Newsletters: NewsBites

Subscribe to SANS Newsletters

Join the SANS Community to receive the latest curated cyber security news, vulnerabilities and mitigations, training opportunities, and our webcast schedule.





SANS NewsBites
@Risk: Security Alert
OUCH! Security Awareness
Case Leads DFIR Digest
Industrial Control Systems
Industrials & Infrastructure


SANS NewsBites is a semiweekly high-level executive summary of the most important news articles that have been published on computer security during the last week. Each news item is very briefly summarized and includes a reference on the web for detailed information, if possible.

Spend five minutes per week to keep up with the high-level perspective of all the latest security news. New issues are delivered free every Tuesday and Friday.

Volume XIX - Issue #23

March 21, 2017

TOP OF THE NEWS


FBI and NSA Warn That Russia Will Likely Target US Elections in 2018, 2020
US-CERT Warns of Dangers of httpS Inspection Tools
Cisco Discloses Flaw Leaked in Vault 7

THE REST OF THE WEEK'S NEWS


James Lyne on ICS Security and Ransomware
Atlassian Makes Struts Patches Available
Git Moving in Direction of Replacing SHA-1
Mozilla Fixes Critical Flaw in Firefox in Less Than a Day
Man Arrested for Allegedly Sending Seizure-Inducing Tweet
Minnesota Police Obtain Warrant Asking Google to Identify People Who Searched for Man's Name
Bill Would Designate Election Systems as Critical Infrastructure
Reasons for Microsoft's Patch Delay Still Vague
UK Inter-ACE Cybersecurity Challenge

INTERNET STORM CENTER TECH CORNER

INTERNET STORM CENTER TECH CORNER


*************************** Sponsored By Sophos Inc. ********************
Botnet attacks can cause severe disruption. Organizations are being targeted with bespoke malware to compromise networks and add their servers and devices to malicious botnets. Visit our Botnets hub page and learn how to stay protected so your organization doesn't become part of the net Botnet. Learn More: http://www.sans.org/info/193437
***************************************************************************


TRAINING UPDATE



-- SANS 2017 | Orlando, FL | April 7-14 | https://www.sans.org/event/sans-2017

-- Threat Hunting & IR Summit & Training 2017 | New Orleans, LA | April 18-25, 2017 | https://www.sans.org/event/threat-hunting-and-incident-response-summit-2017

-- SANS Baltimore Spring 2017 | April 24-29 | https://www.sans.org/event/baltimore-spring-2017

-- SANS Automotive Cybersecurity Summit & Training | Detroit, MI | May 1-8, 2017 | https://www.sans.org/event/automotive-cybersecurity-summit/

-- SANS Security West 2017 | San Diego, CA | May 9-18 |
https://www.sans.org/event/sans-security-west-2017

-- SANS San Francisco Summer 2017 | June 5-10 | https://www.sans.org/event/san-francisco-summer-2017

-- SANS Secure Europe 2017 | Amsterdam, NL | June 12-20 | https://www.sans.org/event/secure-europe-2017

-- SANS Cyber Defence Canberra 2017 | June 26-July 8 | https://www.sans.org/event/cyber-defence-canberra-2017

-- SANS London July 2017 | July 3-8 | https://www.sans.org/event/london-july-2017

-- SANS Cyber Defence Singapore | July 10-15 | https://www.sans.org/event/cyber-defence-singapore-2017

-- SANS Online Training: Special Offer! Register by March 1 and choose a GIAC Certification Attempt or $400 Off your OnDemand and vLive courses.
OnDemand - https://www.sans.org/ondemand/specials
vLive - https://www.sans.org/vlive/specials

-- Single Course Training
SANS Mentor https://www.sans.org/mentor/about
Community SANS https://www.sans.org/community/
View the full SANS course catalog https://www.sans.org/find-training/

***************************************************************************

TOP OF THE NEWS

FBI and NSA Warn That Russia Will Likely Target US Elections in 2018, 2020 (March 20, 2017)

Testifying before the US House Intelligence Committee Committee, FBI Director James Comey and NSA Director Michael Rogers cautioned that Russia is likely to interfere in US elections in 2018 and 2020 because of its success interfering in the 2016 presidential election. The FBI and the NSA are working with European counterparts to help prevent Russian interference in elections there.

Read more in:

Computerworld: Russia will strike U.S. elections again, FBI warns http://computerworld.com/article/3183028/security/russia-will-strike-us-elections-again-fbi-warns.html
CyberScoop: FBI Director: U.S. should expect Russian interference in 2018, 2020 elections https://www.cyberscoop.com/fbi-director-u-s-expect-russian-interference-2018-2020-elections/?category_news=technology

US-CERT Warns of Dangers of httpS Inspection Tools (March 16 & 17, 2017)

The US Department of Homeland Security's (DHS's) US-CERT has issued an alert warning that httpS interception can weaken TLS security. Some httpS inspection tools fail to properly validate certificates, potentially exposing users to man-in-the-middle attacks.

[Editor Comments]

[Neely] Implementation of httpS inspection must include validation of the certificates prior to re-encryption as well as distribution of the intermediate CA public key to users so you are neither training them to accept certificates inappropriately nor raising the trust level for sites inappropriately. With httpS becoming the norm for web sites, httpS inspection can provide the visibility necessary to continue to protect users online. The alternative is to depend on endpoint controls.

Read more in:

Computerworld: US-Cert: Some
httpS inspection tools could weaken security http://computerworld.com/article/3182484/security/us-cert-some-https-inspection-tools-could-weaken-security.html
Dark Reading: US-CERT Warns That httpS Inspection Tools Weaken TLS http://www.darkreading.com/vulnerabilities-threats/us-cert-warns-that-https-inspection-tools-weaken-tls/d/d-id/1328423?
US-CERT: Alert: httpS Interception Weakens TLS Security https://www.us-cert.gov/ncas/alerts/TA17-075A

Cisco Discloses Flaw Leaked in Vault 7 (March 19 & 20, 2017)

Cisco has disclosed a vulnerability that affects more than 300 of its switches. The flaw could be exploited to remotely take control of vulnerable devices. No fix is currently available; Cisco plans to develop patches. The issue lies in Cisco Cluster Management Protocol processing code in its IOS and IOS XE software. Cisco uncovered the issue during its own "analysis of documents related to the Vault 7 disclosure."

[Editor Comments]

[Murray] I fail to see the good in talking about a vulnerability for which one does not have a fix or a work-around. What am I missing?

[Williams] The leaked documents offer insight into the mindset and tradecraft of nation state hackers, but this Cisco vulnerability specifically offers never before seen insight into the Vulnerabilities Equities Process (VEP0. If a vulnerability this serious and widespread wasn't disclosed through the VEP, one must wonder exactly how high the bar is for disclosure.

Read more in:

The Register: Cisco reports bug disclosed in WikiLeaks' Vault 7 CIA dump http://www.theregister.co.uk/2017/03/19/cisco_goes_public_with_its_first_vault7_response/
Ars Technica: A simple command allows the CIA to commandeer 318 models of Cisco switches https://arstechnica.com/security/2017/03/a-simple-command-allows-the-cia-to-commandeer-318-models-of-cisco-switches/
V3: Cisco issues warning over telnet zero-day flaw in 300 switch products http://www.v3.co.uk/v3-uk/news/3006801/cisco-issues-warning-over-telnet-zero-day-flaw-in-300-switch-products
ThreatPost: Cisco Warns of Critical Vulnerability Revealed in 'Vault 7' Data Dump https://threatpost.com/cisco-warns-of-critical-vulnerability-revealed-in-vault-7-data-dump/124414/
Cisco Advisory: Cisco IOS and IOS XE Software Cluster Management Protocol Remote Code Execution Vulnerability https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170317-cmp
*************************** SPONSORED LINKS *****************************
1) Thinking about replacing your antivirus? Download this free proof of concept checklist for selecting a next-gen antivirus solution - Download now: http://www.sans.org/info/193452
2) Why is the US NIST Cybersecurity Framework being quickly adopted around the globe? Learn More: http://www.sans.org/info/193442
3) Don't Miss: Forensic State Analysis: A New Approach to Threat Hunting - with Alyssa Torres. Register: http://www.sans.org/info/193447
***************************************************************************

THE REST OF THE WEEK'S NEWS

James Lyne on ICS Security and Ransomware (March 15, 2017)

James Lyne talks with NBC's Tom Costello about the preponderance of unprotected industrial control systems in the US and the growing threat of ransomware.

Read more in:

Today: US infrastructure is at 'red alert' for hacking, expert says http://www.today.com/video/us-infrastructure-is-at-red-alert-for-hacking-expert-says-898332227709
Sophos: US infrastructure is at 'red alert' for hacking, James Lyne warns on the Today Show https://blogs.sophos.com/2017/03/16/us-infrastructure-is-at-red-alert-for-hacking-james-lyne-warns-on-the-today-show/

Atlassian Makes Struts Patches Available (March 20, 2017)

Atlassian has made available patches for the Apache Struts 2 vulnerability. Fixes are available for Atlassian's Bamboo, Crowd, and HipChat Server products. Atlassian has already patched its cloud services.

Read more in:

The Register: Atlassian admins, your Struts 2 patch has landed http://www.theregister.co.uk/2017/03/20/atlassian_admins_your_struts_2_patch_has_landed/
Atlassian: Bamboo, Crowd, and HipChat Server - Critical Security Advisory http://seclists.org/bugtraq/2017/Mar/50

Git Moving in Direction of Replacing SHA-1 (March 20, 2017)

Git is starting to move away from SHA-1 hash function after Google announced that it hade developed a SHA-1 collision attack. Although Linus Torvalds has observed that in the Git community, SHA-1 is used for version control rather than security, he did raise the question of the best way to replace SHA-1.

[Editor Comments]

[Murray] The "best way to replace SHA-1" is efficiently rather than urgently. What the Google demonstration proved is that, while perhaps easier than previously thought, finding collisions is still too expensive to constitute an efficient attack against most applications and will be so for a while.

[Northcutt] Everybody is right. We have known this day was coming since 2005 and at this point it is still really computationally expensive to force a collision. But now they will start working on improving the techniques till you can do this with an iPhone App.
https://www.schneier.com/blog/archives/2005/02/cryptanalysis_o.html
https://www.theregister.co.uk/2017/02/23/google_first_sha1_collision/
https://blog.qualys.com/ssllabs/2014/09/09/sha1-deprecation-what-you-need-to-know

Read more in:

The Register: Git sprints carefully towards SHA-1 deprecation http://www.theregister.co.uk/2017/03/20/git_sprints_carefully_towards_sha1_deprecation/

Mozilla Fixes Critical Flaw in Firefox in Less Than a Day (March 20, 2017)

Mozilla has fixed a critical flaw in its Firefox browser 22 hours after the issue was discovered at the Pwn2Own competition last week. The vulnerability is fixed in Firefox 52.0.1, released on Friday, March 17. Those who found the bug received a USD 30,000 bounty. Firefox was the first vendor to fix a bug discovered at last week's Pwn2Own.

[Editor Comments]

[Williams] Kudos to the folks are Firefox for fixing this bug so quickly. 22 hours is a great turn around time for patching the vulnerability and testing the release.

Read more in:

Softpedia: Mozilla Fixes Critical Vulnerability in Firefox 22 Hours After Discovery http://news.softpedia.com/news/mozilla-fixes-critical-vulnerability-in-firefox-22-hours-after-discovery-514095.shtml
Computerworld: Mozilla beats rivals, patches Firefox's Pwn2Own bug http://computerworld.com/article/3183264/security/mozilla-beats-rivals-patches-firefoxs-pwn2own-bug.html

Man Arrested for Allegedly Sending Seizure-Inducing Tweet (March 17 & 18, 2017)

US federal authorities have arrested a man for allegedly knowingly sending a tweet containing a strobing image to Newsweek writer Kurt Eichenwald, who has epilepsy. The tweet triggered a seizure. John Rayne Rivello has been charged with cyberstalking.

Read more in:

BBC: US man held for sending flashing tweet to epileptic writer http://www.bbc.com/news/world-us-canada-39315393
Ars Technica: Man accused of sending a seizure-inducing tweet charged with cyberstalking [Updated] https://arstechnica.com/tech-policy/2017/03/man-arrested-for-allegedly-sending-newsweek-writer-a-seizure-inducing-tweet/

Minnesota Police Obtain Warrant Asking Google to Identify People Who Searched for Man's Name (March 17, 2017)

Police in Minnesota are asking Google to identify people who searched for certain terms associated with a crime they are investigating. Edina police are working in a bank fraud case in which USD 28,500 was wired out of an individual's account earlier this year. The perpetrator used a passport photo possibly obtained online. The warrant applies only to residents of Edina and only to searches conducted between December, 2016 and January 7, 2017.

[Editor Comments]

[Williams] Granting this warrant demonstrates a fundamental lack of understanding, by the judge, about the underlying technology.

Read more in:

Computerworld: Minn. Police seek data on who Googled a victim's name http://computerworld.com/article/3182325/data-privacy/minn-police-seek-data-on-who-googled-a-victims-name.html
Tony Webster: Minnesota judge signs a search warrant for personal information on anyone who Googled someone's name https://tonywebster.com/2017/03/minnesota-search-warrant-anyone-who-googled/
Softpedia: Judge Wants Google to Tell Cops Everyone Who Googled One Man's Name http://news.softpedia.com/news/judge-wants-google-to-tell-cops-everyone-who-googled-one-man-s-name-514099.shtml

Bill Would Designate Election Systems as Critical Infrastructure (March 17, 2017)

Legislation introduced in the US House of Representatives would designate election systems as critical infrastructure. Its would also fund upgrades for the systems and look to the Department of Homeland Security (DHS) and the National Institute of Standards and Technology (NIST) for security standards. The bill would cover storage facilities, polling places, voter databases, voting machines, and other systems involved in the election process.

Read more in:

FCW: House bill would keep election systems 'critical' https://fcw.com/articles/2017/03/17/bill-elections-critical-rockwell.aspx
The Hill: Dem bill would codify elections as critical infrastructure http://thehill.com/policy/cybersecurity/324510-dem-reps-bill-would-codify-elections-as-critical-infrastructure
GCN: Election systems security under increasing scrutiny https://gcn.com/articles/2017/03/17/voting-systems.aspx?admgarea=TC_SecCybersSec

Reasons for Microsoft's Patch Delay Still Vague (March 16, 2017)

Dan Goodin writes that Microsoft has not adequately explained the recent month-long delay of its security patches. Patch Tuesday has been a regular event for more than 13 years and has never, until last month, been cancelled. The reason given for February's delay was an unspecified "last-minute issue." Goodin writes that "even if the cancellation was for the most banal of reasons, Microsoft's silence is just wrong. If protecting customers is truly Microsoft's top priority, company officials should explain exactly why they delayed critical bug fixes for four weeks."

Read more in:

Ars Technica: Microsoft's silence over unprecedented patch delay doesn't smell right https://arstechnica.com/security/2017/03/microsofts-silence-over-unprecedented-patch-delay-doesnt-smell-right/

UK Inter-ACE Cybersecurity Challenge (March 20, 2017)

A team of students from Imperial College London, UK, has won the Inter-ACE cybersecurity competition, besting teams from 11 other universities. All universities that sent teams to the competition have been named Academic Centres of Excellence in cybersecurity. The competition was hosted by the University of Cambridge. Members of the winning team are guaranteed spots in the Cambridge2Cambridge (C2C) competition later this year, an event held jointly by the University of Cambridge and the Massachusetts Institute of Technology (MIT).

Read more in:

SC Magazine UK: Students crowned UK's most talented in cyber-security https://www.scmagazineuk.com/students-crowned-uks-most-talented-in-cyber-security/article/645173/

INTERNET STORM CENTER TECH CORNER

An Example of a Multiple States Dropper https://isc.sans.edu/forums/diary/Example+of+Multiple+Stages+Dropper/22197/

Real-World Wiretapping Attacks Against ZRTP https://www.ibr.cs.tu-bs.de/papers/schuermann-popets2017.pdf

Authenticating Against MySQL Server Using a Hashed Password https://github.com/cyrus-and/mysql-unsha1

CISCO Releases Advisory with Details Regarding CMP Vulnerability https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170317-cmp

Pwn2Own Contest Leads to Exploits Against All Browsers (and VM!) https://www.zerodayinitiative.com/blog/2017/3/17/the-results-pwn2own-2017-day-three

Git Moving Away from SHA1 (likely to SHA3) https://news.ycombinator.com/item?id=13906804

Proxy Security https://isc.sans.edu/forums/diary/What+is+really+being+proxied/22165/
https://www.us-cert.gov/ncas/alerts/TA17-075A

***********************************************************************
The Editorial Board of SANS NewsBites

View the Editorial Board of SANS Newsbites here: https://www.sans.org/newsletters/newsbites/editorial-board

Please feel free to share this with interested parties via email, but no posting is allowed on web sites. For a free subscription visit https://www.sans.org/account/create