Vulnerabilities Affect 100,000 Sites Using WordPress Plugin

Vulnerabilities Affect 100,000 Sites Using WordPress Plugin

Researchers have discovered critical privilege-escalation vulnerabilities in a WordPress plugin installed in 100k websites.

The three flaws in Ultimate Member were detected by Wordfence‘s Threat Intelligence Team, which described them as “critical and severe” and “easy to exploit.” 

By abusing the flaws, an attacker could escalate their privileges to those of an administrator and completely take over a WordPress site.

“Once an attacker has administrative access to a WordPress site, they have effectively taken over the entire site and can perform any action, from taking the site offline to further infecting the site with malware,” noted researchers. 

Ultimate Member is a free user profile plugin deployed to create online communities and membership sites with WordPress. It allows site owners to create custom roles and manage the privileges of site members.

“We discovered that the user registration form lacked some checks on submitted user data,” wrote researchers.

“This oversight made it possible for an attacker to supply arbitrary user meta keys during the registration process that would update those meta keys in the database.”

Researchers found the first flaw on October 19, 2020, and reached out to the plugin’s developer on October 23.

“After establishing an appropriate communication channel, we provided the full disclosure details on October 26, 2020,” said researchers.

The developer acted swiftly, sending Wordfence a copy of the first intended patch for testing on October 26. 

“We confirmed the patch fixed one of the vulnerabilities, however, two still remained,” said researchers.

The remaining flaws were fixed with an updated copy provided by the developers to Wordfence three days later. A patched version of Ultimate Member, 2.1.12, was released on October 29, 2020.

“The privilege escalation vulnerabilities found in the WordPress Ultimate Member plugin demonstrate the continued risks of plugins to any web application making them a regular target for attackers. Just one compromised third-party plugin can infect tens of thousands of websites in one stroke,” commented Ameet Naik, security evangelist at PerimeterX.

“Businesses must understand the risks imposed by third-party WordPress plugins and must secure their websites using web application firewalls, as well as client-side visibility solutions that can reveal the presence of malicious code on their sites.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Zix Acquires CloudAlly

Zix Acquires CloudAlly

Texas security technology company Zix Corporation has acquired an Israeli cloud-based backup and recovery provider that will turn ten in 2021.

CloudAlly describes itself as a pioneer of enterprise-grade Software-as-a-Service (SaaS) cloud backup and recovery solutions that serves more than 5,000 customers and boasts around 250,000 users. 

The company offers a suite of award-winning, ISO 27001–certified, and GDPR/HIPAA–compliant solutions for Microsoft Office 365, Google Workspace (formerly G Suite), SharePoint, OneDrive, Salesforce, Box, and Dropbox. 

CloudAlly is a channel-first provider supported by 600 managed service provider (MSP) partners that is projected to generate approximately $8.0m in annual recurring revenue for the fiscal year ending December 31, 2020.

Zix, which is headquartered in Dallas, announced the acquisition on November 9. CEO of Zix, David Wagner, said that the deal was made to directly address growing demand the company has seen from partners, customers, and prospects alike for an enterprise-grade cloud backup offering with a best-in-class solution.

Wagner added that 45% of the company’s MSP partner base said in a recent survey that they would purchase a backup solution from Zix if it became available. 

“Cloud backup being our number one product adjacency, coupled with our proven success attaching additional products to our customer base, gives us a high level of confidence that we can leverage CloudAlly to become a greater business than just the sum of its parts,” said Wagner. 

“With CloudAlly, we can greatly enhance our Secure Cloud platform and also mitigate concerns around ransomware which has become a large industry focus.”

Avinoam Katz, CloudAlly’s CEO, said that the acquisition would benefit customers focused on achieving the best possible cybersecurity for their remote workforce. 

“We’re extremely excited to join forces with Zix at this time and feel that our industry leading cloud backup service will be a complementary and valuable addition to their recently announced Secure Cloud Platform, an integrated suite of productivity, security and compliance services,” said Katz.

“This suite of services will give our rapidly growing combined customer and partner base around the world the tools they need to protect their critical cloud assets across an evolving distributed workforce.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

PKWARE Acquires Dataguise to Expand Data Security Offering

PKWARE Acquires Dataguise to Expand Data Security Offering

Automated data security firm PKWARE has announced the acquisition of Dataguise, a company which specializes in personal data security solutions.

PKWARE believes the deal will help enable it to offer a comprehensive solution to data security and privacy management for organizations through the combination of its automated remediation capabilities, and Dataguise’s ability to discover and protect data stored across IT systems and environments.

In an age when enterprises’ users, systems and data are increasingly distributed, there is an expanded surface area in which cyber-criminals can operate, growing to risk of data breaches. In this environment, Dataguise works with leading companies in sectors such as finance, healthcare, retail and government to discover sensitive information across endpoints, servers, SaaS solutions and public, private or hybrid cloud environments.

The acquisition will also expand PKWARE’s global operations, as it will continue Dataguise’s existing offices in the US, India, Europe and Canada. Together, the two companies are currently tasked protecting sensitive data for over 1000 organizations across the world.

Spencer Kupferman, CEO of PKWARE commented: “The foundation of our increasingly digital life is centered on our personal data —knowing where it is stored and how it is protected is a business imperative for enterprises. Dataguise is a leader in privacy management; adding its technology creates a best-in-class data security company that helps customers find, classify and protect sensitive data, wherever it is.”

Manmeet Singh, co-founder and CEO of Dataguise added: “We’re proud of the team, solutions and customer base Dataguise built over the past 13 years as we delivered on our vision to help enterprises efficiently discover and defend sensitive data. Combining with PKWARE accelerates and expands those advantages, because our customers now have access to a full portfolio of data security and remediation solutions from a single vendor.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#EdgeLive: Selecting the Right Approach to Securing a Remote Workforce

#EdgeLive: Selecting the Right Approach to Securing a Remote Workforce

The ways organizations can secure remote working over the long-term were discussed by a panel at the Akamai Edge Live virtual conference.

This is in the context of the rapid shift to home working as a result of COVID-19 social distancing restrictions which, for many businesses, is expected to sustain beyond the pandemic.

The first thing CISOs need to decide is which approach they should employ that best suits the needs of their business. Patrick Sullivan, VP and CTO of security strategy at Akamai, commented: “The big decision seems to be: do you want to use that shift to remote work to advance your architecture along a strategic axis towards SASI or zero-trust, or do you feel that’s too risky at this time and want to double-down on existing technologies?”

According to Tim Knudsen, VP of enterprise security product management at Akamai, establishing a zero-trust architecture is key for organizations in achieving an improved security posture with lower costs and improved efficiency compared with virtual desktop infrastructure (VDI) and remote desktop (RDP) technologies.

“You can achieve a similar secure environment that allows you to avoid or block any lateral movement but leveraging the application specific approach of zero-trust and getting granular when it comes to context – users’ location, trust with device, time of day etc.,” he explained. “All those things you can apply towards your access policy, but you can also do it in a more flexible way because you don’t need that underlying infrastructure to present those applications.”

Yet in Japan, there has still been a strong emphasis on using VDI architecture in the remote working environment, although zero-trust and SASE solutions are becoming more popular. Takashi Ohmoto, expert engineer, multi-cloud business department, cloud and security services division at CTC, said this is because many Japanese businesses view devices used outside of the corporate network as the biggest security risk to their organization. This way, employees can take their corporate devices home to work on safely. “By using VDI, enterprises don’t have to concern themselves about the risk of the devices,” he commented.

Ohmoto added that, at the same time, employees can send data in the cloud through web conference applications such as Zoom, which “works together well with VDI.”

In keeping with Ohmoto’s point about the importance of device security, Knudsen acknowledged that zero-trust principles have to be strongly focused on devices as well as users to be effective. “Even if those devices are managed, they are exposed to a far greater risk of being compromised,” he said. This means if network level access is granted “even to a user that’s passed multiple factors of authentication, that device, if compromised, now has broad lateral access.”

Countering this requires further application-specific restrictions to decide whether a device can be trusted, “using the context of the device and its risk profile to make that decision,” according to Knudsen.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Malicious Use of SSL Increases as Attackers Deploy Hidden Attacks

Malicious Use of SSL Increases as Attackers Deploy Hidden Attacks

There has been a 260% increase in the use of encrypted traffic to “hide” attacks.

New research by Zscaler, analyzing 6.6 billion security threats, has discovered a 260% increase in attacks during the first nine months of 2020. Among the encrypted attacks was an increase of the amount of ransomware by 500%, with the most prominent variants being FileCrypt/FileCoder, followed by Sodinokibi, Maze and Ryuk.

Zscaler claimed that adversaries have leveraged SSL to hide attacks, “turning the use of encryption into a potential threat without proper inspection.” This means cyber-criminals are using industry-standard encryption methods to hide malware inside encrypted traffic to carry out attacks that bypass detection.

Deepen Desai, CISO and vice-president of security research at Zscaler, said: “We are seeing encrypted channels being leveraged by cyber-criminals across the full attack cycle, starting with initial delivery stage (email with links, compromised sites, malicious sites using SSL/TLS), to payload delivery (payloads hosted on cloud storage services like Dropbox, Google Drive, AWS, etc).”

Tim Mackey, principal security strategist at the Synopsys CyRC, told Infosecurity that using SSL or TLS as part of an attack is an acknowledgement that in 2020, legitimate websites and system traffic will be encrypted.

“Hiding malicious traffic amongst legitimate activity has the distinct benefit of allowing an attacker to progress through the early phases of their attack with a lower risk of detection,” he said. “Further, if the attacker’s toolkit leverages existing system services, such as the encryption modules supplied by the operating system, and popular cloud storage systems, such as Pastebin, GitHub or S3 buckets, then it becomes that much harder to differentiate legitimate access from the malicious.

Also, Matthew Pahl, security researcher at DomainTools, said there are instances where attackers use SSL encryption – over port 443, for example – to exfiltrate data from targets, so the threat outlined in the report is real.

He added: “Organizations should emplace inspection certs on all endpoints in order to carry out SSL inspection. It is also worth remembering, however, that this is not a magic bullet, as the ability to decrypt and read outbound traffic represents just one component of a defense-in-depth strategy.”

Zscaler claimed inspecting encrypted traffic must be a key component of every organization’s security defenses, but the problem is traditional on-premises security tools like next-generation firewalls struggle to provide the performance and capacity needed to decrypt, inspect and re-encrypt traffic in an effective manner. Also attempting to inspect all SSL traffic would bring performance (and productivity) to a grinding halt, so many organizations allow at least some of their encrypted traffic to pass uninspected from trusted cloud service providers.

“This is a critical shortcoming,” the report said. “Failing to inspect all encrypted traffic leaves organizations vulnerable to hidden phishing attacks, malware and more, all of which could be disastrous.”

If inspecting encrypted traffic must be a key component of every organization’s security defenses, are businesses actually able to do this? Mackey said: “Any plan to implement deep inspection of TLS traffic should be reviewed with legal counsel and the business data privacy leaders. As an intermediate step, businesses who operate internal DNS systems can implement network policies that segment their network based on usage profiles. Within each segment, access to cloud-based storage systems can be limited at the DNS layer to only those machines with legitimate business requirements to access them.”

Martin Jartelius, CSO at Outpost24, said: “This is largely an attempt at positioning solutions for ‘legal interception’ towards the market. In part, this of course invades privacy to a great degree, but it also only works if the traffic being sent does not use certificate pinning, or if the traffic being sent in turn does not tunnel encrypted data within the tunnel.

“Detection is great, and if it can be done on the network, that adds a layer and opportunity, but what you need is prevention from initial infection, detection of anomalous user behavior. The ‘legal interception’ solutions in and of themselves are a challenge, for example towards GDPR compliance.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

US Retailers More Vulnerable to Web App Attacks Than EU Counterparts

US Retailers More Vulnerable to Web App Attacks Than EU Counterparts

US retailers are more vulnerable to web application attacks than those based in the EU, according to Outpost24’s 2020 Web Application Security for Retail & E-commerce Report. The cybersecurity firm calculated that web apps used by US retailers had an aggregated average risk score of 35, which compares to 31 for their EU counterparts.

Retailers in the US were found to have a wider attack surface, running more publicly exposed web apps (3357) compared to those in the EU (2799). Despite this, retailers in the EU had a higher proportion of applications using old components that contained vulnerabilities (27%) compared to those based in the US (22%).

The biggest single attack vector for both US and EU retailers was security mechanisms, with risk exposure scores of 99 and 90.5 recorded, respectively, according to the report. The researchers noted that the use of HTTP websites and unrestricted access to unsecured areas of the site without encryption would contribute to a higher attack surface score.

This was followed by active content, with risk scores 88 or above calculated for both US and EU retailers. This looked at how web applications were running scripts. The third highest attack vector was degree of distribution, for which all retailers analyzed had scores above 77.9. Outpost24 said this is due to the difficulty in securing every one of the high number of product pages commonly found on large e-commerce sites.

The study also found that a high proportion of retailers (90% of EU and 50% of US) are currently running outdated jQuery versions on their apps, which may expose them to common cross site scripting attacks.

Nicolas Renard, security analyst at Outpost24, commented: “Hackers are masters of reconnaissance and will go to great lengths to identify weak spots in their target. The rather high risk exposure score among the top retailers is a worrying trend, as bigger attack surfaces create more opportunity for bad actors to find holes in security defense and execute potential exploits.”

Online retailers’ security has become increasingly important in the context of the huge shift to e-commerce this year as a result of the COVID-19 crisis, with online shopping a more lucrative target for cyber-criminals. For instance, it was revealed that nearly 2000 e-commerce stores running the popular Magento software were attacked over a single weekend in September.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Zoom Settles with FTC After Charges it Misled Customers

Zoom Settles with FTC After Charges it Misled Customers

The Federal Trade Commission (FTC) has announced a settlement with Zoom after arguing that the video conferencing firm gave users a false sense of security by misleading them on key encryption and other features.

The original FTC complaint alleged that, since 2016, Zoom had falsely claimed it offered “end-to-end 256-bit encryption” when in fact it offered a lower level of encryption and kept hold of a cryptographic key, theoretically allowing it to access or provide access to customer meetings.

The FTC also said that Zoom falsely claimed that recorded meetings stored on the company’s cloud were immediately encrypted, when they were actually stored unencrypted for up to 60 days.

“During the pandemic, practically everyone — families, schools, social groups, businesses — is using video conferencing to communicate, making the security of these platforms more critical than ever,” said Andrew Smith, director of the FTC’s Bureau of Consumer Protection.

“Zoom’s security practices didn’t line up with its promises, and this action will help to make sure that Zoom meetings and data about Zoom users are protected.”

Other complaints the FTC had included the secret installation of a ZoomOpener web server on its Mac desktop application in 2018, to ensure the app automatically launched without triggering Safari safeguards.

The server represented a hidden security risk to customers and in some circumstances would reinstall Zoom even after it had been removed.

As part of the settlement, Zoom agreed to several measures including: implementing a vulnerability program; documenting security risks annually and developing safeguards; and deploying multi-factor authentication, data deletion and other security features.

The firm has also agreed to a biennial independent assessment of its security program and is prohibited from making further misrepresentations about its privacy and security practices.

Zoom recently began rolling out end-to-end encryption for all of its users.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Ex-Microsoft Engineer Gets Nine Years for $10m Digital Theft

Ex-Microsoft Engineer Gets Nine Years for $10m Digital Theft

An ex-Microsoft engineer has been sentenced to nine years behind bars after stealing $10 million from his former employer.

Ukrainian citizen, Volodymyr Kvashuk, 26, was convicted by a jury of five counts of wire fraud, six counts of money laundering, two counts of aggravated identity theft, two counts of filing false tax returns, and one count each of mail fraud, access device fraud, and access to a protected computer in furtherance of fraud. He was found guilty of the charges in February. 

The Renton, Washington, resident was a contractor and then full-time employee at Microsoft from August 2016 to June 2018. During that time, his work in testing the tech giant’s retail sales platform gave him access to digital gift cards and other currency stored value (CSV) items, which he then sold online.

He started off with small amounts of up to $12,000 using his own account, and then hijacked those of his co-workers as the value of stolen goods escalated into the millions of dollars, according to the Department of Justice (DoJ).

Kvashuk is also said to have used a Bitcoin “mixing” service to try and hide the source of the funds put into his bank account.

In just seven months, he apparently transferred $2.8 million in digital currency to his bank and savings accounts — before filing fake tax returns to say that the money had been given to him by a relative.

Kvashuk also had enough cash to buy a $1.6 million lakefront home and a $160,000 Tesla.

“Kvashuk’s criminal acts of stealing from Microsoft, and subsequent filing false tax returns, is the nation’s first Bitcoin case that has a tax component to it,” said IRS Criminal Investigation (IRS-CI) special agent in charge, Ryan Korner.

“Simply put, today’s sentencing proves you cannot steal money via the internet and think that Bitcoin is going to hide your criminal behavior. Our complex team of cybercrimes experts with the assistance of IRS-CI’s Cyber Crimes Unit will hunt you down and hold you accountable for your wrongdoings.”

Alongside the lengthy jail term, Kvashuk is being ordered to pay over $8.3 million in restitution.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Cadbury Social Media Scammers Take Chocoholics for a Ride

Cadbury Social Media Scammers Take Chocoholics for a Ride

A fake Facebook Group is using the lure of a free hamper of Cadbury chocolate to trick social media users into divulging their personal and financial details, it has emerged.

Spotted by think tank Parliament Street, the campaign is based around “Cadbury Rewards,” which has been set up with official logos to spoof a legitimate group on the social media site.

Various posts from the group claim that the chocolate-maker, now owned by multinational Mondelēz, is sending a hamper to everyone who replies before midnight, as part of a celebration of its 126 years in business. In reality, the company is 196 years old, having been founded in 1824.

Variations on the theme include messages from specific named individuals, said to be ‘managers’ at the firm, while others claim cash prizes will also be sent to randomly chosen individuals.

Victims are urged to click through, where they’ll be taken to a Cadbury-branded phishing page to enter name, home address, phone number, email address and bank card details.

The campaign appears to have been launched over the weekend and already has hundreds of comments and nearly 2000 likes.

“We can confirm that this has not been generated by Mondelēz and would urge the general public to not interact or share personal information through the post,” a Mondelēz International statement warned.

“The security of our customers is our priority and we’re working with the relevant organizations to ensure this is resolved.”

Egress CEO, Tony Pepper, claimed the volume of such scams across social media, email and mobile channels is increasing in the run-up to Christmas.

“If someone is asking for your card details, on social media or over email, always look closely at why they would need that information. If someone is offering you free products, but requesting you provide your card details, alarm bells should start to ring,” he argued.

“A Google search will show you the retailer’s genuine website, where you can find links to their real social media pages, so you can check if the offer is posted there. If you’re still not sure, you can always reach out to the retailer via their website, to check that the offer is genuine.”

This is not the first time Cadbury, which was the inspiration for Roald Dahl novel Charlie and the Chocolate Factory, has been used in phishing scams. A similar hamper scam was spotted back in 2018, although on that occasion getting the age of the company correct.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk