::Trend Micro Threat Resource Center::

Showing posts with label zero day. Show all posts
Showing posts with label zero day. Show all posts

27 October 2015

Asian companies are in biggest danger of cyber attacks

Attackers are advancing zero day exploits into ‘zero-day-plus-one’ attacks at record speed, warns a new report from Nexusguard. Attacks are outpacing even those IT teams working at their most efficient pace, and teams could not possibly be expected to keep up with the rate of attack.


Add to this the falling cost of botnet-for-hire schemes that threaten to attack unsuspecting businesses for as little as twenty-dollars per attack and teams are overwhelmed in their efforts to stay ahead of swiftly evolving threats.

“The Asia Pacific region not only produces the most amount of DDoS scans to the Internet, but is also the biggest target of DDoS attacks than anywhere else in the world,” says Terrence Gareau, Chief Scientist at Nexusguard. “With the highest rate of software piracy globally, it should come as no surprise that the large botnets are able to operate freely in this region simply because there are so many vulnerable systems.”

Industry and analyst research reviewed in the latest Cybersecurity Asia Pacific report sponsored by Nexusguard point further to the serious cybersecurity threat that companies in the region are facing.

The report notes that organizations in the Asia-Pacific region were forecast to spend $230 billion to deal with cybersecurity breaches in 2014 — the highest amount for any region in the world, according to International Data Corporation (IDC) and the National University of Singapore survey, as reported in Marsh’s “Cybercrime in Asia” 2014 report.

The Asia Pacific Cyber Security Market contributes 17.21 percent of the global market and will grow to 21.16 percent by 2019, according to MicroMarketMonitor.

The private sector – highly developed, economically lucrative, and a prime target for the theft of intellectual property, blackmail, phishing, and identity theft – is investing in cybersecurity in nations such as China, Japan, Korea, Australia, New Zealand, Hong Kong, and Singapore”, according to ABI Research.

Research and Markets states that demand for cloud-based security solutions is one  key trend emerging in the cybersecurity market. End-users prefer cloud-based  security solutions because they are cost-effective and can be easily managed. Therefore, both large enterprises and SMEs in the Asia-Pacific region are increasingly adopting cloud-based cyber security solutions.

According to the Asia Cloud Computing Association, China leads Asia-Pacific nations with a total addressable cloud computing market totaling $141.9 billion. Japan is the number two nation in the region at $101.4 billion. Indonesia is number three at $76.8 billion.

More importantly, Gartner predicts that by 2018, more than half of organisations will use security services firms that specialize in data protection, security risk management and security infrastructure management to enhance their security postures. The expected increase in spending to deal with cybersecurity threats and the lack of preparedness of Asian companies thus represents an opportunity for global firms and regional or local service providers to invest in the right partnerships and technologies to beef up their security offerings.

“Cyber threats including DDoS attacks are a serious meance facing CIOs and their teams, and extending across the organization, especially with the growing integration of personal mobile devices into the corporate network, and increasing mobility of the workforce spread across multiple locations, with all of these disparate areas linked through the cloud,” said Jolene Lee, CEO, Nexusguard.

“Combined with the rate and speed of cyber-attacks and the increasing intelligence behind them, companies outsourcing their cybersecurity needs would be well advised to consider not just innovative technology and global reach, but also the depth of experience and expertise in predicting and mitigating threats.”

10 March 2015

More vendors join Cyber Threat Alliance in effort to combat advanced cyber threats

Fortinet, McAfee Labs, Palo Alto Networks and Symantec, co-founders of the industry’s first cyber threat alliance, announced that Barracuda Networks, Inc., ReversingLabs, Telefónica, and Zscaler have joined the Cyber Threat Alliance in its efforts to make united progress in the fight against sophisticated cyber adversaries.


The mission of the Cyber Threat Alliance is to drive a coordinated industry effort against cyber adversaries through deep collaboration on threat intelligence and sharing indicators of compromise.

While past industry efforts have often been limited to the exchange of malware samples, the Cyber Threat Alliance provides more actionable threat intelligence from contributing members, including information on zero-day vulnerabilities, botnet command and control (C&C) server information, mobile threats, and indicators of compromise (IoCs) related to advanced persistent threats (APTs), as well as the commonly-shared malware samples.

By raising the industry's collective actionable intelligence, alliance participants will be able to deliver greater security for individual customers and organizations.

 “We appreciate the charter of the Cyber Threat Alliance and believe there should be closer collaboration across security researchers, industry, education, and government,” said Stephen Pao, GM Security of Barracuda, which provides cloud-connected security and storage solutions that simplify IT.

Pedro Pablo Pérez, CyberSecurity Director, Telefónica, which is one of the largest telecommunications companies in the world believes that the collaboration against cybercrime with leading companies in the security practice will lead to a better cyber-resilience in the digital world.

“Organizations combatting today’s cyber threats require both internal monitoring and external context to identify an adversary’s intentions and tactics. The Cyber Threat Alliance provides a collaborative vehicle for sharing critical external information and improving identification of advanced threats," said Mario Vuksan, CEO of ReversingLabs, which provides enterprises and security vendors a foundation for protecting digital assets.

For his part, Michael Sutton, Vice President, Security Research for Zscaler, which provides a Security-as-a-Service platform delivering a safe and productive Internet experience, said: “Today’s security threats are more insidious and difficult to thwart than ever and they are outpacing the ability of organizations to protect themselves. The exchange of actionable threat intelligence fostered by the Cyber Threat Alliance is a critical step toward a new level of industry collaboration that will result in greater security for vendors and clients alike.”

03 February 2015

Hackers target third new zero-day for Adobe Flash


Security researchers have advised users of Adobe's Flash Player to disable the software temporarily, as yet another remotely exploitable vulnerability is being actively attacked by would-be hackers.

The bug has the potential to allow attackers to take full control of users' computers without their interaction.

Recently-released Flash Player versions 16.0.0.296 for Microsoft Windows and Apple OS X are vulnerable to the CVE-2015-0313 vulnerability, which Adobe rates as critical. Versions 13.0.0.264 and earlier are also vulnerable, along with Flash Player 11.2.202.440 and earlier for Linux.

Security vendor Trend Micro is credited with discovering the new zero-day vulnerability alongside two Microsoft researchers.

The company said CVE-2015-0313 is being actively exploited in drive-by attacks delivered via malicious advertisements, believed to have been executed through the Angler Exploit Kit.

"Malvertisements" on popular websites redirect visitors to a series of other sites, finally landing at a Russian-registered domain that attempts to deliver the payload that executes the exploit.

Trend Micro said it has already counted over 3000 hits related to CVE-2015-0313, suggesting the vulnerability is being widely used by attackers.

Neither the security vendor nor Adobe have yet published a full analysis of the new zero-day, which is the third to strike the popular Flash Player software in a month.


28 March 2012

How much does a 0-day vulnerability cost?

The market for exploits for zero-day vulnerabilities has exploded in the last year, says Adriel Desautels, the founder of Netragard, a penetration testing and vulnerability assessment outfit that, among other things, acquires and develops exploits.


The number of buyers and the money they are willing to pay for working exploits has dramatically increased, and so has the number of exploits offered for sale each month, he says. Also, the purchase deals are made much more quickly than in the past.

Obviously, the whole economy around this "product" has matured.

As a legitimate company, Netragard must be very careful when selling its exploits. According to Desautels, the firm rejects the majority of those who want to buy them.

“Realistically, we’re selling cyberweaponry,” he points out, but does not share how the vetting process is performed or the price that specific exploits can reach.

It is very well known what some software vendors offer for them through their own bug bounty programs, as well as the prizes offered for working exploits to participants in hacking contests such as Pwn2Own and Pwnium.

These sums are considerably smaller that the ones that can be earned by enterprising vulnerability researchers and hackers if they choose to sell exploits to other organizations, and that's counting in the fee for the intermediary.

The Bangkok-based security researcher that goes by the handle “the Grugq” is one of these mediators. His contacts in various governments and knowledge of the matter at hand make him eminently suitable for brokering such deals.

He is also careful when choosing to whom to sell the offered exploits, and that's mostly US and European governments and agencies. Ethical considerations aside, they simply pay much more than a Middle Eastern or Asian government can offer.

The Chinese government doesn't need his services, he says, because its huge number of hackers usually sell their exploits exclusively and directly to them. He also says that he has no contacts in the Russian government, and that "selling a bug to the Russian mafia guarantees it will be dead in no time, and they pay very little money.”

So how much does a working exploit go for? Well, the price depends on a number of things.

An exploit of a vulnerability in a widely used piece of software is more costly than that of one in a less popular one, and the same goes for those that take advantage of vulnerabilities in the latest software versions. Exploits for software that is more difficult to crack is also more pricey.

Taking all this in consideration, it's easy to see that an exploit for Windows will be more expensive than one for breaking into a Mac OS X machine, and that the tougher security features of iOS will raise the price for its exploits above that for Android.

According to Andy Greenberg, the current rough price list looks like this:


"Each price assumes an exclusive sale, the most modern version of the software, and, of course, not alerting the software’s vendor," he says.

"Some fees might even be paid in installments, with each subsequent payment depending on the vendor not patching the security vulnerabilities used by the exploit."

Event though considered unethical by some, these sales and acquisitions are sure to continue for the time being.

Demand creates supply and, according to the Grugq, banning the sale of exploits would have the same effect that the war on drugs has had on eliminating drugs - none.

03 November 2011

Zero-Day Exploit Used for DUQU

A report by a Hungary-based security laboratory, indicates that a Microsoft Word document that triggers a zero-day kernel exploit was identified as the dropper for DUQU. Upon successful exploitation, the Microsoft Word file drops the installer files that load the DUQU components that were initially reported a couple of weeks back.

A visual summary as follows:

Details regarding the zero-day exploit used have not yet been disclosed. However, Microsoft is expected to release information on it soon.

More details on this exploit discussed in an article from Trendmicro.

10 September 2010

Critical 0-day Adobe Acrobat, Reader flaw exploited in the wild

Adobe has released a security advisory warning users about a newly discovered 0-day vulnerability that has already been spotted getting exploited in the wild.

The flaw affects all current versions of Adobe Reader for Windows, Macintosh and UNIX, and of Adobe Acrobat for Windows and Macintosh. "This vulnerability (CVE-2010-2883) could cause a crash and potentially allow an attacker to take control of the affected system. Adobe is aware of public exploit code for this vulnerability," says in the advisory.

The company is still evaluating when a security update to resolve the flaw will be pushed out, and they haven't provided any mitigating instructions so far.

In the meantime, vendors of security solutions have begun detecting malware that exploits the vulnerability. Trend Micro has detected a Trojan that arrives as an attachment to spam email messages, which drops a downloader into the system. This downloader leads to another one, which is downloaded - along with other malware - from various (currently unavailable) URLs.

A quick search for the registration information for those URLs revealed that the registrant is located in Hong Kong, but the servers that host the site are located in the U.S. and in Germany.

Another interesting fact is that the malicious file is digitally signed with a valid certificate of a legitimate American credit union:

Adobe is urging users to keep their anti-malware solutions up-to-date in order to protect themselves until a patch is issued.

02 July 2010

10,000 XP machines attacked through 0-day flaw

The Windows Help and Support Center vulnerability, the details of which have recently been made public by researcher Tavis Ormandy, is being heavily exploited in the wild.

According to a recent post on Microsoft's Malware Protection Center Blog, public exploitation of the vulnerability started on June 15th, but those attacks were probably undertaken by other researchers, since they were targeted and rather limited.

After that, the attacks became more widespread, and the targets more numerous. Microsoft claims that as of yesterday, over 10,000 separate computers have reported witnessing this attack. Computers in Portugal and Russia have seen by far the highest concentration of attacks:

The attacks only increased with time. Microsoft started seeing "seemingly-automated, randomly-generated HTML and PHP pages hosting this exploit", and the goal of the attacks was to plant Trojans and viruses on the targeted system.

For those users who don't use Microsoft's security solutions with updated signatures for the detection of the exploit, the company advises implementing the workaround listed in the advisory.

08 June 2010

Critical Adobe Flash, Reader 0-day flaw exploited in the wild

A zero-day flaw affecting 10.0.x and 9.0.x versions of Adobe Flash Player - including the current version, which is 10.0.45.2 - has been spotted being exploited in the wild. The flaw also affects Adobe Reader and Acrobat 9.3.2 and earlier 9.x, since the vulnerable authplay.dll component ships with those products.

Adobe released on Friday the security advisory detailing the particulars of the critical vulnerability, saying that it "could cause a crash and potentially allow an attacker to take control of the affected system," and that "there are reports that this vulnerability is being actively exploited in the wild against both Adobe Flash Player, and Adobe Reader and Acrobat."

While waiting for the fix to be pushed out, Adobe advises users to switch to Flash Player 10.1 Release Candidate, which does not appear to be vulnerable, or "deleting, renaming, or removing access to the authplay.dll file that ships with Adobe Reader and Acrobat 9.x." This action mitigates the threat, but users will be unable to open PDF files with Flash content because the program will crash or they will witness an error message.

26 February 2010

Skeletons in Adobe's security closet

How many of you out there, perform a computer restart when you are prompted to do so after a software installation or update (unless forced to)? Well, if you're guilty of not doing so, you may seriously want to consider doing so from now onwards.

Some findings revealed:

"While it is true that the Adobe Download Manager is removed upon computer restart, the user, who has just updated their Adobe product (usually without the requirement to restart the computer after the update), is still exposed to forced automatic installation until they restart their computer."

"On the same day I published my last blog post, I found yet another issue — a remote code execution flaw in the Adobe Download Manager. Basically, what I found is that an attacker can force an automatic download and installation of ANY executable he desires. So, if you go to Adobe’s website to install a security update for Flash, you really expose yourself to a zero-day attack."

Full report here.

20 December 2009

Adobe PDF Reader - Zero Day JavaScript attacks circulating in the wild

Please be careful with all PDF files, keep AV protection updated, and look for future Adobe releases which will address this issue. I usually keep JS off unless it's required to fill out a PDF form.

Adobe PDF Reader - Zero Day attack circulating
http://www.adobe.com/support/security/advisories/apsa09-07.html
http://www.avertlabs.com/research/blog/index.php/2009/12/16/another-adobe-reader-zero-day-take-care/

QUOTE: Adobe has confirmed a critical vulnerability in Adobe Reader and Acrobat 9.2 and earlier versions that could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild. Adobe recommends customers follow the mitigation guidance below until a patch is available

HOW TO DISABLE JAVASCRIPT IN ADOBE READER:

Customers can mitigate the issue by disabling JavaScript in Adobe Reader and Acrobat using the instructions below:

1. Launch Acrobat or Adobe Reader.
2. Select Edit>Preferences
3. Select the JavaScript Category
4. Uncheck the 'Enable Acrobat JavaScript' option
5. Click OK

30 April 2009

Adobe Reader, hit with another Zero-Day

Popular PDF plug-in becoming favorite target for attackers, prompting some security experts to recommend open-source alternatives.

A new zero-day vulnerability in Adobe Reader has been disclosed, once again putting the popular PDF reader in possible peril from attackers.

The newly discovered vulnerability affects "all currently supported shipping versions" of the software, meaning Versions 9.1, 8.1.4, 7.1.1, and earlier of Adobe Reader and Acrobat, and on all operating system platforms for the applications, said Adobe's Product Security Incident Response Team (PSIRT) in its blog this afternoon.

F-Secure now advises users to switch over to an alternative PDF reader from the pdfreaders site for open-source PDF readers. The more diverse the PDF reader pool, the better for user security, says Patrik Runald, chief security advisor for F-Secure..

If you can't change from Adobe Acrobat Reader we strongly recommend that you disable the ability for it to run JavaScript. This is easily done via by going to:

Edit -> Preferences -> JavaScript -> Un-check "Enable Adobe JavaScript"

Sources: 1, 2

06 April 2009

Zero-Day PowerPoint Attacks Under Way

Microsoft's PowerPoint application is being used in a new attack that exploits an unpatched vulnerability in the popular Office app. The software giant yesterday issued a security alert confirming "limited and targeted attacks" were under way using malicious PowerPoint files that exploit the flaw.

The exploits carry a Trojan, according to Microsoft, and in an interesting twist, the exploit files were recently submitted to the VirusTotal free malware-scanning site. "Either the miscreants who created these exploits were looking to see how antivirus products detect their new files, or the victims were looking to get some information about their maliciousness," blogged Cristian Craioveanu and Ziv Mador of Microsoft's Malware Protection Center.

When exploited, the vulnerability can give an attacker local rights to a user's machine if he opens the malicious PowerPoint file, which is currently being delivered via targeted email messages, but can also be pushed via a Website or instant messaging link.

The vulnerability affects PowerPoint 2000 Service Pack 3, PowerPoint 2002 Service Pack 3, PowerPoint 2003 Service Pack 3, and Microsoft Office 2004 for Mac . The newer Microsoft Office PowerPoint 2007 and Microsoft Office for Mac 2008 are immune.

For now, Microsoft has provided a few workarounds for users to protect against the new PowerPoint attack:

  • Do not open or save Office files received unexpectedly from a trusted or untrusted source;
  • Use the Microsoft Office Isolated Conversion Environment to open those files; or
  • Use Microsoft Office File Block policy to ban Office 2003 and earlier files from being opened.
Read more here.