Home Blog Page 134

Irish Data Regulator Fines Twitter $547K for 2019 Data Breach

PM Modi Twitter

Seems like Twitter’s is ending 2020 on a bitter note! From multiple data breaches to a series of celebrity account hacks, the social networking giant suffered multiple challenges in 2020. And the latest fine from Ireland’s data regular adds to its woes. On December 15, the Irish Data Protection Commission (DPC) fined Twitter €450,000 ($547,000) as an “effective, proportionate, and dissuasive measure” for a data breach that occurred in January 2019. The data leak was a result of a vulnerability that made users’ private tweets public.

The DPC’s investigation found that Twitter infringed Article 33(1) and 33(5) of the GDPR guidelines by delaying notifying the breach on time to the authorities.

“The draft decision in this inquiry, having been submitted to other Concerned Supervisory Authorities under Article 60 of the GDPR in May of this year, was the first one to go through the Article 65 (dispute resolution) process since the introduction of the GDPR and was the first Draft Decision in a big tech case on which all EU supervisory authorities were consulted as Concerned Supervisory Authorities,” the DPC said in a statement.

As per the GDPR guidelines, organizations are required to notify about any data breaches, to the respective data regulators, within 72 hours after becoming aware of the incident. It is also mandatory for data breach victims to document what data has been compromised and how they responded to it.

Twitter Says…

Commenting on the data breach fine, Twitter’s Chief Privacy Officer Damien Kieran said, “Twitter worked closely with the Irish Data Protection Commission (IDPC) to support their investigation. We have a shared commitment to online security and privacy, and we respect the IDPC’s decision, which relates to a failure in our incident response process. An unanticipated consequence of staffing between Christmas Day 2018 and New Years’ Day resulted in Twitter notifying the IDPC outside of the 72-hour statutory notice period. We have made changes so that all incidents following this have been reported to the DPC in a timely fashion.

We take responsibility for this mistake and remain fully committed to protecting the privacy and data of our customers, including through our work to quickly and transparently inform the public of issues that occur. We appreciate the clarity this decision brings for companies and consumers around the GDPR’s breach notification requirements. Our approach to these incidents will remain one of transparency and openness,” Kieran added.

Microsoft and FireEye Create a “Killswitch” for Sunburst Malware Affecting SolarWinds’ Orion

Sunburst killswitch, Sunburst malware kill switch, Sunburst malware detection, sunburst malware fix, sunburst malware, fix for sunburst malware

The recently reported supply chain attack on the SolarWinds Orion platform has grabbed the attention of many eyeballs because the Orion IT management platform is used by several U.S. government agencies like the Dept. of Treasury, Dept. of Commerce, and Dept. of Homeland Security. Apart from the public sector clientele, SolarWinds Orion is also extensively used by companies in the private domain, including Boeing and Los Alamos National Laboratory. Thus, the extent of damage caused by the attack can only be estimated till the final assessment reports come in.

Related News:

White House Confirms Cyberattack on U.S. Dept of Treasury and Commerce

However, to stop further spread of the nefarious Sunburst malware and to provide interim relief to SolarWinds’ clients, a group of tech firms — Microsoft, FireEye, and GoDaddy ­ — collectively devised a “Killswitch” to take control of one of the domains that attackers used for transmitting the malicious code into victims’ systems.

Sunburst Malware Killswitch

FireEye, in its report, stated that the hacked networks were seen communicating with a malicious domain name, avsvmcloud[.]com, which is one of the many domains that attackers had set up to control and communicate with the affected systems. Thus, gaining control over this domain would at least provide relief to SolarWinds by preventing further spread. For this, researchers from Microsoft and FireEye shook hands, and with the help of domain registrar company, GoDaddy, devised a “killswitch” to take over the malicious domain.

The story was first reported by investigative journalist Brian Krebs, who  stated, “There were signs over the past few days that control over the domain had been transferred to Microsoft.”  FireEye, in its statement, accepted applying a killswitch to the domain and has additionally reconfigured it so that the Sunburst malware does not operate under certain conditions.

Shedding more light on the Killswitch application, a FireEye spokesperson said,

Depending on the IP address returned when the malware resolves avsvmcloud[.]com, under certain conditions, the malware would terminate itself and prevent further execution. FireEye collaborated with GoDaddy and Microsoft to deactivate SUNBURST infections.

This killswitch will affect new and previous SUNBURST infections by disabling SUNBURST deployments that are still beaconing to avsvmcloud[.]com. However, in the intrusions FireEye has seen, this actor moved quickly to establish additional persistent mechanisms to access to victim networks beyond the SUNBURST backdoor.

This killswitch will not remove the actor from victim networks where they have established other backdoors. However, it will make it more difficult for the actor to leverage the previously distributed versions of SUNBURST.

Since the trio of the tech companies now has control over the malicious domain, it could very well mean that more names of SolarWinds’ affected clients will be revealed.

Related News:

U.S. Government Takes the Wind Out of SolarWinds’ Sails…for the Time Being!

How Cyberattacks Cause Severe Hazards to Health Care Industry

Healthcare Data Breaches, Premier Diagnostics data exposed

Cyberattacks on health care organizations have become rampant in 2020. With multiple data breaches and ransomware attacks, the health care providers continued to be the primary target for cybercriminals. According to the “U.S. Health Care Data Breach Statistics” survey, around 70% of the U.S. population is affected by health care data breaches, with over 230,954,151 health records lost, stolen, or exposed in various security incidents. 2018 and 2019 witnessed a sharp increase in the number of individuals affected by health care data breaches, with a six-fold increase between 2017 and 2019.

By Rudra Srinivas, Feature Writer, CISO MAG

Nearly two-thirds of global health care organizations suffered a cyberattack in their lifetime, while 53% were attacked within the last 12 months. The most commonly reported cyberattacks in the health care sector are phishing (68%), malware (41%), and web-based attacks (40%).

The recent outbreak of ransomware attacks on hospitals globally indicates the threat these attack vectors pose. Many industry experts opined that the current cyberthreats to the health care industry might continue in the coming year. Here are four ransomware attacks that took a toll on the health care sector in 2020:

1. Blackbaud Data Breach

Cyberattack on Blackbaud, a third-party cloud-based service provider, is considered one of the largest data breaches of the year, which exposed over 3.4 million patients’ personal information. On July 16, 2020, Blackbaud stated that it discovered unknown ransomware operators accessing its network systems between February 7, 2020, and May 20, 2020 — and illicitly obtained backups of databases used by its customers. Two Minnesota-based organizations – Children’s Minnesota Foundation and Allina Health were severely affected in the data breach incident.

2. Florida Orthopaedic Institute

Tampa-based health care provider Florida Orthopaedic Institute (FOI) reported a data breach in April 2020 that affected over 640,000 patients’ data. FOI alleged that an unknown ransomware group encrypted information stored on its servers. The compromised information included patients’ personal data like names, birth dates, social security numbers, and medical information like appointments, medical claims, addresses, diagnosis codes, insurance plan identification numbers, payer identification numbers, and payment amounts. FOI also faced a class-action lawsuit filed by the law firm Morgan & Morgan, alleging that FOI failed to protect its patients’ personal data. The lawsuit demanded $99 million in compensation.

3. Health Share

On January 2, 2020, Health Share stated that the personal information of over 654,000 patients was compromised by its third-party vendor GridWorks. Burglars broke into GridWorks’ office and stole a laptop that contained PII of its members including names, contact details, addresses, birth dates, social security numbers, and Health Share ID numbers. The nature of the theft suggested that the stolen data was potentially compromised, however, no medical histories were involved in the data breach.

4. A String of Ryuk Ransomware Attacks

Recently, a string of Ryuk ransomware attacks targeted multiple U.S. hospitals in Oregon, California, and New York. Nearly six hospitals were attacked on the same day, which disrupted their entire operations. Even the FBI, the Cybersecurity and Infrastructure Security Agency (CISA), and the Department of Health and Human Services (HHS) jointly issued a red alert to all hospitals and health care institutes across the U.S. The agencies stated that malicious actors targeted hospitals and health care providers with Ryuk ransomware, TrickBot, and BazarLoader malware, which lead to ransomware attacks, data theft, and the disruption of services.

Cybersecurity in Health Care Sector

The research “Moving Forward: Setting the Direction” highlighted that health care supply chain security is one of the lowest-ranked areas for the National Institute of Standards and Technology’s Cybersecurity Framework (NIST CSF) conformance. Only 44% of hospitals and health care providers are following the security protocols outlined by the NIST CSF.

The main factors affecting health care security include poor security planning, lack of organizational focus, inadequate reporting structures and funding, confusion around priorities, lack of necessary staff, and inaccurate planning.

In addition, there are huge cyberthreat risks to connected medical devices, as most organizations are running their medical devices on outdated operating systems, leaving them vulnerable to cyberattacks. According to a research from Atlas VPN, 83% of health care providers in the U.S. are running on outdated software.  Out of the 1.2 million IoT devices used in thousands of health care organizations across the U.S., 56% of devices were still running on the Windows 7 operating system, for which Microsoft discontinued support in January 2020.

Fear of Unhealthy Insiders

Every organization or industry is vulnerable to insider threats, and the health care sector is no exemption. A recent survey revealed that over 71% of health care providers are worried about the risks of data theft due to the negligence or mistakes of their employees and IT admins. Organizations in the health care sector are mostly concerned about employees accidentally sharing sensitive data (88%) and rogue admins (80%), spear-phishing attacks (87%), admin mistakes (71%), and data theft by employees (71%).

In Conclusion

Cyberattacks on hospitals and vulnerable medical devices are likely to be continued until and unless the health care organizations boost their cybersecurity posture. While patient forms and charts are on paper, the medication procedure and reports are maintained online. Ransomware can take an entire health care institute to a road of destruction and cause dire consequences for patients. If systems go down because of cyberattacks, there is a possibility of patients losing their life. It is high time for health care organizations to increase their cybersecurity budget and enhance their security standards.

About the Author

 

Rudra Srinivas is a Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.

Social Media Giants’ Data Collection under FTC Scanner; Amazon, Facebook, and Seven others Summoned

FTC summons social media companies, FTC seeks information, FTC seeks info from social media companies, FTC issues order

The Federal Trade Commission (FTC) of the U.S. has issued orders to nine social media and video streaming giants, asking them to provide data and clarity on how they collect, use, and present the personal information of their consumers. The agency wants to study how the companies in question advertise, conduct user engagement, and how these practices affect their users, especially children and teens, who are the most vulnerable. All companies have 45 days to respond to the order from the time they received it.

FTC’s Legal Route for the Study

When it comes to sharing such information, which involves methodology, technology, and business model, social media companies and other such platforms are apprehensive about it as this could mean sharing of proprietary info. This also means that the company can deny sharing of such info under the proprietary clause. Thus, considering this, the FTC has issued orders to Facebook, WhatsApp, YouTube, Twitter, Amazon, Discord, ByteDance, Reddit, and Snap, under Section 6(b) of the FTC Act, which authorizes the Commission to conduct wide-ranging studies that do not have a specific law enforcement purpose.

The issuance of such order [under section 6(b)] requires a majority vote which the Commission got in a vote count of 4-1. FTC’s Commissioner Noah Joshua Phillips voted against issuing the order and in his dissenting statement argued,

The breadth of the inquiry, the tangential relationship of its parts, and the dissimilarity of the recipients combine to render that these orders are unlikely to produce the kind of information the public needs, and certain to divert scarce Commission resources better directed elsewhere. Hence, I dissent.

The Ones Who Support

Commissioners Rohit Chopra, Rebecca Kelly Slaughter, and Christine S. Wilson have however supported the orders and in their joint statement said,

Digital products were launched with the simple goal of connecting people or fostering creativity. But the industry model has now shifted from supporting users’ activities to monetizing them. This transition has been fueled by the industry’s increasing intrusion into our private lives. Several social media and video streaming companies have been able to exploit their user-surveillance capabilities to achieve such significant financial gains.

What FTC Wants to Study

The joint statement from the Commissioners primarily stated one reason for this inquiry – to know the full scale and scope of social media and video streaming companies’ data collection. However, FTC also has the following agenda on mind:

  • What social media and video streaming services collect, how they use it to track, estimate, or derive personal and demographic information.
  • How these platforms determine the type of ads and other content displayed to the consumers.
  • To know whether any algorithms or data analytics are being applied to users’ personal information.
  • Methods used to measure the metrics of promotion, and user engagement.
  • How these practices affect the users, especially children and teens.

The FTC explained that its primary objective is to promote healthy competition so that the consumers can benefit from it. Their motto is to protect and educate its consumers and, thus, such studies help.

With regards to their primary objective of promoting healthy competition, the FTC, on December 9, 2020, sued Facebook for Illegal Monopolization. It alleged that the social media giant illegally maintained a monopoly in their business space “through the years-long course of anticompetitive conduct.” Read more about this here.

Related News:

4 Times Data Regulators Slapped High Penalties in 2020

45 Mn Unique Medical Images Exposed Online via Unprotected Servers

Cyberattack on Ireland's Health care

Cybersecurity researchers from CybelAngel, a provider of digital risk protection services, uncovered a massive data leak incident that exposed millions of medical-related sensitive images, X-rays, CT scans, and personal health care information (PHI). The images are openly accessible on unsecured servers, allowing anyone to exploit them.

The data breach came to light after CybelAngel’s six-month investigation into Network Attached Storage (NAS) and Digital Imaging and Communications in Medicine (DICOM), the communication standards used by health care providers to send and receive medical data.

CybelAngel’s researchers examined over 4.3 billion IP addresses and found more than 45 million unique medical images that are left exposed on 2,140 unprotected servers across 67 countries, including the U.S., the U.K., and Germany. “The analysts found that openly available medical images, including up to 200 lines of metadata per record, which included PII (personally identifiable information; name, birth date, address, etc.) and PHI (height, weight, diagnosis, etc.), could be accessed without the need for a username or password. In some instances, login portals accepted blank usernames and passwords,” the researchers explained.

David Sygula, Senior Cybersecurity Analyst at CybelAngel, said, “This is a concerning discovery and proves that more stringent security processes must be put in place to protect how sensitive medical data is shared and stored by health care professionals. A balance between security and accessibility is imperative to prevent leaks from becoming a major data breach.”

Todd Carroll, CybelAngel CISO, said, “Medical centers work with a vast, interconnected web of third-party providers and the cloud is an essential platform for sharing and storing data. However, gaps in security, such as this, present a huge risk, both for the individuals whose data is compromised and the health care institutions that are governed by regulations to protect patients’ data.”

The health care sector suffered various challenges in medical data security. While opportunistic cybercriminals are preying on sensitive medical information by exploiting the pandemic,  health care providers must boost their cybersecurity posture to protect their patients’ personal data.

Insider Threats: A Byproduct of the New Normal

Insider attacker leak data

Despite the continuous security improvements, the concern over insider threats seems to be growing for organizations globally. The new distributed working conditions have also added fuel to existing fears. Even though most organizations stretched their security beyond their office perimeter due to remote workforce, the risk from intentional or unwitting insiders is still a primary security concern.

By Rudra Srinivas, Feature Writer, CISO MAG

According to “2020 Cost of Insider Threats: Global Report,” insider threats increased by 47% from 3,200 in 2018 to 4,716 in 2020. The cost of insider threat incidents also surged by 31% from $8.76 million in 2018 to $11.45 million in 2020. Negligent employees create around 62% of security incidents, costing global organizations an average of $307,111 per incident.

Apart from regular data breaches and COVID-19-themed cyberattacks, the year 2020 also witnessed several security incidents caused due to an employee’s malicious intension, negligence, or unintentional actions like responding to a phishing email with sensitive information or downloading malicious attachments.

Here are the four alarming incidents of 2020 that highlight insider risks: 

1. General Electric

Two employees at General Electric (GE) illicitly obtained trade secrets and intellectual properties from the company’s advanced computer models. The employees also stole GE’s marketing and pricing details and misused them for their business advantage. After many years of investigation, the FBI convicted the insiders and penalized them for $1.4 million in compensation to GE.

2. Twitter

In July 2020, cybercriminals obtained access to over 130 private and corporate Twitter accounts, in which attackers misused 45 accounts to promote their Bitcoin scam. Attackers compromised Twitter accounts of notable businesses and celebrities including Elon Musk, Bill Gates, Jeff Bezos, Apple, Uber, and other high-profile accounts. According to Twitter’s statement, attackers pilfered confidential account information by spear-phishing some of its employees. Adversaries targeted remote employees, gathered their login credentials by mimicking Twitter IT administrators. The scammers then used this information to break into administrator tools and compromised numerous accounts, changed their login credentials, and advertised their malicious schemes.  The Twitter hack sheds a spotlight on the dangers that insiders pose to organizations of all sizes.

3. Microsoft

A security blunder caused Microsoft’s unsecured database to expose 14 years of customer service and support data dating back to 2005, making it accessible to anyone with a web browser requiring no authentication at all. The exposure was discovered by security researcher Bob Diachenko, who also uncovered a total of five Elastic Servers containing 250 million records including logs of communication between Microsoft’s support engineers and its customers.

According to Microsoft’s statement, on December 5, 2019, a change was made to the said databases’ network security group. It was later found that appropriate measures were not taken to verify the Azure security rules and this misconfiguration further led to the data exposure.

4. Marriott

Global hospitality group Marriott International suffered a massive data breach that exposed the personal information of around 5.2 million guests after cybercriminals exploited a third-party application that Marriott used to provide guest services. It’s believed that the exposed data has been accessed by an unknown third-party using the login credentials of two employees at a group hotel, which is operated and franchised under Marriott’s brand.

In an official release, the company stated that the breach began in mid-January 2020 and was discovered at the end of February 2020. The incident exposed contact details including names, addresses, birth dates, gender, email addresses, employer name, room stay preferences, and loyalty account numbers. Marriott notified the incident to the relevant authorities for further investigation and informed those who were affected in the breach. Marriott also set up a website to help the impacted guests in the incident.

The Consequences of Insider Attacks

Insider attacks can impact an organization in a variety of ways. From high penalties to brand image damage, it whips multiple blows on companies. Some of the consequences include:

  • Loss of Customers’ Trust
  • Financial Damage
  • Loss of Intellectual Properties
  • Huge impact on the company’s reputation
  • High worth fines from data regulators

Preventive Measures

Though it seems like a tough task to predict or prevent insider threats, there are certain security measures and technologies that can help in identifying them. These include:

  • Providing continuous cybersecurity training to employees of all levels in the organization.
  • Making employees aware of all kinds of phishing attacks and malicious communications from third-party vendors.
  • Securing servers and databases with up-to-date industry specifications.
  • Introducing the Zero-Trust Security model.
  • Practicing robust authentication practices like 2FA and MFA wherever possible.
  • Having an actionable patch management policy.
  • Deploying access management and user activity monitoring solutions.

In Conclusion

The consequences of insider attacks are often devastating. Almost every company is vulnerable to insider-related security incidents. However, with a dedicated security team in place and with advanced cybersecurity measures, it is possible to eliminate them. In the current scenario, just relying on 2FA is not enough. Businesses need to start a board-level conversation about real-time behavioral analysis of end-users. This way, potential malicious insiders can be traced if they know they are being tracked.

About the Author

 

Rudra Srinivas is a Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.

U.S. Government Takes the Wind Out of SolarWinds’ Sails…for the Time Being!

SolarWinds Orion, SolarWinds Orion Hack, SolarWinds, SolarWinds tools, SolarWinds management tools

Earlier in the week, the White House had acknowledged that a Russian state-sponsored group known as the Cozy Bear or APT 29 carried out targeted cyberattack on several U.S. Government agencies. Other than this, the hack is believed to have successfully compromised the networks of many private organizations.

Reports suggest a link between this attack and the mass outage that Google faced yesterday for many of its products, including Gmail and YouTube.

The attack was carried out by means of updates that were provided between March and June 2020, to a widely used IT infrastructure management software provided by SolarWinds, called Orion.

SolarWinds Says Nearly 18,000 Customers Affected

According to the guidelines of regulatory disclosure, SolarWinds filed the Form 8-K with the Securities and Exchange Commission (SEC). In the filing, SolarWinds mentioned that it has a customer base of more than 300,000, however, analysis suggest that only less than 18,000 of them were actually affected by this supply chain attack as they had unknowingly installed the SolarWinds’ Orion backdoored update.

SolarWinds Orion is basically a management tool and thus used by many top organizations including the U.S. federal agencies. In its security advisory, SolarWinds has clearly stated that only Orion software build versions 2019.4 HF 5 and 2020.2 were affected by the vulnerability and no other non-Orion products were impacted.

CISA Issues Code Red

According to the CRN report, after looking at the gravity of the incident and gauging repercussions of this prolonged cyberattack, the U.S. government in its emergency meeting decided to power down all systems with SolarWinds Orion management tools installed on them.

The country’s top cybersecurity governing body, CISA, has also gone ahead and issued only the fifth emergency directive thus far under the authorities granted by Congress in the Cybersecurity Act of 2015, to mitigate the SolarWinds Orion compromise. Taking a stern stance on the situation, CISA Acting Director, Brandon Wales said,

The compromise of SolarWinds’ Orion Network Management Products poses unacceptable risks to the security of federal networks.  This directive is intended to mitigate potential compromises within federal civilian networks, and we urge all our partners—in the public and private sectors—to assess their exposure to this compromise and to secure their networks against any exploitation.

SolarWinds on the other hand has asked its customers to upgrade their platforms to versions 2019.4 HF 6 and 2020.2.1 HF 1, respectively, at the earliest.

SolarWinds’ Director knew this?

Twitter has been abuzz since the outbreak of this cyberattack news simply because of the number of top SolarWinds’ clientele being affected. Many cybersecurity pundits have criticized SolarWinds and the federal authorities for the haphazard way the entire episode was handled.

However, some reports suggest that the Director of SolarWinds, Aurora Co-Invest L.P. Slp, already sniffed the issue in hand and sold 2,079,823 shares amounting to nearly $45.7 Million. The shares were sold at an average price of $21.97 a week before the public announcement.

SolarWinds, as stated earlier, has a huge and diverse clientele. It would be safe to say that the numbers of affected customers and associated breaches can increase in the days to come.

Related News:
White House Confirms Cyberattack on U.S. Dept of Treasury and Commerce

APTs: The Epidemic That Went Under the Radar

Credential Abuse Attack, credential harvesting campaign

Identifying cyber threats and anomalies is like finding a needle in a haystack. It is safe to say that with advanced persistent threats (APTs) in the picture, the needle stays where it was, only that the haystack has multiplied and spread across several million barns. Earlier this month, the Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) notified about cyber intrusions by APT actors targeting the U.S. think-tanks.

By Augustin Kurian, Senior Feature Writer, CISO MAG

According to the release, “APT actors have relied on multiple avenues for initial access. These have included low-effort capabilities such as spear-phishing emails and third-party message services directed at both corporate and personal accounts, as well as exploiting vulnerable web-facing devices and remote connection capabilities.” The federal bodies also noted that remote working due to COVID-19 and the reliance on remote connectivity, have given way for malicious actors to launch targeted attacks. The agencies also advised individuals to be more cyber aware.

Ed Bishop, CTO and co-founder of Tessian, told CISO MAG, “The FBI and CISA are right to advise people working in the U.S think-tanks to ‘adopt a heightened state of awareness’ when you consider the damage that could be caused should an employee fall for the scam.”

He continued, “Hacking humans over email is one of the easiest ways for cybercriminals to hack into organizations. And they’re getting better at it, using clever social engineering techniques and impersonating trusted third parties to trick victims into sharing information or account credentials.

Ed Bishop, CTO and co-founder of Tessian
“If an individual were to unknowingly share their user credentials with a cybercriminal, the hacker could not only access the victim’s network but could also send emails from the person’s account, making it look like the messages they were sending were 100% legitimate and, potentially, influencing U.S. policies.”

 

He stressed how spear-phishing attacks, like this, are low-effort but “high-reward,” which is often the reason “why they won’t be going away any time soon.” He also opined that “the threat has only been exacerbated by the shift to remote work. People are more reliant on email to stay connected with colleagues, customers, and suppliers, and our survey found that half of the employees are less likely to follow safe data practices when working from home. As people in these powerful and influential organizations continue to work away from the office, IT teams must put measures in place to automatically detect spear-phishing attacks and alert people to the threat in their inbox, warning them to think twice before clicking.”

Going Under the Radar

Since the onset of COVID-19, targeted attacks against individuals are on the rise. In October,  in a joint security alert, CISA and the FBI had observed APT actors targeting federal and state, local, tribal, and territorial (SLTT) government networks, and non-government networks. In that instance, APT actors had leveraged legacy network access and exploited critical Netlogon vulnerability CVE-2020-1472, which had the CVSSv3 score of 10.0. Russian hacker groups APT28 and APT29 were also accused of targeting election campaigners, political organizations, and COVID-19 vaccine research, respectively.

APT: An Epidemic

Though APTs only account for about 20% of all cyberattacks, if successful in their execution, the severity of APTs overshadows their numbers by leaps and bounds. Targeted attacks like APTs have siphoned billions of dollars from banks and several other critical infrastructures. These billions include the cost of responding to the attack and restoring systems as well as the loss of public confidence and the institution’s reputation.

“Today most of the organizations or at least the critical part of their networks, are protected by multiple layers of security defenses ranging from Firewall, IPS, Antivirus, Anti-Spam gateways, etc. The attacks can no longer be running a simple executable with exploiting know vulnerabilities (although it may succeed in many cases with due care, is not practiced in security parlance). Enter APT, the most advanced kit attackers use,” Sairam Jetty, a cybersecurity expert.

He continued, “APT relies on two main things: covertness and persistence. The attack might contain a chain of activities by the delivered malware. Some traits followed in the attack are like maintaining low footprint, exploiting zero-day vulnerabilities, scanning the network and exploiting further systems and establishing a secure and covert channel with CnC which looks benign and might not be detected by security solutions.”

What can you do?

At the human level, it is advisable to follow the practices that are suggested by the CISA and FBI. These include:

Leaders

  • Implement a training program to familiarize users with identifying social engineering techniques and phishing emails.

Users/Staff

  • Log off remote connections when not in use.
  • Be vigilant against tailored spear-phishing attacks targeting corporate and personal accounts (including both email and social media accounts).
  • Use different passwords for corporate and personal accounts.
  • Install antivirus software on personal devices to automatically scan and quarantine suspicious files.
  • Employ strong multi-factor authentication for personal accounts, if available.
  • Exercise caution when: Opening email attachments, even if the attachment is expected and the sender appears to be known. See Using Caution with Email Attachments; Using removable media (e.g., USB thumb drives, external drives, CDs).

IT Staff/Cybersecurity Personnel

  • Segment and segregate networks and functions.
  • Change the default username and password of applications and appliances.
  • Employ strong multi-factor authentication for corporate accounts.
  • Deploy antivirus software on organizational devices to automatically scan and quarantine suspicious files.

What can enterprises do?

Machine learning is one of the most potent solutions for dealing with advanced threats as machines often prove useful in finding abnormalities in traffic. “Here I believe, machine learning and predictive analytics can come together for day-to-day security monitoring to proactively determine and mitigate threats by monitoring hundreds of parameters in network and transaction data and identify patterns such as suspicious activity before it progresses into a full-scale attack. This can be of great value especially when the traditional way of spotting an anomaly is becoming difficult as hackers use more advanced methods each time,” Sairam concluded.

Augustin Kurian

About the Author 

Augustin Kurian is part of the editorial team at CISO MAG and writes interviews and features.

 

Moving from Human Error to Human Firewall

Microsoft Azure App, Zero-Day Vulnerability

Cybersecurity experienced multiple challenges in 2020. Rapid digitalization and the new normal — work from home — brought new opportunities as well as risks. Cybercrime is maturing, and hackers are capitalizing on the pandemic by compromising health care institutions working on developing the COVID-19 vaccine. And though ransomware and phishing emails are considered some of the major threat vectors disrupting cyberspace, human error is still the primary reason for major cybersecurity breaches.

By Pooja Tikekar, Feature Writer, CISO MAG

According to the World Economic Forum’s “Global Risks Report 2020,” cyberattacks rank first among global human-caused risks. Let’s accept it, to err is human. However, human error in cybersecurity is often disregarded. So, what can be done to improve and strengthen an organization’s cybersecurity posture? The only way out is to address an employee’s cyber behavior or psychology to prevent mistakes before they turn into data breaches or possible financial losses.

THE RED FLAGS
Unreliable Passwords  

The recurring human error that has wreaked havoc is the use of guessable passwords. “Password,” “123456,” and “Hello123” are some of the most used passwords that have accounted for multiple brute-force attacks. Users also fail to change the default passwords like “admin.”

Delivery Negligence  

Lack of understanding could lead to the mishandling of sensitive data or security information. Employees also accidentally send emails to the wrong recipients or share critical data through unsecured servers.

Delay in Updates or Patch Management  

When software developers discover a vulnerability, patches are sent out to all end users. However, a delay in installing updates or patches may cause dire security consequences.

Downloading Attachments from External Sources  

One of the easiest ways to phish users is via malicious email attachments. These emails are often composed of poor grammar or illogical sentence structures, and the sender’s identity may not match the purpose of the email.

 

While addressing the red flags, it is important to understand that data leaks are often a result of inaction or unintentional actions by employees or users. Sure, the cost of a data breach by human error is low compared to the cost of a breach caused by a threat actor, however, employee negligence cannot be overlooked.

Recently, Vertafore, a provider of insurance software, disclosed that an unknown threat actor group illicitly accessed the personal information of 27.7 million Texas-based drivers who use Vertafore’s services. Vertafore admitted that the data breach was caused due to a human error after three data files were inadvertently stored in an unsecured storage unit. In September 2018, the Information Commissioner Office (ICO) slapped Equifax with a fine of £500,000 ($660,000) for failing to protect the personal and financial data of customers. The ICO, which carried out the investigation, stated that the U.S. Department of Homeland Security warned Equifax about the vulnerabilities in its systems, in 2017. However, Equifax failed to implement the required measures to fix the vulnerabilities.

Cybersecurity Skills Gap

The cybersecurity skills gap has been a perennial issue and it can only be identified by the state of robust cybersecurity professionals and solutions in an organization. According to a survey by the Enterprise Strategy Group (ESG) and the Information Systems Security Association (ISSA), the cybersecurity skills crisis has worsened for the fourth year in a row and impacted 70% of organizations. This is implicative of the fact that businesses need a holistic approach towards continuous cybersecurity education, training, and career development. The pandemic has been a dominant force throughout the year and employers need to offer hands-on experience or security certifications for ensuring proficiency and bridging the skills gaps.

Traditional, once a year security training does not solve the problem anymore. Training plans need to integrate aspects of real-life cyberthreats that an organization is likely to face. These programs should end with an exam or an exercise, which in turn will help employers work on the weaknesses of employees that need further assistance. And the training should continue throughout the year with periodic assessments, to ensure that assesses are abreast of the latest developments.

Towards a Human Firewall

  • Set up strict compliance guidelines on how to manage emails that come from external recipients. One of the most effective ways is by adding a warning message to incoming emails from external domains.
  • Disable or block automatic email forwarding to help control the potential disclosure of information to those outside the organization.
  • Encourage multi-factor authentication (MFA).
  • Attribute or validate the employees who catch phishing emails. Keep it human.
  • Educate employees about social engineering tricks using live demonstrations.

In Conclusion

Humans don’t have to be the weakest links. While building a cyber-aware culture, it is essential to eliminate the opportunities that lead to human error. Businesses need to flush out the “one-size-fits-all” policy and start acknowledging and incentivizing positive behavioral changes in employees who commit to security forefront.

There is no denying that technology and human components go hand-in-hand in mitigating threats. Integrating human touch with automation will help create an ecosystem for responding to cyber risks. And though the hype around artificial intelligence and machine learning may drive the misconception that cyberspace is dominated by machines, the human firewall will always be central to security. And the first line of defense!


About the Author

Pooja Tikekar is a Feature Writer and part of the editorial team at CISO MAG. She writes news reports and feature articles on cybersecurity technologies and trends.

More from the author.

White House Confirms Cyberattack on U.S. Dept of Treasury and Commerce

zero-trust, Counter-Ransomware Meeting , Biden Administration and Tech Giants

The White House on Sunday acknowledged reports that a group backed by a foreign government carried out a cyberattack on the U.S. Department of Treasury and a section of the U.S. Department of Commerce. As per a report from The Washington Post, threat actors are said to belong to the infamous Russian state-sponsored group Cozy Bear or APT 29.

The hack was discovered by the cybersecurity firm FireEye which termed it a “global intrusion campaign.” FireEye’s researchers explained that threat actors successfully compromised the networks of many public and private organizations by providing updates to a widely-used IT infrastructure management software, the Orion network – a product from SolarWinds. The potential vulnerability was related to the updates released between March and June 2020.

CISA is providing technical assistance to affected entities as they work to identify and mitigate any potential compromises.

The SUNBURST Behind the Sudden Burst of Cyberattacks

Researchers further added that this supply chain attack distributed malware called SUNBURST. The specialty of the malware is that, unlike others, the Trojanized code remained dormant for the first few weeks to avoid detection and then executed commands called “Jobs.” Upon execution, SUNBURST gained the ability to transfer and execute files, profile the system, perform system reboot, and disable system services.

After successful data exfiltration and targeted espionage, SUNBURST additionally dropped other malicious payloads like the TEARDROP and BEACON malware and moved laterally. The SUNBURST malware disguises “its network traffic as the Orion Improvement Program (OIP) protocol and stores reconnaissance results within legitimate plugin configuration files allowing it to blend in with legitimate SolarWinds activity.” Hence, its detection is extremely difficult.

Chronology of SUNBURST’s Attack

  • Threat actors used Orion.Core.BusinessLayer.dll (b91ce2fa41029f6955bff20079468448), a SolarWinds-signed plugin component of the Orion software framework that contains an obfuscated (SUNBURST) backdoor that enables communication via HTTP to third-party servers. The code is hidden in the plain site using fake variable names and by inserting them into legitimate components.
  • After an initial dormant period of up to two weeks, it retrieves and executes commands, called “Jobs”, that includes the ability to transfer and execute files, profile the system, and disable system services.
  • The data exfiltrated is then sent to a command and control (C2) server for further analysis. However, the traffic between the compromised system and the C2 server is disguised as a legitimate Orion Improvement Program to avoid detection.
  • SUNBURST additionally drops other malware payloads and moves laterally to inflict maximum damage.

For additional information about the tactics, techniques, and procedures (TTP) of SUNBURST supply chain attack click here.

What the Government Says

The National Security Council spokesman John Ullyot said, “We can confirm there has been a breach in one of our bureaus. We have asked the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) and the FBI to investigate.”

On the other hand, CISA, in a statement, was noted saying that the agency has been working closely with its partners regarding recently discovered activity on government networks. “CISA is providing technical assistance to affected entities as they work to identify and mitigate any potential compromises”.

The latest announcement comes less than a month after President Donald Trump fired Christopher Krebs, the cybersecurity chief of the Department of Homeland Security’s (DHS) Cybersecurity and Infrastructure Security Agency (CISA). He was responsible for leading the effort to protect U.S. elections, but the POTUS said that Krebs gave a “highly inaccurate” statement about the U.S. elections because of which he was shown the exit door.

Related News:

CISA Alerts About Path Traversal Vulnerability in Fortinet VPNs

CISA Warns Potential Cyberattacks from State Actors Amid Geo-Political Tensions