This is default featured slide 1 title

International Institute Cyber Security Mexico provides training for all type of data security.

This is default featured slide 2 title

Webiprints is one of the world famoous company for data security provider in world wide at lowest price with 100% secure.

This is default featured slide 3 title

Webiprints offers Mobile application development services at affordable price and also Mobile Hacking Course. Just visit our website and fill up your query.

This is default featured slide 4 title

Grow your business with us! We offers Digital Marketing including services such as SEO, SMO and PPC.

This is default featured slide 5 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.This theme is Bloggerized by Lasantha Bandara - Premiumbloggertemplates.com.

Tuesday, 29 October 2019

MAJOR MANUFACTURING COMPANY COMPLETELY SHUT DOWN ITS OPERATIONS FOR WEEKS DUE TO RANSOMWARE ATTACK

ORIGINAL CONTENT: https://www.securitynewspaper.com/2019/10/23/major-manufacturing-company-completely-shut-down-its-operations-for-weeks-due-to-ransomware-attack/

Information security specialists reported a serious ransomware infection at automation company Pilz, based in Germany. For more than a week, the company’s operations have been disrupted due to infection with the dangerous encryption malware variant known as BitPaymer.

On its website, the company released a statement that says: “Pilz has been the victim of a cyberattack specifically targeting our systems; it has crippled operations in all our computer and server-based jobs, including the company’s communication networks.” For now, the company is working forced march to meet its pre-established commitments, in addition to restoring all affected operations.

This Monday, October 21, it was completed one week after the infection was detected. Although the company has already managed to restore some of its functions (scheduled deliveries, among others), many of the systems remain paralyzed. “We have integrated an information security team to resolve some technical issues, identify the source of the attack, among other activities,” as mentions one of the latest updates on the incident.

As mentioned by company officials, the full re-establishment of Pilz’s operations is expected to take a few more days.

Speaking to the specialized platform ZDNet, information security expert Maarten van Dantzig mentioned that this is the typical attack linked to the hacker group known as BitPaymer. The expert claims that he discovered some samples of the malware used by this group on the VirusTotal platform, including the ransom note used during this incident, with custom details related to the German company.

Although the amount of ransom demanded from Pilz is unknown, Van Dantzig adds that operators of this ransomware variant have come to demand ransoms of up to $1 million USD in cryptocurrency. Finally, the expert adds that, usually, the BitPaymer ransomware is delivered to victims using the Trojan known as Dridex.

Specialists from the International Institute of Cyber Security (IICS) add that this Trojan is dropped at unsuspecting Windows users via an attached document sent by email. When opened, Dridex is unloaded, opening the door to other threats, as in the case of the affected company.


Monday, 28 October 2019

REGISTROS MÉDICOS DE MILLONES DE PERSONAS EN TODO EL MUNDO EXPUESTOS POR SOFTWARE INSEGURO

CONTENIDO ORIGINAL: https://noticiasseguridad.com/hacking-incidentes/registros-medicos-de-millones-de-personas-en-todo-el-mundo-expuestos-por-software-inseguro/

Un grupo de especialistas en seguridad informática de la plataforma especializada WizCase (reporte completo aquí) ha reportado el hallazgo de múltiples filtraciones de datos desde sitios web de medicina de todas partes del mundo. La información comprometida incluye recetas médicas, diagnósticos, números de Seguridad Social y, en muchos casos, nombres completos y domicilio.

Todas las bases de datos fueron encontradas sin asegurar, ni siquiera se necesitaba de una contraseña para acceder a la información, dejando expuestos a millones de pacientes.

Avishai Efrat, líder de la investigación, descubrió al menso nueve bases de datos médicos sin asegurar en países como Arabia Saudita, Brasil, Canadá, China, Estados Unidos, Francia y Nigeria. Aunque varían en cada caso particular, en general los detalles expuestos incluyen:

  • Nombres completos
  • Números telefónicos
  • Domicilio
  • Dirección email
  • Lugar de trabajo
  • Números de seguro social
  • Diagnósticos
  • Recetas médicas
  • Resultados de análisis clínicos
Infografía de las filtraciones. Fuente: WizCase

Respecto a las compañías operadoras de estas bases de datos expuestas, los expertos en seguridad informática también lograron establecer un perfil detallado, descrito de forma breve en los siguientes párrafos.

  • Arabia Saudita: La compañía de software aplicado a la salud Stella Technology expuso más de 4 GB de información perteneciente a cerca de 300 mil pacientes, incluyendo múltiples detalles personales, en un servidor Elasticsearch
  • Brasil: La base de datos expuesta en territorio brasileño, operada por la compañía Biosoft Medical Software, cuenta con 3 GB de información, equivalente a casi un millón 200 mil registros pertenecientes a pacientes de todo el país
  • Canadá: En el caso de Canadá, la compañía involucrada es Dental Software, con su solución ClearDent. En este caso se descubrió una base de datos de 8 MB, equivalente a casi 60 mil pacientes expuestos, en un servidor Elasticsearch
  • China: La Facultad de Medicina de la Universidad de Tsinghua expuso una base de datos de 650 MB, equivalentes a 60 mil registros de pacientes del Hospital Universitario de Tsinghua y de otros centros médicos en diversas ciudades chinas
  • Estados Unidos: Deep Think Health, compañía que proporciona una plataforma de aprendizaje automático para la industria médica, expuso una base de datos de 2.8 GB, lo que representa más de 700 mil registros sobre pacientes y personal médico en un servidor Elasticsearch. Los casos más sensibles involucran la exposición de diagnósticos y tratamiento de pacientes con cáncer
  • Francia: La compañía involucrada en territorio francés es Essilor, dedicada al diseño y manufactura de aparatos oftalmológicos. La base de datos comprometida consta de 5.7 GB, que incluyen detalles de miles de pacientes, optometristas y empleados de diversas áreas de la compañía
  • Nigeria: Todos los resultados de la Encuesta de Indicadores e Impacto del VIH/SIDA 2018 fueron expuestos en el país africano. En total, la base de datos consta de 1 GB, equivalentes a más de 88 mil registros.
Registro de Encuesta sobre VIH/SIDA en Nigeria. Fuente: WizCase

Acorde a los expertos en seguridad informática, debido a que la mayoría son servicios prestados por terceros, lo más probable es que las personas afectadas ni siquiera sepan que sus datos están en manos de estas compañías. Sin importar si estamos al tanto o no, los riesgos de seguridad son reales; entre estos riesgos se encuentran prácticas ampliamente conocidas, como el phishing, las campañas de emails de extorsión, fraudes telefónicos y por email, y robo de identidad.

Miles de fotografías de recetas médicas expuestas. Fuente: WizCase

La intervención de las compañías externas dificulta el proceso de contención de esta clase de incidentes, no obstante, expertos en seguridad informática del Instituto Internacional de Seguridad Cibernética (IICS) aconsejan a cualquier usuario potencialmente afectado seguir algunos consejos simples. Es necesario ignorar cualquier email sospechoso o que incluya enlaces a sitios externos, pues seguramente ya se están desplegando campañas masivas de phishing usando los datos expuestos. Además, recuerde que nunca se debe revelar información personal vía correo electrónico, pues ninguna compañía legítima solicita datos personales por este medio. El monitoreo continuo de sus cuentas en línea y estados de cuenta bancarios también es una buena alternativa.


LOS SERVIDORES DE NORDVPN FUERON HACKEADOS Y EL TRÁFICO DE USUARIOS RESULTÓ EXPUESTO

CONTENIDO ORIGINAL: https://noticiasseguridad.com/hacking-incidentes/los-servidores-de-nordvpn-fueron-hackeados-y-el-trafico-de-usuarios-resulto-expuesto/

La compañía de servicios de red privada virtual (VPN) NordVPN ha revelado un incidente de hacking ocurrido el año pasado. Acorde a expertos en seguridad de aplicaciones web, en marzo de 2018 un actor de amenazas irrumpió en uno de los servidores de la compañía, ubicado en Finlandia, exponiendo algunos datos sobre los hábitos de navegación de sus clientes.

NordVPN afirma que el servidor no contenía registros de actividad, nombres de usuario ni contraseñas. No obstante, el hacker sí pudo acceder a una lista de sitios visitados durante el tiempo que duró la intrusión, aunque el contenido de dichos sitios web se encuentra protegido con cifrado.

Los servicios de VPN se han vuelto muy populares durante los últimos dos años, aunque muchos usuarios de Internet siguen sin saber en qué consisten exactamente. Los expertos en seguridad de aplicaciones web mencionan que un servicio VPN funciona enviando el tráfico de Internet de los usuarios a través de servidores en múltiples ciudades o países para enmascarar los hábitos de navegación, fortaleciendo la privacidad en línea.

Tom Okman, asesor tecnológico de NordVPN, mencionó: “El responsable del ataque podría haberse infiltrado en el servidor especificado, interceptando sólo el tráfico y el nombre de los sitios web visitados durante un corto periodo de tiempo”.

NordVPN también mencionó que el servidor al que cada usuario se conecta cambia aproximadamente cada cinco minutos, aunque los usuarios pueden elegir en qué país establecer la conexión. En otras palabras, los usuarios podrían haber estado expuestos, pero por periodos de tiempo muy breves y de manera intermitente. Se estima que la mayoría de los usuarios expuestos se encuentra en Finlandia, donde se ubica el servidor.

Algunos expertos en seguridad de aplicaciones web comenzaron a divulgar el incidente durante el fin de semana pasado. Además, en el mensaje publicado por NordVPN se menciona que la intrusión podría haber durado meses y es probable que se haya presentado debido a que se instaló un sistema de acceso remoto muy poco seguro en el servidor comprometido.

Se calcula que el servidor permaneció comprometido desde el 31 de enero hasta el 20 de marzo de 2018, aunque el hacker sólo habría violado la seguridad de la implementación en una ocasión durante el mes de marzo.

Respecto a posibles ataques, la compañía afirma que la información almacenada en el servidor comprometido no puede ser usada para descifrar el tráfico de otros servidores bajo su control. Aunque NordVPN menciona que era posible usar una clave de cifrado robada para desplegar un ataque Man-in-The-Middle (MiTM), la complejidad de este ataque reduce al mínimo las posibilidades de ejecución, además de que las claves de cifrado posiblemente comprometidas ya han sido revocadas.

Como medida de seguridad adicional, NordVPN terminó su relación laboral con la compañía encargada del servidor comprometido.

Expertos en seguridad de aplicaciones web del Instituto Internacional de Seguridad Cibernética (IICS) mencionan que la compañía se encuentra informando a los clientes sobre el incidente vía email, aunque sólo como una formalidad, pues la compañía insiste en que esto no puede ser considerado como un incidente de hacking: “Esto es más bien una violación de seguridad aislada. No se ha comprometido la información de ningún usuario”, concluye Okman.


ALEXA Y GOOGLE HOME SON FÁCILMENTE HACKEABLES; NUNCA COMPRE ESTOS DISPOSITIVOS

CONTENIDO ORIGINAL: https://noticiasseguridad.com/tecnologia/alexa-y-google-home-son-facilmente-hackeables-nunca-compre-estos-dispositivos/

No es la primera vez que se trata este tema, pero esta es una clara confirmación de lo mencionado anteriormente respecto a la seguridad de algunos dispositivos inteligentes. Expertos en protección de datos de la firma Security Research Labs (SRL) alteraron ocho apps con el propósito de espiar a los usuarios de Amazon Echo y Google Home.

“La mayoría de los usuarios asumen que las aplicaciones de voz sólo se activan cuando el usuario menciona una palabra clave; las apps modificadas se aprovechan de este hecho”, mencionó Karsten Nohl, miembro del equipo de investigación.

Los expertos en protección de datos aseguran que la creación de estos “espías inteligentes” fue un proceso relativamente fácil, pues no se requerían conocimientos avanzados en programación. Las aplicaciones alteradas brindan servicios como horóscopo diario o generación de números aleatorios.

Al terminar de interactuar con la aplicación los smart speakers responden con un mensaje de despedida; no obstante, en logar de apagarse de inmediato, el software sigue ejecutándose por varios segundos más. De este modo, cualquier frase o palabra registrada durante el lapso de tiempo que la aplicación sigue ejecutándose era registrada y enviada a los expertos encargados de la investigación.

“Es importante destacar que las luces de los smart speakers objetivo seguían encendidas durante esos segundos posteriores al apagado del dispositivo, por lo que un usuario precavido no debería tener problemas en identificar que el dispositivo sigue activo”, menciona Nohl.

Durante un ataque similar se enviaba al usuario un mensaje que decía: “Una nueva actualización de seguridad para su dispositivo está disponible. Por favor, diga en voz alta ‘Iniciar actualización’, seguido de su contraseña”. En este ataque, cualquier palabra que el usuario mencionara al smart speaker era registrada y enviada a los expertos. Respecto a este escenario, Nohl asegura: “Esta es una conducta anómala, pues se supone que ninguna aplicación legítima debería pedir su contraseña al usuario”.

Por otra parte, David Emm, experto en protección de datos de Kaspersky Lab asegura que un aspecto clave de estas debilidades de seguridad tiene que ver con los desarrolladores de las apps para Google Home y Amazon Echo, pues muchas veces se trata de compañías externas. “Debemos recordar que la capacidad de escucha de estos dispositivos también se extiende a las aplicaciones con las que funcionan”, menciona el experto.

La firma de seguridad notificó a ambas compañías acerca de las pruebas realizadas. Google anunció que eliminaría las apps alteradas: “Además, estamos implementando mecanismos adicionales para evitar que estos problemas ocurran en escenarios reales durante el uso de Google Home”, menciona el comunicado de la compañía.

Por su parte, Amazon también emitió un comunicado: “La confianza de nuestros usuarios es lo más importante. Al recibir el reporte bloqueamos de inmediato los servicios mencionados y aplicamos medidas para prevenir y detectar comportamiento similar en otros servicios”.

Esta no es la primera ocasión en la que el uso de estas herramientas deja dudas de privacidad. Hace un par de meses, expertos en protección de datos del Instituto Internacional de Seguridad Cibernética (IICS) revelaron que Google permite que una compañía de terceros transcriba algunos fragmentos de las conversaciones de los usuarios con el Asistente de Google. Aunque la compañía afirma que esto se hace con el propósito de mejorar el sistema de aprendizaje automático del asistente de voz, miles de usuarios se mostraron preocupados, además de que se ignora bajo qué parámetros se eligen los fragmentos de audio que Google comparte con terceras partes.


MEDICAL RECORDS OF MILLIONS OF PEOPLE AROUND THE WORLD EXPOSED BY INSECURE SOFTWARE

ORIGINAL CONTENT: https://www.securitynewspaper.com/2019/10/22/medical-records-of-millions-of-people-around-the-world-exposed-by-insecure-software/

A group of information security specialists from the security firm WizCase (complete report here) has reported the finding of multiple data leaks from medical websites and software solutions around the world. The compromised information includes prescriptions, diagnoses, Social Security numbers and, in many cases, full names and addresses.

All databases were found unsecured, as experts not even needed a password to access the information, leaving millions of patients and medical staff members exposed.

The research leader Avishai Efrat discovered nine unsecured medical databases in countries such as Saudi Arabia, Brazil, Canada, China, the United States, France and Nigeria. Although they vary in each particular case, in general the details presented include:

  • Full names
  • Phone numbers
  • Home address
  • Email address
  • Workplace
  • Social security numbers
  • Diagnostics
  • Medical prescriptions
  • Clinical test results
Data leaking infographic. Source: WizCase

With regard to the companies operating these databases, the information security experts were also able to establish a detailed profile, described briefly in the following paragraphs.

  • Saudi Arabia: Health-applying software company Stella Technology exposed more than 4 GB of information belonging to nearly 300k patients, including multiple personal details, on an Elasticsearch server
  • Brazil: The database exposed in Brazilian territory, operated by the company Biosoft Medical Software, has 3 GB of information, equivalent to almost 1.2 million records belonging to patients throughout the country
  • Canada: In the case of Canada, the company involved is Dental Software, with its ClearDent solution. In this case, an 8 MB database, equivalent to nearly 60k exposed patients, was discovered on an Elasticsearch server
  • China: Tsinghua University Faculty of Medicine exhibited a database of 650 MB, equivalent to 60k patient records from Tsinghua University Hospital and other medical centers in various Chinese cities
  • United States: Deep Think Health, a company that provides a machine learning platform for the medical industry, exposed a 2.8 GB database, representing more than 700k records of patients and medical staff on an Elasticsearch server. The most sensitive cases involve the exposure of diagnoses and treatment of cancer patients
  • France: The involved company in French territory is Essilor, dedicated to the design and manufacture of ophthalmological devices. The compromised database consists of 5.7 GB, including details of thousands of patients, optometrists and employees from various areas of the company
  • Nigeria: All results of the 2018 HIV/AIDS Indicators and Impact Survey were exposed in the African country. In total, the database consists of 1 GB, equivalent to more than 88 thousand records.
2018 HIV/AIDS Survey entry. Source: WizCase

According to information security experts, because most are services provided by third parties, it is likely that the people affected do not even know that their data is in the hands of these companies. Whether we are aware or not, the security risks are real; these risks include widely known practices such as phishing, extortion email campaigns, phone and email fraud, and identity theft.

Experts even found thousands of pictures. Source: WizCase

The intervention of external companies hinders the process of containment of such incidents; however, information security experts from the International Institute of Cyber Security (IICS) advised any user potentially affected to follow some simple advice. It is necessary to ignore any suspicious or linking emails to external sites, as massive phishing campaigns are already being deployed using the exposed data. Also, remember that personal information should never be disclosed via email, as no legitimate company requests personal data by this means. Continuous monitoring of your online accounts and bank statements is also a good alternative.


NORDVPN SERVERS WERE HACKED; USERS’ TRAFFIC WAS EXPOSED BY THE ATTACKERS

Virtual private network services (VPN) company NordVPN has revealed a hacking incident that occurred last year. According to web application security experts, in March 2018 a threat actor broke into one of the company’s servers, located in Finland, exposing some data on the browsing habits of its customers.

NordVPN states that the server did not contain activity logs, usernames, or passwords. However, the hacker was able to access a list of sites visited during the intrusion, although the content of those websites is protected with encryption.

VPN services have become very popular over the past two years, although many Internet users still don’t know exactly what they consist of. Web application security experts mention that a VPN service works by sending users’ Internet traffic through servers in multiple cities or countries to mask browsing habits, strengthening online privacy.

Tom Okman, NordVPN’s technology advisor, said: “The person responsible for the attack could have infiltrated the specified server, intercepting only the traffic and the name of the websites visited for a short period of time.”

NordVPN also mentioned that the server to which each user is connected changes approximately every five minutes, although users can choose which country to establish the connection. In other words, users might have been exposed, but for very short periods of time and intermittently. It is estimated that the majority of exposed users are located in Finland, where the server is located.

Some web application security experts began spreading the word on this incident over the past weekend. In addition, the message posted by NordVPN mentions that the intrusion could have lasted months and is likely to have been performed due to an unsecured remote access system being installed on the compromised server.

It is estimated that the server remained compromised from January 31 to March 20, 2018, although the hacker would have only violated the security of the deployment on one occasion during the month of March.

Regarding possible attacks, the company states that information stored on the compromised server cannot be used to decrypt traffic from other servers under its control. Although NordVPN mentions that it was possible to use a stolen encryption key to deploy a Man-in-The-Middle (MiTM) attack, the complexity of this attack minimizes the chances of execution, plus possibly compromised encryption keys have been already revoked.

As an additional security measure, NordVPN terminated its working relationship with the company in charge of the compromised server.

Web application security experts from the International Institute of Cyber Security (IICS) mention that the company is informing customers about the incident via email, albeit only as a formality, as the company insists that this is not can be considered a hacking incident: “This is more of an isolated security breach. No user’s information has been compromised,” Okman concludes.


ALEXA AND GOOGLE HOME ARE EASILY HACKABLE; NEVER BUY THESE DEVICES

ORIGINAL CONTENT: https://www.securitynewspaper.com/2019/10/22/alexa-and-google-home-are-easily-hackable-never-buy-these-devices/

This is not the first time this issue has been addressed, but this is a clear confirmation regarding the security of some smart devices. Data protection experts from German form Security Research Labs (SRL) altered eight apps for the purpose of spying on Amazon Echo and Google Home users.

“Most users assume that voice apps are only activated when the user mentions an awake word; modified apps take advantage of this fact,” said Karsten Nohl, a member of the research team.

Data protection experts say that creating these “smart spies” was a relatively easy process, as no advanced programming knowledge was required. Altered applications provide services such as daily horoscope or random number generation.

When users stop interacting with the app the smart speakers respond with a departure message; however, instead of shutting down immediately, the software keeps running for several additional seconds. Thus, any phrase or word recorded during the time that the application keeps running was recorded and sent to the experts in charge of the investigation.

“It’s important to note that the target smart speakers’ lights were still on for those seconds after the device’s shutdown, so a cautious user shouldn’t have a problem identifying that the device is still active,” Nohl says.

During a similar attack, the user was sent a message that says: “A new security update for your device is available. Please say aloud ‘Start Update’, followed by your password”. In this attack, any words that the user mentioned to the smart speaker were registered and sent to the experts. Regarding this scenario, Nohl says: “This is an anomalous behavior, as it is assumed that no legitimate application should ask the user for their password”.

Moreover, David Emm, data protection expert at Kaspersky Lab assures that a key aspect of these security weaknesses has to do with the developers of the apps for Google Home and Amazon Echo, as they are often external companies. “We should remember that the listening capability of these devices also extends to the applications they work with,” the expert says.

The security firm notified both companies of the tests conducted. Google announced that it would remove altered apps: “In addition, we are implementing additional mechanisms to prevent these issues from occurring in real-world scenarios while using Google Home,” the company’s statement says.

On the other hand, Amazon also issued a statement: “The trust of our users is the most important thing. Upon receipt of the report, we immediately block the services mentioned and take steps to prevent and detect similar behavior in other services.”

This is not the first time that the use of these tools leaves doubts on privacy. A couple of months ago, data protection experts at the International Institute of Cyber Security (IICS) revealed that Google allows a third-party company to transcribe some samples of user conversations with the Google Assistant. Although the company claims this is done with the purpose of improving the voice assistant’s machine learning system, thousands of users were concerned, and is ignored under what parameters are the audio snippets that Google shares with third-parties.