Thursday, June 1, 2017

Who's to blame for that cyberattack? Here's why nobody's really sure

(Image: file photo)

There are two things certain in life -- "death" and "taxes," they say. There's a third, thanks to the security community, and that is "nothing is unhackable."

Look no further than the recent massive cyberattack, which crippled hundreds of thousands of computers in dozens of countries, paralyzing hospitals, car plants, and banks across the world. The WannaCry ransomware attack was by far the most public, international, and widescale cyberattack in just a few months, following in the footsteps of the US internet outage led by an army of thousands of badly-secured internet-connected devices.

In both cases, questions remain who's responsible for these two major attacks. Look a little further back, and many other major hacks and cyberattacks remain vague, or entirely unattributed. Hackers already have a wealth of tools to cover their tracks, and without a body of evidence -- unlike at a crime scene -- it almost impossible at the best of times to know who was behind an attack.

That's what security researchers call the "attribution problem," in that security researchers and forensics aren't always sure who's behind an attack, making it difficult -- if not impossible -- to launch a response, or a retaliatory strike.

And sometimes things can be far from what they first seem.

Case in point: Symantec researchers on Thursday discovered what they thought was a nation-state actor, using highly sophisticated malware and techniques typically employed by a government, but was in fact a low-level cyber-criminal, who was just out to make a few bucks. In other words, what could've easily have been the Russian government turned out to be a fairly amateur individual.

It was a rare win for researchers, when in reality the effort to pin the blame is "rarely conclusive," said Cristiana Kittner, a senior analyst at cybersecurity firm FireEye.

"Even with copious amounts of data, it is incredibly difficult to find that one smoking gun," he said.

That's because rarely is the successful attribution of an attack as clear cut and as simple as this one hapless hacker, who was caught in part by inadvertently leaving an evidence trail -- including his real name -- across the internet. Russian security firm Kaspersky has too noted that the use of open source and readily available tools has in part made detection and attribution "almost impossible."

"Much depends on the attacker's 'opsec' practices if they can be identified based on the used tools and procedures," said Timo Laaksonen, who heads cybersecurity firm F-Secure's Americas business, in an email.

Simply put: if the hacker or attacker is sloppy, it can be easier to pin the blame -- and strike back.

But that all that changed when US spy agency, the National Security Agency, lost control of its hacking tools last year and were posted online for anyone to use.

Unknown hackers -- nation state or lone wolf hackers -- took those tools and infected thousands of computers with one of the agency's backdoor tools -- then, on a quiet, unassuming day in mid-May, used that backdoor channel to deliver the WannaCry ransomware on those infected computers. By the time the attack hit, Microsoft had already patched the bulk of the exploits that were published, but there's a looming threat that more tools could soon leak -- opening a whole new can of worms as to whether or not the agency should disclose its entire arsenal of hacking tools to the vendors, in order to prevent another WannaCry-style situation.

Who was behind one of the most disruptive and lengthy cyberattacks in modern history?

Thought to the be the biggest ransomware attack of its kind, the WannaCry ransomware was only successful thanks to the NSA losing control of its key hacking tools. (Image: file photo)

Some said it was North Korea, who was also officially blamed for the 2014 attack on Sony (even if experts remained divided and skeptical of the seemingly positive attribution), following the studio's release of a controversial movie about the country's young despotic leader, Kim Jong-un.

Security researchers said that the WannaCry code was also used by North Korean hackers, known as the Lazarus Group, and that seemed to be a conclusive link that many blindly accepted.

But a tangential connection isn't proof. Adam Meyers, VP of Intelligence at cybersecurity firm CrowdStrike, which had diligently monitored the attack, said that attribution was still a long way off.

"Analysts have reviewed all of the hard data associated with WannaCry -- they reverse engineered the code, analyzed the linguistics of the ransom notes, reviewed the victimology, and the infrastructure used for command and control -- and none of these things say they are explicitly linked to a specific adversary," he said.

Laaksonen too said that there was nothing to "ever conclusively" pinning the nation state to the attack.

It's no wonder the government isn't rushing to conclusions or taking any chances.

When asked about who was behind the attack, Homeland Security adviser Tom Bossert told reporters: "We don't know," admitting that attribution "can be difficult."

The simple reality is that now anyone with nation state hacking tools can launch their own nation state-type attack with relative ease. Given that the tools were designed to keep one of the world's most elusive spy agency's activities secret, it's no wonder the government hasn't declared any one adversary responsible. Without a firm sense of who was behind what, holding those accountable for hacks and cyberattacks is impossible -- or worse, misguided and misdirected against a group or state with no connection whatsoever.

"Attribution might get to a point that we are careless enough to be misled by it. People are quick to jump on conclusions and sometimes it seems attribution is being used for political or marketing purposes," said Laaksonen

"It's no longer a science, it's seems to be a rush to the finish line," he added.

Contact me securely

Zack Whittaker can be reached securely on Signal and WhatsApp at 646-755–8849, and his PGP fingerprint for email is: 4D0E 92F2 E36A EC51 DAAE 5D97 CB8C 15FA EB6C EEA5.



from Latest Topic for ZDNet in... http://ift.tt/2rIxbyr

Under the hood: Why you need AMP on ESA

Under the hood: Why you need AMP on ESA

- June 1, 2017 - 0 Comments

With 95 percent of breaches starting with a malicious email campaign, it’s more important than ever for organizations to be prepared and to be certain that their email security solution will truly protect their data, assets and users.

In a recent blog post we discussed the need for advanced threat protection at the email gateway and the smartest and safest way to approach email security.  In this blog post we’ll take a look under the hood and examine Cisco’s solution for protecting from today’s stealthy email attacks: Cisco AMP for Email.

Let’s start with an example: The HR department at Acme, Co. gets an email from a potential employee with a resume attached. No problem, right? HR receives messages like this regularly, so they open the attachment. However, the attachment contains an executable file that downloads malware in the background. The malware begins to harvest information: passwords, credentials, and company access authorizations have all been compromised and unknowingly gave hackers the ability to steal sensitive company and customer information. These kinds of scenarios are happening every day, so how are you supposed to determine which attachments are real and which ones are malicious? What do you do if a malicious email evades your front line defenses?

So how could Cisco AMP for Email help the HR team at Acme? Cisco Email Security offers multiple layers of protection to block email-based threats. This includes blocking emails from senders with bad reputations, anti-spam engines, anti-virus scanning, AMP and others. Everything that isn’t caught by anti-spam is processed through multiple anti-virus engines that protect against known and emerging threats. For more advanced threats, Cisco Advanced Malware Protection performs additional automated analysis using Cisco threat intelligence.

You may ask yourself, why invest in AMP on Email, if the solution already provides anti-virus scanning with engines from multiple security vendors? The answer to this is simple: most AV tools perform signature-based detection, which means if a piece of malware was specifically crafted to invade your organization and consecutively not yet known to AV vendor – it can be easily bypassed by bad actors. While AV engines will still catch a subset of known threats, we need to ensure protection against more sophisticated or even targeted attacks. AMP for Email adds an additional layer of valuable defense by combining point-in-time detection with continuous analysis. One example of efficacy improvement was observed by Cisco’s own IT department – after enabling AMP functionality on ESA, the overall malware catch rate was improved by approximately 50%. That’s due to the fact that around 31% of encountered malware attacks were zero-day threats blocked by AMP.

AMP for ESA doesn’t just improve your initial blocking and detection. AMP takes your ESA to the next level by continuously tracking disposition changes for files that have crossed your email gateway, being initially classified as clean. If malicious behavior is spotted down the line, AMP sends a retrospective alert allowing you to investigate, contain and remediate the malware.

So how does AMP for Email do it? Let’s now look under the hood.

  • Global threat intelligence from Cisco Talos – security starts with strengthening your defenses using the best global threat intelligence so you can block malware as new threats emerge. Cisco’s team of threat researchers continuously feed threat intelligence into AMP services.
  • File Reputation Lookup – ESA calculates SHA256 hash of the attachment and queries the file reputation service. The service responds with a verdict, either clean, malicious or unknown. Based on the verdict, an action can be taken accordingly – either to deliver, block or quarantine a message. For executable files, ESA also uses machine-learning based technology, that identifies unknown threats using active heuristics to gather execution attributes and produce a Spero fingerprint, which is sent to the service to determine probability of a file being malware.
  • File Analysis – for files with unknown verdict or those that were not seen at all, ESA performs an additional layer of inspection by sending an attachment to Threat Grid, Cisco’s advanced sandboxing solution. While analysis is performed, the message is typically quarantined and not delivered to end user. Threat Grid performs automatic static and dynamic analysis, producing human readable behaviour indicators for each file submitted as well as a threat score. Before an unknown file is submitted the pre-classification engine scans it to select only files with suspicious content (embedded macros, exes, flash, etc), reducing the need to quarantine emails containing benign file attachments.
  • File Analysis Quarantine – a differentiating capability of AMP on ESA, when compared to other AMP integrations, is the ability to hold a message, while the attachment is analysed by Threat Grid and before we ensure if it’s malicious. The average analysis time is 7 to 15 minutes and based on the analysis results, ESA can either release a message to the recipient, release a message without malicious attachment or remove the message completely.
  • Mailbox Auto Remediation – if a file is not detected as malicious the first time through the gateway, but is later determined to be malicious, a retrospective event is generated. Microsoft Office 365 allows the ESA to reach in and quarantine the message with malicious attachment from the mailbox. At the time of this writing, without O365, the ESA will alert the administrator of a file that was delivered to a user.

Cisco AMP for Email is a critical first step that helps protect your organization from the number one attack vector. If you are still asking yourself if that’s really worth to invest in AMP on ESA, just have a look at the following statistics of how AMP increased efficacy for a 30,000-seat deployment in a 3-month period.

For more information:

Tags:


from Cisco Blog » Security http://ift.tt/2qEly7s

Online Training for CISA, CISM, and CISSP Cyber Security Certifications


Believe it or not, but any computer connected to the Internet is vulnerable to cyber attacks.

With more money at risk and data breaches at a rise, more certified cyber security experts and professionals are needed by every corporate and organisation to prevent themselves from hackers and cyber thieves.

That's why jobs in the cyber security field have gone up 80% over the past three years than any other IT-related job. So, this is the right time for you to consider a new career as a cyber security professional.

Cyber security experts with industry-standard certification are coming from a wide range of backgrounds, who prepare themselves to protect computer systems and networks from viruses and hackers.

But before getting started your career as a cyber security expert, it's important to understand basics of networks and how data moves from place to place, and for this, you are highly advised to gain some valuable cyber security certifications.

Cyber security certifications not only boost your skills but also verify your knowledge and credibility.

THN Deals Store this week brings you the 

Cybersecurity Certification Mega Bundle

, which will walk you through the skills and concepts you need to master three elite cyber security certification exams: CISA, CISM, and CISSP.

Online Training for CISA, CISM, and CISSP Certifications

With this online training course, you will get the materials you require to dive deep into the most proven and practical methods for protecting vulnerable networks and any business environment.

From the fundamentals of cryptography and encryption to the security holes in computer networks and mobile apps, this course will help you learn about information security audits, assurance, guidelines, standards, and best cyber security practices in the industry.

If you don't know what are CISA, CISM, and CISSP certifications, below you can find brief information about the courses and their importance in IT industry.

The CISA certification is renowned across the world as the standard of achievement for those who audit, monitor, access and control information technology and business systems.

Being CISA-certified showcases candidates for their audit experience, skills, and knowledge, and signifies that you are an expert in managing vulnerabilities, instituting controls and ensuring compliance within the enterprise.

The demand for skilled information security managers is on the rise, and CISM is the globally accepted certification standard of achievement in this area.

The uniquely management-focused CISM certification ensures you are re-equipped with the best practices in the IT industry and recognises your expertise to manage, design, and oversee and assess an enterprise's information security.

The CISSP certification is a globally-recognised certification in the field of information security and has become a standard of achievement that is acknowledged worldwide.

Offered by the International Information Systems Security Certification Consortium, commonly known as (ISC)², CISSP is an objective measure of excellence, which requires a broad level of knowledge.

How to Join Cybersecurity Certification Training?

If you want to select the best and cost-efficient course to pass CISA, CISM, and CISSP certifications, the

Cybersecurity Certification Mega Bundle

course is the one for you to begin with.

You can get Cybersecurity Certification Mega

Bundle for just $69 (after 99% discount)

at the THN Deals Store.

So, to Sign-up for the Cybersecurity Certification Mega Bundle course,

click on this link

and get your online course now.

We also provide 15-Day Money Back Guarantee. So in case, you are not satisfied with this course for any reason, we will issue a refund within 15 days of purchase. We want you to be happy with every course you purchase!



from The Hacker News http://ift.tt/2qES9hy

Biker group charged with hacking hundreds of Jeeps, motorcycles in crime spree

ramnit-header-imagecredsymantec.jpg Symantec

A motorcycle club has caught the attention of US prosecutors after allegedly making millions of dollars through hacking and stealing hundreds of Jeep Wranglers and motorbikes.

As reported by The Register, in an indictment (.PDF) dated 23 May 2017, the San Diego office of the US Department of Justice (DoJ) and FBI say that nine members of the group, based in Tijuana, Mexico, were part of a two and a half year scheme to steal vehicles.

Although the exact date of the auto theft ring's beginning is unknown, prosecutors say that the club members began stealing vehicles from the US no later than January 2014 until September 2016.

Targeting mainly Jeep Wranglers and a variety of motorbikes in California, the group used scouts to source their targets before obtaining vehicle identification numbers (VINs), usually found on dashboards.

The VINs were then passed to other Hooligans members who had access to stolen credentials obtained from a Jeep dealer in Cabo San Lucas, Mexico.

These members, the so-called "key cutters," would then access a dealer database using the credentials to covertly pull out the information needed to cut and program duplicate keys and the controlling microchips within. In total, two codes per key were required.

Separated into small teams, the scouts, leaders, key cutters, and transporters would then make their way back to the target vehicle.

"Thieves and transporters would return to the targeted Jeep Wrangler with the key and the programming code and would disable certain features of the Jeep Wrangler's alarm system, including the horn and emergency flashers," US law enforcement claims. "Thieves would use the duplicate key to access the Jeep Wrangler's passenger compartment and would then use a handheld key programmer and the code received from the key cutters to program the duplicate key."

Wrestling control of the Jeep would take no longer than a few minutes to pull off.

The Jeep would then be driven back to Mexico or moved through a transporter for part stripping or sale.

When it comes to the motorcycles, the group would "turn on the motorcycles without a key by bypassing the ignition switch," -- although no technical details behind this have been revealed -- before riding them to the same location for the same fate.

Honda CBRs, Kawasaki Ninjas, and Yamaha YZF-R1 models were among those stolen.

In total, at least 28 vehicles were sold, worth approximately $800,000. However, law enforcement has reason to believe that over 150 Jeep Wranglers and motorcycles is closer to the truth, worth a combined $4.5 million.

In an online chat held between Hooligan members, one member said pertaining to another series of planned thefts, "They're going to say, damn hooligans," to which another responded, "We're a plague. They can't stop us."

Three members of the motorcycle club have been tracked down and detained, and the remaining six are believed to be in hiding in Mexico.



from Latest Topic for ZDNet in... http://ift.tt/2qJv5cN

Silk Road founder Ross Ulbricht loses appeal for new trial

Underground marketplace owner Ross Ulbricht has lost a court appeal to have a new trial and now will likely spend the rest of his days behind bars.

screen-shot-2017-06-01-at-09-47-51.jpg

Ulbricht, also known under the moniker Dread Pirate Roberts, was sentenced to life in prison without the possibility of parole in after being convicted of seven counts including drug trafficking, narcotics conspiracy, money laundering, and engaging in a criminal enterprise as the owner of the Silk Road marketplace.

The creator of Silk Road operated the website from 2011 to 2013 and was used by those seeking the sale or purchase of everything from stolen data to drugs, weapons, and hacking tools.

Accessible through the Dark Web, the US government estimates that between these dates, underground trades conducted through Silk Road generated roughly $183 million in Bitcoin, of which the owner received a commission on sales.

In a 2009 email, Ulbricht said Silk Road originally grew from the idea of creating an "an online storefront that couldn't be traced back to [him] . . . where [his] customers could buy [his] products" and pay for them "anonymously and securely."

In October 2013, US law enforcement set up a sting operation using an operative from the inside and arrested Ulbricht in a public library.

The 33-year-old's laptop was seized alongside USB drives containing copies of Silk Road documents, his private PGP key was discovered, and the police also seized roughly $18 million in Bitcoin from a wallet on Ulbricht's laptop. These funds were traced back to Silk Road servers located in Iceland.

Ulbricht was charged and sentenced in 2015 and filed his appeal in the same year, requesting for a new trial which would potentially result in a life sentence being set aside.

According to court documents, Ulbricht asked for a new trial on the basis that the district court made a mistake by rejecting his defenses' motion to suppress evidence obtained in violation of the Fourth Amendment, the court also made a series of errors which meant he did not receive a fair trial, and a sentence of life for his crimes is "substantively unreasonable."

In addition, Ulbricht claimed that the investigation was corrupt from the start, referring to former Secret Service agent Shaun Bridges and former Drug Enforcement Administration agent Carl Force, both of whom were involved and stole seized bitcoin.

The agents were sentenced to 71 months and 78 months in prison respectively, but according to Circuit Judge Gerard Lynch, their conduct did not impact the conclusion of the case.

"Without question, the shocking personal corruption of these two government agents disgraced the agencies for which they worked and embarrassed the many honorable men and women working in those agencies to investigate serious criminal wrongdoing," Lynch said. "At the same time, the venality of individual agents does not necessarily affect the reliability of the government's evidence in a particular case or become relevant to the adjudication of every case in which the agents participated."

The Second US Circuit Court of Appeals in Manhattan, New York, has decided to uphold the original sentence, potentially as a warning to others that are considering setting up the same kind of criminal enterprise.

Dread Pirate Roberts may not have been your traditional, stereotypical drug cartel overlord, but the severity of the sentence and utter refusal to consider lessening the jail term highlights how seriously prosecutors took Silk Road.

As the potential future of underground dealings and more difficult to track due to the Tor network and virtual currency, shutting down the popular trading post was a priority -- as was making sure potential future operators understand the consequences of being caught,



from Latest Topic for ZDNet in... http://ift.tt/2rXAJMR

High-Severity Linux Sudo Flaw Allows Users to Gain Root Privileges


A high-severity vulnerability has been reported in Linux that could be exploited by a low privilege attacker to gain full root access on an affected system.

The vulnerability, identified as CVE-2017-1000367, was discovered by researchers at Qualys Security in Sudo's

"get_process_ttyname()"

function for Linux that could allow a user with Sudo privileges to run commands as root or elevate privileges to root.

Sudo, stands for "superuser do!," is a program for Linux and UNIX operating systems that lets standard users run specific commands as a superuser (aka root user), such as adding users or performing system updates.

The flaw actually resides in the way Sudo parsed "tty" information from the process status file in the proc filesystem.

On Linux machines, sudo parses the /proc/[pid]/stat file in order to determine the device number of the process's tty from field 7 (tty_nr), Qualys Security explains in its

advisory

.

Although the fields in the file are space-delimited, it is possible for field 2 (the command name) to include whitespace (including newline), which sudo doesn't account for.

Therefore, a local user with sudo privileges (Sudoer) on SELinux-enabled systems can cause sudo to use a device number of his choice

"by creating a symbolic link from the sudo binary to a name that contains a space, followed by a number,"

escalating their privileges to overwrite any file on the filesystem, including root-owned files.

"To exploit the bug, the user can choose a device number that does not currently exist under /dev. If sudo does not find the terminal under the /dev/pts directory, it performs a breadth-first search of /dev...The attacker may then create a symbolic link to the newly-created device in a world-writable directory under /dev, such as /dev/shm," an alert on the sudo project website reads. 
"This file will be used as the command's standard input, output and error when an SELinux role is specified on the sudo command line. If the symbolic link under /dev/shm is replaced with a link to another file before [sudo opens it], it is possible to overwrite an arbitrary file by writing to the standard output or standard error. This can be escalated to full root access by rewriting a trusted file such as /etc/shadow or even /etc/sudoers."

The vulnerability, which affects Sudo 1.8.6p7 through 1.8.20 and marked as high severity, has already been patched in Sudo 1.8.20p1, and users are recommended to update their systems to the latest release.

Red Hat yesterday

pushed out patches

for Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, and Red Hat Enterprise Linux Server. Debian has also

released fixes

for its Wheezy, Jessie and Sid releases and SUSE Linux has

rolled out fixes

for a number of its products.

Qualys Security said it would publish its Sudoer-to-root exploit once a maximum number of users have had time to patch their systems against the flaw.



from The Hacker News http://ift.tt/2qIHopK

Wednesday, May 31, 2017

China's cybersecurity law vows to better protect personal information


China's first ever cybersecurity law, which officially takes effect on June 1, vows to protect online users' information by prohibiting abuse from online service providers.

Passed by China's Parliament in November last year, the new law has banned ISPs from collecting and selling users' personal information that is irrelevant to their services. Users also have the right to request their information to be deleted in cases of abuse, according to a Sina news report.

Cybersecurity management employees are also required to protect information obtained, and are prohibited from selling or leaking this information.

The Supreme Court and Supreme Procuratorate in China have further stipulated that those who illegally obtain, sell, or provide personal information of over 50 items will be deemed as "severe cases" and subject to imprisonment, the report added.

The new regulation has also tried to strengthen data surveillance and storage for firms working in the country.

Article 37 of the cybersecurity law stipulated that "citizens' personal information and important business data collected and produced by critical information infrastructure operators during their activities within the territory of the People's Republic of China, shall be stored within the territory".

But the article failed to specifically define "critical information infrastructure operators", only broadly referring to them as "those [that] could cause serious damage to national security, the national economy and public interest if destroyed, functionality is lost, or data is leaked".

According to a Deloitte report on the website, critical information infrastructures can be categorized into "websites, platforms, and production businesses".

Other than influential organizations that affect the national economy and people's livelihood in China, "websites with more than 1 million daily average visits", "infrastructures that can cause leakage of data of more than 1 million people in the event of a cybersecurity incident", "infrastructures with more than 10 million registered users, or 1 million active users", and "infrastructures with daily average transaction or trade amounts of more than 10 million yuan" would all fall into the categories of critical information infrastructures as stated in the new law, Deloitte said.

A Reuters report said earlier that overseas business groups were requesting Chinese regulators to delay implementation of the law, believing the new rules would hurt activities.



from Latest Topic for ZDNet in... http://ift.tt/2rqFWfz