Impressive iPhone Exploit

This is a scarily impressive vulnerability:

Earlier this year, Apple patched one of the most breathtaking iPhone vulnerabilities ever: a memory corruption bug in the iOS kernel that gave attackers remote access to the entire device­ — over Wi-Fi, with no user interaction required at all. Oh, and exploits were wormable­ — meaning radio-proximity exploits could spread from one nearby device to another, once again, with no user interaction needed.

[…]

Beer’s attack worked by exploiting a buffer overflow bug in a driver for AWDL, an Apple-proprietary mesh networking protocol that makes things like Airdrop work. Because drivers reside in the kernel — ­one of the most privileged parts of any operating system­ — the AWDL flaw had the potential for serious hacks. And because AWDL parses Wi-Fi packets, exploits can be transmitted over the air, with no indication that anything is amiss.

[…]

Beer developed several different exploits. The most advanced one installs an implant that has full access to the user’s personal data, including emails, photos, messages, and passwords and crypto keys stored in the keychain. The attack uses a laptop, a Raspberry Pi, and some off-the-shelf Wi-Fi adapters. It takes about two minutes to install the prototype implant, but Beer said that with more work a better written exploit could deliver it in a “handful of seconds.” Exploits work only on devices that are within Wi-Fi range of the attacker.

There is no evidence that this vulnerability was ever used in the wild.

EDITED TO ADD: Slashdot thread.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Account Hijacking Site OGUsers Hacked, Again

For at least the third time in its existence, OGUsers — a forum overrun with people looking to buy, sell and trade access to compromised social media accounts — has been hacked.

An offer by the apparent hackers of OGUsers, offering to remove account information from the eventual database leak in exchange for payment.

Roughly a week ago, the OGUsers homepage was defaced with a message stating the forum’s user database had been compromised. The hack was acknowledged by the forum’s current administrator, who assured members that their passwords were protected with a password obfuscation technology that was extremely difficult to crack.

But unlike in previous breaches at OGUsers, the perpetrators of this latest incident have not yet released the forum database. In the meantime, someone has been taunting forum members, saying they can have their profiles and private messages removed from an impending database leak by paying between $50 and $100.

OGUsers was hacked at least twice previously, in May 2019 and again in March 2020. In the wake of both incidents, the compromised OGUsers databases were made available for public download.

The leaked databases have been useful in reconstructing who’s behind several high-profile incidents involving compromised social media accounts and virtual currency heists that leveraged SIM swapping, a crime that centers around convincing mobile phone company employees to transfer ownership of the target’s phone number to a device the attackers control.

For example, when several high-profile Twitter accounts were hacked in July 2020 and used to promote bitcoin scams, the profile and private message data from previous OGUser forum compromises proved invaluable in piecing together the “who” behind that scam.

The hacker handles featured in the defacement message left on OGUsers — “Chinese” and “Disco” — correspond to two nicknames used by banned OGUser members who have been trying to generate interest for their own forum that seeks to emulate OGUsers.

Disco, a.k.a “Discoli” a.k.a. “Disco Dog,” is a young man from the United Kingdom who has marketed an automated bot program and service advertised as a way for customers to “cash out” illicit access to OneVanilla Visa prepaid card accounts using PayPal. The same individual also earlier this year founded a corporation in the U.K. called Disco Payments.

Reached via Twitter, Discoli said he and his friends hacked OGUsers via an outdated plugin used by the site. But he claims they have no plans to sell the stolen user data, and said the company was registered as a joke.

“I had a sort of feud with the administrator in the past but this one was more for fun,” Discoli said. “Not too interested in doing damage by releasing database or anything like that.”

As I noted the first time OGUsers got hacked, it’s difficult not to admit feeling a bit of schadenfreude in the continued exposure of a community that has largely specialized in hacking others. Or perhaps in the case of OGUsers, the sentiment may more aptly be described as “schadenfraud.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Bomb Threat Hacker Gets 8-Year Prison Sentence

Bomb Threat Hacker Gets 8-Year Prison Sentence

An American hacker has been sent to prison for carrying out a series of cyber and swatting attacks, including sending bogus threats of shootings and bombings to schools in the United Kingdom and the United States.

North Carolina resident Timothy Dalton Vaughn also called in a false report of an airplane hijacking involving a jetliner traveling from London to San Francisco.

The 22-year-old, known online by the handles “WantedbyFeds” and “Hacker_R_US,” was arrested in February 2019 by special agents with the FBI. 

Authorities found that Vaughn had in his possession 200 sexually explicit images and videos depicting children, including at least one toddler.

Vaughn was a member of a worldwide collective of computer hackers and swatters who call themselves the “Apophis Squad.” 

The squad caused disruptions by making threatening phone calls, sending false reports of violent school attacks via email, and launching distributed denial-of-service (DDoS) attacks on websites.

“Vaughn and others sent emails to at least 86 school districts threatening armed students and explosives,” said the Department of Justice. 

“The threatened attacks included the imminent detonation of a bomb made with ammonium nitrate and fuel oil, rocket-propelled grenade heads placed under school buses, and the placement of land mines on sports fields.”

Squad members sometimes reported threats using “spoofed” email addresses to make it appear as though the reports had been sent by innocent parties, including the mayor of London.

Among the squad’s victims was a Long Beach motorsport company whose website hoonigan.com was knocked offline for three days by a DDoS attack. The business received an email demanding a ransom of 1.5 Bitcoin (worth approximately $20,000) to cease the attack.

The Apophis Squad also hacked and defaced the website of a university in Colombia so that site visitors were greeted with the image of Adolf Hitler clutching a sign that read “YOU ARE HACKED.”

In November 2019, Vaughn pleaded guilty to one count of conspiracy to convey threats to injure, convey false information concerning use of explosive device, and intentionally damage a computer; one count of computer hacking; and one count of possession of child sexual abuse material.

Yesterday, Judge Otis Wright sentenced Vaughn to prison terms of 95 months for the child sexual abuse material possession charge and 60 months for each of the other charges. The terms are to be served concurrently.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Cyber Crime Unit Arrests Five in Louisiana

Cyber Crime Unit Arrests Five in Louisiana

Louisiana’s Cyber Crime Unit has arrested five men for allegedly committing internet crimes against children. 

An announcement regarding the arrests was made yesterday by the Bayou State’s attorney general, Jeff Landry.

“My team and our law enforcement partners continue to do more with less to keep our state’s children safe,” said Landry. 

“I am very proud of the work they do every day to bring child predators to justice, and I hope they get the resources necessary to do their jobs even more effectively during this time of increased online activity.” 

Jared Wilkinson, who was booked into the East Feliciana Parish Jail, was the youngest man to be arrested by the CCU. The 20-year-old resident of Jackson was charged with 50 counts of Pornography Involving Juveniles Under the Age of Thirteen (possession).

Denham Springs resident Pedro Moreno was charged with seven counts of Pornography Involving Juveniles Under the Age of Thirteen (possession). 

The arrest of the 40-year-old was the result of a joint investigation with the Louisiana Bureau of Investigation, Homeland Security Investigations, Livingston Parish Sheriff’s Office, and Jefferson Parish Sheriff’s Office. 

Mostafa Rasheed, also aged 40, was arrested and charged with 13 counts of Pornography Involving Juveniles Under the Age of Thirteen (possession) and four counts of Sexual Abuse of an Animal. 

The Baton Rouge resident was booked into the East Baton Parish Prison on November 25 after a March 2020 tip from the National Center for Missing and Exploited Children triggered an investigation.

NCMEC reported that Facebook user Leon Al-Iraqi had uploaded a video depicting child sexual abuse material. The CCU executed a search warrant for the social media account and discovered multiple videos of children being raped and four videos showing the sexual abuse of animals. 

WBRZ reported that authorities were able to trace the social media account back to Rasheed via an IP address. 

Gregory Pratt, a 53-year-old resident of West Monroe, was arrested and charged with one count of Pornography Involving Juveniles Under the Age of Thirteen (possession).

Terrytown resident Charles Howell IV, aged 61, was also arrested and charged with one count of Pornography Involving Juveniles Under the Age of Thirteen (possession).

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Cyber-Attack Exposes Data of 295,000 Colorado Springs Patients

Cyber-Attack Exposes Data of 295,000 Colorado Springs Patients

An American nonprofit mental health and behavioral health services provider has been notifying patients of a recent cyber-attack that exposed the protected health information (PHI) of more than 295,000 patients. 

AspenPointe, which is based in Colorado Springs, Colorado, was successfully targeted by cyber-criminals in September 2020. The attack forced the healthcare provider to take its systems offline, causing several days of operational disruption.

“We recently discovered unauthorized access to our network occurred between September 12, 2020 and approximately September 22, 2020,” said AspenPointe in a notification letter sent out to patients on November 19.

“We immediately launched an investigation in consultation with outside cybersecurity professionals who regularly investigate and analyze these types of situations to analyze the extent of any compromise of the information on our network.”

The investigation, which concluded on November 10, found that cyber-criminals had been able to access patient data that included full names, dates of birth, driver’s license numbers, bank account information, Social Security numbers, Medicaid ID numbers, dates of visitations, admissions dates, discharge dates, and/or diagnosis codes. 

“To date, we are not aware of any reports of identity fraud or improper use of your information as a direct result of this incident,” said AspenPointe.

The security breach was reported to Health and Human Services’ Office for Civil Rights on November 19 as affecting 295,617 individuals. AspenPointe is offering 12 months of complimentary identity theft protection services and a $1m insurance reimbursement policy to those affected. 

The healthcare provider said that following the attack, it has taken steps to improve its cybersecurity, including firewall changes, the implementation of additional endpoint protection, and increased monitoring. A password reset has also been performed. 

AspenPointe manages 12 organizations that help thousands of people every year who are suffering from mental health problems, including depression and grief, and also supports individuals with substance misuse issues. 

The healthcare provider also offers career services, assisting Colorado Springs residents to develop employment goals and teaching them how to search for and apply to jobs, write a resume, and make a good impression in a job interview. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Only 14% of Online Users Frequently Use Biometric Authentication

Only 14% of Online Users Frequently Use Biometric Authentication

Only 14% of consumers frequently utilize biometric authentication methods to log into a digital service, website or account, according to new research by Nomidio.

This is despite more than half (57%) of those surveyed stating that biometrics would make authentication quicker. Additionally, 54% and 53% thought it would make logins easier and more secure, respectively.

The biggest concern people had regarding the use of this authentication method was the risk of the biometric data falling into the hands of malicious actors, cited by a third of respondents. This was followed by 29% expressing concern that their behavioral data, showing where they had logged in, would be sold on by the identity provider.

Close to three-quarters (71%) said they would be put off biometric authentication if they were required to download multiple apps.

Ben Todd, head of worldwide sales at Nomidio, commented: “Consumers are switched on; the loss of biometric identifiers and the risk an identity provider might sell or mine behavioral data are very real.” 

Philip Black, commercial director at Nomidio, added: “Biometric authentication is still emerging and if we want consumers and employees to make the step-up, we must deliver solutions that provide a ‘Netflix style’ user experience. If I can’t log-in because my biometric ID is tied to my phone and it’s lost, stolen or out of battery, I might just stick with a password.”

The use of biometrics to log into online services such as e-commerce accounts is likely to increase in the wake of the shift to digital services during COVID-19 and a resulting rise in online fraud. Recently, Amazon revealed it is trialling a new biometric scanner it hopes will streamline contactless payment security and physical access for consumers and businesses.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#thinkcybersec: Don’t Presume Legacy Tech is a Negative Thing

#thinkcybersec: Don’t Presume Legacy Tech is a Negative Thing

Legacy technology is not always as bad as it is commonly believed to be, according to a panel of CISO speakers.

Speaking during the Think Cybersecurity for Government conference, Bill McCluggage, managing director of Laganview Associates, said that legacy technology “is not all bad” and while all organizations have some sort of legacy technology and accrue not only tech debt but legacy issues, the positive side is that “it is stable and we understand it.”

He said that as well as being reasonably well understood and protected behind layers, the challenges can be in getting provider support and not being able to adapt to the modern threat landscape, as well as facing database issues. “What we create today will be legacy tomorrow; we have got it and have to live with it.”

Paul Jackson, head of public sector at Tanium, said the challenge across government is there is “no shortage of programs looking at digital transformation” and it is common for them to struggle with legacy technology. “I speak to hospitals and universities, and they tell you what [the network is] made up of, and they have not got a hand on what they have got. It is hard to protect and hard to transform.” He recommended “getting the basics right, as the sooner you get a handle on it, the better it is for your environment.”

Greg van der Gaast, CISO of Salford University, said legacy technology “tends to be a known quantity” as most environments have thousands of endpoints, but with legacy technology it is known about and behind layers of protection. “It is like the family jewels; you keep them safe and not hanging out of the window,” he said. “It was said that systems are legacy the minute they hit production, but that should not be the case.”

McCluggage agreed, saying with legacy technology we know that it is stable, and you know the ports of entry, but keeping it managed, with the right people, is a challenge. “Over the next year to 18 months we will have import duties run off backend legacy systems, and they will be the engines of the state,” he said.

Jackson made the point that a lot of attackers target vulnerabilities in the legacy estate, so users would be recommended to take a “holistic view.” Also, van der Gaast said if you do not have awareness of your environment around legacy systems you cannot be sure it is isolated: “if you create layers it requires awareness of these layers.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Personal Info Available on Dark Web for as Little as 50 Cents

Personal Info Available on Dark Web for as Little as 50 Cents

Personal data is being sold on the dark web for as little as 50 cents (USD), an investigation by Kaspersky has found.

The study looked at the potential consequences of doxing, a practice where a person shares information about another individual without their consent with the aim of embarrassing, hurting them or putting them into harm. 

Kaspersky added that particularly determined abusers may even go as far as hacking into the target’s online accounts, a service that can be purchased on the dark web.

In their analysis of active offers on 10 international darknet forums and marketplaces, the researchers revealed the very high demand there is for individuals’ private information. The cost of an ID is as little as 50 cents, and varies according to the type and detail of data on offer. They also found that personal financial information, such as credit card details, banking and e-payment service access have remained just as much in demand as around a decade ago, with prices unchanged in recent years.

In the hands of malicious actors, this type of data can have severe consequences for the victims, potentially leading to extortion scams, phishing attacks, direct theft of money and social damage such as doxing.

In recent years, new types of data have gained prominence. This includes personal medical records  and selfies with personal ID documents, the latter of which can enable bad actors to take a victim’s name or services on the basis of their identity.

Dmitry Galov, security researcher at Kaspersky’s GReAT, commented: “In the past few years many areas of our lives have become digitized – and some of them, such us our health, for instance, are especially private. As we see by the increasing number of leaks, this leads to more risks for users. However, there are positive developments too – many organizations are taking extra steps to secure their users’ data. Social media platforms have made especially significant progress in this regard as it is much harder now to steal an account of a specific user.

“That said, I believe our research highlights how important it is to be aware that your data is in fact in demand and can be used for malicious purposes even if you do not especially have lots of money, do not voice controversial opinions and are generally not very active online.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#thinkcybersec: Reconsider Hiring Strategies to Meet 2021’s Digital Challenges

#thinkcybersec: Reconsider Hiring Strategies to Meet 2021’s Digital Challenges

It is time for government to open up apprenticeship and hiring opportunities for cybersecurity, particularly in the public sector, to meet the needs of the UK industry.

Speaking on a panel as part of the Think Cybersecurity for Government conference, Chris Green, head of communications at (ISC)2, cited the recent Cyber Workforce Study’s finding of a reduced UK skills gap, which found that one in five companies had a staff shortage. “They have not had the staff on hand to deal with issues,” he said, stating that there will be an increased demand as we move into 2021 due to COVID-19 “and a lot has to be done to overcome that issue.”

He called for roles to be more accessible to more people, as we need to identify and train those people. Hiring has increased but “the impact of COVID-19 has accelerated digital transformation, and we can expect the gap to widen again as more and more companies transition to a digital environment.” Green said a lot of companies did not have the infrastructure or people in place to enable that move to a more online existence, and as a result, he expects to see an increase in the size of the skills shortage next year.

Asked by moderator David Bicknell how this issue can be overcome, Green said this can be achieved with government training opportunities, and to “make the route valuable” for those coming from the academic perspective. “Government can do more to qualify professional certifications, especially in cybersecurity,” he said.

Also on the panel was Saj Huq, director of LORCA, who said the cybersecurity field is developing so quickly “it is hard to remain agile and on top of what the changes are.” He claimed he was optimistic about the changes, and that statistics show cybersecurity is “going in the right direction” but he was nervous about maintaining that upswing. “What is clear is that cybersecurity is top of the policy agenda and we can make the right investments into the future,” he said.

Jessica Figueras, founder of Hither Ventures. said we should think about how we use people and skills in roles, and it is important to address the issue at many different levels “and clearly shortage is coming in first place.” She also called for government to increase its leadership role for innovation in order to better develop skills in the UK. Huq agreed, saying it needs to be clearer with regards how to become a technology entrepreneur, while Green said the educational curriculum should be reviewed to make computer studies less about coding and more about cybersecurity skills.

“Introduce more cybersecurity stuff at the educational level and you increase the seed of interest of cybersecurity as a career,” he said. “We struggle to bring Generation Z in, who don’t view cybersecurity professionals as inspirational or critical to society, and that is down to a lack of exposure to the role cybersecurity plays.”

Huq said: “Continued investment in innovation is important as the field is changing, and we cannot afford to stand still and we need to invest. This is not just about public money, but it means the role of industry needs to evolve more broadly as security is treated as a bolt on and insurance policy.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Vietnamese State Hackers Deploy Coin Miners to Victims

Vietnamese State Hackers Deploy Coin Miners to Victims

Vietnamese state-backed hackers have been observed deploying cryptocurrency mining malware to monetize the networks of victim organizations they’re also spying on, according to Microsoft.

APT32, (aka Ocean Lotus, BISMUTH), has in the past been associated with sophisticated cyber-espionage campaigns aimed at targets as diverse as carmakers and local Chinese government departments.

However, from July to August 2020, the group deployed Monero coin miners in attacks targeting private and public sector organizations in France and Vietnam. Doing so may be part of a plan to generate extra revenue alongside such attacks, or an attempt to stay hidden, Microsoft claimed.

“The coin miners also allowed BISMUTH to hide its more nefarious activities behind threats that may be perceived to be less alarming because they’re ‘commodity’ malware,” it said in a blog post.

“If we learned anything from ‘commodity’ banking trojans that bring in human-operated ransomware, we know that common malware infections can be indicators of more sophisticated cyberattacks and should be treated with urgency and investigated and resolved comprehensively.”

Other tactics designed to “blend in” include the targeting of only one individual in an organization with spear-phishing; in some cases, the attackers even corresponded with their victims to encourage them to open the malicious attachment.

Another is the use of DLL side-loading via outdated applications including Microsoft Defender Antivirus.

“Blending in was important for BISMUTH because the group spent long periods of time performing discovery on compromised networks until they could access and move laterally to high-value targets like servers, where they installed various tools to further propagate or perform more actions,” noted Microsoft.

“At this point in the attack, the group relied heavily on evasive PowerShell scripts, making their activities even more covert.”

Organizations faced with this threat group should focus on reducing the attack surface via user education, disabling Macros, tweaking email filters and other techniques, improving credential hygiene through MFA and stopping attack sprawl with intrusion detection, firewalls and other tools.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk