Posts

Showing posts with the label VPN

Nissan North America data breach impacts over 53,000 employees

Image
By Bill Toulas,  Bleeping Computer Nissan North America (Nissan) suffered a data breach last year when a threat actor targeted the company's external VPN and shut down systems to receive a ransom. The car maker discovered the breach in early November 2023 and discovered recently that the incident exposed personal data belonging to more than 53,000 current and former employees. “As shared during the Nissan Town Hall meeting on December 5, 2023, Nissan learned on November 7, 2023, that it was the victim of a targeted cyberattack. Upon learning of the attack, Nissan promptly notified law enforcement and began taking immediate actions to investigate, contain, and successfully terminate the threat,” the company said in a notification to impacted individuals. Nissan disclosed that the threat actor targeted its external VPN and then shut down certain company systems before asking for a ransom. The company notes that none of its systems were encrypted during the attack. Working with extern...

Why Your VPN May Not Be As Secure As It Claims

Image
By Krebs On Security Virtual private networking (VPN) companies market their services as a way to prevent anyone from snooping on your Internet usage. But new research suggests this is a dangerous assumption when connecting to a VPN via an untrusted network, because attackers on the same network could force a target’s traffic off of the protection provided by their VPN without triggering any alerts to the user. When a device initially tries to connect to a network, it broadcasts a message to the entire local network stating that it is requesting an Internet address. Normally, the only system on the network that notices this request and replies is the router responsible for managing the network to which the user is trying to connect. The machine on a network responsible for fielding these requests is called a Dynamic Host Configuration Protocol (DHCP) server, which will issue time-based leases for IP addresses. The DHCP server also takes care of setting a specific local address — known ...

A Deep Dive Into the Residential Proxy Service ‘911’

By  Krebs On Security For the past seven years, an online service known as 911 has sold access to hundreds of thousands of Microsoft Windows computers daily, allowing customers to route their Internet traffic through PCs in virtually any country or city around the globe — but predominantly in the United States. 911 says its network is made up entirely of users who voluntarily install its “free VPN” software. But new research shows the proxy service has a long history of purchasing installations via shady “pay-per-install” affiliate marketing schemes, some of which 911 operated on its own. 911[.]re is one of the original “residential proxy” networks, which allow someone to rent a residential IP address to use as a relay for his/her Internet communications, providing anonymity and the advantage of being perceived as a residential user surfing the web. From a website’s perspective, the IP traffic of a residential proxy network user appears to originate from the rented residential IP a...

India Delays Implementation of VPN Data-Collection Rule by 3 Months

In the meantime, at least five major VPN players have decided to remove their physical VPN servers from the country. By Michael Kan, PC Magazine India’s new policy that requires VPN services to log and potentially turn over data on their customers was supposed to go into effect on Monday, but the country has decided to push back the date by three months.  The policy is now set to go into effect on Sept. 25. The Indian government settled on the new date, citing requests from companies asking for an extension.  “Further, additional time has been sought for implementation of mechanism for validation of subscribers/customers by Data Centres, Virtual Private Server (VPS) providers, Cloud Service providers and Virtual Private Network Service (VPN Service) providers,” Indian authorities announced on Tuesday.  India introduced the policy back in May with the goal of helping the country fight cybercrime. Soon, all internet and cloud service providers will need to maintain logs of ...

Recent Windows Server updates break VPN, RDP, RRAS connections

By Sergiu Gatlan,  Bleeping Computer This month's Windows Server updates are causing a wide range of issues, including VPN and RDP connectivity problems on servers with Routing and Remote Access Service (RRAS) enabled. RRAS is a Windows service that offers additional TCP connectivity and routing features, including remote access or site-to-site connectivity with the help of virtual private network (VPN) or dial-up connections. Last week, Microsoft released the Windows Server 2019 2012 R2 KB5014746, the Windows Server 2019 KB5014692, the Windows Server 20H2 KB5014699, and the Windows Server 2022 KB5014678 updates as part of the June 2022 Patch Tuesday. However, after deploying these recent updates, Windows admins have reported experiencing multiple issues that could only be resolved after completely uninstalling the updates. One of the more severe problems is the servers freezing for several minutes after a client connects to the RRAS server with SSTP.

Spanish police dismantle phishing gang that emptied bank accounts

By Bill Toulas,  Bleeping Computer The Spanish police have announced the arrest of 13 people and the launch of investigations on another seven for their participation in a phishing ring that stole online bank credentials. The threat actors used phishing lures to trick their victims into believing they received an alert from their bank and proceeded to steal their account credentials. Having access to banking accounts, the adversaries used their victims' money to make online purchases, direct transfers to "money mule" accounts, or request personal loans. The police say the threat actors stole at least 443,600 Euros ($466,000). from approximately 146 victims as part of these phishing attacks. "The operation, carried out in several phases between January 2019 and April of this year, has ended with the arrest of 13 people -and another 7 investigated but not detained- in A Coruña, Córdoba (5), Huelva, Madrid (2), Málaga, Murcia, Palma de Mallorca and Terrassa (Barcelona)....

Hackers are exploiting critical bug in Zyxel firewalls and VPNs

By Ionut Ilascu,  Bleeping Computer Hackers have started to exploit a recently patched critical vulnerability, tracked as CVE-2022-30525, that affects Zyxel firewall and VPN devices for businesses. Successful exploitation allows a remote attacker to inject arbitrary commands remotely without authentication, which can enable setting up a reverse shell.

India Orders VPN Providers to Log and Hand Over Customer Data

Image
The Indian government is doing so to address gaps in responding to cybersecurity incidents, but the new regulations undermine a main selling point to having a VPN. By Michael Kan, PC Mag In an effort to fight cybercrime, India is enacting a new policy that’ll require VPN providers to collect and turn over user data, including the IP addresses assigned to customers.  The policy is meant to bolster the powers of the country’s national agency, the Indian Computer Emergency Response Team (CERT-In), which deals with cybersecurity incidents.  “During the course of handling cyber incidents and interactions with the constituency, CERT-In has identified certain gaps causing hindrance in incident analysis,” India’s government said in adopting the new policy last week . The new regulations call for VPN providers to log and store the following information from customers for at least five years:  Name, email address and phone number The customer’s purpose for using the VPN service The...

NordVPN Mulls Pulling All Servers From India Due to Data-Collection Requirement

Image
Other providers are signaling they'll oppose the new policy in India, which will require VPN providers to collect and turn over data on customers. By Michael Kan, PC Mag India’s new policy requiring VPN services to collect and hand over data on customers is prompting NordVPN to consider pulling its servers from the country.  “We are committed to protecting the privacy of our customers; therefore, we may remove our servers from India if no other options are left,” NordVPN told us. India is implementing the new policy to help it fight cybercrime. But the data-collection requirement also undermines the whole point of installing a VPN, which are often designed to protect a user's privacy.  Under the new policy, VPN providers would need to log data on which IP addresses their customers are using and store the information for at least five years. As a result, the data could be used to map out customers' web activities if it’s ever turned over to Indian authorities.  NordVPN sa...

Hands on with Microsoft Edge's new built-in VPN feature

Image
By Mayank Parmar, Bleeping Computers Microsoft is working on a built-in VPN functionality for the Edge browser called ' Edge Secure Network ', but there's a catch - it is not a proper replacement for your VPN. Edge's Secure Network is powered by Cloudflare - one of the most trusted DNS hosts in the industry - and it aims to protect your device and sensitive data as you browse. The feature is in the early stage of development available to select users in Edge Canary and it's not a full-fledged VPN service offered in rival browsers like Opera. So how does Microsoft Edge's Secure Network actually work? As per the support document and our tests, Edge uses Cloudflare's routing to encrypt your internet connection and protect your data from online threats like hackers. Microsoft says Edge Secure network feature sends your traffic through an encrypted tunnel to create a secure connection, which means even HTTP URLs are accessed securely in a bid to make it harder ...

Cybersecurity agencies reveal top exploited vulnerabilities of 2021

By Sergiu Gatlan, Bleeping Computer In partnership with the NSA and the FBI, cybersecurity authorities worldwide have released today a list of the top 15 vulnerabilities routinely exploited by threat actors during 2021. The cybersecurity authorities urged organizations in a joint advisory to promptly patch these security flaws and implement patch management systems to reduce their attack surface. Globally, malicious actors have been observed focusing their attacks on internet-facing systems, including email and virtual private network (VPN) servers, using exploits targeting newly disclosed vulnerabilities. "U.S., Australian, Canadian, New Zealand, and UK cybersecurity authorities assess, in 2021, malicious cyber actors aggressively targeted newly disclosed critical software vulnerabilities against broad target sets, including public and private sector organizations worldwide," the advisory reads. This might be due to malicious actors and security researchers releasing proof o...

T-Mobile breached by cybercrime group LAPSUS$ through compromised employee accounts

Image
By Michael Potuck, 9 to 5 Mac T-Mobile has suffered another data breach, this time carried out by young hackers that were part of the LAPSUS$ group. While T-Mobile has said that no customer or government information was compromised, it appears LAPSUS$ gained access to T-Mobile’s source code repositories along with its customer account management system. Reported and seen by Krebs on Security , leaked messages between members in the LAPSUS$ cybercrime group show that they successfully hacked into T-Mobile multiple times last month. The hackers gained access to T-Mobile’s internal systems by taking over multiple employee accounts with purchases through sites like “Russian Market,” social engineering, and other methods of stealing the information. The messages reveal that each time LAPSUS$ was cut off from a T-Mobile employee’s account — either because the employee tried to log in or change their password — they would just find or buy another set of T-Mobile VPN credentials. T-Mobile curr...