Cybersecurity Visuals

The Hewlett Foundation just announced its top five ideas in its Cybersecurity Visuals Challenge. The problem Hewlett is trying to solve is the dearth of good visuals for cybersecurity. A Google Images Search demonstrates the problem: locks, fingerprints, hands on laptops, scary looking hackers in black hoodies. Hewlett wanted to go beyond those tropes.

I really liked the idea, but find the results underwhelming. It’s a hard problem.

Hewlett press release.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Cyber-attack on Mississippi Schools Costs $300k

Cyber-attack on Mississippi Schools Costs $300k

A Mississippi school district has voted to pay $300,000 to recover files that were encrypted during a suspected ransomware attack.

A federal investigation was launched after threat actors accessed Yazoo County School District’s information technology system without authorization. 

Superintendent Dr. Ken Barron told WLBT news that the school became aware of the cyber-attack on Monday, October 12. Barron did not state how the attackers had gained access to the system or what information had been compromised as a result of the incident.

The superintendent said that individuals would be notified about the incident if required by law. He stated that he had been advised against revealing any further details of the attack in case it jeopardized the investigation being carried out by federal law enforcement. 

Following the attack, the school took its IT systems offline and engaged a cybersecurity firm to help recover data encrypted by threat actors. Classes at the school are operating as normally as possible under existing COVID-19 restrictions.

The school board voted to pay a company $300,000 to recover the data that was encrypted by malware. 

“Last week, the Yazoo County School District detected a potential cyber event impacting certain devices on our network. We took our IT systems offline to investigate and address. National cyber-security firms were engaged to assist. We also reported this to federal law enforcement,” wrote Barron in a statement issued by the school

“In an abundance of caution, we are deploying advanced cyber-security tools throughout our environment to ensure devices can be used without issues and to allow us to resume normal IT operations as quickly as possible. We are also taking measures to unlock the encrypted files.”

Barron said that staff payroll, cafeteria transactions, and the school’s phone, fire alarm, and burglary systems were not impacted by the attack.

He added: “This is an ongoing investigation and as such, we have been advised by cyber-experts not to comment further at this time. We will notify individuals if and when needed in compliance with federal and state law.”

Lincoln County Schools, another Mississippi school district, fell victim to a ransomware attack in November 2019.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Instagram’s Handling of Children’s Data Under Investigation

Instagram’s Handling of Children’s Data Under Investigation

Social media app Instagram is being investigated by the EU for allegedly failing to protect the privacy of children’s data. 

Instagram’s alleged data mishandling allowed the email addresses and phone numbers of children aged under 18 to become visible to other users of the platform. Facebook, which owns the social media app, has denied breaking any privacy laws. 

The investigation into the app is being led by Ireland’s Data Protection Commissioner (DPC), the lead European Union regulator under the EU’s General Data Protection Regulation (GDPR), which came into force in 2018.

A key role of the Irish regulator is to defend an individual’s right to online privacy. The DPC can fine violators of this right large sums of money.

During the investigation, the DCP will determine whether Facebook has a legal basis for processing children’s personal data. It will also probe the protections and restrictions put in place for children on Instagram to assuage if they are adequate.

Instagram requires users to be at least 13 years old before they can create an account. In some jurisdictions, the minimum age requirement is higher. 

The DCP is also looking at Facebook to check that the company has adhered with GDPR requirements regarding Instagram’s profile and account settings. In this separate investigation, the commissioner will seek to determine whether Facebook is adequately safeguarding the data protection rights of children as vulnerable people.

Facebook has said it is cooperating fully with the DCP. 

“Instagram is a social media platform which is used widely by children in Ireland and across Europe,” said DPC deputy commissioner Graham Doyle.

“The DPC has been actively monitoring complaints received from individuals in this area and has identified potential concerns in relation to the processing of children’s personal data on Instagram which require further examination.”

Research completed by US-based data scientist David Stier prompted the DCP to investigate Instagram. In 2019, Stier analyzed profiles of almost 200,000 Instagram users across the world and estimated that at least 60 million users under the age of 18 were offered the option to switch their personal profiles into business accounts.

Instagram users with business accounts are required to display their phone numbers and email addresses to other users of the platform.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Waze Vulnerability Lets Attackers Track and Identify Users

Waze Vulnerability Lets Attackers Track and Identify Users

A vulnerability has been discovered in Google’s GPS navigation software app Waze that lets hackers identify and track users. 

Autoevolution.com reports that the flaw was discovered by security engineer Peter Gasper. When using the app’s web interface, Gasper discovered that he could request the Waze API to display not only his coordinates, but also those of other drivers traveling nearby. 

The data returned by the API showed unique identification numbers for the icons on the map that represented other drivers. Those ID numbers did not change over time, making it possible for anyone who exploited the flaw to track a particular app user over their entire journey. 

“I decided to track one driver and after some time she really appeared in a different place on the same road,” explained Gasper. “I have spawned code editor and built Chromium extension leveraging chrome.devtools component to capture JSON responses from the API. I was able to visualize how users broadly traveled between the city districts or even cities themselves.”

Further investigation by Gasper revealed that a threat actor could access the actual names of users who had interacted with the app. 

“I found out that if a user acknowledges any road obstacle or reported police patrol, user ID together with the username is returned by the Waze API to any Wazer driving through the place,” said Gasper. 

“The application usually doesn’t show this data unless there is an explicit comment created by the user, but the API response contains the username, ID, location of an event and even a time when it was acknowledged.”

In December, Gasper reported the vulnerability to the Google-owned company Waze, earning a $1,337 bug bounty for his discovery. The flaw has since been patched.

“Across any given enterprise, API-based vulnerabilities are rampant, creating easy opportunities for malicious actors to exploit. That’s why it’s so important for organizations to have runtime visibility into all APIs,” commented Jason Kent, Cequence Security‘s hacker in residence.

“Enterprises need, at all times, to be able to answer simple questions like: how many APIs do we have and who owns them; have the appropriate levels of authentication and access controls been enabled; and what type of data are your APIs transmitting?”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

DDoS Attacks Triple in Size as Ransom Demands Re-Emerge

DDoS Attacks Triple in Size as Ransom Demands Re-Emerge

The last quarter of 2020 has seen a wave of web application attacks which have used ransom letters to target businesses across a number of industries.

According to research from Akamai, the largest of these attacks sent over 200Gbps of traffic at their targets as part of a sustained campaign of higher Bits Per Second (BPS) and Packets Per Second (PPS) than similar attacks had displayed a few weeks prior.

“Prior to August, the signal vectors had been primarily used to target the gaming industry,” the company claimed. “Starting in August, these attacks abruptly swung to financial organizations, and later in the cycle, multiple other verticals.”

Akamai explained that none of the vectors involved in these series of attacks were new, as most of the traffic was generated by reflectors and systems that were used to amplify traffic. “Seeing a common set of protocols being used as amplifiers in a DDoS campaign is, by itself, an indicator of new tools, or configurations, being used by criminals, rather than an indicator of an extortion campaign,” it said.

However, multiple organizations began to receive targeted emails with threats of DDoS attacks, where this would be launched unless a ransom amount was paid. Richard Meeus, director of security technology and strategy at Akamai, said a small DDoS would be made against the company “to show that they [attackers] were serious, and then there was a threat of a 1Tbps attack if you didn’t pay.”

“Many extortion DDoS campaigns start as a threat letter, and never progress beyond that point,” Meeus said. “In contrast, this campaign has seen frequent ‘sample’ attacks that prove to the target that criminals have the capability to make life difficult.”

Whilst Akamai said many of the extortion emails end up caught by spam filters, not all targets are willing to admit they’ve received an email from the attackers

“This extortion DDoS campaign is not over,” Akamai said, “the criminals behind this campaign are changing and evolving their attacks in order to throw off defenders and the law enforcement agencies that are working to track them down.”

Speaking on a webinar last week, Richard Meeus, director of security technology and strategy at Akamai, said the company had seen the number of attacks per day increase from one million in January of this year to three million in September. “When we look at the specific data points, and look at the last two big spikes, they were both against financial services,” he said.

This campaign peaked in August and September, “and it reached its peak, perhaps when the attackers believed they had been mitigated and began to start changing their tactics.” This included a move to use layer three and four attacks, which are usually targeted at data centers, websites and APIs.

Meeus also said there had been a 200% increase in attacks against web application firewalls, which he was quite surprised by. Meanwhile, “DDoS attacks come in waves” and “ransom attacks have been going on for a number of years and we successfully take down the perpetrators, but they come back again as it is an extortion technique that works.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Government Spooks Urge Firms to Patch SharePoint Bug

Government Spooks Urge Firms to Patch SharePoint Bug

Government experts are warning SharePoint customers to urgently patch a remote code execution (RCE) vulnerability fixed by Microsoft last week.

A National Cyber Security Centre (NCSC) alert on Friday claimed successful exploitation of CVE-2020-16952 could enable attackers to run arbitrary code and carry out security actions in the context of a local administrator, on affected installations.

“The NCSC always recommends applying security updates promptly to mitigate the exploitation of all vulnerabilities but in this case the NCSC has previously seen a large number of exploitations of SharePoint vulnerabilities, such as CVE-2019-0604, against UK organizations,” it continued.

“Two SharePoint CVEs also appear in the CISA Top 10 Routinely Exploited Vulnerabilities.”

The vulnerability itself affects Microsoft SharePoint Foundation 2013 Service Pack 1, SharePoint Enterprise Server 2016 and SharePoint Server 2019, but not SharePoint Online as part of Office 365.

It occurs because the software fails to check the source markup of an application package, according to Microsoft. Exploitation therefore requires a user to upload a specially crafted SharePoint application package to an affected version.

The NCSC’s warning comes despite Microsoft rating exploitation as “less likely.” The bug has a CVSS score of 8.6 on all affected versions for SharePoint.

However, although there are no reports of attackers leveraging this vulnerability at the moment, proof-of-concept code is already available.

Experts at Rapid7 also urged SharePoint administrators to prioritize patching.

“SharePoint is a high-value attack target and has seen a number of high-severity vulnerabilities patched in recent months,” the security vendor said. “It is likely that active exploitation will occur within a relatively short time frame; it was trivial for Rapid7 researchers to validate the vulnerability’s exploitability and weaponize [the] PoC.”

As well as this vulnerability, SharePoint accounted for just under a third of the 23 critical flaws patched by Microsoft in September.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

US CEO Charged with $2bn Tax Evasion Scheme

US CEO Charged with $2bn Tax Evasion Scheme

The CEO of a US-based software firm has been charged with a decades-long tax evasion scheme said to have concealed as much as $2bn from the IRS.

Robert Brockman, who is boss of Ohio-based Reynolds and Reynolds, was charged in a 39-count indictment with tax evasion, wire fraud, money laundering and other offenses.

He is alleged to have hidden income earned from private equity investments from the US tax authorities by siphoning the funds to secret bank accounts in Bermuda and Switzerland.

The authorities alleged that Brockman did so between 1999 and 2019, with the help of a co-conspirator with whom he communicated via encrypted channels and using code words to cover his tracks.

Alongside the tax offenses, Brockman is charged with fraudulently obtaining almost $68m in his company’s debt securities. He is alleged to have used a third party to acquire the securities, circumventing strict laws restricting such purchases by a CEO without full disclosure and prior notice.

He is also said to have used insider information about the company to support his decision making in purchasing the debt, and to have persuaded an individual to destroy and alter documents and computer evidence to hide his tracks.

Brockman is charged with seven counts of tax evasion, 20 counts of wire fraud affecting a financial institution, various counts of money laundering, six counts of failing to file foreign bank account reports and evidence destruction and tampering.

Although Brockman is innocent until proven guilty, the Department of Justice warned that if convicted he potentially faces “a substantial period of incarceration.”

“As alleged, Mr Brockman is responsible for carrying out an approximately two-billion dollar tax evasion scheme,” said Jim Lee, chief of IRS Criminal Investigation.

“IRS Criminal Investigation aggressively pursues tax cheats domestically and abroad. No scheme is too complex or sophisticated for our investigators. Those hiding income or assets offshore are encouraged to come forward and voluntarily disclose their holdings.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Google Reveals it Was Hit by 2.5Tbps DDoS

Google Reveals it Was Hit by 2.5Tbps DDoS

Google has revealed a nation state DDoS campaign against it originating from China, which may have been the biggest attack of its kind ever recorded.

The 2.5Tbps DDoS struck in September 2017 but was made public for the first time on Friday in a report designed to share best practices on cyber-defense and plug Google Cloud mitigations.

According to Google security reliability engineer, Damian Menscher, the attack topped a six-month campaign against the firm.

“Despite simultaneously targeting thousands of our IPs, presumably in hopes of slipping past automated defenses, the attack had no impact. The attacker used several networks to spoof 167 Mpps (millions of packets per second) to 180,000 exposed CLDAP, DNS, and SMTP servers, which would then send large responses to us,” he explained.

“This demonstrates the volumes a well-resourced attacker can achieve: this was four times larger than the record-breaking 623 Gbps attack from the Mirai botnet a year earlier. It remains the highest-bandwidth attack reported to date, leading to reduced confidence in the extrapolation.”

A separate report on the same day from Shane Huntley of Google’s Threat Analysis Group revealed that this was a state-sponsored UDP amplification attack “sourced out of several Chinese ISPs (ASNs 4134, 4837, 58453, and 9394).”

“Addressing state-sponsored DDoS attacks requires a coordinated response from the internet community, and we work with others to identify and dismantle infrastructure used to conduct attacks,” he added.

Menscher also argued that collaboration and transparency is important to help reduce the opportunities for such attackers.

For example, Google reported thousands of servers exploited in the DDoS attack to their network providers, so that they could take action.

Neustar last month claimed to have neutralized the largest DDoS it has ever encountered, at just under 1.2Tbps — less than half the size of the attack on Google.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk