Story image

Inside NZ's 'ethical hacking' firm and its quest to make systems safer

26 Jun 2017

New Zealand's first ethical hacking company has issued a critical warning to those using Microsoft Edge and Internet Explorer after it discovered zero-day vulnerabilities back in May.

Attackers are able to exploit the vulnerabilities and gain access to sensitive information. They could also run malicious code on victims' machines, Security-Assessment reports.

The company's principal consultant Scott Bell discovered the vulnerabilities in May, and Microsoft patched them in the same month.

“Security-Assessment follows responsible disclosure guidelines. This means alerting the vendor to the vulnerabilities immediately and not releasing information about the vulnerabilities until they are fixed. This is to prevent malicious actors from actively exploiting the vulnerabilities," Bell explains.

Despite being patched by Microsoft, the company is urging users to apply the patches or face being attacked.

Practice lead Phil Doole says there could be worrying repercussions for those who do not apply the patches.

“The ability for an attacker to run malicious code on a victim’s machine could have dramatic and severely damaging impact for both organisations and individuals,” he says.

"These vulnerabilities are known as 'memory corruption'. The vulnerabilities allow a malicious user to craft a special web page which, when visited, can download a payload to allow access to the victim's machine. This is typically delivered via a technique called spear phishing. Such vulnerabilities are often used by state-sponsored actors (APT) to gain a foothold in the target network," the company adds.

This year the company has facilitated seven security advisories, the most of any New Zealand security firm, it claims.

In one case, the company helped to provide incident response and forensics after a state-sponsored APT group infiltrated a client's network.

The company says that with a 100% hit rate in penetration test this year alone, it means there hasn't been one engagement in which it hasn't identified vulnerabilities.

"User awareness is key. Educating users on the dangers of clicking unsolicited links in emails can help to prevent spear phishing attacks from succeeding. For organisations running Windows 7 or older, upgrading to Windows 10 will bring additional enhancements that help to protect against such vulnerabilities," the company says in a statement.

Security-Assessment was established in 2002. In 2007, it became a wholly-owned subsidiary of Dimension Data and continues to operate as a vendor-neutral offensive security consultancy, providing security, assessment and assurance services for organisations. Dimension Data has offices in Auckland, Wellington and Singapore.

Mozilla launches Firefox Send, an encrypted file transfer service
Mozille Firefox has launched a free encrypted file transfer service that allows people to securely share files from any web browser – not just Firefox.
Online attackers abusing Kiwis' generosity in wake of Chch tragedy
It doesn’t take some people long to abuse people’s kindness and generosity in a time of mourning.
Ransomware’s decline equals cryptomining’s rise
ESET’s Security Days Conference recently took place to go over the current threat environment and what to look out for next.
IoT and DDoS attacks: A match made in heaven
A10 Network’s Adrian Taylor uses findings from a number of reports to illustrate his point that advances in technology are facilitating cybercrime.
ForgeRock launches Sandbox-as-a-Service to facilitate compliance
The cloud-based testing environment for APIs enables banks to accelerate compliance with Open Banking and PSD2 deadlines.
Cloud application attacks in Q1 up by 65% - Proofpoint
Proofpoint found that the education sector was the most targeted of both brute-force and sophisticated phishing attempts.
Singapore firm to launch borderless open data sharing platform
Singapore-based Ocean Protocol, a decentralised data exchange that promotes data sharing, has revealed details of what could be the kickstart to a global and borderless data economy.
Huawei picks up accolades for software-defined camera ecosystem
"The company's software defined capabilities enable it to future-proof its camera ecosystem and greatly lower the total cost of ownership (TCO), as its single camera system is applicable to a variety of application use cases."