. Ditto for James Bond/MI6 and John McClane (Die Hard). For the time being, he can depend on the techie in his team who supports him from a bunker or van laden with technical paraphernalia.

Last week, vpnMentor reported that a database containing 20 million records — of the population of an entire country, including its President –- was compromised. The country in question is Ecuador. They did not spare WikiLeaks founder Julian Assange either – he was granted asylum by Ecuador in 2012. Well, if that’s possible, imagine what would happen if the entire social security database containing national IDs was stolen – and the details leaked online.

While the focus on warfare shifts to outer space, governments should not ignore the warfare that is happening now in cyberspace. And Ecuador is just one example.

Countries will now build armies with soldiers and spies with cybersecurity skills. Yes, new-age spies are already trained in cybersecurity. But it’s going to take some time and effort to build a cybersecurity force, as there is a shortage of cybersecurity professionals in the industry.

But one can start today. Start by training students. Security needs to be included in university curricula. We read somewhere that a school was teaching kindergarten students the basics of cybersecurity. And why not? If a kid can learn to use iPads and Google before they can learn to write essays, then they should be aware of cybersecurity, cyberbullying, trolls, and the dark alleys of the internet.

So, Hunt, McClane, and Bond – you need to get that certification right away because your next assignment will be against cyberterrorists. And be sure to talk to the kids about cybersecurity too!

 

Cybersecurity Startup CyberFortress raises US$ 3 Million

Aviatrix Funding

CyberFortress, a security services provider, recently announced that it has raised US$ 3 million in a seed funding round co-led by Greycroft and LiveOak Venture Partners. The company stated the new proceeds will be used to expand its product development team and business expansion.

Founded in 2018, CyberFortress is an insuretech startup focused on protecting e-commerce companies from cyber threats. The startup offers cyber insurance services to small and medium enterprises to overcome the risk of potential cyber events including cyber-attacks, internal errors, or third-party failure. CyberFortress claims that it worked with data security firms to leverage cybersecurity, risk analysis, and portfolio management expertise.

“The main cyber threat facing e-commerce companies is downtime. A DDoS attack, service provider outage, or internal error that takes down their website can be devastating to an e-commerce company,” said Huw Edwards, CEO of CyberFortress. “If a small e-commerce company can’t collect revenue, they may not be able to make their next payroll. Our policy is laser-focused on solving this critical problem.”

“The elegance of CyberFortress’s product is incredibly unique. Their underwriting is efficient and the rapid, automated payment of claims will make for delightful customer experience. These characteristics are unusual in the commercial insurance universe and we believe they will set CyberFortress on a path to scale,” Edwards added.