CYB 6040 Wilmington University Week 1 Cyber Threat Intelligence Discussion
Description
Having Trouble Meeting Your Deadline?
Get your assignment on CYB 6040 Wilmington University Week 1 Cyber Threat Intelligence Discussion completed on time. avoid delay and – ORDER NOW
Please post your BULLETS for this week’s Discussion Board. Your post should be a short summary or article from an online resource that is relevant to our course. 5 Bullets per week minimum Required for an A. Recommend posting 1 more per week to cover any loss for duplication.
Bullets. Each week, students will prepare short, relevant, current bullets (brief written summaries or use the article itself from online reference but cut it down to core) pertaining to this course: e.g., national / local crises, terror incidents, terror groups, accidents, natural disasters, maritime incidents or piracy, political or infrastructure news, LEO actions, civil / criminal actions, health issues, open intelligence, Threats CIS sector news, Patriot Act, NSA, CIA, WH, laws or rulings of interest; URLS, security events, UAS news, C-UAS news interesting IT/ INFOSEC finds, agency news or actions, or bibliography items. The field of topic possibilities is huge.
The general format for a Bullet is: Author & Source, first; Title, second; Summary, third; [ Bullet Body] and your Opinion or Conclusions, last.
Grading on each Sunday at 2200 EST or before ( if limit is reached) for five consecutive weeks is:
5 Bullets / week = A = 100 points / week
4 Bullets / week = B = 80 points / week
3 or less Bullets / week = F = 0 points / week.
THIS IS AN EXAMPLE OF AN EXCELLENT BULLET
TITLE: Chinese hacking group has found new way to bypass two-factor authentication
SOURCE: siliconangle.com
Author: DUNCAN RILEY (Links to an external site.)
SUMMARY
A group with alleged links to the Chinese government has been accused of hacking networks worldwide, but in a rare twist its said to be bypassing two-factor authentication in the process.
The hack was detailed (Links to an external site.) late last week by security researchers from Fox-IT Holding B.V. APT20, the group behind the campaign, targets web servers as the first point of entry with a particular focus on Jboss.
Once through the door, the group installs web shells then spreads throughout the network. Showing fairly typical behavior, the group seeks out passwords and administrator accounts to obtain more information from their targets utilizing virtual network credentials for more secure access.
Where it gets interesting is that the researchers claim they found evidence that APT20 was gaining access to VPN accounts that were protected by 2FA. Hacking 2FA isnt new, and the process involved is somewhat complicated, but APT20 is said to have found a new way to bypass the process.
The hackers are believed to have stolen an RSA SecurID software token from a hacked system, then modified the key to work on different systems.
The software token is generated for a specific system, but of course this system specific value could easily be retrieved by the actor when having access to the system of the victim, the security researchers explained. As it turns out, the actor does not actually need to go through the trouble of obtaining the victims system-specific value, because this specific value is only checked when importing the SecurID Token Seed, and has no relation to the seed used to generate actual 2-factor tokens. This means the actor can actually simply patch the check which verifies if the imported soft token was generated for this system, and does not need to bother with stealing the system-specific value at all.
While specifically applying to software-based tokens, the method is disturbing particularly given that 2FA is regularly held up as a way to prevent hacking such as this.
A full copy of the research into the group can be found here (Links to an external site.).
Full Report: https://resources.fox-it.com/rs/170-CAK-271/images/201912_Report_Operation_Wocao.pdf (Links to an external site.)
COMMENT:
The Chinese have invested huge assets in cracking USA cryptography (COMSEC) and network protection systems. However, up until now they have not been able to by-pass challenge-response or two-factor authentication controls. This report, if verified, indicates that this wall is now vulnerable.