Retail and Hospitality Facing Deluge of Critical Web App Flaws

Retail and Hospitality Facing Deluge of Critical Web App Flaws

More than three-quarters of applications in the retail and hospitality sector contain at least one vulnerability, with a high percentage of these requiring urgent attention, according to Veracode.

The application security vendor analyzed more than 130,000 applications to compile its latest State of Software Security report.

However, while the 76% of buggy apps in the retail and hospitality sector is about average compared to other verticals, Veracode warned that 26% are high severity — one of the worst rates of any industry.

This matters, as the industry has been delivering a raft of new applications in order to reach customers online during the pandemic, amid social distancing and lockdowns. It’s especially important to hospitality firms, which have been forced to radically reshape their business models to adapt to the new reality.

Yet while web applications can be a life-saver for such businesses, they might also introduce extra cyber-risk. They were involved in 43% of breaches analyzed by Verizon last year and were the number one attack vector for the retail industry, with personal or payment data exploited in about half of all breaches.

That said, retail and hospitality ranked second-best for overall fix rate, according to Veracode. Half of its flaws were remediated in 125 days, which is nearly one month faster than the next-fastest sector.

Veracode claimed that, although retail and hospitality firms did well at addressing common flaw types like information leakage and input validation, developers struggled with encapsulation, SQL injection and credentials management issues.

“Retail and hospitality companies face the dual pressure of being high-value targets for attackers while also requiring software that allows them to be highly responsive to customers and compliant with industry regulations such as PCI,” said Chris Eng, Veracode chief research officer.

“Using API-driven scanning and software composition analysis to scan for flaws in open source components offer the best opportunity for improvement for development teams in the sector.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Malwarebytes: SolarWinds Hackers Read Our Emails

Malwarebytes: SolarWinds Hackers Read Our Emails

Malwarebytes has confirmed that the SolarWinds attackers managed to access internal emails, although via a different intrusion vector to many victims.

While many of the organizations caught up in the suspected Russian cyber-espionage campaign were compromised via a malicious SolarWinds Orion update, US government agency CISA had previously pointed to a second threat vector. This involved use of password guessing or spraying and/or exploiting inappropriately secured admin or service credentials.

The security vendor said attackers abused applications with privileged access to Microsoft Office 365 and Azure environments.

“We received information from the Microsoft Security Response Center on December 15 about suspicious activity from a third-party application in our Microsoft Office 365 tenant consistent with the tactics, techniques and procedures (TTPs) of the same advanced threat actor involved in the SolarWinds attacks,” the vendor explained.

“The investigation indicates the attackers leveraged a dormant email protection product within our Office 365 tenant that allowed access to a limited subset of internal company emails. We do not use Azure cloud services in our production environments.”

Malwarebytes clarified that it found no evidence of unauthorized access or compromise in any of its on-premises or production environments.

The news comes as FireEye released a new report detailing the various ways the SolarWinds attackers moved laterally to the Microsoft 365 cloud after gaining an initial foothold in networks.

They include: stealing an Active Directory Federation Services (AD FS) token-signing certificate and using it to forge tokens for arbitrary users, compromising credentials of highly privileged on-premises accounts synced to Microsoft 365 and modifying/adding trusted domains in Azure AD to add a new federated Identity Provider (IdP) that the attacker controls.

The attackers also backdoored existing Microsoft 365 apps by adding a new application or service principal credential. This enabled them to use the legitimate permissions assigned to the application, such as reading emails, FireEye said.

The security vendor has joined CrowdStrike and CISA in releasing a new tool which will help organizations spot if their Microsoft 365 tenants have been subject to the same techniques used by the group.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Quarter of Orgs Don’t Offer Cybersecurity Training Due to Lack of Budget

Quarter of Orgs Don’t Offer Cybersecurity Training Due to Lack of Budget

A quarter (25%) of company directors are prevented from delivering cybersecurity training to staff by budgetary constraints, according to iomart’s Cybersecurity Insights Report.

The survey of UK-based workers across C-level, director, manager and employee level, found that 28% of businesses offer no cybersecurity training whatsoever. Additionally, 42% said that whilst some training was offered by their firm, it was only available to select staff, while over two-thirds (70%) of respondents revealed their company doesn’t provide training to all employees.

Of those that confirmed they did receive training, 82% admitted this only consisted of a short briefing rather than a comprehensive course, with just 17% receiving regular sessions related to cybersecurity.

iomart therefore calculated that less than one in 10 (8%) of those who took part in the survey received regular cybersecurity training.

The study also found that a quarter (25%) of businesses do not have a disaster recovery policy, while a further 31% said there was one but they had never tested it.

These findings are especially concerning given that 20% of respondents reported they had seen an increase in cyber-attacks as a result of remote working, which has expanded enormously since the start of the COVID-19 pandemic.

Although company directors cited budget as the main factor in not delivering cybersecurity training, other factors highlighted by all respondents were a lack of technical expertise within the business (8%) and the issue not being a main priority (5%).

Bill Strain, security director of iomart, commented: “It’s clear that many organizations still don’t consider cybersecurity and data protection to be a top priority.

“They need to understand what the potential threats are and build resilience into their business strategy so they can react quickly and maintain operations if their IT systems are compromised.

“Many businesses would not survive the operational – let alone financial – impact of a data breach. By understanding the potential risk and introducing positive behavior around cyber-awareness, they have a much better chance of surviving an incident.”

In a survey at the end of last year, a third of remote working employees said they had not received security training in the last six months.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Coin-Mining Malware Volumes Soar 53% in Q4 2020

Coin-Mining Malware Volumes Soar 53% in Q4 2020

Detections of crypto-mining malware surged by 53% quarter-on-quarter in the final three months of 2020 as the value of Bitcoin soared, according to Avira.

The price of one Bitcoin now stands at over $35,500, close to an all-time-high it hit earlier this month, according to the security vendor’s Avira Protection Labs.

“The rapid increase in coin-miner malware suggests that malware authors are taking advantage of the price trend in recent months and increasingly spreading malware that aims to exploit other people’s computer resources for illegal mining activities,” argued Alexander Vukcevic, director of Avira Protection Labs.

“This correlation is not surprising but is nevertheless worrying for legitimate miners and investors.”

Crypto-mining or crypto-jacking came of age in 2017 and 2018 as cyber-criminals sought a quick and easy way to monetize attacks. It was claimed at the time that because attacks didn’t require user interaction to start generating profits for the perpetrator, many would-be ransomware groups were pivoting to the new threat.

Avira listed three main types of coin-mining malware today: executable files, browser-based cryptocurrency miners and advanced fileless miners.

It was the browser-based Coinhive that drove the previous spike in cryptocurrency-mining activity. By February 2018 it had impacted 23% of global organizations, according to one study. One researcher even found it installed on UK and US government sites including those belonging to the UK’s Information Commissioner’s Office (ICO), United States Courts, the General Medical Council, the UK’s Student Loans Company and NHS Inform.

Coinhive shut down in February 2019, but the practice appears to be spiking again alongside the value of digital currency.

Chris Sedgwick, security operations director, Sy4Security, argued that it is the lesser-known Monero currency rather than Bitcoin that’s in high demand.

“The reason why the majority of cryptocurrency malware mines Monero instead of Bitcoin is that the mining requirements for Monero is a fraction of that required for Bitcoin,” he said.

“Monero is also favored over Bitcoin amongst those individuals looking to use their gains for illegal use as there is no tracking of transactions and the Blockchain is not transparent.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk