Home Blog Page 85

Don’t Click! That Meal Delivery SMS Might be Malicious

Smishing attacks

COVID-19 has impacted nearly every industry. Despite the restriction of movement during the pandemic, e-commerce and food delivery services boomed. While the demand for DIY meal kits surged, impersonation scams saw a spike as well.  Recently, cybersecurity firm Tessian warned consumers to be vigilant about the evolving meal kit delivery frauds. Scammers are tricking users by sending phishing messages (Smishing) that appear as offers from legitimate meal-kit delivery services like HelloFresh and Gousto in the U.K.

In smishing attacks, fraudsters send a specially crafted message (SMS) provoking the user to click on a malicious URL hidden in the text.

Tessian’s researchers claimed that the meal-kit phishing campaign is targeted at unwitting consumers, who receive malicious SMS and WhatsApp texts asking them to give feedback to win a prize. The malicious URL within the message leads users to a bogus site designed to pilfer sensitive financial information and account credentials.

Capitalizing on Consumer Trends

From fake vaccines, test results to fraudulent job offers, threat actors are fully capitalizing on the pandemic. The intent behind these scams is to drive users to a phishing site – in any way possible – and trick them into entering their personal data.

Smishing Message from Attackers

Source: Tessian

“Throughout the pandemic, we’ve seen cybercriminals jump on trending topics and impersonate well-known brands, with increasing sophistication. Often, scammers will register new web domains to set up convincing-looking fake websites, luring their victims to these pages using phishing scams, and then harvest valuable information,” said Tim Sadler, CEO and Co-founder of Tessian.

Smishing messages often contain eye-catching phrases like “you’ve won a lottery” to grab users’ attention. Most of these messages are riddled with spelling mistakes.

“Spelling errors are a tell-tale sign that it is not from a legitimate source; brands will rarely make such mistakes in their marketing campaigns. Also, keep an eye out for business and customer messages from unknown numbers or numbers starting with a local area code such as +44, as these are regularly associated with scam texts. These scams are getting harder and harder to spot, with the perpetrators regularly coming up with new tactics to convince users to follow their link and input their confidential data. A general rule of thumb is that, if you’re ever not sure if something is a scam, then assume it is. You can always verify a message’s legitimacy with the company directly,” Sadler added.

Mitigation Measures

Tessian also recommended certain security measures to prevent smishing attacks. These include:

  • If you receive a text requesting that you follow a link, ignore it — at least until you’ve confirmed whether or not it’s legitimate by contacting the company in question via another channel of communication.
  • Inspect the sender’s phone number — unknown numbers or 11-digit long numbers starting with a local area code, such as +44, are often associated with scam texts. Large institutions will generally send text messages from short-code numbers.
  • Check for spelling or grammar mistakes. Legitimate messages from large companies will rarely have errors.
  • Visit the company’s social media channels to see they have warned their customers about potential scams that have been circulating, and research whether other customers have received the same message.

“SMS-based scams are incredibly convincing and are growing in frequency. More and more companies are relying on SMS as a marketing channel to reach their customers and update them about online orders. Given that nine in 10 people open their texts, it’s likely the message will be read. So, while you might not be expecting a delivery, scammers will still try their luck. Often impersonating a legitimate brand, and using sophisticated methods like including a shortened, legitimate-looking URL or an urgent call to action, they’re hoping their targets have signed up to some form of home delivery service, will click the link and fall for the scam,” said Charles Brook, threat intelligence specialist at Tessian.

Japan to Impose Strict Regulations on Private Sector’s Adoption of Foreign Equipment and Technology

Japan restricts foreign equipment and tech, Japan Embraces AI Tools to Fight Cyberattacks with US$237 mn Investment

Fearing a situation like the Colonial Pipeline-like hack, the Japanese government is set to impose restrictions on the usage of foreign equipment and technology in its private sector. It will introduce new security regulations for 14 critical infrastructure sectors including, telecommunications, electricity, finance, railroads, government services, and health care will be covered.

The Policy in Public Sector

Japan had reportedly stopped procuring foreign equipment in government purchases since 2018 “to avoid hacks and intelligence leaks.” The move was specifically aimed at keeping China at bay, who at the time were being blamed by the U.S. for carrying out spying and espionage campaigns through Huawei’s 5G equipment. Following these accusations, the U.S., the U.K., and Australia ordered an immediate ban on importing Huawei’s 5G equipment and ordered the removal and replacement of the installed equipment too. Japan being a close ally of the U.S., and the fact that it could cause economic security risks to its homeland, followed suit.

However, the recent turn of events in the U.S., where the privately run Colonial Pipelines was hacked, probably pressured the Japanese government into extending this ban to the private sector too. The brutal ransomware attack on the Colonial Pipeline infrastructure saw a temporary halt in its supplies affecting many major East Coast cities including Washington, D.C.; Baltimore; and Atlanta. Concerns over a fuel crunch and price hike saw frantic buying from citizens of these regions, which further escalated the fuel shortage. The situation was later brought under control as a partial recovery of fuel supplies was attained soon. The chaos led to the POTUS signing an Executive Order to bolster the nation’s fight against rising cyberattacks.

Present Private Sector Woes

In the same week, another Japanese tech giant Toshiba’s subsidiary in Europe fell victim to a ransomware attack, which was probably conducted by the same threat group involved in the Colonial Pipeline hack. The attack led to the suspension of all communication lines between Toshiba’s European and Japanese offices. The investigation, as last reported, is still underway. However, it seems to have already tolled the warning bells for the Japanese government, which is cautious about a potential cyberthreat aimed at its private sector.

A report from Nikkei Asia said, The government plans to amend the various laws governing each sector in one sweeping motion and add a clause requiring each sector to be conscious of national security risks. These new security regulations will also apply to foreign services including cloud storage, data centers, and servers located offshore. Additionally, the government will also undertake frequent monitoring of private sector companies for compliance and shall withhold them if they are found flouting the norms. This can also lead to the cancellation of their license in case of a major issue.


Related News:

Magecart Group 12 Found Deploying PHP Web Shells to Skim Users’ Payment Information

Patchwork BADNEWS, APT31 threat group

Malicious web shells have been wreaking havoc by enabling remote access, executing arbitrary commands, and controlling servers. It’s a technique mostly used by Magecart threat actors. Recently, security researchers from Malwarebytes found the Magecart Group 12, a cybercriminal gang best known for their attacks on online stores, targeting Magento online stores to pilfer customers’ sensitive information. Magento is an e-commerce platform that allows websites to create their online store. According to the researchers, Magecart attackers have been found distributing malicious PHP web shells, known as Smilodon or Megalodon, disguised as favicon to obtain remote access to the targeted servers.

What is a Web Shell?

A web shell is a malicious script or malware deployed on websites to obtain persistent access to an already compromised site. Attackers usually upload web shells onto a web server after exploiting a vulnerability.

Malicious Web Shells Disguised as Favicons

The attackers used malicious web shells to dynamically load JavaScript skimming code via server-side requests into online stores. The researchers stated that the malware (disguised as favicon) attempts to pass itself as an image/png file and is then injected into compromised websites/online stores by replacing the original icon tags with a path to the fake PNG file.

“This technique is interesting as most client-side security tools will not be able to detect or block the skimmer. There are several ways to load skimming code but the most common one is by calling an external JavaScript resource. When a customer visits an online store, their browser will request a domain hosting the skimmer. Although criminals will constantly expand on their infrastructure it is relatively easy to block these skimmers using a domain/IP database approach,” Malwarebytes said.

The Modus Operandi of Magecart Attackers

Magecart attackers are linked to several cybercrimes on e-commerce sites. Magecart attack, also known as web skimming or e-skimming, is a form of cybercrime where attackers plant malicious JavaScript code on the payment gateway of online stores to collect users’ payment card information while making purchases on the infected site. The stolen card data is later sold on the dark web or used to make fraudulent purchases.

Recent Magecart Attacks

  • Magecart actors compromised government websites of eight U.S. cities across three states via a card skimming attack. The attack occurred when users making payments on the compromised Click2Gov website.
  • In a massive Magecart campaign, threat actors hacked over 2000 Magento online stores to pilfer users’ financial data.
  • The online store of Claire’s and its sister brand Icing were attacked by Magecart operators last year. Attackers illicitly gained access to the company’s online store by compromising and hiding malicious code in it to collect the payment card information from users.
  • RiskIQ uncovered a new Magecart campaign dubbed “Magecart Group 7” that compromised over 19 e-commerce websites to steal customers’ payment card data.

Web skimming attacks that deploy web shells continue to be a severe threat to e-commerce businesses. Several online stores remain vulnerable with unpatched flaws and outdated content management software (CMS). Online merchants need to update their websites to prevent exfiltration of consumers’ payment information.

5 Questions Every CISO Should Ask Before Moving Company

Chief-Information-Security-Officers

The role of a Chief Information Security Officer is a much-coveted position that blends extensive technical know-how, managerial excellence, and strong leadership skills. It’s no surprise that finding individuals with all of these skill sets in equal measure is a major challenge. Companies are in a war for the best CISO talent, meaning candidates are likely faced with multiple offers at any one time.

By Karl Sharman, Head of Cyber Security Solutions, Stott and May

With this in mind, here are the five questions every CISO should ask before moving company:

1. Who is the company’s leadership?

One of the biggest challenges most CISOs face is translating cyber risk into a language the board understands and buys into. You need authority and visibility to effectively manage an enterprise risk management initiative. This makes reporting lines really important, so determine whether you will have access to the CEO and the wider board, and gauge their understanding of security knowledge. Do they see security as a business priority or a checkbox exercise?

Dig a little deeper into the company’s leadership team – what do former colleagues say about them? Where did they come from? Have other team members followed them? This type of loyalty is always a good sign. Lastly, make sure you have an understanding of, and access to all key risks across the organization, including the various technology lines.

2. What is the company’s track record?

Do your research and be thorough. Look at the company’s hiring and firing cycles – how often are they recruiting and for which roles? Find out what happened to the previous CISO and why they left. If it is a new role, why are they looking to invest in security leadership now? Ask questions regarding the financial trajectory of the company, its plans for growth, and how they see security fitting into this.

3. Is there an exit strategy in place?

Determine the long-term goals of the business – is there an exit strategy in place for the company? And if not, what is the ultimate goal? It is important to buy into the future of the business and understand how you, as CISO, will help to achieve this?

4. Who is funding the company?

Understanding who is funding the company will help you determine its priorities and how much investment you will likely receive in the security function. If it is backed by venture capital, the goal will always be to sell or IPO so you will be expected to help the business achieve hyper-growth in a short period of time. If the company is already publicly listed, then you know they cannot afford a cyber breach of any kind, so they are likely already investing heavily in the security function.

5. What does equity really mean?

Most companies will look to lure you in with some degree of equity as part of the offer. But do your research as it can be easy to misunderstand this. The main thing to consider is whether equity is included in the full package amount. This means, with an offer of $150,000 base, a 50% bonus, and $150,000 in equity stock options, a company would equate that to a $375,000 full package. However, the only thing that is guaranteed in this offer is the base salary, while the bonus and stock options are quite often determined by elements completely out of your control as the CISO (performance of the company and market dynamics). Educate yourself on the difference between restricted stock, stock options, stock appreciation rights, phantom stock, and employee stock purchase plans before making an informed decision.

In a rapidly changing market where risk is everywhere (even more so as we emerge from the COVID-19 pandemic and remote working becomes the norm for many companies) and the ability to prioritize is essential, CISOs are in incredibly high demand. Before accepting any offer, do your research into the company’s leadership, its hiring and firing cycles, and whether security is viewed as a business priority or not. Are you the first CISO and if not, why did your predecessor leave? Look at what the future looks like depending on who is funding the company and understand what any equity offer really means. Only by asking the right questions can you determine whether a move is right for you.


About the Author

Karl SharmanAs head of Cybersecurity Solutions at an executive search firm, Stott and May, Karl Sharman has over 10 years of experience building and scaling security teams for Fortune 500 companies, Pre-IPO, late-stage ventures, security consultancies, MSSPs, and more.

 

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Security and Risk Management Spending to Exceed $150 Bn in 2021: Gartner

Sardonic, BitMart

Amid growing cybersecurity risks and the fear of compliance audit failure during the pandemic, most organizations are stepping up their cybersecurity and digital transformation budgets. A recent analysis from Gartner revealed that investment in information security and risk management technology and services is expected to grow 12.4% to reach $150.4 billion in 2021. It was found that the growth rate is due to most organizations looking for remote working technologies and cloud security.

Besides information security, other security services like consulting, hardware support, and outsourced services represent the largest category of spending in 2021, at over $72.5 billion globally.

“Organizations continue to grapple with the security and regulatory demands of public cloud and software as a service. Looking ahead, we’re seeing early market signals of growing automation and further adoption of machine learning technologies in support of AI security. To combat attacks, organizations will extend and standardize threat detection and response activities,” said Lawrence Pingree, Managing Research Vice President at Gartner.

Information Security & Risk Management End-User Spending by Segment:

“The pace of client inquiry indicates that CASB is a popular choice for cloud-using organizations. This is due to the growing popularity of using non-PC devices for interacting with core business processes, which creates security risks that can be mitigated effectively with a CASB. CASBs also enable safer interaction between SaaS applications and unmanaged devices,” Pingree added.

“Areas of significant risk driving near-term demand include the advent of new digital products and services and the related health and safety uses, as well as third-party risks such as customer data breaches or supply chain attacks,” said John A. Wheeler, Senior Research Director at Gartner.

Enterprises Prioritize Digital Innovation Amid Pandemic

Earlier, the 2021 Gartner CIO Agenda survey revealed that top-performing enterprises are focusing on digital innovation and leveraging advanced technologies to come out stronger during the global pandemic. The survey suggested four approaches in which Chief Information Officers (CIOs) can bring a difference both in digital business acceleration and long-term agility. These include: Win differently, Unleash force multipliers, Banish drags, and Redirect resources.

College Students Across U.S. Affected by Herff Jones Payments Card Breach

54% of Universities in the U.K. Suffered a Data Breach Last Year, Herff Jones payments card breach

It’s graduation month in the U.S. and final year students are ecstatic since they will finally get to celebrate with the tradition of heaving their graduation caps into the air. But aren’t we still in the middle of a pandemic? So, how would that be possible? Well, the situation is turning the corner in the U.S. The Centers for Disease Control and Prevention (CDC) has announced that “fully vaccinated people don’t need to wear face masks indoors or outdoors in most settings.” As per the recent reports, the U.S. has roughly inoculated 116 million American citizens (with both doses), which is 45.1% of the total U.S. adult population of age 18 or more until May 12, 2021. However, for some graduates, the joy of dawning their academic regalia and posing for pictures has turned into a nightmare as a well-known company, Herff Jones, which provides graduation day apparel and accessories, reported a data breach.

The Herff Jones Payments Card Breach

Universities and educational institutions in the U.S. have been targeted largely in the past few years owing to online learning. However, the Herff Jones payment card breach incident is probably the first time that students at multiple universities have been reportedly targeted through an apparel and accessories service provider.

The incident first came to light when graduation students started reporting fraudulent transactions being made through their payment cards. Initially, few students from specific universities were targeted, however, alert flags were being raised from institutions of other states. On closely monitoring the situation, two common links between all these attacks were found: first, these were all final year students, and second, and probably the most important, they had made a purchase from Herff Jones.

The company was unaware of the data breach until victims started tagging them on social media, using the company handles. One of the victim students on a Reddit discussion forum said, Someone just bought a PS 5 with my card info and I respect the hustle. While most of the fraudulent transactions ranged between $80 to $1,200 (owing to the limit cap on students’ payment cards) some others also reported transactions of $4,000 and more.

The majority of these transactions came from students from Indiana (Purdue, IU), Boston, Maryland (Towson University), Houston (UH, UHD), Illinois, Delaware, Michigan, Wisconsin, Pennsylvania (Lehigh, Misericordia), New York (Cornell), Arizona, North Carolina (Wake Forest), Florida (State University), and California (Sonoma State).

Herff Jones Accepts “Theft” of Information

In a statement released by Herff Jones, the company confirmed that it had “identified theft of certain customers’ payment information,” and was working towards fixing it at the earliest with the help of “a leading cybersecurity firm.” It further added that due diligence was being done to avoid such incidents in the future and respective law enforcement authorities were also informed to gain their expertise in understanding the scope and depth of the data breach.

Additionally, Herff Jones has set up a dedicated customer service team, which can be reached at 855-535-1795 for any further assistance.

On Sale! Fake Vaccines and Bogus COVID Results Flood Dark Web

covid-19 vaccine, vaccine

While the world is in rush to get vaccinated against Coronavirus, opportunistic criminals are misusing the situation to spread fake COVID-19 vaccines. Anne An, a cybersecurity researcher at McAfee’s Advanced Programs Group (APG), discovered threat actors distributing fake COVID-19 test results, counterfeit vaccination cards, and bogus vaccines on the dark web to capitalize on the situation.

With many people purchasing vaccines on the black market due to the heightened demand across the world, threat actors are spreading illegal and counterfeit vaccines and vaccination records on various darknet marketplaces. “The proliferation of fraudulent test results and counterfeit COVID-19 vaccine records pose a serious threat to public health and spur the underground economy. Individuals undoubtedly long to return to their pre-pandemic routines and the freedom of travel and behavior denied them over the last year,” McAfee said.

Key Findings

  • Pfizer-BioNTech COVID-19 vaccines can be purchased for as little as $500 per dose from top-selling vendors on the dark web.
  • Adversaries use various communication channels like Wickr, Telegram, WhatsApp, and Gmail for advertising fake products and services.
  • Darknet listings associated with alleged Pfizer-BioNTech COVID-19 vaccines are selling for $600 to $2,500.
  • Some of these supposed COVID-19 vaccines are imported from the U.S., while others are packed in the U.K. and shipped to every country in the world.
  • Threat actors selling ten doses of what they claim to be Moderna COVID-29 vaccines for $2,000.
  • Besides, cybercriminals offer antibody home test kits for $152 with various shipping options. It costs $41 for stealth shipping to the U.S., $10.38 to ship to the U.K., and $20 to mail the vaccines internationally.

It was observed that most asymptomatic people are purchasing false COVID-19 test reports or vaccination cards to board flights, enter a new country, or attend an event.  “It also threatens the lives of other people in their communities and around the world. Aside from the collective damage to global health, darknet marketplace transactions encourage the supply of illicit goods and services. The underground economy cycle continues as demand creates inventory, which in turn creates supply,” McAfee added.

Risk of Identity Theft

With consumers looking for fake products on the darknet, cybercriminals started advertising other illicit products for sale on various dark web forums. Apart from selling vaccines, vaccination cards, and fake test results, threat actors are also benefitting by reselling the names, birth dates, home addresses, contact details, and other personally identifiable information (PII) of their customers.

Fake Vaccines – A Rising Threat

Recently, the International Hologram Manufacturers Association (IHMA) stated that it found a 300% increase this year in advertisements on various dark web markets on fake Coronavirus-related products and services. The vaccine research centers and manufacturers have been urged to boost their authentication and verification technologies to protect consumers against rising fake vaccine scams.

The Role of a CISO in Ensuring Application Security for Employees

Application Security

Cybersecurity, now part of the DNA of today’s economy, is significantly about application security. Apps have become ubiquitous today, with every business wanting one. But cybercriminals are finding apps as a gateway to the riches, while global businesses and top political leaders have been speaking of greater openness, transparency, and collaboration in fighting them.

By Anil Bhasin, Former Regional Vice President, India & SAARC, Palo Alto Networks

But, standing in the way of cybercriminals is the Chief Information Security Officer or CISO. The CISOs help to keep enterprises running without compromising security or compliance, while also ensuring that there are product security and service availability built into every step of the quality management process.

New Circumstances

To ensure application or app’s security, the CISO must make all efforts to ensure the board and the CEO of a company understand the positive and negative repercussions of the risks involving an application by mitigating it.

While technology and network companies are moving rapidly to keep pace with the ever-evolving criminal elements, IT alone cannot be at the vanguard in the fight against the attackers. It is also the responsibility of everyone in the organization with access to a computer or a smart device.

COVID-19 has woken us up to this reality and has catalyzed a pivot to a transformational shift, to telecommuting on a global scale. For the first time, millions of employees are logging on remotely, often from their homes, into company servers through their home Wi-Fi network. This sudden spike in demand for bandwidth has stretched digital infrastructure beyond its limits. This opened opportunities for new attack vectors for threat actors. Within days of the onset of the pandemic, sophisticated attacks that exploit the panic over COVID-19 successfully attacked critical healthcare infrastructure and official communication channels.

Times like these call for the CISOs to make a shift in how firms previously sought to strengthen their cybersecurity posture by trying to plug the gaps. This only led to organizations investing in numerous solutions and left exposed to an ecosystem that was spread out. More professionals focused on security were needed to hold up the larger teams, which were challenging due to skills shortages.

The responsibility of CISOs is to make employees more aware of the security issues of the digital age, including malware and phishing, and encourage them to take up best practices. CISOs need to coordinate with the Chief Human Resources Officers to design and implement the information technology and security education of the workforce.

While playing catch-up with the attackers is the new norm, a reactionary approach will not do in the 2020s and beyond. Let’s look at the four developments that would define how the CISOs should prepare as we traverse the 2020s:

1. Gaps in 4G can Carry Over to 5G

The Telecom Regulatory Authority of India (TRAI) is all set to open up the 5G spectrum in 2020. Australia, Singapore, and many others have firmed up plans for 5G networks this year. With telecommuting looking more likely to become commonplace, the much-vaunted very high speed, high reliability, and low latency 5G will get the thumbs up.

While this is the potential of 5G, we are far from there. The 5G is built over the foundations of 4G, and the vulnerabilities in the 4G network may be magnified on 5G networks with more devices on it. If the existing security risks are not checked now, mobile Internet and apps could be the Achilles Heel in a cyberattack, halting all critical services.

2. IoT: A Potential Minefield

Billions of connected devices would be the hallmark of the Internet of Things (IoT). Countries are using it to empower millions through innovative and disruptive technologies; however, if left unsecured, they can leave gaps in the security systems of corporates. Not even biometric identification is safe as deep fake tech would compromise that.

Unsecured IoT devices are a potential minefield of vulnerabilities, especially in healthcare IT, where cyber hygiene, software patches, and updates may have taken a backseat due to the pressures of dealing with the pandemic – a nightmare for the CISOs.

The coming decade will need continuous retrofitting and updates of IoT devices for security, and eventually adopting a “secure by design” approach to built-in security. Karnataka, India, has taken similar steps by promoting innovations such as hackathons and accelerator programs. A case in point is Karnataka’s Centre of Excellence in Cyber Security (CySecK), which launched an accelerator program, HACK, for cybersecurity start-ups. The accelerator program has over 21 startups.

3. AI for Times Ahead

India has a massive shortfall of skilled cybersecurity professionals specialized in application security. While the need is for about 1 million cybersecurity professionals, according to the Data Security Council of India, the supply falls far short. The mismatch between expectations and needs is stark.

As attackers go hi-tech by embracing automation and Artificial Intelligence (AI), cybersecurity professionals are having to try harder to stay ahead by leveraging AI. AI-driven solutions could detect and remedy the anomalies of the network behavior faster than humans can even react. As the use of technology becomes endemic, the role of the cybersecurity expert will see fundamental skills shift.

Implementing the right AI solutions can mitigate any shortage and let smart, innovative, talented people focus on their strengths.

4. Influence on Next-gen Products

The development lifecycle of new apps would see the integration of security processes and tools. Infusing them with security from outset is the way forward as precision is key, given the hyper-connectedness of networks going forward, especially with the soaring appetite for digital financial services and e-commerce in Asia. During the app development lifecycle, everyone is responsible for security.

A 100% secure network is illusory and leaves security as a vulnerability. These germinate from the fact that cybercriminals find ways to sneak past resource-stretched systems or vulnerabilities in partner networks. The security professionals need to remember priorities must define security.

The fast-paced world needs enterprises to be ahead of the cybercriminals. The threat landscape is continuously evolving, impacting the design of the app security infrastructure. Like social distancing, vigilance in digital security should be part of our vocabulary.

This story first appeared in the October 2020 issue of CISO MAG.


About the Author

Anil Bhasin is the former Regional Vice President for the India and SAARC region at Palo Alto Networks. He has over 25 years of experience in the industry. Bhasin earlier worked at Cisco, where he spent 12 years in leadership roles including the Services business for India & SAARC region. Prior to joining Cisco, Anil had a two-year stint at Getronics (formerly known as Wang Global) in Dubai. As a National Sales Manager at Getronics, he was responsible for network integration for Cisco Systems. Anil was also a Senior Account Manager for M/s Computer World in Bahrain. During his six years tenure with M/s Computer World, he managed strategic accounts from the banking, government and manufacturing verticals, offering customized solutions and working very closely with principals such as Compaq, Acer, Microsoft, Novell Synoptics and Cisco.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Multiple Flaws Expose Wi-Fi Connected Devices to FragAttacks

KCodes NetUSB, FragAttacks on Wi-Fi connected devices

Different vulnerabilities affect devices in different ways. They often allow cybercriminals to infiltrate into vulnerable systems to steal sensitive information or compromise devices. Recently, cybersecurity researcher Mathy Vanhoef uncovered a set of critical vulnerabilities, tracked as FragAttacks, that impact the systems connected to Wi-Fi, exposing millions of Wi-Fi users to potential remote attacks.

What is a FragAttack?

Vanhoef claimed that all these vulnerabilities are a combination of fragmentation and aggregation attacks (FragAttacks). FragAttacks can be leveraged by any remote hacker that is within range of a victim’s Wi-Fi network to abuse these flaws. It was found that most Wi-Fi devices are affected by several vulnerabilities, with every Wi-Fi device being vulnerable to at least one flaw.

Vulnerabilities Detected

The researcher discovered multiple vulnerabilities including three design flaws, four implementation vulnerabilities, and five other critical flaws caused by widespread programming mistakes in Wi-Fi products. Vanhoef tested more than 75 Wi-Fi devices including computers from Dell and Apple, mobile products from Huawei, Google, Samsung, and Apple, IoT devices from Xiaomi and Canon, routers from Asus, Linksys, and D-Link routers.

All these bugs will impact all Wi-Fi security protocols, including the Wired Equivalent Privacy (WEP) and the latest Wi-Fi Protected Access (WPA3). The detected vulnerabilities with CVSS scores between 4.8 and 6.5 include:

  • CVE-2020-24588: Which causes an Aggregation attack (accepting non-SPP A-MSDU frames).
  • CVE-2020-24587: Cause Mixed key attack (reassembling fragments encrypted under different keys).
  • CVE-2020-24586: Cause Fragment cache attack (not clearing fragments from memory when (re)connecting to a network).
  • CVE-2020-26145: Accepting plaintext broadcast fragments as full frames (in an encrypted network).
  • CVE-2020-26144: Accepting plaintext A-MSDU frames that start with an RFC1042 header with EtherType EAPOL (in an encrypted network).
  • CVE-2020-26140: Accepting plaintext data frames in a protected network.
  • CVE-2020-26143: Accepting fragmented plaintext data frames in a protected network.
  • CVE-2020-26139: Forwarding EAPOL frames even though the sender is not yet authenticated (should only affect APs).
  • CVE-2020-26146: Reassembling encrypted fragments with non-consecutive packet numbers.
  • CVE-2020-26147: Reassembling mixed encrypted/plaintext fragments.
  • CVE-2020-26142: Processing fragmented frames as full frames.
  • CVE-2020-26141: Not verifying the TKIP MIC of fragmented frames. 

How Attackers Can Exploit these Flaws

The researcher also provided a demo video showing how an adversary can abuse the vulnerabilities to intercept sensitive information, exploit insecure IoT devices remotely, and launch advanced cyberattacks.

Vanhoef stated that many of the companies released mitigation measures to fix these vulnerabilities. Hence, it is highly recommended to update all your connected devices to thwart potential risks.

“The biggest risk in practice is likely the ability to abuse the discovered flaws to attack devices in someone’s home network. For instance, many smart homes and internet-of-things devices are rarely updated, and Wi-Fi security is the last line of defense that prevents someone from attacking these devices. Unfortunately, due to the discovered vulnerabilities, this last line of defense can now be bypassed,” Vanhoef added.

Related Story: How to Secure Your Home Wi-Fi Network

Toshiba’s European Subsidiary Confirms Ransomware Attack; DarkSide’s Involvement Suspected

Toshiba subsidiaries ransomware attack by darkSide ransomware

As the ransomware pandemic ravages through the big and small size industries alike, the Japanese tech giant joins the list of those affected by it. Toshiba’s European subsidiaries have confirmed that it was targeted by a “cyberattack”. As per the initial investigation, the involvement of the DarkSide ransomware gang is being suspected as the malware signatures of this attack are similar to those used in the Colonial pipeline hack.

Toshiba Subsidiary Confirms Ransomware Attack

The European subsidiaries of Toshiba Tec Group on Friday disclosed information that a cyberattack on their network and systems had meant that the network connections between their company assets in Japan and Europe were taken offline to stop the spread of the malware. A tweet from Toshiba’s French subsidiary, Tec France Imaging System (TFIS), confirmed that it was indeed a ransomware attack and took place on the night of May 4.

The official statement made by the Toshiba Tec Group said that the investigation was ongoing and only “some regions in Europe” were affected by the attack. It further added that until now, there was no information available that could pinpoint the fact that customer-related information was leaked externally during the course of the attack. However, it has not entirely ruled out the possibility of the leak either. It said,

The group recognizes that it is possible that some information and data may have been leaked by the criminal gang, we will continue to conduct further investigation in cooperation with the external specialized organization to grasp the details.

DarkSide’s Involvement

Nowhere in its statement or on official channels did Toshiba Tec Group name the DarkSide ransomware gang’s hand in the attack. But in a report from CNBC, a Toshiba spokesperson said that the DarkSide criminal group appeared to be responsible for the security incident. However, the spokesperson confirmed that it did not intend to pay the ransom and instead used its data backup procedures to get the systems and networks back online. They did exactly that and confirmed it in their statement saying, With backups in place and prompt countermeasures (taken), encrypted data was recovered, and connections restored.

The Darkside threat syndicate is offering Ransomware-as-a-Service (RaaS) to smaller threat actors as its affiliates. This way, they have a larger outreach and a double revenue generation model in place. The syndicate has been active since early August 2020 and claims to have victimized nearly 90 companies. But its latest victim the Colonial Pipeline is the one that has made the most noise. The attack had literally dried up 45% of the East Coast’s fuel lines. To learn more about it read the following story.

Related News:

Ransomware Attack Forces Temporary Shutdown of Top U.S. Fuel Pipeline Operator