Microsoft Patch Tuesday, October 2020 Edition

It’s Cybersecurity Awareness Month! In keeping with that theme, if you (ab)use Microsoft Windows computers you should be aware the company shipped a bevy of software updates today to fix at least 87 security problems in Windows and programs that run on top of the operating system. That means it’s once again time to backup and patch up.

Eleven of the vulnerabilities earned Microsoft’s most-dire “critical” rating, which means bad guys or malware could use them to gain complete control over an unpatched system with little or no help from users.

Worst in terms of outright scariness is probably CVE-2020-16898, which is a nasty bug in Windows 10 and Windows Server 2019 that could be abused to install malware just by sending a malformed packet of data at a vulnerable system. CVE-2020-16898 earned a CVSS Score of 9.8 (10 is the most awful).

Security vendor McAfee has dubbed the flaw “Bad Neighbor,” and in a blog post about it said a proof-of-concept exploit shared by Microsoft with its partners appears to be “both extremely simple and perfectly reliable,” noting that this sucker is imminently “wormable” — i.e. capable of being weaponized into a threat that spreads very quickly within networks.

“It results in an immediate BSOD (Blue Screen of Death), but more so, indicates the likelihood of exploitation for those who can manage to bypass Windows 10 and Windows Server 2019 mitigations,” McAfee’s Steve Povolny wrote. “The effects of an exploit that would grant remote code execution would be widespread and highly impactful, as this type of bug could be made wormable.”

Trend Micro’s Zero Day Initiative (ZDI) calls special attention to another critical bug quashed in this month’s patch batch: CVE-2020-16947, which is a problem with Microsoft Outlook that could result in malware being loaded onto a system just by previewing a malicious email in Outlook.

“The Preview Pane is an attack vector here, so you don’t even need to open the mail to be impacted,” said ZDI’s Dustin Childs.

While there don’t appear to be any zero-day flaws in October’s release from Microsoft, Todd Schell from Ivanti points out that a half-dozen of these flaws were publicly disclosed prior to today, meaning bad guys have had a jump start on being able to research and engineer working exploits.

Other patches released today tackle problems in Exchange Server, Visual Studio, .NET Framework, and a whole mess of other core Windows components.

For any of you who’ve been pining for a Flash Player patch from Adobe, your days of waiting are over. After several months of depriving us of Flash fixes, Adobe’s shipped an update that fixes a single — albeit critical — flaw in the program that crooks could use to install bad stuff on your computer just by getting you to visit a hacked or malicious website.

Chrome and Firefox both now disable Flash by default, and Chrome and IE/Edge auto-update the program when new security updates are available. Mercifully, Adobe is slated to retire Flash Player later this year, and Microsoft has said it plans to ship updates at the end of the year that will remove Flash from Windows machines.

It’s a good idea for Windows users to get in the habit of updating at least once a month, but for regular users (read: not enterprises) it’s usually safe to wait a few days until after the patches are released, so that Microsoft has time to iron out any chinks in the new armor.

But before you update, please make sure you have backed up your system and/or important files. It’s not uncommon for a Windows update package to hose one’s system or prevent it from booting properly, and some updates even have known to erase or corrupt files.

So do yourself a favor and backup before installing any patches. Windows 10 even has some built-in tools to help you do that, either on a per-file/folder basis or by making a complete and bootable copy of your hard drive all at once.

And if you wish to ensure Windows has been set to pause updating so you can back up your files and/or system before the operating system decides to reboot and install patches on its own schedule, see this guide.

As always, if you experience glitches or problems installing any of these patches this month, please consider leaving a comment about it below; there’s a better-than-even chance other readers have experienced the same and may chime in here with some helpful tips.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Ransomware Tops 2020 Threat Rankings

Ransomware Tops 2020 Threat Rankings

Ransomware was the most observed threat in 2020, according to a global corporate investigations and risk consulting firm based in New York City.

Kroll‘s proprietary data on cyber incident response cases shows that ransomware attacks accounted for over one-third of all cases as of September 1, 2020. 

While this particular form of malware has struck organizations of all sizes across every sector this year, Kroll has observed that the three industries most targeted with ransomware were professional services, healthcare, and technology.

Over a third of cyber-attacks observed by Kroll in 2020 can be attributed to three main ransomware gangs.

Ryuk and Sodinokibi, perennially the most observed form of ransomware attack in Kroll’s cases, have been joined by Maze as the top three ransomwares so far in 2020, comprising 35% of all cyber-attacks,” said a spokesperson for Kroll.

Business email compromise was almost as prevalent as ransomware, accounting for 32% of cyber-attacks observed by Kroll.

A new tactic of ransomware gangs observed this year by Kroll was the exfiltration and publication of the victim’s data.

“Many ransomware variants have added exfiltration and publication to their bag of tricks over the course of the year, and over two-fifths (42%) of Kroll’s cases with a known ransomware variant are connected to a ransomware group actively exfiltrating and publishing victim data,” said Kroll’s spokesperson.

In nearly half (47%) of the ransomware cases observed by Kroll, threat actors leveraged open remote desktop protocol (RDP) and Microsoft’s proprietary network communications protocol to begin their attacks.

Just over a quarter (26%) of cases were traced back to a phishing email, while 17% were linked to vulnerability exploits, including but not limited to Citrix NetScaler CVE-2019-19781 and Pulse VPN CVE-2019-11510.

“We have seen a predictable surge in cyber-attacks so far in 2020 as the COVID-19 pandemic has given malign actors increased opportunities to cause havoc,” said Devon Ackerman, managing director and head of incident response at Kroll North America. 

“The ongoing evolution of ransomware creators is constantly shifting the goalposts for those trying to defend data and systems, so vigilance must remain at the top of CIO’s to do list.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Microsoft Disrupts Botnet Installing Ransomware

Microsoft Disrupts Botnet Installing Ransomware

Technology giant Microsoft has used a court order to disrupt one of the world’s most notorious botnets.

Trickbot has infected over a million computing devices around the world since late 2016 and is a prolific distributor of ransomware. 

In a statement released today, Microsoft’s corporate vice president of customer security and trust, Tom Burt, echoed a warning shared previously by the United States government that ransomware is “one of the largest threats to the upcoming elections.” Burt said that Microsoft had moved against the botnet chiefly to protect America’s election infrastructure and fight against cyber-attacks.

“Adversaries can use ransomware to infect a computer system used to maintain voter rolls or report on election-night results, seizing those systems at a prescribed hour optimized to sow chaos and distrust,” said Burt.

Using a court order granted by the United States District Court for the Eastern District of Virginia, Burt said Microsoft teamed up with a global network of partners, including FS-ISACESETLumen’s Black Lotus LabsNTT, and Symantec, a division of Broadcom, to “disable the IP addresses, render the content stored on the command and control servers inaccessible, suspend all services to the botnet operators, and block any effort by the Trickbot operators to purchase or lease additional servers.”

Microsoft used the court order to cut off key infrastructure so those operating Trickbot are no longer able to initiate new infections or activate ransomware that has already been dropped into computer systems.

“In addition to protecting election infrastructure from ransomware attacks, today’s action will protect a wide range of organizations including financial services institutions, government agencies, healthcare facilities, businesses, and universities from the various malware infections Trickbot enabled,” said Burt.

Before taking action, Microsoft investigated Trickbot, analyzing approximately 61,000 samples of the malware.

“What makes it so dangerous is that it has modular capabilities that constantly evolve, infecting victims for the operators’ purposes through a ‘malware-as-a-service’ model,” said Burt. 

“Its operators could provide their customers access to infected machines and offer them a delivery mechanism for many forms of malware, including ransomware.” 

Burt said Trickbot’s operators have leveraged topics that have dominated the news in a bid to distribute malware.

“Based on the data we see through Microsoft Office 365 Advanced Threat Detection, Trickbot has been the most prolific malware operation using COVID-19 themed lures.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Gov-Linked “Fatima” Cybersecurity Career Advert Removed After Backlash

Gov-Linked “Fatima” Cybersecurity Career Advert Removed After Backlash

A campaign intended to attract more people to career opportunities in cybersecurity has come under heavy criticism and been removed after only a few hours.

A poster which showed a woman named “Fatima” dressed as a ballet dancer said her “next job could be in cyber – she just doesn’t know it yet” came under criticism after it was announced the UK government was encouraging those in performing arts to retrain for other careers.

Initially it was unclear as to who was behind the campaign, with it featuring the branding of DCMS and NCSC’s Cyber First campaign. Secretary of State for DCMS Oliver Dowden dismissed any involvement with the campaign, saying “this is not something from DCMS” and he agreed “it was crass.”

He explained the advert was from “a partner campaign encouraging people from all walks of life to think about a career in cybersecurity.” However, the campaign was outsourced to tech skills company QA, while a spokesperson for the NCSC confirmed the campaign was created by DCMS using the NCSC’s Cyber First course materials, which is aimed at children and students, to be repurposed for adults in this new campaign.

It was also revealed that the photo of “Fatima” was a stock image from a US photographer based in Atlanta, Georgia. This was apparently one of a series of articles due to be released, however a spokesperson for Prime Minister Boris Johnson said “this particular piece of content was not appropriate and has been removed from the campaign.”

In an email to Infosecurity, Javvad Malik, security awareness advocate at KnowBe4, said the poster did come across as tone deaf. “With any career, you want to pull people towards it and motivate them to want to choose it,” he said. “It’s only when people enjoy, have an interest in, or have a passion for a role that they actually have a sense of achievement and contentment.

“The overall vibe of the poster came across as anyone who spent time in the arts (which is a passion for most) wasted their time and have no career prospects, so should do something like cybersecurity. Just because there is a vacancy in a field, it doesn’t mean you can push anyone into it. If anything, it will only serve as a temporary measure which people will begrudgingly undertake until they can move onto something that offers them fulfilment.”

Infosecurity has reached out to DCMS for a comment.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Cambridge University Releases Fake News Game

Cambridge University Releases Fake News Game

The University of Cambridge has released a new game designed to help people sort fact from cleverly faked fiction when it comes to online information about Covid-19. 

Players of Go Viral! assume the role of a malicious actor who is on a mission to spread misinformation online about the global health pandemic. The online game has been designed to introduce members of the public to the wide variety of techniques criminals use to circulate fake news, particularly on social media.

Go Viral! was launched in partnership with the UK government and published last week in the Journal of Experimental Psychology: Applied. Its creators hope that the game will make it easier for people to identify and disregard information about Covid-19 that can’t be substantiated by legitimate sources. 

The team who made the game say that playing it just once will decrease the chances of a social media user’s being duped with fake news for a period of at least three months. 

Dr. Sander van der Linden, leader of the project and the Social Decision-Making Lab at Cambridge, said false information was difficult to dislodge from the minds of people who have been exposed to it. 

“Fake news can travel faster and lodge itself deeper than the truth,” said van der Linden. “Fact-checking is vital, but it comes too late and lies have already spread like the virus.”

Since the removal of fake news from the mind of a victim is so difficult even when the actual truth has come to light, the game’s makers opted for a more pre-emptive approach to tackling what is a growing problem in all forms of media. 

“We are aiming to pre-emptively debunk, or pre-bunk, misinformation by exposing people to a mild dose of the methods used to disseminate fake news,” said van der Linden.

“It’s what social psychologists call ‘inoculation theory.’”

Over the course of around six minutes, players are introduced to various news-spreading techniques commonly used by bad actors. These include using emotionally charged language to create outrage and fear, quoting from fake ‘experts,’ and mining conspiracies for social media ‘likes.’

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Attackers Chaining Zerologon with VPN Exploits

Attackers Chaining Zerologon with VPN Exploits

The US government has warned of newly discovered APT attacks combining exploits of VPN products with those for the recently disclosed Zerologon bug.

The joint alert from the FBI and Cybersecurity and Infrastructure Security Agency (CISA) revealed that government and non-government targets are being attacked in this campaign.

It warned that access to federal and state, local, tribal and territorial (SLTT) government networks could put election information at risk, although there’s no evidence that this data has been compromised, or that its theft was the ultimate goal of the attackers.

“CISA is aware of multiple cases where the Fortinet FortiOS Secure Socket Layer (SSL) VPN vulnerability CVE-2018-13379 has been exploited to gain access to networks. To a lesser extent, CISA has also observed threat actors exploiting the MobileIron vulnerability CVE-2020-15505. While these exploits have been observed recently, this activity is ongoing and still unfolding,” the warning noted.

“After gaining initial access, the actors exploit CVE-2020-1472 [Zerologon] to compromise all Active Directory (AD) identity services. Actors have then been observed using legitimate remote access tools, such as VPN and Remote Desktop Protocol (RDP), to access the environment with the compromised credentials. Observed activity targets multiple sectors, and is not limited to SLTT entities.”

CISA warned that exploits of similar bugs in products from Juniper (CVE-2020-1631), Pulse Secure (CVE-2019-11510), Citrix NetScaler (CVE-2019-19781) and Palo Alto Networks (CVE-2020-2021) could be chained with Zerologon to achieve the same result.

Fixed by Microsoft back in August, Zerologon was deemed so critical that CISA issued an emergency directive in September demanding all civilian government agencies patch the bug.

A few days later attacks exploiting the critical elevation of privilege flaw were detected in the wild.

CISA has a list of patching and mitigation best practices here.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Five Eyes Repeat Encryption Backdoor Calls

Five Eyes Repeat Encryption Backdoor Calls

The Western Five Eyes powers have issued yet another joint statement effectively calling for tech firms to engineer backdoors into end-to-end and device encryption.

The post-war intelligence alliance of the UK, US, Australia, New Zealand and Canada was joined by India and Japan in issuing the new missive — the latest of many calls to engage with governments on the issue.

The arguments put forward were the same as always: a few lines in support of encryption’s role in protecting data, privacy, and IP, followed by many more decrying the fact that it can also enable violent criminals, terrorists and child abusers to stay hidden online from investigators.

As they did last year, the Five Eyes nations called on tech firms like Apple and Facebook to find a way to accede to law enforcement requests for access to encrypted data on suspects. As it stands, they can do neither this nor police their own platforms for content that violates terms of service, the governments argued.

“We reiterate that data protection, respect for privacy and the importance of encryption as technology changes and global internet standards are developed remain at the forefront of each state’s legal framework,” concluded the statement. 

“However, we challenge the assertion that public safety cannot be protected without compromising privacy or cybersecurity. We strongly believe that approaches protecting each of these important values are possible and strive to work with industry to collaborate on mutually agreeable solutions.”

The problem with these demands is that they are just not technically feasible, according to the technology community. It would require firms to effectively engineer backdoors into services which, they claim, will eventually reach the criminal underground and be abused to undermine security and privacy for hundreds of millions of global users.

A couple of years ago, the world’s leading cryptography experts signed an open letter asking FBI boss Christopher Wray to explain how tech firms could accede to these government demands without degrading security for all users.

The official response to such arguments, as per the latest Five Eyes statement, is that the tech community isn’t trying hard enough to find a way forward and that it can be done, although with no information on exactly how.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Software AG Hit by Data-Stealing Ransomware Attack

Software AG Hit by Data-Stealing Ransomware Attack

A major German enterprise software company has become the latest tech name to suffer a likely ransomware attack featuring information theft.

IoT specialist Software AG, which claims to have over 10,000 customers and annual revenue exceeding €800m, revealed the news in a brief update late last week.

The note claimed the attack had been ongoing since Monday and had yet to be fully contained.

“Today, Software AG has obtained first evidence that data was downloaded from Software AG’s servers and employee notebooks. There are still no indications for services to the customers, including the cloud-based services, being disrupted. The company is refining its operations and internal processes continuously,” it explained on October 8.

“Software AG is further investigating the incident and is doing everything in its power to contain the data leak and to resolve the ongoing disruption of its internal systems, in particular to restart its internal systems as soon as possible which had been shut down for security reasons.”

Although the firm’s website appears to be up and running as normal, it is requesting users with support issues to email their problem and leave a number for call back, “due to technical issues with our online support system.”

Researchers MalwareHunterTeam posted on social media that the firm had been hit by the Clop variant, one which usually demands a ransom of $20 million. The group apparently claims to have swiped around a terabyte of data.

The incident is yet another sign of ransomware groups increasingly going after large enterprise targets with deep pockets. They will often perform detailed reconnaissance before striking in advanced multi-stage attacks using APT-style tactics to stay hidden while exfiltrating data and finally deploying the ransomware.

An attack on IT services giant Cognizant cost the firm an estimated $50-70m in Q2 2020, it admitted earlier this year.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk