Palo Alto Networks Researchers Discover Critical Vulnerabilities in Internet Explorer and Microsoft Edge

Palo Alto Networks researchers Bo Qu and Hui Gao were credited with the discovery of three new critical Microsoft vulnerabilities affecting Internet Explorer (IE) versions 7, 8, 9, 10 and 11 and Microsoft Edge. These vulnerabilities are covered in Microsoft’s December 2015 Security Bulletin and documented in Microsoft Security Bulletins MS15-125 and MS15-124. 

In our continuing commitment to the security research community, these vulnerabilities were disclosed to Microsoft through our participation in the Microsoft Active Protections Program (MAPP) program, which ensures the timely, responsible disclosure of new vulnerabilities and creation of protections from security vendors.

Palo Alto Networks is a regular contributor to vulnerability research and have discovered 80 critical Microsoft vulnerabilities over the past 18 months. By proactively identifying these vulnerabilities, developing protections for our customers, and sharing them with Microsoft for patching, we are removing weapons used by attackers to compromise enterprise, government and service provider networks.

[Palo Alto Networks Blog]

Frost & Sullivan Recognises Palo Alto Networks as Network Security Vendor of the Year in Australia

Last week, Palo Alto Networks received the 2015 Australia Network Security Vendor of the Year award from Frost & Sullivan. Armando Dacal, vice president for Palo Alto Networks Australia/New Zealand, attended the awards banquet in Sydney to accept the award.

The awards recognise ‘exemplary practices and best-in-class companies’ in Australia, across four markets, including ICT, Healthcare, Energy and Environment, Chemicals and Materials. This year was particularly special as it marked the 10th year that Frost & Sullivan hosted the excellence awards in Australia to recognise and celebrate exemplary practices and best-in-class companies in the country.

What a great way to close 2015. Congratulations Australia team!

Armando Dacal, vice president for Palo Alto Networks Australia/New Zealand

[Palo Alto Networks Blog]

Mobile Security: Variations on a Theme

Niccolò Paganini’s Caprice No. 24 in A Minor is a famous and notoriously difficult composition that only the most advanced violinists can play. It’s made up of a theme, along with Paganini’s own variations. But as respectable as it is on its own, it’s been discovered and rediscovered by a large number of composers and artists over the years for new audiences, many of whom may not have realized they were listening to Paganini in the first place.

Each variation on a theme can provide new insights, because they challenge the audience to hear things that they may not have otherwise noticed. But without knowledge of the original theme, there’s also a chance of missing out on the big picture. In some ways, the discussion around mobile security takes on its own variations of a theme, because many people share common concepts on risk but their priorities on what must be done vary greatly.

I’ve had discussions with people who see mobile security as a data at rest issue, namely how to protect and remove data once it reaches the mobile device. That argument may address some of the issues with lost and stolen devices, but it does not address what happens if there is a malicious adversary trying to control the device.

Then there are networking teams who see mobile security as a network blocking issue, namely that they’ll do whatever they can to keep BYOD and unsanctioned devices off their corporate network. That may be a way to keep infected mobile devices out of sight, out of mind, but it doesn’t really make the sanctioned devices any safer to use.

There are also networking teams who see mobile security as being a remote access issue, but as applications move to the cloud, the use case for remote access becomes fuzzy, and the use of standalone VPN appliances even fuzzier.

It’s important to ask whether you’re addressing the problem itself, or a variation of the problem. For example, while each of the problems above are valid in their own right, the bigger issue is that organizations often lack ways to enforce security policies that could prevent improper application traffic and threats from reaching the device in the first place.

These thoughts come to mind as I read through NIST Special Publication 1800-4, which outlines the problem in mobile security. Section 4.4.1 discusses threats (including mobile malware) and Section 4.4.2 discusses exploitable vulnerabilities, both of which are at the heart of modern cyberattacks.

At Palo Alto Networks, we believe that prevention is a necessary and critical measure to prevent exploits and malware from reaching the device in the first place. The next-generation security platform provides an integrated approach toward the use of global threat intelligence to stop threats in application traffic. With GlobalProtect, all corporate application traffic is inspected by the next-generation security platform, regardless of where the user is located. This enables the organization to take a prevention-first approach by applying security policy to stop both known and unknown mobile threats.

As mobile security becomes better understood, it is important to develop strategies and frameworks that will help foster broader understanding of the issues at play – not just one or two variations. Stopping threats won’t come from solving the variations of the theme, but rather by addressing the core of the problem itself. Plan for prevention first in order to strengthen your mobile security strategy.

[Palo Alto Networks Blog]

2016 Predictions #7: Healthcare Technology Advances Will Open Up New Attack Vectors

This is the seventh in our series of cybersecurity predictions for 2016. Stay tuned for more through the end of the year.

2015 was a rough year for the healthcare industry – more than 112 million healthcare records were breached, according to the HHS breach portal. That’s nine times (9x) higher than 2014. C-level executives at healthcare organizations understand that cyberattacks can have a direct impact on patient care, but they still struggle to advance their security maturity to the point that other industries with a longer history of regulation (i.e., financial services) have reached.

2016 will prove to be a year of innovation for healthcare organizations as they rush to implement new technologies that enhance the patient experience, such as remote patient monitoring and video visits, while many of the same core information security challenges persist.

Here’s a look at my top 2016 predictions for the healthcare industry.

The number of breached healthcare records caused by sophisticated cybersecurity attacks will continue to increase

In addition to the fact that there were nine times (9x) more breached healthcare records in 2015 compared to 2014, the top six healthcare breaches in 2015 account for over 98 percent of the 112 million total breached records for the year. Each of the top six was caused by an advanced cyberattack. All signs indicate that sophisticated and targeted cyberattacks in the healthcare industry are increasing with a few of the largest breaches linked to China-sponsored attackers.

In 2016, we will continue to see an increased number of targeted cyberattacks, resulting in major breaches in the healthcare industry. The healthcare providers who will be least impacted are those who:

  1. Conduct regular end-user security training to reduce successful phishing.
  2. Enforce a robust threat and vulnerability management program to identify risks.
  3. Deploy an advanced integrated security architecture to prevent cyberattacks on the network, on the endpoint, and in the cloud.

The IoT revolution will take off in the healthcare industry

For those who don’t know, the Internet of Things (IoT) revolution will go mainstream in 2016. The IOT refers to the vast array of WiFi-enabled sensors that will be available to track everything from the level of milk in your fridge to the angle of your blinds, according to the time of day. According to Gartner, there will be 6 billion of them by 2018. The IoT revolution has many applications within the healthcare industry, including remote patient monitoring for high-risk patients and behavior modification to help with obesity and smoking problems. As these devices get smaller and less expensive, we will see more healthcare practices use them to treat patients.

I wrote a blog post recently in response to the FDA’s alert for all healthcare providers to stop using Hospira’s Symbiq drug infusion pump due to a cybersecurity vulnerability that presented a significant risk to patient safety – the first ever alert of its kind. Billy Rios is the name of the amateur security researcher who identified the vulnerability working out of his garage. This gives you an idea of the amount of research that has been conducted on medical devices (generally, very little). In my recent job as a security lead for a hospital network, I worked directly with multiple medical device manufacturers and was surprised at the extent to which medical device security is an afterthought.

If the IoT devices used in healthcare are produced in the same manner (innovation first, security as an afterthought) they are likely to be compromised by two types of attackers: those interested in profiting (by stealing health data) and those who desire to impact patient safety justbecause they can. The healthcare providers who will be least impacted are those who adopt strict security standards for their medical devices and make efforts to reduce risk by segmenting their network-connected medical devices.

Healthcare organizations will begin to move critical applications and infrastructure to the cloud

“Cloud” has been a buzzword in healthcare IT for years now as industry leadership strategizes to adopt such technology that has significant opportunities for cost savings, performance and scalability. 2016 will be a transition year for many healthcare organizations that will migrate a portion of their critical infrastructure and applications to the private cloud by the end of the year.

  • Big players in the EMR application space (e.g., Epic, Cerner, McKesson) will begin to offer cloud-hosted EMR solutions, and healthcare providers will start executing two-year plans to migrate their EMR to a fully managed private cloud service model.
  • Healthcare providers will begin to deploy certain elements of critical infrastructure to cloud services like Amazon Web Services and virtualize things like Active Directory domain controllers and next-generation firewalls.
  • Cloud-based file sharing and collaboration sites like Box.com will become more prevalent in the healthcare industry, as users urge leadership to provide an easier method to share data.

Attackers will look to mobile devices as the next best vector into healthcare networks

In 2015, we saw a tremendous amount of spear phishing and email malware in the healthcare industry, but mobile devices are likely to be the next target. In a recent HIMSS survey, 90 percent of responders in the healthcare industry said they maintain mobile devices to engage patients in their organizations. Mobile devices in hospitals are often used to connect to EMRs and view PHI, which introduces a slew of risks, most notably: 1) The ability to connect to unsecured public Wi-fi allows eavesdropping, and 2) Normally benign mobile apps can be poisoned with malicious code, such as the recent discovery of XCodeGhost by Palo Alto Networks Unit 42, which allows the attacker to phish passwords and URLs through infected iPhone apps.

Healthcare is already a targeted industry for attackers, and mobile devices are becoming more integrated into patient care services. It’s only a matter of time before mobile devices become a popular vector to steal health records.

The best mitigation for the risks outlined in these healthcare cybersecurity predictions is a combination of improving both security processes and security technology. Read more about joining the community of 1100+ healthcare organizations who trust Palo Alto Networks to provide the technology required to prevent cyberattacks and protect patient care.

Have a happy and prosperous 2016!

Want to explore more of our top 2016 cybersecurity predictions? Register now for Ignite 2016.

[Palo Alto Networks Blog]

BackStab: Mobile Backup Data Under Attack from Malware

Today we are releasing a whitepaper describing how malicious actors are stealing private mobile device data by accessing local backup files stored on PC and Mac computers. We have identified 704 samples of six Trojan, adware and HackTool families for Windows® or Mac® OS X® systems that used this technique to steal data from iOS and BlackBerry® devices. These attacks have been in the wild for over five years, and we have observed them deployed in over 30 countries around the world.

Since these families use a common attack technique to access the backup files, we categorize all of them as using the “BackStab attack,” defined as “an attack approach that captures private mobile device data through the theft of local backup files stored on PC and Mac computers.”

The BackStab attack technique poses a risk to many mobile users for the following reasons:

  • The technique itself has been known to the security and forensic communities for over seven years. There are many publicly available articles and video tutorials describing how to conduct the attack using tools and/or open source projects available to the public.
  • Almost all private data stored in mobile devices can be stolen using this attack.
  • The attack doesn’t require the mobile device to be jailbroken or rooted.
  • The attack requires malware or adware running on PC or Mac, but doesn’t require the malware or adware to have any special privileges, such as root or administrator.
  • The attack requires at least one backup file to exist on the PC or Mac. In 
some situations, official backup software, like that of Apple iTunes, will automatically create backups of mobile devices without the user’s interaction and without encryption. It is also possible for malware to initiate a backup when the device is attached to an infected computer in some cases.
  • The attack is not theoretical and is occurring in the wild, as we have observed 704 malware samples in six Trojan, adware and HackTool families using it. Two of these families adopted the technique at least five years ago.
  • iOS and BlackBerry have been affected by real world attacks.

How BackStab Works

Under certain conditions, mobile devices automatically create un-encrypted backup files on a local computer when they are attached through a USB port. Apple iOS devices began doing this when iTunes backup was introduced with the first generation iPhone in 2007. When users choose the default backup options, the contents of their phone is stored, unencrypted on their computers local hard drive in a well-known location. Forensics experts have known about this behavior for years and have exploited it to gain access to iOS device content even when they cannot directly access an iPhone due to it’s strong protections.

Mitigate the BackStab Attack

As a successful BackStab attack allows a miscreant to steal almost all private data from a mobile device, we suggest users take the following actions (iOS is used as the example here):

  • Check all existing iTunes backups. If there are any unencrypted and unnecessary backups, delete them.
  • When using iTunes backup, always enable encryption with a strong, unique password.
  • When using iCloud backup, set a strong, unique password for the iCloud account, andenable two-step verification.
  • Upgrade the iOS system to newest version (i.e., iOS 9.1).
  • Don’t jailbreak your iOS device.
  • Before entering your Apple account and password in a web browser, carefully check the current website’s domain name and SSL certificate to ensure you’re visiting Apple’s official website.
  • When connecting the iOS device to an untrusted computer or charger via a USB cable, don’t click the “Trust” button in the dialog box that displays.
  • Use an antivirus product or service on your computer or in your network. This will be helpful to find and prevent some known malware families, such as DarkComet.

Palo Alto Networks has adopted these steps to protect our customers from the BackStab attack:

  • WildFire™ has added a new feature to detect possible BackStab attack behavior.
  • WildFire properly classifies all six families mentioned in this report as malware. When those samples are transferred through a network protected by our products, they will be blocked.
  • A public tag has been added to our AutoFocus service to identify potential BackStab attack behavior.
  • AutoFocus also has tags that identify the DarkComet RAT, although not all variants of this malware use BackStab.
  • Endpoints using Traps are protected from this threat through their connection to WildFire.

For complete details on this threat, please download the “BackStab: Mobile Backup Data Under Attack from Malware” whitepaper.

[Palo Alto Networks Blog]

English
Exit mobile version