Home Blog Page 327

Data breach exposes 800+ million records

Data Security, Unprotected Database Exposes 14 Million Key Ring App Users Info

Verifications.io, an enterprise email validation service provider, recently suffered a data breach that exposed more than 800 million customers’ personal data. The incident came into light after the security researcher Bob Diachenko, who worked with fellow researcher Vinny Troia, identified and reported the data breach. Verifications.io stated that it immediately took the server down after Diachenko informed the data incident.

The researchers stated that they found an unprotected MongoDB server, owned by Verifications.io, containing a total of 150GB of data including approximately 808,539,939 records.

“On February 25th, 2019, I discovered a non-password protected 150GB-sized MongoDB instance. This is perhaps the biggest and most comprehensive email database I have ever reported. Upon verification I was shocked at the massive number of emails that were publicly accessible for anyone with an internet connection. Some of the data was much more detailed than just the email address and included personally identifiable information (PII),” Bob Diachenko said in a blog post.

The researcher stated the server exposed personal information like, names, email addresses, phone numbers, physical addresses, gender, birthdates, personal mortgage amount, interest rate, Facebook, LinkedIn, and Instagram accounts associated with email addresses. It’s also believed that other information related to sales leads including company names, annual revenue figures, fax numbers, company websites, Standard Industrial Classification and National Association of Insurance Commissioners codes were also exposed. The researchers clarified that no information related to social security or credit card numbers were exposed.

Also in January 2019, Bob Diachenko discovered an unprotected Elasticsearch server that exposed more than 24 million financial and banking documents online. The exposed server contained highly sensitive data of thousands of individuals who took mortgages over the past decade with the U.S. banks and other financial institutions.

The researcher stated that he identified the unprotected server on January 10, 2019, which contained 24,349,524 credit and mortgages reports in 51 GB size. The server was taken offline and the data was secured on January 15, 2019, after Diachenko reported the incident to the server’s vendor.

Deep learning developer platform Determined AI raises $11 million

Determined AI, a deep learning management platform, recently raised $11 million in a funding round led by GV, formerly known as Google Ventures.

The company stated the new investment will be used to expand its market reach and bring new features to its deep learning model development tool for machine learning engineers to help developers identify and process data sets. Determined AI also stated that it’s going to employ more data engineers to build its AI applications, VentureBeat reported.

Founded in 2017 by security professionals Evan Sparks, Neil Conway, and Ameet Talwalkar, Determined AI is an early stage company with a focus on machine learning technology. Determined AI helps enterprises in improving developer productivity, increasing resource (GPU) utilization, and reducing risk. The company claims that its AI tools can be used to manage model development workflows, facilitate automatic distributed, tweak models, and optimize hyper parameters.

“You care about your data a lot, you care about understanding the metrics associated with your models in a much more granular and fine-grained way than a traditional software developer would. And so, making that kind of GitHub for model development, kind of central to the product experience is also an area that we’re investing in. Our whole offering is really designed around helping these people be much more productive throughout this model development process,” said Evan Sparks, CEO of Determined AI.

A couple of months back, GV invested $2.6 million in a cybersecurity startup Censys. The Michigan-based startup stated it will use the new investment to collect more data and provide additional actionable insights for its clients. The startup is also planning to expand its engineering and product teams.

Started as a research project at the University of Michigan in 2015, Censys helps organizations by providing visibility to find where the information may be exposed and assess security risk. Founded by a group of security researchers, Censys’s foundational technology acts as a custom search engine that monitors all the IoT devices to look for existing vulnerabilities.

Nvidia acquires Israel’s chipmaker Mellanox

FireEye Acquires Respond Software

The U.S.-based gaming and computer graphics firm Nvidia Corp. recently announced the acquisition of chip designer Mellanox Technologies Ltd for $6.8 billion to boost its data center and artificial intelligence business.

Along with providing gaming chips, Nvidia also offers processors to speed up artificial intelligence tasks like teaching servers that recognize images. The latest acquisition will unite NVIDIA’s computing platform and Mellanox’s end-to-end security solutions to become a major cloud service provider and computer maker.

Mellanox provides end-to-end connectivity solutions for servers that optimize data center performance.  Founded in 1999, Israel and the U.S.-based company makes chips and other hardware for data center servers that power cloud computing.

Mellanox claims that it pioneered the InfiniBand interconnect technology and high-speed Ethernet products, which is now used in over half of the world’s fastest supercomputers and in various major data centers. Mellanox and NVIDIA will jointly improve the data center workloads across computing, networking, and storage to achieve higher performance and lower operating cost for customers.

Speaking on the new acquisition Jensen Huang, the founder, and CEO of NVIDIA, said, “The emergence of AI and data science, as well as billions of simultaneous computer users, is fueling skyrocketing demand on the world’s data centers. Addressing this demand will require holistic architectures that connect vast numbers of fast computing nodes over intelligent networking fabrics to form a giant data center-scale compute engine.”

“We share the same vision for accelerated computing at NVIDIA,” said Eyal Waldman, founder, and CEO of Mellanox. “Combining our two companies comes as a natural extension of our longstanding partnership and is a great fit given our common performance-driven cultures. This combination will foster the creation of powerful technology and fantastic opportunities for our people.”

 

IoT cybersecurity bill introduced in Senate

IoT attacks

A legislation was recently introduced to the U.S. Senate and House of Representatives to improve the cybersecurity of Internet-of-Things devices. The Bipartisan legislation, the Internet of Things (IoT) Cybersecurity Improvement Act of 2019, is intended to make sure that the devices purchased by the U.S. government meet minimum security requirements.

The latest bill, which was introduced by U.S. Sens. Mark R. Warner and Cory Gardner, co-chairs of the Senate Cybersecurity Caucus, along with Sens. Maggie Hassan and Steve Daines, mandates the U.S. National Institute of Standards and Technology to create recommendations to address cybersecurity issues and release guidelines for government agencies that align with the NIST recommendations.

The IoT Cybersecurity Improvement Act of 2019 also directs NIST to work with cybersecurity researchers and industry experts to publish guidance on coordinated vulnerability disclosure to ensure that vulnerabilities related to agency devices are addressed, Augusta Free Press reported.

“While I’m excited about their life-changing potential, I’m also concerned that many IoT devices are being sold without appropriate safeguards and protections in place, with the device market prioritizing convenience and price over security. This legislation will use the purchasing power of the federal government to establish some minimum-security standards for IoT devices,” said Sen. Warner, a former technology entrepreneur and executive and Vice Chairman of the Senate Select Committee on Intelligence.

“The Internet of Things (IoT) landscape continues to expand, with most experts expecting tens of billions of devices to be operating on our networks within the next several years. As these devices continue to transform our society and add countless new entry points into our networks, we need to make sure they are secure, particularly when they are integrated into the federal government’s networks. As co-chairs of the Senate Cybersecurity Caucus, Senator Warner and I remain committed to advancing our nation’s cybersecurity defenses,” said Sen. Gardner.

In 2018, the security experts from Edinburgh Napier University and U.S. electronics manufacturer Keysight Technologies stated that they’re working on a new project to assess the vulnerabilities of the Internet of Things (IoT) devices to cyber-attacks. The 12-month project maintained by the Innovation Centre for Sensor and Imaging Systems (Censis) will use data analytics to create an outline for manufacturers to estimate the risks associated with different IoT devices.

Equipment retailer Kathmandu suffers data breach

Kathmandu

Kathmandu, an outdoor wear and equipment retailer, revealed that it suffered a data breach that disclosed its customers’ credit card and personal information. The New Zealand-based company stated that unknown intruders allegedly gained access to its online trading website for over a month between January 8, 2019, and February 12, 2019.

Kathmandu stated the hackers may have captured customer personal information and payment details entered at the check-out points. The company clarified that all Kathmandu physical stores were not impacted by the incident. As soon as Kathmandu became aware of the breach, it took immediate measures to remediate the issue. It is also working closely with leading external IT and cybersecurity consultants to investigate the incident and to find out the customers who may have been impacted.

“Kathmandu has recently become aware that between 8 January 2019 NZDT and 12 February 2019 NZDT, an unidentified third party gained unauthorised access to the Kathmandu website platform. During this period, the third party may have captured customer personal information and payment details entered at check-out,” the company said in a statement to the New Zealand Securities Exchange.

“Whilst the independent forensic investigation is ongoing, we are notifying customers and relevant authorities as soon as practicable. As a company, Kathmandu takes the privacy of customer data extremely seriously and we unreservedly apologize to any customers who may have been impacted,” said Xavier Simonet, Chief Executive Officer of Kathmandu.

Kathmandu stated that it notified potentially affected customers and urged to contact their banks or credit card providers to know any unauthorized activity in their accounts.

US Healthcare institutions are vulnerable to phishing attacks: Survey

Phishing Campaign on FINRA

A recent survey revealed that employees at U.S. health care institutions may be susceptible to phishing emails. The report, Assessment of Employee Susceptibility to Phishing Attacks at US Health Care Institutions, authored by Dr. William Gordon of Brigham and Women’s Hospital and Harvard Medical School in Boston stated that many healthcare organizations remain vulnerable to phishing attacks.

William specified that when the researchers sent simulated phishing emails, nearly one in seven of the emails were clicked by employees of healthcare organizations. The survey also stated the importance of employee awareness of the risks associated with phishing emails. “Cybersecurity is a really important issue for hospitals and healthcare organizations and it’s only getting more important. One of the biggest risks for them is their own employees and it’s manifested through a phishing attack,” said Gordon.

Gordon and his team analyzed data from six U.S. healthcare institutions that ran phishing simulations from August 1, 2011, to April 10, 2018. The report stated that the phishing campaigns produced around 2,971,945 emails in which 422,062 (14.2 percent) of emails were clicked.

The report concluded that the current click rates in phishing simulations at U.S. health care organizations indicate a major cybersecurity risk. It also urged the health care community to understand the risks and implement proper security awareness measures to enhance the security of health information systems.

Recently, a similar report revealed that health care organizations suffered the highest number of data breaches in 2018 across any sector of the U.S. economy. According to Beazley Breach Response, a breach response management and information security insurance solutions provider, the healthcare entities have reported the highest number of data breaches, at 41 percent. The report, dubbed as Beazley Breach Insights Report, stated that direct hacking, the presence of malware, or due to human error were the causes of data breaches in healthcare organizations.

The report also revealed the percentage of breaches in other sectors of the economy. The education sector accounted for 10 percent of security issues, financial institutions reported 20 percent of incidents, and professional services represent 13 percent of cases.

India’s share in global digital ad-fraud stood at 8.7 percent in 2018: Report

Digital Fraud

Contributed by techARC

techARC released its ‘India digital ad-fraud market report’ with key insights about the market pertaining to year 2018.  As per the findings of the research, the total size of digital ad-fraud stood at staggering $1.63 Billion, which is 8.7 percent of the global size.

1

On the release of the report, Faisal Kawoosa, Founder & Chief Analyst, techARC said, “Digital ad-fraud is getting increased attention from the C-level leadership of evolved organisations, where it is no longer an agenda of a CDO or CMO.”

“The impact of digital ad-fraud now goes beyond diminishing the returns on marketing spends and can jeopardies the entire digital transformation journey hampering Brand Equity, Relevance and Positioning among other ramifications,” Faisal added.

Key Takeaways:

Digital Commerce contributed more than half 51 percent of the total ad-fraud in India.  This being due to such organisations being digital only or primarily digital looking for goals through the customer life cycle of acquisition, engagement as well as retention.

Although, App Fraud contributes to over 85 percent of the total digital ad-fraud, the organisations should not ignore the web platform.  Web platforms are more susceptible to frauds as in several organisations the digital teams are primarily focusing on the app leaving the web space vulnerable.  Also, there are several Brand Safety issues specifically emanating from web like fake leads and keyword abuse.

As video is becoming increasingly the preferred medium of content, it is also attracting fraudsters to explore sophisticated fraud techniques to earn more on the premium advertising channel.  This is increasingly putting the brands at harm for Brand Safety as well as Relevance.

There is a need for digital brands as well as the traditional business model marketers to develop comprehensive O2O ad-fraud strategy as businesses continue to dilute their single channel positioning to omni-channel brands.

Businesses who have an ad-fraud solution in place are better equipped to have higher levels of customer engagements.  This is because they are able to contain abuse through their brand and serve only the most relevant things to their customers.

The report concludes projecting a 23 percent increase in the digital ad-fraud in 2019 with the same rising in domains of Banking and Fintech, Entertainment & Gaming (especially video based) and Healthcare and Pharma where the focus is on acquiring new customers while Digital Commerce will see fraud with respect to engagement and retention.

 

Security startup Cyemptive emerges from stealth with $3.5 million funding

Startup funding

Cyemptive Technologies, a provider of failsafe cybersecurity products, recently emerged from stealth mode with $3.5 million seed A funding. The funding round was led by private sponsors and will help the company expand its cybersecurity product suite for businesses and government entities. The Washington-based company also announced the introduction of its leadership team comprising cybersecurity veterans, including former C-level executives from Microsoft, the National Security Agency, and Hitachi.

Founded in 2016, Cyemptive offers failsafe cybersecurity products and technology to private and public enterprises. Focussed on delivering an alternative approach to protecting networks and end point devices, Cyemptive claims that it won the Department of Homeland Security’s Border Security Technology Consortium (BSTC) competition for having the most innovative border security-related solution in the cybersecurity industry.

With its patented technology, Cyemptive provides endpoint protection services that include automatic troubleshooting and self-healing recovery to eliminate the risk of ransomware attacks.  Cyemptive stated that it’s planning to expand its existing private-sector customer base and also collaborating with teams across the DHS organization.

Speaking on the new investment Rob Pike, Cyemptive’s founder and CEO, said, “Emerging threats tied to cybersecurity stand to affect businesses and government operations dramatically in the near future. We’re approaching the problem from a completely different perspective than others in the market, with a focus on ensuring networks and files remain in a known good state at all times. Instead of relying solely on looking for known threats or leveraging machine learning to try to find unwanted activity, we disallow actions that would corrupt a system or encrypt a file in the first place.”

Whitefly: Espionage Group has Singapore in its sights

Group behind the SingHealth breach is also responsible for a string of other attacks in the region. In July 2018, an attack on Singapore’s largest public health organization, SingHealth, resulted in a reported 1.5 million patient records being stolen.  Until now, nothing was known about who was responsible for this attack. Symantec researchers have discovered that this attack group, which we call Whitefly, has been operating since at least 2017, has targeted organizations based mostly in Singapore across a wide variety of sectors, and is primarily interested in stealing large amounts of sensitive information.

Whitefly compromises its victims using custom malware alongside open-source hacking tools and living off the land tactics, such as malicious PowerShell scripts.

Whitefly’s targets

From mid-2017 to mid-2018, Whitefly launched targeted attacks against multiple organizations. While most of these organizations were based in Singapore, some were multinational organizations with a presence in Singapore.

To date, Whitefly has attacked organizations in the healthcare, media, telecommunications, and engineering sectors.

How Whitefly compromises its victims

Whitefly first infects its victims using a dropper in the form of a malicious .exe or .dll file that is disguised as a document or image. These files frequently purport to offer information on job openings or appear to be documents sent from another organization operating in the same industry as the victim. Given the nature of disguise, it’s highly likely that they are sent to the victim using spear-phishing emails.

If opened, the dropper runs a loader known as Trojan.Vcrodat on the computer. Whitefly has consistently used a technique known as search order hijacking to run Vcrodat. This technique takes advantage of the fact that Windows does not require an application to provide a specific path for a DLL that it wishes to load. If no path is provided, Windows searches for the DLL in specific locations on the computer in a pre-defined order. Attackers can therefore give a malicious DLL the same name as a legitimate DLL, but place it ahead of the legitimate version in the search order so that it will be loaded when Windows searches for it.  Whitefly frequently delivers Vcrodat as a malicious DLL that has the same the same name as DLLs belonging to legitimate software from various security vendors.  The group leverages search order hijacking to assure that their malicious DLLs will be executed. Targeting security applications could allow the attackers to gain higher privileges for the malware, since the vendor’s component may be run with elevated privileges.

Once executed, Vcrodat loads an encrypted payload on to the victim’s computer. The payload contacts a command and control (C&C) domain. Whitefly configures multiple C&C domains for each target. The payload sends system information about the infected computer to the C&C server and downloads additional tools.

Once the initial computer on the targeted organization’s network is infected with Vcrodat, Whitefly begins mapping the network and infecting further computers. In order to carry out this operation, it uses publicly available tools, including Mimikatz (Hacktool.Mimikatz) and an open-source tool (SHA2: 263dc5a8121d20403beeeea452b6f33d51d41c6842d9d19919def1f1cb13226c) that exploits a known Windows privilege escalation vulnerability (CVE-2016-0051) on unpatched computers. The attackers rely heavily on tools such as Mimikatz to obtain credentials. Using these credentials the attackers are able to compromise more machines on the network and, from those machines, again obtain more credentials.  They perform this tactic repeatedly until they gain access to the desired data.

Whitefly usually attempts to remain within a targeted organization for long periods of time—often months—in order to steal large volumes of information. It keeps the compromise alive by deploying a number of tools that facilitate communication between the attackers and infected computers. These tools include a simple remote shell tool that will call back to the C&C server and wait for commands, and an open-source hacking tool called Termite (Hacktool.Rootkit), which allows Whitefly to perform more complex actions such as controlling multiple compromised machines at a time.

Additional malware used in selected attacks

In some attacks, Whitefly has used a second piece of custom malware, Trojan.Nibatad. Like Vcrodat, Nibatad is also a loader that leverages search order hijacking, and downloads an encrypted payload to the infected computer. And similar to Vcrodat, the Nibatad payload is designed to facilitate information theft from an infected computer.

While Vcrodat is delivered via the malicious dropper, we have yet to discover how Nibatad is delivered to the infected computer. Why Whitefly uses these two different loaders in some of its attacks remains unknown. And while we have found both Vcrodat and Nibatad inside individual victim organizations, we have not found any evidence of them being used simultaneously on a single computer.

Links to other attacks

Some of the tools that Whitefly has used in its attacks have also been deployed in other targeted attacks outside Singapore.

Between May 2017 and December 2018, a multi-purpose command tool (SHA2: 7de8b8b314f2d2fb54f8f8ad4bba435e8fc58b894b1680e5028c90c0a524ccd9) that has been used by Whitefly was also used in attacks against defense, telecoms, and energy targets in Southeast Asia and Russia. The tool appears to be custom-built and, aside from its use by Whitefly, these were the only other attacks where Symantec has observed its use.

In another case, Vcrodat was also used in an attack on a UK-based organization in the hospitality sector.

It’s possible Whitefly itself performed these attacks but it’s more likely that they were carried out by one or more other groups with access to the same tools.

Adept attackers with a large toolset

It now appears that the SingHealth breach was not a one-off attack and was instead part of a wider pattern of attacks against organizations in the region. Whitefly is a highly adept group with a large arsenal of tools at its disposal, capable of penetrating targeted organizations and maintaining a long-term presence on their networks. Links with attacks in other regions also present the possibility that it may be part of a broader intelligence gathering operation.

This article was contributed by Symantec.

Security startup RackTop Systems secures $15 million

Funding

Cybersecurity startup RackTop Systems recently raised $15 million in Series A funding to accelerate the growth of its CyberConverged Data Storage and Security Platform. The funding round was led by Razor’s Edge Ventures and Grotech Ventures along with the participation from Maryland Venture Fund, Blu Venture Investors, and Gula Tech Adventures. RackTop stated the new investment helps to further develop its sales channel and product development expansion.

RackTop Systems help federal and commercial organizations solve their cybersecurity and compliance challenges with its secure and high-performance Network-Attached Storage (NAS) platform. The company claims that its flagship product, BrickStor, is an all-in-one data storage and management platform that protects sensitive data from cyber-attacks while meeting internal and regulatory compliance requirements.

Based in Fulton, RackTop was founded in 2010 by security veterans of the U.S. intelligence community. The company claims that its technology has been deployed at numerous organizations in a variety of industries worldwide, including public sector, media and entertainment, financial services, health care, higher education, and life sciences.

“It is costly and complex for enterprises to meet the rising challenges of both storing and managing large data volumes, while at the same time addressing expanding compliance requirements and attempting to protect data from persistent cyber threats,” said Eric Bednash, co-founder and CEO of RackTop Systems. “Our product fuses data storage with cybersecurity to create a unique platform that solves these challenges inherently without added complexity or cost beyond that of legacy storage products alone.”

“The RackTop team has a unique perspective and clear vision on how the Security and Data Storage markets are growing and evolving, and their CyberConverged platform addresses major data, security, and compliance challenges within the modern enterprise,” said Jack Kerrigan, co-founder and managing director of Razor’s Edge Ventures. “We invest in great management teams with differentiated products that solve large, difficult problems across both national security and the commercial enterprise markets. We are extremely excited to invest in RackTop to accelerate their growth and continued product development.”