Sunday, September 20, 2020

Billions of devices vulnerable to new 'BLESA' Bluetooth security flaw

 Billions of smartphones, tablets, laptops, and IoT devices are using Bluetooth software stacks that are vulnerable to a new security flaw disclosed over the summer.

Named BLESA (Bluetooth Low Energy Spoofing Attack), the vulnerability impacts devices running the Bluetooth Low Energy (BLE) protocol.

BLE is a slimmer version of the original Bluetooth (Classic) standard but designed to conserve battery power while keeping Bluetooth connections alive as long as possible.

Due to its battery-saving features, BLE has been massively adopted over the past decade, becoming a near-ubiquitous technology across almost all battery-powered devices.

As a result of this broad adoption, security researchers and academics have also repeatedly probed BLE for security flaws across the years, often finding major issues.



Monday, August 31, 2020

TrickBot Trojan: A Short Analysis of the Modular Banking Malware

 TrickBot is a well known modular banking trojan that sometimes acts as an info-stealer or malware dropper. Active since 2016, it has been updated several times with new features and modulations. Recently, it was used along with Ryuk ransomware to target several organizations.


Top targets

TrickBot is used in various attack campaigns to provide a gateway inside a targeted network and act as a dropper to deploy additional ransomware (e.g., Conti, Ryuk, and Emotet). However, it is mostly used to steal information from financial institutions located in the U.S.

In August 2020, it was used in Emotet’s spam campaign sending COVID-19 related emails to U.S. businesses.

In the month of July, TrickBot was observed being installed along with Emotet to infect Windows computers.

In April 2020, TrickBot operators were also observed to be taking advantage of the coronavirus pandemic by sending spam emails related to the Department of Labor FMLA theme.


Modus operandi

TrickBot used several techniques of propagation ranging from smishing, COVID-19 lures, and spam emails, to brute-forcing Remote Desktop Protocol (RDP) endpoints and using the mworm module.

TrickBot's Anchor malware platform known as “Anchor_DNS” was ported to infect Linux devices in July.

At the beginning of July, TrickBot started a new technique of evading detection by checking the screen resolutions of victims to identify if they are running virtual machines or not.

In early-June 2020, the TrickBot operators were found to be using the BazarBackdoor to gain access to targeted networks.


TrickBot Trojan: A Short Analysis of the Modular Banking Malware

Monday, August 17, 2020

Hackers targeted thousands of CRA, government service accounts in ‘credential stuffing’ attacks

 The federal government is warning Canadians not to reuse old passwords after thousands of accounts, including CRA logins, were targeted in a credential stuffing attack.

Hackers obtained and attempted to use the GCKey passwords and usernames of 9,041 people, the Treasury Board of Canada Secretariat said in a statement Saturday.

GCKey is the online authentication system that allows people access to Service Canada, Refugees and Citizenship Canada and more than two dozen other government departments.

For a third of the accounts affected, the hackers were successful in accessing government services online. Those accounts will be “further examined for suspicious activity,” the statement said.

As part of that attack and another recent incident, 5,500 CRA accounts were targeted.


STORY CONTINUES BELOW ADVERTISEMENT

The federal government said all compromised accounts have been disabled and those affected are being contacted. They will receive instructions on how to restore their GCKey or CRA MyAccount access.

Credential stuffing is a form of cyberattack that relies on databases of stolen login information made available through previous data breaches. The hackers use those credentials try to gain access to different online services.

Hackers targeted thousands of CRA, government service accounts in ...


Sunday, August 2, 2020

FSCA and cybercrime — making sure the guard dog is guarded

The digital age is characterised by rapid change and the introduction of pioneering solutions that have the power to make a real difference. Unfortunately, with these innovative solutions comes increased exposure to cybercrime — a fact many South Africans are intimately familiar with, given that more than nine attempted attacks take place every second.

The truth is that no individual or business is immune to the possibility of an attack. Addressing this risk and the catastrophic consequences that come from it requires an intensive approach, something we as the Financial Sector Conduct Authority (FSCA) are aware of, take seriously and are investing in. As the authority responsible for regulating the way SA financial firms conduct themselves, we are required to stay ahead of the curve.

Our cybersecurity technology investments need to be targeted, business-driven, and focused on mitigating the threats and vulnerabilities of our current operations. Improving our ability to detect and respond to cyber threats swiftly is core to what we do. This thinking is important for us to avoid incidents of stolen intellectual property, lost customer data, crippling ransomware and other forms of cybercrime. This is why we have adopted a risk-based approach in our cybersecurity strategy, supported by a dedicated team that is charged with ensuring its implementation.


Picture: 123RF/WELCOMIA

Tuesday, July 21, 2020

Security with a spin: How Xinja’s creating a secure bank in a digital age

Banking in Australia is changing, and quickly. 

The banking and finance sector has seen a flood of tech-driven neobanks and fintechs hit the market in recent years, and if the levels of interest these players have generated is anything to go by, Australians have a real appetite for change. 

In fact, according to a 2019 Mozo survey, one in four Aussies have switched or are considering switching to a neobank.

However, one of the biggest hurdles these digital players face is convincing consumers that the move to a digital-only platform won’t compromise safety and security. Hardly a surprise when money is on the line. 

So, to delve into the issue and learn more about how one of Australia’s leading neobanks is approaching all things security, we sat down with Jean-Baptiste Bres, chief information security officer at Xinja.

More than just money 
Cost, features, ease of use - these are all factors considered important by Australians when it comes to their banking experience. But as 42% of respondents in our 2019 neobank survey showed, the number one priority is security. 

So why is security important, and just what are banks protecting? 

As Bres explains, for a bank - especially a new bank - proving oneself on the issue of security is vitally important - particularly in building trust with customers. 

redactor/hero-images/1787/person-using-smartphone-to-pay_content.jpg

Monday, July 13, 2020

COVID heightening bank vulnerability to cyber attack

The “large-scale shift” to digital banking and remote work off the back of the COVID-19 crisis has heightened the banking sector’s exposure to cyber attack, according to Moody’s.

Over the past few months, banks, like most businesses, have leveraged digital technology to facilitate remote work in response to social distancing measures imposed to curb the spread of COVID-19.

However, according to Moody’s Investors Service, the transition has “increased banks’ vulnerability to cyber attacks”.

COVID heightening bank vulnerability to cyber attack - Report ...

Sunday, June 7, 2020

Cybersecurity: Beware! Coronavirus-themed attacks on the rise

New Delhi was among the top 10 cities in the world that recorded the highest number of cyber attacks during the two-month- long lockdown, with many of them coronavirus-themed attacks according to a report by digital technology provider Subex. India was among the top five most attacked countries in the region throughout the quarter. The country attracted attacks of relatively high quality (as compared to other regions and last year).

India was among the top five most attacked countries in the region throughout the quarter.

Monday, June 1, 2020

HOW FIS IS USING ARTIFICIAL INTELLIGENCE TO MONITOR AND PREVENT CYBER FRAUD

Business continuity amid the COVID-19 lockdown is a big issue for all companies. Firms are not just at risk of facing outages, but also face continuous data security vulnerabilities and cyber threats. As per a study by PwC, the volume of cyberattacks on Indian companies has gone exponential as cybercriminals utilise the new work paradigm brought about by the COVID-19 outbreak to infiltrate corporate networks and steal data. 

With the lockdown around the world, employees are expected to continue working remotely, which is undoubtedly a threat to most companies as the network perimeter has expanded radically. In the new work setting, fraudsters are using fake emails, websites, and VPAs (Virtual Payment Address) for fraud and social engineering.

Monday, May 25, 2020

rowing Threat of Destructive Attacks is One of the Top Cyber Risks Organizations Face

At a time of technological transformation and “cyber everywhere”, the attack surface for organizations is exponentially growing and cyber criminals are going after operational systems and backup capabilities simultaneously in highly sophisticated ways—leading to enterprise-wide destructive cyber attacks.

That’s one of the key findings of a report by consulting firm Deloitte released earlier this year, before the coronavirus pandemic and its related security threats had yet to make a significant impact on the world.

Growing Threat of Destructive Attacks is One of the Top Cyber ...

Monday, May 18, 2020

Recent cyber attacks just the tip of the iceberg for Australia

In a year already marred by natural and biological crises, cyber security failures remain a critical threat.

Government agencies and big Australian companies have fallen victim to cyber attacks with unprecedented visibility.

Industry and government need to understand why we are more exposed, what we can learn from recent national security events, and how to build a more cyber-resilient nation.

Recent cyber attacks just the tip of the iceberg for Australia

Monday, May 11, 2020

Cyber Security in Shipping during COVID-19 pandemic

The COVID-19 crisis has been testing the foundations of our lives, societies and economies posing huge challenges for the future. Organisations across industries are rightly focusing on their employees’ well-being, whilst making sure that their operations continue undisrupted and at the same time, adapting to the new ways of operating. Inevitably, secondary aspects of day-to-day operations such as cyber security may fall by the wayside, potentially increasing the risk of cyber security attacks. Cyber criminals are cognisant of the change in priorities, making the pandemic an attractive opportunity for them to make their way into corporate networks to steal data, money or cause disruption.

HSE finds recruiting cyber security staff 'difficult'

The Health Service Executive has said it is "especially difficult" to recruit cyber security staff right now because of the compet...