Diners Devour Made-to-Order Fraud

Diners Devour Made-to-Order Fraud

Restaurants and food delivery services are being ripped off by a new made-to-order fraud scheme taking place on the messaging app Telegram.

Research and analysis from Sift’s Digital Trust and Safety Architects found that bad actors are advertising heavily discounted food and beverage delivery services on the app’s forums. After receiving an order, the cyber-criminals pay with stolen credentials obtained from data breaches and cyber-attacks or leverage a hacked account with stored value to pay for the meal. 

Fraudsters were found advertising their ability to buy food and drinks at discounted rates ranging from 60% to 75%. Diners looking for a cheap meal add their items to an online shopping cart on a restaurant or delivery app then send the fraudster a screenshot of their order and the delivery address in a Telegram direct message.

Using stolen financial data, the fraudster buys the items in the cart and sends a verification screenshot back to the diner via Telegram. The diner then pays the fraudster for the order using cryptocurrency, such as Bitcoin or Ethereum, via PayPal, Venmo, or Cash App.

The diner gets a discounted meal, the fraudster makes a profit, and the restaurant or food delivery service used to make the purchase is left footing the bill.

“Payment fraud, as orchestrated by the bad actors using Telegram, can have devastating effects for merchant,” said Sift researchers. 

“When consumers notice their credit cards have been stolen and used for unapproved transactions, merchants not only must refund the consumer and lose the item, but also face hefty fines levied by their payment processors.”

According to data from the Sift global network of more than 34,000 apps and sites, fraud rates among restaurant apps and food delivery services increased 14% from Q3 to Q4 2020.

“The Dark Web can be difficult to access and with frequent marketplace shutdowns by law enforcement, bad actors are looking for new places to commit crime. End-to-end encrypted messaging platforms like Telegram are attractive options as they are more accessible and it is easier to go undetected when committing low-level fraud,” said Brittany Allen, trust and safety architect at Sift.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Real Bug Volumes in 2020 Exceed Official CVEs by 29%: Report

Real Bug Volumes in 2020 Exceed Official CVEs by 29%: Report

Total vulnerability disclosures for 2020 are on track to exceed the previous year’s figures, with a large percentage not recorded in the official National Vulnerability Database (NVD), according to Risk Based Security.

The security vendor’s 2020 Year End Vulnerability QuickView Report recorded 23,269 bugs last year, although there may still be some left to come in.

“Organizations should be aware that … 1917 have a public exploit, are remotely exploitable, and do not have a mitigating solution. If a vital asset is affected by any of these vulnerabilities, organizations may want to assess their risk accordingly,” the report warned.

“However, for the 2688 remotely exploitable vulnerabilities that have a public exploit but do have a mitigating solution, organizations should place a first level priority on fixing those issues.”

The figures for 2020 come despite a sharp fall at the start of the year due to COVID-19, when year-on-year disclosures in Q1 dropped by over 19%.

Although things started to normalize soon after when organizations returned to business-as-usual, this arguably put even more pressure on sysadmins. Bug disclosures reached almost 70 per day, peaking at 384 in a single day in 2020, the report claimed.

Risk Based Security also warned that an increasing number of vulnerabilities aren’t being recorded in the NIST NVD, the de facto resource for many in the industry.

In fact, the vendor’s VulnDB team recorded 6767 flaws which had no corresponding CVE, which amounts to nearly 29% of the total for the year. A further 686 (4%) were marked as “Reserved,” meaning that a CVE ID number has been assigned, but the details required to act on the vulnerability are not available.

All told, Risk Based Security claimed to have recorded around 80,000 vulnerabilities over the years which are not in the NVD.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Nearly Two-Thirds of CVEs Are Low Complexity

Nearly Two-Thirds of CVEs Are Low Complexity

Security experts have warned of an increase in published vulnerabilities which are relatively easy to exploit and require no user interaction.

Managed security service provider Redscan’s latest report, NIST Security Vulnerability Trends in 2020: An Analysis, takes a look back at the 18,000+ Common Vulnerabilities and Exposures (CVEs) recorded in NIST’s National Vulnerability Database (NVD).

Aside from the fact that more CVEs were reported in 2020 than any year previously, a fact Infosecurity reported on in December, it raised concerns about the types of vulnerabilities emerging.

Over half (57%) of vulnerabilities in 2020 were classified as “critical’ or “high” severity, amounting to over 10,300 CVEs.

However, perhaps more concerning is the fact that 63% of the total number disclosed in 2020 were classed as “low complexity,” which means an attacker with low technical skills could exploit them. This figure has been on the rise since 2017, after largely falling between 2001 and 2014, according to the report.

The 63% figure represents a 13-year-high, Redscan claimed.

“The prevalence of low complexity vulnerabilities in recent years means that sophisticated adversaries do not need to ‘burn’ their high complexity zero-days on their targets and have the luxury of saving them for future attacks instead,” the report warned.

“Low complexity vulnerabilities lend themselves to mass exploitation as the attacker does not need to consider any extenuating factors or issues with an attack path. This situation is worsened once exploit code reaches the public and lower skilled attackers can simply run scripts to compromise devices.”

There was further bad news in that vulnerabilities which require no user interaction to exploit are also on the rise: they represented 68% of all CVEs recorded in 2020.

Attacks exploiting these CVEs are difficult to detect and have the potential to cause significant damage, the vendor claimed.

“Attackers exploiting these vulnerabilities don’t even need their targets to unwittingly perform an action, such as clicking a malicious link in an email. This means that attacks can easily slip under the radar,” the report noted.

“Vulnerabilities which require no interaction to exploit present a complex challenge for security teams, underscoring the need for defense-in-depth. This includes enhancing visibility of attack behaviors once a compromise has occurred.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Singtel Supply Chain Breach Traced to Zero-Day Bug

Singtel Supply Chain Breach Traced to Zero-Day Bug

One of APAC’s biggest telecoms companies has admitted that a supply chain attack may have led to the compromise of customer data.

Singtel released a statement on Thursday revealing that it was running Accellion’s legacy file sharing system FTA to share information internally and with external stakeholders.

Cyber-criminals appear to have exploited potentially multiple FTA vulnerabilities in attacks against various customers.

Although Singtel said its core operations “remain unaffected and sound,” it admitted there may be an impact on customers.

“We are currently conducting an impact assessment with the utmost urgency to ascertain the nature and extent of data that has been potentially accessed. Customer information may have been compromised,” it explained.

“Our priority is to work directly with customers and stakeholders whose information may have been compromised to keep them supported and help them manage any risks. We will reach out to them at the earliest opportunity once we identify which files relevant to them were illegally accessed.”

Accellion said in an update at the start of February that it was the target of a “sophisticated cyber-attack” which all FTA customers were informed of on December 23. As of February 1 it said it had “patched all known FTA vulnerabilities exploited by the attackers and has added new monitoring and alerting capabilities to flag anomalies associated with these attack vectors.”

Singtel corroborated this in its own version of events, stating that the supplier had made two patches available to fix the bug, which it applied on December 24 and 27 2020. However, there was a further issue the following month.

“On January 23, Accellion issued another advisory citing a new vulnerability which the December 27 patch was not effective against and we immediately took the system offline. On January 30, Accellion provided another patch for the new vulnerability which triggered an anomaly alert when we tried to apply it,” it continued.

“Accellion informed thereafter that our system could have been breached and this had likely occurred on January 20. We continued to keep the system offline and activated cyber and criminal investigations which has confirmed the January 20 date. Given the complexity of the investigations, it was only confirmed on February 9 that files were taken.”

Other customers known to have been hit by the same attacks are the New Zealand central bank, which issued a statement on January 10 and so is likely to have been caught out by an exploit of the vulnerability patched in December.

Saryu Nayyar, CEO of Gurucul, argued that the incidents highlight the risks associated with running legacy software. FTA is thought to be over 20-years-old.

“Patch cycles in enterprise environments can be complicated, especially for mature organizations with a robust change management system, but the malicious actors do not wait,” she added.

“They know there is usually a limited time between an exploit being released and a defense going in place, so they tend to move quickly. That means cybersecurity needs to move at least as quickly.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Queen’s University Belfast Recognized for Role in Growing Cybersecurity Awareness

Queen’s University Belfast Recognized for Role in Growing Cybersecurity Awareness

Queen’s University Belfast in the UK has been recognized for its cybersecurity education program and work promoting cyber-skills in its local community.

As a result of these efforts, the institution has been awarded silver recognition from its Academic Center of Excellence in Cyber Security (ACE-CSE) program by the National Cyber Security Center (NCSC). The ACE-CSE initiative was introduced by the NCSC and Department for Digital, Culture, Media and Sport with the purpose of developing a community of cybersecurity influencers who support education in this area as well as engage with industry, government, educators and students.

Queen’s University Belfast’s ACE-CSE program forms part of efforts to increase the number of cybersecurity professionals in the region of Northern Ireland to 5000 by 2030, and it is hoped the recognition will support the university to continue building a strong pipeline of highly skilled graduates to enter the industry.

The Center for Secure Information Technologies (CSIT) at Queen’s was formed in 2009 and is renowned for its cybersecurity research and collaboration. In 2011, it was recognized as one of the first Academic Centers of Excellence in Cyber Security Research by GCHQ.

Chris Ensor, NCSC deputy director for cyber-growth, commented: “I am delighted we can now recognize the first tranche of universities as Academic Centers of Excellence in Cyber Security Education, complementing our existing programs which recognise high quality cybersecurity research and degree courses.

“It is a testament to the continual efforts of academics, support staff and senior management that cybersecurity remains high on their agenda.

“We very much look forward to working with them over the coming years and strongly encourage other universities to work towards achieving similar recognition in the future.”

Professor Ian Greer, president and vice-chancellor of Queen’s University Belfast, said: “I welcome this recognition of Queen’s by the NCSC as one of the first Academic Centers of Excellence in Cyber Security Education highlighting our commitment to rolling out cybersecurity awareness and knowledge across all education pathways, operational areas of the institution and the wider community. I congratulate the ACE-CSE team led by Dr Sandra Scott-Hayward, which has secured this recognition.”

Scott-Hayward, the University’s ACE-CSE director, added that plans are in place to further develop awareness and knowledge of cybersecurity both inside and outside the institution, as this is “fundamental to addressing the societal challenge of cybersecurity.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk