Home Blog Page 322

Security bug allows hacker to break into GPS tracking apps

GPS hacking

A security flaw in GPS tracking applications allowed remote hackers to hijack the car and kill the engine. According to Motherboard, a hacker named L&M allegedly broke into thousands of accounts belonging to users of GPS tracker apps iTrack and ProTrack. The hacker claimed that he’s able to track vehicles in several countries, including South Africa, Morocco, India, and the Philippines.

The flaw gave the hacker access to monitor the locations of tens of thousands of vehicles and even turn off the engines while they were in motion. The hacker stated that he compromised more than 7,000 iTrack accounts and more than 20,000 ProTrack accounts which were used to monitor and manage navigations of the vehicles through GPS tracking devices. The compromised information included, name, the model of the GPS tracking devices, IMEI numbers, usernames, real names, phone numbers, email addresses, and physical addresses.

Protrack is a web-based GPS tracking software which provides live tracking service to the vehicle owners. And, iTrack is a mobile application that provides GPS Tracking Security Systems, GPS Security System India, vehicle tracking system, vehicle protection, and fleet management system.

A couple of months back, an unsecured Elasticsearch database exposed the real-time location data for over 11,000 Indian buses online over three weeks. ElasticSearch, an enterprise search engine, provides technology solutions for powering search functions. According to Justin Paine, the security researcher who discovered the breach, the unprotected server was left visible online without a password exposing real-time GPS and bus route information from 27 Indian transportation agencies via an ElasticSearch server.

The server exposed the data of 26 road transport agencies including Kochi Metro Rail Limited. The exposed information included the details like bus license plates, start-stop stations, route names, GPS coordinates, and details of commuters like usernames and emails.

Paine said he discovered the server using search engines for connected devices on December 5, 2018, and after reaching the Indian Computer Emergency Response (ICERT) team the server was secured on December 22, 2018.

 

Docker Hub Database hack exposes 190,000 users’ data

106 million Thailand visitors

Docker, a provider of cloud-based services to programmers and developers, recently announced that hackers had accessed one of its Docker Hub databases and stolen sensitive data from around 190,000 user accounts. Docker hub is the official cloud repository for Docker container images that allows users to create a test, store, and distribute container images.

Docker offers developers to run software packages known as Containers. The company claims that its software tools and cloud-based services are used by some of the largest tech companies and thousands of developers across the world.

The company notified its customers via emails. “On Thursday, April 25, 2019, we discovered unauthorized access to a single Hub database storing a subset of non-financial user data. Upon discovery, we acted quickly to intervene and secure the site,” the company said in a statement.

The company stated that hackers gained unauthorized access to the Docker hub database and allegedly acquired access keys and tokens that could have potentially given access to private code repositories. The stolen data includes usernames, hashed passwords, Github, and Bitbucket tokens for Docker auto-builds, according to Docker. The company stated that it’s unclear what information was accessed, and which companies’ accounts were affected.

The security officials clarified the customers that only non-financial user data is affected. It also recommended the users to change their passwords and to check with security logs for any unauthorized access.

“We are enhancing our overall security processes and reviewing our policies. Additional monitoring tools are now in place. Our investigation is still ongoing, and we will share more information as it becomes available,” the statement added.

 

4 things CISOs get wrong about AppSec

Application Security

By Lee Carsten

Application security has matured quite a bit since the early days of OWASP.  The pace of software development is growing exponentially, and the industry is doing all we can to keep up.  Here are some of the areas I have seen that can get you into trouble if you aren’t paying close attention.

1. Lack of visibility into what you own

Apple Notarization

Coverage is a key component of any Application Security program.  It is typical for a modern enterprise to have 2-4 times as many applications as the security team is tracking.  This condition is caused by many issues.  Shadow IT, adoption of cloud technologies and Software as a Service platforms, legacy systems that have never been tracked, and the list goes on.  One of the first places that good pen testers (and many attackers) start is with open-source intelligence (OSINT), including deep web/dark web research.  It’s not just credentials and passwords, but systems that are targeted.  If a tester can get into a system you aren’t even tracking, there is a good chance they can gain undetected entry and pivot into more desirable targets.  This problem is real enough that Jeremiah Grossman and Robert Hansen, two of the luminaries in the AppSec space, left what they were doing and launched a startup to help companies combat this issue.

2. Over reliance on tools and automation

Tools and Automation

One of the trends in the industry right now is to automate all security testing.  DevOps has pushed security teams to invent new models to keep up with constant change.  These models eliminate much of the human inspection that was historically worked into waterfall and agile development sprints.  The problem is that the models aren’t just being used on the CI/CD workflows, but full automation is being applied all over the place.  What you end up with is a bunch of false negatives, because nobody is looking at the code that is being shipped out the door.  Regular manual review of application snapshots is essential to make sure a business logic flaw hasn’t exposed a vulnerability that you can’t accept.

3. Bad metrics

Quantifying security risk is something that the industry continues to struggle with.  We use heat maps and high/medium/low scorecards to discuss known vulnerabilities and make decisions about which ones to fix vs which ones to write off.  The biggest problem this has created for security leaders is that this isn’t how the rest of the business deals with risk.  When talking with peers in their organization, CISO’s need a common language and criteria to measure the impact of what could happen.  Find out how the other groups look at risk, and align what you are presenting to leadership with that.  Start measuring what you are doing.  Small data first, and grow from there.  Quantitative analysts don’t say things like there is a medium likelihood of being hit by a hurricane this season.  They say things like “there is a 2% chance of sustaining a $10M property loss across our facilities in Southeast Texas between July and November of this year”.  Find someone who can help you quantify your program and it will change how you are perceived in your company.  Rich Seiersen and Doug Hubbard wrote a great book on this subject titled How to Measure Anything in Cybersecurity Risk that is worth checking out.

4. Not incorporating application security into your incident response strategy

Experian API Flaw

Unlike an attack against your network, your applications have a much higher likelihood of involving different vendors, contractors, cloud providers, and people who long ago worked at your company that aren’t listed anywhere in your IR Playbook.  You need to know who wrote the application, what kind of documentation exists, who supports the application, what kind of logs are being kept (and persist), what cloud vendors or outsourced third parties are part of the picture, and how the contracts are written so you know what kind of response you can expect.  It is important to plan and practice how you will respond if hit by an attack against one of your applications.  Traditional IR planning practices apply, but make sure you include the elements that you will need to lean on, if (and when) things go south.  Get a $0 IR Retainer in place with a firm that has experience not just in networks, but has an application security team as well.   Perform a tabletop exercise using an attack against a critical application as part of the scenario.

The opinions expressed within this article are the personal opinions of the author. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. 

Lime scooters hacked to yell profane messages to riders

Cyber-attacks often never stoop to a derogatory level, we mean, there would be a crime, but criminals often show some sort of dignity. Now, that might be a thing of the past. Lime Scooters was hacked only with the intention of belting out disturbingly offensive messages including several racist and sexual in nature to the riders. According to reports, the attack affected eight scooters in Brisbane, where the hacker(s) penetrated the scooter’s audio files.

‘Okay, if you’re going to ride my a** then please pull my hair, okay?,’ says one scooter in a goofy Australian-sounding accent, while another goes with ‘Don’t take me around, because I don’t like to be ridden.’

The company did not find the profanity spewed across as a funny one. “We are aware that a few Lime scooters in Brisbane have had their audio files changed by vandals recording over the existing audio file with inappropriate and offensive speech,” the company said in a statement. “It’s not smart, it’s not funny and is akin to changing a ringtone.”

“It’s disappointing that someone has taken this opportunity to poke fun at members of the community in a hurtful way that is so far removed from the values we hold as a company,” the statement added.

The incident has once again brought cybersecurity issues among connected vehicles to the forefront. Earlier this year, it was reported that cars, including the most popular models in the United Kingdom from Ford, Nissan, and Volkswagen, can be easily stolen/hacked by attackers using wireless transmitters. The report revealed that more than 30 car manufacturers, including Audi, BMW, Honda, Hyundai, Kia, Peugeot, Renault, Skoda, and Volvo, made cars that are not secured. The German General Automobile Club (ADAC) stated that it tested 237 keyless model cars and found that 230 of them can be unlocked and started in just 18 seconds using a Relay Attack.

 

Don’t let your gamers grow up to be hackers

Nickel, Hackers, Twitch source code

Contributed by SecureWorld

Gaming is not a crime.

But can it lead to one?

New research says yes, and that young gamers are increasingly turning into hackers who commit cybercrime.

The research found that 82% of teens and young adults recruited by online criminals had developed their cybercrime skills through video gaming.

The UK’s National Crime Agency (NCA) held a forum and published a special report about the problem. The agency report looks at ways to identify those at risk of hacking, how to intervene before they go too far, and then inspire them to pursue a career in IT security.

Progression: how gamers become hackers

To paint a picture of a gamer’s potential progression into cybercrime, the NCA created this pyramid:

Gamers and Hacker

In other words, gamers aren’t learning to hack at first, they are hacking to learn.

It’s often innocent at the start, as they become more interested in coding, then in modifications of computer games.

And then they progress through hacking forum membership, gaining notoriety as they develop their skills.

Next, they become identified and groomed by professional hackers and cybercriminals as they move toward the top of the pyramid.

Then the cycle repeats itself with those coming up from below.

What makes hacking attractive to young people?

The UK crime fighting agency asked why this progression from innocent gamer to criminal hacker seems to be attractive. It heard comments about a sense of belonging, accomplishment, and common purpose.

“You are with people who are like-minded. The computer removes race, creed, sexuality. You’re with people you can relate to.”

“Hacking is a very creative art. You get addicted to it because by going up the ranks you get more points. People want to know you because you’re higher up the food chain. These communities are structured around reputation and getting to the next level.”

“You only ask for part of the puzzle. You smell that it’s illegal but you just ignore it. You don’t really see what’s wrong with knocking out some code.”

And just like that, young gamers find themselves accepted, approved, and addicted to conquering the next level.

Like a video game.

Psychological profile of gamers most at risk of becoming hackers

The UK’s National Crime Agency, as part of its effort to uncover who needs intervention to break the gaming-hacking cycle, developed this psychological profile of those most at risk:

“These young people are often academically gifted, certainly in terms of achievement in technology and related subjects. In some cases, they appear to have started to investigate the intellectual challenges coding and hacking present at least in part because they are not adequately challenged by school or university technology subject syllabuses.

Some have been diagnosed with forms of autism or with Asperger’s Syndrome.

They are likely to have a deep interest in technology, often first sparked by an enthusiasm for gaming; and are likely to spend a large and increasing proportion of their lives online.

In some cases when these individuals have been contacted via a home visit, parents and carers are frequently amazed to discover they have been engaging in illegal activity, because they spend so much time in their bedrooms.”

Breaking the gaming-hacking cycle

The NCA’s Prevent Campaign targets young people in several ways, and could be a model for other law enforcement around the world.

  • Letters or home visits to those whose information is found on hacker forums;
  • Publicity campaigns targeting gamers to explain clearly to them what is illegal online, while raising awareness within this group of the potential consequences of cybercrime for victims and for perpetrators;
  • Highlighting the benefits of a career in the technical security industry or the wider IT industry that could lie ahead for talented individuals who use their technical abilities for legitimate purposes;
  •  Encouraging them to participate in legitimate competitive activities that could offer them prestige and reward, and in other events such as cyber camps or university or industry mentoring programs
If we don’t intervene, cybercrime talent will increase

You can read the NCA report, “Identify, Intervene, Inspire: Helping young people to pursue careers in cyber security, not cyber crime,” for yourself.

Its ideas are thought provoking and fit in with our SecureWorld mission of “Connecting, informing, and developing leaders in cybersecurity.”

We encourage you to share these ideas with your peers, because as the report concludes, there is a lot on the line, for all of us.

“In a world where young people are—rightly—being encouraged to learn more about coding and about technology in general, the opportunities for a greater number of talented individuals to be tempted into criminal activity will surely continue to increase.”

This article was originally published here.

The opinions expressed within this article are the personal opinions of the author. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. 

Speedcast announces partnership with Nelco

Abnormal Security Partners with Microsoft to Boost Cybersecurity

Speedcast, a provider of remote communication and IT solutions, has signed a partnership agreement with VSAT service provider Nelco Limited, a subsidiary of Tata Enterprise, to offer seamless global communications while at sea in Indian waters.

The partnership is a first-of-its kind which is aimed at connecting vessels of both the companies to Ku-band networks which will help both the companies to seamlessly communicate in and out of Indian waters. As part of the partnership Nelco will leverage several capabilities of Speedcast including cybersecurity.

“In this partnership with Nelco we are able to open up the Indian market to drive new growth for both Speedcast and Nelco, as well as deliver the best possible customer experience,” said Speedcast CEO Pierre-Jean Beylier. “We are proud to be offering a unique proposition to thousands of vessels sailing in and out of Indian waters every year and we look forward to a long and mutually beneficial relationship between Speedcast and Nelco.”

Speedcast entered cybersecurity solution in late December 2018 with the launch of its new Cybersecurity as a Service solution. Ever since then the company has been on a roll. “”Companies are undergoing digital transformation and implementing automation across all levels of their organizations,” said Tim Bailey, Executive Vice President, Products, Marketing & Business Development, Speedcast at the launch. “Our Cybersecurity as a Service solution provides advanced cybersecurity applications and best-in-class services, enabling our customers to proactively control cyber threats. This solution underscores our focus on extending our product portfolio to deliver applications and services that bring value to our customers.”

Post hack, Japanese cryptocurrency exchange Zaif resumes operations

Cryptocurrency

After seven months of pause, Japanese cryptocurrency exchange Zaif has resumed its operations, starting this week. The reason for the break was the cyber-attack that crippled the company in September 2018. In the attack, Zaif lost nearly $60 million in bitcoin, bitcoin cash, and MonaCoin (MONA) from its hot wallets. Following the attack, Zaif suspended its new registration, as well as trading, depositing and withdrawing MONA for the next one month. It also assured refund to users who lost holdings in the breach.

Post the attack, the company entered into a strategic agreement with Fisco Digital Asset Group. As part of the agreement, Zaif would receive a ¥5 billion ($44.5 million) investment in exchange for a share of ownership. The sale of the exchange was part of the efforts of the company to compensate the users who lost MonaCoin in the hack. Now, the affected users have been repaid entirely in their original cryptocurrency while MONA users have been refunded 40 percent in Japanese yen and 60 percent in crypto.  “The yen conversion rate will be 144.548 yen per MONA. Zaif said, “MONA physical trading is scheduled to resume from April 23, 2019.”

The details of the hackers are still not known but it is reported that Japan Digital Design and several other security firms may have zeroed in on the identity of the hackers.

Earlier this year, Coinmama, a crypto brokerage platform, notified users that it suffered a security breach which affected around 450,000 users’ emails and hashed passwords. The company stated that a few unknown intruders compromised customer data and kept for sale on a dark web registry.

“Today, February 15, 2019 Coinmama was informed of a list of emails and hashed passwords that were posted on a dark web registry. Our Security Team is investigating, and based on the information at hand, we believe the intrusion is limited to about 450,000 email addresses and hashed passwords of users who registered until August 5th, 2017. This comes as part of a larger breach affecting 30 companies and a total of 841 million user records,” Coinmama had said in an official post.

“As of February 15, 2019, there has been no evidence of this data being used by perpetrators. Given the dated nature of the published data, we have no reason to suspect that any other Coinmama systems are compromised. Coinmama does not store credit card information, and do not hold user funds,” Coinmama added.

Brits asked to change their passwords to something stronger

common password of 2021,Password Protection, password spray attacks, Microsoft accounts passwords

The National Cyber Security Centre (NCSC) of UK has issued a warning to British citizens to have stronger and unique passwords after releasing a file containing the top 100,000 passwords from the ‘Have I Been Pwned’ data set. According to the data, the password ‘123456’ was found 23 million times in the breaches.

Among the other commonly hacked passwords globally were “12345”, “123456789”, “qwerty”, “1111111” and even the term “password”. But the buck doesn’t stop there. Bands, celebrities, and even favorite clubs appeared more than a thousand times. Among the bands, popular 90s pop-punk outfit, Blink-182 took the cake. Among the common names that were used, Ashley and Michael topped the list which was followed by Daniel, Jessica and Charlie. In the category of favorite clubs, Liverpool came first with 280,723 uses, followed by Chelsea at 216,677 uses, Arsenal at 179,095 uses, manutd with 59,440 uses, and Everton 46,619 uses.

The surprising entries were the phrase “iloveyou”, and words like “monkey” and “dragon” making an appearance. Several users also used pretty colorful swear words as passwords. The report also noted that even complex passwords like “oreocookie” appeared over 3,000 times.

According to the report, among internet users, only 15 percent agreed to know about basic internet security and how to protect themselves. The NCSC also stressed the possible harm that can arise from re-using passwords across multiple accounts. “Password re-use is a major risk that can be avoided — nobody should protect sensitive data with something that can be guessed, like their first name, local football team or favorite band,” Ian Levy, NCSC Technical Director, said in a statement.

“Using hard-to-guess passwords is a strong first step and we recommend combining three random but memorable words. Be creative and use words memorable to you, so people can’t guess your password,” he added.

Stealthcare signs partnership agreement with Optiv Security

Stealthcare has entered a strategic partnership with Optiv Security. “Our agreement with Optiv marks a pivotal moment for Stealthcare and further validates our technology platform as being a disruptor in the cybersecurity market. This underscores the strength of our unique differentiators, value proposition and market potential of this product,” said Jeremy Samide, CEO of Stealthcare.

Stealthcare is a renowned cybersecurity and threat management company with an arsenal of product lineup including the Zero Day Live (ZDL), a complete cyber threat intelligence and aggregation platform which has always outshined the brightest of its competition. It procures unique threat intelligence (TI) via tradecraft and proprietary machine learning and then automatically integrates its intel directly into the organization’s existing security infrastructure—all without human intervention.

Earlier this month, Optiv Security was it ranked second overall in Canada for accumulative positive brand perception. The company bagged the rank in the 2019 IDC Brand Perceptions of Canadian Security Service Providers report.

The report surveyed Canadian midmarket and large enterprises on general brand perception, current customer perceptions, and prospective customer perceptions. Optiv’s high mark in this report comes on the heels of the company posting its largest year-over-year growth in Canada. In response to the under-served market gap and need for cybersecurity innovation and services, “Due to cloud, mobile and digital transformation, data is created at a volume and velocity never before experienced,” said Julie Talbot-Hubbard, global vice president, digital identity and data services, Optiv. “If organizations can carefully manage who has access to applications and data, then they can accomplish the same objectives as the old perimeter – keeping unauthorized people out of corporate IT assets and ensure only the right people have access to the right data, in the right way, at the right time.”

Optiv was recognized in the report as a Trusted Advisor in the Canadian market, especially to organizations in financial services, manufacturing services, and infrastructure services.

“The fear of external threats and vulnerabilities has guided security initiatives for too long. Our approach – that cybersecurity needs to be managed from the ‘inside-out’ as part of the greater corporate objective – is clearly a welcomed one in Canada,” said Cheryl McGrath, vice president and country general manager for Canada, Optiv. “Our consulting, delivery, and technical leaders meld people, processes, and technologies in long-lasting ways that not only positively impact the company’s security health, but also optimize and rationalize security programs to ensure cost-effectiveness and enable overall program efficacy and resilience.”

DXC Technology launches Security Operations Center in Malaysia

Threat Hunting Report, security breach, data breach, data breach management

BUSINESS WIRE: DXC Technology, a provider of end-to-end IT services, recently inaugurated a DXC Next Generation Security Operations Center (SOC) in Kuala Lumpur, Malaysia.

Serving both regional and global clients, the Malaysia SOC helps strengthen and enhance overall security of enterprises by integrating advanced security analytics across information technology (IT) and operational technology (OT) to provide better visibility, correlation and response to security threats and vulnerabilities. The center is Next Generation as it supports DXC Intelligent Security Operations, providing expertise in advanced analytics, digital forensics, investigations and incident response and tailored solutions to protect the digital enterprise.

As noted in DXC’s “Top 10 Security Trends for 2019” report, enterprises must guard against a wide range of threats, including extortion attacks, hardware vulnerabilities and increased international tension. Additionally, the challenge of recruiting and retaining skilled cybersecurity professionals is making security a top priority for enterprises across the region.

“While digital transformation delivers business value, it can also introduce security risks,” said Mark Hughes, senior vice president and general manager, Security, DXC Technology. “DXC Security’s end-to-end portfolio of advisory services and managed security helps clients draw out a competitive niche by building security into the fabric of applications, infrastructure and culture to help enable large-scale digital change.”

DXC has intensified investments in its Security practice to help clients better manage cybersecurity risks. The DXC Malaysia SOC is integrated with the DXC Managed Security Services global network of more than a dozen SOCs, providing 24/7 cyber threat detection and response services to clients in industries such as financial services, travel and transportation, and media and entertainment.

Multidisciplinary teams of highly skilled security professionals at the Malaysia SOC specialize in services such as identity and access management, data loss prevention, security device management, digital forensics, threat intelligence, threat monitoring and incident response. Additionally, cybersecurity today is merged with big data analytics, where security detection and response capabilities are amplified through machine learning and artificial intelligence.

The team works with clients to define their challenges and develop use cases for their specific needs. The Malaysia SOC’s security accreditations meet local and international laws and regulations.

“In the digital era, technology can sometimes be disruptive. The scope of technology risk management is continuously expanding. A greater focus on a proactive approach to data and client protection, coupled with high-quality incident management solutions, can guide stakeholders in the event of a cyberattack,” said Koushik Radhakrishnan, vice president and general manager, DXC Asia. “DXC is a leader in risk management and cybersecurity globally and has invested in the Malaysia SOC to ensure alignment with the strategic investments for our clients in the region.”

DXC is an industry leader in enterprise security, with global security operation centers across five continents, supporting clients in 70-plus countries and more than 3,500 highly experienced security professionals worldwide. DXC capabilities include the full suite of cyber security services and solutions, including advisory services, security operations and risk management. Along with cyber defense blueprints for rapid deployment and proven cyber-reference architecture, DXC Security helps clients manage diverse threat environments effectively.