15.9.21

What is a cyberattack surface and how can you reduced it?


 Discover the best ways to mitigate your organization’s attack surface in order to maximize cybersecurity

 By Phil Muncaster

 In almost all coverage of modern breaches you’ll hear mention of the “cyberattack surface” or something similar. It’s central to understanding how attacks work and where organizations are most exposed. During the pandemic the attack surface has grown arguably further and faster than at any point in the past. And this has created its own problems. Unfortunately, organizations are increasingly unable to define the true size and complexion of their attack surface today—leaving their digital and physical assets exposed to threat actors.

Fortunately, by executing a few best practices, these same defenders can also improve their visibility of the attack surface, and with it, gain enhanced understanding of what’s necessary to minimize and manage it.

What is the corporate attack surface?

At a basic level, the attack surface can be defined as the physical and digital assets an organization holds that could be compromised to facilitate a cyber-attack. The end goal of the threat actors behind it could be anything from deploying ransomware and stealing data to conscripting machines into a botnet, downloading banking trojans or installing crypto-mining malware. The bottom line is: the bigger the attack surface, the larger the target the bad guys have to aim at.

Let’s take a look at the two main attack surface categories in more detail:

The digital attack surface

This describes all of an organization’s network-connected hardware, software and related components. These include:

Applications: Vulnerabilities in apps are commonplace, and can offer attackers a useful entry point into critical IT systems and data.

Code: A major risk now that much of it is being compiled from third-party components, which may contain malware or vulnerabilities.

Ports: Attackers are increasingly scanning for open ports and whether any services are listening on a specific port (ie TCP port 3389 for RDP). If those services are misconfigured or contain bugs, these can be exploited.

Servers: These could be attacked via vulnerability exploits or flooded with traffic in DDoS attacks.

Websites: Another part of the digital attack surface with multiple vectors for attack, including code flaws and misconfiguration. Successful compromise can lead to web defacement, or implanting malicious code for drive-by and other attacks (ie formjacking).

Certificates: Organizations frequently let these expire, allowing attackers to take advantage.

This is far from an exhaustive list. To highlight the sheer scale of the digital attack surface, consider this 2020 research into firms on the FTSE 30 list. 

Full article on www.welivesecurity.com


BladeHawk group: Android espionage against Kurdish ethnic group

ESET researchers have investigated a targeted mobile espionage campaign against the Kurdish ethnic group. This campaign has been active since at least March 2020, distributing (via dedicated Facebook profiles) two Android backdoors known as 888 RAT and SpyNote, disguised as legitimate apps. These profiles appeared to be providing Android news in Kurdish, and news for the Kurds’ supporters. Some of the profiles deliberately spread additional spying apps to Facebook public groups with pro-Kurd content. Data from a download site indicates at least 1,481 downloads from URLs promoted in just a few Facebook posts. The newly discovered Android 888 RAT has been used by the Kasablanka group and by BladeHawk. Both of them used alternative names to refer to the same Android RAT - LodaRAT and Gaza007 respectively.

BladeHawk Android espionage The espionage activity reported here is directly connected to two publicly disclosed cases published in 2020. QiAnXin Threat Intelligence Center named the group behind these attacks BladeHawk, which we have adopted. Both campaigns were distributed via Facebook, using malware that was built with commercial, automated tools (888 RAT and SpyNote), with all samples of the malware using the same C&C servers.

Distribution

We identified six Facebook profiles as part of this BladeHawk campaign, sharing these Android spying apps. We reported these profiles to Facebook and they have all been taken down. Two of the profiles were aimed at tech users while the other four posed as Kurd supporters. All these profiles were created in 2020 and shortly after creation they started posting these fake apps. These accounts, except for one, have not posted any other content besides Android RATs masquerading as legitimate apps.

These profiles are also responsible for sharing espionage apps to Facebook public groups, most of which were supporters of Masoud Barzani, former President of the Kurdistan Region; an example can be seen in Figure 1. Altogether, the targeted groups have over 11,000 followers.

Read full article on www.welivesecurity.com




7.9.21

 

Faille dans la preuve vaccinale québécoise : analyse

Les chercheurs d’ESET expliquent les détails d’une faille découverte dans VaxiCode Vérif, l’application mobile permettant la vérification des preuves vaccinales québécoises.

Marc-Etienne M.Léveillé

La sortie d’applications mobiles permettant le stockage et la vérification du passeport vaccinal par le gouvernement du Québec (VaxiCode et VaxiCode Vérif) a fait couler beaucoup d’encre la semaine dernière. C’est avec raison; l’application VaxiCode Vérif sera utilisée par tous les commerçants de services non essentiels dès le 1er septembre 2021.

Comme plusieurs autres, j’ai analysé le contenu du code QR dès que je l’ai reçu lors de mon premier vaccin en mai dernier. La semaine dernière, j’ai aussi analysé les deux applications établies par le gouvernement du Québec et développées par Akinox.

Ce blog explique comment fonctionne le système de passeport vaccinal mis sur pied par le gouvernement du Québec d’un point de vue technique, ainsi que les détails sur la vulnérabilité que nous avons trouvée dans l’application VaxiCode Vérif qui permettait de forcer l’application à reconnaître comme étant valides des codes QR non émis par le gouvernement. À l’heure actuelle, il est impossible de confirmer qu’il s’agit de la même faille trouvée par « Louis » telle que rapportée par Radio-Canada vendredi dernier, puisqu’aucun détail technique n’a encore été publié.

Nous avons nous-mêmes rapporté la vulnérabilité que nous avons trouvée à Akinox dimanche, et nous avons confirmé que la mise à jour de VaxiCode Vérif 1.0.2 pour iOS publiée dans les derniers jours corrige la faille. La version Android des applications n’a pas encore été analysée, mais VaxiCode et VaxiCode Vérif utilisent le cadriciel Expo qui permet de produire des applications iOS et Android en utilisant le même code source. Les applications sur les deux platformes sont donc probablement équivalentes.

Détaillons le contenu du passeport vaccinal québécois

Lisez la suite de l’article sur :

https://www.welivesecurity.com/2021/08/31/faille-preuve-vaccination-quebec-vaxicode-verif/?utm_source=feedburner&utm_medium=email&utm_campaign=Feed%3A+eset%2Fblog+%28ESET+Blog%3A+We+Live+Security%29

30.8.21

Man impersonates Apple support, steals 620,000 photos from iCloud accounts. ESET explains.

 


 By Amer Owaida

The man was after sexually explicit photos and videos that he would then share online or store in his own collection

A California man has fessed up to breaking into the Apple iCloud accounts of hundreds of individuals and downloading more than 620,000 images and 9,000 videos while on the prowl for nude photos of young women. He would then share or trade these images online or keep them for his own collection.

Hao Kuo Chi, a 40-year-old citizen of La Puente, Los Angeles County, pleaded guilty to four counts including committing computer fraud, according to a report by the Los Angeles Times. Going by the online handle “icloudripper4you”, he billed himself as being adept at infiltrating iCloud accounts and pilfering their content, an activity he referred to as “ripping”.

According to his plea agreement, Chi was able to access the iCloud accounts of at least 306 victims from around the United States. After investigators searched his house, he also admitted to infiltrating some 200 accounts at the behest of individuals that he had met online.

 “Chi acknowledged in court papers that he and his unnamed co-conspirators used a foreign encrypted email service to communicate with each other anonymously. When they came across nude photos and videos stored in victims’ iCloud accounts, they called them ‘wins,’ which they collected and shared with one another,” reads the Los Angeles Times report.

To achieve his goal, Chi contacted his victims and duped them into parting with their Apple IDs and passwords by masquerading as an Apple customer support agent using various email accounts. The Federal Bureau of Investigation (FBI) said that it was able to pinpoint two Gmail addresses that were used to trick victims – “applebackupicloud” and “backupagenticloud”, which contained in excess of half a million emails. These included some 4,700 emails with iCloud user IDs and passwords that Chi received. According to the FBI, Chi had over 620,000 photos and 9,000 videos, which were partly organized based on whether they contained explicit images or not.

How to keep your Apple account secure

Phishing campaigns are one of the favorite tools in a cybercriminal’s tool bag. Over the years, online fraudsters have been finetuning their ruses, so much so that many schemes may be difficult to spot even for the trained eye. However, there are still multiple steps you can take to keep your accounts secure:

·       If you receive an unsolicited email from a service you supposedly use, scrutinize the email address; if it didn’t come from an official support address (in this case Gmail) you’re most probably dealing with a scam.

·       Look out for bad spelling and numerous grammar mistakes, more often than not, phishing emails are riddled with them.

·       Always enable two-factor authentication (2FA), which acts as an extra layer of security and makes it harder for cybercriminals to infiltrate your account even if they have access to your password. Apple allows you to use one of your Apple devices as an authentication factor by displaying a verification code on it. Besides trusted devices, you can also set up trusted phone numbers by following Apple’s handy guide to their 2FA settings.

If you want to take a deep dive into the tell-tale signs of phishing, read our article on how to recognize phishing messages. If you’d like to test yourself on whether you’re adept at spotting the phish, you can take our phishing quiz.

 

26.8.21

Hackers swipen bijna $ 100 miljoen van grote cryptomunten-uitwisselingsplatform




Het Japanse cryptomunten-uitwisselingsplatform Liquid is het slachtoffer geworden van ondernemende hackers die zijn ‘warm wallet’ hebben gecompromitteerd en er vandoor gingen met meer dan US $ 97 miljoen aan verschillende cryptomunten-activa.

 "Op 19 augustus, rond 07:50 uur SGT, ontdekten Liquid's Operations & Technology-teams ongeautoriseerde toegang tot enkele van de crypto-portefeuilles die bij Liquid worden beheerd", leest het incidentenrapport (incident report) van het bedrijf.

Het bedrijf zei op Twitter (said on Twitter) dat de aanvallers zijn zogenaamde ‘warm wallet’ hebben gecompromitteerd. Voorlopig werden cryptomunten en activa naar een ‘cold wallet’ verplaatst. Ondertussen heeft Liquid alle stortingen en opnames van cryptomunten opgeschort, terwijl het incident onderzocht en de impact ervan beoordeeld wordt. Gebruikers hebben nog steeds toegang tot fiat-opnames en stortingen, alsook tot de andere diensten van het platform.

Ter verduidelijking : ‘hot-wallets’ zijn cryptomunten-portefeuilles die verbonden zijn met het internet en basistransacties makkelijker maken. ‘Warm wallets’ lijken erg op ‘hot wallets’, maar ze zijn afhankelijk van lokaal geïnstalleerde software en hebben verbeterde beveiligings- en identiteitsverificatiecontroles.

‘Cold wallets’ zijn offline en vaak op hardware gebaseerde portefeuilles- en verreweg de veiligste optie. Eigenaars van cryptomunten kunnen doorgaans  best het merendeel van hun investeringen in een ‘cold wallet’ houden en slechts een klein deel van hun cryptomunten in een ‘hot wallet’ opslaan voor dagelijkse transacties.

De dader(s) achter de aanval werden nog niet geïdentificeerd. Volgens de blog, in het Japans, van Liquid (Liquid’s blog) leidt de aanvalsvector naar een gecompromitteerde portefeuille gebruikt door QUOINE, zijn Singaporese dochteronderneming. Het Japanse uitwisselingsplatform schat dat in totaal 69 verschillende cryptomunten-activa verduisterd zijn en naar andere uitwisseling of DeFi swapping-locaties doorgestuurd werden.

Volgens een analyse (analysis) door het blockchain-analysebedrijf Elliptic konden de hackers meer dan 97 miljoen US $ aan verschillende cryptomunten-activa stelen. "Dit omvat $ 45 miljoen aan Ethereum-tokens, die momenteel omgezet worden in Ether met de hulp van gedecentraliseerde uitwisselingplatformen en (DEX's) zoals Uniswap en SushiSwap. Zo voorkomt de hacker dat deze activa bevroren worden - wat mogelijk is met veel Ethereum-tokens, "aldus Elliptic.

Een blijvend probleem

Cryptomunten-uitwisselingsplatforms worden vaak aangevallen door cybercriminelen in de hoop een stevig bedrag eraan over te houden.

Deze nieuwste hack volgt op een andere grote inbraak waarbij hackers meer dan 600 miljoen dollar (US$600 million) aan cryptomunten konden stelen van het gedecentraliseerde financiële platform Poly Network. In een onverwachte wending gaven de hackers nadien bijna de hele buit terug (returned).

Over ESET

Al meer dan 30 jaar ontwikkelt ESET® geavanceerde IT-beveiligingssoftware en -diensten om bedrijven, kritieke infrastructuur en consumenten wereldwijd te beschermen tegen steeds meer gesofisticeerde digitale dreigingen. Van eindpoint- en mobiele beveiliging tot detectie en respons van eindpoints, encryptie en multi-factor authenticatie, beschermen en bewaken ESET's krachtige, gebruiksvriendelijke oplossingen discreet 24/7. Ze updaten in realtime de verdediging om ononderbroken gebruikers en ondernemingen te beveiligingen.

De constant veranderende bedreigingen vragen een schaalbare provider van IT-beveiliging zodat technologie veilig kan gebruikt worden. Dit wordt ondersteund door ESET’s R & D-centra over de hele wereld. Deze zetten zich in om onze gemeenschappelijke toekomst te ondersteunen.

Voor meer informatie bezoek www.eset.com  of volg het nieuws op LinkedIn, Facebook, en Twitter.

5.8.21

 


Freedelity fête sa 100 millionième vente enregistrée avec une carte d'identité belge

Lancé il y a 10 ans, Freedelity fête sa 100 millionième vente enregistrée avec une carte d'identité.

Aujourd’hui, l'utilisation de la carte d'identité comme carte de fidélité, carte de membre ou pour digitaliser des garanties est devenue pour beaucoup une réelle habitude. Chaque mois, plus d'un million de belges utilisent ce système qui totalise maintenant plus de 6.5 millions de membres uniques.

La carte d'identité numérique, une innovation dont la Belgique a été une pionnière, a démontré être un outil indispensable pour les activités officielles et a pris une place importante dans la société civile belge. Ainsi, la Belgique a une considérable avance sur ses voisins européens tels que la France, l’Allemagne ou les Pays-Bas. 

A la lumière de ces informations, Freedelity - une société avec ses racines en Belgique, accueille avec enthousiasme l'obligation par tous les états européens de distribuer dès 2021 des documents d'identité numérique à travers toute l'Europe, ouvrant ainsi le marché européen à son appli fort appréciée, pour les années à venir.

Fortement intégré avec les systèmes de caisses, la plateforme Freedelity propose aux consommateurs une série de services sous le nom de MyFreedelity.

Accessible via un portail et une application mobile, chaque consommateur peut donc contrôler ses coordonnées et avoir accès à son historique d'achats, ses garanties, sa fidélité, mais aussi à son historique de communications avec ses fournisseurs et, bien entendu, aux dépliants publicitaires.

A propos de Freedelity

Freedelity, société ICT basée à Nivelles (Brabant Wallon), est née en 2010 de la réunion de trois passionnés. Elle s'est donné pour objectif de doter la carte d'identité électronique d'une réelle utilité pratique au quotidien. Freedelity offre des services à forte valeur ajoutée pour le marché du retail, de l'évènementiel d'entreprise et du field marketing grâce à ses multiples solutions CRM inédites en gestion et dynamisation de bases de données, en fidélisation de clientèle et de marketing multi channel. Avec MyFreedelity, adoptée aujourd'hui par plus de 6.500.000 consommateurs et plus de 1.000 professionnels, la société nivelloise a pleinement réussi son défi de remplacer les trop nombreuses cartes de fidélité qui encombrent les portefeuilles par la simple carte d’identité.

Visitez aussi Freedelity sur  www.myfreedelity.com et www.custocentrix.be  


 


*Freedelity viert 100 miljoenste verkoop geregistreerd met een Belgische ID-kaart

Freedelity,  10 jaar geleden op de markt gebracht, viert nu zijn 100 miljoenste verkoop geregistreerd met een Belgische ID-kaart

Vandaag is het gebruik van de identiteitskaart als klantenkaart, lidkaart of om garanties te digitaliseren voor velen een gewoonte geworden. Elke maand maken meer dan een miljoen Belgen gebruik van dit systeem, dat nu in totaal meer dan 6,5 miljoen leden - individuele personen- telt.

De digitale identiteitskaart, een innovatie waarin België een pioniersrol speelde, is een essentieel instrument gebleken voor officiële activiteiten en heeft een belangrijke plaats ingenomen in het Belgische maatschappelijk middenveld. Zo komt het dat België een aanzienlijke voorsprong heeft op zijn Europese buren zoals Frankrijk, Duitsland of Nederland.

In het licht van deze informatie verwelkomt Freedelity - een bedrijf met wortels in België, enthousiast de verplichting om vanaf 2021 digitale identiteitsdocumenten in alle EU-landen in te voeren en zo in de komende jaren een Europese markt te openen voor zijn succesvolle toepassing.

Het Freedelity-platform is sterk geïntegreerd met kassasystemen en biedt consumenten een reeks diensten aan onder de naam MyFreedelity.

Toegankelijk via een portaal en een mobiele app, kan elke consument met MyFreedelity zijn contactgegeve ns beheren en toegang krijgen tot zijn aankoophistoriek, waarborgen, loyalitypunten, maar ook tot reclamefolders en natuurlijk tot de historiek van zijn communicatie met zijn leveranciers.

Over Freedelity

Freedelity, een ICT-bedrijf uit Nijvel (Waals-Brabant), ontstond in 2010 uit de ontmoeting van drie enthousiastelingen. Het heeft zich tot doel gesteld om de elektronische identiteitskaart dagelijks echt praktisch bruikbaar te maken. Freedelity biedt diensten met een hoge toegevoegde waarde voor de retail-, bedrijfsevenementen- en fieldmarketingmarkt dankzij zijn meerdere nieuwe CRM-oplossingen op gebied van management en dynamisatie van databases, klantenbinding en multi-channelmarketing.

Met MyFreedelity, de digitale portefeuille die vandaag door meer dan 6.500.000 consumenten en meer dan 1.000 professionals wordt gebruikt, is het bedrijf uit Nijvel volledig geslaagd in zijn opzet om de talloze klantenkaarten te vervangen die portefeuilles en portemonnees overvol maken.

  Bezoek Freeddelity ook op www.freedelity.be/facebook; www.freedelity.be/twitter en  www.freedelity.be/linkedin