MITRE, CISA Announce 2021 List of Most Common Hardware Weaknesses

MITRE and the DHS’s Cybersecurity and Infrastructure Security Agency (CISA) have announced the release of the “2021 Common Weakness Enumeration (CWE) Most Important Hardware Weaknesses” list.

Composed of the most frequent and critical errors that result in serious hardware vulnerabilities, the list includes a total of 12 entries, with five additional weaknesses that scored just outside the final list also mentioned.

The list is meant to raise awareness of common hardware weaknesses and to help prevent hardware vulnerabilities at the source, MITRE says.

In addition to instructing designers and programmers on how errors can be eliminated during product development, the list can help analysts and engineers plan security testing and evaluation, as well as consumers to ask suppliers to deliver more secure hardware.

The list is also expected to help managers and CIOs assess the progress of their efforts to secure hardware and to decide where resources should be directed to build tools and automation processes to mitigate a wide class of vulnerabilities, MITRE notes.

The final 2021 CWE Most Important Hardware Weaknesses list includes the 12 entries that scored highest during analysis.

 2021 CWE Most Important Hardware Weaknesses

Five other weaknesses (the Hardware Weaknesses on the Cusp) scored just outside of the final list, but risk-decision makers and those performing mitigations should still consider these in their analyses, MITRE says.

Although the methodology used to create the list resulted in a ranking for the 12(+5) CWEs, the hardware team and the Hardware CWE Special Interest Group (SIG) believe that the list should not be viewed as a hierarchical, ordered set when it comes to the importance of each weakness.

“The entries should be thought of as a set of mostly equal hardware weakness concerns based on our methodology,” MITRE notes.

Future versions of the CWE Most Important Hardware Weaknesses are expected to include other entries, aiming to deliver a list considered to be the most useful for the community.

The United States Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review the list and the recommended mitigations, to determine which are suitable to adopt.

“The 2021 Hardware List is a compilation of the most frequent and critical errors that can lead to serious vulnerabilities in hardware. An attacker can often exploit these vulnerabilities to take control of an affected system, obtain sensitive information, or cause a denial-of-service condition,” CISA notes.

Related: OWASP Top 10 Updated With Three New Categories

Related: What We Learn from MITRE’s Most Dangerous Software Weaknesses List

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/CcKvBH0s8Xs/mitre-cisa-announce-2021-list-most-common-hardware-weaknesses




NSA, CISA Release 5G Cloud Security Guidance

The NSA and the DHS’s Cybersecurity and Infrastructure Security Agency (CISA) on Thursday released the first in a series of guidance documents for securing 5G cloud infrastructure.

The guidance comes from the Enduring Security Framework (ESF), a public-private partnership between the NSA, CISA, the Defense Department, the intelligence community, as well as IT, communications, and defense industrial base companies.

The first of the four-part series on securing 5G clouds focuses on preventing and detecting lateral movement.

5G networks rely on cloud infrastructures for agility, resilience and scalability. These networks need to be secure as they will be a tempting target for threat actors looking to cause disruptions or compromise information.

A significant security challenge is related to the use of shared physical infrastructure by multiple mobile network operators. CISA and the NSA highlighted that cloud providers and mobile operators will need to share security responsibilities, with operators being responsible for securing their cloud tenancy.

The agencies pointed out that while defending the perimeter is important, it’s also important to have measures in place to limit lateral movement in case threat actors manage to breach the perimeter.

Recommendations for limiting lateral movement in 5G cloud networks include implementing secure identity and access management, keeping 5G cloud software updated to ensure it’s not affected by known vulnerabilities, securely configuring networking, locking down communications among isolated network functions, monitoring systems for signs of lateral movement, and developing and deploying analytics to detect the presence of sophisticated threat actors.

While these recommendations are mostly for cloud providers and mobile network operators, some also apply to customers.

The other three parts of this guidance will focus on isolating network resources, protecting data through all phases of its lifecycle (transit, in use, and at rest), and ensuring the integrity of infrastructure.

“This series exemplifies the national security benefits resulting from the joint efforts of ESF experts from CISA, NSA, and industry,” said Rob Joyce, cybersecurity director at the NSA. “Service providers and system integrators that build and configure 5G cloud infrastructures who apply this guidance will do their part to improve cybersecurity for our nation.”

Related: CISA Details Strategy for Secure 5G Deployment

Related: NSA Publishes Guidance for Enterprises on Adoption of Encrypted DNS

view counter

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Previous Columns by Eduard Kovacs:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/fDXjV21bFTw/nsa-cisa-release-5g-cloud-security-guidance




HelpSystems Expands Shopping Spree With Digital Guardian Acquisition

Minnesota-based IT management and software powerhouse HelpSystems expanded its year-long cybersecurity shopping spree with a new deal to acquire data loss prevention specialists Digital Guardian.

Financial terms of the acquisition were not released.   

Digital Guardian is a late-stage Massachusetts-based startup that raised $173 million over multiple venture capital funding rounds.  The company has gained traction in large and mid-sized organizations looking for DLP tools to protect sensitive data and corporate assets.

Digital Guardian also provides a managed service that operates as an extension of an enterprise security team to protect sensitive data from threats originating inside and outside the organization.

[ READ: Inside the Battle to Control Enterprise Security Data Lakes ]

HelpSystems said the Digital Guardian’s technology will plug right into a data security portfolio that swelled in 2021 through multiple acquisitions of prominent cybersecurity startups.

Just this year, HelpSystems acquired Agari (email security), Beyond Security (vulnerability management), Vera (data security and control), PhishLabs (email security) and Digital Defense (network security)..

“In addition to extending HelpSystems’ DLP capability, this acquisition further improves the company’s ability to categorize, or classify, data and protect it across a wide set of applications and operating systems,” HelpSystems said in a statement announcing the latest purchase.

HelpSystems is owned by private equity firms HGGC, TA Associates, Charlesbank Capital Partners, and Harvest Partners.

Related: HelpSystems Acquires Vera to Broaden Data Security Portfolio

Related: For Microsoft, Security is a $10 Billion Business

Related: Inside the Battle to Control Enterprise Security Data Lakes

view counter

Ryan Naraine is Editor-at-Large at SecurityWeek and host of the popular Security Conversations podcast series. He is a journalist and cybersecurity strategist with more than 20 years experience covering IT security and technology trends.
Ryan has built security engagement programs at major global brands, including Intel Corp., Bishop Fox and Kaspersky GReAT. He is a co-founder of Threatpost and the global SAS conference series. Ryan’s career as a journalist includes bylines at major technology publications including Ziff Davis eWEEK, CBS Interactive’s ZDNet, PCMag and PC World.
Ryan is a director of the Security Tinkerers non-profit, and a regular speaker at security conferences around the world.
Follow Ryan on Twitter @ryanaraine.

Previous Columns by Ryan Naraine:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/Vrngud9osXU/helpsystems-expands-shopping-spree-digital-guardian-acquisition




Massachusetts Health Network Hacked; Patient Info Exposed

A Worcester, Mass. health care network says someone hacked into its employee email system, potentially exposing the personal information of thousands of patients.

UMass Memorial Health notified patients earlier this month if their information was involved in the breach, which occurred between June 2020 and January. The personal data included Social Security numbers, insurance information and medical information, The Telegram & Gazette reported Thursday.

More than 200,000 patients and health plan participants could have been affected by the breach, according to a federal database of cybersecurity incidents at medical facilities.

The hospital says it has investigated the incident but couldn’t determine how much of the personal information may have been stolen.

Affected patients will receive free credit monitoring and data protection assistance.

Related: Massachusetts Electric Utility Hit by Ransomware

Related: Hospital Network Reveals Cause of 2020 Cyberattack

Related: Irish Health System Says It’s Targeted in Ransomware Attack

Related: UHS Shuts Down Systems in U.S. Hospitals Following Cyberattack

view counter

Previous Columns by Associated Press:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/YU9uxRmCLa4/massachusetts-health-network-hacked-patient-info-exposed




Shrootless: macOS Vulnerability Found by Microsoft Allows Rootkit Installation

Microsoft on Thursday published information on a vulnerability in Apple’s macOS platform that could allow an attacker to bypass System Integrity Protection (SIP) and modify operating system files.

Tracked as CVE-2021-30892 and named “Shrootless” by Microsoft, the vulnerability exists in the method used to install Apple-signed packages with post-install scripts.

To successfully exploit the vulnerability, an attacker needs to create a specially crafted file that would allow them to hijack the installation process of said packages.

Apple introduced SIP in macOS Yosemite to restrict root users from performing actions leading to system integrity compromise, but the newly addressed security error could allow an attacker to install a malicious kernel driver (rootkit), deploy persistent malware, or overwrite system files.

Also referred to as rootless, SIP locks the system from boot time, to keep the platform protected, and can only be modified when the machine is in recovery mode.

Apple also improved SIP restrictions to harden it, but included several exceptions (entitlements) for specific Apple processes, such as system updates, which have unrestricted access to SIP-protected directories.

What Microsoft discovered was that the entitlement for the daemon system_installd allows for child processes to bypass SIP filesystem restrictions.

Such is the case with Apple-signed packages (.pkg files). Should post-install scripts be included in the package, system_installd executes them by invoking the default shell, zsh.

“When zsh starts, it looks for the file /etc/zshenv, and—if found—runs commands from that file automatically, even in non-interactive mode. Therefore, for attackers to perform arbitrary operations on the device, a fully reliable path they could take would be to create a malicious /etc/zshenv file and then wait for system_installd to invoke zsh,” Microsoft explains.

The tech giant also explains that zshenv could be abused as a general attack technique, given that there’s an equivalent of /etc/zshenv for each user, “which has the same function and behavior but doesn’t require root permissions to write to.”

Apple addressed the vulnerability with the macOS Big Sur 11.6.1 update, which started rolling out on October 26, containing patches for 23 other vulnerabilities. This week Apple also released iOS 15.1 and iPadOS 15.1, with patches for 22 security flaws.

Related: PoC Exploit Released for macOS Gatekeeper Bypass

Related: Apple Ships iOS 15 with MFA Code Generator

Related: Apple Patches Recent Sudo Vulnerability in macOS

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/dN5IcBVibg0/shrootless-macos-vulnerability-found-microsoft-allows-rootkit-installation




Russian Man Extradited to U.S. for Role in TrickBot Malware Development

A Russian national has been extradited from South Korea to the United States to face charges for his alleged role in the cybercriminal organization behind the TrickBot malware.

The man, Vladimir Dunaev, 38, allegedly was part of the TrickBot group from November 2015 through August 2020, stealing money and information and damaging the computers of financial institutions, school districts, government entities, private businesses, and utility companies, court documents reveal.

The TrickBot group allegedly used “a network of co-conspirators and freelance computer programmers” to develop, deliver, and maintain TrickBot. Millions of computers globally have been infected with the Trojan, the indictment claims.

According to the U.S. Justice Department, Dunaev worked as a developer for the cybercrime group in various roles, such as supervising the malware execution, building browser modifications, and helping with hiding the malware from security software.

TrickBot was created to capture online banking credentials and other sensitive information, such as credit card numbers, dates of birth, emails, passwords, social security numbers, and more. More recent versions of the malware were designed to help distribute ransomware.

The indictment alleges that the TrickBot operators used the stolen credentials and other personal data to access victims’ online bank accounts, make unauthorized transfers, and to launder money.

Dunaev is charged with aggravated identity theft, wire fraud, bank fraud, conspiracy to commit computer fraud, and money laundering, among others. If convicted on all counts, he faces up to 60 years in prison.

TrickBot, which has been around since 2016, is believed to be operated by the same cybercriminal organization that operated the Dyre Trojan.

In October 2020, Microsoft announced an operation aimed at taking down TrickBot, but the malware managed to survive the attempt and even received several updates after. In March, CISA and the FBI warned of continuous attacks employing TrickBot.

In June, U.S. authorities announced charges against a Latvian woman who allegedly also helped develop TrickBot.

Related: TrickBot Gets Updated to Survive Takedown Attempts

Related: Supermicro, Pulse Secure Respond to Trickbot’s Ability to Target Firmware

Related: Five Months After Takedown Attempt, CISA and FBI Warn of Ongoing TrickBot Attacks

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/pt1G2wRPn3Y/russian-man-extradited-us-role-trickbot-malware-development




12 People Arrested Over Ransomware Attacks on Critical Infrastructure

Europol and Norwegian Police on Friday announced the arrests of 12 individuals suspected of being involved in ransomware attacks launched against companies around the world, including critical infrastructure organizations.

According to Europol, the suspects played various roles in ransomware attacks that impacted more than 1,800 victims across 71 countries, including many major corporations that suffered significant disruptions due to the attacks.

The law enforcement operation targeting the 12 suspects was carried out on October 26 in Ukraine and Switzerland, and it resulted in the seizure of cash, luxury vehicles and electronic devices.

“Most of these suspects are considered high-value targets because they are being investigated in multiple high-profile cases in different jurisdictions,” Europol said.

Each of the alleged cybercriminals played a different role. Some of them were in charge of breaching an organization’s systems using brute-force attacks, SQL injections, phishing emails and stolen credentials. Others focused on lateral movement and deployment of malware such as Trickbot or post-exploitation frameworks such as PowerShell Empire and Cobalt Strike. Some of the suspects were allegedly in charge of laundering ransom payments.

The malicious hackers used various ransomware families, including LockerGoga, MegaCortex and Dharma.

Norwegian Police said one of the victims of these threat actors was Norwegian metals and energy giant Norsk Hydro, which lost tens of millions of dollars following an attack in 2019.

Just before Europol announced the arrests, the U.S. Department of Justice revealed that a Russian national who was allegedly part of a cybercrime group that used the Trickbot malware had been extradited from South Korea to the United States. This was the second Trickbot-related arrest in recent months as part of an operation conducted by the DoJ’s Ransomware and Digital Extortion Task Force.

The Trickbot suspect, 38-year-old Vladimir Dunaev, faces up to 60 years in prison for his role in the cybercrime operation.

Earlier this month, Europol announced the arrests of two alleged members of a prolific ransomware group in Ukraine. The ransomware was not named at the time due to what the police agency described as “an operational reason.”

Related: Ransomware Takedowns Underscore Need for Private-Public Cybersecurity Collaboration

Related: Ukrainian Suspected of Leading Carbanak Gang Arrested in Spain

Related: Ukraine Arrests ‘Avalanche’ Cybercrime Organizer: Police

view counter

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Previous Columns by Eduard Kovacs:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/lNcRfzrW8vg/12-people-arrested-over-ransomware-attacks-critical-infrastructure




Ransomware Attack Hits PNG Finance Ministry

A cyberattack on Papua New Guinea’s finance ministry briefly disrupted government payments and operations, officials said late Thursday.

Ransomware infiltrated and compromised a core server at the department of finance last week, hampering the government’s access to foreign aid, its ability to pay cheques and carry out other basic functions in the midst of a spiralling Covid-19 surge.

“The department has now managed to fully restore the system, however, because of the risk, we are playing safe by not allowing full usage of the affected network,” said John Pundari, acting treasurer.

Pundari said the department “did not pay any ransom to the purported hacker or any of its third party agents. We have managed to restore normalcy.”

The attack took place in the middle of the night on October 22.

The platform controls budgeting and financing for the entire Papua New Guinea government.

Related: Belgium Interior Ministry Targeted in Cyber Attack

Related: Japanese Ministries Confirm Impact from Fujitsu Data Breach

Related: Belarus Brands Group Who Claimed to Hack Interior Ministry ‘Extremist’

view counter

© AFP 2020

Previous Columns by AFP:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/ebZeBtN0_Iw/ransomware-attack-hits-png-finance-ministry




Chrome 95 Update Patches Exploited Zero-Days, Flaws Disclosed at Tianfu Cup

A Chrome 95 update released by Google on Thursday patches two actively exploited Chrome vulnerabilities, as well as flaws that were disclosed recently at a Chinese hacking contest.

The actively exploited vulnerabilities are tracked as CVE-2021-38000, which has been described as an insufficient validation of untrusted input in Intents, and CVE-2021-38003, an inappropriate implementation issue affecting the V8 JavaScript engine. CVE-2021-38000 was discovered in September and CVE-2021-38003 was identified just three days ago.

Google employees have been credited for both zero-day vulnerabilities. No information has been made available regarding the attacks in which these vulnerabilities have been exploited.

More than a dozen Chrome vulnerabilities discovered this year have been exploited in the wild, according to data from Google’s Project Zero group.

The latest Chrome 95 update includes eight security fixes, including at least seven classified as high severity. Wei Yuan of MoyunSec VLab earned $10,000 for a use-after-free bug, and while that is the highest bounty awarded by Google, two of the CVEs patched this week earned two research teams a total of $300,000 at the Tianfu Cup hacking contest that took place recently in China.

The Kunlun Lab and 360 Alpha Lab teams each earned $150,000 for Chrome exploit chains that achieved remote code execution with a sandbox escape. The rewards were paid out by the organizers of Tianfu Cup — Google does not pay out separate rewards for vulnerabilities disclosed at hacking competitions such as Tianfu Cup and Pwn2Own.

SecurityWeek has learned that the Kunlun Lab exploit also involved a Windows kernel bug that has yet to be patched.

At the Tianfu Cup, participants earned a total of $1.9 million for demonstrating exploits targeting Windows 10, Ubuntu, iOS 15 on iPhone 13 Pro, Microsoft Exchange, Chrome, Safari, Adobe Reader, Parallels Desktop, QEMU, Docker, VMware ESXi and Workstation, and ASUS routers.

Related: Google Patches Two More Exploited Zero-Day Vulnerabilities in Chrome

Related: Chrome 94 Update Patches Actively Exploited Zero-Day Vulnerability

Related: Google Warns of Exploited Zero-Days in Chrome Browser

view counter

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Previous Columns by Eduard Kovacs:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/dCutI0Cf03M/chrome-95-update-patches-exploited-zero-days-flaws-disclosed-tianfu-cup




India’s Top Court Orders Probe Into Pegasus Snooping

India’s Supreme Court on Wednesday ordered an independent investigation into the alleged government use of Pegasus spyware on journalists, opposition politicians and activists with the chief justice calling the implications “Orwellian”.

India was one of 45 countries where tens of thousands of numbers were targeted by the spyware made by Israeli firm NSO, according to leaked documents released this year.

More than 1,000 of the numbers were Indian and the Supreme Court order followed petitions from individuals that the chief justice N.V. Ramana said “raise an Orwellian concern”.

He added that the court had accepted the petitions because “there has been no specific denial” by the government.

The state cannot be given a “free pass every time the spectre of national security is raised,” the court said as it named cyber and computer science experts to look into the allegations.

Phones infected with Pegasus software, which is normally only sold to governments or security agencies, give the user access to the target’s messages and photos, and track their location.

Critics say that in India it is part of a growing assault on dissent and civil liberties under the Hindu nationalist government of Prime Minister Narendra Modi.

The Indian government would not deny or confirm the use of Pegasus because of national security. It offered to set up its own committee.

Soon after the Pegasus reports emerged in July, India’s Parliament was disrupted by opposition calls for an investigation.

The Indian phone numbers put under surveillance reportedly included senior opposition leader Rahul Gandhi, journalists, activists, government critics and former judges.

A woman who had accused India’s former chief justice of sexual harassment was also reported to be on the list.

The Washington Post said an analysis of more than 20 Indian phones on the list showed that 10 had been targeted by Pegasus, seven successfully.

Related: Threat Actor Promises Pegasus Spyware Protection, Serves Trojan Instead

Related: Germany Admits Police Used Controversial Pegasus Spyware

Related: Pegasus Scandal Shows Risk of Israel’s Spy-tech Diplomacy

view counter

© AFP 2020

Previous Columns by AFP:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/fJZdWmDKSsE/indias-top-court-orders-probe-pegasus-snooping