Monday, May 16, 2016

Issue 64 - Week of May 9th

1.       Tumblr discloses email security breach: Hackers obtained access to a set of Tumblr user email addresses with salted and hashed passwords from early 2013, the Yahoo-owned microblogging site Tumblr announced last week. Tumblr staff confirmed in a blog they believe that this information was not used to access Tumblr accounts but as a precaution the affected users will be required to set a new password.

2.       4 data breaches reported last week: (i) Kiddicare, company that sells child toys and accessories across the United Kingdom was hacked and 794,000 Accounts Leaked. (ii) UserVoice, a web-based service that offers customer service and helpdesk tools, notified that the company suffered a data breach and some user accounts were compromised, including their names, email addresses, and passwords. (iii) Google suffered a minor data breach after a vendor unintentionally leaked sensitive information about its undisclosed number of employees to the wrong email address — but luckily, the person who received it deleted the email straight away. (iv) A fine of about $260,000 was imposed on a London-based HIV clinic, for leaking data of 781 HIV patients.

3.       InvestBank UAE breached: Close on the heels of the Qatar National Bank leak - a 10 gigabyte file holding sensitive financial data compromised from an InvestBank in the United Arab Emirates (UAE) has been leaked online. The file contains information on tens of thousands of customers from a bank based in Sharjah. The dump appears to contain payment card data, as well as a large number of sensitive, internal files relating to the bank's employees and systems.

4.       Commercial Bank of Ceylon hacked?: Commercial Bank of Ceylon, based in Colombo, Sri Lanka, has apparently been hacked, with its data posted online last week by the Bozkurtlar hacking group, which has also posted five other data dumps from banks including The Dutch Bangla Bank (Bangladesh), The City Bank (Bangladesh), Trust Bank (Bangladesh), Business Universal Development Bank (Nepal) and Sanima Bank (Nepal).

5.       'Pawn Storm' APT campaign rolls on with attacks in Germany, Turkey: A sophisticated group of hackers called 'Pawn Storm' setup a fake webmail server designed to look like a German Political party's webmail server in an apparent attempt to steal the email credentials of party members. They also targeted the personal emails credentials of these party members. In a similar attack - Turkish prime minister, members of the country’s parliament and Turkey’s largest newspapers were targeted.  Based on the profile of the Pawn Storm's victims, it is suggested that the group is based out of Russia.

6.       OkCupid user account data released: OkCupid is an American-based international operating free online dating, friendship, and social networking website. Sensitive data like usernames, sexual preferences, orientation and more, belonging to almost 70,000 users has been released online by researchers. Last year, another online dating service -  Ashley Madison suffered a breach.

7.       Pornhub launches Bug Bounty program; offering reward up to $25,000: With the growing number of cyber-attacks and data breaches, a significant number of companies and organizations have started Bug Bounty Programs to encourage hackers and security researchers to find and responsibly report bugs in their services and get a reward. Now, even pornography sites are starting to embrace bug bounty practices in order to safeguard its user's security. Pornhub has partnered with HackeOne - a bug bounty startup that operates bug bounty programs for companies.

8.       10-year-old boy becomes the youngest Bug Bounty hacker: 10-year-old Finnish boy - Jani from Helsinki, recently reported an Instagram bug to Facebook that allowed him to delete other Instagram users' comments just by entering a malicious code into the app's comment field. Jani was rewarded $10K, he said he will use the money to buy a football and a new bicycle. He has been learning about hacking and programming from instructional videos on YouTube. His dream job is to become an information security expert.

9.       Sony 2014 breach linked to $81m Bangladesh Bank cyber heist: After SWIFT announced that a second unnamed banking customer had been hit with malware similar to that of the Bangladesh heist  - a security firm has published an analysis linking the tools used in both these attacks to the 2014 attack on Sony Pictures.  While North Korean hackers are believed to be behind the Sony breach the recent attack on banks is suspected to be the handiwork of North Korea and Pakistani hackers.


10.   Mozilla asks court to disclose firefox exploit used by FBI to hack Tor users: Mozilla has filed a brief with a U.S. District Court asking the FBI to disclose the potential vulnerabilities in its Firefox browser that the agency exploited to unmask TOR users in a criminal investigation. Last year, the FBI used a zero-day flaw to hack Tor browser and de-anonymize users visiting child sex websites.



Sunday, May 8, 2016

Issue 63 - Week of May 2nd


1.       BEC hack scams company of $495,000: An investment company - Pomeroy Investment Corp - was recently robbed of $495,000 through a common email fraud method where the hacker, posing as a co-worker, had the funds transferred to his account. A staff received an email from another "employee" of the company asking for transfer of funds into a Hong Kong bank. The so-called email appeared genuine to the recipient, who had the money transferred. It was few days later the company realized they had been cheated via what is known as a business email compromise (BEC). Police received a complaint about the incident and have cautioned against transfer of any amount of money based on emails and advised verifying messages before making any money transactions.

2.       Another Ransomware victim: Michigan Public Utility is currently cleaning up its administrative systems after an undisclosed number of computers were infected with ransomware. The agency has stressed that the cyber incident "should have no impact on the delivery of water and electricity to its customers". In February, a ransomware attack shut down medical record systems at a LA Hospital and the hospital paid $17,000 in Ransom to the criminals.

3.       Wendy's hit with lawsuit over data breach: A class action lawsuit has been filed against Wendy’s for alleged negligence in securing its computer systems and customer data. According to the filing, Wendy’s did not update its computer system when required, thus making it susceptible to hacks. Confidential details of millions of customer credit cards were possibly leaked from various Wendy’s locations. The lawsuit accused Wendy’s of using outdated credit card systems that do not comply with federal guidelines, and for holding card details for too long.

4.       For sale - 272 million email passwords for just $1: A massive database of emails and passwords for popular email services, including Gmail, Microsoft, and Yahoo, are being offered for sale on the Dark Web for $1. An anonymous Russian hacker, who goes by the moniker "the Collector," was first spotted advertising 1.17 Billion user records for email accounts on a dark web forum. A large number of those 1.17 Billion accounts credentials turned out to be duplicate and that 272 Million records were unique. In an unrelated but similar incident - it was revealed last week that a database containing the details of over 57 million email accounts was put up for sale on the dark web.

5.       ImageMagick tool vulnerable to remote code execution: ImageMagick is an open-source image processing library that lets users resize, scale, crop, watermarking and tweak images. A serious zero-day vulnerability has been discovered in ImageMagick, which could allow hackers to execute malicious code remotely on servers by uploading a maliciously-crafted image. The vulnerability will be patched in next versions, which are due to be released by this weekend.

6.       ADP data used in US bank employee W-2 breach: ADP is a payroll processing provider, thieves used unregistered employee accounts to create fake accounts and siphon W-2 information from the ADP portal. This leaves the victims exposed to the risk of tax returns being filed fraudulently in their names. Mattel, Snapchat, Seagate, Polycom have all been recently lost W-2 data.

7.       2016 Global threat report: INSIDER THREAT- THE MALICIOUS AND THE ACCIDENTAL: Insider threats refer to attacks that either originate or receive cooperation from sources within an organization. Attackers are targeting insiders within organizations – or via business partners and third party suppliers – and gaining access to networks by manipulating staff into revealing their credentials. With these stolen credentials, criminals move among networks, accessing and stealing sensitive data, often going unnoticed until it’s too late. Industry measures the time that attackers spends in the network as Dwell time - which begins when an attacker enters a network and continues until they leave or are forced out. Minimizing dwell time reduces the opportunity for an attacker to achieve lateral movement and steal data.

8.       Russian hacker who stole from banks ordered to pay $7 million: A Russian man who spent about 3 years behind bars in the United States has been spared further prison time due to his "substantial assistance" in the investigation but ordered to pay $7 Million to cover damages he caused to banks for using Gozi - a vicious computer virus. The hacker used to rent the Gozi malware out for $500 a week to cyber criminals who in turn, used the malware to steal money from bank accounts, he also would control all compromised computers remotely as Botnet to steal data and access banks accounts.

9.       High-severity openSSL vulnerability allows hackers to decrypt HTTPS traffic: OpenSSL has released a series of patches against six vulnerabilities, including a pair of high-severity flaws that could allow attackers to execute malicious code on a web server as well as decrypt HTTPS traffic. One of the high-severity flaws, allows a man-in-the-middle attacker to initiate a "Padding Oracle Attack" that can decrypt HTTPS traffic if the connection uses AES-CBC cipher. The other high-severity bug, is a memory corruption flaw in the OpenSSL.


10.   IRCTC denies hack, says committee is examining alleged data theft: IRCTC has a total user-base of 39 million, and sells 500,000 railway tickets every month. Last week, cyber cell found a CD containing 15K IRCTC data records in the market for sale. This led to wide spread speculation that IRCTC was hacked. IRCTC has denied the hack, but has formed a team to investigate the data theft.

Monday, May 2, 2016

Issue 62 - Week of April 25th


1.       Qatar National Bank Probes Possible Data Breach: Qatar National Bank is probing reports of an online leak of confidential data of a large number of its customers, but has not confirmed it suffered a data breach. The details leaked include names, passwords, and banking information of several journalists, ruling family, government and defense officials. Some 1.5GB of information was found online and Reuters reports seeing recent transactions of overseas remittances. The bank is one of the largest in the Middle East.

2.       German Nuclear Power Plant Infected With Malware: A German nuclear power plant near Munich reportedly was found infected with malware, It has confirmed that since the plant is cut off from Internet, the malware infection did not affect or harm operations. Conficker and W32.Ramnit malware were discovered in unit B of the Gundremmingen plant on the computer system that operates the tools that move nuclear fuel rods. Conficker is a worm that can spread quickly through networks, while W32.Ramnit steals files from computers and is spread through USB sticks.

3.       Spotify Hacked! Change your Password ASAP: If you are one of the millions of people around the world who love to listen to music on Spotify, you may need to change your password immediately. Spotify apparently suffered a security breach that leaked hundreds of Spotify accounts details, including emails, usernames, passwords and account type, which was published last week to the popular anonymous file sharing website Pastebin. Spotify is investigating.  Couple of months ago, hundreds of spotify premium accounts were exposed online.

4.       Nearly 93.4 Million Mexican Voter Data Leaked Online: A hacker discovered over 100 gigabytes of an extensive database completely open on the Internet for anyone to download while the hacker was browsing Shodan – a search engine for servers and Internet-connected devices. The database turned out to be a voter registration database for the country of Mexico that contained the personal information, including full names, residential addresses, and national identification numbers, of virtually all registered voters.  Philippines and Turkey too suffer similar hacks.

5.       DDoS Extortionists made $100,000 without Launching a Single Attack: Cyber crooks find a new and ingenious way to make hundreds of thousands of dollars with no effort.  An unknown cyber gang, pretending to be Armada Collective, has made more than $100,000 in less than two months simply by threatening to launch DDoS attack on websites, but never actually launched a single attack. Armada Collective is the criminal gang that was responsible for one of largest DDoS attacks against ProtonMail in November 2015 and extorted $6,000 to stop sustained DDoS attack that had knocked its service offline.

6.       Details emerge on the Bangladesh Heist: Investigators discovered that hackers who stole $81 million from the Bangladesh Central Bank actually hacked into software from SWIFT financial platform, a key part of the global financial system. The hackers used a custom-made malware to hide evidence and go undetected by erasing records of illicit transfers with the help of compromised SWIFT system. Recently, Bangladesh police investigators uncovered evidence revealing that the Bank was using second-hand $10 network switches without a Firewall to run its network, which offered hackers access to the bank’s entire infrastructure, including the SWIFT servers.

7.       Former Tor Developer Created Malware for FBI to Unmask Tor Users: Tor is an anonymity software used by millions of people, including government officials, human rights activists, journalists and, of course, criminals around the world to keep their identity hidden while surfing the Internet. According to an investigation, a cyber-security expert and former employee of the Tor Project, helped the FBI with Cornhusker a.k.a Torsploit malware that allowed Feds to hack and unmask Tor users in several high-profile cases, including Operation Torpedo and Silk Road.

8.       MIT University Launches Bug Bounty Program: The Massachusetts Institute of Technology (MIT) launches its experimental bug bounty program this week, which aims at encouraging university students and security enthusiasts to find and responsibly report vulnerabilities in its official websites. The MIT becomes the first academic institution to reward hackers, open only for university affiliates with valid certifications.  Other recent Bug bounty programs – Uber, General Motors, Pentagon.

9.       Irremovable Android malware poses as Google Chrome update: A banking and personal information stealing mobile malware posing as a Google Chrome update for Android, and which can't be removed from the infected device, has been spotted in the wild by cybersecurity researchers. The malware is capable of harvesting banking information, call logs, SMS data and browser history which are all sent to a remote command-and-control server. The Malware can't be removed as it refuses to allow the user to remove administrative access. The only way to remove the infection is to return the device to factory settings - an option which causes all data stored on the phone to be lost.

Bank of Baroda hacked: Hackers infiltrated the bank and started carrying out transactions through debit cards of BoB customers. One time passwords were not generated or needed for such fraudulent transactions. 70 customers’ accounts were affected and a loss of over ₹ 1Million reported.


Monday, April 25, 2016

Issue 61 - Week of April 18th


1.       Singapore penalizes firms for data breaches: Several organizations in Singapore have been fined and issued warnings for breaching the country's Personal Data Protection Act (PDPA), including local IT retail chain Challenger Technologies and Chinese handset maker Xiaomi. The Act does not apply to public sector or Govt. K Box entertainment had suffered a breach in 2014 but till date - failed to put in place adequate data protection policies and security safeguards - they were fined S$50,000. The Institution of Engineers in Singapore as well as Fei Fah Medical Manufacturing were fined S$10,000 and S$5,000, respectively, for their failure to implement sufficient security measures to safeguard the data of their members and customers.

2.       Creepy new ransomware uses image from popular horror film: Another ransomware has entered circulation.  Known as  BitcoinBlackmailer.exe or JIGSAW. This malicious program starts encrypting your files while adding, with no irony, the '.FUN' file extension. It also threatens to start deleting files if the ransom is not paid within an allotted time, complete with countdown timer. To add to the distress of the victim, the ransomware displays the face of the character Billy the Puppet from the horror movie series Saw (see image below). Forcepoint Security Labs was able to reverse engineer and retrieve the encryption key. This malware can be detected and blocked by web security solutions like Forcepoint using the ACE technology.

3.       Samsam server-side ransomware targets schools, hospitals: A new ransomware program called Samsam- uses vulnerabilities in the JBoss application server to infect networks, with attackers focusing on health care organizations and schools. Samsam and another recent ransomware program known as Maktub do not require a connection to a command-and-control server to encrypt data on a targeted system.

4.       Security expert builds ransomware blocker for Mac: An expert has built an utility that scans for untrusted processes that are encrypting personal files, and stops them dead. The utility is called "RansomWhere?". False positives are kept to a minimum because ‘RansomWhere?’ explicitly trusts binaries signed by Apple. It also trusts applications that are already present on the system when it is installed. This is a double-edged feature - on the one hand it helps reduce false positives, but on the other hand if ransomware is already present on the system before RansomWhere? is installed, it may not be detected.

5.       Python-Based Malware Infects European Companies: IT security researchers have discovered an unusual family of malicious code written entirely in the Python programming language, making it easy to port to different operating systems. The malware uses a modular design that allows it to carry out a selection of different attacks, including executing files, logging keystrokes, mining bitcoins, executing arbitrary Python code and communicating with a remote server. The malware has targeted a number of European organizations, particularly in Poland, the targets include a national research institution, a shipping company, a large retailer and an IT organization, as well as a construction company in Denmark and an optical equipment provider in France.

6.       Manufacturers suffer increase in cyber-attacks: The manufacturing sector is now one of the most frequently hacked industries, second only to healthcare, financial services has dropped to third place. Many manufacturing companies are behind the curve in security because they have not been held to compliance standards like the financial services has. Manufacturers also appear to be vulnerable to older attacks, such as Heartbleed and Shellshock & SQL injection. Industrial control systems also pose a challenge to manufactures as most of them use decade old OS. Recommended Defensive Strategies are - Annual IT risk assessment, Annual penetration tests, Conduct ongoing vulnerability scanning.

7.       Apple v/s FBI: In the New York drug dealer iPhone case, Justice Dept. finds way into locked phone and hence drops demand for Apple's help. In this case, no hacks needed, after someone provided the passcode to unlock the device, according to the prosecutor. In the other case, FBI director hinted that the agency spent more than $1.3M to hack into the terrorist's iPhone.

8.       Hackers can spy on your calls and track location, using just your phone number: The famous ‘60 Minutes’ television show shocked some viewers Sunday evening when a team of German hackers demonstrated how they spied on an iPhone used by U.S. Congressman, then recorded his phone calls and tracked his movement through Los Angeles. Hackers leverage a security flaw in SS7 (Signalling System Seven) protocol that allows hackers to track phone locations, listen in on calls and text messages. The weakness affects all phones, whether it's iOS, Android, or whatever, and is a major security issue. The network operators are unwilling or unable to patch the hole, there is little the smartphone users can do.

9.       Long arm of law catches up: Two International hackers, have been sentenced to 24 years and 6 months in prison for their roles in developing and distributing SpyEye banking Trojan, a powerful botnet similar to the infamous ZeuS malware. Both hackers were charged with stealing hundreds of millions of dollars from banking institutions worldwide. In a different case - A Former Reuters journalist, who was convicted last year of helping the Anonymous group of hackers, has been sentenced to 24 months in prison for computer hacking charges. He was found guilty of giving login credentials to Anonymous, using which the group defaced the Los Angeles Times.

10.   Don't fool around with politicians esp. Lalu: An Indian engineering student, who was arrested last week for hacking into and posting objectionable content on Lalu Prasad’s Facebook page, was expelled from his college. He is a third year student at a local engineering college in Bihar. The cyber cell arrested the student and seized two mobile phones and a SIM card which he allegedly used.


Billy the Puppet from the horror movie series Saw:

Sunday, April 17, 2016

Issue 60 - Week of April 11th

1.       FDIC suffers data breach: Federal Deposit Insurance Corporation (FDIC) provides deposit insurance to depositors in US banks, it suffered a major data breach- exposing  the records of 44,000 customers. A former employee - who had legitimate access to the data - downloaded the data to a personal device and left the corporation with the data. An FDIC spokeswoman confirmed that the former employee has signed an affidavit specifying no breached information was used in any form. This growing threat from Insiders is a big worry for all CIOs whose companies handle sensitive data.

2.       Hybrid GozNym malware targets customers of 24 financial institutions: A group of cybercriminals have combined two powerful malware programs (Gozi ISFB Malware + Nymaim malware), to create a new online banking Trojan (GozNym) that has already stolen millions of dollars from customers of 24 U.S. and Canadian banks. Nymaim is a dropper file that uses a DLL of Gozi- which is capable of injecting malicious code into Web browsing sessions. Together they are used to steal credentials and perform online banking fraud.

3.       Cybercriminals now target tier-2 systems: With Tier 1 systems like retail banking becoming more secure, the Cybercriminals targeting Australia are shifting their focus to other targets where money is held and security is poor, such as payroll, invoicing, and superannuation systems. The criminals log in to these systems using stolen credentials, check the date of the next pay run, and log out. They log back in just before the pay run, change employees' bank details to their own or to accounts that they control and let the payroll run proceed.

4.       Are you using Apple iPad? if yes- upgrade to iOS 9.3.1 immediately: iOS versions pervious to this are vulnerable to 1/1/1970 bug attack. If the iPad is in untrusted Wi-Fi network with a spoofed NTP server that sets the date as 1/1/1970, then the iPad's software becomes unstable and causes overheating and permanently damages the device. Fortunately this cannot happen to iPhone, as the phone depends on GSM network for its date and time.

5.       Are you using QuickTime for Windows? if yes- uninstall it now: Two reasons why you should do it - (i) Apple has abandoned QuickTime for Windows and it will not deliver security updates. (ii) There are two known critical vulnerabilities that could allow an attacker to take control of a system running QuickTime.

6.       Apple v/s FBI: After getting a third party to hack the shooter's iPhone – Sources have confirmed that nothing useful was found on it. In the drug dealer iPhone case, Apple resists FBI’s call to unlock the iPhone. Apple told a federal court last week that it should not be asked to help the FBI unlock the iPhone used by the drug dealer and that the case would lead to "an avalanche" of similar demands if prosecutors prevailed.

7.       FBI Director puts tape over his webcam: The director admitted that he has put a piece of tape over his personal laptop's webcam. On one hand he says 'absolute privacy hampers the law enforcement' but on the contrary, he is doing exactly the same with his personal webcam. However, tape on webcam cannot stop hackers or government spying agencies from recording your voice. FBI in the past has used malware to hack into cameras to spy on targets.

8.       Petya ransomware cracked: In issue 58, we spoke about this new ransomware that encrypts the whole hard drive. A researcher discovered a weakness in the nasty malware's design. To crack the malware - victims need to run a tool that extracts specific data from the infected hard drive and upload it to the researchers password generator tool - which will generate the decryption key for free. This is a great solution to decrypt the infected files, but most likely, the Petya authors have already heard about this tool and are modifying their code to disable the solution. So, there is no guarantee the tool will continue to work indefinitely. Regular backups and good web security solution are the best bets against ransomware.

9.       Cox investigates as employee data appears for sale on the dark web: Names, email addresses, phone numbers, and other information relating to some 40,000 Cox Communications employees is currently advertised on a marketplace specializing in stolen data and computer exploits. Cox is aware of this matter and have engaged a third-party forensic team to conduct a comprehensive investigation and are actively working with law enforcement.


10.   Online banking and plastic card-related fraud in India increases: The incidence of ATM, credit, debit card and net banking-related fraud has gone up by more than 35 percent between 2012-13 and 2015-16 in India, according to Reserve Bank of India. 11,997 cases have been booked in the first nine months of 2015-16. In Mumbai alone the credit card fraud rises 151% and it makes up 55% of cyber-crimes this year.

Sunday, April 10, 2016

Issue 59 - Week of April 4th


1.       'Panama Papers' Law Firm was hacked: In the latest twist in the historic "Panama Papers" data leak and scandal, the founding partner of the law firm whose files were dumped, exposing illicit offshore holdings of global political leaders, celebrities, and others, says his firm was hacked by an outsider. The law firm 'Mossack Fonseca' has two main websites, one runs on WordPress and the customer portal runs Drupal. Both of those sites were running outdated versions of the software and in both cases significant security holes existed that would have allowed hackers access.

2.       Heartbleed remains a risk 2 years after it was reported: On April 7, 2014, Heartbleed was publicly disclosed by the OpenSSL project, affecting millions of users and devices around the world. It was used by hackers to attack several corporates, government agencies like Canada's Revenue Agency (CRA) and some of the largest banks in US. Two years after it was first reported, the vulnerability remains a risk and is likely still being exploited by attackers taking advantage of unpatched servers. Most of the organizations that are still at risk because they don't know what their third-party vendors are implementing in products that they run on their network.

3.       Trump hotel chain suffers fresh data breach: Republican candidate Donald Trump's hotel chain, The Trump Hotel Collection, has become the victim of a credit card system data breach for the second time in only a year. Experts have spotted a "pattern of fraud" relating to customer credit cards, which implies the Trump Hotel Collection may once again be harboring malware on point-of-sale (PoS) systems within some hotels, or potentially all of them. In January - Hyatt Hotels had admitted that 250 hotels in 54 countries were affected by a cyber-attack which targeted customer financial information.

4.       FBI says it can unlock 5c but not 5s or later phones: The Apple V/s FBI case did not prolong as a third party helped FBI unlock the 5c iPhone. The director confirmed that they now have a tool that works on a narrow slice of phones. However, the agency could not unlock an iPhone 5s running iOS 7 that was used by a drug dealer in New York and has sought Apple's help. This new case represents the latest battleground in the legal dispute between US officials and Apple over encryption.

5.       Philippines and Turkey suffer hacks: The database of the Philippine Commission on Elections (COMELEC) has been breached and the personal information of 55 million voters potentially exposed in what could rank as the worst ever government data breach anywhere. Meanwhile in Turkey - Personal details of nearly 50 Million Turkish citizens, including that of the country's President, have been compromised and posted online in a massive security breach.

6.       Phishing email that knows your address: We are moving into a “post-privacy” society, where it is not uncommon for an attacker to have access to information that we have previously considered as personal. Using this - Hackers carefully-craft user-specific emails that contain links and personal information to trick victims into installing a new kind of Ransomware. BBC News reported that some of their staffers have received such emails. Ransomware is increasingly becoming problematic for private companies, hospitals and citizens.

7.       Dridex becomes more dangerous: Experts have observed that in addition to stealing banking credentials, the malware increasingly is also being used to steal credit card information. First few versions of Dridex were focused on English-speaking countries like Australia, the UK and the U.S, while the current versions target companies from all over the world. Dridex seems to be back after it was taken down by authorities in last Oct.

8.       Adobe Patches Zero-Day Flaw Used by Exploit Kit: Adobe patches 24 vulnerabilities, including a zero-day issue being exploited by the Magnitude Exploit Kit and flaws reported at the Pwn2own contest. Some of the vulnerabilities were being used by the Magnitude Exploit kit to deliver ransomware identified as Cerber and Locky thru "drive-by downloads", which do not require user action to initiate. Unlike attachment-based malware, simply visiting a Website, by browsing to the site or clicking on a URL in email exposes the browser's Adobe Flash Player to the exploit.

9.       Over 135 million modems vulnerable to denial-of-service flaw: A vulnerability, found in a modem used in millions of households, can allow an attacker with access to the network to remotely reset the device, which wipes out the internet provider's settings and causing a denial-of-service attack until the modem owner contacts their internet provider. The problem lies with how the modem, handles authentication and cross-site requests. A firmware upgrade that ensures the need of credentials before rebooting or resetting will sort this issue.

10.   State Bank of Mysore customers lose money after accounts hacked: SBM has initiated an internal probe and lodged a complaint following hacking of their banking system last week, which resulted in many customers losing large sums through multiple online transactions of ₹49. The bank has refunded the lost money to its customers. It is reported that some of them have lost upwards of ₹50,000/-. Experts familiar with the matter have blamed the bank for its unpatched systems and poor security posture – which was not enough to defend against zero day attacks or modern malware.
The series of text messages that customers of State Bank of Mysore received:

Sunday, April 3, 2016

Issue 58 - Week of Mar 27th


1.       Mattel nearly loses $3M to a classic phishing scam: A finance executive with the maker of children’s toys - Mattel, fell victim to a phishing scam and wired a cool $3 million to Chinese hackers. The phishing email was unremarkable and came directly from their new CEO, or so the executive thought. She was wrong. She wired the money and within few hours during a discussion with CEO she realized the scam. Luckily the transfer took place on a bank holiday, with cooperation from Chinese authorities, Mattel was able to reclaim the wired cash, before the hackers could have claimed it on the next working day. Other recent Phishing attacks have targeted W-2 data.

2.       MedStar Hospital forced to turn patients away after virus attack: Last week the hospital was hit by ransomware, the hospital responded quickly by taking the infected IT systems offline to avoid further corrupting its network infrastructure. The Baltimore Sun reported a ransom of $18,500 was sought. MedStar declined to comment. FBI is currently investigating the incident. Recently, a Cancer Hospital reported a breach while a hospital in Germany was held to ransom by cyber-attackers but they did not pay-up and a LA Hospital that went thru a similar attack paid $17k.

3.       Magento becomes fresh target for KimcilWare ransomware: Magento is an e-commerce platform - that is used by over 200,000 companies worldwide. A strain of ransomware called KimcilWare is being used in campaigns against Magento websites. The malware is installed via a script which encrypts all data and can be spotted through the .kimcilware extension, which is added to all locked files. A new index.html file displays a ransom note, alongside a readme file, which demands a ransom of $140 to unlock the e-commerce store. There is no cure for the Infection and Infected users should consider reverting to backups to wipe clean the infection.

4.       New ransomware encrypts the whole hard drive: While most ransomware focuses on infecting systems in order to lock files, a new breed called Petya goes further – by completely removing access to hard drives and operating systems. Phishing emails are being sent to targeted firms (mostly HR departments) containing Dropbox links to applications which install Petya on systems. Once installed Petya forces a reboot and loads the Malicious code, which under the guise of system tool check disk (CHKDSK) -runs a 'scan'. As this fake scan proceeds, Petya is encrypting the Master File Table on the drive. The ransom price is 0.9 BTC ($370). Regular backup and good web security solutions are a must to combat Ransomware.

5.       Apple v/s FBI: Last week, the FBI announced that the third party had helped it unlock the iPhone, and the Department of Justice dropped the case. Apple got some kudos from consumers for standing its ground against the government. Apple is expected to tighten security even more with its next iPhone software, likely to be announced in June and available in September.

6.       Bangladesh Heist update: Last week - a Chinese casino junket operator returned $4.63 million of the $81 million that hackers stole from the Bangladesh central bank's account in the US Federal Reserve Bank and laundered in Manila's casinos. Earlier, $20 million transfer was rejected by a receiving bank in Sri Lanka because the beneficiary's name was misspelled.

7.       Prepare to be hacked if you don't use a password for VNC: By choosing to use no authentication to secure VNC connection, users are sending out a 'please hack me' invitation. A hacker created a script that cycles through internet IP addresses and tries to connect to unsecured servers through a web-based VNC viewer. If the script finds an available connection without any authentication, it will connect and grab a screenshot, otherwise the script will kill the session and move to a different IP address. The hacker now has about 23GB of screenshots and some of them have been posted to VNC Roulette. Some of the Images are mundane like people browsing Facebook, doing their online banking, reading email, shopping etc., while other images feature SCADA systems and sensitive data.

8.       Security flaw in Apple lets malicious apps in: Despite new security features in iOS 9, businesses still need to be alert to employees being duped into installing malicious configuration profiles on their iPhones. Apple offers enterprise certificates to allow businesses to distribute apps outside the App Store and it allows any app installed by the MDM to be trusted. MDM is third party to Apple and vulnerable to a man-in-the-middle attack. Researchers have shown how an attacker can hijack and imitate MDM commands that iOS trusts, including the ability to install enterprise apps over the air.

9.       6 Charged for hacking lottery terminals to produce more winning tickets: Police have arrested and charged six people with crimes linked to hacking Connecticut state lottery terminals in order to produce more winning tickets than usual. Prosecutors say all the six suspects are either owners or employees of retail stores that produced a much higher number of winning tickets than the state average. The hack appears to have exploited some software weaknesses in lottery terminals that not only caused ticket requests to be delayed but also allowed operators to know ahead of time whether a given request would produce a winning ticket.


10.   Tech companies play April Fool's Day pranks: On April 1st every year - Internet gets its funny bone and is filled with viral pranks from tech companies, this year Google, Samsung, Kayak all had their pranks. One of Google's prank "Introducing the self-driving bicycle in the Netherlands" was well received. Google said the self-driving bicycle would enable safe navigation through the city for Amsterdam residents, and it furthers Google’s ambition to improve urban mobility with technology.