Home Blog Page 393

Researchers unveil dual spam campaign with Locky and FakeGlobe

Dual attack

Researchers at Trend Micro have recently discovered a large spam campaign in which cyber criminals use two types of ransomware alternately to force victims to pay twice or lose all their data permanently. The ransomware rotated during the campaign include an updated versions of Locky along with FakeGlobe.

The researchers found that the attack is carried out by sending emails with an embedded link and attachment disguised as bills or invoices to people during their work hours. The invoices contain a script similar to the one inside archive downloaded from the link. However, the link comprises different binaries and have connectivity to different URLs for downloads, leading to the download of Locky and FakeGlobe ransomware. The two ransomware would then re-encrypt the victims’ files, forcing them to pay twice or lose their data. The campaign affected more than 70 countries, with Japan, China, and the United States being the major victims.

Speaking about the attack, Chief Cybersecurity Officer at Trend Micro Ed Cabrera said in statement to Dark Reading, “When it comes to these types of attacks – ransomware attacks – it’s all about speed and impact; something that can shock and awe. They want to be able to attack as many individuals and organizations as they possibly can, and do it fairly quickly while having the biggest impact.”

Cabrera also said that the recent attack was launched with an intention of achieving financial gains. He said, “The intended outcome is to really scare their victims into believing there’s no other option than paying. The shock value is to improve their financial gain, to improve the odds of them being paid … if they overwhelm their intended victims, they believe they have a better chance.”

Detected in 2016, Locky spreads by showing links to fake dropbox websites. In a recent study by researchers at Google, Chainalysis, UC San Diego, and the NYU Tandom School of Engineering, the ransomware has so far accounted for $7 million from the time it was detected. On the other hand, Fakeglobe, detected in 2017, is distributed through spam emails posing as legitimate invoices or automated responses.

BT opens new cybersecurity hub in Australia

BT

Telecommunications provider BT and the New South Wales government recently announced the opening of a new global security hub in Sydney, Australia. The new facility, which is BT’s first R&D facility outside of the UK, will help in research and development with regards to key areas such as cybersecurity, machine learning, cloud computing, big data engineering, data science analytics and visualization among others.

“We are thrilled at this exciting new opportunity to tap into local cyber security skills,” Mark Hughes, CEO of BT Security, said in a statement. “Never before has cyber security been more important and we see potential for growth in New South Wales, Australia and further afield. The hub will be a cornerstone of our global cyber security capabilities and help us stay ahead in this fast moving space.”

To build the center, BT invested AU$2 million ($1.6 million) whereas the New South Wales government invested AU$1.67 ($1.34 million). It will create 172 new jobs over the next five years and will be among BT’s 14 global security operations centers.

“This cutting edge operation will help keep Australia’s best cyber security talent here in NSW while nurturing our next generation of specialists to ensure we remain a regional leader in this fast growing industry. As well as creating 172 jobs, including 38 jobs for skilled graduates over the next five years, BT will also make a $2 million investment in capital infrastructure and a further multi-million dollar investment to employ cyber security specialists at the hub,” said Matt Kean, minister for innovation.

US Senate bans Kaspersky products for use by federal agencies

Kaspersky

The Senate has barred the federal agencies from using products from Kaspersky Lab. The Senate voted on Monday to ban the Moscow-based cyber security firm Kaspersky Lab, citing concerns the company may be linked to Kremlin and Russian spy agencies. The vote is the latest in a series of setbacks for Kaspersky Lab. On Wednesday, the U.S. Department of Homeland Security banned the Kaspersky products for use by federal agencies.

The directive issued by DHS instructs federal agencies to identify within 30 days if they are using any Kaspersky products. The products need to be removed from all information systems within 90 days.  “The department is concerned about the ties between certain Kaspersky officials and Russian intelligence and other government agencies,” the directive said. “The risk that the Russian government — whether acting on its own or in collaboration with Kaspersky — could capitalize on access provided by Kaspersky products (in order) to compromise federal information and information systems directly implicates US national security.”

Kaspersky Lab in a statement said that it is very disappointed to be on the wrong side of the verdict by DHS. It maintained its stance that “it does not have unethical ties or affiliations with any government, including Russia.” It went on to say, “No credible evidence has been presented publicly by anyone or any organization as the accusations are based on false allegations and inaccurate assumptions, including claims about the impact of Russian regulations and policies on the company.”  The company has an opportunity to respond or mitigate the department’s concerns.

There were regular calls from several senators to ban the products supplied by Kaspersky Lab. Senator Jeanne Shaheen pressed for a federal government-wide ban of all Kaspersky Lab products in U.S. two weeks ago. According to a statement released from Shaheen, the company have been involving in malicious activities, with founder of Kaspersky, Eugene Kaspersky, instructing his staff to work on a secret Project “per a big request on the Lubyanka side,” a reference to the F.S.B.’s Moscow offices.

New York governor wants credit-reporting firms to comply with cybersecurity regulations

Andrew Cuomo

New York Governor Andrew Cuomo recently said that all credit-reporting firms should comply with the state’s cybersecurity regulations. The statement came in the wake of the massive Equifax hack that potentially compromised sensitive information for 143 million American consumers.

The Democrat said in a statement that he has directed the state Department of Financial Services to issue new regulations requiring credit reporting agencies to register in New York for the first time and to comply with the state’s cybersecurity standards. He said consumer credit reporting agencies operating in New York will be required to register annually with Department of Financial Services by Feb. 1, 2018, and by Feb. 1 of each year afterward. The DFS would have the authority to bar credit-reporting agencies from doing business in New York if the state found they failed to comply, the governor said.

“The Equifax breach was a wake-up call,” Cuomo said. “And with this action, New York is raising the bar for consumer protections that we hope will be replicated across the nation.”

After the close of trading on September 7, 2017, Equifax disclosed that its databases had been breached between May and June 2017, that hackers had gained access to Company data that potentially compromised sensitive information for 143 million American consumers, including Social Security numbers, credit card numbers and driver’s license numbers.  Equifax discovered the breach on July 29, 2017, but had waited until after the close of trading nearly six weeks later to disclose the breach to consumers and Equifax’s investors.

The breach opened a floodgate of lawsuits against Equifax. Murphy, Falcon & Murphy filed a national class action lawsuit on behalf of over 143 million consumers whose personal information, social security numbers, birth dates, names, addresses, driver’s license information and credit loan balances, were stolen. Scott Cole, class action veteran and founder of Oakland-based Scott Cole & Associates, also announced the filing of a class action lawsuit against Equifax for “negligence, violations of fair credit reporting and deceptive business practices.” The breach also led to the ouster of the company’s Chief Information Officer and Chief Security Officer.

 

Singapore to allocate $1.1 million to train cybersecurity professionals

MICA Singapore

Yaacob Ibrahim, Minister for Communications and Information, recently announced that Singapore will allocate S$1.5 million ($1.1 million) to train incident responders and operators to tackle cyber threats. The move is a part of ASEAN Cyber Capacity Building Program (ACCP) that endeavors to develop technical, policy and strategy-building capabilities within ASEAN member states.

The announcement was made at the opening ceremony of the Asean Ministerial Conference on Cybersecurity. Ibrahim said that in a bid to collaborate on cybersecurity and workforce development, the Cyber Security Agency of Singapore (CSA) also plans to sign a memorandum of understanding (MOU) with Information Systems Audit and Control Association (ISACA), a leading professional body with members in 188 countries. Also, up to 18 candidates from ASEAN member states would be trained in incident detection, threat containment, service recovery, and forensics as the part of ASEAN Cybersecurity Industrial Attachment Program.

In his speech, the minister stressed on three following factors to ensure a safe cyberspace in the ASEAN region:

  • A strong domestic cybersecurity structure
  • Collaboration among ASEAN states to minimize cyber risks
  • Strong international partnerships to combat cyber threats

“Hopefully we will succeed, and look back in 2067 to this day when our collective efforts to tackle cybersecurity paved the way for a sustained 50 years of growth and development,” he said.

Singapore government recently earmarked as much as $528 million of its tech budget, representing 22 percent of the total, to cybersecurity programs. The four keys to the plan were to strengthen information infrastructure, mobilize efforts to counter cyber threats, develop a cybersecurity ecosystem that included a skilled workforce and strong research collaborations, and forging international partnerships.

Vevo hacked; 3.12TB data compromised

Vevo breach

In another hack by OurMine, the notorious hacker group broke into the servers of entertainment company Vevo and released approximately 3.12TB of its internal documents and video content. The group later removed the content at Vevo’s request.

Vevo confirmed the breach in a statement. “We can confirm that Vevo experienced a data breach as a result of a phishing scam via Linkedin. We have addressed the issue and are investigating the extent of exposure,” a Vevo spokesperson told Mashable. Vevo is jointly owned by Universal Music Group, Sony Music Entertainment, Warner Music Group, Abu Dhabi Media, and Alphabet (Google’s parent).

OurMine released a number of documents, including promotional materials, videos, weekly music charts, and office documents. Some sensitive information was also compromised. The group later said that “We deleted the files because of a request from VEVO.” Vevo said they are still investigating the impact of the breach.

OurMine has been involved in a number of high-profile breaches over the past few years. Two weeks ago, the group hacked WikiLeaks, the data-leaking site owned by Julian Assange. The users of the website were redirected to a page that claimed the attack was a response to a challenge from WikiLeaks to hack them. It also breached the Twitter account of the Real Madrid Club de Futbol as well as the social media handles of HBO.

US Senator cites concerns over Apple’s Face ID and privacy

Apple Notarization

Yet again another set of Apple phones are rolling out and the world can’t seem to stop talking about it. But the ‘X’ takes the prize here. The flagship phone from the stables of Apple is dubbed as the iPhone X and sports a Face ID or facial recognition feature in simpler words. Apple even took a dig at Samsung at the launch event differentiating the face recognition feature from Samsung’s which can simply be hacked by a photograph of the owner. The makers stood to their ground elaborating that the facial recognition of Apple Face ID relies on sophisticated technology and deploys a machine learning chip to accurately map and recognize a face. “iPhone X is the future of the smartphone. It is packed with incredible new technologies, like the innovative TrueDepth camera system, beautiful Super Retina display and super fast A11 Bionic chip with neural engine,” said Philip Schiller, Apple’s senior vice president of Worldwide Marketing at the launch. “iPhone X enables fluid new user experiences — from unlocking your iPhone with Face ID to playing immersive AR games, to sharing Animoji in Messages — it is the beginning of the next ten years for iPhone.”  But the assertion was simply not enough.

The United States Senator Al Franken has written to Apple CEO Tim Cook citing concerns on privacy and security of the users.  Franken is a ranking member of the Senate Judiciary Subcommittee on Privacy, Technology and the Law. In a wordy letter addressed to Tim Cook, he pointed out, “While details on the device and its reliance on facial recognition technology are still emerging, I am encouraged by the steps that Apple states it has taken to implement the system responsibly.” He continues, “However, substantial questions remain about how Face ID will impact iPhone users’ privacy and security, and whether the technology will perform equally well on different groups of people. To offer clarity to the millions of Americans who use your products, I ask that you provide more information on how the company has processed these issues internally, as well as any additional steps that it intends to take to protect its users.”

Apple in its launch pointed out how Face ID is more secure than biometrics. According to Apple, “there’s a one in a million chance someone else’s face will fool Face ID.”

According to AppleInsider, “Face ID projects more than 30,000 invisible IR dots. The IR image and dot pattern are pushed through neural networks to create a mathematical model of your face and send the data to the secure enclave to confirm a match while adapting to physical changes in appearance over time.”

Franken cited concerns over the storage of the Face ID faceprint as well. And if the prints can be extracted from the device. He also asked Apple if they intended to store data on offsite servers.

Apple its press release had stated, “All saved facial information is protected by the secure enclave to keep data extremely secure, while all of the processing is done on-device and not in the cloud to protect user privacy”. Franken also asked Cook how the company would respond to law enforcement requests to access ‘faceprint’ data or the Face ID system itself. Franken has requested Cook to respond by October 13, 2017.

FA to ramp up FIFA World Cup cybersecurity over hacking concerns

FIFA world cup

To address the threats of hacking and breach of sensitive information, the English Football Association has decided to bolster the cybersecurity prior to the 2018 FIFA World Cup in Russia. The FA wrote to FIFA expressing its concerns about IT security and, particularly, the leak of its own correspondence with the governing body.

According to reports, the FA is already taking steps to boost its cybersecurity practices by strengthening firewalls and introducing encrypted passwords for websites and devices. The soccer board also asked the players to adhere to strict guidelines regarding social media. Placed at the top of their World Cup qualifying group, England plays Slovenia on October 5 at Wembley, London.

Responding to FA’s letter, FIFA spokesperson said, “FIFA has informed the FA that [it] remains committed to preventing security attacks in general and that, with respect to the Fancy Bears attack in particular, it is presently investigating the incident to ascertain whether FIFA’s infrastructure was compromised.”

The spokesperson further added, “Such investigation is still ongoing. For the purposes of computer security in general, FIFA is itself relying on expert advice from third parties. It is for this reason that Fifa cannot and does not provide any computer security advice to third parties.”

FA had fallen victim to data theft last month in an attack by the Fancy Bears group. Releasing a series of leaked documents, the Russian hacking group claimed that more than 150 players had not cleared drug tests in 2015. The hackers also claimed the Ex-Premier League players Carlos Tevez, Dirk Kuyt, and Gabriel Heinze were cleared to use banned medicines at the 2010 World Cup.

 

8.2 billion devices worldwide at risk of remote attacks

Flaw in Bluetooth Devices

Nearly 8.2 billion devices are at risk, globally, from remote attack vectors like device take over and man-in-the-middle (MITM), et al. According to researchers from Armis Labs, the Bluetooth vulnerability is on all devices running iOS, Windows, Android, and even Linux processors. Dubbed as BlueBorne, “as it spread through the air (airborne) and attacks devices via Bluetooth. Armis has also disclosed eight related zero-day vulnerabilities, four of which are classified as critical. BlueBorne allows attackers to take control of devices, access corporate data and networks, penetrate secure “air-gapped” networks, and spread malware laterally to adjacent devices. Armis reported these vulnerabilities to the responsible actors, and is working with them as patches are being identified and released,” suggests a statement released from Armis Labs.

The attack works similar to the recently discovered Broadcom Wi-Fi chip by Project Zero and Exodus giving attackers complete access and controls from the beginning.  But unlike WiFi, Bluetooth offers a wider attacker surface and thus, contains a lot more vulnerabilities.

What’s worse is that the attack doesn’t require targeted devices to be paired, or even be discoverable. The attack vector subterfuges as a Bluetooth device and exploits weaknesses in the protocol to deploy malicious code. “The BlueBorne attack vector requires no user interaction, is compatible with all software versions, and does not require any preconditions or configurations aside of the Bluetooth is active. Unlike the common misconception, Bluetooth enabled devices are constantly searching for incoming connections from any devices, and not only those they have been paired with. This means a Bluetooth connection can be established without pairing the devices at all. This makes BlueBorne one of the broadest potential attacks found in recent years, and allows an attacker to strike completely undetected.”

iPhones devices running iOS 10 are immune to the attack vector. Microsoft released a patch to fix the bug for all the computers since Windows Vista which was vulnerable to “Bluetooth Pineapple”. Android devices prior to Kit Kat are still vulnerable. Google has issued a patch for Nougat and Marshmallow and has notified its partners.

“Current security measures, including endpoint protection, mobile data management, firewalls, and network security solution are not designed to identify these type of attacks, and related vulnerabilities and exploits, as their main focus is to block attacks that can spread via IP connections,” stated Armis Labs. “New solutions are needed to address the new airborne attack vector, especially those that make air gapping irrelevant. Additionally, there will need to be more attention and research as new protocols are using for consumers and businesses alike. With the large number of desktop, mobile, and IoT devices only increasing, it is critical we can ensure these types of vulnerabilities are not exploited.”

EC-Council announces World’s First Fully Proctored Hands-On Penetration Testing Exam

EC-Council

EC-Council will be launching a fully-proctored Licensed Penetration Tester (LPT) certification at the upcoming flagship event, Hacker Halted, 2017. The new LPT (Master) certification exam is the first globally accepted, hands-on penetration testing certification exam administered in a fully proctored environment.

Penetration testing professionals around the world will be able validate their skills in this new exam format launched by EC-Council. The new LPT (Master) certification exam will be delivered as a secure, fully-proctored, live certification test that can be taken anytime, anywhere by busy professionals.

“With the increase in the sophistication of cyber-attacks and with ever growing security needs, today’s digital enterprises are looking for experts that have proven abilities to function as competent penetration testers in order to secure their operations,” commented Jay Bavisi, the president and CEO of EC-Council. “The fully proctored, hands-on LPT (Master) certification exam combines effectiveness with convenience to deliver a highest standard of exam that enables the candidates to demonstrate expertise in applying their skills in a hands-on environment.”

The exam provides a level playing field where candidates are challenged to prove their skills as expert-level penetration testers. “In the real world, penetration testers go through a strenuous, arduous and laborious process to keep their clients and organizations secure. This exam is meant to mimic the real-world environment and is meant to stress, burden and ardently push the candidates to their limits to test their actual abilities in penetration testing,” Bavisi added.

The new LPT (Master) certification is the crown jewel of the EC-Council penetration testing track. It challenges candidates through a grueling 18 hours of hands-on exam categorized into three practical tests for six hour intervals, each of which provide a multidisciplinary approach for targeting and compromising high security environments. Upon completion of the exam, candidates will have to demonstrate an advanced understanding of testing modern infrastructures by completing a professional penetration test report to be evaluated by EC-Council experts for completeness and professionalism.