Home Blog Page 339

Cybercriminals using Google Cloud to attack Financial Services Companies: Research

Google Cloud, Google bug bounty

According to a research by Menlo Labs, a company that provides cybersecurity solutions, employees at financial services firms in the United States and the United Kingdom are being targeted by a malicious email campaign.

The researchers revealed that cybercriminals are storing malicious payloads on storage.googleapis.com, the domain of the Google Cloud Storage service. The email campaign might have been active in the United States and United Kingdom since August 2018. The victims received emails containing malicious links to archive files, which appears to be genuine and related to Google’s cloud storage service. The research report stated the attackers used two types of payloads to compromise PCs and the endpoints by duping employees into clicking on malicious links.

“The malicious payload was hosted on storage.googleapis.com, the domain of the Google Cloud Storage service that is used by countless companies. Bad actors may host their payloads using this widely trusted domain as a way to bypass security controls put in place by organizations or built into commercially security products. It’s an example of the increased use of “reputation-jacking”—hiding behind well-known, popular hosting services to help avoid detection,” the research noted.

“These attackers may have chosen to use malicious links rather than malicious attachments because of the combined use of email and the web to infect victims with this threat. Many email security products can detect malicious attachments, but identify malicious URLs only if they are already in their threat repositories. To prevent these kinds of blended threats, visibility and correlation across both email and web traffic is essential,” the report added.

Google recently announced key security improvements to beef up the data protection measures of Google account users. According to Jonathan Skelker, product manager at Google, the search engine giant is enhancing the account security by introducing a new step-by-step checkup, notifications, and JavaScript requirement.

Shelker explained the Google’s new step-by-step checkup activates automatically whenever it detects any unauthorized activity and diverts the users to a four-step process: verifying security settings, securing other accounts linked to Google account, checking financial activity to ensure no payment methods connected to the google account weren’t compromised, and reviewing whether any content and files on Gmail or Google drive was compromised.

 

Ships at Sea: More Ways to Hack Them

Shipping cybersecurity, carnival cruise line

Contributed by SecureWorld

Taking a cruise in 2019?

If so, try not to think about significant cybersecurity risks and failures detailed in the shipping industry’s new report, “The Guidelines on Cyber Security Onboard Ships.”

Instead, be thankful that the 56-page industry report outlines a cyber risk management strategy, giving the industry guidelines on improving cybersecurity.

If the guidelines are adopted, it will help protect you while you go back to the buffet line. Again.

Shipping cybersecurity incidents

Ships and their systems are increasingly connected to the internet and are becoming more technologically advanced.

However, the idea that these advancements increase the risk of a cyber attack on ships is a relatively new thought, as the following example from the report points out. (Note: ECDIS is the electronic navigation system used in many seafaring craft.)

A new-build dry bulk ship was delayed from sailing for several days because its ECDIS was infected by a virus. The ship was designed for paperless navigation and was not carrying paper charts. The failure of the ECDIS appeared to be a technical disruption and was not recognized as a cyber issue by the ship’s master and officers. A producer technician was required to visit the ship and, after spending a significant time in troubleshooting, discovered that both ECDIS networks were infected with a virus. The virus was quarantined and the ECDIS computers were restored. The source and means of infection, in this case, are unknown. The delay in sailing and costs in repairs totaled in the hundreds of thousands of dollars (US).

Ships are turning into floating computer networks

If you’ve taken a cruise lately, you’ve probably noticed: Wi-Fi actually works most of the time and the price of it is coming down on cruises. You can now stay connected in the middle of the ocean.

This means a better shot for hackers, too, to connect with the ship.

The new shipping cybersecurity report lists an incredible number of connected systems that must be made protected with onboard cybersecurity:

  • Communications systems, from satellite connections to Wi-Fi networks to public address and alarm systems
  • Bridge systems, like GPS and other positioning and charting systems, and the Global Maritime Distress and Safety System
  • Propulsion and machinery power control systems, like the engine governor and integrated ship controls
  • Access control systems, like the closed circuit cameras, shipboard security alarms, and bridge navigation alarms
  • Passenger information systems, like financial and billing systems and electronic health records for those who visit the doctor
  • Passenger-facing networks, like public Wi-Fi and guest entertainment systems
  • Core infrastructure systems, like routers, switches, firewalls, intrusion prevention systems, and security event logging
  • Administrative systems, like crew tracking and personnel systems and crew-facing Wi-Fi or networks

Third-party security a challenge for the shipping industry

One thing the report also details is that ships pull into ports around the world and receive customs forms and cargo documents from some places that have incredible cybersecurity and others that may have no clue about it. And this creates problems.

“A shipowner reported that the company’s business networks were infected with ransomware, apparently from an email attachment. The source of the ransomware was from two unwitting ship agents, in separate ports, and on separate occasions. Ships were also affected but the damage was limited to the business networks… individual efforts to fortify one’s own business can be valiant and well-intended but could also be insufficient. Principals in the supply chain should work together to mitigate cyber risk.”

Hopefully, the cruise industry (which co-authored the report) will adopt the report’s guidelines.

That will decrease the odds of a hacker joining your cruise without ever boarding the ship.

The article was originally posted here and is published with SecureWorld’s permission.

The opinions expressed within this article are the personal opinions of the author. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. 

Saint John’s parking payment system breached; 6000 users affected

Parking System

Saint John, a city in Canada, is the latest victim of a data breach. The city notified via a public notice that it has shut down its online system used to pay parking tickets after discovering a data breach that exposed around 6000 users’ personal information, including names, addresses, and credit card information.

According to the official statement, Click2Gov, a third-party software product that allows residents to pay parking tickets through the Saint John website, was breached by unknown intruders who compromised users’ sensitive information. The city administration stated that it has suspended the payment site temporarily and contacted CentralSquare Technologies, the operator of Click2Gov,to investigate the incident.

The security officials at Saint John stated the breach could have affected a number of municipalities across North America. The people of Saint John are advised to check their financial statements to look for any unauthorized activity.

“Obviously the privacy of our citizens and their payment information is non-negotiable, it must be private. I’m disappointed that this has happened, but we certainly live in a complicated world in this day and age in terms of online forces and hackers and folks that are out and after our public information but we’re taking this very seriously and our teams are working on this to figure out the level of impact and we’ll fix it,” said Mayor Don Darling.

“We want to know how this happened, how many people were impacted and the indication that I have is this is going to take up to four or five days to get this completed.”

Darling clarified that CentralSquare Technologies didn’t notify the people of the city about the breach. He stated the information on the breach was disclosed to the city through media reports from other municipalities that use the online parking payment service.

“If CentralSquare was aware of this breach and they didn’t let us know, then I’ll certainly be looking to follow up on that up to and including is that a breach — I would hope that’s a breach — of our agreement with them. It’s a pretty serious and neglectful act, in my view, on their part not to let us know of a breach that happened,” Darling added.

Data breach affects 500,000 students of San Diego School District

Data Security, Unprotected Database Exposes 14 Million Key Ring App Users Info

San Diego Unified School District recently reported a data breach that affected more than 500,000 students and staff members. According to the official statement, a phishing scam led to unauthorized access to the staff’s log-in information, including the network services and students’ database.

The security officials at the school district stated they discovered the breach in October 2018. It’s believed that the incident occurred between January 2018 and November 2018. The school district declared the compromised students’ information included social security numbers, names, date of birth, mailing address, home address, attendance records, ID numbers, and phone numbers. Some staff members’ information like payroll, deduction information, tax information, direct deposit financial institution name, account number, salary, and leave information was also compromised.

“We sincerely regret that, after completing a thorough forensic investigation, we have reason to believe personal data may have been compromised through the access or use by an unauthorized individual. The unauthorized access resulted in the potential viewing of the personal data of some students and staff members. The personal data potentially included social security numbers and other personally identifying information,” SDUSD said in a statement.

“The data file contained information on students dating back to the 2008-09 school year or more than 500,000 individuals. For that reason, all of those individuals have been notified of the incident. Additionally, some 50 district employees had their log-in credentials compromised as part of the phishing operation. All students and staff who had their information accessed have been alerted by district staff,” the statement added.

SDUSD announced that it has introduced additional data security measures to prevent future threats. It also notified all the victims about the incident and suggested to reset their log-in credentials.

 

“People within smart city framework must understand cybersecurity”

Gaurav Agarwal

The concepts of smart cities have always triggered an evangelical sloganeering from every stakeholder, be it a planner, an engineer or a futurist. At its core, a smart city amalgamates local information systems, hospitals, schools, transportation systems, law enforcement under one grid, and efficiently uses real-time control systems and sensors from data gathered from people and enterprises leading to optimized systems.

But where does security come into the picture? Gaurav Agarwal, Managing Director at Symantec, India, in an exclusive interview with CISO MAG pointed out, “Cybersecurity can be success or failure for a smart city depending on how the entire concept is rolled out. For example, if the city is rolling out public WIFI, and for whatever reasons, user credentials get stolen from the way the WIFI system is implemented, the confidence from smart cities will completely be eroded and the whole program moves three to four steps backwards before it even began.” Adding, “also, if citizen services are rolled out using a smart city platform and if the data that flows through the platform is not protected using the right protection, resulting in a leak of data, it will also have a similar impact.”

He highlighted that security must never be an afterthought of a project like smart cities, and there should be enough groundwork that should be done before implementing a smart city project.

Commenting on how existing cities are migrating toward a smart one and how several patchworks are already required, he pointed out, “Cities are where people are living, so it makes sense for making the existing cities smarter rather than converting a new place where there is nobody living into a smart city. We should think about the people as we invest in new programs and projects, therefore we need a right cybersecurity framework to make sure that the services are been delivered in a manner that it is cyber safe.

“For example, if there are multifactor authentication or login id required, create such a framework which makes sure that even if the login id and password are compromised, the multi-factor authentication can ensure that nobody’s identities and credentials can be misused. You must ensure data that is collected is encrypted so that even if it is stolen or leaked the data can’t be used elsewhere because it cannot be decrypted, thus placing a preventive measure from the very beginning. The third most important factor is the people who work within the smart city framework or the municipal corporation. They must understand cybersecurity and understand bad websites, bad email, wrong USB device entering PCs, et al. Here basic training must be given to everyone on safe computer usage.”

India joined the smart cities cause in 2015, under the vision of its Prime Minister Narendra Modi who identified 100 cities for the project across the sub-continent. Ever since then the country has been trying to integrate multiple technological solutions electronically to create a connected environment for the management of the city’s infrastructures. When asked if Symantec been involved with any smart city project, he said, “Symantec has been involved in various projects in bits and pieces, but I believe it is the Panaji Smart city program that we have been actively proactively involved with right from the design space, giving input to the clients, decision making criteria on what they have to secure from a technological perspective.

“It is one good start which we believe should be an essential part of a smart city, keeping citizens secured, making a platform very strong, giving them analytics on what’s happening on the environment so that if something unwelcome is occurring we can take action. Also, right from day zero we are working on building a SOC which will also make the governing bodies aware on what’s happening in the data center, what’s happening in the network so that they can take right actions and we will support them with an incident that is needed with if something goes out of control.” He is certain that Goa will serve as a great example on this and Imagine Panaji project might get the ball rolling.

When asked if Panaji is ready to jump on the smart city bandwagon, “I think Panaji is outstanding and have done a lot of work on making the city cleaner, building networks, and have been involved in several other developmental activities,” he opines.  “The government is making the life better for tourist who make it to the city and is making it a safer place. Some of the projects that are getting a lot of attention into include city WIFI, surveillance, solid waste management solutions, environment census in terms of geographic systems, smart parking, integrated command and control, et al. According to him these will enable different authorities to act on what’s happening in the city. It is a good start and absolutely a good vision that city is taking off.

We can conclude that the upcoming smart city in Panaji is on the right road which has kept cybersecurity at its core and that is indeed a good start.

Singapore Government to launch bug bounty program with HackerOne

network and ransomware attacks in Singapore, Singapore Ranks Most Prepared in Cybersecurity Readiness: Deloitte

The Government Technology Agency of Singapore (GovTech) and the Cyber Security Agency of Singapore (CSA) recently announced that they’re going to partner with the hacker-powered security platform HackerOne to jointly work with the hackers on a government bug bounty initiative. The new bug bounty program is part of the Singapore government’s ongoing commitment to protect its citizens and secure government network systems.

The hacking challenge will offer a monetary reward to the hackers for discovering and reporting potential vulnerabilities. The Singapore government stated the bug bounty program will run over a period of three weeks between December 2018 and January 2019 to find security flaws in five public-facing government network systems and websites.

HackerOne helps organizations find and fix the potential vulnerabilities before they can be exploited by cybercriminals.  The hacking platform provider claims that it has a wide range of client base, including the U.S. Department of Defense, General Motors, Google, Twitter, GitHub, Nintendo, Lufthansa, Panasonic Avionics, Qualcomm, Starbucks, Dropbox, Intel, the CERT Coordination Center, and over 1,200 other organizations.

“Singapore is again setting an example for the rest of the world to follow by taking decisive steps towards securing their vital digital assets,” said Marten Mickos, CEO HackerOne. “Only governments that take cybersecurity seriously can reduce their risk of breach and interruption of digital systems. Singapore’s continued commitment to collaboration in cybersecurity is something that will help propel the industry’s progress just as much as it will contribute to protecting Singapore citizen and resident data.”

In related news, the Monetary Authority of Singapore (MAS) recently announced the launch of S$30 million (US$22 million) cybersecurity capabilities grant.  The new allocation helps Singapore’s financial institutions strengthen their cyber resilience and upskill local talent through cybersecurity-related training programs like security operations, cyberthreat surveillance, computer forensics, malware analysis, and cyberthreat hunting.

The grant provided under the Financial Sector Technology and Innovation Scheme (FSTI) will co-fund up to 50 percent of expenses in Singapore-based financial institutions to establish their global or regional cybersecurity centers of excellence in the country. It would also support the organizations with regional cybersecurity centers to expand their cybersecurity capabilities globally.

Smart hot tubs hackable: Research

Smart Hot Tub

A recent research study revealed the vulnerabilities in an app that allow hackers to access control system of smart hot tubs, pumps, and lights via a smartphone or laptop.

In a television program dubbed BBC Click, the security researchers from Pen Test Partners Ltd showcased the vulnerabilities in Balboa Water App, a mobile app used for controlling around 30,000 hot tubs manufactured by Balboa Water Group Inc. The security vulnerabilities apparently allow hackers to turn up/down the temperature sensors of the tubs and control the functionality of pumps and lights. The researchers also said the location of hot tubs can be discovered due to an authentication error in the app.

“We emailed Balboa Water Group on 28th November, explaining the flaw and asking for an acknowledgment so that we could start responsible disclosure. We had no reply,” the researchers said in a statement.

“We tried again on 30th November, asking for an acknowledgment by 10 pm GMT on Friday 3rd December. Again, we had no reply. We then asked the BBC if they could use their influence to elicit a response. They kindly obliged and, as if by magic, we had a response from BWG within an hour of the BBC emailing them,” the statement added.

Balboa Water Group stated that they’re introducing a robust security system to patch-up the potential vulnerabilities and notified that the problem would be fixed by the end of February 2019.

In a similar research, the researchers from the University of Texas revealed how Smart Lights can be maliciously used to violate users’ privacy and security. According to the researchers, the hackers can make use of internet-connected light bulbs as a covert channel to exploit the user’s private data.

The research stated that hackers can launch an attack by manipulating the infrared light by creating a communication channel between the smart lights and a device that senses infrared light. And by installing a malicious agent on the phone, the attackers can encode the private data and transfer them through the infrared covert channel.

Cryptomining and IoT malware rose 70% in 2018: McAfee

McAfee

A recent research from McAfee revealed that the cybercriminals are generating 480 new threats per minute. In its latest report, “McAfee Labs Threats Report: December 2018,” McAfee highlighted the IoT malware increased to 73 percent, while the cryptocurrency mining malware was up to 71 percent in the third quarter of 2018.

“The McAfee Advanced Threat Research team has noticed a shift in dark web platforms. Several individual sellers have moved away from large markets and have opened their own specific marketplaces. They hope to fly under the radar of law enforcement and build a trusted relationship with their customers without the fear of a quick exit by the market owners. This shift has sparked a new line of business: Defiant website designers who offer to build hidden marketplaces for aspiring vendors. Other vendors are moving away from the TOR network, choosing platforms such as Telegram to offer their goods and services,” the report stated.

Further, the McAfee stated the mobile malware declined by 24% and new threats ranged from fake mobile applications to mobile banking Trojans. According to the report, the fake apps exfiltrated data, including location details, contact list, and listening to phone calls. McAfee evaluates the state of the cyber threat landscape based on its research, investigative analysis, and threat data gathered by the McAfee Global Threat Intelligence cloud each quarter.

A recent research from the company exposed an active phishing campaign that turns Android devices into mobile proxies. The McAfee mobile research team stated that the phishing attack was performed by sending a malicious code, named as Android/TimpDoor, via text messages that trick users into downloading a fake voice-message app. The installation of the fake application enables attackers to steal the device information and use the infected mobile devices as network proxies.

The researchers stated that the devices infected with TimpDoor could serve as mobile backdoors for stealthy access to the device’s internal networks. Once installed, the fake application runs a Socks proxy redirecting the device’s network traffic through a secure shell connection bypassing the network security mechanisms offered by Google Play Store.

Bruegger’s Bagels reports data breach

Bruegger's Bagels

Bruegger’s Bagels, a restaurant chain, recently reported a data breach on November 28, 2018, that exposed its customers’ data, including name, debit/credit card number, expiration date, and card security code. A subsidiary of the Luxembourg-based company JAB Holding Company, Bruegger’s Bagels stated that it has discovered an unusual activity in its network systems that might cause potential exposure of customers’ data.

Bruegger’s approached cybersecurity company Mandiate to investigate the incident. Mandiant found unauthorized access to Bruegger’s point-of-sale systems, which compromised the customers’ data. Bruegger’s stated the information of the customers visiting the restaurant between August 28, 2018, and December 03, 2018, may be compromised. The security professionals at Bruegger’s have been advising its customers to check their payment card information to find any unusual transactions.

“If you visited any of our company-owned Bruegger’s locations between August 28, 2018, and December 3, 2018, there is a possibility that your name and credit card information, including card number, expiration date, and card security code may have been accessed as a result of this unauthorized activity. Payments made through your Bruegger’s Bagel Inner Circle account or any one of your customer loyalty accounts were not affected. Any catering orders placed online with Bruegger’s Bagels, Einstein Bros. Bagels, Manhattan Bagel, and Noah’s NY Bagels were also not affected by this breach,” Bruegger’s stated in its official statement.

“We sincerely apologize that this breach occurred and assure you that our team is working to help prevent data security issues from occurring in the future. The privacy and security of your information are very important to us and we remain committed to doing everything we can to maintain the confidentiality of your information. We appreciate your patience and loyalty as a customer,” the statement added.

Tyler Ricks, the President of Bruegger’s Bagels stated the company is working on to strengthen its network and payment systems to prevent any future attacks.

IoT cybersecurity startup Cybeats raises $3 million

Startup Funding

The IoT cybersecurity startup Cybeats recently announced that it has raised $3 million in a funding round led by Ripple Ventures, GreenSoil Building Innovation Fund and along with the participation of MaRS IAF, MLA48, ScaleX, and inovia capital. Cybeats provides cybersecurity protection solutions for smart buildings, medical devices, and critical infrastructure. The Toronto-based company stated the new investment will be used to expand its business reach abroad.

Co-founded by cybersecurity veterans Dmitry Raidman, Peter Pinsker, and Vlad Kharbash, Cybeats claims that it helps companies solve security problem with its inside-out approach to cybersecurity. Its micro-agent platform is embedded into IoT devices to provide continuous protection that allows devices to detect and prevent the possible cyber-threats. Matt Cohen, Founder and Managing Partner of Ripple Ventures and Susan McArthur, Managing Partner of GreenSoil Building Innovation Fund will be joining Cybeats’s board.

“With the proliferation of IoT devices where we work, live, travel, and increase in the number of access points prone to malware attacks, it is critical that we adopt a new approach to cybersecurity for all network-connected devices,” said Dmitry Raidman, co-founder and CEO of Cybeats. “The security certification of IoT devices is imperative in order to detect and neutralize these growing threats. Cybeats provides an efficient, simple solution to monitor and overcome security threats.”

“Ripple Ventures is extremely excited to be leading this investment in Cybeats as they help detect and prevent more cyber-attacks from occurring,” said Matt Cohen, Founder and Managing Partner, Ripple Ventures. “The Cybeats team is among the most experienced and knowledgeable cybersecurity experts we have encountered. We look forward to working closely with Cybeats as they expand their solutions globally.”