Friday, 1 March 2019
DATA BREACH AT TURBOTAX EXPOSES USERS’ INFORMATION

Company officials report that unknown actors got access to data using credentials obtained in other incidents
According to network security and ethical hacking specialists from the International Institute of Cyber Security reports, Intuit, a financial software developer and creator of services like Mint and TurboTax, has been the victim of a credential stuffing attack. It is believed that attackers aim to the tax return information of users of these systems.
During a routine safety check, the company’s network security specialists discovered the cyberattack. According to Intuit, both the authorities and the affected users have already been notified; in the incident report, it is mentioned that an unauthorized agent accessed the data of the affected users using user names and passwords obtained from a non-intuitive source, thanks to a credential stuffing attack.
In cases where the attack was successful, hackers could have accessed user tax returns, in addition to additional information stored on the platform, such as:
- Full names
- Social Security numbers
- Users’ addresses
- Dates of birth
- Financial information
The compromised information could also include details about some close relatives of the affected users, according to network security experts.
As a security measure, Intuit temporarily disabled the affected accounts after discovering the incident. In addition, the platform has provided affected users with a year of free identity protection services, bank account monitoring and identity restoration through a certified service.
Intuit insists that the incident should not be considered as a data theft that compromised its infrastructure, but it is an attack against specific accounts of some users.
SPECTRE AND MELTDOWN VULNERABILITIES CAN’T BE CORRECTED WITH SOFTWARE IMPLEMENTATIONS

Google experts consider these vulnerabilities to be inherent in modern processors design
According to network security and ethical hacking specialists from the International Institute of Cyber Security, the vulnerabilities Spectre and Meltdown were reported for the first time about a year ago; since then, countless teams of independent specialists and researchers have tried multiple methods to mitigate the risk of exploiting these flaws, expecting to be able to completely eradicate it in the future.
Unfortunately, for Google network security specialists these vulnerabilities seem to be an inherent feature of modern processors. In other words, software-based correction and mitigation techniques are not enough to overcome these vulnerabilities.
It is worth noting that Meltdown and Spectre attacks take advantage of the speculative execution, a feature of the currently used processors. This means that a processor may assume that a condition can be true or false. If it turns out to be true, the speculative results are maintained; if the condition turns out to be false, the results will be discarded.
Initially, network security specialists assumed that speculative execution was invisible to running programs, as it is a feature of implementations. However, evidence was later discovered that some traces of false speculation were not completely eliminated.
A malicious user could take control of this data through a side channel. In addition, attackers can trick computers into loading sensitive data, such as administrators’ information, passwords, etc. To mitigate the risks posed by these vulnerabilities, developers have resorted to using software-based techniques, such as using sandbox environments, or preventing the processor from running sensitive information.
While these software techniques are quite functional, Google experts claim that this is just a shallow solution. A test made in the Chrome browser showed that, in trying to implement a comprehensive solution against a Spectre attack, the administrators generated a considerable drop in the performance of their developments.
In conclusion, it is not possible to solve Spectre-type vulnerabilities with software deployments only. Speculative execution is a fundamental part of a modern processor; so many specialists consider that Spectre and Meltdown will keep bringing problems for a long time.
HOW TO CHECK IF YOUR DUBSMASH, COFFEE MEETS BAGEL OR MYFITNESSPAL ACCOUNTS WERE HACKED

Hackers accessed personal data from more than 160 million users
According to network security and ethical hacking experts from the International Institute of Cyber Security, Dubsmash, the popular video app, suffered a data breach at the end of 2018. It is estimated that the incident affected about 162 million users, exposing information such as:
- User full names
- Usernames
- passwords
- Phone Numbers
- Emails
- Location data
Recently, the compromised information was found for sale on some hacker forums on dark web. The app has more than 100 million downloads only in Google Play Store.
The information has been published on the Have I Been Pwned platform, which records known data breaches and allows users to check if their email credentials have been compromised in any of these incidents. According to this website, the data breach notification at Dubsmash was published on February 25, 2019, specifying that 161,749,950 Dubsmash accounts worldwide were affected.
Although, according to network security specialists, Dubsmash should notify affected users, the company has not made any actions to meet this requirement. However, not everything is bad news, users concerned about the state of their personal information can go to the Have I Been Pwned (haveibeenpwned.com) website, enter their email id and the platform will verify if their account has been Involved in some data breach incident.
Fortunately there are other similar platforms that host huge databases on security incidents where users can verify if their information has been compromised. As an additional measure, network security specialists recommend identity Protection Services, which monitor the network for suspicious activity carried out with the accounts of the affected user.
The information extracted from Dubsmash is offered for sale on dark web along with another 500 million of accounts stolen from sites such as CoffeeMeetsBagel, MyHeritage, MyFitnessPal, among others. Apparently, the entire database is offered at about $20k USD, paid through cryptocurrency transactions.
ICANN SUGGESTS IMPLEMENTING DNSSEC TECHNOLOGY IMMEDIATELY

The Domain Name System is vulnerable to multiple cyberattacks, so the organization has requested to implement better security measures
According to network security and ethical hacking experts from the International Institute of Cyber Security, the Internet Corporation for Assigned Names and Numbers (ICANN) has called for a collective effort to develop a security technology to reinforce reliability of Domain Name System (DNS) that can protect website operators from attacks by the most dangerous hacker groups.
To be specific, what ICANN proposes is to perform a complete implementation of the DNS Security Extensions (DNSSEC) on all unsecured domain names. The DNS system is the part of the Internet infrastructure worldwide that is responsible for moving the names of sites in common language to IP addresses needed to access websites, use email platforms, etc. DNSSEC would try to implement a new security layer for DNS.
DNSSEC technologies have existed for almost 10 years, although they are not yet widely used. According to network security specialists, less than 20% of DNS registrars worldwide have implemented this technology. It is believed that the adoption of DNSSEC has been delayed because it could reduce functionality in favor of improving security measures, and that DNSSEC was always considered an option, not as a security requirement.
This technology could prevent attacks that take advantage of replies to DNS queries by cryptographically signing DNS records to verify their authenticity.
The problem is that most DNSSEC implementations are incompatible with current DNS requirements. “Inherited implementations of DNSSEC break basic DNS functions, such as geo routing, it is also difficult to implement this technology in multiple vendors, so performance would be affected, as well as its availability for final users would be reduced,” said network security specialists.
According to ICANN, the total implementation of DNSSEC technology ensures that end users access legitimate online websites and services. “While this is not a solution to all Internet security issues, DNSSEC would provide additional protection to a critical sector,” adds ICANN.
In a statement, ICANN claims that its application is backed by multiple reports that mention groups of malicious hackers exploiting a wide variety of resources and methodologies to carry out their plans.
“Some recent cyberattacks have focused on DNS; hackers make some changes to the domain name structure without authorization, so you can perform various malicious activities. DNSSEC technology is fully functional against this type of attack,” says ICANN.
ICANN also published a list of DNS security measures so that industry members can protect their customers, their information systems, and their entire infrastructure.
ICANN’s call comes shortly after the U.S. Department of Homeland Security decreed that all agencies at the federal level had to reinforce their computer security systems to the growing tide of global cyberattacks.
DATA BREACH AT TURBOTAX EXPOSES USERS’ INFORMATION

Company officials report that unknown actors got access to data using credentials obtained in other incidents
According to network security and ethical hacking specialists from the International Institute of Cyber Security reports, Intuit, a financial software developer and creator of services like Mint and TurboTax, has been the victim of a credential stuffing attack. It is believed that attackers aim to the tax return information of users of these systems.
During a routine safety check, the company’s network security specialists discovered the cyberattack. According to Intuit, both the authorities and the affected users have already been notified; in the incident report, it is mentioned that an unauthorized agent accessed the data of the affected users using user names and passwords obtained from a non-intuitive source, thanks to a credential stuffing attack.
In cases where the attack was successful, hackers could have accessed user tax returns, in addition to additional information stored on the platform, such as:
- Full names
- Social Security numbers
- Users’ addresses
- Dates of birth
- Financial information
The compromised information could also include details about some close relatives of the affected users, according to network security experts.
As a security measure, Intuit temporarily disabled the affected accounts after discovering the incident. In addition, the platform has provided affected users with a year of free identity protection services, bank account monitoring and identity restoration through a certified service.
Intuit insists that the incident should not be considered as a data theft that compromised its infrastructure, but it is an attack against specific accounts of some users.









