Home Blog Page 87

Twitter’s Latest Feature “Tip Jar” Draws Privacy Concerns

PM Modi Twitter

On May 6, Twitter added a new feature, the Tip Jar. The intent behind this innovation, as Twitter says, “is to support voices of creators, journalists, experts, and nonprofits.” However, within hours of the launch, security experts raised concerns over the privacy of people sending the tips, which according to Twitter’s policies seemed like a violation.

What is Twitter’s Tip Jar

Tip Jar allows the Twitterati to generate an additional income source directly via the social media platform. It is a new way of sending and receiving tips so that people can support each other not only in terms of Follows, Retweets, and Likes but even monetarily.

 How to enable Twitter’s Tip Jar? 

Setting up the Tip Jar feature is just a matter of few clicks. Follow these simple steps:

  • Go to the Edit Profile
  • Switch On the “Tip Jar” setting.
  • Toggle and activate Allow Tips. This will display a list of all payment services and platforms available for setting up your tip receiving account.
  • Select one or multiple services and add a $Cashtag.
  • Once done, the Tip Jar account for your profile is successfully set up and a small button appears on the profile next to the “Follow” button.

 How to send a tip using Tip Jar? 

Users can send or donate a tip using Tip Jar by:

  • Click on the Tip Jar
  • Select the payment service which you want to send money from (eg. Bandcamp, Cash App, Patreon, PayPal, and Venmo. Additionally, on Android, tips can also be sent using Spaces).
  • Once selected, a Tip Jar prompt appears indicating that the tipper will be redirected to a third-party service outside the platform. Click Continue.
  • Go to the platform and complete your payment.

Twitter’s Tip Jar Privacy Issue

Though Twitter seems to have nailed this function, some privacy advocates stated that it was exposing the tipper’s identity under certain scenarios.

Problem 1: Security researcher Rachel Tobac found out that while sending someone money via PayPal, it revealed the receiver her home address.

Problem 2: Former Federal Trade Commission chief technologist, Ashkan Soltani, also dug deeper and found that using PayPal for the Tip Jar not just revealed users’ addresses but even their email addresses, although no transaction took place.

Following these discoveries, Twitter quickly worked around the problem and noticed that the privacy issue was not at their end but the third party i.e. at PayPal’s end. After working out the permutations, they decided that they cannot change PayPal’s functionality but update its notification process. Twitter’s support handle backed this by tweeting,

“We’re updating our tipping prompt and Help Center to make it clearer that other apps may share info between people sending/receiving tips, per their terms.”

The Real Problem

On the other hand, PayPal, in its terms and conditions, has already mentioned under which scenarios will the receiver get the address in the receipt. When people are receiving payments through the platform, they need to either select a “goods and services” or “friends and family” payment. In the case of the former, their address is shared, and in the other case, it is not.

At this point, these Tip Jar privacy issues are still limited to a smaller subset of Twitter’s worldwide users because it has only been made available to “Twitter in English.” Thus, expect Twitter to work overtime before its wider roll-out.

Related News:

How to Report and Regain Access to Your Hacked Twitter Account

34 Ransomware Operators Flood Dark Web with Stolen Data of 2,155 Victim Organizations

Ransomware gangs

Cybercriminals often change their hacking tactics to get access to users’ sensitive information. Earlier ransomware operators only focused on encrypting critical systems and demand ransom to decrypt them. But now several some of these operators are leveraging new tactics like double-extorsion to threaten victims in two ways – ransom demand and data leak. In a double extortion approach, ransomware operators initially steal data before encrypting it and demand ransom. Later, they threaten victims by leaking the stolen data on the dark web for additional ransom.

Hack and Leak

An investigation by dark web intelligence profiling platform DarkTracer revealed that around 34 ransomware gangs have exposed sensitive information of over 2,155 victim organizations on the dark web.

According to DarkTracer, the 34 ransomware groups include Avaddon, DarkSide, Team Snatch, Maze, Conti, NetWalker, DoppelPaymer, NEMTY, Nefilim, RansomEXX, Sekhmet, Pysa, AKO, Sodinokibi (REvil), Ragnar_Locker, Suncrypt,  CL0P,  LockBit, Mount Locker, Egregor, Ranzy Locker, Pay2Key, Cuba, Everest, Ragnarok, Babuk locker, Astro Team, LV, File Leaks, Marketo, N3tw0rm, Lorenz, Noname, and Xing Locker.

Out of these 34 groups, the top five active ransomware operators are Conti (338 data leaks), Sodinokibi/REvil (222 data leaks), DoppelPaymer (200 data leaks), Avaddon (123 data leaks), and Pysa (103 data leaks).

Double Extortion – A Rising Threat

Double extortion technique has become a lucrative approach because threat actors cash in on victims’ fear of data leak. The trend seems to be attracting several ransomware groups globally.

While organizations pay ransom to prevent a data leak or decrypt critical data, there is no guarantee that cybercriminals will decrypt the data or will not leak it on the dark web.

A similar analysis from F-Secure revealed that double extortion ransomware attacks increased drastically in 2020. Researchers observed over 15 different ransomware families using a double-extortion approach to target organizations. Besides, nearly 40% of ransomware families discovered last year utilized this method. The major active ransomware families using the double-extortion method include Ragnar Locker, Doppelpaymer, Clop, Conti, and ChaCha.

Upwork, the largest work marketplace, also revealed that 36.2 million Americans will be working remotely by 2025, an 87% increase from pre-pandemic levels. This new normal of working remotely broadens the opportunities for ransomware operators to target and exploit the small, medium, and large businesses, making them gullible to pay ransom more than ever.

CISOs Must Declare an End to the War Between Security and Compliance

cybersecurity practices, Automotive Cybersecurity

The time has long passed for CISOs and other security leaders to shift their perception regarding cybersecurity compliance assessments. These assessments have traditionally been viewed as nuances that you have to undertake because a prospective customer or other interested third-party is demanding a compliance report. Senior executives understand these assessments are not going away, the requests are increasing and becoming more challenging to understand and address.

By AJ Yawn, Co-Founder and CEO of ByteChek

These mandatory assessments are not nice-to-haves; they are required to conduct business in the modern Business-to-Business (B2B) space. You will be hardpressed to find a vendor management or supply chain process that does not involve questionnaires or requests related to cybersecurity best practices. According to a recent survey of North American CISOs, CISOs are preparing for an average of 3.3 security compliance standard audits over the next six to 12 months. That’s a lot of audits!

Three cybersecurity assessments a year is not a light undertaking, these audits are significant financial and operational investments. A typical cybersecurity assessment involves months of meetings, emails, evidence request lists, and your team spending hours in interviews with third-party auditors. The audit interviews pull your team members away from their day jobs, causing delays or other issues with important tasks to continue to grow your business. Along with this operational disruption, every CISO knows that these compliance assessments are not cheap. These assessments cost tens of thousands of dollars in most cases and are required to be renewed annually.

Cybersecurity audits are not going anywhere, and the investment is not insignificant. Investing significant time and money should result in significant value add to the organization right? In most companies, the sales teams, marketing teams, Board members, and other executives realize the benefits of completing a cybersecurity audit. These leaders have experienced several benefits from the achievement of a cybersecurity compliance report such as unlocking sales, entering new markets, or establishing trust with interested parties. Those are all important benefits and ostensibly help the bottom line. However, it is time for security practitioners to receive benefits as well. The value that security professionals should receive and begin to expect from a cybersecurity compliance assessment is — better security.

Compliance should be the outcome of security best practices

I know it’s bizarre to associate compliance with security, and we’ve heard the saying “compliance is not security.” This article is not disagreeing with that statement, I agree that compliance does not equal security and do not think it ever will. Meeting a particular compliance framework or standard does not mean you are secure or won’t be breached. The stories of companies that were breached and recently underwent third-party audits are well-known. Compliance should be the outcome of the security best practices implemented and operating effectively at an organization.

Security leaders should begin to rephrase that statement to “security IS compliance.” When you abstract the core concepts from different frameworks, you see many similarities and repeated themes. Privileged access, onboarding, and offboarding procedures, vulnerability management, network security, and availability of resources are all concepts you can find across multiple compliance frameworks and standards (PCI, SOC 2, ISO 27001, HITRUST, etc.). These concepts are security concepts and not compliance-specific requirements. Implementing a robust vulnerability management program that identifies, tracks, and remediates vulnerabilities to protect your system is good security. It just happens that implementing a vulnerability management program will help you address requirements in a SOC 2 examination or an ISO 27001 certification. Similarly, ensuring that only authorized users have access to your sensitive resources and those users only have access to resources that they require to do their job is good security that also addresses multiple compliance standards and frameworks.

Focusing on security will enable auditors and organizations to critically evaluate the security risks you face, abstracted from the compliance framework relevant to your company. Often audits are not seen as valuable because they are only concerned with the prescriptive requirements of the standard or framework without considering the unique security risks and threats that a company is facing. If an organization is hosted on Amazon Web Services (AWS), there are certain controls and threats that should be considered from a security perspective, irrespective of the compliance framework you are being assessed against.

For example, any organization hosted on AWS understands the threat of storing sensitive data in an open Amazon Simple Storage Service (S3) bucket. However, S3 bucket security doesn’t fit neatly in any particular cybersecurity compliance framework. Should that matter? Whether or not S3 bucket security maps to a requirement should not determine whether that potential misconfiguration is evaluated by a third party hired to assess the cybersecurity risks you are facing. It doesn’t make sense for an organization hosted on AWS to undergo a cybersecurity assessment without their third-party auditors evaluating their S3 buckets’ security.

This is a two-way street, security leaders within the organization have to want a focus on security during their audit, and auditors need to understand the technical environment to focus on security. This understanding will allow the auditor to perform a technically accurate assessment that is not based only on a standard or compliance regulation but also considers the true security risks facing their clients. Understanding compliance standards and the technical environment is a sign of a strong auditor that is adding value to their clients. As we take a look at the S3 bucket example, while that concept does not fit neatly into a cybersecurity framework. A technical auditor will be able to identify compliance requirements or standards that S3 bucket security does relate to and incorporates that into his or her audit. A strong auditor knows that S3 bucket security is relevant to the AICPA SOC 2 reporting framework, specifically criteria CC6.6 and CC7.1, ultimately resulting in a stronger security-focused report.

Focusing on security helps enhance the other realized benefits of cybersecurity audits as well. Your security-focused compliance report can be used as a differentiator during the sales and procurement process. As auditors and internal security leaders come to an understanding that security is the most critical aspect of these assessments, the security profession will reap the benefits of greater trust and security between companies operating in our interconnected world.

This story first appeared in the November 2020 issue of CISO MAG.


About the Author

AJ Yawn - ByteChek

AJ Yawn is the Co-Founder and CEO of ByteChek. He is a seasoned cloud security professional that possesses over a decade of senior information security experience with extensive experience managing a wide range of cybersecurity compliance assessments (SOC 2, ISO 27001, HIPAA, etc.) for a variety of SaaS, IaaS, and PaaS providers.

AJ advises startups on cloud security and serves on the Board of Directors of the (ISC)2 Miami chapter as the Education Chair, he is also a Founding Board member of the National Association of Black Compliance and Risk Management professions, regularly speaks on information security podcasts, events, and he contributes blogs and articles to the information security community including publications such as CISOMag, InfosecMag, HackerNoon, and (ISC)2.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Lemon Duck Botnet Quacks Again with New TTPs

Lemon Duck

It is a common practice for cybercriminal groups to slow down for a while or announce a shutdown of operations to only come back stronger. Security researchers recently found a cryptocurrency-mining botnet Lemon Duck, which was inactive for months, making rounds again by adding new attacking exploits in its arsenal. According to researchers from Cisco Talos, Lemon Duck has added a set of ProxyLogon exploits and targeted unpatched Microsoft Exchange servers.

Cisco Talos claimed that it discovered updated tactics, techniques, and procedures (TTPs) and new components related to the Lemon Duck botnet group. The threat actor group also added the Cobalt Strike attack framework into its malware toolkit. The group is now leveraging fake domains on East Asian top-level domains (TLDs) to hide command-and-control (C2) infrastructure.

Newly Identified Lemon Duck Domains:

  • hwqloan.com
  • hwqloan.com
  • ouler.cc
  • jusanrihua.com

Key Findings 

  • Lemon Duck continues to refine and improve upon their tactics, techniques, and procedures as they attempt to maximize the effectiveness of their campaigns.
  • The group remains relevant as the operators begin to target Microsoft Exchange servers, exploiting high-profile security vulnerabilities to drop web shells and carry out malicious activities.
  • Lemon Duck continues to incorporate new tools, such as Cobalt Strike, into their malware toolkit.
  • Additional obfuscation techniques are now being used to make the infrastructure associated with these campaigns more difficult to identify and analyze.
  • The use of fake domains on East Asian top-level domains (TLDs) masks connections to the actual command and control (C2) infrastructure used in these campaigns.
  • Lemon Duck operators have previously employed several exploits for vulnerabilities, such as SMBGhostand Eternal Blue, and appear to be implementing new exploit code and targeting additional software vulnerabilities 

“Lemon Duck continues to launch campaigns against systems around the world, attempting to leverage infected systems to mine cryptocurrency and generate revenue for the adversary behind this botnet. The use of new tools like Cobalt Strike, as well as the implementation of additional obfuscation techniques throughout the attack lifecycle, may enable them to operate more effectively for longer periods within victim environments,” Cisco Talos said.

Recently, the technology giant Microsoft claimed that Lemon Duck was targeting its Exchange Servers to install cryptocurrency-mining malware and a malware loader that was used to deliver secondary malware payloads like information stealers. Lemon Duck targeted the vulnerabilities, which Microsoft issued patches for, include CVE-2021-26855CVE-2021-26857CVE-2021-26858, and CVE-2021-27065.

“Lemon Duck dove into the Exchange exploit action, adopting different exploit styles and choosing to use a fileless/web shell-less option of direct PowerShell commands from w3wp (the IIS worker process) for some attacks. While still maintaining their normal email-based campaigns, the Lemon Duck operators compromised numerous Exchange servers and moved in the direction of being more of a malware loader than a simple miner,” Microsoft said.

Know the Worth of Your Data on the Dark Web Price Index 2021

digital assets on dark web forums, Know the Worth of Your Data on the Dark Web Price Index 2021

Ever wondered what happens to your stolen data? Most of the leaked/stolen personal information like credit card numbers, bank usernames and passwords, and social media credentials often end up for sale on underground dark web forums. Apart from hacking tools and malware samples, threat actors often trade users’ sensitive data for monetary benefits.

According to a recent investigation by Privacy Affairs on various darknet markets, private data related to organizations like NASA, McDonald’s, Visa, MasterCard, Microsoft, and Google was found trading on the dark Web. Privacy Affairs discovered hundreds of data samples that were being sold for various price tags ranging from $25-$6000, based on the sensitivity of the data. The researchers scanned various dark web marketplaces and created a Dark Web Price Index, a price menu of various stolen information.

Buy One Get One Offers

Cybercriminals advertised and lured users with discounted prices and buy one get one free offer on users’ basic info to sensitive financial details on the dark web. Privacy Affairs found that online banking logins cost an average of $40, credit card details including associated data cost $14-$30. A full range of documents and account details can be obtained at $1,000.

Image Courtesy: Privacy Affairs

“With the massive influx of supply, buyers seem to be gravitating towards bigger, trustworthy sites, with White House Market holding the largest market share of sales. The Dark Web markets are even starting to parody traditional markets with comical offers of buy 2 cloned credit cards and get 1 for free!! for example,” Privacy Affairs said.

New Data Added on Regular Basis

Privacy Affairs found that there is much more volume being sold this year compared to last year. Fake ID, cloned credit cards, hacked crypto accounts, and Uber accounts are the newest entry to dark web sales this year.

Image Courtesy: Privacy Affairs

“Hacked crypto accounts seem to be one of the most valuable items for purchase. Due to the skyrocketing prices of BTC and other cryptocurrencies, hacked accounts may hold large sums of coin-based currency and cash, protected by relaxed security measures after the initial verification process,” Privacy Affairs added.

Image Courtesy: Privacy Affairs

It was also found that darknet market operators did not accept Bitcoin payments and moved towards Monero payments and communicated only via PGP encryption to evade tracking and detection by law enforcement.

Our personal information is valuable to cybercriminals for various reasons. They forge documents like driving licenses, passports, cloned credit cards, and auto-insurance cards with the leaked users’ data. It is advised to be vigilant on the potential data theft risks and act accordingly. Boost your data security by avoiding unnecessary information sharing on social media platforms and maintaining a robust cyber hygiene practice.

Did Apple choose to keep mum about the XcodeGhost malware attack affecting 128Mn iPhone users?

Apple App Store, Apple vulnerabilities

Apple entered the courtroom of the U.S. District Court for the Northern District of California on May 3, 2021, for a showdown against Epic Games Inc. However, what unraveled took everyone by surprise.

Epic Games vs Apple

Epic Games founder Tim Sweeney, who previously challenged Apple’s 30% revenue cut that is applicable on each purchase made on the App Store, has once again filed another lawsuit against the latter in August 2020. The gaming giant has specifically challenged Apple’s restrictions on apps from having other in-app purchasing methods outside of the one offered by the App Store. However, due to the pandemic, the suit went on trial just a week back.

The trial made public an email chain exchange between Apple’s top brass on September 21, 2015, which hints that potentially 128 million iPhone users downloaded 2500+ malicious apps over 203 million times. Although the conversations in the email suggest that Apple executives were trying to find ways of informing the end-users, these notifications never reached them. However, a few weeks later, stories of XcodeGhost apps haunting the App Store surfaced, which confirms that the conversation was about this exact malware.

The XcodeGhost Malware

Xcode is Apple’s integrated development environment (IDE) for macOS. It is specifically used to develop software and apps for macOS, iOS, iPadOS, watchOS, and tvOS. Xcode gives users the advantage of having a unified workflow for user interface design, coding, testing, and debugging. But in 2015, a counterfeit of Xcode – dubbed XcodeGhost – was being inserted into legitimate apps through rogue versions of Xcode downloaded from third-party websites. The malicious code of the XcodeGhost malware worked as a botnet that collected critical user information from its victims’ devices.

Related News:

Why France Digitale Filed Privacy Complaint Against Apple

Apple Faced Logistical Issues for Sending Notifications

Matthew Fischer, the App Store VP, wrote in one of the mails, due to the large number of customers potentially affected, do we want to send an email to all of them? There were logistical issues that Apple was facing in sending out emails to all the affected users.

 Problem 1  Sending huge volumes of notification mail

Dale Bagwell, who was then in charge of customer experience at Apple said,

We have a mass-request tool that will allow us to send the emails, however, we are still testing to make sure that we can accurately include the names of the apps of each customer. There have been issues with this specific functionality in the past.

 

Also – I want to be clear that the tool is limited in the number of emails it can handle. With a batch this big (128Mn) we would likely have to spend up to a week sending these messages.

 Problem 2  Language localization

Language localization was another roadblock that Apple faced while deciding to send notifications to worldwide customers. In response to Bagwell’s email, Fischer discussed this issue with his marketing and PR officials. He said,

This will pose some challenges in terms of language localizations of the email since the downloads of these apps took place in a wide variety of App Store storefronts around the world (e.g. we wouldn’t want to send an English-language email to a customer who downloaded one or more of these apps from the Brazil App Store, where Brazilian Portuguese would be the more appropriate language).

Even after discussing the problem statements and viable solutions, the notification email was never sent to the end-users. However, now a deleted post, which gives a rough idea of the XcodeGhost malware infesting several App Store apps, has surfaced on archive channels. It does not mention the exact number of apps affected but vaguely provides a list of “top 25 impacted apps,” which included WeChat, Angry Birds 2, Baidu Music, and many more. In the post, Apple suggested its users update the listed apps immediately to fix the issue on their respective devices.

But what happens in “one of the most important legal battles in the history of video games,” only time and the U.S. District Court’s judgment will tell.

Related News:

German Security Researcher Claims Apple AirTag can be Hacked

Beware of the Return to Office: How Organizations Can Protect Against Pandemic Sleeper Threats

return to office, business, hybrid work

As organizations get closer to implementing return-to-work plans, most employees are excited about getting back into an office routine. They miss their colleagues, their favorite lunch spots, and the on-site corporate culture that can’t totally be replicated over Zoom.

By Rick Vanover, Senior Director of Product Strategy; and Dave Russell, Vice President of Enterprise Strategy, Veeam Software

IT administrators have a slightly different view. They miss all the in-office benefits, too, but for them, the prospect of having employees all get back on the network after a year of remote working is a scary thought. The admins worry that, after a period of being lax about security, employees will bring compromised devices back to the office and expose the company to new threats.

They may have a point. Work computers have played many roles during the pandemic – hosting everything from social gatherings to workouts, online learning sessions, home shopping, and Netflix streams. Family members have borrowed Mom’s computer to play online games, and passwords have been passed around. Cyber diligence has taken on a lower priority than it should have.

Cybercriminals are well aware of how insecure employee environments have been. They struck with a round of phishing attacks during the spring 2020 lockdown period. Now, administrators are concerned that hackers might implant vulnerabilities in unsecure laptops and unleash them once employees reconnect with a wider array of resources inside the corporate network.

Some companies did a good job getting ahead of security threats. When remote working became standard practice, some were able to issue company standard devices with regularly patched antivirus security. But the majority found themselves scrambling to enable quick and adequate working-from-home setups that didn’t require regular updates, patches, and security checks.

A cybersecurity survey conducted in February reflects just how unprepared enterprises appear to be for the return-to-work security threat. Of those surveyed, 61% used their own personal devices – not work-issued computers – at home. Only 9% used an employer-issued antivirus solution, and only 51% received IT support services while transitioning to remote workstations.

Administrators are bracing for trouble. They’re bringing large numbers of potentially unsecured devices back into the fold at the same time they’re preparing to accommodate a new normal based on hybrid home/office staffing. According to Veeam’s Data Protection Report, 89% of organizations increased their cloud services usage significantly as a result of remote work, and the trend is expected to continue, meaning there will be more endpoints to protect.

So, how can organizations prepare for this transition? Here are a few steps they can take:

Undergo rigorous return-to-work preparation

This is essentially the step where IT administrators physically go through all the affected resources and ensure they’re ready to re-enter the game.

Start by carrying out risk assessments for each employee and each device. Which devices have been patched and regularly maintained? Computers used for remote working are likely to have confidential company data on them; where has the company data been saved, and under which account? These checks need to be performed to minimize risk and make sure compliance standards like General Data Protection Regulation (GDPR) are being maintained.

Also, check to see if employees have given away passwords to family members using work computers. Did employees change their passwords? Did they use the same passwords across work accounts and personal accounts? Did they install any new software or remove any during the remote work period? Administrators need to know before they let employees back on their networks.

Next, make sure to scan all relevant devices for unauthorized apps and software. Employees needed to get creative with work solutions, so they may have tapped resources that help them get through everyday tasks but aren’t up to security standards. Run endpoint detection scans on all returning devices to uncover any hidden vulnerabilities. Cybercriminals often target endpoints, so IT teams need to scan all corporate and personal employee devices that will be brought back to the network.

Improve employees’ digital hygiene

While employees may have let their proverbial hair down during remote work, they’ll need to rededicate themselves to proper digital hygiene. Push them to use separate passwords for home and work devices. And make sure they’re using conventions that are complex and hard-to-crack. Bring back regular training to ensure that they’ll be able to spot phishing emails and other threats. Set up guidelines for using public wi-fi and for downloading materials. As employees return to work, it’s up to the administrators to refine IT practices, one by one, to protect against the top threats in the organization.

Monitor all activities

The best way to spot problems is to set up a system to flag them as they happen. This practice can be applied to workers’ tools – and behaviors – as they reintegrate themselves with all of the company’s applications. Take advantage of monitoring tools that track changes in usage and applications. If an employee makes a change in an application, you’ll want to know. It could be a bug altering a piece of code. Or it could be a change that you made – purposefully or inadvertently – that you’ll want to reset. Get in the habit of checking your monitoring tools at least a couple of times a day. It takes a minute, but it allows you to continually reassess your cybersecurity footprint.

Ensure cloud data management and backups are sound

This is a time for IT administrators to make sure all data management and backup services are in good order. If a rogue device does put any data at risk, you’ll want to make sure to have backups in service and programmed with practices that will ensure that the data in question is protected and fully available. Keeping the so-called “3-2-1 rule” in mind: Make sure to maintain at least three copies of business data, store critical business data on at least two different types of storage media, and keep one copy of the backups in an off-site location. To that, in the ransomware era, we’d expand 3-2-1 to 3-2-1-1-0: Adding another one to the rule where one of the media is offline, and ensuring that all recoverability solutions have zero errors.

Conclusion

While IT administrators are looking forward to water-cooler talk and on-site collaboration as much as anybody else, they’re understandably concerned about the cybersecurity implications of a more broad-based return to work. It could be a challenge. But with proper planning and follow-through, enterprises can manage the risk and solidify their strategies for protection going forward.


About the Authors

Rick VanoverRick Vanover (Cisco Champion, VMware vExpert) is Senior Director of Product Strategy for Veeam Software based in Columbus, Ohio. Vanover’s experience includes system administration and IT management; with virtualization, cloud, and storage technologies being the central theme of his career recently. As a blogger, podcaster, and active member of the IT community, Vanover builds relationships and spreads excitement about Veeam solutions. Before becoming the “go-to” guy for Veeam questions, Vanover was in system administration and IT management.  His community designations include VMware vExpert and Cisco Champion.

A 28-year veteran in the storage industry, Dave Russell recently joined Veeam as its new Vice President of Enterprise Strategy, responsible for driving strategic product and go-to-market programs, spearheading industry engagement, and evangelizing Veeam’s vision for the Hyper-Available Enterprise at key events across the globe, and working with the Executive Leadership team in accelerating the company’s growth in the enterprise. Russell most recently held the role of Vice President and Distinguished Analyst at Gartner. His research focus at Gartner was on storage strategies and technologies, with an emphasis on backup/recovery, snapshot and replication, software-defined storage (SDS), and storage management. He was the lead author of the Magic Quadrant for Data Center Backup & Recovery Solutions from 2006 to 2017. Prior to joining Gartner, Russell spent 15 years at IBM in storage product development as a Software Engineer in mainframe backup/recovery and as a manager of product development, architecture, and strategy teams for distributed systems backup/recovery, and storage solutions.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

NSW Government Proposes Mandatory Notification of Data Breach Scheme

New South Wales data breach disclosure bill

The organizations in New South Wales (NSW), Australia, would mandatorily need to report data breaches to the law enforcement authorities. The NSW government recently proposed the “Privacy and Personal Information Protection Amendment Bill 2021” that will require public and private enterprises to disclose any security breaches to the Privacy Commissioner and any affected people.

The proposed mandatory notification of the data breaches (MNDB) scheme, which is open for consultation until June 18, 2021, aims to bolster data privacy protection and extends the data breach reporting requirements in the state.  Once approved, NSW would become the first Australian state to introduce a mandatory data breach notification scheme, creating new security standards and transparency in data protection management.

The data disclosure notification should contain:

  • Formation and description about the data breach, including when and how it happened
  • Details of the date that the agency first become aware of the breach
  • Description of what data has been disclosed
  • Assurances about what data has not been disclosed
  • What the agency is doing to control or reduce the harm
  • What steps the organization has taken to protect and negate further disclosure
  • Details of the number of persons affected in the data breach
  • Whether the affected persons have been advised
  • Information about the agency’s remedial action plan
  • Information as to whether any reports have been made to other relevant bodies

Currently, there are no obligations on data breach disclosures. The agencies are encouraged to voluntarily report any data breaches to the Privacy Commissioner and the affected individuals. Besides, organizations are urged to implement robust security measures to protect users’ personal information.

What the experts say…

Commenting on the proposed bill, Attorney General Mark Speakman said, “The protection of people’s privacy is crucial to public confidence in NSW Government services. I encourage anyone with an interest in this area to submit. If passed, this Bill will introduce a scheme that will ensure greater openness and accountability in relation to the handling of personal information held by NSW public sector agencies.”

“The NSW Government is committed to enhancing services through digital innovation, but it is vital the use of technology and data embodies the highest privacy, trust, and security standards. The Information and Privacy Commission NSW and agencies such as Cyber Security NSW support the introduction of mandatory reporting to clarify agency obligations and give the NSW public greater certainty about how data breaches involving personal information will be handled,” said the Minister for Digital and Minister for Customer Service Victor Dominello.

Ransomware Attack Forces Temporary Shutdown of Top U.S. Fuel Pipeline Operator

Ransomware attack on Colonial Pipeline

Colonial Pipeline, a top U.S. fuel pipeline operator, shut down its operations temporarily after being hit by a ransomware attack. The company stated the attack halted all pipeline operations and affected some of its IT systems.

“The Colonial Pipeline Company learned it was the victim of a cybersecurity attack. We have since determined that this incident involves ransomware. In response, we proactively took certain systems offline to contain the threat, which has temporarily halted all pipeline operations and affected some of our IT systems. Upon learning of the issue, a leading, third-party cybersecurity firm was engaged, and they have launched an investigation into the nature and scope of this incident, which is ongoing. We have contacted law enforcement and other federal agencies,” the company said.

The Colonial Pipeline infrastructure is the source for half of the U.S. East Coast’s fuel supply. The temporary halt in its operations will affect the supplies from Gulf Coast refining centers to the major cities in the country including Washington, D.C.; Baltimore; and Atlanta. The ransomware attack raised concerns over fuel crunch and price hike as Colonial froze fuel deliveries of 2.5 million barrels per day of gasoline, diesel, and jet fuel through 5,500 miles (8,850 km) of pipelines.

Is DarkSide ransomware group involved?

Colonial engaged cybersecurity firms and third-party security experts to investigate the incident, and informed the law enforcement and the Department of Energy about the attack.

While the investigation is in its early stages, several industry experts opine that ransomware group DarkSide is likely behind the cyberattack. DarkSide ransomware group is known for encrypting systems with ransomware and extorting victims to pay the ransom.

“Colonial Pipeline is taking steps to understand and resolve this issue. At this time, our primary focus is the safe and efficient restoration of our service and our efforts to return to normal operation. This process is already underway, and we are working diligently to address this matter and to minimize disruption to our customers and those who rely on Colonial Pipeline,” the company stated.

Rising Threats to Critical Infrastructures 

The attack on Colonial represents how critical infrastructures become primary targets for cybercriminals. Earlier, a similar ransomware attack on a U.S. natural gas supplying facility brought its operations to a standstill for two days when the organization’s incidence response team implemented a deliberate and controlled shutdown to contain the ransomware spread. Read More Here…

German Security Researcher Claims Apple AirTag can be Hacked

Apple AirTag hacked

On April 20, 2021, Apple launched its upgraded product line of iPads and iMacs in a live streaming event from its HQ in Cupertino. However, the showstopper of the event was not the huge 24” iMac, which was integrated with Apple’s proprietary M1 chipset and a 4.5K retina display, but a small palm-sized gadget weighing just 11 g and merely a quarter over an inch (1.26 in). You guessed it right! We are talking about Apple’s AirTag, the most-awaited and affordable product in the tech giant’s product catalog. This NFC and Bluetooth-enabled gadget was designed to help its users find and secure their essentials like keys, wallets, luggage, etc., but if the latest claims of a German security researcher are true, then Apple’s AirTag can be hacked too.

How Apple’s AirTag Gets Hacked

Apple has been known for adhering to strict security and privacy regulations for countering the exploitation of its products. However, a German researcher going by an alias name “stacksmashing,” has proven otherwise. The researcher successfully broke into the microcontroller of Apple’s AirTag, which gave him access to reprogram or modify the firmware.

In pursuit of hacking the AirTag, the researcher reverse-engineered the microcontroller. This might sound easy, but it certainly was not, as he reportedly bricked two AirTags in the process. However, once he successfully broke into the microcontroller, he re-flashed it and made changes as per his convenience.

Apple’s AirTag has a “Lost” mode, which, when activated by its owner, displays a default “found.apple.com” URL on the finder’s NFC-enabled device when it comes in proximity of the AirTag. On clicking this URL, the finder is redirected to Apple’s website where they can manage to contact the owner of the tag.

The Intent Behind the Hack

To test his break-in, the researcher changed this URL on the AirTag to show that, if the URL is modified, threat actors can intentionally leave AirTags on “Lost” mode around public places for people to find them. And when they attempt to launch the website for finding its owner, they could be redirected to a malicious URL instead.

Apple’s fans might feel awry about the product being compromised this soon after its launch, however, the researcher’s intent at pinpointing the problem could help Apple resolve and patch the loophole at the earliest.

Watch the demo video of the Apple’s AirTag hack below:

Related News:

REvil Ransomware Gang Targets Apple’s Supplier, Quanta; Threatens to Leak Blueprints