Home Blog Page 35

Italy’s Antitrust Regulator Fines Google and Apple for Poor Data Practices

Accellion Lawsuit, Google and Apple, Excellus to Pay $5.1 Mn to Settle Potential HIPPA Violations

Sensitive data is a goldmine for adversaries. Recently, the Italian Antitrust Authority fined Google Ireland Ltd. and Apple Distribution International Ltd. €10 million ($11.26 million) each, citing aggressive data practices. The agency stated that both companies had violated the Consumer Code practices during customers’ data acquisition and commercial use.

Both companies leveraged consumers’ data for commercial purposes, promoting their various products and services. As per data privacy laws, organizations should not leverage users’ data for commercial/promotional purposes without their consent.

Reasons for Penalty

The privacy regulator mentioned multiple reasons for its penalty:

  • Google and Apple did not provide clear and immediate information on the acquisition and use of user data for commercial purposes.
  • Google, both in the account creation phase, which is essential for the use of all the services offered, and during the use of the services themselves, omits relevant information that the consumer needs to consciously decide to accept that the Company collects and uses their personal information for commercial purposes.
  • Apple, both in the phase of creating the Apple ID and on the occasion of accessing the Apple Stores (App Store, iTunes Store, and Apple Books), does not immediately and explicitly provide the user with any indication on the collection and use of your data for commercial purposes, emphasizing only that data collection is necessary to improve the consumer experience and use of services.

Also Read: French Regulator Fines Google €220 Mn for Unfair Advertising Practices

“In the account creation phase, Google pre-sets the user’s acceptance of the transfer and/or use of their data for commercial purposes. This pre-activation allows the transfer and use of data by Google, once generated, without the need for other steps in which the user can confirm or change the choice pre-set by the agency from time to time. In the case of Apple, the promotional activity is based on acquiring consent to use user data for commercial purposes without providing the consumer with the possibility of a prior and express choice on sharing their data. This acquisition architecture, prepared by Apple, does not make it possible to exercise one’s will on the use of one’s data for commercial purposes. Therefore, the consumer is conditioned in the choice of consumption and undergoes the transfer of personal information, which Apple can dispose of for its own promotional purposes carried out in different ways,” the regulator said.

Organizations need to be vigilant and practice robust cybersecurity measures while handling users’ classified information.

CyberCrimeCon 2021: Top-tier Cybersecurity Gathering to Go Live on December 2

CyberCrimeCon 2021

Group-IB, one of the global cybersecurity leaders, will stream its annual signature event CyberCrimeCon on December 2, 2021. The 10th edition of CyberCrimeCon, a global threat hunting and intelligence conference, will assemble more than 5,000 cybersecurity pros from around the world and reveal research findings and investigation insights into the recent operations of nation-state threat actors and cybercriminal syndicates.

At CyberCrimeCon, the industry leaders will get together to talk about the most acute cybercrime trends, exchange threat data, and learn from each other with a view of reducing the global impact of cybercrime. This year’s CyberCrimeCon speaker line-up includes Group-IB researchers, INTERPOL and Europol representatives, security analysts of major international financial institutions, and other well-known cybersecurity service providers.

Group-IB will unveil its traditional Hi-Tech Crime Trends report that has been serving as a single comprehensive source of information about threats and adversaries targeting different industry verticals and locations as well as reliable forecasts for what the future may bring. Unlike previous years, Group-IB is issuing a series of in-depth exclusive papers each dedicated to a specific topic: ransomware (analysis of underground affiliate programs, DLS, TTPs), initial network access brokers (market leaders, alliances with ransomware), cyberwarfare, financial sector threat landscape, phishing, and scam.

CyberCrimeCon 2021 will host two simultaneous tracks dedicated to cybercrime groups and cyber espionage & vulnerabilities. The attendees will get to join exclusive talks about the latest operations of APT 41, EvilCorp, ChamelGang, APT 27, infamous ransomware gangs and other hacker groups operating all around the world. The representatives of international law enforcement organizations will share insights into a joint public-private effort combating online fraud.

To meet the global demand for the high-fidelity intel from the battlefields the conference will for the first time have 5 streams tailored to different time zones: Asia-Pacific (GMT+8, 10 AM – 4 PM), Europe (GMT+2, 10 AM – 4 PM), Middle East & Africa (GMT+4, 10 AM – 4 PM), North America (GMT-5, 1 PM – 7 PM EST), Russia (GMT+3, 10 AM – 4 PM).

CyberCrimeCon is intended for CISOs, CIOs, threat hunters, DFIR specialists and investigators, SOC experts, TI analysts, pentesters, and researchers. Visit the official website to learn more about the event’s agenda and speaker line-up. Media registration is open at https://cybercrimecon.com/media-accreditation/.

Media partnership requests can be submitted via email [email protected].


About Group-IB

Group-IB is one of the leading providers of solutions dedicated to detecting and preventing cyberattacks, identifying online fraud, investigation of high-tech crimes, and intellectual property protection, headquartered in Singapore. The company’s threat intelligence and research centers are located in the Middle East (Dubai), Asia-Pacific (Singapore), Europe (Amsterdam), and Russia (Moscow).

Market Trends Report: Global Blockchain Impact

Blockchain

Blockchain technology has sparked interest across all industry types due to its prime feature of data immutability and distributed consensus helping to secure and validate data across the internet. Organizations aspire to boost their business with the help of blockchain-based solutions to increase the trust involved with the process to improve their branding.

Blockchain holds the solution for most information security, transparency, integrity, and trust challenges. With such developments taking place in the digital environment, it is imperative for business and blockchain enthusiasts to understand the impact of emerging technology in the industry.

blockchain survey reportTo understand the trends and challenges involved with integrating blockchain-based technology with their supply chain, CISO MAG, in collaboration with EC-Council’s CBP (Certified Blockchain Professional), conducted the survey “Global Blockchain Impact.” The market report inquiries professionals and leaders from institutes that have or are in the process of implementing blockchain-based solutions tailored to their business needs.

The survey aims to assess the state of the integration process through enquiring the state of associated elements such as skill employment, budget, business impact, use case, challenges, standard practice, solution development, etc.

Key Findings

  • Nearly 40% of the respondents are investigating blockchain implementation possibilities.
  • Nearly 35% of the organizations have developed budgets for blockchain-based solutions.
  • According to more than a quarter of the respondents, the banking industry stands to gain the most benefits.
  • Nearly 42% of the organizations lack skilled cybersecurity professionals with experience in securing blockchain-based architecture and assets.
blockchain survey reportTo view the complete analysis and reportage, hit the download button now!

 

Check out our other Market Trends Reports here.

 

Exposed Services Commonly Observed in Public Clouds

Public cloud

Cloud misconfigurations become one of the major reasons for unauthorized intrusions and accidental data breaches. Threat actors often target unsecured or poorly configured cloud infrastructures to compromise and steal classified information. Recently, security experts from Palo Alto Network’s Unit 42 performed a honeypot experiment to determine how fast cybercriminals attack exposed cloud services, and the results are alarming.

The Honeypot Experiment

A honeypot is a decoy security mechanism used to detect or counteract unauthorized intrusions to critical network systems. Once an attacker breaks into the honeypot, the security admins can identify how the hackers compromised the target, the hacking techniques they deployed, and how their networks defended or were compromised.

Palo Alto researchers stated they had used a honeypot infrastructure containing 320 nodes and deployed across North America, Asia Pacific, and Europe, exposing it online. They misconfigured the primary services within the cloud, including the remote desktop protocol (RDP), secure shell protocol (SSH), server message block (SMB), and Postgres database in the honeypot infrastructure. The experiment calculated the time, frequency, and source of the attacks between July and August 2021.

Key Findings

  • Over 80% of the 320 honeypots were compromised within 24 hours, and all of the honeypots were compromised within a week.
  • SSH was the most attacked application. The number of attackers and compromising events was much higher than for the other three applications.
  • The most attacked SSH honeypot was compromised 169 times in a single day.
  • On average, each SSH honeypot was compromised 26 times daily.
  • One threat actor compromised 96% of our 80 Postgres honeypots globally within 30 seconds.
  • 85% of the attacker IPs were observed only on a single day. This number indicates that Layer 3 IP-based firewalls are ineffective as attackers rarely reuse the same IPs to launch attacks. A list of malicious IPs created today will likely become outdated tomorrow.

“The speed of vulnerability management is usually measured in days or months. The fact that attackers could find and compromise our honeypots in minutes was shocking. This research demonstrates the risk of insecurely exposed services. The outcome reiterates the importance of mitigating and patching security issues quickly. When a misconfigured or vulnerable service is exposed to the internet, it takes attackers just a few minutes to discover and compromise the service. There is no margin of error when it comes to the timing of security fixes,” the researchers said.

How Honeypots Boost Organizations’ Security

Deploying honeypots offer several security advantages to companies that are trying to boost their network defenses. Implementing honeypot technologies help security admins to break the attacker chain and avoid possible cyber risks. Identifying attackers’ hacking courses and paths help security experts build their own strategies to thwart potential cyberattacks. The honeypot experiments help organizations identify security loopholes and strengthen the overall cybersecurity defenses. Read More Here

Hybrid Work Model and a Digital-first Economy Raise the Stakes on Cybersecurity

return to office, business, hybrid work

Disruption in the way we work has exploded in intensity and breadth since the onset of 2020.  As India starts to see some semblance of normality, businesses need to think about what the future of work looks like and how to secure it. According to a Forrester study commissioned by Tenable, 80% of Indian organizations plan to have employees working from home at least once a week in the next 12-24 months. This hybrid work model, however, isn’t without risk.

By Kartik Shahani, Country Manager, Tenable India

Fast-paced Tech Adoption has Atomized the Attack Surface

With employees splitting time between the office and offsite locations, it will become even more challenging for organizations to protect enterprise data as employees connect to public Wi-Fi at the local coffee shop, and access enterprise information on their mobile devices while commuting. These changing conditions will require organizations to take a much more adaptive approach to evaluate how users are configured and managed.

What’s more, over the next two years, organizations in India are enhancing their digital platforms (63%), moving non-critical business functions to the cloud (62%), and expanding the software supply chain (49%) to ensure employees have the right tech stacks to work efficiently in a hybrid environment.

Fast-paced digitization surely facilitated business continuity but also increased the number of cyberattacks. There was an average of 27,966 records breached between May 2020 and March 2021 in India. Organizations with hybrid work models took 271 days as the average mean time to identify a data breach, 63 days longer than the average mean time to identify a data breach in organizations working out of perimeter office.

It’s therefore evident that changes are taking place at light speed but security leaders in India are unprepared to secure workforce strategies. This is a clear sign that tech adoption to facilitate a hybrid work model is outpacing the speed of security in India.

So, what can organizations do?

Redefining What a Vulnerability Is

The hybrid work model has shattered the corporate network into numerous devices across cloud and on-premises. It’s impossible for organizations to rely on yesterday’s tools to secure this new reality. Instead, organizations must adopt a zero-trust model where no one is trusted and everything must be validated. It’s built upon cyber best practices and sound cyber hygiene, such as vulnerability management, proactive patching and continuous monitoring. Identifying each and every user in the network provides full visibility into the attack surface including IT, OT, and IoT. Once security teams know how data flows within the organization, identifying critical assets that need to be secured becomes easier. Limiting access to these assets reduces the attack pathways and allows ease in monitoring the attack surface, identifying end-point vulnerabilities, and patching them regularly.

To prevent another SolarWinds incident from taking place, organizations need to consistently evaluate third-party and contractor access to enterprise data, scan for unmanaged assets to effectively stop attackers.

The future of work is without perimeters and organizations must be prepared to secure their new reality. Also importantly, organizations must ensure that the lessons learned from the past 18 months are reflected in their disaster response and business continuity plans for the future.


About the Author

Kartik-ShahaniKartik Shahani is the Country Manager for Tenable in India. Based in Mumbai, India, Shahani has over 30 years of experience in the IT industry, driving momentum for enterprises. He spearheads initiatives for Tenable in the enterprise security market, manages operations, and continues efforts towards channel activities in India.

He has extensive experience in the telecommunications, finance, and government sectors. Along with his innovative sales strategies, he is instrumental in driving growth in India. Shahani previously worked in RSA Security, a division of Dell EMC, where he was Director for Channel in the Asia Pacific and Japan. Prior to this, he was the Executive Director of Integrated Security for India and South Asia at IBM. 

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

U.K. Government Introduces PSTI Bill to Strengthen IoT Security

PSTI IoT Bill, Common IoT Attacks

The U.K. government has introduced the Product Security and Telecommunications Infrastructure (PSTI) Bill in Parliament to strengthen consumers’ Internet of Things (IoT) against rising hacker intrusions. The new legislation requires IoT manufacturers, importers, and distributors to meet certain cybersecurity standards. The Bill supports the introduction of gigabit-capable broadband and 5G networks to protect citizens against the risks associated with insecure consumer-connected devices.

Risks with Unsecured IoTs

Consumer IoT devices like smart baby monitors, smart bulbs, smart speakers, smart TVs, fitness trackers, smartphones, etc., provide easy access to vast information, making lives easier and more connected. According to the Department for Digital, Culture, Media, and Sport (DCMS), it’s estimated that there could be up to 50 billion IoT devices across the globe by 2030, and on average, there are nine in each U.K. household. But the implementation of necessary cybersecurity measures within these IoT devices is poor, with only one in five manufacturers embedding basic security requirements. Millions of users’ data could be exposed to cybercriminals due to these unsecured connected devices.

Also Read: 10 IoT Security Incidents That Make You Feel Less Secure

The PSTI Bill requires manufacturers to:

  • Ban default passwords as they are an easy target for cybercriminals
  • Require products to have a vulnerability disclosure policy
  • Need transparency about the length of time for which the product will receive important security updates
  • Require manufacturers, importers, and distributors to comply with new security requirements relating to consumer connectable products
  • Create an enforcement regime with civil and criminal sanctions aimed at preventing insecure products from being made available on the U.K. market
  • Ensure that consumer connectable products, such as smart TVs, internet-connectable cameras, and speakers, are more secure against cyberattacks, protecting individual privacy and security
  • Amend the Electronic Communications Code to support the quick and efficient rollout of gigabit-capable broadband and 5G networks in a way that balances the interests of landowners, telecoms operators, and the public
  • Align the process and framework for renewal agreements with those for new agreements and encourage more collaborative negotiations; and
  • Introduce measures that will help optimize the use of existing infrastructure

The PSTI Bill Address IoT Risks by:

  • Providing Ministers with powers to specify and amend minimum security requirements in relation to consumer connectable products
  • Placing duties on the manufacturers, importers, and distributors that must be complied with in relation to these products
  • Giving powers to allow breaches of these duties to be enforced against

The new regulations, jointly developed by DCMS and the National Cyber Security Centre, are intended for companies that manufacture, import, and sell consumer IoT devices in the U.K.

Following Royal Assent of the Bill, the U.K. government will provide at least 12 months notice to enable manufacturers, importers, and distributors to adjust their business practices before the legislative framework comes into action. The government also informed that non-compliance might lead to a fine or penalties.

“A primary aim of this approach has been to ensure that interventions in this space are maximally effective whilst minimizing impact on organizations involved in the manufacture and distribution of consumer connectable products,” the DCMS said.

Episode #17: Combating Attacks in the Health Care Sector

Attacks in the Health Care Sector

Last year around December, there were many ransomware attacks on U.S. health care institutions. And in May this year, the Conti ransomware gang targeted the Irish health care system. With the holiday season round the corner, we anticipate more cyberattacks on the health care sector.

With multiple data breaches and ransomware attacks, the health care providers continued to be the primary target for cybercriminals. According to the “U.S. Health Care Data Breach Statistics” survey, around 70% of the U.S. population is affected by health care data breaches, with over 230,954,151 health records lost, stolen, or exposed in various security incidents. 2018 and 2019 witnessed a sharp increase in the number of individuals affected by health care data breaches, with a six-fold increase between 2017 and 2019.

Nearly two-thirds of global health care organizations suffered a cyberattack in their lifetime, while 53% were attacked within the last 12 months. The most commonly reported cyberattacks in the health care sector are phishing (68%), malware (41%), and web-based attacks (40%).

In this episode, Jeremy Kennelly, Senior Manager, Mandiant Intelligence gives us an overview of some of the new threat actors seen this year, especially those targeting the health care sector. In this episode he tells us about the typical TTPs and attack patterns, alluding to threat actor groups like FIN12.

Jeremy is a senior manager and principal analyst on the Mandiant Intelligence team focused on the analysis of financially-motivated cyber threat activity. Prior to his time at Mandiant, Jeremy worked as a security architect, incident responder, and in a number of other operational security roles at multiple major multinational corporations.

Vulnerabilities in MediaTek Chips Found in 37% of Smartphones Worldwide

MediaTek, Intel Processor Vulnerability, chip

Security experts from Check Point discovered multiple security flaws in smartphone chips developed by MediaTek, which could have led attackers to spy on Android Users.

In its report, Check Point identified multiple vulnerabilities inside the chip’s audio processor embedded in 37% of smartphones worldwide. Taiwan-based MediaTek is one of the largest chipset vendors that supply its products to various smartphone brands, including Xiaomi, Realme, OPPO, and Vivo.

The Vulnerabilities

The vulnerabilities in MediaTek’s audio Digital Signal Processor (DSP) include CVE-2021-0661, CVE-2021-0662, CVE-2021-0663, and audio HAL CVE-2021-0673. If exploited, the vulnerabilities could allow a remote hacker to spy or eavesdrop on the targeted user from an unprivileged Android app.

MediaTek said that it had fixed all vulnerabilities after the vulnerability disclosure.

“A malformed inter-processor message could potentially be used by an attacker to execute and hide malicious code inside the DSP firmware. Since the DSP firmware has access to the audio data flow, an attack on the DSP could potentially be used to eavesdrop on the user. By chaining with vulnerabilities in Original equipment manufacturer (OEM) partner’s libraries, the MediaTek security issues we found could lead to local privilege escalation from an Android application,” the researchers said.

Attack Methodology

  • A user installs a malicious app from the Play Store and launches it.
  • The app uses the MediaTek API to attack a library with permissions to talk with the audio driver.
  • The app with system privilege sends crafted messages to the audio driver to execute code in the firmware of the audio processor.
  • The app steals the audio flow.

While there is no evidence that the vulnerabilities were being exploited before they were patched, MediaTek urged users to immediately update their smartphones and IoT devices to prevent any risks.

Commenting on the vulnerability disclosure, Slava Makkaveev, Security Researcher at Check Point Software, said, “We embarked on research into the technology, which led to the discovery of a chain of vulnerabilities that potentially could be used to reach and attack the audio processor of the chip from an Android application. Left unpatched, a hacker potentially could have exploited the vulnerabilities to listen in on conversations of Android users. Furthermore, the security flaws could have been misused by the device manufacturers themselves to create a massive eavesdrop campaign. Although we do not see any specific evidence of such misuse, we moved quickly to disclose our findings to MediaTek and Xiaomi. In summary, we proved out a completely new attack vector that could have abused the Android API.”

CISA, FBI Ask Critical Infrastructure Partners to be Vigilant This Festive Season

IoT Connections to Reach 83 Billion by 2024: Report, CISA alerts critical infrastructure, CISA – FBI holiday season alert

With the onset of the holiday season, employees, especially in the West, take off on the much-awaited annual leave and head home for family vacations. It is also the time when threat actors wait for their annual bounty. With holiday fever at its peak and organizations in “out of office” mode, cybercriminals continue to be in “active mode.”

See also: How to Stay Digitally Safe This Black Friday and Cyber Monday

In a joint alert, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) are alerting all organizations – big or small – and critical infrastructure partners that malicious actor groups are in full fire to launch premeditated cyberattacks during the holiday season.

“Recent history tells us that this could be a time when these persistent cyber actors halfway across the world are looking for ways — big and small — to disrupt the critical networks and systems belonging to organizations, businesses, and critical infrastructure,” the alert said.

Friendly reminder to remain vigilant to #ransomware and other cyber threats this holiday season. Cybercriminals don’t take off days! Follow our tips in our joint release with the @FBI: https://t.co/gFmiRTR2rK #StopRansomware https://t.co/KRnPXhNwaJ

Tessian researchers reveal that almost two-thirds (64%) of the top couriers are at risk of having their domains impersonated by scammers, as their email domains are not sufficiently protected against phishing, spoofing, or fraud. What’s more, only 20% of the top global couriers have configured DMARC (Domain-based Message Authentication, Reporting & Conformance) to its highest security level.

The FBI and CISA have stringent advice for organizations, especially critical infrastructure and services, to assess the current security posture and implement best practices and mitigations to attenuate the threat posed by cyberattacks this festive season.

CISA and the FBI Recommend

  • Identify IT, security employees, for weekends and holidays who would be available to surge during these times in the event of an incident or ransomware attack.
  • Implement multi-factor authentication for remote access and administrative accounts.
  • Mandate strong passwords and ensure they are not reused across multiple accounts.
  • If you use remote desktop protocol (RDP) or any other potentially risky service, ensure it is secure and monitored.
  • Remind employees not to click on suspicious links and conduct exercises to raise awareness.

Caroline Wong, Chief Strategy Officer at Cobalt, opines, Caroline Wong, Cobalt“Cybercriminals don’t take off for Thanksgiving holidays, and neither should your cybersecurity safety measures. To combat malicious attackers, business leaders should heed CISA’s warning and proactively search their systems for potential security vulnerabilities now before it’s too late. Year-round preventative security measures go a long way. It’s simple — you must identify your assets, find your security problems, and promptly fix those security problems. This will protect you when cybersecurity incidents occur, whether during the holidays or not.”

“People are expected to receive a lot of packages during the holiday season – and hackers take advantage of this by pretending to be FedEx, UPS, and Amazon, to trick victims into giving them personal information that they can use for personal gain. Remain vigilant to avoid falling prey to malicious actors’ ploys.”

Watch Out For

  • Phishing scams, such as unsolicited emails posing as charitable organizations.

Being vigilant is imperative and not a choice. It is important to closely monitor your security posture before signing off for the season.

 

Iranian Threat Actors Leverage PowerShortShell to Exploit Microsoft Flaw

Log4j, Iranian Ransomware Actors, SpoofedSccholars, second-tier targets, NIOPDC

Security experts from SafeBreach Labs identified a new Iranian threat actor group exploiting a Microsoft MSHTML Remote Code Execution (RCE) flaw – CVE-2021-40444. The group reportedly used a new PowerShell stealer code, dubbed PowerShortShell, to target social media accounts of Farsi-speaking users since mid-September 2021.

PowerShortShell Explained

SafeBreach Labs researchers stated the threat actor group leveraged spear-phishing emails to distribute PowerShortShell script across the targeted devices. PowerShortShell provided the hackers access to critical data, including screen captures, telegram files, document collection, and extensive data about the victim’s environment. While the operators behind the PowerShortShell campaign are unknown, the researchers stated the group might be linked to Iran’s Islamic regime.

“Based on the Microsoft Word document content, we assume that the victims might be Iranians who live abroad and might be seen as a threat to Iran’s Islamic regime. The adversary might be tied to Iran’s Islamic regime since the Telegram surveillance is typical of Iran’s threat actors like Infy, Ferocious Kitten, and Rampant Kitten. Surprisingly, the usage of exploits for the infection is unique to Iranian threat actors, which heavily rely on social engineering tricks,” the researchers said.

PowerShortShell Attack Sequence

  • The attack starts by sending a spear phishing mail (with a Winword attachment) that the victim is lured to open.
  • It then exploits Microsoft MSHTML Remote Code Execution Vulnerability CVE-2021-40444.
  • The Word file connects to the malicious server, executes the malicious HTML, and then drops a DLL to the %temp% directory.
  • The malicious DLL executes the PowerShell script.
  • inf is a DLL that downloads and executes the final payload (PowerShell script).
  • The PowerShell script collects data and exfiltrates it to the attacker’s C2 server.

Also Read: Microsoft Identifies Six Iranian State Actor Groups Deploying Ransomware

The researchers found two phishing campaigns intended to harvest credentials for Gmail and Instagram using the C2 server – Deltaban[.]dedyn[.]io – a phishing HTML page masquerading as the legit deltaban.com travel agency.

Victims Affected

While the exact victims of PowerShortShell are unknown, the number of reported victims include the U.S. (45.8%), followed by the Netherlands (12.5%), Russia (8.3%), Canada (8.3%), Germany (8.3%), China (4.2%), and India (4.2%).

Indicators of Compromise (IOC)

  • dedyn.io – C2 and infection server
  • dedyn.io – phishing
  • dedyn.io – phishing
  • dedyn.io – phishing