Monday, September 5, 2022

LastPass Security Breach – Hackers Steal Company’s Source Code.

 

World-leading password manager, LastPass, is the latest victim of a security breach. In an advisory, the company confirmed the stealing of its internal source code and technical documents. LastPass is owned by GoTo and boasts over 25 million users and serves around 80,000 businesses worldwide.

Incident Details.

On 25 August 2022, LastPass’s CEO Karim Toubba confirmed that an unauthorized party stole some portions of its internal source code and proprietary technical information. The company revealed that an attacker broke into one of its developers’ accounts and gained access to proprietary data.

The company stressed on the breach occurred through a “single compromised developer account. It noted that all of its products and services are “operating normally,” and that the situation is under control. The breach took place around two weeks back.

How the Breach was Detected?

The break-in was detected after unusual activity was noticed in the LastPass computer network’s development area. The security breach was promptly contained and the company took necessary steps to prevent another intrusion from happening. 

According to LastPass’ blog post, the company also outsourced infosec experts to investigate the incident. An investigation was launched and it was later confirmed that the cybercrook couldn’t access customer data. Per LastPass CEO, the company will ramp up its network defenses. 

What About User Passwords?

For your information, LastPass provides a software vault where usernames and passwords are stored in pairs to allow users to log in to websites. This makes it tougher to crack passwords. 

After the breach, a lot of speculations emerged about the safety of passwords. The company addressed these concerns by explaining that master passwords are safe and weren’t compromised or accessed by the hacker. LastPass also added that vault contents also remained untouched.

LastPass noted that it doesn’t keep a copy of users’ master passwords as that’s for the user to memorize and protect. The Massachusetts-based company insisted that encrypted user passwords are safe due to the zero-knowledge architecture it has implemented.

 

 

 

Sunday, September 4, 2022

5 Signs Your WordPress Site Is Hacked (And How to Fix It).

 

Currently, there are over 455 million websites powered by WordPress which highlights the fact that this open-source content management system is a lucrative target for cybercriminals and why security should be the top priority of WP users.

Yes, there are signs that your WordPress or any website has been hacked, and yes there are ways to fix it. This article offers five ways you can tell if your website has been hacked, and then offers a few ways to solve the hack.

Remember that a malicious attacker has several ways of gaining access. It may be malware or a nefarious plugin, but it may be something more sinister like your email has been hacked or your smartphone/computer has spyware. Here are a few signs that your website has been hacked.

1 – You Are Unable to Log Into Your Account

If you are unable to log into your account, then that is a classic sign that you have been hacked. Yet, despite being a classic sign, it is one of the least common issues. Many hackers don’t want you to notice that you have been hacked. This allows them to keep gathering your customer information and/or keeps you working on your website so they can keep exploiting it. 

There are some great WordPress hacks where you have to log in two or three times. It will say that your password is incorrect the first one or two times, and the third time it will let you in. This is because the WordPress hack is actually processing your request. By your third attempt at your real password, you are allowed access and any trace of the hacker has disappeared.

2 – Unknown Files and Scripts

For those of you who know about programming, you may be able to scrub your own website clean of any malware and security risks. If you have the skills, you can look over your WordPress code, you may notice unknown scripts and possibly unknown files in your WordPress. This is often because of nefarious plugins leaving their files behind that may be used by hackers or other malware at a later date.

3 – Your Website Started Going Slow

This is a signal that somebody is using your website for nefarious reasons. It can be anything, from people hotlinking from your images and using up your bandwidth, to spammed people being redirected from your Google safe website to one of their nefarious ones.

Another reason your website may take a lot longer to load than is normal is that it may be compromised and used as part of a botnet on a larger scale. In 2018, researchers identified 20,000 compromised WordPress websites working as a botnet to carry out cyber attacks.

4 – Odd Additions to Your Website

A silly trick is to add pop-ups to your website. It is silly because it alerts you to the hack and causes you to react. In reality, they will add links to spam websites where your innocent viewers will be ripped off. After a while, you will be banned by search engines for being a suspicious website.

5 – Your Traffic or Affiliate Revenue is Down

This is another classic sign that your website has been hacked. The attacker is using your traffic and maybe even your affiliate money for his or her own ends. Often, it is odd behavior in your analytics that alerts you to a WordPress hack.

How to Fix it

First things first, you’ll need to identify the source of the attack. If not, you can check your server access logs. Once you know where the attack came from, you can take steps to block that IP address.

Then you need to start changing your passwords – for your WordPress account, as well as any FTP or hosting accounts associated with your site. Be sure to use strong passwords that are difficult to guess.

In addition, you could change the primary email for WordPress just in case that is the problem. You need to go through your plugins to figure out if any of those have caused the problem. If you have a security plugin installed, check its logs to see if there are any clues.

You need to go through the people you have given permission to because they may have fallen for a WordPress scam or a fake website and unknowingly given their information away.

You may also need to suspect your web host too because they are often hacked or expose customer data online without any security authentication.

If you are still unsure get in touch with a website security company like Sucuri or a service like WP-Masters to let them run through your website, fix it up, remove the hackers, remove the malware, and regain full control over your website. It is often the only definitive way to regain full control of your website. Finally, you’ll need to clean up any malicious code that may have been injected into your site.

 

 

 

 

 

 

Anonymous Hacked Russian Yandex Taxi App Causing A Massive Traffic Jam.

 

Russia has been one of the prime target of hackers since the country waged war against Ukraine. The latest attack was targeted against a ride-hailing service Yandex Taxi.

For your information, Yandex Taxi is owned by Yandex, Russia’s leading IT corporation, also called Russian Google. It is worth noting that the EU sanctioned the company’s co-founder Arkady Volozh for “de-ranking and removing” content related to Russian aggression against Ukraine.

Incident Details.

After hacking the Yandex Taxi app, the unknown hackers created a massive traffic jam in Moscow, Russia. On September 1st, 2022, motorist complaints emerged after they witnessed an unusual accumulation of taxis in the Russian capital’s western area. 

What happened was that the attackers ordered all available taxis to a particular address, and an unprecedented traffic jam ensued as dozens of Yandex drivers were stuck due to being in the exact location.

According to Forbes Russia, the cabs were directed to one of the main avenues in Moscow, Kutuzovsky Prospekt, which is widely known for the Stalinist-era building called Hotel Ukraina (Hotel Ukraine).

The traffic jam lasted three hours. Yandex’s security team quickly addressed the standstill and promised to improve the algorithm to prevent such attacks in the future.

Who’s Responsible for the Hack?

The online hacktivist collective Anonymous has taken the responsibility for the cyber attack.

 

 

Important Notification Phishing Scam Targeting American Express Customers.

 

In this phishing scam, the email is designed to appear as an authentic American Express notification. The email subject reads: “Important Notification About Your Account.” 

Armorblox security researchers have uncovered a new phishing campaign in which attackers are targeting American Express customers.

As per researchers, in this phishing scam, scammers lure American Express cardholders into opening an attachment and try to steal confidential data to access their accounts.

In this financially motivated campaign, attackers first send a spoofed email of the much-recognized card brand and ask the customers to click on the link included in the email attachment. 

Using social engineering and brand impersonation, the attackers lure their targets onto fake and malicious landing pages.

When the victim clicks on this link, they are redirected to a fake American Express landing page. This page is also crafted smartly to resemble the original American Express login page, including the company’s genuine logo, navigational links, and a link to download the American Express app.

In reality, scammers are using a customised domain for this attack. Once there, victims are prompted to sign in to verify their accounts. They enter their user ID and password.

The Legit-looking Phishing Email

In this phishing scam, the email is designed to appear as an authentic American Express notification. The email subject, according to Armorblox’s blog post, reads: “Important Notification About Your Account.”

It informs the recipient to verify their account. Otherwise, the company will suspend it.   The phrase “This is your last chance to confirm it before we suspend it” is included to create a sense of urgency. Victims are requested to complete a one-time verification process to update their credentials and prevent suspension of their accounts.

The email content is created wisely so that a sense of trust is evoked in the recipient.   For instance, it includes the American Express logo on the top left, and a signature is featured at the end to deceive the users into believing that the company’s customer service team sent the email.

Prime Targets

Armorblox co-founder and CEO DJ Sampath stated that financial firms are more frequently targeted with credential phishing scams. The main targets of this scam are holders of American Express charge cards.

What’s note worthy is that the phishing scam has bypassed Google Workplace Security successfully, and so far, the email has been sent to around 16,000 email addresses of American Express employees. 

How to Identify a Phishing Scam?

Most people are familiar with the term “phishing” but may not know how to identify a phishing scam. Phishing is a type of online fraud that involves tricking someone into giving personal information such as passwords, credit card numbers, or banking information. Scammers do this by sending fake emails or setting up fake websites that look like the real thing.

Here are some tips to help you spot a phishing scam:

  • Be suspicious of any email or website that asks for personal information such as your password, Social Security number, or credit card number. Legitimate companies will never ask for this information via email or an online form.
  • Phishing attempts almost always contain a link, downloadable attachment, or directive telling people to do something ASAP.
  • There are often a lot of spelling mistakes, but not always.
  • The email or message can instill a sense of urgency to get people to act quickly without thinking.
  • It may be a threat or even blackmail, as is the case with sextortion phishing scams.
  • The email signature will usually look strange or different from normal.
  • Phishing emails or messages aren’t always from strangers. Sometimes they’re sent from the compromised accounts of friends, coworkers, or other contacts.
  • Inspect the URL of any website you’re directed to from an email before entering any information on it.

 

 

 

 

Thursday, September 1, 2022

Sephora Fined $1.2 Million For Breaching CCPA And Selling User Data.

 


Sephora claims it respects consumer privacy and “strives to be transparent about how their personal information is used” to improve customer experience.

The world’s leading cosmetics and beauty products manufacturer Sephora will pay a fine of $1.2 million to settle claims with a California district court.

The fine was brought under the California Consumer Privacy Act (CCPA) 2018 after more than a hundred retailers were examined for compliance with the act. The law was implemented primarily to ensure consumers can control the kind of data businesses can collect.

The Accusation

The company allegedly breached the California Consumer Privacy Act by ignoring to inform its customers that it sold their data. The company also failed to honor consumer requests to avoid selling their data by using the opting-out feature on its website.

Furthermore, Sephora ignored customers’ requests who signed through a Global Privacy Control supporting browser/extension and didn’t want to sell their private data. Instead, it allowed third-party firms, including marketing, advertising, and data analytics companies, to access its customers’ online activities in exchange for their services.

To do so, third parties created profiles of customers and accessed personal data like their shopping cart items, device details, and location, court documents revealed. The court was further informed of the following:

 “Consumers are constantly tracked when they go online. Sephora, like many online retailers, installs third-party companies’ tracking software on its website and in its app so that these third parties can monitor consumers as they shop. Third parties track all types of data; in Sephora’s case, third parties can track whether a consumer is using a MacBook or a Dell, the brand of eyeliner that a consumer puts in their “shopping cart,” and even the precise location of the consumer.”

“Some of these third-party companies create entire profiles of users who visit Sephora’s website, which the third parties then use for Sephora’s benefit. For example, the third party might provide detailed analytics information about Sephora’s customers and provide that to Sephora, or offer Sephora the opportunity to purchase online ads targeting specific consumers, such as those who left eyeliner in their shopping cart after leaving Sephora’s website. This data about consumers is frequently kept by companies and used for the benefit of other businesses, without the knowledge or consent of the consumer.”

Sephora’s Response

However, Sephora claims it respects consumer privacy and “strives to be transparent about how their personal information is used” to improve customer experience.

“Sephora was not the target or victim of a data breach, and this agreement with the California Office of the Attorney General (“OAG”) does not constitute an admission of liability or fault by Sephora. We have always cooperated fully with the OAG and Sephora’s practices are already in compliance with the CCPA.”

Furthermore, Sephora explained that it uses data “strictly for Sephora experiences” and that the CCPA doesn’t define SALE in its conventional sense. That’s because traditionally, Sale entails industry-wide implemented standard practices like cookies that allow the company to provide its customers “more relevant Sephora product recommendations,” customized shopping experiences, and advertisements.

Consumers can simply opt-out of this by “CA- Do Not Sell My Personal Information. The link is available on the Sephora website footer, the company said.

According to Segev, “Business leaders are tasked with finding ways to leverage data to create new revenue streams. Especially with the shift to remote work, permissive access and applications like Google Drive or Slack make it easy to access and spread information across a business.”

“The people or teams involved may have believed they were permitted to monetize this data. How many businesses are prepared for this kind of action? Security and risk teams need a simple way to answer basic questions like What data do I have? Where is it now? Who is accessing it? How should it be governed and secured? Those are questions you need answers to at your fingertips, not something to be found after a lengthy audit process following a security incident,” Segev emphasized.

CCPA Details

The law entails that Californian consumers are entitled to know what information a business can collect, how they can use it, and the option to delete the data a company collected from them.

For your information, the act applies to for-profit retailers doing business in California earning gross annual revenue of more than $25 million and also to companies that buy, sell, or receive the personal data of 50,000+ devices, residents, and households in California and derive over 50% of their annual revenues from selling the residents’ private data.

The settlement resulted from a year-long Enforcement Sweep channeled by California Attorney General Rob Bonta. He investigated Sephora and many other businesses to check if any of them breached the CCPA.

 

 

 

 

European Spyware Vendor Offering Android And IOS Device Exploits.

 

The proposal documents were leaked on a Russian hacking forum showing Intellexa is offering remote data extraction from Android and iOS devices in exchange for $8 million. 

Intellexa is a spyware firm based and regulated in Europe. The company has six offices and R&D Labs spread across the EU. It has emerged as the rival of NSO Group, the company behind the infamous Pegasus Spyware since, reportedly, the company is offering Android and iOS hacking services for $8 million. 

The company, founded by entrepreneur Tal Dilian, claims that it helps intelligence and law enforcement agencies across the globe with its “best-in-class Nebula platform.” Last year, Citizen Lab published a report on Cytrox's Predator iPhone Spyware, in which Intellexa was mentioned. The spyware was used to target a lawmaker in Greece, and reportedly, Cytrox was linked to the Intellexa Alliance.

The same firm also made headlines in November 2019 when authorities in Cyprus confiscated a surveillance van belonging to Intellexa. The surveillance van was equipped with hacking tools capable of hacking, cracking, and tracking any smartphone.

On August 24th, 2022, malware source code providing platform Vx-Underground came across some undated leaked documents containing details of a proposal by Intellexa to offer remote data extraction from Android and iOS devices in exchange for money. In its tweet followed by leaked documents screenshots, Vx-Underground noted that: “Leaked Documents Online Show $8,000,000 iOS Remote Code Execution Zero Day Exploit.”

Intellexa’s offer includes ten infections for Android and IOS devices and The Magazine of 100 Successful Infections. The documents are titled Proprietary and Confidential, which revealed that the exploits work on iOS 15.4.1 and Android 12 updates.

It is worth noting that iOS 15.4.1 was released in March 2022, and this offer includes exploits for this version, so Intellexa must have offered this package recently.

So far, Apple has released three security updates since the mobile operating system release, so presumably, the iPhone maker has patched multiple o-day vulnerabilities possibly exploited by Intellexa. However, it is also possible that the exploits it is offering may remain unpatched.

Researchers say that Intellexa is asking for $8 million for an iOS exploit. The offer is valid for a platform including stolen data analysis and a 12-month warranty.

As per Vx-Underground, although the documents have no date, the screenshots it received were posted on a Russian hacking forum on 14th July 2022.

 

 

Hackers Spreading Malware Through Images Taken By James Webb Space Telescope.

 

 

Researchers have identified a new Golang-based malware campaign leveraging deep field images from the James Webb Space Telescope to deploy malware on infected devices. 

National Aeronautics and Space Administration’s (NASA) James Webb Space Telescope is known for the stunning images from space that it has been delivering us since its launching. Given its superior technology, the telescope can capture the earliest galaxies created shortly after the Big Bang.

Reportedly, hackers are also aware of their popularity and have decided to monetize from it.

Beware of Images Containing Malware

Securonix security researchers have identified a new Golang-based malware campaign leveraging deep field images from the James Webb Space Telescope to deploy malware on infected devices.

Dubbed GO#WEBBFUSCATOR, this persistent campaign highlights the increasing preference of malware operators for the Go programming language, probably because of its cross-platform support that lets hackers target different operating systems through a common codebase.

Attack Details

In their report, researchers D. Iuzvyk, T. Peck, and O. Kolesnikov explained that this campaign involves sending phishing emails that contain a Microsoft Office attachment named Geos-Rates.docx. The file is downloaded as a template.

 These emails are the attack chain’s entry point. When the attachment is opened, an obfuscated VBA macro is auto-executed if the recipient has enabled macros. When executed, the macro downloads an image file titled OxB36F8GEEC634.jpg. 

This appears to be the image of the First Deep Field sent from the telescope, but in reality, it is a Base64-encoded payload. The Windows 64-bit executable binary is 1.7MB in size. It can easily evade antimalware solutions and uses a technique called gobfuscation to utilize a Golang obfuscation tool, which is publicly available on GitHub.

According to researchers, crooks are using encrypted DNS queries/responses to communicate with the C2 server through which the malware can accept and run commands sent via the server through Windows Command Prompt.

 

 

The Benefits Of Blockchain In The Travel Industry.

  Blockchain technology advocates say it’s poised to disrupt numerous industries, ranging from finance to supply chain tracking and real e...