Monday, 5 May 2014

Attackers Use Microsoft Security Hole Against Energy, Defense, Finance Targets


A security vulnerability that affected all versions of Microsoft's Internet Explorer browser took on added urgency because the company had stopped supporting its Windows XP operating system. 
A security vulnerability that affected all versions of Microsoft’s Internet Explorer browser took on added urgency because the company had stopped supporting its Windows XP operating system.
SAN FRANCISCO — By the time Microsoft warned customers of a nasty security hole in its web browser Saturday, a sophisticated group of attackers were already using the vulnerability against defense and energy companies, according to FireEye, the security company.
Things went from bad to worse over the weekend. FireEye’s researchers watched as the attackers shared their exploit with a separate attack group, which began using the vulnerability to target companies in the financial services industry, according to Darien Kindlund, the director of threat intelligence at FireEye.
Even after Microsoft issued its advisory on Saturday, Mr. Kindlund said, “There was a notable increase in proliferation.”
Soon, the attackers were using the vulnerability for so-called watering hole attacks, in which hackers infect a popular website with malware, then wait for victims to click to the site and infect their computers.
Mr. Kindlund said FireEye believed the two attack groups were nation-state sponsored. While he said the company did not yet have conclusive evidence, based on the groups’ previous campaigns it was believed they were operating from China.
The vulnerability affected all versions of Microsoft’s Internet Explorer web browser. Only those who had configured their browsers to run in enhanced protection mode were protected.
The situation took on added urgency because Microsoft stopped supporting its Windows XP operating system last month, meaning that any devices running Windows XP would be permanently vulnerable to attack.
Typically in its regular upgrade cycle, Microsoft waits to issue security fixes on the first Tuesday of every month — what system administrators call “Patch Tuesday.” But given the gravity of the hole, Microsoft raced to issue a patch Thursday and decided to update Windows XP systems as well.
“The security of our products is something we take incredibly seriously,” Adrienne Hall, the general manager of Microsoft’s Trustworthy Computing project, said in a statement on Thursday. “When we saw the first reports about this vulnerability we decided to fix it, fix it fast, and fix it for all customers.”
The timing of FireEye’s discovery was fortuitous for the company, whose stock has tumbled 40 percent since a finding last month by NSS Labs, an independent research company, that FireEye’s breach-detection systems underperformed similar offerings by Cisco Systems, Trend Micro and General Dynamics. NSS Labs actually issued a grade of “caution” to customers using FireEye’s web and email malware protection systems.
The findings set off an unusual back-and-forth online between NSS Labs and FireEye. Responding to the report in a blog post, Manish Gupta, FireEye’s senior vice president for products, said NSS Labs’ test environment did not match the real threat landscape. NSS Labs’ researchers responded in a blog post of their own — titled “Don’t Shoot the Messenger.” 
FireEye’s stock, which had been trading at $65 before the NSS Labs report was released, has been tumbling and closed near $40 Thursday.
Mr. Kindlund, of FireEye, said this week’s discovery of the security hole in Internet Explorer was proof that isolated tests did not reflect real-world threats. A separate finding by NSS Labs released in March had found that Internet Explorer was more secure than Google’s Chrome and Apple’s Safari browser.
“Look, we’re focused on protecting and defending against real-world attacks,” Mr. Kindlund said. “It’s hard to model and test for that in any controlled way. Clearly, there’s a disconnect between what’s happening in the real world and what’s currently being tested.”

Hackers target Windows XP users with Internet Explorer attacks

Microsoft Windows XP screen
Hackers are leveraging a zero-day vulnerability in Microsoft's Internet Explorer (IE) web browser to target Windows XP users with an advanced cyber attack.
Researchers from FireEye uncovered the attack and listed it as being a part of a wider campaign, codenamed "Operation Clandestine Fox". FireEye reported uncovering the IE vulnerability earlier this week.
The vulnerability affects IE6 through IE11 and can theoretically be used to exploit machines running Windows XP, 7 and 8.1. The original Operation Clandestine Fox attacks focused on targeting Windows 7 and 8.1 machines running IE9 through IE11. The new attacks target Windows XP machines running IE8.
Threat intelligence manager at FireEye Darien Kindlund told V3 the attacks have the same end goal as the earlier Windows 7 and 8 raids and are designed to infiltrate businesses involved in critical infrastructure areas.
"The XP attack is identical to the previously discovered vulnerability," said Kindlund. "It lets attackers gain remote access to compromised systems, and it appears to be used in targeted attacks against [the] defence, finance, and energy sectors."
The attacks' discovery comes just after Microsoft released a patch plugging the IE vulnerability which included a fix for Windows XP users. The fix comes less than a month after Microsoft officially ceased support for its decade-old Windows XP operating system (OS). Microsoft said the XP fix is a one-off, promising it will not release any further patches for the OS.
Kindlund told V3 the advanced nature of the attack makes tracking its origin difficult, but FireEye is operating under the assumption that it's state sponsored. "We don't have definitive evidence to link the attackers to a particular country of origin; however, we believe these attacks were sponsored by at least one nation state," said Kindlund.
State-sponsored cyber attacks have been a growing concern within the security community with new campaigns believed to be government funded and appearing on a near-monthly basis. For a look at the most dangerous state-sponsored cyber attacks check out V3's top 10 guide.