Home Blog Page 143

Over 126 Mn People are Victims of Cybercrime Across U.S. and U.K.

Over 126 Mn People are Victims of Cybercrime Across U.S. and U.K.

A cybercrime research report from Clario and Demos revealed that nearly 64% of Americans are worried about their financial data being accessed illegally, and 53% think there have been more online scams since the beginning of the pandemic. The research “the State of Cybercrime in U.S. and U.K.” uncovered the issues relating to rising cybercrimes and their impact on consumers in the U.K. and the U.S.

Key Takeaways

  • The staggering total cost of cybercrime will amount to around six trillion dollars by 2024.
  • One in three Americans and one in five Britons has been a victim of cybercrime – equivalent to 126 million people across the two countries.
  • Only one in four Britons (27%) and four in ten Americans (40%) who were victims reported the crime.
  • Both law enforcement and victim support regarding cybercrime are woefully inadequate in both the U.K. and the U.S. Just 1% of annual Cybercrime incidents in the U.S. lead to an arrest, let alone prosecution.
  • Many victims suffer serious psychological effects due to the financial losses of cybercrime including self-harm, suicidal thoughts, and depression. 75% experience stress, 70% anxiety, 52% fear, 51% shame, 48% anger, and 43% isolation.
  • People are aware that there are dangers in principle, but are not protecting themselves in practice. 59% of Britons and 55% of Americans still do not invest in protecting themselves from online fraud.
  • The growth of Cybercrime-as-a-Service means that even the least tech-savvy criminals can now pay to target everyday consumers. The COVID-19 pandemic saw an intensification in criminal capabilities, with people exploiting an increased reliance on technology while targeting pressing fears or anxieties.

Scarlet Jeffers, VP of UX at Clario, said, “The report demonstrates a disconnect between American’s concerns about security and their own knowledge and ability to take action when comes to protecting themselves online. This is especially important when you consider we are living in a world where our lives are managed almost entirely online. The public have been made to think that cybercrime isn’t preventable and that they should suffer in silence because, so little is done to reprimand hackers. We need to change people’s perceptions and raise awareness of how consumers can strengthen their cybersecurity to not only protect their personal data but their digital lives.”

Web Hosting Provider Managed.com Suffers Ransomware Attack

Hive Ransomware

Managed web hosting provider Managed.com has temporarily taken down its servers and web hosting systems after suffering a suspected ransomware attack. In a security release, the company stated that they had encountered an issue affecting the availability of their web hosting services. The attack impacted a limited number of the company’s systems and files with critical data.

While the threat actors behind the ransomware attack are unknown, Managed.com said it is working with law enforcement to identify the attackers and restore its operations.

“Upon further investigation and out of an abundance of caution, we took down our entire system to ensure further customer sites were not compromised. Our Technology and Information Security teams are working diligently to eliminate the threat and restore our customers to full capacity. Our first priority is the safety and security of your data. We are working directly with law enforcement agencies to identify the entities involved in this attack,” Managed.com said in a statement.

Have you heard about REvil?

Multiple reports claim that the attack on Managed.com is linked to REvil ransomware operators, who demanded over $500,000 ransom in Monero to receive a decryption key.  REvil is a Ransomware-as-a-Service that affected various organizations globally. REvil operators recently carried out a cyberattack on New York-based law firm Grubman Shire Meiselas & Sacks. In the attack, the cybercriminals claimed to have stolen nearly 756 GB data of several high-profile celebrities like Lady Gaga, Elton John, Robert DeNiro, and Madonna. Grubman Shire Meiselas & Sacks is a premier entertainment and media law firm handling the legal profiles of Hollywood A-listers.

REvil operators also launched an auction website on the dark web, Happy Blog, to sell stolen data from victims who have denied paying ransom. REvil is auctioning the stolen data of a U.S. food distributor and a Canadian agricultural company, for starting prices of $100,000 and $50,000 respectively. To read full story, click here…

21 Questions to Determine if Your MSP is Ready for Prime Time or is Setting the Stage for Cybersecurity Problems

managed services provider (msp)

As if 2020 wasn’t challenging enough for businesses, reports warn that Managed Service Providers (MSPs), often contracted to provide outsourced IT and cybersecurity services, can represent a significant security risk to the companies they protect. The U.S. Government and cybersecurity firms are sounding the alarm that MSPs represent a significant threat vector for enabling breaches or spreading ransomware to their customers.

By Ryan Heidorn is a Co-Founder and Managing Partner at Steel Root

Ironically, many businesses hire MSPs to address their cybersecurity challenges (a 2019 SANS Institute survey found that one-third of small business respondents were outsourcing cybersecurity). But the MSP cybermaturity problem is real – and well documented. In a security alert released in June 2020, the U.S. Secret Service warned that their global investigations team continues to see an increase in incidents of hackers specifically targeting MSPs as a springboard into their customers’ internal networks.

Because MSPs often use centralized platforms to manage remote access into their customers’ environments, they are an attractive target for cybercriminals seeking to exploit this one-to-many relationship. CrowdStrike’s 2020 Global Threat Report states, “An alarming trend in targeted ransomware operations is the compromise of MSPs. Subsequent use of remote management software can enable the spread of ransomware to many companies from a single point of entry.”

Perch Security details real-world examples of this threat in their 2020 MSP Threat Report. One of the most prominent examples is APT10, a nation-state hacker group, attributed to China, also known as STONE PANDA. In 2019, the FBI reported that APT10 had hacked into the eight largest MSPs, with the end goal of pivoting into the MSPs’ customers’ networks.

If your business uses a third-party vendor like an MSP or MSSP to manage your IT or security operations, for better or worse, you inherit many elements of the vendor’s own internal cybersecurity maturity (or immaturity). Because of the direct relationship between your MSP’s security practices and your organization’s security posture, there is significant upside for your organization if your MSP has developed a mature security practice and substantial risk if they have not.

The “maturity check” below includes 21 questions you should ask to vet a potential MSP or MSSP partner to understand their security posture, along with some suggested actions based on the answers you may receive.


Security starts with governance

1. Is the MSP’s security program based on a publicly vetted framework, such as the NIST Cybersecurity Framework or CIS Controls? It should be. When it comes to building cybersecurity maturity, a standards-based approach is always better than trying to piece together ad hoc

2. Has the MSP designated an internal Information Security Officer or similar role? Ask about this person’s experience and qualifications, if he or she exists, as well as finding out how many other internal staff are in security-relevant roles.

3. Request a copy of the MSP’s information security plan and related policies. You’ll likely need to be under NDA for the vendor to consider sharing these documents. If they are reticent to provide this information, ask if you can see the table of contents – this may give you an idea of how robust their security program is (or is not).

4. How does the MSP support their clients’ compliance requirements? (For companies subject to DFARS or CMMC, see our article on additional compliance considerations for working with an MSP.)

Get to know the people you’ll be working with

5. Will the MSP subcontract any work in conjunction with delivering services to your business? If so, you should find out if these contractors are contractually bound by the MSP’s security policies, and/or if relevant compliance requirements flow down contractually from you, the client, to relevant subcontractors.

6. What kind of background checks does the MSP conduct on its employees and contractors? Make sure these checks are, at the very least, on par with what your company requires for its own employees.

7. If you need to comply with export control requirements like EAR or ITAR, are the MSP’s staff all US Persons? They likely need to be if they will have access to your network.

8. Does the MSP employ individuals with cybersecurity credentials such as CISSP or CISM? Certifications aren’t everything, but they are an indicator that the MSP has invested in hiring the necessary skillsets to secure their own systems and manage yours.

Your MSP should practice what they preach

9. What security technologies are employed on the MSP’s internal systems and infrastructure? Make sure the MSP is meeting best practices in basic cybersecurity hygiene categories like network security, access control, and multi-factor authentication.

10. How does the MSP assess and manage risk? Determine the frequency with which the MSP conducts risk assessments and ask for details (who, what, when, where, how) on their internal risk management program.

11. Where does the MSP store client data – including network diagrams, configurations, and knowledge base articles – and what access controls, authentication methods, or other security practices are in place to ensure that client security and compliance requirements are being met?

12. Does the MSP conduct regular vulnerability scanning of its environment? If so, are scans conducted internally, externally, or both? You should be aware of your MSP’s process and the timeline for detecting and remediating vulnerabilities.

13. How does the MSP manage configuration changes to their internal systems? Determine if the MSP has a formal change management process in place to control the security configuration of critical systems.

Access to your network should be authorized and controlled

14. How does the MSP manage access to your environment? Many MSPs rely on software products designed to manage multiple clients simultaneously, including remote monitoring and management (RMM) platforms, which are frequently the target of attacks such as those mentioned in this article. While RMM platforms help MSPs deliver services at scale, vulnerabilities in these systems are leveraged by attackers to gain access or simultaneously spread malware to all the MSP’s clients.

  • Ask about the infrastructure used by the MSP to deliver services to clients. Where are these systems hosted – on-premises or in the cloud? Who is responsible for managing vulnerabilities on these systems – the MSP or another vendor?
  • What access controls, authentication methods, or other security practices are in place to secure these systems?
  • How does the MSP protect its systems to prevent attackers from moving laterally from one point of entry to gaining access to all the MSP’s clients? Similarly, how does the MSP segment data, documentation, and management capabilities for different clients?

15. What are the MSP’s practices for managing privileged account credentials, private keys, and other secrets? Make sure that a breach of the MSP’s RMM platform would not expose this information to attackers.

16. Does the MSP retain access logs of remote connections to their clients’ networks? If so, this information should be regularly reviewed for unauthorized activity.

17. Does the MSP operate a security operations center (SOC) or subscribe to a third-party service? There should be continuous monitoring systems in place to identify suspicious, anomalous, or unauthorized activity across the MSP’s systems and network.

The best MSPs prepare for the worst

18. What are the MSP’s backup and recovery strategies for systems that contain client data or are used to deliver services to clients?

19. Does the MSP undergo periodic testing of their security controls (e.g., penetration testing, red teaming, security controls validation)? If so, request the results of the most recent test – like security documentation, you will likely need to be under NDA to receive this information.

20. How prepared is the MSP to respond to security incidents? Request details of the MSP’s incident response plan and dig into their Service Level Agreement (SLA) for reporting incidents to clients. If it is not already part of your standard contract terms, consider contractually requiring the MSP to report relevant security incidents to you.

21. Does the MSP retain any third-party services for responding to a breach of its own systems or client systems? Determine the MSP’s insurance coverage amounts (cyber liability and professional liability) and assume the MSP will get breached – do they have the resources to respond rapidly and appropriately?

There’s no such thing as perfect security, and if your MSP doesn’t have good answers for each of these questions, it doesn’t necessarily mean they are putting your company at risk. But the strongest indicator of an MSP’s ability to secure their clients’ information may be the nature of their own internal security practices. Like the story of the cobbler’s children who go without shoes, some MSPs operate at low cybersecurity maturity even as they sell security solutions to their clients. The best way to determine if your MSP is the right fit for your business and not a potential source of cybersecurity headaches is to have a candid conversation about their security practices. Getting the answers to these 21 questions is a great place to start.


About the Author

Ryan HeidornRyan Heidorn is a Co-Founder and Managing Partner at Steel Root, a cybersecurity firm that specializes in compliance for the U.S. Defense Industrial Base. Ryan teaches cybersecurity at Endicott College and serves on the board of directors of the National Defense Industrial Association (NDIA) New England chapter.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Cisco Fixes Multiple Vulnerabilities in Cisco Security Manager

Beware! Counterfeit Cisco Switches Bypass Network Authentication

In response to the multiple Cisco Security Manager vulnerabilities reported by security researcher Florian Hauser, the networking device manufacturer has published three advisories. The vulnerabilities, if exploited, allow remote code execution (RCE), thus giving the attacker complete control of the victim’s system.

The Backstory

Hauser, who is a security researcher at Code White, had originally found 12 vulnerabilities affecting the web interface of Cisco Security Manager nearly four months back. As per standard ethical practice, Hauser shared his findings with Cisco so that they could fix it. However, even after 120 days Cisco failed to reply or acknowledge the fixes in their latest update v4.22. Hence he decided to tweet about it and go ahead with the publishing of the Proof-of-Concept (PoC) of the vulnerabilities.

Related News:

Patched! Cisco Fixes High-Severity Bugs Impacting its Fabric Services Component

Cisco finally acknowledged and contacted Hauser on November 17, and announced that they had indeed fixed the issues reported and, in response, released three advisories for the three CVEs that contained multiple vulnerabilities.

The Cisco Security Manager Vulnerabilities

As per the analysis shared by cybersecurity service provider Tenable, following was the description of the three CVEs fixed by Cisco:

  • CVE-2020-27125 (CVSSv3 score – 7.4): This is a static credential vulnerability in Cisco Security Manager. If exploited successfully, an unauthenticated remote attacker could easily obtain static credentials by viewing the source code of a specific file. This would allow the attacker to “carry out further attacks.”
  • CVE-2020-27130 (CVSSv3 score – 9.1): This is a critical path traversal vulnerability in Cisco Security Manager. If exploited successfully, an unauthenticated remote attacker could send a specially crafted request containing directory traversal character sequences (e.g. “../../”) to a vulnerable device. This would allow the attacker to arbitrarily download and upload files to the device.
  • CVE-2020-27131 (CVSSv3 score – 8.1): It addresses multiple vulnerabilities in the Java deserialization function of Cisco Security Manager. A remote attacker could exploit this vulnerability by generating malicious serialized Java objects using a tool like ysoerial.net and sending them as part of a specially crafted request to the vulnerable device. Successful exploitation would grant the attacker arbitrary code execution privileges on the device as NT AUTHORITY\SYSTEM.

Rody Quinlan, Security Response Manager at Tenable said, “These vulnerabilities are relatively easy to exploit and the researcher who discovered them, Florian Hauser, has already publicly shared proofs-of-concept (PoCs). Almost all the vulnerabilities directly give RCE, which presents multiple attack vectors that a threat actor could potentially exploit to take control of affected systems. Given the impact of exploiting these vulnerabilities could have, and the fact that PoCs are available, it is imperative organizations patch as soon as updates are released as it’s inevitable that we will see in-the-wild attacks in the coming weeks, if not days.”

Cisco has already released patches for CVE-2020-27125 and CVE-2020-27130, and a patch for CVE-2020-271131 will be made available soon. However, the company’s Security Response Team has not yet found any evidence of these vulnerabilities being exploited in the wild but cautioned its users about keeping their systems updated with the latest patches.

Related News:

Multiple Security Flaws Detected (and fixed) in Cisco Small Business Routers

Hackers Evade Secure Email Gateways via Advanced Phishing Attacks

Phishing, phishing attacks

Cybercriminals are increasingly leveraging social engineering scams via sophisticated phishing techniques. According to a research from Ironscales, nearly 50% of all advanced phishing attacks like spear-phishing and social engineering evade popular secure email gateways (SEGs). Ironscales researchers stated they evaluated the effectiveness of Microsoft ATP, Mimecast, Proofpoint, and other SEGs services in preventing advanced email attacks.

It was found that the majority of the phishing emails were social engineering techniques, including email spoofing, business email compromise (BEC), executive impersonation, and other email frauds.

Key Findings

  • The research emulated 162 emulations against the top SEGs, equating to 16,200 malicious messages sent.
  • Over 7,614 emails bypassed the SEG and landed inside the inbox. Interestingly, both Proofpoint and Mimecast incurred a greater penetration rate than Microsoft ATP.
  • The SEGs were mostly successful at thwarting phishing emulations containing malicious payloads. Emulations with links had a penetration rate of only 3%, while those with attachments had a penetration rate of just 4%.
  • The phishing attack technique with the greatest penetration rate was sender name impersonations. Sender name impersonations accounted for 30% of all SEG penetrations, which represents a 6% increase from our 2019 analysis.
  • Domain name impersonations accounted for 25% of penetrations. This represents a 23% increase from the 2019 research.
  • VIP impersonations, such as CEO spoofs, and fake login pages came in at 22% and 16%, respectively.

“From an attacker’s perspective, the transition from spear-phishing emails packed with malicious payloads to social engineering was a no brainer. The most commonly deployed secure email gateways, such as Microsoft Advanced Threat Protection (ATP), Mimecast, Proofpoint and others, were not built to analyze the language within an email and decipher a message’s context and intent,” the researchers said.

Senate Passes IoT Cybersecurity Improvement Bill by Unanimous Consent

IoT attacks

The Senate, on November 17, 2020, approved the Internet of Things Cybersecurity Improvement Act (H.R. 1668) by unanimous consent and sent it to the White House for President’s signature. The bill, which was first introduced in 2017 and reintroduced in 2019, passed the U.S. House of Representatives in September 2020 by voice vote.

The new IoT legislation, which is backed by Reps. Will Hurd (R-Tex.), Robin Kelly (D-Ill.), Sens. Mark Warner (D-Va.), and Cory Gardner (R-Colo), mandates the U.S. National Institute of Standards and Technology (NIST) to create recommendations to address cybersecurity issues and release guidelines for government agencies that align with the NIST recommendations.

The IoT Cybersecurity Improvement Act also directs NIST to work with cybersecurity researchers and industry experts to publish guidance on coordinated vulnerability disclosure to ensure that vulnerabilities related to agency devices are addressed. As per the new legislation, the federal agencies should only acquire IoT devices that meet NIST’s recommendations.

“While more and more products and even household appliances today have software functionality and internet connectivity, too few incorporate even basic safeguards and protections, posing a real risk to individual and national security. The legislation will harness the purchasing power of the federal government and incentivize companies to finally secure the devices they create and sell. I urge the President to sign this bill into law without delay,” Sen. Warner said in a media statement.

“Most experts expect tens of billions of devices operating on our networks within the next several years as the Internet of Things (IoT) landscape continues to expand. We need to make sure these devices are secure from malicious cyberattacks as they continue to transform our society and add countless new entry points into our networks, particularly when they are integrated into the federal government’s networks,” Sen. Gardner commented.

WFH Concern! 73% of Executives Worried About Distributed Workforce Risks

remote work, Remote workforce security

Cybersecurity management firm Skybox Security stated that 73% of security and IT executives across the globe are concerned about new vulnerabilities and risks introduced due to the distributed workforce. In its survey “Cybersecurity in the new normal,” Skybox Security highlighted that 2020 will be a record-breaking year for new vulnerabilities with a 34% increase year-over-year.

The report, which surveyed 295 global executives, found that organizations are overconfident in their security posture. Skybox suggested that new strategies are required to secure a long-term remote working environment.

Key Findings:

  • Over 30% of security executives said software updates and BYOD policies were deprioritized. Further, 42% noted reporting was deprioritized since the onset of the pandemic.
  • Around 32% had difficulties validating if network and security configurations undermined security posture. 55% admitted that it was at least moderately difficult for them to validate network and security configurations did not increase risk.
  • Security teams are overconfident in security posture. Only 11% confirmed they could confidently maintain a holistic view of their organizations’ attack surfaces. Shockingly, 93% of security executives were still confident that changes were correctly validated.
  • And 70% of respondents projected that at least one-third of their employees will remain remote 18 months from now.

Gidi Cohen, Co-founder and CEO, Skybox Security, said, “Traditional detect-and-respond approaches are no longer enough. A radical new approach is needed – one that is rooted in the development of preventative and prescriptive vulnerability and threat management practices. To advance change, it is integral that everything, including data and talent, is working towards enriching the security program as a whole.”

The Right Data Integrity Approach Will Ramp Up Your Cyber Protection Strategy

data integrity, website, security

Way back in 2018, cyber threats were prevalent, but those were simple attacks that penetrated the data center and randomly encrypted data, holding it hostage.  If you paid the ransom, it was hit or miss if the unlock keys delivered by the criminals would, in fact, unlock your data.  These were attacks by unorganized, unsophisticated rouge cyber thugs.

By Jim McGann, Vice President Marketing & Business Development, Index Engines

Fast forward to 2020, amid a global pandemic, these cyber thugs have transformed into cyber opportunists.  They have invested in technology and resources that make them smarter and their attacks far more sophisticated.  Let’s review some of their latest tactics:

  • Cyberattack as a Service (CAaaS): Cyber organizations now run as global enterprises.  They offer a service where you can call them and they will plan and execute an attack based on your request and share in the revenue.  They have help desks and financing to make it easy to monetize the attack on the organization of your choice.  Disgruntled students, employees, or customers can now attack any size organization without any technical expertise.
  • New Approaches: Cybercriminals are deploying new and intelligent approaches that easily circumvent real-time security solutions to penetrate the data center. The Ragnar Locker ransomware deploys virtual machines to dodge security and bypasses most common security scanners – once inside the data center they deploy.  WastedLocker evades traditional security products that are scanning files on disk by hiding in cache memory.  Once real-time security and behavioral analytics solutions are updated to protect against these new approaches, the cybercriminals will move on and continue to find new successful methods of attack.
  • Data Breaches: Cyberthreats are now becoming data breaches.  Cybercriminals have quickly realized they can make money by holding data ransom, but even more money by finding sensitive data and extracting it from the data center and threatening to publish it to the world.  What used to be an internal attack that could potentially be hidden from the public now has become a global data breach that severely impacts the company’s reputation with customers.

The ransomware market has transitioned this year from a bunch of independent cybercriminals to sophisticated technology organizations that are smarter and more profitable than their predecessors. These organizations have invested in technology and expanded their activity ensuring that every organization can expect to face an attack regardless of the security defenses they have deployed.

The Last Line of Defense

With cybercriminals circumventing real-time protection and behavioral analytics, what can you do?  The answer is to continue to strengthen your existing security solutions, assuming they will protect you from the bulk of the threats.  Beyond real-time security, you should also continually validate the integrity of your data to ensure it is protected and reliable and has not already been corrupted by ransomware.

Some technology providers approach validating data integrity by looking at file metadata; others look at event logs or user behavior for unusual activity, and others rely on signature-based tools to check for suspicious files.  But will those approaches be effective? Cybercriminals have many sophisticated approaches that will hide their tracks and circumvent these common security approaches.  In fact, many of these approaches do not observe enough evidence of an attack and make “guesses” as to signs of corruption.  This approach is fraught with false positives and even worse false negatives that miss hidden types of data corruption.

We know that cyberattacks corrupt data in a number of predictable ways.  The most common approach is encryption.  Encryption can mean many things.  Encrypting a file – this is common.  But more sophisticated approaches will encrypt content inside a file and avoid impacting the metadata, which is much harder to detect.  Another approach will encrypt the content inside a database page.  Again, this is difficult to detect, especially if you’re only analyzing metadata.

Another ransomware approach is corrupting data.  The most common method is changing or appending the extension of a file with .lol or .encrypted.  This is easy to detect.  However, more sophisticated approaches use known valid extensions to corrupt a file, such as .fun, which is a  known extension for an obscure application.  If you are just inspecting metadata a .fun file would be detected as a valid file extension and not set off any alarms.

When cybercriminals see their simple approaches failing, they will go deeper inside files and databases to execute data corruption.  They will hide their tracks and make it more difficult to detect their activity, especially if you rely on metadata-only analytics.

Content-Based Analytics and Data Integrity

The only confident approach towards checking data’s integrity is through the use of full-content-based analytics.  These analytics look inside every file and database for signs of corruption.  This approach will not only find the more sophisticated signs of corruption mentioned above but will provide a high level of confidence that data has integrity and is clean from tampering allowing for informed and streamlined recovery in the event of an attack.

Content-based analytics that looks inside every file is a technology challenge.  Some vendors accept that this is difficult or impossible, based on their architecture, and will simply examine file metadata, stating that this approach is “good enough.”  This has its flaws, as previously discussed, and more importantly, when cybercriminals see these types of attacks on metadata are detected, they will go deeper to hide their tracks inside the content.  Basing your cyber analytics on metadata-only will hurt you in the long run.

Another compromised approach is only using content-based analytics on a small subset of the data.  One vendor looks for signs of metadata corruption in the first analytics pass and then sends those corrupt files for more comprehensive content-based analytics.  But again, when cybercriminals detect that the metadata analytics are uncovering their tracks, they will go deeper and utilize more extensive content-based approaches.  This will render this two-step approach (metadata followed by content analytics) approach useless.

Find a Cybersecurity Product that Works Smarter, Not Harder

Metadata based analytics can only provide up to 88% level of confidence that corruption exists, and when cybercriminals go deeper into the corruption of content, this level of confidence will plummet. Checking the integrity of files through full-content analytics provides a 99.5% level of confidence that data has not been corrupted by malware. If corruption is detected, the solution should have the ability to report on the last good version of files for rapid recovery and minimized disruption.

Enterprises need a solution that inspects both the metadata and content inside every file and database at scale to validate the integrity of files and databases efficiently.  By implementing a solution with full-content analytics using a single-pass approach, organizations will have confidence in their data’s integrity while minimizing false positives and negatives.

Conclusion

As cybercriminals get smarter and more organized, it is critical that organizations deploy more advanced and diverse approaches that will help thwart these attacks.  Without a new layer of defense that checks the integrity of data using content-based analytics, organizations will continue to be vulnerable.

The obvious choice, the best choice is to ensure that critical data assets have integrity.  The only way to achieve this is with a data analytics product that offers full-content analysis rather than just scanning metadata.  Knowing what was attacked, who was impacted, where the source of the attack occurred and when it happened is the only way to quickly recover and minimize business interruption.  Without this, you will be at the mercy of ever-increasing and sophisticated cyberthreats.


About the Author

Jim McGann has extensive experience with the eDiscovery and Information Management in the Fortune 2000 sector. Before joining Index Engines in 2004, he worked for leading software firms, including Information Builders and the French-based engineering software provider Dassault Systemes. He is a frequent writer and speaker on the topics of big data, backup tape remediation, electronic discovery, and records management.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Facebook Users Tricked in a Massive Phishing and Credit Card Scam

one million card data exposed

Cybersecurity researchers from vpnMentor uncovered a global hacking operation targeting Facebook users after discovering an unsecured Elasticsearch database obtained by the threat actors. The hackers used the database to store usernames and passwords of around 100,000 Facebook account holders. The researchers stated that fraudsters behind this scam tricked users into entering their login credentials via an application pretending to reveal their Facebook profiles visitors.

The Next Phase of Scam

Once the fraudsters had the login credentials, they accessed the accounts to comment on Facebook posts published in the victims’ network. The comments include a separate network of scam websites that redirect users to fake Bitcoin scheme sites.

Threat Summary

 

Hackers’ Target

 

Facebook Users

Type of Scam

Phishing attacks and Credit card scam

Size of data

5.5 GB+

No. of people exposed in Bitcoin scam

100,000

No. of people exposed in Facebook scam

100,000

Types of data exposed

Facebook usernames and passwords, IP Addresses

 

The scam came to light after vpnMentor’s researchers found the leaky database used by hackers to harvest and store their victims’ details. While there is no evidence about whether the unsecured database was accessed or misused by any other malicious actors, the researchers stated they reported the issue to Facebook authorities.

“The fraudsters used the stolen login credentials to share spam comments on Facebook posts via the victims hacked account, directing people to their network of scam websites. These websites all eventually led to a fake Bitcoin trading platform used to scam people out of ‘deposits’ of at least €250 ($295). It was a vast operation, spanning the entire globe,” vpnMentor said.

“The most obvious action is the fraudsters taking over a person’s Facebook account, posting a link to one of their websites on the victim’s timeline, and tricking their friends into falling prey to the scam, growing its potential impact exponentially,” vpnMentor added.

With Pluton, Microsoft Brings Chip-to-Cloud Security Tech to Windows PCs

microsoft ransomware cybersecurity CISOMAG, Microsoft Patch Tuesday October 2020

Microsoft has introduced a new security chip, “Pluton,” to its Windows PCs. The chip-to-cloud security technology, which  has already been used in Xbox and the Azure Sphere IoT security solution, aims to incorporate hardware and software security to avert cyberattack techniques and breaches.

What’s Different with Microsoft Pluton?

For the past 10 years and more, Windows PCs have been using the Trusted Platform Module (TPM) to store encryption keys and metrics that confirm the system’s integrity. However, the data is left exposed while passing through the communication channel (which is typically a Bus interface) between the TPM and the CPU. This could be fatal if the attacker has physical access to the system.

Microsoft’s Pluton chip aims to address this issue by storing the encryption keys and other critical data within the chip/processor itself. It means that with the implementation of Pluton, the need of a communication channel will be negated by building security directly into the CPU.

Related News:

Is Samsung’s New Data Security Chip a Game Changer?

Talking about the usefulness and the difference that Pluton will bring to the fore, Microsoft explained, “Windows PCs using the Pluton architecture will first emulate a TPM that works with the existing TPM specifications and APIs which will allow customers to immediately benefit from enhanced security for Windows features that rely on TPMs like BitLocker and System Guard. Windows devices with Pluton will use the Pluton security processor to protect credentials, user identities, encryption keys, and personal data. None of this information can be removed from Pluton even if an attacker has installed malware or has complete physical possession of the PC.”

Chip-to-cloud-security, Microsoft Pluton
Image Credit: Microsoft

Pluton also provides the unique Secure Hardware Cryptography Key (SHACK) technology that helps ensure keys are never exposed outside of the protected hardware, even to the Pluton firmware itself, providing an unprecedented level of security for Windows customers.

– Microsoft

Microsoft Partners for Chip-to-Cloud Security Integration

Microsoft is still uncertain about the timeline of releasing the Pluton chip to its end-users. However, they have already found efficient partners in Intel, AMD, and Qualcomm Technologies, who can potentially develop and integrate these chips with their future Windows PCs in record time.

Jason Thomas, head of product security, AMD said, “AMD and Microsoft have been closely partnering to develop and continuously improve processor-based security solutions, beginning with the Xbox One console and now in the PC. We design and build our products with security in mind and bringing Microsoft’s Pluton technology to the chip level will enhance the already strong security capabilities of our processors.”

Related News:

Japan, Canada and U.K. Welcome Google’s Security Key Called “Titan”