4.10.19

Hospitals in US, Australia hobbled by ransomware


 The incidents send medical staff back to the days of pen and paper
 Several hospitals in the United States and Australia have been paralyzed byransomware attacks, leading to the cancellation of all but the most urgent appointments and surgeries.
In the US, the outbreak affected three Alabama-based healthcare providers –

DCH Regional Medical Center, Northport Medical Center, and Fayette Medical Center. Early on Tuesday, all of them were hit by a ransomware strain known as Ryuk, said the DCH Health System, which operates all three facilities.
Ryuk – which is detected by ESET endpoint protection as a variant of Win64/Filecoder.T – has previously been used in other highly disruptive attacks, including one that resulted in printing and delivery delays for a number of US newspapers late last year.

All three affected hospitals have implemented emergency procedures to ensure the safety of their patients. The DCH has given assurances that the hospitals are “still able to provide critical medical services to those who need it”.

On the other hand, patients with non-emergency health needs were encouraged to seek assistance in neighboring medical facilities. Only elective procedures and surgical cases that had been scheduled for Wednesday went ahead as planned.

There is no word on the demands of the cyber-extortionists, according to an earlier press release that is no longer available on the DCH’s website. The new statement notes that the DCH is working closely with federal authorities and IT security experts on restoring its systems.

Meanwhile in Australia, the Victorian government announced on Tuesday that “a number of hospitals and health services” in the state had fallen victim to ransomware attacks on Monday. The affected healthcare providers are part of the Gippsland Health Alliance and the South West Alliance of Rural Health. At least seven major regional hospitals were impacted, according to The Age.
The government has deployed the Victorian Cyber Incident Response service to deal with the attack. The report states that computer systems in the affected hospitals have been isolated in order to quarantine the infection. The impacted systems include patient records, booking, and management systems.

According to a report published earlier this year by the office of the Victorian Auditor-General, Victoria’s public health system is highly vulnerable to cyberattacks like those that affected healthcare providers in Singapore and the United Kingdom (UK) in recent past.

The UK’s National Health System was crippled by WannaCryptor (aka WannaCry) in 2017, which cost the NHS £92 million (US$115 million). This prompted the NHS to bolster its cybersecurity posture and work on an infrastructure that would prepare it for any such future attacks.
A few years ago, ESET security researcher Lysa Myers brought up the issue of what healthcare organizations need to do to get their cybersecurity in order. More recently, she also looked at why successful ransomware attacks are symptomatic of a greater problem. Security advice on ransomware attacks is provided in our comprehensive white paper, Ransomware: An enterprise perspective.

In recent months, a number of US municipalities and other public entities have been hit particularly hard by ransomware attacks. Baltimore, for one, has spent a whopping US$18.2 million on restoring access to its systems. Twenty-three towns in Texas and two in Florida have also had their systems locked down and faced downtime due to ransomware recently.


2.10.19


Êtes‑vous bien sûr d’avoir nettoyé votre disque dur comme il se doit?
Une étude montre que près de 60% des disques durs d'occasion contiennent toujours des données résiduelles de leur ancien propriétaire.

Avez-vous déjà vu un film de pirates informatiques? Lorsque l’autre chaussure tombe, vous pouvez voir le hacker se précipiter vers son ordinateur, arracher ses disques durs et essayer de les effacer. Parfois, il va jusqu’à glisser des aimants au néodyme sur ces disques avant d’enfoncer une perceuse électrique directement dans les plateaux des lecteurs. Au pis, ils l’écrasent avec un marteau et espèrent pour le mieux.

Rassurez-vous, vous n’avez vraiment pas besoin d’écrabouiller vos disques sur tous les bords. Cependant, il est vrai que l’importance d’assurer la sécurité et la confidentialité de vos données en toutes circonstances. Une récente étude montre encore une fois l’importance de nettoyer adéquatement vos disques durs avant de vous en départir.

Cette étude, commandée par Comparitech et menée par l’Université du Hertfordshire, visait à déterminer dans quelle mesure nous sommes minutieux lorsqu’il s’agit d’essuyer nos disques durs avant de les vendre. Il s’avère que beaucoup d’entre nous ne sont pas très minutieux, voire aucunement.
Les chercheurs ont effectué une série de tests sur un échantillon de 200 disques durs d’occasion, achetés en ligne et chez divers marchands. Ils ont découvert que près de 60 % de ces disques durs contenaient encore des informations stockées sur eux par les anciens propriétaires.

Les informations restantes comprenaient des données sensibles qui pouvaient être exploitées par de mauvais acteurs. Les données allaient des documents officiels tels que les scanners de passeports et de permis de conduire, aux relevés bancaires et documents fiscaux, en passant par les demandes de visa et même les photos à caractère intime. La liste des documents découverts sur ces disques durs est beaucoup plus variée, mais c’est juste pour illustrer combien de données sensibles vous pouvez stocker sur vos disques durs, et sans trop y penser.

D’autre part, bien qu’il puisse sembler que les propriétaires soient indifférents à la sécurisation de leurs données, l’étude montre le contraire. Les anciens propriétaires ont essayé d’effacer leurs données, mais ils ne l’ont pas fait en toute sécurité. Seulement 26 % des disques ont été nettoyés correctement, ne permettant la récupération d’aucune donnée tandis que 16 % n’étaient pas accessibles et ne pouvaient être lus. Pour le reste, les données ont pu être récupérées avec plus ou moins de difficulté. Il est inquiétant de constater qu’une personne sur six n’a fait aucune tentative pour effacer les données.

Une étude similaire avait été menée en 2007. À l’époque, la quantité de données récupérables sur les disques durs d’occasion analysés était nettement inférieure. De plus, dans l’étude précédente, un nombre considérable de lecteurs se sont révélés illisibles. Compte tenu de cette tendance à la facilitation de récupérer les données sur les disques durs d’occasion, les vendeurs devraient aujourd’hui redoubler de prudence.

Vous pouvez toujours prendre des mesures préventives, la plus simple étant de crypter votre disque dur pour que vous puissiez dormir tranquille si vous le perdez. Quand il s’agit de faire le nettoyage du disque dur que vous voulez vendre, vous pouvez consulter le site Web du fabricant de votre disque dur. Celui-ci devrait inclure les outils qui vous permettront de gérer correctement le processus de nettoyage. Toutefois, avant de continuer, assurez-vous d’avoir sauvegardé toutes les données que vous voulez conserver.

Plus tôt cette année, des chercheurs de l’Université du Hertfordshire sont parvenus à des résultats assez semblables dans une étude récentes portant sur les clés USB usagées.

À propos de l’auteur : Amer Owaida est rédacteur en cybersécurité pour WeLiveSecurity.

19.9.19

Le premier espiongiciel d’un nouveau genre se faufile dans Google Play



ESET analyse le premier espiongiciel connu qui est construit sur l’outil d’espionnage open-source AhMyth et qui est apparu sur Google Play – deux fois.

Lukas Stefanko

Les chercheurs d’ESET ont découvert le premier espiongiciel (spyware) connu qui est construit sur les fondations du malware open-source AhMyth et a contourné le processus de validation des applications de Google.

L’application malveillante, appelée Radio Balouch aka RB Music, est en fait une application radio entièrement fonctionnelle pour les amateurs de musique balouchi, sauf qu’elle est livrée avec une très mauvaise surprise pour les utilisateurs – une fonctionnalité pour voler les données personnelles de ces derniers. L’application s’est glissée deux fois dans l’app store officiel d’Android, mais a été rapidement supprimée par Google à chaque fois après que nous avons alerté l’entreprise à ce sujet.

AhMyth, l’outil d’accès à distance open-source auquel l’application Radio Balouch a emprunté sa fonctionnalité malveillante, a été rendu public fin 2017. Depuis, nous avons été témoins de diverses applications malveillantes basées sur cette application, mais l’application Radio Balouch est la toute première à apparaître sur la boutique officielle des applications Android.

La solution de sécurité mobile d’ESET protège les utilisateurs d’AhMyth et de ses dérivés depuis janvier 2017 – avant même qu’AhMyth ne devienne publique. Comme la fonctionnalité malveillante d’AhMyth n’est pas cachée, protégée ou obscurcie, il est trivial d’identifier l’application Radio Balouch – et d’autres dérivés – comme étant malveillante, et de les classer comme appartenant à la famille AhMyth.

Outre Google Play, le logiciel malveillant, détecté par ESET sous le nom Android/Spy.Agent.AOX, était aussi disponible sur d’autres boutiques d’applications. De plus, un site Web dédié en assurait pour la diffusion, via Instagram et YouTube. Nous avons signalé la nature malveillante de la campagne aux fournisseurs de services respectifs, mais nous n’avons reçu aucune réponse.

Radio Balouch est une application de streaming radio entièrement fonctionnelle pour la musique spécifique à la région Balouchi (pour des raisons de cohérence, nous suivons l’orthographe utilisée dans la campagne; les transcriptions les plus courantes en anglais sont « Balochi » ou « Baluchi »). Cependant, l’application espionne ses victimes en arrière-plan.

Nous avons découvert deux fois différentes versions de l’application malveillante Radio Balouch sur Google Play. Dans chaque cas, l’application comptait plus de 100 installations. Nous avons signalé la première apparition de cette application sur la boutique officielle Android à l’équipe de sécurité de Google le 2 juillet 2019; elle a été retirée dans les 24 heures.

L’application malveillante Radio Balouch est réapparue sur Google Play le 13 juillet 2019. Comme auparavant, ESET a immédiatement avisé Google, qui l’a rapidement supprimée.


Universities warned to brace for cyberattacks



The UK’s cybersecurity agency also outlines precautions that academia should take to mitigate risks


The United Kingdom’s National Cyber Security Centre (NCSC) has issued a stark warning to universities across the country, urging them to be on their guards against cyberattacks.

The main risk is, in fact, two-fold. Firstly, it comes from ne’er-do-wells seeking financial gain via what are often untargeted attacks. When the attacks are targeted, however, they “have the potential for greater financial impact”, notes the cybersecurity agency.

“Cybercrime will probably present the most evident and disruptive difficulties for universities,” reads the threat assessment.

At the same time, however, the report sounds the alarm on a more silent threat, one that is “likely to cause greater long-term damage” – state-sponsored attacks and espionage. These incursions seek strategic gain and are aimed at intellectual property theft from institutions that house valuable research data and other assets, which is largely why they fall in the crosshairs of cyberattackers.

To defend against incursions, the universities are being urged to ensure they have a range of basic measures in place. This includes security-conscious policies and strict authentication and access controls, as well as making sure that university networks are designed with security considerations in mind. Still, the very first line of defense, as noted by the report, is “good security awareness among staff and students”.

Techniques may be evolving but, courtesy of their high success rate, attacks involving social engineering remain a staple. Indeed, a team of ethical hackers recently conducted simulated attacks at more than 50 universities in the UK and, in each case, got their hands on high-value data within two hours. As we also wrote back then, key to the 100-percent success rate was spear-phishing, a targeted form of phishing that involves sending a bespoke email to a well-researched prospective victim.

Here is our list of measures that educational institutions are well advised to take in order to defend against cyberattacks.


8.9.19



Firefox 69: Third‑Party Tracking Cookies and Cryptomining Now Blocked by Default

Firefox new Enhanced Tracking Protection (ETP) feature launched to all users of the browser to offer better privacy and protection from cryptojacking.

Protecting user’s privacy is a long-time preoccupation in IT security, and corporations are also taking action. We saw another example this week with Firefox Version 69.0. Since Tuesday September 3, third-party tracking cookies and cryptominers are now blocked by default for all Firefox users – on desktop as well as Android.

The feature, called Enhanced Tracking Protection (ETP), rolls out stronger privacy protections. The Mozilla Blog explains the specificity of this feature:

·         The default standard setting for this feature now blocks third-party tracking cookies and cryptominers.
·         The optional strict setting blocks fingerprinters as well as the items blocked in the standard setting.

While the announcement is important, we should note that this feature is not exactly new from Mozilla. It was already enable for new users since last June. However, it is now available for all users of the open-source Web browser.
Marissa Wood, Vice President of Product at Mozilla, explains: “Currently, over 20% of Firefox users have Enhanced Tracking Protection on. With today’s release, we expect to provide protection for 100% of ours users by default. “

The new feature targets third-party cookies, which are usually begetting by advertising networks. First-party cookies are not affected by this feature.
The second target of this feature is cryptojacking. In brief, cryptojacking is in brief the usage of a computer or device’ to mine cryptocurrency without the user’s knowledge. Cybercriminals instigate attacks in order to hijack digital currencies, or use compromise computer resources to mine cryptocurrencies unwittingly to the legitimate users of those devices. According to a recent survey, a third of British corporations have been hit this serious threat.

If you want to go further in protecting your privacy online, you might want to read these articles as well:





ESET door Gartner genoemd als enige ‘Challenger’ in zijn Magic Quadrant 2019, voor Endpoint Protection Platforms, voor het tweede jaar op rij

ESET, wereldleider in cybersecurity, werd genoemd als enige Challenger in de 2019 Gartner Magic Quadrant for Endpoint Protection Platforms*, voor het tweede jaar op rij. ESET werd geëvalueerd op basis van zijn uitvoeringscapaciteiten en de  volledigheid van zijn visie.

“Voor ons was een enorme prestatie om vorig jaar in de Gartner Magic Quadrant als enige uitdager te worden genoemd. Deze herkenning voor een tweede keer mogen ontvangen, bewijst onze vastberadenheid om voortdurend de beste endpoint bescherming, detectie en reactie aan de bedrijven te bieden,” verduidelijkte Ignacio Sbampato, chief business officer bij ESET. “ We zijn trots op onze aanpak dat gebaseerd is op vooruitstrevend onderzoek en visie om oplossingen te ontwikkelen die organisaties beschermen op een consistente en uitgebreide wijze. We zijn ervan overtuigd dat onze rangschikking te danken is aan onze voortdurende groei als een globale speler op het gebied informatiebeveiliging.

Sbampato vervolgt: “Sinds vorig jaar  heeft ESET zijn aanbod voor bedrijven versterkt met ESET Enterprise Inspector, een oplossing voor Endpoint Detection en Response, alsook ESET Dynamic Threat Defense, een cloud-gebaseerde  sandbox, die een complete Endpoint Protection Platform aanbiedt aan zijn bedrijfsklanten wereldwijd. Dit maakt deel uit van ESET’s strategie om zijn aanwezigheid in het bedrijfssegment uit te breiden.”

Van zijn positionering als Challenger  voor het tweede jaar op rij, denkt ESET dat het te danken is aan zijn capaciteiten om een gebruiksvriendelijk, uitgebreid en consistent eindpuntbeschermingsproduct te bieden en weerspiegelt zijn groeiend marktaandeel in alle segmenten die voor het bedrijf cruciaal zijn. Dit gaat van de bedrijven tot  de consument en de KMO’s. ESET is trots op de hoge graad van detectie en de kleine voetafdruk van zijn producten. Het bedrijf is ervan overtuigd dat de kwaliteit van zijn klantenservice zijn positie in Gartner’s Magic Quadrant zijn toewijding aan de best mogelijke service voor al zijn klanten benadrukt.

Volgens de IT-woordenschat van Gartner **, “Gartner’s Magic Quadrants bieden visuele snapshots, diepgaande analyses en bruikbaar advies die inzicht geven in de richting, maturiteit en spelers van een markt. Magic Quadrants vergelijken vendors op basis van de standaardcriteria en methodologie van Gartner. Elk rapport heeft een Magic Quadrant grafiek die een markt beschrijft met behulp van een tweedimensionale matrix waarin leveranciers geëvalueerd worden op basis van hun volledigheid van visie en capaciteit om die uit te voeren. "

Ontvang nu uw gratis exemplaar van het Gartner-rapport en bekijk de positionering van ESET in het Magic Quadrant op: https://www.eset.com/int/business/gartner-epp-mq-2019/ .

*Bron: Gartner, “Magic Quadrant for Endpoint Protection Platforms,” Peter Firstbrook, Dionisio Zumerle, Prateek Bhajanka, Lawrence Pingree, Paul Webber, 20 August 2019.
** Bron: Gartner IT Glossary, “Magic Quadrant,” 22 August 2019. https://www.gartner.com/it-glossary/magic-quadrant

Waarschuwing van  Gartner 
Gartner endosseert geen enkele leverancier, product of dienst die in zijn onderzoekpublicaties vermeld staan en geeft ook technologiegebruikers geen raad om uitsluitend de vendors te selecteren die de hoogste ratings of andere vermeldingen kregen. De publicaties van Gartner geven de opinie weer van Gartner’s onderzoeksteams  en moeten niet beschouwd worden  als feitelijke verklaringen. Gartner verwerpt alle waarborgen, expliciet en impliciet, wat zijn onderzoek betreft met inbegrip van waarborgen van verkoopbaarheid of geschiktheid voor een bepaald doel.

Voor het gratis e-book over gegevensbescherming, bezoek  https://www.eset.com/be-nl/zakelijk/data-protection-ebook/