Archive for June 26, 2023

Grafana Critical Authentication Bypass Due To Azure AD Integration

Posted in Commentary with tags on June 26, 2023 by itnerd

When authentication uses sender email addresses, you should assume you’ve been breached.

In a critical advisory put out by Grafana, the popular open-source data analytics visualization application has been validating some users by their email claim. Grafana offers extensive integration options with a wide range of monitoring platforms and applications.

“Grafana validates Azure Active Directory accounts based on the email claim. On Azure AD, the profile email field is not unique across Azure AD tenants. This can enable a Grafana account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant Azure AD OAuth application.

“If exploited, the attacker can gain complete control of a user’s account, including access to private customer data and sensitive information. All users in Grafana deployments with Azure AD OAuth configured with a multi-tenant Azure app and that do not have allowed_groups configured are affected and can be compromised.”

According to Wikipedia, Grafana has over 1,000 paying customers, including well known organizations such as Wikimedia, Bloomberg, JP Morgan Chase, eBay, PayPal, and Sony.

Grafana has released security fixes for the vulnerability tracked as CVE-2023-3128.  The vuln received a CVSS v3.1 score of 9.4, a critical severity.

Roy Akerman, Co-Founder & CEO, Rezonate said this:

   “This critical vulnerability reported by Grafana introduces a major risk to organizations, their identities and data. Most often account takeover requires higher privileges to successfully being exploited, however in this case we see the simplicity of which a bad practice of AAD implementation allows an attacker to assume any user available. The risk of false impersonation however does not only exist in AAD and most probably not only for Grafana and therefore, the need, to monitor access attempts and compare past behavior information is needed to monitor for any suspicious access attempts.”

If you use Grafana, you should apply the patch related to this ASAP. Because given what this product does, it’s safe to assume that threat actors will attack those who have not applied the patch related to this issue.

American Airlines And Southwest Airlines Disclose 3rd Party Data Breach Affecting Pilots 

Posted in Commentary with tags on June 26, 2023 by itnerd

According to breach notifications filed on Friday by American Airlines and Southwest Airlines, both disclosed data breaches caused by the hack of Pilot Credentials, a third-party vendor that manages numerous airlines’ pilot applications and recruitment portals.
 
On May 3rd, the two airlines were informed an unauthorized individual gained access to Pilot Credentials’ systems on April 30 and stole documents containing the data of 5,745 American Airlines and 3,009 Southwest applicants in the pilot and cadet hiring process. The incident was limited solely to the systems of the third-party vendor, with no compromise on the airlines’ own networks.
 
“Our investigation determined that the data involved contained some of your personal information, such as your name and Social Security number, driver’s license number, passport number, date of birth, Airman Certificate number, and other government-issued identification number(s),” American Airlines revealed.

“We are no longer utilizing the vendor, and, moving forward, Pilot applicants are being directed to an internal portal managed by Southwest,” Southwest Airlines said.

Roy Akerman, Co-Founder & CEO, Rezonate had this to say:

   “Third party access and supply chain risks continue to be the leading reasons for recent security breaches. Whether critical information is managed by a third-party application, or a vendor has direct access to one’s infrastructure, additional security risk is introduced and therefore must be monitored and controlled. While organizations are realizing more and more that third party risk is their risk, more work is required to enable this awareness across people, technology and processes.”

Supply chain attacks are real. Thus organizations need to make sure that the diligence that they apply to their internal systems is applied to all the external systems that they use. That way the chances of getting pwned by hackers is way less.

Confirmed: Petro Canada Parent Company Pwned By Hackers

Posted in Commentary with tags on June 26, 2023 by itnerd

Yesterday, I noted that every Petro Canada gas station that I went to wasn’t accepting debit or credit cards. Instead they were cash only. And their mobile app wasn’t working as well. At the time, I said this:

But this reminds me of the Sobeys situation as well as the Garmin situation. In both cases, normal business was disrupted for some period of time. Neither company commented in any significant way on their issues. Then it later came out that both companies were pwned by ransomware. This Petro Canada situation has that feel to it. 

It appears that I might have been correct on them getting pwned by hackers. As per Reuters:

Canadian energy firm Suncor on Sunday said it experienced a cybersecurity incident, adding that some transactions with customers and suppliers could be impacted while they investigate and resolve the situation.

“At this time, we are not aware of any evidence that customer, supplier or employee data has been compromised or misused as a result of this situation,” the company said in a statement.

Suncor owns Petro Canada. Thus if Suncor has been pwned, Petro Canada has been pwned. The question that we all have to be asking is what did the hackers do (chances are it’s ransomware, but let’s leave that question open ended for now) and what info did they steal? And is any of that information personally identifiable information? For example, I use the Petro Canada app, is any of my info on the dark web someplace? These are all questions that Petro Canada needs to answer. And answer soon as silence isn’t an option if they want to regain the trust of Canadians that almost certainly been shaken because of this incident.

Reddit’s New Problem: The Lack Of Accessibility Features

Posted in Commentary with tags on June 26, 2023 by itnerd

Well, this is going from bad to worse for Reddit. On top of everything else that’s going on with the API protests, and Reddit’s frankly ham fisted response to them. The company has a new problem. Accessibility. Or rather the lack of it. Via The Verge:

Reddit will make “accessibility improvements” to many moderator tools in its official mobile apps by July 1st, the company announced on Friday

Some moderators rely on third-party apps because Reddit’s apps have what they characterize as “significant accessibility challenges,” and the accessibility community has expressed concerns over how they will moderate on mobile after popular apps like Apollo shut down on June 30th due to potentially expensive API pricing changes. It seems this roadmap, which promises improvements to features like the moderation queue and the ModMail messaging system on Android and iOS, is intended to assuage those fears.

Based on the replies to the announcement post, however, many are still unhappy with the company’s plans. “A multibillion dollar corporation forcing disabled people (including the profoundly disabled) to simply ‘learn new tools,’ and to stop using the accessibility tools they’re used to — the tools they depend on — to access / moderate the communities they depend on — is cruel,” wrote PotRoastPotato, a moderator who has advocated for disabled communities as part of the recent protests across Reddit. “As long as there are disabled users who depend on and are accustomed to the accessibility features of third-party apps, these apps need to be preserved,” PotRoastPotato added in an email to The Verge.

Reddit’s roadmap notes that some features won’t be available until late July or sometime in August, and some are critiquing the company for that choice. “Why are these not blockers that you are forcing Reddit to delay API changes for?” one user wrote. “Do you find it acceptable to have an inherently worse moderator accessibility experience while pulling the rug out from underneath the community?”

Well, I am sure that this isn’t the response that Steve Huffman and company were hoping for. But it’s Reddit’s fault that they are in this situation. If they thought this whole situation through rather than taking an Elon Musk approach to this, perhaps they would be in a different place. But much like Elon Musk, Steve Huffman doesn’t strike me as the type to think things through. Instead he strikes me as the type to just do stuff and then be surprised when there’s blowback. This is another reason, on top of the ones that I outlined here, why Reddit is doomed.

UPDATE: Meanwhile on Reddit, posts like this are starting to appear:

This situation may be about to get really bad for Reddit.