Home Blog Page 122

Infamous Emotet Malware Campaign Disrupted in an International Action

Rootkits, Mobile Malware in Asia

Law enforcement authorities across Europe and judicial agencies worldwide have disrupted the operations of Emotet, an infamous malware strain that affected multiple organizations over the years. Dubbed “Operation Ladybird,” the international coordinated action has taken control of Emotet group’s infrastructure.

The operation is a collaborative effort between authorities in the Netherlands, Europe, Germany, the U.S., the U.K., France, Lithuania, Canada, and Ukraine, and carried out in the framework of the European Multidisciplinary Platform Against Criminal Threats (EMPACT).

The Emotet malware was linked to various other botnet-based cyber campaigns and delivered malicious payloads like TrickBot and Ryuk ransomware by renting its botnet to other cybercriminal groups. Industry experts said that the successful action would help various organizations and over a million Microsoft Windows systems that are compromised with Emotet malware.

“The infected machines of victims have been redirected towards this law enforcement-controlled infrastructure.  This is a unique and new approach to effectively disrupt the activities of the facilitators of cybercrime,” Europol said.

The Emotet operators mostly used malicious email attachments to distribute the malware into victims’ computers. Besides, the operators used a variety of phishing tactics to trick users into downloading malicious attachments. These attachments contained fake Word docs, macros, or malicious links, either attached for download or in the email text. Once a user clicks the link or downloads the attachment, the Emotet malware code hidden in the Word file installs automatically on the victim’s device.

“Emotet was much more than just a malware. What made EMOTET so dangerous is that the malware was offered for hire to other cybercriminals to install other types of malware, such as banking Trojan or ransomware, onto a victim’s computer. This type of attack is called a ‘loader’ operation, and Emotet is said to be one of the biggest players in the cybercrime world as other malware operators like TrickBot and Ryuk have benefited from it. Its unique way of infecting networks by spreading the threat laterally after gaining access to just a few devices in the network made it one of the most resilient malware in the wild,” Europol added.

Google Chrome OS Update: No Passwords, Only Fingerprint Required

Google WebAuthn, Google, WebAuthn, web authentication
Image Credit: Google

WebAuthn, or web authentication, which has been regarded as an official web standard since 2019, has finally been introduced for passwordless authentication on Chromebooks. Using this, users can sign into their favorite websites, including Google, Dropbox, GitHub, Okta, Twitter, and Microsoft, by simply scanning their fingerprint that is registered to unlock their Chromebook. Alternatively, users can also use a PIN.

What is Google’s WebAuthn?

WebAuthn primarily allows users to register and authenticate on websites or applications using any “authenticator.” This authenticator could be a fingerprint or PIN, which can be easily used instead of a password. However, the catch is that you need a fingerprint scanner/reader to do this in the first place. Thus, Google has come up with a smart solution of using the fingerprint reader of a Chromebook to scan users’ fingerprints; match it with the one saved to unlock the Chromebook, and allow users to sign in.

Today, when remote working is at an all-time high and the uptake of Chromebooks, especially among students, is breaking the roof, Google’s WebAuthn feature will let its users breathe a sigh of relief. It lessens the burden of remembering multiple passwords and makes web sign-in faster and easier.

Alexander Kuscher also confirmed that if users “use 2-Step Verification to sign-in, your Chromebook PIN or fingerprint ID can be used as the second factor, so you no longer need to pull out your security key or phone to authenticate.

Personalize Your Lock Screen

Apart from the web authentication feature, Google has also allowed its users to add their personal touch to the lock screen. It has turned the screen into an art display where users can add their favorite photos or albums from Google Photos or the device gallery. Additionally, this screen can also be used to check the current weather and control music functions like play, pause, or skip, all without unlocking the device. To turn ON this feature, go to your Chrome OS Settings and select Personalization > Screen saver.

How to Get the Latest Chrome Update

To get the latest version of the Chrome OS installed on your device, follow these simple steps:

  1. On your computer, open Chrome.
  2. At the top right, click More.
  3. Click Update Google Chrome. (Note: If this button is not visible, then you have the latest version installed already.)
  4. Click Relaunch.

Incidentally, Chrome 88 also has a feature that allows fixing weak passwords for better online security. Read the story here: Google Chrome 88 To Fix Weak Passwords for Better Online Security

Preach and Practice Data Privacy Every Day

personal data collection, Personal data. Data Privacy

The National Cyber Security Alliance (NCSA) continues to raise awareness on the significance of data security and privacy with its annual Data Privacy Day, which is observed on January 28 every year. This year, the NCSA kickstarted the Data Privacy Day 2021 as an international effort to empower users with the theme: “Own Your Privacy” and encourage businesses to “Respect Privacy” for safeguarding data and enabling trust.

By Rudra Srinivas, Senior Feature Writer, CISO MAG

Data Privacy Day aims to encourage individuals to take control of their personal data, as most users are unaware or uninformed about how their personal data is being used, collected, and shared by technological companies.

Why Data Privacy is Important?

Most users are concerned about the lack of control over their personal information online, which is vulnerable to data and identity theft. Most people are uninformed about how much of their private data is online and how it is obtained without their consent. According to the Pew Research Center study, 79% of U.S. adults reported being concerned about the way their data is being used by companies. Nearly 81% feel they have little or no control over how organizations use their personal information.

How to Enhance Your Data Privacy Online?

Your sensitive information is worth a lot to cybercriminals. Private data such as geolocation, purchase history, IP address, full names, birthdates, and other personally identifiable information has tremendous value on the darknet, where several hackers trade databases stolen from users. That’s why Own Your Privacy by firmly deciding whether or not to share your sensitive info with certain online services.

1. Limit Your Data on Social Media

Never overshare your personal information on social media. Cybercriminals often target popular social networking sites such as Facebook, Twitter, and Instagram to phish users and illicitly steal your data. Many online services ask for access to your personal info like your geographic location, contacts, and images even before using their services. Be mindful while giving such access permissions if you are not sure about their security practices. Log out or completely delete your social handles if you are no longer using their services.

Related story: How to Report and Regain Access to Your Hacked Facebook Account
2. Manage Your Privacy

Cross-check the privacy and security settings on the websites, apps, social media handles, and other online services you use for information sharing priorities. Each service will have its data sharing policy. So, make sure to learn what information the service is obtaining from you and with whom it is sharing it. Review or change your privacy and security settings using NCSA’s Manage Your Privacy Settings page. Use the direct links provided on the page to update your privacy settings on almost all popular online services.

3. Browse Private

If you don’t want others to trace your browsing history, surf in private mode. Every web browser has its version of the privacy protection feature. In Firefox, this service is available as Private Browsing; in Google Chrome it is called Incognito Mode; and in Internet Explorer, it is InPrivate Browsing. These privacy features won’t save your browsing history, temporary internet files, and cookies from your device.

4. Use a VPN

A Virtual Private Network (VPN) helps improve your data privacy and security online by providing a secure connection when joining different networks. VPN changes your IP address and location details, making your browsing activity safe and private from cybercriminals. Even if attackers penetrate your network, they still cannot compromise/access your data when a VPN is active on your device.

Conclusion

Data privacy is the most influential factor in determining the safety of digital systems. The unexpected crisis from the pandemic made people across the globe connect virtually more than ever before. Users are sharing more personal data via connected devices, allowing third parties to inevitably collect and store users’ data. Every form of data is sensitive and can be illicitly used for malicious operations such as launching social engineering attacks. Adhering to regulatory compliance may seem tough, but not impossible. Remember, practicing data privacy is as important as preaching!


About the Author

 

Rudra Srinivas is a Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.

How Does GDPR Regulation Help in Data Protection and Data Privacy?

General Data Protection Regulation Act is a popular and widely accepted EU law that is concerned with the data protection and privacy of citizens of the EU. It is said to be the most stringent data security and privacy law enforced by the EU enforcement directives. Organizations that are subjected to the Regulation need to understand the significance of the two broad categories of compliance, namely Data Protection and Data Privacy for its successful implementation.

By Narendra Sahoo, Founder and Director of VISTA InfoSec

This article covers details on how the GDPR Regulation facilitates data protection and data privacy of citizens of the EU. The article will briefly shed a light on the regulation and explain how Data Protection and Data Privacy are interrelated.

Data Protection and Data Privacy: How are they different yet inter-related

More than often, organizations believe that by securing their sensitive data they are also covered for the data privacy regulation. But, that is not the case. Data Security and Data Privacy are often interchangeably used and has often led to the ignorance of implementing necessary measures to cover both the essential aspects of the Regulation.  It is critical that your business understands the difference and addresses the two individually or it will have a significant impact on your business.

Data Privacy is a part of the broader spectrum of Data Protection, which is concerned with secure processing, storing, and management of sensitive data. So, while data protection ensures securing of data from unauthorized access, data privacy is about empowering individuals of their privacy rights. Data Security protects sensitive data against external attackers and malicious insiders, but Data Privacy governs how the data is collected, shared, and used considering the individual’s consent for the same. The table will precisely outline the differences between Data Privacy and Data Security.

Data Security vs. Data Privacy

Data Security

Data Privacy

Data security focuses on protecting sensitive data against unauthorized access and use. Data Privacy focuses on ensuring appropriate handling processing, storage, and use of Personal Information and defines who has the authorized access permission
It is more about protecting the integrity of the data and ensuring data accuracy, reliability, and availability to authorized parties. It is about the rights of individuals with respect to their personal information.
Data security is for any kind of sensitive data be it personal, financial, or any confidential information. Data privacy is more about securing the personal information of an individual.
Data security is the responsibility of the organizations handling and using the data. The control of data privacy is in the hands of individuals who can decide on how their data can be used or shared.
Data protection aims at securing information from hackers. Data privacy aims at securing the data from being shared or sold without the individual’s consent.
Data protection is a mechanism to secure sensitive data against hack or theft. Data Privacy is a regulation comprising of policies and procedures that helps govern the data.
Data security may not necessarily include data privacy. Data Privacy cannot be achieved without data security.

 

Basically, Data protection is an amalgamation of security measures and privacy policies. Now that we have covered the key differences between Data Security and Data privacy, let us move on to understand GDPR Regulation and learn how it helps in data protection and data privacy.

GDPR Regulation

General Data Protection Regulation Act is a law that aims at securing the data and privacy of citizens of the EU. It is a Privacy law that has a direct impact on businesses around the world dealing with sensitive data of EU citizens. GDPR mandates standards for companies that handle EU citizens’ data to safeguard the processing and movement of citizens’ personal data. The regulation clearly outlines certain requirements pertaining to data protection and data privacy for organizations to follow. All organizations falling in the ambit of the regulation be it, small businesses to large enterprises, must be aware of all the data privacy and security requirements of GDPR and accordingly comply with it. Moving ahead, let us now understand what the GDPR says about Data Security and Data Privacy.

GDPR Regulation on Data Protection

If your organization falls under the ambit of GDPR Regulation your organization is expected to meet the requirements as stated in the protections and accountability principles outlined in Article 5-6:

Lawfulness, fairness, and transparency – The requirements outlined in the GDPR Regulation clearly states that the processing of data must be done fairly, lawfully, and with complete transparency.

Purpose limitation – The article also clearly states that the organization must process data for the legitimate purposes specified explicitly to the data subject when you collected it.

Data minimization – Organizations are expected to collect and process only as much data as absolutely necessary for the purposes as specified.

Accuracy of Data – As per the stated requirements, organizations are expected to keep personal data accurate and up to date.

Data storage limitation – Organizations are allowed to store personal data for only as long as necessary for the specified purpose.

Integrity and Confidentiality of Data – The data collected must be processed in a way that ensures appropriate security, integrity, and confidentiality of information. This can be achieved by adopting the technique of encryption.

Accountability – The data controller is responsible for demonstrating compliance with all of the standard requirements set in the GDPR Regulation.

GDPR Regulation on Data Privacy

The GDPR Regulation also lays out Data Privacy rights and principles for organizations to follow when processing the personal information of citizens of the EU. Articles 12-23 in Chapter 3 clearly draws out principles that the organizations are obliged to facilitate data subject rights.

Right to Transparency in information, and communication for exercising data subject rights Organizations are expected to communicate in a concise, transparent, intelligible, and easily accessible form, using clear and plain language on how the data is processed. Further, organizations are expected to inform and make it easy for people to make access requests, rectify, erase or restrict the processing of data.  Organizations are expected to respond to those requests quickly and adequately.

Right to be informed Data Subjects have the right to be informed about where their personal data is collected from, how they are processed, and to whom they are shared.

Right to access Data subjects have the right to access information pertaining to their personal data from the controller. The type of information that can be accessed may include the category of personal data, the purpose of processing data, source of collected data, location of storing data, or duration of storing data to name a few.

Right to rectification – The data subject has the right to demand rectification of inaccurate information of their personal data without any undue delay.

Right to erasure The data subject has the right to demand the erasure of their personal data without any undue delay. This would include also the right to withdraw their consent of processing data at any point of time considered appropriate by the data subject.

Right to restrict processing of data – The data subject has the right to restrict the processing of data in the pretext of them processing inaccurate information, illegal purpose, or processing beyond the original purpose specified.

Right to data portability – The data subject has the right to receive their personal data in a structured, commonly used, and machine-readable format. They further hold the right to transmit those data to another controller without hindrance from the controller who currently has it.

Right to object – The data subject has the right to object the controller from collecting or processing your personal data. However, the controller can override the objection by providing a legitimate basis for using the data

Right to notification obligation – Based on the data subject’s right to restrict, object, or erasure of their personal data, the controller is obliged to notify and ensure the requests are met by the third-party with whom they have shared the information.

Right to object automation of decision – The data subject has the right not to be subjected to an automated decision of processing, including profiling, which have a legal effect on him or her.

For more details on the Data security and privacy rights outlined in the GDPR Regulation, you can refer to the link https://gdpr.eu/tag/chapter-3/

Conclusion

Considering the growing concerns of Data Security and Privacy in the industry, the GDPR Regulation was established and enforced across the EU. With its far-reaching implications on businesses globally, organizations are now expected to implement the best practices to ensure Data Security and Privacy of personal information. The purpose of imposing the regulation is to ensure consistency in the data protection and privacy laws across the EU and for organizations globally, if applicable to them. The enforcement of the regulation has surely had a positive impact on the cybersecurity industry, ensuring the implementation of the industry’s best privacy law for securing data.


About the Author

Narendra SahooNarendra Sahoo (PCI QSA, PCI QPA, CISSP, CISA, and CRISC) is the Founder and Director of VISTA InfoSec, a global Information Security Consulting firm, based in the U.S., Singapore, and India. Sahoo has more than 25 years of experience in the IT Industry, with expertise in Information Risk Consulting, Assessment, and Compliance services.

DISCLAIMER

Views expressed in this article are personal. The facts, opinions, and language in the article do not necessarily reflect the views of CISO MAG.


Related story: What the Experts Have to Say on this Data Privacy Day

What the Experts Have to Say on this Data Privacy Day

On this day in 2007, the Council of Europe first initiated the European Data Protection Day. A day to raise awareness about the best practices in cybersecurity, data protection, and data privacy. In the ensuing years, the U.S. Senate passed Resolution 25 to recognize the day as National Data Privacy Day. Ever since then, several nations across the world have observed January 28 as Data Privacy Day.

With the emergence of several social networking platforms, there was a renewed interest in the sphere, and most countries observed this day toward a better focus on protecting information online.  The focus on privacy was further expanded toward families, consumers, and, most importantly, businesses. Down the line, the Data Privacy Day marked a beginning for better cybersecurity awareness across the world — for devising privacy policies and compliance norms.

The theme for this year’s Data Privacy Day is “Own Your Privacy,” a departure from the earlier ill-thought analogy of “I don’t care about privacy. I have nothing to hide.” Reports and surveys indicate that several people feel there is an increasing lack of control over their data. To shed light on the topic and to build better cybersecurity awareness, CISO MAG has gathered opinions from infosec leaders across the world. Take a look:

1. Data is the lifeblood

“Data is the lifeblood of most modern companies, and the long-term negative impact on those who suffer breaches demonstrates just how serious the issue of data loss has become today. And for those of us who are now working from home, the threat level posed by the blurred lines of using personal devices to respond to work emails, or using our work laptops to buy something online, has increased exponentially.

With such a high volume of data flowing in and out of businesses every day, effective data protection strategies must embrace the following: visibility to all data, all the time; analytics to understand and manage risk; controls to enforce data protection policies; and a consolidated view into all threats targeting sensitive data.

Taking a comprehensive approach while implementing cybersecurity controls is imperative for protection, especially when it comes to sensitive and valuable customer or financial information. Fundamentally, what we’re talking about here is no-compromise data protection for your no-compromise organization.”

2. Securing Access to a Broader Data Landscape Is Not Without Its Pitfalls

“Public health breakthroughs rarely happen in a silo. Researchers crave access to any and every piece of relevant data available, especially in the midst of a pandemic. Access to real-time data from disparate, global sources can help public health officials advance critical decisions when every moment counts. However, securing access to this broader data landscape is not without its pitfalls. The sensitivities associated with these assets dictate that additional access cannot come at the expense of privacy and security.

While discussions on data sharing have been taking place in the health care industry for years, COVID-19 has notably advanced the conversation, especially as it pertains to sharing sensitive information on a global scale. The pandemic has made it clear that we need to be able to share public health data quickly and efficiently without tearing down the existing regulatory frameworks put in place to protect the privacy of the individual.

This search for balance is increasingly leading towards the use of privacy-enhancing technologies (PETs), which are gaining recognition for their transformational ability to enable and preserve data privacy throughout its processing life cycle. By giving public health officials involved in the fight against COVID-19 access to data collected and generated by health care workers and researchers around the globe, PETs can enable collaborative health care efforts with the potential to benefit us all.”

3. Other Countries Are on Their Way Too

“In our new digital economy, people around the world are becoming acutely aware of how their information is being collected, stored, and used. The GDPR ushered in a new paradigm that elevated awareness about the importance of privacy and the exploitation of data. Some of the largest countries around the world have responded by enacting or augmenting their privacy protections to closely mirror the GDPR. We see this in Brazil and recently in California through the recent passage of California Privacy Rights Act (CPRA). Other countries are on their way too. Steps are being taken in India, China, and Canada, to potentially modernize and augment their data privacy rights and protections.

 With stricter data privacy enforcement and consumers empowered to act on their rights, companies must be prepared to deploy technology and aggressively operationalize their data privacy programs to meet the most stringent standards. Beyond potential fines, any organization that fails to comply with data privacy laws risks breaking trust with their customers. By investing in comprehensive privacy management capabilities underpinned by information governance and automation, organizations can achieve data protection by design and default – satisfying regulatory requirements, avoiding non-compliance penalties and more importantly, maintaining customer trust.”

4. Data Privacy Has Become an Urgent Priority

“We live in a world where people rely heavily on mobile apps and the internet for many of their daily tasks. This trend has accelerated since last year, owing the pandemic, with people preferring to work from the safety of their homes. Increased usage and dependency on mobile devices create more opportunities for cybercriminals to steal user data. Data privacy has therefore become an urgent priority today.

Personally Identifiable Information (PII) such as medical records, bank details, passwords, phone numbers, and email IDs are most commonly targeted by cybercriminals. While organizations and the government are investing increasing amounts of money to safeguard the personal data of customers and consumers, it is also important for us to take proactive steps at an individual level to secure our data and our devices. Some of the simplest ways to do this are to use strong passwords; avoid using public Wi-Fi; watch out for phishing emails; regularly back up important data, and keep all apps and operating systems on our devices up-to-date. With the evolving cybersecurity landscape, it has become imperative for us as individuals to invest in a robust multi-device security to ensure digital safety for us.”

5. Data Is the New Oil

“The analogy of ‘data is the new oil’ has quickly become the defining metaphor in this digital age. Although data is deeply integrated into the functioning of online collaboration tools and modern cloud architectures, the risk of theft and exfiltration looms higher than ever as most employees work remotely on unsecured home networks. With cybercriminals getting creative to steal users’ personal information, data privacy and security have become elemental in this new reality.

With no overarching framework or a unified approach to data privacy, it all boils down to ensuring the right levels of protection, access control, and encryption for the right data. As industries rally under the seismic shift to digitalization, businesses need to go above and beyond to cultivate digital trust and adopt a robust cybersecurity posture to help consumers exercise their rights to data privacy. Adopting a threat-aware network built on a combination of ethical, compliant and privacy-preserving principles, and driven by AI assisted automation will be key to scale for the future.”

6. Review and Refresh Your Privacy and Data Protection Practices

“Data Privacy Day is an annual reminder to review and refresh your privacy and data protection practices. As cyberthreats become more vicious and regulations more complex, organizations must evolve how they protect the personal data of their employees and customers. An effective data privacy policy will safeguard from GDPR and CCPA fines and build trust with customers who are wary of how organizations handle their data.

On this Data Privacy Day, don’t just try to ‘get well’ on your protection policy, but plan how to ‘stay healthy.’ Over the next year, data will fuel your business growth, and protecting data privacy will help you build a company that your customers trust. To keep pace with the business, you must integrate data privacy and protection into your organization’s data management strategy because it takes only one wrong step to lose the customers’ trust. Data Privacy Day only comes once a year, but data protection matters every day. With an integrated approach to data protection and privacy, next year’s Data Privacy Day will be a reminder to celebrate your successes!”

7. Data Privacy Day Serves as an Important Reminder

“In the wake of COVID-19, remote work, cybersecurity concerns, and the high-profile SolarWinds hack, we’ve seen security elevate in importance, and the protection of sensitive data has become more of a shared responsibility across the company. Organizations are realizing that IT and security teams aren’t the only ones with something to lose in the event of a breach; the whole business is at stake. The board doesn’t want to risk a security breach or be found negligent based on a lack of investment in security.

With more and more companies experiencing breaches and people’s personal information being shared with so many businesses, Data Privacy Day serves as an important reminder for organization leaders to acknowledge their shared responsibility for cybersecurity and effective data protection across the entire business. For companies that aren’t currently operating in this way, it is time for them to take a step back and make a plan to prioritize it in 2021.

For consumers, it is time to develop a better understanding of how companies are using their data. Just a few weeks ago, WhatsApp updated its privacy policy to state that the company reserves the right to share data such as phone numbers, IP addresses, and payments made through the app with Facebook and other Facebook-owned platforms like Instagram. Consider this: if it’s free or low priced, then you (and your information) are the payment.

As we’ve seen with the recent additions and revisions to the California Consumer Privacy Act (CCPA), a U.S. privacy statute that governs residents of California, states are beginning to place more stringent requirements on themselves and businesses operating within their borders to protect their residents’ data. While there is currently no federal data privacy law in the U.S. that compares to the European Union’s General Data Protection Regulation (GDPR), we can expect to see more states step up to lead change in privacy policy in 2021 and beyond that ultimately could influence federal privacy laws.”

8. Online Privacy is in its Lowest Point Ever

“It isn’t a secret that online privacy in 2020 is in its lowest point ever; we carry around tracking devices, self-report our activities and have given blanket permissions to both governments and corporations to access what we shop for, what we search for and who we communicate with.

This isn’t a technology problem – the Internet allows distributed, anonymous communication and there are various layers of anonymous communication protocols we can use (which is why terrorists can use those same applications without worry), but blaming the average user for choosing convenience over privacy is the wrong way to go about it. The actual blame lies with us, IT security professionals. We got distracted, got addicted to the simplicity of some of these services and often focused on security when we should have also insisted on privacy. Fortunately, the last few months were a multi-stage wakeup call; we now need to use this momentum to change the standards: it falls on us, security professionals, to give normal users the tools protect their privacy; we’ve done a reasonably good job with getting the average user more secure over time (though there’s still a long way to go), we now need to do the same with privacy. With some luck, 20 years from now online privacy will increase the way that online security has increased dramatically from 2000 to 2020. It’s on us, security professionals, to get it right. “

Data Privacy Day 2021: 5 Tips to Secure Your Sensitive Data

The National Cyber Security Alliance (NCSA) observes its annual Data Privacy Day on January 28, 2021, highlighting the state of the global data privacy landscape. This year, the NCSA is leading the Data Privacy Day 2021 as an international effort to empower users to “Own Your Privacy” and encourage businesses to “Respect Privacy” for safeguarding data and enabling trust.


To mark the same, Nir Chako, the security research team leader at CyberArk, has recommended security measures for individuals to enhance their data privacy online.

 


1. Update Your Router

Cybercriminals can easily break into home networks by exploiting vulnerabilities in out-of-date firmware on Wi-Fi routers. Outdated firmware often contains multiple unpatched flaws that can be easily exploited by hackers, so it is important to keep it regularly updated. Making sure your router is up-to-date not only reduces the risk to your personal information and devices on your home network, but also helps safeguard against attacks on your employer that might inadvertently come via your home network.

2. Update Your Device

The proliferation of working made us more vulnerable to cyberthreats. Cybercriminals targeted the remote workforce, trying to exploit loopholes in the corporate networks to break into employees’ work devices and eventually pilfer sensitive corporate data. Updating work devices (laptop or desktop computers) and activating anti-virus software on them helps defend against unauthorized intrusions. Whether you have Windows Defender or security software from a third-party, make sure that the antivirus you are using is active and updated with the most recent security fixes, so you are best placed to proactively identify and rectify any security issues before data becomes at risk.

3. Think Before You Click

Users must be vigilant about threat actors misusing the User Access Control (UAC) feature while installing a new program or software. UAC can be used for malicious purposes. It asks the users whether they want to change something on their computer by manifesting itself as a pop-up tool window. This feature is often spoofed by attackers to either install malware or steal credentials to infiltrate an employee’s device or a company’s corporate network. When permission is granted, the software is allowed access to a user’s computer. If in doubt, do not do it, and flag any suspicious activity to your company’s security team.

4. Avoid Malicious URLs

Cybercriminals often use malicious URLs to phish users into giving login credentials or other sensitive information. Malicious URLs are specially crafted links that host viruses and malware that could infect users’ devices or redirect users to fake login pages to pilfer private data. These types of URLs are a constant threat to both personal and business devices but are easy to avoid. Be wary of clicking on something unexpected or use security services to check the safety of files and weblinks before you visit them.

5. Secure Your IoT Devices

The proliferation of the Internet of Things (IoT) in consumer, health care, and other enterprises, and their internal vulnerabilities, has created a security blind spot where adversaries can launch Zero-day attacks to break into connected devices like smart TVs, webcams, routers, printers, and even a smart home. IoT devices are Wi-Fi-enabled and, if compromised, can be used to access data, credentials, and passwords from other areas of our home networks — to steal information or plant malicious software. Never use easy-to-guess or weak passwords for your connected devices. Also, make sure to update them often to fix known and unknown security flaws.

Cybercriminals continue to innovate their hacking techniques and never miss a chance to exploit a vulnerable resource. When it comes to safeguarding critical data, it is our responsibility to secure all the endpoints and networks against online intruders.

On Data Privacy Day, Acronis Forecasts Critical Privacy Risks for 2021

Acronis, data privacy, data security, data privacy day, data privacy day 2021, critical privacy risks in 2021, critical privacy risks, privacy issue, privacy day, data privacy and security, International Data Privacy day, Acronis Cyber Protection Operations Centers, CPOC, password compromise, SolarWinds attack, SolarWinds Hack, cybercriminals, financial and reputational risks, Zero trust model, brute force attacks, password stuffing,

Ahead of International Data Privacy Day 2021, Acronis, a cybersecurity solutions provider, issued a warning that organizations around the globe will face even more critical data privacy and security threats in 2021. Based on the research of recent cyberattack trends and existing business practices, the company’s researchers have alerted organizations to take immediate action to avoid costlier attacks and severe repercussions.

The Findings

Researchers from the Acronis Cyber Protection Operations Centers (CPOCs) found a glaring fact that 80% of companies do not have an established password policy. Additionally, their analysis also uncovered that 15-20% of the passwords used in a business environment include the name of the company itself, making it easier to crack.

Two recent high-profile breaches illustrate this problem. Before its Orion IT Management software’s compromise, SolarWinds was warned that one of its update servers had a publicly known password of “solarwinds123,” while former President Donald Trump’s Twitter account was hacked because the password was alleged “maga2020!”.

Of the organizations that do have a password policy in place, the researchers found that many rely on default passwords, and up to 50% of those are categorized as weak. With the ongoing COVID-19 pandemic and employees are working remotely, attackers are targeting these weak password practices.

Related News:

CISO MAG Market Trends Report on Data Security – 2020

Concurrently, researchers also observed a dramatic increase in the number of brute force attacks during 2020, and found that password stuffing was the second most used cyberattack last year, just behind phishing.

Candid Wüest, VP of Cyber Protection Research at Acronis, explained, “The sudden rush to remote work during the pandemic accelerated the adoption of cloud-based solutions. In making that transition, however, many companies did not keep their cybersecurity and data protection requirements properly in focus. Now, those companies are realizing that ensuring data privacy is a crucial part of a holistic cyber protection strategy – one that incorporates cybersecurity and data protection – and they need to enact stronger safeguards for remote workers.”

Financial and Reputational Risks

While the businesses are realizing the need to ensure the privacy of their own and their customers’ data, a lag in awareness among digital users remains. A recent report stated that 48% of employees admit they are less likely to follow safe data practices when working from home.

Experts believe that poor password hygiene and lax cybersecurity habits of remote workers could lead data exfiltration to soar in 2021. Threat actors will primarily be interested in accessing and stealing valuable company data. The trend is like the one seen among ransomware attackers, who are stealing proprietary or embarrassing data and then threatening to publish it if the victim does not pay. Last year, Acronis identified more than 1,000 companies around the world that experienced a data leak following a ransomware attack.

Implementing Stricter Authentication

To avoid costly downtime, significant reputational damage in the marketplace, and steep regulatory fines caused by a data breach, organizations must strengthen the authentication requirements needed to access company data.

Acronis and other cybersecurity experts recommend the following practices for better security:

  • Multi-factor authentication (MFA), which requires users to complete two or more verification methods to access a company network, system, or VPN, should be the standard for all organizations. By combining passwords with an additional verification method, such as a fingerprint scan or randomized PIN from a mobile app, the organization is still protected if an attacker guesses or breaks a user’s password.
  • A Zero Trust model must be adopted to ensure data security and privacy. All users, whether they are working remotely or operating inside the corporate network, must be required to authenticate themselves, prove their authorization, and continuously validate their security to access and use company data and systems.
  • User and entity behavior analytics, or UEBA, helps automate an organization’s protection. By monitoring the normal activity of users with AI and statistical analysis, the system can recognize behavior that deviates from normal patterns – particularly those that indicate a breach has occurred and data theft is underway.

On Data Privacy Day 2021, Acronis has released the Acronis Cyberthreats Report. Refer to the report for detailed information on other threats and trends to look out for in 2021.

Related News:

Federated Learning Can Solve Security and Data Privacy Challenges: Intel Labs

Cisco Fixes Multiple Vulnerabilities in its SD-WAN Products

Cisco Vulnerabilities

Networking and hardware company Cisco asked its users to update their networking software immediately, citing critical security vulnerabilities in its products, including software-defined networking for wide-area networks (SD-WAN), Dynamic Network Analysis (DNA), and the Smart Software Manager Satellite. Cisco stated that these vulnerabilities are critical and need immediate action.  Threat actors could exploit the flaws to launch command injection attacks and take over the root privileges on the affected devices.

Affected Devices

  • IOS XE SD-WAN Software
  • SD-WAN vBond Orchestrator Software
  • SD-WAN vEdge Cloud Routers
  • SD-WAN vEdge Routers
  • SD-WAN vManage Software
  • SD-WAN vSmart Controller Software

 Multiple Vulnerabilities

Multiple Command Injection vulnerabilities tracked as CVE-2021-1260, CVE-2021-1261, CVE-2021-1262; and Buffer Overflow vulnerabilities CVE-2021-1300, CVE-2021-1301 in Cisco SD-WAN products could allow a remote attacker to execute attacks on compromised devices.

  • CVE-2021-1260 – This is a Command Injection vulnerability in the CLI of Cisco SD-WAN Software that could allow an authenticated, local attacker with read-only credentials to inject arbitrary commands. These arbitrary commands could allow the attacker to obtain root privileges and read, write, and delete files of the underlying file system of an affected device.
  • CVE-2021-1261- This Command Injection vulnerability in the CLI utility tcpdump of Cisco SD-WAN Software could allow an authenticated, local attacker with read-only credentials to inject arbitrary commands that could allow the attacker to obtain root privileges.
  • CVE-2021-1262- The vulnerability exists in the CLI of Cisco SD-WAN Software and could allow an authenticated, local attacker with read-only credentials to inject arbitrary commands.
  • CVE-2021-1300- A Buffer Overflow vulnerability in Cisco SD-WAN Software could allow an unauthenticated, remote attacker to cause a buffer overflow condition.
  • CVE-2021-1301- Another Buffer Overflow flaw in the NETCONF subsystem of Cisco SD-WAN Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device or system.

Cisco has released security updates to fix all the vulnerabilities, as there are no workarounds to address these flaws.

“The vulnerabilities are not dependent on one another. The exploitation of one of the vulnerabilities is not required to exploit the other vulnerability. In addition, a software release that is affected by one of the vulnerabilities may not be affected by the other vulnerability,” Cisco said.

Phone Numbers of 533 Mn Facebook Users on Sale via Telegram Bot

Facebook copyright complaint

Facebook’s nearly 533 million users from over 100 countries are at risk of being targets of malicious activities. A vulnerability discovered earlier allowed a notorious threat actor to create a database of Facebook users along with their phone numbers, which are now being sold on Telegram via a bot. The security researcher Alon Gal, who made this finding public on his Twitter handle, highlighted that this has a “huge impact on privacy.”

Not the First Time

In 2019, Facebook was marred with a similar incident where it exposed 419 million records from across the globe. It included users’ unique Facebook IDs and phone numbers linked to their accounts. It was due to a lapse in Facebook’s security since no password-protection was provided to the said database, which the social media giant fixed later. However, a Guardian report stated that Facebook was trying to downplay the impact of the breach considering the socio-political pressure it was under, especially from the EU post the Cambridge Analytica spill-out.

Related News:

Unprotected Database Exposes Millions of Facebook users’ Contact Numbers

Gal claimed the same in the latest incident. He stated that the database was compiled by the Telegram bot operator in early 2020 when a vulnerability was discovered by security researchers that exposed the phone numbers of Facebook users. The said vulnerability no longer exists because it was patched by Facebook, but it could be downplaying the actual extent of the number of affected users since there is a growing discontent against the social media giant’s data-sharing privacy policy, which it has currently put on hold.

The Telegram Bot

The threat actor who compiled this database has only come to the reckoning because of a Telegram bot. This bot allows users to input a query to its database for a minimal fee of $20. According to an interview given to Motherboard, Gal said the threat actor also had a bulk offer running where 10,000 credits were being offered for $5,000. Interested people can pay the sum and either input a Facebook ID or the phone number to find details.

It is worth noting that not all phone numbers might be valid since these were collected almost a year ago; however, since people do not change mobile phone numbers often, a large portion of these Facebook users are still vulnerable.

Related News:

How to Report and Regain Access to Your Hacked Facebook Account