FireSale HackBoy

Knowledge Shared By FireSale HackBoy...

Hacking

The Art Of Exploitation...

Ethical Hacking

Security Experts...Same Techniques To Make Hacker's Stuff Useless.

Black Hat Hacking

Dark Side Of Hacking... In Short Destruction Of Cyber Stuff.

Digital Stuff

All The Digital Stuff Is Under The Influence Of Cyber Attacks... Be Safe

Monday, January 27, 2020

Citrix Server Vulnerability leads to Ransomware Attack

Citrix Server which allows centrally hosted applications to be delivered to mobile and desktop clients is found to be vulnerable to cyber-attacks which when exploited by hackers can lead to ransomware infections and bitcoins mining.

 

Citrix has however released a patch for CVE-2019-19781 bug infecting its Application Delivery Controller (ADC) systems and Gateways last week in a hope that all its users will patch their systems to keep away their servers from malware attacks.

 

Security researchers from FireEye have warned that attackers are exploring the flaw and are succeeding in deploying a backdoor named “NotRobin” which then leads them to install malware such as coin miners and file encryption.

 

Germany automobile spare parts manufacturer Gedia reportedly became a victim of a ransomware attack last week through the Citrix vulnerability alerting manufacturing companies all over the world. And this was confirmed by the researchers from FireEye early today.

 

FireEye confirms that the new vector of infecting enterprise victims with malware has emerged through the Citrix Vulnerability and in some cases, the servers were being infected by a new ransomware variant named as “Ragnarok” that appears to have been created in Mid-January this year to use the Gateway to deploy ransomware via Central Pivot Point. And hackers are seen demanding a ransom of 1BTC to decrypt one machine or 5 BTC/ $43,000 for decrypting all machines.

 

Researchers claim that currently 4-5 hacking groups are trying to exploit the Citrix Flaw in ransomware attacks and might have succeeded in infiltrating 2-3 companies(including GEDIA) by now.

 

Note- GEDIA has to endorse the news that it was hit by a ransomware attack. However, the officials of the German manufacturer did release a press statement on Thursday last week saying their systems were experiencing downtime due to a cyber attack.

 

The post Citrix Server Vulnerability leads to Ransomware Attack appeared first on Cybersecurity Insiders.


January 27, 2020 at 08:49PM

Sunday, January 26, 2020

UK PM Boris Johnson phone hacked by Saudi Prince Salman

Just when the reports are emerging that Amazon founder Jeff Bezos phone was hacked by Saudi Ruler Mohammad Bin Salman in 2018 to access sensitive information, here comes a piece of information from a source from Daily Mail that the Saudi ruler might also have access to UK Prime Minister Boris Johnson’s mobile phone as the latter had exchanged his number with the former during his regime as a foreign secretary of UK in 2016-18.

Last Wednesday, some of the media resources alleged the Saudi Prince had hacked the Amazon Chief’s mobile phone in 2018 through WhatsApp by sending him a video file of cladily lady dressed up resembling Jeff Bezos Pilot girlfriend Lauren Sanchez.

Security analysts now suggest that the message was infected by a spying malware that had the capability of analyzing and sending all the data from the victim’s device to remote servers.

Bezos could have been made the target as he owns The Washington Post which first published a detailed article on the murder mystery of Journalist Jamal Khashoggi, who was brutally murdered by the ruler of Saudi in 2018.

Now, news is out that the mobile phone of Boris Johnson was also bombarded by ‘Emoji-laden’ WhatsApp messages by Saudi Ruler Mohammad Bin Salman in 2016 which has sparked fears that the UK Prime Minister’s phone might have also been under control of the Saudi Prince- as Ms. Johnson seems to be in regular contact with the Prince Mohammad Bin Salman Bin Abdul AI Saud.

While the PM’s office in Downing Street has refused to comment on the article published in Daily Mail, cyber experts say that opening such files can allow hackers or the threat actors’ access data, photographs and contacts on the infected device.

However, Officials who provide security in all ways to Johnson have assured that the smartphone used by Britain’s PM has all necessary security measures in place which protect the device from all malicious ‘Stuff’.

Meanwhile, Saudi Foreign Minister Prince Faisal Bin Farhan Al Saud has dismissed all allegations as absurd and added that Prince Salman does not need to peep into the lives of his friends through their devices.

The post UK PM Boris Johnson phone hacked by Saudi Prince Salman appeared first on Cybersecurity Insiders.


January 27, 2020 at 10:13AM

Deloitte acquires Cybersecurity consulting firm SecurePath

New York-based Professional Services firm Deloitte has made it official that it is going to acquire Malaysian Cybersecurity Consulting firm SecurePath. The objective is to strengthen the services of blockchain technology-based Deloitte’s Cyber Risk Services with SecurePath’s Risk Advisory practices such as data loss prevention, cyber threat defense and such.

Founded in the year 2011, SecurePath is known to offer cyber threat defense-line to governments and private entities that need Risk & Compliance and Information Management & Protection. Some of the partners and vendors of the company include VERITAS, NetIQ and Symantec.

“As businesses are investing more on projects and programs which help them monitor and thwart cyber threats in real-time, SecurePath’s inclusion will help our clients accelerate their insights needed to detect, analyze and block the threats before they cause any untoward incident”, said James Nunn Price, the Cyber Leader of Deloitte Asia Pacific.

“Joining Deloitte will create unparalleled Synergy in the market both locally and regionally, with the credentials of the SecurePath’s team”, said Kim Chung, the founder of SecurePath.

As per the details available to our Cybersecurity Insiders, SecurePath’s Kim Chuen( Chung) and his staff will be joining Deloitte by early next month and will work full force to strengthen the latter’s cybersecurity capabilities within the Asia Pacific.

Thus, with this latest deal, Deloitte seems to have completed its sixth purchase from last year’s resolution of investing heavily in risk and cyberspace which includes purchase o Converging Data Australia, CBIG Consulting, Connected Analytics, Practical Smarts, Qubit Consulting.

The post Deloitte acquires Cybersecurity consulting firm SecurePath appeared first on Cybersecurity Insiders.


January 27, 2020 at 10:11AM

Friday, January 24, 2020

Ransomware payments and downtime grew in 2019

Ransomware which is a file-encrypting malware has been tagged as the most disruptive cyber-attack of 2019. And this was confirmed by a study carried out by Connecticut based Cybersecurity firm Coverware.

In a recent Ransomware Marketplace report released by Coverware, the downtime caused by the malware is reported to have grown by 60% in the last 3Q of 2019 i.e from an average of 12.1 days in 2018 to 16.2 days in 2019.

Security researchers who conducted the research say that the rise in the downtime was because hackers were seen targeting mostly large-sized organizations where the staff needed some time to remediate and restore the systems- as they had to deal with humongous data sets.

Furthermore, the report confirmed that the average ransom payment to free up the database from the file-encrypting malware in the Q4 was $84,116, up by 104% from the previous 3 quarters of last year.

“As hackers spreading Ryuk and Sodinokibi ransomware were mainly concentrating on large-sized firms, they were found demanding a seven-figure payout($780,000) as a minimum ransom for such incidents. On the other hand, smaller ransomware variants such as Dharma, Snatch and Netwalker kept their focus still on the small business space with a minimum ransom demand of $1500”, says the Coveware Ransomware Marketplace report.

That said, the most number of ransomware cases spotted in Q4 of 2019 were of Sodinokibi(29%) and Ryuk(22%) where hackers are seen first stealing data and then encrypting the database for ransom- which forces the victims to bow down to the demands at any cost.

Professional services, healthcare and financial sector along with software services were seen as the top 5 sectors most targeted by hackers. And Phishing, attacks on RDP and vulnerability exploit topped as the most popular attack methods in the past year as per the Coveware report.

The highlight of the report is that the inclusion of certain points which confirm that 98% of organizations that paid ransom received a decryption key and out of them over 96% of them succeeded in decrypting their data on a complete note.

So, now comes the million-dollar question- should we pay if we are targeted by a ransomware attack….?

The post Ransomware payments and downtime grew in 2019 appeared first on Cybersecurity Insiders.


January 24, 2020 at 08:49PM

SO YOU HAVE DECIDED TO BECOME CYBER SECURITY CERTIFIED, NOW WHAT?

This post was originally published by (ISC)² Management.

Toward the end of 2019, I met many aspiring women and men who approached me and said, “Tony, I want to become cyber security certified, how do I do it?”

Read more here: https://blog.isc2.org/isc2_blog/2020/01/so-you-have-decided-to-become-cyber-security-certified-now-what-.html

Photo:www.mcvts.org

The post SO YOU HAVE DECIDED TO BECOME CYBER SECURITY CERTIFIED, NOW WHAT? appeared first on Cybersecurity Insiders.


January 24, 2020 at 08:31PM

MOST EMPLOYERS DON’T PAY FULL COST OF CERTIFICATIONS

This post was originally published by  (ISC)² Management.

One of the most common complaints cybersecurity professionals voice about their employers is that they have to pay for certifications out of their own pockets. It’s not a trivial issue, since workers consider certifications their number one career hurdle, according the (ISC)2 Cybersecurity Workforce Study 2019.

Read more here: https://blog.isc2.org/isc2_blog/2020/01/most-employers-dont-pay-full-cost-of-certifications.html

The post MOST EMPLOYERS DON’T PAY FULL COST OF CERTIFICATIONS appeared first on Cybersecurity Insiders.


January 24, 2020 at 08:25PM

SWITCHING FROM OTHER FIELDS TO CYBERSECURITY IS PROFITABLE

This post was originally published by (ISC)² Management.

Here’s a bit of good news for anyone contemplating a career in cybersecurity: Cybersecurity workers who started their careers in other fields tend to get paid more than career-long cybersecurity professionals, according to new research.

Read more here: https://blog.isc2.org/isc2_blog/2020/01/switching-from-other-fields-to-cybersecurity-is-profitable.html

Photo:blog.eccouncil.org

The post SWITCHING FROM OTHER FIELDS TO CYBERSECURITY IS PROFITABLE appeared first on Cybersecurity Insiders.


January 24, 2020 at 08:18PM