Chinese Actors Reportedly Breached America’s Largest Transport Network

Chinese Actors Reportedly Breached America’s Largest Transport Network

According to a new report, Chinese threat actors breached North America’s largest transport network in a likely cyber-espionage campaign earlier this year.

The attackers reportedly exploited a zero-day vulnerability in the Pulse Connect Secure remote access product to penetrate the IT systems of New York’s Metropolitan Transportation Authority (MTA) in April.

Although they achieved persistence for several days and compromised three of the transit authority’s 18 computer systems, the MTA claimed that the actors stole no customer or internal data and made no changes to critical systems.

“Our response to the attack, coordinated and managed closely with state and federal agencies, demonstrated that while an attack itself was not preventable, our cybersecurity defense systems stopped it from spreading through MTA systems,” a statement sent to the New York Times revealed.

The MTA is said to have begun a forensic review following warnings about the zero-day by US authorities.

According to the report, the attack involved two sets of Chinese threat groups. A potential target for the attack was insider information on subway cars and rail networks that could allow the country to dominate the global market.

Pulse Secure customers were warned about the bug in late April. As Infosecurity reported at the time, CVE-2021-22893 has a CVSS score of 10.0 and is listed as a critical authentication bypass.

It was being exploited in combination with multiple legacy CVEs in the product from 2019 and 2020 to bypass multi-factor authentication — enabling attackers to install web shells and perform espionage activities.

Brooks Wallace, VP EMEA at Deep Instinct, argued that although the attackers didn’t cause any physical damage to transport networks around New York, they had the opportunity.

“This attack could easily have been a way for the attackers to determine whether or not an isolated infrastructure could be breached and taken down, with plans for a more widespread cyber-attack across the US in the future,” he added.

“Staying at the bleeding edge of innovation is the only way to outpace the attackers. The best protection against attacks such as this one is a multi-layered approach using a variety of solutions. A ‘prevention-first’ mindset is also key.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Security and Human Behavior (SHB) 2021

Today is the second day of the fourteenth Workshop on Security and Human Behavior. The University of Cambridge is the host, but we’re all on Zoom.

SHB is a small, annual, invitational workshop of people studying various aspects of the human side of security, organized each year by Alessandro Acquisti, Ross Anderson, and myself. The forty or so attendees include psychologists, economists, computer security researchers, sociologists, political scientists, criminologists, neuroscientists, designers, lawyers, philosophers, anthropologists, business school professors, and a smattering of others. It’s not just an interdisciplinary event; most of the people here are individually interdisciplinary.

Our goal is always to maximize discussion and interaction. We do that by putting everyone on panels, and limiting talks to six to eight minutes, with the rest of the time for open discussion. The format translates well to Zoom, and we’re using random breakouts for the breaks between sessions.

I always find this workshop to be the most intellectually stimulating two days of my professional year. It influences my thinking in different, and sometimes surprising, ways.

This year’s schedule is here. This page lists the participants and includes links to some of their work. As he does every year, Ross Anderson is liveblogging the talks.

Here are my posts on the first, second, third, fourth, fifth, sixth, seventh, eighth, ninth, tenth, eleventh, twelfth, and thirteenth SHB workshops. Follow those links to find summaries, papers, and occasionally audio recordings of the various workshops. Ross also maintains a good webpage of psychology and security resources.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Apple Users: This macOS Malware Could Be Spying on You

In 2018, Macs accounted for 10% of all active personal computers. Since then, popularity has skyrocketed. In the first quarter of 2021, Macs experienced 115% growth when compared to Q1 2020, putting Apple in fourth place in the global PC market share. It is safe to say that Macs are well-loved and trusted devices by a significant portion of the population — but just how safe are they from a security perspective? 

Many users have historically believed that Macs are untouchable by hackers, giving Apple devices a reputation for being more “secure” than other PCs. However, recent attacks show that this is not the case. According to TechCrunch, a new malware called XCSSET was recently found exploiting a vulnerability that allowed it to access parts of macOS, including the microphone, webcam, and screen recorder — all without consent from the user.  

Let’s dive deeper into how XCSSET works.  

Manipulating Macs with Zero-Day Exploits 

Researchers first discovered XCSSET in 2020. The malware targeted Apple developers and the projects they use to build and code apps. By targeting app development projects, hackers infiltrated apps early in their production, causing developers to unknowingly distribute the malware to their users.  

Once the malware is running on a user’s device, it uses multiple zero-day attacks to alter the machine and spy on the user. These attacks allow the hacker to:   

  • Steal cookies from the Safari browser to gain access to a user’s online accounts. 
  • Quietly install a development version of Safari that allows attackers to modify and snoop on virtually any website. 
  • Secretly take screenshots of the victim’s device.  

XCSSET’s Significance for macOS Users 

While macOS is supposed to ask users for permission before allowing any app to record the screen, access the microphone or webcam, or open the user’s storage, XCSSET can bypass all of these permissions. This allows the malware to sneak in under the radar and inject malicious code into legitimate apps that commonly ask for screen-sharing permissions such as Zoom, WhatsApp, and Slack. By disguising itself among these legitimate apps, XCSSET inherits their permissions across the computer and avoids getting flagged by macOS’s built-in security defenses. As a result, the bug could allow hackers to access the victim’s microphone, webcam, or capture their keystrokes for login credentials or credit card information.  

How to Stay Protected Against macOS Malware 

It is unclear how many devices were affected by XCSSET. Regardless, it is crucial for consumers to understand that Mac’s historical security reputation does not replace the need for users to take online safety precautions. The following tips can help macOS users protect themselves from malware:  

1. Update your software.   

Software developers are continuously working to identify and address security issues. Frequently updating your devices’ operating systems, browsers, and apps is the easiest way to have the latest fixes and security protections. For example, Apple confirmed that it addressed the bug exploited by XCSSET in macOS 11.4, which was made available on May 24th, 2021. 

2. Avoid suspicious emails or text messages from unknown senders.  

Hackers often use phishing emails or text messages as a means to distribute malware by disguising their malicious code in links and attachments. Do not open suspicious or irrelevant messages, as this can result in malware infection. If the message claims to be from a business or someone you know, reach out to the source directly instead of responding to the message. This will allow you to confirm the sender’s legitimacy.  

3. Use a comprehensive security solution. 

Use a solution like McAfee Total Protection, which can help protect devices against malware, phishing attacks, and other threats. It also includes McAfee WebAdvisor — a tool to help identify malicious websites. 

Regardless of whether you are Team PC or Team Mac, it is important to realize that both platforms are susceptible to cyberthreats that are constantly changing. Doing your research on prevalent threats and software bugs puts you in a better position to protect your online safety.  

Stay Updated 

To stay updated on all things McAfee and on top of the latest consumer and mobile security threats, follow @McAfee_Home on Twitter, subscribe to our newsletter, listen to our podcast Hackable?, and ‘Like’ us on Facebook.  

The post Apple Users: This macOS Malware Could Be Spying on You appeared first on McAfee Blogs.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Museum Website Vandalized with X-Rated Ads

Museum Website Vandalized with X-Rated Ads

Visitors to a Scottish tourism website were greeted with X-rated images after malicious cyber-criminals plastered its pages with pornographic promotions. 

The independent site eastlothianmuseums.org was set up by organizers ABC to help tourists seeking cultural experiences in East Lothian. 

“People usually tend to overlook museums when they are on a break because these places take time and lot of patience, but we at ABC are dedicated towards changing that mindset and introduce people to museums in East Lothian,” said the group. 

But despite describing themselves as a “team that loves museums and wants the natives of Scotland as well as travelers from other countries to know their importance,” ABC appears to have abandoned the website.

The East Lothian Courier reports that no news or updates have been posted to the eastlothianmuseums.org site in more than two years. 

After apparently being forsaken by its operators, the site fell into the hands of cyber-criminals hoping to lure victims with links to sexually explicit content. After hacking into the site, the threat actors posted links to adult websites that promise to fulfill “society’s darkest fantasies.”

In addition to adware, the site was laced with graphic descriptions of sex acts that could be viewed by clicking on certain links.

East Lothian Council said the racy site has now been updated with a security warning. 

“We are aware of this site, which details information on a range of museums and related visitor attractions across the county. It is not linked to or connected with East Lothian Council and our museums service or using the council branding style or logo.

“Anyone connecting to this site will see a security warning which indicates that continued use of the site may cause problems to the user.”

Enquiries by the council were unable to establish where the site might be hosted. But misspellings of the word ‘whisky’ suggest it may not be based in Scotland. 

Dirk Schrader, global vice president of security research at New Net Technologies, commented: “Websites are an easy target for attackers, as they are destined to be publicly available. This means the attacker can scan them with a range of automated penetration tools. 

“Badly maintained websites, using outdated content management systems, are the go-to place for attackers to install reflectors or agents to enable additional attacks.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Missing Toddler Chat Group Banned

Missing Toddler Chat Group Banned

A partial settlement has been reached in a cyber-bullying case brought by the parents of a missing toddler against the operator of a chat group set up to discuss the fate of their son.

Dylan Ehler was three years old when he vanished from the backyard of his grandmother’s home in Truro, Nova Scotia, at around 1:15 pm on May 6, 2020. Searches for the missing child were called off after two weeks, and his whereabouts remain a mystery.

The only trace of the toddler discovered to date were his rubber boots, which were located roughly 150 meters apart along Lepper Brook.

In online discussions of the case, Ehler’s parents, Jason Ehler and Ashley Brown, have been variously accused without evidence of involvement in the boy’s disappearance and of murdering their son. 

In February, Ehler’s parents decided to take April Diane Moulton and Tom Hurley, also known as Tom Hubley, to court, arguing that the accusations and insults posted on a Facebook page administered by the pair constitute cyber-bullying.

The page, which was called “Dylan Ehler Open for Discussions” or “Dylan Ehler Open for Suggestions,” at one point had over 17,000 members. 

“It’s been horrific quite frankly,” said the parents’ lawyer, Allison Harris. “They’re dealing with looking for their son, and this has taken away from that.

“Every time they go online, they get these kinds of messages, and some of this has spilled over into the community, and that’s impacting them as well.”

In an order signed late last month in Nova Scotia Supreme Court, Moulton was prohibited from re-opening the now closed Facebook page about Dylan and from starting another one like it. Moulton is also banned from making any further public posts about the missing child or his parents.

Hurley was offered a similar agreement to the one accepted by Moulton but has not accepted it. He reportedly said that since he lives in the same small town as Ehler’s parents, he cannot agree to a ban on seeing them. 

The parties are due to meet face to face in court on August 3 for a hearing.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk