Google’s Project Zero Finds a Nation-State Zero-Day Operation

Google’s Project Zero discovered, and caused to be patched, eleven zero-day exploits against Chrome, Safari, Microsoft Windows, and iOS. This seems to have been exploited by “Western government operatives actively conducting a counterterrorism operation”:

The exploits, which went back to early 2020 and used never-before-seen techniques, were “watering hole” attacks that used infected websites to deliver malware to visitors. They caught the attention of cybersecurity experts thanks to their scale, sophistication, and speed.

[…]

It’s true that Project Zero does not formally attribute hacking to specific groups. But the Threat Analysis Group, which also worked on the project, does perform attribution. Google omitted many more details than just the name of the government behind the hacks, and through that information, the teams knew internally who the hacker and targets were. It is not clear whether Google gave advance notice to government officials that they would be publicizing and shutting down the method of attack.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Consulting Firm Data Breach Impacts MSU

Consulting Firm Data Breach Impacts MSU

Michigan State University (MSU) has been impacted by a data breach stemming from a cyber-attack on an Ohio law firm.

Bricker & Eckler LLP, which is associated with MSU Title IX contractor INCompliance Consulting, was hit with ransomware in January 2021. 

An investigation into the incident determined that an unauthorized party gained access to certain Bricker internal systems at various times between approximately January 14 and January 31.

“Findings from the investigation indicate that the party obtained some data from certain Bricker systems during this period,” said the law firm in a data security incident notice.

“Bricker was able to retrieve the data involved from the unauthorized party and has taken steps to delete the data. At this time, Bricker has no reason to believe this data was further copied or retained by the unauthorized party.”

Data that may have been exposed in the attack includes names, addresses, and in certain instances medical-related and/or education-related information, driver’s license numbers, and/or Social Security numbers.

Lansing State Journal reports that the cyber-attack on Bricker resulted in the exposure of Title IX case information belonging to nearly 350 people at MSU. 

In a letter sent this week to faculty, students, and staff, MSU wrote: “A limited number of individuals, some of whom are no longer affiliated with MSU, may have been impacted. Those individuals have been contacted and connected with the proper resources.”

MSU hired INCompliance in 2019 to investigate and resolve complaints regarding sexual misconduct, relationship violence, and discrimination.

The university said that the cyber-criminals who attacked Bricker had stolen documents from MSU cases handled by INCompliance. Among the documents were investigation reports, scheduling emails, and final determinations. 

“INCompliance is the entity that we work with on some of those external investigations,” said Michigan State’s Title IX communications manager, Christian Chapman.

“Bricker and Eckler is their parent company or law firm, so to speak.”

Chapman said that the personal data of six people involved in MSU investigations had been leaked in the data breach. 

“Our systems are secure and have not been impacted,” said Chapman. “And it will not impact any cases that are happening on MSU’s end.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

IT Pros Share Work Devices with Household

IT Pros Share Work Devices with Household

New research has revealed that nearly a quarter of IT security professionals share their work devices with members of their household. 

The finding comes from the 2021 Global IT Security Survey published today by hardware-encrypted USB drive manufacturer Apricorn.

Researchers questioned more than 400 IT security practitioners across North America and Europe about their security practices and policies during remote working conditions over the past 12 months.

Sixty percent of respondents agreed that COVID-induced remote work conditions had created data security issues within their organizations, with 38% noting that data control during the pandemic has been very hard to manage.

The majority of respondents (75%) said that they had put COVID-centric cybersecurity policies in place, such as two-factor authentication (48%) and encryption of sensitive data (41%). However, nearly 20% admitted that their work devices had been used by other members of their household. 

Nearly half (45%) of respondents had allowed the use of personal USB devices without corporate oversight, letting the employee decide which device to use, when to use it, and for what data. 

Almost 70% said that they want an encrypted USB policy within their organization, but 40% did not have plans to roll out a corporate USB program.

More than a quarter (27%) of respondents expressed that they were not concerned about losing data through third-party vendors and have increased the number of vendors with whom they work. 

“The third-party vendor findings were a surprise given the large number of high-profile third-party breaches in recent years,” said Kurt Markley, US managing director, Apricorn. 

“Misplaced trust is risky. Businesses must strengthen their security posture, consider security policies and processes related to how they handle data, and make policy adjustments inside organizations and within agreements with partners.”

Nearly half of respondents (49%) had observed that individual employees in their organization did not consider themselves as targets that attackers could exploit to access company data. 

Markley said: “In many cases, successful attacks target employees, so if they are unprepared or untrained, they are a risk.”

He added: “The importance of creating a culture of security, educating users and vendors about security practices, and implementing policies such as end-to-end encryption cannot be overstated for helping organizations remain secure as their operating environments continue to shift.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Phishing Emails Most Commonly Originate from Eastern Europe

Phishing Emails Most Commonly Originate from Eastern Europe

Scam emails most commonly originate from Eastern European countries, according to a study by Barracuda Networks.

Analyzing geolocation and network infrastructure across over two billion emails from its Threat Spotlight data, the researchers calculated the quantity of phishing emails as an overall percentage of total messages sent from regions throughout the globe.

It was discovered that the five countries with the highest proportion of phishing attacks from emails sent were all from Eastern Europe. In descending order, they were: Lithuania, Latvia, Serbia, Ukraine and Russia.

The next countries in the list were from the Americas and Asia: Bahamas, Puerto Rico, Colombia, Iran, Palestine and Kazakhstan.

While certain countries had high volumes of phishing emails recorded, the large amount of overall emails originating from them meant the proportion of phishing messages was actually very low. For instance, 129,369 phishing emails in the dataset were sent from the US, representing 0.02% of the total number of emails. Most countries had a phishing probability of 10% or less, according to the report.

Barracuda also noted that phishing emails are more likely to be routed through multiple countries than benign emails. While 60% of phishing emails traversed through two or fewer countries this was 80% for non-phishing emails.

Another interesting finding was that Amazon, Microsoft and Twitter had the highest volume of phishing emails being sent using their infrastructure.

Chris Ross, SVP international at Barracuda Networks, commented: “It would be absurd to ‘blacklist’ all emails from the named countries with a high probability of phishing, however, this research could provide IT managers and CISOs with the information needed to screen or flag some emails with certain features – such as whether an email has passed through more than one country and originates from one of the countries perceived to be a high threat.

“Deploying email security that utilizes artificial intelligence will help streamline this process to pick up and flag communication anomalies and detect certain threats designed to bypass basic email protection. Additionally, improving security awareness through training will help to detect security weak points in an organization and improve data management protocols for the long term.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Chemical Weapon Shopping Sends Dark Web User to Prison

Chemical Weapon Shopping Sends Dark Web User to Prison

An American man who stole someone’s identity and tried to purchase a chemical weapon on the dark web after going through a breakup has been sent to prison.

Forty-six-year-old Jason William Siesser admitted attempting to buy a highly toxic chemical in amounts capable of killing hundreds of people on two occasions between June 14 and August 23, 2018.

On August 4, 2020, Siesser pleaded guilty to one count of attempting to acquire a chemical weapon and one count of aggravated identity theft.

Siesser, who resides in Columbia, Missouri, attempted to mask his identity when giving dark web sellers his delivery address. Instead of using his own name, he gave the moniker of a minor whose identity Siesser used without authorization. 

On July 4, 2018, Siesser ordered two 10 milliliter units of the chemical on the dark web, paying in Bitcoin. When the seller didn’t immediately dispatch the chemical, Siesser contacted them on multiple occasions to follow up.

The communication between Siesser and the seller indicates that the chemical was part of a short-term scheme devised by Siesser.

On July 19, 2018, Siesser told the seller that “I plan to use it soon after I receive it.”

On August 5, 2018, Siesser ordered three 10 milliliter units of the chemical—enough to kill approximately 300 people—and paid for the toxic substance with Bitcoin worth roughly $150. 

Siesser subsequently signed for a package delivered to his residence on August 23, 2018, believing it to be the chemical that he ordered. In reality, the drop was a controlled delivery of a dummy package containing an inert substance, which had been arranged by law enforcement.

Officers executed a search of Siesser’s home, where they found approximately 10 grams of the toxic compound cadmium arsenide, which can be deadly if ingested or inhaled; roughly 100 grams of cadmium metal; and around 500 mL of hydrochloric acid. 

“Writings located within the home articulated Siesser’s heartache, anger and resentment over a breakup, and a desire for the person who caused the heartache to die,” said the Department of Justice.

On April 6, Siesser was sentenced to 12 years in federal prison.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Privacy Concerns Raised Over Scotland’s New #COVID19 Check-In App

Privacy Concerns Raised Over Scotland’s New #COVID19 Check-In App

Concerns have been voiced by leading data privacy advocates regarding a new COVID-19 venue check-in app announced by the Scottish government.

The app, Check In Scotland, which is separate from the Protect Scotland contact tracing app, requires citizens to check into venues as the country reopens from pandemic-induced lockdowns.

As outlined on the Scottish government’s website, “Check In Scotland is a way to collect the contact details of people who visit a wide range of businesses and venues in Scotland. It’s designed to work with NHS Scotland’s Test and Protect.”

It has been created for use by certain businesses in Scotland – including pubs, bars, restaurants, cafes, hairdressers, beauticians and tattooists – in accordance with law that states such establishments must collect and record the contact details of visitors to help track and trace people potentially exposed to the virus.

However, Ray Walsh, digital privacy expert at ProPrivacy, has warned of the potential data privacy issues that surround the use of the app, with particular focus on the fact that it collects and stores venue attendance information such as name, email address and mobile phone number, along with the time and date of venue visits, in a centralized database.

“This raises serious privacy concerns that will likely impact the number of people willing to use the app,” he said. “Any centralized repository of people’s location information results in a highly detailed record of their daily activities and potentially information about who they choose to associate with. This is highly revealing habitual information that results in the potential for pervasive government surveillance.”

Whilst the government has assured that any information collected will be used solely to prevent the spread of COVID-19, Walsh pointed out that a data protection impact assessment highlighted that there is nothing to stop the data from being exploited for secondary purposes using a warrant.

“There is no doubt that this data can cause a significant breach of people’s privacy rights, making it impossible for them to move around public spaces and venues without constantly informing the government about where they go,” he added.

Walsh argued that it is therefore vital that the government upholds transparent sunset clauses to ensure that data is deleted once it has served its purpose, as “failure to do so provides an ongoing threat to citizens’ privacy that is out of line with its promise to use the data only to prevent the spread of the virus.

“We urge the Scottish government to consider moving to a decentralized approach like that being used in the rest of the UK, where the app allows citizens to be informed about the risk to their health without their personal details and location information being harvested to a central database.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Cybersecurity Industry Must Find Solutions for Third Party Data Security

Cybersecurity Industry Must Find Solutions for Third Party Data Security

Organizations must take more responsibility for the security of third party providers that access their data, according to experts speaking during a webinar session organized by Atakama.

Moderating the discussion, Brian Herr, field CISO at Mainline Information Systems, firstly highlighted how organizations are becoming increasingly reliant on third parties, meaning growing numbers of entities are getting access to their confidential information. “Organizations are putting more data outside of their control,” he explained, adding that “the regulatory and legal landscape is trying to keep tabs on this and it’s changing the way we do business.”

The EU’s GDPR legislation is generally seen as the pioneer for data protection rules, with other countries such as the US starting to follow suit in terms of their own regulations. There are now some clarifications emerging in regard to third party data access from the GDPR, which are likely to have implications throughout the world. Patrick Burt, former NY regulator/privacy attorney at Philip Nizer, outlined that “there is more and more focus on third parties.” Under GDPR, organizations are given clear responsibilities to undergo risk assessments and other checks when handing over data to a third party.

Burt noted that in a number of recent cases in which fines were handed out by the UK’s Information Commissioner’s Office (ICO), including against BA, Marriott and Ticketmaster, it was argued that third parties were liable, “but in each case, the ICO found it was their responsibility – they were not holding those third parties responsible at all,” explained Burt. This was ultimately because of their failures to carry out due diligence.

Burt added that similar principles are in place in the California Consumer Privacy Act (CCPA).

Dimitri Nemirovsky, co-founder and COO at Atakama, concurred, stating that organizations are still ultimately in control of what happens to their data. In an increasingly digitized environment “I don’t think you can exist today without using a third party in some form or another,” he outlined. In this context, it is critical that companies find the right approach to ensuring the integrity of the data being entrusted to these third parties is maintained. Nemirovsky said that “it is really important that you vet those tools you are using and to do it in such a way where you are maintaining the performance that is expected of your workforce.”

Managing the distribution of encryption keys is particularly vital in achieving this, according to Nemirovsky. “It does boil down to an identity and access management issue,” he commented. This is because, if an authorized user’s credentials are compromised, all the data will be decrypted for the attacker.

Account compromise is therefore arguably the biggest security issue when it comes to third parties, as breaches can still be caused even after adequate risk assessments are carried out. “This is going to become a very big problem that the industry is going to have to solve,” said Herr. “Ultimately, it boils down to understanding and getting that encryption as close to the data usage as possible so that anything in the middle doesn’t really matter.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Wormable Netflix Malware Spreads Via WhatsApp Messages

Wormable Netflix Malware Spreads Via WhatsApp Messages

Security researchers have discovered new malware disguised as a Netflix application, designed to spread worm-like via victims’ WhatsApp messages.

Check Point discovered the wormable malware in an application on the Google Play Store called ‘FlixOnline’. It was designed to attract Android users by promising unlimited entertainment from anywhere in the world, using the Netflix logo to add legitimacy.

Once a victim installs the application, the malware will change permissions on their device to enable automatic responses to new WhatsApp notifications. Then it will send an automated reply to every message that user receives — encouraging them to visit a fake Netflix site designed to phish for log-ins and credit card details.

The WhatsApp message itself promises the recipient two months of Netflix Premium free of charge if they click on the malicious link.

Unfortunately, Check Point claimed the malware is likely to return in another guise.

“The malware’s technique is new and innovative, aiming to hijack users’ WhatsApp accounts by capturing notifications, along with the ability to take predefined actions, like ‘dismiss’ or ‘reply’ via the Notification Manager,” explained the security vendor’s manager of mobile intelligence, Aviran Hazum.

“The fact that the malware was able to be disguised so easily and ultimately bypass the Play Store’s protections raises some serious red flags. Although we stopped one campaign using this malware, the malware may return hidden in a different app.”

In this case, the offending FlixOnline app had only been downloaded around 500 times before Google removed it after being notified by Check Point.

However, the vendor urged users to download a security solution to their device, only install apps from official marketplaces and to keep all software up-to-date to stay safe online.

“Users should be wary of download links or attachments that they receive via WhatsApp or other messaging apps, even when they appear to come from trusted contacts or messaging groups,” concluded Hazum.

“If you think you’re a victim, we recommend immediately removing the application from devices, and changing all passwords.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

CISA: Patch Legacy SAP Vulnerabilities Urgently

CISA: Patch Legacy SAP Vulnerabilities Urgently

The US government is urging SAP owners to urgently patch and fix their application environments after a new report warned of mass exploitation.

The Cybersecurity and Infrastructure Security Agency (CISA) urged SAP businesses to prioritize reviewing the Onapsis report. It said affected customers could be exposed to data theft, financial fraud, ransomware and disruption of mission critical operations and processes.

Onapsis claimed to have discovered over 300 successful exploitation attempts in the course of its research alone, related to six known vulnerabilities and one critical configuration issue.

Although two of these bugs were from last year, one dated back to 2018, two were patched in 2016 and one was fixed all the way back in 2010.

The report also warned that attackers are quick to jump on newly discovered vulnerabilities, weaponizing exploits in less than 72 hours from the time patches are released and compromising new SAP apps in IaaS environments in under three hours.

“The evidence clearly shows that cyber criminals are actively targeting and exploiting unprotected SAP applications with automated and sophisticated attacks. This research also validates that the threat actors have both the means and expertise to identify and exploit unprotected SAP systems and are highly motivated to do so,” the report noted.

“Onapsis researchers found reconnaissance, initial access, persistence, privilege escalation, evasion and command and control of SAP systems, including financial, human capital management and supply chain applications.”

Beyond vulnerability exploits, the researchers also discovered brute-forcing of high-privilege SAP user accounts, and attempts at chaining vulnerabilities to achieve privilege escalation for OS-level access, which could grant attackers access to wider corporate systems.

SAP is used by over 400,000 organizations worldwide, including 92% of the Forbes Global 2000, 18 of the world’s top 20 vaccine-makers, and over 1000 government, NATO and military entities.

“Despite patches being available for months and even years, attackers are still finding and exploiting unpatched SAP systems,” said Tenable research engineering manager, Scott Caveza.

“This serves as a reminder to administrators of sensitive data and applications that applying patches, mitigations, or workarounds are paramount to thwarting malicious actors looking to exploit well known vulnerabilities.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Office Depot Configuration Error Exposes One Million Records

Office Depot Configuration Error Exposes One Million Records

A misconfigured Elasticsearch server belonging to a popular office supplies store chain was found leaking nearly one million records including customers’ personal information, it has emerged.

The non-password protected database was discovered by a Website Planet team led by Jeremiah Fowler on March 3. They quickly traced it back to Office Depot Europe, which operates across the region with bricks-and-mortar stores and online under the Office Depot and Viking brands.

Among the 974,000 unencrypted records found in the database were customer names, phone numbers, home and office addresses, @members.ebay addresses, marketplace logs, order histories and hashed passwords.

Fowler warned that such data could have been used by cyber-criminals to perform convincing phishing attacks.

“Let’s hypothetically say a criminal calls the customer and they validate the recent order. Next the criminal says something is wrong with your billing information, can you please provide me with the credit card number used for your purchase?” he explained.

“The customer would have no reason to doubt this because the caller can validate real details that only the retailer would know. This is how a social engineering attack works and it is one of the most common forms of fraud used today.”

Although Office Depot Europe secured the database within hours of notification, thanking the researchers for bringing it to their attention, Fowler claimed it may have been exposed for up to 10 days.

This would have put it at risk not only from data-hunting fraudsters but automated ransomware scripts and other tools which scour the internet for misconfigured databases like this.

Alongside the customer information was data on middleware, IP addresses, ports, pathways and storage systems used by the organization which Fowler said could have been exploited to target the Office Depot corporate network.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk