25.4.20

iOS Mail app flaws may have left iPhone users vulnerable for years





A pair of vulnerabilities in the default email app on iOS devices is believed to have been exploited against high-profile targets.

By Amer Owaida

Apple’s iOS Mail app, which comes pre-installed on all iOS devices, has been found to contain two severe security vulnerabilities that, if exploited, could enable hackers to steal the victims’ data.

In fact, the attackers have leveraged these flaws for attacks against various targets, including a European journalist, a Japanese executive, and individuals from an undisclosed Fortune 500 company among others, said ZecOps researchers, who uncovered the flaws. Some of the attacks are thought to go back all the way to January 2018.

“Successful exploitation of this vulnerability would allow the attacker to leak, modify, and delete emails. Additional kernel vulnerability would provide full device access – we suspect that these attackers had another vulnerability,” said the company.

The security flaws allow attackers to remotely compromise a device by sending an email that will consume high amounts of the device’s memory – without actually requiring a large email to do so. The vulnerability can be triggered before the whole email is downloaded, although the trigger varies depending on the iOS version the device is running.

On devices running iOS 13, the vulnerability is triggered by an unassisted attack, also known as a ‘zero-click’ attack, which means the Mail app has to be running in the background. On iOS 12, meanwhile, the victim would have to click on the email. These aren’t the only two iOS versions vulnerable; devices running iOS 6 and above are all susceptible to the attack, while older versions haven’t been checked.
Once the vulnerability has been exploited, on iOS 12 the email app would appear to be sluggish and sometimes even crash. On iOS 13, it would manifest as a temporary slowdown of the mail app. In case of a failed attack, the emails send by the hacker would show “This message has no content.”

ESET Security Specialist Jake Moore said that the flaw is unlikely to have been used to target people en masse: “For complete remote access to occur under the radar it will have most likely been used for highly-targeted attacks on high-profile victims. Although this is a very professionally designed secret hack, it would be very unlikely that it was used on mass. Some flaws are kept even further underground amongst cybercriminals and keep certain exclusive vulnerabilities to themselves, so law enforcement and developers are kept in the dark – hence this particular defect has not been spotted for years. This particular flaw will be patched in the next update, so make sure you have your phone set to auto-update to the next version.”

The researchers alerted Apple to the two vulnerabilities and it has developed a fix that is currently available as iOS 13.4.5 beta. As a result, the patch is not readily available yet, since beta versions are mainly aimed at developers. For the time being, you can mitigate the issue by using other email clients.

Last year, Apple had to rush a fix for a FaceTime spying bug.

Following ESET’s discovery, a Monero mining botnet is disrupted



ESET researchers discover and play a key role in the disruption of a 35.000-strong botnet spreading in Latin America via infected USB drivers

By Alan Warburton

ESET researchers recently discovered a previously undocumented botnet that we have named VictoryGate. It has been active since at least May 2019 and, since then, three different variants of the initial module have been identified, in addition to approximately 10 secondary payloads that are downloaded from file hosting websites. The initial module is detected by ESET security products as MSIL/VictoryGate.

This botnet is composed mainly of devices in Latin America, specifically Peru, where over 90% of the compromised devices are located. We’ve been actively sinkholing several command and control (C&C) domains, allowing us to monitor this botnet’s activity. The combination of the sinkhole data and our telemetry data allows us to estimate the botnet’s size to be at least 35,000 devices.

To control its botnet, VictoryGate used only subdomains registered at the dynamic DNS provider No-IP. ESET reported the malicious subdomains to No-IP, who swiftly took them all down, effectively removing control of the bots from the attacker. Also, ESET is collaborating with non-profit Shadowserver Foundation by sharing sinkhole logs in an effort to further remediate this threat.


Read the complete article on:

https://www.welivesecurity.com/2020/04/23/eset-discovery-monero-mining-botnet-disrupted/?utm_source=feedburner&utm_medium=email&utm_campaign=Feed%3A+eset%2Fblog+%28ESET+Blog%3A+We+Live+Security%29

24.4.20

Buying a second hand device? Here’s what to keep in mind!




If you are trying to be responsible towards the planet, also be responsible to yourself and take these steps so that the device doesn’t end up costing you more than you’ve saved?

by Amer Oweida

 According to a report released by the World Economic Forum, the world produced an estimated 50 million tons of electronic waste in 2018. This figure is expected to double in the upcoming years if we don’t change our consumer behaviour. In a bid to reduce the stress on our planet, many people have started “going greener”. They have reduced their meat consumption, started to buy less “fast fashion” products and even increased their efforts in recycling… all in a bid to reduce their carbon footprint.

Another way to reduce waste and save your hard-earned money is by buying second hand electronic devices, notably computers and smartphones – an option that’s especially worth discussing since today is Earth Day.
However, purchasing a second hand device bears a certain risk since you don’t really know what the device has been through and how it has been used over its months or years of service. But the risks can be mitigated; read on.

Buying the device
When you’re choosing to buy a used device, you have a variety of sources to choose from. The first and probably the best choice is buying a refurbished device from an authorized seller. This basically means that the device has been cleaned and checked by the seller, both from the hardware and software sides. In some cases, you might even get a warranty on the device, which saves you from a headache if it starts failing shortly after purchase.

Alternatively, the other choice is resorting to buying from advertising websites and online marketplaces. In this case, you probably won’t have a chance to inspect the device personally before you order it. If you opt for this scenario, you should definitely use a reputable marketplace that has security measures to deal with scammers. Research the seller, look at their reviews and ask them questions about the device. When you’ve made up your mind, you should use a payment service that has purchase protection just to be safe.

What to do if I bought a second hand computer?
If you didn’t buy refurbished, then purchasing the computer or laptop is just half of the battle. Now you have to check if everything is in running order. You basically purchased a cat in a bag and you shouldn’t just rush into using the computer. If you turn it on it already has a running operating system, you don’t rush headlong into downloading your favourite programs or go about checking your social media. First, check that there aren’t any remnants of the previous owner’s data on the hard drive. Then try downloading and installing a reputable endpoint security product to scan the computer.

“Why?” you may ask. Well, you have no other reasonable way of knowing whether the seller installed any malicious code on the computer in an effort to defraud you. The computer may have a key logger installed to gain access to the credentials of all your accounts or perhaps some other form of malware that can steal your data and transfer it to a remote server. Alternatively, any of the previously mentioned things can be present due to the owner failing to take the right precautions.

A green option – compared to replacing the hard drive in the computer with a new one – would involve wiping the drive. Hard drive manufacturers offer utilities that allow you to wipe your drive with varying degrees of security ranging from a single overwrite to multiple passes with random data and even specific security protocols. Once you’ve chosen and done one or the other, you should proceed and do a clean install of the OS of your choice. Adding an endpoint security solution to your computer for added protection will be more than a nice final touch, and you should be ready to go.

What to do if I bought a second hand smartphone?
As with the case of computers, the same logic applies for smartphones: if you haven’t bought it refurbished with a warranty, you have to get your hands dirty. After the smartphone checks out and has no signs of hardware damage, it’s time to see how the software is doing. If you start it up and it readily goes through the booting process and doesn’t walk you through a setup process, you should immediately be suspicious. The former owner may have been lazy and not gone through the wiping process properly or alternatively or the device may contain some form of malware.

To wipe the phone securely, start by checking whether all of the services have been signed out; once you’ve done that, you should remove all the accounts associated with the phone. The next step is to encrypt the phone’s data. Since you don’t know what kind of data has been stored on the phone, it’s probably safer that way. You’ve finally made it to the factory reset step. The name of the option may vary from manufacturer to manufacturer but in the end, it should always do the same thing: reset the smartphone to factory settings. That means that everything is deleted or wiped, and it should revert to the state it was in when it came out of the box.

Hopefully these tips will help you on your quest to buy a second hand device and we applaud you for being responsible to our planet. After all, it is the only one we have.

21.4.20

Work from home: should your digital assistant be on or off?





Being at your beck and call is central to the “personality” of your digital friend, but there are situations when the device could use some time off.

Do you start the day with “Alexa, what’s the weather today?”

Many of you may have a digital friend at home, an Amazon Alexa, Google Assistant, Apple’s Siri or Microsoft Cortana (does anyone actually use this?). Has your digital friend ever interrupted your conversation or randomly spoken up despite not being hailed? The answer is likely to be yes, and your response has probably been just to dismiss the interruption as unwanted.

 

Just say the word(s)

A recent study by Imperial College London and Northeastern University examined how many times digital assistants activate without the wake-up word being used. The devices were subjected to 125 hours of Netflix content from numerous shows; the verbal content was analyzed with the closed caption text from the show to remove the instances when an actor may have used the actual wake-up word. The devices wrongly interpreted a word and activated up to 19 times per day.

The experiment was repeated 12 times with the same content and the result showed little to no consistency, less than 9% of all the “misheard” dialog that activated a device did so in 75% or more of the replication runs. Some devices activated on word patterns or specific letter sounds – for example, Alexa activated on words that contain a “k” and sound similar to Alexa, such as “exclamation” or “Kevin’s car”. Not being able to replicate the test result consistently suggests that there is a level of randomness to the unwanted activations. So, don’t take it personally the next time your digital assistant interrupts.

When the digital assistant is awoken and springs into life, the interaction is captured so it can be analyzed and the instruction, if there is one, is acted upon. Some of the systems retain a voice recording or a text transcript of the interaction either until you decide to delete it or the vendor’s policy removes it, based on time or other criteria.

At the moment of an unexpected activation, or if you don’t want any other activation stored, then each assistant has the ability to delete the last interaction. For example, if during a TV show the device mistakenly awakens, a response from you of “Alexa – delete what I just said” will remove the last interaction. For the more privacy conscious then, an “Alexa – delete everything I said today” might be part of the good night routine.

If you have introduced the digital assistant to additional digital friends, such as a home automation system, then the interaction is analyzed and the instruction or request is transferred to the third party. What data is being shared with the third party will depend on the functionality of the additional services or devices.
Your digital friend is listening constantly, is activated on demand or randomly and is potentially storing the interaction forever. And in some circumstances, maybe chatting with other digital friends to fulfill your requests. If only human friends were that attentive.

So, how does this relate to working from home?


Hopefully, you have adopted a routine and start work at a regular time and maybe even kick-off with a team call to sync with colleagues. I suspect that, like me, you then have a varied set of calls and video meetings throughout the day; some more sensitive than others. If you work in a collaborative open office space in normal circumstances, then you probably utilize a private space to participate in the more sensitive or confidential calls to avoid any inadvertent sharing of information.

But what if you’re working from home and know that the digital assistant is constantly listening, is extremely attentive, and is not an employee of the company bound by any confidentiality agreement? Then additional caution beyond what you practice in the office should be applied.

When conducting a sensitive call while working from home, switch off the digital assistant’s microphone and camera to avoid potentially sharing sensitive material. If you find it difficult to adopt an “as needed” approach to switching the digital friend off, I recommend giving your digital assistant the day off while you work.

The risk is not only from oversharing with your digital assistant’s vendor; there is also a risk that a bad actor could gain access to your account or, worse still, inflict a data breach on the vendor and have access to all previous interactions.

This could have been a short article, unplug the digital assistant, open the front door and throw it in the street, but I know my own paranoia will probably not resonate with that many of you.

ESET has been here for you for over 30 years. We want to assure you that we will be here in order to protect your online activities during these uncertain times, too.
Protect yourself from threats to your security online with an extended trial of our award-winning software.

Try our extended 90-day trial for free.


17.4.20

InterSystems lance une nouvelle version de la plate-forme de données InterSystems IRIS ®


La nouvelle version du logiciel leader du marché facilite encore plus le développement et le déploiement d'applications en temps réel, basées sur l'apprentissage automatique, qui relient les données et les silos d'applications
Cambridge, Mass. - InterSystems, un fournisseur de technologies de données créatives dédié à aider les clients à résoudre les problèmes les plus critiques en matière d'évolutivité, d'interopérabilité et de vitesse, vient d’annoncer la disponibilité d’une nouvelle version  de la plate-forme de données InterSystems IRIS® (InterSystems IRIS® data platform). Il s’agit de la troisième version majeure d'InterSystems IRIS, la plateforme de données phare de l'entreprise, qui permet aux entreprises de résoudre leurs problèmes les plus critiques d’interopérabilité, d’évolutivité et de vitesse.
InterSystems IRIS propose maintenant une version bêta d'IntegratedML, permettant aux développeurs d'applications et d’SQL de développer des algorithmes d'apprentissage automatique (ML) et de les intégrer de manière simple, intuitive et évolutive dans des applications sophistiquées. IntegratedML améliore aussi la productivité des scientifiques qui traitent des données en automatisant une grande partie du travail fastidieux nécessité par le développement d'algorithmes d'apprentissage automatique.
« Cette nouvelle version de la plate-forme InterSystems Iris accroit son utilité pour développer des applications hautes performances, basées sur l'apprentissage automatique, qui couvrent les données et les silos d'applications », explique Scott Gnau, responsable plates-formes de données chez InterSystems. « Nous continuons à piloter la plate-forme en fonction des besoins de nos clients qui mettent activement en Å“uvre leurs initiatives de transformation numérique. »
En plus du lancement d’IntegratedML, InterSystems IRIS Data Platform 2020.1 comporte des fonctionnalités avancées et des améliorations de performances significatives. Celles-ci sont :
·       Rapidité et évolutivité. La nouvelle version améliore encore les performances et l'efficacité. Ces performances ont été testées pour être jusqu'à 200 fois plus rapides que celles d’autres technologies de gestion des données. De plus, elle permet aux utilisateurs de faire évoluer plus facilement les déploiements et cela avec des capacités supplémentaires pour la gestion d’environnements distribués.
·       Cloud et déploiement. Désormais, InterSystems IRIS propose des améliorations supplémentaires qui étendent et simplifient la prise en charge du cloud public et privé, du déploiement multi-cloud, sur site, hybride et les options cloud tout comme le support améliorée de Kubernetes.
La nouvelle version d’InterSystems IRIS comporte également une amélioration de l’interopérabilité, de la sécurité et des  fonctionnalités et simplifie la migration à partir d'autres technologies de gestion des données. InterSystems IRIS Data Platform 2020.1  est disponible dès maintenant.
Pour en savoir plus et pour recevoir gratuitement la  version d’essai, visitez https://gettingstarted.intersystems.com/.

16.4.20

ESET Foundation ondersteunt Slowaakse onderzoek tegen COVID



Vorsers van de Slowaakse bedrijven MultiplexDX, Lambda Life en ProScience Tech werken samen met virologen van het Biomedical Research Center van de Slovak Academy of Sciences (BMC SAV) om een reagenskit te ontwikkelen volgens de protocollen van de Wereldgezondheidsorganisatie (WHO) voor betrouwbare detectie van SARS-CoV-2.
In een eerste fase zijn ze van plan 100.000 PCR-tests te produceren en beschikbaar te stellen. De ESET Foundation heeft de ontwikkeling van de kit ondersteund en zal de eerste 100.000 tests financieren, die als donaties in natura aan de Slowaakse Republiek zullen worden aangeboden.
Sleutelcomponenten werden aan het project toegevoegd door MultiplexDX, een bedrijf gespecialiseerd het ontwikkelen en producuren van innovatieve moleculaire diagnostische reagentia. De Slowaakse PCR-test wordt gevalideerd in samenwerking met een team wetenschappers van BMC SAV. De voorlopige resultaten van de nieuwe test laten niet alleen nominale functionaliteit zien, maar ook een goede gevoeligheid in vergelijking met de momenteel gebruikte diagnostische tests. “Door betrouwbaarheid en precisie te combineren, is het mogelijk om met onze test patiënten in een vroege fase te diagnosticeren. We zijn in staat om de belangrijkste componenten voor 100.000 PCR-tests binnen twee weken te produceren ”, aldus Pavol ÄŒekan, oprichter van MultiplexDX.
"Als onderdeel van de validatie en registratie van het rapport werken we samen met CCCT SK, een non-profitorganisatie. Deze fase duurt ongeveer drie weken ', zegt Adam Andráško van ProScience Tech.
"De detectie van het virus bestaat uit het nemen van een staal, het isoleren van het RNA en het uitvoeren van een diagnostische PCR-test, waarbij onze gezamenlijke inspanningen gericht zijn op deze laatste stap", verduidelijkt Ivan Juráš van Lambda Life.
"Ik ben ervan overtuigd dat de inspanningen van onze wetenschappers succesvol zullen zijn en dat we genoeg PCR-tests zullen laten produceren uit eigen middelen voor de detectie van coronavirus. Zo  zullen we niet alleen Slowakije kunnen helpen door de nodige tests uit te voeren, maar ook een reserve creëren in geval van een tekort aan tests op wereldvlak, ”zegt Robert Mistrík, lid van de permanente crisisstaf.
De ESET Foundation ondersteunt de ontwikkeling van de test en financiert de eerste 100.000 eenheden voor een effectieve diagnose en preventie van COVID-19. Deze tests worden geschonken aan Slowaakse openbare instellingen. 'Het doel van deze schenking  is om op grote schaal een effectieve diagnose mogelijk te maken, wat alleen kan door wetenschappelijke samenwerking. De huidige crisis geeft het belang aan van ondersteuning van de wetenschap in Slowakije, waar de ESET Foundation zich al lang voor inzet ', aldus Richard Marko, CEO van ESET.
De productiecapaciteit - inclusief de eerste 100.000 tests - wordt voornamelijk ter beschikking gesteld aan Slowaakse diagnose labo’s. “We zijn bereid om samen te werken met openbare labo’s door flexibel in te spelen op hun behoeften en door hen op een efficiënte manier tests te leveren. Als we aan de behoeften van Slowaakse labo’s hebben voldaan, kunnen we onze producten vervolgens aanbieden aan andere landen die ze nodig hebben ", aldus de testontwikkelaars.

15.4.20

Is global Privacy an oxymoron?




While in France a citizen of Brazil who resides in California books a bungee jump in New Zealand. Is it a leap of faith into the unknown for both the operator and the thrill-seeker?

By Tony Anscombe

The internet has created truly global markets for businesses that would have once remained local and may have struggled to reach a large enough audience to be profitable. Access to any website, from nearly anywhere in the world, and the willingness of the business behind it to engage with customers and deliver services or products to faraway places, has revolutionized business opportunities for entrepreneurs.

This increased opportunity brings about many challenges – for example, checkout, payment options and tax regulations may differ from country to country. Fortunately, businesses can utilize a number of outsourcing service providers and rely on them to provide the needed expertise for e-commerce and payment systems that comply with local laws and regulations. The entrepreneur is then free to focus on delivering goods or services to customers. This opens the opportunity for even the smallest business to trade on a global basis.

Conducting business online typically requires the collection of data about customers and visitors to a web site; this takes the form of web analytics, newsletter subscriptions, ad targeting, or it may be a service subscription or product purchase. Depending on the location of the business, and the location, residency or citizenship of the visitor or customer, the company may need to comply with data privacy legislation. As a consumer, I am an advocate for the need to protect my personal information through robust legislation, but companies doing global business may be stepping into a minefield.

In February I delivered a presentation at CyberSecCon2020 in Auckland, New Zealand on the lessons learned around the requirements of the data privacy regulations of both the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA) ahead of the forthcoming New Zealand Privacy Bill, which is currently working its way through the legislative procedure and is expected to become law in the coming months.
There are over 100 countries in the world having some form of data privacy legislation, ranging from limited all the way through to robust. Then add do that a number of countries, like the USA, that have individual legislation state-by-state. This is a complex subject!

Taking a leap of faith
Let’s imagine a fictional customer – Francisco – a citizen of Brazil, who is a legal resident of California and travels frequently on business. Francisco has decided to check off a life goal and bungee jump in the home of bungee, New Zealand. He travels from California to France on business and will then travel to New Zealand, but while in France he books a bungee experience with a company based in New Zealand.
·       For the purpose of my example, let’s imagine that 50,000 California residents a year visit the bungee business in New Zealand. As a California resident, Francisco is protected by CCPA, since the legislation applies to the state’s residents regardless of where they, or the businesses they are transacting with, are located.
·       The transaction was initiated in France, a country that is part of the European Union (EU). The EU’s GDPR legislation covers anyone located in an EU country at the time of the personal information being collected.
·       The website Francisco is transacting with is based in New Zealand, where the proposed legislation applies to agencies (businesses) located there.

Which legislation should the company in New Zealand comply with? Last year when I asked a similar hypothetical question of someone in the European Commission, they responded with “that’s a great question”.
The confusion is likely to exist from Francisco’s perspective as well. As a Brazilian citizen, he may think that the Brazilian General Data Protection Law (LGPD) provides protection, or that as a California resident the CCPA provides his protection.

Let’s extend the hypothetical scenario: Francisco returns home to California and requests the bungee company to delete his personal information and they refuse or fail to confirm the request. To which regulator should he make a complaint? It’s highly probable that consumers may not understand their rights when companies are in countries where they are not residents, or they could assume the process to be too complicated when a company holding their personal data is in another country.

Each of the regulations in my example has different requirements: the GDPR is opt-in for data collection, the CCPA is opt-out. The GDPR states that data must be encrypted; CCPA and the proposed New Zealand Privacy Bill both state that reasonable security measures should be taken but do not specify any further detail. The differences in the requirements are numerous and in the unfortunate instance of a data breach occurring, who should be notified, and could fines be levied by multiple regulators in different countries? And which of the several legal systems will apply, or will several? There may be legal precedent for which regulation takes priority, but this is not clear to me, a non-lawyer.

Confused? Probably. I know I am!
Our entrepreneur from earlier needs clarity so that data privacy does not inhibit anyone from conducting business in any location. And consumers should be able to visit any business online with assurance that there is protection of their data and accountability regardless of where they or the business is located, including in countries without specific legislation.

One rule to ring them all
The internet is a global marketplace and there are some existing data privacy agreements in place that attempt to provide a baseline. These are limited in participation and regional; a list can be found on the Electronic Frontier Foundation website.
Is it time for one common set of rules on data privacy regardless of residency, citizenship or location? There is precedent for such rules; for example, 123 countries signed the World Trade Organization’s (WTO) Marrakesh Agreement in 1994, which regulates international trade between nations. If we accept that data is now a commodity item that has a value and is traded, then maybe it could be included in a standard agreement, in the same way the WTO regulates trading rules. A truly international standard would need to adopt core principles and countries could always supplement these with their own amendments, in the same way countries adopt trade agreements between each other on top of the current WTO standard.

I am using the WTO as an example, but there are numerous global organizations where a centralized data privacy agreement could reside. Probably the most important element of any widely agreed international regulation would be defining which regulator is responsible and when, clarifying whether a citizen, resident or their location takes precedence or whether a business is responsible by location or place of transaction.

At CyberSecCon2020, all the attendees I talked to were clearly engaged in preparing for the New Zealand Privacy Bill, but at a security conference covering data privacy this is probably to be expected. It’s the people who don’t attend that are the challenge. Many companies may want to comply and have a desire to sell and transact globally but are confused about what they should comply with.

There are core principles for data privacy that are common in the majority of the regulations and legislation:
·                 The reasons why personal information is collected, where it is collected and how it is          collected.
·                How the personal information is protected from unauthorized access and how the data is stored.
·               The right for an individual to know what personal information is being held about them.
·              The ability to request the correction of inaccurate data and the right to request data be deleted.
·               Limitations on how organizations can use the information collected.

Unfortunately, the same core principles are not so clear when it comes to security requirements, as some legislation details specific requirements and others talk about “reasonable” security. Prior to the CCPA taking effect in January, I co-authored a white paper that gives a view on what could be considered essential security requirements. I recommend that any business collecting or storing data follows the principles listed in the ESET’s guide to reasonable security section of that white paper.