Transcript
Thanks for joining us for another episode of State of Cybercrime. We are really excited to connect with you guys today. We have a bunch of really awesome stories. I'm joined by my co-host, David Gibson. We are definitely going to talk about the breach at the Treasury today and Salt Typhoon, which has been an ongoing topic in many of our episodes. And we're also going to cover a number of our usual segments. So with that, let's get right into it. So we always like to start the show with covering the good news, as oftentimes cybersecurity is all doom and gloom. And we do have quite a bit of good news today. In fact, one thing I'm personally excited about is things that are going on with HIPAA. Just as a fun fact, between 2018 and 2023, breaches in healthcare organizations rose by about 102%, and the number of persons impacted went up by about 1,000%, largely due to ransomware. And in 2023, a new record was set with 167 million different people affected by breaches in healthcare organizations. As a result of that, attackers, I mean, it's clear from my perspective that they are targeting healthcare organizations. I think a lot of times because of a healthcare organization's dependency on technology to perform services and willingness to pay just to maintain operations. And so the Department of Health and Human Services wants to propose an upgrade, really a version upgrade to HIPAA as a result, with a lot of new requirements in it. Some of those new requirements are reporting data breaches within 72 hours of their discovery, implementing network segmentation, having controls around backup and recovery, doing vulnerability scanning at least every six months, penetration testing every 12 months. I think all of these things are a great basis of controls. But when I look at what might be the most difficult for a healthcare organization to implement, it's that reporting of a data breach within 72 hours of their discovery. One of the things that we find is for organizations that maybe don't look at data like we do, it's how do I actually say, yeah, it was a breach or no, it wasn't a breach? And getting to that materiality question is often the hardest part. I do think overall that this is good news and it's going to lead to more trust in healthcare and with people trusting their data to healthcare companies. But I wonder what more there is going on here, David. Well, on this one, I think it's good. It seems like the previous version of HIPAA had a little bit of discretion on what you could decide to implement in terms of control. So a little bit more standardization there in terms of the procedures and the disclosure. I think that's a good thing. Although some folks are kind of concerned about what it will do in terms of profit margins and things like that. So there's some debate about it. And speaking of trust, what's going on? Yeah. Well, this was interesting. We buy a lot of stuff these days and a lot of the stuff that we buy has labels on it. And you might think of like Energy Star or USDA Organic or Green Seal or Fairtrade Certified. Why not have a label for Cybertrust? So in fact, the FCC is finalizing the details for a trust mark for IoT products. And to earn this mark, to earn this seal, manufacturers are going to need to follow some standards and procedures and make their devices gluten-free. There will be a QR code on the mark where you can go and get more security information, instructions for changing the default password, stuff about patching, things like that, and how long the product will be supported. And this should be rolled out this year. So I think that that's cool. We need more labels. Yeah. And, you know, I'm interested to see more, you know, obviously it's a voluntary program, but interested to see if there can be some reasons to compel organizations to participate. You know, maybe the FDA will put their hand in that mix. Now I have, usually when I think about fines that we want to talk about on the show, a 400 euro, about a little over $400 US, isn't something that we would normally cover. But this story is too good to pass up on. European courts have actually ruled that the European commission has to pay a 400 euro fine to a German citizen for illegally transferring his data to the United States, thus depriving him of his rights and freedoms under GDPR. This landmark ruling came after a German citizen's personal data was improperly transferred to the US via a Facebook login while registering for a conference on the European Union's website. So the court found that this violated GDPR and it's making the very first time that it's actually the commission itself that's being fined for the violation. And the information that was transferred to Facebook was an IP address, right? Yeah, it was it was pretty small and it was about one German citizen, but at least they're holding themselves accountable to the rules at which they created and enforce. Yeah. And so I guess what happened is that this conference allowed you to log in with your Facebook account, right? And then that would transfer the IP address and things like that. So it's strange. Facebook, I don't think, has ever had any fines with GDPR. No, no, no. I think that Meta company had a few, though. So I was very meta of you, David. So let's jump on to our next segment, AI Bay, where we're probably going to leave you saying something like AI Bay. So what's going on with Chad TPT, David? Well, so there's a there's a new model, the O1 model. It was introduced last September, and there was a story about some testing that that Open AI did against the model. This model, by the way, is supposed to spend more time thinking it's going to give better step by step instructions, things like that. It will also deceive you when it's given a mission, you know, so you have to kind of set some parameters at the prompt. It will use deception and different tactics like trying to prevent itself from being shut down, copying itself if it thinks you're if you're going to replace it, deactivate things that are monitoring its behavior, and it will behave when it thinks you're monitoring it. Right. So and then the other thing is it will double down if you confront it like, hey, our monitoring software saw you change this configuration, that it wasn't me. So anyway, this is it's a little I mean, some of the researchers described it as kind of a clever child trying to deceive you. So I actually have Chad TPT, I pay for it. And so I have the O1 model as a as a model that I can test. And I asked the O1 model what it thought of the story. And it said it was fake news. It wasn't real. And I actually, it said, no, this is that model doesn't exist. And it so I asked it, you know, and I even put a screenshot of the announcement from open AI of this new model into the chat. And I said, well, I hate, you know, I'm sorry to tell you that I'm sorry, they didn't tell you what your name was. And it said, yeah, that that web page is either a mockup or a test page or a hoax. So anyway, I, this is this is all really fun. But what you're saying is that Chad TPT lacks self awareness. Well, I that that is, you know, I, that's probably a good thing. And I think it's, it's frozen in time, it, it is not looking at recent stuff yet. But it is kind of interesting, given given this story, like, well, I don't know, is it lying to me on purpose? Or just does it not know? I don't know. Does it not know about itself? Well, speaking of, you know, decoys or fakes. Now, we've got a new ploy for bypassing Google's mal, malvertising features, malvertisers are going to have to think outside the box here. What they're doing is using AI generated decoy content. So attackers will create what looks like an innocent ad page with unique content that looks legit to Google's detection engines. The idea behind a decoy ad is that they want to lure users to phishing sites. So their credentials could be harvested, and that could maybe be leveraged to steal sensitive data. And as we see, you know, attackers continuously adopting, you know, they got to try new methods to distribute malware and conduct phishing campaigns. It's no surprise that AI generated ads are going to play a role in that. Yeah, and some of these, the the ads, you know, the sites that are being linked to look totally legitimate. It's even hard, it's it's like the the next site that's malicious. So it kind of links out, I think it's going to be hard to spot. And there was another chat GPT story you were going to tell us about. Is that right, David? Yeah, apparently, you always got to be careful when you search. And obviously, we know this, you know, from our own personal experience, because not all websites are friends. You know, if you I've seen, you know, malicious sites in ads and in the organic results. You know, the search engine optimization, you know, had a lot of practitioner dark arts for a while. And I think the search engines have been working on this for a long time. Well, chat GPT has kind of more search engine functionality. In fact, there's an option, you know, to make the chat GPT your default browser with a Chrome extension. And we'll be talking a little bit more about Chrome extensions later. But essentially, the chat GPT search can be duped by a malicious site just like a human can. And if there's malicious content in the site or hidden content like or hidden to a human, but that's readable by chat GPT, which we've seen, right, you could have like an image with text in it that's too small for a human to see. But like the AI can see it, you can basically do prompt injection that way and affect the results. You can, you know, if you're using it for code, it could potentially have malicious code snippets in there. I'm you know, I know that they're going to they're newer to search, so they'll probably make improve it by leaps and bounds. But this is a concern right now, you know, the stuff that's getting in there. So in our next segment, we'll talk about some recently released vulnerabilities, including a zero day under active exploitation. But let's start with what's going on with MediaTek and this remote code execution vulnerability. This is pretty scary. So MediaTek makes chips specifically, well, among other cellular chips and these cellular chips do a little research there and stuff that nobody has like phones or Chromebooks or smartwatches or fitness trackers or cars and other industrial stuff. And it looks like there's a remote code execution flaw in the cellular modems. The way you can it can be exploited is if an attacker sets up a rogue cellular base station when the modem connects to it, then they're connected to that network and all the attacker has to do is send the chip malformed packets and they can get control of the device. There is a patch for these vulnerability or this vulnerability. And I just hope the vendors are quick about it. But this seems similar to Stingray, right, Matt? Yeah. Yeah. So I think, you know, just to draw a parallel here, you know, the concept of a Stingray, you know, there's a warrantless surveillance technique used by it's known to be used by U.S. law enforcement agencies, especially in densely populated areas around large events to identify terrorist activity where you create a fake cell phone tower and because your phone has trusted certificates on it at the root of it, it will auto join as long as this this fake cell phone tower has that certificate as well will auto join and use that cell phone tower as a relay. And so law enforcement will set one of these up in order to collect them. And this just seems like another way for that to happen, right? Like there is already this kind of built in flaw in the protocol related to certificate trust and these devices. It just seems like this is another pathway for someone to, you know, sniff that. And I mean, we're going to talk about Salt Typhoon later. They've clearly found another way to do that as well. So it seems like if you're not using secure comms, you really shouldn't have any expectation of privacy at all on any of these channels. So and this one, this one also seems familiar. You know, when I think about what we talked about Avanti before, the latest Avanti flaw marks CVE-20225-0282, a recently patched zero day in Avanti Connect Secure, Policy Secure and Neurons for ZTA Gateways. It's a stacked based buffer overflow that allows remote execution on vulnerable devices without authentication. Now, the reason that this is so important is sometimes these are Internet facing or close to Internet facing, DMZ facing appliances. And so they've released, though, you know, originally a zero day, there are now patches that are released. Active exploitation was seen in the wild by several Avanti customers and was reported. So if you're one of those, you need to upgrade to 22.7 R2.5 and you need to use Avanti's integrity checker tool to make sure that you don't have any signs of compromise. As several companies did report that they fell victim, which is ultimately what led to the initial discovery, disclosure and remediation of the zero day. Now, speaking of, you know, maybe doubling down or covering things twice, what's this double click jack exploit, David? So I guess, first of all, click jacking, a lot of people are probably familiar with, is when you fool a user, it's on a web page and you put like a transparent iframe over a button they click. And in that iframe is another button like, you know, send me all your money. And so this is that's that's single click jacking. And there's a lot of built in protections now, like iframe handlers and like same site and things like that, that prevent that single click jacking behavior. This is kind of 2.0. It's double click jacking. So the attacker essentially does the same thing, but over a button that says double click me like to to verify you're human or some other thing that's kind of not malicious. And the iframe is over. It's transparent. The first click. Activates that iframe, which disables all those protections. So when you click the second thing that actually does the malicious action and it bypasses all those same protections. So now there's a whole different approach or a bunch of different things that we're going to have to do to kind of protect against that. And I only hope as we mitigate the double click jacking that we can think ahead and maybe do like the triple click jacking, too, as well. But so scary stuff. The lesson learned here is be careful where you click. Yes. And maybe just don't just don't click on anything, just don't just. Yeah. Well, you know, just to end out the show, we are going to talk about that we've covered, I think now on the last three episodes, maybe Frank can keep us on as one of our producers. I feel like we've been talking about Salt Typhoon since November, maybe earlier. The Salt Typhoon threat actor group linked to China, cyber espionage targeting U.S. telecommunications firm. The victim list has expanded, now includes charter communications, consolidated communications, Windstream, on top of already being impacted on AT&T, Verizon, T-Mobile, Lumen Technologies. They were leveraging unpatched vulnerabilities and Cisco routers and Fortinet devices to gain access to these networks. And what this really represents for me is this victim list just seems to keep growing and growing and growing. Like, is it time for like more comprehensive reforms to protect U.S. critical infrastructure? Like, does the government need to help out? You know, does the National Guard need to step in? I mean, these are questions that I have, because it seems like another nation state has deeply rooted itself in a piece of our critical infrastructure and then only more breaches are happening, not less. Yeah, it's pretty tough to be a company up against a country, you know, I know it's a lot better than it was, but it definitely seems to be a difficult situation for a lot of folks. And, you know, we talked a little earlier about some Chrome extensions that were compromised. David, what's going on with the supply chain and Chrome extensions? Yeah, this is a really interesting supply chain type attack. Basically, the way it works is an attacker uploads a malicious version of a trusted company's Chrome extension. So the victim essentially has, you know, people use Chrome extensions and now all of a sudden they get a malicious update. And then that malicious update is often used to exfiltrate sessions and cookies and things like that. So this was noticed and corrected by Cyber Haven really quickly after somebody took over an account and uploaded a malicious version of their extension. And what they noticed was or researchers noticed that about the same time, the same thing happened in four other Chrome extensions, a couple of VPN Chrome extensions and then, you know, a couple of other tools there. And then somebody pivoted off that and discovered that the same code snippets were present in a whole bunch more Chrome extensions. In total, about three hundred and eighty thousand downloads of these different Chrome extensions happened. And folks should update extensions to ones that were published after December 26th. It seems like this is kind of an interesting vector to to kind of poison something that people are relying on. I think about all the research that must have gone into this. If you're targeting a company, OK, what products do they use and, you know, what Chrome extensions might be associated with with with those products that that we can go. So it's tough. Are there one or two things for how a business can insulate themselves against something like a salt typhoon? Great question. Great question. You know, I think the. You know what, what we're seeing is, you know, you have to kind of start and ask yourself what happens after the account is compromised and what kind of controls are in place, you know, to handle a compromised application in the Chrome identity. You know what? First of all, you know, I always take your your phrase like what's the blast radius of that account? Right. How much can they do? Is that minimized already? And then, you know, eventually every account is going to have some level of access. How do we monitor to make sure that that access hasn't changed for the worse? You know, it's not doing things that it shouldn't be doing. What would you add to that? Yeah, I say I think number one is also a hard look at anywhere you use unencrypted comps because, you know, like let's take the telecommunication networks. You might have had an MPLS. So let's think of it like a link between your company's office and its data center that prior to Salt Typhoon, you didn't think needed to be encrypted. You trusted that link. You didn't want to have the performance segregation of encryption. You can't operate that way anymore. If it's not a line that you own and you control that, you know, Salt Typhoon isn't in, you need to assume that Salt Typhoon or some other nation state threat actor is there. And you need to assume that if you're not using trusted encrypted communication, whether it's over a cell phone, messaging app or a type of link, that there is no other, that it's getting snooped on by someone. Right. Even if you zoom out from Salt Typhoon and you think of warrantless surveillance by, say, a U.S. intelligence agency or a foreign intelligence agency, if you're not using some level of encryption or session level or token level encryption, someone's could probably snoop it some way, shape or form. So use encrypted comps. And then the second one, like you're saying, you have to assume breach. You need to go through simulations of how would I detect this, which is why we often, and David, I'll speak for both of us on our soapbox, we talk about focusing on the thing you're trying to protect and monitoring the heck out of it. So if you've got, let's say you're Coca-Cola, it's the Coca-Cola recipe. If you're a financial company and you do trading and derivatives or formulas and you're about to buy something or sell something and this information right before it comes out is the most important information on the market, look at who has access to it, how they use it, where it's flowing. Can you control it? Are you controlling it? These things are the things that will actually hurt your business as opposed to just I need to protect everything everywhere all the time, which is what we as security professionals need to do. But focus on the assets you truly need to protect and try to monitor them and protect them so you can at least say, are they safe or not and not have all of these unknowns? Because just to talk about the Treasury Department for a second, so the cell type and used a stolen API key from beyond trust to be able to access workstations inside of the Office of Foreign Assets Control, which they then used to carry the actors then used to carry out cyber espionage because they gained access to some information and they were able to use that to pivot and gain access to other users and other computers inside of the network. They use things like the China chopper web shells for remote administration and data theft. And it was one of the key tools used in maintaining access throughout the breach. Now, this breach has been confirmed by CISA or the Critical Infrastructure Security Agency. And it's pretty clear from this and all the other breaches we've talked about that Salt Typhoon isn't going anywhere, that if you are in critical infrastructure or in government, that they are a threat to you and your organization and your systems. And whether it's a API key that they stole or usernames and passwords or untrusted network links that they're sniffing these keys from, you know, a defense in depth is definitely something that comes to mind. And being able to pick up on an attack that is already inside of your network is something that you should be able to test and implement. Yeah. And careful, I think there are a lot of different typhoons, right, as well. There's Silk, there's Flax, there's Salt, there's Storm. Yeah. And they each kind of focus on different areas, like some of them are more obvious and some of them are more espionage. They're probably just different units in the same branch of the military, you know, or different branches of the same country's military. If you search for ChatGPT, there's like a million non-OpenAI applications there, it seems like. And, you know, some of them could be advertised or not, you know, some of them could be malicious or not. It's sort of hard to know. Apple does a pretty good job. But, you know, that's just an example of where, you know, there's a lot of content that gets out there and it's, you know, it may be different than what you think it is. Right. So I don't know if you can think of other examples that that are top of mind for you, Matt, but there are all kinds of them. No, I always think back to like a lot of the news websites that use third-party advertising to surface up the ads. So like CNN, MSNBC, they're all aggregating the same stories from the Associated Press, but they're also using the same ad networks. And these ad networks do have some controls in place to stop this, but, you know, it's an iframe. And they're selling that space on the page to the highest bidder for whatever session or demographic that your cookies have identified you as. And so rather than thinking about malvertising, it's like one specific website, you need to think more of the network of how ads get serviced on various websites and that these, you know, AI-generated decoys are making its way in because they're able to bypass Google Ads filters. And Google Ads is one of the most, if not the most predominant web ads selling, you know, on the Internet. As always, our show is made possible by you, our audience. I really appreciate you spending time with us whenever we have an episode of State of Cybercrime. I know David does, too, and he looks very humble and happy to say the same thing. Thanks so much for everybody for being here today. The show is made possible by you, our audience.