Showing posts with label exploit. Show all posts
Showing posts with label exploit. Show all posts

Saturday, December 21, 2019

Asigra’s latest program defends public/non-profit organizations against cyber-attacks targeting backup data

Asigra announced a new program focused on defending the backup repositories and data of Canadian public and non-profit organizations against cyber-attacks. The purpose of the program is to ensure the recovery of data that otherwise may have become compromised as a result of malicious malware or ransomware Attack-Loops that prevent the recovery of mission-critical data and often put large volumes of personally identifiable information (PII) at risk.

Cyber-attacks on public/non-profit organizations have put citizen data at risk like never before as new variants of ransomware and other attacks continue to infiltrate and expose sensitive data to unknown and possibly criminal entities.


In a recent attack covered by the Toronto Star, medical test provider LifeLabs agreed to pay the ransom of attackers in order to retrieve millions of customer records. In a statement, the organization said, “The personal information of over 15 million customers was compromised, mostly in British Columbia and Ontario, including name, address, email, login, passwords, date of birth, health card number and lab test results.”

Like many organizations dealing with a cyber-attack, the last resort for recovery relies on a functioning disaster recovery or backup solution in place. Unfortunately, hackers have now designed ransomware and other malware to seek out secondary storage systems (aka: disaster recovery and backup data) in order to compromise a clean retrieval of the information. 


As a result, these organizations no longer have a way to reinstate their data, and therefore are faced with either relinquishing or paying a ransom which can be exceptionally high for public and non-profit entities.

As a Canadian company, Asigra is planning to help protect these organizations by partially donating a large percentage of its cybersecurity-enabled backup technology to Canada’s extensive list of public and non-profit organizations. Those establishments in the country that can issue a tax-deductible receipt may contact Asigra to receive the company's complete anti-ransomware/backup software suite with the cost covered in large part by a donation-in-kind.

Asigra’s cloud-based data recovery platform is unique in the industry for converging data protection and cybersecurity for effective malware/ransomware detection and prevention that ensures safe, secure and reliable data recovery. 


The advanced software includes initial zero-day Attack-Loop preventative technology using bi-directional cyber-threat detection, zero-day exploit protection, variable repository naming, and multi-factor authentication (MFA) for a full defensive suite against aggressive ransomware and other cyber-threats targeting backup data. This is complemented by FIPS 140-2 certification and military-grade data encryption to ensure enterprise-grade data security, making user data unreadable without the proper encryption key.

“The majority of cybersecurity analysts today agree that cyber-attacks are evolving from the perspective of what they target, how they impact organizations and the changing methods of attack,” said David Farajun, CEO, Asigra. “For the past year, we have seen an increasing number of cyberthreats begin to target the number one method of data recovery – the backup repository. As a specialist in this area, we have developed a very effective solution to fight against this and now offer the technology to public and non-profit organizations we share our data with.”

Thursday, December 12, 2019

Kaspersky finds zero-day exploit in Windows OS used in targeted attack, part of malicious WizardOpium operation

Kaspersky automated detection technologies have found a Windows zero-day vulnerability. The exploit based on this vulnerability allowed attackers to gain higher privileges on the attacked machine and avoid protection mechanisms in the Google Chrome browser. The newly discovered exploit was used in the malicious WizardOpium operation.

Zero-day vulnerabilities are previously unknown bugs in software, which, if found by criminals first, enable them to operate unnoticed for an extended period of time, inflicting serious and unexpected damage. Regular security solutions do not identify the system infection nor can they protect users from a yet-to-be-recognized threat.


The new Windows vulnerability was found by Kaspersky researchers as a result of a separate zero-day exploit. In Nov 2019, Kaspersky’s Exploit Prevention technology, which is embedded in most of the company’s products, detected a zero-day exploit in Google Chrome. 

This exploit allowed attackers to execute arbitrary code on a victim’s machine. Upon further research of this operation, which the experts called ‘WizardOpium,’ another vulnerability was discovered, this time in Windows OS.


It emerged that the newly discovered Windows zero-day elevation of privileges (EoP) exploit, CVE-2019-1458, was embedded into a previously discovered Google Chrome exploit. It was used to gain higher privileges in the infected machine as well as to escape the Chrome process sandbox – a component built to protect the browser and the victim’s computer from malicious attacks.
  
Detailed analysis of the EoP exploit showed that the abused vulnerability belongs to the win32k.sys driver. The vulnerability could be abused on the latest patched versions of Windows 7 and even on a few builds of Windows 10 (new versions of Windows 10 have not been affected).


“This type of attack requires vast resources. However, it gives significant advantages to the attackers and, as we can see, they are happy to exploit it,” said Anton Ivanov, security expert at Kaspersky. “The number of zero-days in the wild continues to grow and this trend is unlikely to go away. Organizations need to rely on the latest threat intelligence available at hand and have protective technologies that can proactively find unknown threats such as zero-day exploits.”

Wednesday, November 27, 2019

Google Security expands its Android Security rewards program

Google is expanding its Android Security Rewards (ASR) program and increasing reward amounts, by introducing a top prize of US$1 million for a full chain remote code execution exploit with persistence which compromises the Titan M secure element on Pixel devices. Additionally, the search engine giant will release a specific program offering a 50 percent bonus for exploits found on specific developer preview versions of Android, offering a top prize of $1.5 million.


The rewards program was created in 2015 to reward researchers who find and report security issues to help keep the Android ecosystem safe. Over the past 4 years, Google has awarded over 1,800 reports, and paid out over four million dollars.

The Android Security Rewards program recognizes the contributions of security researchers who invest their time and effort in helping Google make Android more secure. The reward level is based on the bug severity and increases for complete reports that include reproduction code, test cases, and patches.

Android Security Rewards covers bugs in code that runs on eligible devices and isn't already covered by other reward programs at Google. Eligible bugs include those in AOSP code, OEM code (libraries and drivers), the kernel, the Secure Element code, and the TrustZone OS and modules. Vulnerabilities in other non-Android code, such as the code that runs in chipset firmware, may be eligible if they impact the security of the Android OS.


Earlier this year, Gartner rated the Pixel 3 with Titan M as having the most “strong” ratings in the built-in security section out of all devices evaluated. Due to this, Google has created a dedicated prize to reward researchers for exploits found to circumvent the secure elements protections.

In addition to exploits involving Pixel Titan M, Google has added other categories of exploits to the rewards program, such as those involving data exfiltration and lockscreen bypass. These rewards go up to $500,000 depending on the exploit category. 

During this year, Google made total payouts over the last 12 months to the tune of over $1.5 million. Over 100 participating researchers have received an average reward amount of over $3,800 per finding (46 percent increase from last year), and the top reward that was paid out this year was $161,337.

The highest reward paid out to a member of the research community was for a report from Guang Gong (@oldfresher) of Alpha Lab, Qihoo 360. This report detailed the first reported 1-click remote code execution exploit chain on the Pixel 3 device. 

Guang Gong was awarded $161,337 from the Android Security Rewards program and $40,000 by Chrome Rewards program for a total of $201,337. The $201,337 combined reward is also the highest reward for a single exploit chain across all Google VRP programs. The Chrome vulnerabilities leveraged in this report were fixed in Chrome 77.0.3865.75 and released in September, protecting users against this exploit chain.

Friday, October 25, 2019

McAfee uses Expert Rules in ENS 10.5.3 to prevent malicious exploits

Expert Rules are text-based custom rules that can be created in the Exploit Prevention policy in ENS Threat Prevention 10.5.3+. Expert Rules provide additional parameters and allow much more flexibility than the custom rules that can be created in the Access Protection policy. It also allows system administration to control / monitor an endpoint system at a very granular level. 

Expert rules do not rely on Use-Mode hooking; hence they have very minimal impact on a system’s performance. This blog post acts as a basic guide to show customers how to create them and which threats they can help block.

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...