Sunday, August 16, 2015

The World this week..(Week of Aug 10th)

1.       Oracle Controversy - Mary Davidson - the CSO of Oracle took to the corporate blog to pen her thoughts on Security titled - "No, You Really Can't". The post sharply admonished enterprise customers for reverse engineering, or hiring consultants to reverse engineer, the company's proprietary software, with the aim of finding as of yet unfixed security vulnerabilities. The post was deleted few hours later but social media continues to either roll its eyes or shout in outrage or just laugh at her.

2.       Marketwire, PR Newswire, and Business Wire -- which distribute press releases for major publicly traded companies -- had its systems penetrated by a pair of Ukraine-based hackers who stole 'market-moving media releases' and used this information to profitably trade and pocket $100m.

3.       Cyber thieves broke into the IT systems of Carphone Warehouse, a large cell phone retailer in the U.K., and may have stolen personal and bank data of up to 2.4 million customers and the credit card details of up to 90,000 customers. Specifically, the division that was attacked operates the OneStopPhoneShop.com, e2save.com and Mobiles.co.uk websites, the company said in an emailed statement.

4.       Update on Android's Stagefright vulnerability - Google issued a four line Patch but that does not work. This highlights the utter shoddiness of the Android ecosystem's processes for updates with three parties involved - Google, Device manufacturer and Telcos. An expert in his tweet response to Samsung / HTC 's plan to issue monthly patches to  carriers said -  "I am giving a steak to my dog, to deliver to you. I'm sure it'll arrive." Stagefright vulnerability allows hackers to just send a text message and hack the Android device.

5.       June was "the worst month of malvertising ever" and Flash zero-day vulnerabilities are partly to blame, say experts. In the first six months of 2015, malvertising was one of the biggest threats to endpoint security, causing an estimated $525 million in damages The kind of malware dropped by malvertising on the endpoint was mostly Ransomware, Banking trojans, or Bot code that abuses endpoints for Click fraud campaigns. Malware + Advertising = Malvertising. As you may recall from the last week's blog - Yahoo was recently missued to deliver malvertising.

6.       The Darkhotel cyberespionage crew keeps adding to its bag of tricks: New evidence shows that the group seems to have latched on to some of the zero-day vulnerabilities exposed by the Hacking Team data dump last month. Known best for breaking into Wi-Fi networks in luxury hotels to target very high-profile corporate and government executives, the team has long depended on zero-day vulnerabilities to strike its targets. Darkhotel has gone through half a dozen or more - zero-days targeting Adobe Flash Player in the past year, investing considerable funds to beef up a quiver meant to hit the proverbial bullseyes. The Darkhotel APT will relentlessly spearphish specific targets in order to successfully compromise systems.

7.       Australians are paying thousands of dollars to overseas hackers to rid their computers of an unbreakable virus known as Cryptolocker. There has been a rise in the number of people falling victim to the latest version of an encryption virus which hijacks computer files and demands a ransom to restore them. The "ransomware" infects computers through programs and credible-looking emails, taking computer files and photographs hostage. It can arrive in an email disguised as an installer of the new operating system in a zip file.

8.       Hackers' arsenal was beefed last week, with a drone armed with software weapons to crack into wireless computer networks at close range, whether they be in skyscrapers or walled compounds. The drone is equipped with software tools used to perform the kind of "penetration testing" done by hackers or computer security professionals who seek vulnerabilities in computer networks. The drone is flown past physical defenses of the targeted victim.


9.       India features among the worst affected countries by Black Vine, a formidable, highly resourced attack group, which is equipped to conduct cyber espionage against targeted organizations. Black Vine typically conducts watering-hole attacks against websites that are relevant to its targets' interests and uses zero-day exploits to compromise computers (Recon, Lure, Exploit kit). If the exploits succeed, then they drop variants of Black Vine's custom-developed malware (Dropper file). These threats open a back door on the compromised computers and allow the attackers to steal information. (Call home and Data theft).


Sunday, August 9, 2015

The World this week..(Week of Aug 3rd)

1.       iPhones are generally considered to be safer than Android phones but the data leaked from 'hacking team' network shows that the company used sophisticated, remotely-controllable exploits for all major mobile platforms including iOS, Android, Windows Phone, BlackBerry and Symbian. For the iOS, the Hacking Team tool is disguised as an innocuous newsstand app and comes with a transparent icon that conceals its presence on an iOS device.  The attack method takes advantage of a now-patched flaw in multiple versions of iOS that allowed attackers to replace a legitimate application installed on an iOS device with a malicious application so long as both the apps had the same binary identifier or file name.

2.       OPM Wins Pwnie for Most Epic Fail at Black Hat Awards Show: One of the many categories at the Pwnie Awards is for the Most Epic Fail, with this year's nominees including the Ashley Madison and U.S. Office of Personnel Management (OPM) hacks. OPM came away with this year's Most Epic Fail award, as the hack of its systems resulted in 25.7 million Americans being at risk. The name Pwnie Award is based on the word ``pwn'', which is hacker slang meaning ``to compromise'' or to ``control'' based on the previous usage of the word ``own'' (and it is pronounced similarly).

3.       Starting from July 28th - for 7 days, hackers used Yahoo's ad network to infect millions of computers. A group of hackers bought ads across the Internet giant’s sports, news and finance sites. When a windows computer visited a Yahoo site, it downloaded malware code. Either the victims were being held at ransom until they paid money or their browsers were being redirected discreetly to websites which paid hackers on traffic. Yahoo acknowledged the attack but said the scale of the attack was grossly misrepresented.

4.      
Named after the life size terracotta Chinese soldiers, China has an illegal VPN service that is used to circumvent the Great Firewall of China. This service has over 1500 nodes in the outside world, obtained mainly through exploiting vulnerable Windows-based servers used by legitimate organizations. Terracotta also masks online users, which can be invaluable to individuals in a country where activists do not prove popular with the ruling party. Hackers have begun to exploit this and launch attacks through these VPNs which makes it impossible to track them.


5.       The Sri Lankan prime minister Ranil Wickremesinghe’s  office website was hacked by a hacktivist. The hacker going with the handle of Dr.MwNs, hacked and defaced the official website of Prime Minister’s Office in Sri Lanka last Thursday.

6.       Researchers participating in the Black Hat USA, have released details about the "Man in the cloud" attack. This attack does not depend on any malware or stolen credentials. It instead uses the synchronization token that is used by all cloud apps to authenticate the user and sync files. The attacker social engineers the victim to install a simple piece of code that creates a new synchronization token with the attackers cloud account, it also steals the victims original synchronization token and runs it on the attackers cloud account. Now every time the victim uses the cloud, the files are uploaded to the attacker's cloud account, from where it is synced to the victims cloud account.

7.       Classic case of typosquatting - Cybercriminals hacked into the email conversations between a Marine Lines pharmaceutical firm in Mumbai and a US company, they used the information in the mails, created a similar ID and duped the Mumbai firm of ₹5 lakh. Through the emails, the accused had found out that the Mumbai company had ordered for medical equipment. They created a fake ID by flipping just one letter of the US company’s ID.

8.       Some more news from Black Hat USA - researchers have shown how finger prints from Android devices can be stolen and maliciously used by hackers for the rest of Victim's life time. This  "fingerprint sensor spying attack" -- can "remotely harvest fingerprints in a large scale,", Many android phones use Finger print sensor to login the user into the phone, hackers can steal this image from the sensor and misuse it in a variety of ways as fingerprints are used in mobile payments, unlocking devices, identity, immigration, and for criminal records. Apple phones remain unaffected in this attack as Apple encrypts the image.


9.       A new Variant of Ransomware has surfaced in Australia, this variant can double the ransom price of decryption after a deadline of five days. The malware can encrypt text, image, data, web, database, video, web, backup, and other file formats. Once done, it deletes traces of itself from the machine and leaves only the .ZIP file in the temporary Internet files and some HTML warnings. Since the business owner did not engage with the cybercriminal, the company lost thousands of valuable files, including business-related databases.

Sunday, August 2, 2015

The World this week..(Week of July 27th)

1.       Android phones can be hacked with a text, over 1 Billion devices at risk. A Critical flaw resides in the 'Stagefright' component of Android OS, which is used by  Android to process, record and play multimedia files. To improve user experience any video file that is received by the OS is automatically downloaded and kept ready for play back to the user, this feature makes this vulnerability even more dangerous as hackers can hack any Android device without depending on any action on part of the user. They have to just send a text and hack the device. Researchers have discovered a method of hosting this exploit on a webpage and infecting the visitors. Google has delivered a patch for Stagefright attack but given the shaky history of handset manufacturers and carriers rolling out security patches, it is not known how long the companies will take to update vulnerable Android devices. Till then, the users can protect themselves by turning off MMS auto-retrieval and using 3rd party patched apps to view MMS.

2.       Update on Auto hack - Chrysler has recalled 1.4 Million jeeps to fix the software issues, the company is being criticized for providing an option to send USB sticks to customers that will fix the issue. There is always a possibility of customer not doing it the right way or the sticks getting infected with new bugs during transit by malicious actors. Another Security researcher revealed a kit last week that makes it possible to track, remotely unlock and start the engine of GM vehicles that run the OnStar connected car system. He calls his kit - OwnStar.

3.       Massachusetts General Hospital recently notified 648 patients that their names, lab results and Social Security numbers may have been exposed in May 2015 when an  employee sent an email containing the data to the wrong email address by mistake. To help prevent this from happening again, the hospital will need to update their processes, re-educate their workforce and invest in a world class Data Theft Prevention technology.

4.       Last week witnessed Windows 10 being released, followed by overblown FUD reports of Wi-Fi Sense being a potential security concern and finally the week ended with reports that Wi-Fi Sense not being a security risk. The option to allow Internet sharing is enabled by default but only for networks that the user chooses (like Outlook contacts, Skype contacts, Facebook friends). If any one of these networks are selected then the Wi-Fi Sense only shares Internet access. It doesn't allow any access to local resources or personal files.

5.       Hackers and malicious actors are increasingly targeting online ad networks as a means to infect users, more than half of these "malvertising" (Malware + Advertising) attacks originate from news and entertainment sites that inadvertently display infected online ads. Attackers buy ads from online advertising companies and insert Exploit Kits in these ads, which in turn help the hackers profile the victim’s machine and launch the malware payload (Dropper file). The hosting websites cannot be blamed completely as Ads are their key revenue model and it is impossible for them to check all the ads, though they try to limit third party code running on their sites.

6.       "National defense is too important to leave to the military", is a famous quote - this also applies to Cybersecurity. The IT team manages data on the frontlines but the impact of a data theft is very severe most of the times and it is advisable for the Board to get involved from the scratch. For many in the Board, cybersecurity is very formidable and the best way to overcome is by investing in a "Right Cybersecurity partner".

7.       White hat hackers are usually rejected and sometimes even threatened by Indian firms, this is now gradually changing. After the recent hacks of Ola cabs, Zomato and Ganna.com, where hackers publicly pointed to flaws, some Indian firms are finally following in the footsteps of US bigges by allowing ethical hackers to test their security systems for bugs. At stake are cash rewards and career boosts. Ola now pays minimum of  ₹ 1000 for bugs with no upper limit for complex bugs, Indians identified the largest number of valid bugs in the last two years for Facebook, which paid an average of $1343 per bug in 2014.

8.       Indian companies are increasingly suffering huge losses due to rising cyber-attacks that leads to interruption of business and loss of customer data. However, with only 100-150 policies covering 'cybercrime liability insurance' being sold in the country, majority companies are inadequately protected against the growing menace. A typical cybercrime policy can take care of monetary loss arising out of the loss of financial data, hacking leading to business interruption, loss of customer data, bank data and patient data. BPOs and the software companies are the top buyers and mostly at the insistence of their foreign clients.


9.       On the dark web’s marketplaces, the full set of someone’s personal information—identification number, address, birthdate, etc.—are known as “Fullz.” Each Fullz has a market price ranging from $1 to $450, The median price for someone’s identity is $21.35. Fullz are generally used to make fraudulent Credit card transactions, Online transfers, Phone banking, Fake insurance claims, etc. The below screen shot is from the Dark web:

Sunday, July 26, 2015

The World this week..(Week of July 20th)

1.       "Life is short. Have an affair."- is the slogan of Ashley Madison, a Canadian-based online dating service marketed to people who are married or in a committed relationship. It has over 37 Million registered users and over 124 Million visits per month. Last week this website was hacked by a group called Impact team. The hackers are blackmailing the company to shut down all its services failing which they will publish the user information online, which includes Names and personal profile details.

2.       The website requires registered members to pay every time they want to start an conversation with other members and the chat sessions are also metered. The users who wish to delete their profiles including historical data need to pay $19. The hackers have claimed that the website collects the deletion fee but never deletes the full profile and maintains some basic records of users, they have cited this as the reason for the hack. In light of the hack, the company is now offering full-delete option free to any member.

3.       What could be worse than publishing user name online is that hackers may sell the stolen data to highest bidders on the Dark Web. These bidders may use the data and blackmail individual users for commercial exploitation or other favors. Ashley Madision's public listing plan in the London stock Exchange to raise $200Million - now looks unlikely, according to bankers cited by CNBC.

4.       Hackers can take over your Jeep, literally driving you off the road. This was demonstrated last week by cyber security experts, when two of them remotely hacked into a running Jeep Cherokee being driven by the third expert on a busy highway. The root of the attack was a vulnerability in the Uconnect system, a software-based connected car system for a number of Fiat Chrysler cars. The vulnerability allowed these researchers to remotely control the vehicle through its IP address, such as turning on and off the brakes, interfering with the driver's visibility by switching on the windshield wipers, and shutting off the engine. Chrysler has recalled 1.4M Vehicles for Bug Fix while the researchers released a video of their demo.

5.       Cylance, the first predictive cyber security company that applies artificial intelligence to stop malware, and Raytheon|Websense, last week, announced a partnership that extends Cylance's next-generation security technology to Raytheon|Websense customers. Raytheon|Websense has embedded Cylance Infinity Engine, a next-generation malware detection technology engine, into its SureView Threat Protection solution.

6.       Hacking team news - A Researcher has lashed out at Hacking Team after discovering his codes have been used (without notice or permission by Hacking Team), as a springboard in the development of Android surveillance tools sold to governments and law enforcement agencies. In South Korea, the revelation that their National Intelligence Service (NIS) was a hacking team customer, has been politically explosive. An Intelligence officer who used this software was found dead over last weekend in an apparent suicide as controversy swirls in the country over use of the software.

7.       An IT security drill went off the tracks in Belgium. The govt. wanted to train its employees against phishing attacks and hence setup a fake spam email confirming the employee's travel to Paris and stay in a fancy hotel. Those who choose to cancel the trip were supposed to reply to the said email within 3 days along with their credit card number. Instead the worried employees called the train company to complain, overwhelming the bewildered staff . The govt. apologized  to the train company for not keeping them informed and “being a bit overzealous.”

8.       According to Global CEO Outlook 2015 by KPMG - Half of the CEOs are not fully prepared for a cyber-event. Yet, cyber security was named by 20 percent of respondents as one of the top five risks—right behind the related issues of third party and supply chain risks. For technology firms, information security edged out all other risks as the most pressing threat. Most of them also believe that Cyber security risk is the most unpredictable one.

And finally the Indian connection to Ashley Madison - of the 37Million global users, 2.7 Lakh users are from India and now may stand to be exposed:

Sunday, July 19, 2015

The World this week..(Week of July 13th)

1. Hacking team released a press statement stating that the recent hack and leak of information is now "obsolete because of universal ability to detect these system elements." The statement went on read that there will be version 10 of Hacking Team's Remote Control System, calling it "a total replacement for the existing ‘Galileo’ system, not simply an update." Six former employees of the surveillance software maker are reportedly under investigation for the breach that led to the company's corporate secrets leaking online.

2. A former intern at FireEye has been arrested for creating and selling the slick and sophisticated Dendroid malware program after being caught in a global police sting that destroyed the Darkode cybercrime forum. Prosecutors say that he was most recently working as a whitehat anti-malware professional at the company while also building and selling Dendroid, a product which the company would label its chief enemy. The alleged hacker sold the toolkit for $300 and its source code for $65k on the Darkode forum. He was arrested in the global sting along with a total of 70 administrators and members.

3. A vulnerability researcher (read hacker) from Florida, was the first recipient of United Airline’s highest-level reward in its bug bounty program, reserved for remote  code execution (RCE) vulnerabilities in its web properties. He was rewarded 1 Million Air miles.

4. Lots of excitement building up about the upcoming security conferences – BlackHat and Defcon. Both events are planned in Las Vegas in August. Black Hat Set to Expose More Than 30 Zero-Day Flaws while the Defcon consists of several tracks of speakers about computer- and cracking-related subjects, as well as social events and contests.

5. In the past, phishing campaigns were less believable, like - You may have won a lottery or you may have a undelivered parcel. However, phishing can now be very complex, well-engineered and professionally crafted, which makes them far more difficult to detect. One of ways to beat this is by training staff to detect a phishing email. Staff can be periodically sent benign phishing emails and armed with reports - as to who opened, who clicked the links in those emails etc - staff can be (re)trained.

6. A browser called the TOR (The Onion Router) delivers untraceable access to the Internet by linking all the computers onto a network. By routing connections through a chain of users, the IP address of the user is kept hidden. India is estimated to have between 500,000 to 1 million daily users of this browser. Tor's use is intended to protect the personal privacy of users, as well as their freedom and ability to conduct confidential communication by keeping their Internet activities from being monitored. However, it is widely used for unscrupulous and illegal activities like drugs, weapons, counterfeit currency, forged documents and other illicit and legal goods.

7. The website of Antrix, Indian Space Research Organization’s commercial arm, was hacked last week. The URL antrix.gov.in led to a web page to buy sports merchandise and is believed to be the handiwork of Chinese hackers. This comes two days after ISRO launched five British satellites from its Polar Satellite Launch Vehicle, its heaviest commercial launch, from Andhra Pradesh, India.


Sunday, July 12, 2015

The World this week..(Week of July 6th)

1.       The irony of Hacking Team—an Italian company that sells surveillance software being hacked last weekend, is interesting, especially given Hacking Team’s denials it  sold to governments with notorious human rights records. Hacking Team still insists it broke no laws and has behaved ethically. Whether Hacking Team survives remains  to be seen, as of now the company has asked its clients to stop using its software for the time being and to cease operations, but when you consider the kinds of clients -- from law enforcement to government agencies and intelligence units - you have to ask whether Hacking Team has enough of a reputation left to restore client trust.

2.       WikiLeaks has released 440-GB of data stolen from Hacking team, Email exchanges indicate that top Indian security agencies were secretly negotiating with the surveillance firm to procure software for intercepting communications through remote bugging of devices. RAW, IB, NIA and NTRO did attend a PoC, the WB and Maharashtra govts., were in touch with the company. The Hacking Team was mostly interested in pushing its flagship product Galileo, a platform-independent undetectable Remote Control System, that takes control of targeted devices and monitor them regardless of encryption and mobility.

3.       Cybercriminals start using Flash zero-day exploit leaked from Hacking Team - It took just a day for cybercriminals to start using a new and yet-to-be-patched Flash Player exploit. The exploit was found among the stolen files. Adobe Systems confirmed the vulnerability, which received the identifier CVE-2015-5119, and is planning to release a patch for it. According to a researcher, the leaked Hacking Team exploit has already been integrated into three commercial exploit kits: Angler, Neutrino and Nuclear Pack.

4.       OPM has been hit by a second breach, leading to the theft of more than 21 million individuals' records. The figure confirmed Thursday by OPM is in addition to the previous breach, and the total figure now stands at almost 26 million individuals affected by the two breaches. The two attacks are separate, but related. It has been reported that OPM's director had no technology, cybersecurity or crisis management experience -- she quit last week.

5.       US presidential candidate Hillary Clinton has accused China of "trying to hack into everything that doesn't move in America" and stealing government information, in strongly worded comments likely to irk Beijing. Clinton, a former secretary of state, pulled no punches in remarks to Democratic supporters at a campaign event in New Hampshire.

6.       In other news, The hackers that targeted Twitter, Facebook, Apple and Microsoft developers two years ago have escalated their economic espionage efforts as they seek confidential business information and intellectual property they can profit from. The hacking group, motivated by financial gain, is thought to target companies on request, and "ought to be taken seriously by corporations," said an expert.


7.       Within a week of CEO Rahul Yadav's controversial exit from Housing.com, the online realty startup's website was allegedly hacked by an anonymous group, which put up a cheeky message demanding his reinstatement. Nobody claimed responsibility for the hack, though social media was rife with rumours that Yadav might have been behind it. But on his Facebook page, the founder and ex-CEO of Housing.com was quick to dissociate himself from the attack. "I would have designed it better," he wrote.

Sunday, July 5, 2015

The World this week..(Week of June 29th)



1.       Pitching India as the world's destination for the next big idea, Prime Minister Narendra Modi on Wednesday, launched his ambitious Digital India project. The project aims to create a digitally empowered society and knowledge economy. He also spoke of the role of Digital India in a world where cyber security is becoming increasingly important. "Everyone is worried about cyber security and cyber warfare. India should work towards giving the world a shield from the threat of cyber warfare," he said. "I dream of a Digital India where cyber security becomes an integral part of national security," he added.
2.       Maharashtra government ropes in PwC, to prepare an exclusive cyber security plan for the state. Once the plan is ready, the department aims at training at least 1,000 police personnel to crack cases of cybercrime.
3.       A data breach at Harvard University has exposed system and email passwords belonging to an unspecified number of faculty, staff, and students from numerous schools and at least one major administrative network at the university. Harvard discovered the intrusion on June 19 but publicly disclosed it only Thursday while it worked to mitigate the issue. A statement disclosing the breach said Harvard discovered an intrusion into the Faculty of Arts and Sciences (FAS) network and another one at the university Central Administration network.
4.       Trump Hotel Properties, has confirmed that it is investigating reports that it suffered a data breach, leading to the theft and fraudulent use of its customers' payment card data. The company's executive vice president of development and acquisitions, Eric Trump - son of Donald Trump- on July 1 confirmed the breach investigation in a statement.
5.       An overwhelming majority of Infosec professionals (92%) said they have lost confidence in the ability of traditional endpoint protection solutions, such as antivirus and white listing, to detect unknown threats like zero-day attacks. Additionally, 78 % believe antivirus is not effective against general cyber-attacks. Not so long ago in May 2014, Symantec's SVP went on record to say that "AV is dead" and he had estimated that AV can stop only about 45% of cyber-attacks.
6.       Another big news on insider threat - 2 brothers working as contractors with the US govt., have admitted during a Friday hearing that they infiltrated the department’s networks in order to pilfer passport and visa information. Allegedly, the brothers were attempting to create and sell fake passports and visas on the black market. They face up-to 50 years in prison and both will be sentenced in September.
7.       A woman in the UK has been scammed out of her life savings through a simple phishing email orchestrated by cyber criminals. She was in the middle of buying a house when she received an email claiming that she needed to transfer her deposit of nearly £50,000 ($78,000), which she did. Little did she know her email account had been hacked and was being monitored by cyber criminals. The hackers setup an account in the name of her Lawyer and the email was crafted with similar language used by the lawyer in the previous legitimate emails.
8.       One of the biggest threats that employees need to be made aware of is phishing. Today's cyber criminals use highly sophisticated social engineering tactics, which can make phishing attempts hard to spot, especially for the untrained. The best way to begin combatting this threat is to run mock phishing attacks. This way you can get an insight into how security savvy your workforce is, and then take steps to address any issues.
A day after Prime Minister Narendra Modi launched Digital India week to reform government through technology, the official website of National Institute of Technology was hacked and defaced by Pakistan cyber hacker on Thursday.

9.