Showing posts with label vulnerability. Show all posts
Showing posts with label vulnerability. Show all posts

Wednesday, November 27, 2019

Google Security expands its Android Security rewards program

Google is expanding its Android Security Rewards (ASR) program and increasing reward amounts, by introducing a top prize of US$1 million for a full chain remote code execution exploit with persistence which compromises the Titan M secure element on Pixel devices. Additionally, the search engine giant will release a specific program offering a 50 percent bonus for exploits found on specific developer preview versions of Android, offering a top prize of $1.5 million.


The rewards program was created in 2015 to reward researchers who find and report security issues to help keep the Android ecosystem safe. Over the past 4 years, Google has awarded over 1,800 reports, and paid out over four million dollars.

The Android Security Rewards program recognizes the contributions of security researchers who invest their time and effort in helping Google make Android more secure. The reward level is based on the bug severity and increases for complete reports that include reproduction code, test cases, and patches.

Android Security Rewards covers bugs in code that runs on eligible devices and isn't already covered by other reward programs at Google. Eligible bugs include those in AOSP code, OEM code (libraries and drivers), the kernel, the Secure Element code, and the TrustZone OS and modules. Vulnerabilities in other non-Android code, such as the code that runs in chipset firmware, may be eligible if they impact the security of the Android OS.


Earlier this year, Gartner rated the Pixel 3 with Titan M as having the most “strong” ratings in the built-in security section out of all devices evaluated. Due to this, Google has created a dedicated prize to reward researchers for exploits found to circumvent the secure elements protections.

In addition to exploits involving Pixel Titan M, Google has added other categories of exploits to the rewards program, such as those involving data exfiltration and lockscreen bypass. These rewards go up to $500,000 depending on the exploit category. 

During this year, Google made total payouts over the last 12 months to the tune of over $1.5 million. Over 100 participating researchers have received an average reward amount of over $3,800 per finding (46 percent increase from last year), and the top reward that was paid out this year was $161,337.

The highest reward paid out to a member of the research community was for a report from Guang Gong (@oldfresher) of Alpha Lab, Qihoo 360. This report detailed the first reported 1-click remote code execution exploit chain on the Pixel 3 device. 

Guang Gong was awarded $161,337 from the Android Security Rewards program and $40,000 by Chrome Rewards program for a total of $201,337. The $201,337 combined reward is also the highest reward for a single exploit chain across all Google VRP programs. The Chrome vulnerabilities leveraged in this report were fixed in Chrome 77.0.3865.75 and released in September, protecting users against this exploit chain.

Monday, November 25, 2019

Nyotron releases RIPlace technique that renders ransomware invisible to security software

Nyotron announced it has discovered a new Microsoft Windows file system technique that enables cyberattackers to maliciously encrypt files in a way that existing anti-ransomware products cannot detect. The company has alerted security vendors of the threat it has named "RIPlace," and released a free tool that allows users to check their systems for exposure to the technique.



Ransomware has been around since 1989, yet remains one of the most common and successful attack types, causing billions of dollars in damages worldwide every year. 


The Verizon 2019 Data Breach Investigations Report (DBIR) states that ransomware accounts for nearly 24 percent of all incidents where malware was used last year, making it the second most common type of malware reported. 



The combination of timely patching and using modern antivirus solutions helps stop some ransomware. However, RIPlace can bypass these defenses by using a legacy file system "rename" operation. It takes only two lines of code for hackers to unleash this technique.



Nyotron's free tool enables users and organizations to check their systems for the RIPlace vulnerability. If the system is deemed to be at-risk, the tool provides solution recommendations.

Sunday, November 24, 2019

Kaspersky predicts advanced persistent threats in 2020, with abuse of personal information, sophisticated attacks leading the pack

Kaspersky researchers have shared their predictions on Advanced Persistent Threats (APTs) in 2020, pointing out some of the ways the landscape of targeted attacks could change in the coming months. 

The overall trend shows that threats will grow in sophistication and become more targeted, diversifying under the influence of external factors, such as the development and propagation of machine learning, technologies for deepfake development, and tensions around trade routes between Asia and Europe.

The predictions were developed based on changes that the Global Research and Analysis Team witnessed over 2019, and are an effort to help the cybersecurity community prepare for the challenges that lie ahead in the coming year.


Other targeted threat predictions for 2020 include false flag attacks reach a whole new level. These attacks will develop further, with threat actors seeking not only to avoid attribution but also to actively lay the blame on someone else. Commodity malware, scripts, publicly available security tools and administrator software, mixed with a couple of false flags, where security researchers are hungry for any small clue, might be enough to divert suspected authorship to someone else.

Attackers will focus more on organizations that are likely to make substantial payments in order to recover their data. A potential twist might be that, instead of making files unrecoverable, threat actors will threaten to publish data that they have stolen from the victim company. As banks will be required to open their infrastructure and data to third parties who wish to provide services to bank customers, it is likely that attackers will seek to abuse these new mechanisms with new fraudulent schemes.


Determined threat actors have, for some time, been extending their toolsets beyond Windows, and even beyond PC systems. VPNFilter and Slingshot, for example, targeted networking hardware. New attacks could hit regions including Turkey, East and South Europe and East Africa. Possible scenarios include a growth in political espionage as governments seek to secure their interests at home and abroad. They could extend also to technological espionage in situations of economic crisis and instability.

With new interception capabilities and data exfiltration methods, use of supply chains will continue to be one of the most difficult delivery methods to address. It is likely that attackers will continue to expand this method through manipulated software containers, for example, and abuse of packages and libraries.

There are no good reasons to think this will stop any time soon. However, due to the increased attention given to this subject by the security community, the number of attacks being identified and analyzed in detail will also increase.

Personal information abuse grows, armed with AI. It is very similar to some of the techniques used for driving election advertisements through social media. This technology is already in use and it is just a matter of time before some attackers take advantage of it.


“The future holds so many possibilities that there are likely to be things that are not included in our predictions. The extent and complexity of the environments in which attacks play out offer so many possibilities,” said said Vicente Diaz, security researcher at Kaspersky. “In addition, no single threat research team has complete visibility of the operations of APT threat actors. We will continue to try and anticipate the activities of APT groups and understand the methods they employ, while providing insights into their campaigns and the impact they have.”

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...