Home Blog Page 309

Smartphone’s microphone used for launching Acoustic side-channel attack: Researchers

Ultrasonic Waves Used to Launch Surfing Attacks on Smartphones

With technology advancing day by day, the cyber-attackers too are finding innovative ways to get into our devices.  Researchers have discovered that hackers can use the microphone on the smartphone to steal the phone password and gain access to the device’s data.

Academic researchers from England and Sweden designed a malware that can exploit the smartphone’s microphone to steal the device’s passwords and codes. In their report, Hearing your touch: A new acoustic side-channel on smartphones, the researchers claimed that they’ve found the first Acoustic side-channel attack that presents what users type on their touch-screen devices.

The malware is created to figure out the PIN code and password to your phone or tablet by simply hearing your keystrokes, according to the researchers.

“We found the device’s microphone(s) can recover this wave and ‘hear’ the finger’s touch, and the wave’s distortions are characteristic of the tap’s location on the screen,” the researchers said in the report. The researchers performed the attack trail by monitoring 45 participants with Android smartphones are were able to recover 61% of 200 PINs on the devices within 20 tries.

Many of the recent surveys discovered the unknown vulnerabilities in the smart devices that we use often. Recently, a security researcher revealed that hackers can exploit smart home appliances like coffee machines and TVs to steal people’s sensitive information. According to Vince Steckler, Chief Executive at security firm Avast, the Internet-connected devices used in the home, like laptops, mobile phones, and other smart gadgets, aren’t secure as they allow hackers to use them to get hold of bank details and other personal information.

Steckler stated that cybercriminals can make use of potential vulnerabilities in the Internet of Things (IoT) devices and compromise them to steal their owner’s sensitive details.

“Coffee machines are not designed for security. TVs are not designed for security. What they are is additional vectors to get into your network. And you can’t protect them,” Steckler said in a media statement.

Also, a cybersecurity expert Yossi Atias took the stage at Mobile World Congress to demonstrate a live hack of the Amazon Ring video doorbell, exposing a previously unknown vulnerability in the popular IoT device. The hack revealed unencrypted transmission of audio and/or video footage to the Ring application allows for arbitrary surveillance and injection of counterfeit video traffic, effectively compromising home security and putting family members’ safety at risk.

Earlier in 2018, a research from cybersecurity solutions provider Check Point revealed how organizations and individuals are vulnerable to hacking through their fax machines. The researchers at Check Point stated that fax machines have security vulnerabilities which could possibly allow a hacker to steal data through a company’s network using just a phone line and a fax number. The researchers also showed how they were able to exploit security flaws in a Hewlett Packard all-in-one printer. The findings were presented by Check Point’s researchers Yaniv Balmas and Eyal Itkin at DEFCON 26.

Acuris Risk Intelligence partners with SILO Compliance to boost AML Investigations

Partnership

Acuris Risk Intelligence, a provider of data intelligence and cybersecurity professionals, recently announced its partnership with diligence management solutions provider SILO Compliance System to enhance Anti-Money Laundering (AML) efforts.

Based in the Cayman Islands, SILO Compliance is a comprehensive and risk-based diligence management solutions platform, providing its services to corporate service providers, law and accounting firms, and other financial organizations services providers that observe AML regulations.

Established in 2004 as C6, Acuris Risk Intelligence has now become as one of the top suppliers of proprietary data on PEPs, sanctions, and AML data for due diligence and compliance. It’s a trusted and independent provider of data intelligence for anti-money laundering, anti-corruption, and cybersecurity professionals.

The company claims that it combines a world-class dataset, that includes fraud and cybersecurity content, with expert human analysts and state-of-the-art technology to help organizations manage the risk in business relationships effectively. The latest alliance enables SILO’s customers to access a dataset that includes fraud and cybersecurity content as well as expert human analysts to help manage risk in business relationships.

Speaking on the new partnership deal Joel Lange, the Managing Director at Acuris Risk Intelligence said, “We’re delighted to join forces with an industry-leading provider such as SILO Compliance. Our integration into SILO Compliance System will further streamline its already efficient system.”

“SILO is pleased to have the Acuris Partnership.” Kimberly Smith, co-founder of SILO Compliance System, advises. “Pulling our experiences and technologies has already proven to be of value to our customers. The integration of Acuris into the SILO platform further serves our customer’s needs for more automation and streamlining of their compliance processes.”

Recently, Acuris Risk Intelligence announced its partnership with technology company Quantifind in order to boost anti-money laundering (AML) investigations. The new collaboration allows Quantifind’s clients to have access to a high-quality data source, KYC6, Acuris Risk Intelligence’s online portal, which integrates into Quantifind’s AI platform. It also enables Quantifind to provide compliance teams with key capabilities of individuals via search, on-going monitoring, sanctions, and Enhanced Due Diligence (EDD) report.

IoT Security: Needed now more than ever

Number of IoT Devices Expected to Reach 24.1 Bn in 2030: Report

Contributed by Anoop, Grand View Research

Over time, technological advancements have created tools and resources that have enabled users to get all useful information at their fingertips. One such technology is IoT, which connects everything to the Internet. It has not only helped in improving the connected lifestyle, by delivering several benefits to individuals, but also created new business values for organizations. The application of IoT in several verticals has enabled users to interconnect everything, from sprinkler systems to refrigerators. However, drawbacks such as the possibility of creating new attack vectors for hackers have led to growing concerns among users. IoT devices are expected to gain more popularity than smartphones in future. These devices would have the ability to collect and share data which could potentially be misused for personal gains. Moreover, IoT devices would have access to private data such as banking information and social security number. In light of the importance of what these devices have access to, it is crucial to understand their security risk across the network, cloud, and application areas.

According to IoT Security Market study by Grand View Research, the security type segment was valued at USD 1,242.3 million in 2017 and is expected to reach USD 9,881.2 million by 2025.

IoT involves four significant steps — capturing data using sensors, processing the captured data, connecting the data to the network, and making use of the information to improve the productivity of smart applications. Allowing devices to connect to the Internet makes them prone to serious vulnerabilities if not adequately protected.

IoT security is a technology area that focuses on protecting networks and connected devices in the Internet of things. These devices are the number one target for cyberattacks, surpassing application & web servers, databases, and email servers. Security is an essential factor to consider for operating IoT devices or systems, particularly for the industrial Internet. An additional aspect that has triggered the growth of IoT is the concept of Industry 4.0. It is described as the latest revolution in manufacturing, powered by IoT technology and smart factories.

The growing demand for enhanced privacy is driving the growth of IoT security market. Increasing government efforts are being made to implement stringent regulations for limiting the volume of data being collected by IoT devices in industries such as retail, BFSI, and healthcare. This is a prominent factor that is expected to boost the market growth. Additionally, configuring the necessary/next-generation security features, increasing transparency, and providing consumers with a choice to opt-out of data collection option are some key factors that are likely to drive the market growth in the next five years.

Common attacks in the IoT ecosystem include steal key certification, fake firmware, and data breaches. Besides, IoT is a growing market and many product designers and manufacturers are more interested in getting their products to the market quickly. As a result, security is of least importance during the design phase of a product.

IoT network security is more challenging as compared to the traditional network security as it involves a broader range of standards, communication protocols, and device capabilities, thereby increasing complexity.

The IoT security market is characterized by the presence of major dominant players such as Cisco Systems Inc., IBM, Symantec Corporation, Gemalto NV, and McAfee, LLC. Companies are focusing on enhancing their product portfolios to stay ahead in this competitive market.

Drivers

High number of ransomware attacks on IoT devices

The rise in the adoption of IoT has increased the potential of cyberattacks. Cybercriminals seek to exploit susceptibilities in smart devices manufactured with poor security practices. It is estimated that over 30 million IoT attacks were done in 2018, an increase of 200% than that recorded in 2017.

By the end of 2025, approximately 30 billion devices are expected to be connected to the Internet. This has led to the growing need for avoiding ransomware attacks and reinforcing security. Additionally, the increasing adoption of cloud-based technologies by a large number of organizations for storing confidential data has given rise to the risk of unauthorized data access. Moreover, the growing trend of Bring Your Own Device (BYOD) has led to increased concerns regarding the security of data among enterprises and organizations. This, in turn, has unfolded numerous opportunities for security providers to offer effective security solutions, such as device and data security, implementation of security operations at IoT scale, and meeting compliance requirements along with performance requirements.

Growing number of IoT security regulations

The growing popularity of 3G and 4G networks and wireless technologies has led to an increasing number of cyberattacks. In order to address this, governments across the globe is focusing on implementing stringent regulations regarding data security and privacy. Advancements in technology have led manufacturers to connect consumer goods, right from toys to lights and other major appliances, to the Internet. This indicates that there is a wide range of exposure to potential vulnerabilities with multiple attack surfaces, making it easier for hackers to gain control. Thus, implementation of IoT security regulations to safeguard data is anticipated to enhance the use of IoT enabled devices.

Various regulations have been introduced to strengthen the security of IoT devices and avoid misuse of data. For instance, in September 2018, California was the first state to pass a law addressing the security of connected devices. The law, which is likely to come into effect by 2020, has mandated manufacturers to equip their internet-connected devices with sound security features. Moreover, the Federal government has introduced the IoT Cybersecurity Improvement Act of 2019 to encourage cybersecurity practices for IoT devices. The act would also help in preventing the use of any default passwords for IoT devices sold to the U.S. government. Moreover, it would offer a mechanism to patch the devices and not have any known vulnerabilities.

The opinions expressed in this article are the personal opinions of the author. The facts and opinions appearing in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

DDoS-for-hire websites make a comeback despite FBI crackdown: Nexusguard report

DDoS attacks “for hire” made a comeback in the beginning of the year, with booter-originated attacks rebounding to more than double their amounts in Q4 2018, according to Nexusguard’s “Q1 2019 Threat Report.” Despite the earlier FBI crackdown, the DNS amplification types of DDoS attacks continued to be a favorite of DDoS-for-hire websites, soaring more than 40 times their volume compared to last quarter. The resurgence of DDoS-as-a-service and the growing botnets reinforce the evolving cyber threat of DDoS attacks for enterprises and communications service providers (CSPs).

The quarterly report, which measures thousands of DDoS attacks around the world, revealed DNS amplification attacks were also the most frequently employed against CSPs and telcos in Brazil this quarter. One of the largest banks in South America bore the brunt of these Brazilian DNS amplification attacks—more than 17 percent of all attacks. “Bit and piece” types of attacks, or DDoS attacks that were smaller than one Gbps in size, continued to cause issues in the beginning of 2019 by becoming more automated and targeted, bypassing detection. Nexusguard researchers warn that CSPs will need to approach these evolved attacks with scalable, cloud-based DDoS detection and mitigation in order to reduce potential damages. CSPs that fall victim to bit-and-piece attacks and unknowingly pass on malicious traffic will risk undermining customer confidence.

“Due to the increasing demand for DDoS attack services and the boom in connected devices, hackers for hire have doubled and DDoS campaigns are not going away for organizations,” said Juniman Kasman, chief technology officer for Nexusguard. “Businesses will need to ensure their attack protections can seamlessly evolve with new vectors and tactics that attackers seek out, which ensures service uptime, avoids legal or reputational damages, and preserves customer satisfaction.”

Nexusguard findings confirm the continued shift to leveraging mobile devices in attacks, which has created a new breed of botnets that caused the maximum attack durations to spike to more than 40,000 minutes at a time, or more than 27 days. People who experience sluggish performance, surges in data usage or noticeable decrease in smartphone battery life may be seeing warning signs of malware. Smartphone users should keep devices up to date with the latest patches, uninstall suspicious apps and run anti-virus software as a few ways to stay safe from malware.

Nexusguard’s quarterly DDoS threat research gathers attack data from botnet scanning, honeypots, CSPs and traffic moving between attackers and their targets to help companies identify vulnerabilities and stay informed about global cyber security trends.

US Air Force strikes on Iranian Military computer systems

US-Iran

The Military cyber forces of the United States launched a cyber-attack against Iranian Military computer systems in response to Iran’s shootdown of $240 million worth U.S. surveillance drone. The attack was performed with the approval from the President Donald Trump.

The attack was targeted on the Iranian military computers that used to control the entire Iran missile operations. According to the Islamic Revolutionary Guard Corps, the drone was taken down when it entered Iran’s airspace near the Kouhmobarak district in the south of Hormuz.

“The downing of the American drone was a clear message to America … our borders are Iran’s red line and we will react strongly against any aggression … Iran is not seeking war with any country, but we are fully prepared to defend Iran,” the Revolutionary Guard commander, Hossein Salami, said in a media statement.

However, the U.S. Air Force denied Iran’s argument. “This was an unprovoked attack on a U.S. surveillance asset that had not violated Iranian airspace at any time during its mission,” said General Joseph Guastella. “This attack is an attempt to disrupt our ability to monitor the area following recent threats to international shipping and the free flow of commerce. The aircraft was over the Strait of Hormuz and fell into international waters.”

Recently, the cybersecurity research firm FireEye claimed that an undetected hackers’ group from Iran is allegedly stealing travel and mobile data of individuals in the Middle East region. According to FireEye, the Iranian group dubbed APT39 has targeted a number of people in the Middle East, especially in the Gulf region. It’s believed that the espionage group is allegedly providing information to the Iranian government. The researchers at FireEye stated that they had been tracking APT39 activities since 2014 to protect organizations from cyber incidents.

The researchers said the group uses phishing emails that target specific people and include malicious attachments or links resulting in a POWBAT infection. FireEye also observed that the group uses Persian language words in encrypting data. APT39’s activities are reportedly focussed on the telecommunications sector, the travel, and IT industry, and allegedly represent Iran’s potential global operational reach and how it collects key data.

Critical vulnerability in Outlook for Android affects more than 100 million users

Outlook

The technology giant Microsoft recently discovered a security vulnerability that exists in its Outlook for Android app. In its security advisory, Microsoft stated that the older versions prior to 3.0.88 of Outlook for Android carries a spoofing vulnerability that allows attackers to perform cross-site scripting (XSS) on mobile devices.

The security flaw, named as CVE-2019-1105, could be exploited by attackers by sending a specially crafted email message to the victims. Once compromised, the attackers can perform XSS attacks and run malicious scripts.

“A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email messages. An authenticated attacker could exploit the vulnerability by sending a specially crafted email message to a victim.” Microsoft said in its security advisory.

“The attacker who successfully exploited this vulnerability could then perform cross-site scripting attacks on the affected systems and run scripts in the security context of the current user. The security update addresses the vulnerability by correcting how Outlook for Android parses specially crafted email messages,” the statement added.

Microsoft stated the flaw was reported by multiple security researchers, including Bryan Appleby from F5 Networks, Sander Vanrapenbusch, Tom Wyckhuys, Eliraz Duek from CyberArk, and Gaurav Kumar. The company also clarified that it has mitigated the flaw and notified the users to update the Outlook applications on their devices.

Recently, Microsoft issued an alert to several users of over its mail platform Outlook hack. In a wordy notification, it stated hackers may have accessed data sent by several users on the platform between January 01, 2019, and March 28, 2019.

“Upon awareness of this issue, Microsoft immediately disabled the compromised credentials, prohibiting their use for any further unauthorized access. Our data indicate that account-related information (but not the content of any e-mails) could have been viewed, but Microsoft has no indication why that information was viewed or how it may have been used. As a result, you may receive phishing emails or other spam mails. You should be careful when receiving any e-mails from any misleading domain name, any e-mail that requests personal information or payment or any unsolicited request from an untrusted source,” it said in a statement.

According to Microsoft, apart from the contents of the emails which includes attachments, hackers may have also accessed email addresses, folder names, subject lines from both senders and recipients.

It is still unclear what the hackers target and why they launched an attack like this. “We addressed this scheme, which affected a limited subset of consumer accounts, by disabling the compromised credentials and blocking the perpetrators’ access,” the report quoted a Microsoft spokesperson as saying.

 

Hackers use Firefox ‘Zero-day’ bug to attack against Coinbase employees

Mozilla-Firefox

Web browser developer Mozilla announced that it has patched its Firefox browser’s vulnerability in response to a spear-phishing campaign targeting employees of cryptocurrency exchange Coinbase. The company has released the latest version of the Firefox browser and urged the users to update their browsers.

The Coinbase security team and a security researcher Samuel D. Gross from Google discovered a “Zero-day” vulnerability in the Mozilla Firefox browser, which can be used to launch a cyber-attack using JavaScript objects, ZDNet reported.

“The bug can be exploited for RCE [remote code execution] but would then need a separate sandbox escape in order to run code on an underlying operating system. However, most likely it can also be exploited for UXSS [universal cross-site scripting] which might be enough depending on the attacker’s goals,” Gross said in a statement.

The hackers have attempted to phish Coinbase staff with emails containing links to malicious websites. The malware can automatically download, if the links were clicked using Firefox browser, and run malware on the system, stealing browser passwords and other sensitive information, according to Coinbase.

“On Monday, Coinbase detected & blocked an attempt by an attacker to leverage the reported zero-day, along with a separate zero-day Firefox sandbox escape, to target Coinbase employees,” said Philip Martin, a member of the Coinbase security team, which reported the attacks to Mozilla.

“We walked back the entire attack, recovered and reported the 0-day to Firefox, pulled apart the malware and [infrastructure] used in the attack, and are working with various organizations to continue burning down [the] attacker’s infrastructure and digging into the attacker involved,” Martin added.

Recently, the cryptocurrency exchange Bithumb once again made it to the headlines after discovering a cyber-attack. This is the third such incident for the South Korean exchange platform in the past three years.

In an official statement, Bithumb stated that on March 29, 2019, at around 10:15 pm the company detected abnormal withdrawals of its cryptocurrencies from its hot wallets. It’s believed that attackers possibly made off around three million EOS (worth $13.4 million) and 20 million Ripple coins (XRP) of worth $6 million.

Bithumb stated that it secured all the cryptocurrency during the detection time and confirmed that the customers’ assets are safe under the protection of a cold wallet. Describing the incident as an “accident involving insiders”, Bithumb said “we are conducting intensive investigations with KISA, Cyber Police Agency and security companies. At the same time, we are working with major exchanges and foundations and expect to recover the loss of the cryptocurrency equivalent.”

This is a third cyber-attack the company revealed in the past three years. The first hack happened in July 2017, when hackers stole $7 million in Bitcoin and Ethereum, while the second incident took place in June 2018, when hackers stole hackers stole 35 billion won ($31 million). Bithumb released a list of 11 cryptocurrencies lost during the hack as well as the corresponding amounts.

 

Cloud data management startup Druva raises $130 million, Joins the Unicorn Club

Druva, a cloud data management and protection services provider, recently raised $130 million in a funding round led by Viking Global Investors along with the participation from Riverwood Capital, Tenaya Capital, Nexus Venture Partners, and Atreides Management. The California-based company is now passed the $1 billion valuation and acquired the unicorn status.

Druva stated the new investment will be used for business expansion globally and accelerate the innovation of its data protection technology built for the cloud. Founded in 2008, Druva delivers Data Protection and Management services to companies. Druva’s Cloud Platform, which is built on Amazon Web Services (AWS), offers covering backup, recovery, archives, and analytics services.

“The line between data and business is blurring. The data management market is forecasted to be worth $55 billion next year, yet the landscape is dominated by solutions that are 20 years old. Druva is disrupting the way enterprises protect and leverage their data with a modern, cloud-native SaaS platform,” said Jaspreet Singh, Founder and CEO, Druva. “Today’s funding will help Druva to power data protection for the cloud era and accelerate our momentum to better serve the needs of enterprise customers.”

“Druva’s product capabilities and market adoption have continued to surprise us ever since. We remain excited about Druva’s cloud-native architecture for enterprise data protection at scale and believe it will be a category-defining company for data protection in the cloud era,” Jaspreet Singh added.

“Druva is a leading Advanced Technology Partner in the AWS Partner Network,” said Mike Clayville, Vice President Worldwide Commercial Sales, and Business Development, Amazon Web Services. “Druva’s solutions powered by AWS are changing the way data is managed and protected at thousands of companies globally. We’d like to congratulate Druva on its latest fundraise and look forward to innovating with Druva to create new solutions that benefit our customers.”

NASA hacked! Attackers used basic Raspberry Pi computer for breach

NASA

The National Aeronautics and Space Administration (NASA) of the United States recently confirmed that it has been hacked in April 2018. According to an audit document from the U.S. Office of the Inspector General published by NASA, the hackers allegedly connected to its Jet Propulsion Laboratory (JPL) servers and moved laterally further into the NASA network, Forbes reported.

NASA stated the hackers have used a basic, build-it-yourself computer to attack two of the Jet Propulsion Laboratory’s main networks and steal around 500 megabytes of data from 23 files. The information in the files included International Traffic in Arms Regulations information related to the Mars Science Laboratory mission, which includes the Curiosity rover, along with other valuable information.

After NASA revealing the security incident, the Johnson Space Center in Houston disconnected its system from JPL’s exploited gateway because of fears of hacking. The audit report stated that, “Johnson officials were concerned the cyber attackers could move laterally from the gateway into their mission systems, potentially gaining access and initiating malicious signals to human space flight missions that use those systems. Johnson had not restored its use of all communications data because of continuing concerns about its reliability.”

Last year, NASA reported a major cyber-attack. In a statement sent to its employees, NASA stated that an unknown intruder illegally gained access to one of its servers that stores current and former employees’ Personally Identifiable Information (PII), including the social security numbers.

NASA stated the hack occurred on October 23, 2018, and it didn’t have the information on the exact number of employees who were affected. However, NASA said its Civil Service employees who were on-boarded or transferred to other centers from July 2006, to October 2018, may have been affected.

“NASA cybersecurity personnel began investigating a possible compromise of NASA servers where personally identifiable information (PII) was stored. After initial analysis, NASA determined that information from one of the servers containing Social Security numbers and other PII data of current and former NASA employees may have been compromised,” NASA said in a statement.

NASA confirmed that its cybersecurity officials took immediate actions to secure the data servers and it’s working with federal cybersecurity partners to determine the potential data exfiltration and identify the affected employees. The agency is notifying all the employees and suggesting precautionary measures to counter against the possible fraud.

 

Ransomware hit Florida city agrees to pay $600,000

Hive Ransomware

Riviera Beach, a city in Florida, has recently decided to pay $600,000 in bitcoin as a ransom to hackers behind a ransomware attack that locked down the local government’s data.

The hackers took down the city email network, seized its computer systems, and forced Riviera Beach officials to pay employees and contractors by check instead of direct deposit, the Associated Press reported.

According to the official statement, the attack occurred on May 29, 2019, when a police department employee opened an email that contained malicious code. The malware quickly spread to Riviera Beach’s government IT systems and took them all offline.

“The Riviera Beach City Council voted unanimously this week to pay the hackers’ demands, believing the Palm Beach suburb had no choice if it wanted to retrieve its records, which the hackers encrypted. The council already voted to spend almost $1 million on new computers and hardware after hackers captured the city’s system three weeks ago,” the officials said in a statement.

Several governments and businesses have been hit in the United States and in other countries in recent years. On May 7, 2019, several of the Baltimore city services were halted after a ransomware attack hit city computers. The hackers infected about 10,000 of Baltimore city government’s computers with ransomware called RobbinHood. The attackers asked the city officials pay 13 bitcoins (about $100,000) to release the city’s systems, warning that price would go up every day after four days, and after the tenth day, the affected files would be lost permanently.

“We’ve been watching you for days and we’ve worked on your systems to gain full access to your company and bypass all of your protections,” the ransom note read.  “We won’t talk more; all we know is MONEY. Hurry up! Tik Tak, Tik Tak, Tik Tak!”

The authorities stated the attack taken the Baltimore city government hostage. The city government can’t access email accounts, parking fines database, process payments to employees and the citizens remain unable to make utility payments, property taxes, and vehicle citations.

Later, the hackers leaked government documents on Twitter. It’s believed that an unknown Twitter account, which is claimed to be owned by the hacker group, has been used to leak the sensitive documents, the Baltimore Sun reported.

The officials of Baltimore and federal authorities stated that they’re investigating the documents posted by the attackers. One of the documents that hackers leaked included a detailed assessment of a woman’s medical history, the officials said. The authorities also clarified that there’s no evidence that any personal data misused in the incident.