Major HTTP Vulnerability in Windows Could Lead to Wormable Exploit

Today, Microsoft released a highly critical vulnerability (CVE-2021-31166) in its web server http.sys. This product is a Windows-only HTTP server which can be run standalone or in conjunction with IIS (Internet Information Services) and is used to broker internet traffic via HTTP network requests. The vulnerability is very similar to CVE-2015-1635, another Microsoft vulnerability in the HTTP network stack reported in 2015.

With a CVSS score of 9.8, the vulnerability announced has the potential to be both directly impactful and is also exceptionally simple to exploit, leading to a remote and unauthenticated denial-of-service (Blue Screen of Death) for affected products.

The issue is due to Windows improperly tracking pointers while processing objects in network packets containing HTTP requests. As HTTP.SYS is implemented as a kernel driver, exploitation of this bug will result in at least a Blue Screen of Death (BSoD), and in the worst-case scenario, remote code execution, which could be wormable. While this vulnerability is exceptional in terms of potential impact and ease of exploitation, it remains to be seen whether effective code execution will be achieved. Furthermore, this vulnerability only affects the latest versions of Windows 10 and Windows Server (2004 and 20H2), meaning that the exposure for internet-facing enterprise servers is fairly limited, as many of these systems run Long Term Servicing Channel (LTSC) versions, such as Windows Server 2016 and 2019, which are not susceptible to this flaw.

At the time of this writing, we are unaware of any “in-the-wild” exploitation for CVE-2021-31166 but will continue to monitor the threat landscape and provide relevant updates. We urge Windows users to apply the patch immediately wherever possible, giving special attention to externally facing devices that could be compromised from the internet. For those who are unable to apply Microsoft’s update, we are providing a “virtual patch” in the form of a network IPS signature that can be used to detect and prevent exploitation attempts for this vulnerability.

McAfee Network Security Platform (NSP) Protection
Sigset Version: 10.8.21.2
Attack ID: 0x4528f000
Attack Name: HTTP: Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability (CVE-2021-31166)

McAfee Knowledge Base Article KB94510:
https://kc.mcafee.com/corporate/index?page=content&id=KB94510

 

 

The post Major HTTP Vulnerability in Windows Could Lead to Wormable Exploit appeared first on McAfee Blogs.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

What the MITRE Engenuity ATT&CK® Evaluations Means to SOC Teams

SOCwise Weighs In

When the infamous Carbanak cyberattack rattled an East European bank three years ago this month few would have guessed it would later play a starring role in the MITRE Engenuity™ enterprise evaluations of cybersecurity products from ourselves and 28 other vendors. We recently shared the results of this extensive testing and in a SOCwise discussion we turn to our SOCwise experts for insights into what this unprecedented exercise may mean for SOC teams assessing both strategy concerns and their tactical effectiveness.

Carbanak is a clever opponent known for innovative attacks on banks. FIN7 uses the similar malware and strategy of effective espionage and stealth   to target U.S. retail, restaurant and hospitality sectors, according to MITRE Engenuity™, and both were highlighted in this emulation. These notorious actors have reportedly stolen more than $1 billion worldwide over the past five years. An annual event, the four-day ATT&CK Evaluation spanned 20 major steps and 174 sub-steps of the MITRE framework.

The first thing to realize about this exercise is few enterprises could ever hope to match its scope. What do you get when you match up red and blue teams? “I have not been through an exercise like that in an organization with both the red team and blue teams operationally trying to determine what their strengths and weaknesses are,” said Colby Burkett, McAfee XDR architect, a participant in the event, on our recent SOCwise episode. “And that was fantastic.”

A lot of SOC teams conduct vulnerability assessments and penetration testing, but never emulate these types of behaviors, noted Ismael Valenzuela, McAfee’s Sr. Principal Engineer and co-host of SOCwise. And, he adds that many organizations lack the resources and skills to do purple-teaming exercises.

While our SOCwise team raved about the value of conducting broad scale purple-team exercises, they expressed concern that the emphasis on “visibility” is no more valuable than “actionability.” McAfee, which scored 87% on visibility, one of the industry’s best, turned in a remarkable 100% on prevention in the MITRE Engenuity™ evaluations.

Illuminating Visibility

When we think about visibility, we think about how much useful information we can provide to SOC analysts when an attack is underway. There may be a tsunami of attack data entering SOCs, but it’s only actionable when the data that’s presented to analysts is relevant, noted Jesse Netz, Principal Engineer at McAfee.

A well-informed SOC finds a sweet spot on an axis where the number of false positives is low enough and the true positives are high enough “where you can actually do something about it,” added Netz.

He believes that for SOC practitioners, visibility is only part of the conversation. “How actionable is the data you’re getting? How usable is the platform in which that data is being presented to you?”

For example, in the evaluation we saw McAfee’s MVISION EDR preserve actionability and reduce alert fatigue. We excelled in the five capabilities that matter most to SOC teams: time-based security, alert actionability, detection in depth, protection, and visibility.

If you can’t do anything about the information you obtain, your results aren’t really useful in any way. In this regard, prevention also trumps visibility. “It’s great that we can see and gain visibility into what’s happening,” explained Netz. “But it’s even better at the end of the day as a security practitioner to be able to prevent it.”

Expanding the Scope

The SOCwise team overall applauded the progressively sophisticated approach taken by the MITRE Engenuity™ enterprise evaluations of cybersecurity products—now in its third year. However, our panel of experts noted that this round of testing was more about defending endpoints, rather than cloud-based operations, which are fairly central to defending today’s enterprise. They expect that focus may change in the future.

The MITRE Engenuity™ enterprise evaluations provide a lot of useful data, but they should never be the single deciding factor in a cybersecurity product purchase decision. “Use it as a component of your evaluation arsenal,” advises Netz. “It’ll help to provide kind of statistics around visibility capabilities in this latest round, including some detection capabilities as well, but be focused on the details and make sure you’re getting your information from multiple sources.”

For instance, Carbanak and FIN 7 attacks may not be relevant to your particular organization, especially if they’re centered on Cloud-based operations.

While no emulation can perfectly replicate the experience of battling real-time, zero-day threats, McAfee’s Valenzuela believes these evaluations deliver tremendous value to both our customers and our threat content engineers.

 

SOCwise

Optimize your Security Operations Center with SOCwise
Visit Now

The post What the MITRE Engenuity ATT&CK® Evaluations Means to SOC Teams appeared first on McAfee Blogs.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

5 Ways to Protect Your Online Privacy

When you open your laptop or your mobile device, what is the first thing you do? Do you head to your favorite social media site to skim the latest news, or do you place your weekly grocery delivery order? No matter what your daily online habits are, even the slightest degree of caution can go a long way in staying secure onlineThat’s because hackers are experts at hiding malware in your everyday online routines, or even infiltrating your cookies to steal login information and learn about your personal preferences. According to a StatsCan Canadian internet use survey, six out of ten internet users reported experiencing a cybersecurity incident. There are many hoops to jump through when navigating the digital landscape. By taking the necessary steps to remedy vulnerabilities in your digital activity, you can dramatically improve your online protection. 

Online Threats to Watch Out For 

Cybercriminals take advantage of online users through routine avenues you would not expectHere are three common ways that cybercriminals eavesdrop on online users. 

1. Adware 

Adware, or advertising-supported software, generates ads in the user interface of a person’s device. Adware is most often used to generate revenue for the developer by targeting unsuspecting online users with personalized ads paid by third parties. These third parties usually pay per view, click, or application installation.  

Though not always malicious, adware crosses into dangerous territory when it is downloaded without a user’s consent and has nefarious intent. In this case, the adware becomes known as a potentially unwanted application (PUA) that can remain undetected on users’ devices for long periods of timeAccording to a report by the Cybersecure Policy Exchange, an unintentionally installed or downloaded computer virus or piece of malware is one of the top five cybercrimes that Canadians experience. The PUA can then create issues like frequent crashes and slow performance 

Users unknowingly download adware onto their device when they download a free ad-supported program or visit a non-secure site that does not use the Hypertext Transfer Protocol Secure (HTTPS) to encrypt online communication.  

2. Malvertising 

Hackers also use invasive tactics known as ad injections, where they inject ads with malicious code for increased monetary gain. This is a practice known as malvertising.” If a user clicks on a seemingly legitimate and well-placed ad, they risk exposing themselves to numerous online threats. These ads can be infected with malware such as viruses or spyware. For example, hackers can exploit browser vulnerabilities to download malware, steal information about the device system, and gain control over its operations. Hackers can also use malvertising to run fraudulent tech support scams, steal cookie data, or sell information to third-party ad networks. 

3. Autofill 

Another vulnerability that many may not realize is their browser’s built-in autofill functions. As tempting as it is to use your browser’s autofill function to populate a long-formthis shortcut may not be safe. Cybercriminals have found ways to capture credentials by inserting fake login boxes onto a web page that users cannot see. So, when you accept the option to autofill your username and password, you are also populating these fake boxes.  

Tips For Rethinking Your Online Habits 

Take a proactive approach to your digital protection the next time you are browsing the internet by reassessing your online habits. Check out these five tips to ensure you are staying as safe as possible online. 

1. Clear your cookies on your browser 

Cookie data can contain anything from login information to credit card numbers. Cybercriminals looking to exploit this information can hijack browser sessions to pose as legitimate users and steal cookies as they travel across networks and servers. As a result, it is essential for online users to regularly clear out their cookies to better protect their information from falling into the wrong hands. Navigate to your browser’s history, where you can wipe the data associated with each browser session, including your cookies.  

2. Use a reliable password manager 

Clearing your browser’s cookie data will also remove your saved logins, which is why leveraging a password manager can make it easier to access regularly visited online accounts.  

Many browsers come with a built-in password generator and manager; however, it is better to entrust your logins and password to a reputable password manager. Browser password managers are not as secure as password managers, because anyone who has access to your device will also access your online information. A password managersuch as True Keyprovides a more secure solution since it requires you to log in with a separate master password. A password manager also works across various browsers and can generate stronger passwords than those created by your browser.  

3. Adjust browser privacy settings 

In addition to clearing cookie data, users should adjust their browser settings to ensure their online sessions remain private.  

Another option is to access the internet in Private Browsing Mode to automatically block third-party tracking, making it a quick and easy option to ensure private browsing. Users can also enable the “do not track” function of their browser to prevent third-party tracking by advertisers and websites. Additionally, you can adjust your browser settings to block pop-up ads and control site permissions, such as access to cameras and locations.  

4. Use an ad blocker 

Ad blockersuppress unwanted and potentially malicious ads to ensure a safer browsing experience. Ad blockers can also make it easier to view page layout by removing distracting ads and optimizing page load speed. Additionally, they prevent websites from tracking your information that third parties can sell. 

5. Leverage a reputable security solution  

Deploying a security solution like McAfee Total Protection ensures the safest internet browsing experience through a holistic approach for threat detection, protection, and remediation. Equipped with a password manager, antivirus software, and firewall protection, users can effectively sidestep online threats while browsing thinternet. 

Take Action to Ensure Safe Browsing 

Your online behavior can say a lot about you so make sure you safeguard your internet protection. Whether it is through malvertising or invisible forms, hackers can glean information to paint a picture of who you are to target you through deceptive tactics. Cybercriminals are always looking for vulnerabilities which is why assessing your online habits sooner rather than later is a critical first step to smarter online browsing. 

Stay Updated 

To stay updated on all things McAfee and on top of the latest consumer and mobile security threats, follow @McAfee_Home on Twitter, subscribe to our newsletter, listen to our podcast Hackable?, and ‘Like’ us on Facebook. 

The post 5 Ways to Protect Your Online Privacy appeared first on McAfee Blogs.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Kansas Identity Theft Spike Could Be Linked to Data Breach

Kansas Identity Theft Spike Could Be Linked to Data Breach

The state with the highest identity theft rate in the country may have been impacted by a Department of Labor data breach.

According to new data released by the Federal Trade Commission (FTC), the reported rate of identity theft in Kansas in 2020 was higher than that of any other state and more than three times greater than the national average. 

Last year, 43,211 Kansans informed the FTC that someone had stolen or attempted to steal their identity, a year-on-year increase of 1,802%.

KWCH reports that Kansas lawmakers are investigating the possibility of a connection between the surge in identity theft and an alleged data breach at the Kansas Department of Labor (KDOL). 

An investigation into a possible breach was launched after a woman named Lisa Hirst accidentally entered the wrong Social Security number into the KDOL website in February and was shown someone else’s personal information. 

“I can’t be the only one who found this,” said Hirst. “I mean, it was so easy to do, and I didn’t even mean to.”

A February report from the Kansas Legislative Post Audit Division stated that just under a quarter ($600m) of the roughly $2.6bn Kansas paid in state and federal unemployment benefits in 2020 could have been fraudulent.

In its own statement, KDOL put the figure lost through fraudulent claims at $290m. 

“LPA did not use the data available to them and instead chose to use a flawed methodology that fundamentally misunderstands KDOL’s fraud prevention process,” said KDOL.

Representative Stephen Owens said that a link between the possible data breach exposed by Hirst and the rise in fraudulent claims might explain a lot.

“Now that this information has been brought to light, it actually, it helps me understand what might actually be going on,” said Owens.

“Originally when we were questioning the fraud department, they were referring back to the Experian and Equifax breach of data a few years back, and possibly that data was sold on the dark web that those Social Security numbers were being utilized to manipulate our system. But if it’s as easy as (Hirst) has found it to be, then there wouldn’t even require any purchase on the dark web; the information is just there and it’s just a click away.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Germany Bans Facebook from Processing WhatsApp Data

Germany Bans Facebook from Processing WhatsApp Data

A German privacy watchdog has banned social media company Facebook from harvesting data on WhatsApp users. 

Hamburg’s data protection commissioner said that WhatsApp’s privacy policy was in breach of European data protection rules following a recent change. 

WhatsApp, which was bought by Facebook in 2014, has more than 2 billion monthly users. In January 2021, the app asked its users to grant WhatsApp additional powers to share their data with its parent company, Facebook. 

Users have been given until May 15 to agree to the new terms and conditions. WhatsApp has told its users that after this deadline, “you won’t have full functionality of WhatsApp until you accept. 

“For a short time, you’ll be able to receive calls and notifications, but won’t be able to read or send messages from the app.” 

Johannes Caspar, Hamburg’s commissioner for data protection and freedom of information, said in a statement that WhatsApp users had been confronted “with non-transparent conditions for far-reaching data transfer.”

Caspar said that he feared the new terms and conflation would allow WhatsApp to “expand data transfers with Facebook for marketing purposes and direct advertising.”

He also noted that by denying its users the app’s full functionality unless they agreed to the new terms, WhatsApp was preventing users from giving their consent freely. 

“WhatsApp is now used by almost 60 million people in Germany and is by far the most widely used social media application, even ahead of Facebook,” said Caspar. 

“It is therefore all the more important to ensure that the high number of users, which makes the service attractive to many people, does not lead to an abusive exploitation of data power.”

WhatsApp has denied that the privacy update relates to any expansion of data sharing with its parent company. The company said that “the update includes new options people will have to message a business on WhatsApp and provides further transparency about how we collect and use data.” 

The company went on to refute the legality of the commissioner’s statement, which WhatsApp claimed “is based on a fundamental misunderstanding of the purpose and effect of WhatsApp’s update and therefore has no legitimate basis.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

AGs Question Safety of Kids-Only Instagram

AGs Question Safety of Kids-Only Instagram

Attorneys general from 44 states and territories have asked Facebook to ditch its plan to launch a kids’ version of Instagram.

Under federal privacy regulations, children under the age of 13 are technically not allowed to use the Instagram app. In March, Facebook confirmed that it was “exploring a parent-controlled experience” on Instagram that could be used by minors under the age of 13.

In a letter sent yesterday to Facebook CEO Mark Zuckerberg, the attorneys general urged Facebook to “abandon these plans,” citing research that indicated social media, especially Instagram, is damaging to children’s mental health. 

“Use of social media can be detrimental to the health and well-being of children, who are not equipped to navigate the challenges of having a social media account,” stated the letter.

“Further, Facebook has historically failed to protect the welfare of children on its platforms.”

The attorneys general went on to reference research carried out by dozens of organizations and experts that links the use of Instagram to depression, body image concerns, and suicidal ideation among children and adolescents. 

In the letter, they criticize recent comments made by Facebook on the impact of social media use on children, considering this research.

The letter states: “This data and research directly contradict your statements made at the March 2021 Congressional hearing dismissing the idea that social media is harmful to children and claiming that ‘[t]he research we’ve seen is that using social apps to connect to other people can have health benefits.’

“This overly simplified statement conflates the benefits of social connection (of which there are many) with purported benefits of using social media to enable that connection, which as outlined above, carry distinct harms to young children.”

The attorneys general warned that young children who lack a fully developed sense of privacy may not understand what content is appropriate for them to share with others. They warned that this could leave children who use the proposed kids Instagram app vulnerable to sexual grooming. 

A 2019 report by the charity NSPCC found that sex offenders were grooming children on Instagram more than on any other online platform. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#CYBERUK21: Home Secretary Outlines UK Government’s Plan to Tackle Growing Cyber-Threats

#CYBERUK21: Home Secretary Outlines UK Government’s Plan to Tackle Growing Cyber-Threats

Cybersecurity has become a critical component of the UK’s homeland security mission, with more robust action from government required to deal with the dangers in this space. This was the message of UK Home Secretary Priti Patel, speaking during the CYBERUK 2021 online event.

Patel noted that as home secretary, it is her duty to keep citizens safe while at the same time protecting economic prosperity, with “cybersecurity and resilience [becoming] increasingly important” aspects of this, particularly given the technology shift during the COVID-19 crisis.

She described the growing impact of cybercrime, declaring that “the scale of this type of criminality is truly shocking.” For example, Patel said that in the year ending September 2020, there were an estimated 1.7 million cyber-dependent crimes experienced by adults in England and Wales, and the overall cost of computer misuse incidents impacting individuals has been estimated to be over £1bn.

Additionally, recent incidents have emphasized the cyber-threat to nations’ critical national infrastructure. Patel noted the recent ransomware attack on the largest fuel pipeline in the US. She added that the SolarWinds attacks at the end of last year demonstrated that “cyber-operations are often highly sophisticated, and many are very likely to be state sponsored.”

Against this backdrop, Patel said that the UK government is continually working on boosting the nations’ cyber-defenses. “Just as our adversaries are continually developing their tactics, we are always seeking new ways to bolster our defenses,” she outlined. This includes the creation of the National Cyber Force late last year “to help transform the UK’s ability to counter and deter adversaries, further our interests, and promote our values.”

All of this feeds into the government’s ambition to “make the UK one of the safest places to be online.”

Despite the progress made, Patel emphasized that much more needs to be done, and said the government will be developing a comprehensive cyber-strategy to counter cyber-threats. As part of this, Patel noted that it is crucial that law enforcement bodies have the ability to catch and prosecute cyber-criminals, including those perpetrating online child sexual abuse and serious acts of fraud.

Therefore, to ensure these agencies are equipped with “the right tools and mechanisms to detect, disrupt, and deter our adversaries,” Patel said there will be a formal review of the Computer Misuse Act, and will be launching a call for information on the legislation this year.

Patel ended by stating: “These are complex challenges and difficult issues, so it’s vital we work together closely to confront them.” She added: “Ultimately, this is about keeping our citizens, businesses, and our national security safe.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#CYBERUK21: We Have Reached a Moment of Reckoning in Cybersecurity, Says GCHQ Director

#CYBERUK21: We Have Reached a Moment of Reckoning in Cybersecurity, Says GCHQ Director

We have reached “a moment of reckoning” in the cybersecurity and technology space, and urgent action is required to address the challenges being faced, according to the director of GCHQ, Jeremy Fleming, during a keynote address at the CYBERUK 2021 online event.

Fleming began his talk by highlighting the greater role technology is playing in our lives as a result of the ongoing COVID-19 pandemic. While accelerated digitization has enabled society to continue functioning while maintaining social distancing restrictions, it has also provided more opportunities for malicious actors to launch cyber-attacks. “The result is that cybersecurity is even more relevant to our economy, society, and, increasingly, to our security,” noted Fleming.

It is also crucial to recognize that the tech environment is changing, with control shifting toward nations with fundamentally different values from those of the Western world. “We can see that key technology leadership is moving East, which is causing a conflict of interest, of values, where prosperity and security are at stake,” said Fleming, adding that “it follows that cybersecurity is an increasingly strategic issue.”

Greater collaboration is needed to tackle these issues, according to Fleming. This first must occur between nations. He outlined: “No one country can do this in isolation. Working with like-minded partners around the world is key—cyber is most definitely a team sport.”

As well as partnering between countries, there needs to be a much broader perspective brought in within societies to deal with the more sophisticated threat landscape, and to better understand how society interacts with technology. This requires a focus on diversifying the sector. Fleming commented: “The UK will only be able to thrive in the digital era if we’re able to draw people from all backgrounds to work together on these problems.”

Fleming emphasized that such an approach isn’t just morally right, but is also a strategic necessity in intelligence and cybersecurity. “I’ve seen first-hand how bringing together people who think differently helps us to be more innovative, spot better intelligence, and design better tech.”

Fleming concluded that the UK and its allies are at a critical juncture in the technology space, as the recovery from COVID-19 begins. “We know that tech, digital, and cyber are central to our future, and that means all of you, as critical members of the UK’s world-leading cyber team, have a fundamental role to play in unblocking the opportunities that lie ahead,” he stated.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk