Salesforce Communities Could Expose Business-Sensitive Information

Salesforce Communities Could Expose Business-Sensitive Information

Numerous publicly accessible Salesforce Communities are misconfigured and could expose sensitive information, says research published today.

A Salesforce Community site lets customers and partners interface with a Salesforce instance from outside an organization. For example, they can open support tickets, ask questions, manage their subscriptions and more.

According to Varonis, anonymous users can “query objects that contain sensitive information such as customer lists, support cases and employee email addresses.” The research team explains in a blog post that a “malicious actor could exploit this misconfiguration to perform recon for a spear-phishing campaign” at a minimum.

“At worst, they could steal sensitive information about the business, its operations, clients, and partners,” it goes on to say. “In some cases, a sophisticated attacker may be able to move laterally and retrieve information from other services that are integrated with the Salesforce account.”

Salesforce communities run on Salesforce’s Lightning framework — a rapid development framework for mobile and desktop sites. It is a component-oriented framework, using aura components — self-contained objects that a developer can use to create web pages. In the case of Salesforce, aura components can be used to perform actions such as viewing or updating records.

“In misconfigured sites, the attacker can perform recon by looking for information about the organization, like users, objects, and fields that expose names and email addresses and in many cases, they can infiltrate the system or steal information” explains the Varonis research team. “First, the attacker must find a community site to exploit.”

The researchers go on to explain that “there are common URL “fingerprints” that will indicate a website is powered by Salesforce Communities” such “/s/topic,” “/s/article” and “/s/contactsupport.” The attacker will then retrieve information about the site by returning the organization’s domain and some security settings and available objects.

According to the research team, Salesforce admins can take the following steps to protect themselves from attackers:

  • Ensure guest profile permissions don’t expose things that shouldn’t be exposed such as account records, employee calendars, etc.
  • Disable API access for guest profiles.
  • Set the default owner for records created by guest users.
  • Enable secure guest user access.

This finding shows that security teams need to access their SaaS exposure continually, says the research team.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Fraudsters Impersonate DPD in “Convincing” New Smishing Scam

Fraudsters Impersonate DPD in “Convincing” New Smishing Scam

Consumers have been warned about a new “convincing” smishing scam that impersonates international parcel delivery firm DPD.

The consumer group Which? provided insights into the smishing campaign, in which scammers attempt to trick recipients into giving away personal information, including payment details.

In the scam, consumers receive a text that states: “DPD: We tried to deliver your parcel however no one was available to receive it. To arrange your redelivery, please proceed via: *link.”

The Which? researchers were then taken to a very convincing DPD copycat website requesting the user’s personal details to rearrange delivery and payment of a small ‘redelivery’ fee.

Although the website looked very similar to the official DPD site, Which? noted an error in the date format used: it stated that the ‘parcel’ was in the depot on ‘-1 August’ and ‘0 August’.

Interestingly, the researchers were unable to take a screenshot of the website on the device they were using, raising further suspicion. “Some security measures on the copycat website were blocking us from doing so,” they explained.

Which? reported the scam text and website to DPD, who recommended that users download its ‘Your DPD’ app as a safe alternative to text and email notifications. The firm added: “We continue to stress that only emails sent from one of three DPD email addresses are genuine, these are dpd.co.uk, dpdlocal.co.uk and dpdgroup.co.uk.

“With texts, we advise consumers to double check the links within the notifications to confirm that they are legitimate. These links should only be for www.dpd.co.uk/ or www.dpdlocal.co.uk/. We have worked with Action Fraud and regional police focus in the last couple of years on awareness campaigns and will continue to do so.”

The discovery of this new scam has followed the dramatic shift to online shopping during COVID-19, which has provided fraudsters with more opportunities to target consumers, including by impersonating delivery services.

In May, consumers were warned to be vigilant about a surge in meal kit delivery scams, following rising demand for these DIY recipe kits in the pandemic.

Commenting on Which? ’s investigation, Tony Pepper, CEO of Egress, said, “Cyber-criminals will always take advantage of any opportunity to trick people into giving up their valuable personal and financial information. Over the last year, there’s been a significant increase in this type of activity, and we’ve seen scams using the branding of well-known organizations such as DPD and Royal Mail to exploit people into sharing sensitive data. We urge anyone who has received a text message or email requesting their personal data to remain vigilant and always question why a company might need this information, and to double check with DPD directly if you’re unsure. We’d also encourage anyone who has received an email or text message of this nature to report it to the NCSC’s text reporting number at 7726, or to their Suspicious Email Reporting Service.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

NCSC Announces First Cohort for New Cyber Startup Program

NCSC Announces First Cohort for New Cyber Startup Program

The UK’s National Cyber Security Centre (NCSC) has unveiled the first five tech companies that will take part in its new startup program.

The NCSC For Startups initiative, first announced in June, will support innovative cybersecurity firms to develop products that will help protect critical areas of the UK’s economy and society from online harms.

The NCSC is collaborating with innovation company Plexal to run the program. It is the successor to the highly successful NCSC Cyber Accelerator initiative, which helped more than 40 startups raise over £100m in external investment.

The first five successful applicants for the new program focus on a range of areas within cybersecurity, including cyber fraud detection, SaaS and ransomware protection. They are as follows:

These companies will receive continuous onboarding from NCSC experts and Plexal’s cyber innovation team over 12 months. Additionally, they will gain access to wider technical and commercial opportunities with Plexal’s industry partners. The startups will also keep all intellectual property and equity created during the program, which is supported by Deloitte, CyNam, Cheltenham-based coworking space Hub8 and tech skills provider QA. 

The onboarding will take place both in the NCSC for Startups HQ in Cheltenham and remotely. 

Chris Ensor, NCSC deputy director for cyber growth, commented, “The UK has a thriving cybersecurity industry, and I’m excited to get to work with our first five companies and bring their innovations to life.

“Finding great ideas that can help protect all areas of society is a key part of our mission, and we look forward to collaborating with more startups as the program rolls on.”

Saj Huq, director of innovation at Plexal, said:, “We’re excited to welcome the first innovators to NCSC For Startups. The response to our call for applications has been phenomenal, and we’re looking forward to bringing on more startups throughout 2021 in response to specific challenges and technology needs in the cybersecurity market.

“The NCSC understands the UK’s cybersecurity challenges better than anyone, and the opportunity for innovative startups to benefit from its world-class insight and expertise is unique. Combined with Plexal’s extensive track record in supporting startups to become market leaders, NCSC For Startups will help companies address some of the most challenging security problems facing the government, businesses and society now and in the future.”

Further information on the program and how to apply can be found here.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Chinese Espionage Group UNC215 Targeted Israeli Government Networks

Chinese Espionage Group UNC215 Targeted Israeli Government Networks

Chinese espionage group UNC215 leveraged remote desktop protocols (RDP) to access an Israeli government network using stolen credentials from trusted third parties, according to research published today.

Mandiant, part of cybersecurity firm FireEye, analyzed data gathered from their telemetry and the information shared by Israeli entities in collaboration with the authorities. The data revealed multiple concurrent operations against Israeli government institutions, IT providers and telecommunications entities beginning in January 2019.

FireEye has published the findings in a blog detailing the post-compromise tradecraft and operational tactics, techniques and procedures (TTPs) of UNC215. The group has targeted private companies, governments and various organizations in the Middle East, Europe, Asia and North America.

Mandiant’s research comes after a joint announcement by governments in North America, Europe, Asia and organizations such as NATO and the EU on July 19 2021. The announcement condemned widespread cyber espionage conducted on behalf of the Chinese government.

“These coordinated statements attributing sustained cyber espionage activities to the Chinese Government corroborate our long-standing reporting on Chinese threat actor targeting of private companies, governments, and various organizations around the world, and this blog post shows yet another region where Chinese cyber espionage is active,” says the blog post.

The group remotely executed FOCUSFJORD on their primary target. Since 2019, UNC215 has been exploiting the Microsoft SharePoint vulnerability CVE-2019-0604 to install web shells and FOCUSFJORD payloads. Manidant says that even though it and FireEye telemetry has been working with Israeli defense agencies, UNC215 has been using TTPs to hinder “attribution and detection, maintain operational security, employ false flags and leverage trusted relationships for lateral movement.

“UNC215 made technical modifications to their tools to limit outbound network traffic and used other victim networks to proxy their C2 instructions, likely to minimize the risk of detection and blend in with normal network traffic,” the blog post explains.

The team also found a sample of a new malware (MD5:625dd9048e3289f19670896cf5bca7d8), which shares code with FOCUSFJORD. The malware is distinct and only contains functions to relay communications between another FOCUSFJORD instance and a C2 server, which the Mandiant team believes was used in the operation to reduce the likelihood of being detected.

“UNC215 has compromised organizations in the government, technology, telecommunications, defense, finance, entertainment, and health care sectors,” explains the Mandiant Israel Research Team, U.S. Threat Intel Team, who authored the blog post. “The group targets data and organizations which are of great interest to Beijing’s financial, diplomatic, and strategic objectives.” The blog post goes on to say that the activity demonstrates “China’s consistent strategic interest in the Middle East” against the backdrop of “China’s multi-billion-dollar investments related to the Belt and Road Initiative (BRI) and its interest in Israeli’s robust technology sector.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains