Sunday, November 27, 2016

Issue 92- Week of Nov 21st


1.      Madison Square Garden admits hackers spent a year harvesting visitor credit-card data: Card issuing banks noticed suspicious patterns and notified MSG. After investigation, MSG has revealed that for a year malware has been capturing payment-card data from a system that processes payments for several of its properties. MSG warned customers that the breach had exposed customer data held on the magnetic strip of credit cards, including card numbers, cardholder names, expiration dates, and internal verification codes. Exact number of victims is not known, though it is known fact that millions of people visit MSG every year.

2.      Hackers attack Canada Army site, redirect visitors to China: Canada’s Defense Ministry has confirmed that hackers recently attacked its armed forces recruitment website and changed configurations redirecting visitors to the Chinese government’s official page instead, says a Reuters report. Canadian authorities have in the past complained of the country’s official network being frequently targeted by hackers. An official complaint had even been lodged with Beijing in 2014 about Chinese hackers compromising a key network system.

3.      FBI hacked into 8,000 Computers in 120 Countries using a single warrant: While investigating a child pornography website, the FBI used a malware on the site to gather details of all its visitors. FBI admitted in a court filing that they used the single warrant to hack 8000 computers in 120 countries.

4.      Hackers are targeting ATMs and stealing wads of cash: Issue 79 - we discussed - 'ATMs in Thailand hacked; 12 Million Baht stolen'. Now according to a Russian cyber security firm, cyber crooks have remotely infected ATMs with malware in more than dozen countries across Europe this year, which forces machines to spit out cash. The world's two largest ATM manufacturers, Diebold Nixdorf and NCR Corp., said they were aware of the ATM attacks and had already been working with their customers to mitigate the threat.

5.      Telecrypt Ransomware cracked, free Decryptor released: TeleCrypt, is a typical ransomware. For Russian victims, the blackmailing message is in Russian and they demand a ransom of 5,000 rubles ($77). Some of its unusual features are that it abuses Telegram Messenger's communication protocol to send decryption keys and other communication. If the victim has an unencrypted version of the file, Researchers can use this as an sample to generate the decryption key and thus easily crack this Ransomware.

6.      Locky ransomware spreading on Facebook Messenger via JPG file: Early part of last week - it was reported that a Malware in the form of .SVG image files was being spread using Facebook Messenger. Compromised FB accounts were extensively used to spread the Malware. Later part of last week - experts discovered how cyber criminals are hiding malware in image files, and how they are executing the malware code within these images to infect social media users with Locky variants. We discussed Locky way back in Issue 52, it has since become the biggest and most common Ransomware.

7.      Stampado ransomware gets worm-like techniques to spread in network: Stampado ransomware is available for sale on the dark web for $39, the seller describes this as a easy to manage ransomware with life time license. This ransomware also has capabilities to spread in the network like a worm and re-encrypt already encrypted files. It installs itself in the %AppData% folder under the name scvhost.exe, a slight deviation on a genuine Windows process named svchost.exe, and creates a registry entry to load automatically. Researchers advise victims not to pay the ransom, stating that it's possible to decrypt files infected by Stampado on their own.

8.      Headphones can be used to Spy - even with disabled Microphone: Issue 70, we saw the picture of Mark Zuckerberg with his laptop’s Webcam and Microphone taped for Privacy. Researchers have now shown that even if one tapes his camera and microphone, it is possible to turn headphones into a microphone by turning the output channel on the laptop for input signal, in order to spy on all the conversations in the background without user's knowledge. This malware is dubbed as 'Speake(a)r'.

9.      NTP DoS exploit released: A proof-of-concept (PoC) exploit for a critical vulnerability in the Network Time Protocol daemon (ntpd) has been publically released that could allow anyone to crash a server with just a single maliciously crafted packet. The vulnerability has been patched by the Network Time Foundation with the release of NTP 4.2.8p9, which includes a total of 40 security patches, bug fixes, and improvements.

PM Modi urges India to go Cashless / Less-Cash: After the demonetization process started 3 weeks ago, there has been a great push towards cashless society, while this is a welcome move - the experts are cautionary. They say that Cyber Security is clear and present danger and it is here to stay. Major concerns include - Card cloning, Malware infections, Card theft and misuse. Building awareness can help in keeping the crime under check. If these security issues result in declined / failed transactions - people will revert to the older ways of handling cash, slowing down the process of going cashless


Sunday, November 20, 2016

Issue 91- Week of Nov 14th


1.      Mobile company in UK hacked: One of UK's biggest mobile operators called 'Three', has been hacked and massive data containing personal information and contact details of 6 Million of its customers exposed. The company admitted the data breach last week, saying that computer hackers gained access to a phone upgrade database. It is reported that hackers used an employee login to gain entry. Three people have been arrested. In 2015, another British carrier called TalkTalk was hacked and it suffered a loss of 60M pounds.

2.      Hacker group breaches Mega.nz servers: MEGA is New Zealand-based website that offers  cloud storage and file hosting service. A hacking group has hacked this site and dumped the stolen data online. In a statement released following the dump, Mega Chairman confirmed the incident but said no user data was compromised. The hackers managed to steal the credentials of one of Mega's contractors and using that they gained access to the servers. The dump includes admin logins of several employees, Mega's CMS and some emails. The hackers also claimed to have stolen source codes of various Mega apps and have put them on Auction.

3.      Some Android phones secretly sent user data to China: Shanghai Adups Technology, a China-based company, developed a back-doored firmware software that is installed in thousands of Android-based devices. This backdoor sends all text messages, call log, contact list, location history, and app data to China every 72 hours. It also has the capability to remotely install and update applications on a smartphone. Google issued a statement saying that the company is working with all affected parties to patch the issue, though the tech giant said that it doesn't know how widely AdUps distributed its software.

4.      Three Million Android smartphones infected with dangerous Rootkit: Nearly 3 Million Android devices worldwide are vulnerable to man-in-the-middle (MITM) attacks that could allow attackers to remotely execute arbitrary code with root privileges, turning over full control of the devices to hackers. According to a report, the issue is due to a vulnerability in the insecure implementation of the OTA (Over-the-Air) update mechanism used by certain low-cost Android devices. This vulnerability is associated with Chinese mobile firm Ragentek Group and it runs with root privileges to communicate over unencrypted channels - allowing a remote attacker to extract personal information from an affected device, remotely wiping the whole device, and even make it possible to gain access to other systems on a corporate network and steal sensitive data.

5.      BlackNurse attack: BlackNurse is the name of a recently discovered network attack that can crash firewalls and routers via ICMP packets, known by most of us as "pings". In this attack, Type 3 ICMP packets with a code of 3 are send to cause a Denial of Service (DoS) state by overloading the CPUs of certain types of server firewalls. The vulnerable firewalls are - some Cisco ASA models, Sonicwall, Palo Alto & Zyxel firewalls. The BlackNurse traffic volume is very small - 40,000 to 50,000 packets per second, which is tiny when compared to the recent 1.1 Tbps DDoS attack on French ISP OVH. The good news is that there are several ways to defend and some of the Vendors have already issued Advisories.

6.      iPhone lock screen hack puts contacts, messages and pics at risk: A new exploit video has been put on Internet, this shows - Hackers can bypass the passcode to access Contacts, Pictures and Messages of a locked phone. All that they need is a physical access to the phone. This vulnerability is across all the current versions of Apple. The Company is likely to patch this in its next release. As this exploit leverages SIRI, one can turn off SIRI till the patch is available.

7.      $5 'Poison Tap' hacks locked computers: A developer has created a $5 device that can hack into an unattended computer even with a locked screen. The tool called Poison Tap can break into a password-protected computer if the user has left an internet browser running in the background. The attacker can then remotely use the victim's web accounts undetected. Samy Kamkar, who has made a YouTube video showing what happens when it breaks into a computer, created the device on a Raspberry Pi microcomputer. As physical access to a machine is required, the best defense is to avoid leaving laptops and computers unattended.

8.      Gone in 70 seconds - Holding Enter key can smash through defense: If a hacker enters a blank password 93 times – or simply holds down the 'Enter' key for roughly 70 seconds – he will gain access to a root initramfs (initial RAM file system) shell. The simple exploit, which requires physical access to the system, exists due to a bug in the Linux Unified Key Setup (LUKS) used in popular variations of Linux.  Exploiting the flaw remotely is also possible. With access to an 'initramfs' environment shell, an attacker could then attempt to decrypt the encrypted filesystem by brute-force. Fortunately, the vulnerability is easy to fix - all that one needs to do is add a command to stop the boot sequence after 'x' number of password attempts.

9.      Password typing fingers can leak passwords: Researchers have found a technique, dubbed 'Windtalker', to exploit a feature called CSI in the WiFi protocol. CSI monitors the general information about the status of the signal. When a user is typing his password (or using keyboard), his fingers are interfering with signal in a certain pattern, which causes the CSI to fluctuate. Analyzing the strong correlation between the CSI fluctuation and the keystrokes, it is possible with 68% accuracy to infer the user’s keystrokes. If the keypad layouts are randomized this attack can be defeated. In Issue 72, we discussed how “Hackers can steal your ATM PIN from your smartwatch or fitness tracker”, using related tricks.

10.   Indian Cybercrime victims refuse to learn from past experience: Consumers in India may be increasingly becoming aware of the cyber threats they face but their online behavior is often contradictory and puts them at risk to ransomware, malware and attacks from cyber criminals. It is also estimated that there are at least 15 ransomware attacks per hour in the country and one in three Indians fall prey to it. In another report based on figures from Ministry of Finance - Top 51 Banks in India have lost ₹485Cr ($71M) between Apr'13 to Nov'16. 56% of the money lost is due to Net-banking thefts and Card cloning.

Sunday, November 13, 2016

Issue 90- Week of Nov 7th


1.      Tesco Bank hacked: Tesco Bank customers have had their money stolen from their accounts after the banking arm of UK's biggest retailer fell victim to a hacking attack last week. As a result of the hack, Tesco Bank had frozen online transactions for few days, while only allowing the use of credit/Debit cards. Tesco Bank has confirmed that a total of £2.5 Million was stolen from its 9,000 customers in the cyber-attack, the entire amount has been refunded to the customers. Further details of the attack are yet to be disclosed and as of now all account services have returned to normal.

2.      Websites of 7 Indian embassies hacked, database leaked: Indian embassy websites in seven different countries have been hacked, and attackers have leaked personal data, including full name, residential address, email address, passport number and phone number, of Indian citizens living abroad. This incident is extremely worrying because it involves diplomatic personnel working in the embassies that have always been a favorite target of state-sponsored hackers launching cyber espionage campaigns. Security pen-testers have claimed responsibility for the hack and apparently the reason behind the hack was to force administrators to consider the cyber security of their websites seriously.

3.      5 major Russian Banks hit with powerful DDoS attacks: Distributed Denial of Service (DDoS) attacks have risen enormously in past few months, and mostly they are coming from hacked and insecure IoT. Recently, a similar DDoS attack against DNS provider Dyn brought down a large chunk of the Internet. Researchers said more than a half of the IoT botnet devices used in this attack, were situated in the United States, India, Taiwan, and Israel. In a similar but separate incident,   a  DDoS attack through hacked IoT devices led to the disruption of the heating systems for at least two apartments in Finland, literally leaving their residents in subzero weather. It is advised to change the default settings and credentials of IoT devices and always protect the devices behind a firewall.

4.      Recruitment firm hacked: Michael Page, a global recruitment consultancy, has been hacked and a wide range of personal information on 710,000 applicants has been stolen. The company has formally admitted the attack. The leaked personal information includes full names, email address, telephone numbers, locations, sectors, job types and current positions. The company claimed in the statement that due to the nature of the data, there is limited risk of fraudulent activity, they also confirmed that no other data was compromised.

5.      Gone in 60 seconds - Google phone hacked: At the 2016 PwnFest - the brand new Android smartphone launched by Google just a few months back has been hacked by Chinese hackers in less than a minute. The team demonstrated a proof-of-concept exploit that used a zero-day vulnerability in order to achieve remote code execution (RCE) on the target smartphone. They also won $120K for this effort, Google will now work to patch the vulnerability.

6.      Hackers launch targeted Cyberattacks hours after Trump’s win: Merely a few hours after Donald Trump declared his stunning victory, a group of hackers that is widely believed to be Russian and was involved in the breach of the DNC (Democratic National Committee) launched a wave of attacks against dozens of people working at universities, think tank tanks, NGOs, and even inside the US government. It is very common for hackers to use major world events to spread malware.

7.      Facebook buys leaked Passwords from Black Market: According to Facebook's Chief Security Officer, the company buys passwords that hackers are selling in the black market and cross-references them with encrypted passwords used on their platform. Facebook then asks the users to re-think the password and change it. While Password reuse is a big cause of harm on the internet, weak passwords like '12345'/'password' add to the problem.

8.      Russian court bans LinkedIn in Russia; Facebook and Twitter could be next: According to a new Russian data protection law, foreign tech companies are required to store the personal data of its citizens within the country. As LinkedIn violated this law, it will be banned in Russia. Other bigger companies, including WhatsApp, Facebook, and Twitter, could be next on the list. Some of the companies, including Google, Apple, and Viber, have reportedly moved some of their servers to Russia. LinkedIn, which has some 5 Million users in Russia, is considering arrangements that will allow it to avoid the ban. It could also appeal against the court's decision.

9.      SWIFT Hack: Bangladesh Bank recovers $15 Million from a Philippines Casino: Part of the $81 Million stolen in February from Bangladesh bank's New York Federal Reserve account earlier this year in the wake of the major malware attack on the SWIFT interbank transfer network has been tracked down to a casino in the Philippines and has been recovered.

RIP - For a short while, Facebook killed us all: Last week, Facebook declared everyone dead, including the company's CEO Mark Zuckerberg, in a massive memorial 'remembering' profile glitch. Facebook in a statement apologized and accepted that it was a terrible error. The bug was quickly fixed. This idea of memorial was suggested as part of a recent Facebook hackathon. Facebook didn’t comment further on the what caused the glitch.

Sunday, November 6, 2016

Issue 89- Week of Oct 31st


1.      Medical procedures cancelled after network attack: Hundreds of planned operations, outpatient appointments, and diagnostic procedures have been canceled at multiple hospitals in Lincolnshire, England, after a "major" computer virus compromised the National Health Service (NHS) network last week. Some patients, including major trauma patients and high-risk women in labor, were diverted to neighboring hospitals. Although the majority of systems are now back and working, the NHS Trust has not provided any specific information about the sort of virus or malware or if it managed to breach any defense. Issue 52 -  we discussed the Ransomware attack in which Hospital paid hackers $17,000 in Bitcoins.

2.      Hack attacks cut internet access in Liberia: A small African country - Liberia, has been repeatedly cut off from the internet by hackers targeting its only link to the global network. Experts said the same group that caused world-wide disruption recently is behind this hack. Mirai botnet have been used in this attack and vulnerable IoTs continue to be misused to launch massive DDoS attacks. Most IoT users are unaware that a simple step like changing default password can go a long way in making the world far more secure that it is now. The other steps can be disable universal Plug and Play (UPnP) & remote management thru’ Telnet.

3.      Hacker providing DDoS-for-Hire service arrested: A 19-year student created a tool called ‘Titanium Stresser’- that offers DDoS as a service. The tool was used to launch hundreds of attacks between Dec'13 to Mar'15 and also earned him $385K. The hacker was arrested in 2015 and will be sentenced in Dec'16.

4.      Microsoft fires back at Google for Windows 0-Day disclosure: Microsoft says Google's disclosure last week of a zero-day security vulnerability in Windows prior to a patch being issued put users "at increased risk." The flaw, which Google revealed under its policy of reporting bugs after 7 days if they haven't been fixed. The bug is a local privilege-escalation flaw in the Windows operating system kernel that can be used to bypass a security sandbox. Some of the hacker groups have been spotted exploiting this bug already.

5.      Cisco job applicants warned of potential mobile site data leak: Users of Cisco's Professional Careers mobile site, mjobs.cisco.com, have been warned of a potential leak of their data, which the networking giant is pinning on an incorrect security setting. Cisco said the impact was restricted to a "limited set of job application-related information", however the personal data that could have been exposed included name, address, race, gender, veteran status, disability status, username, password, answers to security questions, education, professional profile, cover letter, and resume text.

6.      Tracking cell-phones using Wi-Fi: A controversial cell phone spying tool, known as  ‘IMSI catchers’, is used to track and monitor mobile users by mimicking a cellphone tower and tricking their devices to connect to them. Sometimes it even intercepts calls and Internet traffic, sends fake texts, and installs spyware on a victim's phone. In a presentation at BlackHat Europe, researchers have demonstrated a new type of IMSI catcher attack that operates over WiFi, allowing anyone to capture a smartphone's IMSI number within a second as the users' pass by. The captured IMSI would then allow attackers to track the user's movements. Mobile manufactures have begun working to ensure the future protection of the IMSI number.

7.      MalwareMustDie spotted a new IoT Linux/IRCTelnet malware: Security researchers at MalwareMustDie have discovered a new malware family designed to turn Linux-based insecure Internet of Things (IoT) devices into a botnet to carry out massive DDoS attacks. Dubbed ‘Linux/IRCTelnet’, the nasty malware is written in C++ and, just like Mirai malware, relies on default hard coded passwords in an effort to infect vulnerable Linux-based IoT devices. The malware works by brute-forcing a device's Telnet ports to infect it, which then connects to a malicious IRC channel and reads commands sent from a command-and-control server.

8.      XSS flaw that places millions of websites at risk: An XSS vulnerability discovered on the Wix.com platform is putting millions of websites and their users at risk of attack. The website hosting provider, which provides free drag-and-drop website building tools, hosts millions of websites with 87 million registered users -- and all of which are currently vulnerable to an XSS bug which can be utilized by attackers to create worms capable of taking over administrator accounts. This, in turn, gives attackers full control over websites. A Spokesperson from Wix has confirmed that the issues have now been addressed.

9.      OAuth 2.0 - can be hacked to hijack mobile apps: OAuth 2.0 is an open standard for authorization that allows users to sign in for other third-party services by verifying existing identity of their Google, Facebook or other accounts. So, when a user wants to log into a travel app, he can request Facebook to authenticate him. Facebook sends a 'Access Token' to the user which is forwarded to the travel app. Now Researchers have found a loophole - the hacker can download the travel app, change the username to the person he wants to hack and request for the token from Facebook and get access to the user's data on the travel app. The Researchers presented their research paper at BlackHat Europe conference last week.


10.   Jharkhand emerges hotbed of low-tech cyber-crimes: Jamtara, a predominantly tribal district in Jharkhand is one of the biggest centers of organized cyber-crime in India. As per estimates, close to 150 gangs are involved in developing cyber fraud as a cottage industry. There are training centers in Jamtara, where for as low as ₹7000 ($100) for a four day training - hackers are taught to make fake phone calls, mostly in the guise of a bank employee, and seeking information like the CVV or ATM pin for urgent account verification. This is followed by prompt illegal transfer of money. There are also cases of card cloning and Ransomware.


Sunday, October 30, 2016

Issue 88- Week of Oct 24th


1.      Indian origin teenager hacker arrested for disrupting 911 service with DDoS attack: 18 year old Indian origin teen discovered an iOS vulnerability that could be exploited to manipulate devices, including trigger pop-ups, open email, and abuse phone features. He posted links of his exploits on his Twitter account, which has a follower base of 12000 people, all those who clicked on that link had their iPhones hacked and ended up automatically calling 911 non-stop. This resulted in the disruption of 911 service in state of Arizona. Authorities swung into action and traced the issue to the teen and have arrested him.

2.      Hacker gets 18 months in Prison for hacking Celebrity nude photos: The hacker who stole nude photographs of female celebrities two years ago in a massive data breach — famous as "The Fappening" or "Celebgate" scandal — has finally been sentenced to 18 months in federal prison. The hacker  ran phishing scheme between November 2012 and September 2014 and hijacked more than 100 Identities using fake emails disguised as official notifications from Google and Apple, asking victims for their account credentials. Many of the compromised accounts belonged to famous female celebrities including Jennifer Lawrence, Kim Kardashian.

3.      LinkedIn hacker also charged with Dropbox hacking: Last issue we discussed the arrest of the LinkedIn hacker from Prague. Now, US authorities have officially indicted the 29-years-old Russian national, for hacking not just LinkedIn, but also the online cloud storage platform Dropbox. The hacker remains in custody in Prague, Czech Republic. The FBI is waiting for a Czech court to decide on his extradition to the United States.

4.      Chinese IoT cameras used in Dyn DDos attack: Issue 87 - we discussed the DDoS attack on DNS provider Dyn by an army of hacked IoT devices. A Chinese IoT firm admitted its products inadvertently played a role in the massive cyber-attack against DynDNS. More such attacks are expected to happen and will not stop until IoT manufacturers take the security of these Internet-connected devices seriously. The company has rolled out patches and has advised its customers to update their product's firmware and change their default credentials. The company also said it will also recall up to 10,000 webcams.

5.      Mirai Botnet that attacked Dyn is itself Flawed: A Botnet called Mirai was used in the Dyn DDoS attack.  The author of the Botnet released the source code and a researcher found that the botnet itself contains several vulnerabilities that might be used against it in order to destroy botnet's DDoS capabilities and mitigate future attacks. The researcher has now released his exploit. The DDoS attack that hit French Internet service and hosting provider OVH with 1 Tbps of junk traffic, which is the largest DDoS attack known to date, also came from Mirai bots.

6.      Chinese Hackers won $215k for Hacking iPhone and Google Nexus at Mobile Pwn2Own: For hacking Apple's iPhone 6S (with the latest iOS 10), the hackers exploited two iOS vulnerabilities – a use-after-free bug in the renderer and a memory corruption flaw in the sandbox – and stole pictures from the device, for which the team was awarded $52.5k. They won another $60k for installing an app on the iPhone though it did not survive a reboot. For hacking the Nexus 6P, the hackers used a combination of two vulnerabilities and other weaknesses in Android and managed to install a rogue application on the Google Nexus 6P phone without user interaction. They were awarded them a whopping $102,500 for the Nexus 6P hack.

7.      AtomBombing is a design flaw in Windows that cannot be patched: Security researchers have discovered a new technique that could allow attackers to inject malicious code on every version of Microsoft's Windows operating system, even Windows 10, in a manner that no existing anti-malware tools can detect. Dubbed "AtomBombing," the technique does not exploit any vulnerability but abuses a designing weakness in Windows. AtomBombing attack abuses the system-level Atom Tables, a feature of Windows that allows applications to store information on strings, objects, and other types of data to access on a regular basis. This issue cannot be patched as it is a design issue.

8.      You can hijack nearly any Drone mid-flight using this tiny Gadget: A Security researcher has devised a small hardware, dubbed Icarus, that can hijack a variety of popular drones mid-flight, allowing attackers to lock the owner out and give them complete control over the device. Besides Drones, the new gadget has the capability of fully hijacking a wide variety of radio-controlled devices, including helicopters, cars, boats and other remote control gears that run over the most popular wireless transmission control protocol called DSMx. The loophole relies on the fact that DSMx protocol does not encrypt the 'secret' key that pairs a controller and flying device.

9.      Now – iPhone can also be hacked with an Image: Attackers can take over a vulnerable Apple's iOS device remotely – all they have to do is trick the user to view a maliciously-crafted JPEG graphic or PDF file, which could allow them to execute malicious code on the mobile. That's a terrible flaw (CVE-2016-4673), but the good news is that Apple has released the latest version of its mobile operating system, iOS 10.1, for iPhones and iPads to address this remote-code execution flaw, alongside an array of bug fixes. Users running older versions of iOS are advised to update their mobile devices to iOS 10.1 as soon as possible. Last year, Stagefright bug in Android allowed hack via just a text message, while in Issue 81 – we saw how an image can be used to hack the unpatched Android devices.


10.   Big spike in cybercrimes in India: Latest statistics released by the National Crime Records Bureau (NCRB) reflect a massive spike in cybercrimes in India. In Issue 77 - we saw "Pune based Indian Manufacturing Co. losing $175k". Last week it was few Hyderabad based Pharma companies that fell victim to a typo-squatting attack when they received fake details of change in bank in an Email, from what appeared to be their suppliers. They ended up sending huge sums of money to Scamsters instead of their suppliers. There are also cases where hackers hacked the email servers and send emails to the company's customers informing about a fake change in bank details to swindle money. These kinds of hacks are also called BEC - Business Email Compromise.



Sunday, October 23, 2016

Issue 87- Week of Oct 17th


1.      Massive ATM hack hits 3.2 Million Indian Debit cards: India is undergoing the biggest data breaches to date with as many as 3.2 Million debit card details reportedly stolen from multiple banks and financial platforms. The massive financial breach has hit India's biggest banks including State Bank of India (SBI), HDFC Bank, Yes Bank, ICICI Bank and Axis, and customers are advised to change their ATM PIN immediately. Hackers stole the data by allegedly using malware to compromise the Hitachi Payment Services platform — which is used to power country's ATM, point-of-sale (PoS) machines and other financial transactions.

2.      An army of Million hacked IoT devices almost broke the Internet: A massive Distributed Denial of Service (DDoS) attack against Dyn, a major domain name system (DNS) provider, broke large portions of the Internet on Friday, causing a significant outage to a ton of websites and services, including Twitter, GitHub, PayPal, Amazon, Reddit, Netflix, and Spotify. Though the exact details of the attack remain vague, it is suspected that it could have been using hijacked IoT devices - very similar to the  1 Tbps DDoS attack on France-based hosting provider OVH.

3.      Weebly & Foursquare join the massive Data breach family: Weebly and Foursquare are the latest victims of the massive data breach, joining the list of "Mega-Breaches" revealed in recent months, including LinkedIn, MySpace, VK.com, Tumblr, Dropbox, and the biggest one -- Yahoo. Website building service company - Weebly, lost details of 43 Million users, which includes usernames, email addresses, passwords, and IP addresses. The passwords were encrypted and salted, so it will be difficult for hackers to obtain the real passwords. Location based search-and-discovery service mobile app company - Foursquare, lost details of 22.5Million customers.

4.      LinkedIn hacker arrested: The 29 year old Russian hacker responsible for massive 2012 data breach at LinkedIn, has been arrested in Prague. The breach had affected 117 Million users. He had managed to break into the company's computers in March 2012 by stealing the username and password of a LinkedIn employee who worked at the company's Mountain View, California, headquarters. This stolen data was put on sale by a hacker called 'Peace', who also put data dumps of MySpace, Tumblr, VK.com, and Yahoo! on the dark web marketplace. As of now it is not sure if the arrested person and ‘Peace’ are the same.

5.      Details emerge after the NSA contractor's arrest: Issue 85 - we discussed -  "Another NSA Contractor arrested for stealing 'Secret' documents". Now, according to a court document filed last week, the FBI seized at least 50 terabytes of data from the contractor that he had siphoned from government computers over two decades, he also took several physical documents, many of which were marked "Secret" and "Top Secret." The stolen data also contained the hacking tools that were recently leaked by 'The Shadow Brokers', further investigation will determine if there is any connection between these events.

6.      Dirty COW — critical Linux kernel flaw being exploited in the wild: A nine-year-old critical vulnerability Dubbed "Dirty COW", has been discovered in virtually all versions of the Linux OS and is actively being exploited in the wild. The flaw is a privilege-escalation vulnerability, that is part of every distro of Linux - RedHat, Debian, and Ubuntu and it can be easily/reliably exploited. The flaw gets its name from the copy-on-write (COW) mechanism in the Linux kernel, which is so broken that any application or malware can tamper with read-only root-owned executable files to gain administrative (root-level) access to the device and completely hijack it.

7.      This free tool protects PCs from master boot record attacks: In Issue 58 -we discussed - Petya Ransomware which not only encrypts the files but also locks down the entire computer by attacking the Master boot record. Now Cyber security experts have developed an open-source tool that can protect the master boot record of Windows computers from modification by ransomware and other malicious attacks. Dubbed ‘MBRFilter’, the tool is nothing more than a signed system driver that puts the MBR into a read-only state, preventing any software or malware from modifying data of the MBR section.

8.      Ransomware update: Ransomware has exploded in 2016 and is increasingly targeting business networks instead of individual users. The total cost of damages related to these attacks is set to cross $1 billion this year. The primary drivers of Ransomware growth have been that attacks are easy to carry out and victims are willing to pay to get their data back. The bad news is that ransomware doesn't show any signs of slowing down and it's likely to only become a bigger problem during 2017. Building awareness, regular back-ups and a good Web Security solution can go a long way in protecting networks from Ransomware.

9.      St. Jude Medical and Muddy Waters update: Issue 81 - St. Jude Medical (STM) sued Muddy waters to set the records right. Last week - Muddy waters launched a new website, posting more demo videos and information about vulnerabilities in STM's implantable cardiac devices. STM claims that MedSec and Muddy Waters falsely issued warnings about insecure medical devices in order to intentionally drop the share value of STM - with an objective to profit from it. Meanwhile, STM has announced plans for a Cyber Security Medical Advisory Board which will handle all issues related to cybersecurity standards of its medical devices.


10.   Indo-pak cyberwar update: Pakistani hackers often tap into the frequencies that Indian airlines use to communicate with ATC while landing in border towns like Jammu. The hackers then block the communication and start transmitting Pakistani patriotic songs. Indian pilots quickly coordinate with other Airforce ATC in the vicinity to change the frequency to restore communications. For all its IT prowess, cyberspace is one frontier on which India remains seriously vulnerable. Steps are being taken to plug the gaping holes. The ambitious Digital India program will also need to factor in Cybersecurity. We can also learn from the Yahoo breach and protect our own billion+ user database – Aadhar.

Sunday, October 16, 2016

Issue 86- Week of Oct 10th


1.      Indo-Pak cyber war continues: Patriotic Indian hackers continue to damage crucial Pakistani websites. They have been defacing Pakistani Govt. websites and launching Ransomware attacks. Pakistan has been responding and at least 50 IT companies in Hyderabad have come under cyber-attacks from Pakistan-based hackers over the past 10 days, the Society for Cyberabad Security Council (SCSC) revealed. The Cyber Security Forum officials said Pakistani hackers have used servers in Turkey, Somalia and Saudi Arabia to launch attacks. Meanwhile in Delhi - Pakistan Cyber Army tried but failed to breach the Delhi Police website and steal the GPS data of the PCR vans.

2.      Air Force computer outage hits drone center: The US Air Force is investigating the failure of its classified computer network at Creech Air Force Base, a key nerve center for worldwide drone and targeted killing operations mainly in Syria, Afghanistan, Pakistan and Somalia. Military officials would not say whether the critical failure was due to internal technical issues, a cyberattack, or something else. Within weeks of the network crash at Creech, there were a series of airstrikes that went terribly wrong. It will be difficult to connect these events with each other. The investigation into the issue is ongoing.

3.      BlockChain.info Domain hijacked; site goes down: Blockchain.info, the world's most popular Bitcoin wallet and Block Explorer service, was down for few hours last week. It is believed that a possible cyber-attack had disrupted the site. The site has more than 8 million Digital Wallet customers. It was a DNS issue that led to their Domain name getting hijacked. It could be possible that the attacker wanted to host a fake web page on the same domain in an effort to steal bitcoin wallet credentials. The site is back now and there is no statement from the Blockchain.info team that suggests any hacking or compromise of its users bitcoin wallets.

4.      Turkey Blocks several sites to censor RedHack leaks: RedHack, a 20-year-old hacktivist group leaked 17GB of files containing some 58,000 stolen emails dating from April 2000 to Sep'16. In order to suppress the circulation of these stolen emails - Turkey has blocked access to cloud storage services including Microsoft OneDrive, Dropbox, and Google Drive, as well as the code hosting service GitHub. Like China, Turkey has long been known for blocking access to major online services in order to control what its citizens can see about its government on the Internet.

5.      New Android banking Trojan discovered in Singapore and HK: A recent version of a banking Trojan called Acecard - pretends to be a video plugin/Flash Player/app/video codec. If it gets installed on Mobile phones, it waits for victims to open any financial app. The Trojan then overlays itself on top of the legitimate app where it proceeds to ask users for their payment card number and card details such as card holder's name, expiration date, and CVV number. It also requests for personal information including a selfie of the victim holding his ID card under the face. With all this info - Hackers can make illegal transfers and take over victim's online accounts.

6.      Hackers leverage 12-year-old OpenSSH vulnerability for IoT attack: We have seen examples of DDoS attack launched from hacked Smart devices. Now, Researchers have discovered a new attack that was using compromised IoT devices to act as proxies for malicious traffic. Dubbed "SSHowDowN Proxy," this attack uses different types of IoT devices, from Wi-Fi routers and internet-connected NAS devices to DVRs and wireless cameras. More importantly, the SSHowDowN Proxy attack exploits a default configuration flaw in OpenSSH that was first discovered and addressed in 2004. It is recommended that end users always change the factory default credentials of any internet-connected device; disable SSH services on the devices unless they are required to operate; and establish firewall rules that prevent SSH access to and from IoT devices.

7.      Social media apps used for surveillance: It was disclosed last week that Facebook, Instagram, Twitter, VK, Google's Picasa and Youtube were handing over user data access to the developer of a social media monitoring tool called Geofeedia — which then sold this data to law enforcement agencies for surveillance purposes. The company has marketed its services to 500 law enforcement and public safety agencies. Facebook, Instagram, and Twitter have all moved to restrict access to Geofeedia after learning about the tool's activities when presented with the study's findings.

8.      Beware of Security Fakeware: A hacker group called StrongPity has been using watering hole attacks to distribute compromised versions of WinRAR and TrueCrypt. By setting up fake distribution sites that closely mimic legitimate download sites, StrongPity is able to trick users into downloading malicious versions of these encryption apps in hopes that users encrypt their data using a Trojanized version of WinRAR or TrueCrypt apps, allowing attackers to spy on encrypted data before encryption occurred. The top five countries affected by the group are Italy, Turkey, Belgium, Algeria and France.

9.      Microsoft and Adobe patch vulnerabilities: Microsoft has released its monthly Patch Tuesday update including a total of 10 security bulletin, and you are required to apply the whole package of patches altogether. MS has removed the ability to pick and choose which individual patches to install. Adobe also released a new version of Flash Player that patched a dozen of vulnerabilities in its software, most of which were remote code execution flaws. Users are advised to apply Windows and Adobe patches to keep away hackers and cybercriminals from taking control over your computer.


10.   MITRE will award $50,000 for a solution that detects rogue IoT Devices: The non-profit research and development organization MITRE has challenged security researchers to propose new methods and technologies that could help in detecting rogue Internet of Things (IoT) devices on a network. It will give a $50,000 reward to the researchers who will propose a non-traditional method for enumerating IoT devices through passive network monitoring. Recently IoT botnets were observed launching massive DDoS attacks against the OVH websites and on Infosec websites.