Home Blog Page 119

How Internet Scams Persist in the Face of the COVID-19 Pandemic

initial access brokers

The more technology advances, the more sophisticated the methods that fraudsters employ to cheat people out of their hard-earned money. And it’s only gotten worse since the onset of the COVID-19 pandemic, as more and more people get stuck inside their homes, unable to go out to get even their basic needs. The resulting increase in digital use means that hackers and scammers have a wider market to exploit, capitalizing on people’s fears.

By Andriana Moskovska, Community Manager at TheHighCourt.co

In the world of cybersecurity, this kind of development is both a headache and a challenge. While the more common threats, such as malware, phishing emails, and weaponized websites are still there, more sophisticated forms of attacks are also cropping up, often exploiting people’s fears.

The Usual Forms of Scams During COVID-19

Some of the most common forms of scams include those that disguise themselves as financial support from legit organizations. Many individuals have received fake government emails that offer grants amounting to thousands of dollars. These emails are notorious for containing links that enable scammers to steal personal and financial information.

Another modus operandi concerns health scams. This method employs phishing emails that inform recipients they have been in contact with a suspected COVID-19 case. Just like the financial support scams, this spurious claim often includes a link to fake websites that snatch important information or even compromise devices by infecting them with malware.

What’s worse, with the imposition of restrictions and lockdowns and ensuing loneliness, people are even more susceptible to scams. Many have lost their jobs and are worried sick night and day about catching the virus. Scammers know this and have been taking advantage of the chaos.

Global fraud reports in 2020 ballooned to 50,176, amounting to losses that reached $154.8 million

This brings cybersecurity to the forefront of the issue, prompting many to assess and reconsider their strategies and policies.

So, how can individuals dodge cyber threats like internet scams?

Here’s our quick guide.

Education is still the best defense

Most email providers have put safeguards in place to diminish spam and keep out suspicious emails. However, no matter how many safety precautions are put in place, scammers will still find a way to get into your inbox. That’s why human intervention is still the key to thwarting scammers’ advances. You should be aware and vigilant enough to recognize a phishing attack.

Cyber education is a long-term strategy that can help prepare individuals to spot malicious emails and know what to do about them. This is especially important to businesses and other remote-work organizations. They need to be able to deal with emerging threats at any given time. This could be done through phishing training, which allows employees to recognize phishing attacks and prevent them.

Securing network connections

There are basic steps to securing your network connections, and everyone must know and apply them. This often involves changing the network name and administrator credentials. But it would be even more effective if you know how to layout appropriate network encryptions. You should be careful about accessing public Wi-Fi, especially when network names can be spoofed.

For employers, having a clear policy on the flow of communication can go a long way. This includes setting out the accepted communication channels, such as work emails. They should know what kind of software and apps they could safely install, so the line of communication is safe and secure.

Preparing for the worst

A true cybersecurity professional knows that nothing is absolutely safe from a malicious threat. That is why it is important to review and update your cyber incident response, crisis management, and recovery plans.

This means you can easily access the equipment you need for testing and resetting in case of an attack. Backing up essential data to a secure site is of paramount importance, too.

There are also important questions you need to think about.

How do you report an attack? Will there still be a back-up channel of communication should devices get encrypted with ransomware?

It is also crucial to delegate responsibilities so that it will be easier to respond to a crisis.

Evolve with the times

As mentioned before, scammers are getting smarter by the day. The types of attack might be the same, but their tactics can change at the drop of a hat. So, cybersecurity should be at the core of IT and business planning instead of being considered as an afterthought. Recognizing the data, assets, and services that need protection is also vital.

But most crucial of all, there should be abreast of the latest cybersecurity developments If something no longer works, it’s time to reconsider and reset. It is important to remain one step ahead of scammers and other cybercriminals.

Wrapping it up

Cybersecurity measures are more important than ever in an uncertain time when tensions and fears are high. And while scammers often find more sophisticated ways to deceive, they are by no means infallible. Recognizing their methods and putting safety precautions in place can go a long way in ensuring the safety and protection of both individuals and organizations.

While the world is still reeling from the continuous onslaught of COVID-19, scammers are not showing any signs of slowing down. They will persist. The best protection is to remain vigilant and always think that prevention is always better than cure.


About the Author

AndrianaAndriana Moskovska is the Community Manager at TheHighCourt.co. With a passion to engage people in and out of the workplace, working for The High Court was right up her alley. She is also a writer and a contributor to CISO MAG. She has her expertise in cybersecurity, cyber law, IT and OT, and also presents cybersecurity industry analysis.

 

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Hackers Posted Patients’ Data of Two U.S. Hospitals on Dark Web

BigBasket Allegedly Suffers Data Breach, Customer Data on Dark Web for Sale

Cybercriminals have posted massive patients’ and employees’ personal data, from two of the biggest hospital chains in the U.S., on the dark web to extort them for ransom. Attackers published tens of thousands of files from the Leon Medical Center, which runs eight health care facilities in Florida, and Nocona General Hospital, which has three facilities in Texas.

According to a report, the exposed information included patients’ personal identifying information (PII) like their names, addresses, date of birth, scanned diagnostic results, letters to insurers, background checks on hospital employees, and patients’ medical diagnoses.

While there was no sign of encrypting systems by threat actors, the hospitals authorities stated they did not open a ransomware demand.

Cyberattacks on health care organizations have become rampant in 2020. With multiple data breaches and ransomware attacks, health care providers continued to be the primary target for cybercriminals. According to the “U.S. Health Care Data Breach Statistics” survey, around 70% of the U.S. population was affected by healthcare data breaches, with over 230,954,151 health records lost, stolen, or exposed in various security incidents.

Not the First Time for Leon

Leon Medical Centers suffered a data breach in November 2020, which compromised patients’ names, contact information, social security numbers, medical records, financial information, date of birth details, family details, prescription information, diagnosis and treatment history, and health insurance details. The authorities stated that cybercriminals illicitly obtained access to its computer networks and infected them with malware. Leon Medical notified the U.S. Department of Health and Human Services (HHS), the Florida Attorney General, and the FBI for further investigation.

India Reported More than 2.9 Lakh Digital Banking Security Incidents in 2020

Acronis Cyber Readiness Report, cyberattacks in India, cybercrime in India, India’s Private Sector

As per a survey conducted by U.S.-based financial technology firm FIS, around 68% of Indian consumers now use digital banking services, for both online and mobile banking. Digital transactions rose by 46% in 2020 (45.72 billion transactions) compared to the F.Y. 2018-19 (31.34 billion transactions). The uptake of these services was due to the COVID-19 pandemic, which meant buying day-to-day groceries online.

Considering this boom and the rapid rise of the use of Bitcoin, India is also getting ready to soon launch its digital currency that would “mostly be based on the blockchain technology,” informed Anurag Thakur, the Minister of State for Finance. However, to learn about the threats harming the digital banking landscape, the Rajya Sabha (the upper house of the bicameral Parliament of India) had asked for a comprehensive report that would give a clear picture of the tasks ahead. Responding to Rajya Sabha’s query, Sanjay Dhotre, Minister of State for Electronics and IT, informed the upper house that more than 2.9 Lakh (290,445) cybersecurity incidents related to digital banking have been reported in 2020.

Related News:

Airtel Data Leak: Close to 2.5 Mn Indian Users Likely Affected

Referring to the findings from the Indian Computer Emergency and Response Team (Cert-In), Dhotre said that the number of incidents reported has nearly doubled as compared to 2018 when it was 1,59,761. The reported “incidents included phishing attacks, network scanning and probing, viruses and website hacking.”

Responses to Other Queries

The Rajya Sabha had also made some additional requests to get deeper insights on the number of fraudulent and cheating cases reported in the same period, along with the number of websites blocked as evasive measures. To this, Dhotre responded with the following details:

  • As per the National Crime Records Bureau (NCRB) data, 6,233 cases were registered in 2019 under fraud and cheating (involving communication devices as medium/ target as per Information Technology Act 2000). This number too has nearly doubled since 2018 when only 3,353 cases were reported.
  • Approximately 9,849 websites/webpages/or respective accounts were blocked in 2020 as opposed to 3,635 in 2019 and 2,799 in 2018. The section 69A of the IT Act was enforced by the Government in such cases which empowers it to “block any information generated, transmitted, received, stored or hosted in any computer resource in the interest of sovereignty and integrity of India, defense of India, security of the State, friendly relations with foreign states or public order.”

Related News:

Indian Government Asks WhatsApp to Withdraw its “Discriminatory” Policy

Unpatched Vulnerability in WordPress Plugin Affects 50,000 Sites

Attackers Target 900,000 WordPress Sites in a Week

Threat intelligence team from security firm Wordfence discovered a Cross-Site Request Forgery (CSRF) to Stored Cross-Site Scripting (XSS) vulnerability in Contact Form 7 Style, a WordPress plugin installed on over 50,000 sites.

The vulnerability, with a CVSS Score: 8.8, could allow a remote hacker to inject malicious JavaScript on a site using the plugin. Upon successful exploitation, an attacker can trick the site’s admin into clicking on a malicious URL or attachment. The vulnerable plugin was temporarily removed from the repository after Wordfence reported the issue to the WordPress officials.

As the vulnerability remains unpatched, Wordfence said, “We strongly recommend deactivating and removing this plugin and finding a replacement as it no longer appears to be maintained by its developer.”

“This vulnerability can only be exploited if a user with administrative capabilities performs an action while authenticated to the vulnerable WordPress site. As a general recommendation, site administrators should always be alert when clicking on any links. If you feel you must click a link, we recommend using incognito windows when you are unsure about a link or attachment. This precaution can protect your site from being successfully exploited by this vulnerability along with all other CSRF vulnerabilities,” Wordfence added.

Contact Form 7 Style is used to add additional styles to forms created with Contact Form 7. It allows users to customize Cascading Style Sheets (CSS) code to customize the appearance of contact forms.

Wordfense researchers recommended users deactivate or remove the Contact Form 7 Style plugin until they find a replacement, as it appears the vulnerable plugin won’t be fixed soon.

700,000 WordPress Users at Risk

In a similar discovery, Wordfence found a zero-day vulnerability in the File Manager plugin, which could allow cybercriminals to execute arbitrary code on a WordPress site. The File Manager plugin is intended to help WordPress admins manage files on their websites. To read the full storyclick here… 

Woodland Trust Hit by High-Level Cyberattack

initial access brokers

Woodland Trust, a charitable trust organization that protects and restores woodland in England, Scotland, Northern Ireland, and Wales, was hit by a sophisticated, high-level cyberattack in December 2020. Woodland Trust stated that unknown attackers illicitly obtained access to the charity’s IT systems. The organization temporarily disconnected all its systems to prevent any further unauthorized access after being hit by the security incident. While there is no information on what data has been accessed by the threat actors, Woodland Trust claimed that an investigation is ongoing to determine the data loss.

“We believe the incident took place after 7 pm on December 14, 2020. As soon as we became aware of the incident, we took immediate action to mitigate the impact, appointing a number of third-party experts including forensic IT specialists and legal counsel, to determine the nature of the criminal activity,” Woodland Trust said.

Woodland Trust reported the security incident to the Information Commissioner’s Office (ICO), the Charity Commission, and the Police department. Besides, the organization has notified its supporters and partners and assured to alert individuals whose information may have been impacted in the incident, as per GDPR guidelines.

“Investigations of this nature take time due to the complexity of the work being carried out. As soon as new information becomes available, we will of course share further updates with you. In the event of confirmed data loss, we will identify and inform those affected immediately, in accordance with GDPR. As a precaution, we are encouraging all our supporters to be mindful of any suspicious activity, especially unexpected emails or phone calls from unknown sources or purporting to come from your bank. Your bank can also help you to protect your account further,” Woodland Trust added.

“We believe there is a large opportunity in the digital identity and privilege management space”

In an exclusive interview with Brian Pereira of CISO MAG, Umesh Padval, Venture Partner at Thomvest Ventures shares his thoughts on the current and future state of cybersecurity from a VC perspective. He also tells us about the type of companies he would like to invest in during 2021, and the potential he sees in Indian companies. Thomvest has an extensive network of CIOs and CISOs and Umesh tells us what the C-suite is looking for in terms of cybersecurity skills and technical prowess.

Thomvest Ventures is based in San Francisco, California, and has invested in companies like Thousandeyes, Lastline, Shiftlift Inc., and more recently, in Harness.io.

Umesh has a keen insight as he has been actively investing in the cybersecurity and cloud infrastructure space over the last 5 – 7 years.

Umesh has served on over 30 public and private company boards, bringing extensive operating experience and skill set valued by CEOs and founders. He currently serves as a Board Member at Avalanche Technology, Bolster, ShiftLeft, and Tactus Technology and Impinj (public company), and as a Board Observer at Clari and ShieldX. He is also an investor in Baffle and Harness.

Prior to joining Thomvest, Umesh was a successful entrepreneur, investor, and CEO of a public company. He most recently worked for over eight years at Bessemer Venture Partners in their Menlo Park offices. Prior to Bessemer, he was an Executive Vice President at LSI after its acquisition of a public video infrastructure and distribution company in C-Cube Microsystems, where he served as President and CEO.

BP: With increased cybersecurity incidents last year, demand for cybersecurity professionals soared. And the valuation of cybersecurity companies, especially startups, should have skyrocketed. But why did investors, particularly for early-stage, hold back?

Umesh: Venture investments in cybersecurity and cloud Infrastructure accelerated in the second half of 2020, across all stages and exits. This was driven by the increase of remote work during the COVID-19 pandemic. Remote work forced enterprises to accelerate their already in-progress transition to the cloud and digitization. The first half of 2020 started off well, but as the pandemic hit in late February and early March, investors became very cautious as to its impact on companies and paused their investments — or even bailed out of committed investments.

We, just like other venture firms, assessed the impact first on our existing portfolio companies. We took appropriate actions to react to the impact of the pandemic over the first 3 to 4 months and made sure they were well-funded so that they would come out stronger post-pandemic. As we got comfortable with our existing portfolio companies, we began focusing on new early-stage investments. One obstacle we had to overcome was becoming comfortable investing in startups over Zoom meetings, without a single in-person meeting. In-person meetings have always been key for fully evaluating a team. Over time, we got comfortable and started investing again. As you saw, there was a massive amount of capital invested in all stages of private companies, and many were sold or went public. Overall, the 1H20 investments were lower due to the pandemic, but then accelerated in 2H20 with a vengeance.

BP: Companies accelerated their digital transformation plans during the pandemic, as business models changed, and supply chains were disrupted. While many rushed to adopt cloud, it threw up new cloud security issues. This was attributed to misconfigurations, over or under-provisioning. Analysts say that there will be a recalibration this year. What do you think will happen on the cloud security front? How will technology like secure containers, threat intelligence, and AI help?

Umesh: The move to the cloud happened overnight when employees started working from home. The only way remote work would “work” was to adopt cloud-based tech versus on-premise infrastructure. When that happened, CIOs and CISOs had to suddenly deal with all kinds of security issues and policies, which they had not planned for. This opened up massive opportunities for bad actors to infiltrate enterprises demanding ransomware or accessing large amounts of sensitive data.

The most infamous one was the SolarWinds hack in December — the impact of which we will not know for many months to come. However, CISOs across all sectors have had almost a year to develop cybersecurity strategies to make the enterprises secure and safe. This accelerated the adoption of new platforms from cybersecurity and cloud infrastructure companies with increased cybersecurity spend. It was a major boom to innovative companies in this space, and many of our portfolio companies benefited from this.

Looking into 2021, this trend will continue and perhaps accelerate. The adoption of containers driven by Kubernetes and container security, all workload protection in the hybrid and multi-cloud environment, the digital identity and privilege management platforms, and the governance and compliance platforms driven by privacy issues will accelerate in 2021. ML/AI has become a major horizontal technology used by all technology companies in every vertical to increase the productivity and efficiencies of businesses and will continue for a long time.

BP: What types of startups do you want to invest in this year? What kind of security technology and skills are you looking for in these companies?

Umesh: In the cloud infrastructure space, we are focused on software development platforms. There are over 25 million software developers around the globe developing and releasing multiple software releases a day, compared to one or two releases per year, 10 years ago. This is in response to their customers’ desire for more features and capabilities. This acceleration provides a massive opportunity for companies to automate the software development process, to allow creative developers to release their products faster.

In January 2021, we invested in Harness.io which is a market leader in providing the best in class rapid automated software delivery (CI/CD) platform via integration with best in class tools. Another company in our portfolio, Shiftleft Inc., integrates security into this DevOps automation platform, enabling software developers to secure the code in their development and release process. We will continue to look at more opportunities in this space.

We also believe there is a large opportunity in the digital identity and privilege management space for hybrid and multi-cloud environments. The use of APIs has skyrocketed, especially in the API security space. We are so excited that Thomvest has been focused on cybersecurity and cloud infrastructure space over the last 5–7 years, which provides tremendous opportunities to invest in companies.

BP: As you interact with CISOs, what are the security skills they look for when hiring staff?

Umesh: We have an extensive network of advisor CIOs and CISOs who are looking at two things:

  1. People with the right cybersecurity skillset. But that pool of talent is very small relative to the needs in the market. The best way to address that problem is using the latest cybersecurity platforms to automate as much vulnerability management on the secondary security alert and complement it with the scarce security analysts’ talent to identify and proactively fix the most critical high priority alerts in the enterprises.
  2. Long term, we need colleges and universities to focus on educating and graduating new security talent to help fill the void for small and large companies. Secondly, companies need to implement formal training programs to continue to educate and train their talented employees as the sector continues to evolve on a daily basis.

BP: Why do we see security startups flourishing in pockets like Israel?  What drives such communities?

Umesh: Israel is second only to the Bay Area for security talent and startups. Most of these entrepreneurs in Israel come from the Israeli Defense Forces, which has developed many sophisticated cybersecurity platforms for its defense industry. The mandatory military service for all Israeli residents has created a well-trained cybersecurity workforce. Combined with an incredible entrepreneurial culture and the “can do” attitude of the people, Israel has created amazing cybersecurity companies. As more and more companies exit over time, there will continue to be a large pool of security talent in Israel over the years. This talent, along with entrepreneurial risk and venture capital available in Israel, is why they are and will be a global force in cybersecurity.

BP: What about India? Do you see promising cybersecurity startups here? Can you comment on local talent?

Umesh: With over a billion people, India is very promising. The country’s cultural focus on education, combined with high-quality engineering schools like the IITs around the country, has educated a massive workforce of software and hardware professionals. They are a global force in software and technology development for enterprise software and have an entrepreneurial risk-taking culture as well. There are many CEOs at top cybersecurity and software companies in the U.S. who are of Indian origin and act as mentors. However, India does not yet have the DNA for cybersecurity and a skilled workforce to create a critical mass of talented entrepreneurs in cybersecurity. As more and more security companies open small offices and development centers in India, we see a bright future for cybersecurity startups in the next 3–5 years.

BP: What are the risks you see in cybersecurity startups and what kind of startups do you avoid?

Umesh: The cybersecurity market is massive and competitive; there are over 1,500 companies and over 18 subsegments in this space. Expect a few companies in each of the subsegments to break out and have a massive exit. The rest will either not succeed or will be sold for low to modest value. We look at companies with successful repeat or amazing new founders solving a major CISO pain point in a large market. But when you invest early in startups, it is all about team, team, team!


Brian PereiraAbout the Author

Brian Pereira is the Editor-in-Chief of CISO MAG. He has been writing on business technology concepts for the past 26 years and has achieved basic certifications in cloud computing (IBM) and cybersecurity (EC-Council).


References:

Securing Bytes to Prevent Bites in the Enterprise Network

4 in 10 Companies Expose Unsafe Network Services Online, network and security

Today, everywhere you turn, there are warnings about the surge in cybercrimes, as miscreants take advantage of the globe’s newfound dependence on the virtual world. This has also drawn attention to the breeding ground of cybercrime – the dark web. A haven for communication and exchange between cybercriminals, the dark web is easily accessible and owing to anonymization and digital currencies, a full-fledged economy is now looming on a global scale, right under the nose of law enforcement agencies.

By Sridhar S, Head of Managed Cloud and Security Services, Tata Communications

If you looked closer, this digital black market devotes a good chunk to trading stolen enterprise, financial, and personal information. Recently, a cloud-based instant messaging service provider became a victim of one such attack. The leaked data, which included personal information like user identities, phone numbers, and e-mail IDs, was eventually discovered on the dark web with most of it belonging to large enterprises, whose annual incomes run into hundreds of millions of dollars.

The ongoing and ever-shifting threat environment necessitates real-time monitoring and exposure scanning on the dark web for data leakage and attack anticipation, which can help an organization identify, assess, monitor, and respond to cyberthreats posted on the unregulated part of the internet.

But the bigger question here is that with employees across the world still working from home, how can enterprises mitigate security lapses on the network perimeter? Given the dark web’s sophisticated privacy and encryption techniques, traditional cybersecurity measures cannot promise substantial cyber safety. Consequently, enterprises must rethink their remote working solutions and implement better security controls and more stringent policies. For instance, putting in place zero-trust solutions can help them leverage micro-segmentation and limit remote users’ access to enterprise data based on their locations and other credentials. However, to do this, the zero-trust model relies on technologies, such as orchestration and multi-factor authentication. While multi-factor authentication can add extra layers of security and prevent cybercriminals from breaking into the enterprise’s network and stealing confidential data, orchestration is focused on integrating security tools and systems into an automated workflow. These automation tools issue an alert when new and relevant information emerges on the dark web, enabling the organization to determine which instance requires escalation and investigation. Further, automation tools can also help businesses to understand emerging malware and accordingly develop cybersecurity technology stacks.

Additionally, emerging machine learning and data analytics tools can also become strong weapons to provide early warnings on threats by enabling cyber-threat intelligence, which integrates a combination of open source and commercial threat providers.

However, as we look at the post-COVID-19 scenario, we can only expect digitization to grow dramatically across the globe, especially in India. This in turn will increase demand for cybersecurity and privacy regulations, which can play a critical role in creating a culture of compliance, addressing the current gaps, and providing a strong framework to handle issues related to cybersecurity. Along these lines, the Government of India has envisioned the National Cyber Security Strategy 2020, to focus on all areas of cybersecurity through its three key pillars – secure, strengthen, and synergize. Further, the Government of India has also initiated the setting up of the National Cyber Coordination Centre (NCCC) to generate awareness on potential threats on the dark web and other cybersecurity risks.

While the reality of the dark web can be unsettling, even scary, the security community must rethink its approach and come together to deal with cybercrime. Though endpoint protection can help to an extent, understanding the dynamic and nonlinear network mechanics can help disrupt the supply chain of tools between criminal groups. Until then, enterprises need to continually access the value of their confidential data and prepare their defense cybersecurity strategies accordingly.


About the Author

Sridhar S. heads the Managed Services businesses of Cloud, Hosting and Security for Tata Communications. He has been in the IT industry for nearly 30 years and has held several leadership roles in blue-chip companies such as Dell, IBM, Intel, and HCL, working across markets such as India, Asia, and the U.S. He is based in Bangalore, India.

DISCLAIMER

Views expressed in this article are personal. The facts, opinions, and language in the article do not necessarily reflect the views of CISO MAG.


Read Sridhar’s interview here.

 

Fortinet Fixes Four Critical Vulnerabilities in FortiWeb

Vulnerabilties

Fortinet, a cybersecurity solutions provider, has addressed four critical vulnerabilities in its FortiWeb web application firewalls. Tracked as CVE-2020-29015, CVE-2020-29016, CVE-2020-29019, and CVE-2020-29018, the vulnerabilities were discovered by Andrey Medov, a security researcher from Positive Technologies.

Vulnerability Details

  1. CVE-2020-29015This vulnerability exists in a blind SQL injection in the user interface of FortiWeb. The flaw, with CVSS v3.1 score 6.4, allows an unauthenticated, remote attacker to execute arbitrary SQL queries or commands by sending a request with a crafted authorization header containing a malicious SQL statement.

Affected Products

  • FortiWeb versions 6.3.7 and below
  • FortiWeb versions 6.2.3 and below

Fix

  • Upgrade to FortiWeb versions 6.3.8 or above
  • Upgrade to FortiWeb versions 6.2.4 or above 
  1. CVE-2020-29016The stack-based buffer overflow vulnerability, with CVSS v3 score 6.4, exists in FortiWeb, which allows a remote attacker to overwrite the content of the stack and potentially execute arbitrary code by sending a crafted request with a large certname.

Affected Products

  • FortiWeb versions 6.3.5 and below
  • FortiWeb versions 6.2.3 and below

Fix

  • Upgrade to FortiWeb versions 6.3.6 or above
  • Upgrade to FortiWeb versions 6.2.4 or above
  1. CVE-2020-29018A format string vulnerability, with CVSS v3 score 5.3, in FortiWeb allows a hacker to read the content of memory and retrieve sensitive data via the redir parameter.

 Affected Products

  • FortiWeb versions 6.3.5 and below

Fix

  • Upgrade to FortiWeb versions 6.3.6 or above
  1. CVE-2020-29019This is also a stack-based buffer overflow vulnerability in FortiWeb. The flaw, with CVSS v3 score 6.4, allows a remote hacker to crash the httpd daemon thread by sending a request with a crafted cookie header.

Affected Products

  • FortiWeb versions 6.3.7 and below
  • FortiWeb versions 6.2.3 and below

Fix

  • Upgrade to FortiWeb versions 6.3.8 or above
  • Upgrade to FortiWeb versions 6.2.4 or above

Fortinet issued fixes for all the vulnerabilities and urged users to install updates as soon as possible.

“The most dangerous of these four vulnerabilities are the SQL Injection (CVE-2020-29015) and Buffer Overflow (CVE-2020-29016) as their exploitation does not require authorization. The first allows you to obtain the hash of the system administrator account due to excessive DBMS user privileges, which gives you access to the API without decrypting the hash value. The second one allows arbitrary code execution. Additionally, the format string vulnerability (CVE-2020-29018) also may allow code execution, but its exploitation requires authorization,” said Medov.

Meet Kevin Fu – The FDA’s First Acting Director of Medical Device Cybersecurity

Kevin Fu

In December 2020, we reported a data leak that potentially exposed 45 million unique medical images due to unprotected servers. It exposed the increasing vulnerability of the health care industry towards the ever-rising cyberthreats. However, the U.S. Food and Drug Administration (FDA) has always been proactive in warning the health care sector about the potential threats in the past. Keeping up with their relentless pursuit of providing the best security standards to medical device manufacturers and owners alike, the FDA has now appointed Kevin Fu as the first acting director of medical device cybersecurity at its Center for Devices and Radiological Health.

Related News:

FDA Reveals Potential Vulnerabilities in Certain Medical Devices

More About the First Director

Kevin Fu has been an associate professor of electrical engineering and computer science at the University of Michigan since 2013. He also wears a badge of honor for being the Dwight E. Harken Memorial Lecturer and the founder of the Archimedes Center for Medical Device Security in his career, which spans over more than 20 years.

Fu has always been an advocate of bridging the gap between medicine and computer technology. He believes that the marriage of these two fields is inadvertent in today’s digital world. Looking at his resume and expertise in the associated field of medical device security, it is obvious why he is the most suitable candidate for the job. However, there was one more thing that could have added as brownie points in his selection – his stint as the Federal Advisory Board Member who advised the National Institute of Standards and Technology (NIST).

Fu worked for four years (from 2011 – 2015) with NIST and advised them, the Secretary of Commerce, and the Director of the Office of Management and Budget, on information security and privacy issues about the federal government’s information systems. His responsibilities included a thorough review of proposed standards and guidelines developed by NIST and annually addressing the congress about his findings.

Naturally, his experience of how government policies and agencies work, made him a perfect fit for the position.

Fu’s Immediate Plan of Action

In comparison to a decade ago, today’s medical devices are heavily dependent on computer software. However, Fu states that changing legacy device software is a huge task. And this is what the threat actors seem to be exploiting, as was evident in the recent spate of ransomware attacks on hundreds of hospitals. Thus, keeping the medical devices safe despite the growing cybersecurity risks is Fu’s top priority.

Fu, in an interview for his University’s publication, discussed the importance of building cybersecurity into the design of medical devices itself. He finds it amusing that legal experts, engineers, patients, and clinicians, are all considered as stakeholders, but “there simply is no software security expert at the table.

Fu also highlighted the importance of imparting security training to manufacturers of both IoT and medical devices. He said, “We are not providing the necessary level of security engineering training that companies need. Right now, though, I’m focused on medical device safety. I’m really looking forward to working at the FDA to help build public trust in the safety and effectiveness of medical devices despite the inherent cybersecurity risks.”

During his 12-month long appointment as the director, Fu shall retain his other positions and appointments, including his work at the University of Michigan.

Related News:

45 Mn Unique Medical Images Exposed Online via Unprotected Servers

Scammers Use Bots and Automation to Make Cyberattacks Effective

Cloud Security

Since organizations are working remotely, most IT and cloud security professionals globally are concerned about their cloud environment’s security. Besides, the security vulnerabilities created during the adoption of new access policies, networks, and devices used for managing cloud infrastructure remotely became a challenge for many organizations. Alternatively, cybercriminals too changed their attacking vectors by leveraging botnets and automation techniques to exploit victims’ cloud environments.

According to a report from Barracuda, a provider of cloud-enabled security solutions, threats actors are shifting to bots and automated attacks to evade threat detection tools.  Barracuda researchers analyzed a sample of global data on web application attacks and found a surprisingly high number of automated attacks reported across the world, especially in Asia-Pacific.

In automated attacks, cybercriminals use bots to exploit vulnerabilities in web applications. They often send web or mobile requests to the targets to perform malicious operations like sensitive data theft, compromise users’ login credentials, automated password reset, and account takeover attempts.

“These kinds of attacks are often used to retrieve sensitive data, and Barracuda researchers noted an overwhelming number of exfiltration attempts focused on stealing credit card numbers, with Visa being the clear focus, accounting for more than three-quarters of these attacks,” Barracuda said.

According to Barracuda, the top attack vectors that are deployed using automated tools include fuzzing attacks, injection attacks, fake bots, application distributed denial-of-service (DDoS), and blocked bots.

Fuzzing attacks, which use automation to break into applications, accounted for nearly 20% of attacks, followed by injection attacks at 12%, which sees hackers using automated tools like SQL map to access applications. Bots, pretending to be a Google bot or similar, also stood at 12%. Application DDoS attacks made up more than 9% of the sample across all geographies, followed by bots blocked by site admins, which accounted for just under 2%.

“Automated tools continue to advance in their level of sophistication, allowing even the most unsophisticated hacker with a convenient way to successfully steal valuable data from unsuspecting users. Our research shows that these attacks can take many forms, making it crucial to invest in a cloud-based solution that offers total application security to find and remediate vulnerabilities automatically. This, coupled with the right cyber awareness training for your team, will give you the best possible chance of staying protected against these evolving threats,” said Mark Lukie, Engineer Manager, Barracuda, Asia-Pacific.