Home Blog Page 348

Cryptocurrency exchange MapleChange suffers breach

Bitcoin hack

MapleChange, a cryptocurrency exchange, recently declared that it suffered a breach that resulted in the theft of its customers’ funds.  The Canada-based trading platform took to Twitter to declare the incident.

“Due to a bug, some people have managed to withdraw all the funds from our exchange. We are in the process of a thorough investigation of this. We are extremely sorry that it has to come to end like this. Until the investigation is over, we cannot refund anything,” the Twitter post said. MapleChange has temporarily suspended its trading platform.

MapleChange received some serious backlash post the breach announcement. The platform posted another message on Twitter in response to the bashing. “We have not disappeared guys. We simply turned off our accounts temporarily to think this solution through. We cannot refund everyone all their funds, but we will be opening wallets to whatever we have left so people can (hopefully) withdraw their funds,” MapleChange posted.

In a similar cyber-attack, Coincheck, a Japanese cryptocurrency exchange, lost 58 billion yen ($530 million) in what was dubbed as biggest cryptocurrency heist ever recorded. On January 26, 2018, the President of Coincheck Koichiro Wada made a public statement apologizing to the customers and stated that the company may seek financial assistance. Coincheck assured that it would return about 90 percent with internal funds, but hasn’t released a scheduled date.

IBM to acquire cybersecurity company Red Hat

IBM CISO MAG Cybersecurity

IBM recently announced the acquisition of cybersecurity company Red Hat in a cash deal of around $34 billion. The computer manufacturing giant stated the acquisition will help it to adopt cloud-related technologies and securely move all business applications to the cloud.

According to the acquisition agreement, IBM will maintain Red Hat’s open source innovation legacy and Red Hat will work as a separate unit within IBM’s hybrid cloud team. Together, IBM and Red Hat help clients create cloud-native business applications faster, drive greater data security with consistent cloud management.

“The acquisition of Red Hat is a game-changer. It changes everything about the cloud market,” said Ginni Rometty, IBM Chairman, President, and Chief Executive Officer. “IBM will become the world’s #1 hybrid cloud provider, offering companies the only open cloud solution that will unlock the full value of the cloud for their businesses.”

“Most companies today are only 20 percent along their cloud journey, renting compute power to cut costs. The next 80 percent is about unlocking real business value and driving growth. This is the next chapter of the cloud. It requires shifting business applications to the hybrid cloud, extracting more data and optimizing every part of the business, from supply chains to sales,” she added.

British Airways reveals another cyber-attack

British Airways

British Airways recently announced a second data breach that affected over 185,000 customers. In its latest statement, the company announced that its payment website was compromised, affecting customers who made reward bookings between April 21 and July 28, 2018, using a payment card.

The British Airways discovered the incident while investigating on its previous breach that occurred in September 2018, which affected 380,000 transactions.

Of the 185,000 affected customers, the airlines stated that personal information of 77,000 customers was exposed, including name, billing address, email address, card number, expiry date, and CVV. And, the remaining 108,000 customers lost personal details apart from the CVV number.

British Airways is communicating with affected customers and requesting them to reach out to their respective banks or credit card providers and follow their recommended advice.

The airline made an announcement regarding the first breach on September 6, 2018. It notified its customers that “From 22:58 BST August 21, 2018 until 21:45 BST September 5, 2018 inclusive, the personal and financial details of customers making or changing bookings on our website and app were compromised.” Around 380,000 payment-card details were stolen during the period. The airline has notified the police and investigations are underway. The airlines also assured that it will compensate for all the losses to its customers.

Recently, a research report stated that a hacker group dubbed Magecart were responsible for the data breach on British Airways. According to the security researcher Yonathan Klijnsma from cybersecurity company RiskIQ, the attackers allegedly used a skimming script, a malicious code, designed to steal the data from the British Airways website.

“This particular skimmer is very much attuned to how British Airway’s payment page is set up, which tells us that the attackers carefully considered how to target this site instead of blindly injecting the regular Magecart skimmer,” the researcher wrote in a report. “The infrastructure used in this attack was set up with British Airways in mind and purposely targeted scripts that would blend in with normal payment processing to avoid detection.”

eSentire acquires AI startup Versive

Acquisition

Managed Detection and Response (MDR) provider eSentire has acquired AI cybersecurity startup Versive, which specializes in advanced threat detection and automation with its platform. Apart from these, there has been changes made at the senior leadership levels with the appointments of Versive executives Dustin Rigg Hillard as Chief Technology Officer, Ashley Fidler as Vice President, Product, and Matthew Vanderzee as Vice President, Engineering. Financial details of the acquisition have not been revealed.

“Our evolution of MDR blends expert human analysis with AI systems to effectively act on the increasing volume of threats impacting organizations. Traditional managed security approaches and tools can’t rapidly scale to cope with the challenges of today’s business environments,” said Kerry Bailey, CEO, eSentire. “Merging expert data scientists, engineers, and security teams and integrating the power of AI into eSentire services will result in the most advanced MDR platform delivering the scalability, automation, and speed that the modern organization demands without sacrificing quality.”

It was reported that eSentire was looking at three other prospects around AI related activities and finalized Versive after eSentire was impressed by the vision of the company as well as its prowess in artificial intelligence and machine learning. It was also reported that the companies had partnered for the last 18 months to check if Versive’s platform could be applied to eSentire’s use case.

For the latter, Versive was looking at accelerating its technology market as well as intended to extend its capabilities around artificial intelligence into actual products and software. The deal has been a win-win situation for both the parties.

“Rapidly evolving IT environments require a new approach to security. Automating and scaling security expertise with machine learning is the clear path to protecting organizations facing machine-scale security threats,” said Dustin Rigg Hillard, CTO, eSentire. “This is the perfect partnership to drive the next evolution of the Managed Detection and Response (MDR) category that eSentire created, further integrating human security expertise and machine scale automation to secure customer networks.”

Malware turns Android devices into mobile backdoors: Report

GO SMS Pro Android App Still Vulnerable to Data Exposure

A recent research from cybersecurity firm McAfee exposed an active phishing campaign that turns Android devices into mobile proxies. The McAfee mobile research team stated that the phishing attack was performed by sending a malicious code, named as Android/TimpDoor, via text messages that trick users into downloading a fake voice-message app. The installation of the fake application enables attackers to steal the device information and use the infected mobile devices as network proxies.

The researchers stated that the devices infected with TimpDoor could serve as mobile backdoors for stealthy access to the device’s internal networks. Once installed, the fake application runs a Socks proxy redirecting the device’s network traffic through a secure shell connection bypassing the network security mechanisms offered by Google Play Store.

“Once the device information is collected, TimpDoor starts a secure shell (SSH) connection to the control server to get the assigned remote port by sending the device ID,” the researchers stated.

The compromised devices could also be used for sending spam and phishing emails, performing ad click fraud, or launching distributed denial-of-service attacks, according to the research report.

“Based on our analysis of 26 malicious APK files found on the main distribution server, the earliest TimpDoor variant has been available since March, with the latest APK from the end of August. According to our telemetry data, these apps have infected at least 5,000 devices. The malicious apps have been distributed via an active phishing campaign via SMS in the United States since at least the end of March. McAfee notified the unwitting hosts of the phishing domains and the malware distribution server; at the time of writing this post we have confirmed that they are no longer active,” the research report stated.

Most CISOs in North America believe cybersecurity breaches are inevitable: Report

Cyber attack

Kaspersky: A new research from Kaspersky Lab has found that 84 percent of CISOs in North America now believe cybersecurity breaches are inevitable, with financially motivated groups being their primary concern. The findings also show a lack of influence in the boardroom, making it difficult to justify the budgets they need to properly protect their organizations.

The report, “What It Takes to Be a CISO: Success and Leadership in Corporate IT Security,” is the result of an inaugural survey carried out by PAC on behalf of Kaspersky Lab that analyzes the status quo and future developments worldwide of the CISO’s role in organizations across the globe. To collect the research, 250 IT-decision-makers in both the manufacturing and services sectors were surveyed from May to July 2018.

 The findings show that globally, CISOs believe financially motivated criminal gangs (40%) and malicious insider attacks (29%) are the biggest IT security risks to their businesses today – and these types of threats are extremely difficult to prevent. CISOs can face challenges with these because attacks are either launched by ‘professional’ cybercriminals or because they are assisted by employees who are expected to be protecting the business.

In addition, the rise of cyberthreats combined with the digital transformation that many enterprises are currently undergoing is making the role of the CISO increasingly critical in modern business. The report shows that there is now more pressure on CISOs across the globe than ever, with 57 percent considering complex infrastructures involving cloud and mobility to be the top challenge, managing personal data and sensitive information the second biggest challenge at 54 percent, and worrying about the continuing increase in cyberattacks is third at 50 percent.

 With pressure on the CISO increasing, budgets allocated to cybersecurity are reported to be growing across businesses worldwide. More than half (56% globally and 60% in North America) of CISOs are expecting their budgets to increase in the future, while 38 percent of respondents globally – and in North America – expect budgets to remain the same.

Nonetheless, CISOs are up against major budgetary challenges, because it’s almost impossible for them to offer a clear return on investment (ROI), or 100 percent protection from cyberattacks. For example, more than a third (36%) of CISOs say they cannot secure their required IT security budgets because they cannot guarantee there will not be a breach.

When a business views security budgets as part of the overall IT spend, CISOs find themselves vying for budget against other departments. The second most likely reason for not getting budget, is that security is sometimes part of the overall IT spend. In addition, a third of CISOs (33%) claim the budget they could receive is sometimes prioritized for digital, cloud or other IT projects instead – which may be able to demonstrate a clearer ROI.

Although ROI is difficult to prove, there’s no denying that cyber-attacks can have drastic consequences for businesses, with more than a quarter of respondents’ identifying reputational (28%) and financial (25%) damage as the most critical consequences of a cyberattack. However, despite the negative impact of a cyberattack, only 26 percent of the IT security leaders surveyed are members of the board at their respective businesses. Of those who aren’t board members, one-in-four (25%) believe that they should be.

Overall, the majority of IT security leaders (58%) globally believe that that they are adequately involved in business decision making. However, as digital transformation becomes key to the strategic direction of large enterprises, cybersecurity should be a top priority. For many organizations, the role of the CISO will need to develop to reflect these changes to give them the ability to influence important business decisions.

“Historically, cybersecurity budgets were perceived as a low priority IT spend, but this is no longer the case,” said Maxim Frolov, vice president of global sales at Kaspersky Lab. “Today, cybersecurity risks are top of the agenda for CEOs, CFOs and Risk Officers. In fact, a cybersecurity budget is not just a way to prevent breaches and the disastrous risks associated with them – it’s a way to protect business continuity, as well as a company’s core profile investments.”

The report is available here: https://www.kaspersky.com/blog/ciso-report/24288/

The opinions expressed within this article are the personal opinions of the author. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Yahoo agrees to pay $85 mn fine in data-breach settlement

Yahoo

In one of the biggest lawsuit settlements in the United States history, Yahoo Inc. has agreed to pay $50 million in restitution to settle a class-action lawsuit over a data breach in 2013. Altaba, formerly Yahoo, has also agreed to pay $35 million for attorney fee and provide free credit-monitoring services. The company stated that $50 million will be used to compensate consumers for the losses they suffered due to the data breach.

“We are pleased that we were able to reach a settlement with Yahoo, which would provide relief to impacted users and ensure that Yahoo improves its security practices going forward,” said lead plaintiffs’ attorney John Yanchunis of Morgan & Morgan in Tampa, Florida.

The class-action lawsuit relates to a data breach occurred in 2013 that affected three billion accounts worldwide. The company took three years to discover and disclose the breach. Yahoo was hit by another enormous cybersecurity breach in late 2014 that affected 500 million accounts. It was disclosed in September 2016. Due to the severity of the two cyber-attacks, the U.S. telecom firm Verizon lowered its original offer to acquire Yahoo by $350 million and finalized the deal at $4.48 billion in June 2017.

In April 2018, the Securities and Exchange Commission (SEC) revealed that Altaba agreed to pay a $35 million penalty to settle charges for failing to disclose the breach. “Yahoo’s failure to have controls and procedures in place to assess its cyber-disclosure obligations ended up leaving its investors totally in the dark about a massive data breach.  Public companies should have controls and procedures in place to properly evaluate cyber incidents and disclose material information to investors,” said Jina Choi, Director of the Securities and Exchange Commission’s San Francisco Regional Office.

Team8 raises $85 million to build cybersecurity startups

Startup Funding

Cybersecurity think tank and company creation platform Team8 recently announced that it has raised $85 million investment to create eight cybersecurity startups. The investment round was led by Walmart, Airbus, SoftBank, Moody’s, Dimension Data, Munich Re, and Scotiabank along with the existing investors Cisco Investments, Nokia, and Microsoft’s venture arm M12.

“The commitment from our new partners illustrates the significance of our work to galvanize digital transformation across all industries,” said Team8 CEO Nadav Zafrir in a statement. “The synergy and insight from leaders in retail, aerospace, insurance, financial services and technology combined with our unrivalled attacker perspective and data expertise at Team8 will enable companies to adopt new data-driven methods of working, ensuring they can retain their competitive advantage and thrive, in spite of cyber threats.”

Founded by ex-leaders of Israel’s military intelligence Unit 8200, the Israel-based firm develops companies that address cybersecurity issues. In the process of creating advanced cybersecurity solutions/startups, Team8 partners with other security firms who later become their clients. According to Team8’s company-building model, the chief information officers and engineers from its corporate partners are involved in the creation of the cybersecurity companies. So far, Team8 created eight cybersecurity startups in which four startups are working in stealth mode.

“Walmart’s readiness to experiment with and adopt emerging technologies such as blockchain, VR and robotics is pivotal to continually improve our customer shopping experience, stay ahead of the curve and drive market share,” said Jerry Geisler, Walmart’s Chief Information Security Officer, in a statement. “Our digital transformation is underpinned by more connectivity than ever before. We’re joining Team8’s coalition because of their cybersecurity expertise, proven ability to integrate their viewpoints into leading technology solutions and unique access to insights from other sectors.”

Four things to know about Deception Technology and EDR

Deception technology

Contributed by Carolyn Crandall, Chief Deception Officer, Attivo Networks

Many will advocate that the cybersecurity battle is fought at the endpoint. Completely secure these devices and the attacker will not be able to advance their attack. This belief has fueled a new interest and focus on moving from endpoint protection (EPP) to endpoint detection and response solutions (EDR) as well as managed detection and response (MDR) solutions.

The threat landscape is rapidly changing, and organizations’ defenses need to change with it. The latest generation of sophisticated attackers have proven that they can evade anti-virus solutions and bypass traditional perimeter defenses. Given their ability to routinely compromise networks, it has become more important than ever to layer in a “Defense in Depth” strategy that includes prevention, detection, and response. In many cases, predictive measures are also becoming a factor, increasing the need for collection of threat intelligence, which may have been discarded with prior prevention-only approaches.

Unlike endpoint protection solutions, EDR is more than a single product or simple set of tools. The term covers a range of capabilities that combines monitoring, analysis, reporting, response, and forensic functions into a suite of defenses designed to respond to highly skilled attackers. By placing sensors and response capability on the endpoints, these systems are positioned to identify and stop an attacker while the attack is in play. The forensic capabilities in many EDR solutions also facilitate the ability to capture threat intelligence and to analyze an attack for identifying weaknesses in their existing defenses.

Despite the many enrichments found in EDR, a full Defense-in-Depth strategy requires more. EDR solutions from major providers such as Carbon Black, Cisco, CrowdStrike, Cybereason, FireEye, Symantec, Tanium, and others still have gaps related to the detection of in-network threats, discovery and inventory of endpoint assets, information sharing amongst security controls, and processes to minimize response times. Complementary technologies can close many of these gaps.

The deployment of deception technology as a complimentary technology alongside an EDR platform can play a significant role in closing these exposures. Most people will identify with deception as an efficient means for early and accurate detection of threats and for its role in reducing attacker dwell time. However, with advanced distributed deception platforms (DDPs), organizations can also gain visibility, asset discovery, and information sharing automations.

The following are four areas in which deception technology adds significant value when deployed with EDR platforms for Defense-in-Depth, or what Gartner, Inc. refers to as an “Adaptive Defense.”

In-network Detection and Visibility

Deception Technology enhances EDR defenses by quickly detecting threats that are moving laterally within the network, credential theft, and other forms of sophisticated attacks like man-in-the-middle compromises. By creating a synthetic attack surface based on skillfully crafted decoys designed to mirror production assets, organizations create an environment where an attacker is unable to differentiate between deception and real devices. This not only redirects them away from legitimate targets, but also proactively lures and entices them into engaging with the deception environment that will raise a real-time alert of their presence.

Detection strategies include placing breadcrumbs on the endpoints in the form of fake credentials, file shares, mimicked services, and decoy data that can quickly lure attackers into the deception environment where their actions can be recorded and studied without their knowledge.

Discovery and Tracking of Endpoints

To prepare, deploy, and operate deceptions, modern-day DDPs use machine self-learning to understand new devices coming on and off the network, along with their profiles and attributes. Originally designed for creating authenticity, this information also provides security teams with powerful knowledge of adds and changes to the network. This has proven invaluable for detecting unauthorized personal devices, IoT, and other less-secure devices being placed on the network, or devices added with malicious intent. In addition to device visibility, platforms also come with the ability to alert on exposed credential attack paths. Exposed and orphaned credentials, along with system misconfigurations, are often the opening needed for an attacker to gain a foothold. The insight provided in topographical maps not only reduces risk but eliminates hours of manual processing work.

Information Sharing

By using high-interaction decoys, security teams can gather detailed forensic analysis on their attacker. Following the initial detection, deception technology safely collects and automatically correlates attacker TTPs, IOCs, and counterintelligence for insight into attacker capabilities, goals, and the information they are seeking to exfiltrate. With 3rd party integrations, IOC information can be shared automatically with EDR solutions and used to accelerate incident handling, threat hunting, and remediation.

Automated Incident Response

DDP solutions will also now facilitate the automation of incident response, which can be critical for high severity alerts. With native integrations, security teams can set the deception platform to automatically trigger endpoint isolation, blocking, and threat hunting, saving critical time in stopping the spread of an attack and the harm it can inflict. Some solutions will also integrate with EDR management tools, further simplifying the view and response to threats.

Coupled with conventional perimeter defenses and EDR on the endpoints, a deception platform complements and enhances ones Defense-in-Depth strategy, make an attacker’s job radically more difficult, and often serve as a deterrent that drives them to pursue an easier target.

The opinions expressed within this article are the personal opinions of the author. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Researcher points out multiple vulnerabilities in IoT operating systems

Internet of Things

A research expert from the security firm Zimperium recently pointed several vulnerabilities in a number of IoT (Internet of Things) operating systems, including FreeRTOS from AWS. Ori Karliner, the researcher from zLabs, came across 13 flaws in the FreeRTOS operating system that could let attackers compromise the connected devices or leak data in infrastructure systems and smart homes.

“During our research, we discovered multiple vulnerabilities within FreeRTOS’s TCP/IP stack and in the AWS secure connectivity modules. The same vulnerabilities are present in WHIS Connect TCP/IP component for OpenRTOS\SafeRTOS,” explained Karliner. “These vulnerabilities allow an attacker to crash the device, leak information from the device’s memory, and remotely execute code on it, thus completely compromising it.”

Karliner stated the discovered vulnerabilities include four remote code execution bugs (CVE-2018-16522, CVE-2018-16525, CVE-2018-16526, CVE-2018-16528), seven information leak vulnerabilities (CVE-2018-16524, CVE-2018-16527, CVE-2018-16599, CVE-2018-16600, CVE-2018-16601, CVE-2018-16602, CVE-2018-16603), one denial of service flaw (CVE-2018-16523), and an unspecified flaw (CVE-2018-16598), which impact FreeRTOS V10.0.1, AWS FreeRTOS V1.3.1 and its below versions. The vulnerabilities have been disclosed to Amazon Web Services (AWS).

Recently, the experts from Edinburgh Napier University and US electronics manufacturer Keysight Technologies started working on a research project to assess the vulnerabilities of the Internet of Things (IoT) devices to cyber- attacks. The 12-month project maintained by the Innovation Centre for Sensor and Imaging Systems (Censis) will use data analytics to create an outline for manufacturers to estimate the risks associated with different IoT devices.

“The biggest thing holding back the development of the IoT is security – specifically, concerns about the vulnerabilities of devices, the ease of hacking them, and the consequences of such hacks. In healthcare, for example, IoT could transform the way we monitor health and manage conditions like asthma. Only if we can improve confidence in IoT security can we realize the potential of smart technology,” said Professor Bill Buchanan, supervisor of the project.