Home Blog Page 388

Pizza Hut suffers data breach; nearly 60,000 customers affected

Pizza Hut

Quick Service Restaurant Chain Pizza Hut reportedly suffered a massive data security breach on October 1 and October 2. The chain notified the patrons nearly two weeks after the hack.

In a damage control exercise, Pizza Hut is now offering approximately 60,000 impacted customers across the U.S. free credit monitoring through Kroll Information Assurance for one year. January 11, 2018 is the last date to apply for registration.

The cyber theft may have exposed customers’ personal information such as names, billing zip codes, delivery addresses, email addresses, and payment information such as account numbers, expiration dates and Card Verification Value numbers.

In an email, the Italian-American cuisine franchise Pizza Hut said “we have learned that the information of some customers who visited our website or mobile application during an approximately 28-hour period (from the morning of October 1, 2017, through midday on October 2, 2017) and subsequently placed an order may have been compromised.”

“Pizza Hut identified the security intrusion quickly and took immediate action to halt it. The security intrusion at issue impacted a small percentage of our customers and we estimate that less than one percent of the visits to our website over the course of the relevant week were affected”, the notification said.

Breach-beleaguered Pizza Hut has consulted cybersecurity experts to look into the apparent hack and to make sure it doesn’t happen again.

Some customers even posted about the delay in getting information about the data breach on social networking websites.

Ariel Nikole, whose Twitter handle is @ArielNikole708 on October 15 tweeted “There was fraud on my account & I had to cancel my cards. My fat a** orders pizza ? too much ? thanks @pizzahut for compromising my info ??”

Michael Richardson @marichardsonjrr tweeted “@pizzahut great security there & thanks for the delay in notifying us after thieves already charged our accts. Keep up the excellent work”

In 2012, Pizza Hut Australia was hit by a cyber attack that affected its 2,40,000 customers. Recently, Sonic Drive-In, Chipotle and Wendy’s also became victims of cyber attacks.

66% of IT employees admit to snooping sensitive company info: Survey

Snooping

A recent global survey revealed what percentage of information technology professionals access unauthorized resources and who snoops more – executives or middle management, big companies or small ones. The findings were an eye opener, as the survey exposed global epidemic of worst practices for Identity and Access Management (IAM).

According to the Dimensional Research survey commissioned by One Identity, nearly two in three or 66 percent of survey respondents admitted that they seek out and access company information that they didn’t need to do their work.

The online survey polled more than 900 IAM-knowledgeable IT security professionals from the U.S., the U.K., Australia, Canada, France, Germany, Hong Kong, and Singapore.

It was found out that 36 percent of respondents were willing to take it a step further and admitted to hunting down, or accessing, sensitive company performance information that was irrelevant to their work.

Seventy-one percent of IT security executives admitted to general snooping of company information that is not sensitive, while 40 percent of them were willing to track down or access sensitive company performance information.

The survey also found out that less than 50 percent of companies track the movements of their IT security teams and IT administrators as they move through the corporate network and other systems.

Ninety-two percent of IT security professionals say that employees at their companies attempt to access the information they don’t need for their day-to-day work. Also, 44% of IT security professionals admit to searching for sensitive company information, compared to 36% of financial services employees or 21% of healthcare employees.

Wi-Fi networks using WPA2 protocol vulnerable to KRACK attack: Research

Krack

Any device using Wi-Fi Protected Access II (WPA2) encryption could allow nearby attackers to intercept and steal data transmitted across a Wi-Fi network, as it is reportedly vulnerable to newly discovered series called Key Reinstallation Attacks (KRACKs).

KRACKs that have been discovered by Mathy Vanhoef, a security researcher at a Belgian university, consists of 10 separate vulnerabilities and three keys in 4-way handshake: reinstallation of the pairwise encryption key (PTK-TK), reinstallation of the group key (GTK, and a reinstallation of the integrity group key (IGTK).

Vanhoef wrote in Krackattacks “An attacker within range of a victim can exploit these weaknesses using KRACKs. Concretely, attackers can use this novel attack technique to read information that was previously assumed to be safely encrypted. This can be abused to steal sensitive information such as credit card numbers, passwords, chat messages, emails, photos, and so on. The attack works against all modern protected Wi-Fi networks. Depending on the network configuration, it is also possible to inject and manipulate data”.

“The weaknesses are in the Wi-Fi standard itself, and not in individual products or implementations. Therefore, any correct implementation of WPA2 is likely affected. To prevent the attack, users must update affected products as soon as security updates become available. Note that if your device supports Wi-Fi, it is most likely affected.”

On being asked whether changing Wi-Fi password would help, Vanhoef answered “Changing the password of your Wi-Fi network does not prevent (or mitigate) the attack. So you do not have to update the password of your Wi-Fi network. Instead, you should make sure all your devices are updated, and you should also update the firmware of your router. Nevertheless, after updating both your client devices and your router, it’s never a bad idea to change the Wi-Fi password.”

DHS issues directive for federal agencies to use DMARC, HTTPS, and STARTTL

DHS

In an attempt to secure emails and deploy authentication technologies, the U.S. Department of Homeland Security (DHS) on October 16, 2017, issued a binding operational directive requiring all federal agencies to use DMARC, HTTPS, and STARTTLS.

Domain-based Message Authentication, Reporting & Conformance (DMARC) is a security protocol, which is designed to prevent phishing and spamming attacks. All federal agencies have been instructed to implement this domain within one month.

DMARC has three categories of filtering content: monitoring email for phishing and spam, quarantining emails that fall into this category, and deleting such emails. It creates a whitelist of verified senders, then it delivers only authenticated emails and deletes fake ones before a user sees them. It also restricts the ability for company employees to send out unauthorized email campaigns.

During a joint press conference with the Global Cyber Alliance, Jeanette Manfra, assistant secretary for the Office of Cybersecurity and Communications at the DHS said “over the coming year, the DHS aims to have 100% of federal agencies rejecting phishing and spam emails”.

“Citizens who depend upon interaction with the government deserve a trusted relationship. So, if they see an email from the IRS or FEMA, they need to believe and trust it is an email from the IRS or FEMA,” Manfra said.

Within coming four months, all federal agencies have to mandatorily use encryption on their websites via HTTPS and STARTTLS for email. Tech giants such as Microsoft, Google and Yahoo are already supporting DMARC email services.

Seventy-six percent of global email accounts or 4.8 billion inboxes worldwide support DMARC, DHS and industry report said. Federal agencies and enterprise companies are far from the 50% DMARC level, the report added.

According to an analysis of DNS records by Agari, two-thirds of Fortune 500 companies have not deployed any level of DMARC. 25 percent of survey respondents chose to only monitor email, 3 percent have a quarantine policy, and 5 percent have implemented a reject policy, Agari report revealed.

Patrick Peterson, Agari’s founder and executive chairman said “this mandate will reduce risk for the enterprise as many phishing and malware attacks impersonate government agencies such as recent threats highlighting SEC and IRS spoofing. This leadership from DHS also sets a clear message that DMARC is valuable and should be implemented at scale which will drive enterprise awareness and adoption”.

A 2016 report by Valimail found out that 62 percent to 80 percent of DMARC efforts failed. The reason behind the delay on DMARC deployment was cited as reluctance to change back-end email systems, which have complex DNS tables.

Peter Goldstein, chief technology officer and co-founder of ValiMail said “you have to get to enforcement to get real value out of DMARC. At enforcement, receiving mail servers are instructed to quarantine (flag as spam) or delete messages that fail authentication. But getting there requires authenticating all of an organization’s legitimate senders — both internal and cloud services sending on their behalf”.

Industry experts said the protocol’s low adoption rate may be due to lack of education by users, as well as hesitation to try a new technology.

However, Shehzad Mirza, Global Cyber Alliance (GCA) director of global operations said “organization has a relatively easy DMARC setup guide on its website”, while adding “anyone with an email domain, small businesses, large businesses, should be using it.”

Auto industry finally serious about cybersecurity: Jeep Hackers

Automotive cybersecurity

Modern-day connected cars carry million lines of code. In fact, the technology is almost 100 times more powerful than Apollo 11, the first spacecraft that landed on moon.  And experts have been stating that “Vehicle data could be the beginning of a modern-day gold rush.” But the vulnerability of car hacking was first demonstrated by hackers Charlie Miller and Chris Valasek, while the duo remotely took controls of a Jeep Grand Cherokee in 2015. The celebrated automotive ethical hackers now believe that auto industry is finally getting serious about cyber security.

In an interview with Which-50, Miller said “If we look at the demo that we did with the Jeep, I think that opened a lot of eyes that this is a problem that companies need to face. Everyone I’ve talked to in the industry sees it as a serious problem that they’re trying to address to the best of their abilities,” The duo spoke to the publication during the AISA conference held recently in Sydney.

Cars come with connected features to pair your personal device for several purposes like hands-free driving, access to infotainment, GPS, and maps. With standard cars generating 25 gigabytes of data per hour, enterprises may need to consider connected cars as an insider threat and its vulnerability to data theft.

According to them, automotive cybersecurity is no longer an afterthought but something very similar to how organizations now consider information security for organizations. “20, 25 years ago people didn’t think of web browsers as needing security,” Valasek said. “But now we know that a huge piece of end-user security is how secure the web browser is. This is where we are going with automobiles. “Just like we saw with Microsoft and other software companies it’s an iterative process and it will get better over time. At one point Microsoft was the insecure operating system. Now they’re doing a really good job of it. So it just takes time.”

The experts argued that remotely hacking cars within minutes are still a pipe dream.  “It’s not something you can do on a weekend. It’s not something you have to worry about a bored teenager doing. It’s really difficult to do and it’s only ever been done for research purposes,” Miller said.  “You have to remember that in the car industry it takes a long time to make changes, so the cars designed today won’t see the road for three or four years. And so it will take a while. But I think we are going to get there.  Toasters will probably never be secure but hopefully, important things like pacemakers and cars will be.”

New US revenge law allows you to “hack the hackers who hacked you”

France Fines Facebook and Google,Russia fines Google, Meta heavily New York City Law Department Hit by a Cyberattack

As part of the cybersecurity awareness month, the US Congress has reportedly introduced a ‘hack back’ revenge law. As its name suggests, the new bill would allow hacking victims to seek revenge and hack the hackers who hacked them.

A press release said two members of the US House of Representatives, Republican Tom Graves from Georgia and Republican Kyrsten Sinema from Arizona announced the formal introduction of the law on October 13, 2017.

For the first time in history, the Active Cyber Defense Certainty Act (ACDC) has amended the Computer Fraud and Abuse Act (CFAA), which was enacted in 1986, to make limited retaliatory strikes against cyber-miscreants legal.

The amended bill allows hacked organizations to venture outside their networks to identify an intruder and infiltrate their systems, destroy stolen data, and deploy a technology to trace the physical location of the perpetrator.

Republican Tom Graves said “While it doesn’t solve every problem, ACDC brings some light into the dark places where cybercriminals operate.”

“The certainty the bill provides will empower individuals and companies use new defenses against cybercriminals. I also hope it spurs a new generation of tools and methods to level the lopsided cyber battlefield, if not give an edge to cyber defenders. We must continue working toward the day when it’s the norm – not the exception – for criminal hackers to be identified and prosecuted.”

The lengthy process began on March 3 this year when Republican Graves introduced the first ACDC discussion draft, after which it was updated on May 25. After soliciting lot of feedbacks and suggestions with the business community, academia and cybersecurity policy experts, the final version of the bill was introduced on October 13, 2017.

Meanwhile, the amended bill has put Information Technology experts into a tizzy as they are worried about consequences of “collateral damage”.

At the same time, the sponsors of the bill have assured that additional safeguards have built in, such as:

  • the legislation only allows hacking of computers on American soil, which instantly limits its usefulness
  • the legislation is time limited and will expire after two years

The IT department would have to inform the FBI’s National Cyber Investigative Joint Task Force before hacking back any attacker.

Republican Representative Kyrsten Sinema said “The Active Cyber Defense Certainty Act gives specific, useful tools to identify and stop cyberattacks that have upended the lives of hundreds of millions of Americans.”

Currently, the proposed act is on a pilot basis, that has to cross various hurdles. If enacted, the US Department of Justice would have to address Congress once a year to keep them updated on cyber-sorties carried out under the law.

Equifax temporarily loses contract worth $7.25 million with IRS

IRS

Amid the second malware incident, the credit reporting agency Equifax on October 12, 2017, temporarily lost a fraud prevention contract worth $7.25 million with the Internal Revenue Service (IRS) that it had received on September 29, 2017. As a precautionary measure, the multi-million-dollar deal was put on hold after the discovery of an adware installer on Equifax’s website.

Noting that the tax-collecting agency will continue its review of Equifax systems and security, the IRS spokesperson Matthew Leas said “following new information available, the IRS temporarily suspends its short-term contract with Equifax for identity proofing services. There is still no indication of any compromise of the limited IRS data shared under the contract.”

An alert on the IRS website says “This service is unavailable for new users at this time. If you already have an account, please continue the login process. We apologize for any inconvenience.”

IRS’ no-bid contract drew lot of criticism from members of Congress from both political parties as well as from ordinary citizens.

Senator Orrin Hatch, R-Utah, chairman of the Senate Finance Committee told AP “Given that Equifax failed to secure their own systems and provide timely notifications of a massive security breach, they should have never been an option for hire by the IRS.”

Republican Representatives Greg Walden and Robert Latta told Reuters in a joint statement said “from its initial announcement, the timing and nature of this IRS-Equifax contract raised some serious red flags…we are pleased to see the IRS suspend its contract with Equifax”.

After the suspension, breach-beleaguered Equifax said, “We remain confident that we are the best party to perform the services required in this contract. We are engaging IRS officials to review the facts and clarify available options.”

“Since we learned that the third party vendor was “running code that was serving malicious content”, the code was removed from the webpage and we have taken the webpage offline to conduct further analysis”, it further said.

In September this year, Equifax came under scanner after the personal data of 145.5 million users was reportedly hacked. The stolen data included social security numbers, birth dates and addresses, and in some cases driver’s license numbers. The massive breach resulted in the stepping down of its CEO Richard Smith.

Sensitive data about Australian defense projects hacked: Reports

Australia Defense

A subcontractor for Australia’s Department of Defense (DoD) became the latest victim of hacking as commercially sensitive information about next generation spy planes and naval warships were reportedly stolen.

The Australian Cyber Security Centre (ACSC) reported the data theft as part of the 2017 Threat Report. Mitchell Clarke, Australian Signals Directorate (ASD) incident response manager, disclosed at the Australian Information Security Association (AISA) conference that “military equipment data and diagrams related to the country’s $14 billion Joint Strike Fighter program were included among 30 gigabytes of data stolen by the attacker”.

Clarke also reportedly stated that some of the stolen information was related to the U.S. International Traffic in Arms Regulations. The attacker used a tool called “China Chopper”, which is apparently popular among Chinese hackers and the breached contractor practiced “sloppy” security, using default logins and passwords.

“That ITAR data included information on the [F-35] Joint Strike Fighters, the C-130, the P-8 Poseidon, the JDAM –that’s a smart bomb – and a few Australian naval vessels,” Clarke noted.

The mysterious perpetrator has been nicknamed Alf, which is an allusion to a character Alf Stewart from Australian TV soap opera Home and Away character played by Ray Meagher.

As per a report published in ZDNet, the hacker infiltrated the 50-person aerospace engineering firm system in mid July 2016 and authorities were only alerted in November by a “partner organization”. In December 2016, the government cyber officials started fixing the system and referred the duration before they responded as “Alf’s Mystery Happy Fun Time”.

Meanwhile, Defense Industry Minister Christopher Pyne said “I am sure there is work being done on finding out who did it. It could be a number of different actors, it could be a state actor, a non-state actor, it could’ve been someone who was working for another company.”

92 percent of organizations attacked with DDoS just once suffer theft: Survey

Multiple Banks and Telecoms in Hungary Affected in a DDoS Attack

Neustar, Inc., a provider of real-time information services, recently released its bi-annual Global DDoS Attacks and Cyber Security Insights Report, affirming DDoS attacks continue to be an effective means to distract and confuse security teams while inflicting serious damage on organizations. The report highlights that organizations experienced a 27 percent increase in the number of breaches per DDoS attack, despite suffering similar attack levels in the same period last year.

Data from the report shows attackers are achieving higher levels of success against organizations they only hit once: 52 percent of organizations reported a virus associated with a DDOS attack, 35 percent reported malware, 21 percent reported ransomware and 18 percent reported lost customer data. Over a twelve-month period, 75 percent of respondents recorded multiple DDoS attack attempts following an initial assault on their organization’s network. The resulting breach ratio increases as the number of DDoS attacks increases, but the net result is it only takes one attack to breach an organization’s defences. Findings suggest that cybercriminals are focused on taunting defences, probing network vulnerabilities and executing more targeted strikes, instead of making noise with a singular, large attack.

“Not only are hackers becoming craftier and more dangerous, but they’re also becoming more opportunistic,” said Nicolai Bezsonoff, Vice President, Neustar Security Solutions. “The importance of always-on vigilance and investment in DDoS security technology is essential for organizations looking to adapt and evolve their defences. Protecting an organization’s infrastructure and customer data against threats is paramount in the current digital landscape.”

Key findings from the report include:

Organizations have a lot to lose – even if attacked only once

  1. 92 percent of those attacked just once reported theft of intellectual property, customer data and/or financial assets and resources
  2. 89 percent acknowledged some form of associated activity, including data theft, dangerous ransomware, and network compromise with DDoS attacks
  3. 36 percent saw malware activation during DDoS attacks as part of multi-tactic assaults

Internet of Things (IoT) devices remain a tempting target for DDoS attacks

  1. 76 percent of organizations that have IoT devices in active operation were attacked
  2. Of those 76 percent, nearly one-third suffered network compromises or damage to physical equipment
  3. 40 percent of respondents are actively focused on finding ways to prevent IoT devices from becoming compromised

Attacks and breach activities were not contained to large organizations

  1. Over 50 percent of mid-sized organizations encountered an average of three breach incidents (malware, ransomware, virus, etc.)
  2. Mid-sized organizations were hit the hardest with 60 percent experiencing an attack
  3. On average, DDoS attacks caused organizations $4.3M in revenue generation risk

Organizations are continuing to make DDoS protection a budget priority, with layered defences and web application firewalls (WAFs) listed as a top investment. Respondents noted that on average their organizations have at least two components of DDoS protection that can include appliance hardware, cloud services, and hybrid deployments. Notably, protection against application layer threats has increased significantly with Web Application Firewall (WAF) solution deployments nearly tripling in the past year. Using WAF to protect the most exploited layer in the network stack reflects organizations drive for the right combination of defences to protect against growing concerns associated with DDoS attacks.

Top motivators for increased budget spend on DDoS protection include:

  • Preserving customer confidence and brand reputation
  • Prevention of associated attacks, including ransomware
  • Proactively strengthen existing protection

“Organizations need to continuously diversify their security strategy for DDoS – it’s no longer ‘good enough’ to accept a pre-packaged solution as the cornerstone of your security portfolio,” said Barrett Lyon, Vice President of Research and Development, Neustar Security Solutions. “Writing application code is difficult, but it is also fraught with security failings and attacker know this. Organizations are making investments in layered protection, including the deployments of WAF solutions, to level the playing field and decrease the time cybercriminals will have to execute a successful attack.”

Cybersecurity veteran Kirstjen Nielsen nominated as DHS secretary

DHS

The U.S. President Donald Trump nominated 45-year-old Deputy Chief of Staff Kirstjen Nielsen as the Secretary of the Department of Homeland Security. Nielsen will take over from Elaine Duke, the acting DHS secretary.

In the White House, Nielsen was responsible for carrying out White House Chief of Staff John Kelly’s orders on who gets access to the president. Both Trump and Kelly will keep a close watch on the DHS.

“She is the first nominee for this position to have previously worked within the Department of Homeland Security, having served there in two administrations, first as senior legislative policy director for Transportation and Security Administration under President George W. Bush and then as Department of Homeland Security Chief of Staff under President Trump. She also served as a corporate attorney and a congressional staff member”, the White House statement said. “The administration praised Nielsen for her “extensive professional experience” in homeland security policy, cybersecurity, critical infrastructure and emergency management.”

Having a reputation of being an “enforcer” and “no-nonsense leadership style”, Nielsen would immediately be given the task of helping coordinate the federal response to potential cyber attacks that target elections. Nielsen, a close and longtime aide of Kelly, is widely viewed as a competent, experienced and nonpartisan security professional.

It was reported that Kelly made a personal appeal to Trump for nominating Nielsen after the president reportedly rejected several contenders for the job. Before the elevation, Nielsen will have a hearing in front of several Republican-controlled Senate committees, and her appointment will then be voted on by the homeland security committee and the entire Senate.

Born on May 14, 1972, Nielsen has an experience in handling cybersecurity-related issues, as she has worked at a cyber-think-tank at George Washington University and is considered well-versed in some of the more technical missions at the department, such as sharing cyber threat information with the private sector. She is a former marine general and a lawyer.