Showing posts with label authentication. Show all posts
Showing posts with label authentication. Show all posts

Saturday, December 21, 2019

YubiKey for RSA SecurID Access offering helps address growing digital risks with enterprise-grade FIDO authentication capabilities

RSA will extend its enterprise offering of modern authentication and identity assurance through an alliance and joint solution with Yubico. The solution, YubiKey for RSA SecurID Access, set to be available by March 2020, combines a FIDO2-enabled hardware device by Yubico with the benefits of enterprise-grade security, risk-based authentication and simplified credential lifecycle management delivered by RSA SecurID Access.


In a dynamic workforce, users expect a frictionless experience, regardless of where they are or what applications they are accessing. At the same time, organizations want to reduce the risk of security breaches, secure critical assets and minimize the costs associated with credential lifecycle management. 



Stolen identity is a critical security issue, and often the weakest link in security postures. In fact, 80 percent of breaches involve compromised and weak credentials and last year security breaches cost companies an average of $3.86 million per breach.


As organizations continue to pursue digital transformation initiatives, identity management has become increasingly complex. Continuing leadership in authentication and identity assurance, the strategic partnership will add to the range of authentication methods offered in the RSA SecurID Access Suite. 


RSA and Yubico will address a variety of workforce use cases with a simple login experience enabled by the YubiKey for RSA SecurID Access and backed by the enterprise-grade security of RSA SecurID Access. The YubiKey complements the existing range of authentication methods of RSA SecurID Access including push notification, one-time password, SMS and biometrics to enable the broadest support for diverse user populations and use cases. 


FIDO authentication is uniquely suited for use cases like passwordless logon to PCs and laptops and mobile-restricted environments (e.g., call centers). The joint solution will also provide identity insights, threat intelligence, and business context for user access, devices, applications and behavior to provide businesses with the confidence that users are who they say they are.


RSA SecurID Access provides the backend software and services required for a full range of authentication options like the YubiKey for RSA SecurID Access to be successfully deployed, managed and used across an enterprise environment. 


RSA SecurID Access bridges islands of identity, and with one of the strongest partner ecosystems in the industry (RSA Ready), RSA SecurID Access provides a unified platform for secure enrollment, access control, policy enforcement and lifecycle management across all of an enterprise’s applications from data center, endpoint and network perimeter to the cloud. 



For customers, this enables features like secure (multi-factor) enrollment, self-service, emergency access, and a single FIDO registration across all enterprise applications. It also provides broader compatibility and a consistent user experience for YubiKeys within the enterprise.


RSA is a longstanding member of the FIDO Alliance as well as a member of the Board of Directors. As a market leader in multi-factor authentication, RSA is committed to supporting the new FIDO2 standard and providing best practices for FIDO deployment in the enterprise with RSA SecurID Access.


“Our partnership with RSA demonstrates a shared commitment to protect millions of users from security breaches,” said Jerrod Chong, Chief Solutions Officer, Yubico. “This collaborative effort combines RSA’s long-standing expertise in identity and access management, with Yubico’s proven leadership in standards and innovation, to bring forward a unified FIDO-based hardware authentication solution for enterprises, their partners and their customers.”


“With ongoing support for FIDO, RSA continues to deliver modern authentication solutions and identity assurance to help enterprises meet business needs, provide a range of authentication options for users and protect their most valuable assets,” said Jim Ducharme, VP of Identity and Fraud & Risk Intelligence Products, RSA. “The strategic partnership extends our support for FIDO in RSA SecurID Access allowing integration with applications from ground to cloud to address the evolving threats and challenges in today’s dynamic workforce.”

Symantec releases its Holiday Wishlist, with key cyber safety tools making it to the Holiday Shopping listing

As consumers head into the end-of-year holiday celebrations, they are expected to go shopping. But as they trek to the malls or go online, shoppers need to consider the security implications of the vast array of cool, connected devices now on the market.

After a hacker accessed a security camera and harassed an 8-year-old, the chilling recording of the encounter sends a clear warning to shoppers this holiday season. This could happen with anyone using smart-home devices can potentially be hacked or modified to lock out. General device privacy and security concerns apply here to protect users from the misuse of their data.


Consumers must make purchases from reputable manufacturers, and make sure to change the default passwords that these devices come with and don’t forget to use security software to help prevent malware from infecting devices on home network. 

Smart watches and activity trackers are soaring in popularity with nearly 85 million people around the world last quarter discovering the convenience of having the power of the internet within reach. But these accessories don't stand alone. Rather, they serve as extensions of smartphones and collect personal information. So, carefully read the privacy policies regarding the information that the user intends to share, including reviewing geographical location settings.


Increasingly, smart watches are gaining access to certain functions in smart homes, such as the ability to remotely unlock the front door. That sounds great until the device gets lost or stolen. If it does, review all passwords to make sure they’re protected with two-factor authentication. Even though some accessories include security settings that ought to help protect users in case of loss or theft, be sure to understand the tradeoffs of convenience.

Any internet-connected, voice-enabled TV has the capability to track what you are searching and watching. What’s more concerning is attackers can hack into smart TV webcams for spying or capitalize on software vulnerabilities to insert malware that can move through  connected devices. Also, when shopping for a unit, don’t forget to ask whether it has a camera. Also, does it come with a physical cover or is there one that can be added?

It’s worth researching whether the brand has a good or bad reputation when it comes to privacy and data collection. Once the user brings it home, think about whether they want to be tracked for advertising purposes. Most smart TVs do come with an option for users to turn off such tracking, but it may not be the default setting. So, check the fine print before turning on or turning off features on the smart TV.


A general rule with Smart TV software (and any computing device), to keep the software up to date or turn on automatic updates if there’s such an option.

Another great convenience of the last few years, robot vacuum cleaners have become a must-have appliance for many. Independent research finds that the devices enjoy off-the-chart loyalty with 89 percent of people who own robot cleaners saying they would recommend them to friends and family.

But don’t ignore the privacy implications. Many robot cleaners have cameras to map the house floor layout and optimize operation. This poses potential areas of concern if the robot is connected to the internet. Ensure the manufacturer is protecting the mapped layout data and that it is not shared. Also ensure the cameras are not capturing additional data from within the home.


Another point to consider is that unlike most other devices users may own around the house, this is a machine that physically moves inside the home. As such, a compromised vacuum potentially can enable other types of creepy activity.

So again, ask whether the user trust the manufacturer and whether the company not only can build a vacuum, but also safeguard data. If the answer to that question is yes, also inquire how they go about doing it. Don’t take “why, of course we protect you” as the final answer. Do the research and focus on reputable manufacturers. 

NPR and Edison Research estimates that there are now about 120 million smart speakers in U.S. homes, representing 78 percent year-over-year growth. But most of these devices have “always on” speech listening and recognition features so that they can identify the “wake word” — even while they are standing by?

It’s no longer exceptional to read about people complaining that their private conversations somehow triggered the device’s wake word to start eavesdropping. So, before buying a smart speaker for the home, ask whether they are comfortable with this?


Many of users see this as a small price to pay for the convenience being offered. But always-on listening means that such devices can not only listen to what the user says (and potentially use it — for advertising, for instance), but they can also capture ambient noise that reveals a lot of other things about the user.

The electronic/computing system of a car controls most of its operation and is far more vulnerable than, say, a gas-guzzling station wagon from yesteryear. Increasingly, our cars are turning into the equivalent of iPads on four wheels as vehicles incorporate more and more electronic gadgetry each year to add customer convenience.

But as with any technology device, it’s wise to take precautions that mitigate security risks. For instance, in this case the USB ports in certain newer cars might be manipulated to read files on the cell phone or install malware on the device. This is the latest practice known as Juice Jacking, where malware gets installed onto a device or information and can be stolen via the USB charging port.

Also, hackers may be able to launch attacks against audio systems in a bid to control the vehicle remotely. Similar vulnerabilities have also been found with key fobs and certain apps that get used to communicate with the cars. Users must take basic precautions, and be extremely careful with car port dongles that are plugged into the car control port. As with any other computing devices, it is vital to apply software updates in a timely manner and fix any potentially relevant recalls. Don’t make an attacker’s job any easier for them.

Every year more devices become part of the Internet of Things, and that includes children’s toys. But now that digital toys and devices come with built-in cameras and GPS trackers, users need to consider benefits with the potential security risks. Some toys may interact with smart speakers, which introduces a new category of threats.


Like other connected digital devices, they are potentially vulnerable to hacks and any data they collect may not be private — or secure. The threat is not theoretical. Symantec has seen instances in which companies neglected to protect their online storage system and hundreds of thousands of records, including childrens’ names, ages and voice recordings, got exposed.

That puts the onus on parents to use complicated passwords for every connected toy they buy for their kids. Also, never let children access the internet from an unsecure Bluetooth or Wi-Fi connection.

Many wireless headphones now come with integrated voice assistants and involve security issues with which users are familiar. Also, if users can connect over Bluetooth, there’s always the risk it may not be secure, especially outdated versions of the protocol which likely have unpatched security holes. One easy precaution: Just turn off Bluetooth when the users are not using it, or near anyone who do not trust.

Friday, December 13, 2019

Trend Micro warns against sighting of ransomware bugs, Snatch and Zeppelin

Two ransomware families – Snatch and Zeppelin – with noteworthy features were spotted this week. Snatch ransomware is capable of forcing Windows machines to reboot into Safe Mode. Zeppelin ransomware, on the other hand, was responsible for infecting healthcare and IT organizations across Europe and the U.S.

Snatch reboots infected machines into Safe Mode to bypass security software and encrypt files without being detected. It was designed to do this because security software often do not run in Windows Safe Mode, since it’s meant for debugging and recovering a corrupt operating system (OS).


Researchers at SophosLabs found that the ransomware operators use a Windows registry key to schedule a Windows service called SuperBackupMan, which can run in Safe Mode and cannot be stopped or paused. The malware even goes further by deleting all volume shadow copies on the system, thus preventing the forensic recovery of encrypted files.

Snatch ransomware, first discovered back in 2018, does not target home users or use mass distribution methods such as spam campaigns or browser-based exploits. Instead, the malware operators go after a small list of targets that include companies and government organizations. The operators were also found recruiting hackers on hacking forums and stealing information from target organizations.


Zeppelin, which is a new variant of the VegaLocker/Buran ransomware, was spotted (with compilation timestamps no earlier than November 6, 2019) infecting companies located in Europe and the U.S. through targeted installs. Reported by BlackBerry Cylance, the Zeppelin ransomware, also a ransomware-as-a-service (RaaS) family, was found being used to infect certain healthcare and IT companies.

Zeppelin ransomware appears to be highly configurable and can be deployed as a .dll or .exe file, or wrapped in a PowerShell loader. Aside from encrypting files, it also terminates various processes, including those associated with backup, database, and mail servers. Zeppelin executables were found wrapped in three layers of obfuscation. Its ransom notes range from generic messages to elaborate notes tailored to specific organizations. Notably, it appears Zeppelin ransomware is not being widely distributed — or at least not yet.

The researchers believe that Zeppelin, similar to Sodinokibi ransomware, is being spread through managed service providers (MSPs) to further affect customers. Moreover, the ransomware can also be distributed through malvertising operations and watering hole attacks.


Aside from maintaining an up-to-date operating system to address exploitable vulnerabilities, users should adopt the standard best practice of backing up data via the 3-2-1 rule. Users can also consider deploying comprehensive, multilayered security solutions that will protect against ransomware attacks coming from different entry points. 

Trend Micro advises users and organizations to secure ports and services that are exposed on the internet; enable multi-factor authentication to protect admin accounts from potential brute-force attacks; secure remote access tools as they can be used as entry points; employ the principle of least privilege and regularly monitor the network for threats; and perform regular password audits for stronger access control to help prevent ransomware attacks.

Trend Micro solutions such as the Smart Protection Suites and Worry-Free Business Security solutions, which have behavior monitoring capabilities, can protect users and businesses from these types of threats by detecting malicious files, scripts, and messages as well as blocking all related malicious URLs. 

Trend Micro XGen security provides a cross-generational blend of threat defense techniques against a full range of threats for data centers, cloud environments, networks, and endpoints. It infuses high-fidelity machine learning with other detection technologies and global threat intelligence for comprehensive protection against advanced malware.

Saturday, December 7, 2019

Trend Micro reveals that Magecart group sets sights on Smith & Wesson, other high-profile stores

Trend Micro announced this week that the infamous credit card-skimming group Magecart has struck again. After incidents in the past few months that saw the threat actor go after customers of online shops and hotel chains, the group has set its sights on a new set of targets: high-profile stores, including firearms vendor Smith & Wesson (S&W).


According to security researcher, Willem de Groot of Sanguine Security, threat actors took advantage of the Black Friday rush by injecting credit card skimmers into the sites of a number of high-profile stores such as S&W. The group behind the attack injected the skimmer into S&W’s website on Nov. 27 — a couple of days before Black Friday, most likely in anticipation of the high volume of traffic going to the website. Note that the skimmer has been removed from the S&W store as of the time of writing.

The skimmer features an impressive list of capabilities, such as reverse engineering, a three-stage loader, and multiple layers of JavaScript obfuscation to hide its tracks. When a user visits the compromised website, the command-and-control (C&C) server initially sends harmless code — up until the actual payment process, when the skimmer begins its malicious routine. 


To make the skimming attack look more legitimate, a fake payment confirmation code is presented to the user. Behind the scenes, however, malicious code is already running, sneakily exfiltrating customer data such as payment information to the C&C server.

Sanguine Security notes that these attacks only worked for users which met various criteria, including using U.S.-based IP addresses, using non-Linux-based browsers, and not using the AWS platform.

The rise of Magecart highlights the need for vendors and other organizations to properly secure their websites and applications. Data theft via an attack such as the ones regularly performed by Magecart can mean monetary losses, not only for customers but also for the company whose website or application was compromised, especially given the potentially steep fines meted out to violators of data privacy laws such as the General Data Protection Regulation (GDPR).  


Organizations can minimize the chances of compromise by consistently applying the newest patches and updates to the software they use and by shoring up the authentication mechanisms provided to customers. Furthermore, it is recommended that IT and security teams proactively monitor their websites for any sign of malicious activities, such as unauthorized access or data exfiltration.

Friday, November 22, 2019

Kaspersky uncovers 37 vulnerabilities in open-source VNC systems; exploitation could lead to remote code execution

Kaspersky presented on Friday an analysis of open source Virtual Network Computing (VNC) which uncovered memory corruption vulnerabilities that existed in a substantial number of projects for a significant period of time. 

According to shodan.io, the exploitation of some detected vulnerabilities could lead to remote code execution affecting the users of VNC systems, which amounts to over 600,000 servers accessible from the global network. 


VNC systems provide remote access to one device from another through the use of remote frame buffer (RFB) protocol. Due to its availability on multiple platforms and presence of multiple open sources, VNC systems have become some of the more popular desktop sharing tools to date. 

They are actively used in automated industrial facilities enabling remote control of systems, and approximately 32% of industrial network computers having some form of remote administration tools, including VNC.


The prevalence of such systems in general, and particularly ones that are vulnerable, is a significant issue for the industrial sector as potential damages can bring significant losses through disruption of complex production processes. 

As such, Kaspersky researchers studied some VNC systems including LibVNC, UltraVNC, TightVNC1.X and TurboVNC.

Although these VNC projects were previously analyzed by other researchers, not all vulnerabilities were uncovered and patched. As a result of Kaspersky’s analysis, 37 CVE records marking various vulnerabilities were created. 


Vulnerabilities were found not only on the client, but also on the server-side of the system. Some allowed remote code execution, which can then permit a malicious actor to make arbitrary changes on the attacked systems. Alternatively, many server-side vulnerabilities could only be exploited after password authentication, and some servers do not allow password-free access.

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...