Archive for July 12, 2023

Stealthy Microsoft-Signed Rootkit Target The Gaming Sector

Posted in Commentary with tags on July 12, 2023 by itnerd

Trend Micro researchers have a report on a signed rootkit that communicates with a large C&C infrastructure whose main victims are the gaming sector in China. The malware appears to have passed through the Windows Hardware Quality Labs (WHQL) process for getting a valid signature. Which to me is mind-blowing. I’ll explain why in a moment.

The malware goes to great lengths to remain stealthy and take control of the target systems, most of which should set off red flags:

  • Disables the User Account Control (UAC) and Secure Desktop mode
  • Initializes Winsock Kernel objects for initiating network comms with the C&C server
  • Periodically connects to the C&C server, retrieves and decrypts new payloads and loads them directly into memory (never touching the disk to bypass detections)
  • Plug-ins modify the Registry to achieve persistence, disarm Microsoft Defender Antivirus, and deploy a proxy on the machine, redirecting web browsing traffic to a remote proxy

Dave Ratner, CEO, HYAS had this to say:

“This is yet another example where having visibility into anomalous communication to command-and-control structures, aka adversary infrastructure, is a vital part of a defense-in-depth strategy and a key component of the overall security stack.  If organizations haven’t yet deployed Protective DNS across their infrastructure and environments, they should make plans to do so immediately.”

Why this blows my mind is simple. The whole point of having signed drivers is to stop this scenario dead. But it seems that somehow the threat actors managed to take advantage of the WHQL process to execute their plans. Hopefully Microsoft can do something to make this scenario far less likely in the future.

Uber celebrates National Ice Cream Day by sharing sweet trends and deals

Posted in Commentary with tags on July 12, 2023 by itnerd

National Ice Cream Day is coming up on Sunday, July 16th, serving up some much-needed cool amidst the record-breaking heat. To celebrate, Uber Canada is sharing some chill trends revealing how Canadians are getting their ice cream fix, from top flavours and the largest ice cream orders to which cities have the biggest sweet tooth.  

  • Getting straight to the pint: Halifax, NS takes the title of the Canadian city with the biggest sweet tooth, with eaters ordering ice cream more than in any other city in the country. Hamilton and Ottawa take second and third place, followed by Toronto in fourth. 
  • Moo-ve over dairy: Ottawa, ON residents search for dairy-free ice cream more than anywhere else in the country.
  • Legen-dairy ice cream orders: London, ON had the largest ice cream order in the last year consisting of nine boxes of milk chocolate ice cream bars with nuts—because one is never enough.
  • The inside scoop on top flavours: When it comes to the most popular flavours, Canadians stick to the classics, including chocolate, vanilla and berry, but are also sampling mango, coffee and taro.

And for the cherry on top, we’re also sharing exclusive ice cream deals on Uber Eats in honour of everyone’s flavour-ite holiday. Baskin Robbins is offering a BOGO for their 3 Take Home Sundae flavours when you order for delivery through the Uber Eats app. 

Check out some highlights from Uber’s National Ice Cream Day trends:

Top 10 cities in Canada that order ice cream the most:

  1. Halifax 
  2. Hamilton 
  3. Ottawa 
  4. Toronto 
  5. Kingston
  6. Kitchener-Waterloo
  7. Vancouver 
  8. Edmonton 
  9. Calgary 
  10. Montreal 

Top 10 flavours in Canada

  1. Chocolate 
  2. Vanilla 
  3. Berry 
  4. Caramel 
  5. Peanut butter 
  6. Cherry 
  7. Hazelnut 
  8. Mango 
  9. Taro
  10. Coffee

Twitter Took Yet Another Dirt Nap Today…. Expect More People To Sign Up For Threads As A Result

Posted in Commentary with tags on July 12, 2023 by itnerd

If you’re Elon Musk, it’s bad enough that Threads exists and is taking your breakfast, lunch, and dinner. But it’s worse that you can’t keep your site up and functioning for users. I cite DownDetector as a source for today’s latest Twitter outage:

I also cite this Daily Mirror story that confirms that Twitter took a dirt nap today:

Twitter experienced a worldwide outage for more than one hour Wednesday  – another blow for Elon Musk, who is battling Meta over its newly launched Threads.DownDetector, which monitors online issues, began to receive issue reports around 10:22 am ET.

And:

Many have shared that their tweets are not loading and Timelines are not updating.

It is unclear what sparked the outage or how long it will last. DownDetector’s US outage map showed New York City all in red- meaning it is hit hard – followed by Boston, Dallas and other major cities nationwide. 

At the peak, more than 6,000 Americans issued reports to DownDetector. 

Countries like Italy, China, the UK and other parts of Europe were also experiencing problems. 

This isn’t going to help Elon to stop Twitter users from running to Threads. In fact, I expect it to accelerate the defection of Twitter users to Threads. Which means that Mark Zuckerberg and a huge percentage of the Internet are going to have a great laugh at Elon’s expense.

Microsoft Attacked By Hackers Linked To China In Cyber Espionage Campaign

Posted in Commentary with tags on July 12, 2023 by itnerd

Microsoft said in a blog post published late yesterday that hackers linked to China, dubbed Storm-0558, broke into email accounts at approximately 25 organizations, including some U.S. government agencies, and hit consumer accounts as part of a suspected cyber-espionage campaign to access data in sensitive computer networks.   

The hackers took advantage of a security weakness in Microsoft’s cloud-computing environment gaining access to victims’ email by forging digital tokens beginning on May 15 and operated in stealth for more than a month, until June 16, when Microsoft began its investigation and mitigated the situation.  

“Last month, U.S. government safeguards identified an intrusion in Microsoft’s cloud security, which affected unclassified systems. Officials immediately contacted Microsoft to find the source and vulnerability in their cloud service. We continue to hold the procurement providers of the U.S. government to a high security threshold,” Adam Hodge, spokesman for the White House National Security Council, said.  

The full scope and severity of the incident, and which institutions and individuals were hacked, are currently not available. 

Willy Leichter, VP, Cyware had this comment:  

“Attacks like this will continue to grow in frequency, as vulnerabilities are inevitable, and many well-funded hacking groups are always looking to exploit them. The critical test is how quickly organizations like Microsoft react and take definitive action to stop the spread. In this case, 3+ weeks from the problem being reported to being fixed is well above industry average, but still leaves a large window of exposure. But compared to SolarWinds (which was exploited for months), we’re making progress.”

It’s clear from attacks like this one that nation states with hostile intent are coming for you and your infrastructure. Thus you need to ensure that your defences are in place to either stop them, or at least quickly detect them so that you can take the required action to stop them.

UPDATE: Snehal Antani, CEO and Co-Founder of Horizon3.ai adds this:   

“With everyone pointing fingers at Microsoft, there actually is a bigger concern. When thinking about credential stuffing, this attack is used to first gain access to credentials for one online account, and then use those same credentials to access other online accounts. Was that the motive?    

“In terms of password spraying, this attack is focused on reusing a username without knowing the password. Attackers then try commonly used passwords to log in to other systems. Maybe this was the motive? Either way, the key takeaway is that there is now a long tail of risk that exists for all victims of the compromise which could extend for quite a long period of time.” 

Laminar Adds Data Access Governance (DAG) and Data Detection and Response (DDR) to Data Security Platform

Posted in Commentary with tags on July 12, 2023 by itnerd

Laminar, the leading agile data security platform provider, today announced new data access governance (DAG) and data detection and response (DDR) functions to its Laminar Data Security Platform, making it the first solution on the market to deliver complete identify, protect, detect, and respond capabilities for multi-cloud and SaaS data security. Laminar is now the only data security provider to integrate all critical data security functions – data landscape intelligence, data security posture management (DSPM), DAG, DDR, and privacy and compliance – in a single, integrated platform.   

Data security and governance professionals need agile data security solutions that automatically scale with the business to combat the growing divergence between the dynamic and ever-growing activities that contribute to innovation while also fighting the lagging data security efforts intended to protect the business — that are becoming increasingly insufficient. 

The foundation of agile data security begins with cloud-native data discovery and classification which detects all known and unknown, or “shadow,” data to help organizations understand what data resides where, how sensitive the data is, and who or what has access to it. With this context, security posture can be assessed and appropriately enforced. From there, it’s critical to have the ability to continually monitor and protect against emerging threats.  

The addition of DAG and DDR to the Laminar Data Security Platform provides the following benefits to organizations:

  • Data Access Governance (DAG) reduces exposure and minimizes the blast radius from data leaks by controlling user and machine access to sensitive data and ensuring least privilege.         
  • Data Detection and Response (DDR) alerts on data breaches and other anomalies as they occur to quickly contain any active threats and minimize the potential damage for businesses.  

The new DAG and DDR services complement the following capabilities already existing in the Laminar Data Security Platform:  

  • Data Landscape Intelligence: Provides a holistic view of asset and data inventory with contextual intelligence from autonomous discovery and classification of all known and unknown cloud data. 
  • Data Security Posture Management (DSPM): Enforces policies and safeguards sensitive data with risk-based prioritization, enabling organizations to focus on what matters most.        
  • Privacy & Compliance: Ensures data security practices align with regulations and standards to streamline audits, avoid fines and reduce audit costs.  

Laminar is the only data security provider to now integrate all five elements of an agile platform architecture for a complete data security solution. This integrated design provides more accurate detection, comprehensively protects data, and streamlines remediation.    

To learn more about the Laminar Data Security Platform, visit https://laminarsecurity.com.   

Cradlepoint Announces 5G SASE Strategy for Cellular and Hybrid WAN Security

Posted in Commentary with tags on July 12, 2023 by itnerd

Cradlepoint, the global leader in cloud-delivered LTE and 5G wireless network edge solutions, today announced its phased rollout strategy for the industry’s first 5G-optimized Secure Access Service Edge (SASE) solution designed for the enterprise and purpose-built for Wireless Wide Area Network (WAN) deployments. With unique cellular capabilities and the simplicity of Cradlepoint’s cloud-based management platform, NetCloud Manager, Cradlepoint 5G SASE features zero trust, cellular intelligence along with cloud and SIM-based security to address the challenges and threats faced by today’s extended enterprise.

As enterprises evolve beyond fixed sites to include mobile and IoT, they are looking to the flexibility and agility of Wireless WAN and 5G. These geographically dispersed networks, combined with the proliferation of connected devices and ill-fitting network security solutions, can significantly increase security vulnerability. With IoT device deployments projected to reach 30 billion by 2027, and the perennial IT talent shortage, the seamless integration of 5G-centric SASE solutions to manage Wireless WAN infrastructure is critical.

As an industry leader in Wireless WANs and with the recent acquisition of Ericom, Cradlepoint is uniquely positioned to deliver a comprehensive 5G-optimized SASE solution that enables organizations to seamlessly match the security challenges of extended networks. Cradlepoint 5G SASE will be delivered in phases over the next 12 months:

  • Cradlepoint Cellular Intelligence: Available today, cellular telemetries, such as signal strength and data plan usage, can be leveraged for SD-WAN traffic steering. As 5G StandAlone (SA) networks become mainstream, Cradlepoint’s network slicing capabilities will work with carriers’ services to offer prioritization and slice-based isolation.
  • SIM-based Security: Cradlepoint offers SIM management and GPS tracking to secure the physical devices and to detect rogue movement. Cradlepoint’s vision for the future is to work with carriers for tighter SIM-based security using SIMs as the basis for authentication, regardless of the connecting hardware. 
  • Connect-and-Go Zero Trust Security: Creating WANs in just a few clicks, 5G SASE replaces complex VPNs. Zero trust shrinks the lateral attack surface—devices connected to a Cradlepoint router are immediately dark to the outside world and other sites. Soon, this capability will be delivered from the cloud, offering an easier deployment option.
  • Cloud-Delivered Security: Ericom’s full suite of SSE solutions, including SWG, CASB, RBI and DLP, protects users browsing in fixed and mobile environments from threats such as phishing and ransomware. Cradlepoint will integrate these capabilities with existing zero trust and SD-WAN solutions into Cradlepoint NetCloud for a single pane of glass user experience for IT teams.

Cradlepoint’s security portfolio is augmented by leading industry security solutions through Cradlepoint Technical Alliance Partners.

To learn more about Cradlepoint security capabilities, please visit their Security Solutions page.

Cyware Expands Partnership with ZeroFox

Posted in Commentary with tags on July 12, 2023 by itnerd

Cyware, the leading provider of threat intelligence management, security collaboration, and cyber fusion solutions, today announced that ZeroFox, an enterprise software-as-a-service leader in external cybersecurity, has been added to the Cyware Partner Advisory Marketplace, making select ZeroFox threat advisories available to Cyware customers including all ISAC and ISAO sharing communities powered by Cyware.

The Cyware Partner Advisory Marketplace provides a platform for security vendors to make intelligence feeds easily available to Cyware’s extensive network of direct customers, and members of ISACs, ISAOs, and other intelligence sharing communities. These vendors can make free or subscription-based premium feeds available to thousands of enterprises using the Cyware Collaborate solution. In addition to ZeroFox, the Advisory Marketplace includes intelligence feeds from RiskIQ, Flashpoint, Polyswarm, and others. These advisories include timely alerts on malware, vulnerabilities, threat actors, attack campaigns, and other critical threats.

ZeroFox’s comprehensive threat intelligence feeds are already well integrated into the Cyware Intel Exchange (CTIX) and Orchestrate modules, enabling the full range of Cyware’s Cyber Fusion capabilities, including threat aggregation, prioritization, enrichment, sharing, orchestration, and intelligence-based actions. ZeroFox enhances these models by leveraging global intelligence collection and analysis across a broad set of data sources, continuously monitoring the surface, deep, and dark web to detect external cyber threats.

10 Canadian female business-owner recipients a of She’s Next Grant Program announced

Posted in Commentary with tags on July 12, 2023 by itnerd

Visa Canada today announced 10 recipients of its She’s Next Grant Program. Reflecting a wide range of consumer products and services, the recipients are innovating, creating new jobs, and driving economic growth. Through this initiative, recipients each receive a $10,000 CAD grant and access to an accelerated mentorship program through York University. 

According to Visa Canada’s latest Small Business Pulse report, funding is particularly important for women-owned businesses with 40% of women-owned SMBs citing they have sought or anticipate seeking new financing in 2023 and 42% concerned with the lack of available financing options.

Through its She’s Next Grant Program, to date Visa has awarded 50 grants to women-owned small businesses, totalling $500,000 CAD and countless hours of coaching to women founders across Canada. Today’s recipients include: 

Barumba Play, Thornhill, ON: Barumba Play supports imaginative fun through its signature 11-piece, life-sized play couch. Barumba Play exists to better the toy industry while making life easier for families through the development of high-quality, open-ended toys that are designed with kids and parents in mind. 

Goldminds Class, Mississauga, ON: Goldminds Class provides research-backed, engaging classes designed to teach kids how to understand, accept and process their emotions while providing calming strategies to manage them now, so that they are set up for success later. 

Little Yogis Academy, Toronto, ON: Little Yogis is a mobile yoga and mindfulness program for kids in Canada age 2.5 to 13 years with the goal of improving physical, mental, and emotional health through our curriculum. It partners with schools, childcare centres, non-profit, and for-profit organizations to improve the health and wellness of our communities. 

Luna Nectar, Vancouver, BC: Nectar is a line of sustainable, waterless hair density and haircare products that are kicking the taboo of women’s hair loss. Luna Nector uses naturally occurring actives that make up most of each formula. No unnecessary fillers or false fragrances. Every drop is as good as nectar for your hair and skin. 

Mindful Monk, Langley, BC: Mindful Monk, a chocolate company geared for diabetes, was created in 2020 to help people make better nutrition choices and lead healthier, happier, and longer lives. 

Sootsoap Supply Co. Ltd., Coburg, ON: Originally developed for firefighters’ decontamination, SOOTSOAP is an all-natural, industrial strength line of personal care products formulated with the power of white charcoal to detoxify skin and hair and combat odours onsite, at home and on-the-go.  

Tacit, Toronto, ON: Tacit is an online art gallery and consultancy dedicated to amplifying female creatives in a way that is approachable to the emerging art collector. Its goal is to address the disparity between women and men as art by women accounts for a mere 2% of the art sold. 

The Dough Parlour, Oakville, ON: Dough Parlour manufactures sweet fruity-scented play dough made from 100% non-toxic, natural food-grade materials. It is the premium, eco-friendly alternative to store bought play dough and caters to eco- and health-conscious parents and families. 

VG Gourmet Vegetarian Foods Inc. St. Laurent, QC: VG Gourmet’s mission is to make better, healthier and more gourmet food products. Products contain only ingredients you can pronounce because you deserve to know what you’re eating. It’s not just plant-based, it’s just plants. 

Wolfe Co. Apparel and Goods, Huntsville, ON: Proudly made in Canada, Wolfe Co. casual clothing is rooted in its uncompromising commitment to quality domestic product and now has customers across the country and abroad. 

The Visa She’s Next Grant Program and initiatives like the Visa Canada Small Business Hub, which has resources and solutions to support small businesses in driving efficiency, fraud mitigation, and sales through the expansion of e-commerce, digital payments, marketing, and more, are part of the Visa commitment to supporting Canadian businesses.  

To learn more about the program and recipients, visit: Visa.ca/grantprogram

Former Water Treatment Plant Employee Charged With Remote Attack 

Posted in Commentary with tags on July 12, 2023 by itnerd

In a press release, the U.S. Department of Justice said that a former employee of Discovery Bay Water Treatment Facility in California was indicted by a federal grand jury for intentionally attempting to cause a malfunction to the facility’s safety and protection systems. 

Employed as an “instrumentation and control tech” between July 2016 and December 2020 for a private Massachusetts company under contract with the facility, the indictment alleges that Rambler Gallo had installed remote control software on his employer’s systems as well as his personal computer. After resigning from his job in January 2021, he used his personal computer to send remote commands to the water treatment’s computers to uninstall critical software tools responsible for monitoring water pressure, filtration, and chemical levels on the water. Although the reason is unknown, it is assumed his intent was to cause harm.  

According to the indictment, filed June 27, 2023, and unsealed earlier today, prior to the attack on the Discovery Bay Water Treatment facility, Gallo, 53, of Tracy, Calif., was a full-time employee of a private Massachusetts-based company identified in the indictment as Company A. Company A contracted with Discovery Bay to operate the town’s wastewater treatment facility; the facility provides treatment for the water and wastewater systems for the town’s 15,000 residents. During his employment with Company A, from July of 2016 until December of 2020, Gallo was the company’s “Instrumentation and Control Tech,” with responsibility for maintaining the instrumentation and the computer systems used to control the electromechanical processes of the facility in Discovery Bay.

The indictment alleges that while Gallo was employed with Company A, he installed software on his own personal computer and on Company A’s private internal network that allowed him to gain remote access to Discovery Bay’s Water Treatment facility computer network. Then, in January of 2021, after Gallo had resigned from Company A, he allegedly accessed the facility’s computer system remotely and transmitted a command to uninstall software that was the main hub of the facility’s computer network and that protected the entire water treatment system, including water pressure, filtration, and chemical levels.

The indictment charges Gallo with one count of transmitting a program, information, code, and command to cause damage to a protected computer, in violation of 18 U.S.C. §§ 1030(a)(5)(A) and (c)(4)(B)(i).If convicted, Gallo faces a maximum statutory penalty of 10 years in prison and a fine of $250,000.

Roy Akerman, Co-Founder & CEO, Rezonate had this comment:

      “Insider threats are an uprising risk to organizations of all sizes across all verticals. An over privileged workforce raises the question of who is “watching the watchers.” The case of the Discovery Bay Water Treatment Facility in California appears to be a faulty deprovisioning process, but any administrative access that lacks the proper permissions processes around it is a huge vulnerability – regardless of who the user is. Never trust, always verify.” 

Insider threats are more dangerous than external ones because they’re already in. Organizations need to make sure that the threats posed by insiders are not only minimized as much as possible, but addressed quickly if they turn out to be a real threat.

The Flashpoint Research Team Offers 10 Takeaways From Clop Ransomware Plus Practical Advice For How To Navigate Attacks

Posted in Commentary with tags on July 12, 2023 by itnerd

Flashpoint has put up a post on LinkedIn about the 10 Takeaways from Clop ransomware including the details we feel are key when dealing with the fallout of a major cyber extortion or ransomware event, either directly or via a third-party provider. It’s a very interesting read and well worth your time.

You can find the post here: https://www.linkedin.com/pulse/10-takeaways-from-clop-practical-advice-navigating-high-profile/