Home Blog Page 394

Most Android phones prone to overlay attack: Researchers

PhantomLance Targets Android App Store to Spread Malware and Spyware, message encryption for Android

Palo Alto researchers have discovered a vulnerability that can affect all Android devices running on any version older than Oreo. The vulnerability allows the hackers to lock the device screen, reset the PIN, wipe the data, and prevent a user from uninstalling app by tricking him/her to click on a fake dialog box, asking permission. Google was informed about the vulnerability by Palo Alto on May 30, 2017.

Reporting about the discovery, the research team of Palo Alto Unit 42 said that the vulnerability allows for an overlay window attack by tricking the user to enable Android Accessibility Service and granting device administrator privilege to the attackers by changing what the victim sees on the display. The overlay is called the Toast and has several built-in abilities. The researchers also said that the existing Android version does not have any safeguards available to prevent a malicious overlay from gaining control over the device due to a missing permission and operation check. Though an overlay requires both, no such check is present for TYPE_TOAST as permission is automatically granted.

Unit 42 said, “The Toast overlay is typically used to display a quick message over all other apps. For example, a message indicating that an e-mail has been saved as a draft when a user navigates away without sending an e-mail. It naturally inherits all configuration options as for other windows types. However, our research has found using the Toast window as an overlay window allows an app to write over the interface of another App without requesting the SYSTEM_ALERT_WINDOW privilege this typically requires.”

Android version 7.1 comes with two layers of protection that include a timeout and use of only single overlay layer at a time. The researchers said that single-layer feature can be bypassed with a LooperThread which shows a continuous Toast window. Due to the continuous display, the timeout feature also gets confused as it cannot tell if any overlay window has been clicked.

A patch was released by Google with the Android Security Bulletin on September 5, to be installed by the users.

 

DOE announces $50M investment for cybersecurity infrastructure

Department of Energy

To support research and development for next generation security and mitigation tools, the United States Department of Energy (DOE) has announced awards of up to $50 million to DOE’s National Laboratories. With this initiative, the DOE aims to bolster the resilience, security, sustainability, and reliability of critical national infrastructure including oil, gas, and the electric grid for the coming generations.

“A resilient, reliable, and secure power grid is essential to the Nation’s security, economy, and the vital services that Americans depend on every day,” said Secretary of Energy Rick Perry. “As round-the-clock efforts continue to help communities recover from the devastation of Hurricanes Harvey and Irma, the need to continue strengthening and improving our electricity delivery system to withstand and recover from disruptions has become even more compelling. By leveraging the world-class innovation of the National Laboratories and their partners, this investment will keep us moving forward to create yet more real-world capabilities that the energy sector can put into practice to continue improving the resilience and security of the country’s critical energy infrastructure.”

There are seven Resilient Distribution Systems awards which will be rolled out through DOE’s Grid Modernization Laboratory Consortium (GMLC). These will “develop and validate innovative approaches to enhance the resilience of distribution systems – including microgrids – with high penetration of clean distributed energy resources (DER) and emerging grid technologies at regional scale.”  Project selections for this segment include: Grid Resilience and Intelligence Platform (GRIP), Resilient Alaskan Distribution System Improvements using Automation, Network Analysis, Control, and Energy Storage (RADIANCE), Increasing Distribution Resiliency using Flexible DER and Microgrid Assets Enabled by OpenFMB, Integration of Responsive Residential Loads into Distribution Management Systems, CleanStart-DERMS, Resilient Distribution Systems, and Laboratory Valuation Analysis Team.

Apart from these, the DOE has also announced 20 cybersecurity projects that “will enhance the reliability and resilience of the Nation’s electric grid and oil and natural gas infrastructure through innovative, scalable, and cost-effective research and development of cybersecurity solutions.” Six topic areas for the projects are: partnerships to reduce risk through vulnerability mitigation; identification of energy delivery system (EDS) equipment inadvertently exposed to the public internet to reduce the cybersecurity risk on the operational technology (OT) infrastructure, adapt to survive a cyber-incident and those have with verifiable trustworthiness; cybersecure communications for operating resilient grid architectures; and tools and technologies that enhance cybersecurity in the energy sector.

The DOE expects the projects to deliver credible information on the technical point, economic viability, and security of energy resources. The award amounts will be subject to Congressional appropriations.

Earlier this year, Senator Maria Cantwell (D-WA), along with 18 fellow Senate colleagues, wrote a wordy public letter dated June 22, 2017 had urged President Donald Trump to reverse the 32 percent cut to the Department of Energy’s cybersecurity budget citing concerns of Russian interference and ransomware attacks.  “These recent attacks are another sign that we must improve the cyber security of our energy networks. The Trump Administration has been dragging their feet on this urgent task-we need action now to keep our energy networks safe. I am calling on President Trump to reverse his harmful 32% cut to the Department Of Energy’s cyber security budget and lay out a comprehensive cybersecurity plan without further delay,” said Cantwell in response to the attacks,” wrote Cantwell.

Around the same time, the Federal Bureau of Investigation (FBI) and the Department of Homeland Security (DHS) had issued warnings to the energy companies being a target of cyberattacks. According to reports, suspected Russian hackers had intruded into American power plants. Reports suggested that hackers have been trying to penetrate into the energy facilities since May.

iOS 11 to make data extraction difficult for law enforcement agencies

Apple App Store, Apple vulnerabilities

In a move that may not please law enforcement agencies, Apple is looking to add security features to its upcoming operating system iOS 11 for protecting owners’ privacy. According to the security researchers and forensic analysts who have seen the developer version of the latest OS, the features are designed in such a way that any data extraction process will be difficult without the owner’s approval or the phone’s six-digit passcode.

Accessing data will be difficult even if a device is confiscated in an unlocked state and connected to an unknown computer as the device will ask for permission before “trusting” the computer. The new iOS would require a touchID sensor along with the six-digit passcode for investigators to access the data, unlike the previous version where only the TouchID sensor was enough to allow someone to upload the device data on a computer.

Nicholas Weaver, a security researcher at the International Computer Science Institute at the University of California at Berkeley, told Wired, “this will be a major pain in the a**. Apple wants to live in a world where the phone in your hands is super valuable, but in anyone else’s hands is a brick…If that messes up police’s and customs’ forensic dumps? So what. The benefits outweigh the harm.”

The new operating system will also have S.O.S. mode, a feature that will launch a new lock screen after the user taps the phone’s home button five times. The new lock screen will come with options to make an emergency call or will show owner’s emergency medical information.

Equifax breach may be caused due to Apache Struts vulnerability

Equifax breach

The recent data breach suffered by Equifax seems to be due to vulnerability in the open-source Apache Struts Framework, as suggested by a Baird Equity Research report. Equifax has neither publicly confirmed nor denied that the flaw in Apache Struts is the root cause of the incident, though the company has admitted that a Web application vulnerability may be the reason behind the breach.

The Apache Software Foundation said that Struts may have been the reason for the breach that potentially compromised sensitive information for 143 million American consumers. In a statement, René Gielen, vice president of Apache Struts, said, “We are sorry to hear the news that Equifax suffered from a security breach and information disclosure incident that was potentially carried out by exploiting a vulnerability in the Apache Struts Web Framework. At this point in time, it is not clear which Struts vulnerability would have been utilized if any.

Equifax discovered the breach on July 29, 2017, but had waited until after the close of trading nearly six weeks later to disclose the breach to consumers and Equifax’s investors. As part of its investigation of this application vulnerability, Equifax  identified unauthorized access to limited personal information for certain UK and Canadian residents. The company found no evidence that personal information of consumers in any other country has been impacted.

Earlier this week, it was reported that shareholder Rights Law Firm Johnson Fistel, LLP (formerly Johnson & Weaver, LLP) is investigating potential violations of the federal securities laws by Equifax Inc. and certain of its officers.

Spanish data privacy regulator imposes $1.4 million on Facebook

Facebook copyright complaint

Spanish data privacy regulator AEPD has imposed a fine of 1.2 million euros ($1.44 million) on Facebook for failing to protect the users’ data that is being accessed by advertisers. AEPD said that the personal data of users collected by Facebook “does not adequately collect the consent of either its users or nonusers, which constitutes a serious infringement.”

AEPD, an agency which enforces Organic Law on Data Protection (LOPD), said that the data collected by Facebook include political ideology, sex, religious beliefs, personal tastes, and browsing history, but the users remain unaware of the purpose of the data collected. Facebook is also accused of using cookies to track user activity on the Web, including non-Facebook sites. Additionally, the agency claims that the users’ site navigation information and personal data are retained by Facebook beyond the period of its stated purpose.

“When a social network user has deleted his account and requests the deletion of the information, Facebook still keeps the information for more than 17 months, through a deleted account cookie. Therefore, the personal data of the users is not canceled in full when it is no longer useful for the purpose for which it was collected, nor when the user explicitly requests its removal,” AEPD said.

AEPD further claims that the privacy policy of Facebook contains “generic and unclear expressions” which can be accessed by a user after many levels of navigation. Saying that Facebook should obtain “unequivocal, specific and informed consent” from the users, the enforcement agency found one “very serious” and two “serious” issues of LOPD. The regulatory body fined Facebook €600,000 for the first incident and €300,000 each for the second.

Earlier this year, Facebook was found guilty of not following data regulation norms on several occasions and was penalized by multiple regulatory bodies. European Commission imposed a fine of $122 million on the company for not providing correct information during the purchase of WhatsApp in 2014. The Italian authority and the French data protection regulators had also slapped a fine of €3 million and €150,000, respectively, for violating rules regarding consumer data. Moreover, an investigation into Facebook’s privacy practices is ongoing in Germany.

Honeywell and Lear collaborate on automotive cybersecurity software solutions

Raytheon Partners IronNet for Enhanced Protection for OT/IT Systems

Honeywell, a Fortune 100 diversified technology and manufacturing company, and Lear Corporation, a supplier of automotive seating systems and electrical distribution systems, recently announced the two companies are collaborating to provide automotive software technology and infrastructure solutions to address threats associated with emerging connected and autonomous vehicle development. The announcement was made at the 67th Annual IAA Cars event in Frankfurt.

As suppliers to the automotive industry, Honeywell and Lear are focused on pairing Honeywell’s intrusion detection technology software and security operations centers with Lear’s automotive electrical distribution systems and connected gateway expertise. As the industry increases system communications within the vehicle and external connectivity via cellular and satellite communications, the collaborative effort between Honeywell and Lear seeks to provide automakers with an architecture to address vehicle prognostics and help ensure passenger vehicle safety and security.

The two companies are working under a non-exclusive agreement to develop an effective system to identify and validate software commands and data generated by more than 100 million lines of code governing modern vehicle operation. Honeywell’s software and global security centers monitor in-vehicle network communications. Lear’s electrical gateways and security modules can be an effective toolset to detect and report anomalies preceding a mechanical failure or intentional hack of the vehicle. Captured data can be transmitted in either real time or via a scheduled download to Honeywell security centers for analysis and remediation.

“There are more than a dozen clearly defined attack surfaces which can provide points of entry for hacking into a passenger vehicle, and the number is growing fast,” said Olivier Rabiller, Honeywell Transportation Systems president and CEO. “Honeywell is a long-time leader in the development of software that enables safety and cybersecurity solutions for a number of industries, and we are now extending this knowledge to connected and autonomous vehicle development. Our software architecture is based upon best practices we have already developed during the past 30 years for aerospace, military, defense and critical industrial facility security. Automakers can count on us to support the near-term and long-term future of the industry.”

“Lear is focused on delivering cutting edge, secure vehicle-network-integrated connectivity solutions, built on our heritage as an innovation leader in vehicle electrical architectures,” said Frank Orsini, Lear Corporation senior vice president and president of Lear E-Systems. “Our complete capabilities in connectivity, gateway modules, and vehicle networking are helping to enable secure connected cars for our OEM customers.  Collaborating with Honeywell is one important aspect of our strategy to create and aggregate the industries best security solutions paired with our leading expertise in connectivity and vehicle networking.”

SEBI boosts cyber infrastructure, on lookout for cybersecurity experts

SEBI cybersecurity CISOMAG

Securities and Exchange Board of India (SEBI) is mulling on bolstering its cybersecurity infrastructure as a preventive measure against all vectors of cyber attacks. This comes in the wake of several cyber attacks across the globe and the apparent scenario where SEBI might be a potential target. It is also mulling on increasing its cybersecurity workforce. SEBI has already instructed stock exchanges and other organizations to watch out for threats and attacks.

“A robust cybersecurity and cyber resilience framework should identify the plausible sources of operational risk, both internal and external, and mitigate the impact through the use of appropriate systems, policies, procedures, and controls,” stated SEBI in a statement. “Systems should be designed to ensure a high degree of security and operational reliability and should have adequate, scalable capacity. Business continuity management should aim for timely recovery of operations and fulfilment of its obligation in the event of cyber attack.”

According to a PTI report, “The regulator plans to hire four Grade A officers in its information technology stream and wants the aspirants to have extensive experience in cyber security space (…) who have knowledge of global best practices in the area of cyber security and information technology and are familiar with compliance requirements with cyber security policies”

SEBI would also be roping in an advisor for cybersecurity and other IT related initiatives who will be responsible for strengthening its regulatory policy framework in this space.

The experts would be responsible for the installing firewalls, encrypting data, developing the cybersecurity infrastructure, and ensuring compliance with the cybersecurity policies. They would also be engaged in conducting penetration testing and mock drills.

From the compliance perspective, SEBI wants the aspirants to be familiar with internal policies on IT deployment, implementation, and standardizing procedures. The advisor would also be instrumental in strategizing IT policies and preparing a five-year roadmap.

 

Security flaw discovered in German voting software prior to general election

Germany cybersecurity CISOMAG

In a recent release, German hacker association Chaos Computer Club (CCC) claimed that the PC-Wahl version 10 software, used in Germany during elections to count and distribute voting results, contains serious vulnerabilities. The group said that the attackers can secretly modify vote totals before they are reported to electoral officers. The CCC said, “The analysis shows a host of problems and security holes, to an extent where public trust in the correct tabulation of votes is at stake.” Germany is due for its parliamentary elections on September 24.

According to the press release, CCC found that the PC-Wahl software does not adhere to even basic principles of IT security. The entire voting system can be compromised in a single click due to a broken software update mechanism. Also, insufficient security measures on the update server allow the hackers to gain control over the attacked server and distribute harmful updates to its users. CCC published proof-of-concept attack tools including source code on GitHub to support their claim.

The CCC spokesperson Linus Neumann, said, “The amount of vulnerabilities and their severity exceeded our worst expectations. A whole chain of serious flaws, from the update server, via the software itself through to the election results to be exported allows for us to demonstrate three practical attack scenarios in one.”

Reportedly, some of the vulnerabilities are being fixed after the CCC’s report.

Resolve Systems appoints Dan Sibille as vice president

Resolve Systems appoints Dan Sibille

PRWEB: Resolve Systems, recently announced that Dan Sibille, a cybersecurity and technology channel veteran with 25+ years’ experience and accomplishment, has joined the company as Vice President of Global Channels & Strategic Alliances. Resolve Systems provides a single platform for enterprise-wide incident response, automation and process orchestration for Security Operations, IT Operations, Network Operations and service desk teams.

“Dan has an impressive track record of accelerating channel development for emerging security companies which uniquely qualifies him for this strategic position,” said Martin Savitt, CEO of Resolve Systems. “His background and expertise in designing global channel go-to-market strategies, including solution sales, support, marketing, and partner programs, is the perfect fit for Resolve Systems. Dan’s channel plan is going to accelerate our growth as well as allow us to expand and enhance this critical part of our business.”

Dan Sibille joins Resolve Systems with extensive channel experience. Dan comes from TrapX where he led their worldwide channel efforts. Before that, he held channel leadership roles at several global cybersecurity companies including Cisco, Lancope, WatchGuard, and Internet Security Systems where he also created and launched innovative partner programs to capitalize on the Enterprise and SMB markets.

His expertise in channel development has been proven through his success in building a global array of best in class security partners, partner programs, and channel teams. He and his teams have also received numerous “5-Star Partner Program” awards by Computer Reseller News (CRN).

“I’m thrilled to join Resolve Systems,” said Mr. Sibille. “CISOs and CIOs require seamless integration of advanced technologies to resolve Security, Network and IT incidents. I look forward to expanding our global partner community and enabling our channel to exceed the demands of our end customers. My ultimate goal is to cultivate a robust partner community for successful customer experiences and to accelerate our company growth.”

EU calls for increase in spending, diplomacy to boost cybersecurity

EU cybersecurity CISOMAG

Looking to boost cybersecurity in the European Union, European Commission has laid down several proposals in its upcoming report. Some of the measures include increasing investment in technology, setting more stringent consumer safeguards, and improving diplomacy. EU also stressed on the importance of greater national and law enforcement cooperation to counter cyber attacks as well as increasing technical capabilities for cyber attack investigation.

EU has proposed injecting funds as investment to strengthen regional cyber industry. The prior plan to spend 1.8 billion Euros by 2020 was made in 2016, which the report calls as a “first step.”

Citing private and public estimates, the report said the impact of cybercrime saw a fivefold increase between 2013 and 2017, and could rise another four times in the next two years. According to Europol, the total losses due to the cybercrime stand at 265 billion euros.

The report emphasizes on developing a European encryption capability using quantum technologies for secure digital identification systems, intellectual property protections, and safe e-commerce. For the same, EU aims to establish a “duty of care” principle for vendor product and software development. It also aims to lay down the proposals to give law enforcers cross-border access to electronic evidence in 2018.

The creation of a European Cybersecurity Research and Competence Centre was also proposed in the report as a part of the plan to strengthen existing European Union Agency for Network and Information Security. A policy framework that will bring the EU, member states, industry, as well as citizens together for providing better resilience to cyber attacks.

“The framework constitutes a first step in developing signaling and reactive capacities at EU and member-state level with the aim of influencing the behavior of potential aggressors,” the report said.