Category: Cyber Security

  • Chinese threat actors have been compromising telecom networks for years, investigation finds – Cyber Security

    Chinese threat actors have been compromising telecom networks for years, investigation finds – Cyber Security

    [ad_1]

    Hackers linked to the Chinese government invaded major telecom companies “across Southeast Asia,” says reporting firm Cybereason, and the tools they used will sound familiar.

    deadringer-diagram.jpg

    A diagram of the three APTs acting against Southeast Asian telecoms.

    Image: Cybereason

    New research has been published that points the finger at the Chinese government for being behind hacks of major telecommunications companies around Southeast Asia, all for the purpose of spying on high-profile individuals. 

    Published by Cybereason, the report said that it found evidence of three different clusters of attacks going back to at least 2017, all perpetrated by groups or individuals connected in some way to advanced persistent threat (APT) groups Soft Cell, Naikon and Group-3390, which have each operated for the Chinese government in the past. 

    SEE: Security incident response policy (TechRepublic Premium)

    Cybereason said it believes the goal of the attacks was to established continuous access to telecom provider records “and to facilitate cyber espionage by collecting sensitive information, compromising high-profile business assets such as the billing servers that contain Call Detail Record (CDR) data, as well as key network components such as the Domain Controllers, Web Servers and Microsoft Exchange servers.”

    Those up-to-date on the latest cybersecurity news will probably have heard of the exploit the attackers used to establish access. It’s the same one Chinese-based hacking group Hafnium used, and it’s the same one that allowed attackers to infiltrate SolarWinds and Kaseya: A set of four recently disclosed Microsoft Exchange Server vulnerabilities.

    Target selection follows suit with SolarWinds, Kaseya and Hafnium attacks as well: APTs in those instances compromised third parties with the intent to surveil high-value customers of the affected organizations, like political figures, government officials law enforcement, political dissidents and others. 

    Cybereason said its team started looking into Exchange vulnerabilities immediately after the Hafnium attacks “During the investigation, three clusters of activity were identified and showed significant connections to known threat actors, all suspected to be operating on behalf of Chinese state interests,” the report said. 

    Overlap between the three clusters has occurred, Cybereason said, but it can’t figure out why: “There is not enough information to determine with certainty the nature of this overlap — namely, whether these clusters represent the work of three different threat actors working independently, or whether these clusters represent the work of three different teams operating on behalf of a single threat actor,” the report said.

    Regardless of origin, the attacks have been very adaptive and actively maintain the backdoors they have into telecom networks. The report found that “attackers worked diligently to obscure their activity and maintain persistence on the infected systems, dynamically responding to mitigation attempts,” which it said indicates that the targets are highly valuable to the attackers.

    SEE: How to manage passwords: Best practices and security tips (free PDF) (TechRepublic)

    “These attacks compromised telcos primarily in ASEAN countries, but the attacks could be replicated against telcos in other regions,” the report concluded. As is often the case with widely publicized exploits used by APTs and cybercriminals, patches are available that close the gaps, and it’s in the best interest of companies using Microsoft Exchange both in-house and through Outlook Web Access (targeted by one of the clusters).

    For more information on the report, be sure to attend Cybereason’s Aug. 5 seminar, where it will discuss its findings. 

    Also see

    [ad_2]

    Source link

  • What to expect from the security events – Cyber Security

    What to expect from the security events – Cyber Security

    [ad_1]

    Key topics analysts anticipate for these security conferences include supply chain attacks, Microsoft Exchange vulnerabilities and the iPhone/Pegasus spyware incident.

    Abstract Malware Ransomware virus encrypted files with keypad on binary bit red background. Vector illustration cybercrime and cyber security concept.

    Image: iStockphoto/nicescene

    Following a string of major cyberattacks and proposed initiatives by the U.S. government to better thwart them, cybersecurity has never been so uppermost on the minds of organizations and individuals around the world. That’s why this week’s Black Hat and DEF CON conferences promise to run hot and heavy with a host of topics in the world of security. But what discussions should we expect at this year’s events? Here are some thoughts from a variety of analysts.

    First, how might Black Hat USA 2021 (held July 31 – Aug. 5) and DEF CON 29 (held Aug. 5 – 8) differ in their topics and slants? Both are joined at the hip because of their back-to-back schedules and slight distinctions, but there are some nuanced differences between the security conferences, according to 451 Research senior research analyst Daniel Kennedy. The events focus on information security, but Black Hat tends to adopt a more corporate slant.

    SEE: Security incident response policy (TechRepublic Premium)

    Looking at the lineup at DEF CON, Kennedy points to an expected slate of talks, such as ones on exploiting vulnerabilities in Windows and macOS/iOS, DNS issues, cryptography weaknesses and the compromising of security tools.

    “But even a conference that focuses on the practical implementation of security compromises is not immune from macro issues discussed in information security,” Kennedy said. “And so not surprisingly there are topics on the evolution of ransomware to the scale of threat it has posed in the last twenty four months, concerns around security in healthcare specifically, and the role and scope of critical infrastructure protection and nation-state or equivalent capable threats.”

    The government’s renewed attention on cybersecurity also seems reflected in the conference topics, Kennedy noted. The announcement of Secretary of Homeland Security Alejandro Mayorkas as a keynote speaker generated some controversy, though he had attended in 2015.

    Supply chain attacks are likely to be a key topic on the agenda, according to senior security researcher Boris Larin. These types of attacks don’t just target one specific party; rather, they try to target an entire string of dependent companies. Recent supply chain attacks such as the SolarWinds breach, the Microsoft Exchange hack and the Kaseya ransomware incident show how a single security vulnerability can be exploited to affect multiple organizations and users.

    Supply chain attacks are hard to detect and may infect hundreds, thousands or even millions of computers, Larin said. As such, these types of attacks are effective for cybercriminals who aim at a single supplier but gain access to the networks of all the customers and vendors who use its products.

    “Suppliers might also be weaker from a security point of view; it is just simpler to infect a supplier than the end target,” Larin added. “The result of such attacks could be very devastating if instead of performing espionage operations, attackers would launch a wiper or ransomware. The effectiveness and impact of supply chain attacks leads us to expect that more APT groups and cybercriminals will try to perform such attacks in the future.”

    The conferences are likely to pay attention to Exchange vulnerabilities, nation-state attacks, critical infrastructure and IoT and even jailbreaks of IOS 14, according to security researcher Victor Chebyshev.

    With nation-state attackers perhaps the most important theme, Chebyshev said he believes there will be a lot of discussion about Pegasus and the NSO Group. But the starting point for this topic will be such Black Hat presentations as “The Kitten that Charmed Me: The 9 Lives of a Nation State Attacker about ITG18” by IBM X-Force about the infamous Charming Kitten threat group.

    SEE: Checklist: Securing digital information (TechRepublic Premium)

    Another topic expected by Chebyshev will focus on ways that attackers may bypass certain security tools. Specifically, Endpoint Detection and Response (EDR) and Managed Detection and Response (MDR) are two promising security methods designed to find and deal with cyberthreats. The Black Hat presentation “Rope: Bypassing Behavioral Detection of Malware with Distributed ROP-Driven Execution” will cover the topic of bypassing these detection mechanisms based on behavior.

    Further, Chebyshev advises Black Hat attendees to check out “20+ Ways to Bypass Your macOS Privacy Mechanisms” and “Come to the Dark Side, We Have Apples: Turning macOS Management Evil” for details about attacks that target Macs.

    “What I see lacking is the reports on attacks on Apple’s macOS ecosystem,” Chebyshev said. “Yes, there are a few reports on the topic, but not that many, especially given the relevance of the platform.”

    Chris Steffen, research director at Enterprise Management Associates, expects a range of topics at Black Hat. 2020 was supposed to be the year people started to focus on IoT security, but the pandemic changed that; however, IoT security still needs to be a priority, and organizations want IoT security vendors to provide direction in this area.

    IT management tools is another topic that should garner attention.

    “With the recent ransomware attacks, there is a need to understand how these tools are being secured, evaluated, and reevaluated,” Steffen said. “It is something that the security industry has known for years, but it has taken high visibility attacks to finally get people (vendors, users, regulators) to pay attention to it.”

    Chris Clements, vice president of solutions architecture for Cerberus Sentinel, sees three topics that promise to pop up at the conferences: 1) The continuing ubiquity of ransomware; 2) Potential targets and defenses for supply chain attacks; and 3) Microsoft’s recent security struggles.

    For ransomware, Clements said he believes there will be a focus on new attack techniques as well as prevention and detection methods. In the realm of supply chain attacks, SolarWinds and Kaseya have shown us how many vendors have deep access into different networks. And as for Microsoft: “The recent ugly vulnerabilities in legacy Windows components like the print spooler have exposed that while the upcoming Windows 11 release may look slick and modern, Windows is a gigantic amalgamation of components with some code that’s old enough to drink in the US,” Clements said.

    Also see

    [ad_2]

    Source link

  • PwnedPiper flaws in PTS systems affect 80% of major US hospitals – Cyber Security

    PwnedPiper flaws in PTS systems affect 80% of major US hospitals – Cyber Security

    [ad_1]

    Cybersecurity researchers disclosed multiple flaws, dubbed PwnedPiper, that left a widely-used pneumatic tube system (PTS) vulnerable to attacks.

    Researchers from cybersecurity Armis disclosed a set of nine vulnerabilities collectively tracked as PwnedPiper that could be exploited to carry out multiple attacks against a widely-used pneumatic tube system (PTS).

    The Swisslog PTS system are used in the hospitals to automate logistics and the transport of materials throughout the building via a network of pneumatic tubes. 

    The flaw affects the Translogic PTS system manufactured by Swisslog Healthcare, which is installed in about 80% of all major hospitals in North America and thousands of hospitals worldwide.

    An attacker could exploit the PwnedPiper vulnerabilities to completely take over the Translogic Nexus Control Panel, which powers current models of Translogic PTS stations.

    The flaws could be exploited by attackers to conduct a broad range of malicious activities, such as carrying out a man-in-the-middle (MitM) attack to change or deploying ransomware

    “These vulnerabilities can enable an unauthenticated attacker to take over Translogic PTS stations and essentially gain complete control over the PTS network of a target hospital,” reads the post published by Armis. “This type of control could enable sophisticated and worrisome ransomware attacks, as well as allow attackers to leak sensitive hospital information.”

    PwnedPiper

    The flaws include privilege escalation, memory corruption, remote-code execution, and denial-of-service issues. An attacker could also push an insecure firmware upgrade to fully compromise the devices.

    These are the nine vulnerabilities discovered by the researchers:

    • CVE-2021-37161 – Underflow in udpRXThread
    • CVE-2021-37162 – Overflow in sccProcessMsg
    • CVE-2021-37163 – Two hardcoded passwords accessible through the Telnet server
    • CVE-2021-37164 – Off-by-three stack overflow in tcpTxThread
    • CVE-2021-37165 – Overflow in hmiProcessMsg
    • CVE-2021-37166 – GUI socket Denial Of Service
    • CVE-2021-37167 – User script run by root can be used for PE
    • CVE-2021-37160 – Unauthenticated, unencrypted, unsigned firmware upgrade

    Swisslog has released Nexus Control Panel version 7.2.5.7 that addresses most of the above vulnerabilities. The CVE-2021-37160 has yet to be addressed.

    “This research sheds light on systems that are hidden in plain sight but are nevertheless a crucial building block to modern-day healthcare. Understanding that patient care depends not only on medical devices, but also on the operational infrastructure of a hospital is an important milestone to securing healthcare environments.” concludes the report.

    Swisslog has also published security advisories for these vulnerabilities.

    Follow me on Twitter: @securityaffairs and Facebook

    Pierluigi Paganini

    (SecurityAffairs – hacking, PTS Systems)




    [ad_2]

    Source link