Archive for July 7, 2023

Shell Becomes The Latest Company To Be Pwned By The MOVEit Vulnerability

Posted in Commentary with tags on July 7, 2023 by itnerd

Shell has confirmed in a very brief statement that hackers accessed the personal information of some employees as part of the global MOVEit Transfer tool vulnerability exploitation.  

The Clop ransomware group claims on its leak site that it published Shell’s data after the company refused to negotiate, but the links to the 23 archive files labeled ‘part1’ appear to be broken. Shell currently has 86,000 employees around the world, but they did not mention how many of those employees may have been affected or what data was be stolen. 

Shell was also targeted by the Cl0p group in 2020, through a zero-day exploit targeting an Accellion file transfer service. 

According to Brett Callow, threat analyst at Emsisoft, so far, the vulnerability in MOVEit has pwned this number of organizations: 

Carol Volk, EVP, BullWall had this to say:

   “According to Brett Callow, threat analyst at Emsisoft, so far, the vulnerability in MOVEit has Affected more than 17.5 million people’s PII. Much of this information will be used in attempts to access networks and some of those attempts will be successful. At this rate of exposure is almost impossible to fully protect networks from intrusion. Get your defenses up – get your backup and containment systems ready, they are definitely coming for the rest of us.”

Stephen Gates, Principal Security SME, Horizon3.ai followed up with this:

   “The MOVEit debacle, and associate breaches now impacting 17.5+ million people (and counting), will likely go down in history as proof that organizations must do a better job of immediately applying patches when they are available. When organizations wait to apply patches means the window of opportunity is wide open for attackers.

   “Although multiple patches have been available to address CVE-2023-36934, 36933, and 36932, the Clop ransomware group is still making claims that it has compromised data from many organizations. The conclusion one can draw from this is that many organizations have not applied the patches. So why is that probably the case?

  1. Organizations may be delaying, seeing if there are any new vulnerabilities lying in wait.
  2. They may be waiting for a final patch to avoid multiple patch cycles.
  3. They may be waiting for an approved maintenance window to patch.
  4. They do not believe they are exploitable or that the risk of exploitation is low.
  5. They are completely unaware of the issue at hand.

   “Regardless of their reasoning, organizations are putting tens of millions of people at risk.”

I think it’s more than clear that the MOVEit vulnerability is a “today problem.” Organizations need to patch. And then if new patches come out, they need to patch some more. Alternately they can just dump MOVEit. Either way, sitting on the sidelines is not an option.

NEW REPORT: Canada can’t reach net-zero without digital technology

Posted in Commentary with tags on July 7, 2023 by itnerd

Telecommunications play a critical role in the climate change discussion. It’s why companies like TELUS are invited to sit at the strategy table with wildfire experts during increasingly severe fire seasons. With climate change fuelling increasingly severe wildfires across Canada, TELUS has been building specialized expertise to ensure vital lines of communication remain open so that impacted residents and emergency providers are connected to reliable networks when and where they are needed the most. By necessity, that expertise has now expanded to seasonal flooding. 

TELUS is also looking to the future; specifically, supporting Canada in reaching its Paris climate targets through digital technology. 

A new report “Clean Connection: How Digitiation Can Support Canada’s Path to Net-Zero” developed by Toronto Metropolitan University in partnership with 17 cross-industry organizations, and sponsored by TELUS, has found that digital tech — missing from Canada’s climate action plan — is a virtually untapped resource and the missing link in Canada’s journey toward net-zero. The report lays out 10 recommendations that industry actors and policy-makers should take to realize the benefits that connectivity can have on lowering emissions.

The public conversation surrounding climate change policy completely misses this data-backed reality.

Here is the link to the report: https://dais.ca/reports/clean-connection-how-digitization-can-support-canadas-path-to-net-zero/

Reddit To Subreddits Who Marked Themselves NSFW In Protest…. This Is Your Final Warning

Posted in Commentary on July 7, 2023 by itnerd

Clearly the API protests that have led numerous subreddits to mark themselves NSFW in protest, which in turn deprives Reddit of advertising dollars, is hurting reddit. I say that because news is filtering out that Reddit has given these subreddits a “final warning” to drop the NSFW tags:

However, Reddit has sent messages to the mods of those subreddits saying they must “immediately correct” their NSFW labeling, claiming each community “has not historically been considered NSFW nor would they under our current policies.” If the designation isn’t corrected, any moderators involved in that decision will be removed. Those mods may be “subject to additional actions,” such as losing the ability to join future moderator teams.

And:

Here is the message from Reddit, as shared by the r/PICS moderators:

This is a final warning for inaccurately labeling your community NSFW which is a violation of the Mod Code of Conduct rule 2. Your subreddit has not historically been considered NSFW nor would they under our current policies.

Please immediately correct the NSFW labeling on your subreddit. Failure to do so will result in action being taken on your moderator team by the end of this week. This means moderators involved in this activity will be removed from this mod team. Moderators may also be subject to additional actions, e.g., losing the ability to join mod teams in the future.

Lastly, if you suddenly begin to post, or approve content that features sexually explicit content to your community in order to justify the NSFW label, we will immediately remove and permanently suspend moderators who have participated in this action.

Is it just me or are Steve Huffman and company being real bullies here? They are really trying to make this go away by any means other than to actually try to address the concerns of those who are protesting. Assuming that the actions of Huffman and company are based on the fact that they want to IPO Reddit and cash in, this sort of thing isn’t going to help because of the bad press that actions like these generate. Not to mention that it sends users running for places other than Reddit. Honestly, Huffman and company need to rethink this before they drive Reddit into extinction.

Human Error is Still Leading Cause of Cloud Data Breaches

Posted in Commentary with tags , on July 7, 2023 by itnerd

According to the 2023 Thales Global Cloud Security Study, of the 39% of businesses that experienced a data breach in their cloud environment in 2022, the leading cause of these breaches was human error, at 55%, significantly above the next highest factor which was vulnerabilities exploitation, 21%.

Also measured is a 41% rise in SaaS usage from 2021 to 2023. With these applications usually replacing on-premises application functionality, 55% of cyber professionals say this increase has made it more complex to secure data in the cloud. Meanwhile, the risk is compounded with 75% of respondents saying that more than 40% of data stored in their organizations’ cloud was ‘sensitive.’

The targeting of users to infiltrate cloud networks is a trend being observed by other cybersecurity companies as we shared in Proofpoint’s June report The Human Factor 2023. Matt Cooke, Cybersecurity Strategist at Proofpoint told Infosecurity: 

  • “Attackers realize that people and their accounts are still the vulnerability. And it actually doesn’t matter now where that person is because everyone’s pretty much using the same tools. For example, everyone’s got a Microsoft 365 account.”

George McGregor, VP, Approov had this to say:

“A key recommendation of the report is to take steps to manage keys. As cloud services and APIs proliferate so do the keys and credentials used to access them. In particular, keys exposed in mobile app code can provide a path to cloud services for hackers, and central key management should be used to ensure keys are not exposed in code.”

Since we all work in the cloud for a variety of reasons, it makes sense that everything that be done to make the cloud a safe place to work and store data in. Which means that everyone needs to do everything possible to remove the human element from the cloud security equation.

Trend Micro Details How Cybercriminals Use AI and ChatGPT For Extortion Scams

Posted in Commentary with tags on July 7, 2023 by itnerd

Although emerging technologies such as AI are being developed to increase efficiency and make our lives easier, cases in which these technologies have been exploited are becoming increasingly frequent. Cybercriminals have been extorting innocent people through deepfake technology and the use of manipulated photos and videos to carry out these scams, which have  resulted in losses of $2.6 billion last year alone.

Young people and public figures are the most at risk of falling victim to these attacks. These individuals are prone to having their voice cloned due to their large social media presence. While AI Voice Cloning has provided comic relief using voice filters and allowed us to listen to classic songs from different artists, it has also allowed cybercriminals to adopt another avenue of crime. AI tools such as VoiceLab can harvest a person’s voice biometrics, producing a deepfake voice that would sound exactly like them. Coupled with an input script from a movie, it can cause close family and friends to believe their loved one has been abducted.

Additionally, by using ChatGPT, attackers can fuse large datasets of potential victims with voice, video and signal data information, and SIM jacking allows threat actors to control the kidnappee’s phone, making it difficult to track and unreachable.

You can read the full report by Trend Micro here: https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/how-cybercriminals-can-perform-virtual-kidnapping-scams-using-ai-voice-cloning-tools-and-chatgpt

ALPHV Claims To Have Pwned An NHS Trust… And The Pwnage Could Be Huge

Posted in Commentary with tags on July 7, 2023 by itnerd

The Russian gang ALPHV claimed on its website last week that it had obtained seven terabytes of internal documents from the Barts Health NHS Trust, a network of five hospitals in London that care for about 2.5 million people, and threatened to post them online unless a ransom is paid.

 A spokesperson for the UK’s National Cybersecurity Centre said in a statement on Wednesday that it was “working with Barts Health NHS Trust and partners to fully understand the impact of an incident,” and a spokesperson for Barts said that it was “urgently investigating” the hacking gang’s claims.
 
The extent of the damage caused by this incident isn’t clear yet, but the gang published a selection of files it said it stole, including copies of employees’ driving licenses and passports, internal emails and correspondence marked confidential. In broken English, the hackers claimed that the haul of data amounted to the “most bigger leak from health care system in UK.”
 
The breach marks the third major cyberattack that Barts has faced in the last six years.

Roy Akerman, Co-Founder & CEO, Rezonate had this to say:

 “Healthcare providers continue to be a target for malicious adversary and in particular Ransomware groups. The PII reported stolen is valuable intelligence attackers are constantly trying to obtain to be used as follow up attacks and sell them to the highest bidder. As such, healthcare providers must validate their security and assure readiness at all times, across every initial attack technique as well as the detection and prevention once the attacker tries to expand across the network.”

Carol Volk, EVP, BullWall follows up with this:

   “This new cyberattack on the Barts Health NHS Trust highlights the persistent and growing dangers of ransomware in the health sector. This incident serves as a stark reminder of the urgent need for robust cybersecurity measures, including ransomware containment, to be made mandatory for organizations in the healthcare industry. This breach not only poses a significant risk to the affected individuals but again raises broader concerns regarding patient privacy and the security of healthcare systems as a whole.

   “What makes this incident particularly alarming is that it is the third major cyberattack that Barts Health NHS Trust has faced in the past six years. This pattern of repeated attacks underscores the vulnerability of the healthcare sector to cyber threats. It is imperative that healthcare organizations prioritize cybersecurity investments and adopt proactive measures to safeguard patient data and critical infrastructure.”

 Roy Akerman, Co-Founder & CEO, Rezonate concludes with this:

 “Healthcare providers continue to be a target for malicious adversary and in particular Ransomware groups. The PII reported stolen is valuable intelligence attackers are constantly trying to obtain to be used as follow up attacks and sell them to the highest bidder. As such, healthcare providers must validate their security and assure readiness at all times, across every initial attack technique as well as the detection and prevention once the attacker tries to expand across the network.”

We’ll find out the full scale of this breach soon enough, assuming that this breach actually happened. Consider this one of those stories to stay tuned to.