Millions of Households at Risk from Outdated Routers

Millions of Households at Risk from Outdated Routers

Millions of households could be at risk of cyber-attack because they’re running outdated and unpatched routers, a new investigation has found.

Unprotected routers are an increasingly popular target for attackers, theoretically enabling them to hijack smart home devices and eavesdrop on communications and web browsing.

Consumer rights group Which surveyed more than 6000 UK adults back in December to find out which router models they were using.

Extrapolating this data, it calculated that as many as 7.5 million households may be running routers with security issues.

After selecting some of the most common devices, it enlisted the help of Red Maple Technologies to test them, and discovered issues with more than half, from ISPs including Virgin, Sky, TalkTalk, EE and Vodafone.

One of the most common issues was a lack of firmware updates, leaving the devices potentially exposed to exploitation. Which claimed most of the models it tested hadn’t been updated since 2018, and some since 2016 — affecting an estimated six million users.

Another problem is weak default passwords which are easy to guess, allowing remote attackers to potentially hijack devices.

The researchers also discovered local network vulnerabilities, although these require an attacker to be within Wi-Fi range to exploit.

Which said not all old routers are inherently insecure, as long as they don’t allow weak default passwords and have regular firmware updates. However, it urged consumers to check and change any weak passwords and to request a new model if theirs is no longer receiving updates.

Tripwire VP of product management and strategy, Tim Erlin, argued that most modern connected devices will automatically update.

“The situation with updating connected devices in consumers’ homes has changed fairly dramatically and rapidly. It wasn’t long ago that the idea of a device automatically updating without the user’s knowledge was considered problematic, whereas now it’s a basic expectation,” he added.

“That rapid shift has left a sizable security gap in terms of deployed devices that don’t auto-update. Unfortunately, it’s likely that gap won’t be closed until those devices are simply replaced.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Millions of Households at Risk from Outdated Routers

Millions of Households at Risk from Outdated Routers

Millions of households could be at risk of cyber-attack because they’re running outdated and unpatched routers, a new investigation has found.

Unprotected routers are an increasingly popular target for attackers, theoretically enabling them to hijack smart home devices and eavesdrop on communications and web browsing.

Consumer rights group Which surveyed more than 6000 UK adults back in December to find out which router models they were using.

Extrapolating this data, it calculated that as many as 7.5 million households may be running routers with security issues.

After selecting some of the most common devices, it enlisted the help of Red Maple Technologies to test them, and discovered issues with more than half, from ISPs including Virgin, Sky, TalkTalk, EE and Vodafone.

One of the most common issues was a lack of firmware updates, leaving the devices potentially exposed to exploitation. Which claimed most of the models it tested hadn’t been updated since 2018, and some since 2016 — affecting an estimated six million users.

Another problem is weak default passwords which are easy to guess, allowing remote attackers to potentially hijack devices.

The researchers also discovered local network vulnerabilities, although these require an attacker to be within Wi-Fi range to exploit.

Which said not all old routers are inherently insecure, as long as they don’t allow weak default passwords and have regular firmware updates. However, it urged consumers to check and change any weak passwords and to request a new model if theirs is no longer receiving updates.

Tripwire VP of product management and strategy, Tim Erlin, argued that most modern connected devices will automatically update.

“The situation with updating connected devices in consumers’ homes has changed fairly dramatically and rapidly. It wasn’t long ago that the idea of a device automatically updating without the user’s knowledge was considered problematic, whereas now it’s a basic expectation,” he added.

“That rapid shift has left a sizable security gap in terms of deployed devices that don’t auto-update. Unfortunately, it’s likely that gap won’t be closed until those devices are simply replaced.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#COVID19 Researchers Lose a Week’s Work to Ryuk Ransomware

#COVID19 Researchers Lose a Week’s Work to Ryuk Ransomware

An organization involved in COVID-19 research lost a week’s worth of critical data after a Ryuk attack which used a stolen password, according to Sophos.

Cybersecurity vendor Sophos revealed the case yesterday as a cautionary tale of what can happen when organizations don’t follow security  best practice.

The problem was traced back to one of the university students that the European research institute collaborates with as part of its outreach programs.

That student obtained what they thought was a ‘crack’ version of a data visualization tool they needed, except in reality it contained information-stealing malware. The individual apparently disabled Windows Defender and their PC firewall after the security tool triggered a malware alert pre-download.

The malware harvested keystrokes, stealing browser, cookies, clipboard data and, it transpired, the student’s log-ins for the research institute.

“Thirteen days later a remote desktop protocol (RDP) connection was registered on the institute’s network using the student’s credentials,” Sophos explained.

“A feature of RDP is that a connection also triggers the automatic installation of a printer driver, enabling users to print documents remotely. This allowed the Rapid Response investigation team to see that the registered RDP connection involved a Russian language printer driver and was likely to be a rogue connection. Ten days after this connection was made, the Ryuk ransomware was launched.”

Although the unnamed biomolecular specialist had back-ups, they were not fully up-to-date, meaning that a week’s worth of vital research was lost. The firm also suffered a significant operational cost as all computer and server files had to be rebuilt from the ground-up before data could be restored, the security vendor said.

“It is unlikely that the operators behind the ‘pirated software’ malware are the same as the ones who launched the Ryuk attack,” said Peter Mackenzie, manager of Rapid Response at Sophos.

“The underground market for previously compromised networks offering attackers easy initial access is thriving, so we believe that the malware operators sold their access on to another attacker. The RDP connection could have been the access brokers testing their access.”

Sophos recommended organizations deploy multi-factor authentication (MFA) for access to any internal networks, especially from third-parties, keep software regularly updated, segment networks and restrict account privileges.

It also urged customers to lock down RDP access with static Local Area Network (LAN) rules, via a group policy or using access control lists.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#COVID19 Researchers Lose a Week’s Work to Ryuk Ransomware

#COVID19 Researchers Lose a Week’s Work to Ryuk Ransomware

An organization involved in COVID-19 research lost a week’s worth of critical data after a Ryuk attack which used a stolen password, according to Sophos.

Cybersecurity vendor Sophos revealed the case yesterday as a cautionary tale of what can happen when organizations don’t follow security  best practice.

The problem was traced back to one of the university students that the European research institute collaborates with as part of its outreach programs.

That student obtained what they thought was a ‘crack’ version of a data visualization tool they needed, except in reality it contained information-stealing malware. The individual apparently disabled Windows Defender and their PC firewall after the security tool triggered a malware alert pre-download.

The malware harvested keystrokes, stealing browser, cookies, clipboard data and, it transpired, the student’s log-ins for the research institute.

“Thirteen days later a remote desktop protocol (RDP) connection was registered on the institute’s network using the student’s credentials,” Sophos explained.

“A feature of RDP is that a connection also triggers the automatic installation of a printer driver, enabling users to print documents remotely. This allowed the Rapid Response investigation team to see that the registered RDP connection involved a Russian language printer driver and was likely to be a rogue connection. Ten days after this connection was made, the Ryuk ransomware was launched.”

Although the unnamed biomolecular specialist had back-ups, they were not fully up-to-date, meaning that a week’s worth of vital research was lost. The firm also suffered a significant operational cost as all computer and server files had to be rebuilt from the ground-up before data could be restored, the security vendor said.

“It is unlikely that the operators behind the ‘pirated software’ malware are the same as the ones who launched the Ryuk attack,” said Peter Mackenzie, manager of Rapid Response at Sophos.

“The underground market for previously compromised networks offering attackers easy initial access is thriving, so we believe that the malware operators sold their access on to another attacker. The RDP connection could have been the access brokers testing their access.”

Sophos recommended organizations deploy multi-factor authentication (MFA) for access to any internal networks, especially from third-parties, keep software regularly updated, segment networks and restrict account privileges.

It also urged customers to lock down RDP access with static Local Area Network (LAN) rules, via a group policy or using access control lists.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Misconfigured Database Exposes 200K Fake Amazon Reviewers

Misconfigured Database Exposes 200K Fake Amazon Reviewers

A misconfigured database has exposed what appears to be a major coordinated scheme by Amazon vendors to procure fake reviews for their products.

At team at AV reviews site SafetyDetectives found the China-based Elasticsearch server exposed online without any password protection or encryption.

The 7GB trove contained over 13 million records including the email addresses and WhatsApp/Telegram phone numbers of vendor contacts, plus email addresses, surnames, PayPal account details and Amazon account profiles of reviewers.

According to SafetyDetectives, fake review scams typically begin with vendors sending their reviewer contacts a list of products for which they would like a five-star review. 

After leaving the review and sending the vendor a link, the reviewer will be paid via PayPal to compensate them for the product purchase and will be allowed to keep the product itself as payment. The reviews site claimed that the leak implicated around 200,000 individuals in such schemes.

The SafetyDetectives team discovered the database on March 1 and it was secured around a week later, although the researchers weren’t able to track down its owner.

“Given the extent of the records and vendors included in the database, it’s possible that the server is not owned by the Amazon vendors running the scam. The server could be owned by a third party that reaches out to potential reviewers on behalf of the vendors,” it explained.

“Third parties might post a picture of the product in a Facebook or WeChat group, asking for reviews in return for free products. The server could also be owned by a large company with several subsidiaries, which would explain the presence of multiple vendors. What’s clear is that whoever owns the server could be subject to punishments from consumer protection laws, and whoever is paying for these fake reviews may face sanctions for breaking Amazon’s terms of service.”

There’s also a potential data security and identity fraud risk for those whose information was exposed in the privacy snafu, SafetyDetectives warned.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Misconfigured Database Exposes 200K Fake Amazon Reviewers

Misconfigured Database Exposes 200K Fake Amazon Reviewers

A misconfigured database has exposed what appears to be a major coordinated scheme by Amazon vendors to procure fake reviews for their products.

At team at AV reviews site SafetyDetectives found the China-based Elasticsearch server exposed online without any password protection or encryption.

The 7GB trove contained over 13 million records including the email addresses and WhatsApp/Telegram phone numbers of vendor contacts, plus email addresses, surnames, PayPal account details and Amazon account profiles of reviewers.

According to SafetyDetectives, fake review scams typically begin with vendors sending their reviewer contacts a list of products for which they would like a five-star review. 

After leaving the review and sending the vendor a link, the reviewer will be paid via PayPal to compensate them for the product purchase and will be allowed to keep the product itself as payment. The reviews site claimed that the leak implicated around 200,000 individuals in such schemes.

The SafetyDetectives team discovered the database on March 1 and it was secured around a week later, although the researchers weren’t able to track down its owner.

“Given the extent of the records and vendors included in the database, it’s possible that the server is not owned by the Amazon vendors running the scam. The server could be owned by a third party that reaches out to potential reviewers on behalf of the vendors,” it explained.

“Third parties might post a picture of the product in a Facebook or WeChat group, asking for reviews in return for free products. The server could also be owned by a large company with several subsidiaries, which would explain the presence of multiple vendors. What’s clear is that whoever owns the server could be subject to punishments from consumer protection laws, and whoever is paying for these fake reviews may face sanctions for breaking Amazon’s terms of service.”

There’s also a potential data security and identity fraud risk for those whose information was exposed in the privacy snafu, SafetyDetectives warned.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk