Home Blog Page 303

Hackers move Bitcoins stolen from Binance to other cryptocurrency exchanges

Bitcoin

Hackers who stole 7,000 Bitcoins from the Binance exchange are found transferring the digital assets to other cryptocurrency exchanges. A research report from the Cybersecurity and Blockchain company Confirm stated that they’ve discovered signs indicating a possible start of transferring stolen funds to Fiat via different cryptocurrency exchanges.

“Analysis of one of the mainchains used by the hacker in layering stolen funds shows that they were able to liquidate at least 1.8087 BTC (21,000.00 USD) on the following exchanges,” Confirm said in a statement.

The Taiwanese company stated it discovered the breach on May 7, 2019, at 17:15:24 (UTC), in which hackers illegally obtained over 7,000 Bitcoins by using a variety of attack methods, including phishing, viruses, and other attacks.

According to Binance, hackers also accessed several user API keys, 2FA codes, and other information. Following the hack, the exchange suspended all the operations temporarily and assured that it will refund the affected customers in full.

“The hackers had the patience to wait and execute well-orchestrated actions through multiple seemingly independent accounts at the most opportune time. The transaction is structured in a way that passed our existing security checks. It was unfortunate that we were not able to block this withdrawal before it was executed. Once executed, the withdrawal triggered various alarms in our system. We stopped all withdrawals immediately after that,” Binance said in a statement.

In a recent cyber-attack, popular cryptocurrency exchange Bithumb lost around three million EOS (worth $13.4 million) and 20 million Ripple coins (XRP) of worth $6 million. In an official statement, Bithumb stated that on March 29, 2019, at around 10:15 pm the company detected abnormal withdrawals of its cryptocurrencies from its hot wallets. Bithumb stated that it secured all the cryptocurrency during the detection time and confirmed that the customers’ assets are safe under the protection of a cold wallet.

Describing the incident as an “accident involving insiders”, Bithumb said “we are conducting intensive investigations with KISA, Cyber Police Agency and security companies. At the same time, we are working with major exchanges and foundations and expect to recover the loss of the cryptocurrency equivalent.”

10 percent of Indian IT managers think they can handle cyber-attack

cybersecurity career

According to a recent survey by network and endpoint security firm Sophos, less than 10 percent of Indian IT managers are confident that they have skilled cybersecurity talent to thwart a cyber attack. The survey titled, ‘The Impossible Puzzle of Cybersecurity’, points out that IT teams only about a third of their time to manage security, but most of them takes a punch due to lack of experts, budget and technology.

Among the surveyed, nearly 81 percent felt that the cybersecurity budget of their organization is way below what is required, with 89 percent stating that they find it very difficult to keep up with the challenges that are thrown at them.

“Staying on top of where threats are coming from takes dedicated expertise, but IT managers often have a hard time finding the right talent or don’t have a proper security system in place that allows them to respond quickly and efficiently to attacks,” said Chester Wisniewski, principal research scientist, Sophos. “If organizations can adopt a security system with products that work together to share intelligence and automatically react to threats, then IT security teams can avoid the trap of perpetually catching up after yesterday’s attack and better defend against what’s going to happen tomorrow.”

The study surveyed over 3,100 IT decision makers from several small and medium sized industries in India, Canada, Mexico, Colombia, Brazil, the UK, France, Germany, Australia, Japan, South Africa and the United States and was conducted between December 2018 and January 2019.

“Cybercriminals are evolving their attack methods and often use multiple payloads to maximize profits. Software exploits were the initial point of entry in 23 percent of incidents, but they were also used in some fashion in 35 percent of all attacks, demonstrating how exploits are used at multiple stages of the attack chain,” Wisniewski added.

Earlier, a survey by outbound hiring firm, Belong, the demand for cybersecurity professionals in India has gone up three times in past 12 months creating an eminent skill gap.  “As companies seek to bolster their defence against data security breaches, the demand for cybersecurity experts in India has outstripped supply of these professionals by three times over the past 12 months,” the company stated in a release.

Indian security researcher wins bug bounty after exposing a flaw in Instagram

Instagram

An Indian-based security researcher discovered a bug in Instagram’s Account Recovery Process that could have allowed attackers to break into users’ accounts.

Independent researcher Laxman Muthiyah said that he found the vulnerability while investigating how the account recovery process of the photo sharing application allows you to regain access to your account when you’ve forgotten the password. In a video, the researcher presented how he used ‘brute-force’ attack to break into Instagram’s account recovery process.

“Instagram forgot password endpoint is the first thing that came to my mind while looking for an account takeover vulnerability. I tried to reset my password on the Instagram web interface. They have a link-based password reset mechanism which is strong, and I couldn’t find any bugs after a few minutes of testing. Then switched to their mobile recovery flow, where I was able to find a susceptible behaviour,” Laxman Muthiyah said in a post.

“When a user enters his/her mobile number, they will be sent a six-digit passcode to their mobile number. They must enter it to change their password. Therefore, if we can try all the one million codes on the verify-code endpoint, we would be able to change the password of any account. But I was pretty sure that there must be some rate-limiting against such brute-force attacks. I decided to test it,” Muthiayah added.

The researcher said the security team of Facebook fixed the issue and rewarded him $30,000 as a part of their bug bounty program.

Recently, an unprotected server containing personal information of millions of Instagram influencers, celebrities, and brand accounts have been found online. According to the security researcher Anurag Sen, who discovered the leak and notified TechCrunch, the database had over 49 million records exposed online, allowing anyone to access.

The exposed data included users’ biodata, profile picture, the number of followers they have, their location by city and country, and contact information like the Instagram account owner’s email address and phone number. Anurag stated the leaky database belongs to a social media marketing firm Chtrbox, which is based in Indian state Mumbai. The database was taken offline and called for an investigation on the incident, Chtrbox stated.

 

Attackers can exploit media files on WhatsApp and Telegram accounts: Symantec

Whatsapp

Security experts recently discovered a flaw affecting WhatsApp and Telegram accounts for Android devices. According to Symantec’s Modern OS Security team, the flaw allows the malicious attackers to manipulate and expose media files in WhatsApp and Telegram.

Symantec stated the security flaw, dubbed Media File Jacking, affect WhatsApp for Android by default, and Telegram for Android if certain features are enabled. The flaw, if exploited, allows the attackers misuse and manipulate sensitive information like personal photos and videos, corporate documents, invoices, and voice memos, Symantec stated.

“The Media File Jacking threat is especially concerning considering the common perception that the new generation of IM apps is immune to content manipulation and privacy risks, thanks to the utilization of security mechanisms such as end-to-end encryption. Users generally trust IM apps such as WhatsApp and Telegram to protect the integrity of both the identity of the sender and the message content itself. This contrasts with older apps/protocols such as SMS, which are known to be spoofed easily,” Symantec said in its research report.

“However, as we’ve mentioned in the past, no code is immune to security vulnerabilities. While end-to-end encryption is an effective mechanism to ensure the integrity of communications, it isn’t enough if app-level vulnerabilities exist in the code. What the Media File Jacking research we found demonstrates is that attackers may be able to successfully manipulate media files by taking advantage of logical flaws in the apps, that occur before and/or after the content is encrypted in transit,” the report added.

The popular messaging applications recently suffered a hacking attack in different scenarios. WhatsApp revealed that it discovered a vulnerability in its network system that allowed hackers to install spyware via an infected WhatsApp voice call. The Facebook-owned social messenger stated the spyware can exploit the mobile device, its calls, texts, and other data. It can also activate the phone’s camera, microphone, and able to perform other malicious activities. According to Facebook, the malicious spyware was developed by Israel-based cyber intelligence company NSO Group.

Telegram recently suffered a DDoS attack that affected the users in the United States, Hong Kong, and in other countries. Telegram, well-known for its encryption, privacy, and self-destructive private messages, stated the users might have experienced connection issues due to the attack.

DefenseStorm raises $15 million in Series A financing

Startup funding

DefenseStorm, a cloud-based cybersecurity and cyber compliance management provider, announced that it has raised $15 million in a Series A financing round led by Georgian Partners.

The Atlanta-based startup stated the new proceeds boost the company’s commitment to offer enhanced cybersecurity solutions and accelerate growth. In addition to the investment, Justin LaFayette, Managing Partner at Georgian Partners, will join the DefenseStorm board of directors.

DefenseStorm provides cybersecurity and cyber compliance solutions for regional, community banks, and credit unions in order to achieve Cyber Safety & Soundness. The company claims that its DefenseStorm GRID technology is the only co-managed, cloud-based, and compliance-automated solution that watches everything on a bank or credit union’s network and matches it to defined cyber exposure readiness.

“DefenseStorm is growing rapidly, and our primary goal is not only to ensure that we take care of both our current and potential customers, but also that we invest in our employees and the innovation they continue to bring to the table,” said Harold Brewer, DefenseStorm CEO. “We are thrilled to have the support of the Georgian Impact team and look forward to a lasting partnership benefitting the entire cybersecurity community.”

“We are very excited to be partnering with DefenseStorm through this new investment and our R&D collaboration.” said Mads Mihailescu, Partner and Chief Technology Officer, Georgian Partners. “The combination of DefenseStorm’s deep domain expertise, and our own expertise in trust and artificial intelligence, has already identified a number of opportunities to further accelerate new product capabilities.”

Artificial Intelligence: A new frontier in cybersecurity

Security experts opined that more organizations are turning up to Artificial Intelligence (AI) to shore up their security defenses against cybercrimes. Technology firm Capgemini stated that firms find AI as increasingly necessary to bolster cybersecurity.

In its research, Reinventing Cybersecurity with Artificial Intelligence, Capgemini revealed that most of the technology firms are already started using AI in their cybersecurity initiatives or planning to introduce shortly. The research, which surveyed 850 senior executives from IT Information Security, Cybersecurity, and IT Operations across 10 countries, stated that three in five firms that surveyed said using AI improves the accuracy and efficiency of cyber analysts.

Capgemini stated that 61 percent of enterprises surveyed said that they can’t detect breach attempts without AI technologies and 64 percent of firms said that AI lowers the cost to detect and respond to breaches.

The telecom industry has reported the highest security incidences of losses exceeding $50 million. The U.S.-based enterprises are placing AI-based cybersecurity platforms on the highest priority, according to the research.

“Our findings indicate those organizations that have implemented AI in cybersecurity are realizing significant benefits. Two out of three organizations say AI increases ROI on cybersecurity tools. Take global electrification, automation, and digitalization leader Siemens AG, for example. The Siemens Cyber Defense Center (CDC) used AWS (Amazon Web Services) to build an AI-enabled, high-speed, fully automated, and highly scalable platform to evaluate 60,000 potentially critical threats per second. Because of the AI, they were able to manage this capability with a team of less than a dozen people and without impacts to system performance,” the report stated.

Attackers nab $32 million from BITpoint cryptocurrency exchange

Horangi Raises US$20 Million in Funding to Strengthen Cybersecurity in Southeast Asia

Cryptocurrency exchange BITpoint has become the latest victim of a hacking attack. The Japan-based exchange stated that it discovered an unauthorized withdrawal of $32 million from its hot wallet. The incident came into light when BITpoint tried to make a payment using the cryptocurrency Ripple and got an error message.

BITpoint held five cryptocurrencies in its hot wallet- Bitcoin, Bitcoin Cash, Ethereum, Litecoin, and Ripple. However, the company clarified that its cold wallet and cash holdings were not affected in the incident.

BITpoint halted all the payments In and Out of the exchange temporarily. “To prevent any harm to customer assets, we will handle this responsibly, for example in terms of compensation from Bitpoint,” said the company in a statement. “We regret to inform you we terminate all our services immediately due to Securities Commission Malaysia didn’t permit us to operate as Digital Asset Exchange. We start to return all our existing customer asset. Please note, we are keeping customer asset safely.”

In a recent cyber-attack, popular cryptocurrency exchange Bithumb lost around three million EOS (worth $13.4 million) and 20 million Ripple coins (XRP) of worth $6 million. In an official statement, Bithumb stated that on March 29, 2019, at around 10:15 pm the company detected abnormal withdrawals of its cryptocurrencies from its hot wallets. Bithumb stated that it secured all the cryptocurrency during the detection time and confirmed that the customers’ assets are safe under the protection of a cold wallet.

Describing the incident as an “accident involving insiders”, Bithumb said “we are conducting intensive investigations with KISA, Cyber Police Agency and security companies. At the same time, we are working with major exchanges and foundations and expect to recover the loss of the cryptocurrency equivalent.”

This is a third cyber-attack the company revealed in the past three years. The first hack happened in July 2017, when hackers stole $7 million in Bitcoin and Ethereum, while the second incident took place in June 2018, when hackers stole hackers stole 35 billion won ($31 million). Bithumb released a list of 11 cryptocurrencies lost during the hack as well as the corresponding amounts.

Hackers target online shoppers ahead of Amazon Prime Day

Amazon

Security experts warned online buyers to be vigilant while shopping online, as cybercriminals are taking advantage of the Amazon Prime Day sale to steal sensitive information.

Computer security company McAfee stated that they’ve discovered a new version of a phishing kit, which is being observed since 2018. The new phishing kit, dubbed 16Shop, has been used by malicious actors to target Apple account holders in the United States and Japan, according to McAfee. It’s said that the new version is using to target Amazon customers for the biggest shopping day of Amazon, which is starting from July 15, 2019.

In this type of attack, the victims receive an email with a pdf file attachment that looks like an original email alert you would get from Apple, Amazon, or any other tech company. If the users click on the link in the attached pdf file, they are redirected to a fake site where they trick the user to enter sensitive information like bank account number, debit, and credit card details.

“Most phishing kits will email the credit card and account details entered on the site directly to the malicious actor. The 16Shop kit does this, too, and stores a local copy in other text files. This is a weakness in the kit because anyone visiting the site can download the clear-text files (if the attacker uses the default settings),” McAfee said in a statement. “The kit includes a local blacklist, which blocks certain IP addresses from accessing the website. This blacklist contains lots of IPs of security companies, including McAfee. The blacklisting prevents malware researchers from accessing the phishing sites.”

Meanwhile, Amazon suggested users don’t open any attachments or click any links from suspicious emails. The E-Commerce giant urged its customers to follow basic security measures while shopping.

Amazon recently suffered a fraud attack in which hackers siphoned funds from its merchant accounts over six months last year. The Seattle-based e-tailer stated that unknown cybercriminals broke into around 100 seller accounts and siphoned money into their own accounts, the Bloomberg reported. Amazon said the hack took place between May 2018 and October 2018, and it’s unclear how much money was stolen in the incident.

According to Amazon’s legal team, the hackers managed to alter account details on the Seller Central platform to their own at Barclays Plc and Prepay Technologies Ltd. It’s believed that the accounts were compromised by using phishing techniques that deceived sellers into giving up sensitive information. Amazon stated that its investigation is still ongoing and asked the London judiciary for approval of searching the accounts of hackers.

Hackers demand $2 million after attacking New York’s Monroe College

Bitcoin, Ransomware Attacks

Monroe College in New York City has been under a cyber-attack. According to the officials, the hackers have compromised college’s computer systems and demanded a ransom of around $2 million in bitcoin.

The college authorities stated the incident is investigating by the NYPD. “We are, in fact, under cyberattack. A lot of our systems are being held — we do not have access at the moment,” Monroe’s officials said in a statement.

“We are obviously taking this very seriously … but we’ve rolled up our sleeves. Monroe was founded in 1933, and what that means is we know how to teach the old-fashioned way,” the statement added.

Several of the Baltimore city services were halted after a ransomware attack hit city computers. According to the news portal Baltimore Sun, hackers infected about 10,000 of Baltimore city government’s computers on May 07, 2019, with ransomware called RobbinHood. The attackers asked the city officials pay 13 bitcoins (about $100,000) to release the city’s systems, warning that price would go up every day after four days, and after the tenth day, the affected files would be lost permanently.

“We’ve been watching you for days and we’ve worked on your systems to gain full access to your company and bypass all of your protections,” the ransom note read.  “We won’t talk more; all we know is MONEY. Hurry up! Tik Tak, Tik Tak, Tik Tak!”

The authorities stated the attack taken the Baltimore city government hostage. The city government can’t access email accounts, parking fines database, process payments to employees and the citizens remain unable to make utility payments, property taxes, and vehicle citations.

 

New Magecart attack affects 17,000 sites

Data leak

A hacker group named Magecart, a website and card skimming group, is being held responsible for the recent data breach that impacted several websites by injecting malicious code.

According to a report from threat intelligence firm RiskIQ, the hackers used a “spray-and-pray” approach to compromise and plant malicious code on over 17,000 domains since April 2019. RiskIQ stated the attackers have been active in web skimming for a long time and started compromising unsecured S3 buckets in early April.

By compromising a few sites, the malicious code spread to thousands of other sites, including Picreel, Alpaca Forms, AppLixir, RYVIU, OmniKick, eGain, and AdMaxim.

“The actors behind these compromises have automated the process of compromising websites with skimmers by actively scanning for misconfigured Amazon S3 buckets. These buckets are un-secure because they are misconfigured, which allows anyone with an Amazon Web Services account to read or write content to them,” RiskIQ said in a statement.

“RiskIQ has been monitoring the compromise of S3 buckets since the beginning of the campaign, which started in early April 2019. We’ve been working with Amazon and affected parties to address Magecart injections and misconfigured S3 buckets as we observe them,” the statement added.

Earlier, the hacker group is responsible for the data breach that impacted 201 online campus stores in the United States and Canada. According to the cybersecurity firm Trend Micro, the attackers allegedly used a skimming script, a malicious code, designed to steal the data from 201 online stores that were catering to 176 colleges and universities in the U.S. and 21 in Canada.

The security researchers at Trend Micro stated that they detected the attack, dubbed as Magecart attack, against multiple campus online store websites on April 14, 2019, which were injected with a malicious skimming at their payment checkout pages. The hackers use skimming script to compromise the card information and personal details entered on the payment page by users. Trend Micro stated the attackers also compromised PrismWeb, an e-commerce platform designed for college stores by PrismRBS.