Showing posts with label cybersecurity. Show all posts
Showing posts with label cybersecurity. Show all posts

Monday, April 10, 2017

U.S. Trade Group Hacked by Chinese Hackers ahead of Trump-Xi Trade Summit


Thursday, April 06, 2017 Swati Khandelwal


Researchers have uncovered a Chinese cyber-espionage against the United States ahead of the trade summit on Thursday between US President Donald Trump and China's President Xi Jinping.

According to a new report published today by Fidelis Cybersecurity firm, the Chinese APT10 hacking group implanted a piece of malware on the "Events" page of the US National Foreign Trade Council (NFTC) website in February.

Dubbed 'Operation TradeSecret,' the attack against the NFTC site is seen as an attempt to conduct surveillance on the main industry players and lobbyists closely associated with U.S trade policy activities.



Researchers say hackers placed a malicious link on the NFTC website, inviting the organization's board of directors to register for a meeting in Washington DC on March 7. But clicking on the link deployed a spying tool called "Scanbox."

Dates back to 2014, Scanbox – previously used by nation-state threat actors associated with the Chinese government – has the ability to record the type and versions of software a victim is running and run keyloggers on compromised computers, said Fidelis researcher John Bambenek.

"This attack was really at its core a reconnaissance attack. Anyone who visited this calendar entry would expose their software versions and use a JavaScript keylogger that could expose their identity," said Bambenek.
"Traditionally these attacks are used to precisely identify targets and help them craft targeted phishing attacks using exploits they know the victim is vulnerable to."The malicious link was active on the NFTC website between February 27 and March 1. The malware was already removed from the site by the time Fidelis contacted NFTC.



The NFTC's staff and board represent many influential people and companies -- from President Rufus Yerxa, the U.S. Ambassador to GATT to executives from major companies including Google, Amazon, eBay, IBM, Coca-Cola, Microsoft, Oracle, Cisco, KPMG, Pfizer, Visa, Ford, Halliburton, and Walmart.

Although Fidelis detected no further attacks on NFTC board members, the security firm believed the hackers were after a full range of entities relevant to the trade negotiations due to take place Thursday between US and China.

This is the second time in a week when APT10 cyber espionage campaign has come to light. A report released this week by BAE Systems, and PwC also claimed that APT10 was targeting managed IT services providers (MSPs) and their customers across the globe to steal sensitive data.

Saturday, April 1, 2017

WikiLeaks Vault 7 documents about vulnerable Cisco products exposes US govt’s stance on cyber security

WikiLeaks Vault 7 documents about vulnerable Cisco products exposes US govt’s stance on cyber security

Image Credit: REUTERS
When WikiLeaks founder Julian Assange disclosed earlier this month that his anti-secrecy group had obtained CIA tools for hacking into technology products made by U.S. companies, security engineers at Cisco Systems swung into action.
The Wikileaks documents described how the Central Intelligence Agency had learned more than a year ago how to exploit flaws in Cisco’s widely used Internet switches, which direct electronic traffic, to enable eavesdropping.
Senior Cisco managers immediately reassigned staff from other projects to figure out how the CIA hacking tricks worked, so they could help customers patch their systems and prevent criminal hackers or spies from using the same methods, three employees told Reuters on condition of anonymity.
The Cisco engineers worked around the clock for days to analyze the means of attack, create fixes, and craft a stopgap warning about a security risk affecting more than 300 different products, said the employees, who had direct knowledge of the effort.
That a major U.S. company had to rely on WikiLeaks to learn about security problems well-known to U.S. intelligence agencies underscores concerns expressed by dozens of current and former U.S. intelligence and security officials about the government’s approach to cybersecurity. That policy overwhelmingly emphasizes offensive cyber-security capabilities over defensive measures, these people told Reuters, even as an increasing number of U.S. organizations have been hit by hacks attributed to foreign governments.
Larry Pfeiffer, a former senior director of the White House Situation Room in the Obama administration, said now that others were catching up to the United States in their cyber capabilities, “maybe it is time to take a pause and fully consider the ramifications of what we’re doing.” U.S. intelligence agencies blamed Russia for the hack of the Democratic National Committee during the 2016 election. Nation-states are also believed to be behind the 2014 hack of Sony Pictures Entertainment and the 2015 breach of the U.S. Government’s Office of Personnel Management.
CIA spokeswoman Heather Fritz Horniak declined to comment on the Cisco case, but said it was the agency’s “job to be innovative, cutting-edge, and the first line of defense in protecting this country from enemies abroad.” The Office of the Director of National Intelligence, which oversees the CIA and NSA, referred questions to the White House, which declined to comment.
Across the federal government, about 90 percent of all spending on cyber programs is dedicated to offensive efforts, including penetrating the computer systems of adversaries, listening to communications and developing the means to disable or degrade infrastructure, senior intelligence officials told Reuters.
President Donald Trump’s budget proposal would put about $1.5 billion into cyber-security defense at the Department of Homeland Security (DHS). Private industry and the military also spend money to protect themselves.
But the secret part of the U.S. intelligence budget alone totaled about $50 billion annually as of 2013, documents leaked by NSA contractor Edward Snowden show. Just 8 percent of that figure went toward “enhanced cyber security,” while 72 percent was dedicated to collecting strategic intelligence and fighting violent extremism.
Departing NSA Deputy Director Rick Ledgett confirmed in an interview that 90 percent of government cyber spending was on offensive efforts and agreed it was lopsided. “It’s actually something we’re trying to address” with more appropriations in the military budget, Ledgett said. “As the cyber threat rises, the need for more and better cyber defense and information assurance is increasing as well.”
The long-standing emphasis on offense stems in part from the mission of the NSA, which has the most advanced cyber capabilities of any U.S. agency. It is responsible for the collection of intelligence overseas and also for helping defend government systems. It mainly aids U.S. companies indirectly, by assisting other agencies.
“I absolutely think we should be placing significantly more effort on the defense, particularly in light of where we are with exponential growth in threats and capabilities and intentions,” said Debora Plunkett, who headed the NSA’s defensive mission from 2010 to 2014.
Government Role
How big a role the government should play in defending the private sector remains a matter of debate. Former military and intelligence leaders such as ex-NSA Director Keith Alexander and former Secretary of Defense Ashton Carter say that U.S. companies and other institutions cannot be solely responsible for defending themselves against the likes of Russia, China, North Korea and Iran.
For tech companies, the government’s approach is frustrating, executives and engineers say. Sophisticated hacking campaigns typically rely on flaws in computer products. When the NSA or CIA find such flaws, under current policies they often choose to keep them for offensive attacks, rather than tell the companies.
In the case of Cisco, the company said the CIA did not inform the company after the agency learned late last year that information about the hacking tools had been leaked. “Cisco remains steadfast in the position that we should be notified of all vulnerabilities if they are found, so we can fix them and notify customers,” said company spokeswoman Yvonne Malmgren.
Side by Side
A recent reorganization at the NSA, known as NSA21, eliminated the branch that was explicitly responsible for defense, the Information Assurance Directorate (IAD), the largest cyber-defense workforce in the government. Its mission has now been combined with the dominant force in the agency, signals intelligence, in a broad operations division.
Top NSA officials, including director Mike Rogers, argue that it is better to have offensive and defensive specialists working side by side. Other NSA and White House veterans contend that perfect defense is impossible and therefore more resources should be poured into penetrating enemy networks – both to head off attacks and to determine their origin.
Curtis Dukes, the last head of IAD, said in an interview after retiring last month that he feared defense would get even less attention in a structure where it does not have a leader with a direct line to the NSA director. “It’s incumbent on the NSA to say, ‘This is an important mission’,” Dukes said. “That has not occurred.”
Reuters
Publish date: March 30, 2017 7:14 pm| Modified date: March 30, 2017 7:14 pm
×

Friday, January 6, 2017

CyberZeist, a hacker breaches FBI website and posts information on Pastebin

CyberZeist, a hacker breaches FBI website and posts information on Pastebin

Representational image
A hacker has claimed to have breached the US Federal Bureau of Investigation’s website and leaked personal account information to a public site, media reported. The hacker, known as CyberZeist, exploited a zero-day vulnerability in the highly-secured Plone Content Management System (CMS) of the FBI’s website and leaked some of the information to Pastebin, an open source site that is often used by hackers to post stolen information and bits of code, RT.com reported on Thursday.
A zero-day fault is a vulnerability in the code that has not been detected, listed, or patched yet. Therefore, the FBI had zero days to respond to the attack. This is not the first time the hacker claimed breaching the FBI site. In 2011, CyberZeist is believed to have hacked the FBI site as a member of a group known as Anonymous.
Authorities in the US have not yet responded to the recent hacking incident that was claimed to have occurred last month. “fbi.gov CMS Exploited, files in view – PasswordResetTool.py, product permissions, setup file. More coming soon #FBI #PWNED,” the hacker had tweeted on December 22.
“Don’t blame the #hacker, blame the faulty #code!,” CyberZeist had said in another tweet on December 27. CyberZeist warned other agencies that are currently using the Plone CMS that they too are vulnerable to a similar attack. “Amnesty acknowledges to patch the Plone #vulnerability in their CMS, just in time!,” CyberZeist said in a recent tweet.
IANS

Thursday, December 15, 2016

Synaptics has announced optical fingerprint sensors for Smartphones

Synaptics has announced optical fingerprint sensors for Smartphones

Synaptics, a human interface solution developer has unveiled “Natural ID FS9100” optical fingerprint sensor family for smartphone and tablets, which is capable of high-resolution scanning through 1mm of full cover glass and enables clean, button-free industrial designs. The FS9100 optical solution excels with wet finger performance, and being protected by glass, is durable, scratchproof, waterproof, and eliminates ESD concerns.
“Synaptics’ FS9100 family of fingerprint sensors represent a new breed of optical fingerprint sensor technology that is designed to meet the needs of mobile devices, including the ability to image through thick 2.5D glass,” said Anthony Gioeli, Vice President, Marketing, Biometrics Product Division, Synaptics, in a statement.
Unlike optical fingerprint sensors used for access control and public biometric identity verification, the advanced FS9100 sensor leverages unique Synaptics optical technology developed for mobile devices and breaks through key technical barriers with an extremely thin form factor and minimal power consumption. Natural ID FS9100 optical fingerprint sensors are designed for placement under the cover glass, including 2.5D glass, located in the front, bottom bezel of devices.
FS9100 optical fingerprint sensors feature Synaptics’ SentryPoint technology, offering OEMs a wide-range of unique and highly secure authentication features including Quantum Matcher with PurePrint anti-spoof technology. PurePrint examines fingerprint images using unique artificial intelligence technology to distinguish between fake and actual fingers, the company said.
Reuters

Nasscom Data Security Council: India can play important role in global cyber security

Nasscom Data Security Council: India can play important role in global cyber security

India can aspire to build a cyber security product and services industry of USD 35 billion by 2025, generating a skilled workforce of one million in the security sector, in line with the booming global demand, a report by Nasscom-Data Security Council of India today said.
The global cyber security market is expected to reach about USD 190 billion by 2025 from USD 85 billion currently, driven primarily by increasing digitisation wave and smartphone penetration, it said.
“For India to become a global cyber security hub, a list of 16 initiatives has been formulated by NASSCOM-DSCI. These initiatives vary in terms of priority and should be pursued within the next five years,” DSCI CEO Rama Vedashree said.
These include strengthening policy and regulations, developing skilled manpower, enhancing R&D and innovation, formation of clusters and funding startups working on cybersecurity solutions, she added. “An evaluation of global cyber security clusters shows that policy and financing incentives along with opportunities for skill development emerge as pivotal factors,” she said.
These clusters have contributed immensely to the development of the cyber security industry in the respective countries and are important to promote growth of cyber security startups and SMEs as well, Vedashree said.
PTI

Wednesday, December 14, 2016

Qualcomm follows many others in pointing out vulnerabilities of electronic financial transactions in India

Qualcomm follows many others in pointing out vulnerabilities of electronic financial transactions in India

How an ATM attack works. Infographic from Symantec's blog.
By 
Qualcomm has pointed out that most banking apps and mobile digital wallets in India do not use hardware-level security measures to ensure that the financial transactions are not compromised. Qualcomm is in the process of approaching the makers of such apps to integrate hardware level security features of Qualcomm chipsets into the applications. The sandboxing approach prevents any malware from affecting financial transactions.
There has been an increased focus on the security of electronic financial transactions, ever since a malware got into the systems of Hitachi Payment Services, which provides back end services to ATM machines and Point of Sale nodes across India. 32 lakh debit cards were compromised including those issued by SBI, HDFC, YES, AXIS, BOB and ICICI.
Security experts and consultants have pointed out various holes in the electronic transaction systems in place in India. ATMs need to implement state of the art encryption. The magnetic stripe cards need to be replaced with newer EMV chip cards, a global standard created by Europay, MasterCard, and Visa. ATM transactions are vulnerable to skimming and cloning attacks because of the continued use of the magnetic stripe cards. The databases of the banks themselves have to be adequately secured.
Intel has also warned that ATM machines in India are vulnerable to malicious attacks. Intel points out that countries in the Asia Pacific region are developing and are particularly vulnerable because of old systems and machines being used. The ATM machines tend to use outdated operating systems such as Windows XP, which makes them a easier target to execute malicious attacks against. Intel has also called for securing ATM machines with multiple levels of authentication and industry standard encryption.
The humans are the weakest link in the security chain, and there is a need for banks to educate users about phishing web sites, frauds, and scam emails. This is particularly important to users who are only starting to use digital wallets and banking apps after the demonetisation. The critical login credentials of users can be compromised by someone merely glancing at the screen and the app being used in a public place, a method of low-tech hacking known as shoulder surfing.
Antivirus solutions installed by users on their devices to protect financial transactions, actually end up making online banking less secure, according to researchers from the  Concordia University in Montreal, Canada. The anti virus software intervene in the regular operations of the browser and operating system, and can be used to fool the system with fake credentials. Commonly used security services were tested, and the researchers found that they lowered the levels of security normally provided by the browsers.
The hacking collective known as Legion has warned of weaknesses in the Indian Banking System. The group has said that it has the capability of hacking into financial systems, but has chosen not to do so. Legion has also said that there have been significant breaches in the past, but Banks have not alerted their consumers about it. There is no requirement by law to disclose data breaches to customers, the onus is on the Banks to do so.
However, it is not just amateur hackers who are a threat. There are serious cybercriminals and even the largest financial networks are susceptible to attacks. Swift has confirmed that hackers trying to get into the system have succeeded multiple times, and are continuously using newer and more sophisticated techniques. Swift has warned of consistent efforts by the group that pulled of the Banladesh Bank Heist to compromise the systems.
The laws in place are outdated, and need to be tweaked taking into accounts new developments. Digital wallets in India currently have no prescribed security standards, and are free to implement their own measures. There are no laws to hold the digital wallets responsible if something goes wrong during financial transactions.
Qualcomm senior director product management Sy Choudhury lauded the efforts by Aadhaar. The India Stack, which is a collection of APIs, which are ready to be integrated with applications and services. One of the aims of the India Stack is to ensure smooth and secure financial transactions. Unified Payment Interface (UPI), Aadhaar linked biometric identification, Unique Identification Authority of India (UIDAI), e-KYC, Aadhaar Enabled Payments System (AEPS) are all elements of the stack, that can improve security of transactions.

Related Posts Plugin for WordPress, Blogger...