Home Blog Page 135

PLEASE_READ_ME: A Malwareless Ransomware Targeting MySQL Servers

Ransomware attacks, LockBit Ransomware

Security experts found a new “PLEASE_READ_ME” ransomware campaign distributed from the U.K.-based IP addresses targeting unsecured MySQL servers online. According to the researchers from Guardicore, the ransomware preys on weak credentials and has exploited around 83,000 victims and 250,000 databases so far. It was also found that around five million MySQL servers are publicly accessible online.

The Modus Operandi of the PLEASE_READ_ME Ransomware

The hacking operation begins with a password brute-force attack on the MySQL databases.

Once the database is compromised, the attacker strikes a sequence of queries into the server to gather data on users.

The information in the database is encrypted and sent to the attackers’ servers via a zipped file and then deleted from the server.

On successful execution, a ransom note is left demanding payment of up to 0.08 BTC.

The adversaries threaten to sell the stolen data to the highest bidder if the ransom payment is denied.

A Malwareless Ransomware

Guardicore researchers stated that PLEASE_READ_ME is a “malwareless” ransomware operation, which is active since at least the beginning of January 2020.  They also identified over 92 attacks that originated from 11 different IP addresses, mostly from Ireland and the U.K.

“The attack chain is extremely simple and exploits weak credentials on internet-facing MySQL servers. There are close to 5 million internet-facing MySQL servers worldwide. The attackers leave a backdoor user on the database for persistence, allowing them to re-access the network. Monetization of the campaign has evolved into a double extortion attempt – publishing and offering data for sale to pressure victims into paying the ransom. What drove us to closely monitor this threat is its use of double extortion, where stolen data is published and offered for sale to pressure victims into paying the ransom,” Guardicore said.

Ransomware Attacks in 2020! These are 4 Most Affected Sectors

Ransomware attacks, ransomware, Sinclair Broadcast group

From a local food retailer to a multi-national company, ransomware attacks continue to loom over cyberspace. Ransomware operators target victims by encrypting their sensitive files, paralyzing operations, and demanding high ransoms. They also threaten victims by posting the stolen data on darknet forums.  According to a global investigation, ransomware attacks are the most observed security threats in 2020, accounting for one-third of all cyberattacks as of September 1, 2020, with Ryuk, Sodinokibi, and Maze as the most observed ransomware variants.

By Rudra Srinivas, Feature Writer, CISO MAG

Nearly 56% of organizations reported a ransomware attack in the last year. It is suspected that the rising ransomware attacks may impact almost all businesses globally of all sizes and sectors. These are the most targeted and affected industries by ransomware attacks in 2020:

1. Education

The year 2020 witnessed a huge surge in ransomware attacks targeting schools, colleges, and other academic institutions in the country. Threat actors demanded Bitcoins as ransom from the victims and threatened to expose the stolen data of students if not adhered to. Recently, the University of Utah’s College of Social and Behavioral Sciences (CSBS) paid a ransom of $457,059.24 to the attackers to retrieve the decryption key to the seized information. Unknown threat actors encrypted the data stored on CSBS computing servers and stole certain unencrypted data before encrypting the systems.

Ransomware attacks impacted over 86 universities, colleges, and disrupted operations of nearly 1,224 individual schools last year. The U.K.’s National Cyber Security Centre (NCSC) warned educational institutions to be vigilant of rising ransomware attacks and urged them to follow the required mitigation measures.

In a recent joint advisory, the FBI, the Cybersecurity and Infrastructure Security Agency (CISA), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) warned that ransomware, malware, and DDoS attacks are the main threats for K-12 educational institutions. The three government agencies stated that ransomware operators continue to target schools through the 2020-2021 academic year.

2. Information Technology

The information technology (IT) sector faced multiple challenges in 2020 while adjusting its operations according to the aftermath of the pandemic. From securing the distributed networks to defending from sophisticated cyberattacks, it has been a roller-coaster ride for most corporate organizations. Ransomware operators succeeded in targeting large organizations and forcing ransom payments. The average enterprise ransom payments increased 33% ($111,605) in Q1 of 2020 from Q4 of 2019, according to a research report.

Recently, IT services provider Cognizant suffered a Maze ransomware attack that caused service disruptions for some of its clients. The Maze ransomware operators made headlines in recent months for holding its victims’ systems and threatening to leak their information if they fail to pay the ransom.

3. Health Care

The health care providers are primarily targeted and most affected by ransomware attacks in 2020. While hospitals across the globe are preparing to deploy the vaccine for COVID-19, opportunistic cybercriminals are finding their way to exploit the resources and valuable medical data.  Recently, there were a series of Ryuk ransomware attacks targeting multiple hospitals in the U.S. Cybercriminals compromised critical network systems across six hospitals on the same day. The Department of Homeland Security (DHS), CISA, and the FBI jointly issued a red alert to all hospitals and health care providers across the U.S.

According to a survey from privacy website PrivacyAffairs.com, health care data breaches increased by 2,733% between 2009 and 2019 in the U.S., at an average of 1.4 breaches exposing at least 500 records per day.  The survey also found that there were over 3,054 data breaches of health care records over the past decade.

4. Retail

Ransomware attacks continue to be the most concerning threat to retail enterprises in 2020. Recently, an unknown ransomware gang attacked popular Indian sweets and snacks company Haldiram. The attackers compromised the company’s critical data and demanded ₹7.5 lakh (approximately $ 10,220) ransom.

Earlier, security firm Cyble claimed that a threat actor group “John Wick” demanded ransom after gaining unrestricted access to a database belonging to Paytm Mall, an Indian e-commerce unit of payment solutions provider Paytm. Cyble stated that the group uploaded a backdoor/Adminer on the company’s website to obtain access to their production database and compromised all accounts and related information of the company. Paytm Mall denied the data breach allegations saying that the company’s data is secure.

According to a report, organizations in India suffered over 1.45 million ransomware attacks, including data breaches, hacks, and other security incidents between 2015 and 2020.

Ransomware: A Lucrative Business for Cybercriminals

Ransomware actors are openly demanding a higher ransom. They have diversified ransomware attacks by incorporating new revenue streams like forcing victims by threatening to expose their sensitive data online and auctioning off victims’ data to other criminals on the dark web. Putting ransomware on a computer is the most successful way for cybercriminals to churn out money. It continues to be a hot topic, and though paying the ransom is a personal choice, businesses need to rethink how they can step-up their security game to protect customers.

About the Author

Rudra Srinivas is a Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.

Theresa Payton is CISO MAG Cybersecurity Crusader of the Year (2020)

The CISO MAG Cybersecurity Crusader of the Year recognition honors the most influential personalities in cybersecurity. They have, over the years, been committed to bringing awareness into the realm of cybersecurity – to whom the information security industry is profoundly indebted. The parameters of selection include experience, contribution to industry, spreading cybersecurity awareness, authorship, speaking roles, awards & recognitions, influencer status, and patents.

Theresa Payton remains the cybersecurity and intelligence operations expert that people and companies turn to regard efforts to strengthen their privacy and cybersecurity. She is one of America’s most respected authorities on security and intelligence operations.

As the first female to serve as White House Chief Information Officer, Payton oversaw IT operations for the President and his staff from 2006 to 2008. Previously, she held executive roles in banking technology at Bank of America and Wells Fargo, facilitating her broad knowledge of cybersecurity risks and measures in the financial services industry. Currently, as the founder, president, and CEO of a world-class cybersecurity consulting company, Fortalice Solutions, LLC, and co-Founder of Dark3, a cybersecurity product company, she remains the expert that organizations call for discretion and help to understand and improving their IT systems.

Payton collaborated with cybersecurity and privacy attorney, Ted Claypoole, to author two books focused on helping others learn how to protect their privacy online, after receiving a number of pleas from friends and strangers regarding account hacking. Hailed as must-reads, “Privacy in the Age of Big Data” and “Protecting Your Internet Identity: Are You Naked Online?” outline peoples’ rights, as well as tips and strategies for building and maintaining a positive online image. Jon Stewart had Payton on The Daily Show to discuss her book and the emerging threats to our privacy and security.

Payton is often sought out by media news outlets to explain complex security issues in business and consumer terms to get behind the hype to understand, in layman’s terms, how to protect your privacy and security. She has been a repeat guest on the Today Show, Good Morning America, Fox Business Shows, Fox News Shows, CBS Morning & Evening News, CNN, NBC News, MSNBC, and even news outlets in Canada and Ireland. Recognized as a 2015 William J. Clinton distinguished lecturer by the Clinton School of Public Service, Payton passionately protects her clients, from the board room to the server room, and helps them understand the business risks to their organization’s cybersecurity, and she and her team provide insight and methods critical to protecting people and organizations from rapidly evolving cyberattacks. She and the Fortalice team were recently named to the Top 5 Most Innovative Cybersecurity Companies in NoVa/MD/DC.


Our December issue on Endpoint Security is now live. Subscribe now!

Federated Learning Can Solve Security and Data Privacy Challenges: Intel Labs

Federated Learning, Intel Labs
Image Credit: Intel Labs

In many fields like medicine and financial services, the owners of data are bound by regulatory restrictions around data privacy. That can be a real inhibitor to bringing larger data sets together, which in turn limits how much we can learn from that data. To tackle these issues Intel Labs has been making advances in Confidential Computing and Federated Learning.

By Brian Pereira, Principal Editor, CISO MAG

Speaking at Intel Labs Day on December 3, Jason MartinPrincipal Engineer, Secure Intelligence at Intel Labs, explained Intel’s Confidential Computing initiative.

“Today encryption is being used to protect data while it is being sent across the network and while it is stored. But data can still be vulnerable when it is being used. Confidential Computing allows data to be protected while in use,” said Martin.

There are three tenets to Intel Labs’  Confidential Computing:

  1. Data confidentiality –  to protect secrets from exposure.
  2. Execution integrity – to protect the computation from being changed.
  3. Attestation –  to verify the hardware and software are genuine, and not fake.

Trusted execution environments provide a mechanism to perform confidential computing. They’re designed to minimize the set of hardware and software you need to trust to keep your data secure.

“To reduce the software that you must rely on, you need to ensure that other applications, or even the operating system, can’t compromise your data, even if malware is present. Think of it as a safe that protects your valuables even from an intruder in the building,” said Martin.

In the early 2000s Intel Labs began research in ways to isolate applications using a combination of hardware access control techniques and encryption in order to provide confidentiality and integrity. The latest example of putting the capabilities of confidentiality, integrity and attestation together, to protect data in use, is Intel Software Guard Extensions.

All this will protect data on a single computer.

But what if you have multiple systems and data sets and with different owners? How can we support multiple parties to collaborate in a secure way with their sensitive data?

This is where Federated Learning comes in.


RELATED STORY:

Google Cloud Levels-up Confidential Computing with Latest Updates


What is Federated Learning?

Martin explained: “In many industries such as retail, manufacturing, health care, and financial services, the largest data sets are locked up in what is called data silos. These data silos may exist to address privacy concerns or regulatory challenges, or in some cases, the data is just too large to move. However, these data silos create obstacles, when using machine learning tools to gain valuable insights from the data.”

Take medical imaging, for instance. Machine learning has made advances in identifying key patterns in MRIs such as the location of brain tumors. However, getting multiple entities to collaborate in the processing/computation of the data is an inhibiting factor, due to data privacy concerns. Patient data and medical records are protected by standards like HIPAA.

Intel Labs has been collaborating with the Center for Biomedical Image Computing and Analytics at the University of Pennsylvania Perelman School of Medicine (Penn Medicine) — on federated learning.

“In our federated tumor segmentation project, we are co-developing technology to train artificial intelligence models to identify brain tumors,” informed Martin.

Federated Learning
Image Credit: Intel Labs

With federated learning, Intel’s scientists can split the computations, such that each hospital trains the local version of the algorithm on their data at the hospital. And the hospitals can send what they learn to a central aggregator. This combines the models from each hospital into a single model without sharing the data.

However, this poses another challenge. When the computation is split in this manner, you increase the risk of tampering with the computation. To tackle this, each hospital uses confidential computing. This protects the confidentiality of the machine learning model. Intel Labs and the hospitals also use integrity and attestation, to ensure that the data and model are not manipulated at the hospital level.

Federated Learning
Image Credit: Intel Labs

Penn Medicine and Intel Labs published a paper on Federated Learning in the medical imaging domain. The study demonstrated that the federated learning method could train a deep learning model, with 99% accuracy of the same model trained with the traditional non-private method.

The combined research also showed that institutions did on average 17% better when trained in the federation, compared to training with their own validation data (2.6%).

Federated Learning
Image Credit: Intel Labs

Work on this continues and will eventually enable a federation of over 40 international health care and research institutions to collaborate on creating new state-of-the-art AI models, without sensitive patient data leaving the hospitals.

Keep track of Intel Labs’ progress on Federated Learning here: Intel Labs Day 2020 | Intel Newsroom


Brian Pereira

About the Author

Brian Pereira is the Principal Editor of CISO MAG. He has been writing on business technology concepts for the past 26 years and has achieved basic certifications in cloud computing (IBM) and cybersecurity (EC-Council).


 

Sodinokibi Rundown: What it is, why it’s a growing problem, and how to protect against it?

paying ransom, Conti Ransomware Attacks

Sodinokibi ransomware has been wreaking havoc across the globe, hitting high-profile targets like CTAG, one of Europe’s leading automotive research centers, and a housing association in the U.K. Sodinokibi ransomware is currently ranked as one of the most widely distributed ransomware strains worldwide making it a nightmare for the corporate sector.

By Jeff Stout, Chief of Operations, BeforeCrypt GmbH

So, what makes Sodinokibi so dangerous, and how can you protect yourself and your organization?

The Sodinokibi Threat 

Sodinokibi is one of the most common variants of ransomware used by the REvil ransomware gang. It’s especially dangerous because the gang is highly skilled at exfiltrating data which it uses to “double-extort” victims. Ordinary ransomware attacks only encrypt data, locking users out of their own system, and forcing them to pay to regain access to their files.

Data exfiltration attacks collect sensitive data and then demand more money from victims to keep the data private. For some companies, particularly in the finance, legal and health sectors, leaking client data can cause a devastating blow to their reputation. When hackers obtain data, they threaten to publish it on the dark web. In this way, they can demand much larger ransoms.

For this reason, REvil intentionally targets businesses and organizations that are responsible for safeguarding important client data. A ransomware attack with data exfiltration can be more complicated to deal with than a normal encryption attack because of the legal implications of data breaches.

In recent months, Sodinokibi has become even more dangerous as it made the jump from Windows to Linux. Since most servers run on Linux, this means the virus is now even more capable of targeting large corporate or governmental networks.

REvil’s Modus Operandi

REvil is one of the most prolific ransomware gangs in the world. Part of the secret to their success is the use of affiliates to shield themselves. They develop sophisticated ransomware software and then license it out to other criminals in exchange for a percentage of the profits. This approach is termed “ransomware-as-a-service” (RaaS). Some of these affiliates have been arrested, but it doesn’t appear to have any effect on the core gang, which simply recruits new affiliates.

Many experts believe that Sodinokibi was designed by the same hackers who developed GandCrab, Sodinokibi’s predecessor, which collected over $2 billion in ransoms before its retirement.

Since the developers of the software don’t conduct the attacks themselves, they are able to specialize and develop more advanced viruses that are more difficult to detect and can circumvent antivirus software. Sodinokibi is one of the most effective ransomware in terms of data exfiltration; it’s estimated that over 50% of Sodinokibi attacks lead to data exfiltration.

How Sodinokibi attacks happen, and how to protect against them?

The majority of Sodinokibi attacks are highly targeted in nature. Jeff Stout, a ransomware expert at BeforeCrypt, a firm specializing in ransomware recovery and decryption, says that in most cases, Sodinkobi infiltration occurs via phishing.

“Our case data shows that less than 20% of Sodinokibi cases involve random brute force attacks against vectors such as RDP, with the vast majority of attacks being highly targeted and perpetuated as part of sophisticated spear-phishing attacks employing exploits with various characteristics.”

Spear phishing attacks are becoming more sophisticated all the time, and hackers are increasingly known to effectively impersonate trusted businesses, partners, or even family and friends in order to trick victims into clicking malicious links.

The risk of these attacks can also be reduced substantially by adopting strict guidelines to ensure that employees don’t do any personal communications on work computers or networks. Social media giant Twitter was recently hit by a spear-phishing attack that infiltrated the network by targeting employees’ phones. Similar attacks have hit dozens of other companies since.

Training employees to carefully verify all links and downloads before clicking on them is a good start, but a highly effective ransomware prevention strategy may even require some level of structural reorganization. For example, many targeted attacks will attempt to trick dozens of employees before one falls for it, so by adding tiers of access levels to networks and limiting the number of employees with the access necessary to mount an attack, it’s possible to lower the chances of a successful attack.

Of course, there are still a small number of Sodinokibi attacks that utilize conventional exploits. This risk can be minimized by normal countermeasures, like strong antivirus software, regularly updating all software, and keeping up to date with exploit databases.

What to do if you get hit?

There is no easy way out of a Sodinokibi attack. Like most ransomware, Sodinokibi uses military-grade encryption, so there are no free Sodinokibi decryption tools. It’s a bitter pill to swallow, but the reason many organizations pay ransoms is nothing more than an economic decision; if the cost of the ransom is less than the cost of the data loss that would result from not paying it, it just makes sense to pay it. However, paying ransoms empower the hackers who deploy them, so if a company can handle a loss it’s a more responsible decision to take their losses and start from scratch.

Paying a ransom is not as simple as it might sound, however. Ransomware gangs using Sodinokibi will often demand a first ransom to decrypt the data and restore access to a network and then ask for a second ransom to keep the data private. In some cases, attackers will demand a third ransom even after the second one. For this reason, experts track the behavior of individual gangs in order to know what to expect and how to best deal with them.

Contracting a ransomware incident response team can be worthwhile, as specialists have a good idea of what to expect from different gangs. This makes it easier to calculate the real cost of the attack and make a more informed decision about whether or not paying the ransom is the most economical decision.

When will it end?

Unfortunately, it appears that dealing with ransomware, as well as the data exfiltration threat, may become the new normal. Both GandCrab and Sodinokibi were designed with code embedded which prevents them from infecting computers in Russia, Iran, and former Soviet countries. This indicates that the hackers may be operating with the approval of a government in that region.

Since the criminals behind it may have some level of state protection, it is very difficult to bring them to justice. This means organizations of all shapes and sizes must devote more time and resources to their cybersecurity training, especially when it comes to employee training and awareness. This means increased cybersecurity budgets are needed, but the longer the ransomware epidemic continues, the clearer it becomes that these costs are insignificant compared to the costs of falling victim to ransomware extortion.


SPECIAL FEATURES

Disclaimer

CISO MAG did not evaluate the advertised/mentioned product, service, or company, nor does it endorse any of the claims made by the advertisement/writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Supply Chain Security Takes Center Stage in Dell’s Latest Offering

Supply chain

Dell is known to deliver innovative and extremely critical solutions to the world. Continuing this tradition, on December 3, 2020, Dell introduced a new set of security offerings to mainly strengthen its supply chain security product suite. It includes SafeSupply Chain Tamper Evident Services and SafeSupply Chain Data Sanitization Services.

SafeSupply Chain Tamper Evident Services adds tamper-evident seals that ensure the integrity of a device during transport. This enables the receiver to know if any modifications were made to the device during transit — for extra security, customers can also request pallet seals.

Similarly, SafeSupply Chain Data Sanitization Services enable organizations to perform a hard drive wipe before installing their images on the drive. With this, they can be sure that there is no spyware or other malware on the device.

Additionally, Dell also announced that its EMC PowerEdge server portfolio will now be laced with Secured Component Verification. This is an embedded certificate that allows companies to verify whether their servers have arrived as they were ordered and built – without any hardware compromise. When it comes to boot security for PowerEdge customers, Dell said that they can now customize the boot process on their servers to trim down the attack surface. This capability is called PowerEdge UEFI Secure Boot Customization.

As an add-on feature, Dell has also integrated Dell Remote Access Controller (iDRAC) for PowerEdge servers. This gives its users the power to enable or disable a system lockdown without needing to do a reboot, thus, preventing inadvertent or malicious modifications to firmware or configuration data. To beef up the security of iDRAC Dell has also provided multi-factor authentication (MFA) to it.

The tech giant has already rolled out most of its offerings, however, iDRAC security updates will be available by year-end.


Related News:

Update Now! Dell EMC Releases Patch for iDRAC Path Traversal Vulnerability

Lazarus Strikes Again, Attacks Supply Chain in South Korea

Diversify Your Supply Chain to Survive Pandemics, says Deutsche Telekom CSO

4 Times Data Regulators Slapped High Penalties in 2020

France Fines Facebook and Google,Russia fines Google, Meta heavily New York City Law Department Hit by a Cyberattack

Apart from information leaks and reputation damage, data breaches cause a huge financial impact on organizations globally. Ever since the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA) came into effect, data regulators got stringent about organizations that are not serious about their consumer data protection.

By Rudra Srinivas, Feature Writer, CISO MAG

A recent survey on the financial impact of data breaches on organizations revealed that security incidents cost $3.86 million per breach on average for companies. It is found that around 80% of security incidents resulted in the exposure of customers’ personally identifiable information (PII), which in turn led to huge losses for businesses.

Various organizations have been slammed with sizable fines and settlements for data breaches or misusing customers’ information. The year 2020 has witnessed a significant number of organizations that settled their long-awaited class-action lawsuits. These include:

1. Hanna Andersson

U.S.-based kids wear retailer Hanna Andersson recently agreed to pay $400,000 to settle a data breach lawsuit related to the California Consumer Privacy Act (CCPA). The lawsuit claimed that Hanna Andersson and its third-party vendor Salesforce violated the CCPA by exposing customers’ personally identifiable information (PII) in a 2019 data breach. Unknown threat actors compromised Hanna’s retail website in December 2019. The attackers stole credit card details, including customer name, payment card number, CVV code, expiration date — along with billing and shipping addresses from the checkout and payment page of the online portal.

The class-action lawsuit, which is the first monetary settlement under CCPA, was filed in the U.S. District Court for the Northern District of California in February 2020. As per the settlement, more than 200,000 U.S. customers, who made purchases from the Hanna Andersson online store from September 16 to November 11, 2019, will receive $500 to $5,000 compensation.

2. Home Depot

The popular U.S. home improvement retailer Home Depot Inc. recently agreed to pay $17.5 million to settle a multistate investigation related to a data breach, which occurred between April 10, 2014, and September 13, 2014. The threat actors illicitly accessed the payment card details of 40 million customers. Cybercriminals misused a vendor’s username and password to break into Home Depot’s network and install a malicious code to obtain customers’ payment card data. The breach affected the customers who used self-checkout terminals of Home Depot stores across the U.S. and Canada. It is also estimated to have affected over 52 million customers’ data.

3. Anthem

Health insurer Anthem committed to pay $39.5 million to resolve a class-action suit related to a cyberattack in 2015 that exposed the personal data of nearly 79 million people. The settlement is related to an investigation brought by the U.S. states’ attorneys general, including New York, Indiana, Connecticut, Illinois, Kentucky, Massachusetts, and Missouri. The cyberattack, which, in its time, was considered one of the biggest cybersecurity attacks the nation had ever witnessed, had compromised users’ names, addresses, social security numbers, and medical identification numbers. Anthem also agreed to enhance its ongoing data protection measures.

4. Equifax

Atlanta-based consumer credit reporting agency Equifax settled multiple class-action lawsuits this year. In January 2020, the company agreed to pay $380.5 million to resolve a lawsuit, brought forward by the U.S. Federal Trade Commission (FTC), relating to a 2017 data breach that leaked a massive amount of information about more than 147 million people in the U.S. alone. Despite knowing the breach on July 29, 2017, Equifax waited nearly six weeks to disclose the incident to its consumers and investors, after hackers exfiltrated data for 76 days. The class-action members can withdraw up to $20,000 as compensation along with ten years of free credit monitoring services from Equifax.

In April 2020, Equifax resolved another lawsuit with the State of Indiana in a $19.5 million settlement, brought forward by the State’s Attorney General Curtis Hill. The lawsuit concerns the same 2017 data breach that also leaked 3.9 million Indiana residents’ personal information. The lawsuit claimed that Equifax failed to protect its residents’ social security numbers and other private information. As per the settlement, Equifax is also required to correct Indiana’s security deficiencies and safeguard consumer information in the future. Multiple organizations are making the headlines for weakly protected enterprise networks and poor handling of data breaches. It’s high time organizations take information security and compliance very seriously and have strict access controls on the data, or we may continue to see the number rising.

About the Author

 

Rudra Srinivas is a Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.

Lisa Ventura is CISO MAG Infosec Superwoman of the Year (2020)

Infosec Superwoman of the Year

The CISO MAG Infosec Superwoman of the Year recognition honors the most influential women in cybersecurity. These are women who have, over the years, been committed to bringing awareness into the realm of cybersecurity – to whom the information security industry is profoundly indebted. The parameters of selection include experience, contribution to industry, spreading cybersecurity awareness, authorship, speaking roles, awards & recognitions, influencer status, and patents.

Lisa Ventura is an award-winning cybersecurity and content marketing consultant whose career spans over 23 years in PR marketing, technology, and cybersecurity. She entered the cybersecurity industry in 2009 when she became the Chief Operations Officer/PR & Marketing Director at Titania Ltd., a leading cybersecurity software development company in the U.K.

During her time at Titania, she saw the company grow from a tiny start-up to a successful small business with members of staff, offices, and a network of distributors and resellers globally.

Since her time at Titania, Lisa has utilized her expertise in cybersecurity in many other organizations including BT, and more recently as Cyber Security Awareness Professional.

Lisa is a published author and has recently contributed articles to Counter Terror Business Magazine, Europa Business Magazine, and the BPMA Magazine amongst others. Her book entitled “The Rise of the Cyber Women,” which is a collection of interviews and accounts from some of the most inspiring women in the cybersecurity industry today, was released in August 2020.

She also has other books in the pipeline including “Picking Apart The Threads: How One Docu-Film About Nuclear War Influenced a Cold-War Generation,” which was conceived through her strong interest in all things related to nuclear war.

As the Founder and CEO of the U.K. Cyber Security Association, Lisa is known for her expertise as a thought leader and commentator. The U.K. Cyber Security Association is a not-for-profit organization that raises awareness of the importance of cybersecurity for small businesses and SME’s and provides education on the growing cyberthreat to individuals and businesses. As a result of this work, Lisa is also in high demand as a speaker and panelist at various cybersecurity, technology, and IT conferences and events.

Neurodivergent and proud, Lisa is a strong advocate of all things related to neurodiversity since she was diagnosed as being #ActuallyAutistic in June 2018. She is also a strong supporter of promoting cybersecurity as a career path to those who are autistic and neurodivergent and is a mentor to those who are considering entering the cybersecurity and marketing industries. In addition, Lisa is a strong business mentor for Women in Business, Women in Cyber Security, Women in Tech, and more.


Our December issue on Endpoint Security is now live. Subscribe now!

 

FireEye Discloses Breach and Theft of its Red Team Tools

FireEye’s Red Team tools breach

Popular cybersecurity firm FireEye announced that it is a victim of a sophisticated state-sponsored cyberattack. In an official release, the company stated that the attacker compromised its Red Team software tools and accessed information from its internal systems. While there is no information on whether any customers’ data has been misused, the company stated that it is likely a government-backed cyber operation performed using new hacking techniques.

“A highly sophisticated state-sponsored adversary stole FireEye Red Team tools. Because we believe that an adversary possesses these tools, and we do not know whether the attacker intends to use the stolen tools themselves or publicly disclose them, FireEye is releasing hundreds of countermeasures to enable the broader security community to protect themselves against these tools,” FireEye said.

FireEye stated has incorporated certain countermeasures in its security products and shared the same with its partners and government agencies to prevent malicious actors from trying to exploit the Red Team tools.

What’s a Red Team?

A Red Team is a group of security experts who penetrate the network systems or exploit capabilities to test an enterprise’s security standards. The purpose of ​​this exercise is to determine potential vulnerabilities and find the organization’s abilities to prevent, detect, and respond to cyberattacks. The alternative to the Red Team experts is the Blue Team, a team of network defenders trying to protect the security perimeter of the organization.

Experts Tweet

“The Red Team tools stolen by the attacker did not contain zero-day exploits. The tools apply well-known and documented methods that are used by other red teams around the world. Although we do not believe that this theft will greatly advance the attacker’s overall capabilities, FireEye is doing everything it can to prevent such a scenario. It’s important to note that FireEye has not seen these tools disseminated or used by any adversaries, and we will continue to monitor for any such activity along with our security partners,” FireEye added.