Web application compromise beats human error as the top data breach cause, putting finance companies at risk for larger attacks, according to a new study.
Web application compromise has topped human error as the most common type of data breach for finance companies. This shift gives the financial sector reason to be worried about broader, and more dangerous cyberattacks, acccording to a recent report from BitSight.
BitSight investigated types of data breaches targeting finance companies over the past three years. After massive cyber attacks hit major corporations in 2017, researchers wanted to learn the growth and impact of different attack types.
What they discovered was a fundamental shift in the types of attacks hitting the sector.
"One of the first things we were interested in was a significant increase in Web application compromise as the type of breach most prevalent within the finance industry," says BitSight data analyst Ryan Heitsmith
When BitSight says a breach is caused by "human error," Heitsmith explains, it's referring to one-off events in which an employee erroneously emailed personal or financial data to the wrong person. These incidents are typically smaller, and easier to contain, than web-based attacks, he says.
Back in 2015, more than half (51%) of breach events were caused by human error, 13% were caused by privilege abuse, and 8% were caused by Web applications. In 2016, human error caused 35% of breach events, followed by DoS (14%), and Web applications (11%).
This year had a significant uptick in Web application compromise, which accounted for 33% of breach events among finance companies in 2017. Human error fell in second, at 21% of events. Heitsmith says there could be a few reasons behind the shift. Better employee education, for one, could be driving the decrease in human error. More detailed reporting is another factor.
"Over the years we've been collecting data breach events at a large scale. We've seen reporting get a lot better, and stricter mandatory breach reporting requirements," he explains. More intense scrutiny in the press has also driven a broader understanding of the threat landscape, he notes.
Web application compromise, or any incident in which a Web application was the attack vector, encompasses a range of incidents including SQL injection attacks or a hacker who bypasses employee authentication to gain access into the company
This year, researchers also saw the threat landscape shift from events primarily caused by internal actors, to those caused by actors outside the company. Researchers note that while internal actors were sometimes malicious, some were making silly mistakes. Not all attacks were intentional or widespread, according to researchers who observe that external actors intentionally seek data through a variety of different exploits.
"What's interesting is these events tend to be larger in significance due to the large number of records lost as a result of data breaches," says Heitsmith of Web application compromise. "Human error incidents are smaller, maybe one to a couple of records, though some might be larger. But in Web applications, the median record count is a lot larger than any of the other breaches we look at within the finance industry."
There is a two-pronged approach to how finance companies can monitor for Web application compromise, he continues. The first is to ensure all Web applications are properly configured and invest in proper Web application security. The second is to use continuous monitoring platforms to keep an eye on third parties, which Heitsmith says is a weak spot in finance.
The spike in Web application compromise shouldn't diminish the focus on human error, which at 21%, is still a large problem. Mandatory employee training, to provide awareness around common exploits and problems like phishing, says Heitsmith, is as important as Web monitoring.
Source: Darkreading
Web Attacks Spike in Financial Industry
cybersecurity firm discovers severe security vulnerability in LG smart products
Check Point Software Technologies discovered a serious security vulnerability in LG smart products that exposed millions of homes to hackers from around the world. By exploiting the vulnerability, the hackers spied on homeowners and were able to figure out when the houses were empty. According to Check Point, the issue was discovered in July and fixed after two months.
The Israeli cybersecurity giant Check Point Software Technologies revealed Thursday that a severe security vulnerability in LG smart products has been discovered. Hackers have exploited the vulnerability in order to control the devices and surveil the millions of homes where the products are used, making it easier for burglars to spy on homeowners and know when the home is empty. The issue was discovered in July and fixed after two months.
According to Check Point, the security issue was found in the mobile app SmartThinkQ and the LG cloud platform. When hackers gain access to LG user accounts, they can control all the smart electronic devices that are connected to the accounts, such as vacuum cleaners, refrigerators, ovens, washing machines, dryers and air conditioning units.
If an account is linked to an LG Hom-Bot robotic vacuum cleaner, the hackers can monitor the movements and actions of the homeowners through the device’s camera, which streams a live feed to the smartphone using the app. The hackers can also interfere with refrigerator data, change air-conditioning settings and turn on stoves and ovens that are connected to the hacked accounts.
Source: Jerusalem online
DUHK Attack Lets Hackers Recover Encryption Key Used in VPNs & Web Sessions
DUHK — Don't Use Hard-coded Keys — is a new 'non-trivial' cryptographic implementation vulnerability that could allow attackers to recover encryption keys that secure VPN connections and web browsing sessions.
DUHK is the third crypto-related vulnerability reported this month after KRACK Wi-Fi attack and ROCA factorization attack.
The vulnerability affects products from dozens of vendors, including Fortinet, Cisco, TechGuard, whose devices rely on ANSI X9.31 RNG — an outdated pseudorandom number generation algorithm — 'in conjunction with a hard-coded seed key.'
Before getting removed from the list of FIPS-approved pseudorandom number generation algorithms in January 2016, ANSI X9.31 RNG was included into various cryptographic standards over the last three decades.
Pseudorandom number generators (PRNGs) don’t generate random numbers at all. Instead, it is a deterministic algorithm that produces a sequence of bits based on initial secret values called a seed and the current state. It always generates the same sequence of bits for when used with same initial values.
Some vendors store this 'secret' seed value hard-coded into the source code of their products, leaving it vulnerable to firmware reverse-engineering.
Discovered by cryptography researchers — Shaanan Cohney, Nadia Heninger, and Matthew Green — DUHK, a 'state recovery attack,' allows man-in-the-middle attackers, who already know the seed value, to recover the current state value after observing some outputs.
Using both values in hand, attackers can then use them to re-calculate the encryption keys, allowing them to recover encrypted data that could 'include sensitive business data, login credentials, credit card data and other confidential content.'
"In order to demonstrate the practicality of this attack, we develop a full passive decryption attack against FortiGate VPN gateway products using FortiOS version 4." researchers said.
"Our scans found at least 23,000 devices with a publicly visible IPv4 address running a vulnerable version of FortiOS."
Here below you can check a partial list (tested by researchers) of affected devices from various vendors:
The security researchers have released a brief blog post and technical researcher paper on a dedicated website for DUHK attack.
Source: thehackernews
Bad Rabbit: New Ransomware Attack Rapidly Spreading Across Europe
A new widespread ransomware attack is spreading like wildfire around Europe and has already affected over 200 major organisations, primarily in Russia, Ukraine, Turkey and Germany, in the past few hours.
Dubbed "Bad Rabbit," is reportedly a new Petya-like targeted ransomware attack against corporate networks, demanding 0.05 bitcoin (~ $285) as ransom from victims to unlock their systems.
According to an initial analysis provided by the Kaspersky, the ransomware was distributed via drive-by download attacks, using fake Adobe Flash players installer to lure victims' in to install malware unwittingly.
"No exploits were used, so the victim would have to manually execute the malware dropper, which pretends to be an Adobe Flash installer. We’ve detected a number of compromised websites, all of which were news or media websites." Kaspersky Lab said.
However, security researchers at ESET have detectedBad Rabbit malware as 'Win32/Diskcoder.D' — a new variant of Petya ransomware, also known as Petrwrap, NotPetya, exPetr and GoldenEye.
Bad Rabbit ransomware uses DiskCryptor, an open source full drive encryption software, to encrypt files on infected computers with RSA 2048 keys.
ESET believes the new wave of ransomware attack is not using EternalBlue exploit — the leaked SMB vulnerability which was used by WannaCry and Petya ransomware to spread through networks.
Instead it first scans internal network for open SMB shares, tries a hardcoded list of commonly used credentials to drop malware, and also uses Mimikatzpost-exploitation tool to extract credentials from the affected systems.
The ransom note, shown above, asks victims to log into a Tor onion website to make the payment, which displays a countdown of 40 hours before the price of decryption goes up.
The affected organisations include Russian news agencies Interfax and Fontanka, payment systems on the Kiev Metro, Odessa International Airport and the Ministry of Infrastructure of Ukraine.
Researchers are still analyzing Bad Rabbit ransomware to check if there is a way to decrypt computers without paying ransomware and how to stop it from spreading further.
How to Protect Yourself from Ransomware Attacks?
Kaspersky suggest to disable WMI service to prevent the malware from spreading over your network.
Most ransomware spread through phishing emails, malicious adverts on websites, and third-party apps and programs.
So, you should always exercise caution when opening uninvited documents sent over an email and clicking on links inside those documents unless verifying the source to safeguard against such ransomware infection.
Also, never download any app from third-party sources, and read reviews even before installing apps from official stores.
To always have a tight grip on your valuable data, keep a good backup routine in place that makes their copies to an external storage device that isn't always connected to your PC.
Make sure that you run a good and effective anti-virus security suite on your system, and keep it up-to-date.
Source: the hackernews
BoundHook' Technique Enables Attacker Persistence on Windows Systems
CyberArk shows how attackers can leverage Intel's MPX technology to burrow deeper into a compromised Windows system.
Security researchers at CyberArk have developed a technique showing how attackers can exploit a feature in the Memory Protection Extension (MPX) technology on modern Intel chips to steal data from Windows 10 systems and to remain completely undetected on them.
CyberArk's new BoundHook technique is similar to the GhostHook method that the company revealed earlier this year in that it is a post-exploitation technique. In other words, for BoundHook to work, an attacker would need to already have privileged access on a Windows 10 system.
Microsoft itself, for that reason, has refused to categorize the issue as a vulnerability that merits a security patch. "The technique described in this marketing report does not represent a security vulnerability and requires a machine to already be compromised to potentially work," the company said in a statement. "We encourage customers to always keep their systems updated for the best protection."
Intel's MPX technology, introduced with the chipmaker's Skylake line in 2015, is designed to protect applications against buffer overflows, out-of-bounds access, and other memory errors and attacks. Applications running on Windows 10 systems use the feature as protection against buffer overflow attacks.
CyberArk's BoundHook technique uses a boundary check instruction in MPX to hook processes on a system, and to essentially change its behavior. "The BoundHook technique allows you to run your own code inside foreign processes and change its normal behavior, without leaving any traces inside these foreign processes," says Doron Naim, senior security researcher at CyberArk.
Hooking is about changing the behavior of certain functions in the operating system or application software on a system, he says. As one example, he points to the key input function. "If an attacker were able to hook this function, they would be able to sniff and steal your keystrokes."
Typically, to do hooking you have to write hooking code inside a target process, he says. With BoundHook, the code is not used to execute the hook itself but to cause an error, like a boundary exception error in the process. From there an attacker can take complete control of the thread execution, Naim notes. "If you control the thread execution, you can do anything you want by the name of the target process. For example, if it's Word.exe, you can steal credentials or send information to the Internet through this process." Most antivirus tools are not equipped to detect the malicious activity that is enabled via BoundHook, according to CyberArk.
While Microsoft has downplayed BoundHook just as it did with GhostHook, Naim insists CyberArk's latest technique indeed poses a threat. "The first thing to note is that this technique is most likely to be used by nation-state attackers, or very well financed criminal organizations that are looking for infiltrations that last."
In the current threat environment, gaining administrative privileges on an endpoint system is something that administrators should assume even the most basic attacker can accomplish, he says. In most cases, all it takes is for a single individual to click on the wrong link or fall for a phishing scam.
Techniques such as the one that CyberArk demonstrated this week are important because they show how attackers can improve their dwell-time on a compromised network, Naim notes. "Techniques like this are incredibly powerful in helping attackers disappear after the initial infection point — allowing them to build in backdoors and plan their attacks in de facto stealth mode."
Source: Darkreading
How to download and install the Windows 10 Fall Creators Update right now
The much-anticipated Windows 10 Fall Creators Update has now been released, and here’s how you can download and install it right now.
The Fall Creators Update is a major package of new and improved features for Windows 10, and it’s completely free. It brings support for Windows Mixed Reality headsets, as well as improved privacy features, better accessibility options and a new interface.
As with previous updates, Microsoft will be performing a roll-out release for the Windows 10 Fall Creators Update, which means you may have to wait until the update is available for your device – so read on to take matters into your own hands, as we show you how to download and install the Windows 10 Fall Creators Update.
How to download and install the Windows 10 Fall Creators Update using the Update Assistant
You can now officially download the final version of Windows 10 Fall Creators Update using Microsoft's Update Assistant.
To do this, head to the Windows 10 Update Assistant webpage and click 'Update now'.
The tool will download, then check for the latest version of Windows 10, which includes the Fall Creators Update.
Once downloaded, run it, then select 'Update Now'. The tool will do the rest. Your PC will restart a few times – so save any work first – and then your PC will be updated with the Fall Creators Update, while all your files and settings will remain where they were.
How to download and install the Windows 10 Fall Creators Update using a fresh install
If you want to install the Windows 10 Fall Creators Update as a fresh install on your machine you’ll need to download the ISO file with the Fall Creators Update included.
Before you do this, make sure you've backed up all your important information and documents. Check out our list of the best free backup software for advice.
Microsoft has made the process of downloading and installing the Windows 10 Fall Creators Update using a fresh install very easy. Just go to the Download Windows 10 web page, and below where it says ‘Create Windows 10 installation media’, click the ‘Download tool now’ button.
You’ll also need a blank DVD or a USB stick to add the installation files to. Be warned this process wipes any data on the drives, so make sure the drive doesn’t have any important data on it. Also, make sure the USB stick has at least 5GB of space spare.
If you don’t have a spare drive, check out our list of the best USB flash drives 2017.
You’ll need to know if you have a 64-bit or 32-bit processor to download and install the correct version. If you have a recent PC it’s most likely to have a 64-bit processor.
Download and install the tool, then open it up and agree to the license terms. On the ‘What do you want to do?’ page, select ‘Create installation media for another PC’ then click ‘Next’. Select the language, edition and 32-bit or 64-bit version, then select either ‘USB flash drive’ or ‘ISO file’, depending on whether you’re installing from a USB drive or from a DVD (select ISO file for this).
Once the tool has formatted and created the installation drive, you can restart your PC, boot from the drive and install the Windows 10 Fall Creators Update from scratch. Our How to install Windows 10 guide will show you how.
You’ll now have Windows 10 Fall Creators Update installed and ready to go on your PC!
Source: techradar
Secure Wifi Hijacked by KRACK Vulns in WPA2
All modern WiFi access points and devices that have implemented the protocol vulnerable to attacks that allow decryption, traffic hijacking other attacks. Second, unrelated crypto vulnerability also found in RSA code library in TPM chips.
Researchers at Belgium's University of Leuven have uncovered as many as 10 critical vulnerabilities in the Wi-Fi Protected Access II (WPA2) protocol used to secure WiFi networks.
The vulnerabilities are present on both client and access point implementations of the protocol and give attackers a way to decrypt data packets, inject malware into a data stream and hijack secure connections via so-called key reinstallation attacks (KRACKs).
(The disclosure of the WPA2 flaws is the second one in recent days involving a crypto standard. Last week, Google, Microsoft and others warned about a bug in several Infineon trusted platform module (TPM) firmware versions that gives attackers a way to recover the private part of RSA keys generated by the TPM using only the corresponding public key. Nearly all Chrome OS devices that include an Infineon TPM chip are affected, and although large-scale attacks are not possible, a practical exploit already exists for targeted attacks.)
The KRACK attacks work on all modern wireless networks using the WPA2 protocol and any device that supports WiFi is most likely impacted, the researchers said in a technical paper that they will present at the upcoming Black Hat Europe security conference. However the flaws are not easy to exploit and require attackers to be in close proximity to a victim, thereby making the flaws somewhat less severe of a threat despite their ubiquity.
"Vulnerabilities that focus on issues with network protocols across many devices makes the threat landscape of this vulnerability very large," says Richard Rushing, CISO of Motorola Mobility and a speaker at Dark Reading's upcoming INsecurity security conference in November.
But as with all Wifi threats, physical proximity is required for the vulnerabilities to be exploitable, he says. "Most wireless IDS and IPS should be able to see this attack, and take preventative actions," Rushing said. "In many cases there are other Wifi man-in-the-middle attacks that can be just as successful given a user WiFi configuration."
Meanwhile, US-CERT described the KRACK vulnerabilities as existing in the WPA2 standard itself thereby putting all correct implementations of the protocol at risk of attack. An attacker within range of a modern access point and client can use the vulnerabilities to carry out a range of malicious actions. Depending on the encryption protocols being used by the WiFi network, the "attacks may include arbitrary packet decryption and injection, TCP connection hijacking, HTTP content injection, or the replay of unicast and group-addressed frames," US-CERT said. The advisory listed close to 150 vendors whose products are impacted by the vulnerabilities.
In the technical paper and a blog, researchers Mathy Vanhoef and Frank Piessens from the University of Leuven demonstrated a proof-of-concept key reinstallation attack that takes advantage of the WPA2 vulnerabilities to decrypt encrypted data.
The attack is targeted at the four-way handshake that takes place when a client device wants to join a protected WiFi network. The handshake is designed to ensure that both the client and the access point have the correct credentials to communicate with each other. The manner in which the third handshake takes place essentially gives attackers an opportunity to force resets of a cryptographic nonce counter used by the encryption protocol so data packets can be decrypted, replayed or forged, according to the two researchers.
The key reinstallation attack against the 4-way handshake is the most widespread and practically impactful attack currently possible against the WPA2 vulnerabilities, Vanhoef and Piessens said in the paper. "First, during our own research we found that most clients were affected by it. Second, adversaries can use this attack to decrypt packets sent by clients, allowing them to intercept sensitive information such as passwords or cookies." The manner in which WPA-2 has been implemented on devices running Linux and Android 6.0 and above make them particularly vulnerable to key reinstallation attacks, they said.
Organizations – corporate enterprises, businesses, schools and universities, retail shops and restaurants, government agencies – that have deployed Wi-Fi networks using WPA2 encryption are affected. When mobile users connect to these Wi-Fi networks with smartphones, tablets, laptops and other devices, they are also exposed to these vulnerabilities. Both the 802.1x (EAP) and PSK (password)-based networks are affected.
Hemant Chaskar, CISO and vice president of technology, at Mojo Networks says corporate enterprises, businesses, schools and universities, retail shops restaurants, government agencies and any organization that has deployed Wi-Fi networks using WPA2 encryption are affected. "When mobile users connect to these Wi-Fi networks with smartphones, tablets, laptops and other devices, they are also exposed to these vulnerabilities. Both the 802.1x (EAP) and PSK (password)-based networks are affected," he says.
Nine of the 10 vulnerabilities require attackers to be relatively sophisticated, he says. In order to exploit these flaws an attacker would need to use a MAC spoofing access point as a Man-in-the-Middle to manipulate data flowing between the client device and the real access point. "For the remaining, a practical exploit can be launched using a sniffer that can listen to and replay the frames over the wireless medium. So, it requires less attacker sophistication. "The main risk from all of them is replay of packets into the client or access point," Choskar says. "Another potential arising out of these exploits is the presence of packets in the air that are decryption-prone."
Gaurav Banga, founder and CEO of Balbix said the newly vulnerabilities, while present in a lot of products, should not be a cause of widespread panic. For one thing, it requires a sophisticated attacker and physical proximity in order to exploit. There has also been no sign of any exploit code in the wild so far and patches are available or will soon be available. "With iOS and Windows, the attack is quite difficult to pull off. Many of the security questions are around Android, since it is rarely patched," he says.
Users and organizations can mitigate the risk by using VPN over WiFi, avoiding websites that do not use HTTPS and updating their devices as soon as patches are released, he says.
Source: Darkreading
Intel Tiger Lake CPUs to come with Anti-Malware Protection
Intel’s Tiger Lake CPUs will come with Control-flow Enforcement Technology (CET), aimed at battling common control-flow hijacking attacks. I...
-
Last April, Steven Schoen received an email from someone named Natalie Andrea who said she worked for a company called We Purchase Apps. She...
-
Intel’s Tiger Lake CPUs will come with Control-flow Enforcement Technology (CET), aimed at battling common control-flow hijacking attacks. I...
-
By Carl Herberger This is Part 2 of our series on the top 5 most dangerous DDoS attacks and how you can successfully mitigate them. ATTAC...