Tuesday, February 13, 2018

Week 10 - Olympic Destroyer Disrupts the Opening Ceremony


On Feb 9th, before the opening ceremony for the Winter Olympics in South Korea, there was a cyber attack on the Olympic IT infrastructure. The attack lasted about 12 hours and caused damage to systems, monitors, WIFI, and website. Some components were not reachable or disabled, causing much inconvenience for those involved in preparing for the big day. Also, some people could not print tickets which resulted in low attendance for the ceremony.

After security investigations, it was found that the attack was caused by a fast-spreading malware called the Olympic Destroyer. The worm can quickly jump from one machine to another, and shut down services, destroy data, and erase the boot record. The systems were unusable after a reboot. It seems the malware had 44 usernames and passwords in the code that originated from the domain pyeongchang2018.com. By using PSExec and Windows query language, the malware could obtain more credentials by searching browser’s data and system memory. The behavior of the malware is very similar to NotPetya and BadRabbit that targeted Ukraine’s systems, so Ukraine’s government, CIA, and other security firms think that this attack has ties to Russian hackers (GreenBerg, 2018). Also, since Russia has been banned from the Olympic games for the user of performance-enhancing drugs, they have a motive for the attack. Others are accusing North Korea of the attacks, but the country has nothing to gain from the intrusion.

If you are attending the Olympics game, be aware that there might be some technological challenges because there might be ongoing cyber attacks. If there are delays on the Olympic websites, be patient. And, beware of Olympic scams through email.

References


Greenberg, A. (2018, Feb 12). Olympic Destroyer Malware Hit Pyeongchang Ahead of Opening Ceremony. Retrieved from https://www.wired.com/story/olympic-destroyer-malware-pyeongchang-opening-ceremony/

Perlroth, N. (2018, Feb 12). Cyberattack Caused Olympic Opening Ceremony Disruption. Retrieved from https://www.nytimes.com/2018/02/12/technology/winter-olympic-games-hack.html

Sarkar, S. (2018, Feb 12). The Winter Olympics’ systems were hacked during Friday’s opening ceremony. Retrieved from http://www.techradar.com/news/the-winter-olympics-systems-were-hacked-during-fridays-opening-ceremony

Tuesday, February 6, 2018

Week 9 - Take Caution in the Use of Grammarly


Last Friday, Tavis Ormandy, a Google Project Zero researcher disclosed that there was a vulnerability in the popular grammar checker, grammarly.com.  The vulnerability allowed third-party websites to access the authentication token of Grammarly accounts which in turn allowed access to all the user’s documents, history, and website information. An authentication token allows repeated entry to the same website without entering credentials every time. This makes it convenient for users to leave the site and come back at another time. However, in this exploit, Mr. Ormandy shows that it was possible to use a script to create tokens that allow access to Grammarly accounts.

The security breach is devastating because there are 20 million users of the Grammarly application on Chrome and 645,000 users on Firefox. (Kovacs, 2018). However, after Grammarly was notified of the vulnerability, they patched it within a few hours. They also go on to say that there was no evidence that user information was compromised. The vulnerability affected only the text saved on the website, but not the keyboard editor, Microsoft add-in, or text typed in other sites.

If you use Grammarly, you don’t have to take any actions. All components of the software will be automatically updated. However, this is a warning to all users of the software. Be cautious of what is being exposed to the grammar checker. If the document or website is confidential, it is probably best to not use the application. The tool is excellent for checking school documents and is a great supplemental aid for writing. However, sensitive information should not be exposed to Grammarly.

References

Armasu, L. (2018, February 6). Grammarly Bug Could Have Exposed User Data To Any Visited Website. Retrieved from http://www.tomshardware.com/news/grammarly-bug-exposes-user-data,36464.html

Kanaracus, C. (2018, February 5). Grammarly Patches Chrome Extension Bug that exposed users' Docs. Retrieved from https://threatpost.com/grammarly-patches-chrome-extension-bug-that-exposed-users-docs/129794/

Kovacs, E. (2018, February 6). Grammarly Rushes to Patch Flaw Exposing User Data. Retrieved from http://www.securityweek.com/grammarly-rushes-patch-flaw-exposing-user-data

Wednesday, January 31, 2018

Week 8 - Malware Attacks Target Winter Olympics in South Korea


At the start of this year in 2018, about a month before the Winter Olympics begins in South Korea, email infected with malware have been targeting organizations associated with this big event. Initially, the infected emails were targeting groups related to air hockey but have since expanded to all businesses related to the Olympics. The goal of the malware campaign is to steal personal and financial information.

The methodology behind delivering malware through email has greatly improved and is harder than ever to be detected. Companies are aware of the dangers of phishing emails and have enacted security campaigns to counter this threat, but these malware emails are even more difficult to differentiate from regular mail. The spoofed email is in Korean and claims that it is from South Korea's National Counter Terrorism Center (NCTC) even though it originated from an address in Singapore. The emails were also timed to be delivered when the NCTC were conducting their security drills, so businesses were inclined to believe it came from them.

Last year in December, a new method of hiding malware in images were introduced. With this new tool released to the public, Invoke-PSImage allows PowerShell scripts to be hidden in a PNG image. With this ability to hide malware components, the image could be delivered through email.  The recipients would open the image and execute the malware on their computers.

It’s more important than ever to be wary of opening images or text in emails. Even though the file does not seem to be malicious, it can still contain malware. Before opening attachments in emails, it is advised to review the header information and confirm the identity of the sender. If something looks off in the email, report it to the local administrator or delete the email. Phishing emails are becoming difficult to spot, and we must be extra cautious against these malware attacks.

References


AFP. (2018, Jan 6). Hackers Already Targeting Pyeongchang Olympics: Researchers. Retrieved from http://www.securityweek.com/hackers-already-targeting-pyeongchang-olympics-researchers


Riley, D. (2018, Jan 7). Hackers are already targeting the PyeongChang Winter Olympics. Retrieved from https://siliconangle.com/blog/2018/01/07/hackers-already-targeting-yeongchang-winter-olympics/


Samani, R. (2018, Jan 9). Pyeongchang Olympics Hack: Attackers Evolve Beyond Zero Days. Retrieved from https://www.forbes.com/sites/ciocentral/2018/01/09/pyeongchang-olympics-hack-attackers-evolve-beyond-zero-days/#39e00134ef61

Monday, January 22, 2018

Week 7 - RubyMiner Takes Control of Web Servers


On the week of January 8th, many web servers were hit by the malware, RubyMiner which attempted to take control of servers and install the Crypto mining software. Using vulnerabilities from PHP, Microsoft IIS, or Ruby on Rails, the malware could install the Monero miner (XMRig). Since the popularity and rise of cryptocurrency, attackers have been looking for computers to mine crypto coins. Initially, desktop machines were used, but more recently, web servers were targeted for their CPU power. In just one day on Jan 11th, about 700 servers were enslaved to make $540 (Checkpoint Research, 2018).

The malware can be executed on Windows or Linux systems, and has affected web servers in the United States, Germany, United Kingdom, Norway, and Sweden. On vulnerable web servers, the malware downloads and runs the robots.txt file which installs the crypto mining software. Since the malware is instructed to run hourly, the attackers can issue a kill command at any time by modifying the robots.txt file. So far, the compromised domain, lochjol.com is being used for attacks. The Monero miner usually sends 5% of the proceeds to the author of the code, but the attackers have removed that piece of the code to retain all the currency.

Since attackers are utilizing known vulnerabilities that were patched in 2012 and 2013, web server owners should quickly review and update their servers. Also, the incident of compromises should be reviewed so that intrusion detection system can be updated to catch the malware. As the crypto mining software continues to run, it will use up all the resources for the web server and decrease its performance. Also, the attackers are making currency for free with no overhead expenses. Go and update your web servers today!

References
Arghire, I. (2018, Jan 17). Crypto-Mining Attack Targets Web Servers Globally. Retrieved from http://www.securityweek.com/crypto-mining-attack-targets-web-servers-globally

Checkpoint Research. (2018, Jan 11). ‘RubyMiner’ Cryptominer Affects 30% of WW Networks. Retrieved from https://research.checkpoint.com/rubyminer-cryptominer-affects-30-ww-networks/

Monday, January 15, 2018

Week 6 - Equifax's Massive Data Breach


How do you feel safe when one of the three largest credit reporting agencies is compromised? On September 2017, Equifax reports that they discovered a data breach of 143 million accounts which exposed names, social security numbers, birth dates, bank accounts, addresses, and driver licenses. About 209,000 credit cards were also stolen. The information not only impacted US citizens but people in the UK and Canada. The data breach was discovered in July 2017, but it was reported six weeks later. To make matters shadier, three senior executives sold almost 1.8 million shares of Equifax before and after the security breach. It is believed that the attacker used a website application vulnerability to steal the data (Yurieff, 2017).

The Equifax breach was one of the largest data breaches in history. Now, half of all American information is probably on the dark web. Equifax is trusted to record all credit activities and to report on them. We should have confidence that they will also secure that vital information. I’m glad to see that Equifax created a website for the breach. The site at https://www.equifaxsecurity2017.com checks if a person is impacted by the attack. Since many people were compromised, don’t be alarmed if your name appears on the site. Equifax is offering a one-year credit monitoring service to people who might have their information exposed. However, usage of the service also forfeits any legal action against Equifax.

How to protect your credit? From time to time, check the credit reports and look for suspicious activities such as new credit cards and bank accounts. Report any suspicious activities. For more credit protection, it’s possible to freeze an account. Then new accounts can only be opened with the account holder’s approval. You can never be too safe.

References

Gressin, S. (2017, Sept 8). The Equifax Data Breach: What to Do. Retrieved from https://www.consumer.ftc.gov/blog/2017/09/equifax-data-breach-what-do
 
USA today. (2017, Sept 12). At Equifax, a Category 5 data breach. Retrieved from https://www.usatoday.com/story/opinion/2017/09/12/equifax-category-5-data-breach-editorials-debates/657362001/
 
Yurieff, K. (2017, Sept 10. Equifax data breach: What you need to know. Retrieved from http://money.cnn.com/2017/09/08/technology/equifax-hack-qa/index.html

Tuesday, January 9, 2018

Week 5 - Former Employee of Homeland Security Exposes Employee Records


On January 3rd, the Department of Homeland Security (DHS) announced that they had a data breach of 257,167 former and current employees. The breach was discovered on May 10, 2017, and it affected employees who were working in 2014. The exposed data included names, social security numbers, birth dates, positions, grades, and duty stations. Also, the exposure affected people who were part of the DHS Office of Inspector General’s investigations from 2002 to 2014. DHS states the data breach was not an external attack and the personal information was not the primary target (Kaplan, 2018). The cause of the exposure was a former employee of the DHS who accessed unauthorized information.  In December, the DHS notified employees who might have been affected. They waited about seven months for notification because there was a criminal investigation that was going on during that period.


This incident was unusual because it was not an external actor that caused the data breach, but a former employee who did not have authorized access. Still, a dangerous case because the former employee could have sold the information to a third party. Also, these are employees of DHS who protect the security of the citizens of the United States. Some of the personnel could be targets of social engineering to obtain privileged information, or important cases could be put at risk because identities were exposed.


I’m glad to hear that DHS is taking extra steps to secure the employee data, and that access will be restricted to select individuals. Also, unusual behavior patterns by authorized users will be monitored (Kaplan, 2018). DHS is offering credit monitoring to those that are affected by the data breach. For those who were part of the OIG’s investigations between 2002 to 2014, they can contact AllClear ID for free credit monitoring at 855-260-2767.


References


Arghire, I. (2018, Jan 4). 247,000 DHS Employees Affected by Data Breach. Retrieved from http://www.securityweek.com/247000-dhs-employees-affected-data-breach


Cameron, D. (2018, Jan 3). Homeland Security Data Breach Affects 240,000 Federal Employees, Plus Witnesses and Interviewees. Retrieved from https://gizmodo.com/homeland-security-data-breach-affects-240-000-federal-e-1821755817


Kaplan, P. (2018, Jan 3). Privacy Incident Involving DHS Office of Inspector General Case Management System. Retrieved from https://www.dhs.gov/news/2018/01/03/privacy-incident-involving-dhs-oig-case-management-system

Tuesday, January 2, 2018

Week 4 - Nissan Canada Notifies Customers of a Data Breach During the Holidays


This holiday season, Nissan Canada Finance and Infiniti Financial Services Canada were not so lucky and reported a data breach on December 21st. The automaker is not sure how many customers were affected by the breach and notified all 1.13 million of them by email or letter. Nissan found out about the attack on December 11th which included the loss of information such as customer’s name, address, vehicle model, vehicle identification number, credit score, loan amount, and monthly payment. It seems that no payment or contact information (email address, phone number) were taken (Spring, 2017). Nissan is working with law enforcement, security analysts, and Canadian privacy regulators to find out the cause of the breach and who was affected. This incident was not the first time that Nissan has come under attack by hackers. Their websites were attacked in 2016 and malware was detected on their infrastructure network in 2002.

It’s alarming that so much information could be taken from customers of Nissan. The automaker had previous encounters with hackers and should bolster their security technology and teams. Performing vulnerability scans and addressing issues could make systems more resilience to hackers. Also, perhaps, the data could be separated into different systems, so a compromise of one system will not impact the others.

As we head to 2018, it seems that personal information is all over the dark web. There have been a countless number of data breaches, and it has affected all industries. It seems to be one of the risks of doing online business. Nissan has offered Transunion, a fraud monitoring tool for one year to all their customers. If you are affected, please take advantage of the service and be aware of suspicious activities.

References

Kovacs, E. (2017, Dec 22). Nissan Canada Informs 1.1 Million Customers of Data Breach. Retrieved from http://www.securityweek.com/nissan-canada-informs-11-million-customers-data-breach

Nissan. (2017, Dec 21). Nissan Canada Finance informs customers of possible data breach. Retrieved from http://nissannews.com/en-CA/nissan/canada/releases/nissan-canada-finance-informs-customers-of-possible-data-breach

Spring, T. (2017, Dec 22). Nissan Canada Finance Notifies 1.1 Million of Data Breach. Retrieved from https://threatpost.com/nissan-canada-finance-notifies-1-1-million-of-data-breach/129233/