Archive for June 6, 2023

Uber expands rideshare in British Columbia to Victoria, Kelowna, and Chilliwack

Posted in Commentary with tags on June 6, 2023 by itnerd

Today, Uber officially expanded its ridesharing platform in British Columbia to Victoria, Kelowna, and Chilliwack, offering residents and visitors a safe, affordable, and reliable transportation option at the touch of a button.

In over 140 municipalities in Canada and over 10,000 cities globally, Uber users rely on the app to access transportation options whenever they need them. Whether it’s a ride across town to run errands, to get to work or school on time, or a late-night ride home after an evening out, Uber helps riders get where they want to go. 

To meet the expected demand for rides, interested drivers can visit driver.uber.com to learn more about driving with Uber. New drivers in Victoria and Kelowna who complete their profile and take 20 trips within the first 14 days of Uber’s launch will get an extra $1,000 promotion that will be added to their regular earnings.

For service area information and maps in each city, please click the following links: Victoria, Kelowna, Chilliwack.

BA, BBC, Boots Are The Newest Victims of Clop Ransomware’s MOVEit Exploit

Posted in Commentary with tags on June 6, 2023 by itnerd

Yesterday, British Airways, Boots and BBC were among many who have had personally identifiable data stolen. That includes names, contact details, salaries, and national insurance numbers of tens of thousands employees. This was due to a breach of Zellis which is a payroll provider, and their use of the MOVEit file transfer software. In a separate statement, the Nova Scotia government also reported being hit.  


On Sunday, Microsoft said this:

In short, Microsoft believed the group behind the hacks was “Lace Tempest”,  a sub group to online extortionists who run the Clop ransomware site. 

In a statement yesterday, MOVEit said it had fixed the SQL injection vulnerability and was working with experts to further investigate the issue. 

Meanwhile, threat intelligence analyst Germán Fernández said this:

 In short, he had discovered at least 57 other instances of potential MOVEit compromises, with the list of organizations including U.S. governments and banking organizations, such as the FBI and JP Morgan Chase. 

Roy Akerman, Co-Founder & CEO, Rezonate:

   “The MOVEit Transfer SQL injection vulnerability allows un-authenticated attacker to gain access to its Transfer’s database. From there it can recon data, structure, as well as running modification and deletion commands.

“Security teams are advised to go back at least 90 days and investigate any potentially malicious attempts as initial scanning observed by GreyNoise started March 3rd. In addition, rotating relevant keys and credentials are important to make sure no further access, if compromised, is available.“

Clearly if you use MOVEit, you should be making sure that you take the mitigation steps outlined here so that you don’t become the next victim of Clop.

The Verizon DBIR Is Out And It Makes For Interesting Reading 

Posted in Commentary on June 6, 2023 by itnerd

Verizon has dropped their latest Data Breach Investigation Report, or DBIR. Here’s some key highlights: 

  • Cost per ransomware incident doubled over the past two years, with ransomware accounting for one out of every four breaches.
  • Pretexting (Business Email Compromise) has more than doubled since the previous year.
  • The human element is involved in 3 out of 4 breaches.
  • Analysis of the Log4j incident illustrates the scale of the incident and the effectiveness of the coordinated response.

Bhaven Panchal, Senior Director of Service Delivery, Cyware has this comment:

With the median costs of ransomware attacks doubling since last year and reaching the million-dollar range, the new Verizon DBIR once again highlights the upward inflationary trend of the cost of data breaches. Another striking revelation is the prevalence of the human element as the contributing factor behind breaches, whether it be through errors, privilege misuse, use of stolen credentials, or social engineering. It is imperative for organizations to accelerate their security processes and plug visibility gaps in their environments. The operationalization of threat intelligence, threat response automation, and security collaboration are going to help drive this change toward a more resilient cyberspace for all.

Roy Akerman, Co-Founder & CEO, Rezonate follows up with this:

Dependency on privileged identities and access in a cloud and SaaS dominated environment are a key indicator and enabler of the increase in Business Email Compromise. The attackers need to obtain access, making identity security more critical than ever. This aligns with the fact that the root cause of 74% of breaches were identity-related or enabled, which aligns with Verizon DBIR findings over the last decade. 

Identity remains the leading reason for security breaches, yet tools and tactics remain the same, and organizations struggle to deploy and further mature their identity security programs. A shift in approach is required – a holistic, automatic approach to identity management and trusted identities is important automatic approach to identity management and trusted identities is important now and will be for years to come.

This year’s DBIR should be required reading for any enterprise as it will provide a roadmap as to how to protect your enterprise from getting pwned by hackers.

UPDATE: Chad McDonald, CISO, Radiant Logic had this to say:

     “One alarming stat from the 2023 DBIR is the rise in Privilege Misuse and Fraudulent Transactions, up 10% from 2022. For trusted actors in an organization to conduct these fraudulent transactions, they must have a level of privilege that allows access. This means that either the employee’s privileges were not monitored, or the threat actor was able to steal coworkers’ credentials and misuse them to follow through with their ambitions. Either way, this should be an alarming realization to organizations that have neither the spare time nor money to safeguard their assets against their own trusted insiders. Organizations can address this issue by creating full visibility into all users and their access privileges in an approachable, user-friendly way. Once this is accomplished, IT teams can be set up to streamline the management process of identities and ensure access privileges are in the right hands–and quickly revoked when needed.” 

Flashpoint Reports On Third Zero-Day Vulnerability For Google Chrome This Year

Posted in Commentary with tags on June 6, 2023 by itnerd

The Flashpoint research team has posted a blog post this morning about the latest Google Chrome zero-day vulnerability. You can read it here: 

https://flashpoint.io/blog/google-addresses-latest-zero-day-vulnerability-affecting-chrome/

Yesterday, Google addressed another zero-day vulnerability affecting Google Chrome. The Flashpoint Intel Team quickly published an alert to VulnDB customers and have been closely tracking the vulnerability since.

This is the third zero-day vulnerability reported in the popular browser so far this year. Exploitation of the vulnerability was noticed by Google’s own Threat Analysis Group (TAG), but details about active exploitation are currently limited.

While the vulnerability is reported in Google Chrome, the root cause lies within the bundled V8 JavaScript engine that is responsible for executing JavaScript when browsing websites. As a result, the vulnerability may affect other products bundling V8.

Mujjo Offers Up A 15% Discount To Celebrate B Corp Certification

Posted in Commentary with tags on June 6, 2023 by itnerd

Following up on the announcement that Mujjo is B Corp certified, which is the gold standard for third-party verified social and environmental performance, they’re offering a 15% discount off any product in their Leather Collection. Customers just need to use the code BCorp15 at checkout. 

Here’s a few highlights from the collection: 

Canopy AirTag Keychain
Full Leather Magnetic Wallet
Full Leather Wallet Case for iPhone
Echelon AirPods Pro Case

Appdome Partners With GitHub To Automate Delivery Of Secure Mobile Apps

Posted in Commentary with tags on June 6, 2023 by itnerd

 Appdome, the mobile app economy’s one and only Cyber Defense Automation platform, today announced it has integrated its platform with GitHub – the complete developer platform – to build, scale and deliver software. GitHub Actions is now part of the Appdome Dev2Cyber Agility Partner Initiative to accelerate the delivery of secure mobile apps globally. With this new integration, GitHub users can leverage Appdome’s configuration-as-code ease from inside GitHub and build any of Appdome’s security, anti-fraud, anti-malware, anti-cheat and other cyber defenses into Android and iOS apps. 

Appdome’s cyber defense automation platform streamlines delivery and accelerates release times by using technology to build cyber security defenses into iOS and Android apps – including runtime application self-protection (RASP), code obfuscation, mobile data encryption, jailbreak detection, root detection, man-in-the-middle attack prevention, on-device anti-malware, anti-fraud, anti-cheat, anti-bot and other protections. Manual methods of cyber defense implementations in Android and iOS apps are complex, slow and brittle. This solves mobile brands’ need for technology platforms to automate the delivery of cyber defense in mobile apps and to keep pace with modern DevOps pipelines. 

Today, global consumers demand more protection than ever in their mobile app experiences. As Appdome’s recent survey, Global Consumer Expectations of Mobile App Security, revealed, 94% of global consumers said they would promote a brand if the mobile apps protected them against security, fraud and malware risks. Sixty-eight percent also indicated they would abandon brands that offered no protection. 

For more information on how to use Appdome’s GitHub Actions workflow, please see this knowledge base article.  

Guest Post: Nearly 1,000,000 Apps rejected From The Apple App Store For Privacy Violations

Posted in Commentary with tags on June 6, 2023 by itnerd

From 2020 to 2022, Apple has rejected 958,000 applications from appearing on the App Store due to privacy violations, recent findings by Atlas VPN reveal.  

Apple has shared three annual reports on App Store fraud prevention since 2020, detailing how many fraudulent transactions they stopped, how many apps were rejected, user and developer accounts terminated, and similar data. 

Here, Atlas VPN analyzes all three of those reports in a single article to find trends and get a broader view of Apple’s App Store moderation efforts. 

One of the outliers in the year-over-year fraud prevention data is the number of apps rejected for privacy violations. 

The number of applications rejected due to privacy issues keeps increasing exponentially, from 215,000 rejections in 2020 to 400,000 in 2022. 

User privacy is a major concern, as there have been instances where apps collect more data than necessary or share it with third parties without proper disclosure or user consent. 

Many users may not fully understand the privacy implications of using certain apps or may not pay close attention to the permissions they grant when installing an app and unknowingly grant access to sensitive information.

To address these concerns, Apple has implemented various measures to protect user privacy, including app review guidelines, privacy labels, and app tracking transparency features. 

Apple stopped $5 billion in fraudulent transactions

One of the main focal points of Apple’s fraud prevention strategy is stopping fraudulent transactions. 

Since 2020, Apple has prevented over $5.09 billion in potentially fraudulent payments and blocked 10.2 stolen credit cards from transacting.

Apple takes credit card fraud extremely seriously, and remains committed to protecting the App Store and its users from this kind of stress.” Apple states in their annual report. 

Apple touts security to avoid third-party stores

One angle worth considering as to why Apple began releasing its fraud-prevention reports is to indirectly stand against the constant pressure to open up iPhones and iPads to third-party app stores. 

One of the main arguing points by Tim Cook as to why sideloading and third-party app stores should not be allowed is privacy issues: “data-hungry companies would be able to avoid our privacy rules, and once again track our users against their will,” he worryingly stated in IAPP conference in Washington, D.C. last year. 

Apple’s stance on third-party app stores has faced criticism and scrutiny from developers and regulators who argue that it limits competition and innovation. 

The App Store is a significant revenue source for Apple, as they take a 30% commission on most app purchases and in-app transactions. Allowing third-party app stores could potentially disrupt this financial model and revenue stream.

To read the full article, head over to: 

https://atlasvpn.com/blog/nearly-1-000-000-apps-rejected-from-apple-app-store-for-privacy-violations

Approov Secures Genopets Mobile Gaming App To Block Cheaters

Posted in Commentary with tags on June 6, 2023 by itnerd

Approov, the end-to-end mobile app security provider, today added Genopets, developer of a free-to-play mobile pet care game, to its growing user base while stopping cheaters from spoiling the fun.

The Genopets mobile pet care game lets players care for their digital pet while caring for themselves. The game uses step data from a player’s mobile device to power their journey in the game as they explore, battle, and evolve their Genopets — earning crypto while they play.

Genopets’ innovative and popular game attracted hackers and cheaters trying to use its APIs to manipulate data on the backend to gain unfair advantage of the game, spoiling the fun for players who played by the rules.

It selected Approov to protect its API resources from abuse and ensure that every request to its backend originated from its authentic app and an authentic mobile device.

Genopets users appreciate that Genopets take security seriously – both to protect users’ personal information at all times and to protect game fairness.