Showing posts with label Cyber Attacks. Show all posts
Showing posts with label Cyber Attacks. Show all posts

Thursday, 15 March 2018

Meltdown Update For 32-Bit Versions Windows 7 and 8.1


Microsoft released two months after the unveiling of the Spectre and Meltdown attacks , which should protect users of the 32-bit versions of Windows 7 and Windows 8.1 against Meltdown. In addition, Intel microcode updates for various Intel processors have been rolled out.

At the beginning of January, the software giant already released security updates for the 64-bit versions of Windows. A Meltdown update for the 32-bit versions of Windows 10 followed on 18 January. Microsoft now announced that security updates for the 32-bit versions of Windows 7 and Windows 8.1 have also been made available to protect users from the Meltdown attack.

To be fully protected against Spectre and Meltdown attacks, systems require both software and firmware (microcode) updates, Microsoft said. That is why in early March it started to offer microcode updates from Intel via the Microsoft Update Catalog . Initially, it concerned updates for systems that have a Skylake processor and run the Windows 10 Fall Creators Update. Now, Microsoft has also made updates for Kaby Lake and Coffee Lake processors on the same platform.

Monday, 12 March 2018

Recent Adobe Flash Player Vulnerability Leak Attacked Via Exploit Kits



A recently patched vulnerability in Adobe Flash Player is being actively attacked via exploit kits. This means that visiting a hacked website or seeing infected ads with a vulnerable Flash Player version is sufficient to infect with malware.

The vulnerability in question was resolved by Adobe on February 6 through an emergency patch . The vulnerability appeared to have been targeted against South Korean organizations since last November . Here Excel and Word files with embedded Flash objects were used. Now it appears that cyber criminals also have the exploit to use them via the web.

Flash Player was and still is the most popular target for exploit kits. Due to the absence of new exploits, and the fact that more and more browsers are phasing out the support of Flash Player, the effectiveness of exploit kits has declined sharply in the past period . According to researcher Kaffeine of the Malware do not need coffee blog , this is the first new Flash exploit that has been added to an exploit kit since July 2016 for a Flash leak. The new Flash exploit will be deployed via infected ads and will successfully install the Hermes ransomware. Users are therefore advised to upgrade to Flash Player version 28.0.0.161 or later, as the vulnerability has been corrected.

Sunday, 11 March 2018

Leaked Source Code Ammyy Admin Uses For Malware



Source code of the remote desktop software Ammyy Admin has been used for malware that has been used for both targeted and large-scale attacks, according to security firm Proofpoint. Ammyy Admin is a program that allows remote access to computers.

Some time ago the source code of Ammyy Admin version 3 appeared on the Internet and cyber criminals have used it to develop malware called "FlawedAmmyy". This malicious version has been used in attacks since the beginning of 2016, but only recently discovered, Proofpoint says. Among other things, the automotive industry would be the target of the attacks.

To spread the malware, the attackers use e-mails that contain Word or ZIP files as an attachment. The Word files have a malicious macro that, when enabled by the user, downloads the malware on the system. Once active on a system, FlawedAmmyy can be used to steal trade secrets, customer data and other information from companies, according to the researchers.

Thursday, 26 October 2017

Infrastructure Behind BadRabbit Ransomware Since 2016 Active


The infrastructure used last Tuesday to spread the BadRabbit ransomware has been active since 2016, says Dutch security researcher Yonathan Klijnsma from security company RiskIQ. During the attack the attackers used a large number of hacked websites.

These websites showed a popup to visitors that they needed to install an update for Adobe Flash Player. In fact, it was a Petya ransomware variant that encrypted files on the hard drive and overwritten the Master Boot Record from the hard drive. As a result, the operating system can no longer be started. Furthermore, BadRabbit tries to spread on SMB via a list of commonly used passwords and intercepting login credentials via SMB.

On the hacked websites, code was sent to an injection server that showed the malicious popup on the websites. One of these injection servers was first observed last September. In addition, various hacked websites have been compromised since last year. RiskIQ counted 63 hacked websites where the attackers had access. The security company claims, however, that it can go for more websites.

"The group behind the BadRabbit ransomware has been active for quite some time," said Klijnsma. The researcher speaks of a long-term campaign that could possibly be set up for something other than BadRabbit. "Although the BadRabbit ransomware is brand new, we can track the distribution industry by the beginning of 2016, which shows that victims had been compromised a lot before before the ransomware hit and the news cycle began. The campaign could originally be set up for something other than BadRabbit. " Security company Symantec claims that 86 percent of the infections occurred in Russia and it mainly concerns companies.

Wednesday, 25 October 2017

Assault Modifies Dns Coinhive Using Reused Password


An attacker succeeded in adjusting the coinhive dns yesterday, making websites using the cryptominer a JavaScript file of the attacker's being. Coinhive is a cryptominer that uses the computer's computing power to cryptocurrency Monero through the browser. To do this, the computer performs a cryptographic calculation.

Owners of websites that want to use Coinhive must point to a coinhive JavaScript file on their website. This file is then uploaded by the visitor's browser, after which the computing power of their computer is used to perform the cryptographic calculation. The attacker was able to access the Coinhive Cloudflare account. Cloudflare is Coinhive's dns provider.

Then, the attacker changed the DNS settings, which forwarded requests for coinhive.com to another server. This server turned a custom version of the JavaScript file. This caused the attacker to benefit from the calculations made by website visitors, rather than the websites running Coinhive.

According to Coinhive , the Cloudflare account has been hacked through an unsafe password probably stolen at Kickstarter's hack in 2014. "Since then, we learned hard lessons about security and used two-factor authentication and unique passwords for all services, but have failed to update our years-old Cloudflare account," said Coinhive. We are now looking at ways to offset affected websites.

Tuesday, 24 October 2017

Ukraine And Russia Hit By Bad Rabbit Ransomware


Organizations in Ukraine and Russia have been hit by a new ransomware copy called Bad Rabbit, which would be a Petya ransomware variant that spread this summer, reports anti-virus company ESET. The malware would have infected hundreds of systems.

Among the victims are the Kiev metro, the Odessa airport and the Ukrainian ministries, according to the virus fighter. Anti-virus company Kaspersky Lab announces that most victims are in Russia. For example, the Russian press agency Interfax has been hit by the ransomware. The press office reports that the news services are not available because of the attack. "Based on our research, it is a targeted attack on corporate networks through methods similar to the ExPetr attack," said Kaspersky researcher Alex Perekalin. ExPetr is one of the names given to the Petya variant of this summer.

According to Kaspersky Lab, Bad Rabbit ransomware is spread through a number of hacked Russian media websites. ESET researcher Lukas Stefanko , Proofpoint researcher Darien Huss and the known anti-virus veteran Vesselin Vladimirov Bontchev warn that ransomware is on websites as an update for Flash Player . As soon as a user downloads and opens this so-called update, the Bad Rabbit ransomware will be activated on the system. Bad Rabbit tries to spread on the network. To do this, a list of common passwords is used, and Bad Rabbit tries to steal login data through the Mimikatz tool.

Bad Rabbit encrypts files and, like Petya, overwrites the Master Boot Record (MBR) of the hard drive. Therefore, the system becomes unusable. The ransomware claims victims 240 euros for decrypting the files. Whether victims pay the ransom to recover their files is still unknown. Organizations are advised to block executing files c: \ windows \ infpub.dat and c: \ windows \ cscc.dat and, if possible, disable Windows WMI service so that ransomware can not spread further .

Initially, ESET researcher Stefanko reported that the EternalBlue operation was also used. This does not appear to be the case at all. The article has been modified.

The attackers knew to hack several media and news sites. Then there was a malicious code that offered the so-called Flash Player update. Most infections have been observed in Russia, followed by Ukraine, Bulgaria and Turkey. According to ESET, all major companies are affected at the same time. "It is possible that the attackers already had access to the network and launched the attack through the websites at the same time as distraction," said Marc-Etienne M.Léveillé of ESET. He notes that there are no indications that employees of affected organizations have been stepped into the so-called Flash Player update. Anti malware company Malwarebytes announces that the attackers behind Bad Rabbit are likely to be responsible for the Petya / NotPetya variant of last June.

In the meantime, several technical analyzes of Bad Rabbit have appeared online. :

- Bitdefender

- Cisco

- ESET

- Kaspersky Lab

- Malwarebytes

- McAfee

- Qualys

According to Costin Raiu of Kaspersky Lab, the attackers behind Bad Rabbit would have been working on setting up the network of hacked websites since July. The attackers had access to, inter alia, Russian, Turkish, German and Bulgarian websites.

WordPress Sites Attacked Via Zeroday Leak In Plug-In




A zeroday leak in the WordPress plug-in Ultimate Form Builder Lite is actively used to attack and acquire websites before an update was available. Ultimate Form Builder Lite is a WordPress plugin for creating contact forms and runs on over 50,000 websites.

Vulnerability was discovered by security investigators of Wordfence.Wordfence already warned Zeroday leaks in three plug-ins, named Appointments, Flickr Gallery and Registration Magic-Custom Registration Forms, which were actively attacked. These three plug-ins were used in total by 21,000 websites. During the investigation of the attacks, the researchers discovered that attackers had also provided it with WordPress sites with Ultimate Form Builder Lite.

The attackers used SQL injection in combination with a php vulnerability. By sending one request, attackers could completely take over vulnerable websites. The developer of the WordPress extension was informed on October 13 and rolled out an update on Sunday, October 22, which solved the problem.

Wednesday, 5 July 2017

Cyber Security Council Wants More Companies To Be Notified Of Cyber Attack


The Cyber Security Council, the advisory body of the Cabinet when it comes to cyber security, wants more companies to be notified of a cyber attack, rather than just the vital sectors. According to Ron Moss, a member of the Council, the loss of Petya attack could have been less if companies such as APM Terminals and parcel TNT were warned before, let it faces BNR know.

In the case of the Petya-ransomware though there were no signs or information that the attack would take place, and the news was known until the outbreak had occurred. "If the attacks take place, then the damage is already done, then there is not much point to inform," said Ronald Prins of security firm Fox-IT. He points to the outbreak of the WannaCry-ransomware, which spread very rapidly. "And so there was no warning as possible."

D66 MP Kees Verhoeven endorses the opinion of the Cyber ​​Security Council and wants the government will implement it. "There could be considered a National Computer Emergency Response Team. A team which companies can exchange knowledge and information about cyber attacks." According to Verhoeven should be informed on the one hand on attacks and malware, but companies have on the other hand are structurally better prepared. "This is largely the responsibility of the companies themselves, but the government can play a supporting role. We have the National Cyber ​​Security Center. The infrastructure to do it so, but apparently works not yet."

Update


The opinion of the Cyber Security Council has now been published online ( pdf ). It calls for a nationwide system of information centers for information exchange covering all Dutch businesses. In addition, suppliers must of internet products and services have an active stance when it comes to offering safe products and have to do the simple declaration to cybercrime to the police.

Tuesday, 19 April 2016

Adobe: Flash Player Security Thwart Hackers


Adobe security measures in recent months have added to Flash Player ensures that hackers could not carry out successful attacks on the media player during a recent hacking contest, as the software company announced.

During the annual Pwn2Own contest hackers are rewarded for demonstrating unknown vulnerabilities in different browsers and Adobe Flash Player. During the last edition of March Flash Player was finally twice successfully hacked , but that number could be higher, says Peleus Uhley of Adobe. In preparation for the hack contest Adobe rolled several updates to enhance the security of Flash Player.

These measures paid off as several attempts to hack Flash Player failed thus said Uhley. Still, Flash Player has been successfully hacked twice. "These victories show that there is always more vendors can do to improve security," he continues. Uhley notes that companies such as Adobe, Microsoft and Google are engaged in a race with hackers.

Adobe invests in his own words than a lot of security and regularly adds features to thwart it. hackers as only goal. "Such measures are increasingly being added. The companies themselves will change on the frontline of this battle and to grow the more expensive." According Uhley help hacking contests like Pwn2Own software companies to develop. "While Pwn2Own each year seems to take the same required innovations and challenges to books every year results," said Uhley.

Thursday, 11 February 2016

Cyber Attack On US Tax System



One of the US IRS Tax system last month attacked by identity thieves who attempted to retrieve PINs that tax could be committed. The attacks were aimed at a web application that allows taxpayers, after entering their name, social security number, address and date of birth, their Electronic Filing (E-File) PIN to retrieve.

This PIN can then be used to apply for the tax refund. The identity thieves used the information to other parties was stolen to retrieve the PIN. In total, with 464,000 unique social security numbers tried to grab the code, which was successful at 101 000 social security numbers. According to the IRS , there was an automated attack. The Tax Administration claims that no taxpayers' data through IRS systems are won. In addition, the IRS will notify all individuals whose data were stolen by other parties.

Wednesday, 25 November 2015

Lenovo Used Insecure Password For Admin Account


Computer manufacturer Lenovo has released an update to the System Update tool that fixes two critical vulnerabilities could allow a local attacker to gain system or administrator rights. The software is installed on most Lenovo computers and checks for new versions of drivers and other software. Using the software, users can also download and install updates.

The first issue (pdf) in the System Update tool concerned the temporary system administrator account that Lenovo created.This account was generated in a predictable name and insecure password, which allows a local user could then gain admin privileges. The second problem (pdf) concerned a legal problem which allows a local unprivileged user could execute Windows commands with system privileges.

Both vulnerabilities were discovered by security firm IOActive in October and early November reported to Lenovo. The computer manufacturer came last week, 17 days after the notification, with an update to the System Update tool. Then are the details of the vulnerabilities now publicly made, including a proof-of-concept that shows one of the attacks. Lenovo users are advised to install version 5.07.0019 or later of the System Update tool.

Sunday, 15 November 2015

WordPress Websites Frequent Target Of Attacks


WordPress websites are this year more often been the target of attacks than in previous years and are attacked more frequently than other applications. According to a report (pdf) from security firm Imperva. Researchers at the company looked at attacks against websites and web applications. Then it appears that content management systems (CMS) are attacked three times more often than non-CMS applications.

However, when it came to WordPress 3.5 more attacks. Furthermore, WordPress was seven times more often the target of spam and Remote File Inclusion- (RFI) attacks than non-CMS applications. The problem of WordPress is according to Imperva that all plug-ins and extensions for CMS are developed without security to play a role there. This creates ever new vulnerabilities. In addition, WordPress also based on the PHP programming language, according to the security company.

Sunday, 1 November 2015

Pentagon Wants More Cyber Discipline At Workplace


The Pentagon wants employees to have more knowledge of Internet threats and has developed a plan for cyber discipline "in the workplace should provide. Terry Halvorsen announced that the Chief Information Officer (CIO) of the US Department of Defense.

Follow Halvorsen is important that as people go online, they do so with the appropriate rules and knowledge. To achieve this knowledge the Pentagon has developed a plan. "First we look at the basics, such as higher levels of education and more tools for common attacks such as spear phishing, setting up fake sites, things like that." The second step is mainly looked at it the more advanced threats and how they can be prevented. "It is the same combination of training, education and tools, but they are more advanced and you need more education and training." Also according to Halvorsen comes to teaching managers and ensure they know what their responsibilities are and what they need to know.

To bring the desired cyber discipline in card will the Pentagon to work with a scorecard, which measures how leaders, units and commanders do it. "Everyone is judged," said Halvorsen. The new policy has implications not only for the military, but also for suppliers, reports Federal News Radio. In addition, managers will also be held accountable for IT security problems.This relates to measures that both users and their commander accountable if there are violated basic rules for "cyber hygiene". How it will actually look Halvorsen did not know, but according to the CIO know people in the army of the consequences if they do not comply with the basic rules for cyber hygiene.

Tuesday, 27 October 2015

Ads On Porn Sites Spread Browser Ransomware


Visitors to porn sites have been warned of rogue ads that users of Internet Explorer forwarded to a page with browser ransomware. This ransomware encrypts files but locks the browser and that the user has committed a crime.

Also, the claims that the page of the user's files are encrypted, while this is not the case. Then there must be an amount of between 100 and 500 euros paid to regain access to the system. The criminals behind this ransomware use a vulnerability in Internet Explorer to determine whether it is a genuine user and not a sandbox or honeypot researchers.

The page locks the browser uses JavaScript to prevent the closing of the page. Even if users pay will not close the page.Using Task Manager browser lock can however be undone. The ads that direct visitors since August this year already active on porn sites and have the features, reports anti-virus company BitDefender.

Tuesday, 20 October 2015

US Defense Officials: Think Before You Click


US officials increasingly are targeted by so-called spear phishing attacks, reason for the US Department of Defense to issue a brochure with advice. The brochure follows two major break-ins at the Office of Personnel Management (OPM) earlier this year.

In addition, the data of millions of civil servants were stolen. The brochure explains how phishing attacks exactly and how phishing mails can be recognized. During an exercise of the army with a phishing test was a phishing email with a malicious Excel file sent to seven users. Two user opened the file, making the 'attackers' ultimate domain administrator on more than 6800 user and computer accounts were 5400. Officials are therefore given in the leaflet to stop the advice to first and think before they click on something.

Facebook Will Warn Victims Stands Hackers



Facebook users whose account was hacked by state-sponsored hackers or these are the target will now be alerted by Facebook. That's Chief Security Officer Alex Stamos of Facebook last week announced.

Where Facebook is a strong suspicion that, whether or not successful attacks on a Facebook account the work of hackers who work for a State, users receive a separate notice. "We do this because such attacks are more sophisticated and more dangerous than other attacks, and we encourage the users affected to take the necessary actions to secure all their online accounts," said Stamos. He notes that the warning does not mean that Facebook itself has been hacked.

According to the CSO, the warning is displayed when the computer or the user's phone as possible malware has become infected, causing the attackers then have the account hijacking. The warning also get affected Facebook users than the advice to "Login Approvals" enable, so others can not log into the Facebook account. In case it tries to log in from another account or other device is a security code sent to the user's mobile phone, so that only those can log on. Earlier decided Google to warn all users stands for hackers.

Monday, 19 October 2015

IBM Would Give China Access To Source Code


IBM would the Chinese authorities to allow access to the source code of various products so as to remove any worries about American backdoors away, so the claims Wall Street Journal according to two anonymous sources. IBM has not confirmed the reports.

According to the American newspaper, the Chinese authorities would some time have asked for access to the source code, to verify that the software inside backdoors are present so. IBM would have now acceded to the request and allowing Chinese officials to view the software in a secure room. However, the copying or parts of the source code is not allowed.

In a reaction to business magazine Forbes leaves a spokesman for IBM said that the company does "limited demonstration of certain aspects" of IBM's technology in highly secure environments. In IBM environments that are of administration and do not have connections with the outside world. However, it is unclear whether viewing the source code is covered by these demonstrations.

Thursday, 15 October 2015

Adobe Comes Up With New Emergency Patch For Flash Player Flaw


Adobe next week will release an emergency patch for a serious vulnerability in Flash Player that asset is used by attackers to infect computers with malware. The newest vulnerability in the software this week was discovered during attacks in various ministries.

The attacks took place via e-mails containing a link. The link pointed to a website with an exploit that used the vulnerability in Flash Player in order to infect the computer of the target. Adobe has now confirmed that the latest version of Flash Player, version 19.0.0.207, which is indeed a critical vulnerability has been used in a limited number of targeted attacks.

During the week of October 19 will Adobe therefore with an emergency patch to come. The zero-day vulnerability was reported on the very day that Adobe released version 19.0.0.207, where 13 vulnerabilities were fixed. According to anti-malware company Malwarebytes Now is the time to seriously consider switching from Flash Player in the browser or to remove completely from the computer.

Wednesday, 14 October 2015

Zero-Day Vulnerability In Latest Flash Player Active Attacked


In the latest version of Adobe Flash Player that came out yesterday is a zero-day vulnerability for which no update is available and actively attacked. Reported that the Japanese anti-virus company Trend Micro. Several foreign ministries would be attacked by the leak.

Victims receive a spear phishing email containing a link to a website. This website loads an exploit of the Flash Player flaw uses to install malware on the computer. The emails have subjects like: "Suicide car bomb targets NATO troop convoy in Kabul," "Syrian troops make gains as Putin defends air strikes", "Israel launches airstrikes on targets in Gaza", "Russia warns of response to Reported US nuke buildup in Turkey, Europe "and" US military reports 75 US-trained rebels return Syria ". Visiting such a malicious page with a vulnerable Flash Player is enough to get infected. There is no further interaction is required.

According to Trend Micro, the group behind the attack is also responsible for an attack in which a zero-day vulnerability was used in Java. Also, the group behind attacks on NATO, the White House, the German parliament and foreign ministries sit. The message of the anti-virus company coincides with the Tuesday patch from Adobe. Yesterday released a new version of Adobe Flash Player that 13 vulnerabilities were patched. Yet even Flash Player 19.0.0.207, the latest version now vulnerable to the observed attacks. Adobe would be informed of the new leak, but he has not yet written warning.

Saturday, 10 October 2015

China Arrests Hackers At The Request Of United States



Chinese authorities have arrested at the request of the US government several hackers allegedly broke into US companies. In addition, business secrets were stolen for the purpose by which Chinese enterprises play, so the reports Washington Post.

The arrests were made ​​two weeks before the visit of Chinese President Xi to be the USA, as is now known. Earlier, Susan Rice, National Security Advisor of the United States, announced that cyber espionage by China really had to stop. During his visit, Xi showed that China is not engaged in cyber espionage, and he wants to join forces with the US. In recent weeks, US intelligence and investigation agencies made ​​a list of hackers who were sought.

The list was then given to the Chinese authorities that led to the arrests of a handful of individuals. US officials are now wondering whether the Chinese authorities will prosecute the hackers. Earlier this week, the Financial Times said that the US authorities had three Chinese companies identified that have benefited in the past from cyber espionage. Something that denied two of the three companies.