Check Point Research, the Threat Intelligence arm of Check Point® Software Technologies Ltd.has published its latest Global Threat Index for May 2019. The Research team is warning organizations to check for and patch any systems vulnerable to the ‘BlueKeep’ Microsoft RDP flaw in Windows 7 and Windows Server 2008 machines, to prevent the risk of it being exploited for ransomware and cryptomining attacks.
The BlueKeep flaw affects nearly 1 million machines accessible to the public internet, with many more within organizations’ networks. The vulnerability is critical because it requires no user interaction in order to be exploited. RDP is already an established, popular attack vector which has been used to install ransomware such as SamSam and Dharma. The Check Point Research team is currently seeing many scanning attempts for the flaw, originating from several different countries globally, which could be the initial reconnaissance phase of an attack. In addition to the relevant Microsoft patches, Check Point is providing both network and endpoint protections to this attack.
Maya Horowitz, Threat Intelligence and Research Director at Check Point said: “The biggest threat we’ve seen over the past month is BlueKeep. Even though no attacks have yet been seen exploiting it, several public proof-of-concept exploits have been developed. We agree with Microsoft and other cybersecurity industry observers that BlueKeep could be used to launch cyberattacks on the scale of 2017’s massive WannaCry and NotPetya campaigns. One single computer with this flaw can be used to deliver a malicious payload that infects an entire network. Then all infected computers with Internet access can infect other vulnerable devices worldwide – enabling the attack to spread exponentially, at an unstoppable pace. So it’s critical that organizations protect themselves – and others – by patching the flaw now, before it’s too late.”
Other significant malware news in May was the developers of the GandCrab Ransomware-as-a-Service affiliate program announcing on the last day of the month that they were ceasing operation, and asking their affiliates to stop distributing the ransomware within 20 days. The operation has been active since January 2018, and in just two months had infected over 50,000 victims. Total earnings for its developers and affiliates are claimed to be in the billions of dollars. A regular in the Top 10 Most Wanted Index, GandCrab was frequently updated with new capabilities to evade detection tools.
May 2019’s Top 3 ‘Most Wanted’ Malware:
*The arrows relate to the change in rank compared to the previous month.
The three most prominent Cryptominers – Cryptoloot, XMRig, and JSEcoin continue to top the malware index, each with a global impact of 4%.
- ↔ Cryptoloot– Crypto-Miner, using the victim’s CPU or GPU power and existing resources for crypto mining – adding transactions to the blockchain and releasing new currency. It was a competitor to Coinhive, trying to pull the rug under it by asking less percent of revenue from websites.
- ↔ XMRig – Open-source CPU mining software used for the mining process of the Monero cryptocurrency, and first seen in-the-wild on May 2017.
May’s Top 3 ‘Most Wanted’ Mobile Malware:
This month Lotoor is the most prevalent mobile malware, up from 2nd in April. Triada drops from 1st to 3rd, while Hiddad climbs back up from 3rd to 2nd.
- ↑ Lotoor – Hack tool that exploits vulnerabilities on Android operating system in order to gain root privileges on compromised mobile devices.
- ↑ Hiddad – Android malware which repackages legitimate apps and then released them to a third-party store. Its main function is displaying ads, however it is also able to gain access to key security details built into the OS, allowing an attacker to obtain sensitive user data.
- ↓ Triada – Modular Backdoor for Android which grants super user privileges to downloaded malware, as helps it to get embedded into system processes. Triada has also been seen spoofing URLs loaded in the browser.
May’s Top 3 ‘Most Exploited’ vulnerabilities:
In May we saw a comeback of traditional attack techniques (probably caused by the decrease in Cryptominers’ profitability), with SQL Injections techniques leading the top exploits vulnerabilities list with a global impact of 49%. Web Server Exposed Git Repository Information Disclosure and OpenSSL TLS DTLS Heartbeat Information Disclosure ranked second and third, impacting 44% and 41% of organizations worldwide respectively.
- ↑SQL Injection (several techniques) – Inserting an injection of SQL query in input from client to application, while exploiting a security vulnerability in an application’s software.
- ↑ Web Server Exposed Git Repository Information Disclosure – An information disclosure vulnerability has been reported in Git Repository. Successful exploitation of this vulnerability could allow an unintentional disclosure of account information.
- ↓ OpenSSL TLS DTLS Heartbeat Information Disclosure (CVE-2014-0160; CVE-2014-0346)– An information disclosure vulnerability exists in OpenSSL. The vulnerability is due to an error when handling TLS/DTLS heartbeat packets. An attacker can leverage this vulnerability to disclose memory contents of a connected client or server.
Check Point’s Global Threat Impact Index and its ThreatCloud Map is powered by Check Point’s ThreatCloud intelligence, the largest collaborative network to fight cybercrime which delivers threat data and attack trends from a global network of threat sensors. The ThreatCloud database holds over 250 million addresses analyzed for bot discovery, more than 11 million malware signatures and over 5.5 million infected websites, and identifies millions of malware types daily.
Dinesh Nair Appointed as Director for Consumer Business Lenovo India
Global technology leader Lenovo has appointed Dinesh Nair as Director, Consumer Business for India region. Dinesh succeeds Mr. Shailendra Katyal, who has recently been appointed Site Leader for Lenovo India and Managing Director of Lenovo’s PC and smart device business in India.
Dinesh Nair has been an integral part of the Lenovo India consumer business for more than 11 years and has worked successfully across several roles. His most recent role was as the sales & channel management lead for Lenovo’s consumer segment in India. He has handled leadership responsibilities across offline general trade retail, distribution management, field sales, eCommerce, large format retail and category management, and has been a key contributor to the company’s growth journey in India.
“During this difficult time in India, we are working hard to ensure the safety of our employees, partners and customers and I am grateful that we have excellent leaders in place to bring our team together and offer this support. I am proud to hand over the reins of the consumer business to Dinesh. At the same time, this is a demonstration of our commitment to developing talent internally. I am sure he, along with the consumer leadership team, will propel the business to new heights,” said Shailendra Katyal, Managing Director, Lenovo India.
ASUS ROG Announces ROG Masters Asia Pacific eSports Tournament
ASUS ROG will host its first ROG Masters Asia Pacific eSports tournament from March to April 2021. Due to COVID-19 pandemic affecting travel around the region, the tournament will be conducted entirely online, with quarterfinal to final matches livestreamed.
The ROG Masters tournament will feature Counter-Strike: Global Offensive (CS:GO) as the official game title will provide opportunity to teams with enthusiastic players to pitch their skills against each other, as well as the best professional teams from their market and in the region.
The tournament will see various teams from 15 markets across the region vying for the chance to be crowned as the first ROG Masters Asia Pacific Edition CS:GO Champion.
The tournament will be played in three stages played over the course of 2 months:
- Country qualifiers
- Country finals
- Asia Pacific finals
Country qualifiers matches for India will start in the second week of April 2021; 8th April and the finals to be held on the 10th April. The India finals to find the top three teams to represent the country will be livestreamed live on 10th April.
Professional teams from across the region will be automatically placed into seeded positions in the country finals. This gives a greater chance for non-professional, enthusiast teams from India to get through the qualifiers and meet the pro teams in the country finals.
Country Champions will then go on to experience battling winning teams from other APAC markets in the finals that will be livestreamed during 22nd to 25th April 2021.
3 qualifying teams from India finals will stand to win US$800 for first place, US$400 for second place, US$200 for third place. They will then go on to the Asia Pacific finals with the chance to win the following prizes for the championship:
|ROG Masters APAC Championship||APAC Finals (USD/ team)|
Registration and Official Tournament Website
Registration for the first ROG Masters Asia Pacific tournament opens on February 8, 2021 at the tournament’s official website.
Registration closes on February 28, 2021 Further details, match schedules, pro team information as well as rules and regulations can also be found on the tournament website.
Garena Launches Free Fire South Asia Showdown: Battle of the Stars
Garena has announced the Free Fire South Asia Showdown: Battle of the Stars, Free Fire’s first-ever esports tournament for the South Asia region. Taking place on 6 February, the tournament will feature some of the gaming community’s favourite Free Fire streamers and personalities from India, Pakistan, Nepal, and Bangladesh.
The Free Fire community has continued to expand in South Asia and across the world, with the mobile battle royale game the most downloaded mobile game globally in 2020, according to App Annie. Through the Free Fire South Asia Showdown: Battle of the Stars, Garena will look to continue its efforts to excite and delight its fast-growing South Asian community with exciting Free Fire content, and to support and develop the incredible online community in the region.
The Free Fire South Asia Showdown: Battle of the Stars will feature a total of 12 teams. Each team will be led by one of the top 3 streamers from each of the 4 participating nations – chosen by public voting – in this epic clash to determine the best in the region.
The 12 teams will compete in the Battle Royale Squad mode for a slice of the 1 million diamond prize pool. The ultimate winner of this star-studded tournament will receive 500,000 in-game diamonds; the first and and second runners-up will be awarded 300,000 and 200,000 diamonds respectively.
The Free Fire South Asia Showdown: Battle of the Stars will feature some of the most popular streamers and personalities from across South Asia.
The team captains for each nation are:
- Total Gaming (19.4 Million YT Subs)
- Desi Gamers (7.8 Million YT Subs)
- Two-Side Gamers (6.85 Million YT Subs)
- Gaming with Nayeem (1.6 Million YT Subs)
- Illusionist YT (479K YT Subs)
- Gaming With Zihad (698K YT Subs)
- Sooneeta (3.26 Million YT Subs)
- Bshow Mgr (399K YT Subs)
- Tonde Gamer (2.37 Million YT Subs)
- RKG ARMY (1.77 Million YT Subs)
- Unusual Gamer (81K YT Subs)
- The Skinzo FF (75.5K YT Subs)
Fans can witness all the high-octane action by tuning in to the live broadcasts of the Free Fire South Asia Showdown: Battle of the Stars. These will be hosted on Free Fire Esports India YouTube and Facebook, Free Fire Bangladesh Official YouTube and Facebook, as well as on BOOYAH!.
To cater to the diverse South Asian community, the matches will be streamed with live commentary in 5 languages – Bengali, English, Hindi, Nepali and Urdu.
Gadgets4 days ago
RAEGR Launches ‘Vocalz 250’ Condenser Mic Kit
Trending4 days ago
Redmi India Sold 2 Million Note 10 Series Smartphone Worth Rs. 3000+ Crores
Gadgets4 days ago
Relive The Old Memories This Fathers’ Day with Saregama Carvaan
Trending3 days ago
Avail Big Discounts on Infinix Smartphones During from Flipkart’s Big Saving Days Sale
Smartphone4 days ago
TECNO SPARK 7T with 48MP AI Dual Rear Camera Launched in India
Gaming4 days ago
Garena Announced Schedule for City Finals of Free Fire City Open
Trending4 days ago
Realme Brings Amazing Offers on Its Smartphones on Flipkart
Gadgets4 days ago
pTron Launches New Smart Wearables, Starting at Rs. 899/-