Archive for December, 2023

Beeper Has A Fix For Their Latest Issues …. But It Requires A Mac

Posted in Commentary with tags on December 19, 2023 by itnerd

Earlier this week, Beeper Minin was having issues, again, with their iMessage on Android service. As I type this, at least 60% of their users are affected. And like their last outage, you can thank Apple for Beeper’s issues.

Now fast forward to today. This Reddit post says that the company has a fix that is coming tomorrow. But the Devil is in the detail:

The fact that you need a Mac needs that you have to hop through a bunch of hoops to make it work. It’s not worth it if it were me. But if you really want iMessage on your Android phone, I guess you have to do what you need to do to get your fix.

I have to wonder how long it would take before Apple shuts them down again seeing as Beeper has basically telegraphed what they are doing so that Apple can figure out how to kill it. I also wonder how long Apple is going to play cat and mouse with these guys before sending in the iLawyers.

Retailers Brace For ‘Returns Tsunami’ As Salesforce Anticipates 131B Holiday Orders Returned In New Year

Posted in Commentary with tags on December 19, 2023 by itnerd

As we enter the final countdown to the festive period, Salesforce has shared a snapshot of post-Cyber Cyber Week momentum (Nov 29 – Dec 18) through data across commerce, marketing, and service from over 1.5 billion consumers shopping on retail sites:

  • Canadian sales continue to grow YoY: Over this period, Canada bucked the trend and saw 5% YoY growth in online sales
    • Meanwhile, global online sales remained flat year-over-year.
  • Retailers in for a ‘Return Tsunami’: The post-Cyber Week period saw a ‘returns tsunami’ globallyThe percentage of returns more than doubled during the week following Cyber Week and has remained high since. 
    • As consumers become more discerning about discretionary spending, this increase in returns indicates the consumers may be thinking twice about their purchases and returning those that don’t provide the value they’re looking for.
    • Salesforce now predicts over US$131 billion in orders purchased this holiday season will be returned in the new year.
  • BOPIS on the rise for last-minute shoppers: In addition, shoppers are turning to the benefits of Buy Online and Pick Up In Store (BOPIS) for convenience as they look to avoid in-store lines and shipping deadlines ahead of peak holidays. BOPIS accounted for 25% of online orders during the first three weeks of December.

Please find the full mid-December moment newsroom post that provides more details here.

Real Estate & PII Data Exposed In Major Data Breach Says VPN Mentor

Posted in Commentary with tags on December 19, 2023 by itnerd

Over 1.5 Billion records belonging to New York-based Real Estate Wealth Network were exposed according to cybersecurity researcher Jeremiah Fowler, putting its users and customers at risk of many online and physical threats.The key findings are the following:

  • A total 1,523,776,691 records with a size of 1.16 TB
  • Documents revealed information about property owners, sellers, investors, and user logging data that included PII, and more.
  • Real estate-related details include famous people such as Kylie Jenner, Blake Shelton, Britney Spears, Floyd Mayweather, Dave Chappelle, Elon Musk and many others.

If you want to know more about Jeremiah’s findings, you will find all the details here: https://www.vpnmentor.com/news/report-realestatewealthnetwork-breach/

We believe it is important to share this report to raise awareness to your readers about the dangers of leaving such data open to the public, but also to notify people who may have been affected. In this specific case, if it had been discovered by ill-intentioned hackers, the data exposed could pose potential risks such as threats to the personal safety or an invasion of the privacy of the people exposed. Famous people and politicians could face potential stalking or harassment by fans or even individuals with malicious intent and the people exposed in general could face risks of phishing scams, financial fraud, identity theft and more.

Approov Identifies & Addresses Apple Watch Security Issues

Posted in Commentary with tags on December 19, 2023 by itnerd

Approov, the leader in mobile security, today revealed new data indicating that watches, wearables and new devices are now the weakest link in the mobile app threat landscape.

Key findings include:

  • Watches and other wearables now communicate directly with backend APIs and services.
  • An Apple Watch “zero-day” vulnerability was uncovered in September 2023.
  • Unless protected, watches and wearables will become a rich attack vector for hackers.
  • Approov extends its mobile RASP to Watch OS to prevent exploitation of any new zero-day vulnerabilities.

The findings were released in today’s Approov blog “Approov Addresses Apple Watch Security Issues” at this link: https://approov.io/blog/apple-watch-security-issues

Apple and MIT recently published a study indicating that 2.6 billion personal records were exposed through data breaches over the last two years. These findings underscore the need for protecting data in the cloud through mobile attestations and improved API security.

Approov, a trailblazer in mobile app and API security, addresses this threat directly with Release 3.2. The release introduces groundbreaking features, including the first commercially available App Attestation Solution for Apple WatchOS to provide API Protection against emerging threats.

The release also includes Harmony OS support and deployment of extended global Points of Presence (PoPs), and improved ease of deployment and administration.

Approov’s Runtime Application Self Protection (RASP) defenses are also strengthened by extending threat detections to include the latest versions of tools used by hackers to attack apps and APIs.

The danger is real: In September, Citizen Lab found an actively exploited zero-click Apple vulnerability which was used to deliver NSO Group’s Pegasus mercenary spyware. Apple acknowledged the threat to all their devices, issuing a specific WatchOS Security briefing (https://support.apple.com/en-mide/106360) on November 9 concerning a vulnerability in Apple Wallet on WatchOS. Apple quickly released a fix but acknowledged that “A maliciously crafted attachment may result in arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited”.

Approov now extends all the protections available on mobile apps to WatchOS. Approov support of WatchOS allows direct registration of WatchOS apps and ensures API protection against malicious traffic that is communicating directly from the watch to the cloud. WatchOS support is added to the existing support for Android Wearable Devices (which has been available since Version 3.0)

Approov Adds Huawei HarmonyOS Support: A Global Imperative

As a widely adopted operating system in regions such as China, India, the Middle East, and Africa, HarmonyOS plays a crucial role in the global mobile ecosystem. Recognizing the prevalence of this platform, Approov now ensures that mobile applications operating on Huawei devices are seamlessly integrated into our attestation services.

Approov attestation services traditionally supported Android and iOS devices, but the inclusion of Huawei HarmonyOS significantly broadens our platform coverage. This expansion is vital to offering a truly global solution, as any unattested mobile application poses a potential risk to API security, regardless of its geographical origin.

In collaboration with Cylab-Africa, Approov reinforces its commitment to a global solution for mobile app security. Version 3.2 extends support for Huawei app store deployments, catering to developers worldwide.

Enhanced High-Performance Worldwide Coverage

Approov expands its global network with new Points of Presence in São Paulo, Brazil and Singapore. These additions, coupled with existing points of presence (PoPs) in Europe (Dublin) and North America (California), create a worldwide low-latency mobile attestation network.

This move bolsters Approov’s commitment to achieving new levels of security by mitigating bot attacks, Man-in-the-Middle (MitM) attacks, account takeover (ATO) and other threats to mobile APIs, thus ensuring optimal performance and reducing fraud and data breaches.

New Threats are Addressed

The new release also boosts Approov’s RASP feature set to include new countermeasures against emerging and evolving threats. This includes significant hardening improvements to the SDK, including static and dynamic anti-tamper measures. Additionally, Approov’s ThreatLabs have developed further Android based detections for DobbyHook, Magisk, Zygisk, and Zygisk-Frida to fortify defenses against these advanced hacker tools. These changes augment the comprehensive suite of detections that are already implemented. In addition, the dynamic security-policy update facility will be used to improve the detection capabilities of existing deployed apps that currently use Approov’s previous SDKs.

Increased Ease of Use for DevOps/Developers

Approov continues to focus on easing the security burden for developers, DevOps and DevSecOps teams. New features simplify app registration and management, providing an automated and streamlined integration experience. The elimination of the need for individual app registrations and the introduction of tools for managing different app versions reduce complexity. Approov also enhances the registration of developer devices for testing, ensuring a secure and efficient device farm testing process.

Approov Mobile App and API Security Software Release 3.2 reaffirms the Company’s commitment to continued innovation in order to ensure there are no weak links for its customers.

Upgrades to Approov Version 3.2 will be included as part of Approov’s Software-as-a-Service Mobile Security platform. New customers can embrace the future of mobile app and API security by starting a free 30-day trial by registering at Approov.io

New Report to Reveal QR Code Phishing Scams: Quishing You a Happy Holiday Season

Posted in Commentary with tags on December 19, 2023 by itnerd

Netcraft has releasee a new report, Quishing You a Happy Holiday Season, revealing QR Code phishing scams, looking at the threat from QR code-based phishing, why cybercriminals are adopting this technique, and how to detect and disrupt these attacks at scale.

From a cybercriminal’s perspective, there are several reasons to use QR codes for phishing, often dubbed quishing, including hiding URLs from users, bypassing security tools, and circumventing corporate controls.

Netctraft demonstrates the anatomy of a QR code scam with examples of phishing emails, including an email targeting Microsoft in which there’s a QR code, a phishing site designed to capture victims’ account credentials, and targeting DocuSign with a QR code that directs the victim to a malicious website. 

You can read the report here.

Jscrambler Serves Up Their Predictions For 2024

Posted in Commentary with tags on December 19, 2023 by itnerd

Pedro Fortuna, CTO and Co-Founder, Jscrambler has shared with me his predictions for 2024. He’s got three of them to share:

JavaScript Targeted Attacks Accelerates

“In 2024, we predict organizations will encounter persistent challenges concerning their JavaScript and its associated cybersecurity vulnerabilities. Driven by Large Language Models (LLMs), attacks will become more advanced and written with higher levels of speed and sophistication, enabling accelerated learning and control circumvention. Companies will have to evolve their security strategies and implement measures, such as JavaScript code protection, that prevent LLM-powered threats from leveraging early automated learning steps.”

3rd-Party Tag Leakage Fueled by LLM

“Additionally, we anticipate an exponential increase in the leakage and misuse of consumer data collected by 3rd-party tags. Marketing, analytics and payment tag vendors pressured to compete in the market will utilize LLM to improve customer experiences and differentiate services. This will require an increased amount of consumer PII data to be collected which will often go uncontrolled and unmonitored. This collection and processing of more consumer data will have direct and negative consequences on consumer privacy. Therefore, it is imperative for web owners to proactively prepare themselves for this shift and safeguard consumer data through the implementation of 3rd-party script and tag controls. Without proper controls on the collection of consumer data by LLM, it may be too late to prevent the data from being used to train the LLM models, resulting in irreversible consequences. Once done, there’s a risk of potential data leaks by the LLM, as the security of LLMs is still in its infancy.”

PCI v4.0 Moves to Action

“With the increase in JavaScript abuses and e-skimming attacks, we saw the evolution of standards including PCI v4.0 to improve payment page security. While 2023 was the year of preparation for the new PCI v4.0 requirements, 2024 will transition from education to action, as it brings us closer to PCI v4.0 taking mandatory effect in 2025. Companies will quickly move from standards research to vendor research, selection and implementation to effectively prepare for the new 6.4.3 and 11.6.1 payment page security requirements. The best-prepared companies will assess current 3rd-party tag usage and business authorization processes before implementing new technology.”

Abnormal Security Highlights Real-World Examples of AI Weaponized For Cyberattacks In 2023

Posted in Commentary with tags on December 19, 2023 by itnerd

Abnormal Security is reporting on real-world AI-generated malicious emails their customers have received in the last year, with the attack examples from 2023 pointing to threat actors who have embraced the malicious use of AI, including: 

  • A malware attack in which the threat actor poses as an insurance representative and informs the recipient that attached to the email contains benefits information and an enrollment form that must be completed/returned. If the recipient fails to do so, they are told they may lose coverage.
  • Netflix impersonator compromises a legitimate domain in a credential phishing attack, where the threat actor poses as a customer service representative from Netflix, claiming that the target’s subscription has expired. 
  • A cosmetics brand impersonator attempts invoice fraud in a billing account update attempt, posing as a business development manager for cosmetics company LYCON, and informs the recipient of irregularities in their balance sheet noticed during a mid-year audit. 

Even though generative AI has only been used widely for a year, it is evident that the potential is there for widespread abuse. The attacks shown here are well-executed but are only the beginning of what is possible. 

You can view the report here.

Jscrambler Achieves PCI DSS Version 4.0 Compliance

Posted in Commentary with tags on December 19, 2023 by itnerd

Jscrambler today announces it has been assessed as compliant with PCI DSS v4.0  following an external assessment by Advantio, a leading Qualified Security Assessor (QSA), signifying the high-security standards Jscrambler’s platform and environment meets. This achievement, ahead of the April 1st, 2024 deadline for meeting the new standard underpins Jscrambler’s dedication to protecting its customers’ sensitive data and ensuring the security of their financial transactions. 

To be assessed as compliant with PCI DSS, companies must demonstrate the ability to protect both their assets and their clients. While Jscrambler does not store, process, or transmit cardholder data, Jscrambler does provide an agent that is present on customer payment pages. Service providers that can affect the security of cardholder data are considered in the scope of PCI DSS v4.0. 

The Payment Card Industry Data Security Standard (PCI DSS) is a global standard that provides a set of requirements for protecting Cardholder Data. Version 4.0 represents the state of the art in terms of cyber security and demonstrates a commitment to ensuring the protection of customer’s data. The requirements listed in PCI DSS v4.0 will mandate that the businesses that handle (store, process or transmit) or who could affect the security of payment data implement a set of controls (technical, physical and human) to protect such data. PCI DSS compliance must be renewed annually to ensure continued compliance with the security standard. This is an ongoing commitment that reflects dedication to data protection and transaction security. 

New PCI DSS v4.0 Requirements Attempt to Mitigate Expanding Surface Area Risk

JavaScript has become the building block of nearly every modern-day web page. While it can serve many purposes, it can also deliver unprecedented and sometimes unseen security risks that last for months, should it not be monitored properly. The introduction and widespread use of third-party JavaScript is one example, as online businesses increasingly struggle to maintain complete visibility and control over these scripts. Earlier this year, Jscrambler found that 80% of the 20 most highly trafficked US  e-commerce websites had an average of 148 JavaScripts on their payment pages. For these reasons and more, PCI DSS has included specific requirements (6.4.3 and 11.6.1) designed to minimize this increasing attack surface area, manage all JavaScript executing on payment pages, and detect any tampering or unauthorized changes to the payment page that can result in leaking of the cardholder data. 

Jscrambler is fully committed to PCI DSS, with its Co-founder and CTO, Pedro Fortuna, serving as a member of the PCI SSC Board of Advisors and recently having been added as a Principal Participating Organization. With Jscrambler having been externally assessed as compliant with PCI DSS v4.0, clients of Jscrambler can reliably utilize the Jscrambler Client-Side Protection Platform to both protect cardholder data that is entered into a customer’s web page from skimming attacks and to meet the PCI-DSS v4.0 requirements 6.4.3 and 11.6.1. These new requirements are currently considered ‘best practice’ until April 2025 when they become mandatory. Implementing the new requirements will ensure that merchants can prevent and detect unauthorized changes to JavaScript code. For this reason, service providers and merchants must prepare for PCI DSS v4.0 as they can impact the security of the cardholder data environment (CDE). 

To find out more about the potential impacts of first and third-party JavaScript on payment pages, read Jscrambler’s most recent blog post, Are Non-PCI Compliant Scripts Putting Your Business at Risk?

Customers, prospects, and partners may receive the Jscrambler Attestation of Compliance (AOC) report upon request by contacting their account manager.

The QSA company in charge of this project has been Advantio, an Integrity360 company, with over ten years of experience providing PCI consultancy and formal validation services worldwide via a large team of multilingual subject matter experts.

Horizon3.ai Named to New Cyber 60 List

Posted in Commentary with tags on December 18, 2023 by itnerd

Horizon3.ai, a leading provider of autonomous security solutions, today announced that it has been named to the Fortune Cyber 60 2023 list. The Fortune Cyber 60 is a new listing of the most important venture-backed startups that offer enterprise-grade cybersecurity solutions. Horizon3.ai was added to the Early-growth-stage companies category and is the only company on the list that offers an autonomous penetration testing solution like NodeZero™.

The Horizon3.ai NodeZero platform is a SaaS-based autonomous penetration testing solution used to continuously assess an enterprise’s attack surface. NodeZero helps organizations uncover exploitable vulnerabilities, weak and/or reused credentials, deficient security controls, exposed data, misconfigurations, weak security policies, and dangerous product defaults that exist within their networks. NodeZero chains these weaknesses together to discover attack paths an attacker could use to compromise user accounts, applications, domains, on-premises devices, and cloud resources.

To construct the Fortune Cyber 60 list, Lightspeed Venture Partners surveyed over 300 cybersecurity startups based on market data provided by Pitchbook. Lightspeed requested data regarding revenue and current and prior year growth rates and sorted the companies that responded according to their ARR, followed by growth rate, and prior year growth rate as tiebreakers.

About Horizon3.ai

The NodeZero™ platform empowers organizations to continuously find, fix, and verify exploitable attack surfaces. It is the flagship product of Horizon3.ai, founded in 2019 by former industry and U.S. National Security veterans. Our mission is to help organizations see their networks through the eyes of the attacker and proactively fix problems that truly matter, improve the effectiveness of their security initiatives, and ensure that they are prepared to respond to real cyberattacks.

Visit https://www.horizon3.ai/ for more information.

If You Want To Buy An Apple Watch Series 9 Or Ultra 2, Buy It Now Because It’s About To Be Banned In The US

Posted in Commentary with tags on December 18, 2023 by itnerd

Bad news for those who want an Apple Watch for Christmas.

In a statement shared with 9to5Mac, Apple said the Series 9 and Ultra 2 will no longer be available to purchase on Apple’s online store in the U.S. starting December 21.

Now why is this happening? Back in October the ITC ordered a ban on some Apple Watch imports into the U.S. after finding that Apple violated Masimo’s patents related to pulse oximetry. This is part of a long running battle between Masimo and Apple that has more plot twists than a Marvel Movie. Now this could be reversed by President Biden, but that may not happen as those sorts of reversals are rare. Thus it means that the Apple Watch could be off store shelves at Apple’s most profitable time of the year. Though Apple is going to appeal this.

If you want more background on this, here’s a couple of videos that explain this further: