Be Very Sparing in Allowing Site Notifications

An increasing number of websites are asking visitors to approve “notifications,” browser modifications that periodically display messages on the user’s mobile or desktop device. In many cases these notifications are benign, but several dodgy firms are paying site owners to install their notification scripts and then selling that communications pathway to scammers and online hucksters.

Notification prompts in Firefox (left) and Google Chrome.

When a website you visit asks permission to send notifications and you approve the request, the resulting messages that pop up appear outside of the browser. For example, on Microsoft Windows systems they typically show up in the bottom right corner of the screen — just above the system clock. These so-called “push notifications” rely on an Internet standard designed to work similarly across different operating systems and web browsers.

But many users may not fully grasp what they are consenting to when they approve notifications, or how to tell the difference between a notification sent by a website and one made to appear like an alert from the operating system or another program that’s already installed on the device.

This is evident by the apparent scale of the infrastructure behind a relatively new company based in Montenegro called PushWelcome, which advertises the ability for site owners to monetize traffic from their visitors. The company’s site currently is ranked by Alexa.com as among the top 2,000 sites in terms of Internet traffic globally.

Website publishers who sign up with PushWelcome are asked to include a small script on their page which prompts visitors to approve notifications. In many cases, the notification approval requests themselves are deceptive — disguised as prompts to click “OK” to view video material, or as “CAPTCHA” requests designed to distinguish automated bot traffic from real visitors.

An ad from PushWelcome touting the money that websites can make for embedding their dodgy push notifications scripts.

Approving notifications from a site that uses PushWelcome allows any of the company’s advertising partners to display whatever messages they choose, whenever they wish to, and in real-time. And almost invariably, those messages include misleading notifications about security risks on the user’s system, prompts to install other software, ads for dating sites, erectile disfunction medications, and dubious investment opportunities.

That’s according to a deep analysis of the PushWelcome network compiled by Indelible LLC, a cybersecurity firm based in Portland, Ore. Frank Angiolelli, vice president of security at Indelible, said rogue notifications can be abused for credential phishing, as well as foisting malware and other unwanted applications on users.

“This method is currently being used to deliver something akin to adware or click fraud type activity,” Angiolelli said. “The concerning aspect of this is that it is so very undetected by endpoint security programs, and there is a real risk this activity can be used for much more nefarious purposes.”

Sites affiliated with PushWelcome often use misleading messaging to trick people into approving notifications.

Angiolelli said the external Internet addresses, browser user agents and other telemetry tied to people who’ve accepted notifications is known to PushWelcome, which could give them the ability to target individual organizations and users with any number of fake system prompts.

Indelible also found browser modifications enabled by PushWelcome are poorly detected by antivirus and security products, although he noted Malwarebytes reliably flags as dangerous publisher sites that are associated with the notifications.

Indeed, Malwarebytes’ Pieter Arntz warned about malicious browser push notifications in a January 2019 blog post. That post includes detailed instructions on how to tell which sites you’ve allowed to send notifications, and how to remove them.

KrebsOnSecurity installed PushWelcome’s notifications on a brand new Windows test machine, and found that very soon after the system was peppered with alerts about malware threats supposedly found on the system. One notification was an ad for Norton antivirus; the other was for McAfee. Clicking either ultimately led to “buy now” pages at either Norton.com or McAfee.com.

Clicking on the PushWelcome notification in the bottom right corner of the screen opened a Web site claiming my brand new test system was infected with 5 viruses.

It seems likely that PushWelcome and/or some of its advertisers are trying to generate commissions for referring customers to purchase antivirus products at these companies. McAfee has not yet responded to requests for comment. Norton issued the following statement:

“We do not believe this actor to be an affiliate of NortonLifeLock. We are continuing to investigate this matter. NortonLifeLock takes affiliate fraud and abuse seriously and monitors ongoing compliance. When an affiliate partner abuses its responsibilities and violates our agreements, we take necessary action to remove these affiliate partners from the program and swiftly terminate our relationships. Additionally, any potential commissions earned as a result of abuse are not paid. Furthermore, NortonLifeLock sends notification to all of our affiliate partner networks about the affiliate’s abuse to ensure the affiliate is not eligible to participate in any NortonLifeLock programs in the future.”

Requests for comment sent to PushWelcome via email were returned as undeliverable. Requests submitted through the contact form on the company’s website also failed to send.

While scammy notifications may not be the most urgent threat facing Internet users today, most people are probably unaware of how this communications pathway can be abused.

What’s more, dodgy notification networks could be used for less conspicuous and sneakier purposes, including spreading fake news and malware masquerading as update notices from the user’s operating system. I hope it’s clear that regardless of which browser, device or operating system you use, it’s a good idea to be judicious about which sites you allow to serve notifications.

If you’d like to prevent sites from ever presenting notification requests, check out this guide, which has instructions for disabling notification prompts in Chrome, Firefox and Safari. Doing this for any devices you manage on behalf of friends, colleagues or family members might end up saving everyone a lot of headache down the road.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Healthcare Data Breaches to Triple in 2021

Healthcare Data Breaches to Triple in 2021

Data breaches in the healthcare industry are likely to triple in volume in the coming year, according to a new report by Black Book Market Research.

The “2020 State of the Healthcare Cybersecurity Industry” report is based on a survey of 2,464 security professionals from 705 provider organizations. Respondents were asked to identify gaps, vulnerabilities, and deficiencies in security that make hospitals and physicians susceptible to data breaches and cyber-attacks. 

The survey results suggest that 1,500 healthcare providers are vulnerable to data breaches of 500 or more records, representing a 300% increase over 2020.

Nearly threequarters (75%) of health system, hospitals and physician organizations surveyed reported that their infrastructures are unprepared to respond to attacks. Almost all (96%) felt that data attackers are outpacing their medical enterprises, placing providers at a disadvantage.

A further Black Book survey of 291 healthcare industry human resources executives found that the talent shortage of cybersecurity professionals far exceeds the demand by health systems. Researchers found that cybersecurity roles in health systems take, on average, 70% longer to fill when compared to other IT jobs.

“The talent shortage for cybersecurity experts with healthcare expertise is nearing a very perilous position,” said Brian Locastro, lead researcher on the “2020 State of the Healthcare Cybersecurity Industry” study.

Locastro added that the industry’s response to ransomware attacks had spurred cyber-criminals on.

He said: “The willingness of hospitals and physician practices to pay high ransoms to regain their data quickly motivates hackers to focus on patient records.”

The survey of security professionals found that 75% of the 66 CISOs at health systems who responded agreed that experienced cybersecurity pros were unlikely to pursue a career in the healthcare industry. 

The reason given for this was that CISOs in healthcare, more than in other industries, are held responsible for data breaches and their impact on an organization’s finances and reputation while at the same time having extremely limited authority over decision-making, technology, or policy.

Furthermore, the study revealed that 90% of health system and hospital employees who are now working remotely due to the outbreak of COVID-19 were not given any updated security guidelines or training on accessing sensitive patient data.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Teen Wins Peace Prize for Fighting Cyber-Bullying

Teen Wins Peace Prize for Fighting Cyber-Bullying

A tech-minded teenager from Bangladesh has won an international peace prize for inventing an application that supports young victims of cybercrime.

Sadat Rahman’s thoughtful Cyber Teens app helps young people report incidences of online crime, including cyber-bullying, in the western district of Narail. 

Judges at the KidsRights Foundation were so impressed with the 17-year-old’s creation that they awarded him the 2020 International Children’s Peace Prize. 

Rahman’s award was presented by Pakistani female education activist and Nobel Prize laureate Malala Yousafzai, who described the teen as “a true change maker.” The award ceremony was held virtually and hosted by Netherlands-based KidsRights Foundation.

So far, Rahman’s Cyber Teens app has been downloaded over 1,800 times and has supported 300 young victims of cyber-bullying. 

The app puts children in contact with a team of young volunteers that includes Rahman and lets them report crimes confidentially. The team then contacts local law enforcement officers and social workers to secure help for the victims. 

Helpful hints and tips about online safety, including a guide to spotting and avoiding sexual predators, can also be accessed via the app.

Rahman’s team of volunteers has successfully resolved nearly 60 cybercrimes and resulted in eight arrests by local police. Some complaints involved children being sent inappropriate messages and pornographic content by adults. 

“Serious action needs to be taken right now,” said Rahman. “Teenagers continue to remain vulnerable to online crime and cyberbullying, particularly in the times we live in.”

Rahman was inspired to invent the app after learning about the tragic consequences of one particular case of cyber-bullying.

“The idea started after a 15-year-old girl committed suicide because of online bullying,” said Rahman. 

“I decided that teenagers needed help and that we should take action to try to avoid other children facing the same tragedy.”

In addition to the app, Rahman has created Cyber Clubs in every school in his local area to educate young people in digital literacy and safety.

Rahman’s win came with $118,000 in prize money that he intends to use to roll out the app across Bangladesh and to other countries. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#ISC2Congress: How 5G is Expanding the Attack Surface

#ISC2Congress: How 5G is Expanding the Attack Surface

Speaking at the virtual (ISC)2 Security Congress Kevin McNamee, director of threat intelligence at Nokia, explored the security implications surrounding the introduction of 5G mobile technology, outlining five key ways 5G is expanding the attack surface.

“5G is bringing a lot to the table in terms of new security features, but I also [want to] mention the downside – the attack surface,” he said.

The first way in which 5G is widening the attack surface is the huge growth of IoT devices, McNamee continued.

“IOT devices are [often] vulnerable, unprotected and unpatched, and with 5G, more are coming. If they are out there and they are vulnerable and visible to different parts of the network, they are going to be hacked and cause problems.”

The next 5G security issue that McNanee cited was what he coined “multi-access edge computing.”

With multi-access edge computing, “you’ve got millions of devices accessing data centers or spread over the city, and it can become quite a challenge in terms of management, monitoring and incident response.

“So whoever’s operating these multi-access edge clouds has to consider how they’re managed and monitor them to make sure they are functioning properly and not being abused,” McNamee added.

Then there is the abuse of 5G bandwidth via DDoS attacks, McNamee explained. “If you’re running a huge number of mobile devices, there’s the potential for attackers to expand their DDoS attack bandwidth.

“It raises the bar with regards to how we defend against DDoS attacks when there are so many devices out there.”

The fourth security issue that McNamee referred to is the potential visibility of the 5G IP address space.

“With 5G, if we switch to IPv6 default, there’s the potential to open up visibility. If a device is visible from the internet and the network, it makes the attack surface bigger. So visibility becomes a critical thing.”

The last way in which 5G is increasing the attack surface relates to the potential targeting of ‘slicing’ – a modern way of segregating/isolating user and application communities – in attacks. “Slicing does focus the attention on certain parts of the network,” and that can be exploited by cyber-attackers, McNamee concluded.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

IT Leaders Reliant on Data for Threat Insight

IT Leaders Reliant on Data for Threat Insight

Almost three-quarters of IT leaders rely on data to make business decisions, while a third believe the value of data has permanently increased since the beginning of the COVID-19 pandemic.

According to a survey of IT leaders by Druva, as organizational reliance on data continues to rise, 73% of businesses rely on data while 33% believe there has been an impact due to COVID-19. The 2020 Value of Data Report also found that 73% of respondents were more concerned with protecting their organizational data from ransomware than they were before the pandemic.

Also, while 79% see data management and protection as a competitive business advantage, 41% say the data they collect is not readily available or accessible when needed for decision making.

In an email to Infosecurity, BH Consulting CEO Brian Honan said the impact of the COVID-19 pandemic has highlighted to organizations the value that timely and accurate data can provide.

“Organizations quickly adapted and adopted systems to facilitate the rapid sharing of data to enable them to survive through the initial waves of the pandemic,” he said. “However, it is important to remember, that for data to be effective information that a business can rely on, that data and information needs to be accurate and available. As a result, securing that data becomes even more critical to organizations.”

He went on to say that the type of data being shared and accessed needs to be managed in line with regulatory requirements. “In particular, any personal data belonging to EU residents needs to be protected in line with the requirements of the GDPR.”

Jaspreet Singh, founder and CEO, Druva, said: “The rapid move to remote work has permanently changed the way businesses operate, accelerated digital transformation and increased the value of data as a business asset.

“As companies realize that business resilience is data resilience, more and more are turning to Druva to protect and unlock its full value. Tomorrow as we bring together the industry’s most innovative leaders, our goal is for all organizations to realize the promise of the cloud era for their customers and communities.” 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Cyber-Criminal Fined $300,000 for Pipeline Attacks

Cyber-Criminal Fined $300,000 for Pipeline Attacks

A man from New Hampshire has been fined nearly $300,000 after admitting his role in cyber-attacks targeting the construction of a 1,172-mile-long pipeline spanning three American states. 

Joseph Earl Thomas Aubut of Conway confessed to being part of a hacking group that launched a series of Distributed Denial of Service (DDoS) attacks in 2016 in an attempt to prevent the Dakota Access Pipeline from being built. 

Construction of the $3.78bn pipeline that passes under Lake Oahe began in June 2016, and its first oil was delivered in May 2017. In 2016, protests over the pipeline’s impact on the environment and on sacred indigenous sites resulted in the largest gathering of Native Americans in the past hundred years. 

According to records filed in the United States District Court in Concord, Aubut and other members of the hacker-collective Anonymous targeted an unnamed company based in Houston, Texas, with cyber-attacks. 

In 2016, Anonymous began Operation No Dakota Access Pipeline (OpNoDAPL), launching a series of DDoS attacks, posting personal details of people involved with the pipeline project, and threatening their families and employees if construction wasn’t halted.

“We decided to stand with the Native Americans whose land you raped, whose sacred lands you destroyed,” said Anonymous in a 2016 video message to North Dakota’s governor. “We know where you live. Everyone you know. And everything there is to know about you.”

Court documents state that Walmart clerk Aubut began recruiting members of Anonymous in the summer of 2016 to attack the unnamed company with DDoS attacks that used malware to overwhelm the victim’s website with large volumes of traffic. 

Aubut reportedly made YouTube videos, posted under the pseudonym Sergeant Anonymous, to attract cyber-criminals to carry out the attacks. He also threatened to dox (publicly reveal the personal data) of at least one executive who worked at the victim company, the governor of North Dakota, and a law enforcement officer. 

Aubut pleaded guilty to federal charges, including one count of conspiracy to transmit information that damages a protected computer. He was ordered to pay $299,000 restitution to the victim company that hired consultants and invested in cyber-security in order to thwart the attacks.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Crypto Firm Offers $200,000 Bug Bounty to Hacker Who Stole $2m

Crypto Firm Offers $200,000 Bug Bounty to Hacker Who Stole $2m

A cryptography borrowing and savings company has offered an attacker $200,000 as a bug bounty in return for the $2m in funds they stole late last week.

Gibraltar-based Akropolis was attacked on Thursday, when an individual exploited a bug in the deposit logic of its SavingsModule smart contract to make off with a little over two million in DAI virtual currency.

However, the firm’s security company PeckShield claimed to have located the attacker’s Ethereum account, where the funds were transferred to, and said it is monitoring it for any further movement.

This could make it more challenging for the attacker to launder those funds, which might be why Akropolis published an open letter to them over the weekend.

“We have not contacted any form of law enforcement to pursue a criminal investigation. We would like to propose that you return the funds of our community members within 48 hours and in return we will offer a $200,000 USD bug bounty. We will take measures to protect your identity as required,” it said.

“If you decide not to co-operate we will pursue criminal action and contact law enforcement. We hope that we can work together towards a resolution, thank you for your time.”

In the meantime, Akropolis said it has fixed the issue at a contract level, performed an internal investigation with auditors and an external one with investors and exchange partners.

An attack on another decentralized finance (DeFi) protocol firm, Harvest Finance, at the end of October led to the theft of $24m. On that occasion the firm offered a $100,000 reward for the first person to contact the attacker and help them return the funds.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Russian and North Korean Groups Still Targeting #COVID19 Vaccine Firms

Russian and North Korean Groups Still Targeting #COVID19 Vaccine Firms

Microsoft has urged governments to act after revealing that three state-sponsored threat groups have been targeting seven companies currently developing COVID-19 vaccines and treatments.

VP for customer security and trust, Tom Burt, pointed the finger at the Russian military Strontium group (aka APT28, Fancy Bear) and North Korea’s Zinc (aka Lazarus) and Cerium groups.

The pharma and vaccine companies being targeted were not named, but Microsoft said they hailed from Canada, France, India, South Korea and the US, and have vaccines and COVID-19 tests in clinical trials.

“Strontium continues to use password spray and brute force login attempts to steal login credentials. These are attacks that aim to break into people’s accounts using thousands or millions of rapid attempts,” Burt explained.

“Zinc has primarily used spear-phishing lures for credential theft, sending messages with fabricated job descriptions pretending to be recruiters. Cerium engaged in spear-phishing email lures using COVID-19 themes while masquerading as WHO representatives. The majority of these attacks were blocked by security protections built into our products. We’ve notified all organizations targeted, and where attacks have been successful, we’ve offered help.”

Such companies have been targeted throughout the year. Back in May reports suggested state-backed APT attacks on the UK’s leading vaccine contender, being developed by AstraZeneca and Oxford University.

The same month, the US authorities blamed Chinese actors for trying to steal valuable virus research IP from domestic companies.

A couple of months later, Russia’s APT29 or Cozy Bear group were detected targeting vaccine developers in the UK, US and Canada in a campaign the National Cyber Security Centre (NCSC) branded “despicable.”

At the Paris Peace Forum on Friday, Microsoft’s Brad Smith urged governments to respond.

“Microsoft is calling on the world’s leaders to affirm that international law protects healthcare facilities and to take action to enforce the law,” said Burt.

“We believe the law should be enforced not just when attacks originate from government agencies but also when they originate from criminal groups that governments enable to operate – or even facilitate – within their borders. This is criminal activity that cannot be tolerated.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Scammers Expose Facebook Data Haul of 13 Million Records

Scammers Expose Facebook Data Haul of 13 Million Records

Security researchers have uncovered a major Facebook scam exploiting hundreds of thousands of users, after the scammers left an Elasticsearch server unsecured.

Among the 5.5GB haul discovered by vpnMentor on September 21, was 150,000-200,000 Facebook usernames and passwords, and personal info including emails, names and phone numbers for hundreds of thousands who had fallen victim to a Bitcoin scam.

The two datasets are part of the same operation: the first group were tricked into handing over their account log-ins by a fake app promising to reveal who had recently visited their profile. With these log-ins, the scammers hijacked the victims’ accounts and posted comments on their Facebook posts, with links directing individuals to a Bitcoin fraud scheme.

In total, the exposed database contained 13.5 million records, also including domains used in the scheme and text outlines related to the Facebook comments the fraudsters would post.

Although the data came from a relatively short window, June-September 2020, there are fears the scheme may have originally been much bigger. At the time it was registered by Shodan, the database contained 11GB of data relating to the scheme, rather than 5.5GB, meaning many more victims may have been affected.

The database was then wiped by the Meow attack the day after vpnMentor discovered it. New data immediately started to appear again before those in charge finally secured the server.

With access to users’ Facebook accounts, the cyber-criminals behind this campaign have a highly monetizable resource for posting malicious links to scams, launching follow-on phishing or identity fraud attempts, blackmail and credential stuffing of other accounts, vpnMentor warned.

“If you’re a Facebook user and think you’ve been a victim of this fraud, change your login credentials immediately. Furthermore, if you reused your Facebook password on any other accounts, change it immediately to protect them from hacking,” the firm said.

“We recommend using a password generator to create unique, strong passwords for every private account you have, and changing them periodically. Never provide usernames and passwords for Facebook, email or financial accounts to external websites.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk