Home Blog Page 407

Invisible ‘cloak and’ a bloody ‘dagger’

Invisible-cloak-and-a-bloody-dagger

Researchers at Georgia Institute of Technology have discovered a new class of android vulnerability. Dubbed as ‘Cloak and dagger’, the new vulnerability affects android devices including the latest version of Nougat (7.1.2). According to the researchers, the attacks allow a malicious app to completely control the UI feedback loop and take over the device – without giving the user a chance to notice the malicious activity.

The attacks have the capability of affecting both BIND_ACCESSIBILITY_SERVICE (“a11y”) and SYSTEM_ALERT_WINDOW (“draw on top”) functions. If the app reaches the phone through the Play Store, the user is not notified about permissions, and it can succeed without being granted any permission. According to Georgia Tech team, the attacks can vary from capturing passwords or even extracting contacts.

Google has reported the attack method which are hidden within pirated apps.

Winston Bond, EMEA technical director at application security outfit Arxan Technologies, while talking to The Register said: “The discovery of the latest ‘cloak and dagger’ threat facing Android devices demonstrates just how dangerous corrupted or malicious fake applications can be.

“Users have traditionally been told they will be safe as long as they only download apps from official sources and don’t pirate software, but we have increasingly seen cases of malicious apps being downloaded from within app stores or official websites.

“Developers can no longer rely on the ‘walled garden’ approach of app stores to protect their users from malicious copies of their apps, and need to proactively defend their software from criminals seeking to tamper with its code and turn it into a weapon.”

After face recognition, now iris scanner of Samsung S8 hacked

iris-scanner

Seems like even 2017 isn’t that great for Samsung. Its flagship phones have always been marred by different controversies, be it exploding batteries, or hacks on advanced security features.
The new S8 comes loaded with a slew of safety features, facial recognition, iris scan, etc., to name a few. While hacker had staged a hack of face recognition using a photograph of the user, the iris scan also didn’t fare that well. While Samsung describes the it as ‘airtight’, the advances biometrics feature was hacked using a simple technique.

All the researchers at Chaos Computer Club needed was a picture of the eye and a pair of contact lenses.

The researchers first registered a volunteer’s eyes using the iris scanner. They then took a photograph of the volunteer’s eyes with infra-red night vision settings on a digital camera. In the next step, they printed the photograph of the eyes and placed a contact lens over it. And lo, the biometrics enabled smart security feature was hacked. As the trick bypassed the security test.
The research team also posted a video of the hack using the false eye, which is now trending.

According to Samsung, the iris-scanning technology has undergone rigorous testing to prevent any security compromise. “If there is a potential vulnerability or the advent of a new method that challenges our efforts to ensure security at any time, we will respond as quickly as possible to resolve the issue. The discovery was another reminder that biometrics is not a silver bullet”, security expert Ken Munro said, while talking to BBC.

He continued stating that he personally prefers using fingerprints over iris scanners considering that your fingers are already holding the phone. Fingerprints and a secret number are the best option currently.

Ironically, Samsung has told the BBC it was “aware of the issue”. But haven’t stated anything more. Until then, this is just a heads-up for the S8 owners.

NEC manufactures hacker-proof earbuds

NEC-manufactures

NEC Corporation announced the development of a prototype “hearable device” (earphone device) user authentication technology, aiming to achieve new forms of convenient, safe and secure computing.

Security and safety are primary concerns when making use of any product or service. In recent years, as computers and smartphones have become more essential to daily life, reports of losses from leaked passwords and accidents related to smartphone use have become increasingly common. NEC’s hearable device user authentication technology helps reduce these risks by providing an additional layer of personalized security that allows users to devote greater attention to their surroundings.

The device is equipped with NEC’s unique otoacoustic authentication technology, which recognizes the characteristics of a user’s ear in order to enable hands-free authentication of an individual. This enables users to safely and securely activate their computing devices, without distracting their attention to key in a password.

In addition, the prototype’s motion sensor can be used to estimate user locations, even in indoor environments where GPS signals are obstructed. This can help provide guidance to users who become lost in large facilities, such as shopping malls or airports.

Moreover, since the device is situated in a user’s ear, it is subject to less shaking and noise when compared to wearable devices worn around the wrist or neck, enabling it to reliably obtain information. This also means it can recognize the orientation of a user’s face, a change in posture, or activities such as walking or running. In the future, it is expected to track pulse rates and other biometric information.

This authentication device easily connects to a smartphone or other computing devices via BLE (Bluetooth Low Energy) in order to access the Internet and to take advantage of a wide range of services, including map sites for city guidance. Moreover, the device consists of a microphone, speaker, and a 9-axis motion sensor, which is equipped with acceleration, gyroscope, and geomagnetic sensors.

In order to promote the development of a wide range of services for the device, NEC will publicly provide application programming interfaces (API) for its otoacoustic authentication technology and indoor positioning technology, in addition to providing device manufacturers with design specifications for the hearable device prototype.

“NEC is aiming to commercialize hearable platform services that combine individual authentication, indoor positioning, acoustic AR (augmented reality), vital sensing and other technologies by the end of 2018,” said Tomonori Kumagai, General Manager, Business Development Division, NEC Corporation. “Going forward, NEC will accelerate trials in collaboration with service providers and device manufacturers, while proposing new approaches to computing that utilize these technologies.”

98% victims of WannaCry are Windows 7 users

wannacry-windows

The most common Windows is also the worst hit by the ransomware WannaCry attack. According to a research published by Kaspersky Lab, over 98 percent of WannaCry victims were running versions of Microsoft Windows 7 OS.

Even in these, the worst hit lot were among the users running the 64-bit edition of Windows 7. This was followed by users running OS versions like the Windows 2008 R2 and Windows 10.

This comes as a stark contrast to the belief that WannaCry majorly hit Windows XP machines. According to Costin Raiu, director of Global Research and Analysis Team at Kaspersky Lab, the count among in Windows XP is insignificant.

WannaCry apparently used an SMB worm that spread on its own on computers that ran vulnerable SMB services. The SMB worm was powered by an exploit called Eternal Blue, which was part of hacking tools that were kept in the stables of NSA until the hacker group Shadow Brokers stole them in April 2017.

Early analysis had revealed that the worm could run on OS ranging from Windows XP to Windows 8.1 to Windows Server 2012. But during the ransomware outbreak it was found that the worm could run smoothly on Windows 7.

While we are talking, the modules of the ransomware worm are searching for newer victims, with the last tally of 416,989 and counting. Gladly not many had to pay heed to the hackers as the payload of the ransomware was defanged by the young Brit researcher.

Microsoft builds customized Windows 10 for China

Microsoft-China

China’s obsession with censorship and paranoia while adopting foreign technology is known to the whole world. The new cybersecurity law also mandates a safe and stringent architecture. This is one of the reasons why technology giant Microsoft had to push for a customized version of the Windows for the country that it has just released. The custom version of Windows 10 is ready for Chinese government agencies to use.

China has been making way with a customized Windows XP for quite long already. Also, it is one country which has the maximum number of pirated versions of Microsoft OS suite, aggregating to almost 70 percent of its population.

The new customized Windows 10 suite is based on the existing Windows 10 Enterprise Edition which is loaded with numerous security, deployment, identity, and management features that enterprises.

“The China Government Edition will use these manageability features to remove features that are not needed by Chinese government employees like OneDrive, to manage all telemetry and updates, and to enable the government to use its own encryption algorithms within its computer systems,” stated Terry Myerson, Executive Vice President, Windows and Devices Group, in a blog post.

“Windows 10 is the most secure version of Windows ever, and we are humbled that governments around the world like the U.S. Department of Defense, the Australian Health Department, and the Italian Ministry of Defense are choosing Windows 10 for their security, and now the Chinese government has a version of Windows created specifically for it,” he added.

Chinese firm Lenovo will be one of the first OEM partners for Microsoft to preinstall the custom Windows 10 version on new devices.

North Korea denies accusations of conducting WannaCry attack

North-Korea-Cyber-Security

North Korea has rubbished the accusations that linked Pyongyang with the ransomware WannaCry cyberattack, calling it ‘ridiculous’.

“Relating to the cyberattack, linking to the DPRK, it is ridiculous,” North Korea’s Deputy U.N. Ambassador Kim In Ryong told a news conference when asked if Pyongyang was involved in the global WannaCry attack or the U.N. hack.

North Korea is also known as the Democratic People’s Republic of Korea (DPRK).

“Whenever something strange happens, it is the stereotype way of the United States and the hostile forces that kick off noisy anti-DPRK campaign deliberately linking with DPRK,” Kim said.

Symantec and Kaspersky Lab had stated that some code in an earlier version of the WannaCry software had also appeared in programs used by the Lazarus Group, which researchers from many companies have identified as a North Korea-run hacking operation.

A spokesman for the Italian mission to the United Nations, which chairs the U.N. Security Council North Korea sanctions committee, said that a member of the U.N. panel of experts who monitor sanctions violations had been hacked.

A patch in time saves nine

Evil Internet Minute: 1.5 cyberattacks on Computers with an Internet Connection

Unpatched and outdated software are one of the biggest challenges of any cybersecurity corporation. The recent ransomware attack WannaCry made use of this vulnerability infecting computers in over 150 countries and crippling entire grids in many smaller states.

“The primary reasons so many vulnerabilities are left unpatched by companies is the time and resources required to manually identify, test, and deploy patches,” stated Jay Prassl, Automox CEO in a release. “We found that existing solutions focus almost exclusively on scanning and reporting on the state of a company’s infrastructure. These products largely generate lots of bad news, but don’t actually fix the problem by patching the endpoint to bring it into compliance. This is the core reason we built Automox, to help companies of every size address this challenge.”

Automox offers a fully automated closed loop patching platform. These are capable of patching any OS, software, at any location. The Verizon’s 2017 Data Breach Investigations Report suggests that more than 90 percent of vulnerabilities date back to at least a year, with 20 percent of them dating back to even a decade. Here remediation is the key.

As the IT function has evolved and changed in the cloud era, the process for patching has remained the same — a manual and reactive process that leaves companies vulnerable to cyber-attacks. According to a recent cybersecurity report, only 72 of every 1000 threats are remediated, leaving nearly 92 percent of threats unpatched and open to vulnerabilities.

“For organizations of every size, the simplest and most effective step they can take to reduce their attack surface and improve their security posture is to consistently patch both their operating systems and applications,” Joe McManus, Senior Cyber Security Researcher with CERT and Automox CISO, added.

Hallowed be thy Cry

Hallowed-be-thy-Cry

Ransomware WannaCry took the world by storm. From banking corporations to healthcare to federal agencies, everyone was affected. Top cybersecurity agencies deployed a slew of measures to contain it, Microsoft released patches, and Russia sprayed holy water. While, the former two were considered legit approach to the existing predicament, Russia’s measure was met with downright criticism. Well, for obvious reasons.

It can’t be blamed, for the Russian Orthodox Church holds an august office and shares close ties with Russia’s central government. It’s leader Patriarch Kirill of Moscow, holds as much power to Russia as Pope Francis to the Christian world. It is even said that Vladimir Putin consults him in the matters of the state.

So, if the Patriarch of the church feels holy water is a solution to protect the computers of Ministry of Internal Affairs, it better is. It also wasn’t like he volunteered, he visited the premises after receiving an invite from the nodal agency.

In fact, it has also been a ritual of sort in Russia where the priest of Orthodox church blesses the server rooms and every artefact of modern technology. It might be a startling news for rest of the world, but in countries like India, scenarios like these happen every now and then.

The photos have gone viral and has also invited threads of trolls from social media. Some remarked it as the beginning of worshipping Machine God, drawing parallels to the video game ‘Civilization: Beyond Earth’. The creative lot have also done their bit.

While the rest of the world are still fighting WannaCry, we can’t guess what Russia’s next step could be.

Chelsea Manning is a free woman

Chelsea-Manning-is-a-free-woman

“First steps of freedom!!”, Manning wrote on a photo shared on social media.

Seven years after being charged with cyber espionage, Chelsea Manning, earlier known as Bradley Manning, walked out as a free woman. Manning was arrested for passing classified information to WikiLeaks in 2013, in what has been dubbed as the largest breach of secrets in United States history.
This comes after WikiLeaks founder Julian Assange promised to surrender if Manning was freed. The U.S. Attorney General Jeff Sessions stated that the arrest of Assange is priority.

The documents were released on WikiLeaks quoting anonymous sources. Chelsea was sentenced by court-martial for furnishing more than 7,00,000 documents, diplomatic cables, videos and field accounts to WikiLeaks, while she was serving as an intelligence analyst in Iraq. The leaked contents had a gunsight video which shows U.S. Apache helicopter firing at suspected mutineers, killing over a dozen people including two Reuters journalists.

Manning’s action though had put her in serious trouble, she had gained gargantuan support from activists of free-speech, and the advocates of transgender, as Manning was herself born to the male gender. The transition had taken place while she was serving her prison sentence.

“Chelsea might go on to become one of the biggest proponents of transgender rights,” stated Chase Strangio, an American Civil Liberties Union lawyer. Chase had represented Manning in the case. “The U.S. Army kept her in men’s prison and forced her for a male hairdo. During her time in prison, she tried to commit suicide twice and was held in a solitary confinement for prolonged stretches. She was also denied proper medical attention,” Chase claimed.

Manning was welcomed by members of the group PeaceWorks, who credited her with exposing war crimes. “This is the kind of information we the people should have in order to make decisions about our leaders,” said Henry Stoever, leader of the group while talking to Reuters.

WannaCry should be wakeup call

WannaCry-wakeup-call

The global cyber-attack that crippled Britain’s National Health Service and devastated businesses around the world on May 12th may be only the first in a series of sophisticated attacks that will arise out of leaked NSA hacking tools. Security researchers monitoring dark-web forums used by cyber criminals report that hackers are actively discussing different ways the leaked exploits can be used to target and infect more victims.

“This is just the beginning,” warns Dominic Chorafakis, founder of cyber-security consulting firm Akouto. “The NSA leak was a windfall for hackers looking for ways to attack victims and it won’t take them long to create powerful new tools that can infect tens of thousands of systems very quickly. Protecting IT systems in this environment takes knowledge, vigilance and the right tools, but there are some simple and practical things everyone can do.”

Most attacks take advantage of vulnerabilities that have already been fixed, but IT staff and end users fail to apply software updates provided by vendors, as highlighted by the recent outbreak. Reports from the Canadian Cyber Incident Response Center and the US Department of Homeland Security suggest that as many as 85% of targeted attacks are preventable.

“Just keeping software and backups up to date and using professional anti-virus will go a long way and might even be enough for individuals, but the effects of a breach can be catastrophic to a business,” Chorafakis added. “Speaking with a cyber-security professional can help businesses better understand where they are vulnerable and take the necessary steps to protect themselves.”

Security firms started reporting a spike in ransomware attacks even before the leaked NSA exploits, with many factors contributing to the online crime wave. Digital currency like Bitcoin has made it possible for cyber-extortionists to extract payment from their victims electronically with just a few clicks and no money trail for authorities to follow.

This has attracted a new class of cyber-criminal, capable of producing professional grade hacking software, even offering Ransomware-As-A-Service to less tech-savvy criminals who carry out the attacks and share the profits with the developers. Now armed with stolen hacking weapons created by some of the most talented cyber-spies in the world, criminals were able to perpetrate the largest extortion cyber-attack ever seen.

“The WannaCry cyber-attack should serve as a wake-up call to every business out there,” concludes Chorafakis. “Take time today to apply software updates, check that backups are working and ask a security professional what you can do to avoid falling victim to a cyber-attack and make sure your business can recover from one.”