Home Blog Page 296

McAfee acquires Nanosec to strengthen Container Security Capabilities

FireEye Acquires Respond Software

Cybersecurity firm McAfee recently announced the acquisition of NanoSec, a Container Security Startup, to improve its compliance and to mitigate the risk of its container deployments.

NanoSec is a multi-cloud and zero-trust application security platform that’s focused on the container approach to application security. The new acquisition allows McAfee to boost its MVISION Cloud and MVISION Server Protection products.

“McAfee’s focus and innovation have allowed it to deliver industry-leading cloud security capabilities to help our customers securely leverage the cloud to accelerate their business,” said Rajiv Gupta, senior vice president, and general manager of the cloud security business unit, McAfee. “NanoSec’s technology is a natural extension for McAfee MVISION Cloud, enhancing our current CASB and CWPP products, and adding to our ‘Shift-Left’ capabilities to deliver on the DevSecOps best practice to improve governance and security. NanoSec’s team brings a wealth of experience to McAfee, and together we are committed to enabling organizations to reach their full cloud potential.”

“Joining forces with McAfee means that our ground-breaking capabilities including our unique application-identity based approach for app-level protection and micro-segmentation will be available on a global scale,” said Vishwas Manral, founder and CEO of NanoSec. “McAfee has demonstrated not only its leadership in cloud security but its desire to continually innovate and deliver new capabilities that reshape how organizations can operate workloads and applications safely in the cloud. It felt like a natural fit to join McAfee to deliver to application development and security professionals’ greater visibility and control over detecting, responding and resolving threats to reduce risk.”

McAfee recently joined hands with Amazon Web Services (AWS) to offer cloud-based security solutions. McAfee announced its Database Security for Amazon Relational Database Service (Amazon RDS). McAfee stated its new security product delivers real-time visibility into all database activities and offers monitoring services to prevent sophisticated attacks.

The new alliance allows users to benefit from real-time protection for database workloads migrated to Amazon RDS while monitoring databases. McAfee claims that its newly designed Database Security platform is a highly scalable software solution that monitors the Database Management System.

FBI’s new Surveillance Proposal clashes with Facebook’s Privacy Policies

FBI, FatPipe MPVPN zero-day

In an effort to monitor social media platforms for potential threats, the Federal Bureau of Investigation (FBI) came up with a new surveillance proposal last month.

As per the new proposal, the FBI is asking third-party vendors to provide monitoring services, which might bring up possible conflicts with Facebook and other social media companies over privacy policies. It’s said that the new surveillance proposal by FBI would clash with Facebook’s privacy policies settlement, worth  $5 billion, with the U.S. government.

Security experts opine that the FBI’s proposal would violate the companies’ ban against using their data for monitoring purposes. Facebook has not yet commented on the new proposal. However, the microblogging service provider Twitter stated that its privacy policies will not allow using its data for surveillance purposes.

“The Federal Bureau of Investigation (FBI) intends to award a firm fixed-price contract for the purpose of acquiring subscription services to a social media early alerting tool in order to mitigate multifaceted threats, while ensuring all privacy and civil liberties compliance requirements are met,” the FBI said in a post.

Facebook is set to pay the largest fine imposed on a technology company by the Federal Trade Commission. The social media giant has been slapped with a massive $5 billion fine for allegedly violating privacy practices and mishandling user data during the infamous Cambridge Analytica scandal and other privacy breaches.

The FTC ordered Facebook to adopt new policies for protecting users’ data and expand these policies across Instagram and WhatsApp. Facebook has also been asked to create a new privacy committee that will have independent board members. Moreover, a third-party assessor approved by the FTC will be brought on board to conduct biennial assessments and monitor Facebook’s privacy-related decisions.

Apple offers $1 million Bug Bounty to hack its iPhone

Apple Is Hackers’ Favorite for Brand Phishing Attacks, REvil gang threatens Apple blueprint leak

With an aim to find potential vulnerabilities in its network systems, Apple recently announced a reward of $1million (£830,000) for bug hunters. According to Ivan Krstic, Apple’s head of security, the technology giant is going to offer the proposed huge bug bounty to anyone who can hack an iPhone.

Speaking at the Black Hat technology security conference in Las Vegas, Krstic stated that the company is also going to reward another $500,000 (£415,500) to those who can find a Network Attack or any other technical flaws in its devices, making it more lucrative to security researchers.

In order to win the bounty, the attackers are required to gain full access of an Apple device remotely, without the device owner’s knowledge.

Apple isn’t the only company to offer huge bug bounty rewards. Recently, the search engine giant Google announced the increase in bug bounty rewards. The company stated that it has raised the bounties for Chrome and Google Play bugs. Google launched the vulnerability rewards program in 2010 and provides cash rewards to security researchers who report vulnerabilities in Google code. The company stated that they’ve received around 8,500 vulnerability reports and paid rewards over $ 5 million (£4 million).

According to Google’s Chrome security experts Natasha Pabrai and Andrew Whalley, the company has doubled the maximum reward on High-Quality Reports from $15,000 (£12,000) to $30,000 (£24,000) and tripled the baseline reward amount from $5000 ((£4 million) to $15,000 (£12,000) for good measure.

What I learned at the Black Hat USA 2019 Conference

Contributed by Jason Bloomberg

The phrase ‘black hat’ refers to a hacker with criminal intentions, so I expected my first trip to the Black Hat USA conference held in Las Vegas this year to give me exposure to the shady underbelly of the cybersecurity world.

On that account, I was disappointed. Black Hat has gone corporate.

Oh, I’m sure there were a few bona fide criminals in the mix and a far greater number of individuals up for some not-quite-illegal mischief-making. But the vast majority of attendees were more of the ‘white hat’ variety – hackers who seek to find, understand, and exploit software vulnerabilities in order to help protect their employers.

Fortunately for the vendors exhibiting at the show, the white hat hackers brought their bosses as well. Many a CISO roamed the floor, seeking that essential piece of gear that would keep their organization out of the dog house where Capital One, Equifax, and so many others have found themselves of late.

For CISOs and others who routinely attend the much larger RSA Conference, however, Black Hat was indubitably a disappointment, as the exhibit floor was essentially ‘RSA light.’ Many of the same names and faces show off their wares at both shows, so picking one’s way among the booths revealed little that was worthy of Black Hat’s reputation as a hacker show.

The sessions, in contrast, are reasonably different from the fare at RSA. However, with titles like Exploiting the Hyper-V IDE Emulator to Escape the Virtual Machine and Infiltrating Corporate Intranet Like NSA – Pre-auth RCE on Leading SSL VPNs, it’s clear the speakers at Black Hat were targeting the hacker more so than the CISO.

Highlights of the Show Floor

There was still a lot for security professionals to learn on the floor regardless. Established vendors like NETSCOUT discussed the full integration of its 2015 acquisition of security vendor Arbor Networks, combining Arbor’s ability to rapidly identify and characterize threats with NETSCOUT’s extraordinary access to network intelligence, both on the Internet and on corporate networks.

Another established cybersecurity vendor, Securonix, discussed its new network traffic analysis (NTA) product offering that monitors and correlates network traffic events, security events, and user activities to detect even the most advanced threats, thus offering a combination of a standalone traffic analysis tool and security information and event management (SIEM) in one product.

There were also a number of startups on display at Black Hat. Among the more interesting examples is Armis, an Internet of Things (IoT) security vendor. The IoT is remarkably vulnerable, as most devices from baby monitors to hospital MRI machines lack sufficient security, or contain software with known vulnerabilities.

In many situations, furthermore, it’s impractical or impossible to update the software on such devices. In some cases, the devices simply do not allow for updates, and in others, any attempt at such an update would damage the device.

Armis responds to this challenge by securing the network interactions with IoT devices. It can detect vulnerable or compromised devices by looking at their network traffic and then either mitigate vulnerabilities or segment the network, isolating compromised devices from the network.

Most Disruptive: QOMPLX

I spoke with a number of other vendors, and perhaps the most exciting and disruptive is QOMPLX, formerly known as Fractal Industries. QOMPLX is commercializing technology its team originally built for the US Air Force, which required complete situational awareness in cyberspace. In other words, the Air Force wanted a holistic way of understanding who was doing what to whom.

To meet this requirement, QOMPLX’s core innovation is technology for combining time-series and graph data into a single hybrid data platform. Time series data include log files, IoT telemetry, and any other operational data that stream continually from their sources. Graph data include the relationships among entities, allowing for complex, natural language searching.

Never before has a vendor combined these two approaches for storing and managing data in such a high-performance manner. The result is the ability to glean relationships among timestamped data even in situations where the data sets are massive and streaming.

The use cases for QOMPLX’s technology are remarkably varied, and extend well past cybersecurity. However, given the prevalence of time series data relevant to the security domain, Black Hat proved an appropriate forum for the technology.

Case in point: QOMPLX is able to solve the perennial security challenges with Kerberos, an established authentication protocol favored in Windows environments.

Kerberos depends on exchanging tickets that must expire quickly because given enough time, a hacker can compromise them. QOMPLX brings sufficient context to bear in order to solve this problem, which has proven to be one of the knottier cybersecurity challenges of the last 20 years.

QOMPLX, however, is no one-trick pony. It also provides sufficient context for cybersecurity insurers to calculate accurate rates – a problem that has limited the ability of such insurers to cover more than a narrow set of risks.

Expect to see many other disruptive use cases from this startup. QOMPLX is not without its own challenges, however. Top of the list: just explaining what it does. Here’s how its web site explains its platform: “An Enterprise Operation System designed to enable data-driven, contextualized decision platforms that are risk-centric and highly customizable for virtually any business domain.” Got that?

Taking Risk Management to the Next Level

Black Hat may no longer be for the black hats, but its central mission is all about finding and exploiting the software vulnerabilities that represent enterprise cybersecurity risk.

Understanding such risk is essential to managing it – and managing such risk is really what Black Hat is all about. Cybersecurity personnel – white hat or no – are not able to manage such risk by themselves. “Risks are shared. Security is everybody’s job,” explained Dino Dai Zovi, Head of Security – Cash App at Square, in his morning keynote.

As a result, the hacker as outsider is rapidly becoming an obsolete trope in the enterprise. “We’re not outsiders anymore,” Dai Zovi continued. “We’re inside communities and inside organizations.”

Black Hat may have gone corporate, but that’s just what the enterprise needs.

NETSCOUT and Securonix are Intellyx customers. None of the other organizations mentioned in this article are Intellyx customers. Black Hat provided Jason Bloomberg with a free pass to the conference.

The writer is founder and president of Digital Transformation analyst firm Intellyx. He is also a leading IT industry analyst, author, keynote speaker, and globally recognized expert on multiple disruptive trends in enterprise technology and digital transformation. He is ranked #5 on Onalytica’s list of top Digital Transformation influencers for 2018 and #15 on Jax’s list of top DevOps influencers for 2017, the only person to appear on both lists.

The opinions expressed in this article are the personal opinions of the author. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

DSLR Cameras are vulnerable to attacks: Researchers

Security researchers have discovered that DSLR cameras, which are connected to a Wi-Fi network, are vulnerable to ransomware attacks. The researchers, from the security firm Check Point Software, discovered that connected-cameras can be hacked if an attacker is nearer to the camera’s Wi-Fi.

Demonstrating their discoveries at the DefCon 2019 hacking conference, the researchers stated that hackers can encrypt the digital photos once they compromise the device. The researchers used and identified the flaws in a Canon EOS for their demonstration.

According to the researchers, the digital cameras use Picture Transfer Protocol (PTP) to transfer digital files, which can be exploited by malicious actors to infect the camera with ransomware.

The researchers presented how an attacker can inject the malware and encrypt photos in the camera’s memory using the cryptographic process.

Check Point stated that they reported these issues to Canon in March 2019. However, Canon urged its customers to avoid unsafe Wi-Fi networks and upgrade the device in order to fix the bugs.

“Daniel Mende demonstrated all of the different network attacks that are possible for each network protocol that Canon’s EOS cameras supported at the time. At the end of his talk, Daniel discussed the PTP/IP network protocol, showing that an attacker could communicate with the camera by sniffing a specific GUID from the network, a GUID that was generated when the target’s computer got paired with the camera. As the PTP protocol offers a variety of commands, and is not authenticated or encrypted in any way, he demonstrated how he (mis)used the protocol’s functionality for spying over a victim,” Check Point stated in a post.

“In our research, we aim to advance beyond the point of accessing and using the protocol’s functionality. Simulating attackers, we want to find implementation vulnerabilities in the protocol, hoping to leverage them in order to take over the camera. Such a Remote Code Execution (RCE) scenario will allow attackers to do whatever they want with the camera, and infecting it with Ransomware is only one of many options,” the statement added.

Malware campaign against Chinese speaking users

Malware

FortiGuard Labs, the research division of Fortinet has unearthed a backdoor malware campaign against Chinese speakers. The attack exploits a watering hole strategy where the malware is delivered through a hacked Chinese news site. Researchers mull that the campaign is in an experimental phase as several different techniques and tools are being deployed by the hackers to target end-users.

“We first discovered this backdoor malware campaign in 2017, and over the years it has continued to upgrade its functionalities.” states a release on FortiGuard Labs.

The hackers are using exploiting known vulnerabilities on WinRAR and RTF files. The flaws have been identified as cve-2018-20250 and cve-2017-11882 respectively. The biggest victim of the hack currently is the Chinese news website. Hackers have even able to obtain the legitimate domain and have been spreading backdoors to the PCs of readers of the site.

If any computer is vulnerable, a WinRAR flaw is used to hide a .ace file as a regular .rar and another conf.exe file which is then extracted and triggered for spreading. The conf.exe has the trojan called Sality which loads a malicious DLL which can send data to the hacker’s server.  “The Sality-infected backdoor payload is the same as the download qq.exe.  We find that both the backdoor malware code and the Sality code are running when the malware is executed. We also observed the following connections when this sample runs, though we haven’t observed any further activities from the Sality C2 servers,” FortiGuard Labs pointed.

While the company has analyzed the functionalities of the malware and the C2 (attacker’s servers), the trojan is dynamic and has been adding new and more robust functionalities that are aimed at improving the malware’s ability to steal information and data from users.

 

Cybersecurity workers leaving companies over Privacy Disputes

personal data collection, Personal data. Data Privacy

Contributed by Devin Smith

The tech sector is suffering the adversities of shortage of technically skilled employees, particularly in the domain of cybersecurity. This causes the “less-technical” staff to exert pressure on their employers. Research published by an independent think tank revealed that business morality is a primary consideration for skilled tech workers who often quit their jobs because their companies do not comply with privacy norms.

According to the study, one out of five technically sound employees end up quitting their job if they find that the policies of the firm don’t comply with privacy norms. Their decision costs the firm a hefty $38,000 every time a skilled professional leaves the company.

What triggers their decision to quit the job? How do they choose between the most crucial thing (privacy) and their job?

Do consumer opinions matter?

As per the research mentioned above, 38% of the employees used to have web search result access. This itself has potential consequences but can be beneficial to know the company’s reputation among the general public.

The emotional melodrama and the psychological impact of mishandling the data have caused privacy activists to fume. This has also made privacy an alarming issue. Moreover, this also explains why tech firms are more than eager to offer as much privacy to consumers than ever.

Back in 2017, the CEO of Yahoo!, Marissa Meyer, was forced to resign after emails of millions of users was compromised. It was discovered that Yahoo! was secretly scanning customer emails on behalf of U.S. intelligence agencies like the NSA and FBI. The revelation resulted in global outrage, and impacted the value of the company.

This year, two-Facebook employees resigned after a disagreement with the CEO himself, Mark Zuckerberg. The two left the company after they felt the company (Facebook) might be a part of major snooping conspiracy, notably the Cambridge Analytica data scandal. Facebook has already acquired WhatsApp and Instagram, and it is of no question that the social networking giant (can) snoop if needed. It appears to be that these employees had a confrontation over data privacy.

The young generation today is focused on business, with little or no conscience that compromising privacy leaves a daunting impact on society. However, many amongst these young employees say that they would not hesitate to leave if their company violates the terms or has political leanings.

Should you leverage privacy for your career?

After the infamous Cambridge Analytica Scandal and the emergence of GDPR law, privacy has become a huge concern for both consumers and employers. Tech workers are left with no choice but to scrutinize the data practices and make it as fair as possible.

Tech employers know that if a breach takes place or something goes wrong, then they will end up in hot water. Not only do they have the company’s integrity at stake, but they can also end up ruining their reputation and career prospects.

Dawn McGruer the founder of Business Consort once said: “Employees have a good reason to simply shy away from firms that don’t value privacy.”

McGruer added that it is important for firms to make relentless efforts, demystify policies, and educate businesses about how to reduce the strain, and spread the responsibility evenly.

Tech employers are now aware of the fact that a bad decision or a single bad step can negatively affect the ability to get future employment. As it is rightly said: “A breach in violation never impacts positively; it leaves a deep black spot which stays for a lifetime.”

Bi-Polar policies by firms

There are firms whose flawed policies ruins the reputation of the entire industry. Employees often misunderstand the fundamental practice and trade secrets, plus they often get confused with the concept of theft of intellectual property. Firms, on the contrary, find it hard to cope with the vacuum created when a professional leaves the organization.

To mitigate or avoid this situation, businesses demonstrate a desire to protect consumers and their employer’s privacy, just to lure people and tech sector employees.

Sunita Bose who is acting as a Managing Director of the Digital Industry Group, an association which includes tech giants like Facebook, Google, Twitter, Verizon, and Amazon commented on the situation: “The best regulation possible for the online world will arise when the industry and the community will work hand in hand and closely together for the betterment of the entire cyber world.”

GDPR is commendable and is a step in the right direction. Similar legislations are now emerging around the world with many still in the thought process. In the U.S., a federal bill was proposed to supersede the state-level legislation. However, the tech sector and the consumers need to stay vigilant in order to ensure that their privacy stays intact.

Conclusion

Surveillance capitalism has thrived due to the absence of policies, government regulation, and the lack of morality in tech firms. Keeping that in mind, we can conclude that there couldn’t be a better time to influence firms from technically skilled professionals. It will also leave a positive impact on government officials who will forcefully pass the legislation needed to ensure privacy at the earliest.

Anthea Morris, the co-founder of Better2Know once said: “I can see that if digital privacy becomes an increasing issue it might affect people to choose for positions in the company, and with this trend increasing in the future, we might face a challenge to promote the reputation of privacy.”

Devin Smith is a tech-mech by profession. He is also passionate about discovering the varying indulgence of the Tech World. He has studied marketing and is now turning his exposure into an experience. He plays soccer in his spare time.

The opinions expressed in this article are the personal opinions of the author. The facts and opinions appearing in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

WhatsApp yet to fix flaws identified by Check Point

Whatsapp

Check Point Software Technologies Ltd says it has found flaws in the WhatsApp messaging app that hackers could potentially exploit to manipulate messages in private or public conversations. This news was reported in Bloomberg Cybersecurity. If this is possible, it could have serious consequences on private and public security. The privacy of individuals could also be compromised. Threat post reports that reasearchers at the Black Hat USA 2019 conference demoed how known vulnerabilities in WhatsApp could still be exploited in several attacks that manipulate chats.

Check Point said its researchers found three potential ways to alter conversations. One uses the “quote” feature in a group conversation to change the appearance of the identity of a sender. Another lets a hacker change the text of someone else’s reply. And the other, which has been fixed, would let a person send a private message to another group participant disguised as a public message to all, so when the targeted individual responded, it was visible to everyone in the conversation.

“We carefully reviewed this issue a year ago and it is false to suggest there is a vulnerability with the security we provide on WhatsApp,” a spokesperson for Facebook Inc., which owns WhatsApp, said in an emailed statement. “The scenario described here is merely the mobile equivalent of altering replies in an email thread to make it look like something a person didn’t write. We need to be mindful that addressing concerns raised by these researchers could make WhatsApp less private – such as storing information about the origin of messages.”

Oded Vanunu, Check Point’s head of products vulnerability research, feels the flaws could have serious consequences. WhatsApp has about 1.5 billion users worldwide. It is used not just for personal conversations but also for team collaboration in business. Governments also use WhatsApp for government to citizen communication. Groups have misused WhatsApp to spread misinformation leading to riots and public chaos in some countries. Check Point is an Israeli software company that provides security solutions such as firewalls, security gateway appliances, and other security solutions for networks, the cloud and for mobile platforms.

Check Point said it alerted WhatsApp about the flaws late last year. But the company said only one of the flaws — disguising a private message as one that becomes visible to an entire group — has been addressed. Vanunu said his company is working with WhatsApp, but the other problems were difficult to solve because of the messaging app’s encryption.

This is not the first time that WhatsApp bugs are being reported.

Symantec stated the security flaw, dubbed Media File Jacking, affect WhatsApp for Android by default, and Telegram for Android if certain features are enabled. The flaw, if exploited, allows the attackers misuse and manipulate sensitive information like personal photos and videos, corporate documents, invoices, and voice memos, Symantec stated.

Insiders upload Malware to unlock 2 million AT&T Mobiles

AT&T Inc.

A recruiter from the telecommunications company AT&T Network was charged for paying insiders to upload malware on the company’s computer networks to unlock cell phones.

According to the United States Department of Justice (DOJ), Muhammad Fahd, a recruiter in AT&T, was arrested in Hong Kong on February 4, 2018, for committing unauthorized access. The DOJ declared that Fahd has employed several paid insiders and provided them with credentials to inject malware.

The insiders, who worked in AT&T’s Bothell Customer Service Center, allegedly exploited AT&T’s proprietary locking software to remove millions of phones from the AT&T network system and payment plans, which incurred a loss of million dollars to the company. It’s said that Fahd and his co-conspirators gave over $1 million in bribes to install malware and spying devices in the company.

“This arrest illustrates what can be achieved when the victim of a cyber-attack partner quickly and closely with law enforcement,” said Assistant Attorney General Brian A. Benczkowski of the Justice Department’s Criminal Division.  “When companies that fall prey to malware work with the Department of Justice, no cybercriminal—no matter how sophisticated their scheme—is beyond our reach.”

“This defendant thought he could safely run his bribery and hacking scheme from overseas, making millions of dollars while he induced young workers to choose greed over ethical conduct,” said U.S. Attorney Brian T. Moran for the Western District of Washington.  “Now he will be held accountable for the fraud and the lives he has derailed.”

Recently, DoJ had indicted two Chinese nationals for their role in the Anthem hack. The hack, which, in its time, was considered one of the biggest cyber-attacks the nation had ever witnessed, had compromised data of nearly 80 million people. The leaked data included birthdays and Social Security Numbers of the customers. Even though there were four companies that were victims in the released indictment, only Anthem had been named.

The DoJ has not accused both persons, Fujie Wang and the other who has only been identified as John Doe, a Chinese intelligence personnel. The recent indictment answers several speculations among the cybersecurity experts, who have long tried to establish a connection between the hack at Anthem and the involvement of Chinese Intelligence.

North Korean hackers made $2 billion: UN report

Konni Malware, North Korean threat actors target AstraZeneca

State-sponsored hackers from North Korea could have earned around $2 billion by hacking cryptocurrency exchanges and financial organizations.

According to a report from the United Nations (U.N.), North Korea has used its hackers to allegedly generate income to fund its nuclear and missile programmes, Reuters reported.

The security experts opined that North Korea has used sophisticated attacks to snip away funds from cryptocurrency exchanges across the world.

North Korea was accused multiple times earlier for stealing valuable information and cryptocurrencies. Through the years, North Korea has been linked to a series of cyber-attacks, either to display its cyber prowess or just to fund their activities. One of the most brazen attacks occurred in February 2016 when hackers tried to steal $101 million from an account at the New York Federal Reserve and move it to Sri Lanka. Only a spelling error caused the banks to realize they were under attack.

The scandalous Lazarus Group, allegedly backed by North Korea is the prime suspect in these cyber-muggings. Andariel, one of the ill-famed tributaries of the country has already swindled 70 Monero from a South Korean cryptocurrency exchange in 2017.

In another incident, the U.S. Department of Justice announced charges against a North Korean national who was accused of being behind the hack of Sony and the WannaCry ransomware attacks. According to the official statement, Park Jin Hyok worked with a team of hackers, also known as the Lazarus Group, to conduct multiple destructive cyber-attacks around the world, resulting in damage to massive amounts of computer hardware, loss of data, money, and other resources.

Those malicious activities/attacks include the creation of a malware used in the 2017 WannaCry 2.0 global ransomware attack, theft of $81 million from Bangladesh Bank in 2016, attack on Sony Pictures Entertainment in 2014, and numerous other intrusions on the entertainment, financial services, defense, technology, virtual currency industries, academia, and electric utilities.