Finnish IT Giant Hit with Ransomware Cyberattack

A major Finnish IT provider has been hit with a ransomware attack that has forced the company to turn off some services and infrastructure in a disruption to customers, while it takes recovery measures. Norwegian business journal E24 reported the attack on Espoo, Finland-based TietoEVRY on Tuesday, claiming to have spoken with Geir Remman, a […]

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Dependency Confusion: Another Supply-Chain Vulnerability

Alex Birsan writes about being able to install malware into proprietary corporate software by naming the code files to be identical to internal corporate code files. From a ZDNet article:

Today, developers at small or large companies use package managers to download and import libraries that are then assembled together using build tools to create a final app.

This app can be offered to the company’s customers or can be used internally at the company as an employee tool.

But some of these apps can also contain proprietary or highly-sensitive code, depending on their nature. For these apps, companies will often use private libraries that they store inside a private (internal) package repository, hosted inside the company’s own network.

When apps are built, the company’s developers will mix these private libraries with public libraries downloaded from public package portals like npm, PyPI, NuGet, or others.

[…]

Researchers showed that if an attacker learns the names of private libraries used inside a company’s app-building process, they could register these names on public package repositories and upload public libraries that contain malicious code.

The “dependency confusion” attack takes place when developers build their apps inside enterprise environments, and their package manager prioritizes the (malicious) library hosted on the public repository instead of the internal library with the same name.

The research team said they put this discovery to the test by searching for situations where big tech firms accidentally leaked the names of various internal libraries and then registered those same libraries on package repositories like npm, RubyGems, and PyPI.

Using this method, researchers said they successfully loaded their (non-malicious) code inside apps used by 35 major tech firms, including the likes of Apple, Microsoft, PayPal, Shopify, Netflix, Yelp, Uber, and others.

Clever attack, and one that has netted him $130K in bug bounties.

More news articles.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Checkout Skimmers Powered by Chip Cards

Easily the most sophisticated skimming devices made for hacking terminals at retail self-checkout lanes are a new breed of PIN pad overlay combined with a flexible, paper-thin device that fits inside the terminal’s chip reader slot. What enables these skimmers to be so slim? They draw their power from the low-voltage current that gets triggered when a chip-based card is inserted. As a result, they do not require external batteries, and can remain in operation indefinitely.

A point-of-sale skimming device that consists of a PIN pad overlay (top) and a smart card skimmer (a.k.a. “shimmer”). The entire device folds onto itself, with the bottom end of the flexible card shimmer fed into the mouth of the chip card acceptance slot.

The overlay skimming device pictured above consists of two main components. The one on top is a regular PIN pad overlay designed to record keypresses when a customer enters their debit card PIN. The overlay includes a microcontroller and a small data storage unit (bottom left).

The second component, which is wired to the overlay skimmer, is a flexible card skimmer (often called a “shimmer”) that gets fed into the mouth of the chip card acceptance slot. You’ll notice neither device contains a battery, because there simply isn’t enough space to accommodate one.

Virtually all payment card terminals at self-checkout lanes now accept (if not also require) cards with a chip to be inserted into the machine. When a chip card is inserted, the terminal reads the data stored on the smart card by sending an electric current through the chip.

Incredibly, this skimming apparatus is able to siphon a small amount of that power (a few milliamps) to record any data transmitted by the payment terminal transaction and PIN pad presses. When the terminal is no longer in use, the skimming device remains dormant.

The skimmer pictured above does not stick out of the payment terminal at all when it’s been seated properly inside the machine. Here’s what the fake PIN pad overlay and card skimmer looks like when fully inserted into the card acceptance slot and viewed head-on:

The insert skimmer fully ensconced inside the compromised payment terminal. Image: KrebsOnSecurity.com

Would you detect an overlay skimmer like this? Here’s what it looks like when attached to a customer-facing payment terminal:

The PIN pad overlay and skimmer, fully seated on a payment terminal.

REALLY SMART CARDS

The fraud investigators I spoke with about this device (who did so on condition of anonymity) said initially they couldn’t figure out how the thieves who plant these devices go about retrieving the stolen data from the skimmer. Normally, overlay skimmers relay this data wirelessly using a built-in Bluetooth circuit board. But that also requires the device to have a substantial internal power supply, such as a somewhat bulky cell phone battery.

The investigators surmised that the crooks would retrieve the stolen data by periodically revisiting the compromised terminals with a specialized smart card that — when inserted — instructs the skimmer to dump all of the saved information onto the card. And indeed, this is exactly what investigators ultimately found was the case.

“Originally it was just speculation,” the source told KrebsOnSecurity. “But a [compromised] merchant found a couple of ‘white’ smartcards with no markings on them [that] were left at one of their stores. They informed us that they had a lab validate that this is how it worked.”

Some readers might reasonably be asking why it would be the case that the card acceptance slot on any chip-based payment terminal would be tall enough to accommodate both a chip card and a flexible skimming device such as this.

The answer, as with many aspects of security systems that decrease in effectiveness over time, has to do with allowances made for purposes of backward compatibility. Most modern chip-based cards are significantly thinner than the average payment card was just a few years ago, but the design specifications for these terminals state that they must be able to allow the use of older, taller cards — such as those that still include embossing (raised numbers and letters). Embossing is a practically stone-age throwback to the way credit cards were originally read, through the use of manual “knuckle-buster” card imprint machines and carbon-copy paper.

“The bad guys are taking advantage of that, because most smart cards are way thinner than the specs for these machines require,” the source explained. “In fact, these slots are so tall that you could fit two cards in there.”

IT’S ALL BACKWARDS

Backward compatibility is a major theme in enabling many types of card skimming, including devices made to compromise automated teller machines (ATMs). Virtually all chip-based cards (at least those issued in the United States) still have much of the same data that’s stored in the chip encoded on a magnetic stripe on the back of the card. This dual functionality also allows cardholders to swipe the stripe if for some reason the card’s chip or a merchant’s smartcard-enabled terminal has malfunctioned.

Chip-based credit and debit cards are designed to make it infeasible for skimming devices or malware to clone your card when you pay for something by dipping the chip instead of swiping the stripe. But thieves are adept at exploiting weaknesses in how certain financial institutions have implemented the technology to sidestep key chip card security features and effectively create usable, counterfeit cards.

Many people believe that skimmers are mainly a problem in the United States, where some ATMs still do not require more secure chip-based cards that are far more expensive and difficult for thieves to clone. However, it’s precisely because some U.S. ATMs lack this security requirement that skimming remains so prevalent in other parts of the world.

Mainly for reasons of backward compatibility to accommodate American tourists, a great number of ATMs outside the U.S. allow non-chip-based cards to be inserted into the cash machine. What’s more, many chip-based cards issued by American and European banks alike still have cardholder data encoded on a magnetic stripe in addition to the chip.

When thieves skim non-U.S. ATMs, they generally sell the stolen card and PIN data to fraudsters in Asia and North America. Those fraudsters in turn will encode the card data onto counterfeit cards and withdraw cash at older ATMs here in the United States and elsewhere.

Interestingly, even after most U.S. banks put in place fully chip-capable ATMs, the magnetic stripe will still be needed because it’s an integral part of the way ATMs work: Most ATMs in use today require a magnetic stripe for the card to be accepted into the machine. The main reason for this is to ensure that customers are putting the card into the slot correctly, as embossed letters and numbers running across odd spots in the card reader can take their toll on the machines over time.

And there are the tens of thousands of fuel pumps here in the United States that still allow chip-based card accounts to be swiped. The fuel pump industry has for years won delay after delay in implementing more secure payment requirements for cards (primarily by flexing their ability to favor their own fuel-branded cards, which largely bypass the major credit card networks).

Unsurprisingly, the past two decades have seen the emergence of organized gas theft gangs that take full advantage of the single weakest area of card security in the United States. These thieves use cloned cards to steal hundreds of gallons of gas at multiple filling stations. The gas is pumped into hollowed-out trucks and vans, which ferry the fuel to a giant tanker truck. The criminals then sell and deliver the gas at cut rate prices to shady and complicit fuel station owners and truck stops.

A great many people use debit cards for everyday purchases, but I’ve never been interested in assuming the added risk and pay for everything with cash or a credit card. Armed with your PIN and debit card data, thieves can clone the card and pull money out of your account at an ATM. Having your checking account emptied of cash while your bank sorts out the situation can be a huge hassle and create secondary problems (bounced checks, for instance).

The next skimmer post here will examine an inexpensive and ingenious analog device that helps retail workers quickly check whether their payment terminals have been tampered with by bad guys.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Former Employee Behind Earthquakes Stadium Hack

Former Employee Behind Earthquakes Stadium Hack

A vengeful former staff member of a San Jose sports stadium concessionaire has admitted carrying out a costly cyber-attack against his ex-employer after losing his job. 

Salvatore A. La Rosa worked for Spectra Food Services and Hospitality from Valentine’s Day 2015 until his termination on January 6, 2020. Spectra was the concessions contractor for California’s Earthquakes Stadium, home of Major League Soccer team the San Jose Earthquakes. 

To sell food and other concession items at the stadium, Spectra relied on the use of mobile tablets that displayed menus and payment selections from an online-based application as their point-of-sale terminals.

In federal court on February 17, 2021, La Rosa admitted logging into the administrative port for the Earthquakes Stadium from his home using his old work password after he had left the company. After accessing the system without permission, 41-year-old La Rosa intentionally deleted Spectra’s concession menu and payment selections.

With a few clicks of his mouse, La Rosa caused all of the point-of-sale tablets used by Spectra’s staff to stop working and made it impossible for the company to accept credit cards. 

The timing of the cyber-attack forced Spectra staff working during a soccer match on February 29, 2020, to take handwritten orders and use calculators to complete cash transactions. In addition to causing delays and lost sales, the attack resulted in La Rosa’s former colleagues’ being verbally abused by disgruntled customers. 

According to court documents, Spectra had to provide free food and beverages to some club members because of its inability to process credit card transactions.

In an attempt to regain the trust of its customers, Spectra and the San Jose Earthquakes offered 50% off all concessions sold at a subsequent game played at the stadium on March 7. 

Charging documents filed in the case stated that the attack lost Spectra $268,000 in damages, consisting of lost revenue, employee time and labor costs to repair the damage to the data, and concession discounts offered on March 7.

La Rosa has pleaded guilty to one count of Intentional Damage to a Protected Computer. He is due to be sentenced on May 19, 2021. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Content Provenance Group Formed

Content Provenance Group Formed

A number of influential companies have formed a consortium that aims to reduce the amount of disinformation, misinformation, and fraudulent content on the internet. 

The Coalition for Content Provenance and Authenticity (C2PA), a Joint Development Foundation project, has been founded by AdobeArmBBCIntelMicrosoft, and photo and video verification platform Truepic.

Member organizations plan to jointly develop technical standards for certifying the source and history or provenance of media content. 

In a statement released today, a Microsoft spokesperson said: “C2PA member organizations will work together to develop content provenance specifications for common asset types and formats to enable publishers, creators and consumers to trace the origin and evolution of a piece of media, including images, videos, audio and documents.”

“These technical specifications will include defining what information is associated with each type of asset, how that information is presented and stored, and how evidence of tampering can be identified.”

C2PA will use an open standard that can be adopted by any online platform, enabling platforms to preserve and read provenance-based digital content. The coalition hopes that its actions will increase the amount of trust that can be placed in online content. 

Jeffrey McGregor, CEO of Truepic, said: “We firmly believe that ecosystemwide adoption through an open standard is crucial to the long-term health of the internet. The C2PA will streamline the distribution of high-integrity digital content at scale, a vital step in restoring society’s shared sense of reality.”

Coalition members say that collaboration with chipmakers, news organizations, and software and platform companies is necessary to allow a comprehensive provenance standard to be developed and broadly adopted. 

Microsoft chief scientific officer and project origin executive sponsor Eric Horvitz said technological advancements had helped fake information to spread around the internet like wildfire. 

“There’s a critical need to address widespread deception in online content—now supercharged by advances in AI and graphics and diffused rapidly via the internet,” said Horvitz. 

“Our imperative as researchers and technologists is to create and refine technical and sociotechnical approaches to this grand challenge of our time. We’re excited about methods for certifying the origin and provenance of online content.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Silicon Valley VC Firm Phished

Silicon Valley VC Firm Phished

A leading venture capital firm based in California’s Silicon Valley has fallen victim to a cyber-attack.

According to AxiosSequoia Capital contacted investors on Friday, February 19, to inform them that their financial data and personal information had been accessed by an unauthorized third party. The data breach occurred after the email account belonging to an employee at the firm was compromised in a phishing attack. 

Sequoia Capital is run from offices on Sand Hill Road in Menlo Park. Companies that the firm has invested in include Airbnb, DoorDash, 23andMe, GitHub, Google, Zoom, WhatsApp, YouTube, and Robinhood, and cybersecurity firms Carbon Black, Tessian, and FireEye. 

The 49-year-old firm said law enforcement had been notified of the security breach and that IT specialists had been hired to investigate what happened and restore cybersecurity to the company. 

“We recently experienced a cybersecurity incident. Our security team responded promptly to investigate, and we contacted law enforcement and engaged leading outside cybersecurity experts to help remediate the issue and maintain the ongoing security of our systems,” said a Sequoia spokesperson.

“We regret that this incident has occurred and have notified affected individuals. We have made considerable investments in security and will continue to do so as we work to address constantly evolving cyber threats.”

Sequoia Capital, which Pitchbook data states has more than $38bn in assets under management, said it had found no evidence that any investor data compromised in the incident has been misused.  

“Phishing attacks are a real threat for many organizations. However, not all phishing security incidents are equal and successful phishing attacks that compromise employees with privileged access or access to privileged data can have a serious impact either from ransomware or data theft,” Joseph Carson, chief security scientist and advisory CISO at Thycotic told Infosecurity Magazine.

“The latest news regarding Sequoia Capital shows that privileged access continues to be a major challenge for organizations and how critical it is to protect privileged access and access to privileged data,” Carson said. “Privileged access is no longer just about domain admins . . . [I]t is also important to consider business users who have access to sensitive data as privileged access.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Kaspersky Appoints Christopher Hurst GM of UK and Ireland

Kaspersky Appoints Christopher Hurst GM of UK and Ireland

Cybersecurity giant Kaspersky has announced the appointment of Christopher Hurst as general manager of UK and Ireland.

Hurst boasts a 34-year career in the software industry and a proven record of accomplishment in the European tech sector, having held roles at various firms including Veritas/Symantec and Cloudistics.

Kaspersky said his initial objectives include overseeing growth in the company’s enterprise business, generating a stronger presence in the UK channel and implementing a solid strategy to recruit more partners and customers across the B2B portfolio.

Commenting on his appointment, Hurst said: “I’m excited to be taking on this role within such a fast-paced industry and growing company, as Kaspersky continues to take a frontline role in making the world more cyber-secure. The cornerstone of our business strategy in this region is to transform our leading security intelligence into real protection for our clients, to enable them to use technologies in their lives and businesses safely, and trust them. Our goal is to bring on the future for our customers.

“I’m passionate about protecting this country’s industries and consumers, and that’s one of the key reasons I’ve joined Kaspersky.”

Chris Connell, deputy VP of global sales network, MD of APAC and Japan, Kaspersky, added: “We’re very happy to welcome Chris Hurst to Kaspersky. His vast experience in this sector and demonstrated leadership ability from startups to enterprise businesses will bring real value to the business. We are confident that he will help drive strong regional growth in 2021 and beyond, and continue to support and protect our customers from ever-changing and growing cyber-threats.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

BBC Reports Theft of 105 Electrical Devices

BBC Reports Theft of 105 Electrical Devices

The BBC has reported the theft of 105 electrical devices from its premises over the last two years, according to data obtained following a Freedom of Information (FoI) request by litigation firm Griffin Law. The findings have raised fears that confidential information contained in these devices will have fallen into the hands of malicious actors.

A total of 35 mobile phones were stolen over the two years from the premises of the UK’s public service broadcaster: 19 during 2019 and 16 in 2020. Additionally, 17 laptops and MacBooks were taken over this time, 11 in 2019 and six in 2020, and two tablet computers were stolen last year.

Other electrical devices reported as stolen in the two-year period were 36 individual microphones, four hard drives, one camcorder and one firestick.

In response, the BBC said in a statement: “The BBC takes incidents of crime seriously and we are constantly implementing and reviewing measures to reduce crime and recover lost and stolen items.”

Experts believe that the difficulties in preventing theft of such equipment within large mobile workforces highlight the importance of having stringent cybersecurity controls in electrical devices to keep sensitive data safe.

Edward Blake, area vice-president, Absolute Software UK&I, commented: “One of the biggest challenges facing organizations during the COVID-19 pandemic has been successfully securing and managing key devices like laptops from loss, theft and rising cyber-risks. You can’t protect what you cannot see. With so many people either working remotely or on the move, large organizations like the BBC will inevitably see devices go missing, some of which will contain confidential data.

“With many businesses now requiring their employees to work from home, corporations can no longer be solely reliant on network-based security; they need to increase their focus on securing the actual endpoint devices. This means ensuring they have an unbreakable digital tether to all devices, capable of delivering complete visibility and control, enabling real-time insights into the state of those devices, and allowing them to self-heal security controls and productivity tools.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk