Posts

Showing posts with the label APT10

Cyber Security Roundup for June 2019

Keep Patching! June 2019 was another very busy month for security update releases. Microsoft released updates to patch 22 critical rated vulnerabilities, Intel released 11 fixes, and there were also several critical security updates for Apple Airport , Adobe Flash Player , Cisco devices , Cisco Data Centre Network Manager ,  Dell SupportAssist ,  Google Chrome , Firefox and Apache .  One further standout vulnerability was the "SACK Panic" TCP Linux and FreeBSD kernel vulnerability , uncovered by Netflix researchers, however,  Microsoft released a security advisory in regards to TCP SACK Panic by the end of the month. The  National Security Agency (NSA) backed up UK National Cyber Security Centre (NCSC) and Microsoft’s continuing strong recommendations   for everyone to apply the latest security updates to all versions of Microsoft Windows, including the unsupported XP, Vista and Windows 2003 Server, to protect against the supercritical  CVE-2019-07...

Cyber Security Roundup for February 2019

The perceived threat posed by Huawei to the UK national infrastructure continued to make the headlines throughout February, as politicians, UK government agencies and the Chinese telecoms giant continued to play out their rather public spat in the media. See my post Is Huawei a Threat to UK National Security? for further details. And also, why DDoS might be the greater threat to 5G than Huawei supplied network devices . February was a rather quiet month for hacks and data breaches in the UK, Mumsnet reported a minor data breach following a botched upgrade , and that was about it. The month was a busy one for security updates, with Microsoft , Adobe and Cisco all releasing high numbers of patches to fix various security vulnerabilities, including several released outside of their scheduled monthly patch release cycles. A survey by PCI Pal concluded the consequences of a data breach had a greater impact in the UK than the United States , in that UK customers were more likely to abando...

Cyber Security Roundup for December 2018

Image
The final Cyber Security Roundup of 2018 concludes reports of major data breaches, serious software vulnerabilities and evolving cyber threats, so pretty much like the previous 11 months of the year. 5.3 millions users of "make your own avatar" app Boomoji had their accounts compromised, after the company reportedly didn't secure their internet connected databases properly. "Question and Answer" website Quora also announced the compromise of 100 million of its user accounts following a hack. A large data breach reported in Brazil is of interest, a massive 120 million Brazilian citizens personal records were compromised due to a poorly secured Amazon S3 bucket . This is not the first mass data breach caused by an insecure S3 bucket we've seen in 2018, the lesson to be learnt in the UK, is to never assume or take cloud security for granted, its essential practice to test and audit cloud services regularly. Amongst the amazing and intriguing space expl...

Cyber Security Roundup for September 2018

September 2018 started with a data breach bang, with  British Airways disclosing a significant hack and data loss . 380,000 of the airlines' website and mobile app customers had their debit and credit card details lifted via a maliciously injected script.  The breach even caused BA owners, IAG, to drop in value 4%. And to compound matters, there were several claims made that  the BA website wasn't PCI DSS compliant , implying if they were PCI DSS compliant, their customer's personal and payment card information would still be safe.  For further details about this breach see my blog posts;  British Airways Customer Data Stolen in Website and Mobile App Hack  and  British Airways Hack Update: Caused by Injected Script & PCI DSS Non-Compliance is Suspected . Facebook continues to make all the wrong kind of privacy headlines after a massive user data breach was confirmed by the social media giant at the end of the month. Facebook said at ...

Cyber Security Roundup for April 2017

In April the National Cyber Security Centre (NCSC) briefed major UK businesses about a significant Chinese Cyber-Espionage Threat called APT10, also known as Stone Panda, which I have featured in a separate blog post - Detecting & Preventing APT10 Operation Cloud Hopper . The InterContinential Hotel Group, a hotel giant best known for the Crowne Park Plaza and Holiday Inn in the UK, reported data breaches within 12 of its hotels, however, Brian Krebs, the investigative journalist who first broke the story , reckons that there could be more than 1000 locations affected. A statement released on the hotel's website says that the malware, which infected the hotels' card payment systems, was identified between 29 September and 29 December 2016. Payday loan firm Wonga reported a data breach which may affect up to 245,000 of its UK customers. The information stolen includes names, addresses, phone numbers, bank account numbers and sort codes. A BBC Click investigation ha...

Detecting & Preventing APT10 Operation Cloud Hopper

There has been much concern over a state-sponsor threat known as APT10 Operation Cloud Hopper, also known as Stone Panda, after the UK National Cyber Security Centre (NCSC) recently spooked UK businesses and their suppliers about a Chinese threat actor posing a serious threat to IT Managed Service Providers (MPS) and their UK clients.    Overview of the Threat APT10, a Chinese-based hacking  group also known as Stone Panda, MenuPass,  CVNX,  and Potassium is operating a hacking  campaign known as Operation Cloud Hopper, which is  believed to have been underway since 2014. There are intelligence reports which indicate the APT10 threat actor has significantly upscaled their capabilities and attack sophistication in early 2016. The APT10 Cloud Hopper campaign focuses on sending malware infected emails to staff working at  IT Managed Service Providers (MPS) , once executed the malware creates a backdoor which allows the attacker remote access t...