Paleo Lifestyle Site Found Leaking PII on 70,000 Users

Paleo Lifestyle Site Found Leaking PII on 70,000 Users

A misconfigured AWS S3 bucket is leaking personal information on 70,000 customers of a popular paleolithic lifestyle site, security researchers at vpnMentor have revealed.

The research team, led by Noam Rotem, discovered the 290MB trove on February 4, and traced it back to Paleohacks, a US health and lifestyle brand that offers content and resources about the paleo diet.

“At the time of writing, the company has ignored every attempt we’ve made to help them close the vulnerability and told us they’re ‘not interested’,” vpnMentor claimed in a blog post yesterday.

The leaky database apparently exposed the personally identifiable information (PII) of around 70,000 users of the site worldwide, dating back to 2015.

The exposed PII includes full names, usernames, dates of birth, email and IP addresses, hashed passwords, employer details, location and more.

Also exposed were password reset tokens for some subscription account holders.

“While the passwords were protected by the bcrypt hashing algorithm (a sophisticated form of password encryption), a hacker could easily use the tokens to reset a person’s password, gain access, and lock the original user out of their account,” vpnMentor argued.

“Doing so would allow the hackers to take control of thousands of Paleohacks accounts and any additional data stored therein.”

Affected users could also be targeted by follow-on phishing attacks and other identity fraud schemes, if attackers got hold of their data, the researchers warned.

Paleohacks may also invite the scrutiny of Californian privacy regulators and even the GDPR, if EU citizens have had their data exposed, vpnMentor argued.

The S3 bucket was discovered as part of a large web scanning project in which the research team scans for exposed cloud databases. It found the offending bucket unsecured and unencrypted.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

DC Officer Info Leaked Online by Ransomware Group: Report

DC Officer Info Leaked Online by Ransomware Group: Report

The personal safety of Washington DC police officers may be at risk after it emerged that ransomware threat actors had managed to steal personnel files in an attack earlier this month.

The acting chief of the US capital’s Metropolitan Police Department (MPD), Robert Contee, said in an email to staff that ‘HR files’ containing personal information were part of the haul, according to CNN.

That adds extra jeopardy for officers in the event that the ransomware group in question, Babuk, decides to permanently post the information on its dark web naming and shaming site. A separate report claimed that information on at least five officers was temporarily leaked by the group to show it means business.

The gang has already claimed to have 250GB of internal data from the MPD in its possession following the raid, including information on informants which it threatened to share with local gangs unless a ransom was paid.

Such ‘double extortion’ tactics are increasingly common among ransomware groups. According to a Coveware report this week, they now appear in a majority (77%) of attacks.

However, rarely do threat actors have stolen information that could endanger lives.

The case is further complicated by the fact that Babuk appears to be calling it a day after having reached its financial goals.

One version of a widely reported note on the group’s dark web site, titled ‘Hello World 2‘ said that breaching the police department was its “last goal.”

“Only they now determine whether the leak will be or not, in any case regardless of the outcome of events with PD, the babuk project will be closed,” it said.

Unfortunately for future potential victims, the gang is planning to open source its malware for others to use in ransomware-as-a-service campaigns.

Security experts were alarmed at the developments in Washington.

“Our research data shows that cyber-criminals are making a conscious effort to hit high-value targets, but the reality is no one is immune from ransomware. The best defense against ransomware is therefore prevention,” argued Nozomi Networks CEO, Edgard Capdevielle.

“This includes training staff on the threat and the techniques cyber-criminals will use to get it onto systems, and performing continuous security monitoring across the entire IT and OT estate, to identify malicious activity or vulnerabilities which cyber-criminals could exploit.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Serious MacOS Vulnerability Patched

Apple just patched a MacOS vulnerability that bypassed malware checks.

The flaw is akin to a front entrance that’s barred and bolted effectively, but with a cat door at the bottom that you can easily toss a bomb through. Apple mistakenly assumed that applications will always have certain specific attributes. Owens discovered that if he made an application that was really just a script—code that tells another program what do rather than doing it itself—and didn’t include a standard application metadata file called “info.plist,” he could silently run the app on any Mac. The operating system wouldn’t even give its most basic prompt: “This is an application downloaded from the Internet. Are you sure you want to open it?”

More.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Ransomware Task Force Releases its Comprehensive Framework for Action

Since ransomware’s introduction in 1989 in the form of the AIDS Trojan, also known as PS Cyborg, distributed on diskettes, ransomware has continually increased and evolved into a heinous threat to our national security, public safety, and to our economic and public health. With ransoms paid in 2020 reaching more than $300+ million, it has become a disruptive economic leach on the resources of its victims. Local governments, educational organizations, hospitals, critical infrastructure services, businesses and organizations of all sizes have had to decide what to do when presented with a ransomware demand. These activities are highly disruptive, causing far more costs to the victims than just the cost of the ransom.

Ransomware is highly profitable. Today malicious actors are organized and coordinate their operations. We are seeing Ransomware as a Service (RaaS) businesses making it easy for those without the skills or infrastructure to threaten us as well. The scourge of ransomware must be addressed.

The Institute for Security and Technology (IST) stood up and initiated the Ransomware Task Force (RTF) late last year to address ransomware in a more wholistic fashion. In partnership with a broad coalition of 60+ experts from cybersecurity vendors, financial services, governments, law enforcement, non-profits, and international organizations, the RTF developed and released Combating Ransomware: A Comprehensive Framework for Action.

As you might expect, there were some very tough conversations during the development of the recommendations. For example, prohibiting / outlawing ransomware payments was one area of contention. There are valid reasons to want to prohibit payments. No one wants their corporate funds or governmental tax dollars going to pay for other forms of cybercrime or elicit nation state activities. Sadly, the state of cybersecurity maturity, in the U.S. alone, is not ready for such a step. Consensus was reached that we are really not ready to play that game of chicken.

Ransomware is a global problem and while many of the recommendations in the framework for action are directed at specific U.S. government bodies, it is important our international partners map the recommendations onto their specific governmental structures.  Throughout the report it is clear the recommendations are global in nature and that coordinated, international diplomatic and law enforcement efforts are critical. There are 48 recommendations as a part of the report. Most of the recommendations are not technical but rather legal, economic, and diplomatic tools.

It is heartening to see the level of activity focused on addressing ransomware in the new administration. The Department of Justice is standing up a new task force dedicated to dealing with ransomware. The Department of Homeland Security (DHS) recently formed a ransomware task force and launched a 60-day sprint.  Participating in the RTF Launch event, DHS Secretary Alejandro Mayorkas said the IST RTF report will help guide a whole-of-government approach to the problem.  He also stated the White House is developing a plan to combat ransomware.

While all these efforts are welcomed, my hope is that the great work of the IST RTF described in Combating Ransomware: A Comprehensive Framework for Action is used as a foundation  to feed these and future efforts so we can see real progress in the actionable outcomes we all desire.

I’d like to thank IST CEO Philip Reiner and his outstanding team for allowing me to participate as a member of the RTF. To all my fellow RTF members, I hope to work with each of you again.

 

The post Ransomware Task Force Releases its Comprehensive Framework for Action appeared first on McAfee Blogs.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk