New research from WinMagic has revealed that security, management and compliance challenges are affecting the benefits businesses get from using the cloud within their infrastructures.
The firm polled 1029 IT decision makers in the UK, Germany and US and discovered that whilst 98% of respondents use the cloud, 33% admitted that data residing there is only partially encrypted. What’s more, 39% said they do not have unbroken audit trails across virtual machines in the cloud, something that can leave them exposed to risks. Unsurprising then that 58% said security was their top concern on future workloads in the cloud, whilst protecting sensitive data from unauthorized access (55%) came in second.
WinMagic’s research also revealed confusion as to compliance of data stored in the cloud. A worryingly low 39% felt they were ultimately responsible for this, with 20% believing responsibility rests solely with the cloud service provider and the same percentage thinking they were covered by their cloud service provider’s SLA. This confusion is particularly concerning given the fact that GDPR will come into force in little over five months.
“The stakes for companies were already high, with data breaches increasing in frequency and scale,” said Mark Hickman, chief operating officer at WinMagic. “EU GDPR reinforces the care that must be taken with data. The simple fact is that businesses must get the controls in place to manage their data, including taking the strategic decision that anything they would not want to see in the public domain, must be encrypted.”
Finally, cloud adoption is taking its toll on the majority of IT enterprise teams, with over half spending more time on management tasks than ever before and needing to use more management tools to get jobs done.
“At its heart, using heterogeneous cloud environments is making it harder for businesses to manage security and compliance, leaving staff firefighting rather than focusing on new projects that will benefit their businesses,” Hickman added.
Source: Info-Security
Cloud Workloads at Risk from Security, Management & Compliance Failures
WPA3 Set to Secure Public Wi-Fi Networks in 2018
Wi-Fi is about to get more secure this year with the launch of the new WPA3 protocol, the industry body behind it has announced.
The Wi-Fi Alliance — which is comprised of tech stakeholders including Apple, Cisco, Intel, Microsoft and Qualcomm — made the announcement at CES on Monday.
When it lands later this year, WPA3 will offer new features to simplify and enhance security for users and service providers on personal and enterprise networks, the body claimed.
One feature, individualized data encryption, should finally help to mitigate one of the biggest challenges facing users of public Wi-Fi networks — others on the same network snooping on their sessions.
It will do this by creating a secure encrypted channel for each user on the network.
The Alliance also pointed to two other new features which “will deliver robust protections even when users choose passwords that fall short of typical complexity recommendations, and will simplify the process of configuring security for devices that have limited or no display interface.”
It is believed the former will include steps to prevent attackers brute-forcing the Wi-Fi passwords of other users on the same network, and stopping them from making multiple log-in attempts.
“Wi-Fi security technologies may live for decades, so it’s important they are continually updated to ensure they meet the needs of the Wi-Fi industry,” said Joe Hoffman of SAR Insight & Consulting. “Wi-Fi is evolving to maintain its high-level of security as industry demands increase.”
At the same time, the Wi-Fi Alliance announced enhancements to the WPA2 protocol used by most companies today.
It claimed testing improvements will reduce the likelihood of vulnerabilities resulting from network misconfiguration and safeguard managed networks with centralized authentication.
The update to WPA2 is long overdue. The protocol has been around for well over a decade and recently took a major hit when researchers discovered a serious vulnerability (KRACK) which could allow attackers to eavesdrop on users’ data.
Source: info-security
Tories left Red-Faced After HTTPS Gaffe
UK Prime Minister, Theresa May, saw her major Cabinet reshuffle overshadowed yesterday after the governing Conservative Party seemingly allowed its SSL certificate to expire.
Visitors to the Tory Party’s website were greeted with browser-based warnings such as: “Your connection is not private. Attackers might be trying to steal your information from www.conservatives.com (for example, passwords, messages or credit cards).”
The security alert was the result of a basic IT admin error: allowing the political party’s SSL certificate to expire so that it could no longer guarantee a secure HTTPS connection for users.
HTTPS is fast becoming the de facto standard for websites, thanks in part to tools such as Let’s Encrypt and HTTPS Everywhere, which allow web managers to switch to the more secure protocol for free.
The percentage of web pages loaded by Firefox using HTTPS stood at over two-thirds (67%) as of January 2018 — that’s over 63 million active certificates.
The UK government issued an order in autumn 2016 mandating all departments switch to the more secure protocol from October 1 that year.
However, cyber-criminals have also been making use of such tools to help hide malware from security filters. A report from 2016 claimed that almost half of all cyber-attacks in the preceding 12 months made use of malware hidden in encrypted traffic.
The Conservative Party’s IT-related woes didn’t end with the HTTPS gaffe yesterday: it was left further embarrassed after an official tweet was posted congratulating new chairman, Chris Grayling.
There was just one problem with the tweet: Grayling wasn’t appointed the party’s new chairman at all, that job went to former immigration minister Brandon Lewis.
The tweet was swiftly deleted, and the party's SSL certificate has now been renewed.
However, the mistake didn’t go unnoticed on Twitter, where eagle-eyed commentators voiced their views.
This post from journalist Solomon Hughes is typical:
“Conservative Website is down because they forgot to do an IT update. Because they didn't update, the Conservative Party can't communicate.”
Source: infosecurity-magazine
APPLE RELEASES SPECTRE PATCHES FOR SAFARI, MACOS AND IOS
Apple released iOS 11.2.2 software Monday for iPhones, iPads and iPod touch models that patch for the Spectre vulnerabilities. A macOS High Sierra 10.13.2 supplemental update was also released to bolster Spectre defenses in Apple’s Safari browser and WebKit, the web browser engine used by Safari, Mail, and App Store.
This is the second update for Apple since last week’s revelation of the massive processor vulnerabilities, Meltdown and Spectre, impacting CPU’s worldwide. Apple previously released mitigations against Meltdown with updates that included iOS 11.2, macOS and tvOS 11.2.
Monday’s three updates include macOS High Sierra 10.13.2 supplemental, Safari 11.0.2, and iOS 11.2.2. The updates “includes security improvements” to mitigate the two known methods for exploiting Spectre identified as variants “bounds check bypass” (CVE-2017-5753/Spectre/variant 1) and “branch target injection” (CVE-2017-5715/Spectre/variant 2).
Apple said the Safari 11.0.2 update is available for OS X El Capitan 10.11.6 and macOS Sierra 10.12.6. The macOS High Sierra 10.13.2 supplemental update includes security updates for Safari and WebKit. iOS 11.2.2 is for iPhone 5s and later, iPad Air and later, and iPod touch 6th generation.
According to experts, the Spectre vulnerability, variant is much more difficult attack to carry out than Meltdown because it breaks the isolation between different applications. But, at the same time, it will also be harder to patch.
There is also a greater sense of urgency with Spectre. A Meltdown attack scenario requires an attacker to already have a foothold on the targeted system. Spectre opens up certain types of remote attack scenarios such as browser-based attacks, according to researchers.
Last week Mozilla, along with Microsoft and Google, updated the code in their browsers to increase them time it takes to execute certain Java commands that could exploit the Spectre flaws, making it exponentially harder – but not impossible – to exploit.
“A JavaScript attack being able to pull memory contents of the browser and could result in pulling credentials and session keys, which bypasses a lot of a lot of security protections,” said Jimmy Graham, director of product management at Qualys in a previous interview with Threatpost.
Apple is not releasing any additional technical details of the patches, including what – if any – penalty patches may have on device performance.
Source: threatpost
[Guide] How to Protect Your Devices Against Meltdown and Spectre Attacks
Recently uncovered two huge processor vulnerabilities called Meltdown and Spectre have taken the whole world by storm, while vendors are rushing out to patch the vulnerabilities in its products.
The issues apply to all modern processors and affect nearly all operating systems (Windows, Linux, Android, iOS, macOS, FreeBSD, and more), smartphones and other computing devices made in the past 20 years.
What are Spectre and Meltdown?
We have explained both , Meltdown (CVE-2017-5754) and Spectre (CVE-2017-5753, CVE-2017-5715), exploitation techniques in our previous article.
In short, Spectre and Meltdown are the names of security vulnerabilities found in many processors from Intel, ARM and AMD that could allow attackers to steal your passwords, encryption keys and other private information.
Both attacks abuse 'speculative execution' to access privileged memory—including those allocated for the kernel—from a low privileged user process like a malicious app running on a device, allowing attackers to steal passwords, login keys, and other valuable information.
Protect Against Meltdown and Spectre CPU Flaws
Some, including US-CERT, have suggested the only true patch for these issues is for chips to be replaced, but this solution seems to be impractical for the general user and most companies.
Vendors have made significant progress in rolling out fixes and firmware updates. While the Meltdown flaw has already been patched by most companies like Microsoft, Apple and Google, Spectre is not easy to patch and will haunt people for quite some time.
Here's the list of available patches from major tech manufacturers:
Windows OS (7/8/10) and Microsoft Edge/IE
Microsoft has already released an out-of-band security update (KB4056892) for Windows 10 to address the Meltdown issue and will be releasing patches for Windows 7 and Windows 8 on January 9th.
But if you are running a third-party antivirus software then it is possible your system won’t install patches automatically. So, if you are having trouble installing the automatic security update, turn off your antivirus and use Windows Defender or Microsoft Security Essentials.
"The compatibility issue is caused when antivirus applications make unsupported calls into Windows kernel memory," Microsoft noted in a blog post. "These calls may cause stop errors (also known as blue screen errors) that make the device unable to boot."
Apple macOS, iOS, tvOS, and Safari Browser
Apple noted in its advisory, "All Mac systems and iOS devices are affected, but there are no known exploits impacting customers at this time."
To help defend against the Meltdown attacks, Apple has already released mitigations in iOS 11.2, macOS 10.13.2, and tvOS 11.2, has planned to release mitigations in Safari to help defend against Spectre in the coming days.
Android OS
Android users running the most recent version of the mobile operating system released on January 5 as part of the Android January security patch update are protected, according to Google.
So, if you own a Google-branded phone, like Nexus or Pixel, your phone will either automatically download the update, or you'll simply need to install it. However, other Android users have to wait for their device manufacturers to release a compatible security update.
The tech giant also noted that it's unaware of any successful exploitation of either Meltdown or Spectre on ARM-based Android devices.
Firefox Web Browser
Mozilla has released Firefox version 57.0.4 which includes mitigations for both Meltdown and Spectre timing attacks. So users are advised to update their installations as soon as possible.
"Since this new class of attacks involves measuring precise time intervals, as a partial, short-term mitigation we are disabling or reducing the precision of several time sources in Firefox," Mozilla software engineer Luke Wagner wrote in a blog post.
Google Chrome Web Browser
Google has scheduled the patches for Meltdown and Spectre exploits on January 23 with the release of Chrome 64, which will include mitigations to protect your desktop and smartphone from web-based attacks.
In the meantime, users can enable an experimental feature called "Site Isolation" that can offer some protection against the web-based exploits but might also cause performance problems.
"Site Isolation makes it harder for untrusted websites to access or steal information from your accounts on other websites. Websites typically cannot access each other's data inside the browser, thanks to code that enforces the Same Origin Policy." Google says.
Here's how to turn on Site Isolation:
Copy chrome://flags/#enable-site-per-process and paste it into the URL field at the top of your Chrome web browser, and then hit the Enter key.
Look for Strict Site Isolation, then click the box labelled Enable.
Once done, hit Relaunch Now to relaunch your Chrome browser.
Linux Distributions
The Linux kernel developers have also released patches for the Linux kernel with releases including versions 4.14.11, 4.9.74, 4.4.109, 3.16.52, 3.18.91 and 3.2.97, which can be downloaded from Kernel.org.
VMware and Citrix
A global leader in cloud computing and virtualisation, VMware, has also released a list of its products affected by the two attacks and security updates for its ESXi, Workstation and Fusion products to patch against Meltdown attacks.
On the other hand, another popular cloud computing and virtualisation vendor Citrix did not release any security patches to address the issue. Instead, the company guided its customers and recommended them to check for any update on relevant third-party software.
Source: TheHackerNews
Huge Flaws Affect Nearly Every Modern Device; Patch Could Hit CPU Performance
UPDATE: Researchers have finally disclosed complete technical details of two kernel side-channel attacks, Meltdown and Spectre—which affect not only Intel but also systems and devices running AMD, ARM processors—allowing attackers to steal sensitive data from the system memory.
____________
The first week of the new year has not yet been completed, and very soon a massive vulnerability is going to hit hundreds of millions of Windows, Linux, and Mac users worldwide.
According to a blog post published yesterday, the core team of Linux kernel development has prepared a critical kernel update without releasing much information about the vulnerability.
Multiple researchers on Twitter confirmed that Intel processors (x86-64) have a severe hardware-level issue that could allow attackers to access protected kernel memory, which primarily includes information like passwords, login keys, and files cached from disk.
The security patch implements kernel page-table isolation (KPTI) to move the kernel into an entirely separate address space and keeps it protected and inaccessible from running programs and userspace, which requires an update at the operating system level.
"The purpose of the series is conceptually simple: to prevent a variety of attacks by unmapping as much of the Linux kernel from the process page table while the process is running in user space, greatly hindering attempts to identify kernel virtual address ranges from unprivileged userspace code," writes Python Sweetness.
It is noteworthy that installing the update will hit your system speed negatively and could bring down CPUs performance by 5 percent to 30 percent, "depending on the task and processor model."
"With the page table splitting patches merged, it becomes necessary for the kernel to flush these caches every time the kernel begins executing, and every time user code resumes executing."
Much details of the flaw have been kept under wraps for now, but considering its secrecy, some researchers have also speculated that a Javascript program running in a web browser can recover sensitive kernel-protected data.
AMD processors are not affected by the vulnerability due to security protections that the company has in place, said Tom Lendacky, a member of the Linux OS group at AMD.
"AMD processors are not subject to the types of attacks that the kernel page table isolation feature protects against," the company said.
"The AMD microarchitecture does not allow memory references, including speculative references, that access higher privileged data when running in a lesser privileged mode when that access would result in a page fault."
The Linux patch that is being released for ALL x86 processors also includes AMD processors, which has also been considered insecure by the Linux mainline kernel, but AMD recommends specifically not to enable the patch for Linux.
Microsoft is likely to fix the issue for its Windows operating system in an upcoming Patch Tuesday, and Apple is also likely working on a patch to address the vulnerability.
Source: TheHackerNews
Hundreds of GPS Location Tracking Services Leaving User Data Open to Hackers
Security researchers have unearthed multiple vulnerabilities in hundreds of GPS services that could enable attackers to expose a whole host of sensitive data on millions of online location tracking devices managed by vulnerable GPS services.
The series of vulnerabilities discovered by two security researchers, Vangelis Stykas and Michael Gruhn, who dubbed the bugs as 'Trackmageddon' in a report, detailing the key security issues they have encountered in many GPS tracking services.
Trackmageddon affects several GPS services that harvest geolocation data of users from a range of smart GPS-enabled devices, including children trackers, car trackers, pet trackers among others, in an effort to enable their owners to keep track of where they are.
According to the researchers, the vulnerabilities include easy-to-guess passwords (such as 123456), exposed folders, insecure API endpoints, and insecure direct object reference (IDOR) issues.
By exploiting these flaws, an unauthorized third party or hacker can get access to personally identifiable information collected by all location tracking devices, including GPS coordinates, phone numbers, device model and type information, IMEI numbers, and custom assigned names.
What's more? On some online services, an unauthorized third party can also access photos and audio recordings uploaded by location tracking devices.
The duo said they have been trying to reach out to potentially affected vendors behind the affected tracking services for warning them of the severity of these vulnerabilities.
According to the researchers, one of the largest global vendors for GPS tracking devices, ThinkRace, may have been the original developer of the flawed location tracking online service software and seller of licenses to the software.
Although four of the affected ThinkRace domains have now been fixed, the remaining domains still using the same flawed services continue to be vulnerable. Since many services could still be using old versions of ThinkRace, users are urged to stay up-to-date.
"We tried to give the vendors enough time to fix (also respond for that matter) while we weighted this against the current immediate risk of the users," the researchers wrote in their report.
"We understand that only a vendor fix can remove user’s location history (and any other stored user data for that matter) from the still affected services but we (and I personally because my data is also on one of those sites) judge the risk of these vulnerabilities being exploited against live location tracking devices much higher than the risk of historic data being exposed."
In many cases, vendors attempted to patch the vulnerabilities, but the issues ended up re-appearing. Around 79 domains still remain vulnerable, and researchers said they did not know if these services would be fixed.
"There have been several online services that stopped being vulnerable to our automated proof of concept code, but because we never received a notification by a vendor that they fixed them, it could be that the services come back online again as vulnerable," the duo said.
You can find the entire list of affected domains on the Trackmageddon report.
Stykas and Gruhn also recommended some suggestions for users to avoid these vulnerabilities, which includes removing as much data from the affected devices as possible, changing the password for the tracking services and keeping a strong one, or just stopping to use the affected devices until the issues are fixed.
Source: TheHackerNews
Intel Tiger Lake CPUs to come with Anti-Malware Protection
Intel’s Tiger Lake CPUs will come with Control-flow Enforcement Technology (CET), aimed at battling common control-flow hijacking attacks. I...
-
Last April, Steven Schoen received an email from someone named Natalie Andrea who said she worked for a company called We Purchase Apps. She...
-
Intel’s Tiger Lake CPUs will come with Control-flow Enforcement Technology (CET), aimed at battling common control-flow hijacking attacks. I...
-
By Carl Herberger This is Part 2 of our series on the top 5 most dangerous DDoS attacks and how you can successfully mitigate them. ATTAC...