Monday, April 25, 2016

Issue 61 - Week of April 18th


1.       Singapore penalizes firms for data breaches: Several organizations in Singapore have been fined and issued warnings for breaching the country's Personal Data Protection Act (PDPA), including local IT retail chain Challenger Technologies and Chinese handset maker Xiaomi. The Act does not apply to public sector or Govt. K Box entertainment had suffered a breach in 2014 but till date - failed to put in place adequate data protection policies and security safeguards - they were fined S$50,000. The Institution of Engineers in Singapore as well as Fei Fah Medical Manufacturing were fined S$10,000 and S$5,000, respectively, for their failure to implement sufficient security measures to safeguard the data of their members and customers.

2.       Creepy new ransomware uses image from popular horror film: Another ransomware has entered circulation.  Known as  BitcoinBlackmailer.exe or JIGSAW. This malicious program starts encrypting your files while adding, with no irony, the '.FUN' file extension. It also threatens to start deleting files if the ransom is not paid within an allotted time, complete with countdown timer. To add to the distress of the victim, the ransomware displays the face of the character Billy the Puppet from the horror movie series Saw (see image below). Forcepoint Security Labs was able to reverse engineer and retrieve the encryption key. This malware can be detected and blocked by web security solutions like Forcepoint using the ACE technology.

3.       Samsam server-side ransomware targets schools, hospitals: A new ransomware program called Samsam- uses vulnerabilities in the JBoss application server to infect networks, with attackers focusing on health care organizations and schools. Samsam and another recent ransomware program known as Maktub do not require a connection to a command-and-control server to encrypt data on a targeted system.

4.       Security expert builds ransomware blocker for Mac: An expert has built an utility that scans for untrusted processes that are encrypting personal files, and stops them dead. The utility is called "RansomWhere?". False positives are kept to a minimum because ‘RansomWhere?’ explicitly trusts binaries signed by Apple. It also trusts applications that are already present on the system when it is installed. This is a double-edged feature - on the one hand it helps reduce false positives, but on the other hand if ransomware is already present on the system before RansomWhere? is installed, it may not be detected.

5.       Python-Based Malware Infects European Companies: IT security researchers have discovered an unusual family of malicious code written entirely in the Python programming language, making it easy to port to different operating systems. The malware uses a modular design that allows it to carry out a selection of different attacks, including executing files, logging keystrokes, mining bitcoins, executing arbitrary Python code and communicating with a remote server. The malware has targeted a number of European organizations, particularly in Poland, the targets include a national research institution, a shipping company, a large retailer and an IT organization, as well as a construction company in Denmark and an optical equipment provider in France.

6.       Manufacturers suffer increase in cyber-attacks: The manufacturing sector is now one of the most frequently hacked industries, second only to healthcare, financial services has dropped to third place. Many manufacturing companies are behind the curve in security because they have not been held to compliance standards like the financial services has. Manufacturers also appear to be vulnerable to older attacks, such as Heartbleed and Shellshock & SQL injection. Industrial control systems also pose a challenge to manufactures as most of them use decade old OS. Recommended Defensive Strategies are - Annual IT risk assessment, Annual penetration tests, Conduct ongoing vulnerability scanning.

7.       Apple v/s FBI: In the New York drug dealer iPhone case, Justice Dept. finds way into locked phone and hence drops demand for Apple's help. In this case, no hacks needed, after someone provided the passcode to unlock the device, according to the prosecutor. In the other case, FBI director hinted that the agency spent more than $1.3M to hack into the terrorist's iPhone.

8.       Hackers can spy on your calls and track location, using just your phone number: The famous ‘60 Minutes’ television show shocked some viewers Sunday evening when a team of German hackers demonstrated how they spied on an iPhone used by U.S. Congressman, then recorded his phone calls and tracked his movement through Los Angeles. Hackers leverage a security flaw in SS7 (Signalling System Seven) protocol that allows hackers to track phone locations, listen in on calls and text messages. The weakness affects all phones, whether it's iOS, Android, or whatever, and is a major security issue. The network operators are unwilling or unable to patch the hole, there is little the smartphone users can do.

9.       Long arm of law catches up: Two International hackers, have been sentenced to 24 years and 6 months in prison for their roles in developing and distributing SpyEye banking Trojan, a powerful botnet similar to the infamous ZeuS malware. Both hackers were charged with stealing hundreds of millions of dollars from banking institutions worldwide. In a different case - A Former Reuters journalist, who was convicted last year of helping the Anonymous group of hackers, has been sentenced to 24 months in prison for computer hacking charges. He was found guilty of giving login credentials to Anonymous, using which the group defaced the Los Angeles Times.

10.   Don't fool around with politicians esp. Lalu: An Indian engineering student, who was arrested last week for hacking into and posting objectionable content on Lalu Prasad’s Facebook page, was expelled from his college. He is a third year student at a local engineering college in Bihar. The cyber cell arrested the student and seized two mobile phones and a SIM card which he allegedly used.


Billy the Puppet from the horror movie series Saw:

Sunday, April 17, 2016

Issue 60 - Week of April 11th

1.       FDIC suffers data breach: Federal Deposit Insurance Corporation (FDIC) provides deposit insurance to depositors in US banks, it suffered a major data breach- exposing  the records of 44,000 customers. A former employee - who had legitimate access to the data - downloaded the data to a personal device and left the corporation with the data. An FDIC spokeswoman confirmed that the former employee has signed an affidavit specifying no breached information was used in any form. This growing threat from Insiders is a big worry for all CIOs whose companies handle sensitive data.

2.       Hybrid GozNym malware targets customers of 24 financial institutions: A group of cybercriminals have combined two powerful malware programs (Gozi ISFB Malware + Nymaim malware), to create a new online banking Trojan (GozNym) that has already stolen millions of dollars from customers of 24 U.S. and Canadian banks. Nymaim is a dropper file that uses a DLL of Gozi- which is capable of injecting malicious code into Web browsing sessions. Together they are used to steal credentials and perform online banking fraud.

3.       Cybercriminals now target tier-2 systems: With Tier 1 systems like retail banking becoming more secure, the Cybercriminals targeting Australia are shifting their focus to other targets where money is held and security is poor, such as payroll, invoicing, and superannuation systems. The criminals log in to these systems using stolen credentials, check the date of the next pay run, and log out. They log back in just before the pay run, change employees' bank details to their own or to accounts that they control and let the payroll run proceed.

4.       Are you using Apple iPad? if yes- upgrade to iOS 9.3.1 immediately: iOS versions pervious to this are vulnerable to 1/1/1970 bug attack. If the iPad is in untrusted Wi-Fi network with a spoofed NTP server that sets the date as 1/1/1970, then the iPad's software becomes unstable and causes overheating and permanently damages the device. Fortunately this cannot happen to iPhone, as the phone depends on GSM network for its date and time.

5.       Are you using QuickTime for Windows? if yes- uninstall it now: Two reasons why you should do it - (i) Apple has abandoned QuickTime for Windows and it will not deliver security updates. (ii) There are two known critical vulnerabilities that could allow an attacker to take control of a system running QuickTime.

6.       Apple v/s FBI: After getting a third party to hack the shooter's iPhone – Sources have confirmed that nothing useful was found on it. In the drug dealer iPhone case, Apple resists FBI’s call to unlock the iPhone. Apple told a federal court last week that it should not be asked to help the FBI unlock the iPhone used by the drug dealer and that the case would lead to "an avalanche" of similar demands if prosecutors prevailed.

7.       FBI Director puts tape over his webcam: The director admitted that he has put a piece of tape over his personal laptop's webcam. On one hand he says 'absolute privacy hampers the law enforcement' but on the contrary, he is doing exactly the same with his personal webcam. However, tape on webcam cannot stop hackers or government spying agencies from recording your voice. FBI in the past has used malware to hack into cameras to spy on targets.

8.       Petya ransomware cracked: In issue 58, we spoke about this new ransomware that encrypts the whole hard drive. A researcher discovered a weakness in the nasty malware's design. To crack the malware - victims need to run a tool that extracts specific data from the infected hard drive and upload it to the researchers password generator tool - which will generate the decryption key for free. This is a great solution to decrypt the infected files, but most likely, the Petya authors have already heard about this tool and are modifying their code to disable the solution. So, there is no guarantee the tool will continue to work indefinitely. Regular backups and good web security solution are the best bets against ransomware.

9.       Cox investigates as employee data appears for sale on the dark web: Names, email addresses, phone numbers, and other information relating to some 40,000 Cox Communications employees is currently advertised on a marketplace specializing in stolen data and computer exploits. Cox is aware of this matter and have engaged a third-party forensic team to conduct a comprehensive investigation and are actively working with law enforcement.


10.   Online banking and plastic card-related fraud in India increases: The incidence of ATM, credit, debit card and net banking-related fraud has gone up by more than 35 percent between 2012-13 and 2015-16 in India, according to Reserve Bank of India. 11,997 cases have been booked in the first nine months of 2015-16. In Mumbai alone the credit card fraud rises 151% and it makes up 55% of cyber-crimes this year.

Sunday, April 10, 2016

Issue 59 - Week of April 4th


1.       'Panama Papers' Law Firm was hacked: In the latest twist in the historic "Panama Papers" data leak and scandal, the founding partner of the law firm whose files were dumped, exposing illicit offshore holdings of global political leaders, celebrities, and others, says his firm was hacked by an outsider. The law firm 'Mossack Fonseca' has two main websites, one runs on WordPress and the customer portal runs Drupal. Both of those sites were running outdated versions of the software and in both cases significant security holes existed that would have allowed hackers access.

2.       Heartbleed remains a risk 2 years after it was reported: On April 7, 2014, Heartbleed was publicly disclosed by the OpenSSL project, affecting millions of users and devices around the world. It was used by hackers to attack several corporates, government agencies like Canada's Revenue Agency (CRA) and some of the largest banks in US. Two years after it was first reported, the vulnerability remains a risk and is likely still being exploited by attackers taking advantage of unpatched servers. Most of the organizations that are still at risk because they don't know what their third-party vendors are implementing in products that they run on their network.

3.       Trump hotel chain suffers fresh data breach: Republican candidate Donald Trump's hotel chain, The Trump Hotel Collection, has become the victim of a credit card system data breach for the second time in only a year. Experts have spotted a "pattern of fraud" relating to customer credit cards, which implies the Trump Hotel Collection may once again be harboring malware on point-of-sale (PoS) systems within some hotels, or potentially all of them. In January - Hyatt Hotels had admitted that 250 hotels in 54 countries were affected by a cyber-attack which targeted customer financial information.

4.       FBI says it can unlock 5c but not 5s or later phones: The Apple V/s FBI case did not prolong as a third party helped FBI unlock the 5c iPhone. The director confirmed that they now have a tool that works on a narrow slice of phones. However, the agency could not unlock an iPhone 5s running iOS 7 that was used by a drug dealer in New York and has sought Apple's help. This new case represents the latest battleground in the legal dispute between US officials and Apple over encryption.

5.       Philippines and Turkey suffer hacks: The database of the Philippine Commission on Elections (COMELEC) has been breached and the personal information of 55 million voters potentially exposed in what could rank as the worst ever government data breach anywhere. Meanwhile in Turkey - Personal details of nearly 50 Million Turkish citizens, including that of the country's President, have been compromised and posted online in a massive security breach.

6.       Phishing email that knows your address: We are moving into a “post-privacy” society, where it is not uncommon for an attacker to have access to information that we have previously considered as personal. Using this - Hackers carefully-craft user-specific emails that contain links and personal information to trick victims into installing a new kind of Ransomware. BBC News reported that some of their staffers have received such emails. Ransomware is increasingly becoming problematic for private companies, hospitals and citizens.

7.       Dridex becomes more dangerous: Experts have observed that in addition to stealing banking credentials, the malware increasingly is also being used to steal credit card information. First few versions of Dridex were focused on English-speaking countries like Australia, the UK and the U.S, while the current versions target companies from all over the world. Dridex seems to be back after it was taken down by authorities in last Oct.

8.       Adobe Patches Zero-Day Flaw Used by Exploit Kit: Adobe patches 24 vulnerabilities, including a zero-day issue being exploited by the Magnitude Exploit Kit and flaws reported at the Pwn2own contest. Some of the vulnerabilities were being used by the Magnitude Exploit kit to deliver ransomware identified as Cerber and Locky thru "drive-by downloads", which do not require user action to initiate. Unlike attachment-based malware, simply visiting a Website, by browsing to the site or clicking on a URL in email exposes the browser's Adobe Flash Player to the exploit.

9.       Over 135 million modems vulnerable to denial-of-service flaw: A vulnerability, found in a modem used in millions of households, can allow an attacker with access to the network to remotely reset the device, which wipes out the internet provider's settings and causing a denial-of-service attack until the modem owner contacts their internet provider. The problem lies with how the modem, handles authentication and cross-site requests. A firmware upgrade that ensures the need of credentials before rebooting or resetting will sort this issue.

10.   State Bank of Mysore customers lose money after accounts hacked: SBM has initiated an internal probe and lodged a complaint following hacking of their banking system last week, which resulted in many customers losing large sums through multiple online transactions of ₹49. The bank has refunded the lost money to its customers. It is reported that some of them have lost upwards of ₹50,000/-. Experts familiar with the matter have blamed the bank for its unpatched systems and poor security posture – which was not enough to defend against zero day attacks or modern malware.
The series of text messages that customers of State Bank of Mysore received:

Sunday, April 3, 2016

Issue 58 - Week of Mar 27th


1.       Mattel nearly loses $3M to a classic phishing scam: A finance executive with the maker of children’s toys - Mattel, fell victim to a phishing scam and wired a cool $3 million to Chinese hackers. The phishing email was unremarkable and came directly from their new CEO, or so the executive thought. She was wrong. She wired the money and within few hours during a discussion with CEO she realized the scam. Luckily the transfer took place on a bank holiday, with cooperation from Chinese authorities, Mattel was able to reclaim the wired cash, before the hackers could have claimed it on the next working day. Other recent Phishing attacks have targeted W-2 data.

2.       MedStar Hospital forced to turn patients away after virus attack: Last week the hospital was hit by ransomware, the hospital responded quickly by taking the infected IT systems offline to avoid further corrupting its network infrastructure. The Baltimore Sun reported a ransom of $18,500 was sought. MedStar declined to comment. FBI is currently investigating the incident. Recently, a Cancer Hospital reported a breach while a hospital in Germany was held to ransom by cyber-attackers but they did not pay-up and a LA Hospital that went thru a similar attack paid $17k.

3.       Magento becomes fresh target for KimcilWare ransomware: Magento is an e-commerce platform - that is used by over 200,000 companies worldwide. A strain of ransomware called KimcilWare is being used in campaigns against Magento websites. The malware is installed via a script which encrypts all data and can be spotted through the .kimcilware extension, which is added to all locked files. A new index.html file displays a ransom note, alongside a readme file, which demands a ransom of $140 to unlock the e-commerce store. There is no cure for the Infection and Infected users should consider reverting to backups to wipe clean the infection.

4.       New ransomware encrypts the whole hard drive: While most ransomware focuses on infecting systems in order to lock files, a new breed called Petya goes further – by completely removing access to hard drives and operating systems. Phishing emails are being sent to targeted firms (mostly HR departments) containing Dropbox links to applications which install Petya on systems. Once installed Petya forces a reboot and loads the Malicious code, which under the guise of system tool check disk (CHKDSK) -runs a 'scan'. As this fake scan proceeds, Petya is encrypting the Master File Table on the drive. The ransom price is 0.9 BTC ($370). Regular backup and good web security solutions are a must to combat Ransomware.

5.       Apple v/s FBI: Last week, the FBI announced that the third party had helped it unlock the iPhone, and the Department of Justice dropped the case. Apple got some kudos from consumers for standing its ground against the government. Apple is expected to tighten security even more with its next iPhone software, likely to be announced in June and available in September.

6.       Bangladesh Heist update: Last week - a Chinese casino junket operator returned $4.63 million of the $81 million that hackers stole from the Bangladesh central bank's account in the US Federal Reserve Bank and laundered in Manila's casinos. Earlier, $20 million transfer was rejected by a receiving bank in Sri Lanka because the beneficiary's name was misspelled.

7.       Prepare to be hacked if you don't use a password for VNC: By choosing to use no authentication to secure VNC connection, users are sending out a 'please hack me' invitation. A hacker created a script that cycles through internet IP addresses and tries to connect to unsecured servers through a web-based VNC viewer. If the script finds an available connection without any authentication, it will connect and grab a screenshot, otherwise the script will kill the session and move to a different IP address. The hacker now has about 23GB of screenshots and some of them have been posted to VNC Roulette. Some of the Images are mundane like people browsing Facebook, doing their online banking, reading email, shopping etc., while other images feature SCADA systems and sensitive data.

8.       Security flaw in Apple lets malicious apps in: Despite new security features in iOS 9, businesses still need to be alert to employees being duped into installing malicious configuration profiles on their iPhones. Apple offers enterprise certificates to allow businesses to distribute apps outside the App Store and it allows any app installed by the MDM to be trusted. MDM is third party to Apple and vulnerable to a man-in-the-middle attack. Researchers have shown how an attacker can hijack and imitate MDM commands that iOS trusts, including the ability to install enterprise apps over the air.

9.       6 Charged for hacking lottery terminals to produce more winning tickets: Police have arrested and charged six people with crimes linked to hacking Connecticut state lottery terminals in order to produce more winning tickets than usual. Prosecutors say all the six suspects are either owners or employees of retail stores that produced a much higher number of winning tickets than the state average. The hack appears to have exploited some software weaknesses in lottery terminals that not only caused ticket requests to be delayed but also allowed operators to know ahead of time whether a given request would produce a winning ticket.


10.   Tech companies play April Fool's Day pranks: On April 1st every year - Internet gets its funny bone and is filled with viral pranks from tech companies, this year Google, Samsung, Kayak all had their pranks. One of Google's prank "Introducing the self-driving bicycle in the Netherlands" was well received. Google said the self-driving bicycle would enable safe navigation through the city for Amsterdam residents, and it furthers Google’s ambition to improve urban mobility with technology.

Sunday, March 27, 2016

Issue 57 - Week of Mar 21st


1.       Think twice before using USB drives: Security researchers have discovered a new data-stealing Trojan called USB Thief, that has the capability of attacking air-gapped or non-internet computers without leaving any trace of activity on the compromised systems. The malware resides as a Plug-in/DLL and executes from the USB itself, it is bound to that USB making it hard to be replicated or reverse engineer. To stay safe - Never use USB storage devices from non-trustworthy sources, Turn off Auto-run and Regularly backup your data.

2.       Anti-hacker unit of Verizon hacked: Records for more than 1.5 million customers of the computer security wing of Verizon, appeared for sale earlier last week. This division aids large corporations when they’ve been the victims of a hack, ironically, now the division itself has been breached. The entire database was offered up for $100k on a cybercrime forum, or in increments of 100,000 records for $10k apiece. The company has since fixed the security vulnerability and confirmed that the attacker only obtained basic contact information and no customer proprietary network information (CPNI) was accessed.

3.       Uber launches Bug-bounty program: The new bug bounty program is designed for white hat hackers to identify flaws in Uber's codebase; critical bugs could yield up to $10,000 in rewards, the company said. Uber's first reward program will run for 90 days, starting on May 1st. Uber says it will share publicly the "highest-quality" vulnerability discoveries if the winners who found them agree to the disclosure.

4.       Cybersecurity expert assisting with Bangladesh bank heist probe goes missing: A cybersecurity expert was reportedly abducted last week, according to his family, after commenting on an attempted cyber-attack of $1Billion from Bangladesh's central bank. Before disappearing, he met the special police force appointed by the central bank. He also addressed media, where he talked about the three user IDs used for the heist. Police are yet to comment on his disappearance. Meanwhile, the police are seeking both technical and human assistance from the FBI and have confirmed that criminals from multiple countries were involved. $100 million that was stolen has been traced to Sri Lanka and the Philippines

5.       Apple v/s FBI: Last week – court suspended the proceedings of this case, at least until next month after FBI told the federal judge that it needs some time to test a possible method for unlocking the shooter's iPhone for which they have hired an "outside party". Some reports have pointed to a forensic firm- assisting the Justice Dept. in opening the iPhone.

6.       Stop 'rewarding' victims of online fraud with refunds: A top cop has said that Banks should stop automatically reimbursing victims of online financial fraud, since it rewards their bad security habits. He believes consumers would learn to take computer security more seriously, if full refunds are stopped. He suggests banks could refund only a portion of funds lost in online fraud, if the victim is running outdated software. Malware takes advantage of unpatched flaws in browsers and plugins, such as Adobe Flash, Java, etc. Experts advice to keep all the software updated and run an Anti-malware software.

7.       Phishing attacks continue to target W-2 data: Playing on fear and basic human nature in order to succeed - Scammers continue to impersonate CEO/CFO/Senior people to seek W2(Form 16) data from mid/lower rung employees. Attackers play on the trust relationships that exist within the company and exploit the fact that most employees often cannot say ‘No’ to bosses. In the first three months of 2016 - 41 large and small organizations have reported such data loss, these include names like Snapchat, Seagate, Polycom, Netcracker Technology...

8.       Iranians charged with cyber-attacks on US banks, New York dam: The Justice Dept. has charged seven Iranian nationals with computer hacking offences against US banks and a dam in New York. They are said to have carried out numerous distributed denial-of-service (DDoS) attacks, disabling bank websites, preventing customers from gaining access to their online accounts. One of the attackers gained unauthorized access to Bowman dam's industrial automation control (SCADA) system, thru which he could have remotely operated and manipulated the dam's sluice gate. The attackers face up to 10 years in prison. Iran has brushed aside the charges.

9.       Malvertising campaign strikes top websites worldwide: Hackers continue to have a free run with Malvertising. Popular websites - including The New York Times, BBC, AOL, MSN, Lenovo and many others across the world fell prey to a malicious advertising campaign which sent unwitting visitors to the Angler exploit kit which serves TeslaCrypt ransomware. Hackers identify sites with high traffic and leverage third-party ad networks to slip in fraudulent and fake adverts. A mere visit to such sites installs Angler on victim's machines, it is not necessary to click those ads.


10.   Badlock - another branded bug trying to make money?: Samba is a re-implementation of the SMB/CIFS networking protocol, it facilitates file and printer sharing among Linux and Windows systems as an alternative to NFS. Stefan Metzmacher is contributed in the development on Samba; last week he announced a Bug in Samba on a newly created website and indicated it will patched on April 12th – coinciding with the next patch Tuesday. InfoSec professionals across the world panned this move as it gives a heads-up to criminals who can exploit this bug.

Sunday, March 20, 2016

Issue 56 - Week of Mar 14th


1.       US warns against Android apps that secretly listen in on your TV habits: An Indian firm called SilverPush uses a technology called 'Audio Beacon Technology', which uses inaudible audio waves in TV Ads to track TV habits and link it with the mobile user and his/her social-media activity. This technology is available as a SDK, which Android app developers embed in their apps. The US has told 12 Android app developers to declare their use of this technology, as failing to let customers know - violates the FTC Act. The technology runs silently in the background with or without the app being active.

2.       Bangladesh Bank chief throws in the towel after cyber-attack: The head of the Bangladeshi central bank has resigned following the devastating cyber-attack in which a group of hackers managed to steal at least $80 million from Bangladesh's New York-based Federal Reserve account. The criminals infected the Bangladesh Bank's computer systems with surveillance-based malware, and after watching transactions and learning how the banks operated for a few weeks, decided to strike. It was only thanks to a spelling mistake in one of the requests that bank officials became suspicious, querying the transfers and blocking others in the list. If no-one had noticed, the criminals could have gotten away with up to $1 billion.

3.       Lenovo start page pushed Angler: Another webpage (startpage[.]lenovo[.]com) joins the long list of pages/sites that have been compromised to silently redirect traffic to pages that install the infamous Angler exploit kit - which subsequently leads to delivery of TeslaCrypt ransomware. Last week it was Burrp[.]com and week before it was www[.]missmalini[.]com.

4.       Pwn2Own 2016- Chrome, Edge, and Safari hacked: Pwn2Own is a computer hacking contest held annually, contestants are challenged to exploit widely used software and mobile devices with previously unknown vulnerabilities. Winners of the contest receive a cash prize and other goodies. This year too -major browsers fell, security flaws in Google Chrome, Microsoft Edge, and Apple Safari were all successfully exploited. A total of $460,000 was awarded for 21 vulnerabilities across the three browsers as well as Windows, OS X, and Flash. Last year’s total was $557,500.

5.       Apple Fires Back At FBI Court Order: In a legal brief filed last week, Apple said the US founding fathers "would be appalled" by the Department of Justice (DOJ)'s order last month that Apple help bypass security encryptions built into the iPhone. The two sides will meet before a magistrate judge this Tuesday (March 22). Look for the ruling to be appealed, possibly all the way to the Supreme Court.

6.       Anonymous says it's hacking Trump: The 'Hacktivist' collective group Anonymous claimed to have leaked personal details of the controversial US presidential candidate Donald Trump, including his Mobile Phone Number and Social Security Number (SSN). The group posted a video condemning Trump. In response, a Trump representative sought the arrest of the people responsible for attempting to illegally hack accounts and telephone information.

7.       Android Trojan infiltrates mobile firmware: An Android Trojan which displays unwanted ads and installs nuisance software on mobile devices has been discovered in the firmware of smartphones and in popular Android applications. The adware, dubbed Gmobi, has infected the firmware of at least 40 low-end smartphone models and is present in a number of applications provided by well-known companies. Gmobi is packaged as a tailored program in software development kits (SDKs) for Google's Android platform and it is able to "remotely update the operating system, collect information, display notifications (including advertising ones), and make mobile payments.

8.       Hackers can Silently Install Malware in Non-Jailbroken iOS Devices: A new strain of malware designed for the iPhone and iPad poses a major risk to hundreds of millions of devices, because it can infect non-jailbroken devices without the user's knowledge. The Trojan - dubbed as AceDeceiver, installs itself on iOS devices without enterprise certificates and exploits design flaws in Apple's digital rights management (DRM) protection mechanism called FairPlay. Attackers purchase an app from App Store, intercept and save the authorization code. They then developed fake iTunes which tricks iOS devices to believe the app was purchased by victim and thus installs potentially malicious apps without the user’s knowledge.

9.       3 reasons why the Tax refund fraud thrives: A popular scam—where criminals filed fake income-tax returns to collect fraudulent refunds is on the rise in 2016 as well. It largely thrives as 1) Almost all tax returns are now online, 2.) Widespread leakage of personal information, 3.) Low risk of getting caught or being prosecuted for the crime. Storage firm Seagate Technologies and social media firm Snapchat are among the companies that recently announced that their employees had inadvertently given fraudsters W-2 (Form 16) information of their workers.

10.   Flipkart CEO Binny Bansal’s email ‘spoofed’, attempt to steal $80,000: The email account of Binny Bansal, CEO of e-commerce giant, Flipkart has reportedly been ‘spoofed’ and an attempt made to steal $80,000 using his email address. The incident took place two weeks back, when a seemingly official mail (Typosquatting) went from Bansal to the company’s CFO Sanjay Baweja asking him to transfer $80,000. The crime-in-progress was stopped after Baweja, noting the oddity of the request checked with Bansal in person. Flipkart said an official complaint has been lodged with the police. Police sources said that the spoof mails originated from Hong Kong and Canada using a server in Russia.



Sunday, March 13, 2016

Issue 55 - Week of Mar 7th

1.       Phishermen target sensitive data- Again: On the lines of the recent Snapchat attack - in which a scammer impersonating their CEO tricked their payroll department into emailing an attacker the payroll information of current and former Snapchat employees. Last week, it was reported that Alaskan telecom GCI was tricked into handing over employee W-2 forms by a phisher posing as the company's CFO, while a Seagate employee was also fooled into sending thousands of employee W-2's by email to a phisher posing as the company CEO. W-2 (Form 16 in India) contains virtually all of the data one would need to fraudulently file someone’s taxes and request a large refund in their name. Last year - Hackers stole this directly from IRS website. Data security solution prevents accidental data leak.

2.       Cancer clinic warns 2.2 million patients of data breach: Cyber-attackers accessed a key database of the clinic in early October. They were able to access and steal data including patients' names, Social Security numbers, physicians' names, diagnosis and treatment information, as well as insurance records. FBI had requested to delay the announcement and patient notification till last week as they were investigating. There is growing trend of core services being struck by cyber-attacks. Recently, a hospital in Germany was held to ransom by cyber-attackers but they did not pay-up while a LA Hospital that went thru a similar attack paid $17k.

3.       ISIS data breach: A defector has allegedly leaked what appears to be a USB drive's worth of ISIS’s secret data, including the personal information of 22,000 ISIS fighters. The leaked ISIS information could be a unexpected gift for security agencies and prosecutors trying to track ISIS’ members and prevent more recruits from joining. The names of three Paris attackers were found in the list.

4.       Restaurant recommendation site 'Burrp' serves EKs, TeslaCrypt:  Researchers spotted the Indian restaurant recommendation site “Burrp” redirecting visitors to a website that was serving Angler exploit kits (EK) that ultimately led to the delivery of TeslaCrypt ransomware. To begin with - Burrp website was compromised and malicious code was injected in the JavaScript which redirects users. Last week another popular website www[.]missmalini[.]com was compromised. Hackers routinely monitor sites with high traffic and whenever they spot an opportunity - they launch their attacks.

5.       Obama on Apple v/s FBI: The president answering a question on this subject said that one can’t take an absolutist view. He spoke at length on encryption and his position favored the American government's current position in this case. He favored strong encryption with secure keys, accessible to small set of people for a subset of important issues. He repeatedly reassured the audience the agencies are pretty scrupulous and trustworthy. Meanwhile, responding to Justice Dept.'s arguments - Apple slammed it  as  "cheap shot" and will next appear in court in California on March 22, a day after an expected product announcement.

6.       Spelling mistake saves $1 Billion: Attackers successfully breached Bangladesh Bank's systems and stole its credentials for payment transfers, they then "bombarded the Federal Reserve Bank of New York with nearly three dozen requests to move money (total value $1B) from the Bangladesh Bank's account there to entities in the Philippines and Sri Lanka. The first four transfers, totaling about $81 million, went through, but for the fifth transfer, Hackers misspelled "foundation" in the NGO's name as "fandation," prompting a routing bank, Deutsche Bank, to seek clarification from the Bangladesh central bank, which stopped the transactions.

7.       Automakers in the hot-seat for vehicle cybersecurity: Most of the new cars today are equipped with internet connectivity with third party apps running on board, making them vulnerable to hackers. Recently, researchers demonstrated hacks on Nissan Leaf and Chrysler Jeep. Car owners hold car makers responsible for security though many components of this system are not owned by car makers - like Infotainment, Connectivity, OS & Apps. General Motors now has a bug bounty program underway as well as a product security officer position. Someday in near future, we will have end point agents running in our cars like the way they  run on our laptops.

8.       First Fully Functional Mac Ransomware: The first fully functional ransomware for Mac OS X has been discovered in the wild, but was contained before it did damage. The new ransomware is called 'KeRanger' and it bypasses Apple's Gatekeeper -- the tool that prevents unsigned code from running on Mac operating systems -- by piggy-backing on an infected version of Transmission, an open-source BitTorrent client, which is signed with a valid Mac application developer's certificate.  Apple responded quickly to the announcement, revoking the abused certificate and updating XProtect signatures.

9.       Researchers can unlock some Android phones with inkjet-printed fingerprints: Researchers demonstrated a method in which, they first took high resolution image of victim's fingerprints, then print it on a special kind glossy paper. The printed fingerprints could fool the Android device into believing it was human. Way back in 2013, Apple's TouchID was hacked and more recently hackers showed ways to harvest fingerprint data from Android phones.

10.   The Bounty Hunter: A 22-year-old e-commerce company’s employee in Bangalore, earned ₹ 13 Million ($200K) just by reporting bugs for Facebook, Twitter and a host of other US-based companies. He recently found a simple vulnerability on Facebook that could have been used to hack into any user's account to get access to credit or debit card details, personal pictures, and messages without any user interaction, For this - he was awarded $15K (₹1Million). Bug bounty is highly recommended strategy to find new bugs especially for high traffic websites.